Objectives
In this lab, you will complete the following objectives:
- Part 1: Investigate Password Attacks
- Part 2: Crack Hashes with Hashcat Dictionary Attacks
Background / Scenario
Passwords are vulnerable to attack. Passwords are usually stored as encrypted hashes. An attacker can capture the hashes sent over the network using sniffing tools or can gain access to the files containing password hashes on vulnerable systems. When the attacker has the hashes, they can then apply dictionary, rainbow table, and brute force attacks against them offline to crack the hash to recover the plaintext passwords. There are many password attack tools included with Kali Linux. This lab will look at Hashcat.
Required Resources
- Customized Kali VM
- Internet access
Instructions
Part 1: Investigate Password Attacks
Step 1: Log into Kali Linux and verify the environment.
- Log into Kali using kali as the username and password.
- Select Applications > 05 – Password Attacks.
Step 2: Examine the available password attack tools.
- Click each attack subcategory and review the available attack tools.
- Hover the cursor over each tool. Note that some tools have a popup text box containing a brief description of the tool. You can also search for the tools in the Kali Tools page to learn more about them and what they do.
Part 2: Crack Hashes with Hashcat Dictionary Attacks
Step 1: Create a file that contains MD5 hashes to be cracked.
First, some MD5 hashes of passwords are needed. In an actual exploit, an attacker will have already compromised a vulnerable system to obtain a password file containing stored password hashes to be cracked offline. In this step you simulate this by creating a password file that contains the hashes you will crack in an upcoming step.
- In a terminal window, create five target hashes by entering the following commands at the prompt:
- Next, check the password hashes that you just created by entering the cat command.
echo -n 'Password' | md5sum | awk '{ print $1 }' > my_pw_hashes.txt
echo -n 'Password123' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
echo -n 'Letmein!' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
echo -n 'ilovedogs' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
echo -n '1234abcd' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
Note that the passwords vary in complexity.
The hashes generated are written to the my_pw_hashes.txt file.
The output should look similar to that below:
┌──(kali㉿Kali)-[~] └─$ cat my_pw_hashes.txt dc647eb65e6711e155375218212b3964 42f749ade7f9e195bf475f37a44cafcb e85a3b267e94f3721117fc7ac54fbeba 33830b8b7fd414b12c208c4de5055464 ef73781effc5774100f87fe2f437a435
Step 2: Start Hashcat in Kali.
- Open a new Kali console and enter the command: man hashcat.
- Review the options available in the first man page.
This opens the Hashcat manual.
- Scroll through the man page output to find the values that can be supplied to each of these options.
You will use these options soon in upcoming steps.
Step 3: View available wordlists.
Kali comes with several wordlists built in. Hashcat needs to use a wordlist to crack the hashes.
- To view the built-in wordlists, enter the command: ls -lh /usr/share/wordlists/.
┌──(kali㉿Kali)-[~] └─$ ls -lh /usr/share/wordlists/
This lists the wordlists that are distributed with Kali. We will use the rockyou.txt word list. The rockyou.txt wordlist is a password dictionary that contains more than 14 million passwords.
- Change the directory to /usr/share/wordlists by entering the command:
- Extract the rockyou.txt.gz file using the gzip command:
- List the contents of the directory as was done previously using the ls command. Verify that the rockyou.txt file is now unzipped.
- Use the more command, followed by the file name, to view the contents of the file to see some of the passwords that hashcat will use to crack your hashes.
┌──(kali㉿Kali)-[~] └─$ cd /usr/share/wordlists
┌──(kali㉿Kali)-[/usr/share/wordlists] └─$ sudo gzip -d rockyou.txt.gz
┌──(kali㉿Kali)-[/usr/share/wordlists] └─$ ls
┌──(kali㉿Kali)-[/usr/share/wordlists] └─$ more rockyou.txt
Wordlists for cracking hashes or brute forcing logins are often collected from password dumps that publicly disclose stolen user account information. Scroll through the output to get a sense of the file contents.
- Press q or Ctrl-z to exit the file contents.
- Return to the home directory.
┌──(kali㉿Kali)-[/usr/share/wordlists] └─$ cd /home/kali
Step 4: Crack hashes with Hashcat.
- To crack the hashes contained in the my_pw_hashes.txt file use the following command:
- To view the contents of the cracked.txt file and the plaintext password enter the command:
┌──(kali㉿Kali)-[~] └─$ sudo hashcat -m 0 -a 0 -o cracked.txt my_pw_hashes.txt /usr/share/wordlists/rockyou.txt
This command outputs the cracked passwords in the new cracked.txt file.
┌──(kali㉿Kali)-[~] └─$ sudo cat cracked.txt