Tutorial on cracking passwords using GPU graphics card performanc

Because most password cracking tools are extremely slow and support few password cracking protocols, some passwords cannot be cracked even after a year of brute-force cracking. To run a password using a dictionary, the plaintext password must be in the dictionary. Moreover, if the password dictionary is too large, it is a waste of time and failure to crack is common. Below is a recommendation for the world's fastest password cracking tool: hashcat. Simply download the latest version from the hashcat github link.

windows系统下使用GPU显卡性能破解密码教程,含示例,详细步骤!

 

 

 

hashcat supports multiple computing cores:

GPU
CPU
APU
DSP
FPGA
Coprocessor

Download the official NVIDA driver

From the NVIDA official website, download the graphics card driver corresponding to your computer's graphics card model as shown in the image, and then follow the prompts to install it step by step.

windows系统下使用GPU显卡性能破解密码教程,含示例,详细步骤!

 

 

 

After installation, restart your computer.

(NAVIDA's graphics card only needs to install the official driver, which already includes the GPU computing tools required for HASHCAT to crack passwords. Remember to use the officially downloaded graphics card driver in the image above, not the graphics card driver that comes with windows.)

 

Test whether HASHCAT can use GPU computing speed to crack passwords

1 hashcat64.exe -b

windows系统下使用GPU显卡性能破解密码教程,含示例,详细步骤!

 

 

 Benchmark test HASHCAT's speed in cracking various password hashes.

windows系统下使用GPU显卡性能破解密码教程,含示例,详细步骤!

 

 

 Check settings If the GPU is installed correctly, it will be visible and will list its properties and the driver information used.

hashcat detailed command and use of


normal

1 -m, —hash-type=NUM hash category, whose NUM value refers to the hash category value under its help information, and whose value is a number. If no m value is specified, it defaults to md5, for example -m 1800 is sha512  Linux encryption.  2  3 -a, –attack-mode=NUM  attack mode, the value of which refers to the following parameter. "-A 0" dictionary attack, "-A 1"  combination attack; "-A 3" mask attack.  4  5 -V, -version version information 6  7 -h, -help help information.  8  9 –quiet quiet mode, Suppress output

benchmark

1 -b, –benchmark Tests computer cracking speed and displays hardware-related information

 


Miscellaneous

 1 –hex-salt salt value is given in hex  2   3 –hex-charset Set charset is given in hex  4   5 –runtime=NUM Medium after seconds of running (NUM value) 

 

FILE

 1 -o, –outfile=FILE Define hash FILE to restore output FILE  2   3 –outfile-format=NUM Define hash FILE output format as referenced below  4   5 –outfile-autohex-disable disable hex output plaintext  6   7 -p, –separator=CHAR Define separator characters for hash list/output FILE  8    14  15 –remove Removes successfully cracked hashes, useful when the hash is read from text, avoiding manually removing already cracked hashes 16  17 –stdout Console mode 18  19 –potfile-disable Does not write to pot files 20  21 –debug-mode=NUM Define debug mode (mixing only by using rules), see references below 22  23 –debug-file=file Output file for debug rules (see debug mode) 24  25 -e, –salt-file=file Define salted file list{    – words-limit=NUM Word limit (distributed)

 

rules

1 -r,  – rules-file=file Use rule files: -r 1.rule, 2  3 -g,  – generate-rules=NUM Randomly generate rules 4  5  – generate-rules-func-min= min per random rule 6  7  – generate-rules-func-max=max per random rule 8  9  – generate-rules-seed= dabcdef :  settings? 1  is 0123456789abcdef 6  7 -4, –custom-charset4=CS -2mycharset.hcchr : set ? 2  is contained in mycharset. hcchr

 

Attack Mode

 1 –toggle-min=NUM Minimum Value of Letters in Dictionary  2   3 –toggle-max=NUM Maximum Value of Letters in Dictionary  4   5 –increment Use Enhanced Mode  6   7 –increment-min=NUM Enhanced Mode Start Value  8   9 –increment-max=NUM Enhanced Mode End Value 10{ Then print the candidate characters  24  25 –elem-cnt-min=NUM Minimum number of elements per chain  26  27 –elem-cnt-max=NUM Maximum number of elements per chain  28  29 –wl-dist-len Calculate the output length distribution from the dictionary table  30  31 –wl-max=NUM Load NUM words from the dictionary file, setting 0 to disable loading.  32  33  – case-permute Reverse each Word in the dictionary

 

 

Reference

1 = hash[:salt] 2 = plain plain 3 = hash[:salt]:plain 4 = hex_plain 5 = hash[:salt]:hex_plain 6 = plain:hex_plain 7 = hash[:salt]:plain:hex_plain 8 = crackpos 9 = hash[:salt]:crackpos 10 = plain:crackpos 11 = hash[:salt]:plain:crackpos 12  Debug mode output file (for hybrid mode only, by using rules):

1 = save finding rule 2 = save original Word 3 = save original Word and finding rule 4 = save original Word, finding rule andmodified plain

 

<89x8 9> Built-in character set:

 1 ? l = abcdefghijklmnopqrstuvwxyz  represents lowercase letters  2   3 ? u = ABCDEFGHIJKLMNOPQRSTUVWXYZ  represents uppercase letters  4   5 ? d = 0123456789  represents the number   6   7 ? s = !” #$%&’()*+,-./:; < = >? @[\]^_`{|}~  represents special characters   8   9 ? A = ? l? He? d? s Combination of uppercase and lowercase numbers and special characters 10  11 ? b = 
0 – 0xff

 

Attack Mode

 1 0 = Straight  (Dictionary Cracking)  2   3 1 = Combination  (Combination Cracking)  4   5 2 = Toggle- case conversion)   6   7 3 = Brute-force   8   9 4 = Permutation  10  11 5 = Table-Lookup  12  13 6 = Hybrid dict + mask  Dictionary plus mask Cracking   14     15   7   =   Hybrid   mask   +   dict   mask + Dictionary Cracking   16     17   8   =   Prince (Prince Cracking) 

 

Hash type
For examples of specific hash values, please refer to the website

  1 0 = md5   2    3 10 = md5($pass.$salt)    4    5 20 = md5($salt.$pass)    6    7 30 = md5(unicode($pass). $salt)   8    9 40 = md5($salt. unicode($pass))  10   11 50 = HMAC-MD5 (key = $pass)  12   13 60 = HMAC-MD5 (key = $salt)  14   15 100 = sha1  16   17 110 = sha1($pass.$salt)   18   19 120 = sha1($salt.$pass)   20   21 130 = sha1(unicode($pass). $salt)  22   23 140 = sha1($salt. unicode($pass))  24   25 150 = HMAC-SHA1 (key = $pass)  26   27 160 = HMAC-SHA1 (key = $salt)  28   29 200 = MySQL323  30   31 300 = MySQL4.1/MySQL5  32   33 400 = phpass,{   MSCache  42   43 1400 = sha256  44   45 1410 = sha256($pass.$salt)   46   47 1420 = sha256($salt.$pass)   48   49 1430 = sha256(unicode($pass). $salt)  50   51 1431 = base64(sha256(unicode($pass)))  52   53 1440 = sha256($salt. unicode($pass))  54   55 1450 = HMAC-SHA256 (key = $pass)  56   57 1460 = HMAC-SHA256 (key = $salt)  58   59 1600 = md5apr1, MD5(APR), Apache MD5  60   61 1700 = sha512  62 72   73 1760 = HMAC-SHA512 (key = $salt)  74   75 1800 = SHA-512(Unix)  76   77 2400 = Cisco-PIX md5  78   79 2410 = Cisco-ASA md5  80   81 2500 = WPA/WPA2  82 { } $pass)  92   93 3710 = md5($salt. md5($pass))  94   95 3720 = md5($pass. md5($salt))  96   97 3800 = md5($salt.$pass.$salt)   98   99 3910 = md5(md5($pass). md5($salt)) 100  101 4010 = md5($salt. md5($salt.$pass) ) 102  103 4110 = md5($salt. md5($pass.$salt) ) 104  105 4210 = md5($username.0.$pass)  106  107 4300 = md5(strtoupper(md5($pass))) 108  109 4400 = md5(sha1($pass)) 110  111 4500 = Double sha1 112  113 4600 = sha1($pass))) 114  115 4700 = sha1(md5($pass)) 116  117 4800 = md5(Chap),{   120  121 5000 = SHA-3(Keccak) 122  123 5100 = Half MD5 124  125 5200 = Password Safe SHA-256 126  127 5300 = IKE-PSK MD5 128  129 5400 = IKE-PSK SHA1 130  131 5500 = NetNTLMv1-VANILLA /{  700 = AIX {ssha1} 146  147 6900 = GOST, GOST R 34.11-94 148  149 7000 = Fortigate (FortiOS) 150  151 7100 = OS X v10.8+ 152  153 7200 = GRUB 2 154  155 7300 = IPMI2 RAKP HMAC-SHA1 156  157 7400 = sha256crypt, SHA256(Unix) 158  159 7900 = Drupal7 160  161 8400 = WBB3,  Woltlab Burning Board 3 162  163 8900 = scrypt 164  165 9200 = Cisco $8$ 166  167 9300 = Cisco $9$ 168  169 9800 = Radmin2 170  171 10000 = Django (PBKDF2-SHA256) 172  173 10200 =  1}digest authentication (MD5) 184  185 99999 = Plaintext

 

special hash type

 1 11 = Joomla < 2.5.18  2   3 12 = PostgreSQL  4   5 21 = osCommerce, xt:Commerce  6   7 23 = Skype  8   9 101 = nsldap, SHA-1(Base64), Netscape LDAPSHA 10   v10.6 18  19 123 = EPi 20  21 124 = Django (SHA-1) 22  23 131 = MSSQL(2000) 24  25 132 = MSSQL(2005) 26  27 133 = PeopleSoft 28  29 141 =   LDAP {SSHA512} 36  37 1722 = OS X v10.7 38  39 1731 = MSSQL(2012 & 2014) 40  41 2611 = vBulletin < v3.8.5 42  43 2612 = PHPS 44<180x179> Step 4: hashcat Cracking password Rule Example 

  1  (1) Dictionary Attack    2    3 -a 0 password.lst   4  (2) 1 to 8 are digital mask attacks    5    6 -a 3 --increment --increment-min 1--increment-max 8 ? d? d? d? d? d? d? d? d -O   7 ? d represents a number; can it be replaced with a lowercase letter? l, a capital letter? u, special character? s, uppercase and lowercase letter + special character? A and –O represent the optimized cracking mode; this parameter may or may not be added.    8    9  (3) 8 is a number attack   10   11 -A 3 ? d? d? d? d? d? d? d? d  12  Similarly, it can be set to modes such as uppercase, lowercase, and special characters based on the number of bits.   13   14 (4) Custom characters   15  Passwords that are purely numeric or purely alphabetic are relatively rare nowadays. According to the analysis of leaked passwords by cryptography experts, 90% of personal passwords are a combination of letters and numbers, which can be brute-forced using custom characters. Hashcat supports 4 custom character sets, namely  -1 -2 -3 -4. Do you only need to do this when defining -2 ? l? d , then you can specify ? 2,? 2 represents lowercase letters and numbers.At this point, you need to crack an 8-digit mixed lowercase letter plus number:   16   17 Hashcat.exe -a 3 –force -2 ? l? d   hash value or hash file  ? 2? 2? 2? 2? 2? 2? 2? 2  18 For example, cracking dz lowercase letters + numbers mixed 8-digit password:   19   20 Hashcat -m 2611 -a 3 -2 ? l? d dz.hash ? 2? 2? 2? 2? 2? 2? 2? 2  21 (5) Dictionary + Mask Brute Force Cracking  22 Hashcat also supports a dictionary plus brute force cracking method, which is to add a brute force character sequence before and after the dictionary, such as adding 3 as a number after the dictionary. This type of password is very common. Use the sixth attack mode:   23   24 a-6 (Hybrid dict + mask)  25 If it is added before the dictionary, use the seventh attack mode, which is ( a-7 = Hybridmask + dict). The following is to crack the dictionary file by adding the number 123:   26   27 H.exe -a 6 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst ? d? d? d  28 If the password for ffe1cb31eb084cd7a8dd1228c23617c8 is password123, then as long as password.lst contains 123   29   30  (6) Mask + Dictionary Brute Force   31   32 H.exe -a 7 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst ? d? d? d  33 If the password for ffe1cb31eb084cd7a8dd1228c23617c8 is 123password, then password.lst only needs to contain the password.  34   35 (7) Case conversion attack, case conversion attack on words in password.lst  36   37 H.exe-a 2 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst  38 EXAMPLES  39 (1) 8-digit number cracking  40   41 Hashcat64-m 9700 hash -a 3 ? d? d? d? d? d? d? d? d -w 3 –O  42 (2) 1-8 digit cracking  43   44 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? d? d? d? d? d? d? d? d  45 (3) 1 to 8 lowercase letter cracking  46   47 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? l? l? l? l? l? l? l? l  48 (4) 8-digit lowercase letter cracking  49   50 Hashcat-m 9700 hash -a 3 ? l? l? l? l? l? l? l? l -w 3 –O  51 (5) 1-8 uppercase letter cracking  52   53 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? He? He? He? He? He? He? He? u  54 (6) 8-digit uppercase letter cracking  55   56 Hashcat-m 9700 hash -a 3 ? He? He? He? He? He? He? He? u -w 3 –O  57 (7) 5-digit lowercase +  uppercase + number + special character cracking   58   59 Hashcat-m 9700 hash -a 3 ? b? b? b? b? b -w 3  60 (8) Use a dictionary to crack   61 Use the password.lst dictionary to brute-force cracking, -w 3 parameter specifies power consumption   62   63 hashcat -m 9700 -A 0 -w 3 hash password.lst  64 After successful cracking, hashcat will automatically terminate the cracking and display the cracking status as Cracked. Recvoered will also display whether the cracking was successful.  65   66 Cracking the IP address in known_hosts  67 After research, it was found that in known_hosts   68   69  (1) Calculate HMAC SHA1 value  70   71 gitclone https://github.com/persona5/hexhosts.git  72 cdhexhosts  73 gcchexhosts.c -lresolv -w -o hexhosts  74 ./hexhosts  75 获取known_hosts的HMAC SHA1加密值:  76   77 注意:known_hosts值一定要正确,可以将known_hosts文件复制到hexhosts文件目录。  78   79 (2)组合攻击暴力破解  80   81 hashcat-a 1 -m 160 known_hosts.hash ips_left.txt ips_right.txt --hex-salt  82 组合攻击是将ips_left.txt和ips_right.txt进行组合,形成完整的IP地址进行暴力破解。  83   84  The ips_left.txt and ips_right.txt files can be generated with the following code:   85   86 ip-gen.sh:   87   88    89   90 for a in `seq 0 255`  91   92 do  93   94 for b in `seq0 255`  95   96 do  97   Attack with Mask  106  107 hashcat -a 3 -m 160 known_hosts.hash ipv4.hcmask--hex-salt 108 ipv4.hcmask The contents of the file can be downloaded from this site.  109  110  Cracking MD5 Encrypted IP Addresses  111  In networks or configurations such as CDNs, IP addresses are often encrypted with MD5. Since its number of bits is 3×4+3 (xxx.xxx.xxx.xxx) = 17 bits, cracking it with a normal password takes a very long time. However, by analyzing the patterns of its IP addresses, it is found that its addresses xxx are all numbers. Therefore, attacks can be carried out using a combination of hashcats and masks.  112  113 hashcat-a 1 -m 0 ip.md5.txt ips_left.txt ips_right.txt 114  115 hashcat -a1 -m 0 ip.md5.txt ipv4.hcmask 116  Additionally, the IP address of F5 is encrypted in the cookie. The cracking code you can refer to is as follows:  117  118 import struct 119  120 cookie = "1005421066.20736.0000" 121  122 (ip,port,end)=cookie.split(".") 123  124 (a,b,c,d)=[ord(i) for i in struct.pack("i",int(ip))] 125<154x156> 178> Summary of Cracking Techniques   130   When cracking using GPU mode, the -O parameter can be used to automatically optimize   131     132   Brute-force cracking of an md5 value   133   (1) 9-digit cracking   134     135   Hashcat64.exe-a   3   --force   d98d28ca88f9966cb3aaefebbfc8196f  ? d? d? d? d? d? d? d? d? d   136   Cracking a single md5 value requires adding a force parameter   137     138   (2) Cracking 9-digit letters   139     140   Hashcat64.exe-a   3   -- force   d98d28ca88f9966cb3aaefebbfc8196f  ? l? l? l? l? l? l? l? l? l 141  Crack discuz password with salt  142  (1) Digital cracking  143  7-digit number, crack in 7 seconds to complete the task.  144  145 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d 146  8-digit numbers cracked, task completed in 9 seconds.  147  148 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d? d 149  9-digit number crack, complete the task in 9 seconds. 