Quantcast
Channel: hashcat Forum - All Forums
Viewing all 8061 articles
Browse latest View live

Password list maker in progress

$
0
0
Hello everyone,

Sometimes I've just wanted something simple do dump a list of common alterations to words to get a new password list.  For example if I have a list of 100 common words, I wanted to add 1, 123, ! and other things to the end, generate some 1337-speak, capitalize the first letter, uppercase everything, then add everything to the end of the all-caps words, etc.

So here is a little script I've been working on.

C:\wordlists> python passtransform.py --wordlist pass.lst --outfile pass2.lst --sort

If I had "password" in the pass.lst, it would generate the following variations while keeping the original:

P@SSWORD
P@SSWORD!
P@SSWORD1
P@SSWORD123
P@SSWORD1234
P@ssword
P@ssword!
P@ssword1
P@ssword123
P@ssword1234
PASSWORD
PASSWORD!
PASSWORD1
PASSWORD123
PASSWORD1234
Password
Password!
Password1
Password123
Password1234
p@ssword
p@ssword!
p@ssword1
p@ssword123
p@ssword1234
password
password!
password1
password123
password1234


It's still a work in progress, and I haven't yet added $ to the end, little things like that, but easily done.

If you find it useful I'll put it on github and I'll take requests to add features/transformations, new command line switches for things, inserting into a database (MySQL or Postgres) etc. (Why? But I've heard of that).  Adding exclude rules.  Or whatever.

Remember with big password lists it generates word + 29 extras, so a wordlist with 10 words ends up with 370 words.  In its current state... means multiply the number of words by 37.  A password list with 1000 words ends up with 37,000 words, for example.

This is strictly for word lists, and I'm thinking it could also be used with maskprocessor.

Thanks,
James

.txt   passtransform.txt (Size: 4.06 KB / Downloads: 0)

Tutor wanted to ask a few q's: offering BTC payment

$
0
0
Hello,

I have a few questions I'd like to ask about using hashcat, and generating rainbow tables, but just hashcat for now.

One is: suppose I have hashes that are e.g. sha512($password . $salt ) where $salt is unknown but could be an arbitrary length binary object, e.g. 6 bytes.  Then that is hashed 5000 times.  (Similar to what Symfony uses with it's sha512 provider).  I have a password file, and I want to actually crack the salt, assuming that I have the password.  How could I do that?

I have a few other questions, mostly dumb ones I guess.  I've been googling and practicing on my rig but I want to try and get up to speed with my burning questions faster.

If you can help I can optionally send some bitcoin your way, although a modest amount.

Thank you,
James

CL_OUT_OF_HOST_MEMORY

$
0
0
hello
yesterday i install 411.63 drivers at my windows7 rig and got this isue when try run second hashcat instance.
With just one it work fine. Now i work on sha256unix list and cant try even 1 DES hash. Pause unix instance dont help.
Till yesterday i got  hashcat 3.5 and drivers about 360 version Smile. I know that is very old but work like a charm.
Any ideas ?

PS. I use driver fusion to remove old gpu drivers  stuff

kernel implementation quirks between a0, a1, a3

$
0
0
When implementing another custom kernel again, I notice that I am again sometimes struggling with 'obvious' swaps of either pws or difference between the vectorized (mainly a3) and non vectorized approaches (a0, a1).

For example (I do not pretend to  know what all kernel OPTS_TYPES do underwater, so I mainly set them just zero when implementing a kernel)


So I noticed that without the OPTS_TYPE_PT_GENERATE_BE the results of sha512_final_vector() isn't consistent with the non-vectorized sha512_final(). Meaning, not using this OPTS_TYPE creates a different result in sha512_final_vector().

In the a1 and a3 kernels I noticed pws are swapped, but in the a0 they are straightforward. Which means I needed an extra swap in the implementation of the a1 and a3 kernels.


