how to HACK a password // password cracking with Kali Linux and HashCat — Transcript
Full transcript
- 0:00password hacking in this video i'm going
- 0:02to show you how to hack into a server
- 0:03by cracking its password and this is
- 0:05real world you'll get a chance to do
- 0:07this yourself on my server
- 0:09also this is for educational purposes
- 0:10only please don't go hack somebody else
- 0:12without the permission
- 0:13only hack me you need to learn learn
- 0:16learn hacking
- 0:30[Music]
- 0:35okay the goal here is to hack into this
- 0:37server the coffee server
- 0:38why because once we do we get free
- 0:41coffee and coffee is awesome
- 0:42although you might need coffee for this
- 0:43so go ahead and get it now the good news
- 0:45is that we already have a username the
- 0:46username is dwight.schrute
- 0:49which is a great start but what we don't
- 0:51have is the password
- 0:53this is our mission we're going to hack
- 0:55dwight schrute's password
- 0:56and when i say hack i also mean crack oh
- 0:59and by the way this is a real server
- 1:00that i want you to try and break into
- 1:02watch until the end i've got a challenge
- 1:03and the first five people to complete
- 1:04that challenge will win free coffee
- 1:06legit all right here we go i want also a
- 1:08huge shout out to it pro tv the sponsor
- 1:10of this video and my hacking journey
- 1:12they're my primary learning source for
- 1:13learning things like this so if you want
- 1:15to dive deeper
- 1:16check it out link below if you use my
- 1:17code network chuck you get 30
- 1:19off forever so yeah so how do we hack
- 1:22this password how do we crack it well we
- 1:23can do it the old-fashioned way right
- 1:24the good old dwight schrute method try
- 1:26zero zero zero
- 1:28zero zero zero no okay
- 1:31now try zero zero zero zero zero
- 1:34one ssh dwight dot schrute
- 1:38at my host and i just start trying
- 1:40passwords
- 1:41zero zero zero zero zero one no let's
- 1:44try it again zero zero zero zero two
- 1:46no that's not right let's try it again
- 1:47zero zero zero zero three oh let's try
- 1:50it again
- 1:51no why would you keep doing that there
- 1:53are better ways and we can even automate
- 1:54this process to make it killer check
- 1:56this out so what we were just doing is
- 1:57traditionally called a brute force
- 1:59attack
- 2:00we were gonna sit there and try every
- 2:01password under the sun until we found
- 2:02out dwight's password
- 2:04even if it took us five years not the
- 2:05most efficient use of our time
- 2:07now to be fair every attack i'm going to
- 2:09show you is technically a brute force
- 2:11attack but we refer to them in different
- 2:12ways but there are so many better ways
- 2:14and we're going to open up some hacking
- 2:15tools right now and they're amazing
- 2:16check this out the first tool i want to
- 2:18show you is called hydra so fire up kali
- 2:20linux
- 2:20launch your terminal and we'll get going
- 2:22we're going to use hydra for an online
- 2:24attack
- 2:24which basically means we're going to be
- 2:26trying our passwords on a live system
- 2:28we'll be entering those passwords in the
- 2:29prompt and getting denied as we keep
- 2:31trying them now hydra is going to do all
- 2:32the work for us we'll
- 2:33enter our command in step away and done
- 2:35but she's not going to do what we just
- 2:36saw
- 2:37just trying every password under the sun
- 2:39001 002
- 2:41no no no we're going to give her a list
- 2:43a list of passwords that we think
- 2:44might be it what we're doing here
- 2:46providing hydra with a list of passwords
- 2:48is called a dictionary attack
- 2:49and this is crazy effective because it
- 2:51has a list of common passwords that a
- 2:53lot of people might use
- 2:54and we have a lot of passwords at our
- 2:56disposal one list we have that's already
- 2:57built into kali linux is called the
- 2:59roku password list this company rock you
- 3:01got hacked
- 3:02back in 2009 and these hackers released
- 3:04all their passwords they found which
- 3:06were stored in plain text
- 3:07so now we get to use it and this list is
- 3:08massive let's take a look right now if i
- 3:10open another terminal here
- 3:11if you're on cali you can find it in
- 3:13user share
- 3:14word lists and there it is right there
- 3:16rockyu.txt
- 3:18and we'll just unzip that real quick
- 3:20sudo gzip
- 3:22d the file name rock u dot txt dot gz
- 3:25and let's take a look at it i'll cap the
- 3:27file right now
- 3:32look at that so many passwords i better
- 3:34stop before my computer has a heart
- 3:36attack
- 3:37there we go now i will not be using that
- 3:38list that list has 14 million
- 3:40passwords but i do have my own list here
- 3:43is my word list
- 3:44things i think dwight might use so let's
- 3:46try it out first i'll specify my
- 3:48username now i could do dash uppercase
- 3:50l to specify a file name like
- 3:53usernames.txt
- 3:54and look through a list of names now i
- 3:56already know it's dwight so i can just
- 3:57do a lowercase l and put in
- 3:59dwight dot shroot and then i'll specify
- 4:02my password file do dash
- 4:04uppercase p and my file which i have
- 4:05named word
- 4:07list dot txt
- 4:10i'll do a backslash to move to the next
- 4:12line here and then my host which is 45.
