Uploaded June 2023 | Updated September 2026, 2 weeks ago
I stumbled over some WordPress code involving caching. Immediately I had this idea about MD5 collision and how this could affect the implemented logic. I started going down a rabbit hole exploring the feasibility and eventually setting up a PHP debug environment. Only to realize that the idea was flawed from the start. So while this ends up being failed security research, we still learn a lot along the process.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
---
get_page_by_path: developer.wordpress.org/reference/functions/get_page_by_path
Hash Collision Overview: github.com/corkami/collisions#fastcoll-md5
MD5 Collision Demo: mscs.dal.ca/~selinger/md5collision
Is there an ASCII only MD5 hash collision? twitter.com/LiveOverflow/status/1664280653519810563
Wordpress docker image with xdebug: github.com/wpdiaries/wordpress-xdebug
Debugging wordpress with xdebug: wpdiaries.com/wordpress-with-xdebug-for-docker
What is a Server? youtube.com/watch?v=VXmvM2QtuMU
CHAPTERS
00:00 - Intro
00:36 - Finding the Research Topic
03:03 - Dumb Ideas Are NOT a Problem
03:40 - "What happens with a MD5 Hash Collision?"
04:38 - MD5 Hash Collision Feasibility
09:25 - WordPress Development Environment
11:18 - Debugging PHP
12:57 - Configuring xdebug
14:42 - Realizing the Research Idea was Flawed
15:58 - What we learned from the failed research
17:10 - hextree.io
17:47 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Cryptography #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
I stumbled over some WordPress code involving caching. Immediately I had this idea about MD5 collision and how this could affect the implemented logic. I started going down a rabbit hole exploring the feasibility and eventually setting up a PHP debug environment. Only to realize that the idea was flawed from the start. So while this ends up being failed security research, we still learn a lot along the process.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
---
get_page_by_path: developer.wordpress.org/reference/functions/get_page_by_path
Hash Collision Overview: github.com/corkami/collisions#fastcoll-md5
MD5 Collision Demo: mscs.dal.ca/~selinger/md5collision
Is there an ASCII only MD5 hash collision? twitter.com/LiveOverflow/status/1664280653519810563
Wordpress docker image with xdebug: github.com/wpdiaries/wordpress-xdebug
Debugging wordpress with xdebug: wpdiaries.com/wordpress-with-xdebug-for-docker
What is a Server? youtube.com/watch?v=VXmvM2QtuMU
CHAPTERS
00:00 - Intro
00:36 - Finding the Research Topic
03:03 - Dumb Ideas Are NOT a Problem
03:40 - "What happens with a MD5 Hash Collision?"
04:38 - MD5 Hash Collision Feasibility
09:25 - WordPress Development Environment
11:18 - Debugging PHP
12:57 - Configuring xdebug
14:42 - Realizing the Research Idea was Flawed
15:58 - What we learned from the failed research
17:10 - hextree.io
17:47 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Cryptography #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.


![Video Essay about the Security Creator Scene
I wrote an article about the state of the YouTube Hacker Scene for Phrack. I hope you enjoy this reading.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
The article can be read here: http://phrack.org/issues/70/15.html#article
[ Missing parts:
1. Remember the hacking videos without audio using notepad to communicate? Thats definitely a part of the history that should have been included in this article.
[ References:
How SUDO on Linux was HACKED! // CVE-2021-3156
https://youtu.be/TLa2VqcGGEQ?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
XSS on Google Search - Sanitizing HTML in The Client?
https://www.youtube.com/watch?v=lG7U3fuNw3A
Identify Bootloader main() and find Button Press Handler
https://youtu.be/yJbnsMKkRUs?list=PLhixgUqwRTjyLgF4x-ZLVFL-CRTCrUo03
[0] Lenas Reversing for Newbies (2006) https://web.archive.org/web/20070524043123/http://www.tuts4you.com/download.php?list.17
[1] thebroken by Kevin Rose https://archive.org/details/thebroken_xvid
[2] Hak5 - Episode #1 https://www.youtube.com/watch?v=SUEXCCWMfXg
[3] Notacon 2007 Part 1 https://www.youtube.com/watch?v=HXSZ4PRLUDU
[4] CSAW CTF challenge 2.exe, 3.exe and 4.exe flag retrieval https://www.youtube.com/watch?v Ld1cD9d7tI
[5] Beginner Challenge #1... https://www.youtube.com/watch?v=tdqJ8NEcJUM
[6] Phrack issue #69 - International scenes
[7] https://reddit.com/r/WatchPeopleCode
[8] livectf REDEMPTION by geohot 7/27/2014 https://www.youtube.com/watch?v=td1KEUhlSuk
[9] Lets Hack Livestream - exploit-exercises.com (2015) https://www.youtube.com/watch?v=HBnPY77JtqY
[10] The Heap: dlmalloc unlink() exploit - bin 0x18 https://www.youtube.com/watch?v=HWhzH 89UQ
[11] Hacking Livestream #1: ReRe and EZPZP https://www.youtube.com/watch?v=XWozhb1ZOyM
[12] Life of an Exploit: Fuzzing PDFCrack with AFL for 0days https://www.youtube.com/watch?v=8VLNPIIgKbQ
[13] HackTheBox - Popcorn https://www.youtube.com/watch?v=NMGsnPSm8iw
[14] Live CTF v2: ... https://www.youtube.com/watch?v=D7uXE_lEzxI
[15] SMT in reverse engineering, for dummies https://youtu.be/b92CW-NZ3l0
[16] GoogleCTF - XSS Pasteurize https://youtu.be/voO6wu_58Ew
[17] Hacking into Googles Network for $133337 https://youtu.be/g-JgA1hvJzA
[18] https://support.google.com/youtube/answer/2801964?hl=en
[19] Data breaches, phishing, or malware? Understanding the risks of stolen credentials https://dl.acm.org/doi/abs/10.1145/3133956.3134067
[20] Zero to Hero Pentesting https://youtu.be/qlK174d_uu8?list=PLLKT MCUeiwBa7d7F_vN1GUwz_2TmVQj
[21] How the Apple AirTags were hacked https://youtu.be/_E0PWQvW-14
[22] FuzzOS: Day 1, starting the OS https://youtu.be/2YAgDJTs9So
[23] How We Hacked a TP-Link Router and Took Home $55,000 in Pwn2Own https://www.youtube.com/watch?v=zjafMP7EgEA
[24] https://www.tiktok.com/@malwaretech
[ Chapters:
CHAPTERS
00:00 - Intro
00:21 - 0. About the Author
00:50 - 1. Preamble
02:00 - 2. Before 2014
04:40 - 3. My Start in 2015
08:50 - 4. Todays Scene
15:50 - 5. Final Words
16:39 - Some Thoughts
20:06 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#YouTube #Phrack #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Video Essay about the Security Creator Scene](https://i.ytimg.com/vi/mDAwSrH4fqU/mqdefault.jpg)







