Lesson 1 of 1 in john
A Small List Beats a Big One
The password you will never find in a wordlist is the one somebody built out of their own username. john derives it in a handful of guesses.
2 min read
Not yet reviewed
hashcat and john do the same job, and the reason to know both is a mode john has that changes the maths: --single. Instead of running a giant wordlist, it derives a tiny list of candidates from the account itself — the username, the full name, the fields in the record.
This works because most people do not choose a random password. They choose something the account already knows about them, lightly disguised.
What single tries
username: rowan
-> rowan Rowan rowan1 Rowan1 Rowan123
Rowan2026 Rowan2026! Rowan2025! ...
- Line 2A dozen candidates, not a million. Every one is built from the one word the login screen already gave away for free.
Rowan2026! satisfies every complexity policy ever written — upper, lower, digits, a symbol, eight-plus characters. It is also in nobody's rockyou, because it is specific to one person. A generic wordlist runs for an hour and never finds it. Single finds it in six guesses.
Trying it
shadow.txt has one account. Its password is not in any wordlist you have — but it is built from the username. Crack it with single mode.
Note
This is why "the login field is not secret" matters more than it sounds. A username is not a credential, but it is the seed for guessing the credential — and an application that reveals usernames freely is handing an attacker the first half of every password.
Why does `--single` beat a large wordlist against real accounts?
Rowan2026!; a dozen words built from rowan do not.Tip
When you review a login screen, notice whether it tells an attacker which usernames exist. Every leaked username is a head start on a password, and single mode is what turns that head start into a crack.