Because most password cracking tools are extremely slow and support few password cracking protocols, some passwords cannot be cracked even after a year of brute-force cracking. To run a password using a dictionary, the plaintext password must be in the dictionary. Moreover, if the password dictionary is too large, it is a waste of time and failure to crack is common. Below is a recommendation for the world's fastest password cracking tool: hashcat. Simply download the latest version from the hashcat github link.
GPU
CPU
APU
DSP
FPGA
Coprocessor
From the NVIDA official website, download the graphics card driver corresponding to your computer's graphics card model as shown in the image, and then follow the prompts to install it step by step.
After installation, restart your computer.
(NAVIDA's graphics card only needs to install the official driver, which already includes the GPU computing tools required for HASHCAT to crack passwords. Remember to use the officially downloaded graphics card driver in the image above, not the graphics card driver that comes with windows.)
1 hashcat64.exe -b
Benchmark test HASHCAT's speed in cracking various password hashes.
Check settings If the GPU is installed correctly, it will be visible and will list its properties and the driver information used.
normal
1 -m, —hash-type=NUM hash category, whose NUM value refers to the hash category value under its help information, and whose value is a number. If no m value is specified, it defaults to md5, for example -m 1800 is sha512 Linux encryption. 2 3 -a, –attack-mode=NUM attack mode, the value of which refers to the following parameter. "-A 0" dictionary attack, "-A 1" combination attack; "-A 3" mask attack. 4 5 -V, -version version information 6 7 -h, -help help information. 8 9 –quiet quiet mode, Suppress output
benchmark
1 -b, –benchmark Tests computer cracking speed and displays hardware-related information
Miscellaneous
1 –hex-salt salt value is given in hex 2 3 –hex-charset Set charset is given in hex 4 5 –runtime=NUM Medium after seconds of running (NUM value)
FILE
1 -o, –outfile=FILE Define hash FILE to restore output FILE 2 3 –outfile-format=NUM Define hash FILE output format as referenced below 4 5 –outfile-autohex-disable disable hex output plaintext 6 7 -p, –separator=CHAR Define separator characters for hash list/output FILE 8 14 15 –remove Removes successfully cracked hashes, useful when the hash is read from text, avoiding manually removing already cracked hashes 16 17 –stdout Console mode 18 19 –potfile-disable Does not write to pot files 20 21 –debug-mode=NUM Define debug mode (mixing only by using rules), see references below 22 23 –debug-file=file Output file for debug rules (see debug mode) 24 25 -e, –salt-file=file Define salted file list{ – words-limit=NUM Word limit (distributed)
rules
1 -r, – rules-file=file Use rule files: -r 1.rule, 2 3 -g, – generate-rules=NUM Randomly generate rules 4 5 – generate-rules-func-min= min per random rule 6 7 – generate-rules-func-max=max per random rule 8 9 – generate-rules-seed= dabcdef : settings? 1 is 0123456789abcdef 6 7 -4, –custom-charset4=CS -2mycharset.hcchr : set ? 2 is contained in mycharset. hcchr
Attack Mode
1 –toggle-min=NUM Minimum Value of Letters in Dictionary 2 3 –toggle-max=NUM Maximum Value of Letters in Dictionary 4 5 –increment Use Enhanced Mode 6 7 –increment-min=NUM Enhanced Mode Start Value 8 9 –increment-max=NUM Enhanced Mode End Value 10{ Then print the candidate characters 24 25 –elem-cnt-min=NUM Minimum number of elements per chain 26 27 –elem-cnt-max=NUM Maximum number of elements per chain 28 29 –wl-dist-len Calculate the output length distribution from the dictionary table 30 31 –wl-max=NUM Load NUM words from the dictionary file, setting 0 to disable loading. 32 33 – case-permute Reverse each Word in the dictionary
Reference
1 = hash[:salt] 2 = plain plain 3 = hash[:salt]:plain 4 = hex_plain 5 = hash[:salt]:hex_plain 6 = plain:hex_plain 7 = hash[:salt]:plain:hex_plain 8 = crackpos 9 = hash[:salt]:crackpos 10 = plain:crackpos 11 = hash[:salt]:plain:crackpos 12 Debug mode output file (for hybrid mode only, by using rules):1 = save finding rule 2 = save original Word 3 = save original Word and finding rule 4 = save original Word, finding rule andmodified plain<89x8 9> Built-in character set:
1 ? l = abcdefghijklmnopqrstuvwxyz represents lowercase letters 2 3 ? u = ABCDEFGHIJKLMNOPQRSTUVWXYZ represents uppercase letters 4 5 ? d = 0123456789 represents the number 6 7 ? s = !” #$%&’()*+,-./:; < = >? @[\]^_`{|}~ represents special characters 8 9 ? A = ? l? He? d? s Combination of uppercase and lowercase numbers and special characters 10 11 ? b =0 – 0xff
Attack Mode
1 0 = Straight (Dictionary Cracking) 2 3 1 = Combination (Combination Cracking) 4 5 2 = Toggle- case conversion) 6 7 3 = Brute-force 8 9 4 = Permutation 10 11 5 = Table-Lookup 12 13 6 = Hybrid dict + mask Dictionary plus mask Cracking 14 15 7 = Hybrid mask + dict mask + Dictionary Cracking 16 17 8 = Prince (Prince Cracking)
Hash type
For examples of specific hash values, please refer to the website
1 0 = md5 2 3 10 = md5($pass.$salt) 4 5 20 = md5($salt.$pass) 6 7 30 = md5(unicode($pass). $salt) 8 9 40 = md5($salt. unicode($pass)) 10 11 50 = HMAC-MD5 (key = $pass) 12 13 60 = HMAC-MD5 (key = $salt) 14 15 100 = sha1 16 17 110 = sha1($pass.$salt) 18 19 120 = sha1($salt.$pass) 20 21 130 = sha1(unicode($pass). $salt) 22 23 140 = sha1($salt. unicode($pass)) 24 25 150 = HMAC-SHA1 (key = $pass) 26 27 160 = HMAC-SHA1 (key = $salt) 28 29 200 = MySQL323 30 31 300 = MySQL4.1/MySQL5 32 33 400 = phpass,{ MSCache 42 43 1400 = sha256 44 45 1410 = sha256($pass.$salt) 46 47 1420 = sha256($salt.$pass) 48 49 1430 = sha256(unicode($pass). $salt) 50 51 1431 = base64(sha256(unicode($pass))) 52 53 1440 = sha256($salt. unicode($pass)) 54 55 1450 = HMAC-SHA256 (key = $pass) 56 57 1460 = HMAC-SHA256 (key = $salt) 58 59 1600 = md5apr1, MD5(APR), Apache MD5 60 61 1700 = sha512 62 72 73 1760 = HMAC-SHA512 (key = $salt) 74 75 1800 = SHA-512(Unix) 76 77 2400 = Cisco-PIX md5 78 79 2410 = Cisco-ASA md5 80 81 2500 = WPA/WPA2 82 { } $pass) 92 93 3710 = md5($salt. md5($pass)) 94 95 3720 = md5($pass. md5($salt)) 96 97 3800 = md5($salt.$pass.$salt) 98 99 3910 = md5(md5($pass). md5($salt)) 100 101 4010 = md5($salt. md5($salt.$pass) ) 102 103 4110 = md5($salt. md5($pass.$salt) ) 104 105 4210 = md5($username.0.$pass) 106 107 4300 = md5(strtoupper(md5($pass))) 108 109 4400 = md5(sha1($pass)) 110 111 4500 = Double sha1 112 113 4600 = sha1($pass))) 114 115 4700 = sha1(md5($pass)) 116 117 4800 = md5(Chap),{ 120 121 5000 = SHA-3(Keccak) 122 123 5100 = Half MD5 124 125 5200 = Password Safe SHA-256 126 127 5300 = IKE-PSK MD5 128 129 5400 = IKE-PSK SHA1 130 131 5500 = NetNTLMv1-VANILLA /{ 700 = AIX {ssha1} 146 147 6900 = GOST, GOST R 34.11-94 148 149 7000 = Fortigate (FortiOS) 150 151 7100 = OS X v10.8+ 152 153 7200 = GRUB 2 154 155 7300 = IPMI2 RAKP HMAC-SHA1 156 157 7400 = sha256crypt, SHA256(Unix) 158 159 7900 = Drupal7 160 161 8400 = WBB3, Woltlab Burning Board 3 162 163 8900 = scrypt 164 165 9200 = Cisco $8$ 166 167 9300 = Cisco $9$ 168 169 9800 = Radmin2 170 171 10000 = Django (PBKDF2-SHA256) 172 173 10200 = 1}digest authentication (MD5) 184 185 99999 = Plaintext
special hash type
1 11 = Joomla < 2.5.18 2 3 12 = PostgreSQL 4 5 21 = osCommerce, xt:Commerce 6 7 23 = Skype 8 9 101 = nsldap, SHA-1(Base64), Netscape LDAPSHA 10 v10.6 18 19 123 = EPi 20 21 124 = Django (SHA-1) 22 23 131 = MSSQL(2000) 24 25 132 = MSSQL(2005) 26 27 133 = PeopleSoft 28 29 141 = LDAP {SSHA512} 36 37 1722 = OS X v10.7 38 39 1731 = MSSQL(2012 & 2014) 40 41 2611 = vBulletin < v3.8.5 42 43 2612 = PHPS 44<180x179> Step 4: hashcat Cracking password Rule Example1 (1) Dictionary Attack 2 3 -a 0 password.lst 4 (2) 1 to 8 are digital mask attacks 5 6 -a 3 --increment --increment-min 1--increment-max 8 ? d? d? d? d? d? d? d? d -O 7 ? d represents a number; can it be replaced with a lowercase letter? l, a capital letter? u, special character? s, uppercase and lowercase letter + special character? A and –O represent the optimized cracking mode; this parameter may or may not be added. 8 9 (3) 8 is a number attack 10 11 -A 3 ? d? d? d? d? d? d? d? d 12 Similarly, it can be set to modes such as uppercase, lowercase, and special characters based on the number of bits. 13 14 (4) Custom characters 15 Passwords that are purely numeric or purely alphabetic are relatively rare nowadays. According to the analysis of leaked passwords by cryptography experts, 90% of personal passwords are a combination of letters and numbers, which can be brute-forced using custom characters. Hashcat supports 4 custom character sets, namely -1 -2 -3 -4. Do you only need to do this when defining -2 ? l? d , then you can specify ? 2,? 2 represents lowercase letters and numbers.At this point, you need to crack an 8-digit mixed lowercase letter plus number: 16 17 Hashcat.exe -a 3 –force -2 ? l? d hash value or hash file ? 2? 2? 2? 2? 2? 2? 2? 2 18 For example, cracking dz lowercase letters + numbers mixed 8-digit password: 19 20 Hashcat -m 2611 -a 3 -2 ? l? d dz.hash ? 2? 2? 2? 2? 2? 2? 2? 2 21 (5) Dictionary + Mask Brute Force Cracking 22 Hashcat also supports a dictionary plus brute force cracking method, which is to add a brute force character sequence before and after the dictionary, such as adding 3 as a number after the dictionary. This type of password is very common. Use the sixth attack mode: 23 24 a-6 (Hybrid dict + mask) 25 If it is added before the dictionary, use the seventh attack mode, which is ( a-7 = Hybridmask + dict). The following is to crack the dictionary file by adding the number 123: 26 27 H.exe -a 6 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst ? d? d? d 28 If the password for ffe1cb31eb084cd7a8dd1228c23617c8 is password123, then as long as password.lst contains 123 29 30 (6) Mask + Dictionary Brute Force 31 32 H.exe -a 7 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst ? d? d? d 33 If the password for ffe1cb31eb084cd7a8dd1228c23617c8 is 123password, then password.lst only needs to contain the password. 34 35 (7) Case conversion attack, case conversion attack on words in password.lst 36 37 H.exe-a 2 ffe1cb31eb084cd7a8dd1228c23617c8 password.lst 38 EXAMPLES 39 (1) 8-digit number cracking 40 41 Hashcat64-m 9700 hash -a 3 ? d? d? d? d? d? d? d? d -w 3 –O 42 (2) 1-8 digit cracking 43 44 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? d? d? d? d? d? d? d? d 45 (3) 1 to 8 lowercase letter cracking 46 47 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? l? l? l? l? l? l? l? l 48 (4) 8-digit lowercase letter cracking 49 50 Hashcat-m 9700 hash -a 3 ? l? l? l? l? l? l? l? l -w 3 –O 51 (5) 1-8 uppercase letter cracking 52 53 Hashcat-m 9700 hash -a 3 --increment --increment-min 1--increment-max 8 ? He? He? He? He? He? He? He? u 54 (6) 8-digit uppercase letter cracking 55 56 Hashcat-m 9700 hash -a 3 ? He? He? He? He? He? He? He? u -w 3 –O 57 (7) 5-digit lowercase + uppercase + number + special character cracking 58 59 Hashcat-m 9700 hash -a 3 ? b? b? b? b? b -w 3 60 (8) Use a dictionary to crack 61 Use the password.lst dictionary to brute-force cracking, -w 3 parameter specifies power consumption 62 63 hashcat -m 9700 -A 0 -w 3 hash password.lst 64 After successful cracking, hashcat will automatically terminate the cracking and display the cracking status as Cracked. Recvoered will also display whether the cracking was successful. 65 66 Cracking the IP address in known_hosts 67 After research, it was found that in known_hosts 68 69 (1) Calculate HMAC SHA1 value 70 71 gitclone https://github.com/persona5/hexhosts.git 72 cdhexhosts 73 gcchexhosts.c -lresolv -w -o hexhosts 74 ./hexhosts 75 获取known_hosts的HMAC SHA1加密值: 76 77 注意:known_hosts值一定要正确,可以将known_hosts文件复制到hexhosts文件目录。 78 79 (2)组合攻击暴力破解 80 81 hashcat-a 1 -m 160 known_hosts.hash ips_left.txt ips_right.txt --hex-salt 82 组合攻击是将ips_left.txt和ips_right.txt进行组合,形成完整的IP地址进行暴力破解。 83 84 The ips_left.txt and ips_right.txt files can be generated with the following code: 85 86 ip-gen.sh: 87 88 89 90 for a in `seq 0 255` 91 92 do 93 94 for b in `seq0 255` 95 96 do 97 Attack with Mask 106 107 hashcat -a 3 -m 160 known_hosts.hash ipv4.hcmask--hex-salt 108 ipv4.hcmask The contents of the file can be downloaded from this site. 109 110 Cracking MD5 Encrypted IP Addresses 111 In networks or configurations such as CDNs, IP addresses are often encrypted with MD5. Since its number of bits is 3×4+3 (xxx.xxx.xxx.xxx) = 17 bits, cracking it with a normal password takes a very long time. However, by analyzing the patterns of its IP addresses, it is found that its addresses xxx are all numbers. Therefore, attacks can be carried out using a combination of hashcats and masks. 112 113 hashcat-a 1 -m 0 ip.md5.txt ips_left.txt ips_right.txt 114 115 hashcat -a1 -m 0 ip.md5.txt ipv4.hcmask 116 Additionally, the IP address of F5 is encrypted in the cookie. The cracking code you can refer to is as follows: 117 118 import struct 119 120 cookie = "1005421066.20736.0000" 121 122 (ip,port,end)=cookie.split(".") 123 124 (a,b,c,d)=[ord(i) for i in struct.pack("i",int(ip))] 125<154x156> 178> Summary of Cracking Techniques 130 When cracking using GPU mode, the -O parameter can be used to automatically optimize 131 132 Brute-force cracking of an md5 value 133 (1) 9-digit cracking 134 135 Hashcat64.exe-a 3 --force d98d28ca88f9966cb3aaefebbfc8196f ? d? d? d? d? d? d? d? d? d 136 Cracking a single md5 value requires adding a force parameter 137 138 (2) Cracking 9-digit letters 139 140 Hashcat64.exe-a 3 -- force d98d28ca88f9966cb3aaefebbfc8196f ? l? l? l? l? l? l? l? l? l 141 Crack discuz password with salt 142 (1) Digital cracking 143 7-digit number, crack in 7 seconds to complete the task. 144 145 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d 146 8-digit numbers cracked, task completed in 9 seconds. 147 148 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d? d 149 9-digit number crack, complete the task in 9 seconds. 