Playbook · intermediate · 3–5 hours
Password and auth lab narrative
From weak hash capture in lab to cracking methodology to online auth testing — with reporting that does not encourage reckless spraying.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Scenario
In an authorized lab you obtain password hashes (e.g., from a vulnerable app dump or Windows lab). You crack offline, analyze password quality, then practice careful online auth testing against a lab login only.
Goals
Identify hash type and offline attack approach
Crack with hashcat/john ethically in lab
Document password policy recommendations
Practice rate-limited online testing only in lab
Requirements
Lab hashes or DVWA/similar
GPU optional but helpful
Safety
Never use cracked real-world dumps from illicit sources
Online brute force only against systems you own/authorized
Steps
Hash identification
Intent: Know the format before burning GPU time.
Actions
- Inspect prefix/length; use hashid/haiti if needed
- Separate unique hashes; note salt
Offline cracking plan
Intent: Dictionary → rules → targeted, not chaos.
Actions
- Start rockyou or lab wordlist
- Apply rules; track cracked count vs time
- Stop with diminishing returns; document leftovers
Policy findings
Intent: Translate cracks into controls.
Actions
- Analyze patterns (seasons, names, keyboard walks)
- Write policy + MFA + monitoring recommendations
Online lab control
Intent: Understand lockouts and noise.
Actions
- Against lab login only, try tiny controlled list
- Observe lockout/logging; write blue notes
Remediation outcomes
Strong password policy + breached password blocking
MFA on remote and privileged access
Modern hashing (argon2/bcrypt/scrypt) with unique salts
Alert on auth anomalies