Try all combinations from a given keyspace just like in Brute-Force attack, but more specific.
The reason for doing this and not to stick to the traditional Brute-Force is that we want to reduce the password candidate keyspace to a more efficient one.
Here is a single example. We want to crack the password: Julia1984
In traditional Brute-Force attack we require a charset that contains all upper-case letters, all lower-case letters and all digits (aka “mixalpha-numeric”). The Password length is 9, so we have to iterate through 62^9 (13.537.086.546.263.552) combinations. Lets say we crack with a rate of 100M/s, this requires more than 4 years to complete.
In Mask attack we know about humans and how they design passwords. The above password matches a simple but common pattern. A name and year appended to it. We can also configure the attack to try the upper-case letters only on the first position. It is very uncommon to see an upper-case letter only in the second or the third position. To make it short, with Mask attack we can reduce the keyspace to 52*26*26*26*26*10*10*10*10 (237.627.520.000) combinations. With the same cracking rate of 100M/s, this requires just 40 minutes to complete.
There is no inherent disadvantage: a mask can describe the same keyspace as an unrestricted brute-force attack, or a smaller one when you have useful information about the password. A smaller keyspace can finish sooner, but it may miss the password if your assumptions are wrong.
For each position of the generated password candidates we need to configure a placeholder. If a password we want to crack has the length 8, our mask must consist of 8 placeholders.
Optimized due its partially reverse algorithms, password candidates are generated in the following order:
aaaaaaaa aaaabaaa aaaacaaa . . . aaaaxzzz aaaayzzz aaaazzzz baaaaaaa baaabaaa baaacaaa . . . baaaxzzz baaayzzz baaazzzz . . . zzzzzzzz
NOTE: This shows that the first four letters are increased first and most often. The exact number however can vary, especially in a smaller keyspace, but it is fixed until a keyspace has been scanned completely.
Current hashcat versions provide eight command-line options for defining custom charsets. Versions before 7.0.0 provided four.
--custom-charset1=CS --custom-charset2=CS --custom-charset3=CS --custom-charset4=CS --custom-charset5=CS --custom-charset6=CS --custom-charset7=CS --custom-charset8=CS
These options have the shortcuts -1 through -8. You can specify the characters directly on the command line or use a hashcat charset file (a plain-text .hcchr file). See examples below:
The following commands all define the same custom charset that consists of the chars “abcdefghijklmnopqrstuvwxyz0123456789” (aka “lalpha-numeric”):
-1 abcdefghijklmnopqrstuvwxyz0123456789 -1 abcdefghijklmnopqrstuvwxyz?d -1 ?l0123456789 -1 ?l?d -1 loweralpha_numeric.hcchr # file that contains all digits + chars (abcdefghijklmnopqrstuvwxyz0123456789)
The following command defines a charset that consists of the chars “0123456789abcdef”:
-1 ?dabcdef
The following command defines a printable 7-bit ASCII charset (aka “mixalpha-numeric-all-space”):
-1 ?l?d?s?u
The following command sets the first custom charset (-1) to russian language specific chars:
-1 charsets/special/Russian/ru_ISO-8859-5-special.hcchr
If -a 3 is requested without specifying a mask, the following default mask is used:
?1?2?2?2?2?2?2?3?3?3?3?d?d?d?d
… where the custom character sets are:
1 - ?l?d?u (lowercase, digits, and uppercase) 2 - ?l?d (lowercase and digits) 3 - ?l?d*!$@_ (lowercase, digits, and five selected special characters)
This mask is also available as a masks file in the ./masks/ directory,, as hashcat-default.hcmask.
The following commands creates the following password candidates:
command: -a 3 ?l?l?l?l?l?l?l?l keyspace: aaaaaaaa - zzzzzzzz
command: -a 3 -1 ?l?d ?1?1?1?1?1 keyspace: aaaaa - 99999
command: -a 3 password?d keyspace: password0 - password9
command: -a 3 -1 ?l?u ?1?l?l?l?l?l19?d?d keyspace: aaaaaa1900 - Zzzzzz1999
command: -a 3 -1 ?dabcdef -2 ?l?u ?1?1?2?2?2?2?2 keyspace: 00aaaaa - ffZZZZZ
command: -a 3 -1 efghijklmnop ?1?1?1 keyspace: eee - ppp
A mask attack is always specific to a target password length. For example, if we use the mask ?l?l?l?l?l?l?l?l we can only crack a password of length 8, and if the target password is length 7, this mask will not find it. That's why we have to repeat the attack several times, each time with one placeholder added to the mask:
?l ?l?l ?l?l?l ?l?l?l?l ?l?l?l?l?l ?l?l?l?l?l?l ?l?l?l?l?l?l?l ?l?l?l?l?l?l?l?l
To automate this, you can use the --increment flag. This flag will automatically use just the first placeholder, then the first two, then the first three, etc. You can also customize the starting and ending lengths with the --increment-min and --increment-maxflags.
Note: the length of the mask itself is also a limiting factor for hashcat. Masks will not increment beyond their own length. For example, if a mask is only of length 4, --increment won't increment beyond length 4, --increment-min of 5 would have no effect, etc.
hashcat charsets files (file extension: .hcchr) are a convenient way to reuse charsets, define custom charsets and use the language-specific charsets shipped by hashcat.
These files can be used together with the --custom-charsetN= (or -1, -2, -3 and -4) parameter. Instead of providing all the charset directly on command line, the support for .hcchr files allows one to specify the path to the file:
-1 charsets/standard/German/de_cp1252.hcchr
It is important that .hcchr files are created with language specific file encodings (e.g. cp1252, ISO-8859-15 etc). For examples of content and encoding of .hcchr files, see the examples shipped with hashcat (e.g. [HASHCATROOT]/charsets/standard/Italian/).
Hint: use iconv and similar tools to convert the files to a language specific file encoding (if for instance created as UTF-8 file).
hashcat mask files (file extension: .hcmask) are files which contain custom charsets (optional) and masks (e.g. ?1?1?1?1?d?d) line-by-line. The advantage of using .hcmask files, which are plain text files, is that those files allow the hashcat user to have a set of predefined and well-working masks stored within a file (or several e.g. password policy specific files) where the lines contained in the hcmask file could for instance be sorted by increasing runtime and/or likelihood of matches*.
The general format of 1 single line in the .hcmask file is as follows:
[?1,][?2,][?3,][?4,][?5,][?6,][?7,][?8,]mask
where the placeholders are as follows:
--custom-charset1 or -1) is set to this value (optional)--custom-charset2 or -2) is set to this value (optional)--custom-charset3 or -3) is set to this value (optional)--custom-charset4 or -4) is set to this value (optional)--custom-charset5 or -5) is set to this value (optional)--custom-charset6 or -6) is set to this value (optional)--custom-charset7 or -7) is set to this value (optional)--custom-charset8 or -8) is set to this value (optional)
* see the PACK program and some example hcmask files shipped by hashcat (in the masks/ folder).
You supply the .hcmask file just where you would normally place the single mask on the command line, like so:
-a 3 hash.txt mask_file.hcmask
Other less-important syntax available in .hcmask files:
Notes:
The following .hcmask file contains some valid example lines which show how to use this feature:
?d?l,test?1?1?1 abcdef,0123,ABC,789,?3?3?3?1?1?1?1?2?2?4?4?4?4 company?d?d?d?d?d ?l?l?l?l?d?d?d?d?d?d ?u?l,?s?d,?1?a?a?a?a?2
Note: also see FAQ: What is a hashcat mask file?
This can be done by some of the hashcat tools using the “--hex-charset” flag.
A mask does not have to stand on its own. If you want a real word in the candidate and a mask around it, that is the Hybrid attack:
$ hashcat -a 12 -m 0 hash.txt ?d?d?w?d?d example.dict
?w marks the place the word from the wordlist goes, and the rest of the mask works exactly as it does on this page. -a 6 and -a 7 are the older, narrower forms that only put the mask after or before the word.
Applies to master. Attack mode 4 is in hashcat's master branch and is not in the 7.1.2 release, which prints Invalid attack mode if you try it. See hashcat.net/beta.
A mask defines which characters are possible at each position. What it cannot capture is whether any of the strings it spells was ever chosen by a person. The PCFG attack can hold a trained grammar to the same mask, so you keep the shape you are sure of and get the candidates inside that shape in the order real passwords occur. It is -a 4 with a mask= setting, and the syntax is the one on this page, read by the same parser:
$ hashcat -m 0 -a 4 example0.hash mask=?u?l?l?l?l?d?d?d
You can see the difference without cracking anything. -a 3 orders a mask with Markov statistics by default, which works one position at a time, so ?a?a?a opens like this:
$ hashcat -a 3 --stdout ?a?a?a | head sar mar 1ar car bar aar 0ar par lar jar
The same three positions under -a 4 open with passwords:
$ hashcat -a 4 --stdout mask=?a?a?a | head 123 abc asd qwe may lol max 101 007 666
Markov knows which characters are common in a position. The grammar knows which whole passwords are common, which is why 123 and qwe arrive first instead of a plausible looking string nobody ever picked. On a mask this short the count barely moves, 603,812 candidates against 857,375, so the whole gain is in the order.
The gain in size arrives with longer masks, because the grammar rules shapes out before the run starts rather than after each candidate. On the ruleset hashcat ships, ?u?l?l?l?l?d?d?d leaves 13 of the grammar's 23,159 shapes:
?u?l?l?l?l?d?d?d is 296,958,668 candidates under -a 4, against 11,881,376,000 for the same mask under -a 3. 40 times smaller.?u?l?l?l?l?l?l?d?d?d?d?s is 62,006,418,684, against 2,650,497,358,080,000. Roughly 42,700 times smaller.
So the looser the mask, the more there is to rule out. That is the opposite of -a 3, which only rewards you for guessing tightly.
The filtering happens inside the grammar rather than on the finished candidate, and that has a consequence worth knowing before you write a mask: a literal anywhere in it constrains which words can sit around it, so a fragment you already know is worth a great deal even in the middle of the password. The PCFG page shows what that looks like.
Two things to know before reaching for it. A mask fixes the length, so pwmin and pwmax are taken from it and a length that contradicts the mask is refused rather than quietly ignored. The bigger one is that a masked run has no OMEN escape: the escape writes its guesses a character at a time and leaves no terminals for a mask to filter, so hashcat drops it and reports that at startup. On a ruleset trained at the default coverage that escape carries about 40% of the probability mass, so run the mask and the escape as two attacks if you want both.
Options -i and --increment are rejected under -a 4, because they belong to a mask and the positional argument there is a ruleset. The full reference is docs/hashcat-pcfg.md in the hashcat source.