ããã«ã¡ã¯ãHabrasocietyïŒ
ãã®ããã7zipã¢ãŒã«ã€ãã®å€±ããããã¹ã¯ãŒããååŸããå¿
èŠããããŸãããããã«ã¯ãå€ããã£ã¹ã¯ã®ããã€ãã®ãã¡ã€ã«ã®ããã¯ã¢ããã³ããŒãå«ãŸããŠããŸããã ç§ã¯ãã£ãšåã«ãã¹ã¯ãŒããçŽå€±ããŸãããããããå埩ããããã»ã¹ã«ã¯å€å°ã®åªåãå¿
èŠã§ãããªãèå³æ·±ãåºæ¥äºã§ããããšãå€æããŸããã ããã«ã€ããŠã¯ãèšäºã§è©³ãã説æããŸãã
ãã¹ã¯ãŒããšã¯äœã§ããïŒ
éçºè
ã¯ããã¹ã¯ãŒããããã¹ãã§ä¿åããããšã¯å®å
šã§ã¯ãªãããšã«æ°ä»ãããããããã·ã¥ïŒãã¹ã¯ãŒãã«åºã¥ããŠçæãããå€ã®ã»ããïŒã®ã¿ã衚瀺ãããŸãã ãã®ãããªå€æã¯ãæå®ã®ã¢ã«ãŽãªãºã ã«åŸã£ãŠããã·ã¥é¢æ°ã«ãã£ãŠå®è¡ãããäžæ¹åã§ãã
ããã·ã¥ã¢ã«ãŽãªãºã ã«ã¯ãMD5ãSHA-1ãSHA-2ãªã©ããããŸãã ããã·ã¥ãããã¹ã¯ãŒããå埩ããã«ã¯ããã«ãŒããã©ãŒã¹æ¹åŒã䜿çšã§ããŸãã å¯èœãªãã¹ã¯ãŒãããšã«ããã·ã¥ãäœæããããã埩å·åããå¿
èŠã®ããããã·ã¥ãšæ¯èŒããã ãã§ååã§ãã å®éããã¡ã€ã«ãååŸãããã®ãã¡ã€ã«ããããã·ã¥ãæœåºããŠãã¯ã©ãã«ãŒããã°ã©ã ã§åŸ©å·åããå¿
èŠããããŸãã åã¢ã«ãŽãªãºã ã®ããã·ã¥æœåºã®æ¹æ³ã¯ç°ãªããåã¢ã«ãŽãªãºã ã®å埩ã®è€éãã¯ç°ãªããŸãã
æ€çŽ¢ã®è€éããèšç®ããæ¹æ³ã¯ïŒ è€éãªãã¿ã³ã«æ·±ãå
¥ã蟌ãããšãªããããã¯ãã¹ã¯ãŒãã®é·ããšããã«äœ¿çšãããæåã»ããã®äž¡æ¹ã«äŸåããŠãããšèšããŸãã
ããšãã°ãæ°åã®ãã¹ã¯ãŒã0ã9ã«ã¯10æåãå«ãŸããŠããŸãã 5æ¡ã®ãã¹ã¯ãŒãã«ã¯ãm = 5æåãå«ãŸããŠããŸãã çµã¿åããã®æ°ã¯ãP = m ^ nãŸãã¯5ã®10ä¹-9765625ã«ãªããŸãã
ã©ãã³æåïŒå€§å°ïŒãèæ
®ãããšãããã¯26 * 2 + 10 = 62ã§ãããPã¯ãã§ã«5ã®62ä¹ã§ãïŒ
1é±éã§2ã€ã®22ã³ã¢Xeonã䜿çšããŠãã¹ã¯ãŒããzipã«åŸ©å
ããæ¹æ³ãèŠãŸããã ãã®ãããªãªãœãŒã¹ãããã¹ã¯ãŒããéžæããæéãããŸããªããã°ã©ãã£ãã¯ããããèªåã®ç®çã«äœ¿çšããããšãèããŠããŸããã ãããã®ããã€ã¹ã®èšç®èœåã¯çŸåšåºãç¥ãããŠããŸãã ã°ã©ãã£ãã¯ã¢ã¯ã»ã©ã¬ãŒã¿ã®è£œé å
ã¯ãAMDãšNvidiaã§ãã Nvidiaã«ã¯CUDAããããŸã-åæãã¹ãã«ãããšãGPUã§ã®ã³ã³ãã¥ãŒãã£ã³ã°ã®ããã®ç¬èªã®ã¯ããŒãºãAPIã§ãããOpenCLã®ãªãŒãã³ã¢ããã°ãã20ïŒ
é«éã§ããã
ãã¹ãŠã®ããã°ã©ã ã«SDKãããããã§ã¯ãããŸãã ã ããã«ãNvidiaã«ãŒãã¯ãOpenCLã«å®è£
ãããèšç®ã«ãããŠAMDã«ãŒããããå£ã£ãŠããŸãã ãã®åé¡ã¯ãæ°é®®ãªãã©ã€ããŒã«ãã£ãŠéšåçã«åŠçãããŸããããŸã ã®ã£ãããæ®ã£ãŠããŸãã æåŸã«ããããªã«ãŒãã®ã³ã³ãã¥ãŒãã£ã³ã°ãŠãããã®æ°ã«ééããŸãã
以äžã§ã¯ãOpenCLã§å®è¡ãããåæã«æ倧128ã®ãããªã«ãŒããæ¥ç¶ã§ããHashchatãœãªã¥ãŒã·ã§ã³ãæ€èšããŸãã ãã®ãã¹ãã«ã¯ãã®ãããªå¯èœæ§ã¯ãããŸããããããããããå€ãã®ã«ãŒãã眮ãããšãã§ããããã©ãŒãã³ã¹ã®å·®ã¯äŸ¡æ Œã«äžé£ãåããªã®ã§ãäžéäŸ¡æ Œã»ã°ã¡ã³ããåªå
ããããšã¯çã«ããªã£ãŠããŸãã
ãã¹ã¯ãŒãå埩ããŒã«
Hashcatã¯ã以åã«äœ¿çšãããoclHashcat / cudaHashcatãŠãŒãã£ãªãã£ã®åŸç¶ã§ãã çŽå€±ãããã¹ã¯ãŒããéžæããããã®æéã®ããŒã«ãšããŠå®£èšãããŠããŸãã ããŒãžã§ã³3.0以éãCPUãšGPUã®äž¡æ¹ã®äœ¿çšããµããŒãããŠããŸããããã¹ãŠã®ã¢ã«ãŽãªãºã ããµããŒãããŠããããã§ã¯ãããŸããã ããšãã°ãGPUã䜿çšãããšãBcryptã®ãã¹ã¯ãŒããèŠã€ãããŸããã ãã ããMD5ããã³SHA-1ã®ãã¹ã¯ãŒãã¯éåžžã«è¿
éã«éžæãããŸãã 200以äžã®ããã·ã¥ã§åäœããŸãã å®éãããã¯ãŠãããŒãµã«ãªã¯ãã¹ãã©ãããã©ãŒã ãœãªã¥ãŒã·ã§ã³ã§ãã
ãããã®ããã€ããååŸããã«ã¯ã以äžã®ãŠãŒãã£ãªãã£ãå¿
èŠã§ãã
John The Ripper-倱ããããã¹ã¯ãŒããå埩ããããã®ç®¡çè
ããŒã«-äŒèª¬çãªããã¯ãœãããŠã§ã¢ãŠãŒãã£ãªãã£ã å€æ°ã®ããã·ã¥ãšãã®èªåèªèã®ãµããŒãã«ãã人æ°ããããŸãã ãµãŒãããŒãã£ã®ãã®ãå«ãå€ãã®ã¢ãžã¥ãŒã«ããµããŒãããŠããŸãã John The Ripperã¯Kali Linuxã«ãå«ãŸããŠããŸãããåãæšãŠããã圢åŒã§ãã ãã®ããã°ã©ã ã§ã®ã¿ãzip2johnãrar2johnãpdf2john.pyãpfx2john.exeãªã©ãä»ã®åœ¢åŒããããã·ã¥ãæœåºããããã«çµ¶å¯Ÿã«å¿
èŠãªæ¡åŒµæ©èœãèŠã€ãããŸããã
CainïŒAbel-玹ä»ãå¿
èŠãããŸããã ããã°ã©ã ã«ã¯ç¬èªã®ã¹ããã¡ãŒããããŸãã
ä»ã®ããŒã«ããããŸãããããã¥ã¡ã³ããäžååã§GUIããªãããé床ãå£ã£ãŠããŸãã ããŸããŸãªã¿ã€ãã®ããã·ã¥ã®ãµããŒããéèŠã§ãã ãããã£ãŠãHashcatã§åæ¢ããŸãã
äŸãšããŠãã«ã¹ã¿ã 7zipã¢ãŒã«ã€ãã䜿çšããŸãã ã¢ãŒã«ã€ãã¯èªåã§çæããŸãã 7zipã¯AES256ã¢ã«ãŽãªãºã ã䜿çšããŸã
ããã·ã¥ã埩å
ããã«ã¯ããŠãŒãã£ãªãã£7z2hashcatã䜿çšããŸãã ããã¯å®éã«ã¯Perlã¹ã¯ãªããã§ãã
ãªã³ã¯ããããŠã³ããŒãããŠå±éããŸãã7z2hashcat64-1.2 7z.7z > hash.txt
ãã®çµæãããã¹ããã¡ã€ã«ã«ç®çã®ããã·ã¥ã衚瀺ãããŸãã 次ã«ãHashcatãæ§æããŸãã
- 補åèªäœãå
¥ããŸã
- ç§ãã¡ã¯GUIãèªç±ã«ããããŠããã°ã©ã ãããç¥ã£ãŠããããã«ããŠããŸãã
- ããã·ã¥ãã©ãŒã«ç§»åããããããHashcatGUIãåé€ããŸãã
- HashcatGUIã§ãã©ã«ããŒã«ç§»åããApp.HashcatGUI.exeãå®è¡ããŸãã
- èµ·åæã«ãã·ã¹ãã ã®ããã深床ã«å¿ããŠhashcat64.exeãŸãã¯hashcat32.exeããã°ã©ã ã®å®è¡å¯èœãã¡ã€ã«ãæå®ããŸã
GUIã¯ãæ€çŽ¢ãå®äºãããšããšã©ãŒãã¹ããŒããŠã¯ã©ãã·ã¥ããããšããããŸãã ããã§ãããã§ãã¯ãã€ã³ãã¯æäŸãããŸããæåŸã«å®è¡ãããŠããã»ãã·ã§ã³ã«æ»ãã[ã«ã¹ã¿ã ã³ãã³ããšãµãŒãã¹]ã¿ãã§æ€çŽ¢ãç¶è¡ã§ããŸãã
Hashcatã¯ãã³ã³ãã¥ãŒã¿ãŒå
ã®ãã¹ãŠã®GPU / CPUããã€ã¹ãæ€åºãã埩å·åãéå§ããŸãã
ããã°ã©ã ã®æ©èœããã¹ããã
Hashchatãèµ·åããŸãã ããã·ã¥ã¿ã€ããšããŠm 11600ïŒ7zipïŒãæå®ããæ€çŽ¢ã¹ããŒã¿ã¹ã60ç§ããšã«æŽæ°ããåºåãã¡ã€ã«ãšæ€çŽ¢ã®ãã¹ã¯ãæŽæ°ããŸãã
ãã¹ã¯ã«ããæ€çŽ¢ã¯ããã«ãŒããã©ãŒã¹ã®æ¹è¯çãšããŠäœçœ®ä»ããããŠããŸãã ãã¹ã¯ãŒããã¿ãŒã³ã«ã€ããŠäœããç¥ã£ãŠããã°ãæ€çŽ¢ã倧å¹
ã«é«éåã§ããŸãã ãããæ¥ä»ãååã幎ããŸãã¯æå³ããæåãããšãã°ãRïŒRïŒR-ãã·ã¢èªã®ã¢ã«ãã¡ãããã®3æåã§ãããšããŸãã
ãã®å Žåã7æ¡ã§ãã ãã¹ã¯ãŒãã6æ¡ã®é·ãã®å Žåããã¹ã¯ãŒããèŠã€ãããªããããåè©Šè¡ããå¿
èŠãããããšã«æ³šæããŠãã ããã ããã»ã¹ãèªååããããã«ããã£ãã¯ãå¢åããæäŸãããŸãã
hashcat64.exe -a 3 --session=2018-01-24 -m 11600 -w 3 --status --status-timer=60 --potfile-disable -p : --gpu-temp-disable -o "E:\asus\result.txt" --outfile-format=3 "E:\asus\hash.txt" ?d?d?d?d?d?d?d
äžçªäžã®è¡ïŒãã¡ã€ã«
EïŒ\ asus \ result.txt ã ãã¹ã¯ãŒã
3332221ã¯çŽ10ç§ã§ååŸãããŸãã
ãã¹ã¯ãŒãã®é·ããé·ãããããšããŠããŸãã æ€çŽ¢é床ãèããäœäžããŸãã-æ¯ç§635ãã¹ã¯ãŒããŸã§ã
çµæïŒãã¹ã¯ãŒã
3334566611-10æåã å埩ããã®ã«çŽ3åããããŸããã
ã¿ã¹ã¯ãè€éã«ããŸãããã ãã¹ã¯ãŒãã¯ã©ãã³æåãšæ°åã§æ§æãããŠããŸãã ãã¹ã¯ãŒãã¯11æåã«ãªããŸããã ãã®ããã°ã©ã ã«ã¯ãéžæãå éããå€ãã®ãªãã·ã§ã³ããããŸãã æçœãªãªãã·ã§ã³ã¯ãããŒã¿ããŒã¹ã䜿çšããŠæšæºãã¹ã¯ãŒãã®ããŒã¹ã䜿çšããããšã§ãã
èŸæžHashKiller Passwordsã眮ããŸãã ããã°ã©ã ãã©ã«ãã«ã¯æ¢ã«äŸããããŸã-ãã®ããã«1000ã®åèªãããã®ã§ããWordlistsïŒMarkovãã¿ãã«èŸæžãè¿œå ããŸãã
HashKiller PasswordsèŸæžãããŠã³ããŒãããŠãããšãã°ãDictãã©ã«ããŒã«æœåºããŸãã
èµ·åäŸïŒ hashcat64.exe -a 0 --session=2018-01-24 -m 11600 -w 3 --status --status-timer=60 --potfile-disable -p : --gpu-temp-disable -o "E:\asus\result.txt" --outfile-format=3 "E:\asus\hash.txt" "E:\asus\hashkiller-dict.txt"
ãã«ã³ãã¯å¥ã®çµã¿åãããªãã·ã§ã³ã§ãããå¥åã®å®è¡å¯èœãã¡ã€ã«ããããŸãã
https://en.wikipedia.org/wiki/Markov_Chainãªãã·ã§ã³ã®ææžåã¯äžååã§ãã GUIãã«ãã§ã¯ãå
¥åã«ã¯40ã®å€ããå§ãããŸããïŒDïŒLïŒUïŒã©ãã³æåãšæ°åïŒã
ãŸãããã€ããªããæ»æã䜿çšããŸãã ããã¯ãããšãã°
Password113 ã
Qwe1235ã®ããã«ãæ«å°Ÿã«ãã¹ã¯ãè¿œå ããèŸæžããã®åèªã®æ€çŽ¢ã§ãã
ãŸããããã°ã©ã ã«ã¯ã.hcmask圢åŒã®æ¢è£œã®ãã¹ã¯ããããŸããããã«ãããæ¢ç¥ã®ãã¿ãŒã³ã1è¡ãã€å埩åŠçã§ããŸãã ãã®ãã¡ã€ã«ãã¡ã¢åž³ã§éããšãäœåãªè¡ã«ã³ã¡ã³ããä»ããããšãã§ããŸãã ãŸãããã€ã³ã¯ãªã¡ã³ãããªãã·ã§ã³ã§äœ¿çšããããåèªã®ãªã¹ããšçµã¿åããããããããšãã§ããŸãã
ãã€ããªããæ»æã«å ããŠãããã°ã©ã ã¯çµéšçã«ç¹å®ãããç¹å®ã®ã¢ã«ãŽãªãºã ã®éžæã«ãŒã«ããµããŒãããŠãããããã«ããè¯ãçµæãåŸãããŸãã
ããããã«ãŒã«æ€çŽ¢ã¯æãæè¡çã«è€éãªæ»æã§ãããããã°ã©ãã³ã°èšèªã§ãã éçºè
ã«ãããšããã®ã¢ãããŒãã¯æ£èŠè¡šçŸãããé«éã§ãã æ¢è£œã®ã«ãŒã«ã¯ãHashchatã®ã«ãŒã«ãã£ã¬ã¯ããªããGUIã«ããŒãããããšã§ããã§ã«äœ¿çšã§ããŸãã ãããã®ãªãã·ã§ã³ãèãããšãããã°ã©ã ã¯2.5æéã§çµæãåºããŸããã
ãã¹ã¯ãŒã
ããããã£123ã¬ã€ã³ããŒããŒãã«
ãã®äŸã§ã¯ãããªãè€éãªæå·åã¢ã«ãŽãªãºã ã䜿çšããŠããŸãã ããšãã°ã劥åœãªæéå
ã«MD5ãžã®ããã·ã¥ãéžæãããã¹ã¯ãŒããéžæãããŠããªãå ŽåãæåŸã®åŒæ°ã§ããã¬ã€ã³ããŒããŒãã«ã«æ³šæãæãããšã¯çã«ããªã£ãŠããŸãã ãããã¯ãã«ãŠã³ããããŠæ¡ä»¶ããŒãã«ã«ä¿åããããã¹ãŠã®äžè¬çãªãã¹ã¯ãŒãã®æšå®ããã·ã¥å€ã§ãã ããã·ã¥ã¢ã«ãŽãªãºã ãç¥ã£ãŠããã°ãããŒãã«ãã¡ã¢ãªã«ããŒãããç®çã®ããã·ã¥ãæ€çŽ¢ã§ããŸãã éåžžãããšãã°ãWebã¢ããªã±ãŒã·ã§ã³ã®ãã¹ãŠã®æŒæŽ©ãã¹ã¯ãŒããªã©ãæçæéã§å€æ°ã®ãã¹ã¯ãŒããéžæããããã«äœ¿çšãããŸãããããã¯å¥ã®è©±ã§ãã
çŸåšãããŸããŸãªã¿ã€ãã®ããã·ã¥ããµããŒããã2ã€ã®ãããžã§ã¯ãããããŸãã
- Rainbowcrack -4ã€ã®ããã·ã¥ã¢ã«ãŽãªãºã ããµããŒãïŒLN / NTLMãMD5ããã³SHA-1
- Linuxçšã®rcracki_mtãŸãã¯rcracki -MD4ãMD5ãDoubleMD5ãSHA1ãRIPEMD160ãMSCACHEãMySQL323ãMySQLSHA1ãPIXãLMCHALLãHALFLMCHALLãNTLMCHALLãORACLE
ãããã«
åªããã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ããªããŠããä»æ¥ã§ã¯éåžžã«æ°žç¶çãªã¿ã€ãã®ããã·ã¥ã§ã解èªã§ããŸãã æšæºãšããŠã®å¹
åºãé
åžãèãããšãçŸæç¹ã§ã¯ãå€ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ã¢ããªãªãªã«è匱ã§ãã ããããè¿ãå°æ¥ãSHA-2ãGOST_R_34.11-2012ãªã©ã®æšæºã«åãæ¿ããäºå®ã§ãã ãããŸã§ã®éããã¹ã¯ãŒããçæããããã®äžè¬çãªæšå¥šäºé
ã®ã¿ã䜿çšããŸãã
- æ¥åžžçã«äœ¿çšãããäžè¬çãªåèªã䜿çšããªãã§ãã ããã ãããã®æ°åã ãããããŸãã
- ããŒããŒãã§æ°åã®åŸã«ç¶ãåèªãæååã䜿çšããªãã§ãã ããã 1231231ãQwertyã«è¿œå ããŠãããã¹ã¯ãŒãã®å®å
šæ§ã¯åäžããŸããã èŸæžãšãã¹ã¯å
šäœãåæ¥ã§æŽçã§ããŸãã
- åå¢èªãªã©ã®æšæºçãªçµã¿åããã ãã®ãããªææ³ã«çŠç¹ãåãããéžæã«ãŒã«ã«ãã£ãŠå®¹æã«ç解ã§ããŸãã
- å人æ
å ±ã䜿çšããªãã§ãã ããã ç§ãã¡ã®äžçã«ã¯å
¬éæ
å ±ãå€ãããŸãã