โ† All cheat sheets

JOHN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tools: Hashcat / John Rule & Mask Builder, Hash Identifier

BASIC USAGE#

john hashfile                    # Auto-detect hash type
john --wordlist=dict.txt hash    # Dictionary attack
john --show hashfile             # Show cracked passwords
john --list=formats              # List all hash formats

HASH IDENTIFICATION#

john --list=formats | grep -i "md5"
john --list=formats | grep -i "sha"
john --list=formats | grep -i "ntlm"

# Or use hash-identifier tool
hash-identifier <hash>

ATTACK MODES#

# Single crack mode (uses info from username)
john --single hashfile

# Wordlist mode
john --wordlist=/usr/share/wordlists/rockyou.txt hashfile

# Incremental mode (brute force)
john --incremental hashfile

# Incremental with charset
john --incremental=digits hashfile
john --incremental=alpha hashfile
john --incremental=alnum hashfile

# Rules mode (with wordlist)
john --wordlist=dict.txt --rules hashfile
john --wordlist=dict.txt --rules=best64 hashfile
john --wordlist=dict.txt --rules=KoreLogic hashfile

FORMAT SPECIFICATION#

# Common formats
john --format=raw-md5 hashfile
john --format=raw-sha1 hashfile
john --format=raw-sha256 hashfile
john --format=raw-sha512 hashfile
john --format=nt hashfile
john --format=lm hashfile
john --format=bcrypt hashfile
john --format=md5crypt hashfile       # $1$
john --format=sha256crypt hashfile    # $5$
john --format=sha512crypt hashfile    # $6$
john --format=descrypt hashfile

LINUX PASSWORDS#

# Unshadow passwd and shadow files
unshadow /etc/passwd /etc/shadow > unshadowed.txt
john unshadowed.txt

# Specific format
john --format=sha512crypt unshadowed.txt --wordlist=rockyou.txt

WINDOWS PASSWORDS#

# NTLM hashes
john --format=nt hashfile --wordlist=rockyou.txt

# LM hashes
john --format=lm hashfile --wordlist=rockyou.txt

# From pwdump/hashdump output
john --format=nt pwdump.txt

ZIP FILES#

# Extract hash
zip2john protected.zip > zip.hash

# Crack
john zip.hash --wordlist=rockyou.txt

RAR FILES#

# Extract hash
rar2john protected.rar > rar.hash

# Crack
john rar.hash --wordlist=rockyou.txt

7ZIP FILES#

# Extract hash
7z2john protected.7z > 7z.hash

# Crack
john 7z.hash --wordlist=rockyou.txt

PDF FILES#

# Extract hash
pdf2john protected.pdf > pdf.hash

# Crack
john pdf.hash --wordlist=rockyou.txt

OFFICE DOCUMENTS#

# Extract hash
office2john document.docx > office.hash

# Crack
john office.hash --wordlist=rockyou.txt

SSH KEYS#

# Extract hash from private key
ssh2john id_rsa > ssh.hash

# Crack
john ssh.hash --wordlist=rockyou.txt

KEEPASS#

# Extract hash
keepass2john database.kdbx > keepass.hash

# Crack
john keepass.hash --wordlist=rockyou.txt

WPA/WPA2#

# Convert cap file to john format
wpapcap2john capture.cap > wpa.hash

# Or use aircrack-ng format with john
john --format=wpapsk wpa.hash --wordlist=rockyou.txt

BITCOIN WALLET#

# Extract hash
bitcoin2john wallet.dat > btc.hash

# Crack
john btc.hash --wordlist=rockyou.txt

RULES#

# List available rules
john --list=rules

# Common rule sets
--rules=single
--rules=wordlist
--rules=extra
--rules=jumbo
--rules=best64
--rules=d3ad0ne
--rules=KoreLogic

# Custom rules in john.conf
[List.Rules:MyRules]
# Append numbers
$[0-9]
$[0-9]$[0-9]
# Capitalize first
c
# Toggle case
T0T1T2

PERFORMANCE#

# Show status
john --status

# Set session name
john --session=mysession hashfile

# Restore session
john --restore=mysession

# Fork processes
john --fork=4 hashfile

# Use OpenCL (GPU)
john --format=raw-md5-opencl hashfile

# Specific device
john --devices=1 hashfile

OUTPUT & SESSION#

# Show cracked passwords
john --show hashfile

# Show cracked in format user:pass
john --show --format=nt hashfile

# Output to file
john --pot=output.pot hashfile

# Different pot file
john --pot=mypasswords.pot hashfile

WORDLIST MANIPULATION#

# Sort and remove duplicates
john --wordlist=dict.txt --stdout | sort -u > clean.txt

# Apply rules and output
john --wordlist=dict.txt --rules --stdout > mutated.txt

# Generate passwords with mask
john --mask='?l?l?l?l?d?d' --stdout
# ?l = lowercase
# ?u = uppercase
# ?d = digit
# ?s = symbol
# ?a = all printable

MASK ATTACK#

john --mask='Pass?d?d?d?d' hashfile
john --mask='?u?l?l?l?l?l?d?d' hashfile

# Custom charset
john --mask='?1?1?1?1' -1=[aeiou] hashfile

MARKOV MODE#

john --markov hashfile
john --markov=200 hashfile    # Level 200

PRACTICAL EXAMPLES#

# Crack MySQL hashes
john --format=mysql-sha1 mysql.hash --wordlist=rockyou.txt

# Crack PostgreSQL
john --format=raw-md5 --wordlist=rockyou.txt postgres.hash

# Crack MSSQL
john --format=mssql --wordlist=rockyou.txt mssql.hash

# Crack Kerberos TGS
john --format=krb5tgs --wordlist=rockyou.txt kerberos.hash

# Crack NetNTLMv2
john --format=netntlmv2 --wordlist=rockyou.txt ntlm.hash

USEFUL OPTIONS#

--min-length=8              # Minimum password length
--max-length=12             # Maximum password length
--encoding=utf8             # Character encoding
--external=filter           # External filter mode
--save-memory=1             # Memory saving mode
--node=1/4                  # Distributed cracking
--nolog                     # Don't log cracked passwords

WORDLISTS LOCATION#

/usr/share/wordlists/rockyou.txt
/usr/share/john/password.lst
/usr/share/seclists/Passwords/