Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 8 Jun 2011 00:25:50 +0400
From: Solar Designer <solar@...nwall.com>
To: john-dev@...ts.openwall.com
Subject: Re: Status Report [4 of 15]

On Tue, Jun 07, 2011 at 01:08:47PM -0700, Dhiru Kholia wrote:
> It seems that RAR -p mode support requires a full RAR decompression engine.
> (unless some known plaintext attack is found on the recovered
> compressed stream).
> 
> Also there seems to be no documentation if RAR internally uses HMAC
> for the recovered compressed stream. So for the time being, I am
> moving on new tasks (zip support).

OK.  You'll need to do more research on RAR later.

> Latest RAR patch has been uploaded to the wiki in case someone wants
> to take a look.

Thanks!  I am tempted to release a jumbo-6 with your SSH, RAR, and PDF
patches so far.  What do you say?

> > 4. Start working towards adding zip file support to JtR.
> 
> This is what I plan to work during this and next week. ZIP uses HMAC-SHA1 before
> decompression is done, which should make this work simpler compared to
> RAR patch.

Actually, there are different versions of both RAR and ZIP formats, with
very different security properties.  And the same for PDF.  It appears
that you're focusing on modern versions only.  Correct?

> Last week, I published a preliminary pdf support patch which needs
> further work.

Great.  I think all of these patches are preliminary, yet it makes sense
to start including them in jumbo.

> I also briefly played around with hdiutil (10.5.6) and
> vfcrack with no luck (the tools doesn't seem to work for dmg files
> created by me, more debugging required here).

OK.  We can ask David specific questions on vfcrack if we need to.

Thanks,

Alexander

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