[Linuxtrent] [Fwd: more MD5 colliding examples]

  • From: Flavio Visentin <THe_ZiPMaN@xxxxxxxxx>
  • To: linuxtrent@xxxxxxxxxxxxx
  • Date: Sun, 04 Dec 2005 02:47:32 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Interessante

- -------- Original Message --------
To: bugtraq@xxxxxxxxxxxxxxxxx
Subject: more MD5 colliding examples

        hello everybody, last month we presented in a lightning talk at PacSec
a few interesting and somehow new things related to MD5 collisions: 2
different Win32 .EXE files with the same MD5 hash, and 4 different files
(inputs) with the same MD5 hash.

        These are direct results of reimplementing the already known attacks on
MD5, specifically abusing the fact that collisions can be generated for
arbitrary IVs.

        Today we are releasing some new stuff:

        - The 4 colliding files have been increased to 8 files (there is no
real limit in the number of colliding files which can be generated, this
is just an example of what can be done).

        - Two new Win32 .EXE files, this time with the same MD5 hash and also
the same CRC32, the same checksum 32 and the same checksum 16.

        Of course all this is no big theoretical breakthrough, but it's somehow
interesting to have examples to show to the incredulous.

        All the information (the files and presentation explaining how to
regenerate the files) from PacSec is now available at
http://www.corest.com/corelabs/projects/research_topics.php.

        have fun!
        gera

- --
Flavio Visentin

|                     \|||/
|                    @/0.0\@
|                     \ - /
+------------------oOOo---oOOo------------------

There are only 10 types of people in this world:
those who understand binary, and those who don't.

GPG Key: http://www.zipman.it/gpgkey.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDkkqzusUmHkh1cnoRAk/0AJ9rzxeY7EczVSZSmrW3UT+wyjRV9wCeLN87
24Eb/4sqX7hVJsfeuXn/Pf4=
=5GNR
-----END PGP SIGNATURE-----
-- 
Per iscriversi  (o disiscriversi), basta spedire un  messaggio con OGGETTO
"subscribe" (o "unsubscribe") a mailto:linuxtrent-request@xxxxxxxxxxxxx


Other related posts: