pem2john and PEM formats blindly assume SHA-1 instead of encoding/using actual "prf algorithm" (can be SHA-256)
Open
Nobody has claimed this yet.
bug
enhancement
- Dominant language
- C
- Stars
- 13.6k
- Forks
- 2.6k
- PR merge metrics
- No merged PRs in 30d
Description
While working on #4833 I encountered a problem with cracking openssl encrypted private key files. It does work with the example key but not with a newly generated test key. The password is "test".
> openssl req -newkey rsa:2048 -keyout keynamehere.key -out csrnamehere.key
Generating a RSA private key
................................+++++
..........................................+++++
writing new private key to 'keynamehere.key'
Enter PEM pass phrase:
Verifying - Enter PEM pass phrase:
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:
State or Province Name (full name) []:
Locality Name (eg, city) [Default City]:
Organization Name (eg, company) [Default Company Ltd]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:
Email Address []:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
> cat keynamehere.key
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIDow6HN28d5ACAggA
MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECEwJ2k3MnATOBIIEyE04z3UvKMus
5bRcTpU6CWgPIbAhyclZpvr6oI62hr6sMkMqQaq3q3Y1JN5W8C64PLJkS7yTAKIf
k1NT/mFFvFn2i+V+SYgF7TUHERJugZeLwl3BGsvBLpgvW5QKr3vuCEWNAlcFFBH9
7hoKXscuyOIIh0yrceCH3/2SMT1eHy/WdxARrEuX+5oPkQYFp0DDI/EnMtB7MBPh
6Ss7R+Ho73EUI+Zw/yxEQmtbFLdOrALe8DhFO5RD9zZoV7q311MnJuHb/ISrF5Rg
srKXIZyx4cB+kHV5d881sAw/4DwA+1k5ZdMRWoZ5Ha7iYGOmjOlgKO9lodPeFRuE
aVBFViCUQ5SDeBbVzJ1e8xyaui247ylAmX/HTI/hlxtmUQVj80x0vC5zQn5MGtUR
0/lH8SYnIHQLWNtnJDo0R3nxIqe4gDdHsiQpBEJ0rjSgLtNhLz5qoAL2SQanwrjr
GZhA3XsRuNUz8c5xd5qN0HmF5kN5fSQqbrUge0pGuudG6bs+/wVdGhwlg4X4mBlJ
U5jUGftZiqvpPqtciG1lom/TdXQ5b487fNQFCAwtGAPHKjJSmYp+MzvULpzvSqbr
z1DLUOxrrCJFD1PqCkfxxIsLwS0Gzx053CaPJpfYULbbjx5T1WZd0lk8M0eNsh3w
sc9T5wP+YQyC+PuI5nAwvcYy8UaWaQBDlLg71vzgzObOcpIJQxG8DgvcRRL6sz5L
gvQMYXo2E6UUQXxmz32r8bRWL0J7ObQ89Q8HRc+hW0ovYV8TS9uUU5qPFYi6bzoj
FtvSrViG1dw5uyzM3/1swp+hGg+k2LtkNa26IZb9S/D5s5p8DBH7ud2G+yFRUNJD
F+FuE3DyryB43DFVQw1gEjYPFUhQWG/5TUMCln6hBjEMREB7KcN40XZ+srXhgq6+
88O2gUH0PhHpkZTujO20OUQhU5mEmHcCdA68L9jsNQ2vqq73scRfrnFdHZroXqHG
SExIG254UpsoHsw568s0kuGxYNvAxe4VGMqu5RmeOZgaS4BodZbTec/tq1leh7Bk
ClFdg4mpLm+pKxroA+siOtJyCkYjPHJW1s5zn4GofOuuq69KKul8k3O0/8H4DJEW
+I/cbI9CZRJa2aLQTyPPaZPjPsmUCnlZP1P8iJ+K4VcwtbfSADv9cqDsFjq7NpJS
V5PnGTeLdhx2J6cVJc51sKdVZYwYE6JbPZcEBaU1mLPDxOFcmkrqDHnoL6cMsAwa
PRL9J/mfL6yhPRInObj9Q9OOTdMq5ERzUCOZPYn4m0SA4P8Pd7NgZ2Y57+jsylkF
+wCshTTK9Kw4X3qBS0PcGC2dM6MOZDesVoZBXCPjYUJKgORDJyoCFMC9XY7CaCNp
