Security+ Attack Tools
with 100% correct
answers(100%
accuracy)
CeWl - answer Custom Word List generator. Crawls a URL and returns a list
of words that can be used by password crackers like John the Ripper. Can
also create a list of email addresses found in mailto links to use in brute
force attacks
Hashcat - answer Used to conduct rapid and targeted calculations. Ex:
combine password list and password hash values to brute force attack a
weak password
John the Ripper - answer Used to coordinate password cracking across
multiple computers. Find weak passwords. Ex: Hybrid attack of
compromised password file and brute force to find any user with one of
those passwords
Medusa - answer Login brute forcer
Mimikatz - answer Broadly used windows-focused tool that retrieves
passwords, NTLM hashes, and can conduct Kerberos attacks. Ex: used in
an offline attack with a Windows SAM registry hive file
THC-Hydra - answer a Unix/Linux friendly password guessing tool. It
supports dictionary based guessing but not full brute force guessing and
can guess passwords for more than a dozen protocols
with 100% correct
answers(100%
accuracy)
CeWl - answer Custom Word List generator. Crawls a URL and returns a list
of words that can be used by password crackers like John the Ripper. Can
also create a list of email addresses found in mailto links to use in brute
force attacks
Hashcat - answer Used to conduct rapid and targeted calculations. Ex:
combine password list and password hash values to brute force attack a
weak password
John the Ripper - answer Used to coordinate password cracking across
multiple computers. Find weak passwords. Ex: Hybrid attack of
compromised password file and brute force to find any user with one of
those passwords
Medusa - answer Login brute forcer
Mimikatz - answer Broadly used windows-focused tool that retrieves
passwords, NTLM hashes, and can conduct Kerberos attacks. Ex: used in
an offline attack with a Windows SAM registry hive file
THC-Hydra - answer a Unix/Linux friendly password guessing tool. It
supports dictionary based guessing but not full brute force guessing and
can guess passwords for more than a dozen protocols