Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow RarCrack - not exactly accurate
EH-Net
May 23, 2013, 03:39:32 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: RarCrack - not exactly accurate  (Read 7622 times)
0 Members and 1 Guest are viewing this topic.
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« on: August 22, 2009, 04:19:11 PM »

Anyone used RarCrack before, with success?  Smiley
Out of curiosity I have been running some tests on my system using rarcrack 0.2 using a personal rar file with a password of "pAssw0rd" (zero not o) and after a few minutes of running the program the program says that the password has been cracked and is "5Di"
I then thought I'd try a shorter password of "D00dle" (zeros not o's) on a new rar file and ran rarcrack again and this time the password was cracked with a password of "91t"
The test.rar file that came with the rarcrack program was cracked correctly but had a simple password of "100"

Just wondering if anyone else out there has had similar results with rarcrack
Logged

All men by nature desire knowledge.

Aristotle
jimbob
Guest
« Reply #1 on: August 23, 2009, 03:06:30 AM »

Given the short password length I would guess that the tool is finding false positives early on in the search. Does the tool stop running when it finds the false hit?

Jimbob
Logged
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #2 on: August 23, 2009, 12:48:45 PM »

Given the short password length I would guess that the tool is finding false positives early on in the search. Does the tool stop running when it finds the false hit?

Jimbob

Yep, Rarcrack stops and says that the password was cracked.
When RarCrack runs, it creates an xml file for the current rar file you're trying to crack, if the password has been cracked (or at least thinks its cracked) the xml file will contain the cracked password for example: <good_password>5Di</good_password> I also edited the xml file and removed the cracked password as well as modifying the <current></current> info so that Rarcrack won't continue and falsely crack the password again. I then ran Rarcrack again and this time the password was falsely cracked with the password "eW4"

I'll try rarcrack from the BT distro and see if I get the same results.
Logged

All men by nature desire knowledge.

Aristotle
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #3 on: August 23, 2009, 01:27:17 PM »

My guess it's a version issue.  It's probably trying to crack a version of the RAR file it's not designed for.   
Logged

~~~~~~~~~~~~~~
Ketchup
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #4 on: August 27, 2009, 08:21:52 AM »

Just an update on Rarcrack. Using Rarcrack from the BT distro seems to work much better than rarcrack on my openSUSE 64bit system. So far I haven't had any false positives but I haven't had any successful cracks either and rarcrack has been running continuously for 3 days  Smiley
Logged

All men by nature desire knowledge.

Aristotle
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.