Hash Analysis Studio
By: David Midkiff
--------------------

I'll refer to Hash Analysis Studio as HAS to relieve my poor aching fingers. Ok. Here's the sales pitch. HAS contains the MD5, SHA-1 and SHA256 hash algorithms.

MD5 was developed by Ron Rivest as an improvement to the MD4 algorithm. MD stands for message digest if you didn't already know. MD5 produces a fixed 128-bit hash from a message. MD5 has been widely reviewed and considered one of the more secure hash algorithms by programmers and cryptographers alike. As of late its use has been dwindling as the new SHA algorithms are proving more effective. SHA (Secure Hash Algorithm) was designed by our big brother the NSA and our friends from NIST. The original SHA-1 algorithm produces a 160-bit hash string from a message. The latest version of SHA produces a 256-bit hash string. SHA is becoming more widely used then MD5. I chose to implement these three algorithms since they are the most widely used hash algorithms by programmers. Other algorithms such as MD4, MD2, Snefru, N-Hash, Ripe-MD and HAVAL were not included because they are not widely used. I guess you could call it a popularity thing.

Many programmers have implemented these three algorithms in encryption software and security logins. If you can uncover one of these hashes then HAS is your best friend. So what exactly does HAS do? HAS attempts to either brute-force a hash string (up to 64-bits) or do a quick dictionary lookup. HAS concentrates itself on password protection schemes used by these algorithms. HAS could never recover a large message in the age of this universe. (MD5 has a 32 character hexadecimal output. Theoretically it could hash a message up to 340,282,366,920,938,463,463,374,607,431,770,000,000 in size before ever running into collisions. You could only imagine the boundaries of SHA.)

The human brain can only remember strings or numbers in batches of seven characters. This is a major reason why phone numbers are structured as 7 digits. Most of us, when choosing a password, either pick a common word or instead limit the size of our passwords to around 64-bits (8 characters). Smart people will create passwords around the size of 14 to 16 characters. Since the speed of modern computers is considerably slow the speed of brute force attacks will always be slow. Brute force attacks generate every possible string combinations and attempt to match it with the inputted hash. Since the speed of MD5 and SHA are relatively slow this limits the ability of the brute force routines to produce results in a short amount of time.

The brute force routine in HAS is clocked at around 3000 attempts a second on a Pentium II. You can blame the authors of MD5 and SHA for creating such secure algorithms. :) Brute force may seem impractical because of its speed limit ... just reaching 64-bits would take a couple thousand years on a Pentium II. I included the brute force routine to show that anything is possible. It doesn't take much resources and can achieve a relatively satisfactory speed on fast computers. A widespread distributed network could turn HAS into a formidable brute force opponent against these algorithms. (A quick note: HAS generates all possible keyboard printable characters. It skips the lower and higher range of the ASCII spectrum because it is rare to find passwords that have these characters.)

To make up for the lacking of the brute force routines I put my computers to work creating a vast dictionary of around 106,634 words (English) and phrases. I compiled this dictionary into a small customized program which took every single word and pressed it through the three algorithms. The resulting dictionary files contain the Hash output of every word and the words. Around 5 hours of processing by my computers created these 3 dictionary files (one for each algorithm) which can give you literally instant lookups (clocked at 4 milliseconds on a PII). Simply enter a hash and do a dictionary lookup and it will return the original word/message instantly, if that hash is in the dictionary. The dictionary files are around 5-7 megs in size but are well worth the space.

Let's say Mary downloads some new program that implements MD5 for it's password security. She creates a secure login with the password "lovely". The program saves the resulting MD5 hash in the registry. Using regedit one can easily retrieve the Hash, pop it into HAS and do an instant dictionary lookup which will return: "lovely" ... or brute force could be attempted (which could take awhile) and it would successfully return "lovely". This program should never be used to illegally obtain a password but is very useful in audits and analysis.

I have seen no real program on the Internet that attempts to analyze MD5 or SHA hashes. HAS is anything but complete but it definitely is a good start to what I hope becomes a widespread effort in discovering new ways to recover messages from hashes. The more we analyze the securer things will be made.

HAS was developed in the Visual Basic 6.0 programming environment. Because of the power and ease of rapid application development (RAD) in Visual Basic I tend to regard Visual Basic over any other programming language although I do love C and C++. Running the program on an interpreted level will severely limit the speed but because VB6 compiles with a C++ linker the speed of the compiled program is that of any other compiled program. I know many experienced programmers may scoff at Visual Basic but in my opinion anything that saves time and frustration is worth my dollar. HAS is open source to everyone. I hope this encourages people (with more skill then I) to turn this program into something bigger. Please read "source readme.txt" for more information.


About the Author
---------------- 
My name is David Midkiff. I am a 20 year old programmer and network technician. I've spent a great deal of my time in life studying cryptography, mathematics and computer programming. I hope to one day join the NSA and once and for all see their capabilities but for now that's just a goofy dream of mine. :) My studies of Hashes have led me to begin developing a better more fruitful/secure Hash algorithm. I've discovered several weaknesses in most to all Hash algorithms ... from my studies I hope to make brute force obsolete. I have a huge list of ideas for making cryptography more and more secure but as usual I will have to earn my colors with age and experience. Right now I have around 3 years of cryptanalysis study under my belt. :) Anyways. Ok.

You can forward all comments, suggestions, hate mail or requests to mdj2023@hotmail.com. I try to respond to everyone. In light of a free promotional oppurtunity: If you like electronic (techno/euro) music be sure to check out my compositions at www.mp3.com/m-dj. God bless you and God bless America.