Several attack modes of hashcat

hashcat has multiple Attack Modes. Use the parameter –help to view the full help. You can see the "Attack Modes" table as follows:

#Mode
0Straight
1Combination
3Brute-force
6Hybrid Wordlist + Mask
7Hybrid Mask + Wordlist

1.Straight

This Attack mode is also known as a "Dictionary Attack". There's not much to say, it's just that given a dictionary, hashcat will read the contents of the dictionary line by line, calculate the hash value of each line, and compare it with the target hash value.

example:

  hashcat -a 0 -m 400 example400.hash example.dict

2.Combination

Baidu told me that Combination is a noun, meaning: "Combination; union; password Combination; underwear". This attack pattern is actually quite simple: it involves combining the contents of two password dictionaries. Using this attack mode requires specifying no more than two password dictionaries. Suppose we have two password dictionaries, dict1.txt and dict2.txt, with the following contents:

  hunting 
  kitty 
  rainbow

and

  paris 
  rock

Then the command:

  hashcat -m 0 -a 1 hash.txt dict1.txt dict2.txt

The dictionary actually tried is:

  huntingparis 
Hunting Rock 
kittyparis 
kittyrock 
Rainbow Paris 
  rainbowrock

The words in dict1.txt are on the left and the words in dict2.txt are on the right, for a total of 3 × 2 = 6.

The parameters associated with this pattern are:

  -j, --rule-left 
  -k, --rule-right

The rule after -j applies to the left, and the rule after -k applies to the right. If you add the parameter -j '$-', the dictionary you will actually try will be:

  hunting-paris 
  hunting rock 
kitty-paris 
kitty-rock 
Rainbow Paris 
  rain-bowrock

Add parameter -j '^!', The dictionary we actually tried would be:

  ! huntingparis 
  ! hunting rock 
  ! kittyparis 
  ! kittyrock 
  ! Rainbow Paris 
  ! rainbowrock

Add parameter -k '^>', then the actual dictionary attempted is:

  hunting>paris 
  hunting>rock 
  kitty>paris 
  kitty>rock 
  rain>bowparis 
  rain>bowrock

What rule is this? The usage of "$" and "^" is similar to that of regular expressions, so are they regular expressions? Actually, that's not the case. hashcat implements its own rules, which is another big chunk of content. For details, see Rule-based Attack

3. Brute-force

attempts various combinations of a given character set. According to the official hashcat wiki, this method is outdated and has been completely replaced by Mask-Attack, so no further research will be conducted.

4. Mask Attack

This is a relatively novel Attack method. An example is as follows:

  hashcat -a 3 -m 0 md5.hash ? l? l? l? l? l

Although according to the "Attack Modes" table, -A 3 corresponds to Brute-force, in reality, -A 3 uses Mask Attack. Mask Attack can be seen as advanced Brute-force. The

-m parameter is used to specify the hash function type, and the md5 value is stored in the md5.hash file. The key is the last string, "?l?l?l?l?l", which is called a mask.

A mask is a string consisting of several placeholders. "?l" is a placeholder, where "?" is a keyword used to modify the following "l". "?l" together represents a character set. In addition to "?l", there can also be "?u", "?d", "?h", "?h", "?s", "?a" and "?b". The character sets represented are shown in the table below.

0 – 0xff
? Charset
labcdefghijklmnopqrstuvwxyz
uabcdefghijklmnopqrstuvwxyz
d0123456789
h0123456789abcdef
h0123456789abcdef
s! “#$%&'()*+,-./:;<=>?@[\]^_`~{|}
a? l? He? d? s
b

Thus, we understand that "?l" is actually equivalent to a password dictionary:

aaaaa 
aaaab 
... 
zzzzz

Similarly, "?l?u?d" is equivalent to a password dictionary:

  aA0 
  aA1 
  ... 
  bA0 
  ... 
  zZ9

The character set in the table above is built-in to hashcat. We can also specify our own character set:

   --custom-charset1 = character set 1 
    -- custom-charset2 = charset 2 
    -- custom-charset3 = charset 3 
  --custom-charset4=charset 4

The parameter –custom-charsetN can be abbreviated to -N, such as –custom-charset1 can be abbreviated to -1. The character set specified with -N is specified in the mask as a placeholder "? N", such as:

  -1 abc123 ? 1? 1? 1

is equivalent to a password dictionary:

  aaa 
  aab 
  ... 
  aa3 
  ... 
  333

-N In addition to the string representing the character set, it can also be a file ending in .hcchr, which stores the character set. hashcat comes with many .hcchr files, in the charsets/ directory of the installation package.

The character set represented by the placeholder '??' is the '?' itself. Other characters, when used as placeholders, represent the characters themselves. For example, "?lwerner?d" is equivalent to the password dictionary:

  awerner0 
awerner1 
  ... 
  zwerner9

With the above knowledge, it is easy to understand mask. A mask consists of several placeholders, each placeholder is a character set, and a mask is a combination of each placeholder character set. The number of placeholders is equal to the length of the password. What are the advantages of this design over simply giving a set of characters and a password length?

Suppose we know that someone's password has a total of 7 characters, the first character is an uppercase letter, the next 3 are lowercase letters, and the last 3 are numbers. Traditional brute-force cracking requires a character set of AZ, AZ, and 0-9, totaling 62 characters, which requires a maximum of 62^7 = 3 521 614 606 208 attempts, which is trillions of characters. Using a mask to describe this password is "\u\l\l\l\d\d\d", which is easy to calculate. There are (26^4) × (10^3) = 456,976,000 possibilities, which is on the order of hundreds of millions, which is 4 orders of magnitude fewer than the previous method.

Even if we don't know the distribution of passwords, using masks can easily simulate the effects of traditional brute-force cracking.

The problem now is that the mask is fixed, and how many placeholders are fixed? What should we do if we don't know the length of the password? It's one thing if the password is too long, but if someone else's password only has 3 characters and we have 4 placeholders, and we can't crack it no matter what we do, wouldn't that be a huge loss? Do we have to start from 1 and write all the masks of each length? That's so troublesome.

There are two solutions. One is to use a mask file, write multiple masks in one file, and then specify this file in the command line. Note that the mask file must end with .hcmask.

For example, the content of test.hcmask is:

  ? l 
  ? l? l 
  ? l? l? l 
  ? l? l? l? l

then uses the file with the following command:

  hashcat -m 0 -a 3 --show md5.hash test.hcmask

Another solution is to add the parameter –increment, which tells hashcat to start trying with one placeholder according to the mask we gave, then try two, three, until we reach the given length. For example, we write the placeholder "abc" and then calculate the md5 value of the following string:

  a:0cc175b9c0f1b6a831c399e269772661 
  b:92eb5ffee6ae2fec3ad71c777531578f 
  c:4a8a08f09d37b73795649038408b5f33 
  ab:187ef4436122d1cc2f40dc2b92f0eba0 
  ac:e2075474294983e013ee4dd2201c7a73 
  ba:07159c47ee1b19ae4fb9c40d480856c4 
  bc:5360af35bde9ebd8f01f492dc059593c 
  ca:5435c69ed3bcc5b2e4d580e393e373d3 
  cb:d0d7fdb6977b26929fb68c6083c0b439 
  abc:900150983cd24fb0d6963f7d28e17f72 
  abc:900150983cd24fb0d6963f7d28e17f72 
  bac:79ec16df80b57696a03bb364410061f3 
  bca:b64eab8ce39e013604e243089c687e4f 
  cba:3944b025c9ca7eec3154b44666ae04a0 
  cab:16ecfd64586ec6c1ab212762c2c38a90

The ":" is the original string before which the hash value is to be calculated, and the ":" is the calculated hasn value. Save the above content in the file md5.hash, then run the following command:

  hashcat -m 0 -a 3 --show --username md5.hash abc

Adding the parameter –username is because each of our hash values has an original string before it. If this parameter is not added, hashcat will show that the correct hash value was not found. Adding this parameter will make hashcat think that the string before the hash value is the username for that hash value, thus allowing the hash value to be loaded smoothly.

The result of running is that only one hash is resolved:

  900150983cd24fb0d6963f7d28e17f72:abc

Now add the parameter –increment and run again:

  hashcat -m 0 -a 3 --show --increment --username md5.hash abc

This time, two more hashes were solved:

  0cc175b9c0f1b6a831c399e269772661:a 
  187ef4436122d1cc2f40dc2b92f0eba0:ab

As you can see, –increment works. However, we also know that with this parameter, hashcat will only try a, ab, and abc in order, and will not randomly arrange and combine placeholders to try various possibilities.

5. Hybrid Attack

A Hybrid Attack is similar to a Combinator Attack. A Combinator Attack combines two dictionaries, while a Hybrid Attack hybridizes a dictionary with a mask. The two are similar.

Let's say we already have a dictionary, example.dict, with the following content:

   hello 
  werner

then the command:

  hashcat -m 0 -a 6 md5.hash example.dict ? d? d

is equivalent to simply using a dictionary:

  hello00 
  hello01 
  ... 
  hello99 
  werner00 
  werner01 
  ... 
  werener99

then the command:

  hashcat -m 0 -a 7 md5.hash ? d?  dexample.dict

is equivalent to simply using a dictionary:

  00hello 
  01 Hello 
  ... 
  99hello 
  00werner 
  01 Werner 
  ... 
  99werener

Previous: How to use hashcat software to explode various hashes
Next: Hashcat usage method and technical sharing
  • Focus on Word, Excel, PPT, PDF, RAR, ZIP, 7Z, Compressed File, Office Encrypted File Unlock Decryption
  • We provide users with high-quality file compression password recovery, PDF unlocking, and Word password recovery services.
  • Copyright © Document Password Recovery Master Online Decryption Platform