Crack etherem validator keystore
Crack etherem validator keystore
Loading saved threads...
Forgetful Idiot · External communityPost link
External question — Ethereum Stack Exchange
Author: Forgetful Idiot
Original post: https://ethereum.stackexchange.com/questions/166860
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
I am trying to move my validator to an new and better device, but midway I realized I forgot the password used to create the keystore :(
I know parts of it, so I think I can crack it using hashcat like suggested in
https://stealthsploit.com/2017/06/12/ethereum-wallet-cracking/
However, the new keystore V4 (
https://eips.ethereum.org/EIPS/eip-2335
) has a different format, for example:
{
"crypto": {
"kdf": {
"function": "scrypt",
"params": {
"dklen": 32,
"n": 262144,
"p": 1,
"r": 8,
"salt": "d4e56740f876aef8c010b86a40d5f56745a118d0906a34e69aec8c0db1cb8fa3"
},
"message": ""
},
"checksum": {
"function": "sha256",
"params": {},
"message": "d2217fe5f3e9a1e34581ef8a78f7c9928e436d36dacc5e846690a5581e8ea484"
},
"cipher": {
"function": "aes-128-ctr",
"params": {
"iv": "264daa3f303d7259501c93d997d84fe6"
},
"message": "06ae90d55fe0a6e9c5c3bc5b170827b2e5cce3929ed3f116c2811e6366dfe20f"
}
},
"description": "This is a test keystore that uses scrypt to secure the secret.",
"pubkey": "9612d7a727c9d0a22e185a1c768478dfe919cada9266988cb32359c11f2b7b27f4ae4040902382ae2910c15e2b420d07",
"path": "m/12381/60/3141592653/589793238",
"uuid": "1d85ae20-35c5-4611-98e8-aa14a633906f",
"version": 4
}
So the hashcat command doesn't work:
hashcat -m15700 -a0 crackme.txt dic1.txt --status --status-timer=5 -w3 --potfile-disable -o result.txt
I tried using checksum.message in the place of MAC, but no luck.
I am not sure if I am formatting the parameters wrong, or we need a new hashtype (
https://hashcat.net/wiki/doku.php?id=hashcat
), because 15700 doesn't work.
Does anyone have any ideas how to use hashcat to crack an ethereum keystore v4?
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External question — Ethereum Stack Exchange Author: Forgetful Idiot Source score (net votes, not local likes): 2 Original post: https://ethereum.stackexchange.com/questions/166860 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. I am trying to move my validator to an new and better device, but midway I realized I forgot the password used to create the keystore :( I know parts of it, so I think I can crack it using hashcat like suggested in https://stealthsploit.com/2017/06/12/ethereum-wallet-cracking/ However, the new keystore V4 ( https://eips.ethereum.org/EIPS/eip-2335 ) has a different format, for example: { "crypto": { "kdf": { "function": "scrypt", "params": { "dklen": 32, "n": 262144, "p": 1, "r": 8, "salt": "d4e56740f876aef8c010b86a40d5f56745a118d0906a34e69aec8c0db1cb8fa3" }, "message": "" }, "checksum": { "function": "sha256", "params": {}, "message": "d2217fe5f3e9a1e34581ef8a78f7c9928e436d36dacc5e846690a5581e8ea484" }, "cipher": { "function": "aes-128-ctr", "params": { "iv": "264daa3f303d7259501c93d997d84fe6" }, "message": "06ae90d55fe0a6e9c5c3bc5b170827b2e5cce3929ed3f116c2811e6366dfe20f" } }, "description": "This is a test keystore that uses scrypt to secure the secret.", "pubkey": "9612d7a727c9d0a22e185a1c768478dfe919cada9266988cb32359c11f2b7b27f4ae4040902382ae2910c15e2b420d07", "path": "m/12381/60/3141592653/589793238", "uuid": "1d85ae20-35c5-4611-98e8-aa14a633906f", "version": 4 } So the hashcat command doesn't work: hashcat -m15700 -a0 crackme.txt dic1.txt --status --status-timer=5 -w3 --potfile-disable -o result.txt I tried using checksum.message in the place of MAC, but no luck. I am not sure if I am formatting the parameters wrong, or we need a new hashtype ( https://hashcat.net/wiki/doku.php?id=hashcat ), because 15700 doesn't work. Does anyone have any ideas how to use hashcat to crack an ethereum keystore v4?
Checking account access…