HASHCAT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tools: Hashcat / John Rule & Mask Builder, Hash Identifier
BASIC SYNTAX#
hashcat -m <mode> -a <attack> <hashfile> <wordlist/mask> hashcat -m 0 -a 0 hash.txt wordlist.txt
COMMON OPTIONS#
-m <mode> Hash type (see modes below) -a <attack> Attack mode (0-7) -o <file> Output file for cracked hashes -r <file> Rules file -w <level> Workload profile (1-4) --show Show already cracked hashes --left Show uncracked hashes --status Enable status screen --force Ignore warnings -O Optimized kernels (faster, length limit) --potfile-path Custom potfile path --session Session name for restore --restore Restore session -j <rule> Single rule for left wordlist -k <rule> Single rule for right wordlist
ATTACK MODES (-a)#
0 = Dictionary attack (straight) 1 = Combination attack 3 = Brute-force/Mask attack 6 = Dictionary + Mask 7 = Mask + Dictionary 9 = Association attack
COMMON HASH MODES (-m)#
# Unix/Linux 500 md5crypt ($1$) 1800 sha512crypt ($6$) 7400 sha256crypt ($5$) 3200 bcrypt ($2*$) 1500 descrypt 22 Juniper NetScreen/SSG # Windows 0 MD5 100 SHA1 1000 NTLM 3000 LM 5600 NetNTLMv2 5500 NetNTLMv1 1100 Domain Cached Credentials (DCC) 2100 Domain Cached Credentials 2 (DCC2) # Web Applications 0 MD5 100 SHA1 1400 SHA256 1700 SHA512 10 md5($pass.$salt) 20 md5($salt.$pass) 3200 bcrypt 400 phpass (WordPress, Drupal, etc.) 2611 vBulletin < v3.8.5 2711 vBulletin >= v3.8.5 121 SMF > v1.1 11 Joomla < 2.5.18 400 Joomla >= 2.5.18 # Database 0 MySQL323 300 MySQL4.1/MySQL5 1731 MSSQL (2012, 2014) 112 Oracle S: Type (Oracle 11+) 3100 Oracle H: Type (Oracle 7-10) 12300 Oracle T: Type (Oracle 12+) 50 HMAC-MD5 # Network 2500 WPA/WPA2 22000 WPA-PBKDF2-PMKID+EAPOL 16800 WPA-PMKID-PBKDF2 5500 NetNTLMv1 5600 NetNTLMv2 7300 IPMI2 RAKP 8300 DNSSEC (NSEC3) # Kerberos 13100 Kerberos 5 TGS-REP (etype 23) 18200 Kerberos 5 AS-REP (etype 23) 19600 Kerberos 5 TGS-REP (etype 17) 19700 Kerberos 5 TGS-REP (etype 18) # Documents/Archives 9400 MS Office 2007 9500 MS Office 2010 9600 MS Office 2013 11300 Bitcoin wallet 12500 RAR3-hp 13000 RAR5 11600 7-Zip 13600 WinZip 16200 Apple Secure Notes 18300 Apple File System (APFS) # Cloud 21800 Electrum Wallet 21600 Web2py pbkdf2-sha512 22500 MultiBit Classic 22700 MultiBit HD 22911 RSA/DSA/EC/OpenSSH Private Keys
MASK ATTACK (-a 3)#
# Charset placeholders ?l = abcdefghijklmnopqrstuvwxyz ?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ ?d = 0123456789 ?s = special characters (!@#$%^&*...) ?a = ?l?u?d?s (all) ?b = 0x00-0xff # Examples hashcat -m 0 -a 3 hash.txt ?l?l?l?l?l?l # 6 lowercase hashcat -m 0 -a 3 hash.txt ?u?l?l?l?l?l?d?d # Ullllldd hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d # 6 digits hashcat -m 0 -a 3 hash.txt password?d?d?d # password + 3 digits hashcat -m 0 -a 3 hash.txt ?a?a?a?a?a?a?a?a # 8 any chars # Custom charset hashcat -m 0 -a 3 hash.txt -1 ?l?d ?1?1?1?1?1 # lowercase + digits hashcat -m 0 -a 3 hash.txt -1 abc -2 123 ?1?1?2?2 # custom sets # Increment mode hashcat -m 0 -a 3 hash.txt ?a?a?a?a?a?a --increment --increment-min=4
DICTIONARY ATTACK (-a 0)#
