Hashcat Beginner's guide to cracking MD5 hashes with the Rockyou wordlist

Поділитися
Вставка
  • Опубліковано 2 січ 2025

КОМЕНТАРІ •

  • @TheAwillz
    @TheAwillz 4 місяці тому +1

    Yo this channel is a gem!
    Really good video, good editing, very good presentation and tone, you were made for this bro.
    Insightful, helpful, taking things step by step.
    This channel is going to blow up bro

    • @mindofpaul9543
      @mindofpaul9543  4 місяці тому +3

      @@TheAwillz I really appreciate that! Life has kind of gotten in the way of me making videos, but I need to get back at it.

    • @TheAwillz
      @TheAwillz 4 місяці тому

      @@mindofpaul9543 please do

  • @TSlegacy9
    @TSlegacy9 2 місяці тому

    really helpful thanks for going over the whole process so there are no questions left to ask about anything

  • @manoelaldrine1602
    @manoelaldrine1602 Рік тому

    just gained a subscriber, your explanation is cool, simple, detailed and everything amazing. wish all subscribers paid attention to all little details like you

  • @albertwesker2k24
    @albertwesker2k24 4 місяці тому +1

    Bro comeback when you have time. It would be great to see some other tutorials from you, like John the ripper and the other tools. This video was really straightforward and clear. I'm pretty advanced in Windows 11, I know a bunch of things and I made some programs in python too but I'm dumb as fck in Linux. 😂 I subscribed.

  • @jaylee5031
    @jaylee5031 9 місяців тому

    Dude the video I learned this was taken down, but your use of text editor was way better! Subscribed and favorited this video.

  • @PassionateAnalyst
    @PassionateAnalyst Рік тому +2

    Awesome!! Thanks in a hundred folds for the guide.. It was quite refreshing.

  • @Glock725
    @Glock725 Місяць тому

    thank you... there are not many videos of this clarity about hashcat tutorial

  • @srikumarma
    @srikumarma Рік тому

    Thank you so much man, sat around watched over 20 videos. None of them helped but you!
    😃

  • @subliminalcipher5660
    @subliminalcipher5660 9 місяців тому

    Great video. Extremely helpful in completing the challenge. Explained perfectly. Much appreciated.

  • @anirudh5101
    @anirudh5101 7 місяців тому

    Dude you explained each and everything so perfectly.

  • @matthewstocker8816
    @matthewstocker8816 4 місяці тому

    This was amazing. It would have taken me forever to do this without your help. Thanks.

  • @DARG0N
    @DARG0N 9 місяців тому

    Thank you, I spent a while trying to figure out how to use john but this was way easier.

  • @legendofgeoffry6521
    @legendofgeoffry6521 2 роки тому

    4:18 princess paul is back! - "not off the top of my head"

  • @MichaelSantimauro
    @MichaelSantimauro Рік тому

    Amazing video, I would have to say to date this is one of the most helpful videos explained exactly how I needed it! thank you so much!

    • @mindofpaul9543
      @mindofpaul9543  Рік тому +1

      Thank you for the compliment! And I am glad I could help!

  • @TeeHud
    @TeeHud 9 місяців тому

    thanks from Canada... you talked it out and walked it out !!

  • @nazulgomez8594
    @nazulgomez8594 3 місяці тому

    This video was incredibly helpful thank you so much

  • @lilnagoo85
    @lilnagoo85 3 місяці тому

    bro is a legend keep going much love

  • @xDEADxINSIDEx
    @xDEADxINSIDEx 7 місяців тому

    🎉thank you for being the first to make it simple

  • @samratgupta731
    @samratgupta731 Рік тому

    it is always showing "Status...........: Exhausted", how to fix it I already tried in many different ways.

  • @Arno_Saks
    @Arno_Saks 11 місяців тому

    the specified parameter cannot use 'file.name' as a value- must be a number how i can fix it

  • @hanhatquang6405
    @hanhatquang6405 Рік тому +2

    Amazing, I love your Tutorial

  • @AndrewZimba-w5r
    @AndrewZimba-w5r 7 місяців тому

    Thank you,
    And do you mind doing for SHA-1 and SHA-256

  • @montypythondot
    @montypythondot 10 місяців тому +1

    Thank you so much bro!! This video helped me a lot ;)

  • @TapThatCuz_
    @TapThatCuz_ 9 місяців тому

    Thanks for the helpful insight, well explained and keep up the good work

  • @zilog1
    @zilog1 Рік тому +1

    hye nice work dude. great video. hope YT treats you well

  • @MunishMehta-i1p
    @MunishMehta-i1p 4 місяці тому

    Nice video. However, my hashcat failed with reason "* Device #1: Not enough allocatable device memory for this attack.". I am running kali in a virtualbox

  • @lottan2197
    @lottan2197 Рік тому +3

    simple and easy to digest. thanks

  • @itzyaboyj4199
    @itzyaboyj4199 10 місяців тому

    The expliot doesnt crack the hash? please help

  • @ahmadkhalidhotak9399
    @ahmadkhalidhotak9399 Рік тому

    You had a 6317.2 kH/s which is a very high speed, which GPU and drivers are you using my friend ?

