找回密码
 立即注册
查看: 2673|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境; y* d* ?7 V6 a  y
OS 名称: Microsoft® Windows Server® 2008 Enterprise/ o# M: I5 Z6 G$ T6 M5 L
OS 版本: 6.0.6001 Service Pack 1 Build 6001# {5 G9 x5 n- v; ]. @. K* Y
OS 制造商: Microsoft Corporation
' ~" d# a6 P. |7 JOS 配置: 独立服务器9 P: I! p' S& p& U7 @/ _4 v+ g" C
OS 构件类型: Multiprocessor Free  _4 ~  }8 G6 M# D6 I) n( E
注册的所有人: Windows 用户
" I; y6 x; U+ {% u系统型号: PowerEdge R620
  C8 Q- R; i' l. B系统类型: x64-based PC- ?9 E9 O3 D6 o: u. i' M/ S
处理器: 安装了 1 个处理器。0 ]" I+ T1 z- M# W0 f
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~24007 T1 i5 f5 Z; p- r' r; ?1 N
cat md5.txt
7 L" _- {1 ~0 W5 H3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/* M: {+ w9 p5 }# L# B. b# i/ H
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */2 w+ I( F2 n6 W' V6 G2 Y, C4 H3 w
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */0 R, P2 t# d& T+ v3 U$ }5 f
/* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d* @1 L+ ?( L+ a4 }
Input.Mode: Mask (?d?d?d?d?d)
: Z" t" R1 d" d0 k3 P) L  \Index…..: 0/1 (segment), 100000 (words), 0 (bytes)
/ D3 n: m( N$ }7 R! xRecovered.: 0/3 hashes, 0/3 salts' |& Y0 H  P2 |3 z# P/ E0 _
Speed/sec.: – plains, – words3 X% h- q  a+ K  y+ d7 O$ G; W" P
Progress..: 100000/100000 (100.00%)% G6 K  [  F* L) m* c+ E* }
Running…: –:–:–:–
  H& B3 m% i6 Q- r- Q" E" HEstimated.: –:–:–:–+ ]' Y) z  i) W
15b7a21513f24ffe97d9f9830acf51ad:07626c:123456
) E! l4 V; T3 N" tInput.Mode: Mask (?d?d?d?d?d?d). X4 W1 k, u: |
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
1 B( c* g7 T) y/ qRecovered.: 1/3 hashes, 1/3 salts3 l# d; _, q% Z- K/ X! h% M
Speed/sec.: 7.43M plains, 3.72M words! Q# m# v2 r0 Y
Progress..: 1000000/1000000 (100.00%)  l! p/ a. R: y& Q/ O  V+ A
Running…: 00:00:00:01, l6 `4 l4 |# X! f& p7 ?% @( d1 c0 w
Estimated.: –:–:–:–) I' e& H8 G# v  N# @
Input.Mode: Mask (?d?d?d?d?d?d?d)5 C: I$ K/ p/ L, [3 {
Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)
; a& `) K$ d; W; \) R3 C8 ORecovered.: 1/3 hashes, 1/3 salts
/ z2 M: S1 t! Q( q- RSpeed/sec.: 13.67M plains, 6.83M words
8 X0 ~7 h' Z7 k& L4 l8 @" H/ @3 Y( fProgress..: 10000000/10000000 (100.00%)
% a5 O* Q& R" U* X( K6 {* LRunning…: 00:00:00:01
) e( n; g; @" S3 o1 Z- TEstimated.: –:–:–:–
4 R& B% ]/ M6 h. f7 kInput.Mode: Mask (?d?d?d?d?d?d?d?d)5 D6 c- D7 y: {" r7 V4 ~; x2 ?% \
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)
( U- J3 ^. E# |4 Y# e* m( [/ YRecovered.: 1/3 hashes, 1/3 salts% k6 ~0 ~# V: `. X& _$ G7 E- Y
Speed/sec.: 18.59M plains, 9.29M words9 g! r9 ?$ i  U+ J* Q
Progress..: 100000000/100000000 (100.00%)& X9 Z2 e3 W. J; C) T
Running…: 00:00:00:11/ A3 X+ P, n$ R5 I( S
Estimated.: –:–:–:–
5 W+ a; y5 s6 i4 V( g& }8 R865a697fb9b4bd9c6737432aaff136bd:22dc87:3048924155 p2 ?/ k& `$ ~6 m* f3 K# u& _
可以看到破解 9位3开纯数字密码需要11秒。# j/ G6 t* @% }& Y/ O
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
4 G5 x& V! L5 F; @Index…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
3 _9 ?2 z& Z% i! O4 k1 m4 p8 }0 g1 kRecovered.: 2/3 hashes, 2/3 salts
2 Q3 H. M- j5 K/ W' RSpeed/sec.: 12.70M plains, 12.70M words
4 Z( }! y4 A4 o4 p& I3 ]8 V3 OProgress..: 10000000000/10000000000 (100.00%)$ `/ w1 O/ R6 L" D% c
Running…: 00:00:13:07
1 W5 N5 Q3 ~4 z7 |& |Estimated.: –:–:–:–
- Y9 p( C; c- r( d& u而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。4 x/ K& j. c! l4 A9 v. c( ^; d' P! U
在这里可以下载到一些字典,不过国人对这些字典貌似无视。
. u. F% a2 @, g0 d/ ^: Yhttp://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表