Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

real13 - security key ... - wtf


ghost's Avatar
0 0

i have finished all in the mission, except the fuck*ng security key. ok, i found encrypted key in the picture and the format looks like [md4 or md5 hash][AED. - postfix]. i was trying md5 attack:

  • dictionary - nothing
  • bruteforce: capital letters+numbers - nothing
  • bruteforce: small letters+numbers - nothing
  • bruteforce: small + capital letters - nothing i don't like bruteforce attackt and i'm a little confused. well, question: how long is decrypted string from md5 hash or i'm totally wrong?

thx for answer. :)


ghost's Avatar
0 0

It's a security key… i'm pretty sure it's MD5 if my memory serves me (Which I sure as hell hope it does at 14), just try some other things to brute-force, a hint:

It's a security key, not a pass, I brute-forced it within seconds once I found the right Char set…

That probably gives too much away.


ghost's Avatar
0 0

thx a lot Happysmileman.


ghost's Avatar
0 0

insidious wrote: not md5…. but something similar to it. Also theres no need to brute force, im sure oyu can find it in the program your suppose ot crack. sorry i dont really remember…. lol

you mean password hashes. :p yes of course, you need only Olly dbg. security key is other. ;)


ghost's Avatar
0 0

insidious wrote: lmao… sorry idr… which is the security key??

link? might refresh my memory.. security key is in a transparent image.


AldarHawk's Avatar
The Manager
0 0

Yes it is an easy code to crack. Just thrown in there to piss people like you off :P

The challenge is not easy but it is not hard either. The main focus of the challenge is not to crack the software but to hack the password retrieval. But there are more than one way to skin a cat!!!


ghost's Avatar
0 0

i'm totally tired & lost already. i can't find any logical relation between EAD and md5 hash. i was trying find the right char set for brute-forcing(all combinations EAD+some character), but no result. i have no normal idea already. it's lottery for me.


ghost's Avatar
0 0

It's fairly simple… You'll either know the purpose of the EAD fairly quickly or you won't… Don't try and Google it just think about why it'd be put there


AldarHawk's Avatar
The Manager
0 0

is it not AED? That is the god of the underworld in Celtic Mythology…that aside AED is meaningless in this challenge :P


ghost's Avatar
0 0

thx for answer Happysmileman & AldarHawk. Happysmileman: i had idea like first, about AED position, when i seen dot. AldarHawk: yes of course, it's AED. it was mistake. :p

ok, i'll write my own bruteforce application.