hcxtools - solution for capturing wlan traffic and conversion to hashcat formats
Hi ZerBea, thanks for expanded reply, I'm sorry I have omitted few details which probably caused the confusion:

1) I'm running on Windows, source code is compiled under CYGWIN. I have provided EXEs long time ago, can provide latest version again

2) I've fetched latest source about a month ago, it's "-v" looks Frankenstein, version is from 2021 by year is correct:
    hcxpcapngtool 6.2.4-62-g4fe754d (C) 2025 ZeroBeat
    I think I use old Make (seems like year comes from it but version is not from PRODUCTION_YEAR) but code is OK

3) Just fetched latest and getting 7.0.1 buth w/o hex (SHA?)
    hcxpcapngtool 7.0.1 (C) 2025 ZeroBeat
    Converting to JOHN - same result as previously reported

4) I haven't try to run JOHN, I was just concerned generated hash looked different than my "normal" JOHN hashes.

I'm happy to know that JOHN can read various forms of the same WPA hashes, though, as a perfectionists and proponents of simplicity, wonder what the purpose of this? 

BTW, by normal JOHN I assume one generated by john's wpapcap2john.exe:
nokopiallow:4b59ba...5407a4204db*3c37...31b5*b0e...cb27*6e6...6c6f77:b0e..cb27:3c3..31b5:3c3..31b5::test.cap

Just in case my JOHN:
John the Ripper 1.9.0-jumbo-1+bleeding-173b5629e8 2024-01-18 00:08:42 +0100 OMP [cygwin 64-bit x86_64 AVX AC]
Reply


Messages In This Thread
wlandump-ng vs hcxdumptool - by hulley - 02-10-2018, 10:26 PM
RE: hcxtools - solution for capturing wlan traffic and conversion to hashcat formats - by oayz - 09-22-2025, 02:23 AM