ãã®ããŒãžã®å€§éã®ããŒã¿ã®ã¯ã€ãã¯æ€çŽ¢ãã©ã®ããã«å®è£
ããããã«ã€ããŠã§ãã ããã§ã
PvPGNã²ãŒã ãµãŒããŒã®ããã·ã¥ãã¹ã¯ãŒããæ€çŽ¢ããåãããã·ã¥ãçæã§ããŸãã
æ€çŽ¢ã¯ãã¢ãžã¥ãŒã«ãšãµãŒãããŒãã£ã®ããŒã¿ããŒã¹ã䜿çšããã«ãçŽç²ãªPHPã§èšè¿°ãããŠããŸãã ååãšããŠããã®æ¹æ³ã§ããªã¥ãŒã ãæ°ãã©ãã€ãã«å¢ããããšãã§ããå ŽæããããŸã-é床ã¯ããã«ãã£ãŠããã»ã©èŠããããšã¯ãããŸããã
ããã«ãæåããæåŸãŸã§ããã«ãŒããã©ãŒã¹ãããŒãã«ã®ããã·ã¥ã®äœæããœãŒãããããŠå®éã®æ€çŽ¢ãå«ãããã»ã¹å
šäœã説æãããŠããŸãã

ãã«ãŒããã©ãŒã¹
ãã¹ã¯ãŒããæ€çŽ¢ããããã®ããã·ã¥ããŒãã«ãé²ãã«ã¯ããã¹ã¯ãŒããäœæãããšãã«ãã¹ã¯ãŒãã
ãœã«ããšæ··åããå¿
èŠããããŸãã ããããããã·ã¥ã®ãªã¹ããããããœã«ããã©ã®ããã«è¿œå ãããããç¥ã£ãŠããã®ã§ãåçŽãªãã¹ã¯ãŒãã¯åŸ¹åºçãªæ€çŽ¢ã§èŠã€ããããšãã§ããŸãã
ãããã£ãŠãPvPGNã®ããã·ã¥ã¯ãœã«ããªãã§çæããã倧ããªããŒãšå€ã®ããŒãã«ïŒããã·ã¥ãã¹ã¯ãŒãïŒãçæãããšããã¢ã€ãã¢ãçãŸããŸããã
CïŒã§ã®ãã«ãŒããã©ãŒã¹ã®æãåçŽãªäŸã瀺ããMD5ããã·ã¥æ€çŽ¢ã®ãã¹ã¯ãŒãããœãŒãããŸãã ãŸãããœãŒããããŠããªãããŒãã«ã®çæã¯ãçæãããããŒã¿ãCSVãã¡ã€ã«ã«è¿œå ããã ãã§ãã
class Program { static bool _isFound = false; static string _findHash; static string _symbols; static int _pass_lenght; static void Main(string[] args) { _findHash = args[0];
ãœãŒã¹
ãªã³ã¯ã®äŸã
å®è¡ïŒBruteForce.exe [search_hash] [password_length] [password_characters]

ä»åã
çµæã¯ããœãŒããããããŒã¿ã§ã®ã¿æ©èœãããã€ããªæ€çŽ¢ã«ãªããããããã·ã¥ã§ããŒã¿ããœãŒãããå¿
èŠããããŸããã
èãçŽãããšãªãããã¹ãçšã®5 GBã®ããŒã¿ãã³ã³ãã¥ãŒã¿ãŒã®MySQLã«ã€ã³ããŒãããŸããã ã€ã³ããã¯ã¹ã¯äœæããããã¯ãšãªãCSVãžã®ãšã¯ã¹ããŒãã§ãœãŒããéå§ããŸããã
