Cracking md5 hash

Contributor
22Jan2010,02:41   #1
Toddie's Avatar
Here is a question that maybe you guys can help me with.

Suppose a user frequents 2 different websites.
Lets assume that user uses the same password for both sites.
lets also assume that both sites use an md5 hash to encrypt passwords.

one site is not vulnerable to sql injection
the other site is vulnerable to sql injection.

If you obtain the users md5 password hash on the vulnerable website, and you "crack" the hash, would the "crack" work on the other site that you were unable to sql inject?
Go4Expert Founder
22Jan2010,08:23   #2
shabbir's Avatar
Moved your query into separate forum and coming to your question.

It should work.
Security Expert
23Jan2010,13:58   #3
indiansword's Avatar
yes it shdu work as plan text passwords are same AS LONG AS both encryptions are md5.
Contributor
24Jan2010,08:41   #4
Deadly Ghos7's Avatar
yeah because for the same string, its md5 hash will always be the same so it will work definitely.
Know what you can do.
25Jan2010,17:14   #5
SpOonWiZaRd's Avatar
Just make sure its the same case...