vBulletin Search Engine Optimization
| |||||||
| Register | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| ||||
| 2006/8/24, Joachim Schipper <j.schipper@math.uu.nl>: > The current spade of attacks against MD5 and SHA1 are interesting and > cause for concern; however, they are birthday attacks - the attacker can > produce two (to a certain extent, arbitrarily chosen by the attacker) > plaintexts which produce the same hash. > > However, in the ports system, an attacker would have to create a > collision with a known plaintext (in other words, find a file that has > the same hash as a known file). This is an entirely different, and much > more difficult attack. And that completely ignores the fact that what > you discover must be at least a proper gzip file, containing a proper > tar archive, and probably should contain a mostly-functional version of > the program. This seems to be possible to a certain extend. The heise article is here: http://www.heise.de/newsticker/meldung/77235 babelfish: http://tinyurl.com/ojss8 Here are some references: http://www.iaik.tugraz.at/aboutus/pe...rger/index.php Best Martin |
| Thread Tools | |
| Display Modes | |
| |