I am trying to recreate this loop written in JS. From the CryptoJS library, it takes a passphrase and a salt, hashes them 10,000 times (to later derive an AES Key and IV). I believe it is just MD5(passphrase + salt) 10,000 times.
while (derivedKeyWords.length < keySize) {
if (block) {
hasher.update(block);
}
block = hasher.update(password).finalize(salt);
hasher.reset();
// Iterations
for (var i = 1; i < 10000; i++) {
block = hasher.finalize(block);
hasher.reset();
}
derivedKey.concat(block);
}
Simple enough, but when I try to recreate this in C (using OpenSSL’s MD5 function), it gives a different derived key result.
while (sizeof(derivedkey) < keysize) {
MD5_Init(&ctx5);
if (sizeof(dgest) > 0) {
MD5_Update(&ctx5, dgest, sizeof(dgest));
}
MD5_Update(&ctx5, password, sizeof(password));
MD5_Update(&ctx5, salt, sizeof(salt));
MD5_Final(dgest, &ctx5);
for (int j = 1; j < 10000; j++) {
MD5_Init(&ctx5);
MD5_Update(&ctx5, dgest, sizeof(dgest));
MD5_Final(dgest, &ctx5);
}
strcat(derivedkey, dgest);
//I've also tried memcpy(derivedkey, dgest, sizeof(dgest));
}
Thanks!




