John the ripper has a lot to offer. For instance, we can build our own rule(s) and use it at run time while john is cracking the hash or use the rule to build a custom wordlist!
Let's say we wanted to create a custom wordlist from a pre-existing dictionary with custom modification to the original dictionary. The goal is to add special characters (ex: !@#$*&) to the beginning of each word and add numbers 0-9 at the end. The format will be as follows:
[symbols]word[0-9]
We can add our rule to the end of john.conf:
sudo vi /etc/john/john.conf
[List.Rules:Password-Attacks]
Az"[0-9]" ^[!@#$]
[List.Rules:Password-Attacks] specify the rule name THM-Password-Attacks.Az represents a single word from the original wordlist/dictionary using -p."[0-9]" append a single digit (from 0 to 9) to the end of the word. For two digits, we can add "[0-9][0-9]" and so on.^[!@#$] add a special character at the beginning of each word. ^ means the beginning of the line/word. Note, changing ^ to $ will append the special characters to the end of the line/word.Let's create a file containing a single word password to see how we can expand our wordlist using this rule.
echo "password" > /tmp/single.lst
We include the name of the rule we created in the John command using the --rules option. We also need to show the result in the terminal. We can do this by using --stdout as follows:
john --wordlist=/tmp/single.lst --rules=THM-Password-Attacks --stdout