Skip to content

Hashing & cracking

Hashes are everywhere: passwords, integrity, signatures, tokens. This card covers what guarantees they give (and which they don’t), how passwords get cracked in practice, and structural attacks like length extension and collisions.

A cryptographic hash (SHA-256, SHA-3, BLAKE2) must be:
- one-way (preimage): given h, infeasible to find m with hash(m)=h
- 2nd-preimage and COLLISION resistant: infeasible to find two distinct m with equal hash
WATCH the use:
- integrity/fingerprint -> SHA-256/SHA-3 is fine
- authenticity -> do NOT use a bare hash; use HMAC
- passwords -> do NOT use SHA/MD5; use Argon2id/bcrypt/scrypt (SLOW hash + salt)

Why “bare” SHA-256 is bad for passwords

Section titled “Why “bare” SHA-256 is bad for passwords”
SHA-256 is FAST -> a GPU tries billions/sec -> cracked by dictionary
Fix:
salt random value per user -> breaks rainbow tables and precomputed hashes
slow cost factor (Argon2/bcrypt) -> each guess costs; the GPU stops paying off
pepper global secret outside the DB (defense in depth)
# 1. IDENTIFY the hash type
hashid '$2b$12$...' # or hashcat --identify
# 2. pick the hashcat mode (-m): 0=MD5, 100=SHA1, 1400=SHA256, 3200=bcrypt, 1800=sha512crypt...
# 3. dictionary + rules
hashcat -m 0 hashes.txt rockyou.txt -r rules/best64.rule
# 4. mask (structured brute force) if the dictionary fails
hashcat -m 0 hashes.txt -a 3 '?u?l?l?l?l?d?d?d'
# John equivalent:
john --format=raw-sha256 --wordlist=rockyou.txt hashes.txt

For Windows/AD hashes (NTLM, Net-NTLMv2, Kerberos) see ad-creds and ad-kerberos.

Length extension (the flaw of “hash(secret‖message)”)

Section titled “Length extension (the flaw of “hash(secret‖message)”)”
# in Merkle-Damgard (MD5, SHA-1, SHA-256): knowing hash(secret‖msg) and len(secret),
# you can compute hash(secret‖msg‖padding‖EXTRA) WITHOUT knowing the secret
# -> breaks homemade "signature" schemes like MAC = sha256(secret + data)
# tool: hashpump / hash_extender
# FIX: use HMAC-SHA256 (not extensible) or SHA-3/BLAKE2
MD5 trivial collisions today (seconds) -> never for signatures/integrity
SHA-1 real collision: SHAttered (2017) and chosen-prefix (2019) -> deprecated
# impact: two different files with the same hash (e.g. certificates, signed binaries)
  • hashcat (GPU, the standard), John the Ripper (CPU/exotic formats).
  • hashid / name-that-hash (identification), hashpump (length extension), CyberChef.
  • Passwords: Argon2id (or bcrypt/scrypt) with a per-user salt and high cost parameters.
  • Integrity/authenticity: HMAC-SHA256 or a signature; never hash(secret‖msg).
  • Drop MD5/SHA-1 for any security use; monitor credential leaks.
  • Rate limiting and MFA so that even with stolen hashes the impact is limited.
  • SHAttered (2017): first practical SHA-1 collision (two distinct PDFs, same hash).
  • Flame (2012): malware that forged a Microsoft certificate abusing an MD5 collision.
  • Massive leaks (LinkedIn 2012: unsalted SHA-1) cracked almost entirely.
  • Identify the hash algorithm (hashid/—identify)
  • Passwords with a fast, unsalted hash? → dictionary cracking
  • Run hashcat/John with dictionary + rules, then masks
  • hash(secret‖msg) scheme? → try length extension
  • MD5/SHA-1 in signatures/integrity? → collision risk
  • Verify passwords use Argon2/bcrypt/scrypt
  • Check constant-time hash comparison