- 4:15blah blah blah and then the service type
- 4:17now right now i'm accessing the server
- 4:19using ssh
- 4:20so i'll specify ssh it could be ftp it
- 4:22could be telnet whatever
- 4:24and let's go oh password
- 4:28it's all about passwords bam you see how
- 4:30fast that was
- 4:31i mean the list wasn't big right but it
- 4:33found it check it out here's the
- 4:34password
- 4:35bears beats and went through my list
- 4:37tried each one this is the one now this
- 4:39method is fun
- 4:40and useful but let me tell you if you're
- 4:42trying a bunch of
- 4:43login attempts a bunch of passwords
- 4:45firewalls might find you you might get
- 4:47blocked
- 4:47plus you have timeouts the account
- 4:49probably will get locked out not the
- 4:51best method
- 4:52but we have another way a better way
- 4:53check this out let's take our password
- 4:55hacking from online
- 4:56to offline in this situation we're not
- 4:58going to try and log into the server a
- 4:59million times
- 5:00but how does that work how do we know if
- 5:02it's going to be the right password
- 5:04if we can't actually try it one word
- 5:07hashing
- 5:08what is that let's talk about it you see
- 5:10when mr dwight schrute created his
- 5:11password
- 5:12bears beats the server will take this
- 5:14password and store it in its database
- 5:16so that when dwight logs in they can go
- 5:18oh that is dwight's password
- 5:19come on in dwight but they don't store
- 5:21it like this in plain text like you
- 5:23won't log in and see
- 5:24bears beats it won't be there actually
- 5:26let me show you what it looks like right
- 5:27now on that server it'll look like this
- 5:31this right here is dwight's password
- 5:33this crazy mess of numbers and letters
- 5:35is called a hash
- 5:36so when dwight created this password
- 5:37bears beats the coffee server
- 5:39hashed it basically put in his mouth
- 5:41chewed it up and spit it out
- 5:42looks like this now now it's a lot more
- 5:44complex than just chewing it up and
- 5:45spitting it out
- 5:47for the server to turn bears beats into
- 5:48this it uses these crazy hashing
- 5:50algorithms
- 5:51which without getting two in the weeds
- 5:53on it is just a crazy math
- 5:54problem function turning it into this
- 5:57you might already be familiar with some
- 5:58of the hashing algorithms out there
- 6:00popular ones are md5 sha-256
- 6:03you got ntlm on windows and if we were
- 6:05to somehow hack into the server
- 6:07via other means and get a list of all
- 6:09the username and passwords
- 6:10that look like this it would do us zero
- 6:13good no good at all when dwight logs in
- 6:16and he put this password in bears beats
- 6:18the server takes this password
- 6:20chews it up spits it out or in this case
- 6:22runs it through its md5 algorithm
- 6:24and if the hash matches the hash stored
- 6:26in its database
- 6:27you can go in you're good this should be
- 6:29how most websites and services out there
- 6:31are storing your passwords
- 6:32not in plain text like the roku server
- 6:35no no it's hashed so if they do get
- 6:36hacked and hackers
- 6:38get that list of usernames and passwords
- 6:40they don't have your password
- 6:41yet here's what we can do we may not
- 6:43have dwight's password
- 6:45but if we have his hash if we somehow
- 6:47got that information we can do some
- 6:48offline password cracking to figure out
- 6:50what it is
- 6:51now again we can't reverse engineer it
- 6:53but we can
- 6:54brute force our way into it we're going
- 6:56to do what we did before we're going to
- 6:57take our word list and we're going to
- 6:59try and use each of these passwords
- 7:00but instead of trying to log into the
- 7:02server we're going to run that hashing
- 7:04algorithm we're going to chew it up and
- 7:05spit it out we're going to run
