找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2124|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境/ b- P3 X5 r1 N8 y0 a5 b
OS 名称: Microsoft® Windows Server® 2008 Enterprise
& P, H+ l5 R7 d: K$ e- F6 \+ EOS 版本: 6.0.6001 Service Pack 1 Build 6001
! z+ `- S" i- y) D( F+ ~; I$ |OS 制造商: Microsoft Corporation5 W# y6 s8 _/ a$ U$ U, R
OS 配置: 独立服务器5 W* j5 K1 B1 h1 h- G" C1 J
OS 构件类型: Multiprocessor Free2 f4 M+ A: ^7 I! }: d
注册的所有人: Windows 用户# T5 I+ _: }$ U! c/ a5 t
系统型号: PowerEdge R620
# J4 [: \, C5 ?3 E3 T4 D系统类型: x64-based PC) F9 \, L3 U6 A
处理器: 安装了 1 个处理器。  L3 P" S# I( ~/ {, h) b* Y, l
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400
. C  Y* W# x5 b3 X8 G& x( `cat md5.txt  X6 @, q  o# f! |
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/! P! b8 p# N( e, k4 N+ o
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */% Q' D' ]& K! A% x2 k5 X/ ^1 l) \
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
; ?( U1 g% h* b /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
0 n, M$ v7 r: cInput.Mode: Mask (?d?d?d?d?d): ^7 x3 X( D5 z4 o
Index…..: 0/1 (segment), 100000 (words), 0 (bytes)' t$ G! x3 u$ y! x+ N
Recovered.: 0/3 hashes, 0/3 salts* y7 |/ v- a8 ~5 k2 y
Speed/sec.: – plains, – words
, `: r: ?" _% ]Progress..: 100000/100000 (100.00%)
: F# a* N/ L' f- x5 c0 m& K' nRunning…: –:–:–:–
9 F( S2 S, x" y; i- `/ ^Estimated.: –:–:–:–9 ]: }* ~  i8 b$ S- W9 D* p* J4 F6 T3 I
15b7a21513f24ffe97d9f9830acf51ad:07626c:123456
3 P$ k$ R, T; ?- TInput.Mode: Mask (?d?d?d?d?d?d)' W( I5 S7 |  R" ]% o
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)5 N4 }& _, G/ Y8 k( l
Recovered.: 1/3 hashes, 1/3 salts
3 C# _0 H) C% zSpeed/sec.: 7.43M plains, 3.72M words
. K& V3 r1 C" R8 a( _* ], rProgress..: 1000000/1000000 (100.00%)
9 d" X3 I3 @  y, g5 ARunning…: 00:00:00:01
( v& O4 C8 o- J! PEstimated.: –:–:–:–, n! x* Y6 ]( H- o' y$ M) ?
Input.Mode: Mask (?d?d?d?d?d?d?d)
! m- X- r, z7 i4 n' h, pIndex…..: 0/1 (segment), 10000000 (words), 0 (bytes)
' |2 x/ W! F; @- s$ fRecovered.: 1/3 hashes, 1/3 salts: C7 u8 n2 B0 Q' X/ H/ Q5 P
Speed/sec.: 13.67M plains, 6.83M words
* }/ M! [; n0 {; }2 D- vProgress..: 10000000/10000000 (100.00%)
3 n4 w. d6 L$ }7 CRunning…: 00:00:00:01$ Q' E+ S& W8 \  r5 A; R0 ]
Estimated.: –:–:–:–$ d! S/ O6 D; i. l
Input.Mode: Mask (?d?d?d?d?d?d?d?d)* i$ h+ G8 @, _6 N/ B# d
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)
+ Z8 K! O9 l# z9 b+ q% HRecovered.: 1/3 hashes, 1/3 salts5 C4 i* x5 I6 a5 F! u
Speed/sec.: 18.59M plains, 9.29M words
% s/ [; g8 a6 GProgress..: 100000000/100000000 (100.00%)
1 j) E2 P' z3 ^3 _Running…: 00:00:00:11; Z1 N. g6 K, V+ S% v" u7 P
Estimated.: –:–:–:–
0 j( {. W6 v- k1 \# C/ U) V865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415  Y" J6 K! B5 v1 ^" e* A7 N
可以看到破解 9位3开纯数字密码需要11秒。
( _; R8 E  |1 q3 y0 _: }+ r1 u! tInput.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
, ?8 X2 X( K- E# r$ Q/ j: XIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)2 B6 w2 v7 O) Q! Y% K' [; k; I
Recovered.: 2/3 hashes, 2/3 salts: c  `0 J( {. D9 x5 Z
Speed/sec.: 12.70M plains, 12.70M words* I+ P7 i; w5 e
Progress..: 10000000000/10000000000 (100.00%)" s4 H" k% G/ W  ~- h/ g
Running…: 00:00:13:07
- @, _5 d5 @  Q) W- ~" C0 T: FEstimated.: –:–:–:–2 v! Q/ N; Y6 l; s/ n) x2 h
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。  D1 f8 n' J3 v+ L
在这里可以下载到一些字典,不过国人对这些字典貌似无视。7 m) L5 _& q) _: [% t9 P
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表