Its more work to crack hashes than to phish, trust me.
hypothetically speaking if you have say a large Rainbow Table and you have the hashes, it wouldn't be very hard or time consuming to crack those hashes using PasswordPro for example.
This is all hypothetical, not that any of this was actually applied on the IC.
How would you account for the salt in this case though? I still feel like hash cracking would be the long way round when compared to phising.
Again though, I'm also only speculating because I was not around, but I have a hard time believing that a Rainbow Table would work as easily as you're saying with salted hashes.
vB's hash algorithm is:
HASH_PASS = MD5 ( CONCAT(md5(PLAIN_PASS), SALT) )
The salt is random per user, so a rainbow table would ... well it just wouldn't work really.
Its more work to crack hashes than to phish, trust me.
hypothetically speaking if you have say a large Rainbow Table and you have the hashes, it wouldn't be very hard or time consuming to crack those hashes using PasswordPro for example.
This is all hypothetical, not that any of this was actually applied on the IC.
How would you account for the salt in this case though? I still feel like hash cracking would be the long way round when compared to phising.
Again though, I'm also only speculating because I was not around, but I have a hard time believing that a Rainbow Table would work as easily as you're saying with salted hashes.
vB's hash algorithm is:
HASH_PASS = MD5 ( CONCAT(md5(PLAIN_PASS), SALT) )
The salt is random per user, so a rainbow table would ... well it just wouldn't work really.
In vbulletin you could get the hash and salt. The salt is random per user, but if you know the value of the salt would be accounted for in the PasswordPro program, thus allowing you to utilize a rainbow table, instead of a dictionary attack or bruteforcing which would have been very time consuming.
Hypothetically speaking one would have been able to gather the hash+salt combos on vbulletin through sql injection.
That does make sense. Was the previous iteration of vB running on this site susceptible to SQL injection attacks? I don't know what version it was.
this thread is a perfect example of why this site is vulnerable...there is a very frank discussion on how this may have happened and people are ignoring it like its jibberish. It might be... but some quick research into what is being talked about can open a flood of information about this topic.
Replies
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •How would you account for the salt in this case though? I still feel like hash cracking would be the long way round when compared to phising.
Again though, I'm also only speculating because I was not around, but I have a hard time believing that a Rainbow Table would work as easily as you're saying with salted hashes.
vB's hash algorithm is:
The salt is random per user, so a rainbow table would ... well it just wouldn't work really.
- Spam
- Abuse
- Troll
1 • Wack Feelings Nosign 1Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •That does make sense. Was the previous iteration of vB running on this site susceptible to SQL injection attacks? I don't know what version it was.
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
2 • Wack Feelings Nosign 1Cosign Ether 1GOAT LOL •JG, Icy, when's the wedding so that I could come through and shoot it up.
Gay nerds.. the fuck is the IC coming to yo?
- Spam
- Abuse
- Troll
2 • 1Wack 2Feelings Nosign Cosign 3Ether GOAT LOL •there's like......an art to this shit.....
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •Nevermind though, your passwords are safe lol.
- Spam
- Abuse
- Troll
0 • 1Wack Feelings 1Nosign 1Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •thanks....tho...
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •Make sure you check over your notes.
"Even if you have the keys doesn't mean you can drive the car"
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
-1 • 1Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •even though i have no idea what the fuck i just learned.....
other than a nigga needa change that password daily...
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •Especially you......smh
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •No, just don't use a retarded password, and don't get phished, and don't use the same password for a forum as you use for your email.
- Spam
- Abuse
- Troll
1 • Wack Feelings Nosign 1Cosign Ether GOAT LOL •or is that taking it too far??
- Spam
- Abuse
- Troll
5 • Wack 2Feelings Nosign Cosign Ether 5GOAT LOL •I'm clicking emotion buttons now......smh
- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
-1 • 2Wack Feelings Nosign 1Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •he's definitely doing it right......
go play fetch with a stick of dynamite....
- Spam
- Abuse
- Troll
-4 • 4Wack Feelings Nosign Cosign Ether GOAT LOL •- Spam
- Abuse
- Troll
6 • Wack Feelings Nosign Cosign 6Ether GOAT LOL •- Spam
- Abuse
- Troll
0 • Wack Feelings Nosign Cosign Ether GOAT LOL •