GPU CPUは APU DSPは FPGAについて Coprocessor
GPU的驱动要求
AMD GPUs on Linux require "RadeonOpenCompute (ROCm)" Software Platform (1.6.180 or later) AMD GPU for Windows には "AMD Radeon Software Crimson Edition" (15.12 以降 )が必要です。 Intel CPU " は、 Intel Core および Intel Xeon Processors" 用OpenCL Runtimeを必要とする16.1.1 以降 Intel GPU on Linux には "OpenCL 2.0 GPU Driver Package for Linux " 2.0 以降が必要 Intel GPU for Windows " には、 Intel Iris および Intel HD GraphicsのOpenCLドライバーが必要です。"NVIDIA GPU require "NVIDIA Driver " 367.x or later
下面使常见的参数,想了解更多的参数可以hashcat--help
view-a 使用するクラッキングモードを指定します。その値は後の引数を参照します。“-a 0”は辞書攻撃、“-a 1” は組み合わせ攻撃、“-a 3”はマスク攻撃。 -m 解読するハッシュの種類を指定します。型を指定しない場合はMD 5です。 -o は、クラッキング成功後のhashおよび対応する平文パスワードの格納場所を指定し、クラッキング成功後のhashを指定したファイルに書き込むことができる --force クラッキング中の警告メッセージを無視し、単一のハッシュを実行するにはこのオプションが必要になる場合があります --show クラックされたハッシュとそのハッシュに対応するプレーンテキストを表示します。 --increment インクリメンタルクラッキングモードを有効にします。このモードでは、hashcatが指定されたパスワードの長さの範囲内でクラッキング処理を実行できるようにします。 --increment-min パスワードの最小長、直後に1つの整数に等しいだけ、incrementモードを設定して一緒に使用する --increment-max パスワードの最大長、上記# --outfile-format クラック結果の出力フォーマットidを指定します。デフォルトは3です。 --username hashファイル内の指定されたユーザー名を無視します。linuxシステムのユーザーパスワードhashを解読する際に使用される場合があります。 成功 したハッシュを削除します。 -r カスタムクラッキングルール
# | モードモードモード ===+====== 0 | Straight(フィールドブレイク) 1 | 組合せ解読#コンビネーション#(Combination) 3 | ブルートフォース(ブルートフォース) 6 | ハイブリッドワード リスト + マスク(辞書+マスク) 7 | Hybrid Mask + Wordlist(マスク+辞書クラッキング)
1 = hash[salt] 2 = プレーン 3 = hash[salt] plain 4 = hex_plain 5 = hash[salt] hex_plain 6 = plain hex_plain 7 = hash[salt] plain hex_plain 8 = crackpos 9 = ハッシュ[salt] crackpos 10 = plain crackpos 11 = hash[salt] plain ck 12 = hex_plain ck 13 = hash[salt] hex_plain ck 14 = plain hex_plain crack 15 = hash[salt] plain hex_plain crackpos
が多すぎるので、一般的なハッシュタイプの一部を投稿します。すべてのパラメータはhashcat Wikiで見ることができます。hashcat--help hash比較表
- [ Hash modes ] - # | 名前は | Category:カテゴリ ======+==================================================+====================================== 900 | MD 4は | Raw Hash 0 | MD 5は | Raw Hash 5100 | ハーフ MD 5 | Raw Hash 100 | SHA 1より | Raw Hash 1300 | SHA 2 - 22 4 | Raw Hash 1400 | SHA 2 - 25 6 | Raw Hash 10800 | SHA 2 - 3 8 4 | Raw Hash 1700 | SHA 2 - 5 1 2 | Raw Hash 17300 | SHA 3 - 22 4 | Raw Hash 17400 | SHA 3 - 25 6 | Raw Hash 17500 | SHA 3 - 3 8 4 | Raw Hash 17600 | SHA 3 - 5 1 2 | Raw Hash 10 | md5 $pass.$ salt | Raw Hash Salted and/or Iterated 20 | 5 pass | Raw Hash Salted and/or Iterated 30 | md5 utf16le $pass.