🔐 Password Cracking Flow
Try online lookups first (CrackStation, hashes.com) - they're instant!
Hash Identification
Don't guess - identify the hash type before wasting GPU cycles!
📏 Hash Length Quick Reference
⚠️ MD5 and NTLM are both 32 chars - context matters! (Windows = NTLM, web = MD5)
Hashcat - GPU Cracking
The world's fastest password cracker. Uses GPU for blazing speed.
Basic Wordlist Attack
Rule-Based Attacks
Rules mutate wordlist entries (password → P@ssword, Password1, PASSWORD!, etc.)
Mask Attacks (Brute Force)
When you know the password pattern but not the characters.
Mask Characters
💡 Pro Tips
-O for optimized kernels-w 3 for workload tuning--show to see cracked--username if hash has user:Session Management
John the Ripper
The classic cracker. Great at auto-detecting hash types and extracting from files.
Basic Cracking
*2john - Extract Hashes from Files
John includes tools to extract crackable hashes from encrypted files.
💡 Finding *2john tools
locate *2john | head -20 # or ls /usr/share/john/
Linux /etc/shadow
Hydra - Online Brute Force
Attack live services directly - SSH, FTP, HTTP, RDP, SMB, and more.
⚠️ Warning
Online attacks can lock accounts and trigger alerts. Check lockout policy first!
Common Service Attacks
HTTP Form Attacks
🔍 Finding the right parameters
Use Burp Suite or browser DevTools → Network tab to capture the login request and see exact parameter names.
Password Spraying
Try ONE password against MANY users - avoids account lockouts!
❌ Brute Force
Many passwords → 1 user = LOCKOUT
✓ Spraying
1 password → Many users = SAFE
🎯 Passwords to Spray
Advanced Techniques
Custom Wordlist Generation
Combinator Attack
PRINCE Attack
Best Wordlists
Essential
/usr/share/wordlists/rockyou.txt
SecLists
/usr/share/seclists/Passwords/
Weakpass
weakpass.com/wordlist (multi-GB)
CrackStation
crackstation.net/buy-crackstation-wordlist-password-cracking-dictionary.htm