Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Cracking Base64 Passwords Perl Script.

From: Singapore Dragon <dragon(at)securityassoc.com>
Date: Sun Nov 10 2002 - 21:40:27 EST


Tool to crack Base64 passwords - could not find anything similar on the Internet.

Download Tool: http://www.securityassoc.com/base64_crack.zip

MD5 Hash: D905C844168D4D2D1755C1393E18CC96

Below from Readme.txt file:

Base64 Encoding


While pen testing and looking around for something to crack a Base64 encoded password I could not find much in the way of a simple script, so I decided to right a Perl script myself...

Many weak security mechanisms rely on base64 encoding scheme. IIS server is one such example, from the below example we see IIS Basic authenication in action on a GET request:

GET / HTTP/1.1
Host: iis-server
Authorization: Basic dGVzdDpwYXNzd29yZA==

Do you need help?X

The authorization tag is encoded in Base64 and when feed into the decode script is cracked as shown below:

perl decode_base64.pl dGVzdDpwYXNzd29yZA==

 Author: The Singapore Dragon - dragon@securityassoc.com  Web: www.securityassoc.com

 Usage decode_base64.pl [encoded-text]

 The decoded data is: test:password

There is also another script provided to encode data (encode_base64.pl).

Enjoy and please send comments...

The Singapore Dragon
dragon@securityassoc.com Received on Fri Nov 15 18:28:58 2002

Do you need more help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:47 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library