Credential Testing Tools Flashcards

1
Q

Hashcat

A

a fast password recovery tool that helps break complex password hashes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Medusa

A

ntended to be a speedy, massively parallel, modular, login brute-forcer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Hydra

A

a brute-forcing tool that helps penetration testers and ethical hackers crack the passwords of network services. Hydra can perform rapid dictionary attacks against more than 50 protocols. This includes telnet, FTP, HTTP, HTTPS, SMB, databases, and several other services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CeWL

A

(Custom Word List generator) is a ruby app which spiders a given URL, up to a specified depth, and returns a list of words which can then be used for password crackers such as John the Ripper. Optionally, CeWL can follow external links.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

John the Ripper

A

a free password cracking software tool.[3] Originally developed for the Unix operating system, it can run on fifteen different platforms (eleven of which are architecture-specific versions of Unix, DOS, Win32, BeOS, and OpenVMS). It is among the most frequently used password testing and breaking programs[4] as it combines a number of password crackers into one package, autodetects password hash types, and includes a customizable cracker.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Cain

A

WAS (deprecated) a password recovery tool for Microsoft Windows. It could recover many kinds of passwords using methods such as network packet sniffing, cracking various password hashes by using methods such as dictionary attacks, brute force and cryptanalysis attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Mimikatz

A

well known to extract plaintexts passwords, hash, PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash, pass-the-ticket or build Golden tickets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Patator

A

multi-purpose brute-forcer, with a modular design and a flexible usage. Currently it supports the following modules: ftp_login : Brute-force FTP. ssh_login : Brute-force SSH. telnet_login : Brute-force Telnet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

DirBuster

A

a multi threaded java application designed to brute force directories and files names on web/application servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

w3af

A

an open-source web application security scanner. The project provides a vulnerability scanner and exploitation tool for Web applications. It provides information about security vulnerabilities for use in penetration testing engagements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly