Skip to contentExploitQuest

Lesson 1 of 1 in john

A Small List Beats a Big One

The password you will never find in a wordlist is the one somebody built out of their own username. john derives it in a handful of guesses.

2 min read

Not yet reviewed

hashcat and john do the same job, and the reason to know both is a mode john has that changes the maths: --single. Instead of running a giant wordlist, it derives a tiny list of candidates from the account itself — the username, the full name, the fields in the record.

This works because most people do not choose a random password. They choose something the account already knows about them, lightly disguised.

What single tries

username: rowan
->  rowan   Rowan   rowan1   Rowan1   Rowan123
    Rowan2026   Rowan2026!   Rowan2025! ...
  1. Line 2A dozen candidates, not a million. Every one is built from the one word the login screen already gave away for free.

Rowan2026! satisfies every complexity policy ever written — upper, lower, digits, a symbol, eight-plus characters. It is also in nobody's rockyou, because it is specific to one person. A generic wordlist runs for an hour and never finds it. Single finds it in six guesses.

Trying it

Your turn

shadow.txt has one account. Its password is not in any wordlist you have — but it is built from the username. Crack it with single mode.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Note

This is why "the login field is not secret" matters more than it sounds. A username is not a credential, but it is the seed for guessing the credential — and an application that reveals usernames freely is handing an attacker the first half of every password.

Why does `--single` beat a large wordlist against real accounts?

Tip

When you review a login screen, notice whether it tells an attacker which usernames exist. Every leaked username is a head start on a password, and single mode is what turns that head start into a crack.