Modern & Applied Cryptography Breakers Intermediate
Breaking MD5 with Collision Attacks
Every hash function is vulnerable to a generic birthday attack. MD5 is vulnerable to something worse: a real, structural flaw that produces full 128-bit collisions far faster than any generic attack should allow. Both are demonstrated here, live and verified.