Decrypting usenet headers
#3
(09-25-2016, 12:34 AM)radix Wrote: If we pull out the Salted__ bit then you get a len consistent with a number of hash types (32).  However that means the salt is hiding elsewhere.  Without seeing the source it would be hard to figure out a) the hashing, b) what value in the header is the salt.

Well, we do have the logging-data="10878" part, also the date of the post, which in this case has the header:

Injection-Date: Thu, 19 May 2016 14:16:57 -0000 (UTC)


Messages In This Thread
Decrypting usenet headers - by Somnambulist - 09-23-2016, 10:19 PM
RE: Decrypting usenet headers - by radix - 09-25-2016, 12:34 AM
RE: Decrypting usenet headers - by Somnambulist - 09-26-2016, 07:14 AM
RE: Decrypting usenet headers - by radix - 09-26-2016, 03:12 PM
RE: Decrypting usenet headers - by pragmatic - 09-30-2016, 12:12 AM
RE: Decrypting usenet headers - by Somnambulist - 09-30-2016, 11:30 AM
RE: Decrypting usenet headers - by rico - 09-30-2016, 11:05 PM
RE: Decrypting usenet headers - by Somnambulist - 10-02-2016, 09:59 AM
RE: Decrypting usenet headers - by pragmatic - 10-03-2016, 06:53 PM
RE: Decrypting usenet headers - by pragmatic - 10-03-2016, 07:04 PM
RE: Decrypting usenet headers - by Somnambulist - 10-08-2016, 06:14 PM
RE: Decrypting usenet headers - by Somnambulist - 10-09-2016, 11:29 AM