Guest User

md5

a guest
Dec 3rd, 2013
92
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
C 8.88 KB | None | 0 0
  1. /* MD5:BRUTE_FORCE_ATTACK 2013-12-03 v1.0                *
  2.  * file:main.c                                           *
  3.  * Compile:gcc -o MD5Crack main.c                        *
  4.  * gcc(1):http://gcc.gnu.org/releases.html               *
  5.  * gcc(2):http://www.bloodshed.net/download.html         *
  6.  * MD5 generator:http://www.adamek.biz/md5-generator.php *
  7.  * Credits:w2ch.org-Anon                                 */
  8.  
  9.  
  10. #define MD5_LENGTH_BYTES 16 //(128 bits/8 bits)= 16 (bytes)
  11. #define EXIT_FAILURE 13 //ERROR_INVALID_DATA http://msdn.microsoft.com/en-us/library/ms681382.aspx
  12. #include <stdio.h>
  13.  
  14.  
  15. /* --------------------------------------------------------------------------------------------------------- */
  16. /* INFO:I did not write this and I lost where I found it. No credit goes to me here I only did main function */
  17. #include <stdlib.h>
  18. #include <string.h>
  19. #include <stdint.h>
  20.  
  21. // Constants are the integer part of the sines of integers (in radians) * 2^32.
  22. const uint32_t k[64] = {
  23. 0xd76aa478, 0xe8c7b756, 0x242070db, 0xc1bdceee ,
  24. 0xf57c0faf, 0x4787c62a, 0xa8304613, 0xfd469501 ,
  25. 0x698098d8, 0x8b44f7af, 0xffff5bb1, 0x895cd7be ,
  26. 0x6b901122, 0xfd987193, 0xa679438e, 0x49b40821 ,
  27. 0xf61e2562, 0xc040b340, 0x265e5a51, 0xe9b6c7aa ,
  28. 0xd62f105d, 0x02441453, 0xd8a1e681, 0xe7d3fbc8 ,
  29. 0x21e1cde6, 0xc33707d6, 0xf4d50d87, 0x455a14ed ,
  30. 0xa9e3e905, 0xfcefa3f8, 0x676f02d9, 0x8d2a4c8a ,
  31. 0xfffa3942, 0x8771f681, 0x6d9d6122, 0xfde5380c ,
  32. 0xa4beea44, 0x4bdecfa9, 0xf6bb4b60, 0xbebfbc70 ,
  33. 0x289b7ec6, 0xeaa127fa, 0xd4ef3085, 0x04881d05 ,
  34. 0xd9d4d039, 0xe6db99e5, 0x1fa27cf8, 0xc4ac5665 ,
  35. 0xf4292244, 0x432aff97, 0xab9423a7, 0xfc93a039 ,
  36. 0x655b59c3, 0x8f0ccc92, 0xffeff47d, 0x85845dd1 ,
  37. 0x6fa87e4f, 0xfe2ce6e0, 0xa3014314, 0x4e0811a1 ,
  38. 0xf7537e82, 0xbd3af235, 0x2ad7d2bb, 0xeb86d391 };
  39.  
  40. // r specifies the per-round shift amounts
  41. const uint32_t r[] = {7, 12, 17, 22, 7, 12, 17, 22, 7, 12, 17, 22, 7, 12, 17, 22,
  42.                       5,  9, 14, 20, 5,  9, 14, 20, 5,  9, 14, 20, 5,  9, 14, 20,
  43.                       4, 11, 16, 23, 4, 11, 16, 23, 4, 11, 16, 23, 4, 11, 16, 23,
  44.                       6, 10, 15, 21, 6, 10, 15, 21, 6, 10, 15, 21, 6, 10, 15, 21};
  45.  
  46. // leftrotate function definition
  47. #define LEFTROTATE(x, c) (((x) << (c)) | ((x) >> (32 - (c))))
  48.  
  49. void to_bytes(uint32_t val, uint8_t *bytes)
  50. {
  51.     bytes[0] = (uint8_t) val;
  52.     bytes[1] = (uint8_t) (val >> 8);
  53.     bytes[2] = (uint8_t) (val >> 16);
  54.     bytes[3] = (uint8_t) (val >> 24);
  55. }
  56.  
  57. uint32_t to_int32(uint8_t *bytes)
  58. {
  59.     return (uint32_t) bytes[0]
  60.         | ((uint32_t) bytes[1] << 8)
  61.         | ((uint32_t) bytes[2] << 16)
  62.         | ((uint32_t) bytes[3] << 24);
  63. }
  64.  
  65. void md5(const uint8_t *initial_msg, size_t initial_len, uint8_t *digest) {
  66.  
  67.     // These vars will contain the hash
  68.     uint32_t h0, h1, h2, h3;
  69.  
  70.     // Message (to prepare)
  71.     uint8_t *msg = NULL;
  72.  
  73.     size_t new_len, offset;
  74.     uint32_t w[16];
  75.     uint32_t a, b, c, d, i, f, g, temp;
  76.  
