Decrypt md5 - Page 2

Solved/Closed
  1. Contributor
    Well, you know when you cook, sometimes it's better with salt, well, it's the same here ...
    --

    The wolf, solitary and mysterious.
    0
    1. Contributor
      Decipher=not related to numbers. (+ harder to explain)
      With numbers, no. But we decipher what has been encrypted (unlike MD5 which is a hashing function and not encryption). And be careful not to confuse decrypt and decipher ;-))).

      Otherwise, salting consists of concatenating a piece of data with the password (or other) to hash. The result is a hash that will not be in rainbow tables. http://en.wikipedia.org/wiki/Salt_(cryptography)

      Best regards
      --

      Google is your friend
      0
      1. Moderator
        Yeah, well, apparently you didn't get it.

        Xortax: The MD5 works as follows:

        You give it a sequence of bytes of any length, and it outputs a 128-bit string.
        Therefore, it can't be "decrypted", otherwise you could compress a DVD into 128 bits.

        The only thing you can do to find out which string corresponds to an MD5 is to create all possible character strings, calculate their MD5 and compare with the MD5 you're looking for.

        However, some enthusiasts have created gigantic databases of pre-calculated MD5s.

        That's the link I provided: by chance, the MD5 you're searching for is present in that database, and the string corresponding to your MD5 is "????"

        Okay?
        0
        1. Contributor
          It's nice of you to talk to us about rainbow tables, and even to have provided some websites, but you don't talk much about MD5 collisions, which allow for a string that returns the desired MD5 code...
          0
          1. Moderator
            You don't talk much about MD5 collisions, which allow for a string that returns the desired MD5 code ...

            Currently, nothing allows obtaining collisions for a specific MD5.

            The only thing we can do is calculate strings that cause collisions, but you do not control the resulting MD5, and the source strings contain a block of several dozen bytes of random appearance.

            It is therefore still not possible to forge a document or a string having a specific MD5, except through brute force.
            0
            1. Moderator
              @Nabla'sThe Clubic article is full of errors. First of all, they present MD5 as an encryption algorithm :-/

              They didn't break MD5, but what they did was clever:

              Generally, strings with the same MD5 look random.
              It's "easy" to find strings with the same MD5, but much more difficult to generate, for example, two JPG images with the same MD5.

              They used the computing power of PS3s to successfully generate 2 SSL certificates with the same MD5.
              They had the first one signed by RapidSSL, which is a PKI.

              RapidSSL then returned the signed certificate to them. However, when you "sign" a document, you’re actually not signing the document but the MD5 of the document.

              Once they retrieved the RapidSSL signature, they only had to substitute it with the other certificate they generated. Thus, they obtained a makeshift certificate whose MD5 is signed by RapidSSL.

              It's clever, but it still doesn't allow them to generate a document with a precise MD5.
              0
            2. Contributor
              @sebsauvageSure, thanks for the clarification...
              0
          2. Contributor
            Indeed, the collision is quite different from the second pre-image attack: http://fiddy.free.fr/...

            Best regards
            --

            Google is your friend
            0
            1. Moderator
              Thank you for the details.
              0
            2. @sebsauvageThank you all for the details, it's really too bad that I can't know what is hidden behind:
              e088da6d7bf99aa251543ede28c6973d.. sniff
              But thank you very much......
              0
            3. @XortaxGood evening

              But yes, the answer was given to you.
              0
            4. Moderator
              @XortaxYes, it's heavy right now... read what I provided as responses.
              0
          3. It's normal that MD5 hasn't been cracked yet.

            The algorithm is related to the machine's registers and their use in a specific order...

            So, already, to be able to crack MD5, you need to be on the machine so that its signature can be identified... and even then, given that the generation doesn't necessarily go through the same registers, you won't get the same result if you enter the same password twice.

            In short, if you want to know how it works, you just have to go to www.ietf.org (Internet Engineering Task Force).
            You can look in the RFCs (memos describing the standards for how things related to the net have worked since 1969...).

            There is an RFC that describes the logical functioning of MD5.

            -------------------------------------------------------------------------------------------
            There is an RFC for everything...
            0
            1. Moderator
              You need to be on the machine for your signature to be identified...
              And even then, given that the generation doesn’t necessarily go through the same registers, you won’t get the same result if you enter the same password twice.

              False! An MD5 calculation is the same regardless of the machine! Otherwise, I don't see the point...

              And we have already repeated that we don't break MD5; we can just find a sequence of bits that gives the MD5 we are looking for...

              --

              A+ Blux
               "Rude people dare anything. That's how you recognize them" 
              0
            2. Contributor
              @bluxAnd I would even add that for the moment we can only generate two messages with the same hash (collision) and find a weak MD5 through rainbow tables.
              --

              Google is your friend
              0
            3. Moderator
              @fiddytwo... or more ;-)

              --

              See you A+ Blux
               "Fools dare everything. That's how we recognize them" 
              0
            4. Contributor
              @bluxYes, that is possible. But for now, the best algorithms capable of generating collisions are only for two. For three, it would take too much time ^^.
              --

              Google is your friend
              0
          4. Hello everyone

            For searching the cleartext of an MD5 hash, I recommend http://hash.db.hk. It combines a database search with brute force using GPUs (Cuda).

            The results are impressive.

            Robert
            0
            1. But you can use online tools (they use large databases) like this one: http://www.stringfunction.com/md5-decrypter.html
              David
              0
              1. It's possible at the university, the professor gave us an MD5 and we had to decrypt it, it took 6 hours of work, so it is possible.

                MD5 to find: b747f94da7fbbc5def00394f21ce6822

                Word found: Euclid

                So it is entirely possible to find this kind of thing.
                But it is difficult to do so!
                I will not reveal the trick because it might be used for malicious purposes.
                0
                1. Moderator
                  You simply found a word whose MD5 was given to you...
                  There are infinitely many others...
                  0
                2. Contributor
                  I will not reveal the trick because it might be used for the wrong purposes.
                  There is no magic trick. Just brute force, or more subtly, a rainbow table. However, you will only find simple words (like Euclid...).
                  Hence the use of salt before hashing a password.
                  By the way, I can give you an MD5, and we’ll see that you won’t take 6 hours to find it ^^.
                  0
                3. Moderator
                  and we'll see that it won't take you 6 hours to find it
                  No, not it, but finding a string among an infinity that gives the same MD5 ;-)
                  0
                4. Contributor
                  Sure, but if you find an initial string that gives an intelligible word, we can conclude that it's the right one ^^.
                  0
              2. Here’s a decent site to decrypt MD5
                http://hash-decrypter.com
                0
                1. Moderator
                  It doesn't decrypt MD5; at best, it finds things that have the same MD5 hash as what you're looking for...
                  0
                2. No, if it doesn't find the fingerprint, it launches a brute force attack on the server.
                  0
                3. Contributor
                  However, it is still not about decoding.
                  0
              3. Moderator
                Erratum:
                It should read "downloaded content" and MD5, of course...

                Gates gave us the windows.
                Linux gave us the whole house....
                -1
                1. jisisv and Boninours are right.

                  Note that if you have a few million years ahead of you, you
                  can find the file corresponding to an MD5...

                  :-D
                  -1
                  1. Of course it is possible to decrypt an MD5 hash.
                    There are two ways to do it: by using ready-made software
                    - for example: john the ripper for Linux and Unix, https://www.openwall.com/john/
                    - or ophcrack for Windows, https://ophcrack.sourceforge.io/

                    Or by performing rainbow table attacks, brute force (or dictionary attacks) or even by salting (which is essentially organized brute force). If you want to learn more about this, I strongly recommend the security portal on Wikipedia.

                    This is of course to test security

                    but in no case is a hash meant to be "hashed"

                    but know that MD5 has been obsolete for a long time (since SHA-512 has been released).
                    -1
                    1. I also wanted to say…

                      According to the designers of the thing: an average of 87 years to "crack" a 10-character password

                      Just a few hours for one with less than 6 characters

                      We are far from the millions of years that some think...
                      -1
                      1. Moderator
                        Hello,

                        A great man said: "What one man has built, another man can tear down..."

                        And, did this great man ask if the reverse is also true?! ;-)
                        --

                        lami20j
                        -1
                        1. Moderator
                          Yes, that's true...

                          If I break an egg, is there a man who will be able to rebuild it for me?

                          If I mix yellow paint with blue to make green, is there a man who will be able to find the two original paints for me?

                          Does extreme entropy come back to ordering things?

                          --

                          See you, Blux
                           "Stupid people dare everything. That's how you can recognize them." 
                          0
                        2. @bluxYou're amazing, you managed to make me laugh out loud this morning!!!! xD
                          0
                        3. Moderator
                          @kZn.13It's surely funny, but it remains true that breaking an egg is a one-way function, just like mixing paint or calculating an MD5 hash...

                          You can't go back, but you can look for ways to achieve the same result again: re-breaking an egg, mixing several colors until you get the desired one, taking billions and billions of characters to calculate an MD5 identical to the expected one...

                          --

                          See you, Blux
                           "Stupid people dare to do anything. That's how you recognize them." 
                          0
                      2. If you want to decrypt MD5, you can go to this site, which surely has the largest database on the internet:
                        http://decrypt.vanvan.cc
                        -1
                        1. or not :/
                          0
                        2. Moderator
                          YOU DON'T DECRYPT MD5!!!!!!!!!!!!!!!!!!!!!!!

                          It's a non-bijective function. At most, you can find two 'data' that have the same MD5...

                          which probably possesses the largest database on the internet:
                          Certainly not, just loading a rainbow table is enough, which has much more (several tens of gigabytes)...

                          --

                          A+ Blux
                           "Fools dare everything. It's even how you recognize them" 
                          0
                      3. https://www.frameip.com/decrypter-dechiffrer-cracker-hash-md5/

                        For me, this one doesn’t say it decrypts, but that it cracks, if that makes you happy we're glad... and that way we have our answer.

                        Now, this is not a rumor: MD5 cannot be decrypted, otherwise it wouldn’t be used in PHP (among others) or in .htaccess for security!
                        -1
                        1. The result was not found

                          And there you go, security is also about being smart, it's not just technical...
                          ...Or how to invalidate their system really easily...
                          0
                      Previous
                      • 1
                      • 2
                      • 3