> For the complete documentation index, see [llms.txt](https://meowsec.gitbook.io/w1/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://meowsec.gitbook.io/w1/tryhackme/thmw/hashing-crypto-101.md).

# Hashing - Crypto 101

An introduction to Hashing, as part of a series on crypto

This room in the [TryHackMe](https://tryhackme.com/room/hashingcrypto101) teaches about the basics of hashes. It's a walkthrough, so most of the process is included in the room. But I would like to share my findings and additional stuff related to this room.

{% hint style="info" %}
I have not provided any cracked-hash in this write-up. Though I have blurred them in a way, so the reader can get a hint only.
{% endhint %}

### Task 1:

The purpose of **encoding** is to transform data so that it can be properly (and safely) consumed by a different type of system.  The purpose of **encryption** is to transform data in order to keep it secret from others. [Read more](https://danielmiessler.com/study/encoding-encryption-hashing-obfuscation/)

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXQz7gwlDAEZY6LA9I4%2F1.png?alt=media\&token=b50cb45c-8d66-4c68-9128-babafc0e4bec)

### Task 2:

1. Output size of MD5 hash is 128 bit. 128 bit = 16 bytes.  Because 1 byte = 8 bit.
2. Due to the pigeonhole effect, collisions are not avoidable
3. There are 2^8 possibles hashes. 2^8 = 256

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR-f_vs_fOO10EqQi_%2F2.png?alt=media\&token=b0c3ca4c-f82f-4474-a09f-823f1ef196ee)

### Task 3:

1. This blog post is about the Rainbow Table Attack: [Read](https://www.geeksforgeeks.org/understanding-rainbow-table-attack/)&#x20;
2. Online tools to crack hash. This will also tell you the hash type: [Link](https://crackstation.net/)
3. Password should be **hashed**. Encryption is not the correct term for that: [Read more](https://security.blogoverflow.com/2011/11/why-passwords-should-be-hashed/)&#x20;

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR3X7EQZFKRa1VuMnE%2F3.png?alt=media\&token=a5ac91ed-8691-44cc-b9af-d66296d034e7)

### Task 4:

1. SHA-rounds means the iteration of SHA function: [Read more](https://security.stackexchange.com/questions/204813/what-are-sha-rounds)
2. Recommended website is enough to find the hash: [Link](https://hashcat.net/wiki/doku.php?id=example_hashes). Check the image below to understand.

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR5LkMqYc2l-mpQJBL%2F4.png?alt=media\&token=3115aeed-d7c3-4b9b-8f57-5df41665be41)

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR66BYpQOKbPqRZcVW%2F5.png?alt=media\&token=54cab4d1-c09f-423a-869e-905edda8da13)

### Task 5:

1. Hash analyser is an online tool: [Link](https://www.tunnelsup.com/hash-analyzer/). The image below is the result of the first hash.

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR6z034FH35xDcFUJ8%2F6.png?alt=media\&token=0c12cbab-46aa-495b-875f-493219957ecd)

2\. hashcat is kali tool to crack hash. 'bcrypt' hash code is 3200. Command: `hashcat --help`

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXR8gNG_t7df3we1zVA%2F7.png?alt=media\&token=98062a8f-ef88-49b6-9d78-23dc539664e2)

3\. Command to run hashcat:

```
hashcat -m 3200 [Hash saved file] [rockyou.txt file location] 
```

Do not use `--force` as it will generate false positive and false negative.

4\. Crackstation.net can also crack some 'non-salted' hash. Try it too.

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXRACYCvVi_Pms4Oeyn%2F8.png?alt=media\&token=66e7e326-5333-4f80-83a5-cda6d3160c17)

### Task 6:

1. This link will show you the list of SHA1 sum: [Link](http://old.kali.org/kali-images/kali-2019.4/SHA1SUMS)
2. Check 'Hash cat wiki', provided at task 4: [Link](https://hashcat.net/wiki/doku.php?id=example_hashes)

![](https://2384168284-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MXQhX6_v4jPczvvgprg%2F-MXQj4d-H7Sp1R1pIaU0%2F-MXRBJo0fw_3BJUu7HDA%2F9.png?alt=media\&token=ef3583fd-e6a0-4732-9182-43662e2360de)

I hope this will help you. **Thank you**.