  • @marg4686
    @marg4686 Рік тому +3

    This was a great video. And I thought your editing was great.

    • @mindofpaul9543
      @mindofpaul9543  Рік тому

      Thank you! I am glad I could help and appreciate the compliments!

  • @itzyaboyj4199
    @itzyaboyj4199 10 місяців тому

    TypeError: Strings must be encoded before hasing, it cant cracked the hash. what am I doing wrong brother I followed your steps.

  • @jamesrushforth1026
    @jamesrushforth1026 2 роки тому +2

    Hi mate you explained it realy well thanks , ive been practicing on my own wifi i manged to get the 4 way handshake but its downloaded in .cap file and i have no idea what to do now i cant find good information anywhere, first i tried to convert it on the hashcat wesite and said it was too big so then finally found a fourm on there showed me how to clean it in wire shark then now its a txt file but when i try put in the file path i just keep getting stuid errors like its too long no hashes or something and keeps saying no directory exists ,when it clearley does lol you have any ideas how i can sort it

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому +1

      Sounds like there are several problems happening here and would be near impossible to diagnose without being there myself. For the no directory part at least if you are on Linux make sure to use sudo when running hashcat and open your terminal in the folder that your hash file is in.

    • @jamesrushforth1026
      @jamesrushforth1026 2 роки тому +1

      @@mindofpaul9543 yeah its hard to say i haf no luck with hashcat , i read on somefourums that has the file might need to be saved in the hashcat directory. Maby ? Anywya i managed to crack it with aircrack-ng very fast haha so now made a much stronger password , just thinking what is the next fun project to try

  • @javlaboss8353
    @javlaboss8353 Рік тому

    hey paul! could you please help me with some things? Do you have a writing platform or here,how do a figure out a hashed password?

  • @CriticalGamer150
    @CriticalGamer150 2 роки тому

    How to fix the error not enough allocated memory for this attack even though I'm just using 1 hash for test still not enough allocated memory how to fix this?

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      Not easy to diagnose the problem over youtube comments, but I would guess if you are using a virtual machine you may not have enough alloted memory. Look in the virtual machine settings and allocate more ram/ memory.

  • @Giskrenov
    @Giskrenov Рік тому

    Hey so do I need to get kali to be able to run a password crack for my Trezor? Do you have any idea how to do all that. I have my seed phrases I just must have accidentally typed a wrong letter or button mashed and created a hidden passphrase wallet with the public addresses I ended up using thinking it was my main wallet. Basically need to brute force but can create my own wordlist and if it’s not within my word list how can I create a parameter to guess the password. I think my best case is I button mashed but all lower case letters with nothing else

    • @mindofpaul9543
      @mindofpaul9543  Рік тому

      I've never messed with a trezor, so not sure exactly how it would work. Hashcat is the program doing the cracking and their are versions of it for other operating systems, but I'm not sure if the syntax is the same. When I have had to make wordlists in the past I have used crunch, but that is a whole other tutorial on its own.

  • @Chris_derPole
    @Chris_derPole 4 місяці тому

    how do i get the hash without knowing the password though?

    • @mindofpaul9543
      @mindofpaul9543  4 місяці тому

      @Chris_derPole In a capture the flag contest they will probably just give you some hashes to crack. In a real life situation, you probably were able to get into someone's machine or database and their passwords are stored somewhere as hashes rather than plaintext.

  • @travispatt907
    @travispatt907 Рік тому

    Great video, thanks my guy!

  • @vinaypillai744
    @vinaypillai744 11 місяців тому

    Is it show decimal password like 1.2 or 1.34

  • @ashur6773
    @ashur6773 2 роки тому

    I can't cd into documents

  • @fredflintstoner596
    @fredflintstoner596 Рік тому

    Mrs Richards: "I paid for a room with a view !"
    Basil: (pointing to the lovely view) "That is Torquay, Madam ."
    Mrs Richards: "It's not good enough!"
    Basil: "May I ask what you were expecting to see out of a Torquay hotel bedroom window? Sydney Opera House, perhaps? the Hanging Gardens of Babylon? Herds of wildebeest sweeping majestically past?..."
    Mrs Richards: "Don't be silly! I expect to be able to see the sea!"
    Basil: "You can see the sea, it's over there between the land and the sky."
    Mrs Richards: "I'm not satisfied. But I shall stay. But I expect a reduction."
    Basil: "Why?! Because Krakatoa's not erupting at the moment?"

