|
|
|
|
|
by Someone1234
4291 days ago
|
|
> Notice that the two colliding exe are exactly the same file size. These attacks have only gotten better. They're also 6, not 200+ KB. They have been specially crafted to be as small as possible to make the problem set as easy as possible. > The example I gave uses windows and linux executables. No zip files in sight. These attacks are from 2009. That's a really strange reply. What is it you think I said..? I said and to quote you quoting me: "'Really any format which can take arbitrary metadata (which is MOST) is pretty easy.'" So why you felt the need to point out that it is an executable not a zip file is uhh strange to say the least... |
|
That is not how it works, MD5 is vulnerable to length extension attacks[0]. Once you collide part of an MD5 hash, if everything that follows that collision is the same, it can be as long as you want. Colliding large files is just as easy as colliding small files. You could perform the same exercise with 1GB executables.
[0]: http://en.wikipedia.org/wiki/Length_extension_attack