Password Attacks and Cracking Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Password Attacks and Cracking flashcards as text
Which command correctly invokes Hydra to brute-force SSH on a non-standard port 2222?
Answer: hydra -l admin -P passwords.txt -s 2222 target ssh
Hydra uses -s to specify a non-standard port, so 'hydra -l admin -P passwords.txt -s 2222 target ssh' targets SSH on port 2222.
What is the main advantage of bcrypt over MD5 for password storage?
Answer: bcrypt is intentionally slow and includes a work factor that makes brute-force cracking much harder
bcrypt uses a configurable work factor (cost parameter) that makes it computationally expensive to compute, drastically slowing brute-force and dictionary attacks compared to fast hashes like MD5.
When performing a password attack, what does the term 'offline cracking' mean?
Answer: Cracking captured hashes on a local machine without interacting with the target service
Offline cracking means you've obtained hash values and crack them locally, avoiding account lockouts and network detection since you're not making login attempts against the live service.
Which eJPT-relevant scenario best describes when you would use Mimikatz's 'sekurlsa::logonpasswords' module?
Answer: To dump cleartext credentials and hashes from Windows LSASS process memory after gaining admin access
sekurlsa::logonpasswords dumps credentials cached in the LSASS process memory on Windows, often revealing cleartext passwords of recently logged-in users, but requires admin/SYSTEM privileges.
What flag in John the Ripper specifies using a custom wordlist for cracking?
Answer: john --wordlist=wordlist.txt hash.txt
The --wordlist flag in John the Ripper specifies the path to a custom wordlist file, as in 'john --wordlist=rockyou.txt hashes.txt'.
What is the risk of high thread counts (-t flag) when using Hydra against a live service?
Answer: It can trigger account lockouts, IDS alerts, or overwhelm the target service
Too many concurrent threads in Hydra can lock accounts, trigger intrusion detection alerts, or even crash unstable services, making it important to tune thread counts carefully.
Which hash type would you specify with '-m 22000' in Hashcat?
Answer: WPA2-PBKDF2-PMKID+EAPOL
Hashcat mode 22000 targets WPA2 (PBKDF2-HMAC-SHA1) hashes in the modern hcwpax format, used to crack captured Wi-Fi handshakes.