150 151 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? d? d? d? d? d? d? d? d? d 152 Alphabet Cracking 153 (1)6-digit lowercase letters 154 155 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l 156 (2) 7-digit lowercase letter 157 158 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l 159 (3) 8-digit lowercase letter 160 161 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l? l Cracking task completed in about 9 minutes 162 (4) 9-digit lowercase letters 163 164 Hashcat64.exe-a 3 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? l? l? l? l? l? l? l? l? l -O 165 Letters plus numbers 166 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2 167 (3) 7-digit uppercase letter 168 169 Hashcat64.exe-a 3 –force –m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 ? He? He? He? He? He? He? u 170 (4) 6 to 8 digit crack 171 172 Hashcat64.exe-a 3 –force –m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463--increment --increment-min 6 --increment-max 8 ? l? l? l? l? l? l? l? l 173 Custom Crack 174 (1) Crack using a 6-bit mix of numbers and letters 175 176 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2 -O 177 (2) Cracking using a mixture of numbers and letters for 7 bits, cracking time 4 minutes 16 seconds 178 179 Hashcat64.exe-a 3 --force -m 2611 -2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2 – O 180 (3) Crack using 8-bit mix of numbers and letters 181 182 Hashcat64.exe-a 3 -- force - m 2611 - 2 ? d? l ffe1cb31eb084cd7a8dd1228c23617c8:f56463? 2? 2? 2? 2? 2? 2? 2? 2 -o 183 Dictionary Cracking Mode 184 Hashcat64.exe-a 0 --force -m 2611 ffe1cb31eb084cd7a8dd1228c23617c8:f56463 password.lst 185 Crack using the dictionary under the dictionary folder: 186 187 Hashcat32.exe-m 300 mysqlhashes.txt –remove -o mysql-cracked.txt ..\dictionaries\* 188 session Save and Recover Crack 189 (1) Use mask File Rules to Crack Passwords 190 { } 195 mask Cracking 196 The mask rule file is located under masks, for example D:\PentestBox\hashcat-4.1.0\masks. The execution cracking settings are: 197 198 masks/8char-1l-1u-1d-1s-compliant.hcmask 199 masks/8char-1l-1u-1d-1s-noncompliant.hcmask 200 masks/rockyou-1-60.hcmask 201 masks/rockyou-2-1800.hcmask 202 masks/rockyou-3-3600.hcmask 203 masks/rockyou-4-43200.hcmask 204 masks/rockyou-5-86400.hcmask 205 masks/rockyou-6-864000.hcmask 206 masks/rockyou-7-2592000.hcmask 207 Cracking using rule files 208 209 hashcat -m 300 mysqlhashes.txt–remove -o mysql-cracked.txt ..\dictionaries\* -r rules\best64.rule 210 211 hashcat -m 2611 -a 0 dz.hashpassword.lst -r rules\best64.rule -o 212 hashcat Parameter Optimization 213 Considering the hashcat cracking speed and resource allocation, we can configure some parameters 214 1. Workload tuning Load tuning. 215 This parameter supports values of 1, 8, 40, 80, 160 216 217 --gpu-accel 160 to maximize GPU performance. 218 2. Gpu loops Load Tweaking 219 This parameter supports values ranging from 8 to 1024 (some algorithms only support up to 1000). 220 221 --gpu-loops 1024 allows the GPU to maximize its performance. 222 3.Segment size Dictionary cache size 223 This parameter sets the size of the memory cache. Its purpose is to put the dictionary into the memory cache to speed up the dictionary cracking speed. The default is 32MB, which can be set according to your own memory conditions. Of course, the larger the dictionary, the bigger the block. 224 225 --segment-size 512 can improve the speed of large dictionary cracking. 226 LAST: Password setting recommendations 227 Use longer strings 228 Use larger character sets Letters, numbers, symbols 229 230 Do not use any characters that may be related to you as a password or as part of a password 231 232