The security of hash functions based on a block cipher with a block le
ngth of m bits and a key length of k bits, where k less than or equal
to in, is considered. New attacks are presented on a large class of it
erated hash functions with a am-bit hash result which processes in eac
h iteration two message blocks using two encryptions. In particular, t
he attacks break three proposed schemes: Parallel-DM, the PBGV hash fu
nction, and the LOKI DBH mode.