Wednesday, March 1, 2017

MD5 Collision:

MD5 collision is very interesting topic in the field of cryptography. If you browse on this topic you will find good research articles on the collision and even you able to think about what is the future. Very recently google came up with SHA-1 collision.





Google said "We then leveraged Google’s technical expertise and cloud infrastructure to compute the collision which is one of the largest computations ever completed."
 Here are some numbers that give a sense of how large scale this computation was:
  • Nine quintillion (9,223,372,036,854,775,808) SHA1 computations in total
  • 6,500 years of CPU computation to complete the attack first phase
  • 110 years of GPU computation to complete the second phase





Lets go back to our topic MD5 collision:


d131dd02c5e6eec4693d9a0698aff95c2fcab58712467eab4004583eb8fb7f89 
55ad340609f4b30283e488832571415a085125e8f7cdc99fd91dbdf280373c5b 
d8823e3156348f5bae6dacd436c919c6dd53e2b487da03fd02396306d248cda0 
e99f33420f577ee8ce54b67080a80d1ec69821bcb6a8839396f9652b6ff72a70
and
d131dd02c5e6eec4693d9a0698aff95c2fcab50712467eab4004583eb8fb7f89 
55ad340609f4b30283e4888325f1415a085125e8f7cdc99fd91dbd7280373c5b 
d8823e3156348f5bae6dacd436c919c6dd53e23487da03fd02396306d248cda0 
e99f33420f577ee8ce54b67080280d1ec69821bcb6a8839396f965ab6ff72a70 
Each of these blocks has MD5 hash 79054025255fb1a26e4bc422aef54eb4.                              


 This above pair was found in 2005 by researchers from Shandong university in China.


        


We got two set of executable files: one set for windows and other set for Linux.
MD5 for windows file: cdc47d670159eef60916ca03a9d4a007
https://www.virustotal.com/en/file/1316543942a8c6cd754855500cd37068edbbd8b31c4979d2825a4e799fed6102/analysis/1488349995/
https://www.virustotal.com/en/file/60d13913155644883f130b85eb24d778314014c9479aedb5f6323bf38ad3a451/analysis/1488359868/




MD5 for Linux file: da5c61e1edc0f18337e46418e48c1290
https://www.virustotal.com/en/file/1c4ff4e490b15b2b214f26c5654decccbcbea9eb900f88649dc7b1e42341be56/analysis/1488350080/
https://www.virustotal.com/en/file/fad878bd261840a4ea4a8277c546d4f46e79bbeb60b059cee41f8b50e28d0e88/analysis/1488359933/




















                                                                                                                                                                         Post made by
newWorld

No comments:

Operating system - Part 1:

 In our blog, we published several articles on OS concepts which mostly on the perspective for malware analysis/security research. In few in...