> For the complete documentation index, see [llms.txt](https://paul-gleason.gitbook.io/sec-335-eth.-hacking-and-pen.-testing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://paul-gleason.gitbook.io/sec-335-eth.-hacking-and-pen.-testing/labs/lab-6.1-cracking-linux-passwords-with-jtr-and-hashcat.md).

# Lab 6.1: Cracking Linux Passwords with JtR and Hashcat

### Summary

During this lab we explored John the Ripper, Hashcat, and more understanding of the shadow file.&#x20;

### **Deliverable 1.  Provide screenshots similar to the ones above showing the last 3 entries in /etc/passwd and /etc/shadow.**

<figure><img src="https://lh6.googleusercontent.com/nK76TwBjs6o8Y1T60BCCuyISbocDid7H4kI3aH27rbccR7k3rmpQfldevI7dous6FmKDKUgB_zxTvzi0Js8lDtROXJOZuG0bS8PFGPYuRp8XuEqF5iD1FC3yqK-oM58ho_cVvKLyWiHeRb5ekORz7Ps" alt=""><figcaption></figcaption></figure>

### **Deliverable 2.  Research what hashing algorithm is being used on this server, one of the fields in /etc/shadow points to the format.  Explain this.**

$6$ - SHA-512

$rounds=1000$ - “The more rounds are performed the higher the CPU requirements are. This is a safety mechanism which might help counter brute-force attacks in the face of increasing computing power.”  <https://access.redhat.com/articles/1519843>&#x20;

$LneEppAvGXMREfOV$ - Salt

$kOzEXBjXOD0XK3YJUgd5.nfQVq/gM3BEbKbARZu/BNQNi6Uu3cie5JvOIhkJ5A6mKGUIGKpUG3gFi4KE6xXW.$ - Salt + User password

### **Deliverable 3.  Examine user Galadriel's shadow entry.**

* **What is the salt?**
  * LneEppAvGXMREfOV
* **What is the hashed salt+password?**
  * kOzEXBjXOD0XK3YJUgd5.nfQVq/gM3BEbKbARZu/BNQNi6Uu3cie5JvOIhkJ5A6mKGUIGKpUG3gFi4KE6xXW.<br>

#### **Provide a screenshot that shows each explicitly labeled.  Note, you may see a different format between password hashes.  Some explicitly indicate the number of "rounds".**

<figure><img src="https://lh5.googleusercontent.com/SoL4bHlOb2WwAR72jkMx1NYTH1ZVXmrzVv0eOjHbVpNV8QixxQ2Lj2vrr0M3N1kjvcRdO3WTGm2MZpWEwRruwarkdNahh2wtX1HbZh-WtJl-yql6F4RzqjAqJTBF1ABs0ijMtnDcNB7Wq9UR1TPYFfY" alt=""><figcaption></figcaption></figure>

1 = Algorithm

2 = Number of rounds

3 = Salt

4 = Salt + Passwd

5 = Extra information Devin said was rarely used…

### **Deliverable 4.  Figure out how to use the unshadow utility to create a file usable by John the Ripper(JtR) and then crack the unshadowed files hashes using JtR.  Provide a screenshot showing your results.** &#x20;

<https://www.cyberciti.biz/faq/unix-linux-password-cracking-john-the-ripper/>&#x20;

#### **Cracking Passwords in a Virtual Machine can be an exercise in frustration.  Generally, the performance of john and hashcat are abysmal.  The following** [**link**](https://docs.google.com/document/d/17-ERdx_iSediJ5KGIssLKTu-MXLyy0Qm1xA8I12Da2Q/edit) **describes how to leverage humpty.cyber.local to run your cracks on a decent physical workstation.**

### **Deliverable 5.  Let's see if you can reverse engineer the shadow file using python.  We will use peregrin.took's bios hash.**

The grayed out area has the plaintext password for gandalf.  Provide a screenshot similar to the one below.  Use Boromir or Galadriel's shadow entry.

<figure><img src="https://lh3.googleusercontent.com/G1wAQrMLJ6PF86OTQaYsV9AFDZp75Ix51-Ys1iUVDhkkSI6dhlecfzN52rXN5YTLRGRDdNBCGUzeDwUlK-YexJdyn1dC-_fJyrf9H8l-kixNeQ5y9FuVLYbA73BwQ_ghhjteZbYX5m0vlOTlGHCEA1E" alt=""><figcaption></figcaption></figure>

### **Deliverable 6. crack at least one of the hashes using hashcat and show the result in a screenshot similar to the one below (hit s for status).  Again, consider leveraging humpty or your own physical system for this crack.**

<figure><img src="https://lh3.googleusercontent.com/j3PLPGPFXlW6r9kp5mMyKMXuvXmViMuVO5EJrRv8eiWSMsttioS3-rHH30uR30JMlVKDk1B6VGydpObrWFA-SKW1rUUddToz2bnUC6KM7qGBXCN7YVsIR6xjLiRbYD2FRL4kkleQ3Ow5qIZMtl1zths" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/eC-IGvOlN8EedWvkogjo-s2dGRuS47IIvOoNM6ER8Sk0_MFR9d0Pgc9VUWk_8qfROstZBQkXK24GHRkHcBLZtPFZr9GfcIWIlMj_T5xrYGFcKr-SxTc_mwFij5_IUttDWc19viXlU0y-cDRHgRfCmOc" alt=""><figcaption></figcaption></figure>

### **Deliverable 7.  Start a text or csv or markdown file similar to the one below. Include your successful guesses from Week 5 as well as the cracks from this week.  We will need this data in our future adventures.  a listing or screenshot of all your acquired passwords.  This type of material is normally called "loot" in hacker parlance. Documenting uncracked hashes is also a great idea.  You may have better luck cracking them as you learn more about your target or decide to crack on a real workstation instead of a kali vm.**

<figure><img src="https://lh5.googleusercontent.com/-uDEfQxKaZQQMhpWG6xFULlNAG3SAoheyqRdCQ5Zi0ottig36X5mopeBh62dgaqid0kliBeQI2w6meWkIVcgb8TgHhFe-l3RrMn-C-LkmfIEMRwTpoFO2Be1vjaJtkZsB03h-g37knzbTaqHCRIk67o" alt=""><figcaption></figcaption></figure>

<br>
