Specifically, there's a 1-in-2^128 chance that any 128-bit input will give itself as the output. Over 2^128 trials the chance that no input answers itself would be:
(1-(2^-128))^(2^128)
...which mAlphaMatica helpfully calculates as...http://www.wolframalpha.com/input/?i=(1-2^-128)^(2^128)
0.367879441171442321595523770
That is, there's about a 63% chance Kember's quest to find an input whose MD5 output is itself will succeed.Or, is there something in MD5's construction making this impossible, making the random-oracle model inapplicable?