找回密码
 立即注册
查看: 2919|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境7 @0 M& u3 O. q* i; N4 `! v
OS 名称: Microsoft® Windows Server® 2008 Enterprise
& S0 b8 D- ]9 k! I8 m: KOS 版本: 6.0.6001 Service Pack 1 Build 6001
* I+ [: l! x4 |8 H. P# _* kOS 制造商: Microsoft Corporation
' H/ U6 N( C. M$ H7 Q* T3 a9 X4 lOS 配置: 独立服务器& P  Y3 V/ N( h6 O  y# K: l
OS 构件类型: Multiprocessor Free
- f7 @: y! X+ |* O2 N+ @注册的所有人: Windows 用户
: ]+ c3 O! H( x5 h系统型号: PowerEdge R620
3 o1 `/ G5 M# Q6 S系统类型: x64-based PC: @4 ~$ c1 A4 L9 y+ ]" p$ c
处理器: 安装了 1 个处理器。
- o6 l1 h& `3 s[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~24008 G2 k3 @; ~' q% }
cat md5.txt3 O  n9 ]3 ]; ?* V( X# V
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/
3 q+ @1 M+ ~/ m7 W6 h4 S865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */1 r6 T9 o: q; x' e0 x) ~0 q
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */* }  J$ a: [3 H" R  [
/* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
' e. n" T7 [) x0 NInput.Mode: Mask (?d?d?d?d?d)) C$ c( P8 @' ?0 R( L0 {
Index…..: 0/1 (segment), 100000 (words), 0 (bytes)% J% u, n+ J6 t; i5 j( l4 D
Recovered.: 0/3 hashes, 0/3 salts
# K% R) I4 W5 o" j- C" |- u  [) w& SSpeed/sec.: – plains, – words) E/ @% m3 p7 W* M: b+ l6 F& W. z
Progress..: 100000/100000 (100.00%)* {* y4 l+ ]& y8 }1 T' [
Running…: –:–:–:–4 F- s, M7 i' Z/ b5 ?, e: r% w3 L
Estimated.: –:–:–:–
& N4 R' f  x) V7 d% F: i7 B( I15b7a21513f24ffe97d9f9830acf51ad:07626c:123456
* f! n4 H* a9 _, g6 O, v- YInput.Mode: Mask (?d?d?d?d?d?d)
! U6 G0 W( w- H, ]Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)/ Z( ]) `- s: p  }
Recovered.: 1/3 hashes, 1/3 salts
2 s3 b. H* w1 y9 B( M/ v/ {& U, ASpeed/sec.: 7.43M plains, 3.72M words
* d+ P! C5 H% D" Q$ g% @$ eProgress..: 1000000/1000000 (100.00%)& x4 a) F) m( d' O0 x0 i1 V3 J% J
Running…: 00:00:00:01
/ s8 w8 k/ a, Y( QEstimated.: –:–:–:–
! L: E. O% v2 Q0 hInput.Mode: Mask (?d?d?d?d?d?d?d)
! M, K! o! t0 l$ @! J" `4 d9 YIndex…..: 0/1 (segment), 10000000 (words), 0 (bytes)' }/ ^9 b7 r% k. F
Recovered.: 1/3 hashes, 1/3 salts/ v9 i4 J. O! n' B8 z
Speed/sec.: 13.67M plains, 6.83M words8 ?' I& V$ [7 P, E0 M% n0 Y
Progress..: 10000000/10000000 (100.00%)6 f( a3 r* |" |4 W! j# V
Running…: 00:00:00:01; W6 l, @. l3 R1 X! M( V" R/ P' {
Estimated.: –:–:–:–5 y- u( ~! b$ i1 i6 R/ \
Input.Mode: Mask (?d?d?d?d?d?d?d?d)
# n' R( q% K9 j1 t8 XIndex…..: 0/1 (segment), 100000000 (words), 0 (bytes)! w9 q7 B7 l. G
Recovered.: 1/3 hashes, 1/3 salts
5 j8 Y# W' l- q0 w; ]6 Q* sSpeed/sec.: 18.59M plains, 9.29M words6 s: W" p! p2 [" w" T0 G8 G: `
Progress..: 100000000/100000000 (100.00%)6 @$ D% i4 c4 M
Running…: 00:00:00:11
& x) a- }7 m4 g. U7 U$ wEstimated.: –:–:–:–& a8 E) Q" n1 `$ I9 F, a
865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415
" z9 r- `% i& ?% y可以看到破解 9位3开纯数字密码需要11秒。, X3 t9 Q3 C. ^, W3 ~0 c) F, T# j
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
. F6 P- v' X1 G# eIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
: f) z& H& N. I& \- ]8 Q/ kRecovered.: 2/3 hashes, 2/3 salts
4 N) M8 n6 Y- p0 j! ^3 V6 b2 A8 USpeed/sec.: 12.70M plains, 12.70M words
# Q/ P; ^/ d: s- B0 U& B& x! A6 JProgress..: 10000000000/10000000000 (100.00%)/ t; {: s$ }* s' ^
Running…: 00:00:13:07
" m# H& F7 ~5 j8 E7 Z$ \$ bEstimated.: –:–:–:–* n- ?0 K. P* E+ c; Q. m
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。; n. m$ S9 m0 b. z! L; `! c
在这里可以下载到一些字典,不过国人对这些字典貌似无视。. b, N* X9 W4 M) i. L
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表