4 ms·
This comment (http://www.classicshell.net/forum/viewtopic.php?p=27961&sid=e793bf88f4ac6301869fea98aab54756#p27961 http://www.classicshell.net/forum/viewtopic.ph
by warbiscuit 10y ago
This comment (http://www.classicshell.net/forum/viewtopic.php?p=27961&sid=e793bf88f4ac6301869fea98aab54756#p27961 http://www.classicshell.net/forum/viewtopic.php?p=27961&sid=...) on the forum thread posted md5/sha1 checksums of clean & infected 4.3.0 installers (though it's not clear if those are only infected checksums).
ClassicShellSetup_4_3_0_clean.exe
MD5: e10881b65c27c6e09e5a33cd8bcd99c6
SHA1: a6b06d07fe3b1a7204b1b62c67fbf3c602385364
File size: 7220496 bytes
ClassicShellSetup_4_3_0_infected.exe
MD5: c67dff7c65792e6ea24aa748f34b9232
SHA1: 438b6fa7d5a2c7ca49837f403bcbb73c14d46a3e
File size: 7148732 bytes
- beefhash 10y agoAre the people over there sure that it's a good idea to rely on the broken[1] MD5 and the close-to-be-broken[2] SHA-1 for verifying checksums in the context of malicious actors? Though I guess the hashes and file sizes differ, so I guess this is just being pedantic. [1] https://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities https://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities [2] https://sites.google.com/site/itstheshappening/ https://sites.google.com/site/itstheshappening/
- Grom_PE 10y agoMD5 is broken in a sense that you can craft two different files with the same hash, but it's still hard to create a file with specific MD5 hash. So it's still good for identifying files that aren't specifically crafted to have a malicious counterpart.
- kalleboo 10y agoIt seems more reliable to check the developer signature in Properties on the EXE - the correct developer is "Ivaylo Beltchev". The infected download is unsigned and requires you to click through a warning.
- warbiscuit 10y agoThough annoyingly it's signed using sha1, not sha256. So if they were gonna put effort into making an sha1 collision, they'd probably target the signed payload, not the overall exe. Though it doesn't look like sha1 is that broken yet, for the budget of this grade of attacker.
- marcosdumay 10y agoFrom this use case, where one person makes a file, and then an attacker forges another one with the same hash, MD5 was just recently broken and SHA-1 is far from it. Also, it's not immediately clear if a pair of broken hashes is also broken or not (depends on many things, and I probably don't even know half of them). So, I'd say this is safe, for now. Yet, I also get bad feelings when somebody either comes with an MD5 hash or uses a SHA-1 as the most secure option.
- ultramancool 10y agoSomeone have a copy of the infected version? I'd like to take a look.
- deleted 10y ago[deleted]