Is it a md5 colision ?
#15
(04-19-2013, 07:51 AM)Mem5 Wrote: Ok, I'll open a TRAC. Thank you for your help.

Curious question : how can somebody login into a system using a password with the null byte character ? As it is not printable.. ?!

Easy - just as an application can salt using any set of byte the programer likes, client applications can login using whatever set of byte values they care to send to the server application. Not all hashes come from data a human puts in via a keyboard at time of login!

Alternately, systems like Truecrypt and KeePass can use the contents of a binary file to generate a hash or part of a hash. Perhaps some other applications allow file-based entry.

I don't know enough about widgets like the Yubikey to know if it can do anything like that or not.


Messages In This Thread
Is it a md5 colision ? - by Mem5 - 04-12-2013, 07:24 PM
RE: Is it a md5 colision ? - by atom - 04-12-2013, 08:59 PM
RE: Is it a md5 colision ? - by Mem5 - 04-13-2013, 06:17 PM
RE: Is it a md5 colision ? - by eljolot - 04-13-2013, 08:03 PM
RE: Is it a md5 colision ? - by Mem5 - 04-13-2013, 11:21 PM
RE: Is it a md5 colision ? - by Incisive - 04-14-2013, 05:37 AM
RE: Is it a md5 colision ? - by Mem5 - 04-14-2013, 10:54 AM
RE: Is it a md5 colision ? - by philsmd - 04-14-2013, 11:05 AM
RE: Is it a md5 colision ? - by Mem5 - 04-14-2013, 11:50 AM
RE: Is it a md5 colision ? - by philsmd - 04-14-2013, 12:27 PM
RE: Is it a md5 colision ? - by Incisive - 04-15-2013, 06:12 AM
RE: Is it a md5 colision ? - by atom - 04-15-2013, 10:01 AM
RE: Is it a md5 colision ? - by Mem5 - 04-19-2013, 07:51 AM
RE: Is it a md5 colision ? - by Incisive - 04-19-2013, 12:02 PM
RE: Is it a md5 colision ? - by atom - 04-19-2013, 10:47 AM
RE: Is it a md5 colision ? - by philsmd - 06-01-2013, 03:50 PM