How to Automate Password Hacking
Skills:
Security Basics80%
Key Takeaways
The video demonstrates how to automate password hacking, sponsored by Snyk, and provides resources for pentesting, security consulting, and training.
Full Transcript
one of the most common tasks in ethical hacker performs is password cracking if you spent a microsecond studying ethical hacking you've probably cracked a password the problem with password cracking is that it can be slow and tedious why can't we just run one command and have all of our tasks done at once why can't we automate this well we can and in this video I'm going to show you how with about a hundred lines of python code we can automate our password cracking process so that we can do better things with our time [Music] before we get started we're going to take a quick word from our sponsor and as always if you like this video please consider subscribing to the channel if you watch our channel that probably means that you care about security if you're a developer using open source libraries or even writing code from scratch it's important to make sure that your code is secure and that's where sneak comes in sneak integrates into your existing tools your Ides CLI repos and scans your code as you write it in real time I'm not kidding watch this here I'm using visual studio code with the sneak security extension enabled and I'm writing this code in Python I am writing code to log into a SQL database and oh no I can see that I'm getting some errors in here so if I hover over this error it says I have a SQL injection because unsanitized input exists if I come over here and actually click on this I can show the suggestion from sneak which says that yeah it's unsanitized but also here's some examples of how to fix this you can click through there's three here it tells us exactly what we need to do giving us real time examples and we can even learn more about the vulnerability if we want to it's really great the let's see what happens when I fix this code and once we do fix this all I have to do is hit save and it will rescan my file and just so you can see the fix I came in here and added some parameterized queries and now we are all good to go we have saved it and look I've got no errors down here no errors in my file now I'm not going to have SQL injection in my code and that is the power of sneak so make sure your project remains secure from the start you could try sneak today with my code at sneak.com forward slash the Cyber Mentor let's walk through a scenario now let's say that we are on an internal penetration test and we just compromised the domain controller and what we want to do is we want to dump out the ntds.dit and that file allows us to see all the wonderful ntlm hashes that exist on the domain and we can do that here with an example we just go ahead and hit enter we get the spit out of information here so if we come in here we can see that we get an administrator password hash perfect we get all these hashes then we get some hashes I don't want like gas and this krb TGT if we come down a little bit we get all these computer hashes that I don't want either and so what I typically do is I come in here and I copy these first and then maybe I get rid of some of these so maybe I open this and I come in here and I paste and I'll get rid of these two accounts here I'll get rid of these okay and now I've cleaned up my list but there's more problems here well first of all all I need is the LM part of this hash this is an ntlm hash and these are great hashes because they do crack very fast well I need to break this out to where I can grab just the end of this hash we could do this in bash we can come in here and say well I see there's a delimiter maybe of a colon maybe I just grab this field right here we split that out okay that's possible and then the problem is we need this in order to crack it right we need just this hash here so we take a list of these hashes and then we crack them and if we've got a thousand of these now we have to come back and we have to tie this hash specifically back into this account it could become a wild mess let me show you how I do it now and then we can look at how we can automate this process a lot easier than what I'm doing currently listen don't judge me I'm a former accountant I am using Excel all right I come in here I paste this into Excel I can come and actually just go to data and then do a delimited here with the text to columns and if you go in here and do delimited you can go with a colon here for other and it will go ahead and just put everything into columns like I have now again the LM part of the hash is all the same we need this NT hash right here so we would take this we would copy this and then we'd go back to Kali Linux and then maybe I'll make a hash file like hashes we'll call us 3.txt I come in here and I'll paste those hashes and then I'm gonna have to come in a hash cat and I'm gonna have to run this against the hashes and I'm gonna have to put about word list in here user share word list rock you and so I can run this and try to crack these hashes that I found and then once I do crack them I'll just show you because I've already cracked them it comes out into this list like this so I have the hash and the password but if I have a thousand again of these I don't know what these go to so I just come back and I'll take these and I'll copy them again and then I'll go back to Excel and from within Excel I'll have a new tab and I'll paste all my results in here which is great and then I'm gonna have to come in here and I have to do some Wizardry where I do this vlookup command and I have to look up this value here and then I have to come over here and say Here's my row or my table array and the column that I want to grab the password from and that's false because I want the exact match and I come through and okay and I can come in here and final the passwords that were matched to that user gosh that takes for forever to do this so this is slightly annoying there are tools out there that can help with this but why not just automate the whole process so that I can just run this and walk away and that's exactly what I want to do today and that's exactly what I'm going to show you and look I'm a nice guy I'm not going to keep you in suspense this is already the tool I'm going to show you how it works I'm just going to hit enter on this it's going to run secret stump it's going to run hashcat it's going to do all of that back end work for us and then it's going to compile all this and actually put these users to a password we just cut out the file that it creates here and you can see that hey all those passwords that we had in our Excel file match to users Bingo right here they are all matched up perfectly we don't have to worry about it that's awesome let's go ahead and take a look at this code and see how it actually works okay so here's our code it is written in Python it's around 