找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2117|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境
% S: ~& {0 k- J# f% V1 eOS 名称: Microsoft® Windows Server® 2008 Enterprise. u5 W1 A) [* _, E+ O
OS 版本: 6.0.6001 Service Pack 1 Build 60019 l( `7 v) k' F, B6 F3 T, i
OS 制造商: Microsoft Corporation
3 i# n  _, y% LOS 配置: 独立服务器
$ C+ {3 f" t0 I4 }& V" |' G/ ~OS 构件类型: Multiprocessor Free- X+ T. o4 l. b
注册的所有人: Windows 用户
8 N$ `* N, G2 B! w" E7 e) m系统型号: PowerEdge R620
. m( v. A0 B! p- S6 O; i4 `* F% O系统类型: x64-based PC
: W6 m* J2 z8 T3 y处理器: 安装了 1 个处理器。) r! L# w' \. l8 J& l2 ?) q
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~24009 b" D: I" ?& X# ]6 P* ^
cat md5.txt
8 p% c3 y- D; {$ p1 n0 N/ C6 O9 `' C3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/' F2 T: ]4 G# V  Q( v6 o
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */5 M- c! n8 Y! k) K! |* d
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */6 J- k' P- a# v. E, B( |% z2 @
/* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d& b( }0 R. n" x$ s1 T
Input.Mode: Mask (?d?d?d?d?d)
  J! i1 J) _! ]1 {- k% _Index…..: 0/1 (segment), 100000 (words), 0 (bytes)9 M) k1 o9 S) D/ F
Recovered.: 0/3 hashes, 0/3 salts
9 s/ o! f9 y& ^0 T4 bSpeed/sec.: – plains, – words
! [) ?& c$ ~6 N5 G! h; f; sProgress..: 100000/100000 (100.00%)
3 W9 J( _) K- E) P0 Z. v6 |Running…: –:–:–:–8 a5 x" s5 P0 ]. u5 E) ?
Estimated.: –:–:–:–
, s/ X% b" a6 z15b7a21513f24ffe97d9f9830acf51ad:07626c:123456+ ]7 u5 h1 @- r
Input.Mode: Mask (?d?d?d?d?d?d): `" z) `# M( ^' |1 `
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
% r& ?; ^' [0 l7 i8 ORecovered.: 1/3 hashes, 1/3 salts
* ]7 U8 p: C0 L/ b  ~+ @Speed/sec.: 7.43M plains, 3.72M words7 O  e. D/ p4 A
Progress..: 1000000/1000000 (100.00%)& ?" ]) [  g" D/ s6 n
Running…: 00:00:00:01
8 Q8 z8 e" {9 j0 N" aEstimated.: –:–:–:–
3 V/ ^# X$ c: Q" VInput.Mode: Mask (?d?d?d?d?d?d?d)# X2 X8 r# b) U) e
Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)
4 P, G1 [+ r# g! ?Recovered.: 1/3 hashes, 1/3 salts6 s( `6 I6 l5 ]$ I/ Z2 ?+ p
Speed/sec.: 13.67M plains, 6.83M words: p; G" \- Z- R' @' u; `% Z
Progress..: 10000000/10000000 (100.00%)
' c' _% I: j7 B+ n/ s7 {. ?/ eRunning…: 00:00:00:01- t( `8 P# K6 n. q
Estimated.: –:–:–:–
/ K- K& D7 f4 L1 @& GInput.Mode: Mask (?d?d?d?d?d?d?d?d)! H2 K3 r3 Q7 D" i, @
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)( d- Z8 K* F4 Z$ m! |0 J  C
Recovered.: 1/3 hashes, 1/3 salts" m3 N( w7 h( v1 W: M7 m
Speed/sec.: 18.59M plains, 9.29M words
. t( c, S9 _# F+ KProgress..: 100000000/100000000 (100.00%)- Q5 b  J9 v% @
Running…: 00:00:00:11
2 X0 m( I) i0 Y+ }4 \5 Y5 ~; |Estimated.: –:–:–:–
/ Z1 G! }0 r' J! u$ F865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415
2 V8 l) t0 O0 c可以看到破解 9位3开纯数字密码需要11秒。/ L4 S5 Y; I/ V) F
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
5 F% n. b* U4 xIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
* ], T* T# Q+ J0 `" V5 {Recovered.: 2/3 hashes, 2/3 salts
, n$ L: S7 S  L' vSpeed/sec.: 12.70M plains, 12.70M words8 w# s: z. ~7 V% G$ x6 z: K4 F
Progress..: 10000000000/10000000000 (100.00%)
" {, }3 N9 R. D* Z% R! [Running…: 00:00:13:079 R3 s) L( T0 d# f
Estimated.: –:–:–:–
% O" L3 D% y/ ?* E8 X3 U+ u而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。( k8 I4 Y$ o0 t4 I
在这里可以下载到一些字典,不过国人对这些字典貌似无视。" h7 C' Z% {4 {1 P1 R) T; Q
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表