Skip to content

John the Ripper

CPU-oriented password auditor with format detection

VerifiedPentesting· Credential & Hash AuditingIntermediateOpen sourceEntry revised 28 Dec 2025
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Source

Overview

5 commands documented

John the Ripper works offline against hash files, detecting the format, applying wordlist-plus-rules strategies and resuming sessions. Its strength is breadth of formats and the single-shot mode that composes a full strategy for you.

Same rule as every cracker: only hashes you own or are authorized to test, kept and destroyed as sensitive material.

Supported platforms

8

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

hashing, rules, offline, audit, single crack

Dataset entry

john.ts

Reviewed 2025-12-28

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install john-jumbo

Package availability follows your distribution and enabled repositories. Entry revised 28 Dec 2025 — confirm the current release on the project's own download page.

Commands

5 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Run against a hash file

bash

John picks the detected format and applies the default wordlist-plus-rules pipeline.

john --wordlist=/usr/share/wordlists/rockyou.txt captures/hashes.txt

Notes

  • `--format=` overrides detection when a digest is ambiguous (`raw-md5` vs `md5crypt` look similar at a glance).

02Prepare a local shadow file for self-audit

bash

Combines passwd and shadow into John's format so you can test your own machine's policy.

unshadow /etc/passwd /etc/shadow > ~/lab/my-hashes.txt
  • Reading /etc/shadow requires root and is only appropriate on a system you own. Delete the derived file when the audit is done.

03Single-shot mode

bash

Tests permutations derived from the account's own GECOS data — the fastest check for 'password equals username'.

john --single captures/hashes.txt

04Explicit rules pass

bash

Applies a named rule set over a base list, which is how corporate password patterns get covered.

john --wordlist=base.txt --rules=Corporate captures/hashes.txt

Notes

  • Rule sets live in `run/john.conf`; `--rule=':Capitalise'` runs one inline rule for experimentation.

05Show results and drop solved hashes

bash

Reads the potfile instead of re-cracking, and lets you count what remains.

john --show captures/hashes.txt

Notes

  • `--pot=` points at an alternative potfile; `--session=name` isolates a run so parallel audits do not collide.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"Unknown ciphertext format name requested"Cause 1/3

Possible causes

  • The `--format` string does not exist in your build (non-jumbo builds omit many formats).

Usual fix

List what your build supports with `john --list=formats` and use the exact name.

Run reports 0 guesses and says '0p 0g'Cause 2/3

Possible causes

  • Wrong format assumed, or the passwords are outside the covered candidate space.

Usual fix

Feed it a known-answer test vector first (`--test`-style single hash) to prove the pipeline works, then change strategy.

Extremely slow on a modern GPU boxCause 3/3

Possible causes

  • John is CPU-first; GPU kernels are hashcat's territory.

Usual fix

Use OpenCL/CUDA-enabled builds where available, or convert the hashes for hashcat and keep John for the exotic formats.

Tips

  • `--test` and `--format=... --test=0` validate your build's speed per format — good before committing to an overnight run.
  • `--fork=4` splits a large list across processes on multicore CPUs.
  • Report recovery percentage and time, never plaintexts, in an audit deliverable.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

Hashcat cover adjacent parts of the same job.

Compare side by side