Terminal Dojo
Help العربية Sign inGet started

Command library / john

john

BashDraft — pending expert review3 practice missions

Crack password hashes offline

Takes a file of password hashes and tries to recover the plaintext behind them — usually by trying every word in a wordlist (--wordlist=file). --format tells john what kind of hash it's looking at when it can't auto-detect it, and --show prints whatever has already been cracked without starting a new run.

Practice john

Usage

john [--wordlist=file] [--format=type] hashfile
Scope: Only against hashes you own or are explicitly authorised to test — for example your own lab captures or an authorised assessment. Cracking credentials you don't own is unauthorised access.

Options and flags

Examples

Common mistakes

john --wordlist=rockyou.txt john --wordlist=rockyou.txt hashes.txt

john always needs the hash file itself as its last argument — the wordlist alone isn't something to crack.

Related commands

hydra