Questions
1. Crack the hash value stored in hash1.txt
. What was the password?
To crack a hash, the first step is to identify its type. For this, we use the hash-id
tool. This tool analyzes the provided hash and suggests possible hash types, which helps us choose the correct cracking method.
data:image/s3,"s3://crabby-images/33969/3396969651141eee37afa84377e561059c0a3c92" alt=""
Based on the output, the hash type was most likely identified as SHA-256. To crack the hash, we use John the Ripper with the command:
john –format=raw-sha256 –wordlist=/usr/share/wordlists/rockyou.txt hash1.txt.
data:image/s3,"s3://crabby-images/ba5a9/ba5a93dbb5ac6806ae0a3100a0ebc7d180980b66" alt=""
In this attempt, the wordlist failed to crack the hash, indicating that the hash represents a more complex password. The –rules=wordlist option applies modifications to each word in the wordlist (e.g., letter substitution, adding numbers). Using this method, the hash was cracked, and the password was discovered.
data:image/s3,"s3://crabby-images/f11fc/f11fc345fc771703facfbbd94875548044ea3674" alt=""
fluffycat12
2. What is the flag at the top of the private.pdf
file?
To crack a PDF with John, we first convert the PDF into a hash. To guess the PDF password, we need to create a custom wordlist (which is already available in the connected directory).
data:image/s3,"s3://crabby-images/1013f/1013ffaaf463749c9c306e05c009d79fe2d3ade7" alt=""
To crack the PDF password with John:
data:image/s3,"s3://crabby-images/36655/366552ac47489a622c532a973a91f52a9aa6f5ee" alt=""
To extract the content of a password-protected PDF file as plain text:
data:image/s3,"s3://crabby-images/31591/31591492138f05de37d962503fa50817d57831a4" alt=""