> For the complete documentation index, see [llms.txt](https://mo-ela.gitbook.io/shifrablog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mo-ela.gitbook.io/shifrablog/pentesting/ejpt/password-attacks.md).

# 🔐Password Attacks

Various techniques and tools to attack passwords.

Password when stored must be encrypted a Cryptographic Hashing Algorithm  (one-way encryption algorithm) is used to protect from reading by malicious users.

![](https://2411644790-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-McenfzTY6G0gAduakD-%2F-Mgg2pDThcDMV6d7YO4l%2F-Mgg4rF7pcA5KgkIZBwx%2Fimage.png?alt=media\&token=4628ef6c-9e13-4edc-8e12-9b1dc338c513)

## Password Cracking

> guessing process where attacker hash the gussed pass and compare it to the hashing value optianed from the breached DB.

### 💪BruteForce Attack

Will go through every single Capital/small letter + Number + Symbol combination until it finds the password, **always successful** given **enough time**.

![pseudo-code for BruteForce Algo (unkown pass + length)](https://2411644790-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-McenfzTY6G0gAduakD-%2F-Mgg82aQ27_ArCevWC8w%2F-Mgg8KCjOmEyjIuz6Oqb%2Fimage.png?alt=media\&token=26cf86f3-9b5b-4518-b066-eb778735e2b5)

{% embed url="<https://www.betterbuys.com/estimating-password-cracking-times/>" %}

#### John the Ripper:

> Support Bruteforce+Dictionary attacks agianst Passwords DB+ parallelization.

support nearly 100 Encryption formats

```
jhon --list=formates
```

Assuming we got from breached Linux system:

* /etc/passwd -> users accounts info.
* /etc/shadow -> actual hashed passwords.

we would like to bruteforce certain users with John

1- John needs both info in the same file (**unshadow** comes with it):

```
unshadow passwd.txt shadow.txt > crackme.txt
```

2- use this to pick a certain user to crack(pure BruteForce):

```
john -incremental -users:<users_list> <File_to_crack>
```

3- show the cracked password:

```
john --show <Cracked_file>
```

### 📖Dictionary Attack

> Dictionary of common passwords to test.

![Why Dict atttack faste than BruteForce exmaple.](https://2411644790-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-McenfzTY6G0gAduakD-%2F-Mgg82aQ27_ArCevWC8w%2F-MggDx4MW7a9zdGLKSk8%2Fimage.png?alt=media\&token=cecf032b-d32e-4f57-842d-72f74c1f8142)

make sure your password is secure when it's long (preventing BruteForce) + random (preventing Dictionary), check out this online testing tool:

{% embed url="<https://www.security.org/how-secure-is-my-password/>" %}

**Mangling Words:** variation on 'cat' could be: cat12, caT, CAT, c\@t ...etc. \
another thing that Cracking tools provide.

#### John the Ripper:

to use dictionary attacks in John:

```
john -wordlist= <custom_worldlist> -rules <file_to_crack>
john crack_me.txt
```

> -rules: to apply mangling.\
> -users= : may also be used to provide list of users.\
> • By not providing a custome worldlist you will use the defualt one.

#### Some helpful Password Dictionaries:&#x20;

* [SecList](https://github.com/danielmiessler/SecLists)

```
apt -y install seclists
```

> will find your passwords in :\
> /usr/share/seclists/Passwords/leak

### 🌈 Rainbow Tables

[Really Great explaination of what's a Rainbow Table.](https://security.stackexchange.com/questions/379/what-are-rainbow-tables-and-how-are-they-used#answer-172061)

[ophcrack:](https://ophcrack.sourceforge.io/) to crack Windowds Authentication Passwords, tool avilabe for all major OS.

{% embed url="<https://project-rainbowcrack.com/table.htm>" %}

Another tool is [RainbowCrack ](https://project-rainbowcrack.com/index.htm)Create a Rainbow Table:

```
rtgen <Hash_func> <charset> <plaintext_len_min> <plaintext_len_max> <table_index> <chain_len> <chain_num> <part_index>
rtgen sha256 loweralpha-numeric 1 10 0 1000 4000 0
```

> 1 10: from a to j.\
> table index: 0\
> 1000 is the length of the chain (how many times we hash ->reduce)

#### Crackin Pss protected MS Office files:

assuming you want to crack a .docx extract the hash first then crack it:

```
/usr/share/john/office2john.py MS_Word_Document.docx > hash
```

> `office2john.py`is a python script used to extract crackable information from the Microsoft Office .docx file.

```
john --wordlist=<worldlist> <hash>
```

## <img src="https://2411644790-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-McenfzTY6G0gAduakD-%2F-MgkjZswtsnnYZAgNbMT%2F-MglMg3RSjwoIQNcdZjO%2Fimage.png?alt=media&amp;token=6dd94230-a41e-4733-ab1b-c063793779da" alt="" data-size="line"> HashCat

> Another tool that can carry out all the 3 prev. mentioned attacks to crack passwords.

{% content-ref url="/pages/-MglMyGvJlZTsBSfJIT8" %}
[🐱‍👤Hashcat](/shifrablog/tools/hashcat.md)
{% endcontent-ref %}
