Hacking Complex Passwords with Rules & Munging

Hacking Complex Passwords with Rules & Munging

John Hammond

1 год назад

93,068 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

MR. JMXHD
MR. JMXHD - 22.07.2023 00:19

Man you're awesome.

Ответить
Z
Z - 19.07.2023 03:52

@JohnHammond
FYI:
DO NOT USE THE COLABCAT IF YOU WANT TO USE GOOGLE COLAB NOTEBOOKS FOR REGULAR USE!
YOU WILL GET SUSPENDED for violating their terms and conditions. Wish i knew this before trying to run the notebooks.

Ответить
Treptunes
Treptunes - 15.06.2023 21:06

@JohnHammond Google Collab was instantly locked after installing colabcat because of misusuing their service. I am now trying to solve this with google. :/ I could not even buy resources anymore after that.

Ответить
Janim Mikey
Janim Mikey - 23.05.2023 07:28

super

Ответить
jamesOS
jamesOS - 20.05.2023 06:50

Got stopped by Google trying to use collabcat... Something about "potential abuse". Oh well!

Ответить
Paul
Paul - 20.05.2023 02:12

This is awesome! Please do rainbow tables next 🙂

Ответить
Franz
Franz - 19.05.2023 13:26

M U N G

Ответить
t3l3machus
t3l3machus - 16.05.2023 11:29

"Psudohash" can also be added to this mix of awesome tools. It can generate millions of keyword-based mutations in seconds, based on (customizable) leet character substitutions, char-case variations and literally all of the unique word mutations these two methods evaluate to, when combined. It can also append common padding values before or after each word mutation (frequently used to make passwords longer / more complex, e.g. "!@#", "!!!" and so on) as well as range of year values in various patterns (and more).

Ответить
Bhagya Lakshmi
Bhagya Lakshmi - 15.05.2023 16:39

Mor explaining this video hash cat comment skills tools files open

Ответить
Black
Black - 14.05.2023 20:33

dies of cringe

Ответить
Torhe DAC
Torhe DAC - 13.05.2023 23:01

Hey calm down, you are speaking way too fast! Using online services to store password is a madness

Ответить
Klint Krossa
Klint Krossa - 13.05.2023 11:21

Try 2to3 to fix python2.

Ответить
atsekbatman
atsekbatman - 12.05.2023 23:11

Cool video, thx!

Ответить
Michael Ngirazi
Michael Ngirazi - 11.05.2023 16:06

So you look and sound like Seth Rogen 😮😮

Ответить
NightWa1ker
NightWa1ker - 11.05.2023 00:15

How about password masking attacks? You able to showcase those techniques?

Ответить
Rick Hornsby
Rick Hornsby - 10.05.2023 19:09

A bit meta, but related - after hearing about Passbolt from you and looking into it my problem with it is not the concept, but rather what seems like deceptive - at minimum misleading - marketing on their website. There’s no desktop app, but they have images meant to look like screenshots of a desktop app running on MacOS. Second, these MacOS screenshots hint at MacOS “native” - but Safari is conspicuously absent from the supported browsers.

It’s disappointing that a desktop app and Safari support are missing. Disappointment, however, turns to suspicion when presented with mockups masquerading as a real product. If I feel like I’m being deceived, none of the outstanding features or benefits matter.

Ответить
#!DE7CON**L.U.Z.$.E.¢
#!DE7CON**L.U.Z.$.E.¢ - 10.05.2023 16:22

Hey plz make video on Krack attack or Router firmware backdooring😊

Ответить
Tech Account
Tech Account - 10.05.2023 13:50

You are not safe if you're not using a password manager, some 2FA will also go a long way! cool content John!

Ответить
Tuin
Tuin - 10.05.2023 12:10

Take a video about this , The world is now ruled by one community of people, the world Satanic elite, you can also call them the committee to meet the Antichrist and prevent the 2nd coming of Jesus, Trump called them the deep state, at the moment it consists of about 10,000 people, the main ones there are Rockefellers, Rothschilds, Windsors, Baruchs, they, their ancestors, descendants and other people who enter there have the mark of Lucifer, which, if they bring the antichrist and do not allow the 2nd coming, they will receive eternal life after the x hour, and the rest of humanity, for all the time that they have lived, they won't get anything, so all people should know about the existence of a world government (Jesus who was a The Prophet of God, not God.God will send Jesus as a reward to humanity, if humanity deserves it, for this it is necessary to fight Lucifer and his elite)

Ответить
Pratik Dahal
Pratik Dahal - 09.05.2023 17:15

Great video john! But my english is a bit bad i didnt understand what "Munging" meant that you have in your title so i decided to google it and the first link that popped was of the urban dictionary and now im traumatized for my whole life!

