Password Attacks and Cracking Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Password Attacks and Cracking flashcards as text
What is the difference between online and offline password attacks?
Answer: Online attacks guess passwords against live services; offline attacks crack captured hashes without network interaction
Online attacks authenticate against live services (SSH, FTP, RDP) and are rate-limited and detectable, while offline attacks crack captured password hashes locally without network interaction.
What tool is commonly used in OSCP to brute-force SSH, FTP, and HTTP login services?
Answer: Hydra
Hydra is a fast and flexible network login cracker that supports dozens of protocols including SSH, FTP, HTTP, SMB, and RDP, making it the primary online brute-force tool in OSCP.
What Hydra command would brute-force SSH on host 10.10.10.10 using username 'admin' with the rockyou wordlist?
Answer: hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.10.10.10 ssh
The correct syntax uses -l for a single username, -P for a password list file, followed by the target IP and service name.
What is a 'pass-the-hash' (PtH) attack and when is it used in OSCP?
Answer: Authenticating to Windows services using an NTLM hash directly without cracking it
Pass-the-hash allows an attacker to authenticate to Windows services (SMB, WMI, RDP) using a captured NTLM hash directly, without needing to crack it to plaintext.
What type of hash does Windows use by default for local account authentication in modern systems?
Answer: NTLM (NT hash)
Modern Windows systems use NTLM hashes (specifically the NT hash, which is MD4 of the Unicode password) for local authentication stored in the SAM database.
Which hashcat attack mode uses a wordlist to crack password hashes?
Answer: Mode 0 (Straight/Wordlist attack)
Hashcat mode 0 (straight attack) uses a wordlist file, testing each word as a potential password, making it the most common starting point for cracking captured hashes.