I can understand that some algorithms are either designed on either BE or LE, and to some degree I understand some implementation ways might be more efficient on OpenCL. Just trying to get my head around why these differences between the kernel attack modes exist in hashcat.

If anyone can help me understand these quirks, I would appreciate it.

RX 570 benchmark results ?

$
0
0
Hi, I'm interested to know if anyone have some RX570 4GB version to post benchmark results here ?

I need for WPA/WPA2 only.

Thanks.

Help with format

$
0
0
Is it possible to make the format user:hash:password
If so can you please tell me

Freeze / no response when trying to see status or output, most of the time

$
0
0
Hello, I have a question / problem with HC on windows10. Using with five RX570 gpus. I am trying to run a dictionary+mask attack on wpa2. Usually this process takes about 4 hours. Sometimes, I am able to reach the end and see the result, but more often I get no output after the "Status[S] Quit[Q] etc" section and pressing "s" for status or "q" for quit does nothing except show one extra newline the first time the key is pressed.  Also, sometimes this problem shows up right when I start the process (pressing "s" shows nothing), while other times a few status messages work in the beginning, and then somewhere between then and the end it will 'freeze'. The logfile also does not show any more information after the 'freeze'. Furthermore, the actual cracking process does not seem to freeze, as I always note that the GPU fans will spin down after about four hours. Its just something about showing the output that is an issue, I guess. (?) I have also tried with -w1,2,3,4 without any noticeable change. Also, I have tried restarting the PC in between most of these tests. Are there any more efforts I can try to figure out what is going on? 

The dict is 10926977 lines, 171.6MB, and the mask is three digits, right side. 

Thank you for reading.

Problem with 11300

$
0
0
Hello everyone,
My last thread was deleted, don't know why
I have a problem with hashcat because once I run the program says me "token length exception"
I've tried the version 4.2.0 and 4.2.1.
With the version 5.0.0 works but it says me to set --brain-password ( don't know what is )
Thanks

Crack sl3 sha1 based in hash:salt

$
0
0
Hi
Is it possible to crack this HASH:SALT using hashcat ?
FC429C72F6A25311AC7440680CE8B061875BAC98:003597440418504900
It is sha1 used in the passed to calculate sl3 codes.

BR

Zip Problem Still exists

$
0
0
Hey there ,

First something about my system :
  • Running The-Distribution-Which-Does-Not-Handle-OpenCL-Well (Kali) Linux latest ... 64bit updated to extract the hashes.
  • Running Win10 mining rig to crack the hashes with hashcat. (love it).
I am trying to get the hash out of a bigger *.zip file. (80mb)(N.zip).

Ok so when i try to get the hash of it with zip2john (included in the The-Distribution-Which-Does-Not-Handle-OpenCL-Well (Kali) rel.)
i get an hash that looks very similar to the example hash for the zip file but there is a name of the file also inside the hash? WTF ??.


Code:
HASH1: N.zip:$zip2$*0*3*0*blablalenght32*blabl*blaba*ZFILE*N.zip*29f6d4b*29f6db7*50369f939152ed864f14*$/zip2$:::::N.zip

when
Code:
zip2john N.zip | cut -d ':' -f 2 > pw.hash

Code:
HASH1CUT:
$zip2$*0*3*0*blablalenght32*blabl*blaba*ZFILE*N.zip*29f6d4b*29f6db7*50369f939152ed864f14*$/zip2$
EXAMPLE HASH  FROM WIKI:
$zip2$*0*3*0*b5d2b7bf57ad5e86a55c400509c672bd*d218*0**ca3d736d03a34165cfa9*$/zip2$


When loading pw.hash to the windows hashcat it gives me this error :

Code:
Hashfile 'C:\Users\....\Desktop\Hashes\zippw' on line 1 ($zip2$...db7*50369f939152ed864f14*$/zip2$): Token encoding exception

Whats wrong here ? the hash is not like the example one ok.
So i thought i might be the zip2john version.
Installed the new version did the same command and got hashes like :

Code:
HASH2 FUNKING LONG:
N.zip:$zip2$*0*3*0*balblalenght32*8481*211c**50369f939152ed864f14*$/zip2$:::::N.zip-Neuer Ordner/.............

When loading these hashes into hashcat on win machine i get :


Code:
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 1 ($zip2$...24a3359ca27a35a5de4764007bea1a61): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 3 ($zip2$...fc3e2a9f1ccf26f54310e64cf70dcb0d): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 5 ($zip2$...c4de07d847dff890b6020760a485620b): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 7 ($zip2$...1ac08afb98912a7a1288caae1ca68062): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 9 ($zip2$...600c451454f90db8d2cac425840d5c56): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 11 ($zip2$...a388a48b6fdc8cc3ea5fef693f890616): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 13 ($zip2$...6b6b7acc0567f7aec78953cda0d13ffc): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 15 ($zip2$...a207d9d24fcf23e8aacf2fcd7e2b6160): Separator unmatched
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 17 ($zip2$...077*a20cc49cfee3712ccb7a*$/zip2$): Token length exception
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 19 ($zip2$...5f1*904b8ed3958210a40781*$/zip2$): Token length exception
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 21 ($zip2$...b53*38fd8a841533798b032d*$/zip2$): Token length exception
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 23 ($zip2$...131*c581e3031e5a3d3f28fc*$/zip2$): Token length exception
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 25 ($zip2$...b6c*5fa99ebd6c0daad11883*$/zip2$): Token length exception
Hashfile 'C:\Users\Miner\Desktop\Hashes\zippw' on line 27 ($zip2$...443*50369f939152ed864f14*$/zip2$): Token length exception

Commands i use are :
Code:
hashcat64.exe -a 0 -m 13600 C:\Users\...\Desktop\Hashes\zippw D:\Real-Passwords-7z\Top2Billion-probable-v2.txt
hashcat64.exe -a 3 -m 13600 C:\Users\....\Desktop\Hashes\zippw ?a?a?a?a?a?a?a?a?a?a?a?a -i --increment-min=1 --increment-max=12 




Please let me know, what i do wrong ?
Used different versions of zip2John...
tried them with cutting and without ....

Would be nice to get some help here...

I want to run it on the gpus .... so i need to use hashcat :-)

Running the example hash with hashcat works without any problems....


when running on JTR :
Code:
Loaded 1 password hash (ZIP, WinZip [PBKDF2-SHA1 4x SSE2])


and it looks like it works ...

Thanks

Effects of unequal RAM and VRAM in rig

$
0
0
I didn't want to hijack this thread. But reading I came up with some questions.

What could it cause when I wouldn't have 1:1 RAM and VRAM? Could it lead to something like CL_OUT_OF_HOST_MEMORY or "just" to some cracking slow down? 

And could you guess what performance loss could it be? And what attack types would be affected the most?

I'm running 8x GTX 1080Ti with 32GBs of RAM. I know I have encountered some CL_OUT_OF_MEMORY while doing HC benchmarks with workloads 3 and 4. I suppose that the RAM:VRAM ratio was the origin of the issue.

Last thing, could please point me to hash types I should use when I want to test the stability of hashcat on my rig? My aim is to be able to run any attack on any hash type without any errors or failure due to RAM or VRAM. 

Thanks.

2x GTX 1080ti + 1070 on MD5 /NTLM very very slow

$
0
0
hi folks, im getting with my 2x 1080ti + 1070 on stock very weird speeds with md5 and ntlm. -w 3 and only 1 hash is being cracked, but still very low speeds. max 20917.9 MH/s  for NTLM, 12114.5 MH/s  for MD5 per 1080ti.

System specs:
i7 8700k, 64GB DDR4, MSI Z370 Sli plus, ubuntu 18.04,

below outputs.

hashcat64.bin -m 0 tmp_hash -a3 ?a?a?a?a?a?a?a?a
hashcat (v4.2.1) starting...

