Crack the Hash

Task 1: Level 1

48bb6e862e54f2a795ffc4e541caed4d

  • Before we crack the hash we have to find its type.

  • Using hash-identifier we can identify the possible hash type.

  • Let's save the hash to a file.

  • Now we have to find the hash-mode for a MD5 hash.

  • We are now ready to crack the hash using hashcat.

  • We can also crack the hash using john.

Answer

CBFDAC6008F9CAB4083784CBD1874F76618D2A97

  • Let's identify the hash type using hash-identifier.

  • The mode for SHA-1 in hashcat is 100.

  • We can crack the hash now using the Raw-SHA1 format for john.

Answer

1C8BFE8F801D79745C4631D09FFF36C82AA37FC4CCE4FC946683D7B336B63032

  • We can crack the hash using hash-identifier.

  • Let's save it to a file.

  • The mode for SHA-256 in hashcat is 1400.

  • The format for john will be Raw-SHA256.

Answer

$2y$12$Dwt1BZj6pcyc3Dy1FWZ5ieeUznr71EeNkJkUlypTsgbX1H68wsRom

  • hash-identifier is not able to identify the type of this hash.

  • We will have to use another tool called Hash Analyzer.

  • The hash-mode for Bcrypt is 3200.

  • We know that the password is four characters long, so let's filter the rockyou.txt file.

  • Our filtered list only has passwords that are 4 characters long.

  • We can now use this filtered list to crack the hash.

Answer

279412f945939ba78ce0758d3fd83daa

  • Let's identify the type using Hash Analyzer.

  • This time let's use CrackStation to crack the hash.

Answer

Task 2: Level 2

Hash: F09EDCB1FCEFC6DFB23DC3505A882655FF77375ED8AA2D1C13F640FCCC2D0C85

  • Let's use hash-identifier to get the hash type.

  • Since we know that the mode for SHA-256 is 1400, let's just try that first.

Answer

Hash: 1DFECA0C002AE40B8619ECF94819CC1B

  • CrackStation gives us the password.

Answer

Hash: $6$aReallyHardSalt$6WKUTqzq.UQQmrm0p/T7MPpMbGNnzXPMAXi4bJMl9be.cfi3/qxIf.hsGpS41BqMhSrHVXgMpdjS6xeKZAs02. Salt: aReallyHardSalt

  • The $6$ tells us that this is a SHAcrypt512 hash the mode for which is 1800.

  • This time we have to filter for passwords that six characters long.

  • Let's run hashcat with the correct mode.

Answer

Hash: e5d8870e5bdd26602cab8dbe07a942c8669e56d6 Salt: tryhackme

  • Let's identify the hash using hash-identifier.

  • For SHA-1, the mode we will be using is 160.

Answer

Last updated

Was this helpful?