NOTE: When cracking WPA/WPA2 passwords, make sure you check gpuhash.me first incase it's already been processed.

Home - Website Feedback - HLM FOUNDS BYPASS!!??

WARNING!
Due to the number of SCAMS going on in the PAID forum, PLEASE ask an ADMIN or MODERATOR to verify ALL found passwords to ensure you are not being SCAMMED.
DO NOT PAY until an ADMIN or MOD has verified them for you!


12 Results - Page 1 of 1 -
1
Author Message
Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:22:59

Hi

i have been downloading some founds list from the hlm

however i found that some hashes are marked as found while they are NOT!
i have checked this file id: 2164
https://hashkiller.co.uk/hash-list-manager.aspx
algo: md5($pass.$salt)

84405 marked as found, but none of them is correct !

can some one double check?

74868e6a004e4e114f5558f5c693792a:HjssGOnR:09374956259
b264cc93004ee21918a588fc4475147d:gTPR79Hd:123456
febe5c1f005052186bd012cb08ec299d:dIqsaaVe:6312
f1f3ac88005174ae1e7ae34f649f73b9:7z5RVSq5:228811
0f2e939d0051c18fc5610f998e2ef51d:457HDV3O:710701
d6f05be9005225890415d93a02163833:p7StxfHL:123123
a73ab68c005269c00c002b72f58d9b7b:M1z93MgY:919191
35ec2a210053d83499f8d4967bdcadb0:rFBXZeD8:3371671
b84c4bf80053ef4fdf92be7cb60ea0b7:PilaYOfY:407264
f3e960d9005425c2f7ace4291ed1134f:gaYT2FTp:136512
0008db41005473d5d65eb6ee7212bda5:3RSCDEPU:omid
c22f004800547eee2a5975506ad60a0c:6dzSjkzf:1005710
...


or maybe i missed something ?


abdou99

Avatar
Chick3nman
Moderator
Status: Trusted
Joined: Wed, 28 Jan 2015
Posts: 546
Team:
Reputation: 582 Reputation
Offline
Thu, 17 Aug 2017 @ 18:31:52

These are -m 2811 hashes, quite clearly. The algorithm the list was uploaded as is not concrete and founds from any algorithm can be added since mixed lists and bad upload types happen from time to time. If it's been found, its been found, period. It's up to you to understand the data if its not the same algorithm as listed. This shouldn't be difficult for you to identify.


My PGP key is available for security and identity verification here: https://keybase.io/chick3nman

Hardware: 1x D-WAVE 2000Q

BTC: 1Chick3nMTco6sBEByKuvmAzYTBsGN5KzD

Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:33:48

Chick3nman said:

These are -m 2811 hashes, quite clearly. The algorithm the list was uploaded as is not concrete and founds from any algorithm can be added since mixed lists and bad upload types happen from time to time. If it's been found, its been found, period. It's up to you to understand the data if its not the same algorithm as listed. This shouldn't be difficult for you to identify.


means that this is a bug
uploads should be filtered

I'm using a bot to download those founds, so it's not that easy to re-check re-identify each hash


abdou99

Avatar
Chick3nman
Moderator
Status: Trusted
Joined: Wed, 28 Jan 2015
Posts: 546
Team:
Reputation: 582 Reputation
Offline
Thu, 17 Aug 2017 @ 18:35:59

This isn't a bug. This is feature. If you are verifying algorithms on download, that's your own problem.


My PGP key is available for security and identity verification here: https://keybase.io/chick3nman

Hardware: 1x D-WAVE 2000Q

BTC: 1Chick3nMTco6sBEByKuvmAzYTBsGN5KzD

Avatar
s3in!c
Moderator
Status: Elite
Joined: Wed, 10 Apr 2013
Posts: 850
Team:
Reputation: 1219 Reputation
Offline
Thu, 17 Aug 2017 @ 18:37:30

You could just extend your bot to test the most common algorithms if the one from the list does not match. This should not be that complicated.


+Rep if I helped

Hashes.org - Powerful Community Password Recovery
Hashtopolis - Hashcat distributed cracking tool

BTC: 1VTuiKrNoytU1PvYrF3J7VapQ9oPg93Jn

Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:38:33

Chick3nman
What's being called a feature when i see couple hashes uploaded on the wrong algo list

This is a mislead.


abdou99

Avatar
s3in!c
Moderator
Status: Elite
Joined: Wed, 10 Apr 2013
Posts: 850
Team:
Reputation: 1219 Reputation
Offline
Thu, 17 Aug 2017 @ 18:39:36

Would it be better for you when the lists are just not labelled with any algorithm? So there is no "misleading" algorithm? :P


+Rep if I helped

Hashes.org - Powerful Community Password Recovery
Hashtopolis - Hashcat distributed cracking tool

BTC: 1VTuiKrNoytU1PvYrF3J7VapQ9oPg93Jn

Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:40:32

s3in!c

That what i can do for now, yes but not the best practise.

anyway, thanks for the confirmation, topic can be closed, but it's better to look at this more


abdou99

Avatar
Chick3nman
Moderator
Status: Trusted
Joined: Wed, 28 Jan 2015
Posts: 546
Team:
Reputation: 582 Reputation
Offline
Thu, 17 Aug 2017 @ 18:41:02

The upload algorithm is not concrete on purpose. That way when people upload lists with multiple or incorrect algorithms in them, we can still crack them and upload founds. The only people this misleads are people who don't have common sense enough to understand basic hash formats or how the list manager works.


My PGP key is available for security and identity verification here: https://keybase.io/chick3nman

Hardware: 1x D-WAVE 2000Q

BTC: 1Chick3nMTco6sBEByKuvmAzYTBsGN5KzD

Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:44:54

Chick3nman

Seems you prefer not to fix this.
It's not my problem either

what's right is to fix the problem
what's wrong is ignoring it

both hashes have different verification process, what makes you able to list 10 as 10 and 2811 as 2811


abdou99

Avatar
Chick3nman
Moderator
Status: Trusted
Joined: Wed, 28 Jan 2015
Posts: 546
Team:
Reputation: 582 Reputation
Offline
Thu, 17 Aug 2017 @ 18:46:49

It's not a problem, i still dont think you understand.


My PGP key is available for security and identity verification here: https://keybase.io/chick3nman

Hardware: 1x D-WAVE 2000Q

BTC: 1Chick3nMTco6sBEByKuvmAzYTBsGN5KzD

Avatar
hashC.co.uk

Status: n/a
Joined: Mon, 07 Aug 2017
Posts: 144
Team:
Reputation: 84 Reputation
Offline
Thu, 17 Aug 2017 @ 18:50:34

Chick3nman

It's a feature.

you can close the topic.
i got the info that i need, thanks for the help.


abdou99


12 Results - Page 1 of 1 -
1

We have a total of 167021 messages in 20896 topics.
We have a total of 18748 registered users.
Our newest registered member is behuro.