CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard
A client's password policy requires passwords that begin with one uppercase letter, followed by six lowercase letters, and end with one digit, for a total of eight characters. A tester wants to build a hashcat mask attack (attack mode 3) that exactly reflects this policy. Which mask should be used?
- A?d?u?l?l?l?l?l?l
- B?l?u?u?u?u?u?u?d
- C?u?l?l?l?l?l?d?d
- D?u?l?l?l?l?l?l?d
Show answer & explanationAnswer & explanation
Correct answer: D. ?u?l?l?l?l?l?l?d
The policy requires 1 uppercase + 6 lowercase + 1 digit = 8 characters, in that exact order. Option A (?u?l?l?l?l?l?l?d) has 1 uppercase charset, six lowercase charsets, and 1 digit charset, matching the policy precisely. Option B reverses the order (lowercase first), option C puts the digit first, and option D only has 5 lowercase characters with 2 digits, none of which match the stated policy.
Why the other options are wrong
- A. Places a digit at the start, violating the policy's structure.
- B. Places a lowercase character first and uppercase letters afterward — wrong order.
- C. Only includes five lowercase characters and two digits, not matching 6 lowercase + 1 digit.
Hashcat Mask Attack Syntax
A hashcat mask attack (mode 3) defines a per-position character set using placeholders like ?l, ?u, ?d, and ?s to model known password structures.
- ?l = lowercase letter, ?u = uppercase letter
- ?d = digit, ?s = special character
- Masks dramatically reduce keyspace when password structure is known
Memory trick: Build the mask like spelling the password's DNA, position by position