找回密码
 立即注册
查看: 2836|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境8 f* _% z2 Y" Y0 l6 n! Q
OS 名称: Microsoft® Windows Server® 2008 Enterprise% {0 ~5 ^8 z/ ]; @; \) `2 u% f: H' e
OS 版本: 6.0.6001 Service Pack 1 Build 6001
8 x; U8 \0 a9 N. ^  \6 ?4 ?OS 制造商: Microsoft Corporation
3 p- Q' S( p3 k3 J* T8 M: |OS 配置: 独立服务器& b2 e8 J; y9 n9 Q0 A
OS 构件类型: Multiprocessor Free
% B  ~& f6 Y1 I5 L1 p' p# j注册的所有人: Windows 用户
- L( J+ s, x$ Y2 Z1 a6 U系统型号: PowerEdge R620# X& e% J6 v: y: U$ p! i
系统类型: x64-based PC
1 j. Y8 K6 d( u处理器: 安装了 1 个处理器。
6 ^2 u# F2 m9 v2 j) ]) o[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400+ B- U" e6 w) j6 v& i- N) Y. `; N
cat md5.txt' N7 n: V" n4 P2 d# P
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/4 h4 p1 g( s! S  M9 F
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */% _7 P2 R) G2 v  U
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
+ @% x- Y% @' U6 n /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d/ C$ d$ [8 P/ v# C5 A0 S8 z" @/ ^
Input.Mode: Mask (?d?d?d?d?d)
" X9 C8 `3 }" a+ g  \# PIndex…..: 0/1 (segment), 100000 (words), 0 (bytes)+ i# R; H1 B5 @$ f: z; p, {5 B6 O
Recovered.: 0/3 hashes, 0/3 salts) ?- p6 A. r9 M4 x2 ^4 w' r
Speed/sec.: – plains, – words0 ], b; P, Z0 {) p3 C0 R
Progress..: 100000/100000 (100.00%)
8 ~! Y( N+ I! B& q* SRunning…: –:–:–:–% n& j$ O) y3 v; B& J" |! C% Y; I
Estimated.: –:–:–:–
9 |; b" w0 P) W9 R$ K/ s15b7a21513f24ffe97d9f9830acf51ad:07626c:123456( u4 \* S! R2 |/ n/ D* A; i' T* o
Input.Mode: Mask (?d?d?d?d?d?d)# C% B9 W7 Q4 H; |7 i
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)8 ^+ }% u5 t% H3 H' a
Recovered.: 1/3 hashes, 1/3 salts0 `$ a1 H4 U4 }" a
Speed/sec.: 7.43M plains, 3.72M words3 i2 C1 w8 K# _; k/ L
Progress..: 1000000/1000000 (100.00%)3 i# u- @7 W7 s# H  R
Running…: 00:00:00:01' R0 X* ^+ W. f# u9 O4 `
Estimated.: –:–:–:–5 s! Z% ~& T. G
Input.Mode: Mask (?d?d?d?d?d?d?d)- B7 C7 [7 {4 L
Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)# {  B) y% {# p
Recovered.: 1/3 hashes, 1/3 salts/ L% k6 e# U7 e( ]3 D+ p6 `) w+ d# Z' ^
Speed/sec.: 13.67M plains, 6.83M words
4 P8 Y1 ?  j* H+ x; L2 G8 {Progress..: 10000000/10000000 (100.00%)* D3 v, E- d% k
Running…: 00:00:00:01
& K4 b& S/ K* V3 J8 e# N# U0 I+ eEstimated.: –:–:–:–
  m" l# a7 G, u6 X/ i4 u5 QInput.Mode: Mask (?d?d?d?d?d?d?d?d)+ I) @/ s) D3 ^# l. [$ H  W8 B
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)& m# u* f  b4 X/ a! {* l9 n* h/ d
Recovered.: 1/3 hashes, 1/3 salts; h& e; m5 k4 W6 j9 g# d) y
Speed/sec.: 18.59M plains, 9.29M words
0 h" `6 M1 m/ K! k- x/ |8 `5 cProgress..: 100000000/100000000 (100.00%)
9 U+ q+ U3 o. K* v! hRunning…: 00:00:00:11
' [4 `# l3 E1 h- f1 m+ B4 q& _, lEstimated.: –:–:–:–
& b2 `. ]/ Y, C, \2 I865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415) S  D- f' s& |" V( X: X* j7 i
可以看到破解 9位3开纯数字密码需要11秒。" V# R+ o3 c/ X. @' X% g0 Q3 F/ r
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
" d  ]- N. d- d. M) u2 V  AIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)5 _4 [- s, w" y0 t
Recovered.: 2/3 hashes, 2/3 salts1 h3 K- L3 m* ~" n( M9 N
Speed/sec.: 12.70M plains, 12.70M words2 o7 a/ K0 F: n/ J1 u" ]/ f: s
Progress..: 10000000000/10000000000 (100.00%)
8 c1 G6 |! o4 T  T$ NRunning…: 00:00:13:07- v% `/ x* h. o
Estimated.: –:–:–:–
7 z% I4 i6 u. S' u+ h' s! c而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。* k- n1 `$ I( q) X% }2 n7 H5 ?
在这里可以下载到一些字典,不过国人对这些字典貌似无视。; s( z, c+ f7 A; I. s
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表