6wUdDX08cZTJP35PA8c47uDbHchHFSb54xeOTIhxb+CQhskdxXwtpkR5C9XBCHYY
0C0z7BLrylhH7Us2E6NCZJ+2DKX+LNJZxn144rzU61Zn4l4UNLvscF41V5O9Cxua
r/TX4hZOadeXt3KM/GdH5GqJuxRg4bLG7p3MXuP9MQV8Wr3K2gHVfeuEJv20FfPP
KDX/Eqzj8k/4eNeE3MS4djFvEp6uJqFCsVJetRAzsXoj8TaVSQUxqlA1cdqouO99
EDcLtzI/hMEhKaEnM6y7Ug==
-----END ENCRYPTED PRIVATE KEY-----
> ~/Downloads/repos/john/run/pem2john.py keynamehere.key | tee hash
$PEM$1$1$0e8c3a1cddbc7790$2048$4c09da4dcc9c04ce$1224$4d38cf752f28cbace5b45c4e953a09680f21b021c9c959a6fafaa08eb686beac32432a41aab7ab763524de56f02eb83cb2644bbc9300a21f935353fe6145bc59f68be57e498805ed350711126e81978bc25dc11acbc12e982f5b940aaf7bee08458d0257051411fdee1a0a5ec72ec8e208874cab71e087dffd92313d5e1f2fd6771011ac4b97fb9a0f910605a740c323f12732d07b3013e1e92b3b47e1e8ef711423e670ff2c44426b5b14b74eac02def038453b9443f7366857bab7d7532726e1dbfc84ab179460b2b297219cb1e1c07e90757977cf35b00c3fe03c00fb593965d3115a86791daee26063a68ce96028ef65a1d3de151b846950455620944394837816d5cc9d5ef31c9aba2db8ef2940997fc74c8fe1971b66510563f34c74bc2e73427e4c1ad511d3f947f1262720740b58db67243a344779f122a7b8803747b22429044274ae34a02ed3612f3e6aa002f64906a7c2b8eb199840dd7b11b8d533f1ce71779a8dd07985e643797d242a6eb5207b4a46bae746e9bb3eff055d1a1c258385f89819495398d419fb598aabe93eab5c886d65a26fd37574396f8f3b7cd405080c2d1803c72a3252998a7e333bd42e9cef4aa6ebcf50cb50ec6bac22450f53ea0a47f1c48b0bc12d06cf1d39dc268f2697d850b6db8f1e53d5665dd2593c33478db21df0b1cf53e703fe610c82f8fb88e67030bdc632f1469669004394b83bd6fce0cce6ce7292094311bc0e0bdc4512fab33e4b82f40c617a3613a514417c66cf7dabf1b4562f427b39b43cf50f0745cfa15b4a2f615f134bdb94539a8f1588ba6f3a2316dbd2ad5886d5dc39bb2cccdffd6cc29fa11a0fa4d8bb6435adba2196fd4bf0f9b39a7c0c11fbb9dd86fb215150d24317e16e1370f2af2078dc3155430d6012360f154850586ff94d4302967ea106310c44407b29c378d1767eb2b5e182aebef3c3b68141f43e11e99194ee8cedb4394421539984987702740ebc2fd8ec350dafaaaef7b1c45fae715d1d9ae85ea1c6484c481b6e78529b281ecc39ebcb3492e1b160dbc0c5ee1518caaee5199e39981a4b80687596d379cfedab595e87b0640a515d8389a92e6fa92b1ae803eb223ad2720a46233c7256d6ce739f81a87cebaeabaf4a2ae97c9373b4ffc1f80c9116f88fdc6c8f4265125ad9a2d04f23cf6993e33ec9940a79593f53fc889f8ae15730b5b7d2003bfd72a0ec163abb3692525793e719378b761c7627a71525ce75b0a755658c1813a25b3d970405a53598b3c3c4e15c9a4aea0c79e82fa70cb00c1a3d12fd27f99f2faca13d122739b8fd43d38e4dd32ae444735023993d89f89b4480e0ff0f77b360676639efe8ecca5905fb00ac8534caf4ac385f7a814b43dc182d9d33a30e6437ac5686415c23e361424a80e443272a0214c0bd5d8ec2682369eb051d0d7d3c7194c93f7e4f03c738eee0db1dc8471526f9e3178e4c88716fe09086c91dc57c2da644790bd5c1087618d02d33ec12ebca5847ed4b3613a342649fb60ca5fe2cd259c67d78e2bcd4eb5667e25e1434bbec705e355793bd0b1b9aaff4d7e2164e69d797b7728cfc6747e46a89bb1460e1b2c6ee9dcc5ee3fd31057c5abdcada01d57deb8426fdb415f3cf2835ff12ace3f24ff878d784dcc4b876316f129eae26a142b1525eb51033b17a23f13695490531aa503571daa8b8ef7d10370bb7323f84c12129a12733acbb52