SELECT hash, pass INTO OUTFILE 'd:\\result.csv' FIELDS TERMINATED BY ',' OPTIONALLY ENCLOSED BY '' LINES TERMINATED BY '\n' FROM hashes ORDER BY hash
圌ã«ã¯16æéããããŸãããããã®éã«ãTEMPãã©ã«ããŒã«16ã®ã¬ãã€ããš25ã®ã¬ãã€ãã®2ã€ã®ãã¡ã€ã«ãäœæãããŸããã
ããããã€ã³ããã¯ã¹ïŒæ°æéäœæãããïŒã䜿çšããŠããå°ãªããšããœãŒãäžã«ã®ã¬ãã€ããåžåãããããããã®ãªãã·ã§ã³ã¯äŸç¶ãšããŠç§ã«ã¯é©ããŠããªãã ããŒãã«ã®ãµã€ãºã倧ãããªããšããã£ã¹ã¯ã«ååãªã¹ããŒã¹ããªããªããŸãã
SQLiteã§ããŒãã«ãäœæããããšããŸãããã倧容éåãã«èšèšãããŠããªããããåäœãéåžžã«é
ããªããŸããïŒ1 GBã§ã¯ããã·ã¥æ€çŽ¢ã«çŽ6ç§ããããŸããïŒã MySQLã¯é«éã§ãããã©ã¡ãã®å Žåãæçµçãªãµã€ãºã«ã¯é©ãããå
ã®ããŒã¿ã®ã»ãŒ2å以äžã§ããïŒã€ã³ããã¯ã¹ãåãããŠïŒã
ïŒãã¡ã€ã«å
šäœãã¡ã¢ãªã«ããŒãããããšãªãïŒããã°ããŒã¿ã®ãœãŒãã«é¢äžããããšããªããããæåã«ç»å Žããã¢ã«ãŽãªãºã ã§ããã
ããã«ãœãŒã ããæ¡çšããŸãã:)ã ãã¡ã€ã«ãèªåçã«ãœãŒããããããã«CïŒã§å°ããªã³ãŒããäœæãã500ã¡ã¬ãã€ãã§äžæ©ãã¹ããå®è¡ããŸããã ç¿æ¥ããã¡ã€ã«ã¯ãŸã ãœãŒããããŠããŸããã æå°ã¬ã³ãŒãããã¡ã€ã«ã®æåŸã«ããå Žåããã®ã¢ã«ãŽãªãºã ã§ã¯1è¡äžã«ç§»åãããã®ãããªã·ããããšã«ãã¡ã€ã«å
šäœãæåããæåŸãŸã§åŠçããå¿
èŠãããããã§ãã
ç§ã¯ä»ã®ãœãŒãæ¹æ³ã
ããŒãžãæ¢ãå§ãã
ãã©ããããé©åã§ããããšãå€æããŸããã ç§ã¯ãããã®ãã€ããªããã®å®è£
ãéå§ããŸããããXPããWindowsã«ããã©ã«ãã§ä»å±ããŠãã
sortãŠãŒãã£ãªãã£ã«é¢ããæ
å ±ãå¶ç¶èŠã€ããŸããã çµå±ã®ãšããã圌女ã¯ç§ã®ä»äºã«çæ³çã§ããïŒ ã©ã®ããã«æ©èœããã®ãããããŸãããã説æã§ã¯ã1åã®ãã¹ã§ãã¡ã€ã«ããœãŒããããšèª¬æããŠããŸãïŒ30åã§5 GBãœãŒãïŒã ãœãŒãåŠçäžã«ããŠãŒãã£ãªãã£ã¯å
ã®ãã¡ã€ã«ã®ééãšåãã ãã®è¿œå ã®ç©ºãã¹ããŒã¹ãå¿
