The classic platform cracker — brilliant on Linux /etc/shadow and protected archives/keys. Where Hashcat is a dragster, John is a Swiss watch.
Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
unshadow merges /etc/passwd with /etc/shadow first.
Your first cracked password. Feels like magic every time.
--show = the loot table.
john ships *2john converters: ssh2john, pdf2john, office2john…
Incremental = pure bruteforce. Use on short passwords only.
| --wordlist=f | dictionary attack |
| --show | cracked results |
| --format=x | force hash type |
| --incremental | pure bruteforce |
| --rules | mutate guesses |
| *2john tools | hash extract helpers |
Crack = result, format = 50% of the fight; --list=formats to browse.
Combine with CeWL-built wordlists on scoped targets.
On modern GPUs big jobs go to Hashcat; John for formats it lacks.
Lab legality only: shadow files belong to your VMs.
Use John the Ripper only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.