GO KALI FREE

Crunch

Password Attacks

Beginnerlow risk

Crunch is a wordlist generator where you can specify a standard character set or a custom one. It can generate all possible combinations.

Installation

sudo apt install crunch

Basic Syntax

crunch <min> <max> [charset] -o <output>

Quick Facts

Full Name
Crunch
License
GPLv2
Author
Bohannon (various maintainers)
Written In
C
Platforms
Linux, macOS
Category
Wordlist Generation
Generation Method
Pattern-based (character sets)
Output
File or stdout (pipeable)

Tool Overview

Crunch is a wordlist generator that creates every possible character combination within specified parameters. It generates wordlists from minimum and maximum lengths, custom character sets, and pattern templates.

Unlike content-based tools like CeWL, Crunch creates wordlists mathematically. You define the character set (lowercase, uppercase, digits, symbols) and length range, and Crunch generates all permutations. This makes it ideal for creating PIN lists, brute-force dictionaries, and pattern-based wordlists.

Crunch can output directly to files or stdout, allowing it to pipe directly into other tools like Hashcat, John the Ripper, or Hydra without creating intermediate files.

Common Commands

crunch 6 6Generate all lowercase words of exactly 6 characters using the default charset
crunch 4 8Generate words from 4 to 8 characters long using the default lowercase charset
crunch 8 8 abcdefghijklmnopqrstuvwxyzGenerate 8-char words using a custom lowercase-alphabet charset
crunch 6 6 0123456789Generate all 6-digit numeric PIN combinations
crunch 6 8 -o wordlist.txtWrite generated 6-8 char words to a file instead of stdout
crunch 1 8 -f /usr/share/crunch/charset.lst mixalpha -o wordlist.txtUse a named charset from charset.lst and save to a file
crunch 8 8 -t @@@@@@@@ -o pass.txtUse a pattern of lowercase-letter placeholders to build the wordlist
crunch 12 12 -t Pass@@@@%%%%Build passwords with a fixed prefix plus lowercase and numeric placeholders
crunch 10 10 -t @@@@@^^^^^Generate words mixing lowercase letters and symbols via pattern placeholders
crunch 8 8 -t pass,%%%Use uppercase-letter placeholder (,) followed by numeric placeholders in a pattern
crunch 6 6 abcdef -s cadefStart generating from a specific word rather than the first combination
crunch 6 6 abc123 -e fff123Stop generating once a specific end word is reached
crunch 4 6 abc -d 2@ -o wordlist.txtLimit consecutive identical characters (max 2 of the same @ placeholder)
crunch 1 6 abcABC -c 1000 -o STARTSplit output into files of 1000 lines each (START is auto-renamed by content)
crunch 6 8 -b 20mib -o STARTSplit output into files no larger than 20 MiB each

Step-by-Step Guide

  1. 1Establish the minimum and maximum lengths for your requirements
  2. 2Pick the specific alphabet or numbers you wish to include
  3. 3Define the parameters within the command line
  4. 4Incorporate specific patterns if you know part of the string
  5. 5Execute the generation sequence

Warnings

Use Cases

PIN Generation

Generate all 6-digit numeric PINs for testing PIN-based authentication systems.

Pattern-Based Dictionaries

Create wordlists matching known password patterns like 'pass' + 4 digits.

Brute-Force Input

Pipe generated words directly into cracking tools without intermediate files.

Brute-Force Dictionaries

Generate complete character set combinations for exhaustive password testing.

CTF Challenges

Create custom wordlists for cryptography and password cracking challenges.

Key Features

People Also Ask

Is Crunch pre-installed in Kali Linux?

Yes, Crunch is included in the default Kali Linux installation, so no extra setup is needed. If it is missing on a minimal image you can add it with `sudo apt install crunch`. Verify the version with `crunch --version`.

What is the difference between Crunch and CeWL?

Crunch generates wordlists algorithmically from character sets and patterns you define, producing every possible combination. CeWL instead scrapes a website to build a wordlist from words that actually appear on it. Use Crunch for pattern-based or policy-based lists and CeWL for target-specific vocabulary during authorized testing.

How do I use a custom character set file with Crunch?

Crunch ships with `/usr/share/crunch/charset.lst`, which defines named sets like `lalpha` and `mixalpha-numeric-all`. Reference one with the `-f` flag, e.g. `crunch 8 8 -f /usr/share/crunch/charset.lst mixalpha -o wordlist.txt`. You can copy that file and edit it to define your own named character sets.

Can Crunch resume an interrupted wordlist generation?

Crunch has no true resume feature, but the `-s` flag lets you start generation from a specific string, e.g. `crunch 6 6 -s aab000`. By noting the last value written before an interruption, you can restart close to where you stopped instead of regenerating the whole keyspace.

Does Crunch support non-English or Unicode characters?

Crunch works with any byte values you pass in a custom character set, so accented and other characters can be included directly on the command line, e.g. `crunch 4 4 abcñé`. Full multi-byte Unicode support can be inconsistent, so verify a small sample of the output before generating a large list.

How do I split a large Crunch wordlist into multiple files?

