Skip to content

Password Cracking

Recovering plaintext passwords from captured hashes, offline.

Why It Matters

Hashes captured during an engagement (from a database, NTDS.dit, SAM, or intercepted authentication) are only useful once cracked. Cracked passwords reveal credential reuse, weak password policies, and often a direct path to further access, and the crack rate itself is a finding worth reporting.

Reference

Identify the Hash First

Knowing the hash type decides the mode and the effort. Use hashid or hashcat --identify, and check the Hashcat example hashes for the mode number.

Tools

Tool Use
Hashcat GPU-accelerated; the fastest option for most hash types
John the Ripper CPU-based, flexible, with helpers like zip2john and *2john

Approach

Method When
Dictionary First: a wordlist such as rockyou or a target-specific list from CeWL
Rules Apply mutation rules (for example best64) to a wordlist to cover variations
Mask / brute force For short or known-pattern passwords, define a mask
Hybrid Combine a wordlist with a mask (word plus digits or a year)

Example Hashcat runs (mode -m, attack -a):

hashcat -m 1000 -a 0 hashes.txt rockyou.txt                 # NTLM, dictionary
hashcat -m 1000 -a 0 hashes.txt rockyou.txt -r rules/best64.rule
hashcat -m 0 -a 3 hashes.txt '?u?l?l?l?l?d?d'               # MD5, mask

How I Use It

I identify the hash type, then start with a targeted wordlist plus a rules file before resorting to masks or brute force. A wordlist built from the target's own site (CeWL) and OSINT usually outperforms a bigger generic list. The crack rate and the common patterns that fall go into the report as evidence for password-policy recommendations.

Resources