John — Инструмент для активного взлома паролей

Что это

John the Ripper — это инструмент, предназначенный для того, чтобы помочь системным администраторам находить слабые (легко угадать или взломать с помощью грубой силы) пароли и даже автоматически предупреждать пользователей об этом по электронной почте, если это необходимо.

Оригинал описания (EN)

John the Ripper is a tool designed to help systems administrators to find weak (easy to guess or crack through brute force) passwords, and even automatically mail users warning them about it, if it is desired.

Пример использования

root@kali:~# man SIPdump
SIPDUMP(1)                  General Commands Manual                  SIPDUMP(1)

NAME sipdump - Part of SIPcrack, A suite of tools to sniff and crack the digest authentications within the SIP protocol.

SYNOPSIS sipdump [options] <dump_file>

DESCRIPTION This manual page documents briefly the sipdump tool

 Session Initiation Protocol (SIP) is a protocol developed by the IETF MMU-
 SIC  Working  Group  and is a proposed standard for initiating, modifying,
 and terminating an interactive user session that involves multimedia  ele-
 ments  such  as video, voice, instant messaging, online games, and virtual
 reality.

 In November 2000, SIP was accepted as a 3GPP signaling protocol and perma-
 nent element of the IMS architecture.  It is one of the leading signalling
 protocols for Voice over IP, along with H.323. In most VOIP solutions  SIP
 is  used to authenticate the SIPclient.  The protocol is documented inside
 the RFC at www.ietf.org/rfc/rfc3261.txt

 SIPcrack is a SIP login sniffer/cracker that contains 2 programs:  sipdump
 to  capture  the digest authentication and sipcrack to bruteforce the hash
 using a wordlist or standard input.
 sipdump dumps SIP digest authentications. If a login is found, the sniffed
 login is written to the dump file.  See 'sipdump -h' for options.
 sipcrack bruteforces the user's password with the dump file  generated  by
 sipdump. If a password is found, the sniffed and cracked login will be up-
 dated in the dump file.
 See 'sipcrack -h' for options.

OPTIONS A summary of options is included below.

 -i interface,
        interface to listen on

 -p pcap_file,
        use pcap data file

 -m,</code></pre>

Пакеты и установка

john

Инструмент для активного взлома паролей
Установка: sudo apt install john

john-data

Инструмент для активного взлома паролей — наборы символов
Установка: sudo apt install john-data

Официальная документация

https://www.kali.org/tools/john/

Комментарии