SHA256 and Sha512

Interesting discussion though.

Much sensationalism here. Little practical results.

Drifting away from SHA-1 is understandable but still not a hurry in most use cases.

Avoiding NSA-compromised PRNG is certainly a bit more urgent, let it be only for showing they did the wrong move (again).


Speaking of Collisions... Impersonation (Much Sensationalism)

Here is an example you can taste....

17/09/2013 14:43:36


Date   : 01/08/2013

Size   : 1114112

Version: 6.1.7601.18229

MD5    : 365A5034093AD9E04F433046C4CDF6AB

SHA1   : 7244AE695F8E5A730857781635ACB2969F15C594

and another even better:

17/09/2013 14:48:13


Date   : 01/08/2013

Size   : 274944

Version: 6.1.7601.18229

MD5    : 1B7343C3765638D4D17CB925F84F8ABE

SHA1   : B001F04386EBE09DDAC86297FA7B18AF37ABAFFF

This is how you test...

First checks the MD5   Here: https://www.virustotal.com/en/#search

Then check the SHA-1 same way but in another window...

Then compare all the signatures.... and Poof Impersonation discovered!

Not sensationalism... simple hack by highly funded and technically adept professionals...

They can spoof almost anything... but there is a catchf!

They cant spoof the two in tandem!

They can spoof the MD5 or the Sha-1 but not both...

So get vigilant and do some comparission and you will identify all off their attempts many will blow your mind!

Once you identify the impersonation, you then simply use the target to reverse engineer and aquire the code, method etc...

You can use this tool to find the impersonations Advanced Process Analysis and Identification System

(It's what I use: https://hermes-computers.ca//apais_1.php )

oh... and yes I wrote it, and it's in Autoit!


Edited by MindlessGenius

Look: czardas himself admitted volontarily that even his use of SHA-1 would be overkill in his use case. That's true for still many everyday use cases. Targets are simply not worth the effort, as -- as you say : "simple hack by highly funded and technically adept professionals..."

You know that people in charge of protecting really valuableor sensitive data have been using other hashes, or combination of distinct hashes for very long time.

