[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fB9qUNn3jjVtlLsvQ7om4ySdAfBWcLb2ubmgUGO7ulQs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},850,"Why are rainbow table attacks ineffective against Linux password hashes?","Rainbow tables rely on precomputed hash tables for unsalted passwords. Linux password hashes include a unique, random salt for each user, which alters the final hash even if two users share the same password. This salt renders precomputed tables useless, forcing attackers to use dictionary or brute-force attacks. The [Linux Password Hashes article](\u002Fnews\u002Flinux-password-hashes-technical-overview-of-encryption-methods-and-cracking-techniques) explains how the salt is embedded in the hash format (e.g., `$6$C\u002FvGzhVe$`).","\u003Cp>Rainbow tables rely on precomputed hash tables for unsalted passwords. Linux password hashes include a unique, random salt for each user, which alters the final hash even if two users share the same password. This salt renders precomputed tables useless, forcing attackers to use dictionary or brute-force attacks. The [Linux Password Hashes article](\u002Fnews\u002Flinux-password-hashes-technical-overview-of-encryption-methods-and-cracking-techniques) explains how the salt is embedded in the hash format (e.g., `$6$C\u002FvGzhVe$`).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Flinux-password-hashes-technical-overview-of-encryption-methods-and-cracking-techniques\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-are-rainbow-table-attacks-ineffective-against-linux-password-hashes-1777481607525","rainbow table, salt, dictionary attack, brute-force attack, password cracking",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},208,"Linux Password Hashes - Technical Overview of Encryption Methods and Cracking Techniques","linux-password-hashes-technical-overview-of-encryption-methods-and-cracking-techniques","Explore Linux password storage in \u002Fetc\u002Fshadow, encryption methods like SHA-512, and cracking techniques using John the Ripper and hashcat for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Linux systems, user passwords are encrypted and stored in the \u002Fetc\u002Fshadow file. What are the encryption methods and cracking techniques for these passwords? This article attempts to organize this topic, introduce related foundational knowledge, test common methods, and help readers gain a more intuitive understanding.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The storage format of user passwords in Linux\u003C\u002Fli>\u003Cli>Encryption methods for user passwords in Linux\u003C\u002Fli>\u003Cli>Common tools and methods for cracking user password hashes\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Storage Format of User Passwords in Linux\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Linux password information is stored in two files: \u002Fetc\u002Fpasswd and \u002Fetc\u002Fshadow\u003C\u002Fp>\u003Ch3>\u002Fetc\u002Fpasswd:\u003C\u002Fh3>\u003Cp>Viewable by regular user permissions\u003C\u002Fp>\u003Cp>Save user information, each line represents a user, each line is divided into seven parts by a colon:\u003C\u002Fp>\u003Col>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password, x indicates the password is stored in \u002Fetc\u002Fshadow\u003C\u002Fli>\u003Cli>UID, 0 represents root\u003C\u002Fli>\u003Cli>GID, indicates the group\u003C\u002Fli>\u003Cli>Description information, in order: Full Name, Room Number, Work Phone, Home Phone, and Other\u003C\u002Fli>\u003Cli>User home directory\u003C\u002Fli>\u003Cli>Default shell type\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>e.g.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>test2:x:1001:1001:test2,11111,111111-11,222222-22,test:\u002Fhome\u002Ftest2:\u002Fbin\u002Fbash\u003C\u002Fp>\u003Cul>\u003Cli>Username: test2\u003C\u002Fli>\u003Cli>Password stored in \u002Fetc\u002Fshadow\u003C\u002Fli>\u003Cli>UID is 1001\u003C\u002Fli>\u003Cli>GID is 1001\u003C\u002Fli>\u003Cli>Description information:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Full Name []: test2\u003C\u002Fp>\u003Cp>Room Number []: 11111\u003C\u002Fp>\u003Cp>Work Phone []: 111111-11\u003C\u002Fp>\u003Cp>Home Phone []: 222222-22\u003C\u002Fp>\u003Cp>Other []: test\u003C\u002Fp>\u003Cul>\u003Cli>The user's home directory is \u002Fhome\u002Ftest2\u003C\u002Fli>\u003Cli>The default shell is \u002Fbin\u002Fbash\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>\u002Fetc\u002Fshadow:\u003C\u002Fh3>\u003Cp>Only root user privileges can view it\u003C\u002Fp>\u003Cp>Stores encrypted passwords and related password information for users, each line represents a user, and each line is divided into nine parts by colons:\u003C\u002Fp>\u003Col>\u003Cli>Username\u003C\u002Fli>\u003Cli>Encrypted password\u003C\u002Fli>\u003Cli>Last password change time (total days since 1970.1.1)\u003C\u002Fli>\u003Cli>Minimum days between password changes, if 0, there is no restriction\u003C\u002Fli>\u003Cli>Maximum days between password changes, indicating how many days later the user's password will expire, if 99999, there is no restriction\u003C\u002Fli>\u003Cli>How many days in advance to warn the user that the password will expire\u003C\u002Fli>\u003Cli>How many days after password expiration to disable this user\u003C\u002Fli>\u003Cli>User expiration date (total days since 1970.1.1), if 0, the user is permanently available\u003C\u002Fli>\u003Cli>Reserved\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameter description can be obtained via man shadow\u003C\u002Fp>\u003Cp>\u003Cstrong>eg.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>test2:$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0:17470:0:99999:7:::\u003C\u002Fp>\u003Cul>\u003Cli>Username: test2\u003C\u002Fli>\u003Cli>Encrypted password: $6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0\u003C\u002Fli>\u003Cli>Last password change time (total days since 1970.1.1 is 17470)\u003C\u002Fli>\u003Cli>Minimum days between password changes: no restriction\u003C\u002Fli>\u003Cli>Maximum days between password changes: no restriction\u003C\u002Fli>\u003Cli>Warn the user 7 days in advance that the password will expire\u003C\u002Fli>\u003Cli>This user is permanently available\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the example, the encrypted password has a fixed format:\u003C\u002Fp>\u003Cp>$id$salt$encrypted\u003C\u002Fp>\u003Cp>id indicates the encryption algorithm: 1 for MD5, 5 for SHA-256, 6 for SHA-512\u003C\u002Fp>\u003Cp>salt refers to the cryptographic Salt, randomly generated by the system\u003C\u002Fp>\u003Cp>encrypted represents the hash of the password\u003C\u002Fp>\u003Ch2>0x03 Common tools and methods for cracking user password hashes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since Linux password encryption uses Salt, rainbow table attacks are ineffective; common methods are dictionary attacks and brute-force attacks\u003C\u002Fp>\u003Cp>Common tools for dictionary and brute-force attacks:\u003C\u002Fp>\u003Ch3>1. John the Ripper\u003C\u002Fh3>\u003Ch4>(1) Dictionary attack\u003C\u002Fh4>\u003Cp>Kali 2.0 includes John the Ripper\u003C\u002Fp>\u003Cp>The dictionary file is located at \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Using the password list included with John on Kali Linux. The path is \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Performing a dictionary attack:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john --wordlist=\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Other dictionaries can also be used\u003C\u002Fp>\u003Ch4>(2) Brute-force attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List cracked plaintext passwords:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john --show .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017284273_0_49bd63f60c.jpeg\">\u003C\u002Fp>\u003Ch3>2. hashcat\u003C\u002Fh3>\u003Cp>Kali 2.0 includes hashcat\u003C\u002Fp>\u003Cp>Dictionary file uses \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Modify hash format: retain only $salt$encrypted\u003C\u002Fp>\u003Cp>\u003Cstrong>e.g.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Original hash:\u003C\u002Fp>\u003Cp>test2:$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0:17470:0:99999:7:::\u003C\u002Fp>\u003Cp>Modified:\u003C\u002Fp>\u003Cp>$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0\u003C\u002Fp>\u003Ch4>(1) Dictionary Attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 1800 -o found1.txt --remove shadow \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cp>-m: hash-type, 1800 corresponds to SHA-512\u003C\u002Fp>\u003Cp>Detailed parameters can be found in the table: https:\u002F\u002Fhashcat.net\u002Fwiki\u002Fdoku.php?id=example_hashes\u003C\u002Fp>\u003Cp>-o: output file\u003C\u002Fp>\u003Cp>--remove: indicates the hash will be removed from the hash file after being cracked\u003C\u002Fp>\u003Cp>shadow: represents the hash file\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst: represents the dictionary file\u003C\u002Fp>\u003Cp>Successfully cracked 2 hashes, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017313233_1_f316010f96.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Brute Force Attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 1800 -a 3 -o found2.txt shadow ?l?l?l?l --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-a: attack-mode, default is 0, 3 represents Brute-force, i.e., brute force attack\u003C\u002Fp>\u003Cp>?l: represents lowercase letters, i.e., abcdefghijklmnopqrstuvwxyz, 4 ?l indicates the brute force attack length is 4\u003C\u002Fp>\u003Cp>?u: represents uppercase letters, i.e., ABCDEFGHIJKLMNOPQRSTUVWXYZ\u003C\u002Fp>\u003Cp>?h: represents lowercase hexadecimal characters, i.e., 0123456789\u003C\u002Fp>\u003Cp>?H: represents uppercase hexadecimal characters, i.e., 0123456789abcdef\u003C\u002Fp>\u003Cp>?s: represents special symbols, i.e., !\"#$%&amp;'()*+,-.\u002F:;&lt;=&gt;?@[\\]^_`{|}~\u003C\u002Fp>\u003Cp>?a: represents all characters, i.e., ?l?u?d?s\u003C\u002Fp>\u003Cp>?b: represents hexadecimal, i.e., 0x00 - 0xff\u003C\u002Fp>\u003Cp>Successfully brute-forced the hash, result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017355827_2_6319601e4e.jpeg\">\u003C\u002Fp>\u003Ch3>3、Online websites\u003C\u002Fh3>\u003Cp>1.https:\u002F\u002Fhce.iteknical.com\u002F\u003C\u002Fp>\u003Cp>HCE distributed computing platform, requires points to use\u003C\u002Fp>\u003Cp>2.http:\u002F\u002Fwww.cmd5.com\u002F\u003C\u002Fp>\u003Cp>Currently does not support SHA-512\u003C\u002Fp>\u003Ch3>4. mimipenguin\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhuntergregal\u002Fmimipenguin\u003C\u002Fp>\u003Cp>Similar to mimikatz in principle, extracts plaintext passwords from memory\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced password storage formats in Linux and tested two common tools: John the Ripper and hashcat, using dictionary and brute-force cracking methods respectively.\u003C\u002Fp>\u003Cp>As an article summarizing foundational knowledge, we aimed to be as concise and practical as possible. Reader feedback is welcome, and this content will continue to be refined in the future.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Linux systems, user passwords are encrypted and stored in the \u002Fetc\u002Fshadow file. What are the encryption methods and cracking techniques for these passwords? This article attempts to organize this topic, introduce related foundational knowledge, test common methods, and help readers gain a more intuitive understanding.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The storage format of user passwords in Linux\u003C\u002Fli>\u003Cli>Encryption methods for user passwords in Linux\u003C\u002Fli>\u003Cli>Common tools and methods for cracking user password hashes\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Storage Format of User Passwords in Linux\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Linux password information is stored in two files: \u002Fetc\u002Fpasswd and \u002Fetc\u002Fshadow\u003C\u002Fp>\u003Ch3>\u002Fetc\u002Fpasswd:\u003C\u002Fh3>\u003Cp>Viewable by regular user permissions\u003C\u002Fp>\u003Cp>Save user information, each line represents a user, each line is divided into seven parts by a colon:\u003C\u002Fp>\u003Col>\u003Cli>Username\u003C\u002Fli>\u003Cli>Password, x indicates the password is stored in \u002Fetc\u002Fshadow\u003C\u002Fli>\u003Cli>UID, 0 represents root\u003C\u002Fli>\u003Cli>GID, indicates the group\u003C\u002Fli>\u003Cli>Description information, in order: Full Name, Room Number, Work Phone, Home Phone, and Other\u003C\u002Fli>\u003Cli>User home directory\u003C\u002Fli>\u003Cli>Default shell type\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>e.g.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>test2:x:1001:1001:test2,11111,111111-11,222222-22,test:\u002Fhome\u002Ftest2:\u002Fbin\u002Fbash\u003C\u002Fp>\u003Cul>\u003Cli>Username: test2\u003C\u002Fli>\u003Cli>Password stored in \u002Fetc\u002Fshadow\u003C\u002Fli>\u003Cli>UID is 1001\u003C\u002Fli>\u003Cli>GID is 1001\u003C\u002Fli>\u003Cli>Description information:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Full Name []: test2\u003C\u002Fp>\u003Cp>Room Number []: 11111\u003C\u002Fp>\u003Cp>Work Phone []: 111111-11\u003C\u002Fp>\u003Cp>Home Phone []: 222222-22\u003C\u002Fp>\u003Cp>Other []: test\u003C\u002Fp>\u003Cul>\u003Cli>The user's home directory is \u002Fhome\u002Ftest2\u003C\u002Fli>\u003Cli>The default shell is \u002Fbin\u002Fbash\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>\u002Fetc\u002Fshadow:\u003C\u002Fh3>\u003Cp>Only root user privileges can view it\u003C\u002Fp>\u003Cp>Stores encrypted passwords and related password information for users, each line represents a user, and each line is divided into nine parts by colons:\u003C\u002Fp>\u003Col>\u003Cli>Username\u003C\u002Fli>\u003Cli>Encrypted password\u003C\u002Fli>\u003Cli>Last password change time (total days since 1970.1.1)\u003C\u002Fli>\u003Cli>Minimum days between password changes, if 0, there is no restriction\u003C\u002Fli>\u003Cli>Maximum days between password changes, indicating how many days later the user's password will expire, if 99999, there is no restriction\u003C\u002Fli>\u003Cli>How many days in advance to warn the user that the password will expire\u003C\u002Fli>\u003Cli>How many days after password expiration to disable this user\u003C\u002Fli>\u003Cli>User expiration date (total days since 1970.1.1), if 0, the user is permanently available\u003C\u002Fli>\u003Cli>Reserved\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Parameter description can be obtained via man shadow\u003C\u002Fp>\u003Cp>\u003Cstrong>eg.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>test2:$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0:17470:0:99999:7:::\u003C\u002Fp>\u003Cul>\u003Cli>Username: test2\u003C\u002Fli>\u003Cli>Encrypted password: $6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0\u003C\u002Fli>\u003Cli>Last password change time (total days since 1970.1.1 is 17470)\u003C\u002Fli>\u003Cli>Minimum days between password changes: no restriction\u003C\u002Fli>\u003Cli>Maximum days between password changes: no restriction\u003C\u002Fli>\u003Cli>Warn the user 7 days in advance that the password will expire\u003C\u002Fli>\u003Cli>This user is permanently available\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the example, the encrypted password has a fixed format:\u003C\u002Fp>\u003Cp>$id$salt$encrypted\u003C\u002Fp>\u003Cp>id indicates the encryption algorithm: 1 for MD5, 5 for SHA-256, 6 for SHA-512\u003C\u002Fp>\u003Cp>salt refers to the cryptographic Salt, randomly generated by the system\u003C\u002Fp>\u003Cp>encrypted represents the hash of the password\u003C\u002Fp>\u003Ch2>0x03 Common tools and methods for cracking user password hashes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since Linux password encryption uses Salt, rainbow table attacks are ineffective; common methods are dictionary attacks and brute-force attacks\u003C\u002Fp>\u003Cp>Common tools for dictionary and brute-force attacks:\u003C\u002Fp>\u003Ch3>1. John the Ripper\u003C\u002Fh3>\u003Ch4>(1) Dictionary attack\u003C\u002Fh4>\u003Cp>Kali 2.0 includes John the Ripper\u003C\u002Fp>\u003Cp>The dictionary file is located at \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Using the password list included with John on Kali Linux. The path is \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Performing a dictionary attack:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john --wordlist=\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Other dictionaries can also be used\u003C\u002Fp>\u003Ch4>(2) Brute-force attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List cracked plaintext passwords:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>john --show .