GPU CPU Help Chipboard FPGA Coprocessor
GPU driver requirements
AMD GPUs on Linux require "RadeonOpenCompute (ROCm)" Software Platform (1.6.180 or later) AMD GPUs on Windows require "AMD Radeon Software Crimson Edition" (15.12 or later) Intel CPUs require "OpenCL Runtime for Intel Core and Intel Xeon Processors" (16.1.1 or later) Intel GPUs on Linux require "OpenCL 2.0 GPU Driver Package for Linux" (2.0 or later) Intel GPUs on Windows require "OpenCL Driver for Intel Iris and Intel HD Graphics" NVIDIA GPUs require "NVIDIA Driver" (367.x or later)
下面使常见的参数,想了解更多的参数可以hashcat --help View
-a Specifies the cracking mode to use, the value of which refers to the parameters facing later. "-a 0" dictionary attack, "-a 1" combination attack; "-A 3" mask attack. -m specifies the hash type to be cracked. If no type is specified, the default is MD5. -o specifies the storage location of the successfully cracked hash and the corresponding plaintext password. It can be used to write the successfully cracked hash to a specified file. --force ignores warning messages during the cracking process; this option may need to be added to run a single hash. --show displays the cracked hash and the plaintext corresponding to the hash. --increment enables incremental cracking mode, which you can use to have hashcat perform cracking within a specified password length range. --increment-min Minimum password length, followed by an integer. Configure increment mode to use it together. --increment-max Maximum password length, same as above --outfile-format specifies the output format id of the cracked result; the default is 3. --username ignores the specified username in the hash file, which may be used to crack linux system user password hashes. --remove Removes the successfully cracked hash -r Use custom crack rules
# | Mode ===+====== 0 | Straight (field cracking) 1 | Combination 3 | Brute-force 6 | Hybrid Wordlist + Mask 7 | Hybrid Mask + Wordlist
1 = hash[:salt] 2 = plain 3 = hash[:salt]:plain 4 = hex_plain 5 = hash[:salt]:hex_plain 6 = plain:hex_plain 7 = hash[:salt]:plain:hex_plain 8 = crackpos 9 = hash[:salt]:crackpos 10 = plain:crackpos 11 = hash[:salt]:plain:crackpos 12 = hex_plain:crackpos 13 = hash[:salt]:hex_plain:crackpos 14 = plain:hex_plain:crackpos 15 = hash[:salt]:plain:hex_plain:crackpos
Because there are so many, I'll just post some common hash types. To understand all the parameters, you can go to the hashcat Wiki, or you can directly use hashcat --help to view the hash comparison table
- [ hash modes ] -
# | Name | Category
======+==================================================+======================================
900 | MD4 | Raw Hash
0 | MD5 { } | Raw Hash
5100 | Half MD5 | Raw Hash
100 | SHA1 | Raw Hash
1300 | SHA2-224 | Raw Hash
1400 | SHA2-256 | Raw Hash
10800 | SHA2-384 | Raw Hash
1700 | SHA2-512 | Raw Hash
17300 | SHA3-224 | Raw Hash
17400 | SHA3-256 | Raw Hash
17500 | SHA3-384 | Raw Hash
17600 | SHA3-512 | Raw Hash
10 | md5($pass.$salt) | Raw Hash, Salted and/or Iterated
20 | md5($salt.$pass) | Raw Hash, Salted and/or Iterated
30 | md5(utf16le($pass).$salt) | Raw Hash, Salted and/or Iterated
40 | md5($salt.utf16le($pass)) | Raw Hash, Salted and/or Iterated
3800 | md5($salt.$pass.$salt) | Raw Hash, Salted and/or Iterated
3710 | md5($salt.md5($pass)) | Raw Hash, Salted and/or Iterated
4010 | md5($salt.md5($salt.$pass)) | Raw Hash, Salted and/or Iterated
4110 | md5($salt.md5($pass.$salt)) | Raw Hash, Salted and/or Iterated
2600 | md5(md5($pass)) | Raw Hash, Salted and/or Iterated
3910 | md5(md5($pass).md5($salt)) | Raw Hash, Salted and/or Iterated
4300 | md5(strtoupper(md5($pass))) | Raw Hash, Salted and/or Iterated
4400 | md5(sha1($pass)) | Raw Hash, Salted and/or Iterated
110 | sha1($pass.$salt) | Raw Hash, Salted and/or Iterated
120 | sha1($salt.$pass) | Raw Hash, Salted and/or Iterated
130 | sha1(utf16le($pass).$salt) | Raw Hash, Salted and/or Iterated
140 | sha1($salt.utf16le($pass)) | Raw Hash, Salted and/or Iterated
4500 | sha1(sha1($pass)) | Raw Hash, Salted and/or Iterated
4520 | sha1($salt.sha1($pass)) | Raw Hash, Salted and/or Iterated
4700 | sha1(md5($pass)) | Raw Hash, Salted and/or Iterated
4900 | sha1($salt.$pass.$salt) | Raw Hash, Salted and/or Iterated
14400 | sha1(CX) | Raw Hash, Salted and/or Iterated
1410 | sha256($pass.$salt) | Raw Hash, Salted and/or Iterated
1420 | sha256($salt.$pass) | Raw Hash, Salted and/or Iterated
1430 | sha256(utf16le($pass).$salt) | Raw Hash, Salted and/or Iterated
1440 | sha256($salt.utf16le($pass)) | Raw Hash, Salted and/or Iterated
1710 | sha512($pass.$salt) | Raw Hash, Salted and/or Iterated
1720 | sha512($salt.$pass) | Raw Hash, Salted and/or Iterated
1730 | sha512(utf16le($pass).$salt) | Raw Hash, Salted and/or Iterated
1740 | sha512($salt.utf16le($pass)) | Raw Hash, Salted and/or Iterated
14000 | DES (PT = $salt, key = $pass) | Raw Cipher, Known-Plaintext attack
14100 | 3DES (PT = $salt, key = $pass) | Raw Cipher, Known-Plaintext attack
14900 | Skip32 (PT = $salt, key = $pass) | Raw Cipher, Known-Plaintext attack
15400 | ChaCha20 | Raw Cipher, Known-Plaintext attack
2500 | WPA-EAPOL-PBKDF2 | Network Protocols
2501 | WPA-EAPOL-PMK | Network Protocols
16800 | WPA-PMKID-PBKDF2 | Network Protocols
16801 | WPA-PMKID-PMK | Network Protocols
7300 | IPMI2 RAKP HMAC-SHA1 | Network Protocols
7500 | Kerberos 5 AS-REQ Pre-Auth etype 23 | Network Protocols
8300 | DNSSEC (NSEC3) | Network Protocols
10200 | CRAM-MD5 | Network Protocols
11100 | PostgreSQL CRAM (MD5) | Network Protocols
11200 | MySQL CRAM (SHA1) | Network Protocols
16100 | TACACS+ | Network Protocols
16500 | JWT (JSON Web Token) | Network Protocols
121 | SMF (Simple Machines Forum) > v1.1 | Forums, CMS, E-Commerce, Frameworks
400 | phpBB3 (MD5) | Forums, CMS, E-Commerce, Frameworks
2811 | MyBB 1.2+ | Forums, CMS, E-Commerce, Frameworks
2811 | IPB2+ (Invision Power Board) | Forums, CMS, E-Commerce, Frameworks
8400 | WBB3 (Woltlab Burning Board) | Forums, CMS, E-Commerce, Frameworks
11 | Joomla < 2.5.18 | Forums, CMS, E-Commerce, Frameworks
400 | Joomla >= 2.5.18 (MD5) | Forums, CMS, E-Commerce, Frameworks
400 | WordPress (MD5) | Forums, CMS, E-Commerce, Frameworks
2612 | PHPS | Forums, CMS, E-Commerce, Frameworks
7900 | Drupal7 | Forums, CMS, E-Commerce, Frameworks
21 | osCommerce | Forums, CMS, E-Commerce, Frameworks
21 | xt:Commerce | Forums, CMS, E-Commerce, Frameworks
11000 | PrestaShop | Forums, CMS, E-Commerce, Frameworks
124 | Django (SHA-1) | Forums, CMS, E-Commerce, Frameworks
10000 | Django (PBKDF2-SHA256) | Forums, CMS, E-Commerce, Frameworks
12 | PostgreSQL | Database Server
131 | MSSQL (2000) | Database Server
132 | MSSQL (2005) | Database Server
1731 | MSSQL (2012, 2014) | Database Server
