Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

How to crack LDAP hash passwordQ


ghost's Avatar
0 0

Hello world, i need some help, in order to crack some ldap hash password. It's looks like this:(ex) userPassword: {MD5}B+3g3KTTk2oUQCQT6JqsCQ== I think it's a md5 hash encrypted (but i dunno the type of encryption). It doesn't looks like to be MD5 hash. Do you know which algorythm is used in this hash, and how i could crack it? Thanks.


ghost's Avatar
0 0

Clelye wrote: Hello world, i need some help, in order to crack some ldap hash password. It's looks like this:(ex) userPassword: {MD5}B+3g3KTTk2oUQCQT6JqsCQ== I think it's a md5 hash encrypted (but i dunno the type of encryption). It doesn't looks like to be MD5 hash. Do you know which algorythm is used in this hash, and how i could crack it? Thanks.

It's obviously not MD5… at least, not in that form. Here's some reading material for you:

http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol http://www.skills-1st.co.uk/papers/security-with-ldap-jan-2002/security-with-ldap.html

The key thing to recognize is how LDAP functions. Also, you can look at the hash and notice the one distinguishing feature to figure out what it is… As a hint, it's not "encryption".

As for how to crack it… Google is your friend.


ghost's Avatar
0 0

looks like base 64 to me… maybe b64'd md5?


spyware's Avatar
Banned
0 0

mr noob wrote: looks like base 64 to me… maybe b64'd md5?

iTs+nOtbASe64==


ghost's Avatar
0 0

lol ^^ i just made that presumption because it looks like it.


spyware's Avatar
Banned
0 0

mr noob wrote: lol ^^ i just made that presumption because it looks like it.

My point exactly ;).