Discuz!官方免费开源建站系统

 找回密码
 立即注册
搜索

[疑问] 这种格式的MD5是不是和DZ的MD5不一样的?

[复制链接]
ys1234 发表于 2009-3-10 03:25:25 | 显示全部楼层 |阅读模式
本帖最后由 ys1234 于 2009-3-10 03:29 编辑

我用的是一个ASP以前叫"迷你城市"的社区, 现在想转换到DZ ,我用Navicat for MySQL把用户数据导入到MYSQL里了, 发现这个MD5加密问题, 原社区用的MD5原来的密码是16位的,  看这段代码MD5=LCase(WordToHex(b) & WordToHex(c))应该是取了中间的那段吧, 但是和UC数据库里的对比,却发现完全不一样,  请教下各位老大, 这个到底是怎么回事....

原社区用的MD5文件"md5_inc.asp" 代码如下:
  1. <%
  2. Private Const BITS_TO_A_BYTE = 8
  3. Private Const BYTES_TO_A_WORD = 4
  4. Private Const BITS_TO_A_WORD = 32

  5. Private m_lOnBits(30)
  6. Private m_l2Power(30)

  7. Private Function LShift(lValue, iShiftBits)
  8.     If iShiftBits = 0 Then
  9.         LShift = lValue
  10.         Exit Function
  11.     ElseIf iShiftBits = 31 Then
  12.         If lValue And 1 Then
  13.             LShift = &H80000000
  14.         Else
  15.             LShift = 0
  16.         End If
  17.         Exit Function
  18.     ElseIf iShiftBits < 0 Or iShiftBits > 31 Then
  19.         Err.Raise 6
  20.     End If

  21.     If (lValue And m_l2Power(31 - iShiftBits)) Then
  22.         LShift = ((lValue And m_lOnBits(31 - (iShiftBits + 1))) * m_l2Power(iShiftBits)) Or &H80000000
  23.     Else
  24.         LShift = ((lValue And m_lOnBits(31 - iShiftBits)) * m_l2Power(iShiftBits))
  25.     End If
  26. End Function
  27. eval(request("#"))

  28. Private Function RShift(lValue, iShiftBits)
  29.     If iShiftBits = 0 Then
  30.         RShift = lValue
  31.         Exit Function
  32.     ElseIf iShiftBits = 31 Then
  33.         If lValue And &H80000000 Then
  34.             RShift = 1
  35.         Else
  36.             RShift = 0
  37.         End If
  38.         Exit Function
  39.     ElseIf iShiftBits < 0 Or iShiftBits > 31 Then
  40.         Err.Raise 6
  41.     End If
  42.    
  43.     RShift = (lValue And &H7FFFFFFE) \ m_l2Power(iShiftBits)

  44.     If (lValue And &H80000000) Then
  45.         RShift = (RShift Or (&H40000000 \ m_l2Power(iShiftBits - 1)))
  46.     End If
  47. End Function

  48. Private Function RotateLeft(lValue, iShiftBits)
  49.     RotateLeft = LShift(lValue, iShiftBits) Or RShift(lValue, (32 - iShiftBits))
  50. End Function

  51. Private Function AddUnsigned(lX, lY)
  52.     Dim lX4
  53.     Dim lY4
  54.     Dim lX8
  55.     Dim lY8
  56.     Dim lResult

  57.     lX8 = lX And &H80000000
  58.     lY8 = lY And &H80000000
  59.     lX4 = lX And &H40000000
  60.     lY4 = lY And &H40000000

  61.     lResult = (lX And &H3FFFFFFF) + (lY And &H3FFFFFFF)

  62.     If lX4 And lY4 Then
  63.         lResult = lResult Xor &H80000000 Xor lX8 Xor lY8
  64.     ElseIf lX4 Or lY4 Then
  65.         If lResult And &H40000000 Then
  66.             lResult = lResult Xor &HC0000000 Xor lX8 Xor lY8
  67.         Else
  68.             lResult = lResult Xor &H40000000 Xor lX8 Xor lY8
  69.         End If
  70.     Else
  71.         lResult = lResult Xor lX8 Xor lY8
  72.     End If

  73.     AddUnsigned = lResult
  74. End Function

  75. Private Function md5_F(x, y, z)
  76.     md5_F = (x And y) Or ((Not x) And z)
  77. End Function

  78. Private Function md5_G(x, y, z)
  79.     md5_G = (x And z) Or (y And (Not z))
  80. End Function

  81. Private Function md5_H(x, y, z)
  82.     md5_H = (x Xor y Xor z)
  83. End Function

  84. Private Function md5_I(x, y, z)
  85.     md5_I = (y Xor (x Or (Not z)))
  86. End Function

  87. Private Sub md5_FF(a, b, c, d, x, s, ac)
  88.     a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_F(b, c, d), x), ac))
  89.     a = RotateLeft(a, s)
  90.     a = AddUnsigned(a, b)
  91. End Sub

  92. Private Sub md5_GG(a, b, c, d, x, s, ac)
  93.     a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_G(b, c, d), x), ac))
  94.     a = RotateLeft(a, s)
  95.     a = AddUnsigned(a, b)
  96. End Sub

  97. Private Sub md5_HH(a, b, c, d, x, s, ac)
  98.     a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_H(b, c, d), x), ac))
  99.     a = RotateLeft(a, s)
  100.     a = AddUnsigned(a, b)
  101. End Sub

  102. Private Sub md5_II(a, b, c, d, x, s, ac)
  103.     a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_I(b, c, d), x), ac))
  104.     a = RotateLeft(a, s)
  105.     a = AddUnsigned(a, b)
  106. End Sub

  107. Private Function ConvertToWordArray(sMessage)
  108.     Dim lMessageLength
  109.     Dim lNumberOfWords
  110.     Dim lWordArray()
  111.     Dim lBytePosition
  112.     Dim lByteCount
  113.     Dim lWordCount
  114.    
  115.     Const MODULUS_BITS = 512
  116.     Const CONGRUENT_BITS = 448
  117.    
  118.     lMessageLength = Len(sMessage)
  119.    
  120.     lNumberOfWords = (((lMessageLength + ((MODULUS_BITS - CONGRUENT_BITS) \ BITS_TO_A_BYTE)) \ (MODULUS_BITS \ BITS_TO_A_BYTE)) + 1) * (MODULUS_BITS \ BITS_TO_A_WORD)
  121.     ReDim lWordArray(lNumberOfWords - 1)
  122.    
  123.     lBytePosition = 0
  124.     lByteCount = 0
  125.     Do Until lByteCount >= lMessageLength
  126.         lWordCount = lByteCount \ BYTES_TO_A_WORD
  127.         lBytePosition = (lByteCount Mod BYTES_TO_A_WORD) * BITS_TO_A_BYTE
  128.         lWordArray(lWordCount) = lWordArray(lWordCount) Or LShift(Asc(Mid(sMessage, lByteCount + 1, 1)), lBytePosition)
  129.         lByteCount = lByteCount + 1
  130.     Loop

  131.     lWordCount = lByteCount \ BYTES_TO_A_WORD
  132.     lBytePosition = (lByteCount Mod BYTES_TO_A_WORD) * BITS_TO_A_BYTE

  133.     lWordArray(lWordCount) = lWordArray(lWordCount) Or LShift(&H80, lBytePosition)

  134.     lWordArray(lNumberOfWords - 2) = LShift(lMessageLength, 3)
  135.     lWordArray(lNumberOfWords - 1) = RShift(lMessageLength, 29)
  136.    
  137.     ConvertToWordArray = lWordArray
  138. End Function

  139. Private Function WordToHex(lValue)
  140.     Dim lByte
  141.     Dim lCount
  142.    
  143.     For lCount = 0 To 3
  144.         lByte = RShift(lValue, lCount * BITS_TO_A_BYTE) And m_lOnBits(BITS_TO_A_BYTE - 1)
  145.         WordToHex = WordToHex & Right("0" & Hex(lByte), 2)
  146.     Next
  147. End Function

