โ† All EJPT Flashcard Decks

Password Attacks and Cracking Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Password Attacks and Cracking flashcards as text
  1. Which tool is used to extract password hashes from a Windows SAM database?

    Answer: Mimikatz

    Mimikatz is a post-exploitation tool that can extract NTLM hashes, plaintext credentials, and Kerberos tickets from Windows memory and the SAM database.

  2. What is the purpose of the 'unshadow' command in John the Ripper?

    Answer: It combines /etc/passwd and /etc/shadow into a single crackable file

    The unshadow command merges /etc/passwd and /etc/shadow into a single file in the format John the Ripper needs to crack Linux password hashes.

  3. In Hashcat mask attacks, what character set does '?d' represent?

    Answer: Digits 0-9

    In Hashcat mask syntax, ?d represents the digit character set (0-9), ?l is lowercase, ?u is uppercase, and ?s is special characters.

  4. Which attack method is most effective against WPA2 Wi-Fi passwords?

    Answer: Capturing the 4-way handshake and performing offline dictionary/brute-force cracking

    WPA2 cracking requires capturing the 4-way EAPOL handshake (using tools like airodump-ng), then cracking the PBKDF2-HMAC-SHA1 hash offline with Hashcat or Aircrack-ng.

  5. What is a hybrid attack in the context of password cracking?

    Answer: An attack that combines a wordlist with a brute-force mask appended or prepended to each word

    A hybrid attack takes words from a dictionary and appends or prepends brute-force character combinations to each word, targeting passwords like 'password123' or 'abc!password'.

  6. Which Medusa flag specifies the password file to use during a brute-force attack?

    Answer: -P

    In Medusa, -P specifies a file containing a list of passwords to try, while -p specifies a single password to test.

  7. What is a hash collision in the context of password security?

    Answer: When two different inputs produce the same hash output

    A hash collision occurs when two different plaintext inputs produce the same hash value, which can potentially be exploited to authenticate without knowing the original password.