hcmode.sh (1725B)
1 # hcmode — which hashcat -m is this? 2 # 3 # hcmode the modes that come up on HTB / CPTS 4 # hcmode kerb search every mode this hashcat knows (case-insensitive) 5 # hcmode 13100 ...or look one up by number 6 # 7 # The search reads `hashcat -hh` itself, so it always matches the installed 8 # version rather than a list that rots. Not sure what the hash is? `nth -t`. 9 # 10 # From IceBreaker's hcmode; the short list there was all it could search. 11 12 if [ "$#" -eq 0 ]; then 13 cat <<'EOF' 14 0 MD5 15 100 SHA1 16 1400 SHA2-256 17 1700 SHA2-512 18 500 md5crypt $1$ 19 1800 sha512crypt $6$ 20 3200 bcrypt $2*$ 21 7400 sha256crypt $5$ 22 1000 NTLM 23 3000 LM 24 5500 NetNTLMv1 25 5600 NetNTLMv2 Responder / ntlmrelayx captures 26 2100 DCC2 (mscash2) $DCC2$ 27 13100 Kerberoast RC4 $krb5tgs$23$ 28 19700 Kerberoast AES256 $krb5tgs$18$ 29 18200 AS-REP roast $krb5asrep$23$ 30 7500 Kerberos AS-REQ pre-auth 31 13400 KeePass 32 22000 WPA-PBKDF2-PMKID+EAPOL 33 16500 JWT 34 22921 RSA/DSA/EC/OpenSSH private key ($6$) 35 13600 WinZip 36 17200 PKZIP (compressed) 37 9600 MS Office 2013 38 10500 PDF 1.4 - 1.6 39 EOF 40 echo " … hcmode <word|number> searches all of them" >&2 41 exit 0 42 fi 43 44 # Only the "Hash modes" table: the attack-mode table after it also has 45 # ` 0 | Straight`, so a bare grep made `hcmode 0` answer twice. 46 modes=$(hashcat -hh 2>/dev/null | 47 awk 'tolower($0) ~ /- \[ hash modes \] -/ { on = 1; next } /- \[/ { on = 0 } on && /^ +[0-9]+ \| /') 48 case "$1" in 49 *[!0-9]*) printf '%s\n' "$modes" | grep -iF -- "$*" ;; 50 *) printf '%s\n' "$modes" | grep -E "^ +$1 \| " ;; 51 esac || { echo "hcmode: nothing matches '$*'" >&2; exit 1; }