7.3 Network Service Brute-Forcing & Offline Hash Cracking
Key Takeaways
Online service brute-forcing directly tests credentials against running network daemons (SSH, FTP, SMB, RDP) using tools like THC-Hydra, Medusa, and Metasploit auxiliary scanners.
Online credential attacks carry significant operational risks, including account lockouts, defensive telemetry generation, and service denial, requiring disciplined threading and throttling.
Offline password cracking evaluates candidate passwords against extracted cryptographic hashes using John the Ripper and Hashcat, eliminating lockout risks and achieving immense calculation speeds.
Successful offline cracking relies on accurately determining the hash algorithm, character lengths, and salt formats to supply the correct hash mode in Hashcat (-m) or format tag in John (--format).
7.3 Network Service Brute-Forcing & Offline Hash Cracking
Authentication mechanisms form the primary gatekeeping layer for systems, administrative interfaces, and network services. During a penetration test, security professionals frequently uncover network services that are fully patched against known remote code execution vulnerabilities but remain vulnerable to authentication abuse due to weak, default, or reused credentials. In other scenarios, post-exploitation access on a single host yields encrypted or hashed credentials stored in memory, configuration files, or operating system databases.
To compromise additional network services and advance lateral movement, penetration testers utilize two distinct credential attack methodologies:
- Online Service Brute-Forcing: Directly transmitting authentication attempts over the network against active services (such as SSH, SMB, FTP, or RDP).
- Offline Hash Cracking: Utilizing high-performance local computing resources (CPUs and GPUs) to crack extracted cryptographic hashes without interacting with the target system.
Online Service Brute-Forcing Attacks
Online brute-forcing involves systematically submitting candidate usernames and passwords against an active network authentication daemon until a valid combination is accepted. Unlike offline attacks, online attacks generate network traffic, consume daemon resources, and interact directly with defensive controls.
+-----------------------------------------------------------------------------------------+
| ONLINE BRUTE-FORCE VS. OFFLINE CRACKING TAXONOMY |
+------------------------------------+----------------------------------------------------+
| ONLINE SERVICE BRUTE-FORCING | OFFLINE HASH CRACKING |
+------------------------------------+----------------------------------------------------+
| Target: Live network daemon | Target: Dumped cryptographic hash file |
| Medium: Network protocol requests | Medium: Local CPU / GPU calculation loops |
| Speed: 1 to 50 attempts/second | Speed: Millions to Billions of attempts/second |
| Lockout Risk: HIGH | Lockout Risk: ZERO |
| Network Noise: HIGH (Alerts IDS) | Network Noise: ZERO (Passive local computation) |
| Primary Tools: Hydra, Medusa, MSF | Primary Tools: Hashcat, John the Ripper |
+------------------------------------+----------------------------------------------------+
THC-Hydra Fundamentals & Protocol Support
THC-Hydra is the industry-standard multi-threaded network logon cracker. It supports an extensive array of network protocols, including SSH, FTP, SMB, RDP, MySQL, PostgreSQL, MSSQL, HTTP-POST-Form, POP3, IMAP, and Telnet.
Hydra utilizes specific command-line flags to control target specification, credential lists, concurrency, and output formatting:
-l <username>: Specifies a single static username to test.-L <file>: Specifies a path to a file containing a list of target usernames.-p <password>: Specifies a single static password to test against multiple users.-P <file>: Specifies a path to a dictionary file (wordlist) containing candidate passwords.-s <port>: Specifies a custom, non-standard service port.-t <tasks>: Sets the number of parallel tasks (threads) to run concurrently.-v / -V: Enables verbose or very verbose mode, displaying tested credential pairs in real-time.-f: Instructs Hydra to halt execution immediately upon discovering the first valid pair for a target.-o <file>: Writes identified valid credentials to an external output file.
Practical Hydra Command Recipes
# 1. SSH Brute-Forcing (Throttled to 4 threads to prevent daemon rate-limiting)
hydra -l root -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.50 -t 4 -f -vV
# 2. FTP Brute-Forcing with a username list and password wordlist
hydra -L users.txt -P /usr/share/wordlists/rockyou.txt ftp://192.168.1.50 -t 16 -f
# 3. SMB Brute-Forcing against a Windows target
hydra -l Administrator -P /usr/share/wordlists/rockyou.txt smb://192.168.1.50 -t 4 -f
# 4. Remote Desktop (RDP) Brute-Forcing
hydra -l admin -P passwords.txt rdp://192.168.1.50 -t 4 -f
# 5. MySQL Database Brute-Forcing on default port 3306
hydra -l root -P passwords.txt mysql://192.168.1.50 -f
# 6. Password Spraying: Testing one common password across an entire user list
hydra -L /usr/share/seclists/Usernames/top-usernames-shortlist.txt -p 'Winter2026!' 192.168.1.50 smb -t 4
Metasploit Auxiliary Brute-Force Scanners
The Metasploit Framework contains dedicated auxiliary modules designed for credential brute-forcing. A distinct advantage of using Metasploit modules is that they automatically record discovered credentials into the framework database (creds) and can be configured to automatically spawn an interactive session upon successful authentication:
# SSH Login Scanner
msf6 > use auxiliary/scanner/ssh/ssh_login
msf6 auxiliary(scanner/ssh/ssh_login) > set RHOSTS 192.168.1.50
msf6 auxiliary(scanner/ssh/ssh_login) > set USERNAME root
msf6 auxiliary(scanner/ssh/ssh_login) > set PASS_FILE /usr/share/wordlists/rockyou.txt
msf6 auxiliary(scanner/ssh/ssh_login) > set STOP_ON_SUCCESS true
msf6 auxiliary(scanner/ssh/ssh_login) > set CREATE_SESSION true
msf6 auxiliary(scanner/ssh/ssh_login) > run
# SMB Login Scanner
msf6 > use auxiliary/scanner/smb/smb_login
msf6 auxiliary(scanner/smb/smb_login) > set RHOSTS 192.168.1.50
msf6 auxiliary(scanner/smb/smb_login) > set SMBUser Administrator
msf6 auxiliary(scanner/smb/smb_login) > set PASS_FILE /usr/share/wordlists/rockyou.txt
msf6 auxiliary(scanner/smb/smb_login) > set RECORD_GUEST false
msf6 auxiliary(scanner/smb/smb_login) > run
Defensive Controls & Operational Risks
When conducting online brute-forcing in real-world environments, penetration testers must exercise strict operational discipline:
- Account Lockout Thresholds: Enterprise Windows Active Directory domains and Linux authentication systems (
pam_faillock,pam_tally2) commonly enforce lockout policies (e.g., 3 to 5 failed attempts locks an account for 30 minutes). Aggressive brute-forcing can lock out business-critical user accounts, causing denial of service. - Password Spraying vs. Brute-Forcing: To avoid triggering lockout policies, operators employ password spraying—submitting a single commonly used password (such as
Company2026!) against hundreds of distinct usernames with substantial delays between attempts. - Connection Overhead & Daemon Stability: Protocols like RDP and SSH consume substantial CPU and memory per connection handshake. Running Hydra with high task counts (
-t 64) can exhaust target connection pools or crash legacy services.
Wordlists & Custom Dictionary Generation
Every password recovery attack relies heavily on the quality of its underlying wordlist. Penetration testers utilize both standard public dictionaries and custom, target-tailored wordlists.
Standard Wordlists: RockYou & SecLists
- RockYou (
rockyou.txt): The standard dictionary included in Kali Linux, extracted from a historical 2009 data breach containing over 14 million plain-text passwords. Located at/usr/share/wordlists/rockyou.txt.gz, it must be decompressed before initial use:# Decompress rockyou.txt on Kali Linux sudo gzip -d /usr/share/wordlists/rockyou.txt.gz # Verify file extraction and line count (~14.3 million entries) wc -l /usr/share/wordlists/rockyou.txt - SecLists: A comprehensive collection of multiple types of lists, including usernames, passwords, URLs, sensitive data patterns, and fuzzing payloads. Located in
/usr/share/seclists/.
Custom Dictionary Generation with CeWL & Crunch
Generic wordlists often fail against organizations that enforce strict password complexity rules. Attackers generate targeted dictionaries using reconnaissance data.
- CeWL (Custom Word List Generator): Spiders an organization's target website, extracts unique words from the visible HTML content, strips tags, and compiles a dictionary of company-specific vocabulary, executive names, and product lines:
# Spider website down to depth 2, extracting words with a minimum length of 6 characters cewl https://example.corp -d 2 -m 6 -w /tmp/corp_wordlist.txt - Crunch: Generates custom wordlists based on specific character sets, lengths, and patterns:
# Generate all 8-character passwords starting with 'Pass' followed by 4 digits # Pattern symbols: @ = lowercase, , = uppercase, % = numbers, ^ = symbols crunch 8 8 -t Pass%%%% -o /tmp/pattern_passwords.txt
Identifying Cryptographic Hash Types
Before launching an offline cracking tool, the penetration tester must identify the cryptographic hashing algorithm used to produce the hash. Hash identification tools analyze the string length, character encoding, and syntax delimiters.
