All playbooks

Playbook · intermediate · 3–5 hours

Password and auth lab narrative

From weak hash capture in lab to cracking methodology to online auth testing — with reporting that does not encourage reckless spraying.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Scenario

In an authorized lab you obtain password hashes (e.g., from a vulnerable app dump or Windows lab). You crack offline, analyze password quality, then practice careful online auth testing against a lab login only.

Goals

Identify hash type and offline attack approach

Crack with hashcat/john ethically in lab

Document password policy recommendations

Practice rate-limited online testing only in lab

Requirements

Lab hashes or DVWA/similar

GPU optional but helpful

Safety

Never use cracked real-world dumps from illicit sources

Online brute force only against systems you own/authorized

Steps

Step 1

Hash identification

Intent: Know the format before burning GPU time.

Actions

  • Inspect prefix/length; use hashid/haiti if needed
  • Separate unique hashes; note salt
Expected: Mode selected (e.g., 0, 1000, 1800) with rationale.
Step 2

Offline cracking plan

Intent: Dictionary → rules → targeted, not chaos.

Actions

  • Start rockyou or lab wordlist
  • Apply rules; track cracked count vs time
  • Stop with diminishing returns; document leftovers
Expected: Cracked set + methodology paragraph.
Step 3

Policy findings

Intent: Translate cracks into controls.

Actions

  • Analyze patterns (seasons, names, keyboard walks)
  • Write policy + MFA + monitoring recommendations
Expected: Finding(s) suitable for a client appendix.
Step 4

Online lab control

Intent: Understand lockouts and noise.

Actions

  • Against lab login only, try tiny controlled list
  • Observe lockout/logging; write blue notes
Expected: Note on rate, detection, and safer alternatives (password spray ethics).

Remediation outcomes

Strong password policy + breached password blocking

MFA on remote and privileged access

Modern hashing (argon2/bcrypt/scrypt) with unique salts

Alert on auth anomalies