Incomplete Lab - Using Password Tools

Objectives

In this lab, you will complete the following objectives:

  • Part 1: Investigate Password Attacks
  • Part 2: Crack Hashes with Hashcat Dictionary Attacks

Background / Scenario

Passwords are vulnerable to attack. Passwords are usually stored as encrypted hashes. An attacker can capture the hashes sent over the network using sniffing tools or can gain access to the files containing password hashes on vulnerable systems. When the attacker has the hashes, they can then apply dictionary, rainbow table, and brute force attacks against them offline to crack the hash to recover the plaintext passwords. There are many password attack tools included with Kali Linux. This lab will look at Hashcat.

Required Resources

  • Customized Kali VM
  • Internet access

Instructions

Part 1: Investigate Password Attacks

Step 1: Log into Kali Linux and verify the environment.

  1. Log into Kali using kali as the username and password.
  2. Select Applications > 05 – Password Attacks.
In the Kali Password Attacks menu, which four subcategories of password attack tools are available?
Answer Area
Offline Attacks, Online Attacks, Passing the Hash Attacks, Password Profiling & Wordlists

Step 2: Examine the available password attack tools.

  1. Click each attack subcategory and review the available attack tools.
  2. Hover the cursor over each tool. Note that some tools have a popup text box containing a brief description of the tool. You can also search for the tools in the Kali Tools page to learn more about them and what they do.
Which tool is a Microsoft password cracker that uses rainbow tables? Which subcategory contains this tool?
Answer Area
Ophcrack, Offline Attacks

Part 2: Crack Hashes with Hashcat Dictionary Attacks

Step 1: Create a file that contains MD5 hashes to be cracked.

First, some MD5 hashes of passwords are needed. In an actual exploit, an attacker will have already compromised a vulnerable system to obtain a password file containing stored password hashes to be cracked offline. In this step you simulate this by creating a password file that contains the hashes you will crack in an upcoming step.

  1. In a terminal window, create five target hashes by entering the following commands at the prompt:
  2. echo -n 'Password' | md5sum | awk '{ print $1 }' > my_pw_hashes.txt
    echo -n 'Password123' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
    echo -n 'Letmein!' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
    echo -n 'ilovedogs' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt
    echo -n '1234abcd' | md5sum | awk '{ print $1 }' >> my_pw_hashes.txt

    Note that the passwords vary in complexity.

    The hashes generated are written to the my_pw_hashes.txt file.

  3. Next, check the password hashes that you just created by entering the cat command.
  4. The output should look similar to that below:

    ┌──(kali㉿Kali)-[~]
    └─$ cat my_pw_hashes.txt
    dc647eb65e6711e155375218212b3964
    42f749ade7f9e195bf475f37a44cafcb
    e85a3b267e94f3721117fc7ac54fbeba
    33830b8b7fd414b12c208c4de5055464
    ef73781effc5774100f87fe2f437a435

Step 2: Start Hashcat in Kali.

  1. Open a new Kali console and enter the command: man hashcat.
  2. This opens the Hashcat manual.

  3. Review the options available in the first man page.
What is specified with the -m and -a options?
Answer Area
The option -m defines the hashtype and -a defines the attack mode.
  1. Scroll through the man page output to find the values that can be supplied to each of these options.
  2. You will use these options soon in upcoming steps.

Using the hashcat man pages, which hash type and attack mode would you use to crack the password hashes in the my_pw_hashes.txt file? Explain.
Answer Area
Because the hashes were created using md5sum, the option for hash types (-m) should be 0. The attack mode 0 (straight or dictionary) can be used in this instance.

Step 3: View available wordlists.

Kali comes with several wordlists built in. Hashcat needs to use a wordlist to crack the hashes.

  1. To view the built-in wordlists, enter the command: ls -lh /usr/share/wordlists/.
  2. ┌──(kali㉿Kali)-[~]
    └─$ ls -lh /usr/share/wordlists/

    This lists the wordlists that are distributed with Kali. We will use the rockyou.txt word list. The rockyou.txt wordlist is a password dictionary that contains more than 14 million passwords.

What needs to be done to the rockyou.txt.gz file before the wordlist text file can be used?
Answer Area
The rockyou wordlist is in a zipped file (indicated by the .gz file extension). You will need to extract the text file from the compressed archive.
  1. Change the directory to /usr/share/wordlists by entering the command:
  2. ┌──(kali㉿Kali)-[~]
    └─$ cd /usr/share/wordlists
  3. Extract the rockyou.txt.gz file using the gzip command:
  4. ┌──(kali㉿Kali)-[/usr/share/wordlists]
    └─$ sudo gzip -d rockyou.txt.gz
  5. List the contents of the directory as was done previously using the ls command. Verify that the rockyou.txt file is now unzipped.
  6. ┌──(kali㉿Kali)-[/usr/share/wordlists]
    └─$ ls
  7. Use the more command, followed by the file name, to view the contents of the file to see some of the passwords that hashcat will use to crack your hashes.
  8. ┌──(kali㉿Kali)-[/usr/share/wordlists]
    └─$ more rockyou.txt

    Wordlists for cracking hashes or brute forcing logins are often collected from password dumps that publicly disclose stolen user account information. Scroll through the output to get a sense of the file contents.

What seems to be a popular type of password? How could this trend be useful to a penetration tester?
Answer Area
There seem to be a lot of first names in the list. A penetration tester could use OSINT tools to learn the names of family members of employees of the company. These names could be used to attempt logins and crack hashes.
  1. Press q or Ctrl-z to exit the file contents.
  2. Return to the home directory.
  3. ┌──(kali㉿Kali)-[/usr/share/wordlists]
    └─$ cd /home/kali

Step 4: Crack hashes with Hashcat.

  1. To crack the hashes contained in the my_pw_hashes.txt file use the following command:
  2. ┌──(kali㉿Kali)-[~]
    └─$ sudo hashcat -m 0 -a 0 -o cracked.txt my_pw_hashes.txt /usr/share/wordlists/rockyou.txt

    This command outputs the cracked passwords in the new cracked.txt file.

  3. To view the contents of the cracked.txt file and the plaintext password enter the command:
  4. ┌──(kali㉿Kali)-[~]
    └─$ sudo cat cracked.txt
How many passwords were cracked?
Answer Area
Answers may vary but Hashcat should quickly crack all five.

Reflection Questions

1. Why is complexity and length so important with creating passwords?
Answer Area
Answers may vary but as the lab illustrates, short simple password hashes are cracked almost immediately using dictionaries. Even fairly complex passwords can be cracked in a matter of hours.
2. In addition to complexity and length, what other measures can be taken to protect passwords?
Answer Area
Answers may vary but changing passwords periodically, securing servers that house user account and password files, securing wired and wireless networks so that attackers cannot capture password hashes in transit.

© 2023 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public