Courseiva

CCNA Password Attacks and Formats Questions

19 questions · Password Attacks and Formats · All types, answers revealed

1
MCQeasy

A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?

A.It is a bcrypt hash and can be cracked using Hashcat mode 3200.
B.It is a SHA-512 crypt hash and can be cracked using Hashcat mode 1800.
C.It is a SHA-256 crypt hash and can be cracked using Hashcat mode 7400.
D.It is an MD5-based hash and can be cracked using Hashcat mode 500.
AnswerB

The $6$ prefix is the standard identifier for SHA-512 crypt in Linux shadow files. Hashcat mode 1800 is specifically designed for sha512crypt, which includes the salt and iteration count. This mode handles the variable rounds and salt, making it the correct choice for cracking this hash. Using the wrong mode would result in failure to recognize the hash format.

Why this answer

The $6$ prefix in /etc/shadow indicates SHA-512 crypt. Hashcat mode 1800 is the correct mode for cracking sha512crypt hashes. Other modes correspond to different algorithms: mode 500 for md5crypt, mode 3200 for bcrypt, and mode 7400 for sha256crypt.

Identifying the prefix correctly is essential to select the right cracking mode and avoid wasted effort.

Exam trap

The trap here is confusing the $6$ prefix with other common hash identifiers like $5$ for SHA-256 or $2a$ for bcrypt, leading to selection of an incompatible Hashcat mode.

2
MCQmedium

When performing a penetration test, why is it safer to crack hashes offline rather than online?

A.Offline cracking is always faster than online methods.
B.Offline cracking prevents account lockouts.
C.Offline cracking allows for the use of more complex passwords.
D.Offline cracking is required to obtain the hash from memory.
AnswerB

Since offline cracking does not involve sending authentication requests to the target, the target's account lockout policy is never triggered. This allows the tester to run millions of attempts per second without any risk of locking out legitimate users, which is essential for maintaining service availability during an engagement.

Why this answer

Offline cracking is performed on the tester's own hardware, which means there is no network traffic generated towards the target system. This prevents the triggering of intrusion detection systems (IDS), account lockout policies, or audit logs that monitor failed authentication attempts. It provides a stealthy way to test password strength without risking operational disruption or alerting the client's defensive security team, which is the primary concern during a professional assessment.

Exam trap

Test-takers sometimes assume online cracking is faster or more direct, ignoring the severe risk of triggering account lockouts and security alerts.

3
MCQeasy

During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?

A.Hashcat mode 5600 (MS-CHAPv2) with a wordlist.
B.Hashcat mode 5500 (NetNTLMv1) with a wordlist.
C.Aircrack-ng with the `-E` option for MS-CHAPv2.
D.John the Ripper with the `--format=netntlm` option.
AnswerA

Hashcat mode 5600 is specifically designed for MS-CHAPv2 challenge-response pairs. It expects the format `username::::response:challenge`. This mode correctly implements the MS-CHAPv2 algorithm to derive the password from the captured handshake. Using a wordlist or rules with this mode is the standard approach for offline cracking of MS-CHAPv2. Thus, this is the correct tool and mode.

Why this answer

MS-CHAPv2 challenge-response handshakes are cracked using Hashcat mode 5600 or John the Ripper's mschapv2 format. Hashcat mode 5600 correctly processes the challenge and response to recover the password. Other modes like 5500 are for different protocols (NetNTLMv1), and tools like Aircrack-ng are for Wi-Fi.

Thus, the appropriate combination is Hashcat mode 5600 with a wordlist.

Exam trap

The trap here is confusing MS-CHAPv2 with NetNTLMv1 or assuming that general-purpose Wi-Fi cracking tools support PPP authentication protocols.

4
Multi-Selectmedium

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

Select 2 answers
A.They enable the use of rainbow tables.
B.They prevent the identification of identical passwords.
C.They are inherently faster to crack than unsalted hashes.
D.They require the salt to be known for successful cracking.
E.They are usually stored in cleartext in the configuration file.
AnswersB, D

With a unique salt per entry, two users with the same password will have completely different hashes stored in the database. This obscures the fact that they are using the same password, which is a major security benefit when a database is compromised, as attackers cannot easily spot patterns.