$ salt | Raw Hash Salted and/or Iterated 40 | md5 $salt.utf16le $pass | Raw Hash Salted and/or Iterated 3800 | 5パス.$. salt | Raw Hash Salted and/or Iterated 3710 | 5 | Raw Hash Salted and/or Iterated 4010 | md5 $salt.md5 $salt.$ pass | Raw Hash Salted and/or Iterated 4110 | md5 $salt.md5 $pass.$ salt | Raw Hash Salted and/or Iterated 2600 | 5 | Raw Hash Salted and/or Iterated 3910 | md5 md5 $pass. md5 $salt | Raw Hash Salted and/or Iterated 4300 | md5 strtoupper md5 $pass | Raw Hash Salted and/or Iterated 4400 | md5 sha1 $pass | Raw Hash Salted and/or Iterated 110 | sha1 $pass.$ salt | Raw Hash Salted and/or Iterated 120 | sha1 $salt.$ pass | Raw Hash Salted and/or Iterated 130 | sha1 utf16le $pass.$ salt | Raw Hash Salted and/or Iterated 140 | sha1 $salt.utf16le $pass | Raw Hash Salted and/or Iterated 4500 | sha1 sha1 $pass | Raw Hash Salted and/or Iterated 4520 | sha1 $salt.sha1 $pass | Raw Hash Salted and/or Iterated 4700 | sha1 md5 $pass | Raw Hash Salted and/or Iterated 4900 | sha1 $salt.$パス.$. salt | Raw Hash Salted and/or Iterated 14400 | sha1(CX) | Raw Hash Salted and/or Iterated 1410 | sha256 $pass.$ salt | Raw Hash Salted and/or Iterated 1420 | sha256 $salt.$ pass | Raw Hash Salted and/or Iterated 1430 | sha256 utf16le $pass.$ salt | Raw Hash Salted and/or Iterated 1440 | sha256 $salt.utf16le $pass | Raw Hash Salted and/or Iterated 1710 | sha512 $pass.$ salt | Raw Hash Salted and/or Iterated 1720 | sha512 $salt.$ pass | Raw Hash Salted and/or Iterated 1730 | sha512 utf16le $pass.$ salt | Raw Hash Salted and/or Iterated 1740 | sha512 $salt.utf16le $pass | Raw Hash Salted and/or Iterated 14000 | DES (PT = $salt, key = $pass) | Raw Cipher、 Known-Plaintext attack 14100 | 3DES PT = $salt key = $pass | Raw Cipher Known-Plaintext attack 14900 | Skip32 PT = $salt key = $pass | Raw Cipher、 Known-Plaintext attack 15400 | チャチャ20 | Raw Cipher、 Known-Plaintext attack 2500 | WPA-EAPOL-K2 | ネットワーク プロトコルは 2501 | WPA-EAPOL-PMK | ネットワーク プロトコルは 16800 | WPA-PMKID-K2 | ネットワーク プロトコルは 16801 | WPA-PMKID-PMK | ネットワーク プロトコルは 7300 | IPMI 2 RAKP HMAC-SHA1 | ネットワーク プロトコルは 7500 | Kerberos 5 AS-REQ Pre-Auth etype 23 | ネットワーク プロトコルは 8300 | DNSSEC (NSEC3) | ネットワーク プロトコルは 10200 | CRAM-MD 5 | ネットワーク プロトコルは 11100 | PostgreSQL CRAM MD5 | ネットワーク プロトコルは 11200 | MySQL CRAM SHA1 | ネットワーク プロトコルは 16100 | TACACS+ | ネットワーク プロトコルは 16500 | JWT JSON Web Token | ネットワーク プロトコルは 121 | SMF (Simple Machines Forum) > v1.1 | Forums、 CMS、 E-、 Frameworks 400 | phpBB3 MD5 | Forums、 CMS、 E-、 Frameworks 2811 | MBB 1.2以上 | Forums、 CMS、 E-、 Frameworks 2811 | IPB2+ (Invision Power Board) | Forums、 CMS、 E-、 Frameworks 8400 | WBB3 Woltlab Burning Board | Forums、 CMS、 E-、 Frameworks 11 | Joomla < 2.5.1 8 | Forums、 CMS、 E-、 Frameworks 400 | Joomla >= 2.5.18 MD5 | Forums、 CMS、 E-、 Frameworks 400 | Word Press MD5 | Forums、 CMS、 E-、 Frameworks 2612 | PHPSさん | Forums、 CMS、 E-、 Frameworks 7900 | Drupal 7について | Forums、 CMS、 E-、 Frameworks 21 | osCommerce | Forums、 CMS、 E-、 Frameworks 21 | xtコマース | Forums、 CMS、 E-、 Frameworks 11000 | プレスタショップ | Forums、 CMS、 E-、 Frameworks 124 | Django -1 | Forums、 CMS、 E-、 Frameworks 10000 | Django K2-SHA256 | Forums、 CMS、 E-、 Frameworks 12 | PostgreSQL Postgre SQL | Database Serverの略  131 | MSSQL 2000 | Database Serverの略 132 | MSSQL 2005 | Database Serverの略 1731 | MSSQL 2012、 2014 | Database Serverの略  200 | My SQL 32 3 | Database Serverの略 300 | My SQL 4.1とMy SQL 5 | Database Serverの略 3100 | Oracle H Type (Oracle 7+) | Database Serverの略 112 | Oracle S Type (Oracle 11+) | Database Serverの略  12300 | Oracle TType (Oracle 12+) | Database Serverの略 8000 | Sybase ASE | Database Serverの略 15000 | FileZilla Server >= 0.9.5 5 | FTP サーバ 11500 | CRC 32 | Checksum 3000 | LMとは | オペレーティング システム 1000 | NTLM | オペレーティング システムは 500 | md5crypt MD5 Unix Cisco-IOS $1 $MD5 | オペレーティング システムは 3200 | bcrypt $2 *$、 Blowfish Unix | オペレーティング システムは 7400 | sha256crypt $5 $、 SHA256 Unix | オペレーティング システムは 1800 | sha512crypt $6 $、 SHA512 Unix | オペレーティング システムは 122 | macOS v10.4、 macOS v10.5、 macOS v10.6 | オペレーティング システムは 1722 | macOS v 10.7 | オペレーティング システムは 7100 | macOS v10.8+ K2-SHA512 | オペレーティング システムは 11600 | 7-ZIP | Archives for Archivesより 12500 | RAR 3-HP | Archives forアーカイブ 13000 | RAR 5の | Archives for Archivesより 13600 | WinZip | Archives for Archivesより 9700 | MS Office <= 2003 0/1、 MD5 + RC4 | ドキュメント 9710 | MS Office <= 2003 0/1、 MD5 + RC4、 collider #1 | Documents 9720 | MS Office <= 2003 0/1、 MD5 + RC4、 colider #2 | Documents 9800 | MS Office <= 2003 3/4、 SHA1 + RC4 | Documents 9810 | MS Office <= 2003 3、 SHA1 + RC4、 collider #1 | Documents 9820 | MS Office <= 2003 3 、 SHA1 + RC4、 collider #2 | Documents 9400 | MS Office2007 | Documents 9500 | MS