找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2011|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境. W& a! b0 f% b- ], v
OS 名称: Microsoft® Windows Server® 2008 Enterprise
3 F8 t7 l9 z" \0 `OS 版本: 6.0.6001 Service Pack 1 Build 6001
: f- z; x6 K$ }5 a7 v; e5 N! ]: POS 制造商: Microsoft Corporation
" G$ l# G  @* p( tOS 配置: 独立服务器4 z% u+ u( a6 L; u, W: P) x7 a4 w" A) E
OS 构件类型: Multiprocessor Free& ]. ~+ ?: X, G
注册的所有人: Windows 用户
( I7 h& x7 P) ^- K+ ]系统型号: PowerEdge R620
% L# E9 i' _1 @# k3 w系统类型: x64-based PC
( {  Q3 q. ^: |+ X2 `" [处理器: 安装了 1 个处理器。- g1 Y5 I% e+ V  s0 K
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400" B$ m. d1 V9 m4 O
cat md5.txt
7 _8 w/ n  l- ?' L6 H3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/
# p) |8 \# F9 e/ d865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */( n- u. f' M8 b* h
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
4 m7 q; O& Q0 M6 ^5 T/ `5 `) M- Y /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
8 u' z$ Y$ ]5 ~& B4 @+ w- Y: mInput.Mode: Mask (?d?d?d?d?d)7 b3 [+ M' N+ O
Index…..: 0/1 (segment), 100000 (words), 0 (bytes)
8 v3 U* ~3 Y9 P, t. u% `" ]+ xRecovered.: 0/3 hashes, 0/3 salts
% N! D- A+ f: s0 X' s' y5 rSpeed/sec.: – plains, – words- X2 ]# J& w) L1 I2 p3 g3 y% m
Progress..: 100000/100000 (100.00%)6 x( t* D4 m, m; w! s
Running…: –:–:–:–  [; f7 \3 p4 I6 s( i( x8 K, g
Estimated.: –:–:–:–
2 B- J$ S! F; S, h1 I+ }; {3 ?15b7a21513f24ffe97d9f9830acf51ad:07626c:123456
7 k! j( v5 `6 U5 w9 _6 SInput.Mode: Mask (?d?d?d?d?d?d)
4 d! ]" w  K, M  T. tIndex…..: 0/1 (segment), 1000000 (words), 0 (bytes)
2 {9 T; Y6 J, `+ ERecovered.: 1/3 hashes, 1/3 salts! N& c6 g0 H" s' j
Speed/sec.: 7.43M plains, 3.72M words
- K. t( P6 z5 ]* _# lProgress..: 1000000/1000000 (100.00%)3 L1 X& B, P# e/ ^7 I# i+ D4 c/ I
Running…: 00:00:00:01$ E; I: M* |% m' _
Estimated.: –:–:–:–# r: g: X9 O7 w& [2 @+ R8 o- K1 k! V
Input.Mode: Mask (?d?d?d?d?d?d?d)
/ o' I5 c- q7 s1 c, G- }Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)
* |, F& y$ }2 X2 j: \Recovered.: 1/3 hashes, 1/3 salts
6 V, p9 Z1 `6 D( f" r3 P# FSpeed/sec.: 13.67M plains, 6.83M words
& X4 W' U3 v( h' t  BProgress..: 10000000/10000000 (100.00%)4 O9 {4 t6 m6 s& r
Running…: 00:00:00:01( M2 O& x; L: G/ P
Estimated.: –:–:–:–
) {3 m% h, b% l6 c$ r( e, ?9 [Input.Mode: Mask (?d?d?d?d?d?d?d?d)
$ P' t/ i! @  S& p: r/ w9 ~7 YIndex…..: 0/1 (segment), 100000000 (words), 0 (bytes)
- j+ N! Q6 A5 h6 l5 Q% lRecovered.: 1/3 hashes, 1/3 salts- }2 F' g1 T- [* ]
Speed/sec.: 18.59M plains, 9.29M words
6 y* d% d  j+ M* s. L; v: WProgress..: 100000000/100000000 (100.00%)
  _" A; Q* b/ ^8 w. o) ^$ w9 pRunning…: 00:00:00:11
# @7 f" I- I7 zEstimated.: –:–:–:–
# t! i- C3 c& R# C7 K865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415
# ]5 E& r# r/ A' l! b# c# ^可以看到破解 9位3开纯数字密码需要11秒。2 K/ F6 v  U1 B3 o% y' x
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
8 E4 k5 Q, `+ U- j; P; rIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
, t% o8 d" |! N) p7 `4 i5 TRecovered.: 2/3 hashes, 2/3 salts' u8 P# L( A: @  y% r9 G* X4 o
Speed/sec.: 12.70M plains, 12.70M words
7 @8 c/ z; M2 h. P: m8 WProgress..: 10000000000/10000000000 (100.00%)
" A* Z, k( V& z( m; A" H8 KRunning…: 00:00:13:07
: n8 W1 b  q) ]" ]Estimated.: –:–:–:–1 R% T; M7 _! Y% H! ~
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。% `  i. y$ v: ~! S% f7 M& b
在这里可以下载到一些字典,不过国人对这些字典貌似无视。; a" o( ?: X' l; |* L: E3 J8 i
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表