First of all, we need a .pdf file. Download any .pdf file online, or make a file and save it in a .pdf format. Let me just say you should be using a Linux distribution, preferably BackTrack 5. If you do not have Linux, go make friends with Google and do some research on it. Now then, the tool we will be using to password-protect the file is pdftk, and the tool to crack the password is called pdfcrack. It's a nifty little tool that cracks both user and owner passwords applied to .pdf files. To download the tools, make sure you are root (unless you are using BackTrack, in which case you already are), and type in-
apt-get install pdftk
Then-
apt-get install pdfcrack
Once you have both tools installed, we need to password protect our file. Go to your terminal and type-
pdftk unprotected_file.pdf output protected_file.pdf user_pw PROMPT
-where "unprotected_file.pdf" is your original .pdf file that you want to protect with a password, and "protected_file" is the new file that will be password protected (you can name this file anything you want). You will then be asked for a password as input, which will be the password that is used to protect your new .pdf file. I suggest using password as your password, just as a proof of concept for the tool, and also to test it (You can benchmark to do this, but where is the fun in that?). Once you enter it and hit your Return key (your Enter key), you now have two .pdf files- the original one without a password, and the new one that you created with pdftk.
Now you are ready to crack your password-protected .pdf file. Just go to your Terminal and type-
pdfcrack
After you type in this command, you will see plenty of options-
root@bt:~# pdfcrack
Usage: pdfcrack -f filename [OPTIONS]
OPTIONS:
-b, --bench perform benchmark and exit
-c, --charset=STRING Use the characters in STRING as charset
-w, --wordlist=FILE Use FILE as source of passwords to try
-n, --minpw=INTEGER Skip trying passwords shorter than this
-m, --maxpw=INTEGER Stop when reaching this passwordlength
-l, --loadState=FILE Continue from the state saved in FILENAME
-o, --owner Work with the ownerpassword
-u, --user Work with the userpassword (default)
-p, --password=STRING Give userpassword to speed up breaking
ownerpassword (implies -o)
-q, --quiet Run quietly
-s, --permutate Try permutating the passwords (currently only
supports switching first character to uppercase)
-v, --version Print version and exit
For this guide, I will show you two methods of cracking- a Dictionary Attack, and a Bruteforce Attack. The first method we will use is a dictionary attack. This will read every line of a wordlist until a match to the .pdf file's password is found. I specified above that you should have used password as your password for your .pdf file. Make sure you are in the same directory as your password-protected .pdf file, then type this in your Terminal-
pdfcrack -f [password-protected pdf file] --wordlist=[path to wordlist]
I named my .pdf file "crackme.pdf", so in BackTrack 5 my command would look like this-
pdfcrack -f crackme.pdf --wordlist=/pentest/passwords/wordlists/darkc0de.lst
Here is the output from my command-
root@bt:~/Hacking/Tutorials# pdfcrack -f crackme.pdf --wordlist=/pentest/passwords/wordlists/darkc0de.lst
PDF version 1.3
Security Handler: Standard
V: 2
R: 3
P: -3904
Length: 128
Encrypted Metadata: True
FileID: b1de5d9d3ca2f5ec1dc4514f2a583907
U: 1f10ccc1e8a59d7083f9bbc1acf9c70900000000000000000000000000000000
O: 43710afb9adf32376fad13575c2ae401b12dd0cd7b6cde9fca684132393c6604
Average Speed: 14601.4 w/s. Current Word: 'J Arthur Moore'
Average Speed: 14024.8 w/s. Current Word: 'avvizzimento'
Average Speed: 13901.1 w/s. Current Word: 'ferebamque'
Average Speed: 14160.5 w/s. Current Word: 'mescoleremo'
found user-password: 'password'
PDF version 1.3
Security Handler: Standard
V: 2
R: 3
P: -3904
Length: 128
Encrypted Metadata: True
FileID: b1de5d9d3ca2f5ec1dc4514f2a583907
U: 1f10ccc1e8a59d7083f9bbc1acf9c70900000000000000000000000000000000
O: 43710afb9adf32376fad13575c2ae401b12dd0cd7b6cde9fca684132393c6604
Average Speed: 14601.4 w/s. Current Word: 'J Arthur Moore'
Average Speed: 14024.8 w/s. Current Word: 'avvizzimento'
Average Speed: 13901.1 w/s. Current Word: 'ferebamque'
Average Speed: 14160.5 w/s. Current Word: 'mescoleremo'
found user-password: 'password'
As you can see, pdfcrack cracked the password, specified by this line of output-
found user-password: 'password'
Yes, password was the password I chose.
The command for brute-forcing, however, will look like this-
pdfcrack -f crackme.pdf --charset=abcdefghijklmnopqrstuvwxyz -n 6
The output for this command will be similar to the Dictionary Attack output. However, this method will take longer, because it has to use the character set (charset) we specified to find the password, instead of using a dictionary file.
HAPPY HACKING!
i found this tool on the department of defense website (cyber crime unit) great tut on how to use this.. :)
ReplyDeleteHello all
Deleteam looking few years that some guys comes into the market
they called themselves hacker, carder or spammer they rip the
peoples with different ways and it’s a badly impact to real hacker
now situation is that peoples doesn’t believe that real hackers and carder scammer exists.
Anyone want to make deal with me any type am available but first
I‘ll show the proof that am real then make a deal like
Available Services
..Wire Bank Transfer all over the world
..Western Union Transfer all over the world
..Credit Cards (USA, UK, AUS, CAN, NZ)
..School Grade upgrade / remove Records
..Spamming Tool
..keyloggers / rats
..Social Media recovery
.. Teaching Hacking / spamming / carding (1/2 hours course)
discount for re-seller
Contact: 24/7
fixitrogers@gmail.com
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download Now
Delete>>>>> Download Full
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download LINK
>>>>> Download Now
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download Full
>>>>> Download LINK 8X
hello, today as always your post is lovely that I liked it and I am waiting for your new works in future, good luck to all of you.
ReplyDeletedigital marketing company in india
This is a great post ! it was very informative. I look forward in reading more of your work. Also, I made sure to bookmark your website so I can come back later. I enjoyed every moment of reading it.kim kardashian sex tape
ReplyDeleteporn sex video hd
mia khalifa sex video
sunny leone sexy movie
SELLING Fresh and valid USA ssn fullz
ReplyDelete99% connectivity with quality
*If you have any trust issue before any deal you may get few to test
*Every leads are well checked and available 24 hours
*Fully cooperate with clients
*Any invalid info found will be replaced
*Format of Fullz/leads/profiles
°First & last Name
°SSN
°DOB
°(DRIVING LICENSE NUMBER)
°ADDRESS
(ZIP CODE,STATE,CITY)
°PHONE NUMBER
°EMAIL ADDRESS
°REFERENCE DETAILS
°BANK ACCOUNT DETAILS
****Contact Me****
*ICQ :748957107
*Gmail :taimoorh944@gmail.com
*Telegram :@James307
Cost for lead cost $2 for each
Price can be negotiable if order in bulk
*Contact soon!
*Hope for a long term Business
*Thank You!
new version is here ---> Shadow Defender Crack
ReplyDeleteSecret Tool Pro Crack
Proteus Crack
PDF Password Crack
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download Now
ReplyDelete>>>>> Download Full
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download LINK
>>>>> Download Now
Penetration Testing- Hacking To Secure: .Pdf Password Cracking >>>>> Download Full
>>>>> Download LINK fZ