Command library / john
john
Crack password hashes offline
Takes a file of password hashes and tries to recover the plaintext behind them — usually by trying every word in a wordlist (--wordlist=file). --format tells john what kind of hash it's looking at when it can't auto-detect it, and --show prints whatever has already been cracked without starting a new run.
Practice johnUsage
Options and flags
hashfilethe file containing the password hashes to crack
--wordlistFILEdictionary file to try passwords from
--formatTYPEthe hash type, when john can't auto-detect it (e.g. md5, sha256)
--showprint passwords already cracked in a previous run, without cracking again
Examples
john --wordlist=rockyou.txt hashes.txtClassic dictionary attack against a hash file using the rockyou wordlist.
john --format=md5 --wordlist=rockyou.txt hashes.txtSame attack, but the hash format is specified explicitly instead of auto-detected.
john --show hashes.txtSee what's already been cracked from an earlier run, instantly.
Common mistakes
john always needs the hash file itself as its last argument — the wordlist alone isn't something to crack.