📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  Cracking WinRar SFX

Topic created on: October 14, 2007 02:40 CDT by djnemo .

Hi ...
is anyone try to crack winRar SFX files (mean for finding/Bypassing password don't brute force them) ?
are they crack able or not is it Possible to do So?

Tanx Nemo :-x

  nezumi     October 14, 2007 06:34.19 CDT
there is no easy way to do that. there're many rar password cracker (most of them are commercial and want money). the best crackers use very complicated crypto-algorithms and work a bit faster, but if you have no enough CPU power (thousands CPU) you have no chance unless password is quite short or predictable.
use Advanced RAR Password Recovery. IMHO it's the best rar cracker, however, may be I'm totally wrong, so, don't listen me and try another one :)

  MohammadHosein     October 14, 2007 13:09.59 CDT
i never saw any Published work on Rar Algorithm re , but since its not one-way and its symmetric bypassing the whole algorithm without bruteforce is not impossible , theoretically

  nezumi     October 14, 2007 14:25.17 CDT
many researchers analyzed WinRAR. if you want to know how to attack WinRAR just google and read :-) check out the follow paper for example: On the Security of the WinRAR Encryption Method Gary S.-W. Yeo and Raphael C.-W. Phan

there're rumors about super-key allows to decrypt _any_ WinRAR archive, knowing only to Eugene Roshal (the creator of the WinRAR) and probably to Government guys. personally, I don't believe into this. As far as I know, WinRAR uses AES-128bit, and it's very hard to hide back-door inside it. but, I have no guarantee that WinRAR uses standard AES algorithm. I was researching it for years and had found some strange differences between standard AES algorithm and WinRAR AES-like realization. but I don't know much about AES, so, maybe it's just some soft of optimization or something like that. I'm not a crypto-expert.

I just want to say: you have only two way to solve the problem: attack password or 128-bit AES keys themself. but remember that different files of the archive crypted with the different AES keys (and maybe different parts of the single file use different AES keys too! - I just don't remember).

by the way, part of the WinRAR sources are opened, another - still closed, so you have to disassemble the rest (like I did).

I have not found neither back-door, nor faster way to break encryption (well, back in old days I wrote the fastest password finder, but it was very buggy and I had no time to fix bugs, so it was never public-released).

however, if you own a big net of drones, you have a chance to decrypt archive before you die, but even death can be untrue. just remember, WinRar uses salt to prevent you from using pre-calculated tables, like help us to break other chippers like MD5 for example (see, http://distributed.ru/?pro.rc or its google translation distributed computing project

I never saw better crypter than WinRAR (at least version 3.xx and above).

p.s. don't forget dictionary attack. most passwords are not absolute random.

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit