Password Attacks and Credential Testing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Password Attacks and Credential Testing flashcards as text
Which Hydra command correctly performs a dictionary attack against an SSH service on port 22 using a wordlist file?
Answer: hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://192.168.1.10
Hydra uses -l for a single username, -P for a password file, and the format 'protocol://target' to specify the service and host.
What type of password attack tries every possible character combination until the correct password is found?
Answer: Brute force attack
A brute force attack systematically tries every possible combination of characters until it finds the correct password, making it exhaustive but slow.
Which tool is commonly used on Linux to crack password hashes stored in the /etc/shadow file?
Answer: John the Ripper
John the Ripper is an offline password cracker widely used to crack Unix/Linux password hashes extracted from /etc/shadow.
What is the difference between an online and offline password attack?
Answer: Online attacks require an active connection to a service; offline attacks crack captured hashes locally
Online attacks authenticate directly against a live service, while offline attacks crack password hashes captured from a database or file without interacting with the service.
Which file on a Linux system stores hashed user passwords?
Answer: /etc/shadow
Modern Linux systems store hashed passwords in /etc/shadow, which is only readable by root, rather than the world-readable /etc/passwd.
What is credential stuffing?
Answer: Using username/password pairs leaked from one breach to attack other services
Credential stuffing exploits password reuse by taking credentials from known data breaches and trying them against other sites or services.
Which Hashcat attack mode (-a flag) corresponds to a straight dictionary attack?
Answer: -a 0
Hashcat uses -a 0 for a straight (wordlist/dictionary) attack, where each line in the wordlist is tried as a candidate password.