Hashing Kya Hai? | Hashing in Cyber Security | MD5, SHA-256 & John the Ripper

Hashing Kya Hai? Linux & Cyber Security Mein Hashing Ko Samjhein – Cyber-Teck
Cyber-Teck Ethical Hacker Logo
Cyber Security & Ethical Hacking Guide

Hashing Kya Hai? | Hashing in Cyber Security | MD5, SHA-256 & John the Ripper

Hashing cybersecurity और Linux security में एक बहुत important concept है। अगर आप Cyber Security, Ethical Hacking, Penetration Testing या Linux Security सीख रहे हैं, तो आपको hashing को अच्छी तरह समझना चाहिए।

इस Article में हम जानेंगे:
  • Hashing क्या है और Hash क्या होता है?
  • Hashing को One-Way Function क्यों कहा जाता है?
  • Passwords store करने और Integrity Checking में Hashing का रोल।
  • MD5 और SHA-1 weak क्यों माने जाते हैं?
  • SHA-256 vs Dedicated Password Algorithms (Argon2id, bcrypt)।
  • Hash Cracking, John the Ripper, Hash-Identifier और Haiti tools।
  • Hashing vs Encryption में फर्क।

1. Hashing Kya Hai?

Hashing एक process है जिसमें किसी भी input data को एक fixed-format hash value में convert किया जाता है।

Input कुछ भी हो सकता है: Password, Text, File, Message या Data।

उदाहरण:

  • Input: mypassword123
  • MD5 Hash: 9c87baa223f464954940f859bcf2e233

यह output एक hash value है। इसे आप data का एक तरह का Digital Fingerprint समझ सकते हैं।

Simple Example & Integrity:

मान लीजिए हमारे पास यह text है: Hello World

जब इसे किसी hashing algorithm से process किया जाता है, तो हमें एक hash value मिलती है। अगर input में थोड़ा सा भी बदलाव कर दें (जैसे Hello world), तो hash पूरी तरह बदल जाएगा। यही property इसे Data Integrity Checking में बेहद काम की बनाती है।

2. Hash Kya Hota Hai?

Hashing process से मिलने वाले final output को Hash कहा जाता है।

Input ───► [ Hashing Algorithm ] ───► Hash Value

Hash की length इस्तेमाल किए गए algorithm पर depend करती है:

Algorithm Typical Hash Length
MD5 128 bits
SHA-1 160 bits
SHA-256 256 bits
SHA-512 512 bits

3. Hashing ko One-Way Function kyu Kaha Jata Hai?

Hashing को mathematically one-way function माना जाता है क्योंकि hash value से original input को सीधे reverse करने का कोई practical तरीका नहीं होता।

mypassword123 ───► SHA-256 ───► Hash Value

Hash Value ───X (Cannot Reverse Direct) ───► mypassword123

लेकिन इसका यह मतलब नहीं है कि password कभी पता नहीं लगाया जा सकता! अगर password weak या common है (जैसे 123456, password, admin), तो attacker pre-computed hashes या password guessing से original value मैच कर सकता है।

4. Hashing kyu Important Hai?

Cyber Security में Hashing के 2 सबसे प्रमुख उपयोग हैं:

A. Secure Password Storage

Websites कभी भी users के passwords plain text में store नहीं करतीं। अगर database leak हो जाए और passwords plain text में हों, तो attacker आसानी से accounts compromise कर लेगा।

इसलिए system password को hash करके database में रखता है और login के समय entered password का hash बनाकर verify करता है:

Login Password ──► Password Hashing ──► Verification ──► Stored Hash Match?
YES ──► Login Success | NO ──► Reject

B. File Integrity Checking

जब आप internet से कोई file या ISO download करते हैं, तो original supplier उसकी hash value provide करता है। File download होने के बाद आप उसका hash चेक करके यह confirm कर सकते हैं कि file में कोई corruption या malware tampering नहीं हुई है।

5. MD5 aur SHA-1 Weak kyu Mane Jate Hain?

MD5 और SHA-1 historically बहुत popular रहे हैं, लेकिन आज security-sensitive systems के लिए इन्हें outdated माना जाता है।

इनमें Collision Attacks practical पाए गए हैं।

Collision Kya Hai?
जब दो अलग-अलग Inputs (Input A और Input B) का hashing के बाद **Same Hash Output** आ जाए, तो उसे Collision कहा जाता है।

साथ ही, MD5 और SHA-1 बहुत तेज (fast) काम करते हैं, जिससे attackers per second अरबों hashes test करके cracking को आसान बना लेते हैं।

6. Kya SHA-256 Passwords ke Liye Best Hai?

SHA-256 integrity checking के लिए बेहतरीन है, लेकिन सिर्फ SHA-256(password) का उपयोग करना modern security standard नहीं है।

चूंकि SHA-256 की speed भी बहुत फास्ट है, इसलिए attackers GPU/Hardware की मदद से बहुत तेजी से brute force guessing कर सकते हैं।

Modern Password Storage Best Choice:

  • Argon2id
  • bcrypt
  • scrypt

इन dedicated algorithms को intentionally धीमा (computationally expensive) बनाया जाता है ताकि attackers तेजी से guesses न कर सकें।

7. Hash Cracking, Tools & Techniques

Hash Cracking का मतलब hash को decrypt करना नहीं, बल्कि अलग-अलग passwords के hashes बनाकर target hash से match करना है।

Methods:

  • Brute Force: All possible letter/number combinations को try करना (जैसे 0001, 0002…)।
  • Wordlist Attack: Pre-defined common passwords list (जैसे rockyou.txt) के hashes बनाकर compare करना।

John the Ripper:

John the Ripper एक प्रसिद्ध Password Security Auditing और Recovery Tool है जो Kali Linux में pre-installed आता है।

john --format=raw-md5 --wordlist=/path/to/rockyou.txt hash.txt

Hash Identification Tools (Hash-Identifier & Haiti):

जब आपको कोई अज्ञात hash मिलता है, तो उसके algorithm को पहचानना जरूरी होता है:

  • Hash-Identifier: Command-line tool जो possible algorithm types लिस्ट करता है।
  • Haiti: एक modern CLI tool जो अज्ञात hashes को detect और narrow-down करने में मदद करता है।

8. Hashing vs Encryption

Property Hashing Encryption
Type Generally One-Way Two-Way (Encrypt & Decrypt)
Reversibility Original data direct decrypt नहीं होता Key की मदद से data decrypt हो सकता है
Main Purpose Integrity & Verification Confidentiality & Data Protection
Example SHA-256, Argon2id AES, RSA
💡 Quick Memory Trick:
Hashing ──► Verify (जांच करना)
Encryption ──► Protect & Recover (सुरक्षित रखना और वापस पाना)

Conclusion

Hashing Cyber Security का एक fundamental pillar है। Linux password management, file integrity validation, penetration testing और forensic analysis में इसका ज्ञान बेहद आवश्यक है।

एक Ethical Hacker या Security Researcher के तौर पर आपको सिर्फ hashing की परिभाषा ही नहीं, बल्कि fast vs slow hashing algorithms, collision threats और cracking tools की बारीकियों को समझना चाहिए।


© Cyber-Teck | Ethical Hacking & Cybersecurity Knowledge Base

More From Author

Hashing क्या है? Linux में Hashing और Hash Cracking Explained

Bug Bounty Bootcamp

Leave a Reply

Your email address will not be published. Required fields are marked *