Password Attacks and Cracking Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Password Attacks and Cracking flashcards as text
What purpose does salting a password hash serve?
Answer: It adds a random value to the password before hashing, defeating precomputed rainbow tables
A salt is a random value appended or prepended to a password before hashing, ensuring identical passwords produce different hashes and defeating rainbow table attacks.
Which Hydra flag specifies the target username during a brute-force attack?
Answer: -l
The -l flag in Hydra specifies a single username to target, while -L specifies a file containing multiple usernames.
What type of attack involves testing a few common passwords against many accounts to avoid account lockouts?
Answer: Password spraying
Password spraying tests a small set of common passwords (like 'Password1!') across many accounts, staying below lockout thresholds by limiting attempts per account.
Which John the Ripper flag displays the cracked passwords found so far?
Answer: john --show
Running 'john --show ' displays all previously cracked passwords stored in John's pot file for the given hash file.
What is credential stuffing?
Answer: Using leaked username/password pairs from one breach to try logging into other services
Credential stuffing exploits password reuse by testing username/password pairs leaked from one service against other platforms.
Which hash format does Windows NTLM use?
Answer: MD4
Windows NTLM hashes are computed using the MD4 algorithm applied to the UTF-16LE encoded password.
What does the Hashcat -m flag specify?
Answer: The hash type or algorithm to crack
In Hashcat, -m specifies the hash type (e.g., -m 1000 for NTLM, -m 0 for MD5), telling it which algorithm to use during cracking.