下載本文檔
版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
RainbowCrackTutorial
Introduction
RainbowCrackisageneralproposeimplementationofPhilippeOechslin'sfastertime-memorytrade-offtechnique.Functionofthissoftwareistocrackhash.
Thestraightforwardwaytocrackhashisbruteforce.Inbruteforceapproach,allcandidateplaintextsandcorrespondinghashesarecomputedonebyone.Thecomputedhashesarecomparedwiththetargethash.Ifoneofthemmatches,theplaintextisfound.Otherwisetheprocesscontinuesuntilfinishsearchingallcandidateplaintexts.
Intime-memorytradeoffapproach,thetaskofhashcomputingisdoneinadvancewiththeresultsstoredinfilescalled"rainbowtable".Afterthat,hashescanbelookedupfromtherainbowtableswheneverneeded.Thepre-computationprocessneedsseveraltimestheeffortoffullkeyspacebruteforce.Butoncetheonetimepre-computationiscomplete,thetablelookupperformancecanbehundredsorthousandstimesfasterthanbruteforce.
ThisdocumentexplainsthestepstomaketheRainbowCracksoftwareworkingforfirsttimeuser.Mostcontentsinthisdocumentareimplementationspecific,whileothersaregenerictotime-memorytradeoffalgorithm.
TheRainbowCracksoftwareincludesthreetoolsthatmustbeusedinsequencetomakethingsworking.
Step1:Usertgenprogramtogeneraterainbowtables.
Step2:Usertsortprogramtosortrainbowtablesgeneratedbyrtgen.
Step3:Usercrackprogramtolookuprainbowtablessortedbyrtsort.
Thetablelookupprocessinfinalstepisequivalenttothehashcrackingprocess.
Thewaytousetheseprogramswillbeexplainedinthisdocument.Allofthemarecommandlineprograms.
Step1:Usertgenprogramtogeneraterainbowtables
Thertgenprogramneedseveralparameterstogeneratearainbowtable,thesyntaxofthecommandlineis:
rtgenhash_algorithmcharsetplaintext_len_minplaintext_len_maxtable_indexchain_lenchain_numpart_index
Explanationoftheseparameters:
parameter
meaning
hash_algorithm
Thehashalgorithm(lm,ntlm,md5andsoon)usedintherainbowtable.
charset
Thecharsetofallplaintextsintherainbowtable.Allpossiblecharsetaredefinedinthecharset.txtfile.
plaintext_len_min
plaintext_len_max
Thesetwoparametersdefinethepossiblelengthofallplaintextsintherainbowtable.Ifcharsetisnumeric,plaintext_len_minis1,andplaintext_len_maxis5.Thentheplaintext"12345"islikelyincludedinthetable,but"123456"willnotbeincluded.
table_index
chain_len
chain_num
part_index
Thesefourparametersarereallydifficulttoexplaininsimplewords.Toreadandunderstand
PhilippeOechslin'soriginalpaper
canhelptoknowtheexactmeaning.
Thetable_indexisrelatedtothe"reducefunction"thatisusedinrainbowtable.
Thechain_lenisthelengthofeach"rainbowchain"intherainbowtable.A"rainbowchain"sized16bytesisthesmallestunitinarainbowtable.Arainbowtablecontainslotsofrainbowchains.
Thechain_numisthenumberofrainbowchainsintherainbowtable.
Thepart_indexparameterdetermineshowthe"startpoint"ineachrainbowchainisgenerated.Itmustbeanumber(orbeginwithanumber)inRainbowCrack1.3&1.4.InRainbowCrack1.2,thisparametercanbeanystringbecauserandom"startpoint"isused,while1.3&1.4usethesequential"startpoint".
Therightvaluesofalltheparametersdependonwhatyouneed,toselectgoodparametersrequiresomeunderstandingofthetime-memorytradeoffalgorithm.
Onereadytoworkconfigurationisgivenbelow,asanexample:
hash_algorithm
lm,ntlmormd5
charset
alpha-numeric=[ABCDEFGHIJKLMNOPQRSTUVWXYZ]
or
loweralpha-numeric=[abcdefghijklmnopqrstuvwxyz]
plaintext_len_min
1
plaintext_len_max
7
chain_len
3800
chain_num
33554432
keyspace
36^1+36^2+36^3+36^4+36^5+36^6+36^7=
keyspaceisthenumberofpossibleplaintextsforthecharset,plaintext_len_minandplaintext_len_maxselected.
tablesize
3GB
successrate
0.999
Thetime-memorytradeoffalgorithmisaprobabilisticalgorithm.Whatevertheparametersareselected,thereisalwaysprobabilitythattheplaintextwithintheselectedcharsetandplaintextlengthrangeisnotcovered.Thesuccessrateis99.9%withtheparametersusedinthisexample.
tablegenerationcommands
Theactualrtgencommandsusedtogeneratetherainbowtablesare:
rtgenmd5loweralpha-numeric1703800335544320
rtgenmd5loweralpha-numeric1713800335544320
rtgenmd5loweralpha-numeric1723800335544320
rtgenmd5loweralpha-numeric1733800335544320
rtgenmd5loweralpha-numeric1743800335544320
rtgenmd5loweralpha-numeric1753800335544320
Ifntlmorlmtableisdesired,replace"md5"incommandsabovewith"ntlm"or"lm".
Ifalpha-numericcharsetisdesired,replace"loweralpha-numeric"incommandsabovewith"alpha-numeric".
Iflmtableistobegenerated,pleaseCONFIRMthecharsetisalpha-numericinsteadofloweralpha-numeric.ThelmalgorithmNEVERuseslowercaselettersasplaintext.
Nowitistimetogeneraterainbowtable.
ChangethecurrentdirectoryofyourcommandprompttoRainbowCrack'sdirectory,andexecutefollowingcommand:
rtgenmd5loweralpha-numeric1703800335544320
Thiscommandtakesabout4hourstocompleteonCore2DuoE7300processor.ItissafetostopthecomputationanytimebypressingCtrl+C.Nexttimeifthertgenprogramisexecutedwithexactlysamecommandlineparameters,itwillresumefromwherethecomputationisstoppedandcontinuethetablegeneration.
Whenthecommandisfinished,afilenamed"md5_loweralpha-numeric#1-7_0_3800x33554432_0.rt"sized512MBwillbeinplace.Thefilenameissimplyallthecommandlineparametersconnected,withthe"rt"extension.Thercrackprogramtobeexplainedlaterneedthispieceofinformationtoknowparametersoftherainbowtable.Sodon'trenamethefile.
Remainingtablescanbegeneratedinsamewaywithcommands:
rtgenmd5loweralpha-numeric1713800335544320
rtgenmd5loweralpha-numeric1723800335544320
rtgenmd5loweralpha-numeric1733800335544320
rtgenmd5loweralpha-numeric1743800335544320
rtgenmd5loweralpha-numeric1753800335544320
Finally,thesefilesaregenerated:
md5_loweralpha-numeric#1-7_0_3800x33554432_0.rt
512MB
md5_loweralpha-numeric#1-7_1_3800x33554432_0.rt
512MB
md5_loweralpha-numeric#1-7_2_3800x33554432_0.rt
512MB
md5_loweralpha-numeric#1-7_3_3800x33554432_0.rt
512MB
md5_loweralpha-numeric#1-7_4_3800x33554432_0.rt
512MB
md5_loweralpha-numeric#1-7_5_3800x33554432_0.rt
512MB
Nowtherainbowtablegenerationprocesscomplete.
Step2:Usertsortprogramtosortrainbowtables
Therainbowtablesgeneratedbyrtgenprogramneedsomepostprocessingtomaketablelookupeasier.Thertsortprogramisusedtosortthe"endpoint"ofallrainbowchainsinarainbowtable.
Usefollowingcommands:
rtsortmd5_loweralpha-numeric#1-7_0_3800x33554432_0.rt
rtsortmd5_loweralpha-numeric#1-7_1_3800x33554432_0.rt
rtsortmd5_loweralpha-numeric#1-7_2_3800x33554432_0.rt
rtsortmd5_loweralpha-numeric#1-7_3_3800x33554432_0.rt
rtsortmd5_loweralpha-numeric#1-7_4_3800x33554432_0.rt
rtsortmd5_loweralpha-numeric#1-7_5_3800x33554432_0.rt
Eachcommandabovetakesabout1to2minutestocomplete.Thertsortprogramwillwritethesortedrainbowtabletotheoriginalfile.
Don'tinterruptthertsortprogram;otherwisetherainbowtablebeingsortedwillbedamaged.
Ifthefreememorysizeofyoursystemissmallerthanthesizeoftherainbowtablebeingsorted,temporaryharddiskspaceaslargeastherainbowtablesizewillbeneededtostoreintermediatedata.
Nowtherainbowtablesortingprocesscomplete.
Step3:Usercrackprogramtolookuprainbowtables
Thercrackprogramisusedtolookuptherainbowtables.Itonlyacceptssortedrainbowtables.
Assumethesortedrainbowtablesareplacedinc:\rtdirectory,tocracksinglehashthecommandlinewillbe:
rcrackc:\rt\*.rt-hyour_hash_comes_here
Thefirstparameterspecifiesthepathtotherainbowtablestolookup.The"*"and"?"charactercanbeusedtospecifymultiplefiles.
Normallyittakessecondsortensofsecondstofinish,iftheplaintextiswithintheselectedcharsetandplaintextlengthrange.Otherwise,ittakesmuchlongertimetosearchallthetablesonlytofindnothing.
Tocrackmultiplehashes,placeallthehashesinatextfilewitheachhashinaline.Andthenspecifyfilenameinrcrackcommandline:
rcrackc:\rt\*.rt-lhash_list_file
Iftherainbowtablesyougenerateuselmalgorithm,thercrackp
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業(yè)或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025-2030消費級機器人產品定義與消費者支付意愿調研報告
- 2025-2030消費級無人機市場發(fā)展趨勢與投資風險評估報告
- 2025-2030消費級AR眼鏡光學方案對比與元宇宙入口設備競爭格局報告
- 2025-2030消費電子產品迭代升級外觀設計質量問題噪聲干擾測試研究分析報告
- 2025-2030消毒濕巾pH值工廠內自檢流程及菌群存活率跟蹤研究分析項目
- 2025-2030浙江數(shù)字經濟創(chuàng)新行業(yè)市場現(xiàn)狀供需分析及投資評估規(guī)劃分析研究報告
- 2025-2030洗衣機租賃商業(yè)模式可行性及市場培育研究報告
- 固廢處理工程師資源化利用方案考核試卷
- 生產現(xiàn)場安全風險動態(tài)管理方案
- 2026年初中物理實驗報告評價試卷
- 光纖激光打標機說明書
- 勞動者個人職業(yè)健康監(jiān)護檔案
- 《兩角和與差的正弦、余弦、正切公式》示范公開課教學PPT課件【高中數(shù)學人教版】
- 治理現(xiàn)代化下的高校合同管理
- 境外宗教滲透與云南邊疆民族地區(qū)意識形態(tài)安全研究
- GB/T 28920-2012教學實驗用危險固體、液體的使用與保管
- GB/T 26389-2011衡器產品型號編制方法
- GB/T 16588-2009帶傳動工業(yè)用多楔帶與帶輪PH、PJ、PK、PL和PM型:尺寸
- 人大企業(yè)經濟學考研真題-802經濟學綜合歷年真題重點
- 建筑抗震鑒定標準課件
- 人教版二年級數(shù)學下冊《【全冊】完整版》優(yōu)質課件
評論
0/150
提交評論