daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hash-cracking.md (8219B)


      1 ---
      2 title: "Hash Cracking"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/hash-cracking.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/hash-cracking.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hash Cracking
     12 
     13 ## Summary
     14 
     15 * [Hashcat](https://hashcat.net/hashcat/)
     16     * [Hashcat Example Hashes](https://hashcat.net/wiki/doku.php?id=example_hashes)
     17     * [Hashcat Install](#hashcat-install)
     18     * [Mask attack](#mask-attack)
     19     * [Dictionary](#dictionary)
     20 * [John](https://github.com/openwall/john)
     21     * [Usage](#john-usage)
     22 * [Rainbow tables](#rainbow-tables)
     23 * [Tips and Tricks](#tips-and-tricks)
     24 * [Online Cracking Resources](#online-cracking-resources)
     25 * [References](#references)
     26 
     27 ## Hashcat
     28 
     29 ### Hashcat Install
     30 
     31 ```powershell
     32 apt install cmake build-essential -y
     33 apt install checkinstall git -y
     34 git clone https://github.com/hashcat/hashcat.git && cd hashcat && make -j 8 && make install
     35 ```
     36 
     37 1. Extract the hash
     38 2. Get the hash format: [hashcat.net/example_hashes](https://hashcat.net/wiki/doku.php?id=example_hashes)
     39 3. Establish a cracking stratgy based on hash format (ex: wordlist -> wordlist + rules -> mask -> combinator mode -> prince attack -> ...)
     40 4. Enjoy plains
     41 5. Review strategy
     42 6. Start over
     43 
     44 ### Dictionary
     45 
     46 > Every word of a given list (a.k.a. dictionary) is hashed and compared against the target hash.
     47 
     48 ```powershell
     49 hashcat --attack-mode 0 --hash-type $number $hashes_file $wordlist_file -r $my_rules
     50 ```
     51 
     52 * Wordlists
     53     * [packetstorm](https://packetstormsecurity.com/Crackers/wordlists/)
     54     * [weakpass_3a](https://download.weakpass.com/wordlists/1948/weakpass_3a.7z)
     55     * [weakpass_3](https://download.weakpass.com/wordlists/1947/weakpass_3.7z)
     56     * [Hashes.org](https://download.weakpass.com/wordlists/1931/Hashes.org.7z)
     57     * [kerberoast_pws](https://gist.github.com/edermi/f8b143b11dc020b854178d3809cf91b5/raw/b7d83af6a8bbb43013e04f78328687d19d0cf9a7/kerberoast_pws.xz)
     58     * [hashmob.net](https://hashmob.net/research/wordlists)
     59     * [clem9669/wordlists](https://github.com/clem9669/wordlists)
     60 
     61 * Rules
     62     * [One Rule to Rule Them All](https://notsosecure.com/one-rule-to-rule-them-all/)
     63     * [nsa-rules](https://github.com/NSAKEY/nsa-rules)
     64     * [hob064](https://raw.githubusercontent.com/praetorian-inc/Hob0Rules/master/hob064.rule)
     65     * [d3adhob0](https://raw.githubusercontent.com/praetorian-inc/Hob0Rules/master/d3adhob0.rule)
     66     * [clem9669/hashcat-rule](https://github.com/clem9669/hashcat-rule)
     67 
     68 ### Mask attack
     69 
     70 Mask attack is an attack mode which optimize brute-force.
     71 
     72 > Every possibility for a given character set and a given length (i.e. aaa, aab, aac, ...) is hashed and compared against the target hash.
