← All OSCP Flashcard Decks

Password Attacks Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Password Attacks flashcards as text
  1. Which tool is primarily used for offline password hash cracking with GPU acceleration?

    Answer: Hashcat

    Hashcat leverages GPU acceleration for extremely fast offline hash cracking, making it the go-to tool for this purpose.

  2. Which file on a Linux system stores hashed user passwords when shadow password support is enabled?

    Answer: /etc/shadow

    /etc/shadow stores hashed passwords and account expiry data, readable only by root when shadow passwords are enabled.

  3. What Hashcat attack mode (-a) performs a straight dictionary attack using a wordlist without modifications?

    Answer: -a 0

    Hashcat's -a 0 is the straight/dictionary attack mode that reads each line of a wordlist as a candidate password.

  4. Which tool is commonly used for online brute force attacks against SSH, FTP, and HTTP services?

    Answer: Hydra

    Hydra is a fast, flexible online password cracking tool supporting numerous protocols including SSH, FTP, and HTTP/HTTPS.

  5. What is a rainbow table attack?

    Answer: A precomputed lookup table used to reverse cryptographic hash functions

    Rainbow tables are precomputed tables for reversing hash functions, trading disk storage for cracking speed via time-memory trade-offs.

  6. Which Windows file contains local user account password hashes?

    Answer: SAM

    The SAM (Security Account Manager) database stores local Windows user account password hashes and is locked during system operation.

  7. Which type of attack tries every possible character combination systematically until the correct password is found?

    Answer: Brute force attack

    A brute force attack exhaustively tries every possible combination of characters, guaranteeing success but at a potentially enormous time cost.