YouTube2Text

How to Crack Any Password using Kali Linux? — Transcript

by TechSky - Ethical Hacking · 1,292 words · 92 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Whenever you hear about a massive data breach - Facebook users compromised,
  2. 0:05Instagram credentials leaked, millions of accounts sold on the dark web - you might feel a sense of
  3. 0:11relief if you understand basic security. You know passwords are not stored in plain text.
  4. 0:16Companies hash them. So even if the database gets stolen, your actual password is safe,
  5. 0:22right? That's exactly where the misunderstanding creates the risk.
  6. 0:35Welcome back to Tech Sky. We're diving into password cracking: how attackers recover passwords
  7. 0:41from stolen databases and encrypted files. You'll learn why password hashing doesn't
  8. 0:47guarantee safety, how dictionary attacks work, how brute-force systematically breaks passwords, and
  9. 0:53what actually makes a password secure. Before we begin, I need to make something absolutely clear:
  10. 1:00everything demonstrated in this video is strictly for educational purposes only. The knowledge you're
  11. 1:06about to gain comes with significant responsibility. Password cracking tools are
  12. 1:12powerful for security research, penetration testing, and auditing your own security.
  13. 1:18However, using these techniques against files or accounts you don't own or have explicit
  14. 1:23authorization to test is not only unethical but illegal in many jurisdictions. All
  15. 1:29demonstrations use only files we create and own. So let's address that false sense of security.
  16. 1:39Open your terminal and make sure your system is updated. Type "sudo apt update" to refresh
  17. 1:45package lists, then "sudo apt upgrade" to install available updates. This ensures all our tools work
  18. 1:52correctly. Now we need a file to protect. Type "echo 'Tech Sky confidential data' >
  19. 1:59secret.txt" to create a text file with sensitive content. You can see the file is created, but it's
  20. 2:07not secured - anyone with access to this file can read its contents freely. To protect it,
  21. 2:13we'll put it in a ZIP archive with password encryption. Type "zip --encrypt protected.zip
  22. 2:20secret.txt" and press Enter. It prompts for a password. We're setting a simple 6-character
  23. 2:28password here - type "abc123", then confirm it. The file is now encrypted inside the ZIP archive. Try
  24. 2:37to unzip or open it, and you cannot without the password. Our secret file is protected. Now here's
  25. 2:43where password cracking begins. Encrypted files store password hashes, not the actual passwords.
  26. 2:51To crack the password, we first need to extract that hash. Type "zip2john protected.zip >
  27. 2:58zip_hash.txt" and press Enter. John the Ripper, the tool we just used, supports many file formats
  28. 3:07for hash extraction: ZIP files, PDF documents, Office files, RAR archives, encrypted SSH keys,
  29. 3:16KeePass databases, and dozens more. Each file type has its own extraction command. Since we're
  30. 3:23working with ZIP, we used zip2john. Open the hash file - you can see a long, unreadable
  31. 3:30string. This is the password hash extracted from the encrypted ZIP file. This hash is useless until
  32. 3:37we discover what password created it, and that's exactly what we're about to do. The first method
  33. 3:42we'll use is called a dictionary attack. Instead of randomly guessing passwords, this method uses
  34. 3:49pre-built wordlists containing millions of common passwords, previously breached passwords,
  35. 3:55keyboard patterns, and variations. Attackers maintain massive collections of these wordlists -
  36. 4:02some contain billions of entries compiled from real data breaches over decades. Kali
  37. 4:07Linux provides several wordlists by default. Type "ls /usr/share/wordlists" to see available
  38. 4:16lists. You can see multiple wordlists, but the most famous is "rockyou.txt". This wordlist
  39. 4:23contains over 14 million real passwords from an actual data breach. It's the standard for password
  40. 4:29cracking demonstrations and penetration testing. Before we can use it, we need to extract it from
  41. 4:35its compressed format. Type "sudo gzip -d" followed by the "rockyou.txt.gz" file path in the wordlists
  42. 4:44directory and press Enter. The file extracts and is now ready to use. Now we launch the
  43. 4:50dictionary attack. Type "john zip_hash.txt --wordlist=/usr/share/wordlists/rockyou.txt"
  44. 5:02and press Enter. Watch what happens - look at that, password cracked! John the Ripper
  45. 5:09tested millions of passwords per second from the wordlist, hashed each one, compared it to
  46. 5:14our extracted hash, and found the match. The password was "abc123", which appears
  47. 5:21near the beginning of the rockyou wordlist because it's an extremely common password.
  48. 5:26You can verify the cracked password any time by typing "john --show zip_hash.txt".
  49. 5:35It displays the recovered password clearly. Now understand something critical: this attack totally
  50. 5:41depends on your wordlist, the hash algorithm type, and the encryption strength. If the password isn't
  51. 5:48in your wordlist, the dictionary attack fails completely. If the file uses strong encryption,
  52. 5:54cracking takes significantly longer. Weak encryption like old ZipCrypto cracks in seconds.
  53. 6:01Strong AES-256 encryption takes exponentially more time for each password guess. Dictionary attacks
  54. 6:09are fast but limited - they only work if the password exists in your wordlist. What happens
  55. 6:14when it doesn't? Let's test that scenario. Remove the protected ZIP file and the hash
  56. 6:20file. Now encrypt the secret file again with a new password that definitely isn't in any wordlist.
  57. 6:28Type the same ZIP command, but this time use the password "x2f3h" - a random 5-character string.
  58. 6:36Extract the hash again using the same zip2john command. Now run the dictionary attack against
  59. 6:43this new hash. Watch closely - John the Ripper searches through the entire rockyou wordlist, 14
  60. 6:50million password attempts, and finds nothing. The attack fails. If you run "john --show" now,
  61. 6:57it reveals nothing. The password wasn't in the wordlist, so the dictionary attack is useless.
  62. 7:03This is where brute-force comes in. Unlike dictionary attacks that use pre-built lists,
  63. 7:09brute-force systematically generates and tests every possible password combination within defined
  64. 7:15parameters. You're not guessing randomly - you're making informed assumptions about the
  65. 7:21password based on the target. For example, if the target frequently works with files and needs quick
  66. 7:27access, they probably set a short password - maybe 4 to 5 characters, likely lowercase letters
  67. 7:34and numbers for simplicity, no special characters or uppercase because those are harder to type
  68. 7:39quickly. We design our brute-force attack around that scenario. Type "john zip_hash.txt --incremental
  69. 7:46--incremental=LowerNum --min-length=4 --
  70. 7:55max-length=5". Let me explain what this does: the incremental mode uses brute-force,
  71. 8:03LowerNum means only lowercase letters and numbers, min-length 4 and max-length 5 restrict the
  72. 8:09search to 4 or 5 character passwords. And there it is - password cracked! Our dictionary
  73. 8:16attack failed completely, but brute-force succeeded because we correctly predicted the password
  74. 8:21pattern. This is how real password cracking works: dictionary attacks for speed against common
  75. 8:27passwords, brute-force for targeted attacks when you understand the password creation patterns.
  76. 8:36So how do you protect yourself? First, length matters more than complexity. A 16-character
  77. 8:43password of random words is stronger than an 8-character password with symbols. Why? Because
  78. 8:49the number of possible combinations grows exponentially with each additional character.
  79. 8:55Second, use truly random passwords - not patterns, not variations of dictionary words, not personal
  80. 9:03information. Use a password manager to generate and store cryptographically random passwords.
  81. 9:10Third, understand that file encryption is only as strong as the password protecting it. AES-
  82. 9:17256 encryption is unbreakable with current technology, but if your password is "abc123",
  83. 9:24the encryption is worthless. Fourth, for sensitive files, use passphrases instead
  84. 9:30of passwords. Four or five random words create passwords that are both strong and memorable.
  85. 9:36"Correct horse battery staple" is infinitely stronger than "password123". Finally,
  86. 9:42enable additional encryption layers when possible. Encrypt the entire drive with Bit
  87. 9:48Locker on Windows or LUKS on Linux. Use encrypted containers with VeraCrypt. File-level encryption
  88. 9:55is your last line of defense, not your only one. If you found this demonstration valuable,
  89. 10:00hit that like button and hype the video. Subscribe and turn on notifications so
  90. 10:06you never miss a security tutorial. Share this with someone who still thinks their 8-character
  91. 10:11password is secure. In the comments, tell me what topic I should cover next. Until then,
  92. 10:18this is Tech Sky, your ultimate battleground of cybersecurity and ethical hacking.

About this transcript

This page contains the full transcript of How to Crack Any Password using Kali Linux? by TechSky - Ethical Hacking, generated from the public captions YouTube serves with the video. The transcript has 1,292 words across 92 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.