Password cracking experts decipher elusive Equation Group crypto hash
arstechnica.com
arstechnica.com
$ echo -n غير مسجل | iconv -t CP1256 | md5sum
e6d290a03b70cfa5d4451da444bdea39 -[1] http://arstechnica.com/security/2015/02/how-omnipotent-hacke...
Interesting. Aren't MD5s vuln to collisions? http://www.wolframalpha.com/input/?i=%28convert+2+weeks+to+s...
Even if you try 3x10^17 ~= 2^58 in two weeks, MD5 has 128 bits of entropy so you'd need 2^70 ~= 1.1x10^21 times that to exhaust the space. Wolfram Alpha says that's 3.3x10^9 times the age of the universe.
All that is to say that if you (the attacker) have the hash you probably also have the salt.
In reading about it some more (particularly the md5 collision demo based on Patrick Stach's implementation), it looks like it would be trivial to create an md5 hash that resolved to a "fake" username while the real username remained uncracked. Although that would mean that both the fake username and the real one would be exempt from the exploit, so there would really be no point to it.
Yes: "using a computer that tried more than 300 billion plaintext guesses every second"
The Arabic version was obtained by doing an educated guess based on the English version