100 lines and we need to start off with our Imports and so for our Imports we're going to import ARG parse which is going to allow us to have arguments that you can see here we're also going to import sub process which is going to allow us to spawn new processes and also we're going to import re which is going to allow for regular Expressions which you're going to see here very shortly so we're going to Define our main here and then from within main we're going to go ahead and just start listing everything out first things first we need to run secret stump so with secret stump we need to have a set amount of arguments we need to have a domain a user a password and an IP address and we can show that proof of concept off really quick so here's what this looks like secret stump here's our domain here's the user that we used here's the password we provided here's the IP address and I'm just going to hit enter on this so we can see the output as well because it's going to be important here in just a second so with that let's go back we also are going to run hashcad we're going to come in here we need to absolutely have a word list for hashcad so that's true all these so far have been required we also have some other things in hashcat that we can run for example we can run rule set so if we want to run rule sets already built that in we can also optimize this with the dash capital O the thing about this in one caveat about this program is if you run it in a virtual machine which it will work it's going to try to utilize your C CPU instead of your GPU so you should run this on metal now I'm showing you in a virtual machine no big deal but if you want the most out of this it needs to be ran on metal so with that we store our arguments here into an arguments variable coming down we have our Command that we're going to run so our Command we're going to run first is going to be secret stump here we're just putting in all those arguments that we're providing here and we're going to dump out what is called the ntds.dit and here we're just going to print that out execute the command and we're going to store these results you're actually not even going to see it get outputted which is nice and we're just going to store it into a result variable that's what's happening here and then we're going to do a split of the output into new lines which is great then we're going to come in here and we're going to set a few variables we're going to have a start variable that is just set to false we'll talk about Y in just a second we have a couple of indexes indices I don't know what you call them but we have irrelevant lines and anti-hashes and I'll show you why for those as well now all we have to do is come in here and do a simple for Loop we just say for line and lines and then we're going to look for certain lines so if we come back I said it was going to be important if we look at this output here you could see that this line here says Hey using the drsu API to get the ntds.dit perfect and then once it's all done comes up here and it says cleaning up so we want to know really what's in between those lines and that's what we're going to do we're going to grab all this fun stuff in between those lines so if that line exists we're going to go ahead and set start to true if we are true and we eventually reach this cleaning up well then guess what we're going to go ahead and break and then we're going to get rid of the lines that we don't want we don't want that guest account we don't want that care bgt account and we don't want the computer accounts which have the dollar sign with the colon after them right here so we're going to just take all those out of the equation once they are out of the equation we're going to go ahead and just keep our relevant lines and then we're going to extract some data from that relevant line or from those relevant lines I should say and what we're going to do is we're going to basically output to two files what we want to Output is one anything that was relevant so anything in here that was relevant keeping this data the same which is going to be important for later and then also just grabbing these hashes right here so we just want to grab that NT hash out of the ntlm so going back you're going to see that that's exactly what we do so we do a regular expression search and we try to find that once we do find that we're going to go ahead and just grab that data and we're going to write to two files the ntds relevant hashes that's going to be the full hashes and then we're going to have the ntds NT hashes and that's just going to be the NT portion of it so we're going to write to this file and then basically they're going to Output two different files so if we want to take a look we absolutely can since we've already run this before all we have to do is cut out the ntds and then we have the relevant hashes let me just go ahead and come in here we have the NT hashes and then we have a file that was called dump complete we don't have to worry about it but this is what the old naming was old naming convention so if you come in here you can see that yes here we go we've got the complete file here and then we've got the ntds NT hashes and we have our two files so coming through we come in here and now we need to run hashcat so what is our Command going to look like well we're going to run hashcat with a mode of zero because that's going to be our ntlm mode and in here we're going to supply that hashes file and then we're also going to supply our word list we get this from our arguments via Arc bars now if we have additional rules in here for example we want to run a rule set it'll just append it to the end right here if we have to optimize this or we want to optimize this it'll also append that at the end once that all happens we're going to go ahead and execute our Command which is just our hash cat command here and then we're going to go through again same thing we're just going to store our output into a result here and we're going to extract the data from this now this recovered match is important let's go run hashcat really quick and talk about why if we run hashcat without this dash dash show you'll see that in here it's going to say we recovered so many hashes this instance is going to say 5 out of 6 which it is right here we have 0 out of six new not a big deal but here it's going to say yeah I recovered these perfect well once we recover these we want to know what the detail is as well so if we come in here and we do the dash dash show we'll be able to see those hashes right here so we need both of those but this is important with this recovered line because we want to know if this number here is greater than zero then yes we did recover a password of some sort so we want to continue if we did not recover a password there's no point in going on and doing the dash show and trying to do all the magic behind the scenes because we didn't crack a password so we don't need to do it coming back in here we're going to actually check for that so we're going to come in do some more regular Expressions these are not fun Chachi BT can help you write these very easily you come in here and you look look if there's a repair covered match we're going to go ahead and look we're going to say recovered hashes and then we're going to put that to an integer and then we're going to say total hash is going to put that to an integer do we actually need this probably not but if we come in here we say if recovered hashes are greater than zero then we're going to go ahead and continue on with running that dash dash show command which is done right here and then we're going to store that into a variable called show result same concept as everything before then what we're going to do is load up that ntds relevant hashes file because we're going to read from this these are the original hashes remember they are the complete hashes they look more like this so we want to take those we want to kind of search through those and that's exactly what we're going to do we're going to try to put a hash to a user so we're going to search through that and we're going to actually look for that and split the data out we're also going to map those cracked hashes to users here and we're going to do that with a very simple for Loop here for line and crack data and then we're just going to go ahead and map that data out right here okay once that data is mapped out we're going to go ahead and just put that to a new file this is a domain so whatever we supplied for our domain argument is going to be put here and then it's just going to say cracked users.txt we're going to write here as a file and we're going to say a for user password and cracked hashes put the user to the password pretty straightforward coming through here now we can say Okay passwords are cracked see this file if we didn't crack any passwords then we don't need to run most of this stuff and we can say no passwords are cracked now if we had some issue with parsing hashcat then we're going to have an error we're going to split that out here and we're just going to go ahead and kill the program off and then we have our main run down here so that is really it let's take a look at it one more time now that we know everything that we know and so if we come in here and we just run this again and we say okay I'm gonna run python test.pi is what I called it we're going to supply our domain that's mandatory marvel.local our user of Hawkeye or password or password one at our IP which could be considered dcip we might rename this here to domain controller IP because we do have to query the domain controller for this that's the domain controller IP and then the word list that we want to provide to actually crack these passwords so something like rock you just using for an example but then when we run that it's going to run Secrets dump perfect it's going to dump out everything put those two files together and then it's going to run hashcat it's going to try to crack that with rock you if it finds that any passwords were cracked it's going to go ahead and run that show command and then it's going to tie everything back to each other so that way we just have to run that and this runs in seconds just seconds it doesn't take very long at all where if I were going to do this with Excel it's going to take a little bit of time so this is awesome to just let this run and go obviously Rock use a very small word list compared it would take some time to run through a bigger word list but this is something that now I can just set on the machine put my wear list in put my rule set whatever I need to and just walk away or do something else and just let that run I don't have to do any mapping or anything else and that is the power of automation so I challenge you at the end of this video now to think about what in your life you can automate what can you do with code what can you learn to go out there and automate so I challenge you to automate something this week figure out what you can do to free up a little bit of time maybe for a little bit of that relaxation or maybe to do some work wink wink on other things so that is it for this video as always if you liked the video please do consider subscribing to the channel my name is Heath Adams AKA The Cyber mentor and I do thank you for joining me peace out
Original Description
Thank you to our sponsor Snyk! You can check out Snyk at https://snyk.co/thecybermentor
Pentests & Security Consulting: https://tcm-sec.com
Get Trained: https://academy.tcm-sec.com
Get Certified: https://certifications.tcm-sec.com
Merch: https://merch.tcm-sec.com
Sponsorship Inquiries: info@thecybermentor.com
📱Social Media📱
___________________________________________
Twitter: https://twitter.com/thecybermentor
Twitch: https://www.twitch.tv/thecybermentor
Instagram: https://instagram.com/thecybermentor
LinkedIn: https://www.linkedin.com/in/heathadams
TikTok: https://tiktok.com/@thecybermentor
Discord: https://discord.gg/tcm
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
https://www.patreon.com/thecybermentor
Support the stream (one-time): https://streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX
The Hacker Playbook 3: https://amzn.to/34XkIY2
Hacking: The Art of Exploitation: https://amzn.to/2VchDyL
The Web Application Hacker's Handbook: https://amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: https://amzn.to/31HAmVx
Linux Basics for Hackers: https://amzn.to/34WvcXP
Python Crash Course, 2nd Edition: https://amzn.to/30gINu0
Violent Python: https://amzn.to/2QoGoJn
Black Hat Python: https://amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:https://amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: https://amzn.to/30d1UW1
EVGA 2080TI: https://amzn.to/30d2lj7
MSI Z390 MotherBoard: https://amzn.to/30eu5TL
Intel 9700K: https://amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: https://amzn.to/2M638Zb
Razer Nommo Chroma Speakers: https://amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: https://amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: https://amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: https://amzn.to/31MOgpu
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from The Cyber Mentor · The Cyber Mentor · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
Writing a Pentest Report
The Cyber Mentor
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
Top 5 Internal Pentesting Methods
The Cyber Mentor
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Secured MCP Complete Guide: OWASP Top 10, Best Practices, Security Guardrails, and Compliance
Medium · AI
Whose ASN Goes on Your Leased IPv4 Prefix?
Dev.to · Artem Kohanevich
Blank Identifier: Idiomatic Go or Vulnerability Trap?
Medium · Cybersecurity
Kinetix Browser Review: The Ultimate Solution for Fast, Secure, and Private Web Surfing
Medium · Machine Learning
🎓
Tutor Explanation
DeepCamp AI