From 2628bd53928e8659214f9bcbf0733886742fb70e Mon Sep 17 00:00:00 2001 From: HackTricks News Bot Date: Wed, 26 Aug 2026 12:54:00 +0000 Subject: [PATCH] Add content from: Estate Planning of Credentials --- src/generic-hacking/brute-force.md | 35 +++++++++++++++++++ .../office-file-analysis.md | 2 ++ 2 files changed, 37 insertions(+) diff --git a/src/generic-hacking/brute-force.md b/src/generic-hacking/brute-force.md index 2755f0b4437..cd753c7c689 100644 --- a/src/generic-hacking/brute-force.md +++ b/src/generic-hacking/brute-force.md @@ -822,6 +822,37 @@ hashcat.exe -a 1 -m 1000 C:\Temp\ntlm.txt .\wordlist1.txt .\wordlist2.txt hashcat.exe -a 1 -m 1000 C:\Temp\ntlm.txt .\wordlist1.txt .\wordlist2.txt -j $- -k $! ``` +#### Grammar-driven combinator attacks (encrypted Office example) + +A password can be long and contain several character classes while still having a small **effective search space** when it follows a known grammar. For an encrypted Office document obtained during an authorized assessment, `office2john.py` extracts the password-verification record; this enables local guessing without online lockouts, throttling, or MFA. It does not bypass the document encryption.[[2]](#references)[[5]](#references) + +Strip the filename field that John prepends so Hashcat receives only the verifier:[[2]](#references) + +```bash +python3 /path/to/office2john.py secrets.xlsx | sed 's/^[^:]*://' > office.hash +head -c 40 office.hash; echo +``` + +Select `-m` from the extracted prefix rather than from the file extension. Hashcat maps `$office$*2007*`, `$office$*2010*`, and `$office$*2013*` to modes `9400`, `9500`, and `9600`; legacy `$oldoffice$0/$1` and `$oldoffice$3/$4` records use modes `9700` and `9800`, respectively.[[3]](#references) + +If intelligence from password reuse, policies, hints, or people familiar with the user reveals a grammar such as ``, materialize the independently enumerable prefix as the left dictionary. This example tests numbers `0` through `99`; replace the range and transformations with evidence from the assessment.[[5]](#references) + +```bash +while IFS= read -r word; do + for number in $(seq 0 99); do + printf '%s%s\n%s%s!\n' "$word" "$number" "$word" "$number" + done +done < words.txt > wordsAndNumbers.txt +``` + +Hashcat attack mode `1` appends every line of the right dictionary to every line of the left dictionary, so files containing `L` and `R` lines produce `L × R` candidates before any applied rules. The following command is specifically for a legacy `$oldoffice$3/$4` record; change the mode for other Office formats.[[3]](#references)[[4]](#references)[[5]](#references) + +```bash +hashcat -m 9800 -a 1 office.hash wordsAndNumbers.txt english-88k-upper.txt +``` + +This preprocessing pattern generalizes to other offline-verifiable formats: enumerate only plausible capitalization, dates, separators, digits, or punctuation for one component, then combine it with the remaining component instead of brute-forcing the nominal full length.[[4]](#references)[[5]](#references) + - **Mask attack** (`-a 3`) ```bash @@ -903,5 +934,9 @@ Cracking Common Application Hashes ## References - [1] [Inside GoBruteforcer: AI-generated server defaults, weak passwords, and crypto-focused campaigns](https://research.checkpoint.com/2026/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/) +- [2] [John the Ripper: `office2john.py`](https://github.com/openwall/john/blob/bleeding-jumbo/run/office2john.py) +- [3] [Hashcat example hashes and Microsoft Office modes](https://hashcat.net/wiki/doku.php?id=example_hashes) +- [4] [Hashcat combinator attack](https://hashcat.net/wiki/doku.php?id=combinator_attack) +- [5] [Estate planning of credentials](https://pentestpartners.com/security-blog/estate-planning-of-credentials) {{#include ../banners/hacktricks-training.md}} diff --git a/src/generic-methodologies-and-resources/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md b/src/generic-methodologies-and-resources/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md index 14890252cd0..6509e153e67 100644 --- a/src/generic-methodologies-and-resources/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md +++ b/src/generic-methodologies-and-resources/basic-forensic-methodology/specific-software-file-type-tricks/office-file-analysis.md @@ -17,6 +17,8 @@ sudo pip3 install -U oletools olevba -c /path/to/document #Extract macros ``` +For password-encrypted Office documents, see the [grammar-driven offline recovery workflow](../../../generic-hacking/brute-force.md#grammar-driven-combinator-attacks-encrypted-office-example). + --- ## OLE Compound File exploitation: Autodesk Revit RFA – ECC recomputation and controlled gzip