Cracking MySQL passwords with John The Ripper

Dump MySQL Password Hashes mysql_hashdump extracts the usernames and encrypted password hashes from a MySQL server. You can then use jtr_mysql_fast module to crack them. The module is located in auxiliary/scanner/mysql. To use it set RHOSTS option to your target’s ip address and increase THREADS value. If you have managed to reveal root password then …

How to crack passwords with John the ripper

John the Ripper – is free and Open Source. You can find some passwords lists: here, here and here. To provide a wordlist to john you can do it with –wordlist argument like this: –wordlist=password.lst Suppose that you have a file passwords.txt like this: george:827ccb0eea8a706c4c34a16891f84e7b thanos:202cb962ac59075b964b07152d234b70 If you have installed john already, issue the folowing …