Penetration Testing mailing list archives
RE: Does anybody know about encrypting algorithm of Everest Icode?
From: "Alex Eden" <Alex.Eden () senet-int com>
Date: Wed, 21 Jan 2009 10:35:59 -0500
Looks to me like md5. A bit too short for sha1 or sha2. When I'm not sure, I just add a record with all known values. Then take the know value and hash it using different algorithms, and then just compare the resulting strings. Even though in your case this approach may not work as REF_NO is probably a random (okay, pseudo-random) generated string used in a cookie or session ID or as a transaction reference number, or all of the above. You may want to try buying (or getting for free) MD5 rainbow tables. I haven't looked at those in a while, but when I last used them, the free ones were not sufficient to crack longer complex strings. The last time I tried rainbow tables I used them for cracking sha1 fatwire cms passwords. -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of ???? Sent: Monday, January 19, 2009 5:59 AM To: pen-test () securityfocus com Subject: Does anybody know about encrypting algorithm of Everest Icode? I'm pentesting some servers for my clients. There is encrypted field in msssql database. REF_NO -> 1E682975FA1988662A742C830720946F In asp script the line is vData = objShoppingCartUpd.CreateOrderFromCart(sConnectionString,sCartId,vChoice,sCCr esult,rsOrder,iResult) where rsOrder("REF_NO") is a normal string. Does anybody know about encrypting algorithm of Everest Icode system? Or where can i get it?
Current thread:
- Does anybody know about encrypting algorithm of Everest Icode? Волк (Jan 20)
- Re: Does anybody know about encrypting algorithm of Everest Icode? Augusto Pereyra (Jan 21)
- RE: Does anybody know about encrypting algorithm of Everest Icode? Alex Eden (Jan 21)
- Re: Does anybody know about encrypting algorithm of Everest Icode? Shreyas Zare (Jan 21)
- <Possible follow-ups>
- Does anybody know about encrypting algorithm of Everest Icode? christopher . riley (Jan 21)
- Re: Does anybody know about encrypting algorithm of Everest Icode? christopher . riley (Jan 22)
- Re: Does anybody know about encrypting algorithm of Everest Icode? Волк (Jan 22)
- Re: Does anybody know about encrypting algorithm of Everest Icode? Shreyas Zare (Jan 22)
- Re: Does anybody know about encrypting algorithm of Everest Icode? Волк (Jan 22)