Hashcat tutorial on cracking mode parameter settings

1. Combination mode (-a1)

Sometimes, we will encounter such problems. For example, if the password is abcdabcd, and there is no abcdabcd in our dictionary. If we generate it, it will take up a huge amount of space. Can we have a way to generate abcdabcd through abcd? In hashcat, it can of course be implemented. In this section, we will first talk about this pattern, namely the dictionary combination attack pattern (the parameter is represented as-a1).

1. Combination pattern of the same dictionary

First, we will describe the meaning of-a1 with a simple example, and then take you step by step through the complex application of this pattern.

hashcat-a1-m0mima.txt-o outfile dic.txt dic.txt

0.PNG
The meaning of this command is to use the dictionary dic.txt to combine it to decipher mima.txt. If dic.txt is a dictionary as shown in the following figure

1.PNG
, the new dictionary to decipher mima.txt

2.PNG
is formed by combining each line in dic.txt with itself to form a new dictionary.

2. Combination pattern of different dictionaries

The foregoing is the combination of the same dictionary. If it is different dictionaries, hashcat also supports it. Use the command as shown below to represent the solution of

3.PNG
mima.txt by combining all lines in dic1.txt with all lines in dic2.txt to form a dictionary that solves mima.txt.

Under what circumstances is the combination mode used? In combination mode, when the user's password is clearly divided into two paragraphs, such as abcd1234, asdfasdf, aaa19770101,..., etc., the password is obviously expressed as the previous paragraph and the latter paragraph.

3. Points to note

(1) In combination mode, currently hashcat can only support the combination of two dictionaries (or the same dictionary twice), and cannot support multiple dictionaries (more than 3 dictionaries) or more than 3 combinations of the same dictionary. attacks.

That is to say, the following command is wrong:

hashcat -a 1-m0mima.txt-ooutfile dic.txt

hashcat -a 1-m0mima.txt-ooutfile dic1.txt dic2.txt dic3.txt

(2) In the combined mode, directories are not supported (in the previous article, the entire directory is supported in the-a0 mode), which means that the following two situations are not working.

hashcat -a 1-m0 mima.txt-ooutfile /dic/

hashcat -a 1-m0 mima.txt-ooutfile /dic/*.txt

(3) Timeliness problem

When using the combination mode, if the dictionary is very large, for example, two dictionaries are 10,000,000,000, and the combined space is 100,000,000, which is equivalent to an attack with 10,000,000 dictionaries (each dictionary has 10,000,000 entries), the space is too large, and a large number of duplication may occur. Although the coverage has increased, the timeliness is not high.

 2. Brute-force mode (-a3)

Brute-force cracking, as the name suggests, is to violently exhaust the specified plaintext space. It is a helpless method (because you have no way to reduce the exhausted space).

Before formally talking about brute force, let's talk about exhausting space. Take the common lower-case letters + numbers as an example. If the password length is 4, its space is 36**4=1679616, which seems not big and will come out in a while; if the password length is 8, its space is 36**8=2821109907456. If the solution time is 1000,000,000 (1 billion times/s), the solution time is about 2820 seconds, about 47 minutes, which seems to be tolerable; If the password length is 10, its space is 36**10=3656158440062976. If the solution time is 1000,000,000 (1 billion times/s), the solution time exceeds 1000 hours, and there is no way to accept it.

There are many different types of brute-force cracking modes in hashcat (the parameter is represented as-a3), and we will describe them one by one below.

1. In simple mode

hashcat, there are 8 default character sets built in, namely l (26 lowercase letters), u (26 upper case letters), d (10 digits), h (lower case hexadecimal characters), H (upper case hexadecimal characters), s (special characters 31), a (a collection of 95 full characters of l,u,d,s) and b (binary

0 -0xff). as shown in the following figure

4.PNGFor example

(1) If the command to exhaust the 6-bit space of lower-case letters is as follows:

5.PNG(2) If the command to exhaust the 8-bit space of all characters is as follows:

6.PNG(3) If the full number space of 4-6 bits is exhausted, the command is as follows:

7.PNGHere, a parameter--inrcement --increment-min4--inrcement --increment-max6 is added to indicate the minimum and maximum values of the exhaustive length.

