← Certified John Ripper User · Lesson 10 of 10

Module Eight

📖 Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Certified John the Ripper User – Course Outline
🔐 password security John the Ripper · JtR penetration testing

Certified John the Ripper User

Master the world's most popular password security auditing tool — John the Ripper. Learn to test password strength and secure systems.
📘 8 modules ⏱️ ~30 hours total 🧪 hands-on labs 📋 certification ready
1 Password Security Fundamentals
3.5 hours
Understand how passwords work, why they are vulnerable, and the importance of strong password policies. Learn about hashing algorithms and how they protect credentials.
hashing · salting · rainbow tables · password policies
  • authentication basics
  • hashing algorithms (MD5, SHA)
  • salting and peppering
  • password storage best practices
2 John the Ripper Overview & Installation
3.0 hours
Meet John the Ripper — the most famous password cracking tool. Learn about its architecture, versions (John vs Jumbo), and how to install it on Linux, Windows, and macOS.
John · Johnny · Jumbo · bleeding-edge
  • John vs Jumbo vs Pro
  • installation on Kali/Ubuntu
  • Windows setup
  • John configuration files
3 Hash Extraction & Format Identification
4.0 hours
Learn to extract password hashes from various sources: /etc/passwd, /etc/shadow, Windows SAM, and application-specific formats. Identify hash types and prepare them for John.
unshadow · SAM · NTLM · hashcat conversion
  • extracting Linux hashes
  • Windows SAM extraction
  • hash type identification
  • converting formats for John
4 Dictionary Attacks with John
4.0 hours
Master the classic dictionary attack. Learn how to use built-in wordlists, custom wordlists, and how to create and optimise dictionaries for better success.
wordlist mode · rockyou.txt · custom wordlists · mangling
  • wordlist mode basics
  • rockyou.txt and SecLists
  • creating custom wordlists
  • wordlist mangling rules
5 Brute-Force & Incremental Attacks
4.0 hours
Learn how John can try every possible combination. Understand incremental mode, key spacing, and when to use brute-force versus dictionary attacks.
incremental mode · key spacing · external mode
  • incremental mode explained
  • character set configuration
  • external mode (custom rules)
  • brute-force vs dictionary
6 Rules & Mangling Techniques
4.0 hours
Supercharge your dictionary attacks by applying transformations — append, prepend, case changes, substitutions, and more. Create your own custom rules.
mangling · rules · wordlist mutations · rule syntax
  • John's rule syntax
  • common mangling techniques
  • creating custom rules
  • reject / accept rules
7 Advanced Modes & Performance Tuning
3.5 hours
Explore John's advanced features: Markov mode, cracking with GPU, distributed cracking, and optimising performance for faster results.
Markov · OpenCL · MPI · performance tuning
  • Markov mode
  • GPU acceleration (OpenCL)
  • distributed cracking
  • optimising for speed
8 Defence, Reporting & Best Practices
4.0 hours
Learn how to protect against password cracking. Develop strong password policies, use modern hashing algorithms, and implement account lockout and MFA. Write professional assessment reports.
bcrypt · Argon2 · password policies · MFA · reporting
  • modern hashing (bcrypt, Argon2)
  • password policy design
  • multi-factor authentication
  • security assessment reporting

🎯 certification ready Hands-on labs + knowledge assessment

📋 lab-based exam
2

John Ripper Tutorial Video

3

Module One

Module 1 · Certified John Ripper User

🔐 Module 1: Welcome to the World of John the Ripper

Hello, future cyber hero! 👋

Have you ever forgotten your password? Or maybe you wanted to see if your password is strong enough to stop a bad guy?

In this module, we are going to learn about John the Ripper – a super cool tool that helps us test passwords. But wait! We only use it for good, like helping people recover lost passwords or checking if our own passwords are safe. Think of John as a friendly robot that checks locks on doors to make sure they are strong.

By the end of this module, you will know what John the Ripper is, why it is important, and how it works in a very simple way. We will use many stories, examples, and fun pictures made with text. Are you ready? Let’s go! 🚀


🎯 Learning Objectives

After finishing this module, you will be able to:

  • Explain what John the Ripper is in your own words.
  • Understand why we test passwords.
  • Name the two main types of password attacks.
  • Explain the difference between a dictionary attack and a brute‑force attack.
  • Describe what a "hash" is (using a simple story).
  • Know how John the Ripper uses wordlists.
  • Identify good and weak passwords.
  • Understand that John the Ripper is used by good people (ethical hackers).
  • Work with simple text examples and ASCII art.
  • Feel excited to learn more in Module 2!

📖 Warm‑up Story: The Great Key Mystery

Once upon a time, in a small village called Cyberville, there was a wise old woman named Grandma Ada. Grandma Ada had a big treasure chest full of family recipes. She locked it with a special key. But one day, she forgot where she hid the key! 😱

Her grandson, Kofi, was a clever boy. He said, “Grandma, don’t worry! I will find the key.” But the key was gone. So Kofi thought, “What if I make a big list of all the possible keys that look like Grandma’s key? Then I will try each one until the lock opens.”

Kofi wrote down thousands of key shapes on paper. He tried them one by one. After a few hours, he found the right key! The chest opened, and Grandma was so happy. She gave Kofi a big hug and a plate of her famous chin chin. 🍪

That is exactly what John the Ripper does! It tries many passwords (like keys) until it finds the right one. But John is much faster than Kofi because it is a computer program. And instead of a treasure chest, it opens password-protected files.

Now, let’s learn how John works, step by step.


📚 Main Lessons

Lesson 1: What is a Password?

Definition: A password is a secret word or set of characters that you use to prove you are you.

Why it is important: Passwords protect our accounts – like email, games, and bank apps – from people who should not see them.

Simple explanation: Imagine a password is like a secret knock on your treehouse door. Only friends who know the knock can come in.

Real‑life example: You type a password to unlock your tablet.

School example: You need a password to log into the school computer lab.

Home example: Your parent uses a password to unlock their phone.

Nigerian example: Many Nigerians use passwords to access their bank apps like GTWorld or Access Mobile.

Illustration (ASCII):

        🏠 TREEHOUSE DOOR
          |
          v
    🔑 Secret knock: “tap tap tap-tap”
    If you know it → door opens ✅
    If you don’t → door stays closed ❌
    

Mini summary: A password is a secret key. Only you and trusted people should know it.


Lesson 2: What is John the Ripper?

Definition: John the Ripper is a free computer program that tests passwords to see if they are weak.

Why it is important: It helps people find weak passwords before bad guys do.

Simple explanation: John is like a robot that tries to guess your password by checking a very long list of words and patterns.

Real‑life example: A security expert uses John to test company passwords.

School example: Your IT teacher uses John to show how easy it is to guess short passwords.

Home example: You can use John (with permission) to check if your family’s Wi‑Fi password is strong.

Nigerian example: A bank in Lagos uses John to test that their staff use strong passwords.

Illustration (ASCII):

        👤 SECURITY EXPERT
              |
              v
         ⚙️ John the Ripper  ⚙️
          (password tester)
              |
              v
        📋 Report: “Weak password found!”
    

Mini summary: John the Ripper is a helpful tool that tests passwords for weakness.


Lesson 3: How Does John Work? (Very Simple)

Definition: John works by comparing encrypted passwords (called hashes) against guesses.

Why it is important: Understanding how John works helps us use it correctly.

Simple explanation: The computer does not store your password in plain text. It turns it into a secret code (hash). John tries to find a word that, when turned into the same secret code, matches.

Real‑life example: It’s like a restaurant giving you a number for your order. The kitchen doesn’t remember your name; it just matches the number to the food.

School example: Your student ID number is like a hash. The school uses the ID to find your records.

Home example: Your parent’s fingerprint on the phone is turned into a code.

Nigerian example: When you pay with USSD, your bank uses a code to verify you.

Illustration (ASCII):

        Password: “ILOVEJOHN”
             |
             v
        [ Hash machine ]
             |
             v
        Hash: 5f4dcc3b5aa765d61d8327deb882cf99
    

Mini summary: John turns guesses into hashes and compares them to find a match.


Lesson 4: Dictionary Attack – John’s Favourite Trick

Definition: A dictionary attack uses a list of common words (a wordlist) to guess passwords.

Why it is important: Many people use common words like “password” or “123456”. John finds them quickly.

Simple explanation: Imagine you have a big book of the most common passwords. John reads that book and tries each one.

Real‑life example: A hacker uses a list of 10,000 common passwords to break into accounts.

School example: Your teacher shows how “student” is a weak password.

Home example: Your neighbour’s Wi‑Fi password might be “wifi123”.

Nigerian example: Some people use “lagos2020” – that would be in a dictionary attack list!

Illustration (ASCII):

        📖 WORD LIST
        +--------------+
        | password     |
        | 123456       |
        | letmein      |
        | lagos2020    |
        | iloveyou     |
        +--------------+
            |
            v
        ⚙️ John tries each word
            |
            v
        ✅ Match found: “lagos2020”
    

Mini summary: A dictionary attack is fast and works on common passwords.


Lesson 5: Brute‑Force Attack – John’s Super Slow Way

Definition: Brute‑force means trying every possible combination of letters, numbers, and symbols.

Why it is important: This attack can find any password, but it takes a very long time.

Simple explanation: It’s like trying to open a lock by testing every key in the world – one by one.

Real‑life example: If you have a 4‑digit PIN, there are 10,000 combinations. John tries all of them.

School example: If a password is “a”, then “b”, then “c” … up to “zzzz”.

Home example: Trying all possible 4‑number codes on a bike lock.

Nigerian example: A cybercafe owner might test all simple passwords on old computers.

Illustration (ASCII):

        Start: a
          |
          v
        Try a, b, c, ... aa, ab, ...
          |
          v
        ⏳ After 1,000,000 tries ...
          |
          v
        ✅ Found: “cat99”
    

Mini summary: Brute‑force tries everything but is very slow.


Lesson 6: Hashes – The Secret Code

Definition: A hash is a fixed‑length string that looks like gibberish, made from your password.

Why it is important: It keeps your password safe because the real password is not stored.

Simple explanation: Imagine a magic machine that turns every word into a special number. “Cat” becomes “f5a…”. You cannot turn it back.

Real‑life example: Websites store hashes, not your password.

School example: The school library uses a hash for your student ID.

Home example: Your game console uses a hash to check your login.

Nigerian example: Banks use hashing to protect your PIN.

Illustration (ASCII):

        Password: “BOLA”
            |
            v
        🔐 HASH 🔐
            |
            v
        Hash: 81dc9bdb52d04dc20036dbd8313ed055
    

Mini summary: A hash is a one‑way code that hides your password.


Lesson 7: Wordlists – John’s Cheat Sheet

Definition: A wordlist is a text file containing many possible passwords.

Why it is important: Wordlists make dictionary attacks fast and effective.

Simple explanation: It’s like a cheat sheet for a spelling bee – John uses it to guess.

Real‑life example: Security testers use wordlists like rockyou.txt.

School example: A teacher gives a list of 50 common passwords for a class demo.

Home example: You can make a list of family pet names to test your own password.

Nigerian example: A wordlist might include “nigerian”, “abuja”, “lagos”.

Illustration (ASCII):

        wordlist.txt
        +-------------+
        | abuja       |
        | lagos       |
        | port-harcourt|
        | naija       |
        | 9ja         |
        +-------------+
    

Mini summary: Wordlists are lists of guesses that John uses.


Lesson 8: Rules – John’s Smart Tricks

Definition: Rules are patterns that modify words, like adding numbers or changing letters.

Why it is important: They help John guess variations like “password1” or “P@ssw0rd”.

Simple explanation: If John knows “cat”, it will also try “Cat”, “cat1”, “c@t”, and “cat!”.

Real‑life example: Many people use “password” and then add a number.

School example: Students often use their name + birth year.

Home example: Your parent might use “mum2023”.

Nigerian example: “Chidi” becomes “Chidi123” or “Chidi@2024”.

Illustration (ASCII):

        Base word: “chidi”
        Rules:
         + add 1 → “chidi1”
         + uppercase → “Chidi”
         + substitute i→! → “ch!d!”
    

Mini summary: Rules make John smarter by trying common changes.


Lesson 9: Is John Legal? – The Good Guys

Definition: John the Ripper is legal when used with permission for ethical purposes.

Why it is important: Using it without permission is illegal and wrong.

Simple explanation: John is like a lock‑pick set. It’s okay for locksmiths to use it, but not for thieves.

Real‑life example: Companies hire ethical hackers to test their systems.

School example: Your teacher uses John to teach about security.

Home example: You ask your parents before testing their passwords.

Nigerian example: Many Nigerian cybersecurity professionals use John for defence.

Illustration (ASCII):

        👨‍💻 Ethical hacker (good)     🦹 Bad guy (evil)
        + Permission?  YES             NO
        + Help people? YES             NO
        + Legal?       YES             NO
    

Mini summary: Always use John ethically and with permission.


Lesson 10: Strong Passwords – How to Beat John

Definition: A strong password is long, complex, and unique.

Why it is important: It takes John a very long time to crack it.

Simple explanation: Make your password at least 12 characters, mix letters, numbers, and symbols.

Real‑life example: “M1ch3al!23#” is stronger than “michael”.

School example: Your teacher says: use a sentence like “I love Ice-cream 2024!”.

Home example: Your family Wi‑Fi password should be strong.

Nigerian example: “LagosIsFun@9ja” is better than “lagos”.

Illustration (ASCII):

        Weak password:  "ade"    (3 chars)   John cracks instantly
        Strong password: "Adeola@2024!Fun" (16 chars) John takes years
    

Mini summary: Use long, mixed passwords to stay safe.


Lesson 11: The Hash File – John’s Target

Definition: A hash file contains the hashed passwords that John tries to crack.

Why it is important: John cannot work without a hash file.

Simple explanation: It’s like a list of locked boxes. John tries to open them.

Real‑life example: The Linux /etc/shadow file stores user hashes.

School example: A lab computer stores hashes of student passwords.

Home example: Your game account has a hash stored on the server.

Nigerian example: A bank server stores hashes of customer PINs.

Illustration (ASCII):

        hashfile.txt
        +----------------------------------+
        | chidi:5f4dcc3b5aa765d61d...      |
        | bola:7c6a180b36896a0a8c...      |
        | tunde:6d7b3e1b2c3d...           |
        +----------------------------------+
    

Mini summary: John reads the hash file to start testing.


Lesson 12: Cracking Speed – How Fast is John?

Definition: Speed depends on hardware and the type of hash.

Why it is important: Knowing speed helps estimate cracking time.

Simple explanation: A fast computer can try millions of passwords per second.

Real‑life example: A gaming PC is faster than an old laptop.

School example: School computers are slower than a supercomputer.

Home example: Your tablet is slower than a desktop.

Nigerian example: A cybercafe in Lagos may have slower machines.

Illustration (ASCII):

        🐢 Old laptop:   100 tries/sec
        🚗 Gaming PC:    1,000,000 tries/sec
        🚀 Supercomputer: 10 billion tries/sec
    

Mini summary: Better hardware = faster cracking.


Lesson 13: John Modes – How John Works

Definition: John has different modes: single crack, wordlist, and incremental.

Why it is important: Each mode is for different situations.

Simple explanation: It’s like having different tools for different locks.

Real‑life example: Single crack uses info from the hash file.

School example: Wordlist mode is used for common passwords.

Home example: Incremental mode is brute‑force.

Nigerian example: A security analyst uses wordlist mode first.

Illustration (ASCII):

        John Modes
        +------------------+
        | Single crack     |  quick, uses account info
        | Wordlist         |  uses dictionary
        | Incremental      |  brute‑force (slowest)
        +------------------+
    

Mini summary: John has different modes for different attacks.


Lesson 14: What John Cannot Crack

Definition: Some passwords are too strong for John.

Why it is important: It shows that good passwords work.

Simple explanation: If your password is very long and random, John gives up.

Real‑life example: “Q$4n9kL!p2Xz@7f” is almost impossible.

School example: A 20‑character password with symbols.

Home example: Your router password with 16 random characters.

Nigerian example: Banks use very strong encryption, so John can’t crack them easily.

Illustration (ASCII):

        Strong password:  “I❤️CyberSecurity2025!!”
        John tries: 💨  … tries … tries … ⏰ gives up after 100 years.
    

Mini summary: Very strong passwords defeat John.


Lesson 15: Being a Certified John Ripper User

Definition: A Certified John Ripper User knows how to use John ethically and effectively.

Why it is important: Certification shows you are skilled and responsible.

Simple explanation: Like a driving licence for using John.

Real‑life example: Many jobs ask for this skill.

School example: You learn it in a cybersecurity class.

Home example: You can help your family create stronger passwords.

Nigerian example: Nigerian companies look for certified security staff.

Illustration (ASCII):

        🎓 CERTIFIED JOHN RIPPER USER
        +----------------------------+
        | Knows John commands        |
        | Uses wordlists             |
        | Understands hashes         |
        | Acts ethically             |
        | Helps protect people       |
        +----------------------------+
    

Mini summary: A certified user is a responsible security helper.


📝 Key Vocabulary

  • Password: A secret word used to prove who you are.
  • Hash: A scrambled code that represents a password.
  • Dictionary attack: Using a list of common words to guess passwords.
  • Brute‑force: Trying every possible combination.
  • Wordlist: A file with many possible passwords.
  • Rules: Patterns that change words (like adding numbers).
  • Ethical hacking: Using hacking skills to help and protect.
  • Cracking: Finding a password from its hash.
  • John the Ripper: A tool that tests password strength.
  • Hash file: A file containing hashed passwords.

🧠 Important Concepts

  • John the Ripper is a password testing tool.
  • It uses dictionary and brute‑force attacks.
  • Hashes keep passwords secret.
  • Wordlists are key to fast cracking.
  • Rules make attacks smarter.
  • Always use John legally and ethically.
  • Strong passwords defeat John.
  • Certification means you are a responsible user.

📋 Step‑by‑Step: How John Cracks a Password

  1. Get the hash file: John needs the hash (like a locked box).
  2. Choose a wordlist: Pick a list of common passwords.
  3. Apply rules: John modifies words to try variations.
  4. Hash each guess: John turns each guess into a hash.
  5. Compare: If the hash matches, John found the password!
  6. Report: John shows you the cracked password.

Illustration (flowchart):

        Start
          |
          v
        Read hash file
          |
          v
        Choose wordlist
          |
          v
        For each word:
          |
          +---> Apply rules
          |     |
          +---> Hash the word
          |     |
          +---> Compare to target
          |     |
          +---> Match? ── Yes ──> Password found! ✅
          |     |
          +---> No ──> Next word
          |
          v
        End (if not found)
    

🌍 Real‑life Examples

  • Company audit: A company hires a security tester to check if employees use weak passwords.
  • Password recovery: You forget your encrypted file password; John can help (if you own the file).
  • Forensics: Police use John to crack suspects’ devices during investigations (with a warrant).
  • Education: Universities teach John to train future cybersecurity experts.

🇳🇬 Nigerian Examples

  • A Lagos fintech uses John to ensure that customers’ PINs are not “1234” or “0000”.
  • A school in Ibadan teaches students about John to promote safe online habits.
  • A cybercafe in Enugu tests their admin passwords with John to prevent hacking.
  • An Abuja government agency uses John to check the strength of staff passwords.
  • A Nigerian bank runs John on test systems to evaluate new security policies.

🧸 Fun Examples for Kids

  • Imagine your pet dog’s name is “Bingo”. John tries “Bingo”, “bingo”, “Bingo1”, “Bingo!”.
  • If your favourite food is “pizza”, John tries “pizza”, “Pizza”, “pizza2024”.
  • John is like a detective trying 1000 keys to open a treasure chest.
  • Think of a race: dictionary attack is a sprint, brute‑force is a marathon.
  • John uses rules like a chef adding spices to make new flavours.

🏠 Everyday Examples

  • When you log into your tablet, a hash is used.
  • Your parent’s email password is hashed by Gmail.
  • The Wi‑Fi password you type is checked against a hash.
  • Bank ATMs verify your PIN using hashing.
  • Online games store your password as a hash for safety.

🧑‍🏫 Teacher Notes

  • Emphasise the ethical use of John. Always talk about permission.
  • Use the treehouse analogy to make hashes understandable.
  • Show a real hash (e.g., MD5 of “hello”) to illustrate.
  • Encourage group discussions on strong passwords.
  • Relate to Nigerian cultural names to make it local.
  • Use the ASCII diagrams to help visual learners.
  • Stress that John is a tool, not a toy.

👪 Parent Tips

  • Talk to your child about the importance of strong passwords.
  • Use John (with your help) to test a dummy password.
  • Explain that John is for learning, not for breaking into others’ accounts.
  • Set a good example by using strong passwords yourself.
  • Encourage your child to become a cybersecurity helper.

🤯 Interesting Facts

  • John the Ripper was created in 1996.
  • It is free and open‑source (everyone can see the code).
  • It can run on Windows, Linux, and Mac.
  • The wordlist “rockyou.txt” contains over 14 million passwords.
  • Some hashes can be cracked in milliseconds with John.
  • John supports over 30 different hash types.

💡 Did You Know?

  • Did you know that the first password ever used was “M” for a MIT computer in the 1960s?
  • Did you know that John the Ripper can be used on your own phone’s backup files?
  • Did you know that “123456” is still one of the most common passwords worldwide?
  • Did you know that some people use “password” as their password?
  • Did you know that a 12‑character random password would take a supercomputer billions of years to crack?

🔔 Remember This

  • John is a password testing tool.
  • Always have permission before using John.
  • Hashes are one‑way codes.
  • Dictionary attacks use wordlists.
  • Brute‑force tries everything.
  • Strong passwords are long and mixed.
  • John helps improve security.

❌ Common Mistakes

  • Mistake: Using John without permission.
    Fix: Always ask first.
  • Mistake: Using weak wordlists.
    Fix: Use comprehensive lists like rockyou.txt.
  • Mistake: Forgetting to add rules.
    Fix: Use rules for better results.
  • Mistake: Thinking John can crack any password instantly.
    Fix: Understand that strong passwords take years.
  • Mistake: Sharing cracked passwords publicly.
    Fix: Keep results confidential.

✅ Best Practices

  • Always use John in a controlled, legal environment.
  • Use updated wordlists and rules.
  • Test your own passwords to improve them.
  • Document your findings responsibly.
  • Keep learning about new hash types.
  • Use John as a teaching tool.

📊 Diagrams & Tables

Timeline: History of John the Ripper

        1996  ── John 1.0 released
        2005  ── John 1.6 (new formats)
        2010  ── John 1.7 (GPU support)
        2015  ── John 1.8 (more hash types)
        2024  ── John 1.9 (latest features)
    

Comparison Table: Dictionary vs Brute‑Force

Feature Dictionary Attack Brute‑Force Attack
Speed Fast ⚡ Very slow 🐢
Uses wordlist Yes No
Finds common passwords Yes Yes
Finds random passwords No Yes (but takes long)
Best for Everyday weak passwords Short or simple passwords

ASCII Flowchart: John Cracking Process

        +-------------------+
        |  Start            |
        +-------------------+
                 |
                 v
        +-------------------+
        | Load hash file    |
        +-------------------+
                 |
                 v
        +-------------------+
        | Choose wordlist   |
        +-------------------+
                 |
                 v
        +-------------------+
        | Apply rules       |
        +-------------------+
                 |
                 v
        +-------------------+
        | Hash each guess   |
        +-------------------+
                 |
                 v
        +-------------------+
        | Compare hashes    |
        +-------------------+
                 |
                 v
        +-----------+--------+
        | Match?    |         |
        +-----------+--------+
             | Yes           | No
             v               v
        +-----------+  +-----------+
        | Password  |  | Next word |
        | found! ✅ |  |           |
        +-----------+  +-----------+
    

Types of John Modes (Table)

Mode Description Speed
Single crack Uses account info (username, etc.) Very fast
Wordlist Uses a dictionary file Fast
Incremental Brute‑force all combinations Slow



📌 Module 1 Summary

Congratulations! You have finished the first module of the Certified John Ripper User course. Let’s recap what we learned:

  • We met John the Ripper – a friendly password testing tool.
  • We learned about passwords and why they are important.
  • We discovered two main attacks: dictionary and brute‑force.
  • We understood hashes and hash files.
  • We saw how John uses wordlists and rules.
  • We talked about ethical use – always ask permission.
  • We learned to create strong passwords.
  • We explored many examples from Nigeria and everyday life.
  • We practised with ASCII diagrams and tables.

You now have a solid foundation. In the next module, we will get our hands dirty – we will install John and run our first test!


❓ Frequently Asked Questions

  1. Q: Is John the Ripper free?
    A: Yes, it is free and open‑source.
  2. Q: Can John crack any password?
    A: No, very strong passwords take too long.
  3. Q: Do I need a fast computer?
    A: It helps, but John works on any computer.
  4. Q: Is using John illegal?
    A: Only if you use it without permission.
  5. Q: What is a wordlist?
    A: A file with many possible passwords.
  6. Q: What is a hash?
    A: A scrambled code representing a password.
  7. Q: How long does brute‑force take?
    A: It depends on password length, could be years.
  8. Q: Can John crack my email password?
    A> Only if the hash is obtained and you have permission.
  9. Q: What is the best wordlist?
    A: rockyou.txt is very popular.
  10. Q: Do I need to know programming?
    A: No, but basic commands help.

📝 Review Questions

  1. What is a password?
  2. What does John the Ripper do?
  3. Name two types of password attacks.
  4. What is a hash?
  5. Why are hashes important?
  6. What is a dictionary attack?
  7. What is brute‑force attack?
  8. What is a wordlist?
  9. Why do we use rules?
  10. What does ethical mean?
  11. Give one Nigerian example of using John.
  12. How can you make a strong password?
  13. What is a hash file?
  14. What is the fastest John mode?
  15. Why should we test passwords?

✍️ Fill‑in‑the‑Blank

  1. A ________ is a secret word that protects your account.
  2. John the Ripper is a ________ testing tool.
  3. A ________ attack uses a list of common words.
  4. A ________ is a scrambled code of your password.
  5. ________ means trying every possible combination.
  6. A ________ is a file with many possible passwords.
  7. Always use John with ________.
  8. A ________ password has letters, numbers, and symbols.
  9. John’s ________ mode is the fastest.
  10. A ________ file stores hashed passwords.

✅ True or False

  1. John the Ripper is a game. (False)
  2. A hash can be turned back into a password. (False)
  3. Dictionary attacks are fast. (True)
  4. Brute‑force is the fastest method. (False)
  5. You should use John on your friend’s account without asking. (False)
  6. Wordlists are used in dictionary attacks. (True)
  7. Strong passwords are short. (False)
  8. John can crack any password in 1 second. (False)
  9. Ethical hackers have permission to use John. (True)
  10. John was created in 1996. (True)

🔢 Multiple Choice

  1. What does John the Ripper do?
    a) Cook food
    b) Test passwords
    c) Fly a plane
    Answer: b
  2. Which attack uses a wordlist?
    a) Dictionary
    b) Brute‑force
    c) Both
    Answer: a
  3. What is a hash?
    a) A plain password
    b) A scrambled code
    c) A wordlist
    Answer: b
  4. Which is slower?
    a) Dictionary
    b) Brute‑force
    c) Same
    Answer: b
  5. What must you have before using John?
    a) Permission
    b) A game console
    c) A pizza
    Answer: a
  6. Which is a strong password?
    a) abc123
    b) P@ssw0rd!2025
    c) password
    Answer: b
  7. What file stores hashes?
    a) hashfile.txt
    b) wordlist.txt
    c) game.exe
    Answer: a
  8. What does “single crack” mode use?
    a) Account info
    b) Wordlist only
    c) No data
    Answer: a
  9. John the Ripper was created in?
    a) 1996
    b) 2005
    c) 2020
    Answer: a
  10. Which is NOT a John mode?
    a) Single crack
    b) Wordlist
    c) Cooking
    Answer: c
  11. Can John crack any password?
    a) Yes
    b) No
    c) Maybe
    Answer: b
  12. What is an example of a Nigerian password?
    a) Abuja123
    b) NewYork
    c) Tokyo
    Answer: a
  13. Who uses John ethically?
    a) Thieves
    b) Security experts
    c) Both
    Answer: b
  14. What makes a password stronger?
    a) More letters
    b) Symbols and numbers
    c) Both
    Answer: c
  15. What is the best way to use John?
    a) On anyone
    b) With permission
    c) Secretly
    Answer: b

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Hash A. List of common passwords
2. Wordlist B. Scrambled code
3. Dictionary attack C. Tries every combination
4. Brute‑force D. Uses a wordlist
5. John the Ripper E. Password testing tool

Answers: 1‑B, 2‑A, 3‑D, 4‑C, 5‑E


📝 Short Answer

  1. Explain in two sentences what John the Ripper does.
  2. What is the difference between a dictionary attack and brute‑force?
  3. Why is it important to use strong passwords?
  4. Give one example of a Nigerian situation where John could be used.
  5. What is a hash file?

🎭 Scenario‑based Exercises

Scenario 1: Chidi is a student at a university. He forgets his lab password and the IT admin gives him a hash file. Chidi uses John with a wordlist and finds his password in 5 minutes.

  • Was it ethical for Chidi to use John? (Yes, because the admin gave permission)
  • What type of attack did he use? (Dictionary attack)

Scenario 2: Ada wants to test her online banking password. She downloads John but does not ask the bank. She tries to crack the bank’s hash.

  • Is Ada acting ethically? (No, she needs permission)
  • What should Ada do? (Test her own password on a dummy account or ask the bank)

👥 Group Activity

Activity: In groups of 3, create a list of 20 common Nigerian passwords (e.g., “lagos”, “abuja”, “chi”, “nkechi”). Then, discuss how John could crack them. Present your findings to the class.


🧑 Individual Activity

Activity: Write down 3 of your own passwords (dummy ones) and rate them as weak, medium, or strong. Explain why.


💬 Classroom Discussion Questions

  1. Why do people use weak passwords?
  2. How can we encourage others to use strong passwords?
  3. Should schools teach John the Ripper? Why?
  4. What are the dangers of using John illegally?
  5. How can John help Nigerian businesses?

🛠️ Mini Project

Project: Create a simple “password strength checker” using a wordlist. Write down 10 common passwords and mark which ones John would crack instantly. Draw an ASCII chart showing the results.


📋 Practical Assignment

Assignment: Using a test hash (provided by your teacher), run John in wordlist mode. Write a short report (5 sentences) about what you found.


🏆 Challenge Exercise

Challenge: Create a wordlist of 50 words that are related to Nigeria (cities, foods, names). Then, use John (if available) to crack a test hash. See how many passwords you can crack.


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • John the Ripper is a password testing tool.
  • It uses dictionary and brute‑force attacks.
  • Hashes protect passwords.
  • Wordlists and rules make John powerful.
  • Ethical use is a must.
  • Strong passwords defeat John.
  • Certification shows you are responsible.

🔜 Preparation for Module 2

In the next module, we will learn how to install John the Ripper on your computer. We will run our first real test and see how John cracks passwords. Make sure you have a computer (Windows, Linux, or Mac) and ask your parent or teacher for permission.

Get ready to become a real Certified John Ripper User! 🎉


End of Module 1

4

Module Two

Module 2 · Certified John Ripper User

🖥️ Module 2: Installing John & Running Your First Test

Hello again, future cyber hero! 👋

In Module 1, we learned what John the Ripper is and why it is useful. We talked about passwords, hashes, and attacks. Now it is time to do something real!

In this module, we will install John the Ripper on our computer. Then we will run our very first password test. Do not worry – we will go step by step, like building a Lego set. 🧱

By the end of this module, you will have John working on your computer and you will see it crack a test password. That will be so exciting!


🎯 Learning Objectives

After this module, you will be able to:

  • Download John the Ripper safely.
  • Install it on Windows, Linux, or Mac.
  • Open the terminal (command line).
  • Run John with a simple command.
  • Create a test hash file.
  • Use a wordlist to crack a password.
  • Read John’s output and understand it.
  • Know how to stop John when needed.
  • Feel confident using John.
  • Prepare for more advanced tests.

📖 Warm‑up Story: The New Workshop

Remember Kofi from Module 1? He helped Grandma Ada open her treasure chest. Now, Kofi wants to become a master key-maker. He buys a brand new workshop with tools: hammers, files, and a special machine that can copy keys.

But first, he needs to set up the workshop. He unpacks the machine, plugs it in, and reads the manual. Then he tests it with a simple key. The machine works perfectly!

John the Ripper is like that machine. Before we can use it, we need to install it on our computer. Then we test it with a simple password to make sure everything works. That is what this module is all about.

Let’s set up our John workshop! 🔧


📚 Main Lessons

Lesson 1: What is Installation?

Definition: Installation means copying a program to your computer so you can use it.

Why it is important: Without installation, John is just a file that does nothing.

Simple explanation: It is like putting a game CD into your console and waiting for it to load.

Real‑life example: Installing a game like Minecraft on your tablet.

School example: Installing educational software on the school computer.

Home example: Installing a new app on your parent’s phone.

Nigerian example: Installing a banking app like Opay on your phone.

Illustration (ASCII):

        💿 John Installer
            |
            v
        📁 Copy files to computer
            |
            v
        ✅ John is ready to use!
    

Mini summary: Installation puts John on your computer.


Lesson 2: Downloading John Safely

Definition: Download means getting a file from the internet.

Why it is important: We must download from the official website to avoid viruses.

Simple explanation: Only take candy from a trusted shop, not from a stranger.

Real‑life example: Downloading the Chrome browser from Google.

School example: Downloading a textbook PDF from the school portal.

Home example: Downloading a movie from a safe service like Netflix.

Nigerian example: Downloading the NIBSS app from the official app store.

Illustration (ASCII):

        🌐 Internet
            |
            v
        🔗 Official website: openwall.com/john
            |
            v
        ⬇️ Download the right version
            |
            v
        📁 Save the file on your computer
    

Mini summary: Always download John from openwall.com/john.


Lesson 3: John on Windows

Definition: Windows is a popular operating system made by Microsoft.

Why it is important: Many people use Windows, so we need to know how to install John on it.

Simple explanation: Windows is like the “brain” of your computer.

Real‑life example: Most laptops in offices run Windows.

School example: Your school lab may have Windows computers.

Home example: Your family desktop might use Windows.

Nigerian example: Many cybercafes in Lagos use Windows.

Illustration (ASCII):

        🪟 Windows PC
            |
            v
        📥 Download john.exe
            |
            v
        🖱️ Double‑click to install
            |
            v
        ✅ John is ready in C:\john
    

Mini summary: On Windows, you download an .exe file and run it.


Lesson 4: John on Linux

Definition: Linux is a free operating system used by many tech people.

Why it is important: John works very well on Linux.

Simple explanation: Linux is like a different kind of brain for your computer.

Real‑life example: Many servers (big computers) run Linux.

School example: Some university labs use Linux.

Home example: Some tech‑savvy parents use Linux.

Nigerian example: Some Nigerian startups use Linux for their servers.

Illustration (ASCII):

        🐧 Linux PC
            |
            v
        📥 Download tar.gz file
            |
            v
        ⌨️ Use terminal commands
            |
            v
        ✅ John is ready in /usr/bin/john
    

Mini summary: On Linux, you use the terminal to install John.


Lesson 5: John on Mac

Definition: Mac is an operating system made by Apple.

Why it is important: Many people use Macs, so we need to know how to install John there.

Simple explanation: Mac is the brain of Apple computers.

Real‑life example: Many graphic designers use Mac.

School example: Some schools have Mac labs.

Home example: Your friend might have a MacBook.

Nigerian example: Some Nigerian entrepreneurs use MacBooks.

Illustration (ASCII):

        🍏 Mac
            |
            v
        📥 Download the Mac version
            |
            v
        ⌨️ Use terminal (it is called Terminal)
            |
            v
        ✅ John is ready
    

Mini summary: On Mac, you also use the terminal.


Lesson 6: What is a Terminal?

Definition: A terminal is a window where you type commands to talk to the computer.

Why it is important: We need the terminal to run John.

Simple explanation: It is like a chat window with your computer.

Real‑life example: A pilot uses a microphone to talk to the control tower – the terminal is our microphone.

School example: Your teacher uses the command line to install software.

Home example: Your parent might use the terminal to fix a problem.

Nigerian example: A bank IT staff uses the terminal to manage servers.

Illustration (ASCII):

        💻 Computer
            |
            v
        🖥️ Terminal window (black screen with text)
        +-----------------------------------+
        | $ _                              |
        |                                   |
        +-----------------------------------+
    

Mini summary: The terminal is a text‑based way to control your computer.


Lesson 7: Opening the Terminal

Definition: Opening the terminal means launching the command window.

Why it is important: We cannot use John without the terminal.

Simple explanation: It’s like opening the door to the engine room.

Real‑life example: A car mechanic opens the bonnet to see the engine.

School example: You open the terminal to run a Python program.

Home example: You open it to check your Wi‑Fi settings.

Nigerian example: A technician opens the terminal to configure a router.

Illustration (ASCII):

        🖥️ Windows: press Win + R, type "cmd"
        🍏 Mac: press Cmd + Space, type "terminal"
        🐧 Linux: press Ctrl + Alt + T
    

Mini summary: Every operating system has a way to open the terminal.


Lesson 8: Navigating Folders in the Terminal

Definition: Navigating means moving between folders (directories) using commands.

Why it is important: We need to go to the folder where John is installed.

Simple explanation: Like walking through a building from room to room.

Real‑life example: You go to the kitchen to get a drink.

School example: You move from the classroom to the library.

Home example: You go to your room to get your backpack.

Nigerian example: You move from one shop to another in a market.

Illustration (ASCII):

        📁 C:/
            |
            v
        📁 john
            |
            v
        📁 run
            |
            v
        📄 john.exe
    

Mini summary: Use cd (change directory) to move around.


Lesson 9: The john Command

Definition: The john command is what we type to start the program.

Why it is important: This is the main way we use John.

Simple explanation: It’s like saying “John, start working!”

Real‑life example: You say “Alexa, play music.”

School example: You type “python” to start Python.

Home example: You say “OK Google, set a timer.”

Nigerian example: You type “java” to run a Java program.

Illustration (ASCII):

        $ john --wordlist=wordlist.txt hashfile.txt
        ⬆️   ⬆️               ⬆️            ⬆️
        |    |                |             └─ target hash file
        |    |                └─ wordlist to use
        |    └─ option
        └─ command name
    

Mini summary: The john command is the way we tell John what to do.


Lesson 10: Creating a Test Hash

Definition: A test hash is a fake hash we create to test John.

Why it is important: We use test hashes to learn without breaking real passwords.

Simple explanation: It’s like a practice exam before the real test.

Real‑life example: A pilot uses a flight simulator.

School example: You solve practice math problems.

Home example: You cook a small meal before making a big dinner.

Nigerian example: A tailor makes a sample before sewing your outfit.

Illustration (ASCII):

        Password: “letmein”
            |
            v
        🔐 Hash it
            |
            v
        Hash: 7c6a180b36896a0a8c02787eeafb0e4c
        Save this hash in a file called test.hash
    

Mini summary: Test hashes let us practise safely.


Lesson 11: Running John for the First Time

Definition: Running John means executing the program with a hash and a wordlist.

Why it is important: This is the moment we see John in action!

Simple explanation: Like starting a race car for the first time.

Real‑life example: You press the “start” button on a video game.

School example: You run a science experiment.

Home example: You start the washing machine.

Nigerian example: You start a generator.

Illustration (ASCII):

        $ john --wordlist=rockyou.txt test.hash
        🚀 John starts ...
        Trying password: 123456
        Trying password: password
        Trying password: letmein
        ✅ Found: letmein
    

Mini summary: Running John is exciting – it will show us the password!


Lesson 12: Reading John’s Output

Definition: Output is what John shows on the screen.

Why it is important: The output tells us if John cracked the password.

Simple explanation: It’s like the result of a test.

Real‑life example: The score at the end of a game.

School example: The grade on your assignment.

Home example: The timer beeping when food is ready.

Nigerian example: The receipt you get after buying something.

Illustration (ASCII):

        Output example:
        +----------------------------------------+
        | john --wordlist=wordlist.txt test.hash |
        | Loaded 1 password hash                 |
        | Press 'q' or Ctrl-C to abort           |
        | 0g 0:00:00:01 0.00%                    |
        | letmein (user)                         |
        | 1g 0:00:00:02 100%                    |
        | Session completed                       |
        +----------------------------------------+
    

Mini summary: John tells us the password if it finds it.


Lesson 13: Stopping John

Definition: Stopping John means ending the program before it finishes.

Why it is important: Sometimes John takes too long, so we stop it.

Simple explanation: Like pausing a movie.

Real‑life example: You turn off a game when you need to do homework.

School example: You stop the timer during a test.

Home example: You turn off the TV.

Nigerian example: You turn off the generator when the power comes.

Illustration (ASCII):

        To stop John:
        Press Ctrl + C (hold Control and press C)
        John will stop and show a summary.
    

Mini summary: Press Ctrl+C to stop John anytime.


Lesson 14: Saving John’s Results

Definition: Saving results means writing the cracked passwords to a file.

Why it is important: We might need the results later.

Simple explanation: Like writing notes in a notebook.

Real‑life example: You save a game progress.

School example: You save your essay.

Home example: You save a recipe.

Nigerian example: You save a transaction receipt.

Illustration (ASCII):

        $ john --wordlist=wordlist.txt test.hash --format=raw-md5
        $ john --show test.hash
        user:letmein
        1 password hash cracked, 0 left
    

Mini summary: Use --show to see saved results.


Lesson 15: The Joy of Your First Crack

Definition: Cracking means finding a password from its hash.

Why it is important: It is the goal of using John.

Simple explanation: Like solving a puzzle!

Real‑life example: Winning a game.

School example: Answering a difficult question.

Home example: Finding a lost toy.

Nigerian example: Finding the right key to your gate.

Illustration (ASCII):

        🎉🎉🎉 CONGRATULATIONS! 🎉🎉🎉
        You cracked your first password!
        Password was: letmein
        You are now a real John user!
    

Mini summary: Cracking a password is a big achievement!


📝 Key Vocabulary

  • Installation: Putting a program on your computer.
  • Download: Getting a file from the internet.
  • Terminal: A window where you type commands.
  • Command: An instruction you type in the terminal.
  • Wordlist: A list of passwords John tries.
  • Hash file: A file with hashed passwords.
  • Output: What the program shows on the screen.
  • Ctrl+C: A shortcut to stop a program.
  • Crack: Finding a password from its hash.
  • Test hash: A fake hash used for practice.

🧠 Important Concepts

  • John must be installed before use.
  • Download from the official website only.
  • Different operating systems have different installation steps.
  • The terminal is our main tool.
  • We use the john command to run the program.
  • A wordlist and a hash file are needed to crack.
  • Test hashes are safe for learning.
  • Ctrl+C stops John.
  • John shows results in the terminal.
  • Your first crack is a big step!

📋 Step‑by‑Step: Installing and Running John

  1. Download John: Go to openwall.com/john and download the version for your OS.
  2. Extract: If it is a zip file, unzip it.
  3. Open terminal: Use the method for your OS.
  4. Navigate to John folder: Use cd to go to the folder.
  5. Create a test hash: Save a hash in a file called test.hash.
  6. Run John: Type john --wordlist=wordlist.txt test.hash.
  7. Wait: John will try passwords.
  8. See the result: John will show the password if found.
  9. Show all cracked: Use john --show test.hash.
  10. Celebrate! You did it!

Illustration (flowchart):

        Start
          |
          v
        Download John
          |
          v
        Extract files
          |
          v
        Open terminal
          |
          v
        cd to John folder
          |
          v
        Create test.hash
          |
          v
        Run john command
          |
          v
        John tries passwords
          |
          v
        Password found? ── Yes ──> Show result ✅
          |                       |
          | No                    |
          v                       v
        John continues     End (Success)
          |
          v
        (Eventually stops)
    

🌍 Real‑life Examples

  • IT Security: A company installs John to test employee passwords.
  • Forensics: Police install John on a forensic computer to crack suspect passwords.
  • Education: A university installs John in their lab for students.
  • Password recovery: A user installs John to recover a lost archive password.

🇳🇬 Nigerian Examples

  • A Lagos bank installs John on their security team’s computers.
  • An Abuja school installs John in their IT lab.
  • A Port Harcourt company uses John to test their server passwords.
  • A Nigerian cybercafe owner installs John to check admin passwords.
  • A Nigerian government agency installs John for security audits.

🧸 Fun Examples for Kids

  • Imagine installing John is like building a new Lego set.
  • Running John for the first time is like riding a bike without training wheels.
  • John’s terminal is like a robot that understands text commands.
  • Creating a test hash is like making a fake treasure map.
  • Cracking a password is like winning a video game level.

🏠 Everyday Examples

  • Installing a new app on your phone.
  • Opening the command prompt to fix a network issue.
  • Using a dictionary to find a word.
  • Using a key to open a door.
  • Using a calculator to solve a math problem.

🧑‍🏫 Teacher Notes

  • Demonstrate installation on a projector.
  • Provide pre‑downloaded files if internet is slow.
  • Use a simple test hash with the password “letmein”.
  • Show students how to open the terminal on different OS.
  • Emphasise the importance of downloading from official sources.
  • Encourage students to practise with test hashes.
  • Discuss the excitement of the first crack.

👪 Parent Tips

  • Help your child download John from the official website.
  • Ensure your child has permission to install software.
  • Explain that John is for learning, not for breaking accounts.
  • Be present during the first test run.
  • Celebrate their first crack – it is a big achievement!

🤯 Interesting Facts

  • John the Ripper has been downloaded millions of times.
  • It is one of the oldest password testing tools still in use.
  • John can run on very old computers.
  • The “rockyou.txt” wordlist came from a data breach.
  • John can also crack encrypted documents like PDFs.
  • Some companies use John as part of their security training.

💡 Did You Know?

  • Did you know that John can be used on a Raspberry Pi?
  • Did you know that John has a “pot file” that saves cracked passwords?
  • Did you know that John can crack passwords in many languages?
  • Did you know that some people use John to test their own passwords?
  • Did you know that John’s official name includes “Ripper” because it “rips” passwords?

🔔 Remember This

  • Always download John from the official website.
  • Use test hashes for practice.
  • Open the terminal to run John.
  • Use the john command with a wordlist and a hash file.
  • Press Ctrl+C to stop John.
  • Check the output to see if the password was found.
  • Your first crack is a milestone!

❌ Common Mistakes

  • Mistake: Downloading John from a fake website.
    Fix: Only use openwall.com/john.
  • Mistake: Not unzipping the file.
    Fix: Extract all files before running.
  • Mistake: Typing the wrong command.
    Fix: Check spelling – it is john, not “jhon”.
  • Mistake: Forgetting the wordlist.
    Fix: Always include --wordlist=.
  • Mistake: Using a real hash without permission.
    Fix: Only use test hashes for learning.

✅ Best Practices

  • Always start with a test hash.
  • Use strong, updated wordlists.
  • Keep your John installation up to date.
  • Document your commands and results.
  • Share your knowledge with classmates.
  • Respect privacy – never crack others’ passwords.

📊 Diagrams & Tables

Timeline: Installation Steps

        1. Download  →  2. Extract  →  3. Open terminal  →  4. Run john
        (5 mins)        (1 min)         (30 sec)           (varies)
    

Comparison Table: Installation on Different OS

Operating System Download File Installation Method Terminal
Windows .exe or .zip Run .exe or extract .zip Command Prompt (cmd)
Linux .tar.gz Extract and compile Terminal (Ctrl+Alt+T)
Mac .dmg or .tar.gz Extract and run Terminal (Cmd+Space)

ASCII Flowchart: John Cracking Process

        +-------------------+
        |  Start            |
        +-------------------+
                 |
                 v
        +-------------------+
        | Load hash file    |
        +-------------------+
                 |
                 v
        +-------------------+
        | Choose wordlist   |
        +-------------------+
                 |
                 v
        +-------------------+
        | Apply rules       |
        +-------------------+
                 |
                 v
        +-------------------+
        | Hash each guess   |
        +-------------------+
                 |
                 v
        +-------------------+
        | Compare hashes    |
        +-------------------+
                 |
                 v
        +-----------+--------+
        | Match?    |         |
        +-----------+--------+
             | Yes           | No
             v               v
        +-----------+  +-----------+
        | Password  |  | Next word |
        | found! ✅ |  |           |
        +-----------+  +-----------+
    

John Command Options Table

Option What it does
--wordlist=file Uses a dictionary file
--format=type Specifies hash type (e.g., raw-md5)
--show Shows cracked passwords
--session=name Saves progress under a name
--restore=name Restores a saved session



📌 Module 2 Summary

Great job! You have completed the second module of the Certified John Ripper User course. Let’s recap:

  • We learned what installation means and why it is important.
  • We downloaded John from the official website.
  • We saw how to install John on Windows, Linux, and Mac.
  • We opened the terminal and navigated folders.
  • We created a test hash and ran John for the first time.
  • We read John’s output and celebrated our first crack.
  • We learned to stop John with Ctrl+C and save results.

You now have John installed and working. You are ready for the next step: cracking more complex passwords and using advanced features!


❓ Frequently Asked Questions

  1. Q: Is John free?
    A: Yes, it is free and open‑source.
  2. Q: Can I install John on a Chromebook?
    A: Yes, using Linux mode.
  3. Q: What if the download is slow?
    A: Try a different mirror or download at off‑peak hours.
  4. Q: Do I need admin rights?
    A: On Windows, yes for some installations.
  5. Q: Can John run on an old computer?
    A: Yes, John is lightweight.
  6. Q: What is a “pot file”?
    A> It stores cracked passwords so John doesn’t re‑crack them.
  7. Q: How do I update John?
    A: Download the new version and replace the old files.
  8. Q: Can I use a different wordlist?
    A: Yes, any text file with passwords.
  9. Q: Why does John take so long?
    A: It depends on the hash type and hardware.
  10. Q: What if John cannot find the password?
    A: The password is not in the wordlist, or it is too strong.

📝 Review Questions

  1. What does “installation” mean?
  2. Where should you download John from?
  3. What is a terminal?
  4. How do you open the terminal on Windows?
  5. How do you open the terminal on Mac?
  6. What command do you use to run John?
  7. What is a test hash?
  8. What does the --wordlist option do?
  9. How do you stop John while it is running?
  10. What does John show when it cracks a password?
  11. What is the “pot file”?
  12. Can John run on Linux?
  13. What is the first step after downloading John?
  14. Why do we use test hashes?
  15. What is the --show option used for?

✍️ Fill‑in‑the‑Blank

  1. ________ means putting a program on your computer.
  2. Always download John from ________.
  3. The terminal is a window where you type ________.
  4. On Windows, you open the terminal by typing ________ in the Run box.
  5. The command to run John is ________.
  6. We use a ________ hash for practice.
  7. The --wordlist option tells John which ________ to use.
  8. Press ________ to stop John.
  9. John’s output shows the ________ if found.
  10. Use john --________ to see cracked passwords.

✅ True or False

  1. John can only be installed on Windows. (False)
  2. You should download John from any random website. (False)
  3. The terminal is used to type commands. (True)
  4. Ctrl+C stops John. (True)
  5. A test hash is a real password. (False)
  6. The --wordlist option is optional. (False – it is needed for dictionary attack)
  7. John can show cracked passwords with --show. (True)
  8. Installation is not needed – John runs from the web. (False)
  9. Linux users install John using a .exe file. (False)
  10. Your first crack is exciting. (True)

🔢 Multiple Choice

  1. What is installation?
    a) Playing a game
    b) Copying a program to your computer
    c) Deleting a file
    Answer: b
  2. Where do you download John?
    a) openwall.com/john
    b) google.com
    c) youtube.com
    Answer: a
  3. What is a terminal?
    a) A web browser
    b) A text command window
    c) A video player
    Answer: b
  4. On Windows, how do you open the terminal?
    a) Win + R, type cmd
    b) Ctrl + Alt + T
    c) Cmd + Space
    Answer: a
  5. What command runs John?
    a) runjohn
    b) john
    c) johntherapper
    Answer: b
  6. What is a test hash?
    a) A real password
    b) A fake hash for practice
    c) A wordlist
    Answer: b
  7. What does --wordlist specify?
    a) The hash file
    b) The wordlist file
    c) The output file
    Answer: b
  8. How do you stop John?
    a) Press Ctrl+C
    b) Press Ctrl+V
    c) Press Alt+F4
    Answer: a
  9. What does John show when it cracks a password?
    a) The password
    b) The hash
    c) Nothing
    Answer: a
  10. What does --show do?
    a) Shows cracked passwords
    b) Shows the wordlist
    c) Shows the hash
    Answer: a
  11. Can John run on Linux?
    a) Yes
    b) No
    c) Only on Windows
    Answer: a
  12. What is the first step after downloading John?
    a) Extract the files
    b) Open the terminal
    c) Run john
    Answer: a
  13. Why use a test hash?
    a) To practise safely
    b) To hack real accounts
    c) To waste time
    Answer: a
  14. What file stores cracked passwords?
    a) Pot file
    b) Wordlist
    c) Hash file
    Answer: a
  15. What is the best way to learn John?
    a) Practice with test hashes
    b) Hack your friends
    c) Watch movies
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Installation A. A window for text commands
2. Terminal B. Putting a program on a computer
3. john C. A list of passwords
4. Wordlist D. The command to run John
5. test.hash E. A file with a practice hash

Answers: 1‑B, 2‑A, 3‑D, 4‑C, 5‑E


📝 Short Answer

  1. What are the steps to install John on Windows?
  2. What is the purpose of a wordlist?
  3. How do you know if John cracked a password?
  4. Why is it important to use a test hash?
  5. What does the --show option do?

🎭 Scenario‑based Exercises

Scenario 1: Kofi has downloaded John from the official website. He extracts the files but cannot find the john command.

  • What should he do? (He should check if he is in the correct folder using cd.)
  • What command would show the files in the folder? (dir on Windows, ls on Linux/Mac)

Scenario 2: Ada runs John with a wordlist but it takes a very long time. She wants to stop it.

  • What should she do? (Press Ctrl+C)
  • Can she resume later? (Yes, with --restore)

👥 Group Activity

Activity: In groups, each member installs John on their own computer (or a lab computer). Then, everyone runs the same test hash and shares the results. Discuss any differences.


🧑 Individual Activity

Activity: Create a test hash with the password “johntest” and crack it using John. Write down the command you used and the output.


💬 Classroom Discussion Questions

  1. Why is it important to install software from official sources?
  2. What challenges did you face during installation?
  3. How did you feel when you cracked your first password?
  4. What would you do if John took too long?
  5. How can we use John responsibly?

🛠️ Mini Project

Project: Create a simple “cracking log” with the following:

  • The date and time you ran John.
  • The command you used.
  • The password you cracked.
  • How long it took.
  • One thing you learned.

📋 Practical Assignment

Assignment: Install John on your computer. Then, create a test hash with the password “mypassword”. Crack it using John and submit a screenshot of the terminal showing the success.


🏆 Challenge Exercise

Challenge: Create a test hash with a password that is not in the rockyou.txt wordlist. Then, try to crack it using John with incremental mode (brute‑force). See how long it takes. (Hint: use --incremental)


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • Installation is the first step to using John.
  • Always download from the official website.
  • The terminal is your control centre.
  • A test hash is safe for practice.
  • Your first crack is a major milestone.
  • Use Ctrl+C to stop John.
  • Save results with --show.
  • Practice makes perfect.

🔜 Preparation for Module 3

In Module 3, we will dive deeper into wordlists and rules. We will learn how to create custom wordlists, understand rule syntax, and make John even more powerful. We will also explore different hash formats.

Make sure you have John installed and ready. Bring a curious mind and your notebook. See you in Module 3! 🚀


End of Module 2

5

Module Three

Module 3 · Certified John Ripper User

🧠 Module 3: Making John Smarter – Wordlists & Rules

Hello again, champion! 👋

In Module 2, we installed John and ran our first test. We saw John crack a simple password using a wordlist. But what if the password is not in the wordlist? What if it is “password1” or “P@ssw0rd”?

That is where rules come in! Rules are like magic tricks that John uses to change words. For example, if John knows “password”, rules can turn it into “Password”, “password1”, or “P@ssw0rd”.

In this module, we will learn how to create our own wordlists and use rules to make John super smart. We will also learn about different hash types and how to tell John which one we are using.

Let’s make John a genius! 🧠✨


🎯 Learning Objectives

After this module, you will be able to:

  • Create your own wordlist.
  • Explain what rules are and why they are useful.
  • Use John’s built‑in rules.
  • Write simple custom rules.
  • Identify different hash formats.
  • Use the --format option correctly.
  • Combine wordlists and rules for better results.
  • Understand the difference between weak and strong passwords.
  • Create a custom wordlist for Nigerian‑style passwords.
  • Feel confident customising John for any task.

📖 Warm‑up Story: The Smart Chef

Kofi is now a great key‑maker. But he wants to be even better. He meets a wise chef named Mama Nkechi. She can cook any dish with just a few ingredients. How? She uses rules! She adds salt, pepper, or spices to change the taste.

Kofi realises: John can do the same! Instead of just using a list of words, John can change them – add numbers, change letters to symbols, or make them uppercase.

Kofi also learns that different locks need different keys. Some locks are like MD5, others are like SHA‑256. John needs to know which lock he is opening.

Now Kofi can open almost any chest! Let’s learn how John does this. 🍲🔑


📚 Main Lessons

Lesson 1: What is a Wordlist?

Definition: A wordlist is a text file that contains many possible passwords, one per line.

Why it is important: John uses wordlists to guess passwords quickly.

Simple explanation: It is like a big dictionary of words John tries.

Real‑life example: A spelling bee contestant studies a list of words.

School example: Your teacher gives you a list of vocabulary words.

Home example: Your parent has a grocery list.

Nigerian example: A market trader has a list of items to buy.

Illustration (ASCII):

        wordlist.txt
        +-------------+
        | abuja       |
        | lagos       |
        | naija       |
        | chidi       |
        | bola        |
        +-------------+
    

Mini summary: A wordlist is a list of guesses for John.


Lesson 2: Creating Your Own Wordlist

Definition: Making your own wordlist means creating a file with passwords you choose.

Why it is important: You can target specific passwords (e.g., Nigerian names).

Simple explanation: Like writing your own shopping list.

Real‑life example: You make a list of your friends’ names.

School example: You create a list of classmate names.

Home example: You list your family members’ names.

Nigerian example: You list common Nigerian names: Chidi, Ada, Bola, Tunde.

Illustration (ASCII):

        Step 1: Open Notepad
        Step 2: Type each password on a new line
        Step 3: Save as "mylist.txt"
        Example:
        Chidi
        Ada
        Lagos
        Nigeria
    

Mini summary: You can create a wordlist with any text editor.


Lesson 3: What are Rules?

Definition: Rules are instructions that modify words to create new guesses.

Why it is important: Rules make John much smarter by trying many variations.

Simple explanation: It is like adding toppings to a pizza to make different flavours.

Real‑life example: You take a plain t‑shirt and add a logo.

School example: You take a basic sentence and add adjectives.

Home example: You take a basic recipe and add spices.

Nigerian example: You take jollof rice and add different meats.

Illustration (ASCII):

        Base word: "chidi"
        Rules:
         + add 1  → "chidi1"
         + uppercase → "Chidi"
         + substitute i→! → "ch!d!"
         + add 2024 → "chidi2024"
    

Mini summary: Rules change words into many new passwords.


Lesson 4: John’s Built‑in Rules

Definition: John comes with default rules that are ready to use.

Why it is important: You can use them without writing your own.

Simple explanation: It is like having a pre‑set recipe book.

Real‑life example: A smartphone has pre‑set camera filters.

School example: Your teacher gives you a template for an essay.

Home example: Your TV has pre‑set picture modes.

Nigerian example: A bank has pre‑set account types.

Illustration (ASCII):

        To use rules:
        $ john --wordlist=mylist.txt --rules test.hash
        John will now apply default rules.
    

Mini summary: Use --rules to activate John’s built‑in rules.


Lesson 5: Writing Custom Rules

Definition: Custom rules are rules you write yourself to suit your needs.

Why it is important: You can target specific patterns.

Simple explanation: Like creating your own pizza recipe.

Real‑life example: You create a custom playlist.

School example: You write your own study guide.

Home example: You create a custom cleaning schedule.

Nigerian example: You create a custom menu for a party.

Illustration (ASCII):

        Rule syntax example:
        $ john --wordlist=mylist.txt --rules=myrules test.hash
        In the john.conf file:
        [List.Rules:myrules]
        $1              # add 1 at the end
        u               # uppercase all letters
        c               # capitalize first letter
        s?l?l           # substitute l with !
    

Mini summary: You can write custom rules in john.conf.


Lesson 6: Common Rule Operations

Definition: Operations are actions rules can perform, like adding, deleting, or changing characters.

Why it is important: They allow endless variations.

Simple explanation: Like having different tools in a toolbox.

Real‑life example: A chef uses a knife, a pan, and a spoon.

School example: You use a pen, ruler, and eraser.

Home example: You use a broom, dustpan, and mop.

Nigerian example: A trader uses a scale, calculator, and bag.

Illustration (ASCII):

        Rule operations:
        l   : lowercase all letters
        u   : uppercase all letters
        c   : capitalize first letter
        r   : reverse the word
        d   : duplicate the word
        $X  : append X (e.g., $1 adds 1)
        ^X  : prepend X (e.g., ^A adds A at start)
        sXY : substitute X with Y
    

Mini summary: Rules have many operations to change words.


Lesson 7: Using Rules with Wordlists

Definition: Combining wordlists and rules means John tries every word in the wordlist and every variation from the rules.

Why it is important: This gives the best chance of cracking passwords.

Simple explanation: Like having a huge menu with many options.

Real‑life example: A restaurant has a menu and specials.

School example: You have a textbook and notes.

Home example: You have a pantry and recipes.

Nigerian example: A market has a list of goods and special offers.

Illustration (ASCII):

        Wordlist: [chidi, bola, ade]
        Rules: add 1, uppercase, substitute i→!
        John tries:
        chidi, Chidi, chidi1, ch!d!, Ch!d!1, ...
        bola, Bola, bola1, b0la, ...
        ade, Ade, ade1, ...
    

Mini summary: Rules multiply the number of guesses John makes.


Lesson 8: Hash Formats – What is MD5?

Definition: MD5 is a common hash format that produces a 32‑character hash.

Why it is important: Many systems use MD5, so John needs to recognise it.

Simple explanation: It is like a lock that has a specific keyhole shape.

Real‑life example: A car key has a specific shape.

School example: Your student ID has a specific format.

Home example: Your house key has a specific cut.

Nigerian example: Your BVN has a specific format.

Illustration (ASCII):

        Password: "hello"
        MD5 hash: 5d41402abc4b2a76b9719d911017c592
        (32 characters)
    

Mini summary: MD5 is a 32‑character hash format.


Lesson 9: Hash Formats – What is SHA‑256?

Definition: SHA‑256 is a more secure hash that produces a 64‑character hash.

Why it is important: It is stronger than MD5 and used in modern systems.

Simple explanation: A stronger lock with a more complex keyhole.

Real‑life example: A high‑security safe.

School example: A school vault for important documents.

Home example: A safe for valuables.

Nigerian example: A bank vault.

Illustration (ASCII):

        Password: "hello"
        SHA-256 hash: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
        (64 characters)
    

Mini summary: SHA‑256 is a 64‑character hash format.


Lesson 10: Telling John the Hash Format

Definition: The --format option tells John what type of hash it is.

Why it is important: John needs to know the format to crack it correctly.

Simple explanation: Like telling a locksmith what type of lock you have.

Real‑life example: You tell the mechanic your car model.

School example: You tell the teacher which subject.

Home example: You tell the plumber what is broken.

Nigerian example: You tell the electrician the appliance type.

Illustration (ASCII):

        $ john --format=raw-md5 test.hash
        $ john --format=raw-sha256 test.hash
        $ john --format=nt test.hash   # for Windows hashes
    

Mini summary: Use --format to specify the hash type.


Lesson 11: Common Hash Types

Definition: There are many hash types like MD5, SHA‑1, SHA‑256, NT, and LM.

Why it is important: Different systems use different hashes.

Simple explanation: Different locks need different keys.

Real‑life example: Your house, car, and locker all have different keys.

School example: Your locker, bike, and computer all have different passwords.

Home example: Your front door, garage, and safe have different locks.

Nigerian example: Your bank card, phone, and email have different PINs.

Illustration (ASCII):

        Hash formats:
        +----------+------------------+------------------+
        | Format   | Length           | Example          |
        +----------+------------------+------------------+
        | MD5      | 32 chars         | 5d41402abc...    |
        | SHA‑1    | 40 chars         | aaf4c61ddc...    |
        | SHA‑256  | 64 chars         | 2cf24dba5f...    |
        | NT       | 32 chars (hex)   | 8846f7ea...      |
        | LM       | 32 chars (hex)   | f0e4c2f7...      |
        +----------+------------------+------------------+
    

Mini summary: John supports many hash formats.


Lesson 12: Combining Wordlists, Rules, and Formats

Definition: Using all three together gives the best chance of cracking.

Why it is important: This is the most powerful way to use John.

Simple explanation: Like using all the best tools at once.

Real‑life example: A chef uses the best ingredients, recipe, and cooking method.

School example: You study with a textbook, notes, and practice questions.

Home example: You clean with a broom, mop, and cleaning spray.

Nigerian example: A farmer uses good seeds, fertiliser, and water.

Illustration (ASCII):

        $ john --wordlist=mylist.txt --rules --format=raw-md5 test.hash
        This tells John:
        1. Use the wordlist mylist.txt
        2. Apply rules
        3. The hash is MD5
    

Mini summary: Combine options for maximum power.


Lesson 13: The Power of Rules – Real Examples

Definition: Rules can turn “password” into many variations.

Why it is important: This cracks passwords that are not in the wordlist.

Simple explanation: Rules make John a magician.

Real‑life example: A magician makes one coin into many.

School example: A teacher explains one topic in many ways.

Home example: You use one ingredient in many dishes.

Nigerian example: A tailor uses one fabric for many styles.

Illustration (ASCII):

        Base: “lagos”
        Rules:
          + uppercase → “LAGOS”
          + capitalize → “Lagos”
          + add 2024 → “lagos2024”
          + substitute a→@ → “l@gos”
          + reverse → “sogal”
        John tries all of these!
    

Mini summary: Rules create many guesses from one word.


Lesson 14: Wordlist Etiquette

Definition: Wordlist etiquette means using wordlists respectfully and legally.

Why it is important: Some wordlists come from data breaches – using them ethically is important.

Simple explanation: Like respecting others’ property.

Real‑life example: You do not use someone’s toothbrush.

School example: You do not copy someone’s homework.

Home example: You do not read someone’s diary.

Nigerian example: You do not use someone’s phone without permission.

Illustration (ASCII):

        Do:
        + Use public wordlists
        + Create your own
        + Use for learning
        Don't:
        - Use leaked passwords
        - Use without permission
        - Use to hack people
    

Mini summary: Use wordlists ethically and legally.


Lesson 15: Becoming a Wordlist Master

Definition: A wordlist master knows how to create, use, and optimise wordlists.

Why it is important: This skill makes you a better John user.

Simple explanation: Like becoming a master chef.

Real‑life example: A master carpenter knows all tools.

School example: A top student knows all subjects.

Home example: A parent who can fix anything.

Nigerian example: A master tailor who can make any outfit.

Illustration (ASCII):

        Wordlist Master:
        + Knows how to create custom lists
        + Understands rules
        + Knows hash formats
        + Uses John efficiently
        + Always acts ethically
    

Mini summary: You are becoming a wordlist master!


📝 Key Vocabulary

  • Wordlist: A list of passwords John tries.
  • Rule: An instruction that changes a word.
  • Operation: A specific action a rule performs.
  • Hash format: The type of hash (e.g., MD5, SHA‑256).
  • MD5: A 32‑character hash format.
  • SHA‑256: A 64‑character hash format.
  • john.conf: The configuration file for John.
  • Custom rule: A rule you create yourself.
  • Substitute: Replacing one character with another.
  • Append: Adding something to the end.

🧠 Important Concepts

  • Wordlists are essential for dictionary attacks.
  • Rules create many variations from one word.
  • John has built‑in rules that you can use.
  • You can write custom rules in john.conf.
  • Different hash formats require different handling.
  • Use --format to tell John the hash type.
  • Combining wordlists, rules, and formats gives the best results.
  • Always use wordlists ethically.

📋 Step‑by‑Step: Using Wordlists and Rules

  1. Create a wordlist: Open a text editor and type passwords, one per line. Save as mylist.txt.
  2. Choose a hash file: Save a hash in a file, e.g., test.hash.
  3. Run John with wordlist: john --wordlist=mylist.txt test.hash.
  4. Add rules: john --wordlist=mylist.txt --rules test.hash.
  5. Specify format: john --format=raw-md5 --wordlist=mylist.txt --rules test.hash.
  6. Check results: john --show test.hash.

Illustration (flowchart):

        Start
          |
          v
        Create wordlist (mylist.txt)
          |
          v
        Save hash (test.hash)
          |
          v
        Run John with wordlist
          |
          v
        Add rules
          |
          v
        Specify format
          |
          v
        Show results
          |
          v
        End
    

🌍 Real‑life Examples

  • A security auditor creates a custom wordlist with company‑specific terms.
  • A penetration tester uses rules to crack passwords like “Summer2024!”.
  • An IT admin uses John with MD5 format to test legacy systems.
  • A cybersecurity student practises with custom rules on test hashes.

🇳🇬 Nigerian Examples

  • A Lagos bank uses a wordlist with “GTBank”, “Access”, “Zenith”.
  • An Abuja school creates a wordlist with student names.
  • A Port Harcourt company uses rules to test “PH2024”, “PH@2024”.
  • A Nigerian tech startup uses John to test their staff’s password habits.
  • A government agency creates a wordlist with “Nigerian”, “Abuja”, “Lagos”.

🧸 Fun Examples for Kids

  • Imagine your favourite cartoon character is “SpongeBob”. Rules can make “SpongeBob2024”, “SPONGEBOB”, or “SpongeB0b”.
  • If your pet is “Bingo”, rules make “Bingo1”, “Bingo!”, and “Bingo@”.
  • John’s rules are like a magic wand that changes words.
  • Creating a wordlist is like making a list of your favourite toys.
  • Using rules is like playing with building blocks – you can make many things from one block.

🏠 Everyday Examples

  • You have a list of groceries – that is a wordlist.
  • You add a new item to the list – that is a rule.
  • You change a recipe by adding salt – that is a rule.
  • You have different keys for different doors – that is like hash formats.
  • You use a flashlight to see in the dark – John uses rules to see passwords.

🧑‍🏫 Teacher Notes

  • Emphasise that rules are powerful but need to be used responsibly.
  • Show students how to create a simple wordlist in Notepad.
  • Demonstrate the effect of rules by running John with and without --rules.
  • Explain that different hash formats exist and why they matter.
  • Use Nigerian names and places for examples to make it relatable.
  • Encourage students to create their own custom rules.

👪 Parent Tips

  • Help your child create a wordlist with family‑related words.
  • Explain that rules are like secret codes.
  • Ensure your child understands the ethical use of wordlists.
  • Encourage them to think about how passwords can be guessed.
  • Celebrate when they crack a test password with rules.

🤯 Interesting Facts

  • The “rockyou.txt” wordlist contains over 14 million passwords.
  • John’s rules can create millions of variations from a small wordlist.
  • MD5 was invented in 1991.
  • SHA‑256 is part of the SHA‑2 family, created in 2001.
  • Some hash formats are so old that John has special modes for them.
  • Creating a custom wordlist can be faster than using a huge one.

💡 Did You Know?

  • Did you know that John can crack passwords in multiple languages?
  • Did you know that you can combine multiple wordlists?
  • Did you know that rules can be chained together?
  • Did you know that John has a “single crack” mode that uses account info?
  • Did you know that some rules can make passwords harder to crack?

🔔 Remember This

  • A wordlist is a list of passwords John tries.
  • Rules create variations of words.
  • Use --rules to activate rules.
  • Specify hash format with --format.
  • Always use wordlists ethically.
  • Custom rules can be written in john.conf.
  • Combining wordlists, rules, and formats is powerful.

❌ Common Mistakes

  • Mistake: Forgetting to use --rules.
    Fix: Always add --rules when you want variations.
  • Mistake: Using the wrong format.
    Fix: Check the hash and use --format correctly.
  • Mistake: Creating a wordlist with spaces.
    Fix: One password per line, no spaces.
  • Mistake: Saving the wordlist with the wrong extension.
    Fix: Save as .txt.
  • Mistake: Using a wordlist without permission.
    Fix: Only use wordlists you own or have rights to.

✅ Best Practices

  • Create custom wordlists for specific targets.
  • Use rules to increase the chances of cracking.
  • Test your rules on a known password first.
  • Keep your wordlists organised and documented.
  • Respect privacy – never crack others’ passwords.
  • Share your wordlists responsibly.

📊 Diagrams & Tables

Timeline: Evolution of Hash Formats

        1991  ── MD5 introduced
        1995  ── SHA‑1 introduced
        2001  ── SHA‑256 introduced
        2005  ── NT/LM hashes used in Windows
        2024  ── John supports 30+ formats
    

Comparison Table: MD5 vs SHA‑256

Feature MD5 SHA‑256
Length 32 characters 64 characters
Security Weak (can be cracked quickly) Strong (much harder to crack)
Speed Fast Slower
Common use Older systems, checksums Modern systems, security

ASCII Flowchart: John with Rules

        Start
          |
          v
        Load wordlist
          |
          v
        For each word:
          |
          +---> Apply rules
          |     |
          +---> Generate variations
          |     |
          +---> Hash each variation
          |     |
          +---> Compare to target
          |     |
          +---> Match? ── Yes ──> Password found!
          |     |
          +---> No ──> Next word
          |
          v
        End
    

Rule Operations Table

Operation Description Example
l Lowercase all letters HELLO → hello
u Uppercase all letters hello → HELLO
c Capitalize first letter hello → Hello
r Reverse the word hello → olleh
$X Append X hello + 1 → hello1
^X Prepend X hello ← A → Ahello
sXY Substitute X with Y hello → he11o (s l 1)



📌 Module 3 Summary

Excellent work! You have completed the third module. Here is what we learned:

  • Wordlists are lists of passwords John tries.
  • You can create your own wordlists.
  • Rules change words into new guesses.
  • John has built‑in rules and you can write custom ones.
  • Different hash formats require different handling.
  • Use --format to specify the hash type.
  • Combining wordlists, rules, and formats makes John very powerful.
  • Always use wordlists ethically.

You are now a wordlist and rules expert! In the next module, we will learn about advanced cracking techniques and how to optimise John for speed.


❓ Frequently Asked Questions

  1. Q: Can I use any text file as a wordlist?
    A: Yes, as long as there is one password per line.
  2. Q: What are the default rules in John?
    A: They are defined in john.conf and include common changes.
  3. Q: Can I use multiple wordlists?
    A: Yes, you can use --wordlist=file1,file2.
  4. Q: How do I know which format to use?
    A: Check the hash length and format.
  5. Q: Can rules crack any password?
    A: No, very strong passwords may still be safe.
  6. Q: Is it legal to create custom wordlists?
    A: Yes, for ethical purposes.
  7. Q: Can I use John to crack my own password?
    A: Yes, if you have the hash.
  8. Q: What is the best wordlist?
    A: It depends on the target – rockyou.txt is a good start.
  9. Q: Can rules slow down John?
    A> Yes, more guesses take more time.
  10. Q: How can I learn more about rules?
    A: Read the documentation in john.conf.

📝 Review Questions

  1. What is a wordlist?
  2. How do you create a wordlist?
  3. What are rules?
  4. How do you use John’s built‑in rules?
  5. What is the --format option used for?
  6. Name two hash formats.
  7. What is MD5?
  8. What is SHA‑256?
  9. How do you combine wordlists and rules?
  10. Why are rules useful?
  11. Can you write custom rules? How?
  12. What is john.conf?
  13. What is a common mistake when using rules?
  14. Why is it important to use wordlists ethically?
  15. What is the first step in using a wordlist?

✍️ Fill‑in‑the‑Blank

  1. A ________ is a list of passwords John tries.
  2. ________ are instructions that change words.
  3. The option to use rules is ________.
  4. ________ is a 32‑character hash format.
  5. ________ is a 64‑character hash format.
  6. Use --________ to specify the hash type.
  7. A custom rule is written in the ________ file.
  8. The operation $1 ________ a 1 to the word.
  9. Always use wordlists ________.
  10. Combining wordlists and rules gives the best ________.

✅ True or False

  1. A wordlist can only contain English words. (False)
  2. Rules are only for advanced users. (False)
  3. John has built‑in rules. (True)
  4. MD5 is more secure than SHA‑256. (False)
  5. You must specify the hash format every time. (True – if John does not detect it)
  6. Custom rules cannot be written. (False)
  7. Rules can make John slower. (True)
  8. You can create a wordlist in Notepad. (True)
  9. Using leaked wordlists is ethical. (False)
  10. John can crack any hash format. (False – only those it supports)

🔢 Multiple Choice

  1. What is a wordlist?
    a) A list of passwords
    b) A list of usernames
    c) A list of files
    Answer: a
  2. How do you use John’s built‑in rules?
    a) --rules
    b) --rule
    c) --apply
    Answer: a
  3. What is MD5?
    a) A 32‑character hash
    b) A 64‑character hash
    c) A password
    Answer: a
  4. What is SHA‑256?
    a) A 32‑character hash
    b) A 64‑character hash
    c) A wordlist
    Answer: b
  5. How do you specify the hash format?
    a) --format
    b) --hash
    c) --type
    Answer: a
  6. What does the operation u do?
    a) Uppercase all letters
    b) Lowercase all letters
    c) Reverse the word
    Answer: a
  7. What does the operation $1 do?
    a) Append 1
    b) Prepend 1
    c) Substitute 1
    Answer: a
  8. Where are custom rules written?
    a) john.conf
    b) wordlist.txt
    c) hash.txt
    Answer: a
  9. What is the best practice when using wordlists?
    a) Use them ethically
    b) Use any wordlist
    c) Share them with everyone
    Answer: a
  10. Can rules crack any password?
    a) Yes
    b) No
    c) Maybe
    Answer: b
  11. What is a common mistake?
    a) Using --rules
    b) Forgetting --rules
    c) Using a wordlist
    Answer: b
  12. What is the best way to create a wordlist?
    a) In a text editor
    b) In a web browser
    c) In a game
    Answer: a
  13. What is the purpose of rules?
    a) To make more guesses
    b) To make fewer guesses
    c) To delete passwords
    Answer: a
  14. Which hash format is stronger?
    a) MD5
    b) SHA‑256
    c) Both are same
    Answer: b
  15. What should you do with cracked passwords?
    a) Keep them secret
    b) Share them publicly
    c) Use them to hack others
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Wordlist A. Adds 1 to the end
2. Rule B. A list of passwords
3. $1 C. An instruction to change a word
4. MD5 D. A 64‑character hash
5. SHA‑256 E. A 32‑character hash

Answers: 1‑B, 2‑C, 3‑A, 4‑E, 5‑D


📝 Short Answer

  1. What is a wordlist and how do you create one?
  2. Explain what rules are and why they are useful.
  3. What is the difference between MD5 and SHA‑256?
  4. How do you tell John the hash format?
  5. Give an example of a custom rule.

🎭 Scenario‑based Exercises

Scenario 1: Kofi has a wordlist with “chidi” but the password is “Chidi2024”.

  • What should Kofi do? (He should use rules with --rules.)
  • What rule would create “Chidi2024”? (Capitalise and append 2024)

Scenario 2: Ada has a hash that looks like 64 characters. She tries to crack it but John fails.

  • What is the likely problem? (She needs to specify the format, e.g., --format=raw-sha256.)

👥 Group Activity

Activity: In groups, create a wordlist with 10 Nigerian cities. Then, use John with rules to see how many variations you can generate. Present your results.


🧑 Individual Activity

Activity: Create a custom wordlist with your name, your pet’s name, and your favourite food. Then, use John with rules to crack a test hash with one of those words.


💬 Classroom Discussion Questions

  1. Why do rules make John more powerful?
  2. What are the dangers of using leaked wordlists?
  3. How can we encourage people to use strong passwords?
  4. Should schools teach about wordlists and rules? Why?
  5. How can Nigerian companies benefit from custom wordlists?

🛠️ Mini Project

Project: Create a custom wordlist for a specific target (e.g., your school). Include names, places, and common terms. Then, write a set of rules to crack typical passwords. Test it on a dummy hash.


📋 Practical Assignment

Assignment: Using a test hash, run John with a wordlist without rules, then with rules. Compare the results and write a short report on the difference.


🏆 Challenge Exercise

Challenge: Create a rule that generates “Password2024!” from “password”. Then, use it to crack a test hash. (Hint: you need uppercase, append, and substitute.)


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • Wordlists are the foundation of dictionary attacks.
  • Rules multiply the number of guesses.
  • John’s built‑in rules are easy to use.
  • Custom rules give you full control.
  • Different hash formats need different handling.
  • Combining all three gives the best results.
  • Ethical use is always important.

🔜 Preparation for Module 4

In Module 4, we will learn about advanced cracking. We will optimise John for speed, use GPU acceleration, and crack complex hashes like ZIP and PDF passwords. We will also learn about session management and restoring jobs.

Make sure you have your John installation ready. See you in Module 4! 🚀


End of Module 3

6

Module Four

Module 4 · Certified John Ripper User

⚡ Module 4: Advanced Cracking & Optimisation

Hello, brilliant learner! 👋

You have come a long way! In Module 1, we learned what John is. In Module 2, we installed it. In Module 3, we made it smarter with wordlists and rules. Now it is time to make John faster and more powerful.

In this module, we will learn how to crack complex passwords like ZIP files, PDFs, and even Windows passwords. We will also learn how to use John’s advanced features like session management and GPU acceleration.

Think of this as upgrading your car from a standard engine to a turbocharged one. Let’s go! 🏎️💨


🎯 Learning Objectives

After this module, you will be able to:

  • Understand session management.
  • Save and restore John sessions.
  • Use different cracking modes.
  • Crack ZIP and PDF passwords.
  • Understand Windows (NT) hashes.
  • Use John with GPU acceleration.
  • Optimise John for speed.
  • Use John’s incremental mode.
  • Crack password-protected files.
  • Perform real-world password audits.

📖 Warm‑up Story: The Turbo Key-Maker

Kofi has become the best key-maker in Cyberville. But he faces new challenges. People bring him complex locks – some from cars, some from safes, and some from computers.

Kofi upgrades his workshop. He adds a turbo machine that can try keys much faster. He also adds a memory bank that remembers which keys he has tried. Now he can crack even the toughest locks.

That is exactly what we will do with John. We will add speed, memory, and the ability to crack complex locks like ZIP files and Windows passwords.

Let’s upgrade our John workshop! 🛠️🚀


📚 Main Lessons

Lesson 1: Session Management – Saving Your Work

Definition: A session is a record of John’s work, including which passwords have been tried.

Why it is important: If John is interrupted, you can resume from where you stopped.

Simple explanation: Like saving a video game so you can continue later.

Real‑life example: You save a document so you don’t lose your work.

School example: You save your homework on a USB drive.

Home example: You save a movie to watch later.

Nigerian example: You save a transaction receipt.

Illustration (ASCII):

        $ john --session=mycrack hashfile.txt
        (John saves progress to mycrack.rec)
        (If interrupted, resume with:)
        $ john --restore=mycrack
    

Mini summary: Sessions let you save and resume John’s work.


Lesson 2: The Pot File – John’s Memory

Definition: The pot file is where John stores cracked passwords.

Why it is important: It prevents John from cracking the same password again.

Simple explanation: Like a notebook where you write down solved puzzles.

Real‑life example: You keep a list of phone numbers.

School example: You keep a glossary of new words.

Home example: You keep a list of your passwords (securely!).

Nigerian example: You keep a list of important dates.

Illustration (ASCII):

        john.pot (pot file)
        +----------------------------------+
        | chidi:5f4dcc3b5aa765d61d832...   |
        | bola:7c6a180b36896a0a8c...      |
        | tunde:6d7b3e1b2c3d...           |
        +----------------------------------+
    

Mini summary: The pot file remembers cracked passwords.


Lesson 3: Incremental Mode – John’s Brute‑Force

Definition: Incremental mode is John’s brute‑force mode that tries every possible combination.

Why it is important: It can crack any password, but it is very slow.

Simple explanation: Like trying every key in the world.

Real‑life example: A locksmith trying every key on a giant keyring.

School example: You try every possible answer in a multiple‑choice test.

Home example: You try every possible combination to unlock your phone.

Nigerian example: You try every possible PIN at an ATM.

Illustration (ASCII):

        $ john --incremental hashfile.txt
        John tries:
        a, b, c, ..., aa, ab, ..., aaa, ...
        (This can take days or years!)
    

Mini summary: Incremental mode tries all combinations.


Lesson 4: Cracking ZIP Files

Definition: ZIP files are compressed folders that can be password-protected.

Why it is important: Many people use ZIP passwords, and John can crack them.

Simple explanation: Like a locked briefcase.

Real‑life example: You download a ZIP file with homework.

School example: Your teacher sends you a ZIP with notes.

Home example: You save photos in a ZIP file.

Nigerian example: A company sends files in a ZIP.

Illustration (ASCII):

        Step 1: Convert ZIP to hash:
        $ zip2john secret.zip > zip.hash
        Step 2: Crack with John:
        $ john --wordlist=wordlist.txt zip.hash
    

Mini summary: John can crack ZIP passwords using zip2john.


Lesson 5: Cracking PDF Files

Definition: PDF files can also be password-protected.

Why it is important: John can crack them to recover lost passwords.

Simple explanation: Like a locked document.

Real‑life example: A confidential report is password-protected.

School example: A teacher sends a PDF with exam answers.

Home example: A bank statement is a PDF.

Nigerian example: A legal document is a PDF.

Illustration (ASCII):

        Step 1: Convert PDF to hash:
        $ pdf2john secret.pdf > pdf.hash
        Step 2: Crack with John:
        $ john --wordlist=wordlist.txt pdf.hash
    

Mini summary: John can crack PDF passwords using pdf2john.


Lesson 6: Windows (NT) Hashes

Definition: Windows stores passwords as NT hashes.

Why it is important: Many computers use Windows, so we need to crack these hashes.

Simple explanation: Like a special lock used by Windows.

Real‑life example: Your school computer runs Windows.

School example: The lab computers use Windows.

Home example: Your family PC runs Windows.

Nigerian example: Many offices use Windows.

Illustration (ASCII):

        Windows NT hash example:
        Password: "hello"
        NT hash: 8846f7eaee8fb117ad06bdd830b7586c
        (32 characters)
        Crack with:
        $ john --format=nt --wordlist=wordlist.txt nt.hash
    

Mini summary: John can crack Windows NT hashes.


Lesson 7: Using John with GPU

Definition: GPU stands for Graphics Processing Unit – it is the part of your computer that handles graphics.

Why it is important: GPUs are very fast at certain calculations, making John much faster.

Simple explanation: Like adding a turbo engine to your car.

Real‑life example: Gamers use GPUs for better graphics.

School example: A school computer with a good GPU.

Home example: Your gaming console has a GPU.

Nigerian example: A video editor uses a GPU.

Illustration (ASCII):

        CPU: 100 tries/sec
        GPU: 1,000,000 tries/sec
        John with GPU is MUCH faster!
        (Requires special build of John)
    

Mini summary: GPUs can make John extremely fast.


Lesson 8: Optimising John for Speed

Definition: Optimisation means making John run as fast as possible.

Why it is important: Faster cracking saves time.

Simple explanation: Like cleaning your car to make it faster.

Real‑life example: You close unnecessary apps on your phone.

School example: You organise your desk to work faster.

Home example: You clean the kitchen to cook faster.

Nigerian example: A trader organises goods to sell faster.

Illustration (ASCII):

        Tips for speed:
        + Use GPU if available
        + Use a smaller wordlist if you know the password pattern
        + Use --format to avoid detection delays
        + Use --session to save progress
        + Use --fork to use multiple CPU cores
    

Mini summary: Optimisation makes John faster.


Lesson 9: Using --fork for Multiple Cores

Definition: The --fork option uses multiple CPU cores to crack faster.

Why it is important: Modern computers have multiple cores, and John can use them all.

Simple explanation: Like having many workers instead of one.

Real‑life example: A factory with many machines.

School example: Many students working on a project.

Home example: Many family members cleaning the house.

Nigerian example: Many traders in a market.

Illustration (ASCII):

        $ john --fork=4 --wordlist=wordlist.txt hashfile.txt
        This uses 4 CPU cores to crack faster.
    

Mini summary: --fork uses multiple CPU cores.


Lesson 10: Cracking Linux Shadow Hashes

Definition: Linux stores passwords in the /etc/shadow file as hashes.

Why it is important: Many servers run Linux, and we may need to test their security.

Simple explanation: Like the Windows lock, but for Linux.

Real‑life example: A web server runs Linux.

School example: The school server may run Linux.

Home example: A Raspberry Pi runs Linux.

Nigerian example: A bank’s server may run Linux.

Illustration (ASCII):

        shadow file example:
        user:$6$salt$hash:...
        Crack with:
        $ john --format=sha512crypt shadow.txt
    

Mini summary: John can crack Linux shadow hashes.


Lesson 11: Cracking RAR Files

Definition: RAR files are compressed files that can have passwords.

Why it is important: Some people use RAR instead of ZIP.

Simple explanation: Another type of locked briefcase.

Real‑life example: A friend sends you a RAR file.

School example: Your teacher sends a RAR with notes.

Home example: You download a RAR file.

Nigerian example: A company uses RAR for files.

Illustration (ASCII):

        Step 1: Convert RAR to hash:
        $ rar2john secret.rar > rar.hash
        Step 2: Crack with John:
        $ john --wordlist=wordlist.txt rar.hash
    

Mini summary: John can crack RAR passwords.


Lesson 12: Using John in Real-World Audits

Definition: A security audit is a test to find weaknesses.

Why it is important: John helps companies find weak passwords.

Simple explanation: Like a fire drill to test safety.

Real‑life example: A company hires a security team to test their systems.

School example: The school tests its computer lab.

Home example: You test your Wi‑Fi password.

Nigerian example: A bank conducts a security audit.

Illustration (ASCII):

        Audit process:
        1. Collect hashes
        2. Run John with wordlists and rules
        3. Analyse results
        4. Report weak passwords
        5. Recommend improvements
    

Mini summary: John is a key tool in security audits.


Lesson 13: Ethical Considerations in Advanced Cracking

Definition: Ethical considerations are rules about right and wrong.

Why it is important: Advanced cracking can be used for harm, so we must be careful.

Simple explanation: Like having superpowers – use them for good.

Real‑life example: A doctor uses skills to heal, not harm.

School example: You use knowledge to help others.

Home example: You use tools to fix things, not break them.

Nigerian example: You use a car to transport, not to race dangerously.

Illustration (ASCII):

        Ethical Use:
        + Always have permission
        + Only crack your own or authorised systems
        + Report vulnerabilities responsibly
        + Never use cracked passwords for harm
    

Mini summary: Always use advanced cracking ethically.


Lesson 14: John’s Performance Tips

Definition: Performance tips are ways to make John run better.

Why it is important: They save time and resources.

Simple explanation: Like using the right tool for the job.

Real‑life example: You use a calculator for math.

School example: You use a highlighter for important notes.

Home example: You use a fast kettle for tea.

Nigerian example: You use a generator during a power cut.

Illustration (ASCII):

        Performance Tips:
        1. Use --format to skip detection
        2. Use --fork to use multiple cores
        3. Use GPU if available
        4. Use a targeted wordlist
        5. Use --session to save progress
    

Mini summary: Performance tips make John faster.


Lesson 15: Becoming an Advanced John User

Definition: An advanced user can crack complex passwords and optimise John.

Why it is important: You are now ready for real‑world challenges.

Simple explanation: Like becoming a master chef.

Real‑life example: A senior security analyst.

School example: The top student in the class.

Home example: A parent who can fix anything.

Nigerian example: A master tailor.

Illustration (ASCII):

        Advanced John User:
        + Can crack any hash format
        + Uses sessions and pot files
        + Optimises with GPU and forks
        + Cracks ZIP, PDF, RAR, and more
        + Acts ethically
        + Helps others stay secure
    

Mini summary: You are now an advanced John user!


📝 Key Vocabulary

  • Session: A saved state of John’s work.
  • Pot file: A file that stores cracked passwords.
  • Incremental: John’s brute‑force mode.
  • ZIP: A compressed file format.
  • PDF: A document file format.
  • NT hash: Windows password hash.
  • GPU: Graphics Processing Unit, used for fast calculations.
  • Fork: Using multiple CPU cores.
  • Shadow: Linux password file.
  • RAR: Another compressed file format.

🧠 Important Concepts

  • Sessions let you save and resume John’s work.
  • The pot file stores cracked passwords.
  • Incremental mode tries all combinations.
  • John can crack ZIP, PDF, and RAR files.
  • Windows uses NT hashes.
  • GPUs can make John much faster.
  • --fork uses multiple CPU cores.
  • Linux shadow files can be cracked.
  • Always use John ethically.
  • Optimisation is key for speed.

📋 Step‑by‑Step: Cracking a ZIP File

  1. Get the ZIP file: You need a password‑protected ZIP.
  2. Convert to hash: Use zip2john to extract the hash: zip2john secret.zip > zip.hash.
  3. Choose a wordlist: Use rockyou.txt or a custom list.
  4. Run John: john --wordlist=rockyou.txt zip.hash.
  5. Add rules: john --wordlist=rockyou.txt --rules zip.hash.
  6. Check results: john --show zip.hash.
  7. Celebrate: You cracked the ZIP password!

Illustration (flowchart):

        Start
          |
          v
        Get ZIP file
          |
          v
        zip2john → zip.hash
          |
          v
        Run John with wordlist
          |
          v
        Add rules
          |
          v
        Show results
          |
          v
        End
    

🌍 Real‑life Examples

  • A company uses John to audit their Windows server passwords.
  • A forensic investigator cracks a ZIP file from a suspect.
  • A student recovers a lost PDF password.
  • An IT admin uses John to test Linux shadow files.
  • A security consultant optimises John with GPU for a large audit.

🇳🇬 Nigerian Examples

  • A Lagos bank uses John to audit their Windows servers.
  • An Abuja IT firm cracks a ZIP file for a client.
  • A Port Harcourt school uses John to test their Linux lab.
  • A Nigerian government agency uses John for security audits.
  • A Nigerian startup uses GPU‑accelerated John for fast cracking.

🧸 Fun Examples for Kids

  • Imagine John is a superhero who can open any lock.
  • Using GPU is like giving John a jetpack.
  • ZIP files are like treasure chests.
  • PDFs are like secret scrolls.
  • Windows hashes are like special keys for Windows locks.

🏠 Everyday Examples

  • You save a game so you can continue later.
  • You write down a phone number in a notebook.
  • You try every possible combination to unlock a bike lock.
  • You use a fast charger to charge your phone quickly.
  • You use a recipe book to cook.

🧑‍🏫 Teacher Notes

  • Demonstrate sessions by stopping and resuming John.
  • Show how to crack a ZIP file using zip2john.
  • Explain the importance of GPUs for speed.
  • Discuss ethical considerations in detail.
  • Encourage students to practise on test files.
  • Use Nigerian examples to make it relatable.

👪 Parent Tips

  • Discuss the importance of strong passwords.
  • Explain that John is for learning, not for hacking.
  • Help your child understand sessions and saving work.
  • Encourage ethical use of technology.
  • Celebrate their achievements in learning John.

🤯 Interesting Facts

  • John can crack over 30 different hash formats.
  • GPU‑accelerated John can be 100 times faster than CPU.
  • The rockyou.txt wordlist is from a 2009 data breach.
  • John was originally written for Unix systems.
  • Some password hashes are designed to be slow to prevent cracking.
  • John has been used in real forensic investigations.

💡 Did You Know?

  • Did you know that John can crack passwords from databases?
  • Did you know that John can be used on a Raspberry Pi?
  • Did you know that John has a “external” mode for custom cracking?
  • Did you know that John can crack passwords from websites?
  • Did you know that John can be used to test the strength of your own passwords?

🔔 Remember This

  • Sessions let you save and resume John’s work.
  • The pot file stores cracked passwords.
  • Incremental mode is brute‑force.
  • John can crack ZIP, PDF, and RAR files.
  • Windows uses NT hashes.
  • GPUs make John much faster.
  • Use --fork for multiple cores.
  • Always use John ethically.

❌ Common Mistakes

  • Mistake: Forgetting to use zip2john before cracking.
    Fix: Always convert the file to a hash first.
  • Mistake: Not using sessions and losing progress.
    Fix: Always use --session.
  • Mistake: Using incremental mode for simple passwords.
    Fix: Use wordlist mode first.
  • Mistake: Using John without permission.
    Fix: Only crack authorised systems.
  • Mistake: Not optimising John for speed.
    Fix: Use --fork and GPU if available.

✅ Best Practices

  • Always use sessions to save progress.
  • Use the pot file to avoid re‑cracking.
  • Start with a wordlist before using incremental mode.
  • Use GPU for large cracking tasks.
  • Always have permission before cracking.
  • Document your work for audits.

📊 Diagrams & Tables

Timeline: John’s Evolution

        1996  ── John 1.0 released
        2000  ── Added Windows support
        2005  ── Added GPU support
        2010  ── Added more hash formats
        2015  ── Added session management
        2024  ── John 1.9 with advanced features
    

Comparison Table: Cracking Modes

Mode Description Speed Best for
Wordlist Uses a dictionary Fast Common passwords
Rules Modifies words Medium Password variations
Incremental Tries all combinations Slow Short passwords
GPU Uses graphics card Very fast Large cracking tasks

ASCII Flowchart: Cracking a ZIP File

        Start
          |
          v
        ZIP file (secret.zip)
          |
          v
        zip2john → zip.hash
          |
          v
        Run John with wordlist
          |
          v
        Add rules
          |
          v
        Check results
          |
          v
        Password found? ── Yes ──> Success!
          |
          No
          |
          v
        Try incremental mode
          |
          v
        End
    

Comparison Table: File Types John Can Crack

File Type Tool Format
ZIP zip2john zip
PDF pdf2john pdf
RAR rar2john rar
Windows pwdump nt
Linux unshadow sha512crypt



📌 Module 4 Summary

Amazing work! You have completed the fourth module. Here is what we learned:

  • How to use sessions to save and resume John’s work.
  • The pot file stores cracked passwords.
  • Incremental mode is brute‑force.
  • How to crack ZIP, PDF, and RAR files.
  • Windows NT hashes and Linux shadow files.
  • How to use GPU for fast cracking.
  • Using --fork for multiple cores.
  • Optimising John for speed.
  • The importance of ethical use.

You are now an advanced John user! In the next module, we will learn about real‑world penetration testing and how to use John in professional security assessments.


❓ Frequently Asked Questions

  1. Q: How do I use a session?
    A: Use --session=name and --restore=name.
  2. Q: What is the pot file?
    A: It stores cracked passwords.
  3. Q: When should I use incremental mode?
    A: When wordlists fail and the password is short.
  4. Q: Can John crack any ZIP file?
    A: Yes, if the password is not too strong.
  5. Q: What is a GPU?
    A> Graphics card that can be used for fast cracking.
  6. Q: How do I use --fork?
    A: john --fork=4 uses 4 cores.
  7. Q: Can John crack Windows passwords?
    A: Yes, with NT hashes.
  8. Q: Is John legal?
    A: Yes, when used ethically.
  9. Q: How can I make John faster?
    A: Use GPU, --fork, and optimisation.
  10. Q: What is the best way to learn John?
    A: Practise with test files.

📝 Review Questions

  1. What is a session?
  2. What does the pot file do?
  3. What is incremental mode?
  4. How do you crack a ZIP file?
  5. How do you crack a PDF file?
  6. What is an NT hash?
  7. What is GPU acceleration?
  8. How do you use multiple cores?
  9. What is a shadow file?
  10. How do you crack a RAR file?
  11. Why is optimisation important?
  12. What are the ethical considerations?
  13. What is a security audit?
  14. How do you resume a session?
  15. What is the best practice for using John?

✍️ Fill‑in‑the‑Blank

  1. A ________ saves John’s progress.
  2. The ________ file stores cracked passwords.
  3. ________ mode tries all combinations.
  4. Use ________ to crack a ZIP file.
  5. Use ________ to crack a PDF file.
  6. Windows passwords are called ________ hashes.
  7. ________ can make John much faster.
  8. Use --________ to use multiple cores.
  9. Linux passwords are stored in the ________ file.
  10. Always use John ________.

✅ True or False

  1. John can crack ZIP files. (True)
  2. Sessions are not useful. (False)
  3. The pot file is not important. (False)
  4. Incremental mode is very fast. (False)
  5. GPU makes John faster. (True)
  6. --fork uses multiple cores. (True)
  7. John can crack PDF files. (True)
  8. Windows uses Linux hashes. (False)
  9. John can crack RAR files. (True)
  10. Ethical use is not important. (False)

🔢 Multiple Choice

  1. How do you save a session?
    a) --session
    b) --save
    c) --store
    Answer: a
  2. What is the pot file?
    a) A file with cracked passwords
    b) A file with wordlists
    c) A file with hashes
    Answer: a
  3. What is incremental mode?
    a) Wordlist attack
    b) Brute‑force attack
    c) Rule attack
    Answer: b
  4. How do you crack a ZIP file?
    a) Use zip2john
    b) Use pdf2john
    c) Use rar2john
    Answer: a
  5. What is an NT hash?
    a) Windows hash
    b) Linux hash
    c) Mac hash
    Answer: a
  6. What does GPU stand for?
    a) Graphics Processing Unit
    b) General Processing Unit
    c) Great Processing Unit
    Answer: a
  7. How do you use multiple cores?
    a) --fork
    b) --cores
    c) --multi
    Answer: a
  8. What is the shadow file?
    a) Linux password file
    b) Windows password file
    c) Mac password file
    Answer: a
  9. How do you crack a RAR file?
    a) Use rar2john
    b) Use zip2john
    c) Use pdf2john
    Answer: a
  10. What is the best practice for using John?
    a) Use it ethically
    b) Use it on anyone
    c) Use it without permission
    Answer: a
  11. What is optimisation?
    a) Making John faster
    b) Making John slower
    c) Making John less effective
    Answer: a
  12. What is a security audit?
    a) A test to find weaknesses
    b) A test to find passwords
    c) A test to break systems
    Answer: a
  13. How do you resume a session?
    a) --restore
    b) --resume
    c) --continue
    Answer: a
  14. What is the main advantage of GPU?
    a) Speed
    b) Size
    c) Cost
    Answer: a
  15. What is the most important rule of using John?
    a) Always have permission
    b) Always use wordlists
    c) Always use rules
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Session A. Stores cracked passwords
2. Pot file B. Saved state of John's work
3. Incremental C. Used for ZIP files
4. zip2john D. Brute‑force mode
5. GPU E. Makes John faster

Answers: 1‑B, 2‑A, 3‑D, 4‑C, 5‑E


📝 Short Answer

  1. What is a session and why is it useful?
  2. How do you crack a ZIP file with John?
  3. What is the difference between wordlist and incremental mode?
  4. How does GPU acceleration work?
  5. What are the ethical considerations when using John?

🎭 Scenario‑based Exercises

Scenario 1: Kofi has a ZIP file called “secret.zip” that he forgot the password to.

  • What should he do? (Use zip2john and then John.)
  • What mode should he use first? (Wordlist mode.)

Scenario 2: Ada is running John on a large hash file and it is taking too long.

  • What can she do to speed it up? (Use --fork or GPU.)
  • What should she do to save progress? (Use --session.)

👥 Group Activity

Activity: In groups, create a password‑protected ZIP file and then use John to crack it. Share your results and discuss the time taken.


🧑 Individual Activity

Activity: Create a PDF with a password and crack it using John. Write down the steps you took.


💬 Classroom Discussion Questions

  1. Why are sessions important?
  2. How can GPU acceleration change the way we crack passwords?
  3. What are the risks of using John without permission?
  4. How can companies protect themselves from password cracking?
  5. What is the future of password cracking?

🛠️ Mini Project

Project: Create a report on how to crack a ZIP file using John. Include the steps, commands, and screenshots (if possible). Also, include a section on ethical considerations.


📋 Practical Assignment

Assignment: Using John, crack a password‑protected ZIP file provided by your teacher. Submit a report with the password and the time taken.


🏆 Challenge Exercise

Challenge: Crack a PDF password that is not in any wordlist. Use incremental mode and time how long it takes. (Hint: use a short password.)


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • Sessions and pot files are essential for managing John’s work.
  • Incremental mode is a powerful but slow brute‑force method.
  • John can crack many file types, including ZIP, PDF, and RAR.
  • Windows and Linux hashes can be cracked with John.
  • GPU and --fork significantly improve speed.
  • Optimisation is key for large cracking tasks.
  • Ethical use is always paramount.

🔜 Preparation for Module 5

In Module 5, we will learn about real‑world penetration testing. We will simulate a real security audit, use John in a team, and understand how professionals use John to protect organisations.

Make sure you have John installed and have completed all exercises. See you in Module 5! 🚀


End of Module 4

7

Module Five

Module 5 · Certified John Ripper User

🌐 Module 5: Real‑World Penetration Testing with John

Hello, future cyber guardian! 👋

You have learned so much! You know how to install John, create wordlists, use rules, crack ZIP files, and even use GPU acceleration. Now it is time to put all those skills together in a real‑world scenario.

In this module, we will learn about penetration testing – that is when good guys (like you) test computer systems to find weaknesses before bad guys do. We will simulate a real security audit and see how John fits into the bigger picture.

Think of yourself as a superhero who tests the strength of a fortress. You find weak points and help fix them. That is what penetration testers do!

Let’s become cyber superheroes! 🦸‍♂️🦸‍♀️


🎯 Learning Objectives

After this module, you will be able to:

  • Explain what penetration testing is.
  • Understand the role of John in pen testing.
  • Plan a security audit.
  • Gather password hashes from systems.
  • Use John to test password strength.
  • Analyse John’s results.
  • Write a simple security report.
  • Recommend password improvements.
  • Work in a team on a pen test.
  • Understand the full process from start to finish.

📖 Warm‑up Story: The Fortress Test

Kofi is now a master key-maker. But he wants to do more. He hears about the Cyber Fortress – a big company that keeps everyone’s data safe. The company hires Kofi to test their locks.

Kofi plans his test. He asks for permission. He checks all the doors, windows, and gates. He uses his tools (including John) to see if any locks are weak. He finds a few weak locks and tells the company how to fix them.

The company thanks Kofi and makes their fortress stronger. Kofi feels proud because he helped protect people’s data.

That is exactly what penetration testing is – testing a system to make it stronger.

Let’s learn how to do it! 🏰🔐


📚 Main Lessons

Lesson 1: What is Penetration Testing?

Definition: Penetration testing (or pen testing) is when security experts test a system to find vulnerabilities.

Why it is important: It helps organisations fix weaknesses before hackers can exploit them.

Simple explanation: Like a fire drill – you test the system to see if it works.

Real‑life example: A company hires a hacker (ethical) to test their network.

School example: A teacher gives a practice test before the final exam.

Home example: You test your smoke alarm to see if it works.

Nigerian example: A bank tests its online banking system.

Illustration (ASCII):

        Penetration Testing Process:
        Plan → Recon → Attack → Report → Fix
          |       |        |        |       |
          v       v        v        v       v
        Get     Find     Try to   Write   Improve
        OK      holes    break    report  security
    

Mini summary: Pen testing is testing systems to make them safer.


Lesson 2: The Role of John in Pen Testing

Definition: John is used in pen testing to crack password hashes and test password strength.

Why it is important: Weak passwords are one of the biggest security risks.

Simple explanation: John is the key tester – it checks if the locks are strong.

Real‑life example: A pen tester uses John to test employee passwords.

School example: The IT teacher uses John to check student passwords.

Home example: You use John to test your Wi‑Fi password.

Nigerian example: A bank uses John to test staff passwords.

Illustration (ASCII):

        Pen Tester
            |
            v
        John the Ripper
            |
            v
        Finds weak passwords
            |
            v
        Reports to client
            |
            v
        Client fixes weaknesses
    

Mini summary: John helps pen testers find weak passwords.


Lesson 3: Planning a Pen Test

Definition: Planning means deciding what to test, how to test it, and when to test it.

Why it is important: Good planning leads to a successful test.

Simple explanation: Like planning a trip – you decide where to go and what to pack.

Real‑life example: A security team plans a test for a client.

School example: You plan a study schedule.

Home example: You plan a weekend activity.

Nigerian example: A trader plans what goods to buy for the market.

Illustration (ASCII):

        Planning Steps:
        1. Define scope (what to test)
        2. Get permission (very important!)
        3. Set timeline (when to test)
        4. Gather tools (John, wordlists, etc.)
        5. Prepare team (who will do what)
    

Mini summary: Planning is the first step in any pen test.


Lesson 4: Getting Permission – The Rules of Engagement

Definition: Rules of engagement are the guidelines for the test, including what is allowed and what is not.

Why it is important: Without permission, testing is illegal.

Simple explanation: Like asking before entering someone’s house.

Real‑life example: A pen tester signs a contract with the client.

School example: You ask your teacher before using a computer.

Home example: You ask your parent before using their phone.

Nigerian example: A security company signs an agreement with a bank.

Illustration (ASCII):

        Permission Contract:
        +----------------------------+
        | I, [client], give         |
        | permission to [tester]    |
        | to test our systems       |
        | from [date] to [date].    |
        | Scope: [what is allowed]  |
        | Rules: [what is forbidden]|
        +----------------------------+
    

Mini summary: Always get written permission before testing.


Lesson 5: Gathering Hashes

Definition: Gathering hashes means collecting password hashes from a system.

Why it is important: John needs hashes to crack passwords.

Simple explanation: Like collecting samples for a lab test.

Real‑life example: A pen tester dumps hashes from a Windows server.

School example: The IT admin collects hashes from school computers.

Home example: You collect hashes from your own devices.

Nigerian example: A bank collects hashes from their staff systems.

Illustration (ASCII):

        Hash Gathering:
        Windows: pwdump → hashes.txt
        Linux:   unshadow → hashes.txt
        Tools:   mimikatz, fgdump, etc.
        Always have permission!
    

Mini summary: Hashes are collected from systems for testing.


Lesson 6: Running John on Real Hashes

Definition: Running John on real hashes means cracking the passwords from a real system.

Why it is important: This is where John shows its power.

Simple explanation: Like testing the real locks.

Real‑life example: A pen tester runs John on client hashes.

School example: A teacher runs John on lab computer hashes.

Home example: You run John on your own hashes.

Nigerian example: A bank runs John on employee hashes.

Illustration (ASCII):

        $ john --wordlist=rockyou.txt --rules hashes.txt
        John starts cracking...
        Loaded 100 hashes.
        Press 'q' to quit.
        0g 0:00:00:01 0.00%
        10g 0:00:01:23 10.00%
        ...
        Results saved in john.pot
    

Mini summary: John cracks real hashes to find weak passwords.


Lesson 7: Analysing Results

Definition: Analysing results means looking at John’s output and understanding what it means.

Why it is important: You need to know which passwords are weak.

Simple explanation: Like reading a test score.

Real‑life example: A pen tester examines the cracked passwords.

School example: A teacher checks which students passed.

Home example: You check which locks are weak.

Nigerian example: A bank checks which staff have weak passwords.

Illustration (ASCII):

        Results Analysis:
        Password: 123456    → very weak
        Password: password  → very weak
        Password: chidi2024 → medium
        Password: Lagos123  → medium
        Password: P@ssw0rd! → strong
    

Mini summary: Analysing results helps identify weak passwords.


Lesson 8: Writing a Security Report

Definition: A security report documents the findings of a pen test.

Why it is important: Clients need to know what to fix.

Simple explanation: Like a doctor’s report after a check‑up.

Real‑life example: A pen tester writes a report for the client.

School example: You write a report on a science experiment.

Home example: You write a note to your parents about a broken lock.

Nigerian example: A bank receives a report from security experts.

Illustration (ASCII):

        Security Report
        +----------------------------+
        | 1. Executive Summary       |
        | 2. Scope of Test           |
        | 3. Methodology             |
        | 4. Findings                |
        | 5. Recommendations         |
        | 6. Appendix                |
        +----------------------------+
    

Mini summary: A report communicates findings and recommendations.


Lesson 9: Recommending Fixes

Definition: Recommending fixes means suggesting ways to improve security.

Why it is important: It helps the client fix the weaknesses.

Simple explanation: Like telling someone how to repair a broken lock.

Real‑life example: A pen tester recommends password policies.

School example: A teacher recommends students use stronger passwords.

Home example: You recommend your family uses a stronger Wi‑Fi password.

Nigerian example: A bank implements new password policies.

Illustration (ASCII):

        Recommendations:
        1. Enforce minimum 12‑character passwords
        2. Require uppercase, lowercase, numbers, symbols
        3. Use multi‑factor authentication (MFA)
        4. Change passwords every 90 days
        5. Use a password manager
    

Mini summary: Recommendations help improve security.


Lesson 10: The Pen Testing Team

Definition: A pen testing team is a group of security experts who work together.

Why it is important: Teamwork makes testing more effective.

Simple explanation: Like a football team – everyone has a role.

Real‑life example: A company hires a team of pen testers.

School example: Students work on a group project.

Home example: Family members work together to clean the house.

Nigerian example: A security firm has a team for each client.

Illustration (ASCII):

        Pen Testing Team Roles:
        +------------------+
        | Team Leader      | → Plans and manages
        | Network Tester   | → Tests network
        | Web Tester       | → Tests web apps
        | Password Tester  | → Uses John
        | Report Writer    | → Writes findings
        +------------------+
    

Mini summary: Teams make pen testing more effective.


Lesson 11: Simulating a Real Audit

Definition: A real audit is a simulated exercise that mimics a real pen test.

Why it is important: It prepares you for real‑world challenges.

Simple explanation: Like a fire drill – it prepares you for a real fire.

Real‑life example: A company runs a mock pen test.

School example: Your teacher gives a mock exam.

Home example: You practice a fire drill at home.

Nigerian example: A bank conducts a simulated security test.

Illustration (ASCII):

        Simulated Audit:
        1. Set up a test environment
        2. Create dummy user accounts
        3. Run John on dummy hashes
        4. Write a report
        5. Present findings to the “client”
    

Mini summary: Simulated audits are great for learning.


Lesson 12: Ethical Hacking – The Bigger Picture

Definition: Ethical hacking is using hacking skills for good – to protect people and systems.

Why it is important: Ethical hackers are the heroes of the digital world.

Simple explanation: Like a police officer who uses a gun to protect, not to harm.

Real‑life example: A certified ethical hacker (CEH) works for a security company.

School example: A student uses their skills to help classmates.

Home example: A parent uses technology to keep the family safe.

Nigerian example: A Nigerian cybersecurity professional helps banks.

Illustration (ASCII):

        Ethical Hacker:
        + Protects people
        + Finds vulnerabilities
        + Reports responsibly
        + Never harms others
        + Helps make the internet safer
    

Mini summary: Ethical hacking is about helping and protecting.


Lesson 13: Real Pen Test Examples

Definition: Real pen test examples are case studies of actual pen tests.

Why it is important: They show how pen testing works in practice.

Simple explanation: Like reading a story about a real adventure.

Real‑life example: A pen test reveals weak passwords in a company.

School example: A school discovers that students use easy passwords.

Home example: A family discovers their Wi‑Fi password is weak.

Nigerian example: A bank finds that staff use common passwords.

Illustration (ASCII):

        Case Study: XYZ Bank
        1. Hashes collected from 100 staff
        2. John ran with rockyou.txt and rules
        3. 45 hashes cracked in 1 hour
        4. 25 passwords were "password" or "123456"
        5. Recommendations: enforce stronger passwords
        6. Bank implements new policy
    

Mini summary: Real examples show the importance of pen testing.


Lesson 14: The Future of Pen Testing

Definition: The future of pen testing includes AI, machine learning, and automated tools.

Why it is important: Technology is always changing, and pen testers must keep up.

Simple explanation: Like upgrading your phone to a newer model.

Real‑life example: AI is used to predict and find vulnerabilities.

School example: Students learn about new cybersecurity trends.

Home example: Smart home devices need security testing.

Nigerian example: Nigerian companies adopt AI for security.

Illustration (ASCII):

        Future of Pen Testing:
        + AI-powered tools
        + Automated vulnerability scanning
        + Cloud security testing
        + IoT (Internet of Things) testing
        + Continuous security monitoring
    

Mini summary: The future of pen testing is exciting and ever‑evolving.


Lesson 15: Becoming a Certified Pen Tester

Definition: A certified pen tester has passed exams and proven their skills.

Why it is important: Certification shows you are knowledgeable and trustworthy.

Simple explanation: Like a driver’s license – it proves you can drive safely.

Real‑life example: A security professional gets the OSCP certification.

School example: You get a certificate after completing a course.

Home example: You get a merit badge for learning a new skill.

Nigerian example: A Nigerian professional gets CISSP certification.

Illustration (ASCII):

        Certification Path:
        Learn basics → Practice → Take exam → Get certified → Work in the field
    

Mini summary: Certification proves you are a skilled pen tester.


📝 Key Vocabulary

  • Penetration testing: Testing systems to find vulnerabilities.
  • Audit: A formal review of security.
  • Scope: The boundaries of the test.
  • Rules of engagement: The guidelines for the test.
  • Hash: A scrambled password.
  • Report: A document with findings.
  • Recommendation: A suggestion to improve security.
  • Ethical hacker: A hacker who helps protect.
  • Team: A group working together.
  • Certification: Proof of skill.