> echo test > wordlist
> ~/Downloads/repos/john/run/john --wordlist=wordlist hash
Using default input encoding: UTF-8
Loaded 1 password hash (PEM, PKCS#8 private key (RSA/DSA/ECDSA) [PBKDF2-SHA1 256/256 AVX2 8x 3DES/AES])
Cost 1 (iteration count) is 4096 for all loaded hashes
Cost 2 (cipher [1=3DES 2/3/4=AES-128/192/256]) is 1 for all loaded hashes
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Warning: Only 1 candidate left, minimum 64 needed for performance.
0g 0:00:00:00 DONE (2021-09-26 16:11) 0g/s 25.00p/s 25.00c/s 25.00C/s test
Session completed.
> ~/Downloads/repos/john/run/john --show hash
0 password hashes cracked, 1 left
> ~/Downloads/repos/john/run/john --list=build-info
Version: 1.9.0-jumbo-1+bleeding-edf64e869 2021-09-25 12:13:58 -0300
Build: linux-gnu 64-bit x86_64 AVX2 AC OMP
SIMD: AVX2, interleaving: MD4:3 MD5:3 SHA1:1 SHA256:1 SHA512:1
CPU tests: AVX2
$JOHN is /home/jannik/Downloads/repos/john/run/
Format interface version: 14
Max. number of reported tunable costs: 4
Rec file version: REC4
Charset file version: CHR3
CHARSET_MIN: 1 (0x01)
CHARSET_MAX: 255 (0xff)
CHARSET_LENGTH: 24
SALT_HASH_SIZE: 1048576
SINGLE_IDX_MAX: 32768
SINGLE_BUF_MAX: 4294967295
Effective limit: Max. KPC 32768
Max. Markov mode level: 400
Max. Markov mode password length: 30
gcc version: 11.2.1
GNU libc version: 2.33 (loaded: 2.33)
Crypto library: OpenSSL
OpenSSL library version: 0101010cf
OpenSSL 1.1.1l FIPS 24 Aug 2021
File locking: fcntl()
fseek(): fseek
ftell(): ftell
fopen(): fopen
memmem(): System's
times(2) sysconf(_SC_CLK_TCK) is 100
Using times(2) for timers, resolution 10 ms
HR timer: clock_gettime(), latency 125 ns
Total physical host memory: 15647 MiB
Available physical host memory: 12368 MiB
Terminal locale string: en_US.UTF-8
Parsed terminal locale: UTF-8
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by inspecting pem2john.py and the PEM/PKCS#8 format implementation, then reproduce the issue with the OpenSSL-generated encrypted key and password shown here. Trace how the PRF is parsed and used, and check existing PEM-related tests or sample files. Done means keys using a non-SHA-1 PRF, such as SHA-256, are correctly converted and cracked.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, python
- Domain
- cryptography, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100