Hacking Complex Passwords with Rules & Munging

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 พ.ค. 2023
  • j-h.io/passbolt || Use a password manager to keep all your credentials secure -- my code JOHN-HAMMOND will save 20% off!! j-h.io/passbolt
    🔥 TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!
    🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware

ความคิดเห็น • 86

  • @gamerscodex5454
    @gamerscodex5454 ปีที่แล้ว +7

    Knew about OneRuleToRuleThemAll, but learned about CEWL & munging passwords, thank you for another great video! 🙏

  • @hamedranaee5641
    @hamedranaee5641 ปีที่แล้ว +11

    You know what John?! , I've learned many things from you. Thank you 🤩

    • @thehackerman00
      @thehackerman00 ปีที่แล้ว +1

      fr I'm trying to make content around cybersec myself and his is quite good!

  • @HitemAriania
    @HitemAriania ปีที่แล้ว

    I would highly recommend spraygen :). And thanks for a superb video John!

  • @richardmeyer418
    @richardmeyer418 ปีที่แล้ว

    Thanks, John. Most illuminating.

  • @Lampe2020
    @Lampe2020 ปีที่แล้ว +3

    Very interesting video! Just cracking these hashes like nothing...
    To the sponsor segment: I don't need Passbolt, I have a password manager built-in to Firefox.

  • @terminatorfishstudios
    @terminatorfishstudios ปีที่แล้ว

    Haven't watched yet, already hyped, will edit once I've watched

  • @MrRaja
    @MrRaja ปีที่แล้ว +1

    😮 that munge script looks awesome

  • @HaxorTechTones
    @HaxorTechTones ปีที่แล้ว +5

    "Psudohash" can also be added to this mix of awesome tools. It can generate millions of keyword-based mutations in seconds, based on (customizable) leet character substitutions, char-case variations and literally all of the unique word mutations these two methods evaluate to, when combined. It can also append common padding values before or after each word mutation (frequently used to make passwords longer / more complex, e.g. "!@#", "!!!" and so on) as well as range of year values in various patterns (and more).

  • @Zedorek
    @Zedorek ปีที่แล้ว

    i just learnt this in my RED team course :) Cewl!

  • @Swensa1
    @Swensa1 ปีที่แล้ว +17

    Finding the right combination of rules and wordlists is tedious, and I believe it's necessary to use a technique for filtering out duplicate attempts. The hashcat-brain allows you to do just that, which is why I blindly think it's awesome.

  • @dcriley65
    @dcriley65 ปีที่แล้ว

    Thanks John.

  • @NeverGiveUpYo
    @NeverGiveUpYo ปีที่แล้ว +1

    Cewl video John! :)

  • @gamingtsunami6928
    @gamingtsunami6928 ปีที่แล้ว +5

    love your videos sir im 17 years,,from kenya,just got a pc now its time to try some hack the box.

    • @evanalmighty9444
      @evanalmighty9444 ปีที่แล้ว

      I’m 17 too and I’m in the same boat as you, if you want to connect on discord we might have some tips and tricks we can exchange.

    • @gamingtsunami6928
      @gamingtsunami6928 ปีที่แล้ว

      @@evanalmighty9444 hey I would like that very much drop your discord

    • @gamingtsunami6928
      @gamingtsunami6928 ปีที่แล้ว

      @@evanalmighty9444 hey where did you go

  • @user-hm7tn2tb3f
    @user-hm7tn2tb3f ปีที่แล้ว +5

    You are not safe if you're not using a password manager, some 2FA will also go a long way! cool content John!

    • @venomlovekitties
      @venomlovekitties ปีที่แล้ว

      What happened if our password manager got hacked?

    • @user-hm7tn2tb3f
      @user-hm7tn2tb3f ปีที่แล้ว

      @@venomlovekitties You have 2FA

  • @hendrikdeetlefs6266
    @hendrikdeetlefs6266 ปีที่แล้ว +14

    Colabcat bans your google account if you use it

    • @hendrikdeetlefs6266
      @hendrikdeetlefs6266 ปีที่แล้ว +3

      its against the eula

    • @mattob4619
      @mattob4619 11 หลายเดือนก่อน +1

      True. It sucks major ass that it does this.

  • @Metrix2024
    @Metrix2024 ปีที่แล้ว +1

    Passbolt caught my interest

  • @atsekbatman
    @atsekbatman ปีที่แล้ว

    Cool video, thx!

  • @anuragbiswas4337
    @anuragbiswas4337 ปีที่แล้ว

    Hey John, great video once again. I've been meaning to ask something. What's a good course for learning Web App Pentesting out there?

    • @jakesaunders3614
      @jakesaunders3614 ปีที่แล้ว +2

      Check out TCM security’s course

    • @anuragbiswas4337
      @anuragbiswas4337 ปีที่แล้ว

      @@jakesaunders3614 Thanks a lot mate, I didn't know that TCM Security also had a course for Web App Pentesting. I'll check it out immediately. Appreciate your help. Thanks a lot.

    • @AlphaYellow
      @AlphaYellow ปีที่แล้ว

      @@jakesaunders3614 Yeah that's a good one

    • @jamesos2744
      @jamesos2744 ปีที่แล้ว

      @@anuragbiswas4337 Rana Khalil's web security academy is great too... most of it is on TH-cam.

  • @Pratik01337
    @Pratik01337 ปีที่แล้ว +4

    Great video john! But my english is a bit bad i didnt understand what "Munging" meant that you have in your title so i decided to google it and the first link that popped was of the urban dictionary and now im traumatized for my whole life!

  • @kaptianpsyco
    @kaptianpsyco ปีที่แล้ว +8

    I just used AI to convert munge to python3, works great

    • @lancemarchetti8673
      @lancemarchetti8673 ปีที่แล้ว

      Nice! Which Model did you use?

    • @nep7164
      @nep7164 ปีที่แล้ว

      Guess he asked chatGPT to do it

    • @kaptianpsyco
      @kaptianpsyco ปีที่แล้ว +1

      Yes chatGPT

  • @neoninsv
    @neoninsv ปีที่แล้ว +1

    How about password masking attacks? You able to showcase those techniques?

  • @MRJMXHD
    @MRJMXHD 11 หลายเดือนก่อน

    Man you're awesome.

  • @Existence-
    @Existence- ปีที่แล้ว

    Thank you for this Great 👍 content
    But what if passbolt got hacked
    My passwords will be available online like what happened with LastPass?

  • @Pauleegan
    @Pauleegan ปีที่แล้ว +2

    This is awesome! Please do rainbow tables next 🙂

  • @loaderladdy
    @loaderladdy ปีที่แล้ว +6

    it would be good to educate your viewers about the benefits of password length in defeating brute forcing attempts at password cracking like this. would you have attempted this video demo on a password hash for a password that was between 15 and 20 characters and only used 3 simple unrelated lowercase dictionary words? That would be a great educational video to watch John. I enjoyed this video btw 👍😀

  • @IMindiffernt
    @IMindiffernt ปีที่แล้ว

    He mentioned that basic dictionary words should never be used in a password, but aren't these words the basis for things like diceware? Is diceware no longer considered good enough for generating passwords?

  • @rayanfernandes2631
    @rayanfernandes2631 ปีที่แล้ว +1

    This is cool but now most often the hashes are of salted passwords , so its complex to crack those , btw this hack works on leet style wifi passwords 😅

  • @jonny-mp3
    @jonny-mp3 ปีที่แล้ว

    Know any rules that will play around with salts?

  • @lirothen
    @lirothen ปีที่แล้ว

    isn't there a standard Python 2 to 3 converter? 2to3
    I should change my passwords.

  • @hypedz1495
    @hypedz1495 ปีที่แล้ว

    John.. John Hammond.

  • @infinix_6586
    @infinix_6586 ปีที่แล้ว

    Hey plz make video on Krack attack or Router firmware backdooring😊

  • @debrabest5035
    @debrabest5035 ปีที่แล้ว +1

    THANKS JOHN!!!!!!! YOU'RE THE BEST!!!!!!! ENJOY THE MOVIE...... BE BLESSED❤️🙏

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Jupiter nod output coming

  • @anilbangera1
    @anilbangera1 ปีที่แล้ว

    Good

  • @VIVEVIEV
    @VIVEVIEV ปีที่แล้ว +3

    That’s not the type of munging I know about 🤪

  • @U-shapeMgall
    @U-shapeMgall หลายเดือนก่อน

    What about the app that I download to get the password and email

  • @Mohammed_ALQadasi
    @Mohammed_ALQadasi ปีที่แล้ว +1

    I hope that you will make a video by hacking the Mikrotik server, the latest update

  • @janimmikey8286
    @janimmikey8286 ปีที่แล้ว

    super

  • @flok.7735
    @flok.7735 ปีที่แล้ว

    I thought colabcat is dead, thanks to some detecting mech. of google and a use restriction that forbids password cracking

  • @terraflops
    @terraflops 11 หลายเดือนก่อน +1

    @JohnHammond
    FYI:
    DO NOT USE THE COLABCAT IF YOU WANT TO USE GOOGLE COLAB NOTEBOOKS FOR REGULAR USE!
    YOU WILL GET SUSPENDED for violating their terms and conditions. Wish i knew this before trying to run the notebooks.

