Hacking Complex Passwords with Rules & Munging

  Рет қаралды 96,131

John Hammond

John Hammond

Жыл бұрын

j-h.io/passbolt || Use a password manager to keep all your credentials secure -- my code JOHN-HAMMOND will save 20% off!! j-h.io/passbolt
🔥 KZfaq ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 86
@gamerscodex5454
@gamerscodex5454 Жыл бұрын
Knew about OneRuleToRuleThemAll, but learned about CEWL & munging passwords, thank you for another great video! 🙏
@hamedranaee5641
@hamedranaee5641 Жыл бұрын
You know what John?! , I've learned many things from you. Thank you 🤩
@thehackerman00
@thehackerman00 Жыл бұрын
fr I'm trying to make content around cybersec myself and his is quite good!
@HaxorTechTones
@HaxorTechTones Жыл бұрын
"Psudohash" can also be added to this mix of awesome tools. It can generate millions of keyword-based mutations in seconds, based on (customizable) leet character substitutions, char-case variations and literally all of the unique word mutations these two methods evaluate to, when combined. It can also append common padding values before or after each word mutation (frequently used to make passwords longer / more complex, e.g. "!@#", "!!!" and so on) as well as range of year values in various patterns (and more).
@Swensa1
@Swensa1 Жыл бұрын
Finding the right combination of rules and wordlists is tedious, and I believe it's necessary to use a technique for filtering out duplicate attempts. The hashcat-brain allows you to do just that, which is why I blindly think it's awesome.
@Lampe2020
@Lampe2020 Жыл бұрын
Very interesting video! Just cracking these hashes like nothing... To the sponsor segment: I don't need Passbolt, I have a password manager built-in to Firefox.
@terminatorfishstudios
@terminatorfishstudios Жыл бұрын
Haven't watched yet, already hyped, will edit once I've watched
@richardmeyer418
@richardmeyer418 Жыл бұрын
Thanks, John. Most illuminating.
@HitemAriania
@HitemAriania Жыл бұрын
I would highly recommend spraygen :). And thanks for a superb video John!
@MrRaja
@MrRaja Жыл бұрын
😮 that munge script looks awesome
@Zedorek
@Zedorek Жыл бұрын
i just learnt this in my RED team course :) Cewl!
@Metrix2024
@Metrix2024 Жыл бұрын
Passbolt caught my interest
@NeverGiveUpYo
@NeverGiveUpYo Жыл бұрын
Cewl video John! :)
@hendrikdeetlefs6266
@hendrikdeetlefs6266 Жыл бұрын
Colabcat bans your google account if you use it
@hendrikdeetlefs6266
@hendrikdeetlefs6266 Жыл бұрын
its against the eula
@mattob4619
@mattob4619 Жыл бұрын
True. It sucks major ass that it does this.
@dcriley65
@dcriley65 Жыл бұрын
Thanks John.
@kaptianpsyco
@kaptianpsyco Жыл бұрын
I just used AI to convert munge to python3, works great
@lancemarchetti8673
@lancemarchetti8673 Жыл бұрын
Nice! Which Model did you use?
@nep7164
@nep7164 Жыл бұрын
Guess he asked chatGPT to do it
@kaptianpsyco
@kaptianpsyco Жыл бұрын
Yes chatGPT
@gamingtsunami6928
@gamingtsunami6928 Жыл бұрын
love your videos sir im 17 years,,from kenya,just got a pc now its time to try some hack the box.
@evanalmighty9444
@evanalmighty9444 Жыл бұрын
I’m 17 too and I’m in the same boat as you, if you want to connect on discord we might have some tips and tricks we can exchange.
@gamingtsunami6928
@gamingtsunami6928 Жыл бұрын
@@evanalmighty9444 hey I would like that very much drop your discord
@gamingtsunami6928
@gamingtsunami6928 Жыл бұрын
@@evanalmighty9444 hey where did you go
@MRJMXHD
@MRJMXHD 11 ай бұрын
Man you're awesome.
@user-hm7tn2tb3f
@user-hm7tn2tb3f Жыл бұрын
You are not safe if you're not using a password manager, some 2FA will also go a long way! cool content John!
@venomlovekitties
@venomlovekitties Жыл бұрын
What happened if our password manager got hacked?
@user-hm7tn2tb3f
@user-hm7tn2tb3f Жыл бұрын
@@venomlovekitties You have 2FA
@valk9789
@valk9789 Жыл бұрын
Enjoy the movie!
@atsekbatman
@atsekbatman Жыл бұрын
Cool video, thx!
@Pratik01337
@Pratik01337 Жыл бұрын
Great video john! But my english is a bit bad i didnt understand what "Munging" meant that you have in your title so i decided to google it and the first link that popped was of the urban dictionary and now im traumatized for my whole life!
@rayanfernandes2631
@rayanfernandes2631 Жыл бұрын
This is cool but now most often the hashes are of salted passwords , so its complex to crack those , btw this hack works on leet style wifi passwords 😅
@loaderladdy
@loaderladdy Жыл бұрын
it would be good to educate your viewers about the benefits of password length in defeating brute forcing attempts at password cracking like this. would you have attempted this video demo on a password hash for a password that was between 15 and 20 characters and only used 3 simple unrelated lowercase dictionary words? That would be a great educational video to watch John. I enjoyed this video btw 👍😀
@neoninsv
@neoninsv Жыл бұрын
How about password masking attacks? You able to showcase those techniques?
@IMindiffernt
@IMindiffernt Жыл бұрын
He mentioned that basic dictionary words should never be used in a password, but aren't these words the basis for things like diceware? Is diceware no longer considered good enough for generating passwords?
@lirothen
@lirothen Жыл бұрын
isn't there a standard Python 2 to 3 converter? 2to3 I should change my passwords.
@Pauleegan
@Pauleegan Жыл бұрын
This is awesome! Please do rainbow tables next 🙂
@jonny-mp3
@jonny-mp3 Жыл бұрын
Know any rules that will play around with salts?
@hypedz1495
@hypedz1495 Жыл бұрын
John.. John Hammond.
@debrabest5035
@debrabest5035 Жыл бұрын
THANKS JOHN!!!!!!! YOU'RE THE BEST!!!!!!! ENJOY THE MOVIE...... BE BLESSED❤️🙏
@anuragbiswas4337
@anuragbiswas4337 Жыл бұрын
Hey John, great video once again. I've been meaning to ask something. What's a good course for learning Web App Pentesting out there?
@jakesaunders3614
@jakesaunders3614 Жыл бұрын
Check out TCM security’s course
@anuragbiswas4337
@anuragbiswas4337 Жыл бұрын
@@jakesaunders3614 Thanks a lot mate, I didn't know that TCM Security also had a course for Web App Pentesting. I'll check it out immediately. Appreciate your help. Thanks a lot.
@AlphaYellow
@AlphaYellow Жыл бұрын
@@jakesaunders3614 Yeah that's a good one
@jamesos2744
@jamesos2744 Жыл бұрын
@@anuragbiswas4337 Rana Khalil's web security academy is great too... most of it is on KZfaq.
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Jupiter nod output coming
@Existence-
@Existence- Жыл бұрын
Thank you for this Great 👍 content But what if passbolt got hacked My passwords will be available online like what happened with LastPass?
@infinix_6586
@infinix_6586 Жыл бұрын
Hey plz make video on Krack attack or Router firmware backdooring😊
@Mohammed_ALQadasi
@Mohammed_ALQadasi Жыл бұрын
I hope that you will make a video by hacking the Mikrotik server, the latest update
@VIVEVIEV
@VIVEVIEV Жыл бұрын
That’s not the type of munging I know about 🤪
@terraflops
@terraflops 11 ай бұрын
@JohnHammond FYI: DO NOT USE THE COLABCAT IF YOU WANT TO USE GOOGLE COLAB NOTEBOOKS FOR REGULAR USE! YOU WILL GET SUSPENDED for violating their terms and conditions. Wish i knew this before trying to run the notebooks.
@anilbangera1
@anilbangera1 Жыл бұрын
Good
@rvft
@rvft Жыл бұрын
Pro tip, put emoji in your password and keep it at least 12 characters long, there you have uncrackable password, no matter what you put as password.
@jdjax592
@jdjax592 Жыл бұрын
Rule one: everything is crackable. Rule two: saying something is unhackable, makes u get hacked.
@learneducateteach9624
@learneducateteach9624 Жыл бұрын
Number one thing i learned on security+ is that nothing is impossible to crack.😉
@tyrojames9937
@tyrojames9937 Жыл бұрын
COOL
@janimmikey8286
@janimmikey8286 Жыл бұрын
super
@flok.7735
@flok.7735 Жыл бұрын
I thought colabcat is dead, thanks to some detecting mech. of google and a use restriction that forbids password cracking
@motbus3
@motbus3 3 ай бұрын
Chatgpt might allucinate and add words that were not in the list
@U-shapeMgall
@U-shapeMgall 2 ай бұрын
What about the app that I download to get the password and email
@mohammedissam3651
@mohammedissam3651 Жыл бұрын
