โ† All EJPT Flashcard Decks

Password Attacks and Credential Testing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Password Attacks and Credential Testing flashcards as text
  1. Which protocol does Windows use for challenge-response authentication that can be captured and cracked offline using tools like Responder?

    Answer: NTLMv2

    NTLMv2 challenge-response hashes can be captured with Responder when clients attempt to authenticate over the network and then cracked offline with Hashcat or John.

  2. What is a password spraying attack and why is it preferred over traditional brute force in some scenarios?

    Answer: Trying one or a few common passwords against many accounts; preferred to avoid account lockouts

    Password spraying tries a small set of common passwords against many accounts, avoiding repeated failures on any single account that would trigger lockout policies.

  3. Which Hashcat rule file applies common password mutations like adding numbers and capitalizing letters?

    Answer: best64.rule

    best64.rule contains 64 of the most effective password mutation rules (capitalization, number appending, substitutions) and ships with Hashcat.

  4. What is the purpose of using a mask attack (-a 3) in Hashcat?

    Answer: To generate candidate passwords based on a defined character-set pattern

    A mask attack defines a pattern (e.g., ?u?l?l?l?d?d) that specifies the character sets for each position, generating only candidates matching that structure instead of all possible strings.

  5. Which command extracts the /etc/shadow file entries into a format John the Ripper can process when combined with /etc/passwd?

    Answer: unshadow /etc/passwd /etc/shadow > combined.txt

    The 'unshadow' utility (bundled with John the Ripper) merges /etc/passwd and /etc/shadow into a single file that John can read and crack.

  6. During a penetration test you capture an NTLMv2 hash with Responder. What is the next step to obtain plaintext credentials?

    Answer: Use Hashcat with mode -m 5600 to crack the hash offline

    NTLMv2 hashes captured by Responder are cracked offline using Hashcat with -m 5600 (NetNTLMv2) and a wordlist such as rockyou.txt.

  7. What is the main advantage of using Hashcat over John the Ripper for password cracking on a system with a modern GPU?

    Answer: Hashcat natively leverages GPU acceleration for significantly faster cracking speeds

    Hashcat is optimized to use GPU parallelism (OpenCL/CUDA), which can be orders of magnitude faster than CPU-based cracking, giving it a major speed advantage on systems with capable graphics cards.