Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4255c2570810090735o4a0cea5avdc3569a335745ff7@mail.gmail.com>
Date: Thu, 9 Oct 2008 08:35:30 -0600
From: RB <aoz.syn@...il.com>
To: john-users@...ts.openwall.com
Subject: Re: reading "signons.txt" from friefox

> can "john" work in a simple way with the "signons.txt" file (or
> "SIGNONS.TXT") from "firefox"?

I didn't have one (signon saving is one of the first things I kill)
and ended up creating a short one, but there's probably a better way,
given that FF typically auto-decrypts the passwords somehow using
key3.db.  I'll leave analysis of that to someone else.  That said,
it'd probably be even easier to just go check the source.

The records are in a format described here:
http://kb.mozillazine.org/Signons2.txt.  The "encrypted password"
field is a base64 string, which decodes to a 62-byte string.  Cursory
examination seems to indicate the format is:

\x30[18 bytes of administrativa]\x01\x30\x14[12 bytes that remain
constant across account names/passwords][26 bytes of entropy]CR/LF

There was a passing bit of weirdness where one account got stored
doubly and had what seemed to be an extra 16 bytes of entropy;
couldn't re-create the situation, though.  The account names only have
18 bytes of entropy.

It's probably some form of an MD5 hash, and there's some simple way to
extract and crack it, but we've passed both my available time and
interest.


RB

-- 
To unsubscribe, e-mail john-users-unsubscribe@...ts.openwall.com and reply
to the automated confirmation request that will be sent to you.

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.