CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A password policy requires exactly 8 characters formatted as one uppercase letter, followed by five lowercase letters, followed by two digits. Using a hashcat mask attack with the mask ?u?l?l?l?l?l?d?d, how many total password combinations must be tested?
- A26^8 ≈ 2.09 × 10^11
- B95^8 ≈ 6.63 × 10^15
- C62^8 ≈ 2.18 × 10^14
- D26 × 26^5 × 10^2 ≈ 3.09 × 10^10
Show answer & explanationAnswer & explanation
Correct answer: D. 26 × 26^5 × 10^2 ≈ 3.09 × 10^10
The mask ?u?l?l?l?l?l?d?d specifies one uppercase (26 options), five lowercase (26 options each), and two digits (10 options each): 26 × 26^5 × 10^2 = 26 × 11,881,376 × 100 = 30,891,577,600 ≈ 3.09 × 10^10. The other options represent brute-forcing the full printable set (95^8), all alphanumeric characters (62^8), or all uppercase-only (26^8), none of which match the known character-position structure exploited by the mask.
Why the other options are wrong
- A. 26^8 assumes all positions are letters only, ignoring the two digit positions.
- B. 95^8 assumes every position could be any printable character, ignoring the known structure.
- C. 62^8 assumes full alphanumeric charset at every position, ignoring the fixed pattern.
Hashcat Mask Attack
A targeted brute-force technique that defines the character set for each position in a password based on a known or suspected pattern, drastically reducing keyspace versus full brute force.
- ?u = uppercase, ?l = lowercase, ?d = digit, ?s = special
- Keyspace = product of charset sizes per position
- Far more efficient than full charset brute force when policy/pattern is known
Memory trick: 'Mask the password's shape and hashcat needs far fewer guesses'