7 ms·
The URLs of the images seem to be a combination of a MD5 hash and an ID (changing the ID will produce a different image). I guess the point is that only machine
by chpmrc 6y ago
The URLs of the images seem to be a combination of a MD5 hash and an ID (changing the ID will produce a different image). I guess the point is that only machines can reverse MD5 to get the actual "image name"?
- Topgamer7 6y agoThere is no reversing of an md5 hash. You can try to cause a hash collision, or brute force compute it, but you can't turn something like 40 bytes of data into 100 for example.
- gowld 6y agoRainbow table: https://en.wikipedia.org/wiki/Rainbow_table https://en.wikipedia.org/wiki/Rainbow_table
- pc86 6y agoThis still isn't reversing a hash.
- chpmrc 6y agoA one way function cannot be reversed by definition. I obviously meant finding a set of possible strings that produce that hash and one of them will likely be the image name. "Reverse" wasn't the perfectly accuarate word to use but sometimes a bit of intuition goes a long way.
- vivekseth 6y agoHashes are inherently lossy. Although a rainbow table can maybe tell you one possible input for a given hash, it cannot tell you exactly what was hashed.
- maerF0x0 6y agobut in the case of hashes -> URL there is a fairly reasonable rule set of what constitutes a plausible reversal. Therefore generated collisions could be reality checked, unlike other things (like a md5 of an encrypted file)
- kristopolous 6y agoThe sounds like a great research topic
- chpmrc 6y agoObviously I don't mean implementing a function that does f(md5(str)) => str in O(1) but rather performing a dictionary or brute force attack.
- skizm 6y agoYou can't reverse most hashes, you can just check if one thing's hash is the same as another thing's hash. If they are, they're probably the same thing.
- aaomidi 6y agoIf you can reverse a hash, its not a hash.
- skizm 6y agoTheoretically, no, but in practice if you know that "password123" hashes to "blaHb1ah" then you get a DB of hashed passwords and see "blaHb1ah", you probably know that person's password is "password123". (which is why you use salts to fix that). For all intents and purposes I just reversed the hash in this context.
- aaomidi 6y agoKinda? But there's infinite number of other things that will hash to that same value. So you can assume (probably with good certainty) that you've got the correct password, but you can't be sure. So pedantically speaking, it's not really reversible.
- zamfi 6y ago> So you can assume (probably with good certainty) that you've got the correct password, but you can't be sure. That's assuming no other constraints. If the constraints on the password are strong enough (for example, must include letters, numbers, special characters, and be less than 30 characters) that there really may be only one input that satisfies those constraints and also hashes to the found value.
- aaomidi 6y ago100% true.
- 6y ago