Office 2010 | Documents 9600 | MS Office 2013について | Documents 10400 | PDF 1.1 ~ 1.3 Acrobat 2 - 4 | Documents 10410 | PDF 1.1 - 1.3 Acrobat 2 - 4、 collider #1 | Documents 10420 | PDF 1.1 - 1.3 Acrobat 2 - 4、 collider #2 | Documents 10500 | PDF 1.4 ~ 1.6 Acrobat 5 - 8 | Documents 10600 | PDF 1.7 レベル 3 Acrobat 9 | Documents 10700 | PDF 1.7 レベル 8 Acrobat 10 - 11 | Documents 99999 | プレインテキスト | Plaintext
一般的なマスク文字セットをリストします
l | abcdefghijklmnopqrstuvwxyz 純粋小文字
あなたは | ABCDEFGHIJKLMNOPQRSTW プレーキャップ
d) | 0 123456 7 8 9 純粋な数字Hは | 0 123456 7 8 9 abcdef 一般的な小文字サブディレクトリと数字
Hさん | 0 1234567 8 9 ABCDEF 一般的な大文字と数字
Sは | ! "#$%&'()*+,-./:; <=>?@ [\]^_`{|【 特殊文字】
a)は | ? l)��u d)はs キーボード上のすべての表示される文字
b)B | 0 - 0xff はスペースのようなパスワードにマッチするかもしれませんが、マスクの設定を理解するために、いくつかの簡単な例を示します
。d)はd)はd)はd)はd)はd)はd)はd) 8桁の不明なパスワードa)。a)。a)。a)。a)。a)です。a)です。a)は 最初の4桁は大文字、次の4桁は数値u u u u d)はd)はd)はd) 最初の4桁は数字または小文字、次の4桁は大文字または数字h)。h)。h)。h)。H.。H.。H.。Hさん 最初の3文字は不明で、中央はadmin、次の3文字は不明ですa)です。a)です。aadmin a)です。a)です。a)は 6-8ビット数パスワード --increment--increment-min 6 --increment-max 8 l)��l)��l)��l)��l)��l)��l)��Lは 6-8ビット数字+小文字のパスワード --increment-min6 --increment-max 8 h)。h)。h)。h)。h)。h)。h)。h
文字セットを設定したい場合:abcd123456!@-+,どうすればいいのか?これにはカスタム文字セットパラメータが必要で、hashcatは最大4つの文字セットを定義できます。
--custom-charset 1 [chars]は-1と等価です 。 --custom-charset 2 [chars]は-2と等価です 。 --custom-charset 3 [chars]は-3と等価です 。 --custom-charset 4 [chars]は-4と等価です 。 マスクでのEssbaseの使用1. Centera 2、3、CLARiX 4つの表現。
さらに例を挙げてみましょう。
--custom-charset 1 abcd123456!@-+。その場合、EmailXtenderを使用できます"。1".この文字セットを示す --om-charset2 l)��D.ここで。2つはEMCと等価です。Hは -1 つのd)はl)��お、お、1は数字+小文字+大文字を意味する。 -3 abcdef -4 123456 それなら3 RiX 3 3 3 4 4の4の4は、最初の4桁がabcdef、次の4桁が123456である可能性があることを示します。
PS:ここでは、マシンの構成を示して、クラックの速度を比較してみましょう
。Intel R Core TM i5-7300HQ CPU @ 2.50GHz グラフィックスGTX 1050Ti
hashcat64.exe -a 3-m 0 --force 25c3e88f81b4853f2a8faacad4c871b6 d)はd)はd)はd)はd)はd)はd)
hashcat64.exe -a 3 -m 0 - -force 7a47c622760a6d67245d7d8063f3 l)��l)��l)��l)��l)��l)��hashcat
64.exe -a 3-m 0--force 4488cec 2 aea 535179 e 085367 d 8 a 17 d 75--increment--min 1--increment-max 8 d)はd)はd)はd)はd)はd)はd)はd
hashcat 64.exe -a 3-m 0--force ab65d749cba1656ca11dfa 1 cc 2383102---increment-min 1--increment-max 8 h)。h)。h)。h)。h)。h)。h)。h
hashcat64.exe -a 3 - 1 123456abf!@+- 8 b 78 ba5089 b 1132 6 290 bc15 cf0 b 9 a 07 d 1つ目は1つ目は1つ目は1つ目は1ここでは-1と-1を参照。1は数字1で、文字l
