John the Ripper Tutorial


example: 
inside the file i targeted i found the hashed password like this 
blah:S2XSgk2WEfE9w 
so saved to list ready to crack , i called mine MD5pass for this lesson 
this is what jtr will be cracking,
after you have several passwords to various sites you can begin jtr or just use a single hashed password ..its up to you 
now there are many ways to crack the file using jtr am just going to use the basic 
one i find the easiest but slowest to use...there are plenty of jtr guides around for more detail cracking modes
common modes are 
john -si [passfile]
john -w:[wordlist] [passfile]
john -i [passfile]
there are other modes using digits,alpha,all...they all do the same thing... anyway on to basics 
assuming you have john in C:\ directory just type
c:\john -i MD5pass.txt 
image 1
user posted image
after several minutes\hours you should have something like this with cracked passwords if you take a look at the image
after 21 minutes it had cracked 13 of the 36...not bad after 3hrs 24min 18 cracked...half done wink.gif btw each password cracked is a website....so up to now 18 possible targets 
image 2
user posted image
to check progress hit any key 
to stop the cracking hit Ctrl+c session aborted
to view your results type: 
c:\john -show MD5pass.txt>result2.txt....this will save the file called result2.txt in the jtr root like this 
image 3
user posted image
you now have the password to gain access to the ftp,or whatever 
to resume your cracking
type: 
c:\john -restore 
will load the remaning uncracked passwords and resume attempts from were it left off 
image 4
user posted image
JTR Commands and Modes 
**if you look in the doc folder that came with JTR it gives you details on how to use them** 
hope you enjoyed the tutorial...remember if you do gain access to a site\server please inform the admin 
i hold no resposibility for your actions 
ComSec
23 june 2003 
dont come any easier than this...i think !

 

 


GSO
Written on Saturday, 03 October 2009 16:50 by GSO

Viewed 456 times so far.
Like this? Tweet it to your followers!

Rate this article

Latest articles from GSO

Latest 'tweets' from GovernmentSecurity

  • Can I get a Hoot Hoot?! #HootSuite is my number one Twitter client. http://hootsuite.com Link Friday, 06 November 2009 06:03
  • @foadah Thas what Im talking about :) Link Friday, 06 November 2009 05:58
  • #security | Don't panic over the secret copyright treaty | latest-security-news | GSO - Network Security Resources http://bit.ly/1K63Sr Link Thursday, 05 November 2009 08:01
  • #security | Which country has the most bot-infected computers? | latest-security-news | GSO - Network Security Reso... http://bit.ly/HAeG9 Link Thursday, 05 November 2009 08:01
  • #security | Backdoor access for millions of Facebook and MySpace accounts | latest-security-news | GSO - Network S... http://bit.ly/3dwnmc Link Thursday, 05 November 2009 08:01
blog comments powered by Disqus

Site Search

Sponsor Advertisements

SwiftLayer Affiliate Web Hosting

Disqus Tools