commit 6e972204d878787804711cb96ab82e4ea0bf9a8c parent f242877e7c98b49642693ac8ea058b6a59db5b35 Author: DAEMON <zer0sec.xp@icloud.com> Date: Sun, 13 Sep 2026 06:50:29 +0100 updated the JtR cheatsheet thanks Commit-Date: 2026-09-13T06:50:40+01:00 Commit-Host: omarchy Diffstat:
| M | src/content/sheets/password-attacks/john-the-ripper.md | | | 240 | +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++------ |
1 file changed, 223 insertions(+), 17 deletions(-)
diff --git a/src/content/sheets/password-attacks/john-the-ripper.md b/src/content/sheets/password-attacks/john-the-ripper.md @@ -5,7 +5,7 @@ category: password-attacks tags: [password-attacks, cracking, hashes] tools: [John the Ripper] difficulty: intermediate -updated: "2026-08-09" +updated: "2026-09-13" source: "vault:PasswordAttacks/john-cheatsheet.md" --- @@ -24,7 +24,7 @@ Use **John the Ripper Jumbo** (`john-jumbo`, the community build shipped on Kali 5. [Cracking Mode Flags](#5-cracking-mode-flags) 6. [Rules, Masks & Tuning](#6-rules-masks--tuning) 7. [Session, Output & Status Flags](#7-session-output--status-flags) -8. [Questions & Answers](#8-questions--answers) +8. [Running It — Worked Examples](#8-running-it--worked-examples) 9. [Alternative Approaches & Modern Tooling](#9-alternative-approaches--modern-tooling) ## 1. Quick Workflow @@ -247,34 +247,240 @@ john --list=formats # all supported formats john --test --format=sha512crypt # benchmark one format (speeds) ``` -## 8. Questions & Answers +## 8. Running It — Worked Examples + +Every example is the same two steps: **crack** with a format + wordlist, then **`--show`** the plaintext. Pin `--format=` so John never guesses wrong on a shared hash length. + +### NetNTLMv2 (Responder capture) + +```bash +# Crack — file holds the $NETNTLMv2$ line captured by Responder / ntlmrelayx +john --format=netntlmv2 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt p.agila.ntlmv2 + +# Show the recovered password +john --show --format=netntlmv2 p.agila.ntlmv2 +``` + +### NTLM / NT hash (dumped from a DC) -### Q: Which `--format` do I use for a Kerberoast hash from `GetUserSPNs.py`? -**Approach:** The output line begins with `$krb5tgs$23$...`. ```bash -john --format=krb5tgs --wordlist=rockyou.txt spns.txt +john --format=nt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt ntlm.txt +john --show --format=nt ntlm.txt ``` -**Answer:** `krb5tgs`. For AS-REP roasting (`GetNPUsers.py`, `$krb5asrep$…`) use `krb5asrep`. -### Q: I have `/etc/shadow` with `$6$` hashes. What format, and how do I combine passwd + shadow? -**Approach:** `$6$` = sha512crypt. Merge the files first with `unshadow`. +### Kerberoast — TGS ticket (`GetUserSPNs.py`) + ```bash +# Output line begins with $krb5tgs$23$... +john --format=krb5tgs --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt spns.txt +john --show --format=krb5tgs spns.txt +``` + +### AS-REP roast (`GetNPUsers.py`) + +```bash +# Output line begins with $krb5asrep$23$... +john --format=krb5asrep --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt asrep.txt +john --show --format=krb5asrep asrep.txt +``` + +### Linux `/etc/shadow` (`$6$` = sha512crypt) + +```bash +# Merge passwd + shadow first so --single can use usernames unshadow /etc/passwd /etc/shadow > unshadowed.txt -john --format=sha512crypt --wordlist=rockyou.txt unshadowed.txt +john --format=sha512crypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt unshadowed.txt +john --show --format=sha512crypt unshadowed.txt +``` + +### SSH private key + +```bash +ssh2john id_rsa > ssh.hash +john --format=ssh --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt ssh.hash +john --show --format=ssh ssh.hash +``` + +### ZIP archive + +```bash +zip2john secret.zip > zip.hash +john --format=zip --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt zip.hash +john --show --format=zip zip.hash +``` + +### KeePass database + +```bash +keepass2john Database.kdbx > kp.hash +john --format=keepass --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt kp.hash +john --show --format=keepass kp.hash +``` + +### Office document + +```bash +office2john report.docx > office.hash +john --format=office --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt office.hash +john --show --format=office office.hash +``` + +### RAR archive + +```bash +rar2john archive.rar > rar.hash +# rar2john stamps $rar5$ or $RAR3$ into the line — use rar5 for the former +john --format=rar5 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt rar.hash +john --show --format=rar5 rar.hash +``` + +### 7-Zip archive + +```bash +7z2john archive.7z > 7z.hash # may be 7z2john.pl on some builds +john --format=7z --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt 7z.hash +john --show --format=7z 7z.hash +``` + +### PDF + +```bash +pdf2john secret.pdf > pdf.hash +john --format=pdf --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt pdf.hash +john --show --format=pdf pdf.hash +``` + +### GPG / PGP secret key + +```bash +gpg2john secret.gpg > gpg.hash +john --format=gpg --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt gpg.hash +john --show --format=gpg gpg.hash +``` + +### NetNTLMv1 (Responder capture) + +```bash +john --format=netntlm --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt netntlmv1.txt +john --show --format=netntlm netntlmv1.txt +``` + +### Domain cached creds — MS-Cache v2 (DCC2) + +```bash +# Format: username:$DCC2$10240#username#hash +john --format=mscash2 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt dcc2.txt +john --show --format=mscash2 dcc2.txt +``` + +### bcrypt (htpasswd / app DB, `$2a$`/`$2b$`/`$2y$`) + +```bash +# Already a hash — no *2john needed. Slow; keep the wordlist tight. +john --format=bcrypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt bcrypt.txt +john --show --format=bcrypt bcrypt.txt +``` + +### Raw MD5 (unsalted digest) + +```bash +john --format=raw-md5 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt md5.txt +john --show --format=raw-md5 md5.txt +``` + +### LUKS full-disk encryption + +```bash +luks2john disk.img > luks.hash # or point at the LUKS device/partition +john --format=luks --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt luks.hash +john --show --format=luks luks.hash +``` + +### WPA/WPA2 handshake + +```bash +# Convert the capture, then crack the PSK +wpapcap2john capture.cap > wpa.hash +john --format=wpapsk --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt wpa.hash +john --show --format=wpapsk wpa.hash +``` + +### LM hash (legacy Windows) + +```bash +# LM is uppercase-only and split into two 7-char halves — cracks fast +john --format=lm --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt lm.txt +john --show --format=lm lm.txt +``` + +### md5crypt (`$1$` — Linux/BSD, Cisco IOS type 5) + +```bash +john --format=md5crypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt md5crypt.txt +john --show --format=md5crypt md5crypt.txt ``` -**Answer:** `sha512crypt` (running `unshadow` first lets `--single` use the usernames). -### Q: How do I crack an NTLM hash dumped from a DC? +### DES crypt (traditional 13-char Unix) + +```bash +john --format=descrypt --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt descrypt.txt +john --show --format=descrypt descrypt.txt +``` + +### MySQL 4.1+ / 5+ (leading `*`) + +```bash +john --format=mysql-sha1 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt mysql.txt +john --show --format=mysql-sha1 mysql.txt +``` + +### MSSQL 2012/2014 + ```bash -john --format=nt --wordlist=rockyou.txt ntlm.txt +john --format=mssql12 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt mssql.txt +john --show --format=mssql12 mssql.txt ``` -**Answer:** `nt`. NetNTLMv2 captures from Responder use `netntlmv2` instead. -### Q: How do I benchmark how fast John cracks a given hash type? +### Oracle 11g + +```bash +john --format=oracle11 --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt oracle.txt +john --show --format=oracle11 oracle.txt +``` + +### BitLocker volume + ```bash -john --test --format=bcrypt # prints c/s (candidates per second) +bitlocker2john -i disk.img > bitlocker.hash +john --format=bitlocker --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt bitlocker.hash +john --show --format=bitlocker bitlocker.hash ``` -**Answer:** `--test` (add `--format=` to benchmark just one; omit for all). + +### macOS keychain + +```bash +keychain2john login.keychain-db > keychain.hash +john --format=keychain --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt keychain.hash +john --show --format=keychain keychain.hash +``` + +### Bitcoin / crypto wallet + +```bash +bitcoin2john wallet.dat > wallet.hash +john --format=bitcoin --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt wallet.hash +john --show --format=bitcoin wallet.hash +``` + +### DPAPI masterkey + +```bash +# Extract with dpapi.py (impacket) or the DPAPImk2john helper first +john --format=dpapimk --wordlist=/home/daemon-sec/pentest/wordlists/rockyou.txt dpapi.hash +john --show --format=dpapimk dpapi.hash +``` + +> **Tip — benchmark before a slow run.** `john --test --format=bcrypt` prints c/s (candidates per second) so you know whether a wordlist run is minutes or days. Omit `--format=` to benchmark everything. ## 9. Alternative Approaches & Modern Tooling