hashcat -m 0 -a 0 hash.txt wordlist.txt hashcat -m 0 -a 0 hash.txt wordlist.txt -r rules/best64.rule hashcat -m 0 -a 0 hash.txt wordlist1.txt wordlist2.txt
COMBINATION ATTACK (-a 1)#
hashcat -m 0 -a 1 hash.txt wordlist1.txt wordlist2.txt
HYBRID ATTACKS (-a 6, -a 7)#
# Dictionary + Mask hashcat -m 0 -a 6 hash.txt wordlist.txt ?d?d?d?d # Mask + Dictionary hashcat -m 0 -a 7 hash.txt ?d?d?d?d wordlist.txt
RULES#
# Built-in rules (in rules/ folder) best64.rule rockyou-30000.rule d3ad0ne.rule dive.rule generated.rule generated2.rule Incisive-leetspeak.rule InsidePro-HashManager.rule InsidePro-PasswordsPro.rule leetspeak.rule oscommerce.rule T0XlC.rule toggles1.rule to toggles5.rule # Common rule functions : Do nothing l Lowercase all u Uppercase all c Capitalize first, lower rest C Lowercase first, upper rest t Toggle case all $X Append character X ^X Prepend character X d Duplicate word r Reverse word [ Delete first character ] Delete last character sXY Replace X with Y # Example usage hashcat -m 0 -a 0 hash.txt wordlist.txt -r rules/best64.rule hashcat -m 0 -a 0 hash.txt wordlist.txt -r rule1.rule -r rule2.rule
WORKLOAD PROFILES (-w)#
1 = Low (desktop usage during crack) 2 = Default 3 = High 4 = Nightmare (may freeze system)
PRACTICAL EXAMPLES#
# MD5 dictionary attack hashcat -m 0 -a 0 md5.txt /usr/share/wordlists/rockyou.txt # NTLM with rules hashcat -m 1000 -a 0 ntlm.txt rockyou.txt -r rules/best64.rule # WPA2 cracking hashcat -m 22000 capture.hc22000 rockyou.txt # SHA256 brute force 8 chars hashcat -m 1400 -a 3 sha256.txt ?a?a?a?a?a?a?a?a # Kerberos TGS cracking hashcat -m 13100 -a 0 kerberos.txt wordlist.txt # bcrypt slow but possible hashcat -m 3200 -a 0 bcrypt.txt wordlist.txt -w 3 # NetNTLMv2 hashcat -m 5600 -a 0 netntlmv2.txt rockyou.txt # Show cracked passwords hashcat -m 0 hash.txt --show # Restore session hashcat --session=mysession -m 0 -a 0 hash.txt wordlist.txt hashcat --restore --session=mysession
PERFORMANCE TIPS#
# Use optimized kernels (faster but limited length) hashcat -O ... # Adjust workload hashcat -w 3 ... # Use GPU-specific tuning hashcat --force --opencl-device-types 1,2 # Check benchmark hashcat -b -m 0 # Monitor temperature hashcat --hwmon-temp-abort=90
OUTPUT#
# Save to file hashcat -m 0 -a 0 hash.txt wordlist.txt -o cracked.txt # Output format hashcat -m 0 -a 0 hash.txt wordlist.txt -o cracked.txt --outfile-format=2 # 1 = hash[:salt] # 2 = plain # 3 = hash[:salt]:plain # 4 = hex_plain # 5 = hash[:salt]:hex_plain
HASH EXTRACTION#
# From /etc/shadow cat /etc/shadow | grep -v '!' | grep -v '*' > hashes.txt # From Windows (Mimikatz output) # From SAM database # From NTDS.dit (secretsdump.py) # Identify hash type hashid hash hash-identifier hashcat --example-hashes | grep -A2 "MODE:"
TROUBLESHOOTING#
# If GPU not detected hashcat -I # Show devices hashcat --force # Force operation hashcat --opencl-device-types 1,2 # If running out of memory hashcat -n 1 # Reduce threads hashcat -O # Use optimized kernels # Session management hashcat --session=name # Name session hashcat --restore # Resume session hashcat -s 1000000 # Skip first N words hashcat -l 1000000 # Process only N words