hash-cracking.md (8219B)
1 --- 2 title: "Hash Cracking" 3 section: "Cheatsheets" 4 sectionSlug: "cheatsheets" 5 sourcePath: "docs/cheatsheets/hash-cracking.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/hash-cracking.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Hash Cracking 12 13 ## Summary 14 15 * [Hashcat](https://hashcat.net/hashcat/) 16 * [Hashcat Example Hashes](https://hashcat.net/wiki/doku.php?id=example_hashes) 17 * [Hashcat Install](#hashcat-install) 18 * [Mask attack](#mask-attack) 19 * [Dictionary](#dictionary) 20 * [John](https://github.com/openwall/john) 21 * [Usage](#john-usage) 22 * [Rainbow tables](#rainbow-tables) 23 * [Tips and Tricks](#tips-and-tricks) 24 * [Online Cracking Resources](#online-cracking-resources) 25 * [References](#references) 26 27 ## Hashcat 28 29 ### Hashcat Install 30 31 ```powershell 32 apt install cmake build-essential -y 33 apt install checkinstall git -y 34 git clone https://github.com/hashcat/hashcat.git && cd hashcat && make -j 8 && make install 35 ``` 36 37 1. Extract the hash 38 2. Get the hash format: [hashcat.net/example_hashes](https://hashcat.net/wiki/doku.php?id=example_hashes) 39 3. Establish a cracking stratgy based on hash format (ex: wordlist -> wordlist + rules -> mask -> combinator mode -> prince attack -> ...) 40 4. Enjoy plains 41 5. Review strategy 42 6. Start over 43 44 ### Dictionary 45 46 > Every word of a given list (a.k.a. dictionary) is hashed and compared against the target hash. 47 48 ```powershell 49 hashcat --attack-mode 0 --hash-type $number $hashes_file $wordlist_file -r $my_rules 50 ``` 51 52 * Wordlists 53 * [packetstorm](https://packetstormsecurity.com/Crackers/wordlists/) 54 * [weakpass_3a](https://download.weakpass.com/wordlists/1948/weakpass_3a.7z) 55 * [weakpass_3](https://download.weakpass.com/wordlists/1947/weakpass_3.7z) 56 * [Hashes.org](https://download.weakpass.com/wordlists/1931/Hashes.org.7z) 57 * [kerberoast_pws](https://gist.github.com/edermi/f8b143b11dc020b854178d3809cf91b5/raw/b7d83af6a8bbb43013e04f78328687d19d0cf9a7/kerberoast_pws.xz) 58 * [hashmob.net](https://hashmob.net/research/wordlists) 59 * [clem9669/wordlists](https://github.com/clem9669/wordlists) 60 61 * Rules 62 * [One Rule to Rule Them All](https://notsosecure.com/one-rule-to-rule-them-all/) 63 * [nsa-rules](https://github.com/NSAKEY/nsa-rules) 64 * [hob064](https://raw.githubusercontent.com/praetorian-inc/Hob0Rules/master/hob064.rule) 65 * [d3adhob0](https://raw.githubusercontent.com/praetorian-inc/Hob0Rules/master/d3adhob0.rule) 66 * [clem9669/hashcat-rule](https://github.com/clem9669/hashcat-rule) 67 68 ### Mask attack 69 70 Mask attack is an attack mode which optimize brute-force. 71 72 > Every possibility for a given character set and a given length (i.e. aaa, aab, aac, ...) is hashed and compared against the target hash. 73 74 ```powershell 75 # Mask: upper*1+lower*5+digit*2 and upper*1+lower*6+digit*2 76 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?d?d 77 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?l?d?d 78 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?l?d?d?1 79 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?l?l?d?d?1 80 81 # Mask: upper*1+lower*3+digit*4 and upper*1+lower*3+digit*4 82 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?d?d?d?d 83 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?d?d?d?d 84 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?d?d?d?d 85 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?d?d?d?d?1 86 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?u?l?l?l?l?d?d?d?d?1 87 88 # Mask: lower*6 + digit*2 + special digit(+!?