Password Attacks Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Password Attacks flashcards as text
What is password spraying and why is it preferred over traditional brute force in Active Directory environments?
Answer: Using one common password against many accounts to stay below lockout thresholds
Password spraying tests a single common password (e.g., 'Password123!') across many accounts, avoiding per-account lockout thresholds.
Which Hashcat flag is used to specify a rules file that applies transformations to wordlist entries?
Answer: -r
Hashcat's -r flag specifies a rules file containing transformation instructions such as capitalization, substitutions, and appending digits.
What is the correct John the Ripper syntax to crack a hash file using a wordlist?
Answer: john --wordlist=wordlist.txt hashfile.txt
John the Ripper uses --wordlist= to specify the dictionary file, followed by the target hash file as a positional argument.
Which authentication protocol is particularly vulnerable to pass-the-hash attacks?
Answer: NTLM
NTLM authentication can be bypassed by presenting a captured password hash directly, without ever cracking it to obtain the plaintext.
What is the purpose of the rockyou.txt wordlist in password attacks?
Answer: It is a large compilation of real-world leaked passwords from a data breach
rockyou.txt was compiled from the 2009 RockYou data breach and contains over 14 million real passwords used by actual users.
Which tool supports HTTP POST form brute force attacks for testing web application login pages?
Answer: Hydra
Hydra supports HTTP POST form attacks via its http-post-form module, allowing customizable credential testing against web login pages.
What is credential stuffing?
Answer: Using breached username and password pairs to attempt logins on other services
Credential stuffing exploits password reuse by replaying leaked username/password pairs from one breach against other web services.