9:55 What are the odds of two different users generate the same password?
@KR1ML0N
@KR1ML0N Жыл бұрын
Bitwarden ftw
@jamesos2744
@jamesos2744 Жыл бұрын
Got stopped by Google trying to use collabcat... Something about "potential abuse". Oh well!
@klintkrossa6885
@klintkrossa6885 Жыл бұрын
Try 2to3 to fix python2.
@ytsine404
@ytsine404 Жыл бұрын
@mikelawrence1556
@mikelawrence1556 7 ай бұрын
How did you crack the password in only a couple minutes? I did everything you did and have been running John for half an hour.
@oxycodin2253
@oxycodin2253 Жыл бұрын
What’s munging
@liamjones2131
@liamjones2131 Жыл бұрын
Do not search it on Urban Dictionary, you have been warned. It is not the same thing there.
@michaelngirazi5395
@michaelngirazi5395 Жыл бұрын
So you look and sound like Seth Rogen 😮😮
@NormTurtle
@NormTurtle Жыл бұрын
Google will ban if you is use hashcat. I been banned already
@xenostim
@xenostim Жыл бұрын
M U N G
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Mor explaining this video hash cat comment skills tools files open
@Shindignick
@Shindignick Жыл бұрын
Certainly not the word we need to be using in the cyber sec space. yikes.
@pakekoding
@pakekoding Жыл бұрын
I think u just hate JTR cause that had ur name there. Be honest john 😌
@rjhornsby
@rjhornsby Жыл бұрын
A bit meta, but related - after hearing about Passbolt from you and looking into it my problem with it is not the concept, but rather what seems like deceptive - at minimum misleading - marketing on their website. There’s no desktop app, but they have images meant to look like screenshots of a desktop app running on MacOS. Second, these MacOS screenshots hint at MacOS “native” - but Safari is conspicuously absent from the supported browsers. It’s disappointing that a desktop app and Safari support are missing. Disappointment, however, turns to suspicion when presented with mockups masquerading as a real product. If I feel like I’m being deceived, none of the outstanding features or benefits matter.
@BRD691
@BRD691 Жыл бұрын
*dies of cringe*
@terror403
@terror403 Жыл бұрын
Hey calm down, you are speaking way too fast! Using online services to store password is a madness
@ELIAS-og5vf
@ELIAS-og5vf Жыл бұрын
I DONT Recommande USING PASBOLT USE UR BRAIN
@eyephpmyadmin6988
@eyephpmyadmin6988 Жыл бұрын
Not saying I've been cracking neighbors wifi but if I was I'd love using rules
@eyephpmyadmin6988
@eyephpmyadmin6988 Жыл бұрын
And if I was I'd also be very successful in getting free WiFi, but I wouldn't do anything mean like mitm bc that's actually fucked up n I'd already get free WiFi
@eyephpmyadmin6988
@eyephpmyadmin6988 Жыл бұрын
Like dead serious I don't do mitm n stuff I do get their wifi for free tho
@JNET_Reloaded
@JNET_Reloaded Жыл бұрын
no , no1 should use python2 anymore just edit the code and make it work for python3 print("like this dummy")
@treptunes
@treptunes Жыл бұрын
@JohnHammond Google Collab was instantly locked after installing colabcat because of misusuing their service. I am now trying to solve this with google. :/ I could not even buy resources anymore after that.
Password Cracking - Computerphile
20:20
Computerphile
Рет қаралды 3,4 МЛН
He tried to hack me...
34:15
John Hammond
Рет қаралды 376 М.
Osman Kalyoncu Sonu Üzücü Saddest Videos Dream Engine 170 #shorts
00:27
Incredible magic 🤯✨
00:53
America's Got Talent
Рет қаралды 46 МЛН
Password Hacking in Kali Linux
24:22
John Hammond
Рет қаралды 763 М.
OSINT | How to Gather Information on ANYONE!
11:25
AI Video Hub
Рет қаралды 9 М.
catch EVERY reverse shell while hacking! (VILLAIN)
19:03
John Hammond
Рет қаралды 218 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 1,6 МЛН
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,2 МЛН
Ethical Hacking: Bypass Passwords with Linux PAM Degradation Attack
21:45
Tracking Cybercrime on Telegram
23:26
John Hammond
Рет қаралды 293 М.
Hashcat Creating Custom Rules: Ten Minute Tutorials
15:08
stuffy24
Рет қаралды 2,3 М.
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 93 М.