ZeroBox

Password Cracking and Brute Force: practice machines and key commands

Many boxes fall to a password that is weak, default or reused. Offline cracking turns a captured hash into plaintext: identify the hash type first, then choose the matching hashcat mode or John format, starting with rockyou and a rules file before heavier masks. Online attacks with Hydra or NetExec are slower and noisier, so use targeted username lists and watch for lockouts. Always try default credentials for the product you identified, and test every password you find against every service and user, because reuse is common. Build custom wordlists from site content with a tool like cewl when generic lists fail. Keep a running list of credentials in your notes. The machines below involve cracking or guessing a secret to progress.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Hashcat NTLM Hashes (Mode 1000)

High-speed GPU cracking of Windows NTLM hashes dumped from SAM or NTDS.dit.

hashcat -m 1000 ntlm.hashes /usr/share/wordlists/rockyou.txt -O

Hashcat Linux /etc/shadow Hashes (Mode 1800)

Crack SHA512crypt ($6$) passwords dumped from Linux /etc/shadow.

hashcat -m 1800 shadow.hashes /usr/share/wordlists/rockyou.txt -O

Hydra Multi-Threaded SSH Brute Force

Brute-force SSH service credentials using rockyou password list.

hydra -l {USER} -P /usr/share/wordlists/rockyou.txt {TARGET_IP} ssh -t 4

Hydra Web Login Form Brute Force

Target HTTP POST web login endpoint with username and password dictionary.

hydra -l admin -P /usr/share/wordlists/rockyou.txt {TARGET_IP} http-post-form "/login:username=^USER^&password=^PASS^:F=Invalid credentials"

JWT Secret Key HMAC-SHA256 Cracking

Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.

hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txt

Keep going

Password Cracking and Brute Force machines (24)

5 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 17 Linux, 7 Windows.

Very Easy (5)

MachinePlatformOSTags
ExplosionHTBWindowsRDP, Remote Desktop, Default Credentials
MeowHTBLinuxTelnet, Default Credentials, Recon
PennyworthHTBLinuxJenkins, Groovy, RCE, Default Credentials
SequelHTBLinuxMySQL, MariaDB, Default Credentials
GuardHTBLinuxSSH, Hash Cracking, Sudo

Easy (10)

MachinePlatformOSTags
Bounty HackerTHMLinuxFTP-Anonymous, Hydra, Tar-SUID
Agent SudoTHMLinuxUser-Agent-Spoofing, Steganography, Brute-Force, CVE-2019-14287
CorpTHMWindowsTHM, hashcat, PowerUp1.ps1
Crack the hashTHMLinuxTHM, hashcat
CyborgTHMLinuxOSCP, Borg Backup, Hash Cracking, Sudoers
GamingServerTHMLinuxTHM, nmap, hydra, gobuster
LibraryTHMLinuxTHM, nmap, gobuster, hydra
PerfectionHTBLinuxCPTS, SSTI, Ruby, ERB
ToolsRusTHMLinuxTHM, dirbuster, Hydra, Nmap
UnderpassHTBLinuxSNMP-Walk, Daloradius, FreeRADIUS, Password-Cracking

Medium (4)

MachinePlatformOSTags
Brooklyn Nine NineTHMLinuxSteganography, Hydra, SUID
FlightHTBWindowsCPTS, Active Directory, Pivoting, Responder
HackParkTHMWindowsHydra, BlogEngine, CVE-2019-6714
Net Sec ChallengeTHMLinuxTHM, Nmap, hydra

Hard (3)

MachinePlatformOSTags
ControlHTBWindowsBasic-SQL-Injection, CVE-2019-11043, File-System, HTB
Reel2HTBWindowsHTB, JEA-Bypass, Password-Cracking, Phishing
Year of the PigTHMLinuxBrute-Force, Capabilities

Insane (2)

MachinePlatformOSTags
DyplesherHTBLinuxAMQP, Cuberite, HTB, Password-Cracking
MultimasterHTBWindowsCVE-2020-1472, HTB, Password-Cracking, SQL-Injection

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox