Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 

Repository files navigation

OneRuleToRuleThemStill

An revamped and optimised version of OneRuleToRuleThemAll.

OneRuleToRuleThemStill now has a 5% ~6.9% reduction in rules (52,000 down to 49,465 48,414) with 0% performance loss against the Lifeboat and LastFM data breaches.

Updates:

  • De-duplication of resulting candidate generation (previously literal strings only)
  • Added LastFM breach dataset (~21m unique hashes) for larger/better modelling
  • Common non-matching rules removed (Lifeboat and LastFM)
  • Ordered by frequency against LastFM

More detail can be found in the blog: https://in.security/2023/01/10/oneruletorulethemstill-new-and-improved/


Free Training

alt text

I developed Password Cracking 101+1, freely available on our website at https://in.security/technical-training/password-cracking/

  • 4 hours of video content split into 15 parts with hands-on challenges
  • Covers basic/traditional attack techniques as well as deeper, more creative attacks (such as delimited passphrases, foreign language, emojis, non-deterministic attacks etc)
  • VM to download pre-built with training challenges and answers (VirtualBox OVA format)
  • Password Cracking 101+1 training channel in our Discord server to chat

Discord Banner 3


Credits

As well as several default hashcat rules (including generated2 by https://github.com/evilmog), the following non-default rule sets were used in testing to create the original rule:

The tool https://github.com/mhasbini/duprule assisted during development.

Many thanks to https://github.com/hashcat/hashcat and it's team for their continual great work.

License

Individual rules used will use their respective licenses if present. Additional custom rules are MIT licensed.

About

A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors