Blacksec

Administrator
Staff member
ROOT
VIP
Every data breach ends the same way: a pile of locked hashes waiting to be opened. Hashcat and John are the crowbars — GPU-fast, rule-driven, brutally simple once you see the shape. This guide covers hash types, both tools, wordlist craft, and why modern hashing makes cracking slower but never impossible.

TL;DR — A hash is a one-way door — reading a hash is free, reversing it is work. Identify the type, pick the attack (dictionary, rules, brute, mask), point the GPU at it, read the plains. Commands and strategy below.

1. ONE-WAY DOORS (KID VERSION)

Put your lunch in a blender. Blended lunch is easy to make and impossible to un-blend. That is a hash: password in, scrambled fingerprint out, no reverse gear.

Websites store the fingerprint, never the password. Database leaks therefore hand attackers columns of $2y$10$... garbage that looks useless. The game: feed the blender billions of guesses until one produces EXACTLY the leaked fingerprint. Match found means that guess was the password.

Notice what just happened — no encryption broken, no math defeated. Just incredibly fast guessing against a fingerprint match. Cracking is not codebreaking. It is industrial trial and error with a GPU doing the guessing.

The blender's recipe matters more than anything. Old recipes (MD5, SHA1) blend so fast they crumble under billions of guesses per second. Slow recipes (bcrypt, Argon2, PBKDF2) add artificial work — iterations, memory — so each guess costs real time. A bcrypt hash can take milliseconds per guess instead of nanoseconds. That is the entire arms race in one sentence.

2. KNOW YOUR HASH (THE FIRST SKILL)

Cracking without identifying the hash is guessing blind. The structure gives it away:

FormatLooks likeCrack difficulty
MD5 / SHA132 / 40 hex charsBrutal speed — billions/sec on GPU
NTLM32 hex, WindowsGPU monster — billions/sec
bcrypt$2a$ / $2b$ + 60 charsSlow by design — thousands/sec max
sha256crypt$5$ prefix (Linux)Moderate — tens of thousands/sec
phpass$P$ or $H$ prefixModerate — old PHP forums
PBKDF2 / Argon2iterations in hashHeavy — memory-hard monsters

Hashcat's example hashes list (-m to browse) maps every type to its mode number. Common ones to memorize: -m 0 MD5, -m 1000 NTLM, -m 1800 sha512crypt, -m 3200 bcrypt. John auto-detects format from structure — its --format flag when auto-detect guesses wrong.

3. HASHCAT — THE GPU WORKHORSE

Hashcat runs on your graphics card because GPUs do billions of parallel math operations per second — exactly what guessing is. The core workflow in four commands:

Bash:
#1. Identify the hash (or use hashid / john --show logic)
hashcat -m 0 hash.txt --identify

#2. Dictionary attack — feed wordlist, read plains
hashcat -m 0 hash.txt rockyou.txt -o cracked.txt

#3. Dictionary + rules — mutate every word a thousand ways
hashcat -m 0 hash.txt rockyou.txt -r best64.rule -o cracked.txt

#4. Mask attack — password = 8 digits? guess all of them
hashcat -m 0 hash.txt -a 3 ?d?d?d?d?d?d?d?d

Attack modes that matter: 0 (dictionary) tries wordlist as-is. a 6 (hybrid) appends digits to every word (word+123). a 3 (mask) is pattern guessing — ?l lowercase, ?u uppercase, ?d digit, ?s symbol:
Code:
?u?l?l?l?l?d?d?d
guesses Capital+3lower+3digits and finishes 8-char patterns in hours, not years. -a 1 toggles two wordlists against each other.

The rule files are the secret sauce. best64.rule turns each wordlist entry into 64 mutations — Password1, p@ssword, Passw0rd! — so a 14-million-word list becomes 900 million guesses without writing a single new word.

4. JOHN THE RIPPER — THE FLEXIBLE ONE

John runs on CPU, auto-detects formats, and shines at formats and workflows Hashcat does not cover. The usual pattern: convert to John's format first, then attack.

Bash:
# Dump Windows hashes, feed John
secretsdump.py -sam SAM -security SYSTEM local > hashes.txt
john hashes.txt --wordlist=rockyou.txt

# Apply rules (John's equivalent of best64)
john hashes.txt --wordlist=rockyou.txt --rules

# Show progress, then cracked results
john --show hashes.txt

Pro move: once John cracks a format, convert results back for Hashcat or just run both — John catches what Hashcat's GPU focused attack misses on odd formats, and vice versa. Two crowbars, one door.

5. WORDLISTS AND WHERE THEY COME FROM

Rockyou — the14-million classic from a 2009 breach — still cracks a shocking percentage of everything. But real operators build target-aware lists:

  • Platform mutations — breach-specific passwords (companyname2024!, welcome1) beat generic lists on corporate hashes every time.
  • Rule stacking — best64 first, dive.rule for deeper mutation, then custom rules targeting the pattern you observed (Year! suffixes, leet swaps).
  • Profiling — if 60% of cracked passwords end in digits, switch to hybrid word+4digit. Let the cracked sample shape the next attack.
  • Combination attacks — hashcat -a 1 list1.txt list2.txt joins two lists word-to-word, perfect for first-name + pet-name combos.

Strategy beats horsepower. A targeted 10,000-word list with smart rules outperforms brute-forcing rockyou all night.

6. WHY SLOW HASHING CHANGES THE MATH

MD5 at 100 billion guesses per second means any 8-character password falls in minutes. bcrypt at 5,000 guesses per second means the SAME password takes years. Same attack, three orders of magnitude difference — that is why every modern framework defaults to bcrypt or Argon2.

Implications both ways:

  • Sites using slow hashing survive breaches — leaked bcrypt hashes often stay unread while attackers pick the low-hanging MD5 databases instead.
  • Cracking shifts from brute force to intelligence: leaked password corpora, rules, personal knowledge of targets, and passphrases still fall because PEOPLE choose weak, not because the hash is weak.
  • Length beats complexity. horse-battery-staple correct survives dictionary attacks that destroy P@ssw0rd instantly — entropy the user can remember, entropy the attacker must guess through.

7. FIELD CHEAT SHEET

TaskCommand
Identify hashhashcat -m 0 hash.txt --identify
Quick dictionaryhashcat -m 0 hash.txt rockyou.txt
Dictionary + ruleshashcat -m 0 hash.txt rockyou.txt -r best64.rule
All 8-digit pinshashcat -m 0 hash.txt -a 3 ?d?d?d?d?d?d?d?d
Hybrid word+yearhashcat -m 0 hash.txt words.txt -a 6 ?d?d?d?d
John on CPUjohn hashes.txt --wordlist=rockyou.txt --rules
Show crackedjohn --show hashes.txt

— RELATED GUIDES —

Hash identified, GPU warm, rules stacked — dictionary first, mask where the pattern demands it, always let cracked samples shape the next wave. Two crowbars, one door, and a cheat sheet taped to the monitor. Start the run.
 
Last edited: