"Psudohash" can also be added to this mix of awesome tools. It can generate millions of keyword-based mutations in seconds, based on (customizable) leet character substitutions, char-case variations and literally all of the unique word mutations these two methods evaluate to, when combined. It can also append common padding values before or after each word mutation (frequently used to make passwords longer / more complex, e.g. "!@#", "!!!" and so on) as well as range of year values in various patterns (and more).
Very interesting video! Just cracking these hashes like nothing... To the sponsor segment: I don't need Passbolt, I have a password manager built-in to Firefox.
Finding the right combination of rules and wordlists is tedious, and I believe it's necessary to use a technique for filtering out duplicate attempts. The hashcat-brain allows you to do just that, which is why I blindly think it's awesome.
Great video john! But my english is a bit bad i didnt understand what "Munging" meant that you have in your title so i decided to google it and the first link that popped was of the urban dictionary and now im traumatized for my whole life!
@JohnHammond FYI: DO NOT USE THE COLABCAT IF YOU WANT TO USE GOOGLE COLAB NOTEBOOKS FOR REGULAR USE! YOU WILL GET SUSPENDED for violating their terms and conditions. Wish i knew this before trying to run the notebooks.
He mentioned that basic dictionary words should never be used in a password, but aren't these words the basis for things like diceware? Is diceware no longer considered good enough for generating passwords?
it would be good to educate your viewers about the benefits of password length in defeating brute forcing attempts at password cracking like this. would you have attempted this video demo on a password hash for a password that was between 15 and 20 characters and only used 3 simple unrelated lowercase dictionary words? That would be a great educational video to watch John. I enjoyed this video btw 👍😀
Newbies in the field think the password was quickly cracked but he already knew it and it was created in the password list so it was quickly found😅😅 The problem is that the channel owner did not tell them about this. He is proud and believes that he hacked the password
This is cool but now most often the hashes are of salted passwords , so its complex to crack those , btw this hack works on leet style wifi passwords 😅
@@jakesaunders3614 Thanks a lot mate, I didn't know that TCM Security also had a course for Web App Pentesting. I'll check it out immediately. Appreciate your help. Thanks a lot.
A bit meta, but related - after hearing about Passbolt from you and looking into it my problem with it is not the concept, but rather what seems like deceptive - at minimum misleading - marketing on their website. There’s no desktop app, but they have images meant to look like screenshots of a desktop app running on MacOS. Second, these MacOS screenshots hint at MacOS “native” - but Safari is conspicuously absent from the supported browsers. It’s disappointing that a desktop app and Safari support are missing. Disappointment, however, turns to suspicion when presented with mockups masquerading as a real product. If I feel like I’m being deceived, none of the outstanding features or benefits matter.
15 minutes of video to tell me to go to github and download a couple of lists, and that was the usable part of the video. Then you showed a very inefficient use of chatgpt, what movies to watch, a password manager and the google collab thing. If I put everything in a scale, the useless and pointless parts of the video outweight the usable ones. A lot of filler and too little substance in this one.
And if I was I'd also be very successful in getting free WiFi, but I wouldn't do anything mean like mitm bc that's actually fucked up n I'd already get free WiFi
@JohnHammond Google Collab was instantly locked after installing colabcat because of misusuing their service. I am now trying to solve this with google. :/ I could not even buy resources anymore after that.
Knew about OneRuleToRuleThemAll, but learned about CEWL & munging passwords, thank you for another great video! 🙏
"Psudohash" can also be added to this mix of awesome tools. It can generate millions of keyword-based mutations in seconds, based on (customizable) leet character substitutions, char-case variations and literally all of the unique word mutations these two methods evaluate to, when combined. It can also append common padding values before or after each word mutation (frequently used to make passwords longer / more complex, e.g. "!@#", "!!!" and so on) as well as range of year values in various patterns (and more).
You know what John?! , I've learned many things from you. Thank you 🤩
fr I'm trying to make content around cybersec myself and his is quite good!
Very interesting video! Just cracking these hashes like nothing...
To the sponsor segment: I don't need Passbolt, I have a password manager built-in to Firefox.
Finding the right combination of rules and wordlists is tedious, and I believe it's necessary to use a technique for filtering out duplicate attempts. The hashcat-brain allows you to do just that, which is why I blindly think it's awesome.
love your videos sir im 17 years,,from kenya,just got a pc now its time to try some hack the box.
I’m 17 too and I’m in the same boat as you, if you want to connect on discord we might have some tips and tricks we can exchange.
@@evanalmighty9444 hey I would like that very much drop your discord
@@evanalmighty9444 hey where did you go
Passbolt caught my interest
You are not safe if you're not using a password manager, some 2FA will also go a long way! cool content John!
What happened if our password manager got hacked?
@@venomlovekitties You have 2FA
Colabcat bans your google account if you use it
its against the eula
True. It sucks major ass that it does this.
😂 wow
How about password masking attacks? You able to showcase those techniques?
I just used AI to convert munge to python3, works great
Nice! Which Model did you use?
Guess he asked chatGPT to do it
Yes chatGPT
Great video john! But my english is a bit bad i didnt understand what "Munging" meant that you have in your title so i decided to google it and the first link that popped was of the urban dictionary and now im traumatized for my whole life!
Cewl video John! :)
Haven't watched yet, already hyped, will edit once I've watched
I would highly recommend spraygen :). And thanks for a superb video John!
@JohnHammond
FYI:
DO NOT USE THE COLABCAT IF YOU WANT TO USE GOOGLE COLAB NOTEBOOKS FOR REGULAR USE!
YOU WILL GET SUSPENDED for violating their terms and conditions. Wish i knew this before trying to run the notebooks.
😮 that munge script looks awesome
Thanks, John. Most illuminating.
He mentioned that basic dictionary words should never be used in a password, but aren't these words the basis for things like diceware? Is diceware no longer considered good enough for generating passwords?
Enjoy the movie!
isn't there a standard Python 2 to 3 converter? 2to3
I should change my passwords.
Know any rules that will play around with salts?
i just learnt this in my RED team course :) Cewl!
THANKS JOHN!!!!!!! YOU'RE THE BEST!!!!!!! ENJOY THE MOVIE...... BE BLESSED❤️🙏
This is awesome! Please do rainbow tables next 🙂
9:55
What are the odds of two different users generate the same password?
Man you're awesome.
it would be good to educate your viewers about the benefits of password length in defeating brute forcing attempts at password cracking like this. would you have attempted this video demo on a password hash for a password that was between 15 and 20 characters and only used 3 simple unrelated lowercase dictionary words? That would be a great educational video to watch John. I enjoyed this video btw 👍😀
Newbies in the field think the password was quickly cracked but he already knew it and it was created in the password list so it was quickly found😅😅 The problem is that the channel owner did not tell them about this. He is proud and believes that he hacked the password
This is cool but now most often the hashes are of salted passwords , so its complex to crack those , btw this hack works on leet style wifi passwords 😅
Thanks John.
What’s munging
Do not search it on Urban Dictionary, you have been warned. It is not the same thing there.
Cool video, thx!
Hey John, great video once again. I've been meaning to ask something. What's a good course for learning Web App Pentesting out there?
Check out TCM security’s course
@@jakesaunders3614 Thanks a lot mate, I didn't know that TCM Security also had a course for Web App Pentesting. I'll check it out immediately. Appreciate your help. Thanks a lot.
@@jakesaunders3614 Yeah that's a good one
@@anuragbiswas4337 Rana Khalil's web security academy is great too... most of it is on UA-cam.
What about the app that I download to get the password and email
How did you crack the password in only a couple minutes? I did everything you did and have been running John for half an hour.
I thought colabcat is dead, thanks to some detecting mech. of google and a use restriction that forbids password cracking
John.. John Hammond.
That’s not the type of munging I know about 🤪
Pro tip, put emoji in your password and keep it at least 12 characters long, there you have uncrackable password, no matter what you put as password.
Rule one: everything is crackable.
Rule two: saying something is unhackable, makes u get hacked.
Number one thing i learned on security+ is that nothing is impossible to crack.😉
Thank you for this Great 👍 content
But what if passbolt got hacked
My passwords will be available online like what happened with LastPass?
Bitwarden ftw
I hope that you will make a video by hacking the Mikrotik server, the latest update
Chatgpt might allucinate and add words that were not in the list
Google will ban if you is use hashcat. I been banned already
Jupiter nod output coming
What a goated video
Got stopped by Google trying to use collabcat... Something about "potential abuse". Oh well!
Hey plz make video on Krack attack or Router firmware backdooring😊
So you look and sound like Seth Rogen 😮😮
super
COOL
Good
Try 2to3 to fix python2.
M U N G
Certainly not the word we need to be using in the cyber sec space. yikes.
A bit meta, but related - after hearing about Passbolt from you and looking into it my problem with it is not the concept, but rather what seems like deceptive - at minimum misleading - marketing on their website. There’s no desktop app, but they have images meant to look like screenshots of a desktop app running on MacOS. Second, these MacOS screenshots hint at MacOS “native” - but Safari is conspicuously absent from the supported browsers.
It’s disappointing that a desktop app and Safari support are missing. Disappointment, however, turns to suspicion when presented with mockups masquerading as a real product. If I feel like I’m being deceived, none of the outstanding features or benefits matter.
I think u just hate JTR cause that had ur name there.
Be honest john 😌
❤
Mor explaining this video hash cat comment skills tools files open
*dies of cringe*
Hey calm down, you are speaking way too fast! Using online services to store password is a madness
15 minutes of video to tell me to go to github and download a couple of lists, and that was the usable part of the video.
Then you showed a very inefficient use of chatgpt, what movies to watch, a password manager and the google collab thing. If I put everything in a scale, the useless and pointless parts of the video outweight the usable ones. A lot of filler and too little substance in this one.
I DONT Recommande USING PASBOLT USE UR BRAIN
Not saying I've been cracking neighbors wifi but if I was I'd love using rules
And if I was I'd also be very successful in getting free WiFi, but I wouldn't do anything mean like mitm bc that's actually fucked up n I'd already get free WiFi
Like dead serious I don't do mitm n stuff I do get their wifi for free tho
no , no1 should use python2 anymore just edit the code and make it work for python3 print("like this dummy")
This is not working for hacking nearby wifi. Don't waste your time it's just an add video
@JohnHammond Google Collab was instantly locked after installing colabcat because of misusuing their service. I am now trying to solve this with google. :/ I could not even buy resources anymore after that.