  77.     // Initialize variables - simple count in nibbles:
  78.     h0 = 0x67452301;
  79.     h1 = 0xefcdab89;
  80.     h2 = 0x98badcfe;
  81.     h3 = 0x10325476;
  82.  
  83.     //Pre-processing:
  84.     //append "1" bit to message    
  85.     //append "0" bits until message length in bits = 448 (mod 512)
  86.     //append length mod (2^64) to message
  87.  
  88.     for (new_len = initial_len + 1; new_len % (512/8) != 448/8; new_len++)
  89.         ;
  90.  
  91.     msg = (uint8_t*)malloc(new_len + 8);
  92.     memcpy(msg, initial_msg, initial_len);
  93.     msg[initial_len] = 0x80; // append the "1" bit; most significant bit is "first"
  94.     for (offset = initial_len + 1; offset < new_len; offset++)
  95.         msg[offset] = 0; // append "0" bits
  96.  
  97.     // append the len in bits at the end of the buffer.
  98.     to_bytes(initial_len*8, msg + new_len);
  99.     // initial_len>>29 == initial_len*8>>32, but avoids overflow.
  100.     to_bytes(initial_len>>29, msg + new_len + 4);
  101.  
  102.     // Process the message in successive 512-bit chunks:
  103.     //for each 512-bit chunk of message:
  104.     for(offset=0; offset<new_len; offset += (512/8)) {
  105.  
  106.         // break chunk into sixteen 32-bit words w[j], 0 = j = 15
  107.         for (i = 0; i < 16; i++)
  108.             w[i] = to_int32(msg + offset + i*4);
  109.  
  110.         // Initialize hash value for this chunk:
  111.         a = h0;
  112.         b = h1;
  113.         c = h2;
  114.         d = h3;
  115.  
  116.         // Main loop:
  117.         for(i = 0; i<64; i++) {
  118.  
  119.             if (i < 16) {
  120.                 f = (b & c) | ((~b) & d);
  121.                 g = i;
  122.             } else if (i < 32) {
  123.                 f = (d & b) | ((~d) & c);
  124.                 g = (5*i + 1) % 16;
  125.             } else if (i < 48) {
  126.                 f = b ^ c ^ d;
  127.                 g = (3*i + 5) % 16;          
  128.             } else {
  129.                 f = c ^ (b | (~d));
  130.                 g = (7*i) % 16;
  131.             }
  132.  
  133.             temp = d;
  134.             d = c;
  135.             c = b;
  136.             b = b + LEFTROTATE((a + f + k[i] + w[g]), r[i]);
  137.             a = temp;
  138.  
  139.         }
  140.  
  141.         // Add this chunk's hash to result so far:
  142.         h0 += a;
  143.         h1 += b;
  144.         h2 += c;
  145.         h3 += d;
  146.  
  147.     }
  148.  
  149.     // cleanup
  150.     free(msg);
  151.  
  152.     //var char digest[16] := h0 append h1 append h2 append h3 //(Output is in little-endian)
  153.     to_bytes(h0, digest);
  154.     to_bytes(h1, digest + 4);
  155.     to_bytes(h2, digest + 8);
  156.     to_bytes(h3, digest + 12);
  157. }
  158.  
  159. /* --------------------------------------------------------------------------------------------------------- */
  160.  
  161.  
  162. int main(int argc, char** argv)
  163. {
  164.     unsigned char strFindKeyTo[MD5_LENGTH_BYTES],
  165.                   strKey[MD5_LENGTH_BYTES] = {0},
  166.                   strHash[MD5_LENGTH_BYTES],
  167.                   c, cMaxKeyNumber;
  168.    
  169.    
  170.     if(argc==3);
  171.     else
  172.     {
  173.         fprintf(stdout, "INPUT ERROR!\nMD5Crack <32_CHARECTER_MD5_HASH> <0-9_MAX_NUMBER_KEY>");
  174.         return EXIT_FAILURE;
  175.     }
  176.    
  177.     //INFO:cMaxKeyNumber is used as temp value in this for loop
  178.     for(c=0, cMaxKeyNumber=0; c<31; ++c, ++cMaxKeyNumber) //NOTE0:make this smaller and more secure!
