Questions tagged [sha1]

29 questions
40
votes
7 answers

Is there a built-in method for computing an SHA-1 or MD5 hash in Windows 7?

Is there a built-in method for computing an SHA-1 or MD5 hash in Windows 7?
39
votes
1 answer

How to check SSH key version locally

In general i'm searching for a method to show information about a private or public SSH key without contacting a server, like keylength, algorithm, ssh version and so on. Especially I like to know if some key is a sha1 or sha2.
gogan
  • 493
34
votes
8 answers

Can a file be maliciously changed in a way that maintains its original SHA-1 Hash?

According to this article, and many others, SHA-1 is not secure. In my case, I am not concerned about passwords or digital certificates. I am concerned about file integrity. Is it reasonably possible for a file (e.g. an ISO image or executable file)…
misha256
  • 11,543
  • 8
  • 60
  • 70
25
votes
3 answers

How can zero byte files generate a hash value?

How can a zero byte text file generate a hash when hashed with sha1sum, sha256sum etc? What data are the programs hashing to generate a hash value? Ta
18
votes
1 answer

How to check if your ssh keys are in the ssh-rsa2 format?

So recently there were news of OpenSSH dropping support for SHA-1 logins and I am trying to understand which format they are referring to. Since years i've been generating keys via ssh-keygen -t rsa -b 2048. Is this the type not recommended anymore…
strudelj nudelj
  • 291
  • 1
  • 2
  • 7
13
votes
2 answers

Why are Root CAs with SHA1 signatures not a risk

Take Verisign's website, for example, which has a root CA with a sha1 hash signature. Am I mistaken with understanding that were one to find a collision, they could impersonate the Verisign root CA, and use that to generate an intermediate and then…
Chris K
  • 271
5
votes
1 answer

Alternative to xxd that returns bytes?

I am on Mac OS X 10.8.2, running a compiled copy of xxd v1.10 (source code) as well as the copy of xxd that comes preinstalled on OS X. I am trying to generate a Base64-encoded SHA1 signature via a chain of piped commands in Terminal. Normally I…
5
votes
2 answers

Installing sha1sum on git-bash (MinGW)

I've been using git-bash on Windows 7 a lot. I gather it is a wrapper of MinGW. It has md5sum but not sha1sum. I'd like to install sha1sum, but I can't figure out how. When I try mingw-get, it says "command not found" When I tried to download…
mcgyver5
  • 1,121
4
votes
1 answer

Different SHA1 result every time I check, bad drive?

I was attempting to download and run the Windows 10 Insider Preview, but after a few failed boots and installation errors, I decided to test the SHA1 sum before committing. I noticed that every time I ran the SHA1 sum, the outcome was different! I…
Chris
  • 142
4
votes
3 answers

Why Outlook client's S/MIME settings use SHA1 as the default Hash Algorithm for digital signing a message?

can someone tell why Outlook client S/MIME settings use SHA1 as the default Hash Algorithm? Doesn't that put the certificate private key to a risk when weak algorithm is used? Or am I misunderstanding the signing process? Thanks, -Harri
Tuuska
  • 41
  • 1
  • 2
2
votes
1 answer

How to get sha1sum to work on Mac OS X?

I have an application that I'm porting and as part of the test suite, I run sha1sum. I'd like to have test code that works on all my platforms and not vary across platforms. Mac OS X, is the first platform without a sha1sum application. I did…
WilliamKF
  • 8,058
2
votes
3 answers

why do we need SHA1 checksum?

In this page I saw the SHA1 checksum. I know it's a hash algorithm, but I don't know why we need it for download code. So I clicked "what's this?" but got no any more information. It's hash, so what? Why we should know it's hash when we download a…
2
votes
1 answer

Allocate PCR banks for TPM in Linux

I want to have all PCRs (0-23) in sha1 and sha256 banks, but now I only have sha256 set and sha1 is empty but exists, tpm2_pcrread outputs: sha1: sha256: 0 : 0xC373FA10837B62B48E9CA87E5F31440FCDC8F5C51FB1BF0FC72D4E241E680ABC 1 :…
k1r1t0
  • 123
2
votes
1 answer

How reliable are SHA1 sum and MD5 sums on very large files?

I constantly transfer disk images and virtual machine images (usually 800GB to nearly 1 TB per file) to a cloud server via rclone using SSH, and I wonder how reliable are sha1sum and md5sum when it comes to verifying the integrity of very large…
2
votes
1 answer

Sha1Sum on kali.org

I am unable to download kali linux from their official website kali.org. I try to verify the sha1sum but all I get is invalid https://gyazo.com/2e02792c685fbd2ebfd50e04fe218501. Any ideas? I can verify sha1sums of other files from other websites…
1
2