help me make sense of this |
![]() ![]() |
help me make sense of this |
Tue, 27 Mar 2007 15:15:00 +0000
Post
#1
|
|
|
Hackling ![]() Group: Members Posts: 8 Joined: Wed, 08 Mar 2006 23:40:52 +0000 Member No.: 326 |
I have to use this special web browser that locks down my entire computer when I work on stuff for my online classes and its really annoying, I have realized that the only reason I has to be use is because there is a password built into the browser that the website requests and you cant continue with out it. Any ideas on finding it?
I tried to capture packets (from another computer you cant run password sniffers or packet capturing software with the browser running, there is a list of at least 30 page's long of things that cant be running including paint). I also tried cain but it only captures my password and not the second automatic password. Anyways here is a cookie that was captured by ethereal CODE Cookie:lol=username%3Dheck.no%26password%3DtCr2DZDAbqWZo
%26expiry%3D1175033745 %26hash%3D52770e1a5f700cd6f020f815217c4dc9.... proctor=0d9ad48b34cd08911339. I'm hoping that the 3DtCr2DZDAbqWZo or the D52770e1a5f700cd6f020f815217c4dc9 is a password hash, which would make 0d9ad48b34cd08911339 the hash of the automatic password. Or am I completely wrong and those are just session Id's or something else. If they are hashes does anyone recognize the hash? |
|
|
|
Tue, 27 Mar 2007 15:23:38 +0000
Post
#2
|
|
|
Hak.5 Zombie ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 206 Joined: Fri, 06 Oct 2006 14:42:34 +0000 From: Netherlands Member No.: 2,686 |
the 3DtCr2DZDAbqWZo hash should be read as tCr2DZDAbqWZo. This is because %3D is the hex value for the =
this also means that D52770e1a5f700cd6f020f815217c4dc9 should be read as 52770e1a5f700cd6f020f815217c4dc9 52770e1a5f700cd6f020f815217c4dc9 is a normal MD5 hash, crack it to see the value. tCr2DZDAbqWZo probably is a DES hash, but I'm not 100% sure about it, just a quick guess. |
|
|
|
Tue, 27 Mar 2007 17:11:27 +0000
Post
#3
|
|
|
Born-again Hak5er ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Active Members Posts: 3,067 Joined: Tue, 07 Mar 2006 09:28:29 +0000 From: Veenendaal, The Netherlands Member No.: 268 |
I doubt that password is anything but the actual password, _maybe_ ROT13d or BASE64 encoded or something. After all, if you transmit a hash (as opposed to transmit the original, and let the server compute the hash for it and then compare it against the stored hash), the hash becomes the only thing an attacker needs. It effectively becomes the password.
-------------------- I don't need a pass to pass this pass!
- Groo The Wanderer - |
|
|
|
Tue, 27 Mar 2007 17:28:23 +0000
Post
#4
|
|
![]() Also known as Boris ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 7,394 Joined: Tue, 07 Mar 2006 17:32:49 +0000 From: The Great England Member No.: 284 |
Have you tried replicating the browsers user agent? It could be that simple.
-------------------- skype me: tehboris
PS3 ID: tehBoris Twitter: https://twitter.com/tehboris Steam: http://steamcommunity.com/id/tehboris |
|
|
|
Tue, 27 Mar 2007 17:34:41 +0000
Post
#5
|
|
![]() Hak.5 Fan + ![]() ![]() ![]() Group: Members Posts: 43 Joined: Wed, 14 Mar 2007 12:10:41 +0000 Member No.: 7,052 |
What is the browser called?
daedalus |
|
|
|
Tue, 27 Mar 2007 18:31:33 +0000
Post
#6
|
|
|
Hackling ![]() Group: Members Posts: 8 Joined: Wed, 08 Mar 2006 23:40:52 +0000 Member No.: 326 |
Changing the user agent doesn't work, First thing I tried plus and the user agent is the Firefox user agent. I only know its a password because a password box comes up I click no because I was not supplied a password and then the default password is put in the box. I have tried cracking 52770e1a5f700cd6f020f815217c4dc9 at a couple sites and they all came up with nothing. The browser is respondus lockdown browser.
Anyways if 52770e1a5f700cd6f020f815217c4dc9 is a password hash then I'm guessing its for my password and I know what that is. |
|
|
|
Tue, 27 Mar 2007 20:52:59 +0000
Post
#7
|
|
![]() Also known as Boris ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 7,394 Joined: Tue, 07 Mar 2006 17:32:49 +0000 From: The Great England Member No.: 284 |
Have you looked at the programs executable as ASCII? Things like that are sometimes stored as ASCII in the program.
-------------------- skype me: tehboris
PS3 ID: tehBoris Twitter: https://twitter.com/tehboris Steam: http://steamcommunity.com/id/tehboris |
|
|
|
Tue, 27 Mar 2007 21:23:19 +0000
Post
#8
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
Can you get a copy of the program to post here?
|
|
|
|
Tue, 27 Mar 2007 21:30:27 +0000
Post
#9
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
QUOTE ("Cooper") I doubt that password is anything but the actual password, _maybe_ ROT13d or BASE64 encoded or something. After all, if you transmit a hash (as opposed to transmit the original, and let the server compute the hash for it and then compare it against the stored hash), the hash becomes the only thing an attacker needs. It effectively becomes the password.
It doesn't seem to be Rot13 and it's has the wrong number of characters to be Base64 (unless it's padded by the server before decoding) |
|
|
|
Tue, 27 Mar 2007 22:08:24 +0000
Post
#10
|
|
![]() Also known as Boris ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Administrators Posts: 7,394 Joined: Tue, 07 Mar 2006 17:32:49 +0000 From: The Great England Member No.: 284 |
Perhaps the easier solution is to just run the thing in a VM. Then you have both limited and unlimited access at the same time. Plus sniffing the traffic from a VM is much easier then having to use an external device.
-------------------- skype me: tehboris
PS3 ID: tehBoris Twitter: https://twitter.com/tehboris Steam: http://steamcommunity.com/id/tehboris |
|
|
|
Wed, 28 Mar 2007 05:35:19 +0000
Post
#11
|
|
|
Hak.5 Zombie ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 206 Joined: Fri, 06 Oct 2006 14:42:34 +0000 From: Netherlands Member No.: 2,686 |
QUOTE ("Horza") It doesn't seem to be Rot13 and it's has the wrong number of characters to be Base64 (unless it's padded by the server before decoding)
Like I said, it probably is DES and if you know the password in plaintext, try hashing it to MD5 and to DES, so you can see if the hash is of your password, or from something else. |
|
|
|
Wed, 28 Mar 2007 06:19:43 +0000
Post
#12
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
Well, it could be DES, since that's the cipher most often encoded like that (at least by crypt), although it could be Triple DES as well (which would make more sense considering how insecure DES is).
|
|
|
|
Wed, 28 Mar 2007 06:24:20 +0000
Post
#13
|
|
![]() Retired Admin ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Active Members Posts: 4,199 Joined: Tue, 11 Apr 2006 16:23:23 +0000 From: irc://England:6667 Member No.: 514 |
[OT]I gotta say I actually lol'd when I read Horza's sig:
QUOTE ("Horza") There are 01 types of people in the world, those who understand little-endian bit order and those who don't.
:D[/OT] -------------------- |
|
|
|
Wed, 28 Mar 2007 06:24:25 +0000
Post
#14
|
|
|
Hak.5 Zombie ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 206 Joined: Fri, 06 Oct 2006 14:42:34 +0000 From: Netherlands Member No.: 2,686 |
Took me a few seconds to crack with john the ripper.
CODE C:Toolsjohn>john-mmx pass.txt
Loaded 1 password hash (Traditional DES [64/64 BS MMX]) 112688 (phonebooth) guesses: 1 time: 0:00:00:12 (3) c/s: 285148 trying: 11289c - 112659 tCr2DZDAbqWZo = 112688 |
|
|
|
Wed, 28 Mar 2007 06:38:54 +0000
Post
#15
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
Oh, well obviously whoever wrote that software doesn't care about security - why would anyone use standard DES anymore? Heh.
|
|
|
|
Wed, 28 Mar 2007 06:39:47 +0000
Post
#16
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
QUOTE ("moonlit") [OT]I gotta say I actually lol'd when I read Horza's sig:
QUOTE ("Horza") There are 01 types of people in the world, those who understand little-endian bit order and those who don't.
:D[/OT] :) Thank you, I thought of it myself as well, unlike the people who use the old 10 types. |
|
|
|
Wed, 28 Mar 2007 11:21:41 +0000
Post
#17
|
|
|
Hackling ![]() Group: Members Posts: 8 Joined: Wed, 08 Mar 2006 23:40:52 +0000 Member No.: 326 |
Thanks but I know that but I Know what my password is and tCr2DZDAbqWZo is the hash for my password. I'm trying to figure out if 0d9ad48b34cd08911339 is a hash and if it is what is the password.
As for the virtual machine, I never thought of that and I'm currently installing windows in A VM, hopefully that solves my problems and then I wont need the password. |
|
|
|
Wed, 28 Mar 2007 11:36:34 +0000
Post
#18
|
|
|
I am actually called Shaun ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,075 Joined: Sun, 16 Apr 2006 18:57:59 +0000 From: England Member No.: 544 |
Wait, I just reread your first post, you actually have a copy of this browser at home? Have you tried opening it in a disassembler to see what it's doing?
Edit: Also have you checked to see if that string is always the same? If it changes it probably isn't a hash of the password. |
|
|
|
Wed, 28 Mar 2007 11:53:20 +0000
Post
#19
|
|
|
Hackling ![]() Group: Members Posts: 8 Joined: Wed, 08 Mar 2006 23:40:52 +0000 Member No.: 326 |
-1 for me +1 for respondus.
I just I got my VM working all nice and Installed the browser and I get a nice little error message Respondus LockDown Browser can't be used in virtural machine software such as, virtual PC, VMWare and parallels. Seeing if the string is the same I will have to wait for my next assignment next week unless I finish this weeks stuff early and move on depends on how motivated I am. As for the disassembler I have not tried that, I don't even have a disassembler can some one give me some names. |
|
|
|
Wed, 28 Mar 2007 12:24:09 +0000
Post
#20
|
|
|
Hak.5 Zombie ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 206 Joined: Fri, 06 Oct 2006 14:42:34 +0000 From: Netherlands Member No.: 2,686 |
QUOTE ("phonebooth") I'm trying to figure out if 0d9ad48b34cd08911339 is a hash.
Well obviously it's a MD5 hash.. maybe use some rainbow tables on it |
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: Thu, 09 Sep 2010 02:07:08 +0000 |