2. Combination mode The combination

mode here is an organization mode under the exhaustive mode, not the mode of (-a1).

Direct examples are given to illustrate:

(1) A password has an exhaustive range, and the password length is estimated to be 6. The first digit is a full character set, the second digit is a lowercase letter, the third digit is a capitalization letter, and the fourth, fifth, and sixth digits are a full character set., then the command can use the following modes:

8.PNG(2) Several combination modes are given below.

One: If a password has a range of case + number and a length of 6, the command is as follows:

9.PNGHere, use-1 ? l? u? d represents upper and lower case letters + numbers.

Second: If the exhaustive range is 6 digits, the first and fourth digits are case + number, the second digit is case, the third and fifth digits are case + number, and the sixth digit is number, the command is as follows:

10.PNGOf course, you can also specify the minimum length and maximum length, as shown in the following figure.

11.PNG
3. In the beginning of the custom mode

, we introduced that hashcat has 8 built-in character sets, but what if the character set required by the user is not among these 8? What should I do? It doesn't matter, hashcat has also prepared rich customized violent attack modes for everyone.

Using the hashcat-h command, you can see that the following usage patterns are defined

12.PNG. Let's explain them one by one:

(1) If the password length is 8 bits, each bit is defined by "0123456789aqwcfhj,. <>=-_+", the following command can be used.

13.PNGYou can also write these characters as a file, such as char.txt, using the following command.

14.PNG(2) If the password length is 8 bits, the first, third and sixth bits are in "43545yt", the second and fourth bits are in "345dfv-=_+", the fifth and seventh bits are in "9vjnbbf-brg", and the eighth bit is in "345fkfggh", the following command can be used.

15.PNGOf course, you can also write these characters into different files, such as char1.txt,..., using the following command.

16.PNGNote: Some symbols have special meanings on the command line, so when there are special symbols in the character set, it is best to write these symbols in file form.

(3) On the basis of (2), increase the minimum length and maximum length, such as 4-8 bits. The following command can be used.

17.PNG

3. The use of some parameters

In the previous article, we introduced the use of some parameters. Today, we will continue to introduce some commonly used parameters. Today, we will focus on screen display parameters

. In the previous article, we introduced the command related to file output (-o/-outfile-format). Through these commands, the results of hashcat password cracking can be output to a file in a certain format. But while hashcat is running, we can't see which passwords hashcat has cracked. If in the work of hashcat, we can directly print the password decrypted by hashcat to the screen, it will be more intuitive and convenient. There are just a few parameters in hashcat that can output the hashcat running results to the screen.

1. The--show

Show command will output the decrypted hash and password cached in the pot file to the screen window.

18.PNG

2. The--

left command will output the hash value that hashcat has not cracked to the screen.

19.PNG

3. The--stdout

stdout command will not crack the password, but it will print the contents of the dictionary used for password cracking.

20.PNG

Fourth, it is concluded that there are

many commands for Hashcat, and the differences between different parameters are very large. If you want to give full play to the functions and functions of hashcat, it is recommended that you try more with different commands to familiarize yourself with the combination methods of different hashcat commands. For the functions of hashcat parameters, you can learn from hashcat online help (-h).

Previous: Hashcat is a password explosion artifact
Next: Experience sharing of hashcat using GPU acceleration to improve d
  • Focus on Word, Excel, PPT, PDF, RAR, ZIP, 7Z, Compressed File, Office Encrypted File Unlock Decryption
  • We provide users with high-quality file compression password recovery, PDF unlocking, and Word password recovery services.
  • Copyright © Document Password Recovery Master Online Decryption Platform