\u002Fshadow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017284273_0_49bd63f60c-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. hashcat\u003C\u002Fh3>\u003Cp>Kali 2.0 includes hashcat\u003C\u002Fp>\u003Cp>Dictionary file uses \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003Cp>Modify hash format: retain only $salt$encrypted\u003C\u002Fp>\u003Cp>\u003Cstrong>e.g.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Original hash:\u003C\u002Fp>\u003Cp>test2:$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0:17470:0:99999:7:::\u003C\u002Fp>\u003Cp>Modified:\u003C\u002Fp>\u003Cp>$6$C\u002FvGzhVe$aKK6QGdhzTmYyxp8.E68gCBkPhlWQ4W7\u002FOpCFQYV.qsCtKaV00bToWh286yy73jedg6i0qSlZkZqQy.wmiUdj0\u003C\u002Fp>\u003Ch4>(1) Dictionary Attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 1800 -o found1.txt --remove shadow \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Cp>-m: hash-type, 1800 corresponds to SHA-512\u003C\u002Fp>\u003Cp>Detailed parameters can be found in the table: https:\u002F\u002Fhashcat.net\u002Fwiki\u002Fdoku.php?id=example_hashes\u003C\u002Fp>\u003Cp>-o: output file\u003C\u002Fp>\u003Cp>--remove: indicates the hash will be removed from the hash file after being cracked\u003C\u002Fp>\u003Cp>shadow: represents the hash file\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst: represents the dictionary file\u003C\u002Fp>\u003Cp>Successfully cracked 2 hashes, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017313233_1_f316010f96-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Brute Force Attack:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 1800 -a 3 -o found2.txt shadow ?l?l?l?l --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-a: attack-mode, default is 0, 3 represents Brute-force, i.e., brute force attack\u003C\u002Fp>\u003Cp>?l: represents lowercase letters, i.e., abcdefghijklmnopqrstuvwxyz, 4 ?l indicates the brute force attack length is 4\u003C\u002Fp>\u003Cp>?u: represents uppercase letters, i.e., ABCDEFGHIJKLMNOPQRSTUVWXYZ\u003C\u002Fp>\u003Cp>?h: represents lowercase hexadecimal characters, i.e., 0123456789\u003C\u002Fp>\u003Cp>?H: represents uppercase hexadecimal characters, i.e., 0123456789abcdef\u003C\u002Fp>\u003Cp>?s: represents special symbols, i.e., !\"#$%&amp;'()*+,-.\u002F:;&lt;=&gt;?@[\\]^_`{|}~\u003C\u002Fp>\u003Cp>?a: represents all characters, i.e., ?l?u?d?s\u003C\u002Fp>\u003Cp>?b: represents hexadecimal, i.e., 0x00 - 0xff\u003C\u002Fp>\u003Cp>Successfully brute-forced the hash, result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017355827_2_6319601e4e-1.jpeg\">\u003C\u002Fp>\u003Ch3>3、Online websites\u003C\u002Fh3>\u003Cp>1.https:\u002F\u002Fhce.iteknical.com\u002F\u003C\u002Fp>\u003Cp>HCE distributed computing platform, requires points to use\u003C\u002Fp>\u003Cp>2.http:\u002F\u002Fwww.cmd5.com\u002F\u003C\u002Fp>\u003Cp>Currently does not support SHA-512\u003C\u002Fp>\u003Ch3>4. mimipenguin\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhuntergregal\u002Fmimipenguin\u003C\u002Fp>\u003Cp>Similar to mimikatz in principle, extracts plaintext passwords from memory\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced password storage formats in Linux and tested two common tools: John the Ripper and hashcat, using dictionary and brute-force cracking methods respectively.\u003C\u002Fp>\u003Cp>As an article summarizing foundational knowledge, we aimed to be as concise and practical as possible. Reader feedback is welcome, and this content will continue to be refined in the future.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",731,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Linux Password Hashes: Encryption Methods & Cracking Techniques","Linux password hashes, \u002Fetc\u002Fshadow, encryption methods, password cracking, John the Ripper, hashcat, dictionary attack, brute-force attack, SHA-512, salt",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],852,851,849,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.220Z","2026-07-23T16:02:11.926Z","draft","2026-07-23T16:15:06.352Z"]