A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?
The $6$ prefix is the standard identifier for SHA-512 crypt in Linux shadow files. Hashcat mode 1800 is specifically designed for sha512crypt, which includes the salt and iteration count. This mode handles the variable rounds and salt, making it the correct choice for cracking this hash. Using the wrong mode would result in failure to recognize the hash format.
Why this answer
The $6$ prefix in /etc/shadow indicates SHA-512 crypt. Hashcat mode 1800 is the correct mode for cracking sha512crypt hashes. Other modes correspond to different algorithms: mode 500 for md5crypt, mode 3200 for bcrypt, and mode 7400 for sha256crypt.
Identifying the prefix correctly is essential to select the right cracking mode and avoid wasted effort.
Exam trap
The trap here is confusing the $6$ prefix with other common hash identifiers like $5$ for SHA-256 or $2a$ for bcrypt, leading to selection of an incompatible Hashcat mode.