找回密码
 立即注册
查看: 2674|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境
9 }; {4 ]% z% D: }, [OS 名称: Microsoft® Windows Server® 2008 Enterprise
8 H9 ?1 S$ ~3 \. K# g; [8 [. ^% e5 BOS 版本: 6.0.6001 Service Pack 1 Build 6001# ?  O0 J6 p. K9 g4 m3 w! I1 D
OS 制造商: Microsoft Corporation& P5 w% d4 q/ ^$ b8 U1 l; S! |
OS 配置: 独立服务器
, v$ ]* _+ h( w, }1 Y8 iOS 构件类型: Multiprocessor Free
6 F! f9 i; a7 Q注册的所有人: Windows 用户
8 U- M; ]& w$ b- i9 W系统型号: PowerEdge R6203 S9 v  j# A( g3 i: B, J$ h0 T! k
系统类型: x64-based PC
+ W" l1 b* h$ i6 g, o0 B" z0 M: T% e处理器: 安装了 1 个处理器。( T* I& P" E3 M1 E+ v
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~24004 H* F4 L7 A2 v7 ]8 g! H% y
cat md5.txt( a& y. Y- u; j8 Z
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/
. {/ a6 b6 y; C5 y' X7 s# C) c865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */
9 ?! [. E! C$ R* c( @" x15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
. W$ c: I# Z  ?/ k /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d' V) D9 C1 ]7 x: l6 y& x
Input.Mode: Mask (?d?d?d?d?d)
: t# W. F7 i6 u& `9 A. \) a) bIndex…..: 0/1 (segment), 100000 (words), 0 (bytes)7 _, x3 R) b  u! e4 B8 y3 V) v
Recovered.: 0/3 hashes, 0/3 salts
" M% ?$ F; T5 T9 A* jSpeed/sec.: – plains, – words
# Z$ ?3 y$ I; G! s& AProgress..: 100000/100000 (100.00%)
1 N- h$ e& u- h) g7 i; n. SRunning…: –:–:–:–
2 _2 J+ g# I. }% n3 NEstimated.: –:–:–:–) y+ ?. ^0 _+ g& t
15b7a21513f24ffe97d9f9830acf51ad:07626c:1234563 N+ E4 F3 Q4 g$ W
Input.Mode: Mask (?d?d?d?d?d?d)
' X4 s! r) j( I  H* K1 [Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
6 m! ?) k+ x  k7 |7 W9 eRecovered.: 1/3 hashes, 1/3 salts
3 w0 u& e: t  \: [Speed/sec.: 7.43M plains, 3.72M words1 u$ M. c2 g3 z+ t' _
Progress..: 1000000/1000000 (100.00%)- S8 M9 X: H1 \, M# N+ s" o) s; t
Running…: 00:00:00:01
6 l; X& y$ C* DEstimated.: –:–:–:–1 l( Y  X' w) p% u5 h5 k; \( k, e
Input.Mode: Mask (?d?d?d?d?d?d?d)
& p5 |& a3 L) gIndex…..: 0/1 (segment), 10000000 (words), 0 (bytes)4 p7 X0 U& V) f
Recovered.: 1/3 hashes, 1/3 salts- a/ K; m4 i! c" K" S; h' }
Speed/sec.: 13.67M plains, 6.83M words/ M2 \  L3 y' c4 q
Progress..: 10000000/10000000 (100.00%)1 ~: g5 X* T" z. t% r8 \
Running…: 00:00:00:01
' }0 m9 `% Z# T( t, GEstimated.: –:–:–:–$ V% t" C' K2 S- f1 e
Input.Mode: Mask (?d?d?d?d?d?d?d?d)
# v" v/ y9 R% G2 M" w6 yIndex…..: 0/1 (segment), 100000000 (words), 0 (bytes)/ ]$ i2 Z4 U: }3 K7 N" K( C
Recovered.: 1/3 hashes, 1/3 salts
' o- _, e5 `2 G" O2 a4 uSpeed/sec.: 18.59M plains, 9.29M words# \6 C- w+ G5 ]3 V" m( p& a1 r+ f! x
Progress..: 100000000/100000000 (100.00%)6 _9 `% t3 b+ F. }; I
Running…: 00:00:00:11  E0 Y4 M/ l0 l- J' `9 d' P: Y
Estimated.: –:–:–:–' y- h! |4 n" l! Q) |# e2 y
865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415) {; U. ?! @- n# o+ b
可以看到破解 9位3开纯数字密码需要11秒。) S0 E  w6 C$ [8 F- `
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)/ Z5 [: M( W& u+ O8 ?1 H0 @; i
Index…..: 0/1 (segment), 10000000000 (words), 0 (bytes)" K$ v- ]; l/ w# b! v! P
Recovered.: 2/3 hashes, 2/3 salts9 T/ t: X9 p* s
Speed/sec.: 12.70M plains, 12.70M words5 S* F0 Q' M& q% L/ u1 J/ t
Progress..: 10000000000/10000000000 (100.00%)
, [. q/ p( e+ R  i+ dRunning…: 00:00:13:07
$ [  I/ `4 R( UEstimated.: –:–:–:–2 B+ @8 Y  P- ~  T+ v
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。' g( w, L. T7 ^* t' t
在这里可以下载到一些字典,不过国人对这些字典貌似无视。' j! i9 m/ h' \: e  C  g, O- R& p1 h
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表