èŠãšããŸãïŒäžæãã¡ã€ã«ã®å ŽåïŒã
ããããããã§ã¯ãã¹ãŠãã¹ã ãŒãºã§ã¯ãªãã£ãã 190 GBã®ãã¡ã€ã«ã䞊ã¹æ¿ãããšã3åã®ã¹ããŒã¹ãå¿
èŠã«ãªããäœããæ€çŽ¢ããŠåé€ãããã£ã¹ã¯ã¹ããŒã¹ã解æŸããŸããã ããã«ãæçµçãªãã¡ã€ã«ã«å¥åŠãªãã¢ãŒãã£ãã¡ã¯ãããçŸããŸããã

ãããã¯ãã¡ã€ã«ã®ã©ã³ãã ãªéšåã§çŽ10ã«ãªããŸããã ç§ã¯æ°åãœãŒããéå§ããæ¯å24æéåŸ
æ©ããŸããããäŸç¶ãšããŠã¢ãŒãã£ãã¡ã¯ããçŸããŸããã ç§ã¯ããããªãèµ·ãã£ãã®ãç解ããŠããŸããã§ãããç§ã¯12 GBã®RAMãWin7 x64ãæã£ãŠããŸããã ãã®éã«ã¡ã¢ãªããè©°ãŸã£ãããšä»®å®ã§ããŸãã ã·ã¹ãã ãåèµ·åããåŸãåããœãŒããåããŠæåããŸããã
æ€çŽ¢ãã
ä»ã§ã¯éŠ¬é¹¿ããŠããããã«æããŸããã以åã¯ãã¡ã€ã«ã®æ€çŽ¢ã¯ãã¡ã€ã«å
šäœãã¡ã¢ãªã«ããŒããããããã¡ã€ã«å
šäœã1è¡ãã€èªã¿åãããšã«ãã£ãŠããå®è¡ã§ããªããšãã€ãæã£ãŠããŸããã å®éã«å€§ããªãã¡ã€ã«ã§ãã€ããªæ€çŽ¢ãè©ŠããŠã¿ãŠããããã©ããããéãåäœããããèŠãŠãPHPã§ãããããã¯ç§ã«ãšã£ãŠå°ããªçºèŠã§ããããšãå€æããŸããã ãã®ãããªæ€çŽ¢ã¯ãããã»ããµãããŒããããã¡ã¢ãªãæ¶è²»ãããããããšãªããéåžžã«å€§éã®ããŒã¿ãåŠçããã®ãšåããããéãåäœããŸãã

ãã€ããªïŒå¥åãã€ããªïŒæ€çŽ¢ã¯ã次ã®åçã§æ©èœããŸãã
- é
åã¯2ã€ã«åå²ãããèªã¿åãäœçœ®ãäžå€®ã«ç§»åããŸãã
- äžå€®ã«ããçŸåšã®å€ã¯ãç®çã®å€ãšæ¯èŒãããŸã
- desired>ã®å Žåãé
åã®åŸåãååŸãããŸããå¿
èŠãª<current-ååã®å Žåã
- ã¢ã¬ã€ã®ãã®ååã§1ã3ã¹ããããå®è¡ããŸãã
ãããŠãã¡ããããã€ããªæ€çŽ¢ã®äž»ãªæ¡ä»¶ã¯ãé
åãæ€çŽ¢ããŒã§ãœãŒãããå¿
èŠãããããšã§ãã
ãã¡ã€ã«ã§ã¯ããã€ããªæ€çŽ¢ã¯ãŸã£ããåãããã«æ©èœããŸãã
fseeké¢æ°ã䜿çšããŠãªãã»ããäœçœ®ããã¡ã€ã«ã®äžå€®ã«ç§»åããäœçœ®ãè¡ã®å
é ã«èª¿æŽããŠïŒã¬ã³ãŒãã®äžå€®ã«ãããããå ŽåïŒãããã«ããã¬ã³ãŒããå®å
šã«èªã¿åããŸãã
1ã€ã®BUTã§ã¯ãªãå Žåã¯ãããã§åæ¢ããããšãã§ããŸã...
