Skip to contentExploitQuest

Lesson 1 of 1 in hashcat

The Algorithm Decides Everything

The same wordlist against the same password cracks in a second or in a thousand years. The variable is the hash, not the guess.

2 min read

Not yet reviewed

Offline cracking starts after a breach: somebody has your database, and with it the stored hashes. From there it is a race between how fast they can guess and how slow the hash is to compute — and that second number spans nine orders of magnitude depending on one decision the defender made years ago.

How fast is fast

Guesses per second, one GPU

MD5        ~100,000,000,000
NTLM       ~200,000,000,000
SHA-256    ~15,000,000,000
bcrypt     ~200,000
argon2id   ~2,000

What that means for an 8-character password

MD5      the whole keyspace in under a minute
SHA-256  minutes to hours
bcrypt   centuries
argon2id geological

These are order-of-magnitude figures, and the exact numbers move with hardware every year. The ratio does not. A fast hash and a memory-hard one are a hundred million times apart, and that gap is the whole game.

A fast hash — MD5, SHA-1, NTLM, plain SHA-256 — was designed to be quick, because that is what a checksum is for. Using one to store passwords hands an attacker exactly the speed they want. bcrypt and argon2id were designed to be slow and memory-hungry on purpose, which costs your login endpoint a few milliseconds and costs a cracking rig everything.

Trying it

Your turn

dump.txt holds two MD5 hashes from a breached forum. Crack them with the wordlist in rockyou-small.txt. Print the results.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Rules exploit your password policy

Wordlists are only the start. A hashcat rule mutates every candidate — capitalise the first letter, append a digit, swap a for @, add the current year. This is not a lucky guess: it is aimed directly at what your complexity policy forces people to do.

Note

A policy that demands an uppercase letter, a number and a symbol does not produce random passwords. It produces Password1! and Summer2026! — and a rule that appends a capital, a year and a bang finds those as fast as it finds the base word. Complexity rules make the mutations predictable, which is the opposite of what they are sold as.

Two systems store the identical password. One hashes it with SHA-256, the other with argon2id. Which cracks faster, and by how much?

Tip

You cannot change how memorable your users' passwords are. You can change the hash, and that is the lever with a million-times return. If you take one thing from this module, it is the next module's title.