| # | Mode |
|---|---|
| 0 | Straight |
| 1 | Combination |
| 3 | Brute-force |
| 6 | Hybrid Wordlist + Mask |
| 7 | Hybrid Mask + Wordlist |
This Attack mode is also known as a "Dictionary Attack". There's not much to say, it's just that given a dictionary, hashcat will read the contents of the dictionary line by line, calculate the hash value of each line, and compare it with the target hash value.
example:
hashcat -a 0 -m 400 example400.hash example.dict
Baidu told me that Combination is a noun, meaning: "Combination; union; password Combination; underwear". This attack pattern is actually quite simple: it involves combining the contents of two password dictionaries. Using this attack mode requires specifying no more than two password dictionaries. Suppose we have two password dictionaries, dict1.txt and dict2.txt, with the following contents:
hunting kitty rainbow
and
paris rock
Then the command:
hashcat -m 0 -a 1 hash.txt dict1.txt dict2.txt
The dictionary actually tried is:
huntingparis Hunting Rock kittyparis kittyrock Rainbow Paris rainbowrock
The words in dict1.txt are on the left and the words in dict2.txt are on the right, for a total of 3 × 2 = 6.
The parameters associated with this pattern are:
-j, --rule-left -k, --rule-right
The rule after -j applies to the left, and the rule after -k applies to the right. If you add the parameter -j '$-', the dictionary you will actually try will be:
hunting-paris hunting rock kitty-paris kitty-rock Rainbow Paris rain-bowrock
Add parameter -j '^!', The dictionary we actually tried would be:
! huntingparis ! hunting rock ! kittyparis ! kittyrock ! Rainbow Paris ! rainbowrock
Add parameter -k '^>', then the actual dictionary attempted is:
hunting>paris hunting>rock kitty>paris kitty>rock rain>bowparis rain>bowrock
What rule is this? The usage of "$" and "^" is similar to that of regular expressions, so are they regular expressions? Actually, that's not the case. hashcat implements its own rules, which is another big chunk of content. For details, see Rule-based Attack
attempts various combinations of a given character set. According to the official hashcat wiki, this method is outdated and has been completely replaced by Mask-Attack, so no further research will be conducted.
This is a relatively novel Attack method. An example is as follows:
hashcat -a 3 -m 0 md5.hash ? l? l? l? l? l
Although according to the "Attack Modes" table, -A 3 corresponds to Brute-force, in reality, -A 3 uses Mask Attack. Mask Attack can be seen as advanced Brute-force. The
-m parameter is used to specify the hash function type, and the md5 value is stored in the md5.hash file. The key is the last string, "?l?l?l?l?l", which is called a mask.
A mask is a string consisting of several placeholders. "?l" is a placeholder, where "?" is a keyword used to modify the following "l". "?l" together represents a character set. In addition to "?l", there can also be "?u", "?d", "?h", "?h", "?s", "?a" and "?b". The character sets represented are shown in the table below.
| ? | Charset |
|---|---|
| l | abcdefghijklmnopqrstuvwxyz |
| u | abcdefghijklmnopqrstuvwxyz |
| d | 0123456789 |
| h | 0123456789abcdef |
| h | 0123456789abcdef |
| s | ! “#$%&'()*+,-./:;<=>?@[\]^_`~{|} |
| a | ? l? He? d? s |
| b | 0 – 0xff |
Thus, we understand that "?l" is actually equivalent to a password dictionary:
aaaaa aaaab ... zzzzz
Similarly, "?l?u?d" is equivalent to a password dictionary:
aA0 aA1 ... bA0 ... zZ9
The character set in the table above is built-in to hashcat. We can also specify our own character set:
--custom-charset1 = character set 1 -- custom-charset2 = charset 2 -- custom-charset3 = charset 3 --custom-charset4=charset 4
The parameter –custom-charsetN can be abbreviated to -N, such as –custom-charset1 can be abbreviated to -1. The character set specified with -N is specified in the mask as a placeholder "? N", such as:
-1 abc123 ? 1? 1? 1
is equivalent to a password dictionary:
aaa aab ... aa3 ... 333
-N In addition to the string representing the character set, it can also be a file ending in .hcchr, which stores the character set. hashcat comes with many .hcchr files, in the charsets/ directory of the installation package.
The character set represented by the placeholder '??' is the '?' itself. Other characters, when used as placeholders, represent the characters themselves. For example, "?lwerner?d" is equivalent to the password dictionary:
awerner0 awerner1 ... zwerner9
With the above knowledge, it is easy to understand mask. A mask consists of several placeholders, each placeholder is a character set, and a mask is a combination of each placeholder character set. The number of placeholders is equal to the length of the password. What are the advantages of this design over simply giving a set of characters and a password length?
Suppose we know that someone's password has a total of 7 characters, the first character is an uppercase letter, the next 3 are lowercase letters, and the last 3 are numbers. Traditional brute-force cracking requires a character set of AZ, AZ, and 0-9, totaling 62 characters, which requires a maximum of 62^7 = 3 521 614 606 208 attempts, which is trillions of characters. Using a mask to describe this password is "\u\l\l\l\d\d\d", which is easy to calculate. There are (26^4) × (10^3) = 456,976,000 possibilities, which is on the order of hundreds of millions, which is 4 orders of magnitude fewer than the previous method.
Even if we don't know the distribution of passwords, using masks can easily simulate the effects of traditional brute-force cracking.
The problem now is that the mask is fixed, and how many placeholders are fixed? What should we do if we don't know the length of the password? It's one thing if the password is too long, but if someone else's password only has 3 characters and we have 4 placeholders, and we can't crack it no matter what we do, wouldn't that be a huge loss? Do we have to start from 1 and write all the masks of each length? That's so troublesome.
There are two solutions. One is to use a mask file, write multiple masks in one file, and then specify this file in the command line. Note that the mask file must end with .hcmask.
For example, the content of test.hcmask is:
? l ? l? l ? l? l? l ? l? l? l? l
then uses the file with the following command:
hashcat -m 0 -a 3 --show md5.hash test.hcmask
Another solution is to add the parameter –increment, which tells hashcat to start trying with one placeholder according to the mask we gave, then try two, three, until we reach the given length. For example, we write the placeholder "abc" and then calculate the md5 value of the following string:
a:0cc175b9c0f1b6a831c399e269772661 b:92eb5ffee6ae2fec3ad71c777531578f c:4a8a08f09d37b73795649038408b5f33 ab:187ef4436122d1cc2f40dc2b92f0eba0 ac:e2075474294983e013ee4dd2201c7a73 ba:07159c47ee1b19ae4fb9c40d480856c4 bc:5360af35bde9ebd8f01f492dc059593c ca:5435c69ed3bcc5b2e4d580e393e373d3 cb:d0d7fdb6977b26929fb68c6083c0b439 abc:900150983cd24fb0d6963f7d28e17f72 abc:900150983cd24fb0d6963f7d28e17f72 bac:79ec16df80b57696a03bb364410061f3 bca:b64eab8ce39e013604e243089c687e4f cba:3944b025c9ca7eec3154b44666ae04a0 cab:16ecfd64586ec6c1ab212762c2c38a90
The ":" is the original string before which the hash value is to be calculated, and the ":" is the calculated hasn value. Save the above content in the file md5.hash, then run the following command:
hashcat -m 0 -a 3 --show --username md5.hash abc
Adding the parameter –username is because each of our hash values has an original string before it. If this parameter is not added, hashcat will show that the correct hash value was not found. Adding this parameter will make hashcat think that the string before the hash value is the username for that hash value, thus allowing the hash value to be loaded smoothly.
The result of running is that only one hash is resolved:
900150983cd24fb0d6963f7d28e17f72:abc
Now add the parameter –increment and run again:
hashcat -m 0 -a 3 --show --increment --username md5.hash abc
This time, two more hashes were solved:
0cc175b9c0f1b6a831c399e269772661:a 187ef4436122d1cc2f40dc2b92f0eba0:ab
As you can see, –increment works. However, we also know that with this parameter, hashcat will only try a, ab, and abc in order, and will not randomly arrange and combine placeholders to try various possibilities.
A Hybrid Attack is similar to a Combinator Attack. A Combinator Attack combines two dictionaries, while a Hybrid Attack hybridizes a dictionary with a mask. The two are similar.
Let's say we already have a dictionary, example.dict, with the following content:
hello werner
then the command:
hashcat -m 0 -a 6 md5.hash example.dict ? d? d
is equivalent to simply using a dictionary:
hello00 hello01 ... hello99 werner00 werner01 ... werener99
then the command:
hashcat -m 0 -a 7 md5.hash ? d? dexample.dict
is equivalent to simply using a dictionary:
00hello 01 Hello ... 99hello 00werner 01 Werner ... 99werener