GO KALI FREE

John the Ripper

Password Attacks

Intermediatelow risk

John the Ripper is a free and open-source password security auditing and password recovery tool. It can crack various password hash types offline and is highly customizable with different attack modes and mangling rules.

Installation

sudo apt install john

Basic Syntax

john [options] <password-file>

Quick Facts

Full Name
John the Ripper
License
GPL v2+
Author
Openwall (Alexander Peslyak)
Written In
C
Platforms
Linux, Windows, macOS, Unix
Category
Password Cracking (Offline)
Hash Formats
Hundreds (auto-detected)
Attack Modes
Wordlist, Incremental, Single, External, Mask

Tool Overview

John the Ripper (JtR) is a free, open-source password security auditing and password recovery tool. First released in 1996, it has become one of the most versatile and widely-used password crackers in the world.

John excels at automatic hash type detection, making it accessible to beginners. It supports hundreds of hash formats including MD5, SHA, NTLM, bcrypt, DES, and can directly crack passwords from encrypted ZIP, RAR, PDF, and Office documents.

The tool operates entirely offline, making it safe for authorized password auditing without triggering account lockouts. It uses CPU-based cracking with multi-process support for parallelization across multiple cores.

Common Commands

john hashes.txtAuto-detect crack - Launch a quick start cracking session letting John automatically detect the hash type
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txtDictionary attack - Use a specific wordlist to test common passwords against the target hashes
john --show hashes.txtShow cracked - Display the cracked passwords alongside their associated usernames from the session
john --format=raw-md5 hashes.txtSpecify format - Manually set the hash type when the format is already known
john --incremental hashes.txtBrute force - Try all possible character combinations in an exhaustive search
john --incremental=digits hashes.txtDigits only brute force - Restrict character mutations to numeric patterns for PIN cracking
unshadow /etc/passwd /etc/shadow > combined.txtCombine Linux authentication files - Merge system user and shadow files into a format John can read
john --rules --wordlist=wordlist.txt hashes.txtRules mode - Apply wordlist mangling rules to mutate dictionary words into common variations
john --fork=4 --wordlist=wordlist.txt hashes.txtMulti-process execution - Distribute the workload across 4 CPU cores to speed up the cracking process
john --session=mycrack hashes.txtNamed session - Save the current cracking progress under a specified name for long operations
john --restore=mycrackRestore session - Resume an interrupted or paused cracking session from its last saved state
john --format=nt hashes.txtNTLM hashes - Target Windows SAM database or Active Directory password hashes
john --format=raw-sha256 hashes.txtSHA256 hashes - Target standard standalone SHA-256 cryptographic check values
john --format=bcrypt hashes.txtbcrypt hashes - Force parsing rules for modern, high-cost adaptive hashing algorithms
john --format=zip encrypted.zipZIP password - Attempt to crack password-protected ZIP archive extractions directly

Step-by-Step Guide

  1. 1Ensure you have gathered the cryptographic hashes legally
  2. 2Determine the exact algorithm used if it isn't automatically recognized
  3. 3Initiate the attack using a robust dictionary file
  4. 4Be prepared to wait, as complex algorithms take considerable time
  5. 5Press any key during execution to view live status updates
  6. 6Retrieve the decoded text by appending the --show flag
  7. 7Check the internal potfile for a complete history of recovered strings

Warnings

Use Cases

Linux Password Auditing

Crack /etc/shadow passwords using unshadow to combine passwd and shadow files.

Windows SAM Cracking

Recover passwords from extracted Windows SAM database hashes.

Encrypted Archives

Crack passwords from ZIP, RAR, and 7z archives using format-specific modes.

Document Passwords

Recover passwords from encrypted PDF and Office documents.

CTF Challenges

Solve cryptography and password cracking challenges in competitions.

Key Features

People Also Ask

How do I use John the Ripper on Kali Linux?

John is pre-installed on Kali Linux. Run 'john hashes.txt' to auto-detect the hash format, or specify with '--format=md5 hashes.txt'. Use '--wordlist=/usr/share/wordlists/rockyou.txt' for dictionary attacks. The community edition (jumbo) supports 200+ hash formats.

How do I crack Linux /etc/shadow passwords with John?

First combine passwd and shadow files: 'unshadow /etc/passwd /etc/shadow > hashes.txt'. Then crack with: 'john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt'. This only works on systems you own or have authorization to audit. The unshadow tool is included with John.

John vs Hashcat — which should I use?

John the Ripper is better for CPU-based cracking and obscure hash formats. Hashcat excels with GPU acceleration for common hashes (MD5, SHA-1, NTLM). John supports 200+ formats natively; Hashcat has better performance for supported formats. Many professionals use both.

How do I show cracked passwords in John?

Run 'john --show hashes.txt' to display all cracked passwords. Use '--format=raw-md5' to specify the hash type. The output shows each hash alongside its plaintext. Combine with '--incremental' to show only newly cracked hashes since last session.

Can John crack password-protected PDFs and ZIP files?

Yes. Use 'pdf2john protected.pdf > hash.txt' then 'john hash.txt' for PDFs. For ZIP files: 'zip2john protected.zip > hash.txt' then crack. John also supports RAR, 7z, Office documents, and KeePass databases via specialized extraction tools.

What is the John the Ripper wordlist location on Kali?

The default wordlist directory is '/usr/share/wordlists/'. The most commonly used file is 'rockyou.txt' — if it doesn't exist, decompress it: 'sudo gunzip /usr/share/wordlists/rockyou.txt.gz'. You can also use custom wordlists with the --wordlist flag.

Related Tools

Hashcat

Password Attacks

GPU-accelerated password cracker for maximum speed on large hash sets.

THC Hydra

Password Attacks

Online brute-force tool for testing cracked passwords against live services.

CeWL

Password Attacks

Custom wordlist generator for creating targeted dictionaries for John.

Crunch

Password Attacks

Wordlist generator based on character sets, patterns, and length ranges.

Medusa

Password Attacks

Online brute-force tool for testing cracked passwords against live services.

Frequently Asked Questions

What is John the Ripper?

John the Ripper is a free, open-source password cracker used for offline password recovery and security auditing. It automatically detects hash types and supports hundreds of formats including MD5, SHA, NTLM, bcrypt, and encrypted archives like ZIP and RAR.

How do I crack Linux passwords with John?

First combine /etc/passwd and /etc/shadow using: unshadow /etc/passwd /etc/shadow > combined.txt. Then run: john --wordlist=rockyou.txt combined.txt. Use --show to view cracked passwords.

What is the difference between John the Ripper and Hashcat?

John the Ripper automatically detects hash types and runs on CPU without special hardware. Hashcat requires manual mode selection but offers GPU acceleration for much faster cracking. John is better for quick testing; Hashcat for maximum speed.

Can John crack ZIP and RAR passwords?

Yes. Use zip2john or rar2john to extract hashes from encrypted archives, then crack them with John. You can also directly crack some formats: john --format=zip encrypted.zip

What is John the Ripper mode vs. incremental mode?

Wordlist mode uses a predefined dictionary file. Incremental mode generates and tests all possible character combinations up to a length limit. Wordlist mode is faster for common passwords; incremental mode is exhaustive but much slower.

How do I use rules with John the Ripper?

Rules define password mutation patterns applied to wordlist entries. Use --rules or --rules=single for built-in rule sets. Custom rules can be defined in the john.conf file under [List.Rules] to match password policies like minimum length and special characters.

Can John crack Windows NTLM hashes?

Yes. John excels at cracking NTLM hashes extracted from SAM databases or NTDS.dit files. Use --format=nt for raw NTLM hashes. For domain environments, combine with secretsdump.py from Impacket for hash extraction.

How do I speed up John cracking sessions?

Use a larger wordlist (rockyou.txt), enable rules for mutations, increase fork count for multi-core CPUs (--fork=N), and ensure adequate RAM. For truly large-scale cracking, consider Hashcat with GPU acceleration.

What file formats can John the Ripper crack?

John supports over 200 hash formats including MD5, SHA-1, SHA-256, bcrypt, NTLM, Kerberos, SSH keys, SSL/TLS private keys, encrypted archives (ZIP, RAR, 7z), PDFs, Office documents, and database hashes from MySQL, PostgreSQL, and Oracle.

How do I extract hashes for John from different sources?

Use unshadow for Linux passwords, SAMdump2 for Windows SAM databases, secretsdump.py for Active Directory, hashdump for Metasploit, and specialized extractors like zip2john, rar2john, keepass2john, and dpapimk2john for specific formats.

How do I show cracked passwords with John?

Use: john --show hashes.txt to display all cracked passwords. Use --format to specify the hash format: john --show --format=raw-md5 hashes.txt. The output shows each hash alongside its cracked plaintext password.

Can John crack password-protected PDFs?

Yes, use pdf2john to extract the hash: pdf2john protected.pdf > pdf_hash.txt. Then crack with: john --wordlist=rockyou.txt pdf_hash.txt. John supports multiple PDF encryption formats including RC4 and AES.

Can John crack SSH private keys?

Yes, use ssh2john to extract the key hash: ssh2john id_rsa > ssh_hash.txt. Then crack with: john ssh_hash.txt. John supports RSA, DSA, ECDSA, and Ed25519 private key formats.

How do I use John with rules for password mutations?

Rules apply mutations to wordlist entries. Use --rules for built-in rules or --rules=single for single-word mutations. Custom rules go in john.conf under [List.Rules]. Rules add numbers, change case, apply leetspeak, and more.

Can John crack database password hashes?

Yes, John supports MySQL (mode 300), PostgreSQL (mode 12), MSSQL (mode 131), and Oracle (mode 112) password hashes. Extract hashes using database-specific tools or queries, then crack with the appropriate format flag.

How do I save and resume John sessions?

John automatically saves sessions to ~/.john/john_restore. Resume with: john --restore=session_name. Use --session=NAME to name sessions for easier management of multiple cracking tasks.

How do I use John with a custom charset?

For incremental mode, define custom charsets in john.conf under [Incremental:NAME]. Example: [Incremental:AlphaNum] defines letters and numbers. Use: john --incremental=AlphaNum hashes.txt for exhaustive searching with that charset.

Can John crack Kerberos TGT hashes?

Yes, John supports Kerberos 5 TGT (mode 7500) and Kerberos AS-REP (mode 18200) hashes. Extract Kerberos hashes using Impacket's GetUserSPNs.py or Rubeus, then crack with John's Kerberos format support.

How do I update John the Ripper to the latest version?

Update the community edition from GitHub: cd john/src && ./configure && make. This compiles the latest version with new hash format support and performance improvements. Check the version with john --help.

Tags

#password-attacks#offline-cracking#brute-force#hash-cracker#dictionary-attack

Output Explanation

The software outputs the recovered cleartext next to the corresponding user identifier. Status prompts indicate the current speed and an estimated completion timeframe.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.