Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 17 May 2016 12:17:18 -0400
From: Michael Mckenna-Mattiaccio <mckennammj@...il.com>
To: john-users@...ts.openwall.com
Subject: JtR Jumbo 1.79 on Win7, md5hash matching does not work

Hello all,

I have a folder containing .doc .xls .pdf .ppt .zip files that are
encrypted and I need to recover their passwords. I have a custom wordlist
that I know contains at least some correct passwords, but I never get a
single correct guess.

The Windows binary doesn't ship with office2john but it does ship with
pdf2john and zip2john as you can see here https://paste.debian.net/686868/

So I used a random tool my company uses called Karen's Directory Printer. I
fed in the directory with all the files and selected the output of a .txt
file with just a list of all the md5hashes created by Karen's...
https://paste.debian.net/686908/

Here is some sample output from Johnny
https://paste.debian.net/hidden/4cf6b99d/

I don't think the md5crypt script is included in the Windows binaries for
Jumbo 1.79 because when I try to run  --format=md5crypt  I get Unknown
ciphertext format name requested

How do I copy the md5 functionality from the github sources so it works in
JtR?

Also, it doesn't seem to really be using the custom wordlist correctly.
Whenever I link to the custom wordlist, JtR runs quickly and with no
results. If I don't use Wordlist mode then at least JtR seems to be trying.
I even made a .bu of the default wordlist and put my custom wordlist in its
place in the JTr Jumbo folder and I'm still not seeing results.

I have tried the *2john feature of Johnny but it doesn't seem to work well
for me. I was once able to get a pdf password out and removed the prefix
info for https://paste.debian.net/hidden/1eeeaffd/ but the feature is no
longer working, it just hangs on Conversion in progress..... I tried with a
pdf The following command in PowerShell doesn't get me any results either,
regardless of whether the output file exists at the time the command is
run: PS C:\Program Files (x86)\john179j5w\john179j5\run> .\office2john.py
C:\Users\tdmnyadmin\Desktop\Password_Cracking\SampleFiles\001\Doc3.doc
C:\Users\tdmnyadmin\Desktop\Password_Cracking\office.lst

What's the correct command format for these *2john scripts? I can't find
that in the docs.

Thanks everyone! Much love to the community :-)

Best regards,

Michael McKenna-Mattiaccio
Baruch Zicklin MBA in Entrepreneurship & Operations Management cand.
Social Entrepreneur
*MiloSets Inc.*
Founder, CEO

(The best way to contact me is via mckennammj@...il.com )

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.