If you look closely at the url you'll also find a challenge in there..
So it's a challenge/response type authentication.
Just sniffing the current MD5 won't help you as it depends on the challenge..

http://en.wikipedia.org/wiki/Challen...authentication