* Device #1: WARNING! Kernel exec timeout is not disabled.
             This may cause "CL_OUT_OF_RESOURCES" or related errors.
             To disable the timeout, see: https://hashcat.net/q/timeoutpatch
* Device #2: WARNING! Kernel exec timeout is not disabled.
             This may cause "CL_OUT_OF_RESOURCES" or related errors.
             To disable the timeout, see: https://hashcat.net/q/timeoutpatch
* Device #3: WARNING! Kernel exec timeout is not disabled.
             This may cause "CL_OUT_OF_RESOURCES" or related errors.
             To disable the timeout, see: https://hashcat.net/q/timeoutpatch
OpenCL Platform #1: NVIDIA Corporation
======================================
* Device #1: GeForce GTX 1080 Ti, 2794/11178 MB allocatable, 28MCU
* Device #2: GeForce GTX 1080 Ti, 2794/11178 MB allocatable, 28MCU
* Device #3: GeForce GTX 1070, 2029/8119 MB allocatable, 15MCU

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates

Applicable optimizers:
* Zero-Byte
* Early-Skip
* Not-Salted
* Not-Iterated
* Single-Hash
* Single-Salt
* Brute-Force
* Raw-Hash

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

ATTENTION! Pure (unoptimized) OpenCL kernels selected.
This enables cracking passwords and salts > length 32 but for the price of drastically reduced performance.
If you want to switch to optimized OpenCL kernels, append -O to your commandline.

[s]tatus [p]ause ypass [c]heckpoint [q]uit => s

Session..........: hashcat
Status...........: Running
Hash.Type........: MD5
Hash.Target......: e778f845815adedeXXXXXXXXX
Time.Started.....: Tue Sep 25 23:10:27 2018 (11 secs)
Time.Estimated...: Fri Sep 28 13:48:30 2018 (2 days, 14 hours)
Guess.Mask.......: ?a?a?a?a?a?a?a?a [8]
Guess.Queue......: 1/1 (100.00%)
Speed.Dev.#1.....: 10829.8 MH/s (10.58ms) @ Accel:128 Loops:32 Thr:1024 Vec:1
Speed.Dev.#2.....: 12114.5 MH/s (9.51ms) @ Accel:128 Loops:32 Thr:1024 Vec:1
Speed.Dev.#3.....:  6477.9 MH/s (9.51ms) @ Accel:128 Loops:32 Thr:1024 Vec:1
Speed.Dev.#*.....: 29422.1 MH/s
Recovered........: 0/1 (0.00%) Digests, 0/1 (0.00%) Salts
Progress.........: 316867084288/6634204312890625 (0.00%)
Rejected.........: 0/316867084288 (0.00%)
Restore.Point....: 0/7737809375 (0.00%)
Candidates.#1....: RlizXzus -> ;zurc~de
Candidates.#2....: 3 #erane -> E)c!AJUS
Candidates.#3....: E(*Q-uer -> :WOf*MY1
HWMon.Dev.#1.....: Temp: 61c Fan:100% Util:100% Core:1860MHz Mem:5005MHz Bus:8
HWMon.Dev.#2.....: Temp: 62c Fan:100% Util: 99% Core:1961MHz Mem:5005MHz Bus:8
HWMon.Dev.#3.....: Temp: 50c Fan:100% Util: 98% Core:1797MHz Mem:3802MHz Bus:4


[b]hashcat64.bin -m 1000 tmp_hash -a3 ?a?a?a?a?a?a?a?a -w3


[/b][s]tatus [p]ause ypass [c]heckpoint [q]uit => s

Session..........: hashcat
Status...........: Running
Hash.Type........: NTLM
Hash.Target......: b749e584fc1aaXXXXXXXXXXXXXXXXXXXXX
Time.Started.....: Tue Sep 25 23:15:28 2018 (5 secs)
Time.Estimated...: Thu Sep 27 12:45:43 2018 (1 day, 13 hours)
Guess.Mask.......: ?a?a?a?a?a?a?a?a [8]
Guess.Queue......: 1/1 (100.00%)
Speed.Dev.#1.....: 18193.1 MH/s (50.70ms) @ Accel:128 Loops:256 Thr:1024 Vec:1
Speed.Dev.#2.....: 20917.9 MH/s (44.21ms) @ Accel:128 Loops:256 Thr:1024 Vec:1
Speed.Dev.#3.....: 10025.8 MH/s (49.56ms) @ Accel:256 Loops:128 Thr:1024 Vec:1
Speed.Dev.#*.....: 49140.0 MH/s
Recovered........: 0/1 (0.00%) Digests, 0/1 (0.00%) Salts
Progress.........: 239545090048/6634204312890625 (0.00%)
Rejected.........: 0/239545090048 (0.00%)
Restore.Point....: 0/7737809375 (0.00%)
Candidates.#1....: y*sm$GUS ->  am<yQQU
Candidates.#2....: -li~L(34 -> LynJ~dll
Candidates.#3....: .71erane -> c@#2#xer
HWMon.Dev.#1.....: Temp: 64c Fan: 35% Util:100% Core:1860MHz Mem:5005MHz Bus:8
HWMon.Dev.#2.....: Temp: 66c Fan: 36% Util:100% Core:1961MHz Mem:5005MHz Bus:8
HWMon.Dev.#3.....: Temp: 52c Fan: 32% Util:100% Core:1797MHz Mem:3802MHz Bus:4

here benchmark for ntlm:

Benchmark relevant options:
===========================
* --optimized-kernel-enable

Hashmode: 1000 - NTLM

Speed.Dev.#1.....: 60306.4 MH/s (60.43ms) @ Accel:128 Loops:1024 Thr:1024 Vec:2
Speed.Dev.#2.....: 65369.0 MH/s (55.82ms) @ Accel:128 Loops:1024 Thr:1024 Vec:2
Speed.Dev.#3.....: 32376.5 MH/s (61.48ms) @ Accel:256 Loops:512 Thr:1024 Vec:2
Speed.Dev.#*.....:   158.1 GH/s

Hashmode: 0 - MD5

Speed.Dev.#1.....: 36153.9 MH/s (51.07ms) @ Accel:128 Loops:512 Thr:1024 Vec:4
Speed.Dev.#2.....: 39065.0 MH/s (47.32ms) @ Accel:128 Loops:512 Thr:1024 Vec:4
Speed.Dev.#3.....: 19190.3 MH/s (51.83ms) @ Accel:256 Loops:256 Thr:1024 Vec:4
Speed.Dev.#*.....: 94409.2 MH/s

What could be wrong in my setting?

WPA/WPA2 batch processing

$
0
0
Hello,
I heard I can batch process hccapx files to make cracking same-name APs faster, but I got questions
Does it really work for different APs but with same name?
Should I use airolib-ng for batching, or should I use something else?
How can I batch process PMKID (.16800) files? If not, then how do I convert .16800 to .hccapx?

Hashcat start cracking problem

$
0
0
./hashcat -m 16800 hashtocrack -a 3 -w 3 '?d?d?d?d?d?d?d?d' --force
hashcat (v4.2.1-57-g58d101d4) starting...

OpenCL Platform #1: The pocl project
====================================
* Device #1: pthread-Intel(R) Celeron(R) CPU B815 @ 1.60GHz, 1024/2851 MB allocatable, 2MCU

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates

Applicable optimizers:
* Zero-Byte
* Single-Hash
* Single-Salt
* Brute-Force
* Slow-Hash-SIMD-LOOP

Minimum password length supported by kernel: 8
Maximum password length supported by kernel: 63

Watchdog: Hardware monitoring interface not found on your system.
Watchdog: Temperature abort trigger disabled.