200 | MySQL323 | Database Server
300 | MySQL4.1/MySQL5 | Database Server
3100 | Oracle H: Type (Oracle 7+) | Database Server
112 | Oracle S: Type (Oracle 11+) | Database Server
12300 | Oracle T: Type (Oracle 12+) | Database Server
8000 | Sybase ASE | Database Server
15000 | FileZilla Server >= 0.9.55 | FTP Server
11500 | CRC32 | Checksums
3000 | LM | Operating Systems
1000 | NTLM | Operating Systems
500 | md5crypt, MD5 (Unix), Cisco-IOS $1$ (MD5) | Operating Systems
3200 | bcrypt $2*$, Blowfish (Unix) | Operating Systems
7400 | sha256crypt $5$, SHA256 (Unix) | Operating Systems
1800 | sha512crypt $6$, SHA512 (Unix) | Operating Systems
122 | macOS v10.4, macOS v10.5, macOS v10.6 | Operating Systems
1722 | macOS v10.7 | Operating Systems
7100 | macOS v10.8+ (PBKDF2-SHA512) | Operating Systems
11600 | 7-ZIP | Archives
12500 | RAR3-hp | Archives
13000 | RAR5 | Archives
13600 | WinZip | Archives
9700 | MS Office <= 2003 $0/$1, MD5 + RC4 | Documents
9710 | MS Office <= 2003 $0/$1, MD5 + RC4, collider #1 | Documents
9720 | MS Office <= 2003 $0/$1, MD5 + RC4, collider #2 | Documents
9800 | MS Office <= 2003 $3/$4, SHA1 + RC4 | Documents
9810 | MS Office <= 2003 $3, SHA1 + RC4, collider #1 | Documents
9820 | MS Office <= 2003 $3, SHA1 + RC4, collider #2 | Documents
9400 | MS Office 2007 | Documents
9500 | MS Office 2010 | Documents
9600 | MS Office 2013 | Documents
10400 | PDF 1.1 - 1.3 (Acrobat 2 - 4) | Documents
10410 | PDF 1.1 - 1.3 (Acrobat 2 - 4), collider #1 | Documents
10420 | PDF 1.1 - 1.3 (Acrobat 2 - 4), collider #2 | Documents
10500 | PDF 1.4 - 1.6 (Acrobat 5 - 8) | Documents
10600 | PDF 1.7 Level 3 (Acrobat 9) | Documents
10700 | PDF 1.7 Level 8 (Acrobat 10 - 11) | Documents
99999 | Plaintext | PlaintextHere is a list of common mask character sets
l | abcdefghijklmnopqrstup
u | ABCDEFGHIJKLMNOPQRSTUVWXYZ Pure uppercase letters
d | 0123456789 Pure numbers
h | 0123456789abcdef Common lowercase subdirectories and numbers
H | 0123456789ABCDEF Common uppercase letters and numbers
s | ! "#$%&'()*+,-./:; <=>? @[\]^_`{|}~ Special characters
A | ? l? He? d? s All visible characters on the keyboard
b | 0 - 0xff may be used to match passwords like spaces. Here are a few simple examples to understand the mask settings.
Eight-digit password:? d? d? d? d? d? d? d? d 8-digit unknown password:? And? And? And? And? And? And? And? a The first four digits are uppercase letters and the last four digits are numbers:? He? He? He? He? d? d? d? d The first four digits are numbers or lowercase letters, and the last four are uppercase letters or numbers: Huh? Huh? Huh? Huh? Huh? Huh? Huh? H The first three characters are unknown, the middle is admin, and the last three are unknown:? And? And? Admin? And? And? a 6-8 digit password: --increment --increment-min 6 --increment-max 8 ? l? l? l? l? l? l? l? l 6-8 digit number + lowercase letter password: --increment --increment-min 6 --increment-max 8 ? Huh? Huh? Huh? Huh? Huh? Huh? Huh? h
If we want to set the charset to: abcd123456! @-+, what should we do then? This requires the custom character set parameter. hashcat supports users to define up to 4 character sets
-- custom-charset1 [chars] is equivalent to -1 --custom-charset2 [chars] is equivalent to -2 --custom-charset3 [chars] is equivalent to -3 --custom-charset4 [chars] is equivalent to -4 Used in a mask? 1、? 2、? 3、? 4 is used to represent this.
Here are a few more examples:
--custom-charset1 abcd123456! @-+。 Then we can use "? 1 " represents this character set. --custom-charset2 ? l? d, here and? 2 is equivalent to? h -1 ? d? l? u,? 1 represents a number + lowercase letter + uppercase letter. -3 abcdef -4 123456 So? 3? 3? 3? 3? 4? 4? 4? 4 indicates that the first four digits might be "abcdef", and the last four digits might be "123456".
PS: I'll give you my machine's configuration here, and then compare the cracking speed.
CPU: Intel(R) Core(TM) i5-7300HQ CPU @ 2.50GHz Graphics: GTX 1050 Ti
hashcat64.exe -a 3 -m 0 --force 25c3e88f81b4853f2a8faacad4c871b6 ? d? d? d? d? d? d? d
hashcat64.exe -a 3 -m 0 --force 7a47c6db227df60a6d67245d7d8063f3 ? l? l? l? l? l? l? l
hashcat64.exe -a 3 -m 0 --force 4488cec2aea535179e085367d8a17d75 --increment --increment-min 1 --increment-max 8 ? d? d? d? d? d? d? d? d
hashcat64.exe -a 3 -m 0 --force ab65d749cba1656ca11dfa1cc2383102 --increment --increment-min 1 --increment-max 8 ? Huh? Huh? Huh? Huh? Huh? Huh? Huh? h
hashcat64.exe -a 3 -1 123456abcdf! @+- 8b78ba5089b11326290bc15cf0b9a07d ? 1? 1? 1? 1? 1 Note: Here -1 and? 1 is the number 1, not the letter l
hashcat64.exe -a 3 -1 123456abcdf! @+- 9054fa315ce16f7f0955b4af06d1aa1b --increment --increment-min 1 --increment-max 8 ? 1? 1? 1? 1? 1? 1? 1? 1
hashcat64.exe - a 3 - 1 ? d? He? l? s d37fc9ee39dd45a7717e3e3e9415f65d --increment --increment-min 1 --increment-max 8 ? 1? 1? 1? 1? 1? 1? 1? 1 Or: hashcat64.exe -a 3 d37fc9ee39dd45a7717e3e9415f65d --increment --increment-min 1 --increment-max 8 ? And? And? And? And? And? And? And? A
-A 0 is the specified dictionary cracking mode, -o is the output result to a file hashcat64.exe -a 0 ede900ac1424436b55dc3c9f20cb97a8 password.txt -o result.txt
hashcat64.exe -a 0 hash.txt password.txt -o result.txt
hashcat64.exe -a 1 25f9e794323b453885f5181f1b624d0b pwd1.txt pwd2.txt
hashcat64.exe -a 6 9dc9d5ed5031367d42543763423c24ee password.txt ? l? l? l? l? l
hashcat64.exe -a 3 -m 300 --force 6BB4837EB74329105EE4568DDA7DC67ED2CA2AD9 ? d? d? d? d? d? d
can be obtained by cat /etc/shadow
hashcat64.exe -a 3 -m 1800 --force $6$mxuA5cdy$XZRk0CvnPFqOgVopqiPEFAFK72SogKVwwwp7gWaUOb7b6tVwfCpcSUsCEk64ktLLYmzyew/xd0O0hPG/yrm2X. ? l? l? l? l
No need to organize usernames, use --username
hashcat64.exe -a 3 -m 1800 --force qiyou:$6$QDq75ki3$jsKm7qTDHz/xBob0kF1Lp170Cgg0i5Tslf3JW/sm9k9Q916mBTyilU3PoOsbRdxV8TAmzvdgNjrCuhfg3jKMY1 ? l? l? l? l? l --username
You can get the value of NT-hash, LM-hash using saminside
NT-hash: hashcat64.exe -a 3 -m 1000 209C6174DA490CAEB422F3FA5A7AE634 ? l? l? l? l? l LM hash: hashcat64.exe -a 3 -m 3000 F0D412BD764FFE81AAD3B435B51404EE ? l? l? l? l? l
hashcat64.exe -a 3 -m 132 --force 1008c8006c224f71f6bf0036f78d863c3c4ff53f8c3c48edafb ? l? l? l? l? l? d? d? d
The specific encryption script is in the HashPassword function of ./wp-includes/class-phpass.php
hashcat64.exe -a 3 -m 400 --force $P$BYEYcHEj3vDhV1lwGBv6rpxurKOEWY/ ? d? d? d? d? d? d
its password encryption method md5(md5($pass).$salt)
hashcat64.exe -a 3 -m 2611 --force 14e1b600b1fd579f47433b88e8d85291: ? d? d? d? d? d? d
First, rar2john gets the hash value of the RAR file. Download address
Get the hash value of the RAR file: rar2john.exe 1. RAR Results: 1.RAR:$rar5$16$639e9ce8344c680da12e8bdd4346a6a3$15$a2b056a21a9836d8d48c2844d171b73d$8$04a52d2224ad082e
hashcat64.exe -a 3 -m 13000 --force $rar5$16$639e9ce8344c680da12e8bdd4346a6a3$15$a2b056a21a9836d8d48c2844d171b73d$8$04a52d2224ad082e ? d? d? d? d? d? d
Note:
hashcat supports RAR3-hp and RAR5, the official example is as follows: -m parameter type example hash 12500 RAR3-hp $RAR3$*0*45109af8ab5f297a*adbf6c5385d7a40373e8f77d7b89d317 13000 rar5 $rar5$16$74575567518807622265582327032280$15$f8b4064de34ac02ecabfe
Get the hash value of the file with zip2john: zip2john.exe 1.ZIP Results: 1.ZIP:$zip2$*0*3*0*554bb43ff71cb0cac76326f292119dfd*ff23*5*24b28885ee*d4fe362bb1e91319ab53*$/zip2$:::::1.ZIP-1.txt
hashcat64.exe -a 3 -m 13600 $zip2$*0*3*0*554bb43ff71cb0cac76326f292119dfd*ff23*5*24b28885ee*d4fe362bb1e91319ab53*$/zip2$ --force ? d? d? d? d? d? d
Get Office hash value: python office2john.py 11.docx Results: 11.docx: $Office$*2013*100000*256*16*e4a3eb62e8d3576f861f9eded75e0525*9eeb35f0849a7800d48113440b4bbb9c*577f8d8b2e1c5f60fed76e62327b38d28f25230f6c7dfd66588d9ca8097aabb9
hashcat64.exe -a 3 -m 9600 $Office$*2013*100000*256*16*e4a3eb62e8d3576f861f9eded75e0525*9eeb35f0849a7800d48113440b4bbb9c*577f8d8b2e1c5f60fed76e62327b38d28f25230f6c7dfd66588d9ca8097aabb9 --force ? d? d? d? d? d? d
First, convert our handshake packet to hccapx format. The latest version of hashcat only supports hccapx format; the previous hccap format is no longer supported.
Official online conversion https://hashcat.net/cap2hccapx/
hashcat64.exe -a 3 -m 2500 1.hccapx 1391040? d? d? d? d
For cracked hash values, use hashcat64.exe hash --show to view the results.
All hash cracking results are in the hashcat.potfile file.
If the cracking time is too long, you can press the s key to view the cracking status, the p key to pause, the r key to continue cracking, and the q key to exit cracking.
When cracking using GPU mode, the -O parameter can be used for automatic optimization.
Suggestions for actual cracking: If we crack blindly, it will consume a lot of our time and resources.
1. First, go through a commonly used weak password dictionary. 2. Combine passwords, such as: zhang1999, using a combination of surname and year of birth. Of course, other combinations are also acceptable; this is just an example. 3. Organize commonly used mask combinations and place them in the .hcmask file within masks, then let it automatically load and crack them. 4. If all else fails, you can try all low-digit combinations. However, it is not recommended to crack combinations with too many digits. If the other party sets a complex password, you may not be able to crack it in the end, wasting a lot of time and resources, which is not worth the gain. 6. HashCat Parameter Optimization Considering the hashcat cracking speed and resource allocation, we can configure some parameters. 1. Workload tuning
This parameter supports values of 1, 8, 40, 80, 160--gpu-accel 160 to maximize GPU performance.2. Gpu loops Load Tuning
The range of supported values for this parameter is 8-1024 (some algorithms only support up to 1000).-- gpu-loops 1024 allows the GPU to perform at its best.3. Segment size Dictionary Cache size
This parameter sets the size of the memory cache. Its purpose is to put the dictionary into the memory cache to speed up dictionary cracking. The default is 32MB, which can be set according to your own memory conditions. Of course, the larger the dictionary, the bigger the block.--segment-size 512 can improve the speed of large dictionary cracking.This article is reprinted from the Prophet Community, originally authored By Qiyou. Please delete it if it infringes upon your information.