> For the complete documentation index, see [llms.txt](https://hackingforbabies.gitbook.io/en/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackingforbabies.gitbook.io/en/wifi-cracking/hashcat-cracking.md).

# Hashcat Cracking

## <mark style="color:blue;">Overview</mark>

Cracking Wi-Fi passwords using Hashcat is a technique employed to recover the original password from a captured Wi-Fi handshake or PMKID hash. Hashcat is a powerful password recovery tool that utilizes the computational power of GPUs or CPUs to perform brute-force, dictionary, or mask-based attacks. By leveraging various attack modes and wordlists, Hashcat attempts to find the correct password by hashing and comparing it to the captured hash. This process can be time-consuming and resource-intensive, depending on the complexity of the password and the available computing power. It is important to note that cracking Wi-Fi passwords without proper authorization is illegal and unethical.

you can find here the official documentation of Hashcat (and how to use it):

{% embed url="<https://hashcat.net/wiki/doku.php?id=mask_attack>" %}

## <mark style="color:blue;">Cracking WPA WIFI Handshake</mark>&#x20;

1. converting the cap file

* converting the cap captured file into a hccapx file&#x20;

```
sudo /usr/share/hashcat-utils/cap2hccapx.bin captured_file.cap wpa2.hccapx
```

* converting the cap captured file into a hc22000 file

```
hcxpcapngtool -o wpa2.hc22000 captured_file.cap
```

2. Cracking the hc22000 file using Hascat&#x20;

* Check GPU :

```
hashcat -I
```

* Cracking 8 digits WPA WIFI Password

```
hashcat -m 2500 -a 3 wpa2.hccapx ?d?d?d?d?d?d?d?d
```

{% hint style="info" %}
You can press "s" to see the status of the hashing
{% endhint %}

{% hint style="info" %}
to show the cracked password type:

\[the previouse command] --show
{% endhint %}

* Increment from 8 to 20 digits WPA2 WIFI Password

```
hashcat -m 2500 -a 3 wpa2.hccapx --increment --increment-min 8 --increment-max 20 ?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d
```

* Cracking 8 digits WPA WIFI Password (hc22000 method)

```
hashcat -m 22000 wpa2.hc22000 -a 3 ?d?d?d?d?d?d?d?d
```

* Cracking 10 digits WPA WIFI Password (hc22000 method)

```
hashcat -m 22000 wpa2.hc22000 -a 3 ?d?d?d?d?d?d?d?d?d?d
```

* Cracking 10 digits and alphabetic (Lowercase and uppercase) WPA WIFI Password (hc22000 method)

```
hashcat -m 22000 wpa2.hc22000 -1 ?d?l?u -a 3 ?1?1?1?1?1?1?1?1?1?1
```

* Increment from 8 to 18 digits WPA2 WIFI Password (hc22000 method)

```
hashcat -m 22000 wpa2.hc22000 -a 3 --increment --increment-min 8 --increment-max 18 ?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d
```

* Increment from 8 to 12 digits and alphabetic (Lowercase and uppercase) WPA2 WIFI Password (hc22000 method)

```
hashcat -m 22000 wpa2.hc22000 -1 ?d?l?u -a 3 --increment --increment-min 8 --increment-max 12 ?1?1?1?1?1?1?1?1?1?1?1?1
```

## <mark style="color:blue;">Cracking PMKID</mark>

1. converting the pcapng captured file into a hc22000 file&#x20;

```
hcxpcapngtool -o hash.hc22000 -E essidlist dumpfile.pcapng
```

{% hint style="info" %}
essidlist: list containing all SSIDs captured previously&#x20;

hash.hc22000: the new format of the capured file
{% endhint %}

2. finding the mac address of the target WIFI

first, Stop all services accessing the WIFI Network

```
sudo systemctl stop NetworkManager.service 
sudo systemctl stop wpa_supplicant.service
```

second, scaning&#x20;

```
sudo hcxdumptool --do_rcascan -i [interface]
```

finally, you can copy the mac address in any file and complete the steps&#x20;

{% hint style="info" %}
you can restart the Network services.

if you don't restart it is not a problem but in upcoming work with kali you can face some problem while connecting to the internet.
{% endhint %}

3. Cracking the hc22000 file using Hascat

* &#x20;cracking the WIFI using a wordlist

```
hashcat -m 22000 hash.hc22000 wordlist.txt
```

{% hint style="info" %}
you can edit the hash.hc22000 file by deleting the unneeded data of other WIFI Network
{% endhint %}

{% hint style="info" %}
you can use any wordlist you want in this command (exemple: rockyou.txt)
{% endhint %}

* brute forcing an 8 digit password WIFI Password

```
hashcat.exe -m 22000 hash.hc22000 -a 3 ?d?d?d?d?d?d?d?d
```

* brute forcing an 8 to 18 digit password WIFI Password

```
hashcat.exe -m 22000 hash.hc22000 -a 3 --increment --increment-min 8 --increment-max 18 ?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d?d
```

## <mark style="color:blue;">Using GPU Cloud</mark>

You can watch [This YouTube Video](https://www.youtube.com/watch?v=nHDixd-EdEQ) created by [David Bombal](https://www.youtube.com/@davidbombal) to learn more about Cracking WIFI  using GPU Cloud : how to setup an cloud and how to run the attack

## <mark style="color:blue;">Other YouTube Tutorials</mark>&#x20;

You can check those YouTube Videos/Tutorials about Hashcat Cracking

* [This YouTube Video](https://www.youtube.com/watch?v=Usw0IlGbkC4) (PMKID Cracking) created by [David Bombal](https://www.youtube.com/@davidbombal)&#x20;
* [This YouTube Video](https://www.youtube.com/watch?v=J8A8rKFZW-M) (Brute Force WPA2) created by [David Bombal](https://www.youtube.com/@davidbombal)&#x20;
* [This YouTube Video](https://www.youtube.com/watch?v=ZTIB9Ki9VtY) (Brute forcing using powerful GPU) created by [David Bombal](https://www.youtube.com/@davidbombal)&#x20;
* [This YouTube Video](https://www.youtube.com/watch?v=nHDixd-EdEQ) (Cracking using GPU Cloud) created by [David Bombal](https://www.youtube.com/@davidbombal)&#x20;

For more details about Password Attacking and Hashcat , Check this Chapter:

{% content-ref url="/pages/0DNXESVxetgj8FUqhxWJ" %}
[Password Attacks](/en/password-attacks.md)
{% endcontent-ref %}

{% content-ref url="/pages/9zCmgxrLS5nuMH0ChENH" %}
[Hashcat](/en/password-attacks/hashcat.md)
{% endcontent-ref %}