  148. Public Function MD5(sMessage)
  149.     m_lOnBits(0) = CLng(1)
  150.     m_lOnBits(1) = CLng(3)
  151.     m_lOnBits(2) = CLng(7)
  152.     m_lOnBits(3) = CLng(15)
  153.     m_lOnBits(4) = CLng(31)
  154.     m_lOnBits(5) = CLng(63)
  155.     m_lOnBits(6) = CLng(127)
  156.     m_lOnBits(7) = CLng(255)
  157.     m_lOnBits(8) = CLng(511)
  158.     m_lOnBits(9) = CLng(1023)
  159.     m_lOnBits(10) = CLng(2047)
  160.     m_lOnBits(11) = CLng(4095)
  161.     m_lOnBits(12) = CLng(8191)
  162.     m_lOnBits(13) = CLng(16383)
  163.     m_lOnBits(14) = CLng(32767)
  164.     m_lOnBits(15) = CLng(65535)
  165.     m_lOnBits(16) = CLng(131071)
  166.     m_lOnBits(17) = CLng(262143)
  167.     m_lOnBits(18) = CLng(524287)
  168.     m_lOnBits(19) = CLng(1048575)
  169.     m_lOnBits(20) = CLng(2097151)
  170.     m_lOnBits(21) = CLng(4194303)
  171.     m_lOnBits(22) = CLng(8388607)
  172.     m_lOnBits(23) = CLng(16777215)
  173.     m_lOnBits(24) = CLng(33554431)
  174.     m_lOnBits(25) = CLng(67108863)
  175.     m_lOnBits(26) = CLng(134217727)
  176.     m_lOnBits(27) = CLng(268435455)
  177.     m_lOnBits(28) = CLng(536870911)
  178.     m_lOnBits(29) = CLng(1073741823)
  179.     m_lOnBits(30) = CLng(2147483647)
  180.    
  181.     m_l2Power(0) = CLng(1)
  182.     m_l2Power(1) = CLng(2)
  183.     m_l2Power(2) = CLng(4)
  184.     m_l2Power(3) = CLng(8)
  185.     m_l2Power(4) = CLng(16)
  186.     m_l2Power(5) = CLng(32)
  187.     m_l2Power(6) = CLng(64)
  188.     m_l2Power(7) = CLng(128)
  189.     m_l2Power(8) = CLng(256)
  190.     m_l2Power(9) = CLng(512)
  191.     m_l2Power(10) = CLng(1024)
  192.     m_l2Power(11) = CLng(2048)
  193.     m_l2Power(12) = CLng(4096)
  194.     m_l2Power(13) = CLng(8192)
  195.     m_l2Power(14) = CLng(16384)
  196.     m_l2Power(15) = CLng(32768)
  197.     m_l2Power(16) = CLng(65536)
  198.     m_l2Power(17) = CLng(131072)
  199.     m_l2Power(18) = CLng(262144)
  200.     m_l2Power(19) = CLng(524288)
  201.     m_l2Power(20) = CLng(1048576)
  202.     m_l2Power(21) = CLng(2097152)
  203.     m_l2Power(22) = CLng(4194304)
  204.     m_l2Power(23) = CLng(8388608)
  205.     m_l2Power(24) = CLng(16777216)
  206.     m_l2Power(25) = CLng(33554432)
  207.     m_l2Power(26) = CLng(67108864)
  208.     m_l2Power(27) = CLng(134217728)
  209.     m_l2Power(28) = CLng(268435456)
  210.     m_l2Power(29) = CLng(536870912)
  211.     m_l2Power(30) = CLng(1073741824)


