Passwords are commonly hashed when stored in order to provide some protection in the event they fall into the hands of an attacker. Hashing is a mathematical function which transforms an arbitrary number of input bytes into a fixed-size output. They are designed to work in one direction. In order to retrieve the original password we must crack it.
John The Ripper
Dictionary attack known as a wordlist attack attempts every password in a list.
# Single crack mode - generates password candidates based off victim's username, home directory and GECOS values (full name, etc.)
john --single hash_file
# Wordlist mode - crack passwords with dictionnary attack
john --wordlist=<wordlist_file> <hash_file>
# Incremental mode - generates passwords based on statistical model prioritizing more likely passwords
john --incremental <hash_file>
# check hash format
hashid -j 1129r0e324....
# specify hash format to john
john --format=dmd5 [...] <hash_file>
# crack password-protected or encrypted files, e.g. pdf
pdf2john <file_to_crack> file.hashHashcat
Different from JtR, hashcat features GPU support. It also features rules that can perform specific modifications to passwords to generate even more guesses.
Techniques include:
- Rainbow tables are large pre-compiled maps of input and output values for a given hash function.
- To mitigate rainbow tables salting is used. A salt is a random secquence of bytes added to a password before it is hashed. Salts should not be reused accross different passwords. Salts are not secret values, an authentication request needs to know the salt in order to properly authenticate.
- Brute force attack involves attempting every possible combination of letters, numbers, and symbols. Given enough time, any password will cracked via brute-force.
- Password spraying is a type of brute-force attack which an attackers attempts to use a single password across many different user accounts.
- Credential snuffing is an attack in which stolen credentials from one services is used to access others.
# specify attack mdoe (-a), hash type (-m)
hashcat -a 0 -m 0 <hashes> [wordlist, rule, mask, ...]
# hashcat associates hash types to an id, to view
hashcat --help
# Dictionary attack
hashcat -a 0 -m 0 e3e3ec5831ad5e7288241960e5d4fdb8 /usr/share/wordlists/rockyou.txt
# Specify ruleset
hashcat -a 0 -m 0 1b0556a75770563578569ae21392630c /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
# Mask attack - type of brute force in which keyspace is explicitly defined by the user.
hashcat -a 3 -m 0 1e293d6912d074c0fd15844d803400dd '?u?l?l?l?l?d?s'Custom Wordlists
Hashcat supports custom wordlists. You need to provide a list of potential names alongside mutation rules to create custom wordlists. The most common rulesets is best66.rule which applies common trasnformations that result in best guesses. The syntax is as follows:
| Function | Description |
|---|---|
: | Do nothing |
l | Lowercase all letters |
u | Uppercase all letters |
c | Capitalize the first letter and lowercase others |
sXY | Replace all instances of X with Y |
$! | Add the exclamation character at the end |
# Geberate custom wordlist
hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.listCeWL can also scan potential words from a company’s website and save them in a separate list, we can combine them to create a customized password list.
cewl https://www.inlanefreight.com -d 4 -m 6 --lowercase -w inlane.wordlistProtected Files and Archives
Employees will often encrypt sensitive files. Encrypted file can be cracked same as hashes. In many cases, symmetric algorithms are used to encrypt files or folders, the same key is used for both encryption and decryption.
# find encrypted files
for ext in $(echo ".xls .xls* .xltx .od* .doc .doc* .pdf .pot .pot* .pp*");do echo -e "\nFile extension: " $ext; find / -name *$ext 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done
# gzip files can be openssl encrypted (not immediately obvious)
file GZIP.gzipSSH Keys
# find SSH keys
grep -rnE '^\-{5}BEGIN [A-Z0-9]+ PRIVATE KEY\-{5}$' /* 2>/dev/null
# see if the SSH key is encrypted
ssh-keygen -yf ~/.ssh/id_ed25519
# crack SSH keys
ssh2john.py SSH.private > ssh.hash
john --wordlist=rockyou.txt ssh.hashBitLocker
Mount BitLocker-encrypted drivers in Linux.
# extract only the bitlocker password (no need for other entries, which is just recovery key)
bitlocker2john -i Backup.vhd > backup.hashes
grep "bitlocker\$0" backup.hashes > backup.hash
sudo mir kd-p /media/bitlocker
sudo mkdir -p /media/bitlockermount
# configure VH as loop device
sudo losetup -f -P Backup.vhd
# decrypt the drive using dislocker
sudo dislocker /dev/loop0p2 -u1234qwer -- /media/bitlocker
# mount the decryprted volume
sudo mount -o loop /media/bitlocker/dislocker-file /media/bitlockermount
# unmount
sudo umount /media/bitlockermount
sudo umount /media/bitlocker