During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?
The '$6$' prefix indicates a SHA-512 crypt hash, commonly used on Linux systems. Hashcat mode 1800 is designed for sha512crypt hashes. Using this mode ensures correct parsing of the salt and hash, allowing efficient cracking. It is the standard mode for modern Linux password hashes.
Why this answer
The '$6$' prefix unambiguously identifies a SHA-512 crypt hash. Hashcat mode 1800 is specifically built for this format, ensuring correct salt handling and efficient cracking. Other modes correspond to different hash algorithms and would not successfully crack the hash.
Exam trap
The trap here is misidentifying the hash type based on prefix, leading to the wrong Hashcat mode.