02-02-2024, 05:50 AM
I couldnt find a pass for my old (1996) rar file but i knew it was simple. I suspected JTR generated bad hash so i made an experiment.
I downloaded winrar2.0 and winrar3.0. I compressed the same simple txt file with the same password - with 2.0 and 3.0.
JTR gave me different hashes for both rar files.
-for 3.0 gave me hash with random salt
-for 2.0 gave me hash with "0000000000000000" salt.
Both hashes had the same valid syntax - due to hash types list.
I could crack 3.0 hash in JTR and hashcat.
I couldn't crack 2.0 hash in JTR and hashcat.
I suspect JTR gave me bad hash. Magnum! Can u help me?
It's a 20 minutes for u to make a change to rar2john
Here is a quick image with comparison of both rar files and their hashes.
I downloaded winrar2.0 and winrar3.0. I compressed the same simple txt file with the same password - with 2.0 and 3.0.
JTR gave me different hashes for both rar files.
-for 3.0 gave me hash with random salt
-for 2.0 gave me hash with "0000000000000000" salt.
Both hashes had the same valid syntax - due to hash types list.
I could crack 3.0 hash in JTR and hashcat.
I couldn't crack 2.0 hash in JTR and hashcat.
I suspect JTR gave me bad hash. Magnum! Can u help me?
It's a 20 minutes for u to make a change to rar2john
Here is a quick image with comparison of both rar files and their hashes.