Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Hashcat-Cheatsheet — Reference di Hashcat per OSCP/penetration testing: identificazione degli hash, sintassi di cracking per Linux, Windows, archivi, database, ticket Kerberos e attacchi basati su regole. | Kitploit
Strumenti/GitHubGitHub/frizb/hashcat-cheatsheet
Password CrackingAttacchi alle PasswordAnalisi HashPenetration TestingApprendimento e FormazioneRisorse CurateTop in Analisi Hash n.14Top in Attacchi alle Password n.19Top in Password Cracking n.19
631129596 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
GitHubfrizb/hashcat-cheatsheet

Hashcat-Cheatsheet

Reference di Hashcat per OSCP/penetration testing: identificazione degli hash, sintassi di cracking per Linux, Windows, archivi, database, ticket Kerberos e attacchi basati su regole.

Vedi Repository

Hashcat-Cheatsheet

Cheatsheet di Hashcat per OSCP https://hashcat.net/wiki/doku.php?id=hashcat

Identificare gli hash

hash-identifier

Hash di esempio: https://hashcat.net/wiki/doku.php?id=example_hashes

MASSIMA POTENZA!

Ho scoperto che posso ottenere più potenza dal cracking degli hash aggiungendo questi parametri:

--force -O -w 4 --opencl-device-types 1,2

Questi parametri costringono Hashcat a usare l'interfaccia GPU CUDA, che è instabile ma offre prestazioni migliori (–force), ottimizzano per password di 32 caratteri o meno (-O) e impostano il carico di lavoro su "Insane" (-w 4), che dovrebbe rendere il computer di fatto inutilizzabile durante il processo di cracking. Infine, "--opencl-device-types 1,2" forza HashCat a usare sia la GPU che la CPU per gestire il cracking.

Usare hashcat con un dizionario

Crea un file .hash con tutti gli hash che vuoi craccare, puthasheshere.hash: $1$O3JMY.Tw$AdLnLjQ/5jXF9.MTp3gHv/

Esempio di hashcat per craccare password Linux md5crypt $1$ usando rockyou:

hashcat --force -m 500 -a 0 -o found1.txt --remove puthasheshere.hash /usr/share/wordlists/rockyou.txt

Esempio di hashcat per craccare password Wordpress usando rockyou:
hashcat --force -m 400 -a 0 -o found1.txt --remove wphash.hash /usr/share/wordlists/rockyou.txt

Hash di esempio http://openwall.info/wiki/john/sample-hashes

HashCat One Rule to Rule them All

Not So Secure ha creato una regola personalizzata con cui ho avuto fortuna in passato:
https://www.notsosecure.com/one-rule-to-rule-them-all/
La regola può essere scaricata dal loro sito GitHub:
https://github.com/NotSoSecure/password_cracking_rules

Di solito inserisco OneRuleToRuleThemAll.rule nella sottocartella rules e la eseguo così dal mio computer Windows (in base all'articolo di notsosecure):

hashcat64.exe --force -m300 --status -w3 -o found.txt --remove --potfile-disable -r rules\OneRuleToRuleThemAll.rule hash.txt rockyou.txt

Usare hashcat per il brute force

predefined charsets
?l = abcdefghijklmnopqrstuvwxyz
?u = ABCDEFGHIJKLMNOPQRSTUVWXYZ
?d = 0123456789
?s = «space»!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~
?a = ?l?u?d?s
?b = 0x00 - 0xff

?l?d?u equivale a:
?ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789

Forza bruta su tutte le password di lunghezza 1-8 con possibili caratteri A-Z a-z 0-9
hashcat64 -m 500 hashes.txt -a 3 ?1?1?1?1?1?1?1?1 --increment -1 ?l?d?u

Cracking di hash Linux - file /etc/shadow

IDDescriptionType
500md5crypt $1$, MD5(Unix)Sistemi operativi
200bcrypt $2*, Blowfish(Unix)Sistemi operativi
400sha256crypt $5$, SHA256(Unix)Sistemi operativi
1800sha512crypt $6$, SHA512(Unix)Sistemi operativi