éšé
PHP_INT_MAXã®å€ïŒ2147483647ãã€ãïŒãè¶
ãããã¡ã€ã«ã¯æ€çŽ¢ã§ããŸããã§ããã ããã«ãfseeké¢æ°ã-1ãè¿ãå Žåãããã°ããã¹ãŠãåé¡ãªãå ŽåããããŸããããªãã»ããã¯ã©ãã§æ確ã§ã¯ãããŸããã ãã®çµæãå¿
èŠãªãã®ããŸã£ããèªã¿åãããŸããã ãã°ã¯æããã§ã¯ãããŸããã§ããããåé¡ãèŠã€ããéçšã§ããã°
ãã©ãã«ãŒã§æ
å ±ãèŠã€ããŸããã PHPããã¥ã¡ã³ããµã€ãã«ã¯ã2 GBãè¶
ãããã¡ã€ã«ãæ€çŽ¢ãã
fseeké¢æ°ïŒfseek64é¢æ°ïŒã«é¢ããã³ã¡ã³ãããããŸãã ããã¯ããã¡ã€ã«ã®å
é ããã§ã¯ãªããå埩ã«ãã£ãŠçŸåšã®ãªãã»ããããç®çã®å ŽæãŸã§èªã¿åãããšã«ãªããŸãã ããããç§ã¯ãã§ãã¯ããŸããããããæ©èœããŸããã
ãã¡ã€ã«ãåå²ããå¿
èŠããããŸããã ãã¡ã€ã«ãç Žå£ããããã®é©åãªãŠãŒãã£ãªãã£ãèŠã€ãããŸããã§ããïŒããããæ€çŽ¢ã¯äžååã§ããããæ€çŽ¢ã®æåã®ããŒãžã«ã¯çãããã€ã³ã¹ããŒã«ãããããŸããã§ããïŒã Windowsã®å
µåšåº«ã§ã¯ãå¥åŠãªããšã«ããã®ãããªãŠãŒãã£ãªãã£ã¯ãããŸããã ç·åžä»€å®ã§ã¯ããã€ãåäœã§åå²ããããšã¯äžå¯èœã§ããã粟床ãå¿
èŠã§ããã
ãœãŒã¹ãã¡ã€ã«ããã€ãåäœã§èªã¿åããæå®ããããµã€ãºã®åå¥ã®ãã¡ã€ã«ã«é çªã«é
眮ããåçŽãªãŠãŒãã£ãªãã£ãCïŒã§äœæããŸããã
å€å誰ãããããå¿
èŠãšããã
ãããããœãŒã¹ããããŠã³ããŒãããŠ
ãã ãã ã
å®è¡ïŒSplit.exe [ãã¡ã€ã«] [in_bytes]
å§çž®
ãŸãããœãŒããããããŒã¿ã2ã€ã®åå¥ã®ãã¡ã€ã«ã«åå²ããŸããããããã®ããã·ã¥ãšãã¹ã¯ãŒããããããæ ŒçŽãããŠãã.hashã.passã§ãã 次ã«ããã¹ãŠã®ããŒã¿ã1ã€ã®ããã¯ã¹ã«ãããã¯ãããŸããã æ°å€ã¯ãã®æ¹æ³ã§æ倧2åãŸã§ç°¡åã«ããã¯ãããåå€ã®é·ããåºå®ãããŠãããããæ¬ èœããŠããã®ã£ããã«0xFãè¿œå ãããŸãã
å§çž®ã®å®è¡æ¹æ³ãšæ€çŽ¢ã®å®è¡æ¹æ³ã¯ã次ã®äŸã§æ確ã«ããããŸãïŒããã·ã¥0dd5eac5b02376a456907c705c6f6fb0b5ff67cfã®ãã¹ã¯ãŒããæ¢ããŠããŸãïŒã

0D D5 EA
ããã·ã¥ã®æåã®6æåã ãã®æ¹æ³ã§ã¯ããã·ã¥ãéè€ããŸãããããã»ã©å€ãã¯ãããŸããã ãããŠããã¹ã¯ãŒãã¯ãã¹ãŠä¿åãããŠããããã1000ã®ãã¹ã¯ãŒãããã§ããå
ã®ããã·ã¥ãéåžžã«è¿
éã«åŸ©å
ã§ããŸãã
70 FF
