Homebrew
RecommendedHomebrewbrew install john-jumbo
CPU-oriented password auditor with format detection
John the Ripper works offline against hash files, detecting the format, applying wordlist-plus-rules strategies and resuming sessions. Its strength is breadth of formats and the single-shot mode that composes a full strategy for you.
Same rule as every cracker: only hashes you own or are authorized to test, kept and destroyed as sensitive material.
Supported platforms
8
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
hashing, rules, offline, audit, single crack
Dataset entry
john.ts
Reviewed 2025-12-28
Grouped by platform. Elevation requirements are marked per method.
brew install john-jumbo
Needs elevated privileges (sudo / Administrator).
sudo apt install john
git clone https://github.com/openwall/john
cd john/src && ./configure && make -s clean && make -sj$(nproc)
Package availability follows your distribution and enabled repositories. Entry revised 28 Dec 2025 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
John picks the detected format and applies the default wordlist-plus-rules pipeline.
john --wordlist=/usr/share/wordlists/rockyou.txt captures/hashes.txt
Notes
Combines passwd and shadow into John's format so you can test your own machine's policy.
unshadow /etc/passwd /etc/shadow > ~/lab/my-hashes.txt
Tests permutations derived from the account's own GECOS data — the fastest check for 'password equals username'.
john --single captures/hashes.txt
Applies a named rule set over a base list, which is how corporate password patterns get covered.
john --wordlist=base.txt --rules=Corporate captures/hashes.txt
Notes
Reads the potfile instead of re-cracking, and lets you count what remains.
john --show captures/hashes.txt
Notes
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
List what your build supports with `john --list=formats` and use the exact name.
Possible causes
Usual fix
Feed it a known-answer test vector first (`--test`-style single hash) to prove the pipeline works, then change strategy.
Possible causes
Usual fix
Use OpenCL/CUDA-enabled builds where available, or convert the hashes for hashcat and keep John for the exotic formats.
Where to verify anything on this page. External links open in a new tab.
Hashcat cover adjacent parts of the same job.