Initializing device kernels and memory...Segmentation fault


How to fix this problem plz help need crack wifi

Bcrypt Prefix

$
0
0
Help to work out prefix for bcrypt hash to crack.

I have digest for bcrypt hash and know that it has 4 rounds, which doesn't explain me what prefix will have to come with hash.

$2a$10
$2a$13
$2y$10
$2b$10

Please anyone can explain which prefix have to be used?

A very special mask

$
0
0
Hello everybody !

So i've a very specific request.

I need a mask that do these thing:

- the password is 8 chars uppercase (ok i know that: ?u?u?u?u?u?u?u?u).
- The passwork have max two time the same letter.
- if the password contain two time the same letter, they are never next to the other.
- the password nerver have the same 2 or more letter sequency (ABCDEFAB doesn't work because AB is repeted).

If someone here can do something like that (without hundreds lines of code) then this is a genius.

Thank you everybody.
R4ms3s.

Little Help to young Hackerman

$
0
0
Good evening dear members! 
😊


Im trying to crack a wpa2 and i already have read about masks .

Lets suppose that wpa2 password contains 15 digits (i totally dont know what type of characters wpa2 composed of)

What mask do you reccomend me to use since all available dictionaries i used has failed?


Is there any common unfailable method already used? 

Thanks a lot for your time in advice!

hashcat with scrypt(scrypt)

$
0
0
Hello,

I am an idiot and lost the password for my Toast Ripple XRP wallet. 

I have the JSON backup. 

It looks like the Toast wallet follows the format (https://toastwallet.com/cryptodiagram.html)

scrypt(scrypt(password, salt 1), salt 2) = hash

I have hash, salt 1, and salt 2. Is there a way I can use an existing mode with hashcat to run this type of search?


Side question if you feel like answering: the number of passwords I need to check is 2.4 x 10ˆ13. Would I be able to complete such a search in a reasonable amount of time? 

Thank you for your help.

Need help with inputs

$
0
0
Hey,

So i've been trying to figure out how to configure hashcat to crack a SHA-256 pass with the length of 64.
I've tried a few variation of the increment and can't seem to get it to execute. I was wondering if somebody here could guide me through the correct steps to get it running.

For example: 

The pass is something like this: 9414ea9572a96336fc75eaa61f6c24441a54705d867ac26dbdbb6b2a780d854b

Utilizing numbers, and only lowercase letters for each unit. I want to set the script to run for specifically 64 char, length and to only test for a-z, 0-9. I've had a few attempts but the script just stops abruptly without any error, or will give me some sort of invalid mask error. I'm clearly not doing something right, so your help will be much appreciated.

Thank you!

No duplicated characters when cracking wpa2 password

$
0
0
Hello,
i write here because i am a little desperate ( i appologize already for my bad english)

I try to crack an hccpax file with hashcat but it seems i need to use maskprocessor because the options i want to use are not available with hashcat single.

More precisely, the password to crack is exactly 8 characters long, only uppercase and letters and shouldn't contain more that 2 same letters consecutively. Futhermore, it shouldn't contain more that 4 times the same letter in the word.

So i have seen that there were two interessings commands with mp:


-q 2
-r 4

But i don't know how to associate them with hashcat.
I am on windows 10 and i tried to use

Code:
cd C:\Users\Me\Downloads\maskprocessor-0.73\maskprocessor-0.73
mp64 -q 2 -r 4 ?u?u?u?u?u?u?u?u | cd C:\Users\Me\Downloads\hashcat-4.2.1\ && hashcat64.exe -m 2500 -a 3 C:\Users\Alexandre\Downloads\hashcat-4.2.1\handshakes\01.hccapx

But nothing appear when i enter this command.
Maybe i should use a mask file with hashcat ?
But if i understood correctly there aren't the "-q" and "-r" options with hashcat only ?! So i have to use mp but i am not even capable to enter a correct command
:/
So if anyone here would have the kindness to help me a little or even give me the correct command i would be very gratefull Big Grin
Viewing all 8061 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>