150  151 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d? d? d 152 Alphabet Cracking 153 (1)6-digit lowercase letters 154  155 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l 156 (2) 7-digit lowercase letter 157  158 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l 159 (3) 8-digit lowercase letter 160  161 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l? l  Cracking task completed in about 9 minutes   162  (4) 9-digit lowercase letters   163    164  Hashcat64.exe-a  3  --force  -m  2611  ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l? l? l -O 165 Letters plus numbers 166 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2 167 (3) 7-digit uppercase letter 168  169 Hashcat64.exe-a 3 –force –m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? He? He? He? He? He? He? u 170  (4) 6 to 8 digit crack  171  172 Hashcat64.exe-a 3 –force –m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463--increment --increment-min 6 --increment-max 8 ? l? l? l? l? l? l? l? l 173 Custom Crack 174 (1) Crack using a 6-bit mix of numbers and letters 175  176 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2 -O 177 (2) Cracking using a mixture of numbers and letters for 7 bits, cracking time 4 minutes 16 seconds 178  179 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2  – O  180  (3) Crack using 8-bit mix of numbers and letters   181    182  Hashcat64.exe-a  3  -- force  - m  2611  - 2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2? 2 -o 183 Dictionary Cracking Mode 184 Hashcat64.exe-a 0 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 password.lst 185 Crack using the dictionary under the dictionary folder: 186  187 Hashcat32.exe-m 300 mysqlhashes.txt –remove -o mysql-cracked.txt ..\dictionaries\* 188 session Save and Recover Crack 189 (1) Use mask File Rules to Crack Passwords 190 { } 195 mask Cracking 196 The mask rule file is located under masks, for example D:\PentestBox\hashcat-4.1.0\masks. The execution cracking settings are:  197  198 masks/8char-1l-1u-1d-1s-compliant.hcmask 199 masks/8char-1l-1u-1d-1s-noncompliant.hcmask 200 masks/rockyou-1-60.hcmask 201 masks/rockyou-2-1800.hcmask 202 masks/rockyou-3-3600.hcmask 203 masks/rockyou-4-43200.hcmask 204 masks/rockyou-5-86400.hcmask 205 masks/rockyou-6-864000.hcmask 206 masks/rockyou-7-2592000.hcmask 207  Cracking using rule files   208    209 hashcat -m 300 mysqlhashes.txt–remove -o mysql-cracked.txt ..\dictionaries\* -r rules\best64.rule 210  211 hashcat -m 2611 -a 0 dz.hashpassword.lst -r rules\best64.rule -o 212 hashcat Parameter Optimization  213  Considering the hashcat cracking speed and resource allocation, we can configure some parameters  214 1. Workload tuning  Load tuning.  215  This parameter supports values of 1, 8, 40, 80, 160 216  217 --gpu-accel 160  to maximize GPU performance.  218 2. Gpu loops Load Tweaking 219 This parameter supports values ranging from 8 to 1024 (some algorithms only support up to 1000).  220  221 --gpu-loops 1024  allows the GPU to maximize its performance.  222 3.Segment size Dictionary cache size 223 This parameter sets the size of the memory cache. Its purpose is to put the dictionary into the memory cache to speed up the dictionary cracking speed. The default is 32MB, which can be set according to your own memory conditions. Of course, the larger the dictionary, the bigger the block.  224  225 --segment-size 512  can improve the speed of large dictionary cracking.  226 LAST: Password setting recommendations  227 Use longer strings  228 Use larger character sets Letters, numbers, symbols  229  230 Do not use any characters that may be related to you as a password or as part of a password  231  232

 

 


Previous: Crack Exlce by yourself word, pdf, Compressed Password Tutorial
Next: Word, Excel, PPT, RAR, 7Z, PDF Hash Extraction Online
  • Focus on Word, Excel, PPT, PDF, RAR, ZIP, 7Z, Compressed File, Office Encrypted File Unlock Decryption
  • We provide users with high-quality file compression password recovery, PDF unlocking, and Word password recovery services.
  • Copyright © Document Password Recovery Master Online Decryption Platform