Lesson pack 3 · Foundation · 60 minutes
Hashes, identification and cracking
Identify a digest by shape, understand why hashing is one-way, and learn where wordlist cracking works and where it is a trap.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 14 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Identify a hash from its length and prefix, and name the ambiguities that length alone cannot resolve
- Explain the difference between encoding, encryption, and hashing
- Crack a fast unsalted hash with a wordlist and rule transforms
- Recognise a deliberately slow hash and choose a different approach
- Extend a Merkle-Damgard MAC without knowing the secret, and say which constructions stop that
Running order (60 min)
| Time | What happens |
|---|---|
| 0:00-0:06 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:06-0:18 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:18-0:33 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:33-0:54 | Practice setStudents work the challenges. Circulate rather than present. |
| 0:54-1:00 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- Hash identifier with hashcat mode lookup - Identify a hash from its shape and prefix - MD5, SHA family, bcrypt, NTLM, and the salted formats - and get the hashcat mode number to crack it.https://ctfpal.com/?tool=hash-identifier
- MD5, SHA-1 and SHA-256 hash generator - Compute MD5, SHA-1, SHA-256, SHA-384, and SHA-512 of any text in the browser, using Web Crypto. Nothing is sent anywhere.https://ctfpal.com/?tool=hash-generator
- In-browser hash cracker with rule transforms - Crack MD5, SHA-1, SHA-256, SHA-384, and SHA-512 against a wordlist in your browser, with leetspeak, case, reversal, and digit-append rules.https://ctfpal.com/?tool=hash-cracker
- SHA-3, BLAKE2, Keccak and RIPEMD calculator - Compute the hash functions outside the standard set - SHA-3, Keccak, BLAKE2, and RIPEMD-160 - when SHA-2 does not match.https://ctfpal.com/?tool=sha3-blake-hashes
- Hash length extension attack - Append data to a message and forge a valid MD5, SHA-1, or SHA-256 signature without knowing the secret - the Merkle-Damgard flaw behind `hash(secret || message)`.https://ctfpal.com/?tool=hash-length-extension
Reading
- Hash cracking that actually works: identify, wordlist, rules, mask - 7 min. Cracking is a search problem, and most failed attempts are searches aimed at the wrong space. How to identify a hash from its shape, choose between wordlist, rules, and mask attacks, and recognise the hashes you should not be brute-forcing at all.
- Hash length extension: appending to a message you cannot read - 7 min. Why MD5, SHA-1 and SHA-256 let you forge a valid `H(secret || message || padding || yours)` without ever knowing the secret, how to recognise a vulnerable MAC construction on sight, and which hashes are immune.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- hashcrack - picoCTF 2025, easy
- Password Profiler - picoCTF 2026, easy
- Verify - picoCTF 2024, easy
- Chronohack - picoCTF 2025, medium
- Crack the Gate 2 - picoMini by CMU-Africa, medium
- Guess My Cheese (Part 2) - picoCTF 2025, medium
- Hashgate - picoCTF 2026, medium
- It is my Birthday - picoCTF 2021, medium
- It is my Birthday 2 - picoCTF 2021, medium
- No FA - picoCTF 2026, medium
- Pachinko - picoCTF 2025, medium
- investigation_encoded_2 - picoCTF 2019, hard
Checkpoint (gradeable)
Identify an unknown digest, justify the identification, then crack it - or argue from the algorithm why cracking is the wrong path.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
The valuable outcome is the negative one: students should leave able to say 'this is bcrypt, so the password is somewhere else in the challenge'. That judgement is worth more than any successful crack.
- Reading 32 hex characters as 'MD5' rather than as 128 bits, which NTLM, MD4 and a truncated digest also produce.
- Cracking a bcrypt or Argon2 hash because the tool accepted it. The cost parameter is in the string, and it is telling you the password is somewhere else in the challenge.
- Forgetting the salt is part of the input. A rule set that cracks the unsalted corpus finds nothing once a per-user salt is in play.
- Running rockyou against a hash whose plaintext is a flag. Flags are not in any wordlist - the route is a mask over the known format, a prefix plus a small varying tail, and a dictionary run only proves the tool works.
- Reading `H(secret || message)` as a signature. Over a Merkle-Damgard hash that construction extends without the secret, which is the whole reason HMAC exists and is the first thing to check before attacking the key.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Designing Secure Software, Loren Kohnfelder. Chapter 5, Cryptography. Separates the three properties a hash is asked for - preimage, second preimage, collision - so 'broken' stops being one word.
- Practical Forensic Imaging, Bruce Nikkel. Chapter 7, Forensic Image Management. Hashing used for integrity rather than secrecy, which is the other half of what a digest is for and the half CTFs rarely show.
- Windows Security Internals, James Forshaw. Chapter 13, Network Authentication. Where the NTLM hashes people crack actually come from, and why a captured challenge-response is not the same object as a stored digest.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.