Password Cracking Techniques
John The Ripper
Cracking Modes
Single Crack Mode
Wordlist Mode
Incremental Mode
Cracking Files
| Tool | Description |
|---|
| pdf2john | Converts PDF documents for John |
| ssh2john | Converts SSH private keys for John |
| mscash2john | Converts MS Cash hashes for John |
| keychain2john | Converts OS X keychain files for John |
| rar2john | Converts RAR archives for John |
| pfx2john | Converts PKCS#12 files for John |
| keepass2john | Converts KeePass databases for John |
| vncpcap2john | Converts VNC PCAP files for John |
| putty2john | Converts PuTTY private keys for John |
| zip2john | Converts ZIP archives for John |
| hccap2john | Converts WPA/WPA2 handshake captures for John |
| office2john | Converts MS Office documents for John |
| wpa2john | Converts WPA/WPA2 handshakes for John |
Identifying Hash Formats
Hashcat
In the command above:
-a is used to specify the attack mode-m is used to specify the hash type<hashes> is a either a hash string, or a file containing one or more password hashes of the same type[wordlist, rule, mask, ...] is a placeholder for additional arguments that depend on the attack mode
Attack Modes
Dictionary Attack
Hashcat Rules
Mask Attack
| Symbol | Charset |
|---|
| ?l | abcdefghijklmnopqrstuvwxyz |
| ?u | ABCDEFGHIJKLMNOPQRSTUVWXYZ |
| ?d | 0123456789 |
| ?h | 0123456789abcdef |
| ?H | 0123456789ABCDEF |
| ?s | «space»!"#$%&’()*+,-./:;<=>?@[]^_`{ |
| ?a | ?l?u?d?s |
| ?b | 0x00 - 0xff |
Customizing Wordlists
Wordlist using Hashcat
| Function | Description |
|---|
| : | Do nothing |
| l | Lowercase all letters |
| u | Uppercase all letters |
| c | Capitalize the first letter and lowercase others |
| sXY | Replace all instances of X with Y |
| $! | Add the exclamation character at the end |
Generating wordlists using CeWL
Cracking Protected Files
Hunting for Encrypted Files
Hunting for SSH keys
Cracking encrypted SSH keys
Cracking password-protected documents
Cracking Protected Archives
Cracking ZIP files
Cracking OpenSSL encrypted GZIP files
Cracking BitLocker-encrypted drives
Mounting BitLocker-encrypted drives in Linux
Configure VHD as loop device