Password attacks
Ninguna herramienta coincide.
-
cewlweb
Spiders a site to build a custom wordlist from the organization's own language.
ayuda
CeWL 6.2.1 (More Fixes) Robin Wood (robin@digi.ninja) (https://digi.ninja/) Usage: cewl [OPTIONS] ... <url> OPTIONS: -h, --help: Show help. -k, --keep: Keep the downloaded file. -d <x>,--depth <x>: Depth to spider to, default 2. -m, --min_word_length: Minimum word length, default 3. -x, --max_word_length: Maximum word length, default unset. -o, --offsite: Let the spider visit other sites. --exclude: A file containing a list of paths to exclude --allowed: A regex pattern that path must match to be followed -w, --write: Write the output to the file. -u, --ua <agent>: User agent to send. -n, --no-words: Don't output the wordlist. -g <x>, --groups <x>: Return groups of words as well --lowercase: Lowercase all parsed words --with-numbers: Accept words with numbers in as well as just letters --convert-umlauts: Convert common ISO-8859-1 (Latin-1) umlauts (ä-ae, ö-oe, ü-ue, ß-ss) -a, --meta: include meta data. --meta_file file: Output file for meta data. -e, --email: Include email addresses. --email_file <file>: Output file for email addresses. --meta-temp-dir <dir>: The temporary directory used by exiftool when parsing files, default /tmp. -c, --count: Show the count for each word found. -v, --verbose: Verbose. --debug: Extra debug information. Authentication --auth_type: Digest or basic. --auth_user: Authentication username. --auth_pass: Authentication password. Proxy Support --proxy_host: Proxy host. --proxy_port: Proxy port, default 8080. --proxy_username: Username for proxy, if required. --proxy_password: Password for proxy, if required. Headers --header, -H: In format name:value - can pass multiple. <url>: The site to spider. -
chntpwweb
Offline NT password and registry editor for disks you own; resets local account secrets.
ayuda
chntpw: change password of a user in a Windows SAM file, or invoke registry editor. Should handle both 32 and 64 bit windows and all version from NT3.x to Win8.1 chntpw [OPTIONS] <samfile> [systemfile] [securityfile] [otherreghive] [...] -h This message -u <user> Username or RID (0x3e9 for example) to interactively edit -l list all users in SAM file and exit -i Interactive Menu system -e Registry editor. Now with full write support! -d Enter buffer debugger instead (hex editor), -v Be a little more verbose (for debuging) -L For scripts, write names of changed files to /tmp/changed -N No allocation mode. Only same length overwrites possible (very safe mode) -E No expand mode, do not expand hive file (safe mode) Usernames can be given as name or RID (in hex with 0x first) See readme file on how to get to the registry files, and what they are. Source/binary freely distributable under GPL v2 license. See README for details. NOTE: This program is somewhat hackish! You are on your own! -
cmospwdweb
Recovers BIOS passwords from CMOS dumps on machines you own and may reset offline.
-
crackleweb
Cracks and decrypts BLE encryption when you already captured weak pairing traffic.
-
creddump7web
Python toolkit to pull secrets and hashes from Windows credential stores and hives.
ayuda
creddump7 - Python tool to extract credentials and secrets from Windows registry hives /usr/share/creddump7 ├── cachedump.py ├── framework ├── lsadump.py ├── pwdump.py └── __pycache__ = -
crunchweb
Generates wordlists from charset and pattern rules when rockyou-style lists are the wrong shape.
ayuda
crunch version 3.6 Crunch can create a wordlist based on criteria you specify. The output from crunch can be sent to the screen, file, or to another program. Usage: crunch <min> <max> [options] where min and max are numbers Please refer to the man page for instructions and examples on how to use crunch. -
fcrackzipweb
Brute-forces zip archive passwords from wordlists against files you are allowed to open.
ayuda
fcrackzip version 1.0, a fast/free zip password cracker written by Marc Lehmann <pcg@goof.com> You can find more info on http://www.goof.com/pcg/marc/ USAGE: fcrackzip [-b|--brute-force] use brute force algorithm [-D|--dictionary] use a dictionary [-B|--benchmark] execute a small benchmark [-c|--charset characterset] use characters from charset [-h|--help] show this message [--version] show the version of this program [-V|--validate] sanity-check the algorithm [-v|--verbose] be more verbose [-p|--init-password string] use string as initial password/file [-l|--length min-max] check password with length min to max [-u|--use-unzip] use unzip to weed out wrong passwords [-m|--method num] use method number "num" (see below) [-2|--modulo r/m] only calculcate 1/m of the password file... the zipfiles to crack methods compiled in (* = default): 0: cpmask 1: zip1 *2: zip2, USE_MULT_TAB -
X11 RDP client for connecting to Windows lab desktops you are allowed to use.
ayuda
xfreerdp3 - A Free Remote Desktop Protocol Implementation See www.freerdp.com for more information Usage: xfreerdp3 [file] [options] [/v:<server>[:port]] Syntax: /flag (enables flag) /option:<value> (specifies option with value) +toggle -toggle (enables or disables toggle, where '/' is a synonym of '+') /a: <addin>[,<options>] Addin /action-script: <file-name> Action script +admin Admin (or console) session +aero Enable desktop composition /app: program:[<path>|<||alias>],cmd:<command>,file:<filename>,guid:<guid>, icon:<filename>,name:<name>,workdir:<directory>,hidef:[on|off] Remote application program /args-from: file:<file>|stdin|fd:<number>|env:<name> Read command line from a file, stdin or file descriptor. This argument can not be combined with any other. Provide one argument per line. /assistance: <password> Remote assistance password +async-channels Enable Asynchronous channels (experimental) +async-update Enable Asynchronous update /audio-mode: [[none|2]|[server|1]|[redirect|0]] Audio output mode +auth-only Enable Authenticate only /auth-pkg-list: [[none],]<!ntlm,kerberos,!u2u> Authentication package filter (comma-separated list, use '!' to disable). By default all methods are enabled. Use explicit 'none' as first argument to disable all methods, selectively enabling only the ones following. -authentication Disable Authentication (experimental) +auto-reconnect Enable Automatic reconnection /auto-reconnect-max-retries: <retries> Automatic reconnection maximum retries, 0 for unlimited [0,1000] +auto-request-control Automatically request remote assistance input control /azure: [tenantid:<id>],[use-tenantid[:[on|off]],[ad:<url>][ … (114 more lines — see the tool's home page) -
gpp-decryptweb
Decrypts legacy Group Policy Preference passwords cpassword values found in SYSVOL.
ayuda
/usr/bin/gpp-decrypt:25:in `final': wrong final block length (OpenSSL::Cipher::CipherError) from /usr/bin/gpp-decrypt:25:in `decrypt' from /usr/bin/gpp-decrypt:31:in `<main>' -
hash-identifierweb
Guesses the family of an unknown hash string so you pick the right cracker mode next.
ayuda
######################################################################### # __ __ __ ______ _____ # # /\ \/\ \ /\ \ /\__ _\ /\ _ `\ # # \ \ \_\ \ __ ____ \ \ \___ \/_/\ \/ \ \ \/\ \ # # \ \ _ \ /'__`\ / ,__\ \ \ _ `\ \ \ \ \ \ \ \ \ # # \ \ \ \ \/\ \_\ \_/\__, `\ \ \ \ \ \ \_\ \__ \ \ \_\ \ # # \ \_\ \_\ \___ \_\/\____/ \ \_\ \_\ /\_____\ \ \____/ # # \/_/\/_/\/__/\/_/\/___/ \/_/\/_/ \/_____/ \/___/ v1.2 # # By Zion3R # # www.Blackploit.com # # Root@Blackploit.com # ######################################################################### -------------------------------------------------- Not Found. -------------------------------------------------- HASH: Traceback (most recent call last): File "/usr/share/hash-identifier/hash-id.py", line 568, in <module> h = input(" HASH: ") EOFError: EOF when reading a line -
hashcatweb
GPU-friendly offline hash cracker for high-volume wordlist and mask attacks against captured hashes.
ayuda
hashcat (v7.1.2) starting in help mode Usage: hashcat [options]... hash|hashfile|hccapxfile [dictionary|mask|directory]... - [ Options ] - Options Short / Long | Type | Description | Example ================================+======+======================================================+======================= -m, --hash-type | Num | Hash-type, references below (otherwise autodetect) | -m 1000 -a, --attack-mode | Num | Attack-mode, see references below | -a 3 -V, --version | | Print version | -h, --help | | Print help. Use -hh to show all supported hash-modes | -h or -hh --quiet | | Suppress output | --hex-charset | | Assume charset is given in hex | --hex-salt | | Assume salt is given in hex | --hex-wordlist | | Assume words in wordlist are given in hex | --force | | Ignore warnings | --deprecated-check-disable | | Enable deprecated plugins | --status | | Enable automatic update of the status screen | --status-json | | Enable JSON format for status output | --status-timer | Num | Sets seconds between status screen updates to X | --status-timer=1 --stdin-timeout-abort | Num | Abort if there is no input from stdin for X seconds | --stdin-timeout-abort=300 --machine-readable | | Display the status view in a machine-readable format | --keep-guessing | | Keep guessing the hash after it has been cracked | --self-test-disable | | Disable self-test functionality on startup | --loopback | | Add new plains to induct directory | --markov-hcstat2 | File | Specify hcstat2 file to use | --markov-hcstat2=my.hcstat2 --markov-disable | | Disables markov-chains, emulates classic brute-force | --markov-classic | | Enables classic markov-chains, no per-position | --markov-inverse | | Enables inverse markov-chains, no per-position | -t, --markov-threshold | Num | Threshold X when to stop accepting new markov-chains | -t 50 --metal-compiler-runtime | Num | Abort Metal kernel build after X seconds of runtime | --metal-compiler-runtime=180 --runtime | Num | Abort session after X seconds of runtime | --runtime=10 --session | Str | Define specific session name | --session=mysession --restore | | Restore session from --session | --restore-disable | | Do not write restore file | --restore-file-path | File | Specific path to restore file | --restore-file-path=x.restore -o, --outfile | File | Define outfile for recovered hash | -o outfile.txt --outfile-format | Str | Outfile format to use, separated with commas | --outfile-format=1,3 --outfile-json | | Force JSON format in outfile format | --outfile-autohex-disable | | Disable the use of $HEX[] in output plains | --outfile-check-timer | Num | Sets seconds between outfile checks to X | --outfile-check-timer=30 --wordlist-autohex-disable | | Disable the conversion of $HEX[] from the wordlist | -p, --separator | Char | Separator char for hashlists and outfile | -p : --stdout | | Do not crack a hash, instead print candidates only | … (115 more lines — see the tool's home page) -
hashcat-utilsweb
Small companions to hashcat for preparing, combining, and analyzing password-cracking inputs.
-
hashidweb
Identifies likely hash types from a sample string using a large signature catalog.
ayuda
usage: hashid.py [-h] [-e] [-m] [-j] [-o FILE] [--version] INPUT Identify the different types of hashes used to encrypt data positional arguments: INPUT input to analyze (default: STDIN) options: -e, --extended list all possible hash algorithms including salted passwords -m, --mode show corresponding Hashcat mode in output -j, --john show corresponding JohnTheRipper format in output -o, --outfile FILE write output to file -h, --help show this help message and exit --version show program's version number and exit License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> -
johnnyweb
GUI front end for John the Ripper when you want session management around offline cracks.
-
kali-tools-gpuweb
Metapackage pulling Kali GPU-oriented cracking helpers so CUDA/OpenCL stacks are easier to install.
-
Builds high-volume mask-based candidates for hashcat-style attacks.
ayuda
High-Performance word generator with a per-position configureable charset Usage: mp32 [options]... mask * Startup: -V, --version Print version -h, --help Print help * Increment: -i, --increment=NUM:NUM Enable increment mode. 1st NUM=start, 2nd NUM=stop Example: -i 4:8 searches lengths 4-8 (inclusive) * Misc: --combinations Calculate number of combinations --hex-charset Assume charset is given in hex -q, --seq-max=NUM Maximum number of multiple sequential characters -r, --occurrence-max=NUM Maximum number of occurrence of a character * Resources: -s, --start-at=WORD Start at specific position -l, --stop-at=WORD Stop at specific position * Files: -o, --output-file=FILE Output-file * Custom charsets: -1, --custom-charset1=CS User-defineable charsets -2, --custom-charset2=CS Example: -3, --custom-charset3=CS --custom-charset1=?dabcdef -4, --custom-charset4=CS sets charset ?1 to 0123456789abcdef * Built-in charsets: ?l = abcdefghijklmnopqrstuvwxyz ?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ ?d = 0123456789 ?s = !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~ ?a = ?l?u?d?s ?b = 0x00 - 0xff -
onesixtyoneweb
Fast SNMP community guessing against devices that still answer with default or weak strings.
ayuda
onesixtyone: invalid option -- 'h' onesixtyone 0.3.3 [options] <host> <community> -c <communityfile> file with community names to try -i <inputfile> file with target hosts -o <outputfile> output log -p specify an alternate destination SNMP port -d debug mode, use twice for more information -s short mode, only print IP addresses -w n wait n milliseconds (1/1000 of a second) between sending packets (default 10) -q quiet mode, do not print log to stdout, use with -o host is either an IPv4 address or an IPv4 address and a netmask default community names are: public private Max number of hosts : 65536 Max community length: 32 Max number of communities: 16384 examples: onesixtyone 192.168.4.0/24 public onesixtyone -c dict.txt -i hosts -o my.log -w 100 -
ophcrackweb
Windows password cracking with rainbow tables; useful for old LM/NT hashes in labs.
ayuda
ophcrack 3.8.0 by Objectif Securite (http://www.objectif-securite.ch) Usage: ophcrack [OPTIONS] Cracks Windows passwords with Rainbow tables -a disable audit mode (default) -A enable audit mode -b disable bruteforce -B enable bruteforce (default) -c config_file specify the config file to use -D display (lots of!) debugging information -d dir specify tables base directory -e do not display empty passwords -f file load hashes from the specified file (pwdump or session) -g disable GUI -h display this information -i hide usernames -I show usernames (default) -l file log all output to the specified file -n num specify the number of threads to use -o file write cracking output to file in pwdump format -p num preload (0 none, 1 index, 2 index+end, 3 all default) -q quiet mode -r launch the cracking when ophcrack starts (GUI only) -s disable session auto-saving -S session_file specify the file to use to automatically save the progress of the search -u display statistics when cracking ends -t table1[,a[,b,...]][:table2[,a[,b,...]]] specify which table to use in the directory given by -d -v verbose -w dir load hashes from encrypted SAM file in directory dir -x file export data in CSV format to file Example: ophcrack -g -d /path/to/tables -t xp_free_fast,0,3:vista_free -f in.txt Launch ophcrack in command line using tables 0 and 3 in /path/to/tables/xp_free_fast and all tables in /path/to/tables/vista_free and cracks hashes from pwdump file in.txt -
ophcrack-cliweb
Command-line Windows password cracker using rainbow tables on hashes you are allowed to recover.
ayuda
ophcrack 3.8.0 by Objectif Securite (http://www.objectif-securite.ch) Usage: ophcrack [OPTIONS] Cracks Windows passwords with Rainbow tables -a disable audit mode (default) -A enable audit mode -b disable bruteforce -B enable bruteforce (default) -c config_file specify the config file to use -D display (lots of!) debugging information -d dir specify tables base directory -e do not display empty passwords -f file load hashes from the specified file (pwdump or session) -g disable GUI -h display this information -i hide usernames -I show usernames (default) -l file log all output to the specified file -n num specify the number of threads to use -o file write cracking output to file in pwdump format -p num preload (0 none, 1 index, 2 index+end, 3 all default) -q quiet mode -r launch the cracking when ophcrack starts (GUI only) -s disable session auto-saving -S session_file specify the file to use to automatically save the progress of the search -u display statistics when cracking ends -t table1[,a[,b,...]][:table2[,a[,b,...]]] specify which table to use in the directory given by -d -v verbose -w dir load hashes from encrypted SAM file in directory dir -x file export data in CSV format to file Example: ophcrack -g -d /path/to/tables -t xp_free_fast,0,3:vista_free -f in.txt Launch ophcrack in command line using tables 0 and 3 in /path/to/tables/xp_free_fast and all tables in /path/to/tables/vista_free and cracks hashes from pwdump file in.txt -
packweb
Password Analysis and Cracking Kit for studying dump structure before you burn GPU time.
-
pack2web
Updated password analysis kit for statistical looks at dumps and smarter wordlist building.
-
Patched clients that authenticate with NTLM hashes instead of cleartext passwords in Windows labs.
ayuda
Usage: curl [options...] <url> -d, --data <data> HTTP POST data -f, --fail Fail fast with no output on HTTP errors -h, --help <subject> Get help for commands -o, --output <file> Write to file instead of stdout -O, --remote-name Write output to file named as remote file -i, --show-headers Show response headers in output -s, --silent Silent mode -T, --upload-file <file> Transfer local FILE to destination -u, --user <user:password> Server user and password -A, --user-agent <name> Send User-Agent <name> to server -v, --verbose Make the operation more talkative -V, --version Show version number and quit This is not the full help; this menu is split into categories. Use "--help category" to get an overview of all categories, which are: auth, connection, curl, deprecated, dns, file, ftp, global, http, imap, ldap, output, pop3, post, proxy, scp, sftp, smtp, ssh, telnet, tftp, timeout, tls, upload, verbose. Use "--help all" to list all options Use "--help [option]" to view documentation for a given option -
pdfcrackweb
Recovers passwords on PDF files when document cracking is part of an authorized engagement.
-
polenumweb
Reads a Windows password policy over SMB so spray timing respects lockout thresholds.
ayuda
usage: polenum [-h] [--username USERNAME] [--password PASSWORD] [--domain DOMAIN] [--protocols [PROTOCOLS ...]] [enum4linux] positional arguments: enum4linux username:password@IPaddress options: -h, --help show this help message and exit --username, -u USERNAME The specified username --password, -p PASSWORD The password of the user --domain, -d DOMAIN The domain or IP --protocols [PROTOCOLS ...] ['139/SMB', '445/SMB'] -
rainbowcrackweb
Rainbow-table cracker for hashes where precomputation beats online guessing.
-
rarcrackweb
Tries passwords against RAR archives when recovery is authorized and the archive is yours to open.
-
rcracki-mtweb
Multithreaded rainbow-crack variant with hybrid and indexed table support.
