logo elektroda
logo elektroda
X
logo elektroda

[Solved] Unlocking archive password - Rar archive locked with password, AES encryption

segasunset 18567 3
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 17594779
    segasunset
    Level 6  
    Hello to you,


    I downloaded files from a certain page. These files are in the archives. It turned out that they are blocked by a password.

    In each folder there is a text file "read me" which describes how to get passwords. - go to the website and download the password there. The problem is that some of these pages do not work at all, while others are typical fraud attempts - complete survey, provide a phone number, install something and, by the way, infect your computer, etc.

    I managed to look enough at the archives to find that there are no trash inside, as long as the file weighed something, so there is a high probability that the files I'm interested in are actually there.

    Yes, I know that similar topics have already appeared on the forum, but nevertheless the most recent are from a decade ago, so maybe during these few years something in the aspect of password decryption has changed.

    RAR archives, AES encryption. I tried password cracking programs, including paid ones, which probably doesn't surprise those smarter than me - it takes a lot of time. But it's not about patience, it's about meaning, and more precisely, whether such a slamming of the password makes sense at all. I do not care about these files so much that I try to unlock the password for the rest of my life without turning off the computer for the next X years.

    Or maybe there are ways to bypass the password?

    Thank you in advance for your answers and of course - empathy :)


    Greetings,
    Sega
  • ADVERTISEMENT
  • #2 17594811
    dt1
    Admin of Computers group
    Welcome. There is no other way to crack the password than bruteforce. You can't miss it. You can use GPGPU (acceleration using an efficient graphics card, or preferably a few / ten / ten), or a computing cluster (which can work with short passwords), but usually cheaper and certainly faster to buy whatever you tried to download in this archive .
  • ADVERTISEMENT
  • #3 17594836
    E8600
    Level 41  
    dt1 wrote:
    There is no other way to crack the password than bruteforce. You can't miss it.

    In theory this is the case and it is a waste of time to crack a password.
    However, I personally managed to bypass the password in the RAR archive 2-3 times because some versions of the program had errors that are not talked about and then I can unpack without damaging the content.
    In my case, once I removed the password from a single file with an archive repair program, as I remember correctly it was - Advanced RAR Repair (allowed to read / copy the contents of the text file). Otherwise, Winrar helped himself (on the principle of throwing an archive with a password to another archive and changing the extension I do not remember exactly but it also worked and the password was not needed).
    In the video you have an example of another vulnerability in one of the program versions.



    So theoretically you can't and in practice it is different. :)
  • #4 17594883
    segasunset
    Level 6  
    Thank you all for taking the floor. You made me skip these archives with a clear conscience - it's a waste of time, nerves and money :)
    For the future, I have to think about how to check the files before downloading them, because I'm not the bad one, what God knows, God knows how, because wetransfer is not darkweb. However, the one who by blocking archives should try to deceive people, use them and rob them should be stigmatized. Maybe I can get to him :)
    Have a nice Friday ?
ADVERTISEMENT