#hashcat

2025-06-20

Watch out complex passwords, there's a new combinator tool in town.

Vavaldi just released Targinator, a feature-rich wordlist combinator that combines a wordlist with target hints in all possible positions, plus supports applying hashcat-style rules to either or both wordlists being combined.

forum.hashpwn.net/post/652

#hashcracking #combinator #hashcat #infosec #vavaldi #flagg #cyclone #hashpwn

Vavaldi just released Targinator, a feature-rich wordlist combinator that combines a wordlist with target hints in all possible positions, plus supports applying separate hashcat-style rules to either or both wordlists being combined.

Following my Security Fest talk yesterday I've released Hashcatalyst, a wrapper that helps automate non-distributed workflows by chaining multiple attacks with no downtime.

github.com/stealthsploit/Hashc

#hashcat

2025-06-03

Well, this cracking attack is going to take 5.5 days on 2x 4090s.

#PasswordCracking #hashcat

Nicolas Cage as Ben in "Leaving Las Vegas." He's wearing a blue collared shirt, a suitcoat, and sunglasses. His body is facing the camera, but he is looking fully stage left. He's at a pawn shop, and has just been offered $500 for a 1993 Rolex Daytona. (In 1995, the year the film is set, it would probably have gone for a low five figures.) After a pause,  and with a smile of bemused abandon and ironic glee, he says ... "I'll do it".
2025-05-20

🐈‍⬛ Hashcat – A Practical Guide to Password Auditing

Hashcat is a powerful GPU-accelerated password recovery tool used by security professionals to test the strength of passwords in authorized environments.

🧠 What Hashcat is used for:
• Auditing password hashes (e.g., from Windows, Linux, web apps)
• Testing password policies and complexity
• Identifying weak or reused credentials in simulated lab setups

🔐 Key Features:
• Supports a wide variety of hash types (MD5, SHA1, NTLM, bcrypt, etc.)
• Multiple attack modes: dictionary, brute-force, mask, hybrid, rule-based
• Highly customizable and efficient with GPU acceleration
• Works well for red teamers and defenders validating password hygiene

🎯 When to use it:
• During penetration tests (with permission)
• In password policy assessments
• For internal security audits and training exercises

Disclaimer: This guide is for educational and ethical use only. Only audit password hashes on systems you own or have explicit authorization to test.

#Hashcat #CyberSecurity #PasswordAuditing #EthicalHacking #InfoSec #EducationOnly #RedTeamTools #CredentialSecurity #GPUCracking #SecurityAssessment

Top #hashcat tip:

Want per-position duplication in your rules to leverage your GPU?

It's not available in a single op, but you can emulate it by incrementally duplicating the first N chars, and then incrementally deleting the position and frequency of the redundant characters

#password #passwordcracking #pentest #redteam

2025-03-19

New version of #hashgen published.

Changelog:
v1.1.0; 2025-03-19
added modes: #base58, #argon2id, #bcrypt w/custom cost factor

forum.hashpwn.net/post/89

#hashgenerator #hashcracking #hashcat #hashpwn #cyclone #golang

2025-03-13

So I want to make a script that generates a whole slew of generic NTLMv2 hashes for me to try to crack with Hashcat.

I'm doing NTLMv2 because it's actually relavent to my job right now and seems to be the only one I can't find a python script for.

Any recs for how I can do this?

#cryptography #hashcat #kali #cybersecurity

2025-03-08

Installing the official Nvidia CUDA-toolkit on linux distros can be a pain. Here's a script that automates this so you can get back to cracking hashes.

forum.hashpwn.net/post/451

#nvidia #cuda #cudatoolkit #hashpwn #hashcracking #cyclone #hashcat

2025-03-04

After seeing yescrypt hashes appear in CMIYC a while back, I started developing a yescrypt cracker in pure Go. Since then, yescrypt has become the default /etc/shadow hash for many popular linux distros such as Debian, Ubuntu, RHEL, Fedora, and Arch (to name a few), but hash cracking support for this algo has been limited to JtR -- until now.

Here's a sneak peek of the yescrypt_cracker POC:

forum.hashpwn.net/post/446

#yescrypt #hashcracking #cyclone #hashpwn #hashcat #cmiyc #jtr #johntheripper #golang

2025-02-27

Good breakdown from Elcomsoft on 5090 relevance to password cracking.

tl;dr better in theory, not yet in practice (perf/$). Not yet sure if driver or hashcat improvements could eventually take better advantage of new hardware features, though.

blog.elcomsoft.com/2025/02/nvi

#hashcat

2025-02-18

Did you know that Gitea uses pbkdf2 hashes, but they have to be converted for hashcat to crack them?

Hashcat's own unix-ninja has written a tool for that!

unix-ninja.com/p/cracking_gite

#hashcat

2025-02-17

Great coverage by Jan Doskočil of NSEC3 hash enumeration, and cracking with hashcat. Also good info about the limits of making that harder (some resolvers cap the work factor they will resolve!)

infosec.exchange/@jpmens@masto

Via @jpmens

#DNS #NSEC3 #hashcat

2025-02-12

#sydbox 3.32.0 is released! We now officially support #GPU access for #ROCm and #nVIDIA! See the release mail here: is.gd/kN1rUt and here is a profile auto-generated by #pandora for #hashcat accessing an #nVIDIA #GPU using #cuda libraries: dpaste.com/6DQ97T2DM #exherbo #linux #security

2025-02-12

Łamanie haseł szybsze o 35%. Wyniki najnowszej karty NVIDIA RTX 5090.

Właśnie pojawił się benchmark pokazujący szybkość najnowszego flagowca od NVIDII – RTX 5090 FE. Całość oczywiście w kontekście flagowego ;) narzędzia do odzyskiwania/łamania haseł – hashcata. Przykładowe porównania z RTX 4090: Zapewne jeszcze czekają nas aktualizacje sterowników, co wpłynie na szybkość działania hashcata. Czy te szybkości wpływają na obecne rekomendacje...

#WBiegu #5090 #Awareness #Hashcat #Hasła #Nvidia

sekurak.pl/lamanie-hasel-szybs

2025-02-04

Updated source code of phantom_extractor has been released which now supports hashcat modes 30010, 26650 and 26651.

forum.hashpwn.net/post/75

#phantom #wallet #crypto #hashpwn #cyclone #hashcracking #recovery #hashcat

Aaron Toponce ⚛️:debian:atoponce@fosstodon.org
2025-02-03

Do we have any updated #password cracking benchmarks with #Hashcat on the new NVIDIA RTX 5000-series GPUs?

#passwords

Ping: @tychotithonus

2025-02-03

1236 emails envoyés à autant d’utilisateurisses dont j’ai pu casser le mot de passe lors d’un audit.
Si tout se passe bien, demain j’aurais de la lecture.

#hashcat #JohnTheRipper #motdepasse #RSSI

2025-01-24

🚀 New Release: crackmon v0.2.0

Details: Hashcat wrapper for bypassing current session if crack rate falls below threshold.

forum.hashpwn.net/post/79

#crackmon #hashcat #hashpwn #hashcracking #cyclone #golang

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst