The dictionary attack, or “straight mode,” is a very simple attack mode. It is also known as a “Wordlist attack”.
All that is needed is to read line by line from a textfile (aka “dictionary” or “wordlist”) and try each line as a password candidate.
$ hashcat -m 0 -a 0 hash.txt rockyou.txt
-r to get far more out of the same wordlist. This is the single most useful thing to add to a plain dictionary attack.-S builds the candidates on the host instead of on the card. It helps when the card does not need candidates as fast as the host can make them, which is the case for a slow hash, for a fast hash with many salts, and for a small wordlist blown up by a big ruleset. It does not work together with --stdout.$ hashcat -m 0 -a 0 hash.txt rockyou.txt -r rules/best66.rule
A wordlist only ever tries exactly what is written in it. These attacks take the same wordlist further:
-a 5) - leetspeak and case, chosen separately at each character-a 12) - stick a mask on the front, the back, or the middle of each word-a 1) - join words from two wordlists-a 4) - candidates in order of how likely they are, no wordlist needed
There are techniques floating around that exploit the ] function in oclHashcat to enable it to do a Dictionary Attack. Note that this was developed in the early days of the old oclHashcat-old when there was no oclHashcat. Nowadays there is no more need for it.
Outdated. That advice dates from when the GPU tools were separate programs. Current hashcat reads wordlists directly. Use -a 0 for a dictionary attack.