- 7:07that md5 algorithm and see if it matches
- 7:10the hash
- 7:11we have for dwight schrute so we'll take
- 7:12the first password salesman of the year
- 7:14three
- 7:15run it through it looks like this
- 7:17doesn't match we move on
- 7:18we try password one two three and we get
- 7:20this not a match we move on and we keep
- 7:22going until we find a hash that matches
- 7:24and we'll try bears beats and boom this
- 7:27one does match
- 7:28a plus let's go we got the password
- 7:30let's hack into the system
- 7:31let's do this right now okay here in
- 7:32cali we're going to try out a tool
- 7:34called
- 7:34hashcat for this tool we're going to use
- 7:36two things first
- 7:38our word list our list of possible
- 7:39passwords and two we'll need our file of
- 7:41hashes
- 7:42let's go and create this real quick
- 7:43linux will store its hash passwords in
- 7:45the
- 7:46shadow file so i'll grab that right now
- 7:49i'll just create that file paste all
- 7:51that stuff in there
- 7:53save that now let's crack a password the
- 7:55command will be sudo
- 7:57cat now real quick hash cat's pretty
- 7:59crazy you can do a lot of stuff
- 8:01i'm going to show you the basics real
- 8:02quick first we'll start with the method
- 8:03which we'll specify with dash a
- 8:06let's go to the manual page of our
- 8:07hashcat real quick so open up another
- 8:08terminal window and go to man
- 8:10and hashcat a lot of stuff going on let
- 8:13me scroll through to where i'm talking
- 8:14about
- 8:15so we used dash a and here are the
- 8:17options and if i talked about every one
- 8:18of these options this video would be
- 8:20like four hours long so i'm only going
- 8:21to talk about
- 8:22option zero the straight option which is
- 8:25just going through a word list
- 8:27and doing what we just talked about
- 8:28these other options which i would ignore
- 8:30brute force but combination hybrid word
- 8:33list and mask hybrid mask with word list
- 8:35and some crazy stuff it's not just going
- 8:37through a word list but it's auto
- 8:38generating
- 8:39these crazy password lists and these
- 8:41password combinations and what password
- 8:42characters you can use
- 8:43it can be intense and perhaps it's a
- 8:45video for another time for now we're
- 8:46going to talk about just a straight
- 8:48dictionary attack option zero so we'll
- 8:50put in
- 8:51zero now next is our hashing type we'll
- 8:53put in dash m to specify that
- 8:55let's go back to our man page here we
- 8:57have our hashing types and there's a
- 8:59lot a lot of hashing types and this can
- 9:01be based on what type of password you're
- 9:03trying to hack
- 9:04for example if you know you're gonna be
- 9:05hacking cisco look at that you'll enter
- 9:07the
- 9:08code 5700 in that option for a plain
- 9:10jane md5 it'll be zero
- 9:121000 for ntlm which if you're hacking
- 9:14windows based passwords
- 9:15that's what you'll use and for our
- 9:16example we're going to be using 1800 for
- 9:18sha-512
- 9:20unix passwords so we'll put in 1800
- 9:23i'm also going to throw in a dash
- 9:24lowercase o and specify a file name
- 9:28crackpasswords.txt this is where it's
- 9:29going to store
- 9:30the information we find out and then
- 9:32finally the two files we're going to be
- 9:34using the first will be our hashes which
- 9:35we named hashes
- 9:37dot txt and then our word list we're
- 9:39going to use which was word list
- 9:41dot txt and that's all we need hash
- 9:44cat's about to spit some words out let's
- 9:46do it here we go
- 9:49and that gum that was fast
- 9:53now again the word list was not that big
- 9:55and it found the password if you look
- 9:56here at candidates dot number one
- 9:58it gave us two options eminem and bears
- 10:02beats now we know that bears beats is
- 10:03the correct password so great job
- 10:05hashgat now let's try one more let's try
- 10:07a windows based password i'll do sudo
- 10:09hash cat once more do a dash a specify
- 10:12oh not dash one
- 10:13dash a and specify my method which will
- 10:16be zero
- 10:17dash m this time i'm doing ntlm for
- 10:19microsoft windows
- 10:21i know this to be 1000 as the code by
- 10:24looking at the manual page i'll do a
- 10:25dash lowercase o
- 10:26for correctpasswords.txt where i'm going
- 10:28to store my stuff
- 10:30and then my hash now i could specify a
- 10:31file this time i'm going to specify the
- 10:33hash
- 10:34i'm just going to copy that in there so
- 10:35i'll just put that in quotes so i got
- 10:37the one hash i'm looking for
- 10:38then i'll put my word list in right here
- 10:41wordlist.txt
- 10:43and go now it's a bit wonky because it
- 10:46says the candidates right now are
- 10:48bears beats which i know is not the
- 10:49password but if i go to the top here
- 10:52it says the session status cracked it
- 10:54said it did it with this hash let's go
- 10:56look in that file we
- 10:57put that in so i'll sudo cat
- 11:00crackpasswords.txt
- 11:01and let's take a look inside there there
- 11:03it is okay perfect there's the hash i
- 11:05used
- 11:06and there's the password for my word
- 11:07list that we matched up
- 11:09and that was indeed the password so now
- 11:11i have a challenge for you i want you to
- 11:13use the skills
- 11:14you just learned in this video to hack
- 11:16or crack
- 11:17my server's passwords the first five
- 11:19people to do this will win coffee
- 11:21so link below good luck and if you don't
- 11:23win that's fine
- 11:24i'll keep this challenge up for probably
- 11:26a week or maybe two weeks and i would
- 11:28love for you to let me know below what
- 11:29you think about it and again it's using
- 11:30the skills we just talked about here in
- 11:32this video i'm gonna have you crack a
- 11:33password via the online method
- 11:34using a word list using hydra bam bam
- 11:37bam automation and then i'm gonna have
- 11:38you crack an offline password
- 11:40using a word list a hash a password hash
- 11:43using hashcat now there's a lot more to
- 11:45password hacking or cracking
- 11:47i just scratched the surface here but i
- 11:49wanted to get you started
- 11:50hashcat is a crazy program that you can
- 11:52use to do some
- 11:53well crazy stuff if you have something
- 11:55like a beastly gaming pc like this
- 11:57this boy behind me with a crazy cpu and
- 11:59a crazy gpu
- 12:00you can do some serious password
- 12:02cracking going through massive word
- 12:04lists i'm talking millions and millions
- 12:05of passwords in these lists
- 12:07anyways guys that's about it password
- 12:09hacking password cracking whatever you
- 12:10want to call it it's a powerful tool
- 12:12and again please do not use this in any
- 12:15way that's
- 12:16illegal which let me be very clear
- 12:18unless you have someone's explicit
- 12:20permission to do this
- 12:22it's illegal hack yourself hack your own
- 12:24passwords
- 12:25hack me i'm giving you permission to
- 12:27hack my just the one server
- 12:29nothing else in my challenge otherwise
- 12:31set up your own lab and do it and there
- 12:33do not use this for any illegal methods
- 12:36but beyond that i hope you like this
- 12:37video
- 12:38if you do like it like it and if you
- 12:39haven't already hit that subscribe
- 12:40button if you like what i'm doing here
- 12:42yep that's about it i'll catch you guys
- 12:50later
- 12:53[Music]
- 12:56you
About this transcript
This page contains the full transcript of how to HACK a password // password cracking with Kali Linux and HashCat by NetworkChuck, generated from the public captions YouTube serves with the video. The transcript has 2,741 words across 430 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.