โ† All OSCP Flashcard Decks

Password Attacks and Cracking Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Password Attacks and Cracking flashcards as text
  1. What is credential spraying and why is it preferred over traditional brute-force in Active Directory environments?

    Answer: Testing one password against all users avoids account lockout policies that trigger after multiple failed attempts per account

    Credential spraying tries a single common password against many accounts, staying under the failed-attempt threshold per account and avoiding lockouts, unlike brute-force which exhausts all passwords against one account.

  2. What is John the Ripper's primary use case versus hashcat in an OSCP context?

    Answer: John is CPU-based and good for auto-detecting hash types; hashcat is GPU-accelerated and faster for bulk cracking

    John the Ripper auto-detects hash formats and is CPU-based making it versatile for quick analysis, while hashcat leverages GPU acceleration for much faster bulk password cracking.

  3. Which tool can extract password hashes from a Windows system remotely using administrative credentials over SMB?

    Answer: secretsdump.py (impacket)

    Impacket's secretsdump.py can remotely dump SAM hashes, NTDS.DIT hashes, and LSA secrets from Windows systems over SMB when valid administrative credentials are available.

  4. What is the default password for many network devices and why is testing for default credentials important in OSCP?

    Answer: Vendors ship devices with known default credentials that administrators often forget to change, providing easy access

    Many administrators fail to change vendor-supplied default credentials, making default credential testing one of the highest-value, lowest-effort checks during OSCP penetration testing.

  5. What is a mask attack in hashcat and when would you use it?

    Answer: A mask attack defines character set patterns (e.g., 8 chars, uppercase + digits) to generate password candidates matching known policies

    Hashcat mask attacks use character set placeholders (e.g., ?u?l?l?l?d?d?d?d for 1 uppercase + 3 lowercase + 4 digits) to generate candidates matching a known password policy without using a wordlist.

  6. What is a Kerberoasting attack and what does it target?

    Answer: Requesting service tickets for SPN-registered accounts and cracking the ticket's embedded hash offline

    Kerberoasting requests TGS service tickets for accounts with SPNs registered, which are encrypted with the service account's password hash, allowing offline cracking of the hash without requiring high privileges.