Cracking Passwords Using John the Ripper
stealthsecurity.io
stealthsecurity.io
https://nordpass.com/most-common-passwords-list/
Which is why there are Identity and Access Management (IAM) and Privileged Account Management (PAM) solutions that help protect against a users own laziness.
That means that a rainbow table that covers the most common WPA2 SSID names could offer an instant solution, and narrow the search space if no solution is found.
Honestly if I hear someone in infosec start talking about rainbow tables in 2022, that's a good indicator that they have not cracked passwords in a long time, or they are just regurgitating what they learned to pass some basic security cert. Hashcat on a modern GPU is blazingly fast, and barring some really niche edge case, your best bet is just going to involve throwing more GPUs at the problem.
On a lark, I tried to crack my own WPA key for my local network. Captured the handshake, downloaded some wordlists, started it. I have an older CPU and graphics card, i7 4930k + GTX 1060.
Some regular CPU based method, I ran the numbers and figured it would take a bit over a week. Ran it for a day, and then decided to see if something better was available.
Read about Hashcat, gave it a go, and it finished in 90 minutes. At first, I thought I made a mistake and it crapped out, but nope! It cracked it. It was done. 90 minutes on modest hardware. Imagine if you invested some real money in it with a modern system!
If it's brute force that's astounding.
Is your password that bad or did it have some really good mangling going on.
There are 100,000 alphanumeric (including caps) 8-character passwords.
There's no indication from the post that there's any more value to this article than simply reading the docs about a well known tool.
When I was a teenager, sometimes around 1996 or 1997, I watched the movie "Hackers" for the first time and my immature mind was immediately drawn to the idea of using computers to sneak into places you weren't supposed to. (The pretty graphics helped too.) I went online and I found an early version of John The Ripper and thought "yes, this is exactly what I want!" It would be a few years before I even learned what Unix and /etc/passwd were, but it felt so cool to have a real hacking tool on a floppy disk.
I downloaded the passwd file and took it home to crack a few passwords, intending to take over accounts that were unused.
Jack the Ripper beeped loudly every time a match was found. I had it running for hours, with the occasional beep, but suddenly the PC started beeping like crazy for a good minute. Turns out that the default password was no password at all, you'd set it up on the first login.
It had found a big bunch of accounts created and never used, so me and my friends had struck gold.
Even when we were inevitably caught it wasn't a big deal: Some "don't be naughty boys" over a few beers.
Simpler times.
Cracking passwords based on their hash has been a known attack for a long time, here is a web page from 2007 that talks about rainbow table attacks.
I ran something like: getent passwd | johntheripper and it found roughly 40 passwords in 60 seconds, including tenured profs and primary investigators.
I also downloaded a torrent of rainbowtables from some schm00 folks (when it was available) and found other passwords.
PS: JTR is a product of the w00w00 group.
Never quite got the hang of using John the ripper.