Hashing & cracking
Hashes are everywhere: passwords, integrity, signatures, tokens. This card covers what guarantees they give (and which they don’t), how passwords get cracked in practice, and structural attacks like length extension and collisions.
Properties and uses
Section titled “Properties and uses”A cryptographic hash (SHA-256, SHA-3, BLAKE2) must be:- one-way (preimage): given h, infeasible to find m with hash(m)=h- 2nd-preimage and COLLISION resistant: infeasible to find two distinct m with equal hash
WATCH the use:- integrity/fingerprint -> SHA-256/SHA-3 is fine- authenticity -> do NOT use a bare hash; use HMAC- passwords -> do NOT use SHA/MD5; use Argon2id/bcrypt/scrypt (SLOW hash + salt)Why “bare” SHA-256 is bad for passwords
Section titled “Why “bare” SHA-256 is bad for passwords”SHA-256 is FAST -> a GPU tries billions/sec -> cracked by dictionaryFix: salt random value per user -> breaks rainbow tables and precomputed hashes slow cost factor (Argon2/bcrypt) -> each guess costs; the GPU stops paying off pepper global secret outside the DB (defense in depth)Password cracking (lab)
Section titled “Password cracking (lab)”# 1. IDENTIFY the hash typehashid '$2b$12$...' # or hashcat --identify# 2. pick the hashcat mode (-m): 0=MD5, 100=SHA1, 1400=SHA256, 3200=bcrypt, 1800=sha512crypt...# 3. dictionary + ruleshashcat -m 0 hashes.txt rockyou.txt -r rules/best64.rule# 4. mask (structured brute force) if the dictionary failshashcat -m 0 hashes.txt -a 3 '?u?l?l?l?l?d?d?d'# John equivalent:john --format=raw-sha256 --wordlist=rockyou.txt hashes.txtFor Windows/AD hashes (NTLM, Net-NTLMv2, Kerberos) see ad-creds and ad-kerberos.
Length extension (the flaw of “hash(secret‖message)”)
Section titled “Length extension (the flaw of “hash(secret‖message)”)”# in Merkle-Damgard (MD5, SHA-1, SHA-256): knowing hash(secret‖msg) and len(secret),# you can compute hash(secret‖msg‖padding‖EXTRA) WITHOUT knowing the secret# -> breaks homemade "signature" schemes like MAC = sha256(secret + data)# tool: hashpump / hash_extender# FIX: use HMAC-SHA256 (not extensible) or SHA-3/BLAKE2Collisions
Section titled “Collisions”MD5 trivial collisions today (seconds) -> never for signatures/integritySHA-1 real collision: SHAttered (2017) and chosen-prefix (2019) -> deprecated# impact: two different files with the same hash (e.g. certificates, signed binaries)- hashcat (GPU, the standard), John the Ripper (CPU/exotic formats).
- hashid / name-that-hash (identification), hashpump (length extension), CyberChef.
Defense
Section titled “Defense”- Passwords: Argon2id (or bcrypt/scrypt) with a per-user salt and high cost parameters.
- Integrity/authenticity: HMAC-SHA256 or a signature; never
hash(secret‖msg). - Drop MD5/SHA-1 for any security use; monitor credential leaks.
- Rate limiting and MFA so that even with stolen hashes the impact is limited.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- SHAttered (2017): first practical SHA-1 collision (two distinct PDFs, same hash).
- Flame (2012): malware that forged a Microsoft certificate abusing an MD5 collision.
- Massive leaks (LinkedIn 2012: unsalted SHA-1) cracked almost entirely.
Testing checklist
Section titled “Testing checklist”- Identify the hash algorithm (hashid/—identify)
- Passwords with a fast, unsalted hash? → dictionary cracking
- Run hashcat/John with dictionary + rules, then masks
-
hash(secret‖msg)scheme? → try length extension - MD5/SHA-1 in signatures/integrity? → collision risk
- Verify passwords use Argon2/bcrypt/scrypt
- Check constant-time hash comparison