Title: MD5 Algorithm Brute Force Hash Exhaustion Cryptanalysis Compromise
Info
Disclosure
Jan 04, 2009
Discovery
Unknown
Dates
Exploit
Jan 04, 2009
Solution
Unknown
Description
The MD5 encryption algorithm has been compromised through a real-world, practical, low-cost attack. Using consumer-grade hardware, MD5 hashes can be generated at over 258.7 million hashes per second, allowing an attacker to reasonably exhaust password keyspace in a trivial amount of time. Using pre-computed hash tables, the disclosure of a MD5 password hash typically means that the password has been cracked.
Classification
Location:
Context Dependent
Attack Type:
Cryptographic
Impact:
Loss of Integrity
Solution:
Discontinued Product
Exploit:
Exploit Public
Disclosure:
Third-party Verified
Solution
Due to the encryption algorithm being compromised through cryptanalysis, it is generally accepted that it should no longer be used. It is recommended that an alternate, stronger algorithm be used to ensure data is properly protected.