John the Ripper: Your Password Cracking Adventure Starts Here (2026)
Hey friend, let me grab my coffee and introduce you to John – the password cracking tool that has been breaking passwords since before you were born.
You might think password cracking is just for hackers in movies. But understanding how passwords get cracked teaches you why strong passwords matter. It’s like learning how locks work so you can build better doors.
What John the Ripper Actually Does
John takes password hashes and tries millions of possible passwords until it finds a match. Think of it like trying every key on a massive keyring until one unlocks the door. The difference is, John can try millions of keys in seconds.
Sound simple? It is. But simple tools, used well, are the most dangerous. That’s why penetration testers worldwide still rely on John after more than two decades.
Why Password Hashes Matter (The Coffee Cup Explanation)
Before we crack anything, you need to understand what passwords actually look like stored in a system. When you create a password, the website doesn’t save “password123” – that would be like writing your house key on a sticky note by the door.
Instead, it runs your password through a mathematical function called a hash. Your password becomes something like “5f4dcc3b5aa765d61d8327deb882cf99”. That’s MD5 for “password” – and yes, that’s exactly why “password” is a terrible password.
John’s job is to reverse this process. It can’t undo the hash, but it can hash millions of guesses until one matches. This is why password length and complexity matter so much.
Your First Password Crack (5 Minutes)
Alright, let’s get our hands dirty. I’ll walk you through cracking your first hash – ethically, of course.
Step 1: Install John
On Kali Linux or Ubuntu, this is straightforward:
sudo apt update && sudo apt install john -yThis gives you the basic version. If you want GPU acceleration for serious work (which you will), you’ll need John the Ripper Jumbo – but let’s walk before we run.
Step 2: Get a Hash to Practice
For learning purposes, let’s crack one of the most famous weak MD5 hashes:
echo "5f4dcc3b5aa765d61d8327deb882cf99" > hash.txtThat’s the MD5 hash for “password”. Yes, the actual word “password”. You’d be amazed how many real systems have this exact hash in their databases.
Step 3: Identify the Hash Type
John needs to know what type of hash it’s cracking. You can use tools like hash-identifier, or just know your common formats:
# For MD5
john --format=raw-md5 --wordlist=/usr/share/wordlists/rockyou.txt hash.txtIf John complains about “No password hashes loaded”, you’ve got the format wrong. Try hash-identifier first:
hash-identifier
# Paste your hash, it'll tell you the likely typeStep 4: Watch John Work
Hit enter and watch the magic happen. John will show you a progress display:
Loading password hashes...
Loaded 1 password hash (raw-md5)
Press 'q' or Ctrl-C to abort, any other key to see statistics
0g 0:00:00:01 3.45% (ETA: 00:00:28) 0g/s 10000Kp/s 10000Kc/s 10000KC/sThose numbers show attempts per second. Modern GPUs can crack billions per second. Makes you think differently about your passwords, doesn’t it?
Step 5: See the Cracked Password
john --show hash.txtOutput: “password” – Congratulations. You just cracked your first hash. I’ll wait while you finish feeling like a hacker in a movie.
Understanding Hash Types (And Why They Matter)
Not all hashes are created equal. Some are like paper locks, others like bank vaults.
Fast Hashes (Easy to Crack)
MD5: Designed for speed, which makes it terrible for passwords. A single GPU can try 20 billion MD5 hashes per second. “password123” cracks in milliseconds.
SHA-1: Better, but still not designed for passwords. Deprecated for most uses.
NTLM: Windows default. Faster than you’d want for security, but everywhere in enterprise environments.
Slow Hashes (Designed to Resist Cracking)
Bcrypt: Intentionally slow. Each guess takes longer, making brute-force attacks impractical. This is what modern systems should use.
Argon2: Memory-hard function. Slows down GPU attacks by requiring RAM, not just processing power.
SHA-512 with iterations: Run the hash thousands of times. Each round adds time, making attacks expensive.
When you’re auditing a system, check what hashes they use. MD5 and NTLM are red flags. Bcrypt or Argon2 show they care about security.
John’s Attack Methods (When to Use Each)
Dictionary Attack
Start here. Try every word in a predefined list:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txtRockyou.txt contains 14 million real passwords from the 2009 RockYou breach. It’s the standard baseline for password audits because it contains what people actually use.
This works on about 30-40% of real-world passwords. People are predictable. “Summer2024!”, “Welcome1”, “company@123” – they all appear in wordlists.
Rule-Based Attack
People modify common passwords. “password” becomes “P@ssword123” or “password!”. John can apply rules to transform your wordlist:
john --wordlist=rockyou.txt --rules hashes.txtJohn’s default rules try common mutations: capitalization, adding numbers, leet speak (a=@, e=3), appending special characters. These simple transformations crack another 20% of passwords.
Brute Force Attack
When dictionaries fail, try everything:
john --incremental hashes.txtThis tries every possible combination. It’s slow but thorough. For short passwords (6 characters or less), it still finishes in reasonable time.
The reality check: An 8-character password with uppercase, lowercase, numbers, and symbols has 73 quadrillion combinations. At 1 billion per second, that’s 2,300 years. Now you understand why password length matters more than complexity.
The Wordlists That Matter
Your wordlist determines your success. Here are the ones everyone uses:
- rockyou.txt: The classic. 14 million passwords from real users. Available on every system.
- SecLists: A massive collection of security testing lists. Passwords, usernames, directories – everything.
- CrackStation: Every possible combination up to 15 characters for common hashes.
- Custom lists: Company names, local sports teams, important dates. Tailor these for engagements.
Pro tip: Build wordlists from the target’s public information. Company name, motto, product names, local landmarks. These crack passwords that generic lists miss.
Common Problems (And How to Fix Them)
“No password hashes loaded” – John doesn’t recognize the format. Use hash-identifier or try –format=auto. Check that your hash file isn’t corrupted.
“Unknown hash type” – Same issue, different symptom. John Jumbo supports 400+ formats. Standard John supports fewer. Install Jumbo for uncommon hashes.
Taking forever – You’re cracking strong hashes or brute-forcing. Start with wordlists. Use smaller wordlists first. Try common passwords before comprehensive attacks.
Session interrupted – John saves progress automatically. Restore with:
john --restoreEthical Guidelines (The Morality Check)
Password cracking is a powerful tool. Use it responsibly.
Legal when:
- You own the system
- You have written authorization
- It’s part of authorized penetration testing
- You’re testing your own password policies
Illegal when:
- Cracking passwords you don’t own
- Accessing systems without permission
- Sharing cracked credentials
- Using cracked passwords for unauthorized access
The tool isn’t illegal. How you use it determines legality. As penetration testers, we report weak passwords. We don’t exploit them.
Bottom Line: What John the Ripper Teaches Us
After hours of cracking hashes, patterns emerge:
- Passwords aren’t as secure as people think. Complexity requirements don’t help if everyone uses the same patterns.
- Hash functions matter for security. MD5 and NTLM belong in the past. Modern systems need bcrypt or Argon2.
- Good password policies prevent easy cracking. Length beats complexity. Passphrases like “correct-horse-battery-staple” are stronger than “P@ssw0rd!”.
- User education is the real solution. Tools like John prove that technical controls aren’t enough. People need to understand the stakes.
Every time John cracks a password in seconds, that’s a teaching moment. Show your users. Show your clients. Show management why password policies matter.
Now finish that coffee and try cracking some hashes – ethically. And maybe change your password to something longer than 8 characters while you’re at it.
