NODE ad85f39dDecrypting DES
"Wasim Q. Malik" <wmalik@sdnpk.undp.org>Sun, 22 Jun 1997 20:58:25 +0800
Folks, here is a project I am working on. Need your help with it as it is
really important.
You know we often encrypt files using a key (the DES way -- won't talk
about RSA here). Examples are the UN*X "crypt", the MS-Office "Save with
password" option, and lots of other ciphers using this alorithm. Take a
text file, for instance. You provide a key and the file is encrypted using
that key, and can be decrypted only if that key is known. It involved only
one key/password.
Now I was wondering whether we could somehow fool this encryption system
to get to the encrypted material without using the key. It could possibly
be done in many ways:
* The key has to be stored somewhere in the file, in whatever form,
with which the entered key is compared. It could somehow be gotten hold
of from there. Perhaps a hex editor could be used to scan the first few
bytes of a file for the key.
* The decryption algorithm/source could be modified to give access
even for a bad password.
* During the process that the decryptor asks for the input of the
key, we could somehow break out of the routine and bypass it to get to the
contents of the file.
Do you have any ideas about how this could be done? Or is it even possible
theoretically? Any other workarounds you can think of?
Au revoir,
Wasim Q. Malik
NODE c14d6b34Re: Decrypting DES
Paul Bradley <paul@fatmans.demon.co.uk>Mon, 23 Jun 1997 08:16:13 +0800
> * The key has to be stored somewhere in the file, in whatever form,
> with which the entered key is compared. It could somehow be gotten hold
> of from there. Perhaps a hex editor could be used to scan the first few
> bytes of a file for the key.
No, the keys are not stored in the files in anything worth it`s salt, and
if it is a passwd file it`ll be hashed anyway.
Depends entirely on the software, there are freely available crackers for
files from a lot of micro$oft stuff, and some other popular programs such
as pkzip etc... Otherwise get a good cryptgrapher to look at the
software, run a sniffer on the network, a keygrabber on the machine, or
give up.
For a good introduction covering much of the stuff you need try the
sci.crypt FAQ.
Datacomms Technologies data security
Paul Bradley, Paul@fatmans.demon.co.uk
Paul@crypto.uk.eu.org, Paul@cryptography.uk.eu.org
Http://www.cryptography.home.ml.org/
Email for PGP public key, ID: FC76DA85
"Don`t forget to mount a scratch monkey"