Waraxe IT Security Portal
Login or Register
September 20, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 135
Members: 0
Total: 135
Full disclosure
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
CVE-2026-52307: Stored XSS in 1CMS v5.6
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 /CVE-2026-12556
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
O-CMS 1.0.0 Authenticated OS Command Injection viaai_cli_script
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Hash related information -> PasswordsPro Tutorial (How to Crack hashes)
Post new topicReply to topic View previous topic :: View next topic
PasswordsPro Tutorial (How to Crack hashes)
PostPosted: Tue Aug 25, 2009 4:28 am Reply with quote
Mooka91
Advanced user
Advanced user
Joined: Aug 15, 2009
Posts: 73




Hey guys, Just thought i would compile my recently obtained knowledge into a nice little Tutorial on the Basic use of PasswordsPro.

My Tutorial will show you the 3 easiest Functions to make use of, Dictionary attack, Hybrid attack and Brute Force Attack.

Before we begin, You will need the following:

1. PasswordsPro
2. A wordlist (Multiple lists are suggested)
SKMPZ's Wordlist
Earthquake's Birthday Cracked Password List
^^^ These are 2 very good resources, The 28GB list is a waste of space.
3. A Brain
4. Patience (I fail at this one)

To begin i will show you a Dictionary Attack

Note: The algorithm depends on your Hash, For list a of Algorithms click here.

1. Open PasswordsPro

2. Click Options
3. Click Hashing Modules, Right Click, Add
4. Browse to your PasswordsPro Folder

5. Open the Modules folder, Press CTRL+A, Deselect the 2 folders.

6. Press ok
7. Click Dictionaries, Right click, Add






8. Select your Dictionaries (Ensure you click All files) For this ill be using MoPList.dic, Click OK etc etc
9. Note: Time to Input your hashes, This can be done in multiple way, I will only be showing the MANUAL way.
Right click one of the cells, Click Add

10. Insert your hash, I will be using These hashes

Note: Just to show you how i would Usually do it

11. Select your type of attack, Simple Dictionary
12. Press Start
13. The program will then work on cracking your hashes.
14. As you can see, The program has found one of my passwords.
15. Enjoy =)
Note: You have never 100% guaranteed to find a password

Hybrid Attack

Simply follow the steps above, But at Step 7 click press, Hybrid Dictionary Attack


And as you can see, I have found another password =)


Brute Force coming soon.

Version 0.3

=====ChangeLog=====

Version 0.1 - Posted first Version
Version 0.2 - Added Hybrid Attack
Version 0.3 - Added "How to add Modules"


<<<<<< Please offer any advice on how i can improve, Or on what i have done wrong. >>>>>>

<<<<<< This is allowed to be reposted as long as credit is given >>>>>>

From, Mooka91/MoP91
View user's profile Send private message
PasswordsPro Tutorial (How to Crack hashes)
www.waraxe.us Forum Index -> Hash related information
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.035 Seconds