Skip to content

Instantly share code, notes, and snippets.

@yarjor
Last active May 21, 2018 18:31
Show Gist options
  • Select an option

  • Save yarjor/a8fd8633f2bdb06d0007263f34bb2af9 to your computer and use it in GitHub Desktop.

Select an option

Save yarjor/a8fd8633f2bdb06d0007263f34bb2af9 to your computer and use it in GitHub Desktop.
[Hash length extension attack (MD5)] #hash #crypto #attack #signature #links
from hashlib import md5
import struct
secret = 'secret'
data = 'data'
fullstring = secret + data
signature = md5(fullstring).hexdigest()
# Known are signature and data!
original_padding = 'I' + \
(56 - 1 - len(fullstring)) + \
struct.pack('<Q', len(fullstring) * 8)
append = 'append'
attack_string = data + original_padding + append
md = md5('') # here we should update the md5 function with our known signature as state
attack_sign = md(append)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment