Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

my PHP DES dictionary cracker


ghost's Avatar
0 0

this uses no database and is coded all in php

you can check it out here http://zomgz.info/str.php

i just called it sleaztheripper because im loser:p

check it out

it encrypts and decrypts DES

if you would like i will post the source if you would like

tell me what you think

i just thought it was cool because ive never seen an online DES cracker

or any other DES cracker besides jtr really


ghost's Avatar
0 0

hey that's pretty cool! i've also searched for one before but never found anything apart from jtr can you send/post the source? i'd really like to read it =)


ghost's Avatar
0 0

sent.


ghost's Avatar
0 0

yeah, me too :D

nice site sleazoid ;)

EDIT:

send me a copy too ;)


ghost's Avatar
0 0

thanks man! :D

and ok ill send it hold on a second


ghost's Avatar
0 0

thanks for the PM;) , awesome code :o:D


ghost's Avatar
0 0

HackingForce wrote: thanks for the PM;) , awesome code :o:D

no problem man hehe thanks:happy:


ghost's Avatar
0 0

yeah dude. simple effective the way it should be =)

thanks


ghost's Avatar
0 0

try to Encrypt "fuckedup" then do "fuckedupdown"

same DES for both :p


ghost's Avatar
0 0

HackingForce wrote: try to Encrypt "fuckedup" then do "fuckedupdown"

same DES for both :p

woah hahaha wtf:right::p


ghost's Avatar
0 0

sakarin wrote: yeah dude. simple effective the way it should be =)

thanks

yep np

and its fast too

hahah

i own jtr :p

just one thing i noticed…i tried one of my really big wordlists and it gets a fatal error because of too many bytes or something

not tooo big of a deal but just so you know if anyone gets an error like that


ghost's Avatar
0 0

wow pretty cool , i tried looking for one of these before but i couldn't find one good work :)

if you can send me the code as well. thanx


ghost's Avatar
0 0

that might depend on how your host is configured..

carefull with those, i have a dreamhost account and we are limited to 60min cpu usage per day. yeah it doesn't make much sense and i don't know how does that work but running 50mb wordlists might not be a good idea unless you have a server and not an host


ghost's Avatar
0 0

sakarin wrote: that might depend on how your host is configured..

carefull with those, i have a dreamhost account and we are limited to 60min cpu usage per day. yeah it doesn't make much sense and i don't know how does that work but running 50mb wordlists might not be a good idea unless you have a server and not an host

yeah yeah

i got that error when i hosted it on my site (servage hosting)

im sure they limit some stuff like this

so im gonna put it on my comp now and use my huge wordlist heh


ghost's Avatar
0 0

Are you sure it works?

I don't thing that DES encryption has any collisions.

'fuckedup' and 'fuckedupdown'

are same.

Are you sure the code is working?


ghost's Avatar
0 0

has no collisions? impossible.

if there are, say, mayb 70 possible characters (A-Z, a-z, 0-9, + special characters, doesnt matter)

then with a 13 character result= 70707070707070707070707070 = 9.68890104 × 10^23 = 968890104000000000000000

combinations. a fucking huge number but not infinite.

but yeah standing up for kaksii the odds of a collision are, well, REAAAAAAAALLLLLLLLLLYYYYYYYY fucking slim. if you found that by hand then youre jesus. seriously. like the odds are

000000000000000000000000000000000000000001% chance per two random inputs. so pretty much you could spent a trillion trillion trillion lifetimes doing that and never find a collision by hand.


ghost's Avatar
0 0

DigitalFire wrote: has no collisions? impossible.

if there are, say, mayb 70 possible characters (A-Z, a-z, 0-9, + special characters, doesnt matter)

then with a 13 character result= 70707070707070707070707070 = 9.68890104 × 10^23 = 968890104000000000000000

combinations. a fucking huge number but not infinite.

Don't go with that shit "nothing is impossible". Maybe his code is wrong.


ghost's Avatar
0 0

and yeah could i please have a copy too :)

i would like to mod it to run all the wordlists one after another.


ghost's Avatar
0 0

okay kaksii you win. just tested it out, its broken.

fuckedup = fuckedupdown fackedup = fackedupdown fackedup = fackedupdawn applesrgood = applesrgoodandtasty


ghost's Avatar
0 0

DigitalFire wrote: okay kaksii you win. just tested it out, its broken.

fuckedup = fuckedupdown fackedup = fackedupdown fackedup = fackedupdawn applesrgood = applesrgoodandtasty

I always win :D


ghost's Avatar
0 0

yeah yeah yeah… i was beginning to think hackingforce was jesus.


ghost's Avatar
0 0

heh idk why that happens but you guys are right

haha wtf

ill send you all the source

[edit] i emailed you richo…check it out [/edit]


ghost's Avatar
0 0

lol i missed that yesterday..

that's supposed to happen.

htaccess files have a max lenght of 8 for the pass so the crypt() function is defaulted for 8 lenght too.

you can increase the salt but there's really no point..

that's why the best wordlists for this kind of cracking should be truncated for 8 chars.


ghost's Avatar
0 0

sakarin wrote: lol i missed that yesterday..

that's supposed to happen.

htaccess files have a max lenght of 8 for the pass so the crypt() function is defaulted for 8 lenght too.

you can increase the salt but there's really no point..

that's why the best wordlists for this kind of cracking should be truncated for 8 chars.

a really?

haha cool

i guess ill go and limit it hah:p


ghost's Avatar
0 0

DigitalFire wrote: yeah yeah yeah… i was beginning to think hackingforce was jesus.

i am :p