Cracking di hash Windows

IDDescriptionType
3000LMSistemi operativi
1000NTLMSistemi operativi

Cracking di hash di applicazioni comuni

IDDescriptionType
900MD4Hash grezzo
0MD5Hash grezzo
5100Half MD5Hash grezzo
100SHA1Hash grezzo
10800SHA-384Hash grezzo
1400SHA-256Hash grezzo
1700SHA-512Hash grezzo

Cracking delle protezioni con password di file comuni

IDDescriptionType
116007-ZipArchivi
12500RAR3-hpArchivi
13000RAR5Archivi
13200AxCryptArchivi
13300AxCrypt in-memory SHA1Archivi
13600WinZipArchivi
9700MS Office <= 2003 $0/$1, MD5 + RC4Documenti
9710MS Office <= 2003 $0/$1, MD5 + RC4, collider #1Documenti
9720MS Office <= 2003 $0/$1, MD5 + RC4, collider #2Documenti
9800MS Office <= 2003 $3/$4, SHA1 + RC4Documenti
9810MS Office <= 2003 $3, SHA1 + RC4, collider #1Documenti
9820MS Office <= 2003 $3, SHA1 + RC4, collider #2Documenti
9400MS Office 2007Documenti
9500MS Office 2010Documenti
9600MS Office 2013Documenti
10400PDF 1.1 - 1.3 (Acrobat 2 - 4)Documenti
10410PDF 1.1 - 1.3 (Acrobat 2 - 4), collider #1Documenti
10420PDF 1.1 - 1.3 (Acrobat 2 - 4), collider #2Documenti
10500PDF 1.4 - 1.6 (Acrobat 5 - 8)Documenti
10600PDF 1.7 Level 3 (Acrobat 9)Documenti
10700PDF 1.7 Level 8 (Acrobat 10 - 11)Documenti
16200Apple Secure NotesDocumenti

Cracking dei formati di hash comuni dei database

IDDescriptionTypeExample Hash
12PostgreSQLServer di databasea6343a68d964ca596d9752250d54bb8a:postgres
131MSSQL (2000)Server di database0x01002702560500000000000000000000000000000000000000008db43dd9b1972a636ad0c7d4b8c515cb8ce46578
132MSSQL (2005)Server di database0x010018102152f8f28c8499d8ef263c53f8be369d799f931b2fbe
1731MSSQL (2012, 2014)Server di database0x02000102030434ea1b17802fd95ea6316bd61d2c94622ca3812793e8fb1672487b5c904a45a31b2ab4a78890d563d2fcf5663e46fe797d71550494be50cf4915d3f4d55ec375
200MySQL323Server di database7196759210defdc0
300MySQL4.1/MySQL5Server di databasefcf7c1b8749cf99d88e5f34271d636178fb5d130
3100Oracle H: Type (Oracle 7+)Server di database7A963A529D2E3229:3682427524
112Oracle S: Type (Oracle 11+)Server di databaseac5f1e62d21fd0529428b84d42e8955b04966703:38445748184477378130
12300Oracle T: Type (Oracle 12+)Server di database78281A9C0CF626BD05EFC4F41B515B61D6C4D95A250CD4A605CA0EF97168D670EBCB5673B6F5A2FB9CC4E0C0101E659C0C4E3B9B3BEDA846CD15508E88685A2334141655046766111066420254008225
8000Sybase ASEServer di database0xc00778168388631428230545ed2c976790af96768afa0806fe6c0da3b28f3e132137eac56f9bad027ea2

Cracking di hash NTLM

Dopo aver recuperato o dumpato il file NTDS.dit e l'hive di registro SYSTEM, oppure dumpato la memoria LSASS da un sistema Windows, spesso ci si ritrova con hash NTLM.

PathDescription
C:\Windows\NTDS\ntds.ditDatabase di Active Directory
C:\Windows\System32\config\SYSTEMHive di registro contenente la chiave usata per cifrare gli hash
Scarica lo strumento