Skip to contentExploitQuest
LearnCracking & Brute Force

Cracking & Brute Force

How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.

Medium

Not yet reviewed

4 chapters4 lessons4 practice quizzes1 examabout 4hup to 360 XP

Before you start

This course expects those first. Nothing is locked — sign in and it will say where you stand.

Start the courseThe Algorithm Decides Everything
01

hashcat

0/1

Offline cracking against a stolen hash, and why the algorithm decides everything.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
1 lesson · 1 hands-on · 2 min
  1. The Algorithm Decides Everythingchallenge2 min
  2. Practice quiz5 questions
02

john

0/1

When a tiny list built from the account beats a million generic words.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
1 lesson · 1 hands-on · 2 min
  1. A Small List Beats a Big Onechallenge2 min
  2. Practice quiz5 questions
03

hydra

0/1

Online brute force, and why it is mostly a way to get rate-limited.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
1 lesson · 1 hands-on · 2 min
  1. Loud, Slow, and in the Logchallenge2 min
  2. Practice quiz5 questions

A memory-hard hash, rate limiting on both axes, and a constant-time comparison.

One-sided — This module is the defence for the three attacks above. It teaches from the platform's own implementations rather than staging a fresh attack, which the earlier modules already did.

1 lesson · 3 min
  1. Three Defences, All Load-Bearing3 min
  2. Practice quiz6 questions

Exam

Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.

  1. Cracking & Brute Force Exam7 questions · pass at 70%