# length-extension-attacks

Published articles for length-extension-attacks.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Length Extension Attacks: How Hash-Based Signatures Can Be Forged

DevFeed: [Length Extension Attacks: How Hash-Based Signatures Can Be Forged](<https://devfeed.tech/articles/length-extension-attacks-how-hash-based-signatures-can-be-forged-84159.md>)

Original publisher: [Read original article](<https://hackernoon.com/length-extension-attacks-how-hash-based-signatures-can-be-forged?source=rss>)

Author: viodex

Published: 2026-10-09T08:38:27Z

Content type: tutorial

Language: en

Sources: [HackerNoon](<https://devfeed.tech/sources/hackernoon.md>)

Topics: [hashing](<https://devfeed.tech/topics/hashing.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cryptography](<https://devfeed.tech/tags/cryptography.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [hash-padding-vulnerability](<https://devfeed.tech/tags/hash-padding-vulnerability.md>), [hashes-vulnerabilities](<https://devfeed.tech/tags/hashes-vulnerabilities.md>), [keyed-hash-authentication](<https://devfeed.tech/tags/keyed-hash-authentication.md>), [length-extension-attack](<https://devfeed.tech/tags/length-extension-attack.md>), [length-extension-attacks](<https://devfeed.tech/tags/length-extension-attacks.md>), [md5-hash-security](<https://devfeed.tech/tags/md5-hash-security.md>), [padding](<https://devfeed.tech/tags/padding.md>)

### AI overview

The tutorial explains length extension attacks against secret-prefixed MD5 hashes through message padding, internal state, and worked examples. It describes using an original message, its digest, and a known or guessed secret length to append data and generate a valid signature without recovering the secret. It also demonstrates hash_extender and explains that practical impact depends on signature construction and application behavior.

### Source excerpt

Learn how Length Extension Attacks work by exploring MD5 internals, message padding, internal states, and how attackers can extend signed data without knowing t