Identification Tools: hashid & hash-identifier
# Inspect a hash using hash-identifier
hash-identifier
# Paste hash: 8846f7eaee8fb117ad06bdd830b7586c
# [!] Possible Hashs: [MD5, Domain Cached Credentials - MD4(MD4(($pass)).(strtolower($username)))]
# Identify hash and output matching Hashcat mode numbers (-m) and John format flags
hashid -m 8846f7eaee8fb117ad06bdd830b7586c
# [+] MD5 [Hashcat Mode: 0]
# [+] NTLM [Hashcat Mode: 1000]
Common Hash Signatures & Delimiters
| Algorithm | Hex Length | Salting Format | Sample Signature / Structure |
|---|---|---|---|
| MD5 | 32 hex chars | Unsalted | 8846f7eaee8fb117ad06bdd830b7586c |
| SHA-1 | 40 hex chars | Unsalted | 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12 |
| SHA-256 | 64 hex chars | Unsalted | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| NTLM (Windows) | 32 hex chars | Unsalted (MD4-based) | b4b9b02e6f09a9bd760f388b67351e2b |
| MD5-Crypt (Linux) | Variable | Salted (\$1\$) | \$1\$saltval\$jkH8sF9... |
| SHA-256-Crypt (Linux) | Variable | Salted (\$5\$) | \$5\$saltval\$9K8xZ... |
| SHA-512-Crypt (Linux) | Variable | Salted (\$6\$) | \$6\$rounds=5000\$salt\$AbCdEf... |
| Yescrypt (Linux modern) | Variable | Salted (\$y\$) | \$y\$j9T\$salt\$... |
| NetNTLMv2 | Variable | Challenge/Response | admin::DOMAIN:challenge:response |
In Unix /etc/shadow files, the identifier enclosed within the first pair of \$ characters specifies the hashing algorithm: \$1\$ denotes legacy MD5, \$5\$ denotes SHA-256, \$6\$ denotes SHA-512, and \$y\$ denotes yescrypt.
Offline Cracking with John the Ripper
John the Ripper (john) is a versatile, CPU-optimized offline password cracking tool capable of automatically detecting hash types and applying wordlist mutation rules.
Basic Wordlist Cracking Syntax
# Basic dictionary attack using rockyou.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
# Specify the explicit format flag to accelerate cracking
john --format=NT --wordlist=/usr/share/wordlists/rockyou.txt ntlm_hashes.txt
john --format=raw-md5 --wordlist=/usr/share/wordlists/rockyou.txt md5_hashes.txt
john --format=sha512crypt --wordlist=/usr/share/wordlists/rockyou.txt shadow_hashes.txt
Inspecting Cracked Passwords
John stores cracked credentials in an internal database located at ~/.john/john.pot. To view cracked passwords without rerunning the attack:
# Display cracked accounts and cleartext passwords
john --show hashes.txt
# Filter output specifically by format
john --show --format=NT ntlm_hashes.txt
Applying Mangling Rules
When a standard wordlist fails, John's rule engine can mutate dictionary words by appending numbers, capitalizing letters, or substituting leetspeak characters (--rules):
# Apply standard mangling rules to the wordlist
john --wordlist=/usr/share/wordlists/rockyou.txt --rules hashes.txt
Offline Cracking with Hashcat
Hashcat is the world's fastest password recovery utility, specifically engineered to leverage multi-threaded GPU hardware acceleration using OpenCL and CUDA. While John excels at rapid CPU-based cracking and automated format detection, Hashcat delivers orders of magnitude higher throughput when cracking unsalted hashes (like NTLM or MD5).
Hashcat Attack Modes (-a)
-a 0: Straight (Dictionary): Tests each entry from a specified wordlist directly against the hashes.-a 1: Combination: Concatenates words from two dictionaries.-a 3: Brute-Force / Mask: Generates candidates matching a defined pattern mask.
Hashcat Hash Modes (-m)
Unlike John, Hashcat requires the operator to explicitly specify the numeric hash mode using -m:
-m 0: MD5-m 100: SHA-1-m 1000: NTLM (Windows SAM database and Active Directory NTDS.dit)-m 1400: SHA-256-m 1800: SHA-512-Crypt ($6$, modern Linux/etc/shadowdefault)-m 500: MD5-Crypt ($1$, legacy Linux)-m 5600: NetNTLMv2 (Windows network authentication challenge/response)
Practical Hashcat Command Recipes
# 1. Straight dictionary attack against Windows NTLM hashes using rockyou.txt
hashcat -m 1000 -a 0 ntlm_hashes.txt /usr/share/wordlists/rockyou.txt
# 2. Dictionary attack with the Best64 mutation rule set
hashcat -m 1000 -a 0 ntlm_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
# 3. Cracking Linux /etc/shadow SHA-512 crypt hashes ($6$)
hashcat -m 1800 -a 0 shadow_hashes.txt /usr/share/wordlists/rockyou.txt
# 4. Mask Attack: Brute-forcing an 8-character password with uppercase, lowercase, and 4 digits
# Mask tokens: ?u = Upper, ?l = Lower, ?d = Digit, ?s = Special
hashcat -m 1000 -a 3 ntlm_hashes.txt ?u?l?l?l?d?d?d?d
# 5. Display cracked passwords from the hashcat.potfile
hashcat -m 1000 --show ntlm_hashes.txt
Cryptographic Hash Reference & Cracking Modes
| Algorithm / Type | Hashcat Mode (-m) | John Format (--format) | Typical Target Storage Location | Speed / Cracking Feasibility |
|---|---|---|---|---|
| NTLM | 1000 | NT | Windows SAM Hive, NTDS.dit | Extremely Fast (Billions/sec on GPU; unsalted) |
| MD5 (Raw) | 0 | raw-md5 | Web applications, legacy databases | Extremely Fast (Billions/sec on GPU; unsalted) |
| SHA-1 (Raw) | 100 | raw-sha1 | Legacy codebases, Git repositories | Fast (Hundreds of Millions/sec on GPU) |
| SHA-256 (Raw) | 1400 | raw-sha256 | Modern web applications, API tokens | Fast (Hundreds of Millions/sec on GPU) |
| SHA-512-Crypt | 1800 | sha512crypt | Linux /etc/shadow (\$6\$) | Slow (Thousands of rounds of hashing; salted) |
| MD5-Crypt | 500 | md5crypt | Legacy Linux /etc/shadow (\$1\$) | Moderate (Salted, iterated MD5) |
| NetNTLMv2 | 5600 | netntlmv2 | Responder SMB/LLMNR captures | Fast (Vulnerable to dictionary attacks) |
| Kerberos 5 TGS | 13100 | krb5tgs | Active Directory Kerberoasting | Moderate (Standard Active Directory wordlists) |
Online Service Brute-Forcing Syntax Reference
| Protocol | Default Port | Primary Tool | Command Syntax Example | Recommended Threading |
|---|---|---|---|---|
| SSH | 22 | Hydra | hydra -l root -P rockyou.txt ssh://<IP> -t 4 -f | -t 4 (Avoids daemon rate limits) |
| FTP | 21 | Hydra | hydra -L users.txt -P rockyou.txt ftp://<IP> -t 16 -f | -t 16 (FTP daemons handle concurrency) |
| SMB | 445 | Hydra | hydra -l Administrator -P rockyou.txt smb://<IP> -t 4 -f | -t 4 (Prevents IPC connection drops) |
| RDP | 3389 | Hydra | hydra -l admin -P passwords.txt rdp://<IP> -t 4 -f | -t 4 (RDP sessions are resource heavy) |
| MySQL | 3306 | Hydra | hydra -l root -P rockyou.txt mysql://<IP> -t 8 -f | -t 8 (Check for max_connections limit) |
| SSH | 22 | Metasploit | use auxiliary/scanner/ssh/ssh_login | Set STOP_ON_SUCCESS true |
| SMB | 445 | Metasploit | use auxiliary/scanner/smb/smb_login | Set CREATE_SESSION true |
A penetration tester extracts a local password hash from a compromised Windows workstation's SAM database: 'b4b9b02e6f09a9bd760f388b67351e2b'. Which Hashcat command properly executes a straight dictionary attack against this hash using rockyou.txt?
hashcat -m 0 -a 3 sam_hashes.txt /usr/share/wordlists/rockyou.txt
hashcat -m 1800 -a 0 sam_hashes.txt /usr/share/wordlists/rockyou.txt
hashcat -m 1000 -a 0 sam_hashes.txt /usr/share/wordlists/rockyou.txt
hashcat -m 5600 -a 1 sam_hashes.txt /usr/share/wordlists/rockyou.txt
Which THC-Hydra command-line option instructs the utility to terminate testing against a target immediately upon finding the first valid username and password pair?
-vV
-f
-o
-s
During a penetration test on a Linux server, a tester inspects /etc/shadow and finds a password hash beginning with 'k8Z...'. Which cryptographic algorithm was used to generate this password hash?
MD5-crypt
SHA-256-crypt
Blowfish / bcrypt
SHA-512-crypt
Sections you finish are checked off in the contents.