Hashcat - Advanced Password Recovery PDF
Hashcat - Advanced Password Recovery PDF
Hashcat - Advanced Password Recovery PDF
hashcat
advanced password recovery
Navigation
hashcat
Forum
Wiki
Tools
Events
Converter
Contact
Download
Name Version Date Download Signature
hashcat binaries v5.1.0 2018.12.02 Download PGP
hashcat sources v5.1.0 2018.12.02 Download PGP
Signing key on PGP keyservers: RSA, 2048-bit. Key ID: 2048R/8A16544F. Fingerprint:
A708 3322 9D04 0B41 99CC 0052 3C17 DA8B 8A16 544F
Check out our GitHub Repository for the latest development version
Features
World's fastest password cracker
World's first and only in-kernel rule engine
Free
Open-Source (MIT License)
Multi-OS (Linux, Windows and macOS)
Multi-Platform (CPU, GPU, DSP, FPGA, etc., everything that comes with an
OpenCL runtime)
Multi-Hash (Cracking multiple hashes at the same time)
Multi-Devices (Utilizing multiple devices in same system)
Multi-Device-Types (Utilizing mixed device types in same system)
Supports password candidate brain functionality
Supports distributed cracking networks (using overlay)
Supports interactive pause / resume
Supports sessions
Supports restore
Supports reading password candidates from file and stdin
Supports hex-salt and hex-charset
Supports automatic performance tuning
Supports automatic keyspace ordering markov-chains
Built-in benchmarking system
Integrated thermal watchdog
200+ Hash-types implemented with performance in mind
... and much more
Screenshot
https://hashcat.net/hashcat/ 2/11
12/29/2019 hashcat - advanced password recovery
Algorithms
https://hashcat.net/hashcat/ 3/11
12/29/2019 hashcat - advanced password recovery
MD4
MD5
Half MD5
SHA1
SHA2-224
SHA2-256
SHA2-384
SHA2-512
SHA3-224
SHA3-256
SHA3-384
SHA3-512
Keccak-224
Keccak-256
Keccak-384
Keccak-512
BLAKE2b-512
SipHash
RIPEMD-160
Whirlpool
GOST R 34.11-94
GOST R 34.11-2012 (Streebog) 256-bit
GOST R 34.11-2012 (Streebog) 512-bit
md5($pass.$salt)
md5($salt.$pass)
md5(utf16le($pass).$salt)
md5($salt.utf16le($pass))
md5($salt.$pass.$salt)
md5($salt.md5($pass))
md5($salt.md5($salt.$pass))
md5($salt.md5($pass.$salt))
md5(md5($pass))
md5(md5($pass).md5($salt))
md5(strtoupper(md5($pass)))
md5(sha1($pass))
sha1($pass.$salt)
sha1($salt.$pass)
sha1(utf16le($pass).$salt)
sha1($salt.utf16le($pass))
sha1(sha1($pass))
sha1($salt.sha1($pass))
sha1(md5($pass))
https://hashcat.net/hashcat/ 4/11
12/29/2019 hashcat - advanced password recovery
sha1($salt.$pass.$salt)
sha1(CX)
sha256($pass.$salt)
sha256($salt.$pass)
sha256(utf16le($pass).$salt)
sha256($salt.utf16le($pass))
sha512($pass.$salt)
sha512($salt.$pass)
sha512(utf16le($pass).$salt)
sha512($salt.utf16le($pass))
HMAC-MD5 (key = $pass)
HMAC-MD5 (key = $salt)
HMAC-SHA1 (key = $pass)
HMAC-SHA1 (key = $salt)
HMAC-SHA256 (key = $pass)
HMAC-SHA256 (key = $salt)
HMAC-SHA512 (key = $pass)
HMAC-SHA512 (key = $salt)
DES (PT = $salt, key = $pass)
3DES (PT = $salt, key = $pass)
Skip32 (PT = $salt, key = $pass)
ChaCha20
phpass
scrypt
PBKDF2-HMAC-MD5
PBKDF2-HMAC-SHA1
PBKDF2-HMAC-SHA256
PBKDF2-HMAC-SHA512
Skype
WPA-EAPOL-PBKDF2
WPA-EAPOL-PMK
WPA-PMKID-PBKDF2
WPA-PMKID-PMK
iSCSI CHAP authentication, MD5(CHAP)
IKE-PSK MD5
IKE-PSK SHA1
NetNTLMv1
NetNTLMv1+ESS
NetNTLMv2
IPMI2 RAKP HMAC-SHA1
Kerberos 5 AS-REQ Pre-Auth etype 23
DNSSEC (NSEC3)
https://hashcat.net/hashcat/ 5/11
12/29/2019 hashcat - advanced password recovery
CRAM-MD5
PostgreSQL CRAM (MD5)
MySQL CRAM (SHA1)
SIP digest authentication (MD5)
Kerberos 5 TGS-REP etype 23
TACACS+
JWT (JSON Web Token)
SMF (Simple Machines Forum) > v1.1
phpBB3 (MD5)
vBulletin < v3.8.5
vBulletin >= v3.8.5
MyBB 1.2+
IPB2+ (Invision Power Board)
WBB3 (Woltlab Burning Board)
Joomla < 2.5.18
Joomla >= 2.5.18 (MD5)
WordPress (MD5)
PHPS
Drupal7
osCommerce
xt:Commerce
PrestaShop
Django (SHA-1)
Django (PBKDF2-SHA256)
Tripcode
MediaWiki B type
OpenCart
Redmine
PunBB
Atlassian (PBKDF2-HMAC-SHA1)
PostgreSQL
MSSQL (2000)
MSSQL (2005)
MSSQL (2012, 2014)
MySQL323
MySQL4.1/MySQL5
Oracle H: Type (Oracle 7+)
Oracle S: Type (Oracle 11+)
Oracle T: Type (Oracle 12+)
Sybase ASE
Episerver 6.x < .NET 4
Episerver 6.x >= .NET 4
https://hashcat.net/hashcat/ 6/11
12/29/2019 hashcat - advanced password recovery
Citrix NetScaler
RACF
GRUB 2
Radmin2
ArubaOS
SAP CODVN B (BCODE)
SAP CODVN F/G (PASSCODE)
SAP CODVN H (PWDSALTEDHASH) iSSHA-1
Lotus Notes/Domino 5
Lotus Notes/Domino 6
Lotus Notes/Domino 8
PeopleSoft
PeopleSoft PS_TOKEN
7-Zip
RAR3-hp
RAR5
AxCrypt
AxCrypt in-memory SHA1
WinZip
iTunes backup < 10.0
iTunes backup >= 10.0
TrueCrypt
Android FDE <= 4.3
Android FDE (Samsung DEK)
eCryptfs
VeraCrypt
LUKS
FileVault 2
MS Office <= 2003
MS Office 2007
MS Office 2010
MS Office 2013
PDF 1.1 - 1.3 (Acrobat 2 - 4)
PDF 1.4 - 1.6 (Acrobat 5 - 8)
PDF 1.7 Level 3 (Acrobat 9)
PDF 1.7 Level 8 (Acrobat 10 - 11)
Apple Secure Notes
Password Safe v2
Password Safe v3
LastPass + LastPass sniffed
1Password, agilekeychain
1Password, cloudkeychain
https://hashcat.net/hashcat/ 8/11
12/29/2019 hashcat - advanced password recovery
Bitcoin/Litecoin wallet.dat
Blockchain, My Wallet
Blockchain, My Wallet, V2
Electrum Wallet (Salt-Type 1-3)
KeePass 1 (AES/Twofish) and KeePass 2 (AES)
JKS Java Key Store Private Keys (SHA1)
Ethereum Wallet, PBKDF2-HMAC-SHA256
Ethereum Wallet, SCRYPT
Ethereum Pre-Sale Wallet, PBKDF2-HMAC-SHA256
Ansible Vault
TOTP (HMAC-SHA1)
Plaintext
Attack-Modes
Straight *
Combination
Brute-force
Hybrid dict + mask
Hybrid mask + dict
* accept Rules
Help
FAQ
Videos
Forum
GitHub
Twitter
If you still think you need help by a real human come to #hashcat on freenode IRC.
https://hashcat.net/hashcat/ 10/11
12/29/2019 hashcat - advanced password recovery
https://hashcat.net/hashcat/ 11/11