There are four basic decryptionmethods for hashcat:
1. Dictionary decryption
2. Combined string decryption
3. Brute-force decryption(deprecation)-mask attack
4. Hybrid decryption
also has a rule-based decryptionmethod, and there is also a case switch, but it can be classified as rule decryption
a 0 -m type hashfile dictionary1 Dictionary2
It seems that gpu can also be used to accelerate
If the content in the dictionary is like this
11
22
33
, then the combination is:
1111
1122
1133
2222
2233
3333
-j, -rule-left=RULE Single rule applied to each Word on the left dictionary -k, -rule-right=RULE Single rule applied to each Word on the right dictionary123
Give a chestnut:
Dictionary 1:
11 2212
Dictionary 2:
33 4412
commands:
-j '$-' -k '!$ '12
For the words in the $proxy dictionary above, -j '$-'means adding a-, -k $to the right side of the Word'! 'Add one to the left side of the Word!
So the resulting combination is:
11-33! 22-33! 11-44! 22-44! The
official explanation given by the 1234 Mask Attack is relatively simple, that is, mask attack is better than brute-force in that it reduces the number of password tables. As for the algorithm to reduce the number of passwords, there is not much introduction (based on the hcmask file), but it just simply mentions that we can reduce the number of passwords through some conventional password forms. For example: "Kele1997", all possibilities will be enumerated when decrypting violently. etc.. But when mask attack, the program will try to capitalize only the initial letter, because most passwords rarely have capitalized in the second or third position. These rules are used to reduce the number of password candidates
. Officials say that mask attack has no disadvantages compared to brute-force, because mask attack can generate all brute-force passwords
built-in character set? l = abcdefghijklmnopqrstuvwxyz
? u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
? d = 0123456789
? h = 0123456789abcdef
? H = 0123456789ABCDEF
? s = «space»! "#$%&'()*+,-./:; <=>?@ [\]^_`{|}~
? a = ? l? u? d? s
? b = 0 - 0xff123456789There are charsets in the program directory that contain all kinds of weird characters. If you add them to your password, you can use these files
. hashcat has four parameters for specifying a custom character set
-custom-charset1 =CS-
custom-charset2 =CS-
custom-charset3 =CS
-custom-charset4 =CS
These four parameters can be replaced with the abbreviations-1, -2, -3 and-4. You can specify a custom character set to decrypt
. The following command sets the first custom charset (-1) to Russian language specific charsets:
-1 charsets/special/Russian/ru_ISO-8859-5-special.hcchr
We don't need to specify a fixed length of the password, we can use the-increment parameter
-i, --increment | | - - increment-min | Num | Start mask incrementing at X | - -increment-min=4 -- increment-max | Num | Stop mask increasing at X123 Hashcat mask files -a 3 hash.txt mask_file.hcmask Load the hcmask file and use the mask in the file to decrypt | Stop mask incrementing at X 123
-a 3 hash.txt mask_file.hcmask 加载hcmask文件,使用文件中的mask来解密
hashcat comes with several hcmask files, which are placed in the program directory mask/
. The hexadecimal character string after hex-charset is 16.
The password generated by mixed decryption is a combination of a dictionary and characters generated by brute force decryption
. For example:example.dict
password hello12
hashcat64 -a 6 example.dict ? d? d? d? d
? d? d? d? d represents a four-digit integer
, so the final generated password candidate sequence is:
password0000 password0001 password0002 . . . password99991234567
hashcat64 -a 6 ? d? d? d? d example.dict
result:
0000password 0001password . . . 9999password123456
Use maskprocessor to use rules to generate the rules needed for brute force decryption, and then the generated rule file can be loaded using hashcat-r and mixed into password candidates
. For example:example.dict
hello password12
hash -o bf.rule '$? d $? d $? d $? d
The generated rule looks like this:bf.rule
$0 $0 $0 $0 $0 $0 $0 $1$0 $0 $0 $2 $0 $0 $0 $3 $0 $0 $0 $4 . . . $9 $9 $9 $9 $9123456789
Then use hashcat -a 6 example.dict -r bf.rule -m...
The final result is this:
hello0 0 0 0 0 password0 0 0 0 hello0 0 0 1 password0 0 0 1 hello0 0 0 2 password0 0 0 2 . . . hello9 9 9 9 password9 9 9 91234567891011