This was a fun room to complete focussing on the password cracking tool John the Ripper. Definitely one of my favourite ones so far, getting password hashes and running them through the cracker in order to find out what the password was.
Most of the activities in this one were just following the instructions and I didn’t really have any issues with this at all. It was just really interesting to see how easily passwords can be cracked if you have access to the hashes.
I suspect in this room that the passwords were fairly simple and guessable as they were mostly cracked in under one second. I’m interested to try creating a few hashes of my own now to see how long they would take to crack.
This will be a good room to use as a basis for some password cracking activities in my classes as I think that high school students will be able to follow on and should be fairly interested to try out this tool.
The only issue I had with this room was the shadow password section, which informed you to create two files then run the unshadow tool on them in order to create a hash that you can then crack. After trying it a few times, John the Ripper kept telling me there were no hashes to crack. I ended up having to do some digging and found out that you didn’t have to go through the unshadow part as you could just run through the file as normal and that worked. Not sure if that’s the proper way around as I couldn’t find anything about it online.
This was a fun experience in this room, and practical. I’m almost finished the Complete Beginner pathway now. Looking forward to what’s coming up next!