[7034] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: PKZIP: any attacks other than Kocher plain text?

daemon@ATHENA.MIT.EDU (staym@accessdata.com)
Mon May 8 17:02:15 2000

From: staym@accessdata.com
Message-ID: <39171955.36EF@accessdata.com>
Date: Mon, 08 May 2000 13:51:47 -0600
MIME-Version: 1.0
To: cryptography@c2.net
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

You can get away with as few as seven bytes of plaintext and 2^40 work
if you have other files in the archive.  Five of the thirteen bytes are
only used for filtering, so if you have other files you can use the
password check bytes instead of known plaintext bytes.  Also, in
kocher's attack, you can get six bits of one byte.  Kocher throws it out
and requires one more byte of known plaintext, but you can guess those
two bits (raising the workload from 2^38 to 2^40).

Accessdata has another attack that runs in ~2 hours on a 500MHz pentium,
but the details are a secret, sorry.
-- 
Mike Stay
Programmer / Crypto guy
AccessData Corp.
staym@accessdata.com


home help back first fref pref prev next nref lref last post