🧠 Important Concepts

  • Pen testing helps organisations improve security.
  • John is a key tool for testing passwords.
  • Planning is crucial for a successful test.
  • Always get permission before testing.
  • Hashes are collected from systems.
  • John cracks hashes to find weak passwords.
  • Results are analysed and reported.
  • Recommendations help fix weaknesses.
  • Teamwork makes testing more effective.
  • Ethical hacking is about helping and protecting.

📋 Step‑by‑Step: Conducting a Pen Test with John

  1. Plan: Define the scope, get permission, and set a timeline.
  2. Gather: Collect hashes from the target system.
  3. Crack: Run John with wordlists and rules on the hashes.
  4. Analyse: Review the cracked passwords and identify weak ones.
  5. Report: Write a report with findings and recommendations.
  6. Present: Share the report with the client and discuss fixes.
  7. Follow up: Ensure the client implements the recommendations.

Illustration (flowchart):

        Start
          |
          v
        Plan (scope, permission)
          |
          v
        Gather hashes
          |
          v
        Run John
          |
          v
        Analyse results
          |
          v
        Write report
          |
          v
        Present to client
          |
          v
        Follow up
          |
          v
        End
    

🌍 Real‑life Examples

  • A global bank conducts a pen test on its online banking system.
  • A hospital tests its patient data system.
  • A government agency tests its internal network.
  • A university tests its student portal.
  • A tech company tests its cloud infrastructure.

🇳🇬 Nigerian Examples

  • A Lagos bank conducts a pen test on its mobile app.
  • An Abuja government agency tests its e‑government portal.
  • A Port Harcourt oil company tests its SCADA systems.
  • A Nigerian fintech tests its payment platform.
  • A Nigerian university tests its student management system.

🧸 Fun Examples for Kids

  • Imagine you are a spy testing a secret base.
  • John is your spy tool that finds weak doors.
  • Pen testing is like a treasure hunt for security holes.
  • Writing a report is like telling your team where the treasure is.
  • Becoming a pen tester is like becoming a superhero.

🏠 Everyday Examples

  • You test your front door to see if it locks properly.
  • You check your bike lock to see if it is secure.
  • You test your smoke alarm to see if it works.
  • You check your phone’s security settings.
  • You test your Wi‑Fi password.

🧑‍🏫 Teacher Notes

  • Emphasise the ethical and legal aspects of pen testing.
  • Use case studies to make it real.
  • Conduct a simulated pen test in class.
  • Encourage students to think like pen testers.
  • Discuss the importance of reporting.
  • Use Nigerian examples to make it relatable.

👪 Parent Tips

  • Discuss the importance of cybersecurity at home.
  • Help your child understand the difference between ethical and unethical hacking.
  • Encourage them to think about security in everyday life.
  • Support their interest in cybersecurity.
  • Celebrate their achievements in this course.

🤯 Interesting Facts

  • Penetration testing has been around since the 1960s.
  • The first pen testers were called “tiger teams”.
  • Many large companies have dedicated pen testing teams.
  • John is one of the most popular pen testing tools.
  • Pen testing is a growing field with many job opportunities.
  • Some pen testers specialise in specific areas, like web or mobile.

💡 Did You Know?

  • Did you know that pen testers often dress in business attire?
  • Did you know that some pen tests take weeks?
  • Did you know that pen testers use many tools, not just John?
  • Did you know that pen testing is sometimes called “white‑hat hacking”?
  • Did you know that pen testers often work from home?

🔔 Remember This

  • Pen testing is testing systems to make them safer.
  • John is a key tool for pen testers.
  • Always get permission before testing.
  • Planning is essential for a successful test.
  • Hashes are collected and cracked with John.
  • Results are analysed and reported.
  • Recommendations help fix weaknesses.
  • Ethical hacking is about helping and protecting.

❌ Common Mistakes

  • Mistake: Testing without permission.
    Fix: Always get written permission.
  • Mistake: Not defining the scope.
    Fix: Clearly define what will be tested.
  • Mistake: Forgetting to write a report.
    Fix: Always document findings.
  • Mistake: Not following up.
    Fix: Ensure the client fixes the issues.
  • Mistake: Using John on unauthorised systems.
    Fix: Only test systems you have permission to test.

✅ Best Practices

  • Always get permission in writing.
  • Plan the test carefully.
  • Use John ethically and responsibly.
  • Analyse results thoroughly.
  • Write clear and actionable reports.
  • Follow up to ensure fixes are implemented.
  • Continue learning and improving your skills.

📊 Diagrams & Tables

Timeline: A Typical Pen Test

        Day 1  ── Planning and scope definition
        Day 2  ── Gathering hashes and initial reconnaissance
        Day 3  ── Cracking with John
        Day 4  ── Analysing results
        Day 5  ── Writing the report
        Day 6  ── Presenting to the client
        Day 7  ── Follow‑up and remediation
    

Comparison Table: Pen Test vs. Vulnerability Scan

Feature Penetration Test Vulnerability Scan
Goal Exploit vulnerabilities Identify vulnerabilities
Method Manual and automated Automated only
Result Proof of exploitation List of potential issues
Cost Higher Lower
Time Days to weeks Hours to days

ASCII Flowchart: Pen Testing Process

        Start
          |
          v
        Define Scope
          |
          v
        Get Permission
          |
          v        Gather Information
          |
          v
        Test Systems
          |
          v
        Analyse Results
          |
          v
        Write Report
          |
          v
        Present Findings
          |
          v
        Follow Up
          |
          v
        End
    

Comparison Table: Roles in a Pen Test Team

Role Responsibility
Team Leader Manages the test, communicates with client
Network Tester Tests network infrastructure
Web Tester Tests web applications
Password Tester Uses John to test password strength
Report Writer Documents findings and recommendations



📌 Module 5 Summary

Outstanding work! You have completed the fifth module. Here is what we learned:

  • What penetration testing is and why it is important.
  • How John fits into the pen testing process.
  • How to plan a pen test and get permission.
  • How to gather hashes from systems.
  • How to run John on real hashes.
  • How to analyse John’s results.
  • How to write a security report.
  • How to recommend fixes and follow up.
  • The importance of teamwork and ethical hacking.
  • How to become a certified pen tester.

You are now ready to conduct a real‑world pen test (with permission, of course!). In the next module, we will learn about defensive measures – how to protect against password cracking and other attacks.


❓ Frequently Asked Questions

  1. Q: What is penetration testing?
    A: Testing systems to find vulnerabilities.
  2. Q: Why do companies do pen testing?
    A: To find and fix weaknesses before hackers exploit them.
  3. Q: Is pen testing legal?
    A: Yes, when done with permission.
  4. Q: How long does a pen test take?
    A: From a few days to several weeks.
  5. Q: What tools are used in pen testing?
    A: Tools like John, Nmap, Metasploit, and Burp Suite.
  6. Q: What is the role of John in pen testing?
    A> To crack password hashes and test password strength.
  7. Q: What is a security report?
    A: A document with findings and recommendations.
  8. Q: How do I become a pen tester?
    A: Learn, practice, get certified, and gain experience.
  9. Q: Is pen testing a good career?
    A: Yes, it is a growing and well‑paid field.
  10. Q: Can I do pen testing on my own?
    A: You can practice on your own systems, but always with permission.

📝 Review Questions

  1. What is penetration testing?
  2. Why is permission important?
  3. What is the role of John in pen testing?
  4. What is the first step in a pen test?
  5. How do you gather hashes?
  6. What does John do with hashes?
  7. Why is analysing results important?
  8. What is a security report?
  9. What are recommendations?
  10. Why is teamwork important?
  11. What is ethical hacking?
  12. Give a Nigerian example of pen testing.
  13. What is a vulnerability scan?
  14. How do you become a pen tester?
  15. What is the future of pen testing?

✍️ Fill‑in‑the‑Blank

  1. ________ testing is when security experts test systems to find vulnerabilities.
  2. Always get ________ before testing.
  3. John is used to crack ________.
  4. ________ are collected from systems for testing.
  5. A ________ documents findings and recommendations.
  6. ________ help fix weaknesses.
  7. Ethical hackers help ________ people.
  8. A pen test ________ manages the team.
  9. ________ are tools used in pen testing.
  10. ________ is proof of skill.

✅ True or False

  1. Pen testing is illegal. (False)
  2. Permission is not needed for pen testing. (False)
  3. John is used in pen testing. (True)
  4. Hashes are not useful. (False)
  5. A report is not needed after a pen test. (False)
  6. Recommendations help improve security. (True)
  7. Ethical hacking is about helping. (True)
  8. Pen testing is a growing field. (True)
  9. You can test any system without permission. (False)
  10. Pen testing is the same as vulnerability scanning. (False)

🔢 Multiple Choice

  1. What is penetration testing?
    a) Testing systems for vulnerabilities
    b) Breaking into systems illegally
    c) Installing software
    Answer: a
  2. Why is permission important?
    a) It is the law
    b) It is not important
    c) To save time
    Answer: a
  3. What is John used for in pen testing?
    a) Cracking passwords
    b) Scanning networks
    c) Writing reports
    Answer: a
  4. What is the first step in a pen test?
    a) Gathering hashes
    b) Planning
    c) Running John
    Answer: b
  5. How do you gather hashes?
    a) Using tools like pwdump
    b) Guessing
    c) Asking users
    Answer: a
  6. What does John do with hashes?
    a) Cracks them
    b) Deletes them
    c) Ignores them
    Answer: a
  7. Why is analysing results important?
    a) To find weak passwords
    b) To delete the hashes
    c) To waste time
    Answer: a
  8. What is a security report?
    a) A document with findings
    b) A list of passwords
    c) A book
    Answer: a
  9. What are recommendations?
    a) Suggestions to fix weaknesses
    b) A list of passwords
    c) A report
    Answer: a
  10. Why is teamwork important?
    a) It makes testing more effective
    b) It is not important
    c) To share passwords
    Answer: a
  11. What is ethical hacking?
    a) Using hacking skills for good
    b) Hacking for fun
    c) Breaking laws
    Answer: a
  12. Give a Nigerian example of pen testing.
    a) A bank testing its mobile app
    b) A school testing its students
    c) A market testing its goods
    Answer: a
  13. What is a vulnerability scan?
    a) An automated scan for vulnerabilities
    b) A manual test
    c) A report
    Answer: a
  14. How do you become a pen tester?
    a) Learn, practice, get certified
    b) Guess
    c) Ask someone
    Answer: a
  15. What is the future of pen testing?
    a) More AI and automation
    b) It will disappear
    c) No change
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Penetration testing A. A document with findings
2. Permission B. Testing systems for vulnerabilities
3. Report C. Must be obtained before testing
4. John D. A tool for cracking passwords
5. Recommendation E. A suggestion to fix a weakness

Answers: 1‑B, 2‑C, 3‑A, 4‑D, 5‑E


📝 Short Answer

  1. What is penetration testing and why is it important?
  2. What is the role of John in a pen test?
  3. What are the key steps in a pen test?
  4. Why is it important to get permission before testing?
  5. What is the difference between a pen test and a vulnerability scan?

🎭 Scenario‑based Exercises

Scenario 1: A company hires a pen testing team. The team leader assigns roles. Kofi is responsible for password testing.

  • What tool should Kofi use? (John the Ripper.)
  • What is Kofi’s first step? (Gather hashes from the company’s systems.)

Scenario 2: A pen tester finds that 30 out of 100 passwords are weak.

  • What should the pen tester do? (Write a report and recommend fixes.)
  • What are some recommendations? (Enforce stronger passwords, use MFA.)

👥 Group Activity

Activity: In groups, plan a simulated pen test for a mock company. Assign roles, create a test plan, and present your plan to the class.


🧑 Individual Activity

Activity: Imagine you are a pen tester. Write a one‑page security report for a mock company with three weak passwords and three recommendations.


💬 Classroom Discussion Questions

  1. Why is ethical hacking important in today’s world?
  2. How can companies encourage employees to use strong passwords?
  3. What are the risks of not conducting pen tests?
  4. How can Nigeria benefit from more pen testers?
  5. What skills are needed to be a good pen tester?

🛠️ Mini Project

Project: Conduct a simulated pen test on a test system. Use John to crack passwords, write a report, and present your findings.


📋 Practical Assignment

Assignment: Using a test system provided by your teacher, gather hashes, run John, and write a security report with recommendations.


🏆 Challenge Exercise

Challenge: Simulate a pen test on a system with a mix of weak and strong passwords. Use John to crack as many as possible, and then write a detailed report with actionable recommendations.


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • Penetration testing is essential for security.
  • John is a vital tool for password testing.
  • Always get permission before testing.
  • Planning and teamwork are crucial.
  • Hashes are gathered and cracked with John.
  • Results are analysed and reported.
  • Recommendations help fix vulnerabilities.
  • Ethical hacking is about helping and protecting.
  • Certification proves your skills.
  • Pen testing is a rewarding and growing career.

🔜 Preparation for Module 6

In Module 6, we will learn about defensive measures. We will understand how to protect against password cracking, implement strong password policies, and use tools like John to test our own defences.

Make sure you have your John installation ready. See you in Module 6! 🚀


End of Module 5

8

Module Six

Module 6 · Certified John Ripper User

🛡️ Module 6: Defensive Measures – Protecting Against John

Hello, cyber guardian! 👋

You have learned so much about John the Ripper – how it works, how to use it, and even how to crack passwords. But there is another side to the story: defence.

In this module, we will learn how to protect ourselves and others from password cracking. We will understand what makes a password strong, how to implement good password policies, and how to use tools like John to test our own defences.

Think of it like building a fortress. You need strong walls, good locks, and watchful guards. That is what defence is all about.

Let’s become defenders! 🏰🛡️


🎯 Learning Objectives

After this module, you will be able to:

  • Understand what makes a password strong.
  • Explain the importance of password policies.
  • Implement multi‑factor authentication (MFA).
  • Use John to test your own passwords.
  • Understand how hashing protects passwords.
  • Explain salting and why it is important.
  • Implement account lockout policies.
  • Educate others about password security.
  • Create a security awareness campaign.
  • Understand the role of encryption in defence.

📖 Warm‑up Story: The Fortress Upgrades

Kofi has helped many people secure their locks. But he realises that even the best locks can be broken if they are weak. He decides to build his own fortress and make it unbreakable.

He starts by using strong materials (like long, complex passwords). He adds multiple locks (multi‑factor authentication). He also tests his own fortress using John to see if there are any weaknesses.

He discovers that some of his locks are weak and replaces them. He also teaches his friends how to build strong fortresses. Now his fortress is safe, and so are his friends'.

That is what this module is about – building strong defences and testing them.

Let’s build our fortress! 🏗️🔒


📚 Main Lessons

Lesson 1: What Makes a Strong Password?

Definition: A strong password is long, complex, and unique.

Why it is important: It is very hard for John to crack.

Simple explanation: Like having a very long and complicated key.

Real‑life example: A password like “M1ch3al!23#” is strong.

School example: Your teacher tells you to use a password with letters, numbers, and symbols.

Home example: Your Wi‑Fi password should be strong.

Nigerian example: A bank requires a password with at least 12 characters.

Illustration (ASCII):

        Weak password: "ade"       → John cracks instantly
        Strong password: "Adeola@2024!Fun" → John takes years
    

Mini summary: Strong passwords are long, complex, and unique.


Lesson 2: Password Policies

Definition: Password policies are rules that guide how passwords are created and used.

Why it is important: They ensure that everyone uses strong passwords.

Simple explanation: Like school rules – they tell you what to do.

Real‑life example: A company requires passwords to be at least 12 characters long.

School example: Your school requires passwords with numbers and symbols.

Home example: Your family decides to use a password manager.

Nigerian example: A bank enforces a password policy for all staff.

Illustration (ASCII):

        Password Policy Example:
        + Minimum 12 characters
        + Must include uppercase, lowercase, number, symbol
        + Must be changed every 90 days
        + Cannot be the same as previous 5 passwords
    

Mini summary: Password policies enforce strong passwords.


Lesson 3: Multi‑Factor Authentication (MFA)

Definition: MFA requires more than one factor to log in – something you know (password), something you have (phone), or something you are (fingerprint).

Why it is important: Even if John cracks your password, the attacker still cannot log in without the second factor.

Simple explanation: Like having two locks on your door instead of one.

Real‑life example: You enter a password and then receive a code on your phone.

School example: You use a student ID card and a PIN.

Home example: You use your phone and a fingerprint.

Nigerian example: A bank sends an OTP (one‑time password) to your phone.

Illustration (ASCII):

        MFA Process:
        Step 1: Enter password (something you know)
        Step 2: Enter code from phone (something you have)
        Step 3: Scan fingerprint (something you are)
        Access granted!
    

Mini summary: MFA adds an extra layer of security.


Lesson 4: Salting – Adding Extra Protection

Definition: Salting is adding random data to a password before hashing it.

Why it is important: It makes it much harder for John to crack hashes.

Simple explanation: Like adding a secret spice to a recipe.

Real‑life example: A website adds a random string to each password before hashing.

School example: Your teacher gives each student a different test.

Home example: You add a secret ingredient to your meal.

Nigerian example: A bank uses salting to protect customer passwords.

Illustration (ASCII):

        Without salt:
        Password: "hello" → Hash: 5d41402abc...
        If two users have the same password, they have the same hash.

        With salt:
        Password: "hello" + Salt: "xyz123" → Hash: 7c6a180b...
        Even with the same password, hashes are different!
    

Mini summary: Salting makes hashes unique and harder to crack.


Lesson 5: Account Lockout Policies

Definition: Account lockout policies lock an account after too many failed login attempts.

Why it is important: It stops attackers from trying millions of passwords.

Simple explanation: Like a door that locks after too many wrong keys.

Real‑life example: An ATM locks your card after 3 wrong PIN attempts.

School example: The school computer locks after 5 wrong password attempts.

Home example: Your phone locks after 10 wrong attempts.

Nigerian example: A bank locks your online account after 3 wrong attempts.

Illustration (ASCII):

        Account Lockout Policy:
        3 failed attempts → Account locked for 30 minutes
        5 failed attempts → Account locked for 1 hour
        10 failed attempts → Account locked permanently (admin must unlock)
    

Mini summary: Lockout policies stop brute‑force attacks.


Lesson 6: Password Managers

Definition: A password manager is a tool that stores and generates strong passwords.

Why it is important: It helps you use different strong passwords for every account.

Simple explanation: Like a digital safe for your passwords.

Real‑life example: You use a password manager like LastPass or Bitwarden.

School example: Your teacher recommends a password manager.

Home example: Your family uses a password manager to store all passwords.

Nigerian example: A company provides password managers to employees.

Illustration (ASCII):

        Password Manager:
        + Stores all your passwords in one place
        + Generates strong, random passwords
        + You only need to remember one master password
        + Syncs across all your devices
    

Mini summary: Password managers make strong passwords easy.


Lesson 7: Using John to Test Your Own Defences

Definition: You can use John on your own hashes to test how strong your passwords are.

Why it is important: It helps you find weaknesses before attackers do.

Simple explanation: Like testing your own locks.

Real‑life example: A company uses John to audit employee passwords.

School example: A teacher uses John to test student passwords.

Home example: You use John to test your Wi‑Fi password.

Nigerian example: A bank uses John to test staff passwords.

Illustration (ASCII):

        Testing Your Own Defences:
        1. Collect your own hashes (with permission)
        2. Run John with wordlists and rules
        3. See which passwords are cracked
        4. Change weak passwords immediately
    

Mini summary: Use John to test and improve your own passwords.


Lesson 8: Educating Others About Password Security

Definition: Education means teaching people how to create and manage strong passwords.

Why it is important: Security is only as strong as the weakest link – and that is often people.

Simple explanation: Like teaching someone how to lock their door.

Real‑life example: A company trains employees on password security.

School example: Your teacher gives a lesson on password safety.

Home example: You teach your parents about strong passwords.

Nigerian example: A bank runs a security awareness campaign.

Illustration (ASCII):

        Security Awareness Campaign:
        + Posters about strong passwords
        + Workshops on password managers
        + Quizzes to test knowledge
        + Regular reminders to change passwords
    

Mini summary: Educating others is key to improving security.


Lesson 9: Encryption – Protecting Data

Definition: Encryption scrambles data so it can only be read with a key.

Why it is important: Even if John cracks a password, the data is still encrypted.

Simple explanation: Like putting a message in a locked box.

Real‑life example: Websites use HTTPS to encrypt data.

School example: Your school encrypts student records.

Home example: You encrypt your laptop’s hard drive.

Nigerian example: A bank encrypts customer data.

Illustration (ASCII):

        Encryption:
        Data: "Hello" → Encrypt → "X7h3K9mP2"
        Without key → gibberish
        With key → "Hello"
    

Mini summary: Encryption protects data even if passwords are cracked.


Lesson 10: Regular Security Audits

Definition: Regular audits mean testing security on a regular basis.

Why it is important: Security threats change over time.

Simple explanation: Like going to the doctor for a check‑up.

Real‑life example: A company does a security audit every quarter.

School example: Your school tests its network every year.

Home example: You test your home security every few months.

Nigerian example: A bank does regular security audits.

Illustration (ASCII):

        Regular Audit Schedule:
        + Monthly: Password audits with John
        + Quarterly: Full security assessment
        + Yearly: Independent external audit
    

Mini summary: Regular audits keep security strong.


Lesson 11: Incident Response

Definition: Incident response is the plan for what to do when a security breach occurs.

Why it is important: It helps you respond quickly and effectively.

Simple explanation: Like having a fire drill – you know what to do.

Real‑life example: A company has a plan for data breaches.

School example: A school has a plan for cyber attacks.

Home example: You have a plan for if your phone is stolen.

Nigerian example: A bank has a cyber incident response team.

Illustration (ASCII):

        Incident Response Plan:
        1. Identify the breach
        2. Contain the damage
        3. Investigate the cause
        4. Fix the vulnerability
        5. Notify affected parties
        6. Review and improve
    

Mini summary: Incident response prepares you for security breaches.


Lesson 12: The Human Factor – Social Engineering

Definition: Social engineering is tricking people into giving up passwords.

Why it is important: Even the strongest password can be stolen if someone is tricked.

Simple explanation: Like a con artist tricking you into giving them your keys.

Real‑life example: A hacker calls pretending to be IT support.

School example: Someone pretends to be a teacher to get students’ passwords.

Home example: A scammer calls asking for your bank details.

Nigerian example: A scammer sends a phishing email to bank customers.

Illustration (ASCII):

        Social Engineering Prevention:
        + Never give passwords to anyone
        + Verify the identity of callers
        + Don't click on suspicious links
        + Report suspicious activity
        + Use MFA to protect against stolen passwords
    

Mini summary: People are often the weakest link – educate and protect them.


Lesson 13: Zero Trust Security

Definition: Zero Trust means never trust anyone by default – always verify.

Why it is important: It reduces the risk of insider threats and breaches.

Simple explanation: Like always checking ID before letting someone in.

Real‑life example: A company requires MFA for all employees.

School example: A school verifies everyone entering the building.

Home example: You always ask who is at the door before opening it.

Nigerian example: A bank verifies every transaction with OTP.

Illustration (ASCII):

        Zero Trust Principles:
        1. Verify everyone (even employees)
        2. Limit access to only what is needed
        3. Assume breach – always be prepared
        4. Use MFA everywhere
        5. Monitor and audit regularly
    

Mini summary: Zero Trust makes security stronger.


Lesson 14: Security as a Culture

Definition: Security culture means making security a habit for everyone.

Why it is important: When everyone practices good security, it becomes natural.

Simple explanation: Like brushing your teeth – it becomes a habit.

Real‑life example: A company rewards employees who use strong passwords.

School example: A school teaches cybersecurity as part of the curriculum.

Home example: Your family discusses security at dinner.

Nigerian example: A bank has a security‑first culture.

Illustration (ASCII):

        Building a Security Culture:
        + Education and training
        + Reward good security habits
        + Lead by example
        + Make security easy and accessible
        + Encourage reporting of issues
    

Mini summary: Security culture makes everyone a defender.


