Hashcat usage method and technical sharing

There are four basic decryptionmethods for hashcat:
1. Dictionary decryption

2. Combined string decryption

3. Brute-force decryption(deprecation)-mask attack
4. Hybrid decryption
also has a rule-based decryptionmethod, and there is also a case switch, but it can be classified as rule decryption

Dictionary decryption-

a 0 -m type hashfile dictionary1 Dictionary2
It seems that gpu can also be used to accelerate

combined string decryption

If the content in the dictionary is like this
11
22
33

, then the combination is:
1111
1122
1133
2222
2233
3333

Specify the left or right characters

     -j,   -rule-left=RULE               Single  rule  applied  to  each  Word  on  the  left  dictionary    -k,   -rule-right=RULE              Single  rule  applied  to  each  Word  on  the  right  dictionary123

Give a chestnut:
Dictionary 1:

    11
    2212

Dictionary 2:

    33
    4412

commands:

    -j '$-'
    -k '!$ '12

For the words in the $proxy dictionary above, -j '$-'means adding a-, -k $to the right side of the Word'! 'Add one to the left side of the Word!
So the resulting combination is:

    11-33!
    22-33!
    11-44!
    22-44! The

official explanation given by the 1234 Mask Attack is relatively simple, that is, mask attack is better than brute-force in that it reduces the number of password tables. As for the algorithm to reduce the number of passwords, there is not much introduction (based on the hcmask file), but it just simply mentions that we can reduce the number of passwords through some conventional password forms. For example: "Kele1997", all possibilities will be enumerated when decrypting violently. etc.. But when mask attack, the program will try to capitalize only the initial letter, because most passwords rarely have capitalized in the second or third position. These rules are used to reduce the number of password candidates

. Officials say that mask attack has no disadvantages compared to brute-force, because mask attack can generate all brute-force passwords

Charset

built-in character set? l = abcdefghijklmnopqrstuvwxyz
? u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
? d = 0123456789
? h = 0123456789abcdef
? H = 0123456789ABCDEF
? s = «space»! "#$%&'()*+,-./:; <=>?@ [\]^_`{|}~
? a = ? l? u? d? s
? b  =   0  -  0xff123456789

There are charsets in the program directory that contain all kinds of weird characters. If you add them to your password, you can use these files

. hashcat has four parameters for specifying a custom character set
-custom-charset1 =CS-
custom-charset2 =CS-
custom-charset3 =CS
-custom-charset4 =CS
These four parameters can be replaced with the abbreviations-1, -2, -3 and-4. You can specify a custom character set to decrypt

. The following command sets the first custom charset (-1) to Russian language specific charsets:
-1 charsets/special/Russian/ru_ISO-8859-5-special.hcchr

Password length increment

We don't need to specify a fixed length of the password, we can use the-increment parameter

 -i,  --increment                |      | -  - increment-min                            |     Num             | Start mask incrementing at X  | -   -increment-min=4 -- increment-max                          | Num                  | Stop mask increasing at X123 Hashcat mask files -a 3 hash.txt mask_file.hcmask Load the hcmask file and use the mask in the file to decrypt   | Stop  mask  incrementing  at  X                    123

Hashcat mask files

-a 3 hash.txt mask_file.hcmask 加载hcmask文件,使用文件中的mask来解密

hashcat comes with several hcmask files, which are placed in the program directory mask/

. The  hexadecimal character string after hex-charset is 16.

The password generated by mixed decryption is a combination of a dictionary and characters generated by brute force decryption
. For example:example.dict

    password
    hello12

hashcat64 -a 6 example.dict ? d? d? d? d
? d? d? d? d represents a four-digit integer
, so the final generated password candidate sequence is:

    password0000
    password0001
    password0002
    .
    .
    .
    password99991234567

hashcat64 -a 6 ? d? d? d? d example.dict
result:

0000password
0001password
.
.
.
9999password123456

Use rules to simulate mixed decryption (Using rules to simulate Hybrid attack)

Use maskprocessor to use rules to generate the rules needed for brute force decryption, and then the generated rule file can be loaded using hashcat-r and mixed into password candidates
. For example:example.dict

hello
password12

hash -o bf.rule '$? d $? d $? d $? d

The generated rule looks like this:bf.rule

$0  $0  $0  $0
$0 $0 $0 $1$0 $0 $0 $2
$0 $0 $0 $3
$0 $0 $0 $4
.
.
.
$9  $9  $9 $9  $9123456789

Then use hashcat -a 6 example.dict -r bf.rule -m...
The final result is this:

    hello0  0  0 0  0
    password0 0 0 0
    hello0 0 0 1
    password0 0 0 1
    hello0 0 0 2
    password0 0 0 2
    .
    .
    .
    hello9 9 9 9
    password9 9 9 91234567891011

Previous: Several attack modes of hashcat
Next: Hashcat is a password explosion artifact
  • Focus on Word, Excel, PPT, PDF, RAR, ZIP, 7Z, Compressed File, Office Encrypted File Unlock Decryption
  • We provide users with high-quality file compression password recovery, PDF unlocking, and Word password recovery services.
  • Copyright © Document Password Recovery Master Online Decryption Platform