hashcat64.exe -a 3 - 1 123456abf!@+- 9054 fa315 ce16 f7 f0955 b 4 af06 d 1 aa1 b----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- 1つ目は1つ目は1つ目は1つ目は1つ目は1つ目は1つ目は1
hashcat64.exe -a 3 - 1 d)はu l)��s d 37 fc9 ee39 d45 a 7717 e 3 e9415 f 65 d --increment-min 1---increment-max 8 1つ目は1つ目は1つ目は1つ目は1つ目は1つ目は1つ目は1 または: hashcat64.exe -a 3d 37fc9ee3945a7717e3e3e9415f65d -- increment-min 1 --increment-max 8 a)です。a)です。a)です。a)です。a)です。a)です。a)です。辞書
-a 0は辞書クラッキングモードを指定し、-oはファイルへの出力結果を指定しますhashcat 64.exe-a 0 ede 900ac 142443 6 b 55 dc 3 c 9 f 20 cb97 a 8 password.txt -o result.txt
hashcat 64.exe-a 0 hash.txt password.txt password.txt -o result.txt
hashcat 64.exe-a 1 25 f 9 e 794323 b 453885 f 5181 f 1 b 624 d0b pwd 1.txt pwd2.txt
hashcat 64.exe-a 6 9 dc 9 d 5 ed 5031367 d 42543763423 c 24 ee password.txt l)��l)��l)��l)��Mysql
hashcat64.exe-a 3-m 300--force 6 BB 4837 EB 74329105 EE4568 DDA7 DC67 ED2 CA2 AD 9 d)はd)はd)はd)はd)はd sha512 crypt $6 $SHA512 Unixはcat/etc/shadowでhashcat64.exe-a 3-m1800--force $6 $mxuA5cdy $XZRk0CvnPFqOgVopqiPEFAFK72SogKVwwwp7gWaUOb7b6tVwfCpcSUsCEk64ktLLYmzyew/xd0O0hPG/yrm2Xをクラックします。
? l)��l)��l)��lユーザー名を整理せずに、--username hashcat64.exe-a 3-m 1800--force qiyou $6 $QDq75 ki3 $jsKm7qTDHz/xBob 0 kF 1 Lp 170 Cgg 0 i 5 Tslf 3 JW/sm 9 k 9 Q916 mBTyilU 3 PoOsbRdxV 8 TAmzvdgNjrCuhfg 3 jKMY 1
l)��l)��l)��l)��l--username Windows NT-hash LM-hashクラッキングはsaminsideを使用してNT-hash LM-hashの値NT-hash
hashcat 64.exe-a 3-m 1000 209 C 6174 DA 490 CAEB422 F 3 FA 5 A 7 AE 634 l)��l)��l)��l)��Lは LM-hash hashcat64.exe-a 3-m 3000F0D412BD764FFE81AAD3B435B51404EE l)��l)��l)��l)��l mssql hashcat64.exe-a3-m132--force1008c8006c224f71f6bf0036f78d863c3c4ff53f8c3c3c48edafbl)��l)��l)��l)��l)��d)はd)はWord Pressパスワードハッシュは特定の暗号化スクリプトをクラック./wp-includes/class-phpass.phpのHashPassword関数
hashcat64.exe -a 3 -m 400 -- force PBYEYcHEj3vV1lwGBv6rpxurKOEWY/ d)はd)はd)はd)はd)はddiscuzユーザーパスワードhashが
パスワード暗号化方式md5 md5 $pass.$を解読salt
hashcat64.exe -a 3 -m 2611 --force 14 e1 b600 b1 fd579 f47433 b88 e8d85291 d)はd)はd)はd)はd)はdRAR圧縮パスワードを解読
する最初のrar2john rarファイルのハッシュ値を取得ダウンロードアドレス
rarファイルのハッシュ値を取得:RAR 2john.exe 1.RAR 結果は: RAR $RAR 5 $16 $639 e9ce8344 c680 da12 e8 bdd4346 a6 a3 $15 $a2 b056 a21 a9836 d8 d48 c2844 d171 b73 d $8 $04 a52 d2224 ad082 e
hashcat 64.exe -a 3-m 13000-- force $RAR 5 $16 $639 e9ce8344 c680 da12 e8bd4346 a6 a3 $15 $a2 b056 a21 a9836 d8 d48 c2844 d171 b73 d $8 $04 a52 d2224 ad082 e d)はd)はd)はd)はd)はd
