Waraxe IT Security Portal
Login or Register
September 22, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 284
Members: 0
Total: 284
Full disclosure
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
CVE-2026-52307: Stored XSS in 1CMS v5.6
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 /CVE-2026-12556
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
O-CMS 1.0.0 Authenticated OS Command Injection viaai_cli_script
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> All other hashes -> VERY IMPORTANT SALTED HASH!!!!
Post new topicReply to topic View previous topic :: View next topic
VERY IMPORTANT SALTED HASH!!!!
PostPosted: Sat Dec 13, 2008 3:34 am Reply with quote
FBIRyan
Advanced user
Advanced user
Joined: Dec 11, 2008
Posts: 50




This md5(md5($salt).md5($pass)) hash means the WORLD to me! My dictionaries couldn't crack it though.. Crying or Very sad Whoever cracks this one is my hero! Very Happy Seriously though, I really need this hash to be cracked. At least give it a try. Wink
Also the hash doesn't contain any special characters. Just the alphabet and numbers.
Md5: 893bac0dbb511a580e28f8a6805aa2b3
Salt: Xdwe{
Big huge forever thanks in return,
Ryan


Last edited by FBIRyan on Sun Dec 14, 2008 1:56 am; edited 1 time in total
View user's profile Send private message
PostPosted: Sat Dec 13, 2008 7:02 pm Reply with quote
FBIRyan
Advanced user
Advanced user
Joined: Dec 11, 2008
Posts: 50




If you brute force it, tell me what you did. That way that's one less thing I have to try myself. I'm at 7 digits with lower case alphabet and numbers. So I've tried 1-6 with lower case alphabet and numbers.(Something you don't have to do now) My computer is slow though.(Or at least the program I'm using is) Any help is very much appreciated.(Even if you don't crack it)
View user's profile Send private message
PostPosted: Sat Dec 13, 2008 9:53 pm Reply with quote
Chb
Valuable expert
Valuable expert
Joined: Jul 23, 2005
Posts: 206
Location: Germany




Wait a second... md5(md5($salt) . md5($pass))? In my opinion it's nearly impossible to crack such a hash. You already know the half of the password, okay. But actually the "password" you're searching (the hash of the "real password") contains 32 digits.
This means your "real" password is salted with a 32 byte long salt. Wink

Due to the fact that one digit of a hash may be 0 to f, that makes a number of... 16^32 or 3,4028236692093846346337460743177e+38 possibilities, if I recall right.

Do you really want to try this?

_________________
www.der-chb.de
View user's profile Send private message Visit poster's website ICQ Number
PostPosted: Sat Dec 13, 2008 11:47 pm Reply with quote
FBIRyan
Advanced user
Advanced user
Joined: Dec 11, 2008
Posts: 50




Chb wrote:
Wait a second... md5(md5($salt) . md5($pass))? In my opinion it's nearly impossible to crack such a hash. You already know the half of the password, okay. But actually the "password" you're searching (the hash of the "real password") contains 32 digits.
This means your "real" password is salted with a 32 byte long salt. Wink

Due to the fact that one digit of a hash may be 0 to f, that makes a number of... 16^32 or 3,4028236692093846346337460743177e+38 possibilities, if I recall right.

Do you really want to try this?

O.o;
You didn't do your research before you posted, did you? Programs, such as PasswordPro, can do it in reverse. They take the salt and hash it, then take the pass and hash it, then hash them together.(Or something like that) I've cracked IPB passwords within seconds. Rolling Eyes But I've only done them with dictionaries.. So are you saying when you brute force an IPB hash that it's gonna contain 32 digits? I'll prove you wrong. I've got a 6 digit password in an IPB hash format. I'll try to brute force it, with the brute forcer set to 6 digits. BRB Wink
View user's profile Send private message
PostPosted: Sat Dec 13, 2008 11:52 pm Reply with quote
FBIRyan
Advanced user
Advanced user
Joined: Dec 11, 2008
Posts: 50




C:\Documents and Settings\user\Desktop\Assassin's Creed\XtremeBrute>yummy.exe se
t.ini hash.txt
aed8c8c761d0e73e4d94d2553e0f245f:hellos

All passwords found!

Thus, you are wrong. Razz
So yes, whoever can help(And knows how) please do. Wink
View user's profile Send private message
PostPosted: Sun Dec 14, 2008 12:28 pm Reply with quote
gyan007
Advanced user
Advanced user
Joined: Oct 17, 2008
Posts: 106




Dictionary attack relies opn the hashing method being known, and all variables, including the password.. Since it hashes a password and matches it to the unknown password.. Then with a word list u can try most common passwords Smile
View user's profile Send private message
PostPosted: Sun Dec 14, 2008 1:13 pm Reply with quote
Chb
Valuable expert
Valuable expert
Joined: Jul 23, 2005
Posts: 206
Location: Germany




Uh, mea culpa.
The 16^32 combinations aren't that wrong (if you had to crack ALL possible MD5s), but I didn't think about easily cracking the hashes by dictionary or bruteforce (and that way you'd just have to concatenate both hashes and MD5 that again)... Seems like I was too tired... :/

Sorry for the incidence. Wink

_________________
www.der-chb.de
View user's profile Send private message Visit poster's website ICQ Number
PostPosted: Sun Dec 14, 2008 2:42 pm Reply with quote
FBIRyan
Advanced user
Advanced user
Joined: Dec 11, 2008
Posts: 50




Chb wrote:
Uh, mea culpa.
The 16^32 combinations aren't that wrong (if you had to crack ALL possible MD5s), but I didn't think about easily cracking the hashes by dictionary or bruteforce (and that way you'd just have to concatenate both hashes and MD5 that again)... Seems like I was too tired... :/

Sorry for the incidence. Wink

Haha, it's cool mate. Wink I know no ones gonna wanna dedicate their computer to help me brute force this Md5 hash. So wish me luck. Rolling Eyes
View user's profile Send private message
VERY IMPORTANT SALTED HASH!!!!
www.waraxe.us Forum Index -> All other hashes
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.040 Seconds