← Back to Book Detail

48 Gaining Access – Password Cracking (48/26) -- Mastering Enterprise Networks

Browse
184%

48 Gaining Access – Password Cracking

48 Gaining Access – Password Cracking Justin La Zare This lab should familiarize students with generating password hashes and techniques for cracking them. It should also demonstrate brute force and dictionary attacks. Learning Objectives - 1. Generate password hashes - 2. Identify different hash types - 3. Perform a brute force attack using John the Ripper - 4. Perform a dictionary attack using Hashcat Prerequisites Deliverables - Screenshot of the hashes file - Screenshot of John the Ripper brute force attack - Screenshot of Hashcat finished dictionary attack - Screenshot of Hashcat showing the cracked hashes Resources - 1. Jain, Rakesh. “How to create SHA512/SHA256/MD5 password hashes on command line.” Medium. Accessed May 29, 2024. https://rakeshjain-devops.medium.com/how-to-create-sha512-sha256-md5-password-hashes-on-command-line-2223db20c08c - 2. m5kro. “Hashcat vs John the Ripper (JTR).” Medium. Accessed May 29, 2024. https://medium.com/cyberscribers-exploring-cybersecurity/hashcat-vs-john-the-ripper-jtr-f207c34c5b1c - 3. “John the Ripper user community resources.” openwall [wiki]. Accessed May 29, 2024. https://openwall.info/wiki/john - 4. “Hashcat Advanced Password Recovery.” hashcat [hashcat wiki]. Accessed May 29, 2024. https://hashcat.net/wiki/doku.php?id=hashcat. Contributors and Testers - Dante Rocca, Cybersecurity Student, ERAU-Prescott - Jacob M. Christensen, Cybersecurity Student, ERAU-Prescott Phase I – Password Hash Generation with mkpasswd Before we can crack password hashes, we are going to need password hashes. This lab will walk you through generating password hashes utilizing native Linux tools. - Turn on the Kali VM - Open the terminal and run this command to navigate to the Desktop > cd ~/Desktop - We are going to generate a couple of passwords: one that is easily susceptible to a brute force attack and two that will require a dictionary/wordlist attack - We will choose a very low-complexity password to generate a password susceptible to a brute-force attack. Lower complexity means a smaller password with a smaller character set. In this case, we will generate a hash for the password “abc123,” which is short (6 characters) and only features lowercase letters and numbers > mkpasswd -m md5 abc123 | tee -a hashes - Notice above how we use the tee command; this will output the hash to stdout (the terminal) so we can see the hash we generated, but it will also append the hash to the end of a file called “hashes” on the desktop (if that file does not exist, it will create it) - Next, we will generate two passwords susceptible to a dictionary/wordlist attack and add them to the “hashes” file > mkpasswd -m md5 Cybergenius28 | tee -a hashes > mkpasswd -m md5 t0byD0g\$ | tee -a hashes NOTE: The “\” is not part of the password. The “$” indicates to the shell that we want to access a user or environment variable. This indicates that we are not trying to access a variable called “Skywalker1” (from the first password) or 12345 (from t
← Previous Chapter Next Chapter →