-
rsmanglerweb
Mangels seed words into password candidates with common mutations.
ayuda
rsmangler v 1.5 Robin Wood (robin@digi.ninja) <https://digi.ninja> Basic usage: rsmangler --file wordlist.txt To pass the initial words in on standard in do: cat wordlist.txt | rsmangler To send the output to a file: rsmangler --file wordlist.txt --output mangled.txt All options are ON by default, these parameters turn them OFF Usage: rsmangler [OPTION] --help, -h: show help --file, -f: the input file, use - for STDIN --output, -o: the output file, use - for STDOUT --max, -x: maximum word length --min, -m: minimum word length --perms, -p: permutate all the words --double, -d: double each word --reverse, -r: reverser the word --leet, -t: l33t speak the word --full-leet, -T: all posibilities l33t --capital, -c: capitalise the word --upper, -u: uppercase the word --lower, -l: lowercase the word --swap, -s: swap the case of the word --ed, -e: add ed to the end of the word --ing, -i: add ing to the end of the word --punctuation: add common punctuation to the end of the word --years, -y: add all years from 1990 to current year to start and end --acronym, -a: create an acronym based on all the words entered in order and add to word list --common, -C: add the following words to start and end: admin, sys, pw, pwd --pna: add 01 - 09 to the end of the word --pnb: add 01 - 09 to the beginning of the word --na: add 1 - 123 to the end of the word --nb: add 1 - 123 to the beginning of the word --force: don't check output size --space: add spaces between words --allow-duplicates: allow duplicates in the output list -
samdump2web
Extracts password hashes from Windows SAM hives you already obtained offline.
ayuda
samdump2 3.0.0 by Objectif Securite (http://www.objectif-securite.ch) original author: ncuomo@studenti.unina.it Usage: samdump2 [OPTION]... SYSTEM_FILE SAM_FILE Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM -d enable debugging -h display this information -o file write output to file -
seclistsweb
Curated wordlists and payloads for discovery, fuzzing, and password attacks in authorized testing.
ayuda
> seclists ~ Collection of multiple types of security lists /usr/share/seclists ├── Discovery ├── Fuzzing ├── Miscellaneous ├── Passwords ├── Pattern-Matching ├── Payloads ├── Usernames └── Web-Shells = -
smbmapweb
Checks SMB share permissions across hosts to see what an account can list or write.
ayuda
usage: smbmap [-h] (-H HOST | --host-file FILE) [-u USERNAME] [-p PASSWORD | --prompt] [-k] [--no-pass] [--dc-ip IP or Host] [-s SHARE] [-d DOMAIN] [-P PORT] [-v] [--signing] [--admin] [--no-banner] [--no-color] [--no-update] [--timeout SCAN_TIMEOUT] [-x COMMAND] [--mode CMDMODE] [-L | -r [PATH]] [-g FILE | --csv FILE] [--dir-only] [--no-write-check] [-q] [--depth DEPTH] [--exclude SHARE [SHARE ...]] [-A PATTERN] [-F PATTERN] [--search-path PATH] [--search-timeout TIMEOUT] [--download PATH] [--upload SRC DST] [--delete PATH TO FILE] [--skip] ________ ___ ___ _______ ___ ___ __ _______ /" )|" \ /" || _ "\ |" \ /" | /""\ | __ "\ (: \___/ \ \ // |(. |_) :) \ \ // | / \ (. |__) :) \___ \ /\ \/. ||: \/ /\ \/. | /' /\ \ |: ____/ __/ \ |: \. |(| _ \ |: \. | // __' \ (| / /" \ :) |. \ /: ||: |_) :)|. \ /: | / / \ \ /|__/ \ (_______/ |___|\__/|___|(_______/ |___|\__/|___|(___/ \___)(_______) ----------------------------------------------------------------------------- SMBMap - Samba Share Enumerator v1.10.7 | Shawn Evans - ShawnDEvans@gmail.com https://github.com/ShawnDEvans/smbmap options: -h, --help show this help message and exit Main arguments: -H HOST IP or FQDN --host-file FILE File containing a list of hosts -u, --username USERNAME Username, if omitted null session assumed -p, --password PASSWORD Password or NTLM hash, format is LMHASH:NTHASH --prompt Prompt for a password -s SHARE Specify a share (default C$), ex 'C