Skip to content
logo
Red tradecraft
Hash length extension attack
  • Privacy greenhouse
  • Defence blues
  • Purple crossroads
  • Indigo observatory
  • Contact
Initializing search
    • An adversary mind map, one of many
    • The grounds
    • Ankh-Morpork: the city leaves a footprint
    • Fungolia earthworks
    • Unseen University Power & Light Co.
    • The Scarlet Semaphore
    • TryHackMe rooms
    • Root-Me challenges
      • Boars in the API undergrowth
      • Rooting around in memory
      • Picking the locks of ciphers
        • Old tricks, new treats: Unmasking classical ciphers
        • Secret recipes for digital mischief
        • AES: Faults, flips, and forgery
        • Riding the currents: Stream cipher exploits
        • Hash function vulnerabilities
          • DCC Hash
          • DCC2 Hash
          • LM Hash
          • Message Digest 5
          • NT Hash
          • SHA-2 Hash
          • CISCO Salted Password
          • Hash length extension attack
            • Resources
          • SHA-3 Hash
        • Unlocking RSA: Asymmetric mischief
        • Curves ahead: Navigating elliptic curve cryptography
        • The curiosity cabinet
      • Where a script hands over the keys
      • Rhizomatic sprawl: the network underworld
      • Prising binaries open
      • Secrets buried in pixels
      • Foraging in the web orchard
    • RIPE NCC Academy labs
    • Resources

    Hash length extension attack¶

    RootMe challenge: Service - Hash length extension attack: H(key ∥ message)

    You can use Stephen Bradshaw’s hlextend module.

    Resources¶

    • Everything-you-need-to-know-about-hash-length-extension-attacks (blog.skullsecurity.org)

    2026-07-30 17:57
    © Copyright 2025, TyMyrddin.
    Created using Sphinx 7.2.6. and Sphinx-Immaterial

    Made with love by Ty Myrddin, 2026, with a forest garden fostered by /ut7