KB / Статті / Hashcat та John the Ripper: зламування хешів
UA EN

Hashcat and John the Ripper: Password Hash Cracking

✍ admin 📅 09.06.2026 👁 127 переглядів

Why Crack Hashes?

In CTF and pentesting, you often find database dumps containing password hashes. The goal is to recover the original passwords to gain access to systems.

Step 1: Identify the Hash Type

# hash-identifier tool
hash-identifier

# Or hashid
hashid '$2y$10$abcdefghijklmnopqrstuuVGEEkG9psOFMWgRdJR0gk'

# Or online: https://hashes.com/en/tools/hash_identifier

Common types and what they look like:

MD5:        5f4dcc3b5aa765d61d8327deb882cf99
SHA1:       5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8
SHA256:     5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8
bcrypt:     $2y$10$...   (starts with $2y$ or $2b$)
MD5crypt:   $1$salt$hash
SHA512crypt:$6$salt$hash
NTLM:       aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0

Hashcat

Hashcat uses the GPU — significantly faster than John on most systems.

Basic Syntax

hashcat -m <type> -a <attack> <hash/file> <wordlist>

Attack Modes (-a)

0 — dictionary attack
1 — combinator (two wordlists)
3 — brute-force/mask
6 — wordlist + mask
7 — mask + wordlist

Determining -m (mode)

# Show all types
hashcat --help | grep -i md5
hashcat --help | grep -i sha

# Common:
# 0    — MD5
# 100  — SHA1
# 1400 — SHA256
# 1800 — sha512crypt $6$
# 3200 — bcrypt $2*$
# 1000 — NTLM
# 5600 — NetNTLMv2

Examples

Dictionary attack:

# MD5 with rockyou.txt
hashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txt

# bcrypt — slow, but possible
hashcat -m 3200 -a 0 hash.txt /usr/share/wordlists/rockyou.txt

# Save progress
hashcat -m 0 -a 0 hash.txt rockyou.txt --session=mysession
hashcat --session=mysession --restore  # restore

Brute-force with a mask:

# ?l = lowercase, ?u = uppercase, ?d = digit, ?s = special, ?a = all

# 4-digit PIN
hashcat -m 0 -a 3 hash.txt ?d?d?d?d

# 8 characters, lowercase and digits only
hashcat -m 0 -a 3 hash.txt ?l?l?l?l?d?d?d?d

# Password starting with uppercase, 7 lowercase
hashcat -m 0 -a 3 hash.txt ?u?l?l?l?l?l?l?l

With rules:

# Rules modify words from the wordlist (append digits, substitute symbols)
hashcat -m 0 -a 0 hash.txt rockyou.txt -r /usr/share/hashcat/rules/best64.rule
hashcat -m 0 -a 0 hash.txt rockyou.txt -r /usr/share/hashcat/rules/rockyou-30000.rule

Show cracked passwords:

hashcat -m 0 hash.txt --show

John the Ripper

John is more beginner-friendly and works well without a GPU.

Basic Usage

# John auto-detects the hash type
john hash.txt

# With a wordlist
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt

# Show cracked passwords
john --show hash.txt

# Specific format
john --format=bcrypt hash.txt
john --format=Raw-MD5 hash.txt

# List formats
john --list=formats

Preparing Hashes for John

# /etc/shadow format
unshadow /etc/passwd /etc/shadow > combined.txt
john combined.txt

# ZIP archive
zip2john archive.zip > zip.hash
john zip.hash

# PDF
pdf2john document.pdf > pdf.hash
john pdf.hash

# SSH key with passphrase
ssh2john id_rsa > ssh.hash
john ssh.hash --wordlist=rockyou.txt

Online Resources

If the hash is fast (MD5, SHA1) — try online first: - crackstation.net — large tables for MD5, SHA1, SHA256 - hashes.com — database of cracked hashes - md5decrypt.net

Wordlists

# Rockyou — the CTF standard
/usr/share/wordlists/rockyou.txt   # Kali Linux
# or download from GitHub SecLists

# SecLists — large collection of wordlists
git clone https://github.com/danielmiessler/SecLists

# Useful lists:
SecLists/Passwords/Common-Credentials/10-million-password-list-top-1000000.txt
SecLists/Passwords/Leaked-Databases/rockyou.txt

CTF Algorithm

1. Got a hash → identify the type (hash-identifier/hashid)
2. Fast hash (MD5/SHA1) → try crackstation online
3. Not found → hashcat/john with rockyou.txt wordlist
4. No luck → add rules (best64.rule)
5. Know the password format → brute-force with a mask
6. bcrypt/sha512crypt → dictionary only, GPU required
Коментарі (0)
Увійди, щоб залишити коментар.
Коментарів поки немає.
Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?