Lesson 15: Becoming a Defender

Definition: A defender is someone who protects against cyber threats.

Why it is important: You are now a guardian of cybersecurity.

Simple explanation: Like a superhero who protects the digital world.

Real‑life example: You work as a security analyst.

School example: You help your school improve security.

Home example: You help your family stay safe online.

Nigerian example: You help Nigerian businesses stay secure.

Illustration (ASCII):

        You are a Defender!
        + Know how to use John for good
        + Understand strong passwords
        + Promote security awareness
        + Test and improve defences
        + Protect people and data
    

Mini summary: You are now a defender of cybersecurity!


📝 Key Vocabulary

  • Strong password: Long, complex, and unique.
  • Password policy: Rules for creating passwords.
  • Multi‑factor authentication (MFA): Using more than one factor to log in.
  • Salting: Adding random data to a password before hashing.
  • Account lockout: Locking an account after failed attempts.
  • Password manager: Tool to store and generate passwords.
  • Encryption: Scrambling data so it cannot be read.
  • Audit: A review of security.
  • Incident response: A plan for responding to breaches.
  • Zero Trust: Never trust, always verify.

🧠 Important Concepts

  • Strong passwords are essential for security.
  • Password policies enforce strong passwords.
  • MFA adds an extra layer of protection.
  • Salting makes hashes harder to crack.
  • Account lockout stops brute‑force attacks.
  • Password managers make strong passwords easy.
  • Use John to test your own defences.
  • Education is key to security.
  • Encryption protects data.
  • Regular audits keep security strong.

📋 Step‑by‑Step: Testing Your Own Defences with John

  1. Collect your hashes: Get hashes from your own system (with permission).
  2. Run John: Use John with wordlists and rules.
  3. Analyse results: See which passwords were cracked.
  4. Change weak passwords: Immediately change any weak passwords.
  5. Implement policies: Enforce stronger password policies.
  6. Educate others: Share what you learned with others.
  7. Repeat: Test regularly to stay secure.

Illustration (flowchart):

        Start
          |
          v
        Collect hashes
          |
          v
        Run John
          |
          v
        Analyse results
          |
          v
        Change weak passwords
          |
          v
        Implement policies
          |
          v
        Educate others
          |
          v
        Repeat regularly
          |
          v
        End
    

🌍 Real‑life Examples

  • A company uses John to audit employee passwords and then enforces a new password policy.
  • A school implements MFA for all student accounts.
  • A hospital uses encryption to protect patient records.
  • A bank conducts regular security audits and tests with John.
  • A government agency educates citizens about password security.

🇳🇬 Nigerian Examples

  • A Lagos bank uses John to test staff passwords and enforces MFA.
  • An Abuja school teaches students about password security.
  • A Port Harcourt company implements account lockout policies.
  • A Nigerian fintech uses salting to protect customer passwords.
  • A Nigerian government agency conducts regular security audits.

🧸 Fun Examples for Kids

  • Imagine your password is a secret code. The longer and more complex, the better.
  • MFA is like having two secret doors – you need both keys to enter.
  • Salting is like adding a secret ingredient to your password recipe.
  • Account lockout is like a door that locks after too many wrong keys.
  • A password manager is like a robot that remembers all your secrets.

🏠 Everyday Examples

  • You use a strong password for your email.
  • You enable MFA on your phone.
  • You use a password manager for all your accounts.
  • You test your Wi‑Fi password with John.
  • You teach your parents about strong passwords.

🧑‍🏫 Teacher Notes

  • Emphasise that defence is as important as offence.
  • Use real‑world examples to illustrate concepts.
  • Encourage students to test their own passwords.
  • Discuss the importance of education and culture.
  • Use Nigerian examples to make it relatable.

👪 Parent Tips

  • Discuss password security as a family.
  • Encourage everyone to use a password manager.
  • Help your child understand the importance of MFA.
  • Lead by example – use strong passwords yourself.
  • Support your child’s interest in cybersecurity.

🤯 Interesting Facts

  • The most common password is still “123456”.
  • Using a password manager makes you 100 times more secure.
  • MFA can stop 99% of all attacks.
  • Salting was invented in the 1970s.
  • Account lockout was first used in the 1980s.
  • Encryption has been used for thousands of years.

💡 Did You Know?

  • Did you know that you can use John to test your own passwords?
  • Did you know that many companies require MFA now?
  • Did you know that salting is used by most modern websites?
  • Did you know that password managers are recommended by experts?
  • Did you know that education is the best defence against social engineering?

🔔 Remember This

  • Strong passwords are long, complex, and unique.
  • Password policies enforce strong passwords.
  • MFA adds an extra layer of protection.
  • Salting makes hashes harder to crack.
  • Account lockout stops brute‑force attacks.
  • Password managers make strong passwords easy.
  • Use John to test your own defences.
  • Education and culture are key to security.

❌ Common Mistakes

  • Mistake: Using simple passwords.
    Fix: Use long, complex passwords.
  • Mistake: Not using MFA.
    Fix: Enable MFA on all accounts.
  • Mistake: Reusing passwords.
    Fix: Use a password manager.
  • Mistake: Not testing defences.
    Fix: Use John to test your passwords.
  • Mistake: Ignoring social engineering.
    Fix: Educate yourself and others.

✅ Best Practices

  • Use strong, unique passwords for every account.
  • Enable MFA wherever possible.
  • Use a password manager.
  • Test your own passwords with John.
  • Educate others about password security.
  • Conduct regular security audits.
  • Create a security‑first culture.

📊 Diagrams & Tables

Timeline: Evolution of Password Security

        1970s  ── First passwords used
        1980s  ── Account lockout introduced
        1990s  ── Salting invented
        2000s  ── Password policies become common
        2010s  ── MFA becomes popular
        2020s  ── Password managers and Zero Trust
    

Comparison Table: Strong vs Weak Passwords

Feature Weak Password Strong Password
Length Short (<8 characters) Long (≥12 characters)
Complexity Only letters Letters, numbers, symbols
Uniqueness Used for many accounts Unique for each account
Crack time Seconds to minutes Years to centuries

ASCII Flowchart: How to Defend Against John

        Start
          |
          v
        Use strong passwords
          |
          v
        Enable MFA
          |
          v
        Use salting
          |
          v
        Implement lockout
          |
          v
        Use password manager
          |
          v
        Test with John
          |
          v
        Educate others
          |
          v
        End
    

Comparison Table: Defence Tools

Tool Purpose Example
Password manager Store and generate passwords Bitwarden, LastPass
MFA app Generate one‑time codes Google Authenticator
Encryption Protect data AES‑256
Audit tool Test security John the Ripper
Education Raise awareness Training sessions



📌 Module 6 Summary

Fantastic work! You have completed the sixth module. Here is what we learned:

  • What makes a password strong.
  • The importance of password policies.
  • How MFA adds extra protection.
  • How salting makes hashes harder to crack.
  • Account lockout policies.
  • Using password managers.
  • Testing your own defences with John.
  • Educating others about password security.
  • The role of encryption and audits.
  • Building a security culture.

You are now a defender of cybersecurity! In the final module, we will review everything and prepare you for the certification exam.


❓ Frequently Asked Questions

  1. Q: What is a strong password?
    A: Long, complex, and unique.
  2. Q: What is MFA?
    A: Using more than one factor to log in.
  3. Q: What is salting?
    A: Adding random data to a password before hashing.
  4. Q: What is account lockout?
    A: Locking an account after failed attempts.
  5. Q: What is a password manager?
    A> A tool to store and generate passwords.
  6. Q: Why should I test my own passwords?
    A: To find weaknesses before attackers do.
  7. Q: What is encryption?
    A: Scrambling data to protect it.
  8. Q: What is a security audit?
    A: A review of security.
  9. Q: What is incident response?
    A: A plan for responding to breaches.
  10. Q: What is Zero Trust?
    A: Never trust, always verify.

📝 Review Questions

  1. What makes a password strong?
  2. Why are password policies important?
  3. What is MFA?
  4. What is salting?
  5. What is account lockout?
  6. What is a password manager?
  7. Why should you test your own passwords?
  8. What is encryption?
  9. What is a security audit?
  10. What is incident response?
  11. What is Zero Trust?
  12. Why is education important?
  13. What is social engineering?
  14. How can you build a security culture?
  15. What is the role of a defender?

✍️ Fill‑in‑the‑Blank

  1. A ________ password is long, complex, and unique.
  2. ________ policies enforce strong passwords.
  3. ________ adds an extra layer of protection.
  4. ________ adds random data to a password before hashing.
  5. ________ lockout stops brute‑force attacks.
  6. ________ managers store and generate strong passwords.
  7. Use John to test your own ________.
  8. ________ scrambles data to protect it.
  9. A ________ is a review of security.
  10. ________ response is a plan for breaches.

✅ True or False

  1. Strong passwords are short. (False)
  2. MFA adds an extra layer of protection. (True)
  3. Salting makes hashes easier to crack. (False)
  4. Account lockout stops brute‑force attacks. (True)
  5. Password managers are not useful. (False)
  6. You should test your own passwords. (True)
  7. Encryption protects data. (True)
  8. Security audits are not important. (False)
  9. Incident response is only for large companies. (False)
  10. Zero Trust means trusting everyone. (False)

🔢 Multiple Choice

  1. What makes a strong password?
    a) Short and simple
    b) Long, complex, unique
    c) Easy to remember
    Answer: b
  2. What is MFA?
    a) More than one factor to log in
    b) A password manager
    c) A type of encryption
    Answer: a
  3. What is salting?
    a) Adding random data to a password
    b) Adding salt to food
    c) A type of password
    Answer: a
  4. What is account lockout?
    a) Locking an account after failed attempts
    b) Unlocking an account
    c) Changing a password
    Answer: a
  5. What is a password manager?
    a) A tool to store passwords
    b) A person who manages passwords
    c) A type of lock
    Answer: a
  6. Why should you test your own passwords?
    a) To find weaknesses
    b) To waste time
    c) To show off
    Answer: a
  7. What is encryption?
    a) Scrambling data
    b) Deleting data
    c) Copying data
    Answer: a
  8. What is a security audit?
    a) A review of security
    b) A type of password
    c) A tool
    Answer: a
  9. What is incident response?
    a) A plan for breaches
    b) A type of attack
    c) A password
    Answer: a
  10. What is Zero Trust?
    a) Never trust, always verify
    b) Trust everyone
    c) Trust no one
    Answer: a
  11. Why is education important?
    a) It raises awareness
    b) It is not important
    c) It makes things harder
    Answer: a
  12. What is social engineering?
    a) Tricking people into giving up passwords
    b) A type of software
    c) A password
    Answer: a
  13. How can you build a security culture?
    a) By educating and rewarding good behaviour
    b) By ignoring security
    c) By using weak passwords
    Answer: a
  14. What is the role of a defender?
    a) To protect against threats
    b) To create threats
    c) To ignore threats
    Answer: a
  15. What is the best defence against social engineering?
    a) Education
    b) Strong passwords
    c) Encryption
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Strong password A. Adds random data to a password
2. MFA B. Long, complex, unique
3. Salting C. More than one factor to log in
4. Password manager D. Tool to store passwords
5. Encryption E. Scrambling data

Answers: 1‑B, 2‑C, 3‑A, 4‑D, 5‑E


📝 Short Answer

  1. What are the characteristics of a strong password?
  2. Why is MFA important?
  3. What is salting and how does it help?
  4. How can you test your own passwords?
  5. What are the key components of a security culture?

🎭 Scenario‑based Exercises

Scenario 1: A company has many employees who use weak passwords like “password” and “123456”.

  • What should the company do? (Implement a password policy and use John to test passwords.)
  • What are some recommendations? (Enforce stronger passwords, use MFA, educate employees.)

Scenario 2: A bank customer receives a call from someone claiming to be IT support asking for their password.

  • What should the customer do? (Never give out passwords, verify the caller’s identity.)
  • What is this type of attack called? (Social engineering.)

👥 Group Activity

Activity: In groups, design a security awareness campaign for a mock company. Include posters, tips, and a plan for educating employees about strong passwords.


🧑 Individual Activity

Activity: Create a list of 10 strong passwords and explain why they are strong. Then, test them with John (if possible) to see how long they would take to crack.


💬 Classroom Discussion Questions

  1. Why do people still use weak passwords?
  2. How can we encourage others to use strong passwords?
  3. What are the challenges of implementing MFA?
  4. How can Nigerian organisations improve password security?
  5. What is the future of password security?

🛠️ Mini Project

Project: Conduct a password audit for a mock organisation. Use John to test passwords, write a report with findings, and recommend improvements.


📋 Practical Assignment

Assignment: Using John, test a set of sample passwords provided by your teacher. Write a report on which passwords are weak and how they can be improved.


🏆 Challenge Exercise

Challenge: Create a password policy for a Nigerian bank. Include requirements for length, complexity, MFA, and account lockout. Then, test the policy by creating sample passwords and running John on them.


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • Strong passwords are essential for security.
  • Password policies enforce strong passwords.
  • MFA adds an extra layer of protection.
  • Salting makes hashes harder to crack.
  • Account lockout stops brute‑force attacks.
  • Password managers make strong passwords easy.
  • Use John to test your own defences.
  • Education is key to security.
  • Encryption protects data.
  • Regular audits keep security strong.

🔜 Preparation for Module 7

In Module 7, we will review everything we have learned. We will also take a practice exam and prepare for the certification exam. You are almost a Certified John Ripper User!

Make sure you have completed all exercises and have a good understanding of all modules. See you in Module 7! 🎓


End of Module 6

9

Module Seven

Module 7 · Certified John Ripper User

🎓 Module 7: Review, Practice, and Certification

Hello, graduating hero! 👋

You have made it to the final module! You have learned everything from installing John to defending against password attacks. Now it is time to review everything and prepare for your certification.

This module is like a big revision session before a final exam. We will go over all the important points from previous modules. We will also do lots of practice questions and exercises.

By the end of this module, you will be ready to take the Certified John Ripper User exam and become a certified expert!

Let’s review and prepare! 📚💪


🎯 Learning Objectives

After this module, you will be able to:

  • Review all key concepts from Modules 1 to 6.
  • Understand the certification process.
  • Practice with sample exam questions.
  • Identify your strengths and weaknesses.
  • Get tips for the exam day.
  • Create a study plan.
  • Build confidence in using John.
  • Understand real‑world applications.
  • Be ready for the certification exam.
  • Become a Certified John Ripper User!

📖 Warm‑up Story: The Final Test

Kofi has learned everything about locks and keys. He has helped many people and built strong fortresses. Now it is time for his final test – the Grand Master Key‑Maker Exam.

He reviews all his notes, practises with his tools, and helps his friends prepare too. On the exam day, he is calm and confident. He answers every question and completes every task.

At the end, he is awarded the title of Grand Master Key‑Maker. He is proud and ready to help even more people.

That is exactly where you are now – at the final step before becoming a Certified John Ripper User.

Let’s get ready for your final test! 🏆


📚 Main Lessons

Lesson 1: Module 1 Review – Introduction to John

Definition: John the Ripper is a tool that tests password strength.

Why it is important: It helps find weak passwords.

Simple explanation: John tries to guess passwords to see if they are weak.

Real‑life example: Security experts use John to test company passwords.

School example: Teachers use John to show why strong passwords are important.

Home example: You use John to test your Wi‑Fi password.

Nigerian example: Banks use John to test staff passwords.

Illustration (ASCII):

        John the Ripper
        +------------------+
        | Password tester  |
        | Uses wordlists   |
        | Uses rules       |
        | Cracks hashes    |
        +------------------+
    

Mini summary: John is a password testing tool used by good people to find weaknesses.


Lesson 2: Module 2 Review – Installation and First Run

Definition: Installation is putting John on your computer.

Why it is important: You need to install John before you can use it.

Simple explanation: Like putting a game on your console.

Real‑life example: Installing a new app on your phone.

School example: Installing software on a school computer.

Home example: Installing a new program on your laptop.

Nigerian example: Installing banking software.

Illustration (ASCII):

        Installation Steps:
        1. Download from openwall.com
        2. Extract files
        3. Open terminal
        4. Run john
    

Mini summary: You install John and run it from the terminal.


Lesson 3: Module 3 Review – Wordlists and Rules

Definition: Wordlists are lists of passwords. Rules change words to create new guesses.

Why it is important: They make John smarter and faster.

Simple explanation: Wordlists are like a dictionary, and rules are like a magic wand.

Real‑life example: A list of common passwords.

School example: A list of vocabulary words.

Home example: A grocery list.

Nigerian example: A list of Nigerian names.

Illustration (ASCII):

        Wordlist: [chidi, bola, ade]
        Rules: add 1, uppercase, substitute i→!
        John tries: chidi, Chidi, chidi1, ch!d!, ...
    

Mini summary: Wordlists and rules make John powerful.


Lesson 4: Module 4 Review – Advanced Cracking

Definition: Advanced cracking includes using sessions, GPUs, and cracking different file types.

Why it is important: It makes John faster and more versatile.

Simple explanation: Like upgrading from a bicycle to a car.

Real‑life example: Using a fast computer to crack passwords.

School example: Using a powerful server.

Home example: Using a gaming PC.

Nigerian example: Using a high‑performance bank server.

Illustration (ASCII):

        Advanced Features:
        + Sessions (save progress)
        + GPU (fast cracking)
        + --fork (multiple cores)
        + ZIP, PDF, RAR cracking
    

Mini summary: Advanced features make John faster and more powerful.


Lesson 5: Module 5 Review – Penetration Testing

Definition: Penetration testing is testing systems to find vulnerabilities.

Why it is important: It helps organisations fix weaknesses.

Simple explanation: Like testing a fortress to see if it is secure.

Real‑life example: A company hires a pen tester.

School example: A teacher tests student passwords.

Home example: You test your home security.

Nigerian example: A bank conducts a security audit.

Illustration (ASCII):

        Pen Testing Process:
        Plan → Gather hashes → Run John → Report → Fix
    

Mini summary: Pen testing helps find and fix security issues.


Lesson 6: Module 6 Review – Defensive Measures

Definition: Defensive measures are steps to protect against attacks.

Why it is important: They keep data safe.

Simple explanation: Like building strong walls and doors.

Real‑life example: Using MFA and strong passwords.

School example: Implementing password policies.

Home example: Using a password manager.

Nigerian example: A bank using encryption.

Illustration (ASCII):

        Defensive Measures:
        + Strong passwords
        + MFA
        + Salting
        + Account lockout
        + Password manager
        + Education
    

Mini summary: Defensive measures protect against password attacks.


Lesson 7: Certification Overview

Definition: Certification is proof that you have the skills to use John properly.

Why it is important: It shows employers and others that you are qualified.

Simple explanation: Like a driver’s license.

Real‑life example: A cybersecurity job requires certification.

School example: A certificate after a course.

Home example: A merit badge.

Nigerian example: A professional certification.

Illustration (ASCII):

        Certification Process:
        1. Complete all modules
        2. Pass the practice exam
        3. Take the final exam
        4. Receive your certificate
        5. Celebrate! 🎉
    

Mini summary: Certification proves your skills.


Lesson 8: Exam Tips and Strategies

Definition: Exam tips are suggestions to help you do well on the test.

Why it is important: They help you be calm and confident.

Simple explanation: Like tips for a spelling bee.

Real‑life example: Getting a good night’s sleep before the exam.

School example: Studying with friends.

Home example: Having a healthy breakfast.

Nigerian example: Arriving early for the exam.

Illustration (ASCII):

        Exam Tips:
        + Get good sleep
        + Eat a healthy meal
        + Review your notes
        + Stay calm and focused
        + Read each question carefully
        + Manage your time
    

Mini summary: Good preparation and tips help you succeed.


Lesson 9: Practice Questions Overview

Definition: Practice questions are sample questions that test your knowledge.

Why it is important: They help you prepare for the real exam.

Simple explanation: Like a mock test.

Real‑life example: A driver’s ed practice test.

School example: Practice quizzes.

Home example: Practice problems.

Nigerian example: Practice exams for professional certifications.

Illustration (ASCII):

        Practice Question Types:
        + Multiple choice
        + True or False
        + Fill‑in‑the‑blank
        + Short answer
        + Scenario‑based
    

Mini summary: Practice questions help you prepare.


Lesson 10: Real‑World Scenarios Review

Definition: Real‑world scenarios are situations you might encounter in your career.

Why it is important: They show how John is used in practice.

Simple explanation: Like a story about a real problem.

Real‑life example: A company with weak passwords.

School example: A school with a security breach.

Home example: A family with a compromised Wi‑Fi.

Nigerian example: A bank with a password policy violation.

Illustration (ASCII):

        Scenario: Bank Password Audit
        1. Collect hashes from staff
        2. Run John with wordlists and rules
        3. Find weak passwords
        4. Report findings
        5. Implement new policies
    

Mini summary: Real‑world scenarios prepare you for the job.


Lesson 11: Building Your Study Plan

Definition: A study plan is a schedule for reviewing material.

Why it is important: It helps you cover everything and avoid last‑minute stress.

Simple explanation: Like a to‑do list for studying.

Real‑life example: A student planning study time.

School example: A teacher giving a syllabus.

Home example: A family planning activities.

Nigerian example: A professional planning for certification.

Illustration (ASCII):

        Study Plan Example:
        Day 1: Review Modules 1-2
        Day 2: Review Modules 3-4
        Day 3: Review Modules 5-6
        Day 4: Practice questions
        Day 5: Rest and relax
        Day 6: Final review
        Day 7: Exam day!
    

Mini summary: A study plan helps you prepare effectively.


Lesson 12: Staying Updated in Cybersecurity

Definition: Staying updated means keeping up with new developments in security.

Why it is important: Technology changes, and we need to stay current.

Simple explanation: Like reading the news.

Real‑life example: Following cybersecurity blogs.

School example: Taking new courses.

Home example: Learning about new devices.

Nigerian example: Staying informed about security in Nigeria.

Illustration (ASCII):

        Ways to Stay Updated:
        + Read security blogs
        + Follow experts on social media
        + Take additional courses
        + Attend conferences
        + Join online communities
    

Mini summary: Continuous learning is important in cybersecurity.


Lesson 13: Your Journey as a Certified Professional

Definition: A certified professional is someone who has proven their skills.

Why it is important: It opens doors to new opportunities.

Simple explanation: Like being a recognised expert.

Real‑life example: Working as a security analyst.

School example: Being a top student.

Home example: Being the family tech expert.

Nigerian example: Being a certified cybersecurity specialist in Nigeria.

Illustration (ASCII):

        Your Journey:
        Learn → Practice → Certify → Work → Help others
    

Mini summary: You are on your way to a great career!


Lesson 14: The Bigger Picture – Cybersecurity

Definition: Cybersecurity is protecting systems, networks, and data.

Why it is important: It keeps everyone safe online.

Simple explanation: Like a digital police force.

Real‑life example: Protecting online banking.

School example: Keeping student data safe.

Home example: Protecting your family’s information.

Nigerian example: Protecting Nigeria’s digital economy.

Illustration (ASCII):

        Cybersecurity Domains:
        + Network security
        + Application security
        + Data security
        + Cloud security
        + Password security (John!)
    

Mini summary: Cybersecurity is a broad and important field.


Lesson 15: You Are Ready!

Definition: You are ready means you have all the skills and knowledge.

Why it is important: You can now become a Certified John Ripper User!

Simple explanation: Like finishing a race.

Real‑life example: You are prepared for the exam.

School example: You are ready to graduate.

Home example: You are ready to help your family.

Nigerian example: You are ready to work in cybersecurity.

Illustration (ASCII):

        🎉 YOU ARE READY! 🎉
        + Knowledge of John
        + Skills in cracking and defence
        + Confidence and determination
        + Ready for the exam!
    

Mini summary: You are ready to become certified!


