PDA

View Full Version : Blowfish2


venom925
August 5th, 2006, 12:18
I was just wondering if anybody has come across this strain of blowfish. If so are any good tuts for this, i have searched the forum and the net but have yet to find one that will give me a good starting point.

LLXX
August 5th, 2006, 20:44
Perhaps you mean Twofish?

venom925
August 5th, 2006, 21:21
i dont think so. i used a crypto analyzer called x3chun's Crypto Searcher and it said that the file uses blowfish2

the scan says:
BLOWFISH2(?) : First Signature Found At : 000A798C
The First Signature Is 4B7A70E9h ::?::

LLXX
August 6th, 2006, 02:31
That constant is part of sbox 1. If you don't find the contents of the other sboxes in your file, it is probably a false positive.

Otherwise, Blowfish2 is likely just referring to standard Blowfish with precomputed tables.

venom925
August 6th, 2006, 09:58
ok thanks

dELTA
August 6th, 2006, 10:45
Long time no see venom925.

evilcry
August 6th, 2006, 10:48
If you need something about Blowfish and it's modified version
you can read the last part of mine Blowfish art.
that you can find here:

http://www.reteam.org/papers/e75.pdf

Have a nice Day

venom925
August 6th, 2006, 10:51
hey delta,
been away for a while but im back now

evilcry thanks ill check it out

venom925
August 7th, 2006, 16:46
just wanted to let you all know it was blowfish and i got it thanks for the input to everyone who replyed

0xf001
August 31st, 2006, 02:17
heya,

afaik there is no blowfish2. or? if anyone knows i would be happy because i am also curious abt it.
[ where is MIKE ]

is it possible the tool u used to scan uses multiple signatures and tells u that it found blowfish using the 2nd sig it uses for searching?
i saw so with sha sometimes with PEiD iirc. maybe reversing that searcher to see what the sig is would tell

evilcry: nice little tut!!

cheers, 0xf001

Silkut
August 31st, 2006, 04:58
Hmm there is a lot of things about Twofish but not Blowfish2 when you use a search engine. I would be happy to see something about Blowfish2, if it exists.

LLXX
August 31st, 2006, 15:41
Quote:
[Originally Posted by LLXX]Otherwise, Blowfish2 is likely just referring to standard Blowfish with precomputed tables.
Read please ^^

evilcry
September 3rd, 2006, 11:41
Hi all,

Recently a new implementation of Blowfish, has been relased, Eksblowfish
that you can find here: http://search.cpan.org/~zefram/Crypt-Eksblowfish-0.001/


Have a nice day!