JOHN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tools: Hashcat / John Rule & Mask Builder, Hash Identifier
BASIC USAGE#
john hashfile # Auto-detect hash type john --wordlist=dict.txt hash # Dictionary attack john --show hashfile # Show cracked passwords john --list=formats # List all hash formats
HASH IDENTIFICATION#
john --list=formats | grep -i "md5" john --list=formats | grep -i "sha" john --list=formats | grep -i "ntlm" # Or use hash-identifier tool hash-identifier <hash>
ATTACK MODES#
# Single crack mode (uses info from username) john --single hashfile # Wordlist mode john --wordlist=/usr/share/wordlists/rockyou.txt hashfile # Incremental mode (brute force) john --incremental hashfile # Incremental with charset john --incremental=digits hashfile john --incremental=alpha hashfile john --incremental=alnum hashfile # Rules mode (with wordlist) john --wordlist=dict.txt --rules hashfile john --wordlist=dict.txt --rules=best64 hashfile john --wordlist=dict.txt --rules=KoreLogic hashfile
FORMAT SPECIFICATION#
# Common formats john --format=raw-md5 hashfile john --format=raw-sha1 hashfile john --format=raw-sha256 hashfile john --format=raw-sha512 hashfile john --format=nt hashfile john --format=lm hashfile john --format=bcrypt hashfile john --format=md5crypt hashfile # $1$ john --format=sha256crypt hashfile # $5$ john --format=sha512crypt hashfile # $6$ john --format=descrypt hashfile
LINUX PASSWORDS#
# Unshadow passwd and shadow files unshadow /etc/passwd /etc/shadow > unshadowed.txt john unshadowed.txt # Specific format john --format=sha512crypt unshadowed.txt --wordlist=rockyou.txt
WINDOWS PASSWORDS#
# NTLM hashes john --format=nt hashfile --wordlist=rockyou.txt # LM hashes john --format=lm hashfile --wordlist=rockyou.txt # From pwdump/hashdump output john --format=nt pwdump.txt
ZIP FILES#
# Extract hash zip2john protected.zip > zip.hash # Crack john zip.hash --wordlist=rockyou.txt
RAR FILES#
# Extract hash rar2john protected.rar > rar.hash # Crack john rar.hash --wordlist=rockyou.txt
7ZIP FILES#
# Extract hash 7z2john protected.7z > 7z.hash # Crack john 7z.hash --wordlist=rockyou.txt
PDF FILES#
# Extract hash pdf2john protected.pdf > pdf.hash # Crack john pdf.hash --wordlist=rockyou.txt
OFFICE DOCUMENTS#
# Extract hash office2john document.docx > office.hash # Crack john office.hash --wordlist=rockyou.txt
SSH KEYS#
# Extract hash from private key ssh2john id_rsa > ssh.hash # Crack john ssh.hash --wordlist=rockyou.txt
KEEPASS#
# Extract hash keepass2john database.kdbx > keepass.hash # Crack john keepass.hash --wordlist=rockyou.txt
WPA/WPA2#
# Convert cap file to john format wpapcap2john capture.cap > wpa.hash # Or use aircrack-ng format with john john --format=wpapsk wpa.hash --wordlist=rockyou.txt
BITCOIN WALLET#
# Extract hash bitcoin2john wallet.dat > btc.hash # Crack john btc.hash --wordlist=rockyou.txt
RULES#
# List available rules john --list=rules # Common rule sets --rules=single --rules=wordlist --rules=extra --rules=jumbo --rules=best64 --rules=d3ad0ne --rules=KoreLogic # Custom rules in john.conf [List.Rules:MyRules] # Append numbers $[0-9] $[0-9]$[0-9] # Capitalize first c # Toggle case T0T1T2
PERFORMANCE#
# Show status john --status # Set session name john --session=mysession hashfile # Restore session john --restore=mysession # Fork processes john --fork=4 hashfile # Use OpenCL (GPU) john --format=raw-md5-opencl hashfile # Specific device john --devices=1 hashfile
OUTPUT & SESSION#
# Show cracked passwords john --show hashfile # Show cracked in format user:pass john --show --format=nt hashfile # Output to file john --pot=output.pot hashfile # Different pot file john --pot=mypasswords.pot hashfile
WORDLIST MANIPULATION#
# Sort and remove duplicates john --wordlist=dict.txt --stdout | sort -u > clean.txt # Apply rules and output john --wordlist=dict.txt --rules --stdout > mutated.txt # Generate passwords with mask john --mask='?l?l?l?l?d?d' --stdout # ?l = lowercase # ?u = uppercase # ?d = digit # ?s = symbol # ?a = all printable
MASK ATTACK#
john --mask='Pass?d?d?d?d' hashfile john --mask='?u?l?l?l?l?l?d?d' hashfile # Custom charset john --mask='?1?1?1?1' -1=[aeiou] hashfile
MARKOV MODE#
john --markov hashfile john --markov=200 hashfile # Level 200
PRACTICAL EXAMPLES#
# Crack MySQL hashes john --format=mysql-sha1 mysql.hash --wordlist=rockyou.txt # Crack PostgreSQL john --format=raw-md5 --wordlist=rockyou.txt postgres.hash # Crack MSSQL john --format=mssql --wordlist=rockyou.txt mssql.hash # Crack Kerberos TGS john --format=krb5tgs --wordlist=rockyou.txt kerberos.hash # Crack NetNTLMv2 john --format=netntlmv2 --wordlist=rockyou.txt ntlm.hash
USEFUL OPTIONS#
--min-length=8 # Minimum password length --max-length=12 # Maximum password length --encoding=utf8 # Character encoding --external=filter # External filter mode --save-memory=1 # Memory saving mode --node=1/4 # Distributed cracking --nolog # Don't log cracked passwords
WORDLISTS LOCATION#
/usr/share/wordlists/rockyou.txt /usr/share/john/password.lst /usr/share/seclists/Passwords/