Hashcat claims to be the world's fastest password cracking tool. Today, this article will extract several common parameters and combine them with password cracking commands to analyze how to use Hashcat to crack passwords.
We know that hashcat can crack a large number of password types. It can crack about 210 passwords, the vast majority of which are hashes. To crack a password using hashcat, you first need to understand the password format, and then index the password's number in hashcat based on the password format.
We use the password: digapis, and the salt value asdf as examples to show the form of some hash values.
| Number | Name | Type | Example |
|---|---|---|---|
| 0 | MD5 | Hash, length 32 | 8713d75511bea7e0df78c6063dc778b0 |
| 1400 | SHA-256 | hash | aa106625c7de812d6118992a191ea4627e2457fa80bf6ec06f9c60cbf8e5260f |
| 1700 | SHA-512 | hash | 23afac4524f62ea4d941ca4933249b2b78d19069773266abc36d6fd17a6fbe2f4ccc834acc868358ba32ddca553611218a2865f975339fe45d38cc1999f84b5e |
| 10 | Md5($pass.$salt) | password is salted to perform MD5 once, password before | 48985c61e2581c3f9ee5f1cfb775afbc:asdf |
| 20 | md5($salt.$pass) | salt before | 4fa1dd606353e055fed67d9812bddf35:asdf |
| 2600 | md5(md5($pass)) | Password 2 times md5 | 98177c3f36af4a3f77f5b87594e6cf6a |
| 3710 | md5($salt.md5($pass)) | Password 2 times md5{ | }{}98177c3f36af4a3f77f5b87594e6cf6a{ | }{
| }3710{ | }{}md5($salt.md5($pass)){ | }{}Password 2 times md5 conversion, add salt to the beginning, and perform another md5 | 88a535877ec21b8786775a7074e4de4c:asdf |
| 4400 | md5(sha1($pass)) | password to perform sha1 conversion once, then perform MD5 | ec7bf3099984001a2b0f37ba5d1d68fa |
| 4500 | sha1(sha1($pass)) | omitted | 005a41cfe16c9a5556c7a5cdd5f1958991f2e031 |
| 1460 | HMAC-SHA256(key=$salt) | omitted | d684ab7c38ddc262f215328334c4d0273cef10d6c5e61988f5cc87fcab8a7a60:asdf |
| 11500 | CRC32 | omitted | 4C244A19:00000000 |
-a The command can specify an attack mode. To decrypt a password using hashcat, it is not enough to simply know the password number; you also need to select an attack mode that uses hashcat to decrypt the password.
Hashcat4.0.1 has five attack modes, each with its own characteristics.
| number | attack mode | meaning |
|---|---|---|
| 0 | straight | direct attack mode |
| 1 | combininstion | combination attack mode |
| 3 | Brute-force | Explosive Cracking Mode |
| 6 | Hybrid Wordlist+Mask | Dictionary+Mask Combination |
| 7 | Hybird Mask + Wordlist | Mask + dictionary combination |
In these five attack modes, we can use dictionaries for password cracking, use brute force to iterate through all possible passwords, or combine dictionaries and masks for password cracking. The parameters used in the hashcat command differ in different attack modes. We will use the straight attack mode as an example to learn how hashcat uses dictionary files for password cracking." Colleagues will also intersperse the usage of other parameters.
The direct attack mode directly uses dictionaries for password cracking. It can use a single dictionary file or multiple dictionary files for decryption. You can also make password cracking more efficient by combining a dictionary with a rule file.
hashcat -a 0 –m 0 mima.txt –o outfile dic.txt
-a specifies the attack mode as direct attack, -m specifies the hash type as MD5, and -o will write the decrypted password into the outfile.
A double dictionary attack is also a scenario in direct attack mode, where two dictionary files are loaded when a password is cracked using a dictionary file. This expands the space of the dictionary file.
Multi-dictionary attack uses loading multiple dictionary files simultaneously. The following command uses three dictionaries for dictionary attack, and loads the three dictionaries sequentially for explosion. The dic.txt in the command is the dictionary file used in the explosion.
Using the Dictionary Directory Attack will use multiple dictionary files in the dictionary directory for direct attack. Using the Dictionary Directory will load multiple dictionary files in the dictionary directory sequentially during the direct attack process. The dic in the following command is the folder where multiple dictionary files are located.
The -r/--rule-file command applies multiple rules in the rule file to each Word in the dictionary. Rule files can be generated by yourself, or you can use hashcat's built-in rule files. The rules file that comes with hashcat is usually in the rules folder. The rule files in the rules folder are as follows:
In a dictionary + rule attack, you can use a single dictionary, multiple dictionaries, or dictionary directories combined with rule files for password cracking. It's essentially a direct attack combined with a rule file.
So-called rules are similar to the programming language that generates candidate passwords. They can modify, cut, expand words, or skip some operations based on conditional operators. This allows for more flexible and efficient attacks.
Rule attacks can be used in conjunction with dual dictionaries, multiple dictionaries, and even dictionary directories. The method used is similar to a single-dictionary + rule attack.
The -o parameter is followed by the output file. The decrypted password is entered into the specified file using the -o command. The default storage format is hash:plain. There are examples of how to use this command earlier; please refer to the image above.
This command specifies the output format of the outfile file. There are 15 output modes in the Outfile file.
Outfile-format=1 Outputs only the deciphered ciphertext hash;
Outfile-format=2, outputs only the plaintext of the decrypted password.
In addition to using the -o parameter to output, we can also use the remove parameter to filter out the decrypted passwords in the ciphertext file, leaving only the undecryptable passwords. This reduces repetitive work during subsequent password cracking.
When the number of passwords to be cracked is large or the dictionary file is very large, the following option will appear. Inputting S on the keyboard will print the next status on the screen. Through this status, you can view the current password cracking progress.
It's troublesome to have to enter S every time you want to check the current password cracking progress. This is because you can use the status parameter to make the screen automatically update the status screen. Reducing the number of operations you need to perform can also reduce accidental touches.
In addition to using the status parameter to cause hashcat to automatically update the screen state, you can also use the --status-timer parameter to set the interval between status screen updates.
This is roughly how to use the direct attack mode in Hashcat. If you are interested in hashcat, you can also visit the hashcat website directly, which contains detailed information on hashcat's command parameters and various attack modes.
Article reprinted from Ding Niu Cyber Security Lab