Practical Password Recovery on an MD5 Challenge and Response.
Yu Sasaki, Go Yamamoto, Kazumaro Aoki · 2007
This paper shows an attack against APOP protocol which is a challenge-and-response protocol. We utilize the Wang's attack to make collisions in MD5, and apply it to APOP protocol. We confirmed that the first 3 octets of secret key can be recovered by several hundred queries under the man-in-the-middle environment.