hashcat Forum
Password for MS Word - Printable Version

+- hashcat Forum (https://hashcat.net/forum)
+-- Forum: Support (https://hashcat.net/forum/forum-3.html)
+--- Forum: hashcat (https://hashcat.net/forum/forum-45.html)
+--- Thread: Password for MS Word (/thread-10308.html)



Password for MS Word - DCRookie - 08-31-2021

Hi. I am trying to crack a MS Word 2010 which seems to have AES encryption with two hash and two salt values. Any suggestions as to how to go about cracking the password using hashcat?

Thanks


RE: Password for MS Word - Banaanhangwagen - 08-31-2021

- use for example this Python-script to recover the hash
- check the output with https://hashcat.net/wiki/doku.php?id=example_hashes in order to determine the correct mode
- start cracking

Literally the first hit on Google when typing "office crack hashcat" gives you a more detailed how-to.


RE: Password for MS Word - DCRookie - 08-31-2021

Thank you. I did recover the hash and tried to crack with merged.txt and rockyou.txt with code 9500 for office 2010. It didn't work.

I got this info through 7z. Any idea how to plug this in into hashcat?

"<encryption xmlns="http://schemas.microsoft.com/office/2006/encryption" xmlns:p="http://schemas.microsoft.com/office/2006/keyEncryptor/password"><keyData saltSize="16" blockSize="16" keyBits="128" hashSize="20" cipherAlgorithm="AES" cipherChaining="ChainingModeCBC" hashAlgorithm="SHA1" saltValue="mBpBa0/xc+Ne9NmlqOPEbw=="/><dataIntegrity encryptedHmacKey="HUrn5QfXfWAUHwF7gV8V2Gi4B0NhgUJ9TT3l0F1CYnk=" encryptedHmacValue="YM6uHfILRzUazgcZl+o9w6q+gbLKIiLkNzgMA6cKonw="/><keyEncryptors><keyEncryptor uri="http://schemas.microsoft.com/office/2006/keyEncryptor/password"><p:encryptedKey spinCount="100000" saltSize="16" blockSize="16" keyBits="128" hashSize="20" cipherAlgorithm="AES" cipherChaining="ChainingModeCBC" hashAlgorithm="SHA1" saltValue="G3zscs0TucKtP2kMuY+CtA==" encryptedVerifierHashInput="g2QBm8nfS7PF0jBy8jbeSA==" encryptedVerifierHashValue="XpOSz0uQGZ91blr4nb3qdgaffbiFkqnechVO8+O38iI=" encryptedKeyValue="8IgrrhOtHASYziu/j8ez9g=="/></keyEncryptor></keyEncryptors></encryption>"

Thanks again

(08-31-2021, 10:15 AM)Karamba Wrote: - use for example this Python-script to recover the hash
- check the output with https://hashcat.net/wiki/doku.php?id=example_hashes in order to determine the correct mode
- start cracking

Literally the first hit on Google when typing "office crack hashcat" gives you a more detailed how-to.



RE: Password for MS Word - Banaanhangwagen - 08-31-2021

You need to give the extracted hash as input in Hashcat, nothing more nothing less.
You say "it didn't work". What do you mean exactly? What command did you type? Was there an error?

Finally, no need to investigate the .docx itself, the script did it for you.