*) 89 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?l?l?l?l?l?l?d?d?1 90 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 "*+!??" ?l?l?l?l?l?l?d?d?1?1 91 92 # Mask: lower*6 + digit*2 93 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 /content/hashcat/masks/8char-1l-1u-1d-1s-compliant.hcmask 94 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 -1 ?l?d?u ?1?1?1?1?1?1?1?1 95 96 # Other examples 97 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?a?a?a?a?a?a?a?a?a 98 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?a?a?a?a?a?a?a?a 99 hashcat -m 1000 --status --status-timer 300 -w 4 -O /content/*.ntds -a 3 ?u?l?l?l?l?l?l?d?d?d?d 100 hashcat --attack-mode 3 --increment --increment-min 4 --increment-max 8 --hash-type $number $hashes_file "?a?a?a?a?a?a?a?a?a?a?a?a" 101 hashcat --attack-mode 3 --hash-type $number $hashes_file "?u?l?l?l?d?d?d?d?s" 102 hashcat --attack-mode 3 --hash-type $number $hashes_file "?a?a?a?a?a?a?a?a" 103 hashcat --attack-mode 3 --custom-charset1 "?u" --custom-charset2 "?l?u?d" --custom-charset3 "?d" --hash-type $number $hashes_file "?1?2?2?2?3" 104 ``` 105 106 | Shortcut | Characters | 107 | -------- | ------------------------------- | 108 | ?l | abcdefghijklmnopqrstuvwxyz | 109 | ?u | ABCDEFGHIJKLMNOPQRSTUVWXYZ | 110 | ?d | 0123456789 | 111 | ?s | !"#$%&'()*+,-./:;<=>?@[\]^_`{}~ | 112 | ?a | ?l?u?d?s | 113 | ?b | 0x00 - 0xff | 114 115 ## John 116 117 ### John Usage 118 119 ```bash 120 # Run on password file containing hashes to be cracked 121 john passwd 122 123 # Use a specific wordlist 124 john --wordlist=<wordlist> passwd 125 126 # Use a specific wordlist with rules 127 john --wordlist=<wordlist> passwd --rules=Jumbo 128 129 # Show cracked passwords 130 john --show passwd 131 132 # Restore interrupted sessions 133 john --restore 134 ``` 135 136 ## Rainbow tables 137 138 > The hash is looked for in a pre-computed table. It is a time-memory trade-off that allows cracking hashes faster, but costing a greater amount of memory than traditional brute-force of dictionary attacks. This attack cannot work if the hashed value is salted (i.e. hashed with an additional random value as prefix/suffix, making the pre-computed table irrelevant) 139 140 ## Tips and Tricks 141 142 * Cloud GPU 143 * [penglab - Abuse of Google Colab for cracking hashes. 🐧](https://github.com/mxrch/penglab) 144 * [google-colab-hashcat - Google colab hash cracking](https://github.com/ShutdownRepo/google-colab-hashcat) 145 * [Cloudtopolis - Zero Infrastructure Password Cracking](https://github.com/JoelGMSec/Cloudtopolis) 146 * [Nephelees - also a NTDS cracking tool abusing Google Colab](https://github.com/swisskyrepo/Nephelees) 147 * Build a rig on premise 148 * [Pentester's Portable Cracking Rig - $1000](https://www.netmux.com/blog/portable-cracking-rig) 149 * [How To Build A Password Cracking Rig - 5000$](https://www.netmux.com/blog/how-to-build-a-password-cracking-rig) 150 * Online cracking 151 * [Hashes.com](https://hashes.com/en/decrypt/hash) 152 * [hashmob.net](https://hashmob.net/): great community with Discord 153 * Use the `loopback` in combination with rules and dictionary to keep cracking until you don't find new passsword: `hashcat --loopback --attack-mode 0 --rules-file $rules_file --hash-type $number $hashes_file $wordlist_file` 154 * PACK (Password Analysis and Cracking Kit) 155 * [iphelix/pack](https://github.com/iphelix/pack/blob/master/README) 156 * Can produce custom hcmask files to use with hashcat, based on statistics and rules applied on an input dataset 157 * Use Deep Learning 158 * [brannondorsey/PassGAN](https://github.com/brannondorsey/PassGAN) 159 160 ## Online Cracking Resources 161 162 * [hashes.com](https://hashes.com) 163 * [crackstation.net](https://crackstation.net) 164 * [hashmob.net](https://hashmob.net/) 165 166 ## References 167 168 * [Cracking - The Hacker Recipes](https://www.thehacker.recipes/ad-ds/movement/credentials/cracking) 169 * [Using Hashcat to Crack Hashes on Azure](https://durdle.com/2017/04/23/using-hashcat-to-crack-hashes-on-azure/) 170 * [miloserdov.org hashcat](https://miloserdov.org/?p=5426&PageSpeed=noscript) 171 * [miloserdov.org john](https://miloserdov.org/?p=4961&PageSpeed=noscript) 172 * [DeepPass — Finding Passwords With Deep Learning - Will Schroeder - Jun 1](https://posts.specterops.io/deeppass-finding-passwords-with-deep-learning-4d31c534cd00)