Securitylab•September 13, 2026•🇷🇺Translated from Russian

Hashcat Password Cracking: Why Complex Passwords Like Summer2026! Often Fail First

Password Summer2026! appears strong with an uppercase letter, digits, a special character and sufficient length for many registration forms. Yet cracking programs can test such a pattern much earlier than a short random sequence because people create passwords according to recognizable templates that tools are designed to reproduce.

Hashcat and John the Ripper help recover forgotten passwords and evaluate account protection. Results depend on the storage algorithm, hardware and the order in which candidates are tested. Work should be performed only on authorized copies during agreed audits.

What Happens During Password Guessing

Services rarely store passwords in plaintext. At registration the application computes a verification value using a one-way function; on login it repeats the computation for the submitted password. A match grants access. The stored record is commonly called a hash even though it may also contain the algorithm name, salt and computation parameters.

Hashing differs from encryption because no key exists to reverse the operation. The cracking program proposes a candidate, performs the required computation and compares the result with the stored value. Weak passwords can be guessed without inverting the hash function. Known collision issues in MD5 and SHA-1 do not enable instant recovery of arbitrary passwords.

Plain MD5, SHA-1 and SHA-256 compute too quickly for direct storage of human passwords. Even cryptographically strong SHA-256 without a dedicated password scheme permits millions of guesses. Protection therefore requires functions that deliberately consume CPU time and, in modern variants, significant memory.

Why Salt and Expensive Computations Matter

A salt is a random value generated separately for each password entry and stored alongside the result. Different salts produce different verification values even for identical passwords and prevent precomputed tables from being reused across an entire database.

With unsalted hashes of the same type a program computes each candidate once and compares it against many records. Different salts force repetition of the expensive work for every salt. The claim that a million records always takes exactly a million times longer is incorrect; time depends on the number of unique salts, function parameters, hardware, discovered matches and computation organization.

Bcrypt uses a cost parameter that exponentially increases computational complexity. Moving from cost 10 to cost 12 multiplies the main workload by roughly four. Argon2id cost is influenced by memory size, number of passes and parallelism. Algorithm names alone are insufficient to assess protection.

Common Formats Encountered Today

Before starting, the exact contents of the file must be identified. A 32-character hexadecimal string may represent MD5, an NT hash or another value. Record origin, application source code and the complete format are more reliable than automatic detection.

  • NT hash (mode 1000): MD4 of the password in UTF-16LE without salt, common in Windows password storage.
  • NetNTLMv2 (mode 5600): network authentication response data requiring additional exchange fields.
  • sha512crypt (mode 1800): salted repeated SHA-512 computation, usually prefixed $6$.
  • bcrypt (mode 3200): salt and cost embedded in the record, often prefixed $2a$, $2b$ or $2y$.
  • phpass (mode 400): legacy records prefixed $P$ or $H$, still used by older WordPress installations.
  • Argon2id and yescrypt: memory-hard schemes whose exact support must be verified in the build.

Current Linux distributions including Debian, Ubuntu and Fedora have adopted yescrypt (prefix $y$) while older sha512crypt records persist until passwords are changed. WordPress 6.8 now uses bcrypt with SHA-384 preprocessing; new records begin with $wp$2y$.

Preparing Data and Tools

Hashcat excels at rule-based and mask attacks on compatible hardware. John the Ripper Jumbo offers broad format support and extraction utilities. Always work on copies, retain full records including salts and iteration counts, and validate the chosen mode against a known test password.

Why GPUs Do Not Always Deliver Maximum Speed

GPUs parallelize many identical independent computations efficiently for fast hashes. Memory-hard algorithms such as Argon2id, scrypt and yescrypt limit throughput because of memory bandwidth and access patterns. Built-in benchmarks provide baseline figures but real runs on the target set remain necessary.

Dictionaries, Rules, Masks and Statistical Models

Dictionary attacks test existing wordlists while rules transform each entry (case changes, digit insertion, character substitution). Masks describe character sets per position, for example ?u?l?l?l?l?d?d?d?d. Combined modes (-a 6, -a 7, -a 1) and multiple rule files multiply the candidate space rapidly. Markov models and neural generators produce probable passwords from training data but still require verification of every candidate.

Encoding and Length Limits

Passwords pass through several representations: user-visible characters, file bytes and algorithm-specific encodings such as UTF-16LE for NT hashes. Bcrypt commonly limits input to 72 bytes, reached earlier with Cyrillic text. The -O flag in hashcat can further restrict supported lengths for speed.