  • @davidduque2202
    @davidduque2202 2 роки тому

    thank you dude you made it very easy to understand keep it up

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      Thanks. Glad I could help!

    • @Peaker20
      @Peaker20 2 роки тому +1

      Why don't you upload new videos?
      After this video i want you to make tutorial lol ❤️❤️

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      @@Peaker20 I appreciate that. School has been busy and I switched to software development so all of my time has been on java rather than security. Might switch it up and make some beginner coding videos

    • @Peaker20
      @Peaker20 2 роки тому +1

      @@mindofpaul9543 it's okay good luck ❤️, i still waiting for your easy explaining of any tutorial,also i need to learn Java , waiting for you bro❤️ you got my subscripe.

  • @awebuser5914
    @awebuser5914 Рік тому

    Looks interesting, but the examples you show are ridiculously easy. What happens if you use a more useful example of a passphrase like: "yourdogwagshistailalot"? I can only assume the difficulty goes absolutely exponential with that many words. You may want to try a SHA256 of the above and see if it's even crackable.
    Also, something like the Rocky list seems to be ridiculous overkill for passphrases since the length of time to iterate though the entire list must be colossal! A simple list of common English vocabulary (probably less than 10,000 words) would seem to be far more efficient.

    • @mindofpaul9543
      @mindofpaul9543  Рік тому

      So like the title of the video says, this is a beginner's guide. There are many different things you can do with hashcat and this is the simplest. This is more geared to people just starting, or doing their first hackathon. And yes, the more complex the password, the more intensive the process is to crack it. You can quickly go from just a few minutes to crack to hours just by adding a few characters. And the reason for the rockyou list is that it is a document of people's actual passwords from a large data breach. You can hope to get a match from that before creating your own wordlists which is why it usually comes pre installed on kali linux.

    • @awebuser5914
      @awebuser5914 Рік тому

      ​@@mindofpaul9543 "the reason for the rockyou list is that it is a document of people's actual passwords from a large data breach"
      Sort-of, it's one of _many_ combinations of passwords from data breaches, then padded with Wiki word lists, dictionary lists and all sorts of other pointless garbage that a Hashcat ruleset could do more efficiently (random character positions in known passwords, etc.)
      By the look of it, the entire password-cracking "game" is rapidly dying since security of algorithms against brute-force attacks (work-factor) has jumped by a few orders of magnitude since MD5. Gone are the days where lazy admins will use the lamest hashing algo they could find since "it's good enough"; multi-million dollar lawsuits have made taking security seriously a thing. Bcrypt, Argon2id and others make brute-forcing a rather pointless exercise, unless you're the NSA or other agency with extremely deep pockets and a specific mission (cracking Facebook passwords won't qualify!).

  • @rio2rio27
    @rio2rio27 2 роки тому

    sir how to fixerror "no hashes loaded"

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      Are you saving your text file with the hashes in it before trying to run hashcat? And make sure your path and file name are all spelled correctly in your hashcat command.

    • @afriotriputras7517
      @afriotriputras7517 2 роки тому

      @@mindofpaul9543 can you decrypt this code sir "d0071ee9bf9b9cf772c0f2503123b35e"

  • @poorinvestor
    @poorinvestor 2 роки тому +1

    Great intro my friend! Need more subs

  • @ricardozanandrea288
    @ricardozanandrea288 Місяць тому

    Really good video man! ty

  • @Outlaw_Moki
    @Outlaw_Moki 2 роки тому

    I followed you step by step but I still get an error /:

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      An error could occur for many reasons like a mistype or hardware limitations. Google hashcat and the error you got and hopefully a forum will have a fix for you. Usually someone else has experienced the same issue and has posted about it somewhere.

  • @vortexflickens2
    @vortexflickens2 2 роки тому +1

    can u hack any online pages with hashcat

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      From what I understand, hashcat is mostly for cracking hashed passwords. When I have done websites in competitions we would use things like burpsuite and chrome tools. If you go to hackthebox.com and follow their beginner path, they will show you how to crack websites.

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      And just to clarify, you may come across a list of encrypted passwords with those other tools, then you could use haschat to figure out what those passwords are.

