Password Cracking and Brute Force: practice machines and key commands
Many boxes fall to a password that is weak, default or reused. Offline cracking turns a captured hash into plaintext: identify the hash type first, then choose the matching hashcat mode or John format, starting with rockyou and a rules file before heavier masks. Online attacks with Hydra or NetExec are slower and noisier, so use targeted username lists and watch for lockouts. Always try default credentials for the product you identified, and test every password you find against every service and user, because reuse is common. Build custom wordlists from site content with a tool like cewl when generic lists fail. Keep a running list of credentials in your notes. The machines below involve cracking or guessing a secret to progress.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Hashcat NTLM Hashes (Mode 1000)
High-speed GPU cracking of Windows NTLM hashes dumped from SAM or NTDS.dit.
hashcat -m 1000 ntlm.hashes /usr/share/wordlists/rockyou.txt -OHashcat Linux /etc/shadow Hashes (Mode 1800)
Crack SHA512crypt ($6$) passwords dumped from Linux /etc/shadow.
hashcat -m 1800 shadow.hashes /usr/share/wordlists/rockyou.txt -OHydra Multi-Threaded SSH Brute Force
Brute-force SSH service credentials using rockyou password list.
hydra -l {USER} -P /usr/share/wordlists/rockyou.txt {TARGET_IP} ssh -t 4Hydra Web Login Form Brute Force
Target HTTP POST web login endpoint with username and password dictionary.
hydra -l admin -P /usr/share/wordlists/rockyou.txt {TARGET_IP} http-post-form "/login:username=^USER^&password=^PASS^:F=Invalid credentials"JWT Secret Key HMAC-SHA256 Cracking
Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.
hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txt
Keep going
- Methodology: Phase 04: Foothold Execution & Initial Access
- Cheatsheet: Exploitation & Payloads
Password Cracking and Brute Force machines (24)
5 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 17 Linux, 7 Windows.
Very Easy (5)
| Machine | Platform | OS |
|---|---|---|
| Explosion | HTB | Windows |
| Meow | HTB | Linux |
| Pennyworth | HTB | Linux |
| Sequel | HTB | Linux |
| Guard | HTB | Linux |
Easy (10)
| Machine | Platform | OS |
|---|---|---|
| Bounty Hacker | THM | Linux |
| Agent Sudo | THM | Linux |
| Corp | THM | Windows |
| Crack the hash | THM | Linux |
| Cyborg | THM | Linux |
| GamingServer | THM | Linux |
| Library | THM | Linux |
| Perfection | HTB | Linux |
| ToolsRus | THM | Linux |
| Underpass | HTB | Linux |
Medium (4)
| Machine | Platform | OS |
|---|---|---|
| Brooklyn Nine Nine | THM | Linux |
| Flight | HTB | Windows |
| HackPark | THM | Windows |
| Net Sec Challenge | THM | Linux |
Hard (3)
| Machine | Platform | OS |
|---|---|---|
| Control | HTB | Windows |
| Reel2 | HTB | Windows |
| Year of the Pig | THM | Linux |
Insane (2)
| Machine | Platform | OS |
|---|---|---|
| Dyplesher | HTB | Linux |
| Multimaster | HTB | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox