• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

John the Ripper

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
396
Reaction score
208
Points
62
Website
blackhatpakistan.net
Points
1,108
USD
1,108
John the Ripper ("john") is a password hash cracker that tests candidate strings against stolen or captured hashes until one matches - running in wordlist mode (try these passwords), rule mode (mutate the wordlist per these rules), and incremental mode (brute-force by character class). The jumbo community build handles hundreds of formats from Unix crypt variants to NTLM to application-specific hashes, and the workflow is almost always the same: identify the hash format, feed it candidates from most-likely to least-likely, and stop when the cracks you needed are out.

TL;DR - jumbo build + hash format identification first (it guesses, verify it), then wordlist -> rules -> mask escalation in order of cost. Rules are where the yield is - best64 turns one list into billions of mutations. GPU hashcat takes over when john's CPU rate becomes the bottleneck; john remains the better format-support and workflow tool. Cracking is guessing, and guessing is bounded by how the target chose their password, not by how fast your rig is.

i9qnxo.png


SETUP AND FORMAT IDENTIFICATION

Code:
john --list=formats                 every format the build supports

john --format=raw-md5 hashes.txt     explicit format when detection guesses wrong

john hash.txt                        let it detect and crack in one shot

unshadow passwd.txt shadow.txt       rebuild jumbo-compatible Unix hash files

Format tags matter: raw-sha1 and sha1crypt are different algorithms despite the same digest, and picking wrong yields zero cracks with no error. The auto-detection is right for common formats and worth trusting on the first pass.

THE THREE MODES

Code:
john --wordlist=passwords.txt hash.txt                 wordlist - candidates as-is

john --wordlist=passwords.txt --rules=best64 hash.txt    wordlist + mutation rules

john --mask='?u?l?l?l?d?d?d?d' hash.txt                  mask attack on a known pattern

john --incremental hash.txt                              full keyspace, last resort

Mask syntax: ?l lowercase, ?u uppercase, ?d digit, ?s special, ?a all classes. The mask above is one uppercase, three lowercase, four digits - if you know the site enforced that pattern, the keyspace collapses from astronomical to feasible. Incremental mode is the honest brute-force: it works on short passwords and nothing else.

96yr7d.png


RULES - WHERE THE YIELD IS

- best64 - 64 high-value rules, the default first pass, catches capitalization, trailing digits, and leet substitution.
- OneRuleToRuleThemAll - the community mega-rule set, roughly 100x the candidates, proportionally slower.
- Custom rules - append years, toggle a single digit, prepend a site token: anything you know about THIS target's password policy is a rule you write yourself.
- Duplicate mode (with two wordlists) - concatenates lists, useful for "password + extra-words" combinations.

j2np1o.png


A COMPLETE WORKFLOW

Code:
1. hashcat --help | grep -i <format> or john --list=formats   confirm format

2. john --format=raw-sha256 --wordlist=rockyou.txt --rules=best64  hash.txt   pass 1

3. rerun with --rules=OneRuleToRuleThemAll                        pass 2

4. mask with known pattern: --mask='?l?l?l?l?d?d?s?d'            pass 3

5. john --show hash.txt                  everything cracked so far, formatted

6. wordlist additions targeted at the org: company, product, season+year

--show is the report: cracked entries, their format, and the candidate that matched. Cracked hashes drop out of the active set, so re-runs skip completed work.

BENCHMARKS AND GPU OFFLOAD

Code:
john --test --format=raw-sha512    per-format CPU rate, the honest number

CPU john runs millions of guesses per second on fast hashes (raw SHA families) but drops to thousands on slow KDFs (bcrypt, scrypt, sha512crypt) - and that drop is intentional design by whoever set the password, not a flaw in john. Hashcat with GPU takes the same wordlist, rules, and masks to orders-of-magnitude higher rates on fast formats; the format coverage overlap is large but not total, and john's format-detection and file-handling remain the smoother workflow for first contact with an unknown hash dump.

p67yw7.png


SPECIAL FORMATS IN THE JUMBO BUILD

Code:
john --format=zip  archive.zip              encrypted archives

john --format=pdf  --wordlist=pw.txt doc.pdf

john --format= KeePass database.kdbx         kdbx via a converted hash blob

john --format=dynamic_104  custom netntlm    network auth captures

For any application-specific format, the pattern is: export the hash from the captured file (various converters exist for browsers, wallets, and messaging databases), identify it, then run the same wordlist-rules-mask loop.

FAQ

Q: Wordlist or mask first?

A: Wordlist if you have any signal about password habits (always). Mask if you know the enforced pattern. Incremental only when both are exhausted and the hash is fast enough to matter.

Q: Why did nothing crack when hashcat on the same box would?

A: Format mismatch is the usual cause - confirm john picked the right format, run --show to see whether anything was solved, and check the hash file actually contains what you think (truncated hex, extra whitespace, and base64-vs-hex confusion all read as "wrong format").

Q: Is a strong password safe from john?

A: Against this workflow, yes - a 12+ character random passphrase with symbols puts incremental mode at heat-death timescales on slow KDFs. The failures are always policy-created: short, patterned, reused, or derived from public facts about the person.

Q: How do defenders use john?

A: Authorized assessment: cracking password hashes recovered from an engagement to demonstrate policy failure, testing candidate employee passwords against a dumped directory, and validating that stored hashes use slow KDFs (anything fast gets flagged long before cracking).

RELATED ON BLACKHAT PAKISTAN

Password Leak Check - where the weak-password problem starts.

Hydra Brute Force Tutorial 2026 - online guessing, the other half of the same game.

Linux Privilege Escalation Checklist 2026 - where on-box hashes come from.

Metasploit Tutorial - hashdump in meterpreter feeds this workflow.
 
Last edited:
Threads
1,082Threads
Messages
2,148Messages
Members
3,708Members
Latest member
marsmarsmarsLatest member
Top