Login Register






7z bruteforce? filter_list
Author
Message
7z bruteforce? #1
Has anyone had any experience bruteforcing 7z? The extracted hash looks incredibly massive though it IS a valid hash. Trying to brute force a simple one word password with different wordlist including custom ones with no luck.

I definitely don't have the correct wordlist and unless it is a targeted attack, it will take quite a while. It's just surely if it's a single word it should be crackable? Trying to find out the reason why. Must be something 7z is doing when encrypting.

Wondering if anyone has looked at the source code for 7z or any experience?

Reply

RE: 7z bruteforce? #2
john the ripper can brute a 7z file.

https://www.openwall.com/john/

Reply

RE: 7z bruteforce? #3
(02-04-2019, 07:13 PM)sunjester Wrote: john the ripper can brute a 7z file.

https://www.openwall.com/john/

Yea that's what I used. I've never seen a hash this long before tbh.
The issue is the stretching algorithm of 7z. Just wondering if anyone has any insight about it. I know they've released a new bug bounty in the EU.
(This post was last modified: 02-05-2019, 01:41 AM by kyda. Edit Reason: added quote )

Reply

RE: 7z bruteforce? #4
(02-05-2019, 01:39 AM)kyda Wrote: The issue is the stretching algorithm of 7z.

This will slow down the bruteforce to some degree.

How's It proceeding thus far?
[Image: AD83g1A.png]

Reply

RE: 7z bruteforce? #5
(02-04-2019, 07:13 PM)sunjester Wrote: john the ripper can brute a 7z file.

https://www.openwall.com/john/

(02-05-2019, 03:49 AM)mothered Wrote:
(02-05-2019, 01:39 AM)kyda Wrote: The issue is the stretching algorithm of 7z.

This will slow down the bruteforce to some degree.

How's It proceeding thus far?

No luck still. Just passed it to a cracking rig but I doubt there will be results. Any advice?

Reply