Length Extension Attacks: How Hash-Based Signatures Can Be Forged

Length Extension Attacks: How Hash-Based Signatures Can Be Forged

What if it were possible to alter a message without knowing the secret associated with it and it still appeared entirely legitimate?It seems impossible; it’s believed that a secret will prevent you from producing something valid if you don’t know it.However, the way in which something is constructed can allow that to happen.That’s whereLength Extension Attacks come into play. This will be my first advanced-level article, so I hope you enjoy it! :)Introduction When an application wants to make sure that some data hasn’t been modified, it can create a hash of that data. For example, imagine an application receives: username=admin It can calculate a hash for this value and use it to detect whether the data has been changed. Hashing is a one-way process that takes some data and produces a fixed-size value. One of its important properties is that even a small change to the original data should produce a completely different hash. You can read more about hashing here But there is a problem. If an application simply uses: MD5(data) anyone can calculate the same hash. For example: MD5(admin) produces: 21232f297a57a5a743894a0e4a801fc3 So if an application uses the hash as a signature, an attacker could change: role=guest to: role=admin and simply calculate a new MD5 hash for admin : The application has no way to tell whether the hash was generated by the trusted server or by the attacker.Adding a Secret To solve this problem, an application may use a keyed hash. Instead of hashing only the data: MD5(data) the application adds a secret that only the server knows: MD5(SECRET + data) For example, imagine the server has the secret: ABC123 and the data is: admin The server would calculate: MD5(SECRET+DATA) = MD5(ABC123admin) The attacker knows: admin but doesn’t know: ABC123 So they cannot simply calculate the same signature. MD5(admin) --> 21232f297a57a5a743894a0e4a801fc3 MD5(ABC123admin) --> 294d07e02e3b2928c34081f19039725c No Before we dig deeper on the length Extension Attacks we need to udnerstand how the Hash is created to be able to understand it correctly Note: if you already familier with how hashes works you can skip this part How Hashes Are Made? We will demonstrate it using a simple hashing algorithm like MD5. First of all, you have the word you want to hash: abc The hashing function will convert it into UTF-8/ASCII bytes like this: 61 62 63 Then, the bytes are converted into binary bits: 01100001 01100010 01100011 Until now, we have 24 bits of data, but MD5 requires each block to be 512 bits in size. Here, we are coming to our first topic in the MD5 hashing process, which is padding. I will give you a simple example to give you an idea about what padding is. Step 1: Padding What Is Padding? Consider that you have a box containing sensitive and valuable things, such as expensive phones. Now, imagine that the delivery box is much larger than the phone inside it. When you put the phone inside the box, there will be empty space around it. So, you fill that empty space with materials such as foam or bubble wrap to protect the phone from being damaged during delivery. This is the same idea behind padding. Padding is used to add extra data to the original data so that it fits the required size or structure of the algorithm. For example, a hashing algorithm may process data in fixed-size blocks. If the data does not completely fill a block, padding is added to fill the remaining space. Padding is important because it allows the algorithm to process data correctly, regardless of the original size of the data. The hash function itself determines the length of the final hash. For example, MD5 always produces a 128-bit hash, while SHA-256 always produces a 256-bit hash. when padding the message after it was converted to bits it adds [1] that works as delimeter which separte between the orginal message and the padding , finally the last 64-bit of the 512-bit-block-size is resereved for the orignal message size [DATA BITS][1][ZERO PADDING][64-bit ORIGINAL LENGTH] Technical Note (you can skip it): 0 stores the original message length in 64 bits using little-endian byte order. For example, the length of abc is: 3 bytes × 8 = 24 bits 24 = 0x18 Because MD5 uses little-endian, the 64-bit length field is stored as: 18 00 00 00 00 00 00 00 Little-endian means the least significant byte is stored first. Step 2: Dividing the 512-bit Block For the MD5 algorithm, the 512-bit block is divided into 16 words, each containing 32 bits These 16 blocks are referred to using the letter M, and they are arranged from: M[0] to M[15] For example: M[0] = 32-bit M[1] = 32-bit M[2] = 32-bit M[3] = 32-bit M[4] = 32-bit ...... M[15] = 32-bit This step is important because these blocks are required for the hash calculations and rounds that come later. Step 3: The Initial State After dividing the 512-bit block into 16 smaller blocks, MD5 needs four main variables to use during the mathematical calculations and operations performed in the upcoming rounds. These four variables are called A, B, C, and D. You can think of them as the initial base state that MD5 starts with before it begins processing the message. The four variables have fixed initial values: A = 0x67452301 B = 0xefcdab89 C = 0x98badcfe D = 0x10325476 These values are used as the starting state for the calculations that happen during the MD5 rounds. During the rounds, MD5 performs different operations, such as AND, OR, XOR, and other mathematical and bitwise operations, using these variables and the message blocks. To better understand why these four variables are needed, imagine that you have a number such as 15 and you want to start performing several calculations on it. As a non-real example, you could imagine starting with: 15 + A where: A = 0x67452301 Then, you could imagine using the result in another calculation involving B: Result ÷ B This is not how MD5 actually works. It is only a simple example to demonstrate the idea of having several variables that are used as a starting state and then involved in calculations during the process. So, the main idea is that A, B, C, and D provide MD5 with its initial state, which is then used throughout the upcoming rounds while processing the message. Step 4: F/G/H/I Functions In this step, the four variables we initialized earlier: A = 0x67452301 B = 0xefcdab89 C = 0x98badcfe D = 0x10325476 are used together with four different functions. These functions perform different bitwise operations on the variables and are an important part of the MD5 rounds.The four functions are: F Function: F(B,C,D) = (B AND C) OR ((NOT B) AND D) G Function: G(B,C,D) = (B AND D) OR (C AND (NOT D)) H Function: H(B,C,D) = B XOR C XOR D I Function: I(B,C,D) = C XOR (B OR (NOT D)) Each function uses the values of B, C, and D and performs a different combination of bitwise operations such as AND, OR, NOT, and XOR.You can think of these functions as different ways of mixing the bits of the variables together. The result of these operations is then used during the MD5 rounds to transform the internal state as the algorithm processes the message. Step 5: First MD5 rotation In this case I will not go through the entire calculation step by step since the calculations can become rather complicated; instead I’ll explain what takes place in the first operation of an MD5 round. We should first understand two important points — K[0] and s — as well as the LEFTROTATE operation. K[0] — The Constant The MD5 algorithm makes use of 64 pre-determined constants, with each constant corresponding to one of the operations. These constants are known as K[0] to K[63]. For the first operation, MD5 uses: K[0] = 0xd76aa478 A constant is merely a value that has been predefined and is then included in the calculation when the operation is performed. Each different operation makes use of a different constant. s — The Shift Amount The value of s is the number of positions by which the bits will be rotated during the LEFTROTATE operation. The MD5 algorithm employs different rotation amounts depending on the operation, and s indicates to the algorithm how many positions the bits should be rotated to the left. LEFTROTATE LEFTROTATE refers to the circular rotation of the bits to the left. For example, imagine we have only 4bits: [B1][B2][B3][B4] If we perform a left rotation by 2 positions: [B1][B2][B3][B4] ↓ [B2][B3][B4][B1] The key point between LEFTROTATE and a simple left shift is that the bits which exit from the left side are not discarded; instead, they are transferred to the right side. So, the bits are rotated in a circle: 10110001 Now we can understand the complete formula used in the first MD5 operation: A = B + LEFTROTATE(A + F(B,C,D) + M[0] + K[0], s) Each part has a specific purpose: Where: A, B, C, and D — the four internal variables.000000000000000000000 The F function — the one that is used for combining the bits of B, C, and D. M[0] — stands for the first 32-bit block of the message. K[0] — the predefined constant for this operation. s — the number of positions taken for the left rotation. LEFTROTATE — the bits are rotated to the left in a circular manner. This operation is merely a single one; MD5 carries out this process many times, each time using different message words, constants, rotation amounts, and functions. The internal state is gradually transformed through these repeated operations until the final MD5 hash is obtained. Step 6: Repeating the Operations If you did not fully understand Step 5, the main purpose of that step was to update the working state. We start with four working variables: A B C D For each operation, MD5 calculates a temporary value using the current values of A, B, C, and D, together with a message word and a constant. For the first operation, MD5 uses M[0] and K[0]: T = A + F(B,C,D) + M[0] + K[0] Then the working variables are updated: A = D D = C C = B B = B + LEFTROTATE(T, 7) This produces a new working state. The important thing is that we do not return to the original values of A, B, C, and D. The values produced by one operation become the input for the next operation. Second Operation For the second operation, we use the latest values of A, B, C, and D. This time, MD5 uses M[1], K[1], and a different rotation amount: T = A + F(B,C,D) + M[1] + K[1] Then: A = D D = C C = B B = B + LEFTROTATE(T, 12) Again, the resulting values become the working state for the next operation. Third Operation The third operation follows the same process, but uses M[2], K[2], and a different rotation amount: T = A + F(B,C,D) + M[2] + K[2] Then: A = D D = C C = B B = B + LEFTROTATE(T, 17) Fourth Operation The fourth operation uses M[3] and K[3]: T = A + F(B,C,D) + M[3] + K[3] Then: A = D D = C C = B B = B + LEFTROTATE(T, 22) At this point, four operations have been completed. What happens next? We continue applying the same process using the latest working state produced by the previous operation. During Round 1, MD5 uses the 16 message words in this order: M[0], M[1], M[2], M[3], M[4], M[5], M[6], M[7], M[8], M[9], M[10], M[11], M[12], M[13], M[14], M[15] For example, the fifth operation uses M[4]: T = A + F(B,C,D) + M[4] + K[4] A = D D = C C = B B = B + LEFTROTATE(T, 7) The sixth operation uses M[5]: T = A + F(B,C,D) + M[5] + K[5] A = D D = C C = B B = B + LEFTROTATE(T, 12) The same process continues until all 16 message words have been processed. The important idea is that every operation uses the latest values of A, B, C, and D produced by the previous operation. Conceptually: Initial State Operation 1 Updated State Operation 2 Updated State Operation 3 Updated State ... Operation 16 Updated State After these 16 operations are completed, Round 1 is complete. MD5 then moves to Round 2. In Round 2, it uses the G function instead of F, and it also uses a different order for selecting the message words. Step 7: Rounds 2, 3, and 4 After completing Round 1, we end up with a new set of values for the internal state. We can call these the current state: A = A1 B = B1 C = C1 D = D1 MD5 then uses this current state as the starting point for Round 2. It does not go back to the original initial state. However, Round 2 is slightly different from Round 1: It uses the G function instead of the F function, which mixes the bits in a different way. It uses the same 16 message words, M[0] to M[15], but in a different order. It also uses different constants and rotation amounts. After completing the 16 operations of Round 2, we get another updated state: A = A2 B = B2 C = C2 D = D2 The same idea continues in the next two rounds. Round 3 Round 3 uses the H function and another ordering of the message words. ROUND 3 Function: H Message word order: Different Result: A = A3 B = B3 C = C3 D = D3 Round 4 Round 4 uses the I function and another message word order. ROUND 4 Function: I Message word order: Different Result: A = A4 B = B4 C = C4 D = D4 After completing all four rounds, we end up with: A = A4 B = B4 C = C4 D = D4 These four values together are called the Final State. Step 8: MD5 Digest After completing all four rounds, we have the Final State: A = A_FINAL B = B_FINAL C = C_FINAL D = D_FINAL Now, MD5 combines each final value with its corresponding Initial State value. The addition is performed separately for each variable: A_RESULT = A_FINAL + A_INITIAL B_RESULT = B_FINAL + B_INITIAL C_RESULT = C_FINAL + C_INITIAL D_RESULT = D_FINAL + D_INITIAL Each addition is performed modulo 2^32, so every result remains a 32-bit value. Therefore: A_RESULT = 32 bits B_RESULT = 32 bits C_RESULT = 32 bits D_RESULT = 32 bits We then concatenate these four 32-bit results: A_RESULT || B_RESULT || C_RESULT || D_RESULT So: 32 + 32 + 32 + 32 = 128 bits This 128-bit value is called the MD5 digest. Finally, the digest is represented in hexadecimal. Since every 4 bits can be represented by one hexadecimal digit: 128 bits ÷ 4 = 32 hexadecimal digits So the final MD5 hash is a 32-character hexadecimal string. Final Notes If the data is larger than 512 bits, MD5 divides it into multiple 512-bit blocks. Each block is then divided into 16 words, with each word containing 32 bits: BLOCK 1: [M[0] ... M[15]] BLOCK 2: [M[0] ... M[15]] BLOCK 3: [M[0] ... M[15]] The M[0] to M[15] labels start again for every new block because they refer to the 16 words inside the current block. When MD5 finishes processing the first block, we get: A = A4 B = B4 C = C4 D = D4 These values are not the final state of the entire hash yet. Instead, they become the initial state for processing the next block: Block 1 -> 64 operations -> A4 B4 C4 D4 -> Initial State for Block 2 -> Block 2 -> 64 operations -> New State This process continues until all blocks have been processed. Therefore, the Final State used to produce the MD5 digest is the state obtained after processing the last block, not necessarily the state obtained after the first block. I know that understanding a hashing algorithm can be difficult at first, especially with all the new concepts such as padding, initial states, internal states, rounds, operations, and functions. However, these concepts are essential when studying hash-based attacks such as hash collisions and length extension attacks, because understanding how the hashing process works makes it much easier to understand how these attacks work. Returning Back Now that we have understood how hashes work using the MD5 algorithm, it is time to take a closer look at Length Extension Attacks. What Is a Length Extension Attack? A Length Extension Attack is an attack that allows an attacker to append new data to a keyed hash without knowing the secret key, while still being able to calculate a valid hash for the modified data. For example, imagine that an application hashes the following data: hello using a secret: MD5(SECRET || hello) The server gives you the resulting hash, but you do not know the value of SECRET. Now, imagine that you want to append: world to the original data and calculate a valid hash for the new message without knowing the server's secret. To understand why this is significant, let's look at a practical example. A Banking Example Consider a banking website where you log in and receive your bank account ID along with a signature for it. The signature is used to ensure that the account ID has not been modified. When you want to access your bank account information, you send a request such as: https://my-hacker-bank.com/bank?id=12&signature=7ac71959e1b405974b059694c83e5c5c The signature is a keyed hash generated like this: MD5(SECRET || ?id=12) Resulting in: 7ac71959e1b405974b059694c83e5c5c The signature is required because the server wants to make sure that the id parameter has not been tampered with. When the server receives: https://my-hacker-bank.com/bank?id=12&signature=7ac71959e1b405974b059694c83e5c5c it takes the data: ?id=12 and hashes it together with the secret: MD5(SECRET || ?id=12) If the resulting hash is equal to the provided signature, the server assumes that the data has not been modified and that the request contains the valid bank account ID. However, imagine that an attacker changes the request to: https://my-hacker-bank.com/bank?id=1&signature=7ac71959e1b405974b059694c83e5c5c The server will calculate: MD5(SECRET || ?id=1) This result will not be equal to: 7ac71959e1b405974b059694c83e5c5c Therefore, the signature verification fails. The attacker cannot simply generate a new valid signature because they do not know the server's secret. And this is where the Length Extension Attack becomes interesting. Breaking Down the Ice Now that we understand both: The MD5 hashing algorithm Why Length Extension Attacks are needed it is time to understand how the vulnerability works and how Length Extension Attacks are performed. The Final State As we said earlier, after processing the final block, MD5 produces the final chaining state, which is represented by the resulting values:A_RESULT = (A_FINAL (A_WORK) + A_INITIAL) mod 2³² B_RESULT = (B_FINAL (B_WORK) + B_INITIAL) mod 2³² C_RESULT = (C_FINAL (C_WORK) + C_INITIAL) mod 2³² D_RESULT = (D_FINAL (D_WORK) + D_INITIAL) mod 2³² The values obtained (A_RESULT, B_RESULT, C_RESULT, D_RESULT) constitute the final MD5 digest. We can use these values as the current internal state and continue the MD5 computation using additional data, rather than starting again from the original initial state. In other words, the digest represents the state that MD5 reached after processing the original message. We can treat this state as the starting point when processing the appended data. For example, imagine we have two blocks: ABC123 XYZ456 The first block: ABC123 is processed using the initial states: A_INITIAL B_INITIAL C_INITIAL D_INITIAL After processing this block, MD5 produces a new set of states: A_STATE B_STATE C_STATE D_STATE These states are then used as the current state when processing the next block: XYZ456 So, conceptually: Initial State ABC123 - ROUNDS New State XYZ456 - ROUNDS Final State If there is another block after XYZ456, the state produced from XYZ456 becomes the current state for the next block. If there are no more blocks, that state becomes the Final State. This is the important part. After MD5 finishes hashing a message, it returns the final digest. That digest allows us to recover the final internal state of the MD5 computation. If an attacker can recover this final state from the digest, they can use it as the current state for processing additional data. So instead of starting MD5 from the original initial state: Initial State Original Message New Data the attacker can conceptually continue from the state where MD5 stopped: Original Message Final State New Data New Final State But Why Do We Do This? The reason we do this is that we do not know the server's secret. Normally, if we wanted to calculate a new valid hash, we would need to start from the beginning: MD5(SECRET || Original Data || New Data) But the SECRET is unknown to us, so we cannot perform the hashing process from the beginning. Instead, we take advantage of the fact that the final state is exposed through the MD5 digest. We recover that state from the original digest and use it as the current state for processing our new data. This means that we do not need to know the secret or calculate the original message again from the beginning. We can continue the MD5 computation from where the server's hashing process stopped. And this is the fundamental idea behind a Length Extension Attack. Requirements to Perform Length Extension Attacks To perform a Length Extension Attack, we need a few important pieces of information. 1. The Original Message and the Secret's Length We need to know the length of both the original message and the secret. Why? Because MD5 adds padding to the message before processing it. The padding depends on the total length of: SECRET + Original Message We need this length so we can calculate exactly where the original MD5 message ended and reconstruct the padding that MD5 would have added. The resulting structure will look like: SECRET || Original Message || Padding || New Data The padding is important because we are trying to continue the hashing process from the state reached after the original padded message. We do not know the SECRET itself, but knowing or guessing its length allows us to calculate the correct padding. 