John the Ripper: Password Cracking Tool
John the Ripper (JtR) is a free and open-source password cracking software tool. It’s designed to detect weak Unix passwords, but it supports hundreds of hash and cipher types, including network protocol authenticators and various password hash formats from operating systems, databases, and applications. JtR is primarily used for offline password cracking, meaning it works with captured password hashes rather than attempting live login attacks.
Core Concept: Working with Password Hashes
John the Ripper does not attack live login prompts. Instead, it requires password hashes as input. These hashes are typically obtained from various sources such as:
/etc/shadowfiles (Unix/Linux password hashes)- Windows SAM database dumps
- Database dumps
- Network traffic captures (e.g., NTLMv2, Kerberos)
Example: Cracking Hashes with a Wordlist
The most common method for cracking passwords with John is using a wordlist. John will try every word in the specified dictionary as a password against the provided hash(es).
sudo john --wordlist=/usr/share/wordlists/rockyou.txt <hash_file_or_single_hash>Command Breakdown:
sudo john: Invokes the John the Ripper program (often requiressudofor access to certain files or to prevent issues).--wordlist=/usr/share/wordlists/rockyou.txt: Specifies the path to a wordlist file. John will iterate through each line in this file, using it as a potential password.rockyou.txtis a well-known, large password dictionary.<hash_file_or_single_hash>:- If a file path, it should be a file containing one or more password hashes (each on a new line), often in a specific format (e.g., a
/etc/shadowentry, or just the hash string). - If a single hash string, John will attempt to crack just that hash.
- If a file path, it should be a file containing one or more password hashes (each on a new line), often in a specific format (e.g., a
Common Use Cases and Options
Cracking Hashes from a File
John can automatically identify many hash types.
# Assuming 'mypasswords.txt' contains one or more hashes
john mypasswords.txtSpecifying Hash Type
Sometimes you need to explicitly tell John the hash format, especially if it’s not standard.
# Example for NTLM hashes
john --format=NT myhashes.txtShowing Cracked Passwords
After a cracking session, you can view the passwords that were successfully recovered.
john --show mypasswords.txtIncremental (Brute-Force) Mode
If a wordlist doesn’t work, John can attempt a brute-force attack (trying all possible character combinations). This is very time-consuming.
# This will try various character combinations based on built-in rules
john --incremental mypasswords.txtDisclaimer: John the Ripper is a powerful tool for auditing password strength. It should only be used for ethical and authorized security testing. Unauthorized use of this tool for cracking passwords on systems you do not own or have explicit permission to test is illegal and unethical.