Interpreting Results and Avoiding Self-Deception

Status “Exhausted” only means the supplied candidate set finished; it does not prove remaining passwords are strong. The potfile records recovered pairs and should be managed carefully. Audits must log algorithm, parameters, record counts, hardware, software version and runtime. Debug options reveal which rules succeeded.

Actions After Testing

New applications should adopt Argon2id with parameters tuned to acceptable login latency. Records should be recomputed on successful login or password change. Long unique passphrases stored in managers outperform periodic complexity rules. Windows environments additionally require protection against Pass-the-Hash attacks even when the original password remains unrecovered.

Related articles

Habr•Other

Why Defending a Company Costs Millions While Attacks Can Succeed for Just Hundreds of Dollars

In the latest episode of Belyaev Podcast, CISO Vyacheslav Kasimov of Tochka Bank and Boris Evdokimov of ASNA pharmacy chain discussed the persistent asymmetry in cybersecurity spending. Attackers increasingly rely on affordable cloud services, automation, and rented infrastructure, while defenders must invest heavily in monitoring, access controls, backups, and skilled teams. The experts stressed that the absence of known breaches does not equal security, as undetected incidents or delayed discovery remain common risks. They advocated shifting from a "no" culture to risk-based decision making that helps business leaders understand potential losses, mitigation costs, and residual risk. The conversation also covered responsible use of AI in SOC operations and the long-term damage caused by loss of customer trust after incidents.

AntiMalware•Other

Beeline Offers One Month Free Access to Six Services for Prepaid Customers

Beeline has launched a promotional campaign allowing home users on prepaid plans to try up to six digital services for free over 30 days. The offer, tied to the operator's second annual Cellular Independence Day, runs from October 2 to October 9 and includes services such as Virtual Assistant PRO, unlimited mobile data, internet sharing without speed reduction, custom network name display, 250 GB of cloud storage, and access to over 650,000 e-books and audiobooks. Each selected service activates its own free period starting from the moment of connection and deactivates automatically afterward. Customers already paying for four or more of the listed services will receive 300 bonus rubles for communication instead. The unlimited data option is unavailable in the Chukotka Autonomous Okrug and Norilsk. Activation is handled exclusively through the Beeline mobile app, and users with existing paid subscriptions to any service cannot activate the free trial version of the same service.

Habr•Other

Enterprise-Grade Web Protection on a Budget: How Cloud WAF Lowers Barriers for SMBs

A new overview from Reg.cloud explains how cloud-based Web Application Firewalls reduce the cost and complexity of protecting websites, APIs, and web applications for small and medium-sized Russian businesses. According to Positive Technologies data cited in the article, 75% of successful web application attacks in 2025 disrupted organizational operations, while 82% of SMBs faced cyber incidents in the past year. The piece details the differences between traditional on-premises WAF deployments and cloud offerings, emphasizing ready-made protection profiles for CMS platforms, SaaS services, and digital agencies. It outlines a three-stage operational model covering preparation, DNS-based traffic redirection, and ongoing policy tuning that can be handled by existing DevOps or development teams without dedicated security staff. The service currently offers a free tier supporting up to three applications at 50 requests per second, along with seven preconfigured security profiles and dual audit/blocking modes. The article concludes by stressing that WAF remains only one layer and must be combined with patching, access controls, and separate DDoS or anti-bot solutions.

AntiMalware•Other

Yandex B2B Tech Integrates Hybrid Full-Text and Vector Search in Single YDB Query

Yandex B2B Tech has added hybrid search to its YDB database, allowing full-text and vector approaches to run together inside one SQL query. The update helps small and medium businesses as well as large corporations locate exact document identifiers while also matching semantic meaning in descriptions, even when wording differs. Full-text search handles precise elements such as policy numbers, codes, and names, whereas vector search identifies conceptual similarity. Results from both methods are merged and ranked within the same transaction, keeping all data inside a single database instance. This removes the need to maintain a separate search engine and vector store or to reconcile information between them. The technology is aimed at chatbots, recommendation systems, and AI assistants that process technical content where both exact codes and human-readable problem descriptions matter equally. Hybrid search is now available in the on-premises YDB 26.3 release and in the cloud-based Managed Service for YDB.