-70ãããã«ããã¯ãããŸããããã¯ã0dd5eaã§å§ãŸãããã·ã¥ã®digits.passãã¡ã€ã«ã«å«ãŸãããã¹ã¯ãŒãã®æ°ã§ãã
59 99 95 68 FF FF
FF-çªå·59999568ãããã«ããã¯ãããŸããããã¯ãdigits.passãã¡ã€ã«å
ã®ãã¹ã¯ãŒãã®èªã¿åãéå§äœçœ®ã§ãã
11a19a90
-digits.passãã¡ã€ã«å
ã®70åã®ãã¹ã¯ãŒãã®èªã¿åããéå§ããäœçœ®ã 次ã®ããã«èšç®ãããŸãïŒ59999568 * 5ïŒãã§ã«å§çž®ãããŠãããã¹ã¯ãŒãã®é·ãããã€ãåäœïŒ= 299997840ïŒ16é²æ°ã«å€æïŒ
84 04 05 38 8F
8F-çªå·840405388ãããã«ããã¯ãããŠããŸããããã¯ãç®çã®ããã·ã¥ã«å¯Ÿå¿ãããã¹ã¯ãŒãã§ã
次ã«ããã¡ã€ã«ã®æåŸã§ãã¹ã¯ãŒããåãæšãŠããããPHP_INT_MAXïŒ2147483647-ïŒ2147483647ïŒ
ãã¹ã¯ãŒããµã€ãºïŒãã€ããè¶
ããªãããã«ã.passãã¡ã€ã«ãåå²ããŸãã
.hashãã¡ã€ã«ã®æ倧ãµã€ãºã¯185 MBã§ãããç Žæããå¿
èŠã¯ãããŸããã§ããã

å®éãæ€çŽ¢ã¯.hashãã¡ã€ã«ã§ã®ã¿å®è¡ããããã¹ã¯ãŒãã®ã¿ã.passããïŒãã¡ã€ã«å
ã®ç¹å®ã®äœçœ®ããïŒããŒããããŸãã ããããããã¯ãã®èšäºã®äž»èŠãªãããã¯ãåŠå®ãããã®ã§ã¯ãããŸãããçããŒã¿ã§é床ã確èªããŸããã
ãã¹ãŠã®æªå å·¥ãã¡ã€ã«ã®ééã¯260 GBã§ãå§çž®åŸã¯70 GBã«ãªããŸããã ãã®ãµã€ãºã«ã¯ãæåã®ä»ããæ°åãã1ã6æåã®ãã¹ã¯ãŒããšã7ã10æåã®ãã¹ã¯ãŒããå«ãŸããŸããæ°åã®ã¿ãåèšã§çŽ135åã®ãã¹ã¯ãŒãã§ãã ãã®åŸã1åèªã®åèªãè¿œå ããŸããã ãã®çµæãå®éã®PââvPGNãµãŒããŒããã®ãã¹ã¯ãŒãã®çŽ90ïŒ
ãèŠã€ããå¿
èŠããããŸãïŒ93.5ïŒ
ã¯ä»¥åã®PvPGNãµãŒããŒããèŠã€ãããŸããïŒã
å°ãã®æé©å
1人ã®
åªç§ãªäººãPvPGNããã·ã¥é¢æ°ãPHPããJavaScriptã«ç§»æ€ããŸããïŒããŒãã«çšã«250 GBã®ã¹ããŒã¹ãæã€ä»®æ³ãµãŒããŒãæäŸããŸããïŒã
ããŸããŸãªããã·ã¥å®è£
ã®ããã©ãŒãã³ã¹æž¬å®ãè¡ããŸããã
harpywar.pvpgn.pl/?do=hashãããŠã³ããŒããããšãããŸããŸãªèšèªã®å®è£
ãå©çšã§ããŸã
æããã«ãCãæéã§ãã Firefoxã¯ã¹ã¯ãªããã®å®è¡äžã«ãã³ã°ããŸããããã¹ãŠã®ãã©ãŠã¶ãŒã§é床ã¯ã»ãŒåãã§ãã
PHPãåå ã§æ€çŽ¢ãé
ããªããŸããã ãã®ããããã¹ãçŽåŸã«ããã®ãªãœãŒã¹éäžåã¿ã¹ã¯ããã©ãŠã¶ãŒã§ã¯ã©ã€ã¢ã³ãã«éä¿¡ããããšã«ããŸããã ããã«ãã¯ã©ã€ã¢ã³ãã®å Žåãããã¯å®å
