Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
cracken — un generador rápido de listas de palabras para contraseñas, herramienta de creación de Smartlist y análisis de máscaras híbridas de contraseñas, escrita en Rust puro y seguro | Kitploit
Herramientas/GitHubGitHub/shmuelamar/cracken
Descifrado de ContraseñasAtaques de ContraseñasAnálisis de HashPruebas de Penetración
GitHubshmuelamar/cracken

cracken

un generador rápido de listas de palabras para contraseñas, herramienta de creación de Smartlist y análisis de máscaras híbridas de contraseñas, escrita en Rust puro y seguro

Ver Repositorio
3742612hace 4 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Cracken

cracken crate cracken version cracken documentation cracken total downloads

Cracken es un rápido generador de listas de palabras, creador de smartlists y herramienta de análisis de máscaras híbridas para contraseñas, escrito en Rust puro y seguro (más información en talk/). Inspirado por grandes herramientas como maskprocessor, hashcat, Crunch y los 🤗 tokenizers de HuggingFace.

¿Qué? ¿Por qué? ¿¿Cómo??

En DeepSec2021 presentamos un nuevo método para analizar contraseñas como Máscaras Híbridas, explotando subcadenas comunes en contraseñas mediante tokenizadores NLP (más información en talk/).

Nuestro método divide una contraseña en sus subpalabras en lugar de solo una máscara de caracteres. HelloWorld123! dividido en ['Hello', 'World', '123!'] ya que estas tres subpalabras son muy comunes en otras contraseñas.

Máscaras Híbridas y Smartlists

  • 📄 Smartlists - Listas compactas y representativas de subpalabras creadas a partir de contraseñas mediante tokenizadores NLP.
  • 🎭 Máscara Híbrida - Representación de una contraseña como combinación de listas de palabras y caracteres (ej. ?w1?w2?l?d)

Analizando contraseñas de RockYou con Smartlists y Máscaras Híbridas:

Top25 Hybrid Masks from RockYou

tabla completa aquí

Cracken 🐙 se utiliza para:

  • ✅ Generar Máscaras Híbridas MUY MUY RÁPIDO 🦸⚡💨 (ver sección rendimiento)
  • ✅ Construir Smartlists - lista compacta y representativa de subpalabras a partir de archivos de contraseñas (usando tokenizers de 🤗 HuggingFace)
  • ✅ Analizar contraseñas para sus Máscaras Híbridas - construir estadísticas para mejores candidatos a contraseña (nuevamente muy rápido)

Posibles flujos de trabajo con Cracken:

Simple:

  1. Generar candidatos de lista de palabras a partir de una máscara híbrida - ej. cracken -w rockyou.txt -w 100-most-common.txt '?w1?w2?d?d?d?d?s'
  2. Puedes canalizar las contraseñas que genera Cracken a hashcat, john o tu crackeador de contraseñas favorito.

Avanzado:

  1. Crear una Smartlist a partir de contraseñas existentes - cracken create
  2. Analizar una lista de contraseñas en texto plano - cracken entropy
  3. Usar las Máscaras Híbridas más frecuentes para generar candidatos a contraseña rápidamente - cracken generate -i hybrid-masks.txt

Para más detalles, ver sección Uso

Primeros pasos

descarga (solo linux por ahora): última versión 🔗

Para más opciones de instalación, ver sección instalación

ejecuta Cracken:

generar todas las palabras de longitud 8 que comienzan con mayúscula seguidas de 6 minúsculas y luego un dígito:

root@kitploit:~
$ cracken -o pwdz.lst '?u?l?l?l?l?l?l?d'

generar palabras a partir de dos listas de palabras con sufijo de año (1000-2999) <nombre><apellido><año>

root@kitploit:~
$ cracken --wordlist firstnames.txt --wordlist lastnames.lst --charset '12' '?w1?w2?1?d?d?d'

crear una Smartlist de tamaño 50k a partir de subpalabras extraídas de rockyou.txt

root@kitploit:~
$ cracken create -f rockyou.txt -m 50000 --smartlist smart.lst

estimar la entropía de la máscara híbrida de la contraseña HelloWorld123! usando una smartlist

root@kitploit:~
$ cracken entropy -f smart.lst 'HelloWorld123!'

hybrid-min-split: ["hello", "world1", "2", "3", "!"]
hybrid-mask: ?w1?w1?d?d?s
hybrid-min-entropy: 42.73
--
charset-mask: ?l?l?l?l?l?l?l?l?l?l?d?d?d?s
charset-mask-entropy: 61.97

Rendimiento

Al momento de escribir esto, Cracken es probablemente el generador de listas de palabras más rápido del mundo:

resultados de benchmarks

Cracken tiene alrededor de un 25% de rendimiento superior sobre el rápido maskprocessor de hashcat, escrito en C.

Cracken puede generar alrededor de 2 GB/s por núcleo.

más detalles en benchmarks/ 🔗

¿Por qué es importante la velocidad? Una GPU típica puede probar miles de millones de contraseñas por segundo dependiendo de la función hash de la contraseña. Cuando el generador de listas de palabras produce menos palabras por segundo de las que la herramienta de cracking puede manejar, la velocidad de cracking se degrada.

Rendimiento del análisis de Máscaras Híbridas

Cracken usa el algoritmo A* para analizar contraseñas muy rápidamente. Puede encontrar la Máscara Híbrida mínima de un archivo de contraseñas a una tasa de ~100k contraseñas/segundo (cracken entropy -f words1.txt -f words2.txt ... -p pwds.txt)

Instalación

instala Cracken o compila desde el código fuente

Descargar binario (solo Linux por ahora)

descarga la última versión desde releases 🔗

Compilar desde código fuente (todas las plataformas)

Cracken está escrito en Rust y necesita rustc para compilarse. Cracken debería funcionar en todas las plataformas que Rust soporta.

instrucciones de instalación para cargo 🔗

hay dos opciones para compilar desde código fuente: instalar con cargo desde crates.io (preferido) o compilar manualmente desde el código fuente.

1. Instalar desde crates.io (preferido)

instalar con cargo:

root@kitploit:~
$ cargo install cracken

2. Compilar desde el código fuente

clonar Cracken:

root@kitploit:~
$ git clone https://github.com/shmuelamar/cracken

compilar Cracken:

root@kitploit:~
$ cd cracken
$ cargo build --release

ejecutarlo:

root@kitploit:~
$ ./target/release/cracken --help

Información de Uso

root@kitploit:~
$ cracken --help
Cracken v1.0.0 - a fast password wordlist generator 

USAGE:
    cracken [SUBCOMMAND]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

SUBCOMMANDS:
    generate    (default) - Generates newline separated words according to given mask and wordlist files
    create      Create a new smartlist from input file(s)
    entropy     
                Computes the estimated entropy of password or password file.
                The entropy of a password is the log2(len(keyspace)) of the password.
                
                There are two types of keyspace size estimations:
                  * mask - keyspace of each char (digit=10, lowercase=26...).
                  * hybrid - finding minimal split into subwords and charsets.


For specific subcommand help run: cracken <subcommand> --help


Example Usage:

  ## Generate Subcommand Examples:

  # all digits from 00000000 to 99999999
  cracken ?d?d?d?d?d?d?d?d

  # all digits from 0 to 99999999
  cracken -m 1 ?d?d?d?d?d?d?d?d

  # words with pwd prefix - pwd0000 to pwd9999
  cracken pwd?d?d?d?d

  # all passwords of length 8 starting with upper then 6 lowers then digit
  cracken ?u?l?l?l?l?l?l?d

  # same as above, write output to pwds.txt instead of stdout
  cracken -o pwds.txt ?u?l?l?l?l?l?l?d

  # custom charset - all hex values
  cracken -c 0123456789abcdef '?1?1?1?1'

  # 4 custom charsets - the order determines the id of the charset
  cracken -c 01 -c ab -c de -c ef '?1?2?3?4'

  # 4 lowercase chars with years 2000-2019 suffix
  cracken -c 01 '?l?l?l?l20?1?d'

  # starts with firstname from wordlist followed by 4 digits
  cracken -w firstnames.txt '?w1?d?d?d?d'

  # starts with firstname from wordlist with lastname from wordlist ending with symbol
  cracken -w firstnames.txt -w lastnames.txt -c '!@#$' '?w1?w2?1'

  # repeating wordlists multiple times and combining charsets
  cracken -w verbs.txt -w nouns.txt '?w1?w2?w1?w2?w2?d?d?d'


  ## Create Smartlists Subcommand Examples:

  # create smartlist from single file into smart.txt
  cracken create -f rockyou.txt --smartlist smart.txt

  # create smartlist from multiple files with multiple tokenization algorithms
  cracken create -t bpe -t unigram -t wordpiece -f rockyou.txt -f passwords.txt -f wikipedia.txt --smartlist smart.txt

  # create smartlist with minimum subword length of 3 and max numbers-only subwords of size 6
  cracken create -f rockyou.txt --min-word-len 3 --numbers-max-size 6 --smartlist smart.txt


  ## Entropy Subcommand Examples:

  # estimating entropy of a password
  cracken entropy --smartlist vocab.txt 'helloworld123!'

  # estimating entropy of a passwords file with a charset mask entropy (default is hybrid)
  cracken entropy --smartlist vocab.txt -t charset -p passwords.txt

  # estimating the entropy of a passwords file
  cracken entropy --smartlist vocab.txt -p passwords.txt

cracken-v1.0.0 linux-x86_64 compiler: rustc 1.56.1 (59eed8a2a 2021-11-01)
more info at: https://github.com/shmuelamar/cracken

Información de Uso del Subcomando Generate

root@kitploit:~
$ cracken generate --help
cracken-generate 
(default) - Generates newline separated words according to given mask and wordlist files

USAGE:
    cracken generate [FLAGS] [OPTIONS] <mask> --masks-file <masks-file>

FLAGS:
    -h, --help       
            Prints help information

    -s, --stats      
            prints the number of words this command will generate and exits

    -V, --version    
            Prints version information


OPTIONS:
    -c, --custom-charset <custom-charset>...    
            custom charset (string of chars). up to 9 custom charsets - ?1 to ?9. use ?1 on the mask for the first charset

    -i, --masks-file <masks-file>               
            a file containing masks to generate

    -x, --maxlen <max-length>                   
            maximum length of the mask to start from

    -m, --minlen <min-length>                   
            minimum length of the mask to start from

    -o, --output-file <output-file>             
            output file to write the wordlist to, defaults to stdout

    -w, --wordlist <wordlist>...                
            filename containing newline (0xA) separated words. note: currently all wordlists loaded to memory


ARGS:
    <mask>    
            the wordlist mask to generate.
            available masks are:
                builtin charsets:
                ?d - digits: "0123456789"
                ?l - lowercase: "abcdefghijklmnopqrstuvwxyz"
                ?u - uppercase: "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
                ?s - symbols: " !\"\#$%&'()*+,-./:;<=>?@[\\]^_`{|}~"
                ?a - all characters: ?d + ?l + ?u + ?s
                ?b - all binary values: (0-255)
            
                custom charsets ?1 to ?9:
                ?1 - first custom charset specified by --charset 'mychars'
            
                wordlists ?w1 to ?w9:
                ?w1 - first wordlist specified by --wordlist 'my-wordlist.txt'

Información de Uso del Subcomando Create Smartlist

root@kitploit:~
$ cracken create --help  
cracken-create 
Create a new smartlist from input file(s)

USAGE:
    cracken create [FLAGS] [OPTIONS] --file <file>... --smartlist <smartlist>

FLAGS:
    -h, --help       Prints help information
    -q, --quiet      disables printing progress bar
    -V, --version    Prints version information

OPTIONS:
    -f, --file <file>...                         input filename, can be specified multiple times for multiple files
        --min-frequency <min_frequency>          minimum frequency of a word, relevant only for BPE tokenizer
    -l, --min-word-len <min_word_len>            filters words shorter than the specified length
        --numbers-max-size <numbers_max_size>    filters numbers (all digits) longer than the specified size
    -o, --smartlist <smartlist>                  output smartlist filename
    -t, --tokenizer <tokenizer>...               tokenizer to use, can be specified multiple times.
                                                 one of: bpe,unigram,wordpiece [default: bpe]  [possible values: bpe, unigram, wordpiece]
    -m, --vocab-max-size <vocab_max_size>        max vocabulary size

Información de Uso del Subcomando Entropy

root@kitploit:~
$ cracken entropy --help
cracken-entropy 

Computes the estimated entropy of password or password file.
The entropy of a password is the log2(len(keyspace)) of the password.

There are two types of keyspace size estimations:
  * mask - keyspace of each char (digit=10, lowercase=26...).
  * hybrid - finding minimal split into subwords and charsets.


USAGE:
    cracken entropy [FLAGS] [OPTIONS] <password> --smartlist <smartlist>...

FLAGS:
    -h, --help       Prints help information
    -s, --summary    output summary of entropy for password
    -V, --version    Prints version information

OPTIONS:
    -t, --mask-type <mask_type>              type of mask to output, one of: charsets(charsets only), hybrid(charsets+wordlists) [possible values: hybrid, charset]
    -p, --passwords-file <passwords-file>    newline separated password file to estimate entropy for
    -f, --smartlist <smartlist>...           smartlist input file to estimate entropy with, a newline separated text file

ARGS:
    <password>    password to

Licencia

Cracken está licenciado bajo MIT. ESTE PROYECTO DEBE USARSE SOLO CON FINES LEGALES ⚖️

Contribuciones

Cracken está en desarrollo activo. Si deseas ayudar, a continuación se muestra la hoja de ruta parcial para este proyecto. No dudes en enviar PRs y abrir issues.

Descargar herramienta