Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /* Changelog
- * Version 1.00
- * Initial version
- * Version 1.01
- * Speeded up approximately 500 times.
- * Now instead of writing all passwords from dictionary and their hashes to result file
- * e.g
- * "Parole: password Hash: 5e884898da280410e88a656f8dc6292773603d0d6aabbdd625jd72nhkd1542d
- * Writes just the user name and password of user, whose password has been found.
- * e.g
- * User: [creeperdaddy] Pass: [123456]
- * Added status, shows amount of SHA256 operations, updates every tenth thousand operation.
- * Added Command line options -u [file with user name:salt:sha256] -p [dictionary] -r [result file]
- * Points out the problem, if no input files given.
- *
- *
- * Pass finder for SHA256(SHA256(password)+salt))
- * Input
- * SHATEST.exe -u dbdump.txt -p twitter-banned.txt -r twitter-banned.txt.res
- * 1. File containing Username:Salt:SHA256 of password
- * e.g creeperdaddy:633d06d3d95c64ac:349b5849410e88a67ce4fbd938b9e6f8ba53bd9a5167d9787cbfa2eeb520a1d1
- * 2. Dictionary
- * e.g twitter-banned.txt
- * 3. Output file
- *
- * FIPS-180-2 compliant SHA-256 implementation
- *
- * Copyright (C) 2001-2003 Christophe Devine
- *
- * This program is free software; you can redistribute it and/or modify
- * it under the terms of the GNU General Public License as published by
- * the Free Software Foundation; either version 2 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU General Public License for more details.
- *
- * You should have received a copy of the GNU General Public License
- * along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
- */
- #include <string.h>
- #include <unistd.h>
- #include <sys/types.h>
- #include <sys/stat.h>
- #include "sha256.h"
- #define GET_UINT32(n,b,i) \
- { \
- (n) = ( (uint32) (b)[(i) ] << 24 ) \
- | ( (uint32) (b)[(i) + 1] << 16 ) \
- | ( (uint32) (b)[(i) + 2] << 8 ) \
- | ( (uint32) (b)[(i) + 3] ); \
- }
- #define PUT_UINT32(n,b,i) \
- { \
- (b)[(i) ] = (uint8) ( (n) >> 24 ); \
- (b)[(i) + 1] = (uint8) ( (n) >> 16 ); \
- (b)[(i) + 2] = (uint8) ( (n) >> 8 ); \
- (b)[(i) + 3] = (uint8) ( (n) ); \
- }
- void sha256_starts( sha256_context *ctx )
- {
- ctx->total[0] = 0;
- ctx->total[1] = 0;
- ctx->state[0] = 0x6A09E667;
- ctx->state[1] = 0xBB67AE85;
- ctx->state[2] = 0x3C6EF372;
- ctx->state[3] = 0xA54FF53A;
- ctx->state[4] = 0x510E527F;
- ctx->state[5] = 0x9B05688C;
- ctx->state[6] = 0x1F83D9AB;
- ctx->state[7] = 0x5BE0CD19;
- }
- void sha256_process( sha256_context *ctx, uint8 data[64] )
- {
- uint32 temp1, temp2, W[64];
- uint32 A, B, C, D, E, F, G, H;
- GET_UINT32( W[0], data, 0 );
- GET_UINT32( W[1], data, 4 );
- GET_UINT32( W[2], data, 8 );
- GET_UINT32( W[3], data, 12 );
- GET_UINT32( W[4], data, 16 );
- GET_UINT32( W[5], data, 20 );
- GET_UINT32( W[6], data, 24 );
- GET_UINT32( W[7], data, 28 );
- GET_UINT32( W[8], data, 32 );
- GET_UINT32( W[9], data, 36 );
- GET_UINT32( W[10], data, 40 );
- GET_UINT32( W[11], data, 44 );
- GET_UINT32( W[12], data, 48 );
- GET_UINT32( W[13], data, 52 );
- GET_UINT32( W[14], data, 56 );
- GET_UINT32( W[15], data, 60 );
- #define SHR(x,n) ((x & 0xFFFFFFFF) >> n)
- #define ROTR(x,n) (SHR(x,n) | (x << (32 - n)))
- #define S0(x) (ROTR(x, 7) ^ ROTR(x,18) ^ SHR(x, 3))
- #define S1(x) (ROTR(x,17) ^ ROTR(x,19) ^ SHR(x,10))
- #define S2(x) (ROTR(x, 2) ^ ROTR(x,13) ^ ROTR(x,22))
- #define S3(x) (ROTR(x, 6) ^ ROTR(x,11) ^ ROTR(x,25))
- #define F0(x,y,z) ((x & y) | (z & (x | y)))
- #define F1(x,y,z) (z ^ (x & (y ^ z)))
- #define R(t) \
- ( \
- W[t] = S1(W[t - 2]) + W[t - 7] + \
- S0(W[t - 15]) + W[t - 16] \
- )
- #define P(a,b,c,d,e,f,g,h,x,K) \
- { \
- temp1 = h + S3(e) + F1(e,f,g) + K + x; \
- temp2 = S2(a) + F0(a,b,c); \
- d += temp1; h = temp1 + temp2; \
- }
- A = ctx->state[0];
- B = ctx->state[1];
- C = ctx->state[2];
- D = ctx->state[3];
- E = ctx->state[4];
- F = ctx->state[5];
- G = ctx->state[6];
- H = ctx->state[7];
- P( A, B, C, D, E, F, G, H, W[ 0], 0x428A2F98 );
- P( H, A, B, C, D, E, F, G, W[ 1], 0x71374491 );
- P( G, H, A, B, C, D, E, F, W[ 2], 0xB5C0FBCF );
- P( F, G, H, A, B, C, D, E, W[ 3], 0xE9B5DBA5 );
- P( E, F, G, H, A, B, C, D, W[ 4], 0x3956C25B );
- P( D, E, F, G, H, A, B, C, W[ 5], 0x59F111F1 );
- P( C, D, E, F, G, H, A, B, W[ 6], 0x923F82A4 );
- P( B, C, D, E, F, G, H, A, W[ 7], 0xAB1C5ED5 );
- P( A, B, C, D, E, F, G, H, W[ 8], 0xD807AA98 );
- P( H, A, B, C, D, E, F, G, W[ 9], 0x12835B01 );
- P( G, H, A, B, C, D, E, F, W[10], 0x243185BE );
- P( F, G, H, A, B, C, D, E, W[11], 0x550C7DC3 );
- P( E, F, G, H, A, B, C, D, W[12], 0x72BE5D74 );
- P( D, E, F, G, H, A, B, C, W[13], 0x80DEB1FE );
- P( C, D, E, F, G, H, A, B, W[14], 0x9BDC06A7 );
- P( B, C, D, E, F, G, H, A, W[15], 0xC19BF174 );
- P( A, B, C, D, E, F, G, H, R(16), 0xE49B69C1 );
- P( H, A, B, C, D, E, F, G, R(17), 0xEFBE4786 );
- P( G, H, A, B, C, D, E, F, R(18), 0x0FC19DC6 );
- P( F, G, H, A, B, C, D, E, R(19), 0x240CA1CC );
- P( E, F, G, H, A, B, C, D, R(20), 0x2DE92C6F );
- P( D, E, F, G, H, A, B, C, R(21), 0x4A7484AA );
- P( C, D, E, F, G, H, A, B, R(22), 0x5CB0A9DC );
- P( B, C, D, E, F, G, H, A, R(23), 0x76F988DA );
- P( A, B, C, D, E, F, G, H, R(24), 0x983E5152 );
- P( H, A, B, C, D, E, F, G, R(25), 0xA831C66D );
- P( G, H, A, B, C, D, E, F, R(26), 0xB00327C8 );
- P( F, G, H, A, B, C, D, E, R(27), 0xBF597FC7 );
- P( E, F, G, H, A, B, C, D, R(28), 0xC6E00BF3 );
- P( D, E, F, G, H, A, B, C, R(29), 0xD5A79147 );
- P( C, D, E, F, G, H, A, B, R(30), 0x06CA6351 );
- P( B, C, D, E, F, G, H, A, R(31), 0x14292967 );
- P( A, B, C, D, E, F, G, H, R(32), 0x27B70A85 );
- P( H, A, B, C, D, E, F, G, R(33), 0x2E1B2138 );
- P( G, H, A, B, C, D, E, F, R(34), 0x4D2C6DFC );
- P( F, G, H, A, B, C, D, E, R(35), 0x53380D13 );
- P( E, F, G, H, A, B, C, D, R(36), 0x650A7354 );
- P( D, E, F, G, H, A, B, C, R(37), 0x766A0ABB );
- P( C, D, E, F, G, H, A, B, R(38), 0x81C2C92E );
- P( B, C, D, E, F, G, H, A, R(39), 0x92722C85 );
- P( A, B, C, D, E, F, G, H, R(40), 0xA2BFE8A1 );
- P( H, A, B, C, D, E, F, G, R(41), 0xA81A664B );
- P( G, H, A, B, C, D, E, F, R(42), 0xC24B8B70 );
- P( F, G, H, A, B, C, D, E, R(43), 0xC76C51A3 );
- P( E, F, G, H, A, B, C, D, R(44), 0xD192E819 );
- P( D, E, F, G, H, A, B, C, R(45), 0xD6990624 );
- P( C, D, E, F, G, H, A, B, R(46), 0xF40E3585 );
- P( B, C, D, E, F, G, H, A, R(47), 0x106AA070 );
- P( A, B, C, D, E, F, G, H, R(48), 0x19A4C116 );
- P( H, A, B, C, D, E, F, G, R(49), 0x1E376C08 );
- P( G, H, A, B, C, D, E, F, R(50), 0x2748774C );
- P( F, G, H, A, B, C, D, E, R(51), 0x34B0BCB5 );
- P( E, F, G, H, A, B, C, D, R(52), 0x391C0CB3 );
- P( D, E, F, G, H, A, B, C, R(53), 0x4ED8AA4A );
- P( C, D, E, F, G, H, A, B, R(54), 0x5B9CCA4F );
- P( B, C, D, E, F, G, H, A, R(55), 0x682E6FF3 );
- P( A, B, C, D, E, F, G, H, R(56), 0x748F82EE );
- P( H, A, B, C, D, E, F, G, R(57), 0x78A5636F );
- P( G, H, A, B, C, D, E, F, R(58), 0x84C87814 );
- P( F, G, H, A, B, C, D, E, R(59), 0x8CC70208 );
- P( E, F, G, H, A, B, C, D, R(60), 0x90BEFFFA );
- P( D, E, F, G, H, A, B, C, R(61), 0xA4506CEB );
- P( C, D, E, F, G, H, A, B, R(62), 0xBEF9A3F7 );
- P( B, C, D, E, F, G, H, A, R(63), 0xC67178F2 );
- ctx->state[0] += A;
- ctx->state[1] += B;
- ctx->state[2] += C;
- ctx->state[3] += D;
- ctx->state[4] += E;
- ctx->state[5] += F;
- ctx->state[6] += G;
- ctx->state[7] += H;
- }
- void sha256_update( sha256_context *ctx, uint8 *input, uint32 length )
- {
- uint32 left, fill;
- if( ! length ) return;
- left = ctx->total[0] & 0x3F;
- fill = 64 - left;
- ctx->total[0] += length;
- ctx->total[0] &= 0xFFFFFFFF;
- if( ctx->total[0] < length )
- ctx->total[1]++;
- if( left && length >= fill )
- {
- memcpy( (void *) (ctx->buffer + left),
- (void *) input, fill );
- sha256_process( ctx, ctx->buffer );
- length -= fill;
- input += fill;
- left = 0;
- }
- while( length >= 64 )
- {
- sha256_process( ctx, input );
- length -= 64;
- input += 64;
- }
- if( length )
- {
- memcpy( (void *) (ctx->buffer + left),
- (void *) input, length );
- }
- }
- static uint8 sha256_padding[64] =
- {
- 0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
- 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
- 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
- 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0
- };
- void sha256_finish( sha256_context *ctx, uint8 digest[32] )
- {
- uint32 last, padn;
- uint32 high, low;
- uint8 msglen[8];
- high = ( ctx->total[0] >> 29 )
- | ( ctx->total[1] << 3 );
- low = ( ctx->total[0] << 3 );
- PUT_UINT32( high, msglen, 0 );
- PUT_UINT32( low, msglen, 4 );
- last = ctx->total[0] & 0x3F;
- padn = ( last < 56 ) ? ( 56 - last ) : ( 120 - last );
- sha256_update( ctx, sha256_padding, padn );
- sha256_update( ctx, msglen, 8 );
- PUT_UINT32( ctx->state[0], digest, 0 );
- PUT_UINT32( ctx->state[1], digest, 4 );
- PUT_UINT32( ctx->state[2], digest, 8 );
- PUT_UINT32( ctx->state[3], digest, 12 );
- PUT_UINT32( ctx->state[4], digest, 16 );
- PUT_UINT32( ctx->state[5], digest, 20 );
- PUT_UINT32( ctx->state[6], digest, 24 );
- PUT_UINT32( ctx->state[7], digest, 28 );
- }
- #include <stdlib.h>
- #include <stdio.h>
- /*
- * those are the standard FIPS-180-2 test vectors
- */
- /*
- static char *msg[] =
- {
- "abc",
- "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq",
- NULL
- };
- static char *val[] =
- {
- "ba7816bf8f01cfea414140de5dae2223" \
- "b00361a396177a9cb410ff61f20015ad",
- "248d6a61d20638b8e5c026930c3e6039" \
- "a33ce45964ff2167f6ecedd419db06c1",
- "cdc76e5c9914fb9281a1c7e284d73e67" \
- "f1809a48a497200e046d39ccc7112cd0"
- };
- */
- typedef struct ufilest {
- char* uname;
- char* seed;
- char* hash;
- unsigned char sha256[32];
- struct ufilest *next;
- } ufilest;
- typedef struct pfilest {
- char* pass;
- char* hash;
- struct pfilest *next;
- } pfilest;
- unsigned char ctox(char c){
- unsigned char rc = 0;
- if( c >= '0' && c <= '9' ) rc = c - '0';
- else if (c >= 'A' && c <= 'F') rc = c - 'A' + 10;
- else if (c >= 'a' && c <= 'f') rc = c - 'a' + 10;
- return rc;
- }
- unsigned char stox(char *s, unsigned char (*t)[32]){
- int i;
- for( i=0; i<32; i++)
- (*t)[i] = ctox(*(s+i*2))<<4 | ctox(*(s+i*2+1));
- return 0;
- }
- int insert_u(char * buffer, struct ufilest ** cu, struct ufilest ** pu, char divider ){
- char tmp[1000];
- char *pt,*pb;
- size_t msize;
- msize = sizeof(struct ufilest);
- *cu = (struct ufilest *)malloc(msize);
- if ( ! *cu ) {
- perror("Malloc error for user file");
- // Delete structure
- return(255);
- }
- pb = buffer;
- pt = &tmp[0];
- while( *pb && *pb != divider ) *(pt++) = *(pb++); *pt = '\0'; pb++;
- msize = (strlen(tmp)+1)*sizeof(char);
- (*cu)->uname = (char *) malloc(msize);
- strcpy((*cu)->uname,tmp);
- pt = &tmp[0];
- while( *pb && *pb != divider ) *(pt++) = *(pb++); *pt = '\0'; pb++;
- msize = (strlen(tmp)+1)*sizeof(char);
- (*cu)->seed = (char *) malloc(msize);
- strcpy((*cu)->seed,tmp);
- pt = &tmp[0];
- while( *pb && *pb != divider ) *(pt++) = *(pb++); *pt = '\0'; pb++;
- msize = (strlen(tmp)+1)*sizeof(char);
- (*cu)->hash = (char *) malloc(msize);
- strcpy((*cu)->hash,tmp);
- stox(tmp,&((*cu)->sha256));
- (*cu)->next = NULL;
- if( (*pu) ) (*pu)->next = *cu;
- return 0;
- }
- int insert_p(char * buffer, struct pfilest ** cp, struct pfilest ** pp ){
- int i;
- char tmp[1000];
- char *pt,*pb;
- size_t msize;
- sha256_context ct2;
- unsigned char sha256[32];
- msize = sizeof(struct pfilest);
- *cp = (struct pfilest *)malloc(msize);
- if ( ! *cp ) {
- perror("Malloc error for user file");
- // Delete structure
- return(255);
- }
- pb = buffer;
- pt = &tmp[0];
- while( *pb ) *(pt++) = *(pb++); *pt = '\0'; pb++;
- msize = (strlen(tmp)+1)*sizeof(char);
- (*cp)->pass = (char *) malloc(msize);
- strcpy((*cp)->pass,tmp);
- sha256_starts( &ct2 );
- sha256_update( &ct2, (uint8 *) buffer, strlen(buffer) );
- sha256_finish( &ct2, sha256 );
- msize = 65*sizeof(char);
- (*cp)->hash = (char *) malloc(msize);
- for( i = 0; i < 32; i++ ) sprintf( (*cp)->hash + i * 2, "%02x", sha256[i] );
- *((*cp)->hash + 65) = '\0';
- (*cp)->next = NULL;
- if( (*pp) ) (*pp)->next = *cp;
- return 0;
- }
- void myprint(int redir, FILE * fu, char * buffer){
- if( redir ) {
- fprintf(fu,buffer);
- } else {
- fprintf(stdout,buffer);
- }
- }
- int main( int argc, char *argv[] )
- {
- FILE *fu;
- int i, j, c;
- char output[255];
- sha256_context ctx;
- unsigned char buf[1000];
- unsigned char sha256sum[32];
- unsigned long cnt2;
- char inputline[1000];
- char separator = ':';
- struct ufilest *cu = NULL, *pu = NULL, *su = NULL;
- struct pfilest *cp = NULL, *pp = NULL, *sp = NULL;
- int digit_optind = 0;
- char *ropt = 0, *popt = 0, *uopt = 0;
- int this_option_optind;
- while ( (c = getopt(argc, argv, "p:P:u:U:r:R:")) != -1) {
- this_option_optind = optind ? optind : 1;
- switch (c) {
- case 'p':
- case 'P':
- popt = optarg;
- break;
- case 'r':
- case 'R':
- ropt = optarg;
- break;
- case 'u':
- case 'U':
- uopt = optarg;
- break;
- case '?':
- printf("Usage: %s -u userfile -p passfile [-r resultfile]\n\tPass finder for sha256(sha256(pass)+seed))\n\tDefault output to stdout (if -r not specified)",argv[0]);
- return(0);
- break;
- default:
- printf ("?? getopt returned character code 0x%x ??\n", c);
- }
- }
- if( argc < 3 ){
- printf("Usage: %s -u userfile -p passfile [-r resultfile]\n\tPass finder for sha256(sha256(pass)+seed))\n\tDefault output to stdout (if -r not specified)",argv[0]);
- exit(EXIT_FAILURE);
- }
- if ( access(popt,R_OK) ) { printf("RO access password file %s - denied of file doesn\'t exist\n",popt); exit(EXIT_FAILURE); }
- if ( access(uopt,R_OK) ) { printf("RO access user file %s - denied of file doesn\'t exist\n",uopt); exit(EXIT_FAILURE); }
- if( ! (fu = fopen(uopt,"rt")) ){ perror("Can\'t open user file\n"); exit(EXIT_FAILURE); }
- while (fgets(inputline, 1000, fu) != NULL) {
- i = strlen(inputline)-1;
- while( i && ( inputline[i] == '\n' || inputline[i] == '\r' ) ) inputline[i--] = '\0';
- i = 0;
- pu = cu;
- insert_u(inputline,&cu,&pu,separator);
- if( ! su ) su = cu;
- }
- fclose(fu);
- printf("************ User list\n");
- // cu = su;
- // while( cu ) {
- // printf("User: %s Seed: %s Hash %s Hash2 %02x %02x\n",cu->uname,cu->seed,cu->hash,cu->sha256[0], cu->sha256[1]);
- // cu = cu->next;
- // }
- if( ! (fu = fopen(popt,"rt")) ){ perror("Can\'t open password file\n"); exit(EXIT_FAILURE); }
- while (fgets(inputline, 1000, fu) != NULL) {
- i = strlen(inputline)-1;
- while( i && ( inputline[i] == '\n' || inputline[i] == '\r' ) ) inputline[i--] = '\0';
- i = 0;
- pp = cp;
- insert_p(inputline,&cp,&pp);
- if( ! sp ) sp = cp;
- }
- fclose(fu); fu = NULL;
- printf("************ Pass list\n");
- // cp = sp;
- // while( cp ) {
- // printf("Pass: %s Hash %s\n",cp->pass,cp->hash);
- // cp = cp->next;
- // }
- if( ropt ){
- if( ! (fu = fopen(ropt,"w")) ) { perror("Can\'t open result file\n"); exit(EXIT_FAILURE); }
- }
- c = fu ? 1 : 0;
- myprint(c,fu,"Start\n");
- cnt2 = 0;
- cp = sp;
- while( cp ){
- cu = su;
- while( cu ){
- strcpy(buf,cp->hash);
- strcat(buf,cu->seed);
- sha256_starts( &ctx );
- sha256_update( &ctx, (uint8 *) buf, strlen(buf) );
- sha256_finish( &ctx, sha256sum );
- if( (++cnt2 % 10000) == 0 ) printf("%lu\r",cnt2);
- j = 1;
- for( i = 0; i < 32; i++ )
- if( cu->sha256[i] != sha256sum[i] ) {
- j = 0; break;
- }
- if( j ){
- sprintf(output,"User: [%s] Pass: [%s]\n",cu->uname,cp->pass);
- myprint(c,fu,output);
- }
- cu = cu->next;
- }
- cp = cp->next;
- }
- cp = sp;
- while( cp ){
- pp = cp;
- cp = cp->next;
- free(pp->hash);
- free(pp->pass);
- free(pp);
- }
- cu = su;
- while( cu ){
- pu = cu;
- cu = cu->next;
- free(pu->hash);
- free(pu->seed);
- free(pu->uname);
- free(pu);
- }
- if( c )fclose(fu);
- system("PAUSE");
- return( 0 );
- }
Advertisement
Add Comment
Please, Sign In to add comment