šã«ç®ã«èŠããŸãã-å¹³åããŠã1åã®æ€çŽ¢ã¯ãšãªã«ã€ã1,000å以äžã®ããã·ã¥ãçæããã®ã«ããããŸãã ãã§ã«å°ãã ã£ããã®ãããçŽãå¿
èŠããããŸãããèŠã€ãã£ããã¹ã¯ãŒãã¯ãJSONé
åã§ã¯ã©ã€ã¢ã³ãã«æž¡ããããã©ãŠã¶ã§ãã¹ã¯ãŒããç¹°ãè¿ããããã·ã¥ãçæããŸãã çæãããããã·ã¥ãæ€çŽ¢ãããããã·ã¥ãšäžèŽããå Žåããã¹ã¯ãŒãã¯èŠã€ãã£ããšèŠãªãããŸãã
ã¹ã¯ãªãŒã³ã·ã§ããã§ãããã©ã®ããã«æ©èœãããã®å€§ãŸããªãããæ確ãªäŸïŒãŸã å§çž®ãããŠããªããã¡ã€ã«ããããŸãïŒïŒ

ãŸãšã
倧èŠæš¡ãªããŒã¿ã»ããããŸãã¯ã¿ãŒã³ããŒãœãªã¥ãŒã·ã§ã³ãæ€çŽ¢ããä»ã®æ¹æ³ããããããããŸãã ããããç¹å®ã®ã¿ã¹ã¯ã®ããã«ãç§ã®å®è£
ã¯éåžžã«é«éã§ãéåžžã«éèŠãªããš-éåžžã«ã³ã³ãã¯ãã§ããããšãå€æããŸããã ããã¯ã°ã©ãŠã³ãã®çæãšããŒãã«ã®äžŠã¹æ¿ããå«ããããã«çŽ1é±éãè²»ãããŸããã
ãã«ãŒããã©ãŒã¹ã³ãŒãã䞊ååãããŠGPUã«ç§»æ€ããããšãéåžžã«å€ãã®æåãå«ããã¹ã¯ãŒããæ¯èŒçè¿
éã«ãœãŒãããããããããã¯ããããäœããäœæããã®ã«æé©ãªäŸã§ã¯ãããŸããã
ãããããã®éçšã§å€ãã®ç¥èãšçµéšãåŸãã®ã§ãããããå
±æããããšæããŸããã
æŽæ°ãã-èå³ã®ãã人ã®ããã«PHPã®ãœãŒã¹ãã¬ã€ã¢ãŠãããŸããããããŒãã«ãã¡ã€ã«ããªããã°ããã®èª¿æ»ã¯é¢çœããªããããããŸããïŒ
index.php ã
hashcrack.class.php ã
-äŸãšããŠããã¡ã€ã«å
ã®ãã€ããªæ€çŽ¢ã䜿çšããŠã倧ããªãã°ã®ããŒã¿ãã¹ã©ã€ã¹ããããšãã§ããŸãïŒç¹å®ã®æ¥ä»ã®ãéå§ããšãçµäºãã®çµ±èšãåæããå¿
èŠãããå ŽåïŒ
-ç§ã¯ããŒã¿ã«ã³ãã³ããŒã§ãã¹ãç¯ããŸãã-ãããå©çšããŠããã€ãåäœã§ãã¡ã€ã«ãæ£ç¢ºã«åå²ããããšãã§ããŸãïŒ
Joshua5ãææ¡ïŒã
-ããŸããŸãªããŒã¿ããŒã¹ã®æ©èœã«ããŸã詳ãããªããããæ€çŽ¢ã«æéãããããŸããã
Alexey Pechnikovã¯ãSQLiteã§ã¯ããã©ãŒãã³ã¹
ãéåžžã«é«ããªãå¯èœæ§ããããšèšã£ãŠããŸãããããŒãã«ã§ã¯ãfts4ãã䜿çšããå¿
èŠããããŸããã MySQLã«ã¯ãããã䌌ããããªãã®ããããŸãã
-以äžã®ã³ã¡ã³ãã«ã¯ãããŒã¿ãæŽçããŠæ€çŽ¢ããæ¹æ³ã«é¢ããã¢ã€ãã¢ããããŸãã
-webhamsterããã®
ã³ã¡ã³ãã¯ããã®ãããã¯ã§ç€ºãããã£ãããšãå®å
šã«åæ ããŠããŸã