Use `-b` to cap each file by size or `-c` to cap it by number of lines, combined with `-o START`. For example `crunch 8 8 -b 20mib -o START` writes a series of files no larger than 20 MiB each, which keeps individual files manageable for tools that struggle with huge inputs.

Related Tools

CeWL

Password Attacks

Website-based wordlist generator for target-specific dictionaries.

Hashcat

Password Attacks

GPU-accelerated cracker that uses Crunch-generated wordlists.

CUPP

Password Attacks

Personal information-based wordlist generator for social engineering targets.

John the Ripper

Password Attacks

CPU-based password cracker for testing Crunch-generated wordlists.

THC Hydra

Password Attacks

Online brute-forcer for testing Crunch-generated passwords against live services.

Frequently Asked Questions

What is Crunch?

Crunch is a wordlist generator that creates every possible character combination within specified parameters. It generates wordlists from character sets and patterns, making it ideal for PIN lists, brute-force dictionaries, and pattern-based password testing.

How do I generate a 6-digit PIN list with Crunch?

Use: crunch 6 6 0123456789 -o pins.txt. This generates all combinations from 000000 to 999999 (1 million PINs). The first two numbers are min and max length, followed by the character set.

How do I pipe Crunch output to Hashcat?

Use stdout piping: crunch 6 6 0123456789 | hashcat -m 0 hashes.txt. This streams PINs directly to Hashcat without creating intermediate files, saving disk space.

What do the pattern characters mean in Crunch?

@ generates lowercase letters, , generates uppercase letters, % generates numbers, and ^ generates symbols. For example, -t pass@@@@ generates 'pass' + 4 lowercase letters (passaaaa through passzzzz).

How do I limit Crunch output size?

Use -b for maximum bytes per file and -z to compress output. For very large character sets, use patterns to reduce output to only the combinations you need, or pipe directly to tools without saving files.

Can Crunch generate passwords with mixed character types?

Yes, use patterns like -t @@@@%%%% to generate 4 lowercase letters followed by 4 digits. Combine different pattern characters (@, ,, %, ^) in a single pattern for mixed character passwords.

How do I generate a wordlist for a specific password policy?

Analyze the policy requirements (length, character types) and create a matching pattern. For example, policy requiring 8 chars with uppercase, lowercase, digits, and symbols: use -t @@@@%%%% with appropriate character sets.

What is the maximum wordlist size Crunch can generate?

Crunch has no hard limit on output size, but generating all combinations of long passwords with large character sets creates enormous files. Always calculate output size first: charset_length^password_length equals total combinations.

How do I pipe Crunch directly to John the Ripper?

Use: crunch 8 8 abcdefg | john --stdin --format=raw-md5 hashes.txt. The --stdin flag tells John to read candidates from standard input instead of a wordlist file, saving disk space.

Can I use Crunch for WiFi password testing?

Yes, generate 8-digit PIN lists with crunch 8 8 0123456789 and pipe to Hashcat or Aircrack-ng. Crunch is commonly used for WPA PIN recovery and testing default router passwords.

How do I use Crunch with the -t pattern flag?

The -t flag specifies a pattern template: @ generates lowercase letters, , generates uppercase, % generates digits, and ^ generates symbols. For example, -t @@@@%%%% generates 4 lowercase letters followed by 4 digits.

How do I calculate Crunch output file size before generating?

Calculate total combinations: charset_length^min_length to charset_length^max_length. For 8-character lowercase: 26^8 = 208 billion combinations. Each word is 8 bytes + newline, so estimate approximately 1.7 terabytes.

Can Crunch generate passwords with special characters?

Yes, include special characters in the charset string or use ^ pattern. For example: crunch 8 8 '@%^*' generates 8-character combinations from the specified symbols. Combine with letters and digits for mixed character passwords.

How do I pipe Crunch output directly to Aircrack-ng?

Use: crunch 8 8 0123456789 | aircrack-ng -b MAC -w - handshake.cap. The -w - flag tells Aircrack-ng to read from stdin, streaming Crunch output directly without creating intermediate files.

Can Crunch generate only lowercase passwords?

Yes, use lowercase letters as the charset: crunch 6 6 abcdefghijklmnopqrstuvwxyz -o words.txt. This generates all combinations from aaaa to zzzzz using only lowercase characters.

How do I use Crunch in overwrite mode?

Use -o with a filename to save output. Crunch automatically overwrites the file. If you want to append instead, pipe output with >> to a file. Use stdout mode (no -o) for piping to other tools.

Can Crunch generate passwords with a known prefix?

Yes, use the -t pattern flag. For example, -t company@@@@ generates 'company' + 4 lowercase letters. The @ symbol generates lowercase, % generates digits, and ^ generates symbols in the pattern.

How do I generate a wordlist for a specific length range?

Specify min and max length: crunch 4 8 abcdefghijklmnopqrstuvwxyz generates words from 4 to 8 characters. Each length is generated separately, starting with 4-character words and progressing to 8-character words.

Can Crunch generate passwords without repeating characters?

No, Crunch generates all combinations with repetition by default. For non-repeating characters, you would need to post-process Crunch output or use custom scripts. Crunch is designed for maximum coverage including repeated characters.

Tags

#password-attacks

Output Explanation

Outputs a text file populated with every single mathematical permutation based on your input parameters.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.