Every data breach ends the same way: a pile of locked hashes waiting to be opened. Hashcat and John are the crowbars — GPU-fast, rule-driven, brutally simple once you see the shape. This guide covers hash types, both tools, wordlist craft, and why modern hashing makes cracking slower but never impossible.
TL;DR — A hash is a one-way door — reading a hash is free, reversing it is work. Identify the type, pick the attack (dictionary, rules, brute, mask), point the GPU at it, read the plains. Commands and strategy below.
1. ONE-WAY DOORS (KID VERSION)
Put your lunch in a blender. Blended lunch is easy to make and impossible to un-blend. That is a hash: password in, scrambled fingerprint out, no reverse gear.
Websites store the fingerprint, never the password. Database leaks therefore hand attackers columns of $2y$10$... garbage that looks useless. The game: feed the blender billions of guesses until one produces EXACTLY the leaked fingerprint. Match found means that guess was the password.
Notice what just happened — no encryption broken, no math defeated. Just incredibly fast guessing against a fingerprint match. Cracking is not codebreaking. It is industrial trial and error with a GPU doing the guessing.
The blender's recipe matters more than anything. Old recipes (MD5, SHA1) blend so fast they crumble under billions of guesses per second. Slow recipes (bcrypt, Argon2, PBKDF2) add artificial work — iterations, memory — so each guess costs real time. A bcrypt hash can take milliseconds per guess instead of nanoseconds. That is the entire arms race in one sentence.
2. KNOW YOUR HASH (THE FIRST SKILL)
Cracking without identifying the hash is guessing blind. The structure gives it away:
Hashcat's example hashes list (-m to browse) maps every type to its mode number. Common ones to memorize: -m 0 MD5, -m 1000 NTLM, -m 1800 sha512crypt, -m 3200 bcrypt. John auto-detects format from structure — its --format flag when auto-detect guesses wrong.
3. HASHCAT — THE GPU WORKHORSE
Hashcat runs on your graphics card because GPUs do billions of parallel math operations per second — exactly what guessing is. The core workflow in four commands:
Attack modes that matter: 0 (dictionary) tries wordlist as-is. a 6 (hybrid) appends digits to every word (word+123). a 3 (mask) is pattern guessing — ?l lowercase, ?u uppercase, ?d digit, ?s symbol:
guesses Capital+3lower+3digits and finishes 8-char patterns in hours, not years. -a 1 toggles two wordlists against each other.
The rule files are the secret sauce. best64.rule turns each wordlist entry into 64 mutations — Password1, p@ssword, Passw0rd! — so a 14-million-word list becomes 900 million guesses without writing a single new word.
4. JOHN THE RIPPER — THE FLEXIBLE ONE
John runs on CPU, auto-detects formats, and shines at formats and workflows Hashcat does not cover. The usual pattern: convert to John's format first, then attack.
Pro move: once John cracks a format, convert results back for Hashcat or just run both — John catches what Hashcat's GPU focused attack misses on odd formats, and vice versa. Two crowbars, one door.
5. WORDLISTS AND WHERE THEY COME FROM
Rockyou — the14-million classic from a 2009 breach — still cracks a shocking percentage of everything. But real operators build target-aware lists:
Strategy beats horsepower. A targeted 10,000-word list with smart rules outperforms brute-forcing rockyou all night.
6. WHY SLOW HASHING CHANGES THE MATH
MD5 at 100 billion guesses per second means any 8-character password falls in minutes. bcrypt at 5,000 guesses per second means the SAME password takes years. Same attack, three orders of magnitude difference — that is why every modern framework defaults to bcrypt or Argon2.
Implications both ways:
7. FIELD CHEAT SHEET
— RELATED GUIDES —
Hash identified, GPU warm, rules stacked — dictionary first, mask where the pattern demands it, always let cracked samples shape the next wave. Two crowbars, one door, and a cheat sheet taped to the monitor. Start the run.
TL;DR — A hash is a one-way door — reading a hash is free, reversing it is work. Identify the type, pick the attack (dictionary, rules, brute, mask), point the GPU at it, read the plains. Commands and strategy below.
1. ONE-WAY DOORS (KID VERSION)
Put your lunch in a blender. Blended lunch is easy to make and impossible to un-blend. That is a hash: password in, scrambled fingerprint out, no reverse gear.
Websites store the fingerprint, never the password. Database leaks therefore hand attackers columns of $2y$10$... garbage that looks useless. The game: feed the blender billions of guesses until one produces EXACTLY the leaked fingerprint. Match found means that guess was the password.
Notice what just happened — no encryption broken, no math defeated. Just incredibly fast guessing against a fingerprint match. Cracking is not codebreaking. It is industrial trial and error with a GPU doing the guessing.
The blender's recipe matters more than anything. Old recipes (MD5, SHA1) blend so fast they crumble under billions of guesses per second. Slow recipes (bcrypt, Argon2, PBKDF2) add artificial work — iterations, memory — so each guess costs real time. A bcrypt hash can take milliseconds per guess instead of nanoseconds. That is the entire arms race in one sentence.
2. KNOW YOUR HASH (THE FIRST SKILL)
Cracking without identifying the hash is guessing blind. The structure gives it away:
| Format | Looks like | Crack difficulty |
| MD5 / SHA1 | 32 / 40 hex chars | Brutal speed — billions/sec on GPU |
| NTLM | 32 hex, Windows | GPU monster — billions/sec |
| bcrypt | $2a$ / $2b$ + 60 chars | Slow by design — thousands/sec max |
| sha256crypt | $5$ prefix (Linux) | Moderate — tens of thousands/sec |
| phpass | $P$ or $H$ prefix | Moderate — old PHP forums |
| PBKDF2 / Argon2 | iterations in hash | Heavy — memory-hard monsters |
Hashcat's example hashes list (-m to browse) maps every type to its mode number. Common ones to memorize: -m 0 MD5, -m 1000 NTLM, -m 1800 sha512crypt, -m 3200 bcrypt. John auto-detects format from structure — its --format flag when auto-detect guesses wrong.
3. HASHCAT — THE GPU WORKHORSE
Hashcat runs on your graphics card because GPUs do billions of parallel math operations per second — exactly what guessing is. The core workflow in four commands:
Bash:
#1. Identify the hash (or use hashid / john --show logic)
hashcat -m 0 hash.txt --identify
#2. Dictionary attack — feed wordlist, read plains
hashcat -m 0 hash.txt rockyou.txt -o cracked.txt
#3. Dictionary + rules — mutate every word a thousand ways
hashcat -m 0 hash.txt rockyou.txt -r best64.rule -o cracked.txt
#4. Mask attack — password = 8 digits? guess all of them
hashcat -m 0 hash.txt -a 3 ?d?d?d?d?d?d?d?d
Attack modes that matter: 0 (dictionary) tries wordlist as-is. a 6 (hybrid) appends digits to every word (word+123). a 3 (mask) is pattern guessing — ?l lowercase, ?u uppercase, ?d digit, ?s symbol:
Code:
?u?l?l?l?l?d?d?d
The rule files are the secret sauce. best64.rule turns each wordlist entry into 64 mutations — Password1, p@ssword, Passw0rd! — so a 14-million-word list becomes 900 million guesses without writing a single new word.
4. JOHN THE RIPPER — THE FLEXIBLE ONE
John runs on CPU, auto-detects formats, and shines at formats and workflows Hashcat does not cover. The usual pattern: convert to John's format first, then attack.
Bash:
# Dump Windows hashes, feed John
secretsdump.py -sam SAM -security SYSTEM local > hashes.txt
john hashes.txt --wordlist=rockyou.txt
# Apply rules (John's equivalent of best64)
john hashes.txt --wordlist=rockyou.txt --rules
# Show progress, then cracked results
john --show hashes.txt
Pro move: once John cracks a format, convert results back for Hashcat or just run both — John catches what Hashcat's GPU focused attack misses on odd formats, and vice versa. Two crowbars, one door.
5. WORDLISTS AND WHERE THEY COME FROM
Rockyou — the14-million classic from a 2009 breach — still cracks a shocking percentage of everything. But real operators build target-aware lists:
- Platform mutations — breach-specific passwords (companyname2024!, welcome1) beat generic lists on corporate hashes every time.
- Rule stacking — best64 first, dive.rule for deeper mutation, then custom rules targeting the pattern you observed (Year! suffixes, leet swaps).
- Profiling — if 60% of cracked passwords end in digits, switch to hybrid word+4digit. Let the cracked sample shape the next attack.
- Combination attacks — hashcat -a 1 list1.txt list2.txt joins two lists word-to-word, perfect for first-name + pet-name combos.
Strategy beats horsepower. A targeted 10,000-word list with smart rules outperforms brute-forcing rockyou all night.
6. WHY SLOW HASHING CHANGES THE MATH
MD5 at 100 billion guesses per second means any 8-character password falls in minutes. bcrypt at 5,000 guesses per second means the SAME password takes years. Same attack, three orders of magnitude difference — that is why every modern framework defaults to bcrypt or Argon2.
Implications both ways:
- Sites using slow hashing survive breaches — leaked bcrypt hashes often stay unread while attackers pick the low-hanging MD5 databases instead.
- Cracking shifts from brute force to intelligence: leaked password corpora, rules, personal knowledge of targets, and passphrases still fall because PEOPLE choose weak, not because the hash is weak.
- Length beats complexity. horse-battery-staple correct survives dictionary attacks that destroy P@ssw0rd instantly — entropy the user can remember, entropy the attacker must guess through.
7. FIELD CHEAT SHEET
| Task | Command |
| Identify hash | hashcat -m 0 hash.txt --identify |
| Quick dictionary | hashcat -m 0 hash.txt rockyou.txt |
| Dictionary + rules | hashcat -m 0 hash.txt rockyou.txt -r best64.rule |
| All 8-digit pins | hashcat -m 0 hash.txt -a 3 ?d?d?d?d?d?d?d?d |
| Hybrid word+year | hashcat -m 0 hash.txt words.txt -a 6 ?d?d?d?d |
| John on CPU | john hashes.txt --wordlist=rockyou.txt --rules |
| Show cracked | john --show hashes.txt |
— RELATED GUIDES —
- RockYou Wordlist: The 32M Password Story
- Infostealers: From Infection to Combo Lists
- Kali Linux: The Complete Beginner Field Manual
- Combo Lists Are Rotting: The 2026 Truth
- Phishing Explained: How One Fake Page Steals Everything
- Chime Bank Drop Cashout: Instant Transfers Explained
- Fullz to Bank Account: The Onboarding Chain
Hash identified, GPU warm, rules stacked — dictionary first, mask where the pattern demands it, always let cracked samples shape the next wave. Two crowbars, one door, and a cheat sheet taped to the monitor. Start the run.
Last edited: