Credential Testing Tools Flashcards

1
Q

Hashcat (Credential Harvesting Tools)

A
  • A free password recovery tool that is included with Kali Linux and is available for Linux, OS X, and Windows. It includes a very wide range of hashing algorithms and password cracking methods. Hashcat purports itself to be the fastest recovery tool available.
  • *Relies on GPU/CPU
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Hydra (Credential Harvesting Tools)

A

*A free network login password cracking tool that is included with Kali Linux. It supports a number of authentication protocols, repeated attempts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Medusa (Credential Harvesting Tools)

A

*A command-line-based free password cracking tool that is often used in brute force password attacks on remote authentication servers. It purports itself to specialize in parallel attacks, with the ability to locally test 2,000 passwords per minut

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CeWL (Credential Harvesting Tools)

A

*A Ruby app that crawls websites to generate word lists that can be used with password crackers such as John the Ripper. It is included with Kali Linux.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

John the Ripper (Credential Harvesting Tools)

A

*A free password recovery tool available for Linux, 11 versions of Unix, DOS, Win32, BeOS, and OpenVMS. It is included with Kali Linux.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Cain and Abel (Credential Harvesting Tools)

A
  • A free password recovery tool available for Windows that is sometimes classified as malware by some antivirus software.
  • Windows password cracker, conducts network sniffing and task cracking
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Mimikatz (Credential Harvesting Tools)

A
  • targets windows machines to extract plaintext passwords, hashes, PIN codes, and Kerberos tickets from the machines memory
  • can be used for pass the hash, pass the ticket, and creating golden tickets
  • *An open source tool that enables you to view credential information stored on Microsoft Windows computers. It is also included with Kali Linux.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Patator (Credential Harvesting Tools)

A
  • multi purpose brute force attack, supports modules for different target services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dirbuster (Credential Harvesting Tools)

A
  • brute force tool for directories and file names on web/application servers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

W3AF (Credential Harvesting Tools)

A

*Web Application Attack and Audit Framework, Python, tool to find and exploit any web app vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly