Re: Cracking Strings from URLs

[email protected] (Computer Nerd Kev)
Newsgroups comp.misc
Organization Ausics - https://newsgroups.ausics.net
Message-ID <[email protected]>
Rich <[email protected]> wrote:
> Computer Nerd Kev <[email protected]> wrote:
>> Computer Nerd Kev <[email protected]> wrote:
>>> I've got long strings like this from URLs (percent-encoded
>>> characters have been decoded):
>>> 
>>> SdADygkIiM8ED8ZK/ZfkxwbHEgOXnsgKzQcYtq2j3L1HN6OYvET8PwvO2gpCCv4Bp4vIGLwLFN3dDQABOjWT0gVI/EtBlNUIObwLFNnU90IK/gCs2QQzBzhEz8sNAAdBPpmM+T0KRgudx88HxzsFnpjGQs8PBp+fEAvQCgCZnsdKzQz+lpbIBPj7CQ==
>>> 
>>> I believe they might be encrypted strings containing one or more
>>> known fields, probably including a known ten digit number
>>> (1409518286 in that case). They might also be hashes, but I think
>>> it's unlikely.
>> 
>> I got a copy of the PHP code. Turns out it's a "transposition
>> cipher" which adds different numbers to the ASCII value of each
>> character in sequence.
> 
> Also called the Ceasar cipher:
> 
> https://en.wikipedia.org/wiki/Ceasar_Cipher

Almost, but unlike the description there, the number of shifted
positions varies for each character in the encrypted string, since
the shift length depends on the ASCII value of each character in the
password. That means you couldn't simply shift the whole string all
the possible lengths until the string "1409518286" was found in the
result. Instead you'd have all the possible combinations of
independently shifted characters = 128 (ASCII character set) to the
power of the number of characters in the string. In this case
128^182 = 3.25e+383, which is ridiculous, but some shortcuts would
be possible, and probably many more than I can immediately guess.

>> Very simple,
> 
> Yes, that it is, and very weak against attack.

Probably, but a lot stronger than the Ceasar Cipher by my
reckoning.

>> but I still wonder what tools are available to brute-force that 
>> without knowing what sort of encryption method has been used?
> 
> Without working out which encryption algorithm, there are not a lot of 
> tools (besides asking one of these new AI's to "try everything").  
> Brute force has a somewhat narrow definition in the cryptography 
> community of trying all the possible keys until the correct key is 
> found -- which has an unstated dependency of "for the known encryption 
> algorithm used".  So you can't "brute force", per the usual crypto 
> meaning, until after you know (or have a good idea of) the algorithm 
> used.

Well the brute force approach I had in mind was to try brute
force using all the different known ciphers in turn, from simplest
onwards, with this cipher being tried not far after the Ceasar
Cipher, though very possibly not before some infeasible number of
possibilities was reached, given the length of the string. That it
was also base64 encoded would've thrown a spanner in the works, but
I'm thinking there may also be some smarter general-purpose
cracking approaches that could be used instead of pure brute-force.
You don't know if you don't ask...

-- 
__          __
#_ < |\| |< _#
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.