1 option
Ethical Password Cracking : Decode Passwords Using John the Ripper, Hashcat, and Advanced Methods for Password Breaking / James Leyte-Vidal.
- Format:
- Book
- Author/Creator:
- Leyte-Vidal, James, author.
- Language:
- English
- Subjects (All):
- Computer networks--Security measures.
- Computer networks.
- Computers--Access control--Passwords.
- Computers.
- Penetration testing (Computer security).
- Physical Description:
- 1 online resource (168 pages)
- Edition:
- First edition.
- Place of Publication:
- Birmingham, England : Packt Publishing, [2024]
- Biography/History:
- Leyte-Vidal James: James Leyte-Vidal is a 20-plus-year veteran of the computer security industry. After a self-taught career in IT, James worked on a computer security incident that changed his career trajectory to security. James consults independently and has worked for Fortune 100 companies in various roles, including security architecture, penetration testing, compliance, policy, and much more. James is also an instructor at the SANS Institute, a global provider of information security training, and a co-author of three SANS courses: SEC467: Social Engineering for Security Professionals, SEC556: IoT Penetration Testing, and SEC617: Wireless Penetration Testing and Ethical Hacking. When not actively doing security work, James can often be found tinkering with hardware or spending time with his family.
- Summary:
- Investigate how password protection works and delve into popular cracking techniques for penetration testing and retrieving data Key Features Gain guidance for setting up a diverse password-cracking environment across multiple platforms Explore tools such as John the Ripper, Hashcat, and techniques like dictionary and brute force attacks for breaking passwords Discover real-world examples and scenarios to navigate password security challenges effectively Purchase of the print or Kindle book includes a free PDF eBook Book Description Whether you're looking to crack passwords as part of a thorough security audit or aiming to recover vital information, this book will equip you with the skills to accomplish your goals. Written by a cybersecurity expert with over fifteen years of experience in penetration testing, Ethical Password Cracking offers a thorough understanding of password protection and the correct approach to retrieving password-protected data. As you progress through the chapters, you first familiarize yourself with how credentials are stored, delving briefly into the math behind password cracking. Then, the book will take you through various tools and techniques to help you recover desired passwords before focusing on common cracking use cases, hash recovery, and cracking. Real-life examples will prompt you to explore brute-force versus dictionary-based approaches and teach you how to apply them to various types of credential storage. By the end of this book, you'll understand how passwords are protected and how to crack the most common credential types with ease. What you will learn Understand the concept of password cracking Discover how OSINT potentially identifies passwords from breaches Address how to crack common hash types effectively Identify, extract, and crack Windows and macOS password hashes Get up to speed with WPA/WPA2 architecture Explore popular password managers such as KeePass, LastPass, and 1Password Format hashes for Bitcoin, Litecoin, and Ethereum wallets, and crack them Who this book is for This book is for cybersecurity professionals, penetration testers, and ethical hackers looking to deepen their understanding of password security and enhance their capabilities in password cracking. You'll need basic knowledge of file and folder management, the capability to install applications, and a fundamental understanding of both Linux and Windows to get started.
- Contents:
- Cover
- Title Page
- Copyright and Credits
- Contributors
- Table of Contents
- Preface
- Part 1: Introduction and Setup
- Chapter 1: Password Storage: Math, Probability, and Complexity
- What is password cracking?
- Dictionary-based attacks
- Combination attacks
- Brute-force attacks
- Hybrid attacks
- Partial knowledge, also known as mask attacks
- How are passwords stored and used?
- Hashing
- Encryption
- Why are some passwords easier to crack than others?
- Password length
- Password complexity
- Time to hash/encrypt the password
- A word on "ethical" password cracking
- Summary
- Chapter 2: Why Crack When OSINT Will Do?
- How does OSINT help with password cracking?
- Leveraging OSINT to access compromised passwords
- Using OSINT to obtain password candidates
- Chapter 3: Setting Up Your Password Cracking Environment
- Technical requirements
- Installing and introducing John
- Core functions of John
- Installing hashcat
- Core functions of hashcat
- Chapter 4: John and Hashcat Rules
- Analyzing password complexity rules
- Selecting and using John rules
- Selecting and using hashcat rules
- Part 2: Collection and Cracking
- Chapter 5: Windows and macOS Password Cracking
- Collecting Windows password hashes
- Kerberos
- Cracking Windows hashes
- Collecting macOS password hashes
- Formatting/converting hashes into their expected formats
- Cracking hashes
- Chapter 6: Linux Password Cracking
- Collecting Linux password hashes
- Chapter 7: WPA/WPA2 Wireless Password Cracking
- A note about WEP
- WPA/WPA2 architecture
- Obtaining WPA/WPA2 information to crack
- Methods for cracking WPA/WPA2 passphrases.
- Chapter 8: WordPress, Drupal, and Webmin Password Cracking
- Collecting and formatting WordPress hashes
- Cracking WordPress hashes
- Collecting and formatting Drupal hashes
- Cracking Drupal hashes
- Collecting and formatting Webmin hashes
- Cracking Webmin hashes
- Chapter 9: Password Vault Cracking
- Collecting KeePass password hashes
- Cracking KeePass password hashes
- Collecting LastPass password hashes
- Cracking LastPass hashes
- Collecting 1Password password hashes
- Cracking 1Password password hashes
- Chapter 10: Cryptocurrency Wallet Passphrase Cracking
- Cryptocurrencies and blockchain explained
- Collecting and formatting Bitcoin/Litecoin wallet hashes
- Cracking Bitcoin/Litecoin wallet hashes
- Collecting and formatting Ethereum wallet hashes
- Cracking Ethereum wallet hashes
- Part 3: Conclusion
- Chapter 11: Protections against Password Cracking Attacks
- How to choose a password more resistant to cracking attacks
- Additional protections against cracking attacks
- Index
- Other Books You May Enjoy.
- Notes:
- Includes index.
- Description based on publisher supplied metadata and other sources.
- Description based on print version record.
- Other Format:
- Print version: Leyte-Vidal, James Ethical Password Cracking
- ISBN:
- 9781804613856
- OCLC:
- 1440216817
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.