  179.     {
  180.         switch(argv[1][c])
  181.         {
  182.         case '0':
  183.         strFindKeyTo[cMaxKeyNumber]=0;
  184.         break;
  185.         case '1':
  186.         strFindKeyTo[cMaxKeyNumber]=16;
  187.         break;
  188.         case '2':
  189.         strFindKeyTo[cMaxKeyNumber]=32;
  190.         break;
  191.         case '3':
  192.         strFindKeyTo[cMaxKeyNumber]=48;
  193.         break;
  194.         case '4':
  195.         strFindKeyTo[cMaxKeyNumber]=64;
  196.         break;
  197.         case '5':
  198.         strFindKeyTo[cMaxKeyNumber]=80;
  199.         break;
  200.         case '6':
  201.         strFindKeyTo[cMaxKeyNumber]=96;
  202.         break;
  203.         case '7':
  204.         strFindKeyTo[cMaxKeyNumber]=112;
  205.         break;
  206.         case '8':
  207.         strFindKeyTo[cMaxKeyNumber]=128;
  208.         break;
  209.         case '9':
  210.         strFindKeyTo[cMaxKeyNumber]=144;
  211.         break;
  212.         case 'a':
  213.         strFindKeyTo[cMaxKeyNumber]=160;
  214.         break;
  215.         case 'b':
  216.         strFindKeyTo[cMaxKeyNumber]=176;
  217.         break;
  218.         case 'c':
  219.         strFindKeyTo[cMaxKeyNumber]=192;
  220.         break;
  221.         case 'd':
  222.         strFindKeyTo[cMaxKeyNumber]=208;
  223.         break;
  224.         case 'e':
  225.         strFindKeyTo[cMaxKeyNumber]=224;
  226.         break;
  227.         case 'f':
  228.         strFindKeyTo[cMaxKeyNumber]=240;
  229.         break;
  230.         default:
  231.         strFindKeyTo[cMaxKeyNumber]=0;
  232.         break;
  233.         }
  234.         switch(argv[1][++c])
  235.         {
  236.         case '0':
  237.         strFindKeyTo[cMaxKeyNumber]+=0;
  238.         break;
  239.         case '1':
  240.         strFindKeyTo[cMaxKeyNumber]+=1;
  241.         break;
  242.         case '2':
  243.         strFindKeyTo[cMaxKeyNumber]+=2;
  244.         break;
  245.         case '3':
  246.         strFindKeyTo[cMaxKeyNumber]+=3;
  247.         break;
  248.         case '4':
  249.         strFindKeyTo[cMaxKeyNumber]+=4;
  250.         break;
  251.         case '5':
  252.         strFindKeyTo[cMaxKeyNumber]+=5;
  253.         break;
  254.         case '6':
  255.         strFindKeyTo[cMaxKeyNumber]+=6;
  256.         break;
  257.         case '7':
  258.         strFindKeyTo[cMaxKeyNumber]+=7;
  259.         break;
  260.         case '8':
  261.         strFindKeyTo[cMaxKeyNumber]+=8;
  262.         break;
  263.         case '9':
  264.         strFindKeyTo[cMaxKeyNumber]+=9;
  265.         break;
  266.         case 'a':
  267.         strFindKeyTo[cMaxKeyNumber]+=10;
  268.         break;
  269.         case 'b':
  270.         strFindKeyTo[cMaxKeyNumber]+=11;
  271.         break;
  272.         case 'c':
  273.         strFindKeyTo[cMaxKeyNumber]+=12;
  274.         break;
  275.         case 'd':
  276.         strFindKeyTo[cMaxKeyNumber]+=13;
  277.         break;
  278.         case 'e':
  279.         strFindKeyTo[cMaxKeyNumber]+=14;
  280.         break;
  281.         case 'f':
  282.         strFindKeyTo[cMaxKeyNumber]+=15;
  283.         break;
  284.         default:
  285.         strFindKeyTo[cMaxKeyNumber]+=0;
  286.         break;
  287.         }
  288.     }
  289.    
  290.     if(c!=32)
  291.     {
  292.         fprintf(stdout, "INPUT ERROR!\n<32_CHARECTER_MD5_HASH>");
  293.         return EXIT_FAILURE;
  294.     }
  295.    
  296.     cMaxKeyNumber = argv[2][0] & 15; //Max key
  297.    
  298.    
  299.     //main loop:
  300.     fprintf(stdout, "Running!\nInput Hash:\n");
  301.     for (c=0; c<16; c++) fprintf(stdout, "%2.2x", strFindKeyTo[c]);
  302.     fprintf(stdout, "\nMax Key Value:%d\n", (int)cMaxKeyNumber);
  303.    
  304.     do{
  305.         //add one to strKey
  306.         for(c=0; strKey[c]==255; c++) strKey[c]=1;
  307.         if(c) strKey[c]+=1; else ++strKey[0];
  308.         //fprintf(stdout, "strKey[0]:%d\tstrKey[1]:%d\tstrKey[2]:%d\tstrKey[3]:%d\n", (int)strKey[0], (int)strKey[1], (int)strKey[2], (int)strKey[3]);
  309.        
  310.         //calculation MD5 Hash
  311.         md5(strKey, strlen(strKey), strHash); //NOTE:make own strlen(strKey), for fun
  312.        
  313.         //calculation if strHash==strFindKeyTo
  314.         for(c=15; strHash[c-1]==strFindKeyTo[c-1] && --c;);
  315.        
  316.     } while(strKey[cMaxKeyNumber]==0 && c); //strKey[cMaxKeyNumber]==0 makes overflow
  317.  
  318.     if(c) fprintf(stdout, "Failed!\n");
  319.     else fprintf(stdout, "Success! MD5 key:%s\n", strKey);
  320.  
  321.     return 0;
  322. }
Advertisement
Add Comment
Please, Sign In to add comment