  • @motbus3
    @motbus3 3 หลายเดือนก่อน

    Chatgpt might allucinate and add words that were not in the list

  • @KR1ML0N
    @KR1ML0N ปีที่แล้ว +1

    Bitwarden ftw

  • @oxycodin2253
    @oxycodin2253 ปีที่แล้ว +2

    What’s munging

    • @liamjones2131
      @liamjones2131 ปีที่แล้ว +1

      Do not search it on Urban Dictionary, you have been warned. It is not the same thing there.

  • @mikelawrence1556
    @mikelawrence1556 7 หลายเดือนก่อน

    How did you crack the password in only a couple minutes? I did everything you did and have been running John for half an hour.

  • @mohammedissam3651
    @mohammedissam3651 11 หลายเดือนก่อน

    9:55
    What are the odds of two different users generate the same password?

  • @valk9789
    @valk9789 ปีที่แล้ว +15

    Enjoy the movie!

  • @klintkrossa6885
    @klintkrossa6885 ปีที่แล้ว

    Try 2to3 to fix python2.

  • @jamesos2744
    @jamesos2744 ปีที่แล้ว

    Got stopped by Google trying to use collabcat... Something about "potential abuse". Oh well!

  • @tyrojames9937
    @tyrojames9937 ปีที่แล้ว

    COOL

  • @rvft
    @rvft ปีที่แล้ว +3

    Pro tip, put emoji in your password and keep it at least 12 characters long, there you have uncrackable password, no matter what you put as password.

    • @jdjax592
      @jdjax592 ปีที่แล้ว +7

      Rule one: everything is crackable.
      Rule two: saying something is unhackable, makes u get hacked.

    • @learneducateteach9624
      @learneducateteach9624 ปีที่แล้ว

      Number one thing i learned on security+ is that nothing is impossible to crack.😉

  • @NormTurtle
    @NormTurtle ปีที่แล้ว

    Google will ban if you is use hashcat. I been banned already

  • @michaelngirazi5395
    @michaelngirazi5395 ปีที่แล้ว

    So you look and sound like Seth Rogen 😮😮

  • @Shindignick
    @Shindignick ปีที่แล้ว +1

    Certainly not the word we need to be using in the cyber sec space. yikes.

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Mor explaining this video hash cat comment skills tools files open

  • @ytsine404
    @ytsine404 ปีที่แล้ว

  • @xenostim
    @xenostim ปีที่แล้ว

    M U N G

  • @pakekoding
    @pakekoding ปีที่แล้ว

    I think u just hate JTR cause that had ur name there.
    Be honest john 😌

  • @rjhornsby
    @rjhornsby ปีที่แล้ว +1

    A bit meta, but related - after hearing about Passbolt from you and looking into it my problem with it is not the concept, but rather what seems like deceptive - at minimum misleading - marketing on their website. There’s no desktop app, but they have images meant to look like screenshots of a desktop app running on MacOS. Second, these MacOS screenshots hint at MacOS “native” - but Safari is conspicuously absent from the supported browsers.
    It’s disappointing that a desktop app and Safari support are missing. Disappointment, however, turns to suspicion when presented with mockups masquerading as a real product. If I feel like I’m being deceived, none of the outstanding features or benefits matter.

  • @BRD691
    @BRD691 ปีที่แล้ว

    *dies of cringe*

  • @terror403
    @terror403 ปีที่แล้ว

    Hey calm down, you are speaking way too fast! Using online services to store password is a madness

  • @ELIAS-og5vf
    @ELIAS-og5vf ปีที่แล้ว

    I DONT Recommande USING PASBOLT USE UR BRAIN

  • @eyephpmyadmin6988
    @eyephpmyadmin6988 ปีที่แล้ว

    Not saying I've been cracking neighbors wifi but if I was I'd love using rules

    • @eyephpmyadmin6988
      @eyephpmyadmin6988 ปีที่แล้ว

      And if I was I'd also be very successful in getting free WiFi, but I wouldn't do anything mean like mitm bc that's actually fucked up n I'd already get free WiFi

    • @eyephpmyadmin6988
      @eyephpmyadmin6988 ปีที่แล้ว

      Like dead serious I don't do mitm n stuff I do get their wifi for free tho

  • @JNET_Reloaded
    @JNET_Reloaded ปีที่แล้ว

    no , no1 should use python2 anymore just edit the code and make it work for python3 print("like this dummy")

  • @treptunes
    @treptunes ปีที่แล้ว

    @JohnHammond Google Collab was instantly locked after installing colabcat because of misusuing their service. I am now trying to solve this with google. :/ I could not even buy resources anymore after that.