    • @vortexflickens2
      @vortexflickens2 2 роки тому +1

      @@mindofpaul9543 tnx for the info

  • @jesikaemma
    @jesikaemma Рік тому

    you are great at explaining i like your video do more for us thanks
    ❤❤❤❤❤❤❤

  • @JerrySwan
    @JerrySwan 2 роки тому +1

    Should rename channel to Huge Mind of Paul

  • @koffiepou3030
    @koffiepou3030 Рік тому

    Very good and easy explain Bravo

  • @alexidk4641
    @alexidk4641 2 роки тому +1

    this video have some times behind him but really good ty for your help brother ( i'm not really good with your language : p )

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      Thank you for your compliment. Glad I could help!

  • @austinweaver8112
    @austinweaver8112 6 місяців тому

    super helpful, thanks!

  • @wesleystoudenmier-z5v
    @wesleystoudenmier-z5v 9 місяців тому

    Mad helpful, thanks man

  • @haribardolia5505
    @haribardolia5505 2 роки тому

    yes sir, you explained it good 👍

  • @esmetakhom9259
    @esmetakhom9259 Рік тому

    Great video brother...

  • @furyzlm7853
    @furyzlm7853 2 роки тому +1

    tysm that was really helpful

  • @TheRandom_Uzer
    @TheRandom_Uzer 2 роки тому +1

    Thx abunch 😊

  • @iustin1174
    @iustin1174 2 роки тому +1

    thx very much

  • @HungNguyen-il4cg
    @HungNguyen-il4cg 4 місяці тому

    thank you so muchhhhhh

  • @shriram5494
    @shriram5494 Рік тому

    The Pokemon music rip off got me

    • @mindofpaul9543
      @mindofpaul9543  Рік тому

      You're telling me not everyone listens to 8-bit music all the time? Lol. The reality is trying to find decent copyright free music is not the easiest task.

  • @tis_official._
    @tis_official._ 29 днів тому

    Please help me UA-cam family
    Session.....: hashcat
    Status........: exhausted
    Please help guys It's confusing

  • @johnaloe
    @johnaloe 2 роки тому

    thank you

  • @strudolla4684
    @strudolla4684 2 роки тому

    thank you so muchh

  • @siyambhuiyan8798
    @siyambhuiyan8798 Рік тому

    thanks

  • @xanris3271
    @xanris3271 9 місяців тому

    ole kali linux looking....

  • @rupesh9110
    @rupesh9110 2 роки тому +1

    thx sir

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому +1

      No problem. Glad I could help!

    • @rupesh9110
      @rupesh9110 2 роки тому +2

      @@mindofpaul9543 pls keep uploading content about Linux and hashcat

    • @rupesh9110
      @rupesh9110 2 роки тому

      When I am using hashcat it is showing
      device #1: not enough allocatable device memory for this attack.

    • @rupesh9110
      @rupesh9110 2 роки тому

      Pls help

    • @mindofpaul9543
      @mindofpaul9543  2 роки тому

      @@rupesh9110 I haven't encountered that myself, but I looked it up. Are you using a virtual machine? On an actual machine it will use the GPU, but virtual machines don't get access to it fully, so instead it uses RAM. Try turning up your virtual machine settings to use more RAM. I use VirtualBox, and that setting is under system in the Virtualbox manager.

  • @wilmerbossley6742
    @wilmerbossley6742 2 роки тому

    😄 քʀօʍօֆʍ

  • @confidencenwanyanwu9975
    @confidencenwanyanwu9975 6 місяців тому

    Next time please zoom. Everything was really small

    • @vitamin_protein001
      @vitamin_protein001 6 місяців тому

      Are you blind? How big do you want it to be?

    • @confidencenwanyanwu9975
      @confidencenwanyanwu9975 6 місяців тому

      You think you know it all? I got a better video than this wack you call a video.

  • @mariojules1814
    @mariojules1814 9 місяців тому

    Dude, you rock

  • @MichaelSantimauro
    @MichaelSantimauro Рік тому

    after i used this last night, for some reason my rockyou.txt turned into a rockyou.txt.gz, and i have no idea to get it back how it was. Any idea ?

    • @mindofpaul9543
      @mindofpaul9543  Рік тому

      Not sure why that would happen, but a .gz is just a zipped file so you just need to unzip it. Pretty sure the syntax is gzip -d file.gz

  • @deogipark6053
    @deogipark6053 Рік тому

    I have rock you.txt.gz, not rock you.txt. What should I do?

    • @mindofpaul9543
      @mindofpaul9543  Рік тому +2

      That's the zipped version. This command should unzip it. gzip -d rockyou.txt.gz

    • @deogipark6053
      @deogipark6053 Рік тому

      Thank you have a nice day!