Ответить
Flo K.
Flo K. - 09.05.2023 14:23

I thought colabcat is dead, thanks to some detecting mech. of google and a use restriction that forbids password cracking

Ответить
Richard Meyer
Richard Meyer - 09.05.2023 13:49

Thanks, John. Most illuminating.

Ответить
محمد القدسي
محمد القدسي - 09.05.2023 12:38

I hope that you will make a video by hacking the Mikrotik server, the latest update

Ответить
Omi
Omi - 09.05.2023 11:13

Google will ban if you is use hashcat. I been banned already

Ответить
Peter Loader
Peter Loader - 09.05.2023 10:58

it would be good to educate your viewers about the benefits of password length in defeating brute forcing attempts at password cracking like this. would you have attempted this video demo on a password hash for a password that was between 15 and 20 characters and only used 3 simple unrelated lowercase dictionary words? That would be a great educational video to watch John. I enjoyed this video btw 👍😀

Ответить
Call Me Caesar
Call Me Caesar - 09.05.2023 10:01

He mentioned that basic dictionary words should never be used in a password, but aren't these words the basis for things like diceware? Is diceware no longer considered good enough for generating passwords?

Ответить
Lampe2020
Lampe2020 - 09.05.2023 08:42

Very interesting video! Just cracking these hashes like nothing...
To the sponsor segment: I don't need Passbolt, I have a password manager built-in to Firefox.

Ответить
Arsquid
Arsquid - 09.05.2023 08:34

Thank you John for this absolute gem of an episode!

Ответить
Creek
Creek - 09.05.2023 05:21

Passbolt caught my interest

Ответить
Andrew Swenson
Andrew Swenson - 09.05.2023 04:40

Finding the right combination of rules and wordlists is tedious, and I believe it's necessary to use a technique for filtering out duplicate attempts. The hashcat-brain allows you to do just that, which is why I blindly think it's awesome.

Ответить
NeverGiveUpYo
NeverGiveUpYo - 09.05.2023 01:38

Cewl video John! :)

Ответить
Hypedz
Hypedz - 08.05.2023 23:34

John.. John Hammond.

Ответить
Hitem Ariania
Hitem Ariania - 08.05.2023 22:16

I would highly recommend spraygen :). And thanks for a superb video John!

Ответить
Revoky
Revoky - 08.05.2023 22:02

if you use the word N|GGER as your password it will be uncrackable because nobody wants to be associated with racism

Ответить
Rayan Fernandes
Rayan Fernandes - 08.05.2023 21:31

This is cool but now most often the hashes are of salted passwords , so its complex to crack those , btw this hack works on leet style wifi passwords 😅

Ответить
Anil Bangera
Anil Bangera - 08.05.2023 21:10

Good

Ответить
Tyro James
Tyro James - 08.05.2023 20:50

COOL

Ответить
Indiscriminate
Indiscriminate - 08.05.2023 20:29

That’s not the type of munging I know about 🤪

Ответить
ELIAS
ELIAS - 08.05.2023 20:22

I DONT Recommande USING PASBOLT USE UR BRAIN

Ответить
Devin's Codex
Devin's Codex - 08.05.2023 20:19

Knew about OneRuleToRuleThemAll, but learned about CEWL & munging passwords, thank you for another great video! 🙏

Ответить
𝗥𝗩𝗙𝗘𝗧 𝗠𝘂𝘀𝗶𝗰
𝗥𝗩𝗙𝗘𝗧 𝗠𝘂𝘀𝗶𝗰 - 08.05.2023 19:36

Pro tip, put emoji in your password and keep it at least 12 characters long, there you have uncrackable password, no matter what you put as password.

Ответить
Anurag Biswas
Anurag Biswas - 08.05.2023 19:07

Hey John, great video once again. I've been meaning to ask something. What's a good course for learning Web App Pentesting out there?

Ответить
Adam Radloff
Adam Radloff - 08.05.2023 18:59

I just used AI to convert munge to python3, works great

Ответить
Zedorek
Zedorek - 08.05.2023 18:57

i just learnt this in my RED team course :) Cewl!

Ответить
Sulav Adhikari
Sulav Adhikari - 08.05.2023 18:33

john is the degrass tyson of cyber sec

Ответить
Hamed Ranaee
Hamed Ranaee - 08.05.2023 18:28

You know what John?! , I've learned many things from you. Thank you 🤩

Ответить
Eye phpmyadmin
Eye phpmyadmin - 08.05.2023 17:59

Not saying I've been cracking neighbors wifi but if I was I'd love using rules

Ответить
Saif Ahmed
Saif Ahmed - 08.05.2023 17:59

Thank you for this Great 👍 content
But what if passbolt got hacked
My passwords will be available online like what happened with LastPass?

Ответить
Krimlon
Krimlon - 08.05.2023 17:31

Bitwarden ftw

Ответить