Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 3 Mar 2013 15:53:14 +0900
From: Just Me <notsosimpleme@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: dmg2john used and password cracked, hdiutil fails to
 accept it

On Sun, Mar 3, 2013 at 3:03 PM, Dhiru Kholia <dhiru.kholia@...il.com> wrote:
> Can you please generate similar images and post them for development
> and testing purposes?

I believe this would require old Mac OS which I do not have anymore,
however if this is going to help with this case I will try to find a
way to generate those

> Can you post the hash (output of dmg2john)? It does not contain your data.

Posted hash in the first email on this thread. Here it goes again, as
a raw dmg2john output

/dmg2john test.dmg
test.dmg (DMG v1) successfully parsed, iterations count 0
test.dmg:$dmg$1*20*21abcdeba1df423358288fb08e0f0527837075a6*40*79320d32be372c1a3ef6bc3b8a69f01a525e7b10e97929382cb486219a41690a017342bd737e39ed*48*c7221023d7b8ab215635cbe85f02a4573a1724e51d6e305271ff77d73766831f4f582e370265d2d32170ca42a9d3ed40*0::::/test.dmg

and cracked:

./john hash
Loaded 1 password hash (Apple DMG PBKDF2-HMAC-SHA-1 3DES / AES [32/64])
Passwd6          (test.dmg)
guesses: 1  time: 0:00:00:00 DONE (Sun Mar  3 15:45:45 2013)  c/s:
176426  trying: Passwd6

looking at the results it looks like hash got extracted and cracked correctly...

Thanks
notsosimpleme

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.