CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester has obtained a database dump that includes password hashes in an unknown format. They need to identify the hashing algorithm used to then attempt to crack them. They notice that the hashes are 32 characters long and appear to contain only hexadecimal digits. Which hashcat mode is BEST suited for identifying and cracking such a hash, given its characteristics?
- AMode 0 (MD5)
- BMode 900 (MD4)
- CMode 100 (SHA1)
- DMode 1000 (NTLM)
Show answer & explanationAnswer & explanation
Correct answer: A. Mode 0 (MD5)
A 32-character hexadecimal hash is a strong indicator of an MD5 hash. MD5 produces a 128-bit hash, which is 32 hexadecimal characters (128 / 4 bits per hex character = 32). Hashcat mode 0 is specifically for MD5. While other hashes can be 32 chars, MD5 is the most common for this format.
Why the other options are wrong
- B. MD4 hashes are 128-bit, also 32 hexadecimal characters, and Hashcat mode 900 is for MD4. However, MD5 (mode 0) is generally more prevalent for generic 32-char hex hashes than MD4, making MD5 the 'BEST suited' initial guess without further context.
- C. SHA1 hashes are 160-bit, resulting in 40 hexadecimal characters, not 32.
- D. NTLM hashes are 32 hexadecimal characters, but the question states 'unknown format' and MD5 is a more generic and common 32-char hash. NTLM is specific to Windows passwords.
Hashcat Hash Identification (MD5)
Identifying the hashing algorithm is crucial for cracking. A common characteristic is hash length; a 32-character hexadecimal string often indicates an MD5 hash (128-bit). Hashcat uses specific modes for each algorithm, with Mode 0 for MD5.
- MD5 produces a 128-bit hash (32 hex characters).
- SHA1 produces a 160-bit hash (40 hex characters).
- NTLM is also 32 hex characters but specific to Windows.
- Hashcat 'mode 0' is for MD5.
Memory trick: Hash length is the key to identifying the algorithm.