找回密码
 立即注册
查看: 2920|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境
1 U8 h" o: m6 T; R" ^1 D0 ROS 名称: Microsoft® Windows Server® 2008 Enterprise
! q- }. b$ Q& \% W( S9 i2 zOS 版本: 6.0.6001 Service Pack 1 Build 6001
7 i5 Z: y/ i6 q( y& `: `9 COS 制造商: Microsoft Corporation
9 \4 m& `! W+ x: mOS 配置: 独立服务器
4 W( M6 ?. B* H( O0 e/ |/ ~9 B2 pOS 构件类型: Multiprocessor Free+ N( K9 R7 |, A0 z8 M( o! w! l5 Z
注册的所有人: Windows 用户, M; p- R$ y6 B" B1 i# x
系统型号: PowerEdge R620
, Q. J, w0 S  B7 D2 g5 g系统类型: x64-based PC
# p* M/ J% s5 z! c% ?7 M% U处理器: 安装了 1 个处理器。
6 [; m( V6 R2 f0 E. W[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400
* |5 l: ~( m& j, ~: g) n& Ycat md5.txt8 V# ~( J! F2 r6 o
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/  l$ L1 \) Q5 ]
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */" A% I9 l5 Z" Y2 [, ]+ r$ n
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
( N/ H# Q6 ~* A7 C /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
% b4 ^  q* E  g6 a! ^* @Input.Mode: Mask (?d?d?d?d?d)
3 j/ B9 B; H) Q5 X" i- y2 LIndex…..: 0/1 (segment), 100000 (words), 0 (bytes)
" m' K; R' f* ]3 kRecovered.: 0/3 hashes, 0/3 salts
# J5 Z6 T& O5 w- tSpeed/sec.: – plains, – words- A& r# P  |* R* y8 _
Progress..: 100000/100000 (100.00%)
6 B7 T! s6 J" h4 r& ^; P- iRunning…: –:–:–:–; p: f; i# h* I5 r# j# d- T' e
Estimated.: –:–:–:–3 o) r3 `3 k6 o/ P% H8 ~
15b7a21513f24ffe97d9f9830acf51ad:07626c:1234560 B9 U! ]! V# ~/ }, i* ~' J) K
Input.Mode: Mask (?d?d?d?d?d?d). q) P( p/ M, O$ a8 e
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
- T/ i- V" b' d- }% |Recovered.: 1/3 hashes, 1/3 salts
& J5 R2 E5 v2 q0 j: |. f- k9 tSpeed/sec.: 7.43M plains, 3.72M words
+ s& {5 b  w" G* T, Y, {Progress..: 1000000/1000000 (100.00%)6 O" A5 Z/ o, C5 K2 i" \; S
Running…: 00:00:00:019 P3 J8 S9 ^3 y% O$ }) f$ y" {9 J/ v# w2 K
Estimated.: –:–:–:–
9 m" `: R# ?- `Input.Mode: Mask (?d?d?d?d?d?d?d)
1 x- Q7 a: T& G/ C7 w6 ZIndex…..: 0/1 (segment), 10000000 (words), 0 (bytes)
2 ?# r8 `. w" S2 n( v1 T; mRecovered.: 1/3 hashes, 1/3 salts, }' Y7 [& I' n9 D& w: G* [
Speed/sec.: 13.67M plains, 6.83M words2 T% a5 N- _) B
Progress..: 10000000/10000000 (100.00%)* H- [7 h: {9 b; O2 q' x; s: i
Running…: 00:00:00:019 H* K" Y) r2 y9 O7 a
Estimated.: –:–:–:–6 V2 p( L  Z" t2 J4 [
Input.Mode: Mask (?d?d?d?d?d?d?d?d)" R: w6 `2 W7 j7 \" c) s; p
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)3 w" _4 B  T# [9 L
Recovered.: 1/3 hashes, 1/3 salts* [0 \# D+ f/ S7 a' X
Speed/sec.: 18.59M plains, 9.29M words
8 Y% V5 N6 w2 |2 eProgress..: 100000000/100000000 (100.00%); w3 c& V+ S; a* ]" J9 m
Running…: 00:00:00:111 p, g' X& y0 J. ]5 w+ \0 u) D
Estimated.: –:–:–:–) A3 i0 T3 W$ H5 [+ i( v: N
865a697fb9b4bd9c6737432aaff136bd:22dc87:3048924151 f' T7 G. }, V5 o  A+ P; y
可以看到破解 9位3开纯数字密码需要11秒。* a' F: Y# ?' M# T
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)3 v" r  W' ?( I) ?1 Q2 k2 X
Index…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
! \/ a, Y* u9 |! ?Recovered.: 2/3 hashes, 2/3 salts. {: x  n# s% O6 E: }* `6 y+ f7 u. X
Speed/sec.: 12.70M plains, 12.70M words
$ j% e+ p5 U% k/ i7 }Progress..: 10000000000/10000000000 (100.00%)+ B9 H- \( @3 p# J- {
Running…: 00:00:13:07  m2 j1 Q& y  h  L. U
Estimated.: –:–:–:–& _# j0 Q3 b9 T' w0 F$ T' l
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。! P. x7 X( {, d8 I
在这里可以下载到一些字典,不过国人对这些字典貌似无视。! j8 S1 [/ q7 P( ?2 q
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表