← All OSCP Flashcard Decks

Password Attacks and Cracking Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Password Attacks and Cracking flashcards as text
  1. What is a rainbow table attack and why is it less effective against salted hashes?

    Answer: A precomputed table of hash-to-plaintext mappings; salting adds random data making each hash unique and invalidating precomputed tables

    Rainbow tables are precomputed hash-to-password lookup tables; adding a unique salt to each password before hashing means the same password produces different hashes, making precomputed tables useless.

  2. What does the Responder tool do and how is it used in OSCP for credential capture?

    Answer: It poisons LLMNR/NBT-NS/mDNS broadcast queries to capture NTLMv2 hashes from network hosts

    Responder responds to LLMNR, NBT-NS, and mDNS broadcast queries with poisoned responses, tricking Windows hosts into authenticating to the attacker's machine and capturing their NTLMv2 hashes.

  3. What hashcat command cracks an NTLM hash using the rockyou wordlist?

    Answer: hashcat -a 0 -m 1000 hashes.txt /usr/share/wordlists/rockyou.txt

    The command uses -a 0 for wordlist attack mode, -m 1000 which is the hashcat module number for NTLM hashes, then specifies the hash file and wordlist.

  4. What is the purpose of adding rules (like best64.rule) when cracking passwords with hashcat?

    Answer: Rules apply transformations to wordlist words (capitalize, add numbers, leet speak) to create more password candidates

    Hashcat rules apply mutations to each wordlist entry (e.g., capitalize, append digits, leet substitutions), dramatically expanding the candidate pool without requiring a larger wordlist.

  5. What are NTLMv2 challenge-response hashes and how are they typically cracked in OSCP?

    Answer: They are captured during authentication challenges (via Responder) and cracked offline with hashcat using module 5600

    NTLMv2 hashes are challenge-response authentication tokens captured from network traffic or via tools like Responder, and are cracked offline using hashcat module 5600 (NetNTLMv2).

  6. What is the CrackMapExec (CME/NetExec) tool primarily used for in OSCP Windows environments?

    Answer: Executing commands, spraying credentials, and enumerating Windows/AD environments over SMB/WinRM

    CrackMapExec (now NetExec) is a Swiss army knife for Windows/AD environments, supporting credential spraying, command execution, secrets dumping, and enumeration over SMB, WinRM, LDAP, and MSSQL.