2. The Original Message Itself We also need the original message. The original message is required because its length is part of the calculation used to determine the correct MD5 padding. It is also included when constructing the final message that we want the server to process: Original Message || Padding || New Data The important thing to remember is that we are not recovering the secret. We only need its length so that we can reconstruct the correct padding and continue the MD5 computation from the recovered internal state. Length Extension Attack Having now understood the requirements and the way the MD5 internal state works, let's go on to consider what actually takes place in a Length Extension Attack, step by step. The goal is to take a valid signature generated from: MD5(SECRET || Original Message) and create a valid signature for: MD5(SECRET || Original Message || Padding || New Data) 1. Obtaining the Requirements The first thing to do is to gather the information required in order to carry out the attack. We need: The original message The original signature The length of the secret, or a range of possible secret lengths What the original message generally is is something that we can already see. For example: user=auditor&role=user The hardest aspect is the secret. It is not necessary for us to know the actual value of the secret; all we need to know is its length since the MD5 padding relies on the total length of: SECRET || Original Message When the length of the secret is not known, an attacker is often able to guess or use brute force to determine the possible length of the secret. For example: Secret length = 16 Secret length = 17 Secret length = 18 ... Secret length = 40 We can determine a separate padding value for each possible length and thus produce a different candidate signature. When the application provides a method of checking whether the signature is valid, we will be able to tell which secret length was the correct one. So the important distinction is: What we are doing is not trying out all the possible secrets; we are attempting to determine the length of the secret. Having the original message and a possible secret length, we can determine the padding which MD5 would have added to the original message. 2. Obtaining the Signature Itself The next essential requirement is to get the original signature. For example, imagine the server gives us: Message: user=auditor&role=user and its signature: 9cdc8cbee716e38a1549f52a797fc4466e826097 The server originally calculated something equivalent to: MD5(SECRET || user=auditor&role=user) We do not know the SECRET, but we do have the digest obtained as a result. This signature is of great importance since the MD5 digest enables us to obtain the final internal state of the hash. It means that the signature serves not only to verify the original message. It also provides us with the state against which we can carry on the MD5 computation. 3. Obtaining the Final State from the Hash We now have to obtain the last internal state that MD5 attained after the original message had been processed. As we discussed earlier, MD5 finishes with four internal state values: A_FINAL B_FINAL C_FINAL D_FINAL The final digest is produced by adding these values to the original initial states: A_RESULT = (A_FINAL + A_INITIAL) mod 2³² B_RESULT = (B_FINAL + B_INITIAL) mod 2³² C_RESULT = (C_FINAL + C_INITIAL) mod 2³² D_RESULT = (D_FINAL + D_INITIAL) mod 2³² Therefore, we can reverse this operation: A_FINAL = (A_RESULT - A_INITIAL) mod 2³² B_FINAL = (B_RESULT - B_INITIAL) mod 2³² C_FINAL = (C_RESULT - C_INITIAL) mod 2³² D_FINAL = (D_RESULT - D_INITIAL) mod 2³² This gives us: A_FINAL B_FINAL C_FINAL D_FINAL The four values are the state that MD5 reached after it had processed both the original message and the padding. The state which we desire to reuse is this. 4. The construction of the new string We now have to create the message that we want the server to carry out. It is at this point that the importance of MD5 padding comes into play. The original server calculation was conceptually: SECRET || Original Message || Padding The MD5 algorithm processed the whole structure and finally arrived at the end state. We don't know the SECRET, but if we know its length, we can calculate the padding that would have been added after: SECRET || Original Message We then construct our new message as: Original Message || Padding || New Data For example: user=auditor&role=user [MD5 padding] &role=admin It is important that the padding bytes are there since they stand for the padding which had already been processed as part of the original MD5 computation. The complete structure that the server effectively processes becomes: SECRET || Original Message || Padding || New Data The attacker needn't know or send the secret. The attacker only needs to construct: Original Message || Padding || New Data The most important stage in the assault is now reached. Normally, when MD5 starts hashing a new message, it starts with: A_INITIAL B_INITIAL C_INITIAL D_INITIAL However, we are not going to begin at the start. We already know the state where the original MD5 computation stopped: A_FINAL B_FINAL C_FINAL D_FINAL Therefore we take these values to be the current state when we process the new data. Conceptually, the process is: Originally, the MD5 algorithm takes in both the secret and the original message. MD5 adds the padding it needs. The MD5 algorithm arrives at its final internal state. It is possible to reconstruct that state from the original digest. We take that state to be the current state. We carry out the processing of the data that we have just added. The MD5 algorithm results in a new final state. From that condition we get the new signature. The key thing is that we are carrying on with the MD5 computation rather than starting it all over from the beginning. Putting Everything Together The complete Length Extension Attack can be summarized as: Get the original message. Get the original MD5 signature. Work out or estimate the secret length. Work out the amount of padding that would have been added to 'SECRET || Original Message' by MD5.From the original digest extract the four internal states. Take those values and use them as the current state. Form the new message as: Original Message || Padding || New Data Use the extracted state to carry on the MD5 calculation. Work out the new signature. Send the altered message together with the new signature to the server. The attacker never needs to discover the actual SECRET Rather, the attack takes advantage of the fact that the MD5 digest reveals sufficient information about the internal state to enable the hashing process to be carried on. That is the basic concept that underlies a Length Extension Attack. Final Result When doing these steps with real data, knowing that its secret length is 6, like: ?username=auditor&role=user and append: &role=admin with the hash: 74acb4f440c1f28e592c837c940cfc83 all these steps will output two things: 1. The String %3fusername%3dauditor%26role%3duser%80%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%08%01%00%00%00%00%00%00%26role%3dadmin Notice that the padding was added to the real string to process it as real data, not as padding. 2. The Signature The signature after adding &role=admin to it: 5c0a27fb141affe2e67d59da1e675520 Note: The final &role=admin can override the first role value, depending on how the application parses duplicate parameters, so the application may use admin instead of user. Automate It As this process is very complicated to do manually, I prefer to automate it using a tool like hash_extender. The tool can be downloaded using: git clone https://github.com/iagox86/hash_extender.git example usage: ./hash_extender --data '?username=auditor&role=user' --signature 74acb4f440c1f28e592c837c940cfc83 --append '&role=admin' -l 6 --out-data-format=html breakdown: --data --> represents the original message --signature --> represents the hash-signature --appened -- > the part you want to append to the original message -l --> represents the secret's length --out-data-format=html --> tell hash_extender you want the output-string to be in the html-encoded formate Length Extension Attack Impact The vulnerability of this kind may be hard to spot without having access to the source code, but it can still have a great effect depending on where the signature is used. A Length Extension Attack becomes possible when an application uses a vulnerable hashing algorithm, such as: MD5 SHA-1 It does not follow that an application is vulnerable just because one of these algorithms is used. The method of constructing the hash and the way in which the resulting signature is used are also significant. The extent of the impact will depend on the meaning of the data in question and on the extent to which the application permits that data to be controlled. In the case where the signature is employed to guard against alterations to sensitive parameters, an attacker could possibly change the application's behaviour by modifying the data while still producing a valid signature and thus without knowing the secret. For instance, if a signature is employed to guard parameters concerning permissions, account settings, transactions, or other sensitive actions, the result could be far more serious than merely altering an ordinary piece of data. That is the reason by which the effect of a Length Extension Attack cannot be assessed merely from the hashing algorithm; the actual impact varies according to the thing that is being signed, the way in which the signature is generated, and the actions carried out by the application after having verified it. Final Notes I hope you've enjoyed it and have learned something new during your journey through this highly advanced article. I realize that these topics can be difficult even for those who already know something about cryptography; yet a thorough understanding of such small points can be very useful to security researchers and hackers in particular when dealing with real-world vulnerabilities. It is not necessary to remember all the formulas or understand all the internal details right away. What's important is to understand how these concepts function and the reason why they can cause actual security problems. for contact, you can reach me out here Finally as i Always say : play it legal , my friend ;)

Original Source

Read the full article at Hackernoon →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.