Buscador de herramientas

Password attacks

37 herramientas

-d DOMAIN Domain name (default WORKGROUP) -P PORT SMB port (default 445) -v, --version Return the OS version of the remote host --signing Check if host has SMB signing disabled, enabled, or required --admin Just report if the user is an admin --no-banner Removes the banner from the top of the output --no-color Removes the color from output --no-update Removes the "Working on it" message --timeout SCAN_TIMEOUT Set port scan socket timeout. Default is .5 seconds … (64 more lines — see the tool's home page)
  • statsprocessorsp32web

    Markov-based word generator that feeds hashcat-style attacks from per-position statistics.

    ayuda
    sp by atom, High-Performance word generator based on hashcat markov stats
    
    Usage: sp32 [options]... hcstat-file [filter-mask]
    
    * Startup:
    
      -V,  --version             Print version
      -h,  --help                Print help
    
    * Increment:
    
           --pw-min=NUM          Start incrementing at NUM
           --pw-max=NUM          Stop incrementing at NUM
    
    * Markov:
    
           --markov-disable      Emulates maskprocessor output
           --markov-classic      No per-position tables
           --threshold=NUM       Filter out chars after NUM chars added
                                 Set to 0 to disable
    
    * Misc:
    
           --combinations        Calculate number of combinations
           --hex-charset         Assume charset is given in hex
    
    * Resources:
    
      -s,  --skip=NUM            skip number of words (for restore)
      -l,  --limit=NUM           limit number of words (for distributed)
    
    * Files:
    
      -o,  --output-file=FILE    Output-file
    
    * Custom charsets:
    
      -1,  --custom-charset1=CS  User-defineable charsets
      -2,  --custom-charset2=CS  Example:
      -3,  --custom-charset3=CS  --custom-charset1=?dabcdef
      -4,  --custom-charset4=CS  sets charset ?1 to 0123456789abcdef
    
    * Built-in charsets:
    
      ?l = abcdefghijklmnopqrstuvwxyz
    … (8 more lines — see the tool's home page)
  • sucrackweb

    Multithreaded su password guesser for local Linux labs where you already have a low shell.

  • thc-pptp-bruterweb

    Brute-forces PPTP authentication in engagements where that VPN still exists on the edge.

    ayuda
    thc-pptp-bruter: option requires an argument -- 'h'
    thc-pptp-bruter [options] <remote host IP>
      -v        Verbose output / Debug output
      -W        Disable windows hack [default: enabled]
      -u <user> User [default: administrator]
      -w <file> Wordlist file [default: stdin]
      -p <n>    PPTP port [default: 1723]
      -n <n>    Number of parallel tries [default: 5]
      -l <n>    Limit to n passwords / sec [default: 100]
    
    Windows-Hack reuses the LCP connection with the same caller-id. This
    gets around MS's anti-brute forcing protection. It's enabled by default.
  • truecrackweb

    Brute-forces TrueCrypt/VeraCrypt-style volume passwords in an authorized recovery setting.

  • twofiweb

    Builds wordlists from Twitter interest terms when social OSINT is in scope for password guessing labs.

  • wordlistsweb

    Metapackage that ships common password lists including rockyou for offline cracking labs.

    ayuda
    > wordlists ~ Contains the rockyou wordlist
    
    /usr/share/wordlists
    ├── dirb -> /usr/share/dirb/wordlists
    ├── dirbuster -> /usr/share/dirbuster/wordlists
    ├── dnsmap.txt -> /usr/share/dnsmap/wordlist_TLAs.txt
    ├── fasttrack.txt -> /usr/share/set/src/fasttrack/wordlist.txt
    ├── fern-wifi -> /usr/share/fern-wifi-cracker/extras/wordlists
    ├── john.lst -> /usr/share/john/password.lst
    ├── legion -> /usr/share/legion/wordlists
    ├── metasploit -> /usr/share/metasploit-framework/data/wordlists
    ├── nmap.lst -> /usr/share/nmap/nselib/data/passwords.lst
    ├── rockyou.txt
    ├── rockyou.txt.gz
    ├── seclists -> /usr/share/seclists
    ├── sqlmap.txt -> /usr/share/sqlmap/data/txt/wordlist.txt
    ├── wfuzz -> /usr/share/wfuzz/wordlist
    └── wifite.txt -> /usr/share/dict/wordlist-probable.txt
    
    =
  • Cuando hay un propósito escrito para esta ruta, se muestra primero. Si no, ves el resumen del paquete. La ayuda se captura en vivo desde un Kali cuando está disponible.