NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

hcmode.sh (1725B)


      1 # hcmode — which hashcat -m is this?
      2 #
      3 #   hcmode            the modes that come up on HTB / CPTS
      4 #   hcmode kerb       search every mode this hashcat knows (case-insensitive)
      5 #   hcmode 13100      ...or look one up by number
      6 #
      7 # The search reads `hashcat -hh` itself, so it always matches the installed
      8 # version rather than a list that rots. Not sure what the hash is? `nth -t`.
      9 #
     10 # From IceBreaker's hcmode; the short list there was all it could search.
     11 
     12 if [ "$#" -eq 0 ]; then
     13   cat <<'EOF'
     14      0  MD5
     15    100  SHA1
     16   1400  SHA2-256
     17   1700  SHA2-512
     18    500  md5crypt              $1$
     19   1800  sha512crypt           $6$
     20   3200  bcrypt                $2*$
     21   7400  sha256crypt           $5$
     22   1000  NTLM
     23   3000  LM
     24   5500  NetNTLMv1
     25   5600  NetNTLMv2             Responder / ntlmrelayx captures
     26   2100  DCC2 (mscash2)        $DCC2$
     27  13100  Kerberoast  RC4       $krb5tgs$23$
     28  19700  Kerberoast  AES256    $krb5tgs$18$
     29  18200  AS-REP roast          $krb5asrep$23$
     30   7500  Kerberos AS-REQ pre-auth
     31  13400  KeePass
     32  22000  WPA-PBKDF2-PMKID+EAPOL
     33  16500  JWT
     34  22921  RSA/DSA/EC/OpenSSH private key ($6$)
     35  13600  WinZip
     36  17200  PKZIP (compressed)
     37   9600  MS Office 2013
     38  10500  PDF 1.4 - 1.6
     39 EOF
     40   echo "  … hcmode <word|number> searches all of them" >&2
     41   exit 0
     42 fi
     43 
     44 # Only the "Hash modes" table: the attack-mode table after it also has
     45 # `  0 | Straight`, so a bare grep made `hcmode 0` answer twice.
     46 modes=$(hashcat -hh 2>/dev/null |
     47   awk 'tolower($0) ~ /- \[ hash modes \] -/ { on = 1; next } /- \[/ { on = 0 } on && /^ +[0-9]+ \| /')
     48 case "$1" in
     49   *[!0-9]*) printf '%s\n' "$modes" | grep -iF -- "$*" ;;
     50   *) printf '%s\n' "$modes" | grep -E "^ +$1 \| " ;;
     51 esac || { echo "hcmode: nothing matches '$*'" >&2; exit 1; }