     73 
     74 ```powershell
     75 # Mask: upper*1+lower*5+digit*2 and upper*1+lower*6+digit*2 
     76 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?d?d
     77 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?l?d?d 
     78 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?l?d?d?1
     79 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?l?l?d?d?1 
     80 
     81 # Mask: upper*1+lower*3+digit*4 and upper*1+lower*3+digit*4
     82 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?d?d?d?d
     83 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?d?d?d?d
     84 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?d?d?d?d
     85 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?d?d?d?d?1
     86 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?d?d?d?d?1
     87 
     88 # Mask: lower*6 + digit*2 + special digit(+!?*)
     89 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?l?l?l?l?l?l?d?d?1
     90 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?l?l?l?l?l?l?d?d?1?1
     91 
     92 # Mask: lower*6 + digit*2
     93 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 /content/hashcat/masks/8char-1l-1u-1d-1s-compliant.hcmask
     94 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 ?l?d?u ?1?1?1?1?1?1?1?1
     95 
     96 # Other examples
     97 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?a?a?a?a?a?a?a?a?a
     98 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?a?a?a?a?a?a?a?a 
     99 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?l?d?d?d?d
    100 hashcat --attack-mode 3 --increment --increment-min 4 --increment-max 8 --hash-type $number $hashes_file "?a?a?a?a?a?a?a?a?a?a?a?a"
    101 hashcat --attack-mode 3 --hash-type $number $hashes_file "?u?l?l?l?d?d?d?d?s"
    102 hashcat --attack-mode 3 --hash-type $number $hashes_file "?a?a?a?a?a?a?a?a"
    103 hashcat --attack-mode 3 --custom-charset1 "?u" --custom-charset2 "?l?u?d" --custom-charset3 "?d" --hash-type $number $hashes_file "?1?2?2?2?3"
    104 ```
    105 
    106 | Shortcut | Characters                      |
    107 | -------- | ------------------------------- |
    108 | ?l       | abcdefghijklmnopqrstuvwxyz      |
    109 | ?u       | ABCDEFGHIJKLMNOPQRSTUVWXYZ      |
    110 | ?d       | 0123456789                      |
    111 | ?s       | !"#$%&'()*+,-./:;<=>?@[\]^_`{}~ |
    112 | ?a       | ?l?u?d?s                        |
    113 | ?b       | 0x00 - 0xff                     |
    114 
    115 ## John
    116 
    117 ### John Usage
    118 
    119 ```bash
    120 # Run on password file containing hashes to be cracked
    121 john passwd
    122 
    123 # Use a specific wordlist
    124 john --wordlist=<wordlist> passwd
    125 
    126 # Use a specific wordlist with rules
    127 john --wordlist=<wordlist> passwd --rules=Jumbo
    128 
    129 # Show cracked passwords
    130 john --show passwd
    131 
    132 # Restore interrupted sessions
    133 john --restore
    134 ```
    135 
    136 ## Rainbow tables
    137 
    138 > The hash is looked for in a pre-computed table. It is a time-memory trade-off that allows cracking hashes faster, but costing a greater amount of memory than traditional brute-force of dictionary attacks. This attack cannot work if the hashed value is salted (i.e. hashed with an additional random value as prefix/suffix, making the pre-computed table irrelevant)
    139 
    140 ## Tips and Tricks
    141 
    142 * Cloud GPU
    143     * [penglab - Abuse of Google Colab for cracking hashes. 🐧](https://github.com/mxrch/penglab)
    144     * [google-colab-hashcat - Google colab hash cracking](https://github.com/ShutdownRepo/google-colab-hashcat)
    145     * [Cloudtopolis - Zero Infrastructure Password Cracking](https://github.com/JoelGMSec/Cloudtopolis)
    146     * [Nephelees - also a NTDS cracking tool abusing Google Colab](https://github.com/swisskyrepo/Nephelees)
    147 * Build a rig on premise
    148     * [Pentester's Portable Cracking Rig - $1000](https://www.netmux.com/blog/portable-cracking-rig)
    149     * [How To Build A Password Cracking Rig - 5000$](https://www.netmux.com/blog/how-to-build-a-password-cracking-rig)
    150 * Online cracking
    151     * [Hashes.com](https://hashes.com/en/decrypt/hash)
    152     * [hashmob.net](https://hashmob.net/): great community with Discord
    153 * Use the `loopback` in combination with rules and dictionary to keep cracking until you don't find new passsword: `hashcat --loopback --attack-mode 0 --rules-file $rules_file --hash-type $number $hashes_file $wordlist_file`
    154 * PACK (Password Analysis and Cracking Kit)
    155     * [iphelix/pack](https://github.com/iphelix/pack/blob/master/README)
    156     * Can produce custom hcmask files to use with hashcat, based on statistics and rules applied on an input dataset
    157 * Use Deep Learning
    158     * [brannondorsey/PassGAN](https://github.com/brannondorsey/PassGAN)
    159 
    160 ## Online Cracking Resources
    161 
    162 * [hashes.com](https://hashes.com)
    163 * [crackstation.net](https://crackstation.net)
    164 * [hashmob.net](https://hashmob.net/)
    165 
    166 ## References
    167 
    168 * [Cracking - The Hacker Recipes](https://www.thehacker.recipes/ad-ds/movement/credentials/cracking)
    169 * [Using Hashcat to Crack Hashes on Azure](https://durdle.com/2017/04/23/using-hashcat-to-crack-hashes-on-azure/)
    170 * [miloserdov.org hashcat](https://miloserdov.org/?p=5426&PageSpeed=noscript)
    171 * [miloserdov.org john](https://miloserdov.org/?p=4961&PageSpeed=noscript)
    172 * [DeepPass — Finding Passwords With Deep Learning - Will Schroeder - Jun 1](https://posts.specterops.io/deeppass-finding-passwords-with-deep-learning-4d31c534cd00)