Vibe Coding, Copilot, and Hash Length Extension Attacks
Everyone's talking about fable so I decided the bite the bullet and get a subscription to try it out.
But before trying out fable, I wanted to see how much Copilot could accomplish.
I recently spent most of a week learning more about cryptographic vulnerabilities in computers, so I decided to test out copilot by building a python library and CLI tool to perform hash length extension attacks. There's already a couple projects1 on github that perform this attack, but they all were either no longer maintained, messy, or didn't support all the hashes succeptible to this attack2.
After $3 of credits and an hour of prompting and coddling copilot, it pumped out hashle:
$ hashle --help
Usage: hashle [OPTIONS] COMMAND [ARGS]...
Perform hash length extension attacks against vulnerable Merkle-Damgard
hashes.
╭─ Options ────────────────────────────────────────────────────────────────────╮
│ --help Show this message and exit. │
╰──────────────────────────────────────────────────────────────────────────────╯
╭─ Commands ───────────────────────────────────────────────────────────────────╮
│ list-algorithms List every hash algorithm hashle supports. │
│ hash Compute the digest of DATA, mainly useful for generating │
│ test signatures. │
│ extend Perform a hash length extension attack. │
╰──────────────────────────────────────────────────────────────────────────────╯
$ hashle list-algorithms
md4 digest=128 bits block=64 bytes
md5 digest=128 bits block=64 bytes
ripemd160 digest=160 bits block=64 bytes
sha digest=160 bits block=64 bytes
sha1 digest=160 bits block=64 bytes
sha256 digest=256 bits block=64 bytes
sha512 digest=512 bits block=128 bytes
sm3 digest=256 bits block=64 bytes
tiger192v1 digest=192 bits block=64 bytes
tiger192v2 digest=192 bits block=64 bytes
whirlpool digest=512 bits block=64 bytes
$ hashle extend --help
Usage: hashle extend [OPTIONS]
Perform a hash length extension attack.
Computes the message an attacker would send, and the signature it
produces, for every combination of requested hash algorithm(s) and
secret length(s).
╭─ Options ────────────────────────────────────────────────────────────────────╮
│ * --signature -s <str> Known signature of secret+data, │
│ in hex. │
│ [required] │
│ --data -d <str> The original known string. │
│ --file <path> Read the original known string │
│ from a file. │
│ --data-format <str> Format of --data: 'raw' or 'hex'. │
│ [default: raw] │
│ --append -a <str> Data to append. │
│ --append-file <path> Read data to append from a file. │
│ --append-format <str> Format of --append: 'raw' or │
│ 'hex'. │
│ [default: raw] │
│ * --format -f <str> Hash algorithm(s) to target. │
│ Repeat for multiple, or pass │
│ 'all'. │
│ [required] │
│ --secret-length -l <int> Assumed length of the secret, in │
│ bytes. │
│ --secret-min <int> Minimum secret length to try. │
│ --secret-max <int> Maximum secret length to try. │
│ --out-data-format <str> Format for the forged message │
│ output. │
│ [default: raw] │
│ --out-signature-format <str> Format for the new signature │
│ output. │
│ [default: hex] │
│ --quiet -q Only print the new signature and │
│ data. │
│ --help Show this message and exit. │
╰──────────────────────────────────────────────────────────────────────────────╯
Tip
Also today I learned about markdown-exec, my new favorite project that lets you use shell or python code to render docs, which is how the hashle output above is displayed.
For $10/month, copilot's not bad.
-
See hash_extender and hlextend. ↩
-
That is, hashes that use Merkle-Damgard hash constructions. ↩