Why this answer

Salted hashes introduce a unique, random string to the hashing process for every user, ensuring that identical passwords result in different hashes. This makes it impossible to use global rainbow tables. Unsalted hashes are inherently vulnerable to these tables, as the same plaintext always produces the same hash, allowing for near-instant cracking of common passwords across an entire database once a single table is computed.

Exam trap

Candidates often confuse salting with hashing algorithms themselves, mistakenly believing that salting makes the hash itself impossible to reverse rather than specifically preventing the use of precomputed rainbow tables for cracking.

5
MCQmedium

During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?

A.Switch to a rule-based attack using the best64.rule with a large wordlist.
B.Utilize a rainbow table specific to NTLM hashes.
C.Perform a combinator attack using two separate wordlists of common passwords.
D.Use a mask attack with a custom charset targeting the estimated length and character set.
AnswerD

A mask attack allows you to define the exact length and character set, drastically reducing the keyspace compared to a full brute-force. If you have intelligence suggesting the password is at least 13 characters and includes symbols, a mask attack focusing on that length and charset can be feasible, especially with optimized hardware. It directly targets the suspected structure without wasting time on shorter or simpler candidates.

Why this answer

The password is suspected to be long and complex, so a targeted mask attack that specifies the exact length and character set is the most efficient use of cracking resources. Rule-based and combinator attacks rely on existing wordlists and transformations, which may not cover the required length and symbol diversity. Rainbow tables are infeasible for such a large keyspace.

Thus, the mask attack is the best choice.

Exam trap

The trap here is assuming that any rule-based or hybrid attack will eventually hit a long complex password, when in reality the keyspace explosion makes mask attacks the only practical option when length and charset are known.

6
Multi-Selectmedium

Which TWO of the following password cracking techniques are considered 'offline' attacks?

Select 2 answers
A.Brute-forcing an SSH service via an internet-facing portal.
B.Running a dictionary attack against a SAM database file.
C.Spraying common passwords against an O365 login portal.
D.Attacking an NTLM hash dump using Hashcat.
E.Phishing users to submit credentials into a fake form.
AnswersB, D

Accessing the SAM database file directly allows for offline processing. Since the cracking happens entirely on the tester's machine, there is zero network interaction with the target, thus preventing account lockouts, avoiding detection by intrusion detection systems, and allowing for massively parallelized computation using high-end GPU hardware.

Why this answer

Offline attacks involve obtaining a copy of the password hashes and processing them on the attacker's own hardware. This is stealthy as it avoids account lockout policies and audit logging generated by failed login attempts on the target system. Understanding the distinction between online and offline attacks is vital for penetration testers to choose methods that minimize detection while maximizing the probability of successful credential recovery within a controlled and limited engagement timeframe.

Exam trap

Candidates often misclassify spraying attacks or brute-force logins against active services as offline attacks, confusing interactive network authentication with local hash cracking.

7
MCQhard

During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?

A.Mode 1000 (NTLM), and the advantage is that it is the default Windows hash format, making it widely applicable.
B.Mode 3200 (bcrypt), and the advantage is that the cost factor makes brute-force attacks significantly slower.
C.Mode 500 (md5crypt), and the advantage is that it is fast to compute, allowing more guesses per second.
D.Mode 1800 (sha512crypt), and the advantage is that the salt prevents rainbow table attacks.
AnswerB

The `$2y$` prefix indicates bcrypt, and the `10` is the cost factor (2^10 iterations). Hashcat mode 3200 is correct for bcrypt. The cost factor increases the computational effort per guess, making brute-force and rule-based attacks much slower. This is the primary defensive advantage of bcrypt, and the tester must account for it when planning the attack.

Why this answer

The hash prefix `$2y$10$` is characteristic of bcrypt, with the cost factor 10. Hashcat mode 3200 is designed for bcrypt. The cost factor exponentially increases the number of iterations, making each guess computationally expensive.

This slows down brute-force and rule-based attacks, which is the main security benefit. A penetration tester must recognize this and adjust expectations for cracking speed and time.

Exam trap

The trap here is confusing bcrypt's cost factor with a simple iteration count, leading to underestimating the time required for cracking.

8
MCQmedium

During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?

A.Mode 3000 (LM)
B.Mode 5500 (NetNTLMv1)
C.Mode 1000 (NTLM)
D.Mode 5600 (NetNTLMv2)
AnswerD

Hashcat mode 5600 is specifically designed for NetNTLMv2 challenge-response pairs, which are captured by tools like Responder. It correctly handles the format including the username, domain, server challenge, and HMAC-MD5 response. Using this mode allows efficient cracking of the captured hash. Other modes correspond to different hash types and would fail to parse the input correctly.

Why this answer

Responder captures NetNTLMv2 challenge-response pairs, which require Hashcat mode 5600 to crack. Mode 5600 correctly parses the username, domain, challenge, and response. Other modes like 5500 (NetNTLMv1), 1000 (NTLM), and 3000 (LM) are for different hash types and would not work.

Selecting the correct mode is essential for successful offline cracking.

Exam trap

The trap here is confusing NetNTLMv2 with raw NTLM hashes or NetNTLMv1, leading to the use of an incorrect Hashcat mode that cannot parse the captured challenge-response pair.

9
MCQmedium

A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?

A.SHA-256 crypt with 5000 rounds and salt 'abcdefgh'
B.MD5 crypt with 5000 rounds and salt 'abcdefgh'
C.bcrypt with cost factor 5000 and salt 'abcdefgh'
D.SHA-512 crypt with 5000 rounds and salt 'abcdefgh'
AnswerD

The prefix `$6$` denotes SHA-512 crypt, the `rounds=5000` parameter specifies the number of iterations, and `abcdefgh` is the salt. This is a common format in /etc/shadow on modern Linux systems. The tester must use a tool that supports SHA-512 crypt, such as Hashcat mode 1800 or John the Ripper with the crypt format.

Why this answer

The hash begins with `$6$`, which is the standard identifier for SHA-512 crypt. The `rounds=5000` indicates the iteration count, and the following string is the salt. This format is widely used on Linux systems for password storage.

A penetration tester must recognize the prefix to select the correct cracking mode, such as Hashcat mode 1800, and configure the tool accordingly to attempt recovery.

Exam trap

The trap here is assuming that a numeric parameter like 5000 always refers to a cost factor rather than an iteration count, which can lead to using the wrong cracking tool settings.

10
MCQmedium

What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?

A.To decrypt the hash using the specified algorithm.
B.To transform dictionary words into common password variations.
C.To automatically update the hashing algorithm to a newer standard.
D.To bypass account lockout mechanisms on the target system.
AnswerB

Rules allow for the programmatic mutation of wordlist entries. By applying rules such as appending numbers, capitalizing, or substituting characters, testers can simulate common user password patterns. This dramatically improves success rates against users who follow simple patterns to satisfy organizational password complexity policies during the cracking process.

Why this answer

Rules are used to transform wordlist entries into variations. For example, a rule might take the word 'password' and generate 'Password123!' or 'P@ssw0rd'. This increases the effectiveness of dictionary attacks by covering common variations that users employ to meet complexity requirements, without needing a massive, exhaustive dictionary.

This is a critical skill for testers to maximize the utility of limited wordlist sizes while increasing the likelihood of cracking complex, user-chosen passwords.

Exam trap

Many candidates think rules are used to generate completely random passwords, missing their actual purpose of modifying existing dictionary words.

11
MCQmedium

A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?

A.sha512crypt, and the main weakness is that the iteration count is too low by default.
B.descrypt, and the main weakness is that it only uses the first 8 characters of the password.
C.bcrypt, and the main weakness is that the salt is too short, allowing rainbow table attacks.
D.md5crypt, and the main weakness is that it is fast to compute, making brute-force attacks easier.
AnswerD

The `$1$` prefix indicates md5crypt, which is based on MD5. John the Ripper uses the format 'md5crypt' for these hashes. The main weakness is that MD5 is fast, so even with salting and iterations, it can be cracked relatively quickly compared to slower algorithms like bcrypt. This makes it vulnerable to brute-force and dictionary attacks.

Why this answer

The `$1$` prefix is the identifier for md5crypt. John the Ripper supports this format with the 'md5crypt' option. The primary weakness is that MD5 is a fast hash function, so despite salting and a fixed number of iterations, it can be cracked quickly using modern hardware.

This makes it less secure than slower algorithms like bcrypt or SHA-512 crypt with high iteration counts.

Exam trap

The trap here is assuming that any salted hash is slow to crack, but md5crypt's speed makes it relatively weak despite salting.

12
MCQmedium

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

A.They are susceptible to rainbow table attacks.
B.They can be read by any user or process with sufficient file permissions.
C.They prevent the use of multi-factor authentication.
D.They automatically trigger account lockouts after one reading.
AnswerB

If a file containing cleartext credentials has overly permissive access controls, any local user or compromised process can read the file. This allows attackers to harvest high-value credentials without ever needing to perform complex password attacks, making it a critical finding during any security assessment or audit.

Why this answer

Cleartext credentials are easily accessible to anyone with local read access. In a penetration test, finding these files is a 'low-hanging fruit' that often leads to privilege escalation or lateral movement. Many applications inadvertently store sensitive data in logs, config files, or scripts, creating a security debt that attackers exploit to gain unauthorized access without needing to crack passwords through time-consuming cryptographic analysis of captured hashes.

Exam trap

Many test-takers look for complex cryptographic flaws and overlook simple operational oversights like local file permission misconfigurations exposing cleartext credentials.

13
MCQmedium

Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?

A.Dictionary attack
B.Password spraying
C.Birthday attack
D.Rainbow table attack
AnswerB

Password spraying is designed specifically to test one known or common password against many accounts simultaneously. This strategy successfully circumvents account lockout policies that would otherwise trigger after a few failed attempts on a single account, making it highly effective for gaining initial access to large corporate environments.

Why this answer

Password spraying is a technique where an attacker tests a single password against many accounts to avoid triggering account lockout thresholds that occur with brute-forcing a single account. By keeping the number of attempts per account low, the attacker remains under the radar of security monitoring systems. This is a common tactic in modern cloud environments where individual account lockout policies are strict, making mass authentication attempts the most viable entry vector.

Exam trap

Candidates often confuse brute-forcing with password spraying, failing to realize that testing a single password across many accounts avoids lockouts.

14
Multi-Selectmedium

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Select 2 answers
A.Leveraging GPU acceleration with Hashcat
B.Conducting an online brute-force attack against the domain controller
C.Using a rule-based attack with a comprehensive wordlist
D.Performing a rainbow table attack using precomputed tables for NTLM
E.Using a dictionary attack with a list of common passwords only
AnswersA, C

GPU acceleration dramatically increases the number of hash computations per second compared to CPU-only cracking. Hashcat is optimized for GPU usage and can crack NTLM hashes at very high rates. This makes it a highly effective technique for offline attacks, reducing the time required to test large numbers of password candidates.

Why this answer

Rule-based attacks and GPU acceleration are both highly effective for offline cracking of NTLM hashes. Rule-based attacks expand the wordlist with common transformations, covering many user-chosen passwords. GPU acceleration with Hashcat maximizes computational speed, allowing millions of guesses per second.

Together, they significantly improve the success rate. Other options like rainbow tables or online attacks are either impractical or inefficient in this scenario.

Exam trap

The trap here is assuming that rainbow tables are always effective for unsalted hashes, but their size and lookup overhead make them less practical than rule-based GPU cracking.

15
MCQeasy

What is the primary security advantage of utilizing salts in password hashing?

A.It increases the length of the password, making it harder to guess.
B.It prevents the use of precomputed rainbow tables.
C.It forces the hashing algorithm to use more CPU cycles.
D.It encrypts the password instead of hashing it.
AnswerB

Rainbow tables are precomputed databases of hashes for millions of common passwords. By adding a unique salt to every entry in a database, the hash of a password becomes unique to that specific salt, rendering static rainbow tables ineffective as they only contain non-salted or statically-salted hash results.

Why this answer

Salts are random strings added to passwords before they are hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents the use of precomputed lookup tables (rainbow tables) from successfully identifying passwords.

Protecting against rainbow tables is a fundamental security practice that forces attackers to crack each hash individually, significantly increasing the time and computational resources required for a successful breach.

Exam trap

Candidates often mistakenly believe salts increase the complexity of the password itself or slow down the hashing algorithm's execution time, rather than focusing on the prevention of precomputed table lookups.

16
MCQmedium

A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?

A.--format=bcrypt
B.--format=sha512crypt
C.--format=md5crypt
D.--format=descrypt
AnswerB

The hash prefix $6$ indicates SHA-512 crypt, which is the default for many Linux systems. John the Ripper uses the format name sha512crypt for this. Specifying this format ensures John applies the correct algorithm and iteration count (rounds). This is the correct choice for the given hash.

Why this answer

The hash begins with $6$, which is the identifier for SHA-512 crypt. John the Ripper's format for this is sha512crypt. The other formats correspond to different algorithms (bcrypt, md5crypt, descrypt) that do not match the $6$ prefix.

Therefore, specifying sha512crypt is necessary for successful cracking.

Exam trap

The trap here is assuming that any Linux shadow hash uses the same format, ignoring the $ prefix that specifies the algorithm.

17
MCQeasy

A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?

A.MD5, and Hashcat can be used with mode 0.
B.SHA-256, and Hashcat can be used with mode 1400.
C.SHA-1, and Hashcat can be used with mode 100.
D.NTLM, and Hashcat can be used with mode 1000.
AnswerA

The hash is 32 hexadecimal characters, characteristic of MD5. Hashcat mode 0 is specifically for raw MD5 hashes. This is a common scenario in penetration testing when web applications use MD5 without salts. The tester can use Hashcat with a wordlist or rules to crack it. The hash `5f4dcc3b5aa765d61d8327deb882cf99` is the MD5 of 'password', a well-known example.

Why this answer

The hash is 32 characters long, which is the length of an MD5 hash. Hashcat mode 0 is used for raw MD5 hashes. This is a straightforward identification task.

The hash `5f4dcc3b5aa765d61d8327deb882cf99` is a common example (MD5 of 'password'), but the key is recognizing the format. A penetration tester should use this knowledge to select the correct cracking mode and proceed with offline cracking.

Exam trap

The trap here is confusing MD5 with NTLM because both produce 32-character hashes, but context and known hash examples help differentiate.

18
MCQmedium

You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?

A.The LMHash, because it is shorter and faster to calculate.
B.The RID, because it provides the unique identifier for the account.
C.The NTHash, because it is the primary hash used by NTLM authentication.
D.The entire string, including the colons, to ensure format integrity.
AnswerC

The NTHash is a MD4 hash of the Unicode representation of the plaintext password. Since Windows Vista, NTLM has become the standard authentication protocol. Targeting the NTHash allows for direct pass-the-hash exploitation without needing the plaintext, making it the most effective target for modern penetration testing engagements.

Why this answer

Modern Windows systems prioritize NTLM authentication, which relies on the NTHash. The LM hash is deprecated, weak, and often stored as a null value or a fixed constant in modern systems. Targeting the NTHash allows for pass-the-hash attacks or brute-force attempts that align with the underlying authentication protocol.

Understanding the structure of these hashes is crucial for penetration testers to select the correct dictionary or mask attack strategies during local account auditing.

Exam trap

Test-takers frequently focus on legacy LM hashes or duplicate empty fields, forgetting that modern Windows environments exclusively rely on NTLM authentication and NTHashes.

19
MCQmedium

A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?

A.The hash is a domain cached credential and requires mode 2100.
B.The hash is salted, and Hashcat mode 1000 does not support salts.
C.The LM hash is empty, and the NT hash corresponds to a blank password.
D.The hash was captured from a Kerberos ticket and requires mode 13100.
AnswerC

The LM portion `aad3b435b51404eeaad3b435b51404ee` is the well-known constant for an empty LM hash, and the NT hash `31d6cfe0d16ae931b73c59d7e0c089c0` is the NT hash of an empty string. Hashcat mode 1000 targets NTLM, but cracking a blank password yields no plaintext because the password is empty; the tool may not output it by default. Thus, the failure is due to the password being blank, not a format mismatch.

Why this answer

The hash consists of an LM part and an NT part separated by a colon. The LM part `aad3b435b51404eeaad3b435b51404ee` is the constant for an empty LM hash, and the NT part `31d6cfe0d16ae931b73c59d7e0c089c0` is the NT hash of an empty password. Hashcat mode 1000 correctly handles NTLM, but since the password is blank, cracking yields an empty string, which may not be displayed.

Thus, the failure is due to the password being blank, not a mode or salt issue.

Exam trap

The trap here is assuming that a failure to crack indicates an unsupported hash format or missing salt, when the password is simply blank and the tool may not output an empty plaintext.

Ready to test yourself?

Try a timed practice session using only Password Attacks and Formats questions.