Info severity Tool

John the Ripper

Offline password cracker for testing hash strength from leaked or captured databases.

Overview

John takes password hashes and attempts to recover the originals, using dictionary, rules and incremental modes.\nSecurity teams run it against their own exported hashes to find the weak minority that falls to guessing.\nIt supports an enormous range of hash formats and integrates with wordlist generators like Hashcat.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Large hash files staged on admin or build hosts
  • High sustained CPU use with no matching workload
  • Cracking session files in user directories

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used