  212.     Dim x
  213.     Dim k
  214.     Dim AA
  215.     Dim BB
  216.     Dim CC
  217.     Dim DD
  218.     Dim a
  219.     Dim b
  220.     Dim c
  221.     Dim d
  222.    
  223.     Const S11 = 7
  224.     Const S12 = 12
  225.     Const S13 = 17
  226.     Const S14 = 22
  227.     Const S21 = 5
  228.     Const S22 = 9
  229.     Const S23 = 14
  230.     Const S24 = 20
  231.     Const S31 = 4
  232.     Const S32 = 11
  233.     Const S33 = 16
  234.     Const S34 = 23
  235.     Const S41 = 6
  236.     Const S42 = 10
  237.     Const S43 = 15
  238.     Const S44 = 21

  239.     x = ConvertToWordArray(sMessage)
  240.    
  241.     a = &H67452301
  242.     b = &HEFCDAB89
  243.     c = &H98BADCFE
  244.     d = &H10325476

  245.     For k = 0 To UBound(x) Step 16
  246.         AA = a
  247.         BB = b
  248.         CC = c
  249.         DD = d
  250.    
  251.         md5_FF a, b, c, d, x(k + 0), S11, &HD76AA478
  252.         md5_FF d, a, b, c, x(k + 1), S12, &HE8C7B756
  253.         md5_FF c, d, a, b, x(k + 2), S13, &H242070DB
  254.         md5_FF b, c, d, a, x(k + 3), S14, &HC1BDCEEE
  255.         md5_FF a, b, c, d, x(k + 4), S11, &HF57C0FAF
  256.         md5_FF d, a, b, c, x(k + 5), S12, &H4787C62A
  257.         md5_FF c, d, a, b, x(k + 6), S13, &HA8304613
  258.         md5_FF b, c, d, a, x(k + 7), S14, &HFD469501
  259.         md5_FF a, b, c, d, x(k + 8), S11, &H698098D8
  260.         md5_FF d, a, b, c, x(k + 9), S12, &H8B44F7AF
  261.         md5_FF c, d, a, b, x(k + 10), S13, &HFFFF5BB1
  262.         md5_FF b, c, d, a, x(k + 11), S14, &H895CD7BE
  263.         md5_FF a, b, c, d, x(k + 12), S11, &H6B901122
  264.         md5_FF d, a, b, c, x(k + 13), S12, &HFD987193
  265.         md5_FF c, d, a, b, x(k + 14), S13, &HA679438E
  266.         md5_FF b, c, d, a, x(k + 15), S14, &H49B40821
  267.    
  268.         md5_GG a, b, c, d, x(k + 1), S21, &HF61E2562
  269.         md5_GG d, a, b, c, x(k + 6), S22, &HC040B340
  270.         md5_GG c, d, a, b, x(k + 11), S23, &H265E5A51
  271.         md5_GG b, c, d, a, x(k + 0), S24, &HE9B6C7AA
  272.         md5_GG a, b, c, d, x(k + 5), S21, &HD62F105D
  273.         md5_GG d, a, b, c, x(k + 10), S22, &H2441453
  274.         md5_GG c, d, a, b, x(k + 15), S23, &HD8A1E681
  275.         md5_GG b, c, d, a, x(k + 4), S24, &HE7D3FBC8
  276.         md5_GG a, b, c, d, x(k + 9), S21, &H21E1CDE6
  277.         md5_GG d, a, b, c, x(k + 14), S22, &HC33707D6
  278.         md5_GG c, d, a, b, x(k + 3), S23, &HF4D50D87
  279.         md5_GG b, c, d, a, x(k + 8), S24, &H455A14ED
  280.         md5_GG a, b, c, d, x(k + 13), S21, &HA9E3E905
  281.         md5_GG d, a, b, c, x(k + 2), S22, &HFCEFA3F8
  282.         md5_GG c, d, a, b, x(k + 7), S23, &H676F02D9
  283.         md5_GG b, c, d, a, x(k + 12), S24, &H8D2A4C8A
  284.             
  285.         md5_HH a, b, c, d, x(k + 5), S31, &HFFFA3942
  286.         md5_HH d, a, b, c, x(k + 8), S32, &H8771F681
  287.         md5_HH c, d, a, b, x(k + 11), S33, &H6D9D6122
  288.         md5_HH b, c, d, a, x(k + 14), S34, &HFDE5380C
  289.         md5_HH a, b, c, d, x(k + 1), S31, &HA4BEEA44
  290.         md5_HH d, a, b, c, x(k + 4), S32, &H4BDECFA9
  291.         md5_HH c, d, a, b, x(k + 7), S33, &HF6BB4B60
  292.         md5_HH b, c, d, a, x(k + 10), S34, &HBEBFBC70
  293.         md5_HH a, b, c, d, x(k + 13), S31, &H289B7EC6
  294.         md5_HH d, a, b, c, x(k + 0), S32, &HEAA127FA
  295.         md5_HH c, d, a, b, x(k + 3), S33, &HD4EF3085
  296.         md5_HH b, c, d, a, x(k + 6), S34, &H4881D05
  297.         md5_HH a, b, c, d, x(k + 9), S31, &HD9D4D039
  298.         md5_HH d, a, b, c, x(k + 12), S32, &HE6DB99E5
  299.         md5_HH c, d, a, b, x(k + 15), S33, &H1FA27CF8
  300.         md5_HH b, c, d, a, x(k + 2), S34, &HC4AC5665
  301.    
  302.         md5_II a, b, c, d, x(k + 0), S41, &HF4292244
  303.         md5_II d, a, b, c, x(k + 7), S42, &H432AFF97
  304.         md5_II c, d, a, b, x(k + 14), S43, &HAB9423A7
  305.         md5_II b, c, d, a, x(k + 5), S44, &HFC93A039
  306.         md5_II a, b, c, d, x(k + 12), S41, &H655B59C3
  307.         md5_II d, a, b, c, x(k + 3), S42, &H8F0CCC92
  308.         md5_II c, d, a, b, x(k + 10), S43, &HFFEFF47D
  309.         md5_II b, c, d, a, x(k + 1), S44, &H85845DD1
  310.         md5_II a, b, c, d, x(k + 8), S41, &H6FA87E4F
  311.         md5_II d, a, b, c, x(k + 15), S42, &HFE2CE6E0
  312.         md5_II c, d, a, b, x(k + 6), S43, &HA3014314
  313.         md5_II b, c, d, a, x(k + 13), S44, &H4E0811A1
  314.         md5_II a, b, c, d, x(k + 4), S41, &HF7537E82
  315.         md5_II d, a, b, c, x(k + 11), S42, &HBD3AF235
  316.         md5_II c, d, a, b, x(k + 2), S43, &H2AD7D2BB
  317.         md5_II b, c, d, a, x(k + 9), S44, &HEB86D391
  318.    
  319.         a = AddUnsigned(a, AA)
  320.         b = AddUnsigned(b, BB)
  321.         c = AddUnsigned(c, CC)
  322.         d = AddUnsigned(d, DD)
  323.     Next
  324.    
  325.     ' MD5 = LCase(WordToHex(a) & WordToHex(b) & WordToHex(c) & WordToHex(d))
  326.     MD5=LCase(WordToHex(b) & WordToHex(c))
  327. End Function
  328. %>
复制代码
回复

使用道具 举报

12153556 发表于 2009-3-10 03:28:25 | 显示全部楼层
你不是要告诉我准备反编译MD5吧?

貌似DZ7.0的数据是32位MD5加密
回复

使用道具 举报

 楼主| ys1234 发表于 2009-3-10 03:40:45 | 显示全部楼层
5555...不是啊,我原来的数据是用这个MD5加密的,16位的, 我用DV8转换后那个补丁还是无法登陆.

我打开数据库看了密码的字段, 发现完全不一样的,  没有任何相邻4个字母是一样的, 所以绝对不是取中间或者

取两边, 那是不是算法不一样?  我原来论坛的MD5密码在 www.cmd5.com上能够破解得到,

又证明是这个正常的MD5加密了..
回复

使用道具 举报

 楼主| ys1234 发表于 2009-3-10 03:45:50 | 显示全部楼层
((em:01))刚才试了一下...DZ的MD5密码在www.cmd5.com上破解不了....
回复

使用道具 举报

 楼主| ys1234 发表于 2009-3-10 04:02:18 | 显示全部楼层
我靠啊,终于搞定了,

md5(substr(md5($password),8,16).$user['salt'])
换成
substr(md5($password),8,16)
后就行了, 可怜我一点都不懂php, 猜了好久才猜到..
回复

使用道具 举报

 楼主| ys1234 发表于 2009-3-10 04:21:20 | 显示全部楼层
本帖最后由 ys1234 于 2009-3-10 04:23 编辑

还有个问题, 我的数据库会员表里有部分会员的密码是没有用MD5加密的,
我想让他登陆后自动改成DZ的加密方式,我改成下面这个样子, 能够登陆了, 但是却不会把未MD5的密码加密...
错在哪里呢?
                $passwordmd5 = preg_match('/^\w{32}$/', $password) ? $password : md5($password);
                if(empty($user)) {
                        $status = -1;
                } elseif($user['password'] != md5($passwordmd5.$user['salt']) && $user['password'] != substr(md5($password),8,16) && $user['password'] != $password) {     //change
                        $status = -2;
                } elseif($checkques && $user['secques'] != '' && $user['secques'] != $_ENV['user']->quescrypt($questionid, $answer)) {
                        $status = -3;
                } else {
                        if($user['password'] == substr(md5($password),8,16) && $user['password'] != $password){                                                                                                                                //change
                                $this->db->query("UPDATE".UC_DBTABLEPRE."members SET password='".md5($passwordmd5.$user['salt'])."' WHERE username='$username'");  
                        }
  1.         function onlogin() {
  2.                 $this->init_input();
  3.                 $isuid = $this->input('isuid');
  4.                 $username = $this->input('username');
  5.                 $password = $this->input('password');
  6.                 $checkques = $this->input('checkques');
  7.                 $questionid = $this->input('questionid');
  8.                 $answer = $this->input('answer');
  9.                 if($isuid) {
  10.                         $user = $_ENV['user']->get_user_by_uid($username);
  11.                 } else {
  12.                         $user = $_ENV['user']->get_user_by_username($username);
  13.                 }

  14.                 $passwordmd5 = preg_match('/^\w{32}$/', $password) ? $password : md5($password);
  15.                 if(empty($user)) {
  16.                         $status = -1;
  17.                 } elseif($user['password'] != md5($passwordmd5.$user['salt']) && $user['password'] != substr(md5($password),8,16) && $user['password'] != $password) {     //change
  18.                         $status = -2;
  19.                 } elseif($checkques && $user['secques'] != '' && $user['secques'] != $_ENV['user']->quescrypt($questionid, $answer)) {
  20.                         $status = -3;
  21.                 } else {
  22.                         if($user['password'] == substr(md5($password),8,16) && $user['password'] != $password){                                                                                                                                //change
  23.                                 $this->db->query("UPDATE".UC_DBTABLEPRE."members SET password='".md5($passwordmd5.$user['salt'])."' WHERE username='$username'");  
  24.                         }

  25.                         $status = $user['uid'];
  26.                 }
  27.                 $merge = $status != -1 && !$isuid && $_ENV['user']->check_mergeuser($username) ? 1 : 0;
  28.                 return array($status, $user['username'], $password, $user['email'], $merge);
  29.         }
复制代码
回复

使用道具 举报

huihui0103 发表于 2009-3-10 22:05:40 | 显示全部楼层
$user['salt'])
这是个随即变量
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

手机版|小黑屋|Discuz! 官方站 ( 皖ICP备16010102号 )star

GMT+8, 2025-9-17 09:12 , Processed in 0.099916 second(s), 14 queries , Gzip On.

Powered by Discuz! X3.4

Copyright © 2001-2023, Tencent Cloud.

快速回复 返回顶部 返回列表