Password Cracking

Infra password cracking - Build your own wordlist that fits

Take a wordlist

for example staticticaly meaningful

wget https://raw.githubusercontent.com/insidetrust/statistically-likely-
usernames/master/weak-corporate-passwords/english-basic.txt
cat users.txt >> english-basic.txt

or build your own based on user enumeration (SMB, RPC, WEB)

Building Yp Own Passowrd Wordlist

usernames including admins
seasons
password
<empty>

Rules Mangling with

Enrich your wordlist by rules, add a bit of that, reverse, mangle...

hashcat

John The Ripper

where rule file /etc/john/john.conf

Now you have a wordlists that fits, be prepared for online password attack by checking...

Account Policy

Determine the account policy on your infra Active Directory before you start to lock out accounts

Start to crack with

Crackmapexec smb

Last updated

Was this helpful?