注:
hashcat は RAR3 hp と RAR5をサポートしています。 -m引数 型 の例 hash 12500 RAR 3-hp $RAR 3 $*0* 45109 af8ab5 f297 a * adbf6 c5385 d 7 a 40373 e 8 f 77 d 7 b 89 d 317 13000 RAR5 $RAR 5 $16 $74575567518807622265582327032280 $15 $f8b4064de34ac02ecabfezipパスワードクラッキング
ZIP zipファイルのハッシュ値をzip2johnで取得するzip2john.exe 1.ZIP 結果:1.ZIP $zip2 $*0*3*0*554bb43ff71cb0cac76326f292119dfd* ff23 *5*24 b 28885 ee* d 4 fe362bb1 e 91319 ab53*$/zip2$1.ZIP-1.txt
hashcat 64.exe -a 3-m 13600 $ZIP 2 $*0*3*0* 554 bb43 ff71 cb0 cac 7632 6 f292119 dfd *ff23*5* 24 b28885 ee * d 4fe362 bb1 e91319 ab 53 *$/ZIP 2 $ --force d)はd)はd)はd)はd)はOffice
パスワードを解読
してOfficeのハッシュ値を取得する:Python office2john.py 1 1.docx 結果は:docx $Office$*2013*100000*256*16* e4 a3eb62 e 8 d 3576 f 861 f 9eded 75 e0525 * 9 eeb35 f 0849 a7800 d 48113440 b4bbbbb9c * 577 f 8 d 8 b2e1c5 f60 fed76 e 6232 7 b 38 d 28 f25230 f6 c7 dfd66588 d 9 ca8097 aabb9
hashcat 64.exe-a 3-m 9600 $Office$*2013*100000*256*16* e 4 a3eb62 e 8 d 3576 f 861 f 9eded 75 e 0525 * 9 eeb35 f 0849 a 7800 d 481 13440 b 4 bbbbb9 c * 577 f 8 d 8 b 2 e1 c 5 f 60 fed 76 e 6232 7 b 38 d 28 f 25230 f6 c 7 dfd 66588 d 9 ca8097 aabb9 ---force d)はd)はd)はd)はd)はまず
、
私たちのハンドシェイクパケットをhccapx形式に変換しますが、hashcatの最新バージョンはhccapx形式のみをサポートし、以前のhccap形式はサポートされていません。
公式オンライン変換https//hashcat.net/cap2hccapx/hashcat64.exe -a 3-m 2500 1.hccapx1391040 d)はd)はd)はd
Others
クラックされたハッシュ値については、hashcat 64.exe hash--show結果を表示
するすべてのハッシュクラッキング結果はhashcat.potfileファイルにあり
ますクラッキングに時間がかかりすぎる場合は、sキーを押してクラッキングのステータスを確認できます。pキーは一時停止し、rキーはクラッキングを続行し、qキーはクラッキングを終了します。
GPUモードを使用してクラッキングを行う場合、-Oパラメータを使用して自動的に最適化できます。
実用的なクラッキングでは、盲目的にクラッキングすると、多くの時間とリソースを消費します
。まず、一般的に使用される弱いパスワード辞書を見てください。 パスワードの組み合わせ、例えば:zhang1999、姓と生年月日の組み合わせを使用しますが、もちろん、他の組み合わせを使用することができます。 よく使われるマスクの組み合わせをmasks内の.hcmaskファイルに入れ、自動的にロードさせます。 4.それができない場合は、実行するために下位のすべての組み合わせを試すことができますが、高桁の組み合わせを解読することはお勧めしません。相手が設定したパスワードが非常に複雑な場合、最終的にパスワードは解読されませんが、多くの時間とリソースを無駄にします。HashCatパラメータ最適化
hashcatのクラッキング速度とリソースの割り当てを考慮して、いくつかのパラメータを設定することができます
。
このパラメータは1,8,40,80,160の値をサポートしており、gpu-accel 160 はGPUのパフォーマンスを最大限に引き出します。この
パラメータでサポートされる値の範囲は8-1024です(一部のアルゴリズムは1000までしかサポートしていません)。gpu-loops 1024 はGPUのパフォーマンスを最大限に引き出します。セグメントサイズ辞書キャッシュサイズ
このパラメータは、メモリキャッシュのサイズを設定することです。役割は、辞書のクラッキング速度を高速化するために辞書をメモリキャッシュに入れることです。デフォルトは32MBです。独自のメモリ条件に応じて設定することができます。もちろん、大きいほどブロックが大きくなります。--segment-size 512 は、大規模な辞書の解読速度を向上させる。預言者コミュニティからの記事転送,原文著者By七友,侵害削除