Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: Hash forms different from MD5 #11

Open
Brambopulos opened this issue Jan 5, 2021 · 5 comments
Open

Feature Request: Hash forms different from MD5 #11

Brambopulos opened this issue Jan 5, 2021 · 5 comments

Comments

@Brambopulos
Copy link

Just getting started with NSRLLookup, and this program seems to be a fantastic approach to AIO forensics. My organization collects SHA1 sums of binaries on machines to-be-audited, and I was wondering if there is a built in feature, or possibly a feature to be implemented in the future, that would collect hashes of different types from these same resources

@rjhansen
Copy link
Owner

rjhansen commented Jan 5, 2021

The very first version (nine years ago) supported MD5, SHA-1, and SHA-256 hashes. SHA-1 and SHA-256 were quickly dropped due to absolutely no users caring about SHA-1 and/or SHA-256.

I'm currently doing a total rewrite of nsrlsvr (and nsrllookup), and one of the features planned is returning support for hashes other than MD5.

@rjhansen
Copy link
Owner

rjhansen commented Jan 5, 2021

Insofar as a way to collect hashes of different types from these same machines: I personally use @jessek (Jesse Kornblum)'s hashdeep suite. There are many other good tools you can use to collect hash artifacts from target machines, but that's the one I use.

@Brambopulos
Copy link
Author

Brambopulos commented Jan 5, 2021 via email

@rjhansen
Copy link
Owner

rjhansen commented Jan 5, 2021

Sure: NIST! NIST maintains a huge database of known digests of known software packages. I only use one particular digest (MD5), but SHA-1 and SHA-256 digests are also part of the dataset. You want to look for the most recent National Software Reference Library Reference Data Set (NSRL RDS).

https://nsrl.nist.gov

@rjhansen
Copy link
Owner

rjhansen commented Jan 5, 2021

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants