home/toolvault/password attacks/john-the-ripper

John the Ripper //

Password Attackscpu cracking

The classic platform cracker — brilliant on Linux /etc/shadow and protected archives/keys. Where Hashcat is a dragster, John is a Swiss watch.

difficulty · easy
10 min
time to first win
5
guided steps
0
students started here*

HOW TO USE JOHN THE RIPPER

Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

john-the-ripper — guided lab session
static view
step 01

Crack a Linux shadow file

unshadow passwd shadow > un.txt && john un.txt

unshadow merges /etc/passwd with /etc/shadow first.

step 02

Use the big wordlist

john --wordlist=rockyou.txt un.txt

Your first cracked password. Feels like magic every time.

step 03

See results

john --show un.txt

--show = the loot table.

step 04

Crack a ZIP or SSH key

zip2john secret.zip > z.hash && john z.hash

john ships *2john converters: ssh2john, pdf2john, office2john…

step 05

Let it think harder

john --incremental un.txt

Incremental = pure bruteforce. Use on short passwords only.

THE WORKFLOW AT A GLANCE

🗝️
Extract
*2john helper
📖
Wordlist
rockyou.txt
🔄
Rules
mutations
⏱️
Brute
incremental if short
✅
--show
proof
LEARNING CURVE
easy — 10 min to first win

FLAGS & SUPER-MOVES

--wordlist=fdictionary attack
--showcracked results
--format=xforce hash type
--incrementalpure bruteforce
--rulesmutate guesses
*2john toolshash extract helpers

PRO TIPS

01

Crack = result, format = 50% of the fight; --list=formats to browse.

Crack = result, format = 50% of the fight; --list=formats to browse.

02

Combine with CeWL-built wordlists on scoped targets.

Combine with CeWL-built wordlists on scoped targets.

03

On modern GPUs big jobs go to Hashcat; John for formats it lacks.

On modern GPUs big jobs go to Hashcat; John for formats it lacks.

04

Lab legality only

Lab legality only: shadow files belong to your VMs.

⚖️

Golden rule

Use John the Ripper only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 · v2 immersive · latest news
Made for learners, everywhere · 2026
*plausibly. verify commands with official docs.