EC-Council Certified Ethical Hacker (CEH) v12CryptographyHard

A security researcher discovers a vulnerability in a custom cryptographic protocol. The protocol uses a hash function for message integrity, but instead of using a keyed hash (like HMAC), it concatenates the secret key with the message and then hashes the result (e.g., H(key || message)). Which cryptographic attack is this construction primarily vulnerable to?

  1. APreimage attack
  2. BSecond preimage attack
  3. CLength extension attack
  4. DCollision attack
Show answer & explanation

Correct answer: C. Length extension attack

Concatenating the key before the message (H(key || message)) makes the construction vulnerable to length extension attacks. For hash functions built using Merkle-Damgård construction (like MD5, SHA-1, SHA-2), an attacker who knows the hash output and the length of the original message (and key) can append arbitrary data to the message and calculate a valid hash for the extended message without knowing the secret key.

Why the other options are wrong

  • A. A preimage attack aims to find a message that produces a given hash, which is not the primary vulnerability of this construction.
  • B. A second preimage attack aims to find a different message that produces the same hash as a known message, also not the primary vulnerability here.
  • D. A collision attack aims to find two different messages that produce the same hash, but this specific construction vulnerability is about extending a message, not finding collisions.

Length Extension Attack

A length extension attack is a type of cryptographic attack where an attacker can use a hash value for a secret key and a message to calculate the hash value of a new message that includes the original message plus some chosen data, without knowing the secret key. It applies to hash functions built on the Merkle-Damgård construction when the key is prepended to the message.

  • Applicable to Merkle-Damgård hashes (MD5, SHA-1, SHA-2).
  • Exploits H(key || message) construction.
  • Allows extending message and computing new valid hash.
  • Mitigated by HMAC or H(message || key) or H(key || message || key).

Memory trick: Preimages find input, collisions find pairs, length extension extends.

More Cryptography questions