Colliding password protected MS office 97-2003 documents
#14
SHA1 works fine, too :-)

Quote:
root@et:~/oclHashcat-1.31# ./oclHashcat64.bin -m 9810 -w 3 -o hash.rc4 hash -a 3 ?b?b?b?b?b --markov-disable
oclHashcat v1.31 starting...

Device #1: Tahiti, 2967MB, 1000Mhz, 32MCU
Device #2: Tahiti, 2967MB, 1000Mhz, 32MCU
Device #3: Tahiti, 2967MB, 1000Mhz, 32MCU

Hashes: 1 hashes; 1 unique digests, 1 unique salts
Bitmaps: 8 bits, 256 entries, 0x000000ff mask, 1024 bytes
Applicable Optimizers:
* Zero-Byte
* Precompute-Init
* Not-Iterated
* Single-Hash
* Single-Salt
* Brute-Force
Watchdog: Temperature abort trigger set to 90c
Watchdog: Temperature retain trigger set to 80c
Device #1: Kernel ./kernels/4098/m9810_a3.Tahiti_1526.3_1526.3 (VM).kernel (325112 bytes)
Device #1: Kernel ./kernels/4098/markov_le_v1.Tahiti_1526.3_1526.3 (VM).kernel (93212 bytes)
Device #1: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)
Device #2: Kernel ./kernels/4098/m9810_a3.Tahiti_1526.3_1526.3 (VM).kernel (325112 bytes)
Device #2: Kernel ./kernels/4098/markov_le_v1.Tahiti_1526.3_1526.3 (VM).kernel (93212 bytes)
Device #2: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)
Device #3: Kernel ./kernels/4098/m9810_a3.Tahiti_1526.3_1526.3 (VM).kernel (325112 bytes)
Device #3: Kernel ./kernels/4098/markov_le_v1.Tahiti_1526.3_1526.3 (VM).kernel (93212 bytes)
Device #3: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)

Session.Name...: oclHashcat
Status.........: Cracked
Input.Mode.....: Mask (?b?b?b?b?b) [5]
Hash.Target....: $oldoffice$3*02506610865808803242045567403104*4b6442131e0171fd4ebd33c536f23b84*4c5c6a75ee6b771c31d3d26beb93265282d66e58
Hash.Type......: MS Office <= 2003 SHA1 + RC4, collision-mode #1
Time.Started...: Sat Sep 13 19:51:19 2014 (47 mins, 18 secs)
Speed.GPU.#1...: 82917.2 kH/s
Speed.GPU.#2...: 82917.1 kH/s
Speed.GPU.#3...: 82927.8 kH/s
Speed.GPU.#*...: 248.8 MH/s
Recovered......: 1/1 (100.00%) Digests, 1/1 (100.00%) Salts
Progress.......: 706119467008/1099511627776 (64.22%)
Skipped........: 0/706119467008 (0.00%)
Rejected.......: 0/706119467008 (0.00%)
HWMon.GPU.#1...: 88% Util, 38c Temp, 27% Fan
HWMon.GPU.#2...: 88% Util, 39c Temp, 29% Fan
HWMon.GPU.#3...: 88% Util, 39c Temp, 29% Fan

Started: Sat Sep 13 19:51:19 2014
Stopped: Sat Sep 13 20:38:38 2014

Quote:
root@et:~/oclHashcat-1.31# ./oclHashcat64.bin -m 9820 -w 3 hash.rc4 -a 3 ?l?l?l?l?l?l?l?l?l?l
oclHashcat v1.31 starting...

Device #1: Tahiti, 2967MB, 1000Mhz, 32MCU
Device #2: Tahiti, 2967MB, 1000Mhz, 32MCU
Device #3: Tahiti, 2967MB, 1000Mhz, 32MCU

Hashes: 1 hashes; 1 unique digests, 1 unique salts
Bitmaps: 8 bits, 256 entries, 0x000000ff mask, 1024 bytes
Applicable Optimizers:
* Zero-Byte
* Precompute-Init
* Not-Iterated
* Single-Hash
* Single-Salt
* Brute-Force
Watchdog: Temperature abort trigger set to 90c
Watchdog: Temperature retain trigger set to 80c
Device #1: Kernel ./kernels/4098/m9820_a3.Tahiti_1526.3_1526.3 (VM).kernel (187012 bytes)
Device #1: Kernel ./kernels/4098/markov_be_v1.Tahiti_1526.3_1526.3 (VM).kernel (93292 bytes)
Device #1: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)
Device #2: Kernel ./kernels/4098/m9820_a3.Tahiti_1526.3_1526.3 (VM).kernel (187012 bytes)
Device #2: Kernel ./kernels/4098/markov_be_v1.Tahiti_1526.3_1526.3 (VM).kernel (93292 bytes)
Device #2: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)
Device #3: Kernel ./kernels/4098/m9820_a3.Tahiti_1526.3_1526.3 (VM).kernel (187012 bytes)
Device #3: Kernel ./kernels/4098/markov_be_v1.Tahiti_1526.3_1526.3 (VM).kernel (93292 bytes)
Device #3: Kernel ./kernels/4098/bzero.Tahiti_1526.3_1526.3 (VM).kernel (30484 bytes)

$oldoffice$3*02506610865808803242045567403104*4b6442131e0171fd4ebd33c536f23b84*4c5c6a75ee6b771c31d3d26beb93265282d66e58:188b5067a4:mpvwnxeqfa

[s]tatus [p]ause [r]esume [b]ypass [q]uit => q

...

On a sidenote, while computing with roughly the same speed, finding MD5 collisions was much more easy than with SHA1, as expected.


Messages In This Thread
RE: Colliding password protected MS office 97-2003 documents - by atom - 09-13-2014, 09:30 PM