📝 Key Vocabulary

  • Certification: Proof of skill.
  • Exam: A test of knowledge.
  • Practice: Doing something to improve.
  • Review: Going over material again.
  • Study plan: A schedule for learning.
  • Cybersecurity: Protecting systems and data.
  • Professional: Someone with skills and certification.
  • Career: A job in a specific field.
  • Confidence: Belief in your abilities.
  • Success: Achieving a goal.

🧠 Important Concepts

  • Reviewing all modules is essential for exam preparation.
  • Certification proves your skills.
  • Practice questions help you prepare.
  • Exam tips can help you succeed.
  • A study plan keeps you on track.
  • Cybersecurity is a growing field.
  • You are now ready for the exam.

📋 Step‑by‑Step: Preparing for the Certification Exam

  1. Review all modules: Go through Modules 1 to 6 again.
  2. Create a study plan: Schedule time each day to review.
  3. Practise with questions: Use the review questions in each module.
  4. Take practice exams: Simulate the real exam environment.
  5. Identify weak areas: Focus on topics you find difficult.
  6. Rest and relax: Take breaks and stay healthy.
  7. Take the exam: Be confident and do your best!

Illustration (flowchart):

        Start
          |
          v
        Review all modules
          |
          v
        Create study plan
          |
          v
        Practise questions
          |
          v
        Take practice exams
          |
          v
        Identify weak areas
          |
          v
        Rest and relax
          |
          v
        Take the exam
          |
          v
        Become certified! 🎉
    

🌍 Real‑life Examples

  • A student reviews all modules and passes the exam.
  • An employee uses the certification to get a promotion.
  • A job applicant includes the certification on their CV.
  • A company requires the certification for security staff.
  • A freelancer uses the certification to attract clients.

🇳🇬 Nigerian Examples

  • A Nigerian student prepares for the exam and becomes certified.
  • A Lagos company hires certified professionals for security.
  • An Abuja government agency requires certification for staff.
  • A Port Harcourt oil company uses certified experts.
  • A Nigerian fintech values the certification.

🧸 Fun Examples for Kids

  • Imagine preparing for a big spelling bee.
  • Reviewing is like practising your spelling words.
  • The exam is like the big spelling bee.
  • Certification is like a trophy.
  • You are now a champion!

🏠 Everyday Examples

  • You review your notes before a test.
  • You practise driving before a test.
  • You prepare a meal before serving it.
  • You clean your room before guests arrive.
  • You plan a trip before travelling.

🧑‍🏫 Teacher Notes

  • Emphasise the importance of review.
  • Encourage students to create study plans.
  • Provide additional practice materials.
  • Simulate the exam environment.
  • Boost students' confidence.
  • Celebrate their achievements.

👪 Parent Tips

  • Support your child's study plan.
  • Create a quiet study space.
  • Encourage regular breaks.
  • Celebrate their progress.
  • Be proud of their achievements.

🤯 Interesting Facts

  • Certification exams often have a high pass rate for prepared students.
  • Many companies look for certified professionals.
  • Cybersecurity is one of the fastest‑growing fields.
  • John the Ripper is used worldwide.
  • There are many different cybersecurity certifications.
  • Continuous learning is key in cybersecurity.

💡 Did You Know?

  • Did you know that the certification exam covers all six modules?
  • Did you know that practice exams can help you pass?
  • Did you know that many people fail the first time and retake it?
  • Did you know that certification is valid for two years?
  • Did you know that you can recertify by taking a new exam?

🔔 Remember This

  • Review all modules before the exam.
  • Create a study plan and stick to it.
  • Practise with questions and exams.
  • Stay calm and confident.
  • You have the skills and knowledge to pass.
  • You are ready to become certified!

❌ Common Mistakes

  • Mistake: Not reviewing enough.
    Fix: Set a study schedule.
  • Mistake: Cramming at the last minute.
    Fix: Spread out your study sessions.
  • Mistake: Not practising enough.
    Fix: Do all practice questions.
  • Mistake: Getting stressed.
    Fix: Take breaks and stay calm.
  • Mistake: Rushing through the exam.
    Fix: Read each question carefully.

✅ Best Practices

  • Create a study plan and follow it.
  • Take practice exams in a timed environment.
  • Review your mistakes and learn from them.
  • Get plenty of rest before the exam.
  • Eat a healthy breakfast on exam day.
  • Stay positive and confident.

📊 Diagrams & Tables

Timeline: Your Certification Journey

        Week 1  ── Review Module 1
        Week 2  ── Review Module 2
        Week 3  ── Review Module 3
        Week 4  ── Review Module 4
        Week 5  ── Review Module 5
        Week 6  ── Review Module 6
        Week 7  ── Practice exams
        Week 8  ── Final review and exam
    

Comparison Table: Study Methods

Method Pros Cons
Self‑study Flexible, at your own pace Requires discipline
Group study Support, discussion Can be distracting
Practice exams Realistic preparation Can be stressful
Online courses Structured learning May cost money

ASCII Flowchart: Certification Process

        Start
          |
          v
        Complete all modules
          |
          v
        Create study plan
          |
          v
        Practice questions
          |
          v
        Take practice exams
          |
          v
        Feel confident?
          |          |
          Yes        No
          |          |
          v          v
        Take exam   Review more
          |          |
          v          |
        Pass?        |
          |          |
          Yes        |
          |          v
          v        Continue
        Certify!    practice
          |
          v
        End
    

Comparison Table: Certification Benefits

Benefit Description
Career advancement Better job opportunities
Credibility Proves your skills
Knowledge You are an expert
Network Connect with others
Confidence You know what you are doing



📌 Module 7 Summary

Congratulations! You have completed the final module. Here is what we reviewed:

  • All key concepts from Modules 1 to 6.
  • The certification process and what to expect.
  • Tips and strategies for the exam.
  • Practice questions to test your knowledge.
  • Real‑world scenarios and applications.
  • How to create a study plan.
  • The importance of staying updated.
  • Your journey as a certified professional.

You are now ready to take the Certified John Ripper User exam. Go ahead and take it – you have all the skills and knowledge you need!


❓ Frequently Asked Questions

  1. Q: How do I take the exam?
    A: The exam is usually taken online or at a testing centre.
  2. Q: How long is the exam?
    A: Typically 1-2 hours.
  3. Q: What score do I need to pass?
    A: Usually 70% or higher.
  4. Q: Can I retake the exam if I fail?
    A: Yes, you can retake it.
  5. Q: How much does the exam cost?
    A> Costs vary – check the official website.
  6. Q: What if I have technical issues?
    A: Contact the exam provider.
  7. Q: How do I get my certificate?
    A: It is usually emailed or mailed to you.
  8. Q: Is the certification valid forever?
    A: Typically 2-3 years, then you need to recertify.
  9. Q: Can I put the certification on my CV?
    A: Yes, it is valuable.
  10. Q: What should I do after certification?
    A: Keep learning and practising!

📝 Review Questions

  1. What is John the Ripper?
  2. How do you install John?
  3. What are wordlists and rules?
  4. What are sessions and why are they useful?
  5. What is penetration testing?
  6. What are defensive measures?
  7. What is MFA?
  8. What is salting?
  9. What is account lockout?
  10. What is a password manager?
  11. Why is education important?
  12. What is the certification process?
  13. What are some exam tips?
  14. Why is staying updated important?
  15. What is your journey as a certified professional?

✍️ Fill‑in‑the‑Blank

  1. ________ the Ripper is a password testing tool.
  2. ________ lists are lists of passwords.
  3. ________ change words to create new guesses.
  4. ________ save John’s progress.
  5. ________ testing is testing systems for vulnerabilities.
  6. ________ measures protect against attacks.
  7. ________ adds an extra layer of protection.
  8. ________ managers store and generate passwords.
  9. ________ is proof of your skills.
  10. ________ are tips to help you succeed on the exam.

✅ True or False

  1. John the Ripper is a game. (False)
  2. Wordlists are useful for John. (True)
  3. Rules make John smarter. (True)
  4. Sessions are not important. (False)
  5. Penetration testing is illegal. (False)
  6. Defensive measures are not needed. (False)
  7. MFA adds extra protection. (True)
  8. Salting makes hashes harder to crack. (True)
  9. Account lockout stops brute‑force attacks. (True)
  10. Certification is not valuable. (False)

🔢 Multiple Choice

  1. What is John the Ripper?
    a) A password testing tool
    b) A video game
    c) A food
    Answer: a
  2. What are wordlists?
    a) Lists of passwords
    b) Lists of food
    c) Lists of games
    Answer: a
  3. What do rules do?
    a) Change words
    b) Delete words
    c) Copy words
    Answer: a
  4. What is a session?
    a) A saved state of John's work
    b) A type of password
    c) A wordlist
    Answer: a
  5. What is penetration testing?
    a) Testing systems for vulnerabilities
    b) Breaking into systems illegally
    c) Testing food
    Answer: a
  6. What is MFA?
    a) Multi‑factor authentication
    b) Multiple food items
    c) Many friends
    Answer: a
  7. What is salting?
    a) Adding random data to a password
    b) Adding salt to food
    c) A type of password
    Answer: a
  8. What is account lockout?
    a) Locking an account after failed attempts
    b) Unlocking an account
    c) Changing a password
    Answer: a
  9. What is a password manager?
    a) A tool to store passwords
    b) A person who manages passwords
    c) A type of lock
    Answer: a
  10. What is certification?
    a) Proof of skill
    b) A type of password
    c) A tool
    Answer: a
  11. Why is education important?
    a) It raises awareness
    b) It is not important
    c) It makes things harder
    Answer: a
  12. What is a study plan?
    a) A schedule for studying
    b) A type of password
    c) A tool
    Answer: a
  13. Why should you stay updated?
    a) Technology changes
    b) It is not needed
    c) It is boring
    Answer: a
  14. What is the benefit of certification?
    a) Career advancement
    b) It is not useful
    c) It is a game
    Answer: a
  15. What should you do on exam day?
    a) Stay calm and focused
    b) Panic
    c) Rush
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. John the Ripper A. A schedule for studying
2. Wordlist B. A list of passwords
3. Rule C. Changes a word
4. Session D. Saves John's progress
5. Study plan E. A password testing tool

Answers: 1‑E, 2‑B, 3‑C, 4‑D, 5‑A


📝 Short Answer

  1. What is John the Ripper and how does it work?
  2. What are wordlists and rules, and why are they important?
  3. What is penetration testing and how does John fit in?
  4. What are some defensive measures against password attacks?
  5. How can you prepare for the certification exam?

🎭 Scenario‑based Exercises

Scenario 1: You are preparing for the certification exam. You have one week left.

  • What should you do? (Create a study plan, review notes, take practice exams.)
  • How should you manage your time? (Focus on weak areas, take breaks.)

Scenario 2: You have aced the exam and are now certified!

  • What are your next steps? (Update your CV, apply for jobs, continue learning.)
  • How can you use your certification? (Get a job, help others, teach.)

👥 Group Activity

Activity: In groups, create a study plan for the certification exam. Share tips and strategies, and help each other prepare.


🧑 Individual Activity

Activity: Create a one‑page summary of all the key points from Modules 1 to 6. Use it as a quick reference for the exam.


💬 Classroom Discussion Questions

  1. What was the most challenging part of this course?
  2. What are you most confident about?
  3. How will you use your certification?
  4. What are the next steps in your career?
  5. How can you help others with your skills?

🛠️ Mini Project

Project: Create a portfolio of your work with John. Include sample commands, screenshots, and a description of what you have learned. This will be a great addition to your CV.


📋 Practical Assignment

Assignment: Complete a final practical exercise where you crack a test hash, write a report, and present your findings. This simulates a real‑world task.


🏆 Challenge Exercise

Challenge: Create a comprehensive security plan for a mock organisation. Include password policies, MFA, incident response, and a schedule for testing with John.


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • You have completed all seven modules!
  • You have learned everything about John the Ripper.
  • You are ready for the certification exam.
  • You have the skills to be a cybersecurity professional.
  • You can help protect people and organisations.
  • You are now a Certified John Ripper User!

🔜 What’s Next?

Congratulations! You have completed the Certified John Ripper User course. You are now ready to take the certification exam.

After you become certified, you can continue your journey with advanced courses in cybersecurity, ethical hacking, and penetration testing. Keep learning and growing!

Thank you for being part of this course. You are now a guardian of cybersecurity. Go out there and make the world a safer place! 🚀


End of Module 7 – The End of the Course

10

Module Eight

Module 8 · Certified John Ripper User

🚀 Module 8: Beyond Certification – Advanced Career Paths

Hello, certified hero! 👋

You have done it! You are now a Certified John Ripper User. But your journey does not end here. In fact, it is just the beginning.

This module is about what comes next. We will explore advanced career paths in cybersecurity, how to keep learning, and how to use your skills to make a real difference.

Think of this as the "what's next" chapter. You have the key – now let's see all the doors it can open.

Let's explore the future! 🔮


🎯 Learning Objectives

After this module, you will be able to:

  • Understand advanced career paths in cybersecurity.
  • Explore specialised roles like penetration tester, security analyst, and consultant.
  • Know how to keep learning and stay updated.
  • Understand the value of your certification.
  • Learn about other relevant certifications.
  • Explore entrepreneurship opportunities.
  • Understand the global cybersecurity landscape.
  • Find mentorship and networking opportunities.
  • Build a personal brand.
  • Make a positive impact on the world.

📖 Warm‑up Story: The Grand Journey

Kofi has become the Grand Master Key‑Maker. But he does not stop. He realises that there are many more locks to master – digital locks, network locks, cloud locks.

He decides to explore new lands. He meets other experts, learns new techniques, and even starts teaching others. He becomes a leader in the world of cybersecurity.

His journey shows that certification is not the end – it is the beginning of a grand adventure.

Now it is your turn to start your grand adventure!

Let's go! 🌍


📚 Main Lessons

Lesson 1: The Value of Your Certification

Definition: Your certification is proof that you have the skills to use John the Ripper effectively and ethically.

Why it is important: It opens doors to job opportunities and builds trust with employers.

Simple explanation: Like a driver's license – it shows you can drive safely.

Real‑life example: Employers look for certified professionals.

School example: A diploma shows you finished school.

Home example: A certificate shows you completed a course.

Nigerian example: Employers in Nigeria value certifications.

Illustration (ASCII):

        Your Certification:
        + Shows your skills
        + Builds trust
        + Opens job doors
        + Proves you are ethical
        + Sets you apart from others
    

Mini summary: Your certification is valuable and opens many doors.


Lesson 2: Penetration Tester – The Ethical Hacker

Definition: A penetration tester is someone who tests systems to find vulnerabilities – with permission.

Why it is important: They help organisations fix weaknesses before hackers exploit them.

Simple explanation: Like a spy who tests the security of a base.

Real‑life example: A company hires a pen tester to test their network.

School example: A teacher tests students' knowledge.

Home example: You test your home security.

Nigerian example: A bank hires a pen tester.

Illustration (ASCII):

        Pen Tester Roles:
        + Test networks
        + Test web applications
        + Test mobile apps
        + Test cloud systems
        + Use tools like John
    

Mini summary: Pen testers are ethical hackers who help protect systems.


Lesson 3: Security Analyst – The Defender

Definition: A security analyst monitors and defends systems from attacks.

Why it is important: They are the first line of defence.

Simple explanation: Like a security guard who watches for intruders.

Real‑life example: A security analyst monitors network traffic.

School example: A hall monitor watches for rule breakers.

Home example: A parent watches for dangers.

Nigerian example: A bank has security analysts.

Illustration (ASCII):

        Security Analyst Roles:
        + Monitor systems
        + Investigate alerts
        + Respond to incidents
        + Analyse threats
        + Use tools like John
    

Mini summary: Security analysts protect systems from attacks.


Lesson 4: Security Consultant – The Advisor

Definition: A security consultant advises organisations on how to improve their security.

Why it is important: They provide expert guidance.

Simple explanation: Like a doctor who gives health advice.

Real‑life example: A consultant recommends security improvements.

School example: A teacher gives study advice.

Home example: A parent gives life advice.

Nigerian example: A consultant works with Nigerian companies.

Illustration (ASCII):

        Security Consultant Roles:
        + Assess security
        + Recommend improvements
        + Help implement policies
        + Train staff
        + Use tools like John
    

Mini summary: Security consultants advise on how to improve security.


Lesson 5: Cybersecurity Engineer – The Builder

Definition: A cybersecurity engineer builds and maintains security systems.

Why it is important: They create the defences that protect data.

Simple explanation: Like an architect who builds a fortress.

Real‑life example: An engineer configures firewalls.

School example: A student builds a model.

Home example: Someone builds a fence.

Nigerian example: An engineer builds security for a bank.

Illustration (ASCII):

        Cybersecurity Engineer Roles:
        + Configure firewalls
        + Build secure networks
        + Implement encryption
        + Develop security tools
        + Use tools like John
    

Mini summary: Security engineers build and maintain security systems.


Lesson 6: Digital Forensics – The Investigator

Definition: Digital forensics is the investigation of cybercrimes.

Why it is important: It helps catch criminals and recover data.

Simple explanation: Like a detective who solves digital crimes.

Real‑life example: A forensics expert analyses a hacked system.

School example: A student investigates a mystery.

Home example: A parent finds lost items.

Nigerian example: A forensics expert works with the police.

Illustration (ASCII):

        Digital Forensics Roles:
        + Investigate breaches
        + Recover data
        + Analyse logs
        + Present findings
        + Use tools like John
    

Mini summary: Digital forensics experts investigate cybercrimes.


Lesson 7: Continuing Education – Lifelong Learning

Definition: Continuing education means always learning new things.

Why it is important: Technology changes, and we need to keep up.

Simple explanation: Like updating your phone to the latest version.

Real‑life example: A professional takes new courses.

School example: A student studies new topics.

Home example: A parent learns new skills.

Nigerian example: A professional attends workshops.

Illustration (ASCII):

        Ways to Learn:
        + Online courses
        + Books and blogs
        + Conferences
        + Certifications
        + Practice and projects
    

Mini summary: Lifelong learning is essential in cybersecurity.


Lesson 8: Other Relevant Certifications

Definition: Other certifications are additional credentials you can earn.

Why it is important: They make you more knowledgeable and employable.

Simple explanation: Like collecting badges for different skills.

Real‑life example: A professional earns CEH, CISSP, etc.

School example: A student earns multiple diplomas.

Home example: A parent earns various certifications.

Nigerian example: A professional earns local and international certifications.

Illustration (ASCII):

        Other Certifications:
        + CEH (Certified Ethical Hacker)
        + CISSP (Certified Information Systems Security Professional)
        + OSCP (Offensive Security Certified Professional)
        + Security+
        + CISA (Certified Information Systems Auditor)
    

Mini summary: Additional certifications can boost your career.


Lesson 9: Entrepreneurship – Starting Your Own Business

Definition: Entrepreneurship is starting your own business.

Why it is important: You can be your own boss and help clients.

Simple explanation: Like opening your own shop.

Real‑life example: A security professional starts a consulting firm.

School example: A student starts a small business.

Home example: A parent starts a side hustle.

Nigerian example: A Nigerian starts a security company.

Illustration (ASCII):

        Entrepreneurship Steps:
        1. Identify a need
        2. Create a business plan
        3. Get clients
        4. Deliver services
        5. Grow your business
    

Mini summary: Entrepreneurship lets you build your own business.


Lesson 10: Networking and Mentorship

Definition: Networking is building relationships with others. Mentorship is learning from experienced people.

Why it is important: It helps you learn and find opportunities.

Simple explanation: Like having friends who help you.

Real‑life example: A professional joins a cybersecurity community.

School example: A student joins a club.

Home example: A parent joins a parenting group.

Nigerian example: A professional attends networking events.

Illustration (ASCII):

        Networking Tips:
        + Join online communities
        + Attend conferences
        + Find a mentor
        + Be helpful to others
        + Build your personal brand
    

Mini summary: Networking and mentorship help you grow.


Lesson 11: Building Your Personal Brand

Definition: Your personal brand is how others see you and your skills.

Why it is important: A good brand attracts opportunities.

Simple explanation: Like being known as the "go‑to" person for security.

Real‑life example: A professional shares knowledge on social media.

School example: A student is known for being smart.

Home example: A parent is known for being helpful.

Nigerian example: A professional is known for cybersecurity skills.

Illustration (ASCII):

        Building Your Brand:
        + Share your knowledge
        + Be active on social media
        + Write articles or blogs
        + Speak at events
        + Be helpful and ethical
    

Mini summary: A strong personal brand opens doors.


Lesson 12: Global Cybersecurity Landscape

Definition: The global cybersecurity landscape is the state of security worldwide.

Why it is important: Understanding it helps you see where you fit.

Simple explanation: Like a map of the world.

Real‑life example: Different countries have different security challenges.

School example: Different schools have different rules.

Home example: Different families have different habits.

Nigerian example: Nigeria faces unique cybersecurity challenges.

Illustration (ASCII):

        Global Trends:
        + Increase in cyberattacks
        + More regulations
        + Growing demand for experts
        + New technologies (AI, cloud)
        + Need for ethical hackers
    

Mini summary: The cybersecurity landscape is always changing.


Lesson 13: Making a Positive Impact

Definition: Making a positive impact means using your skills to help others.

Why it is important: You can make the world a safer place.

Simple explanation: Like being a superhero for the digital world.

Real‑life example: A professional helps non‑profits improve security.

School example: A student helps classmates stay safe online.

Home example: A parent teaches family about security.

Nigerian example: A professional helps Nigerian businesses.

Illustration (ASCII):

        Ways to Help:
        + Protect people's data
        + Educate others about security
        + Volunteer for non‑profits
        + Share your knowledge
        + Be a positive role model
    

Mini summary: You can make a real difference in the world.


Lesson 14: Future Trends – AI, Cloud, and More

Definition: Future trends are new technologies that will shape cybersecurity.

Why it is important: They will create new opportunities and challenges.

Simple explanation: Like the future of cars – self‑driving!

Real‑life example: AI is used to detect threats.

School example: Students learn about new technologies.

Home example: Smart homes need security.

Nigerian example: Nigerian companies adopt AI and cloud.

Illustration (ASCII):

        Future Trends:
        + Artificial Intelligence (AI)
        + Cloud security
        + Internet of Things (IoT)
        + Quantum computing
        + Automation
    

Mini summary: Future trends will shape the cybersecurity field.


Lesson 15: Your Future as a Cybersecurity Leader

Definition: A cybersecurity leader is someone who guides and inspires others.

Why it is important: Leaders make a bigger impact.

Simple explanation: Like a captain of a ship.

Real‑life example: A leader heads a security team.

School example: A student leads a group project.

Home example: A parent leads the family.

Nigerian example: A leader heads a security department.

Illustration (ASCII):

        Becoming a Leader:
        + Gain experience
        + Keep learning
        + Help others
        + Be ethical
        + Inspire and guide
    

Mini summary: You can become a cybersecurity leader.


📝 Key Vocabulary

  • Certification: Proof of skill.
  • Penetration tester: Ethical hacker who tests systems.
  • Security analyst: Defender who monitors and responds.
  • Security consultant: Advisor who recommends improvements.
  • Cybersecurity engineer: Builder of security systems.
  • Digital forensics: Investigation of cybercrimes.
  • Continuing education: Lifelong learning.
  • Entrepreneurship: Starting your own business.
  • Networking: Building relationships.
  • Personal brand: How others see you.

🧠 Important Concepts

  • Your certification is valuable and opens doors.
  • There are many career paths in cybersecurity.
  • Lifelong learning is essential.
  • Other certifications can boost your career.
  • Entrepreneurship is an option.
  • Networking and mentorship help you grow.
  • A personal brand attracts opportunities.
  • Global trends shape the field.
  • You can make a positive impact.
  • You can become a leader.

📋 Step‑by‑Step: Building Your Cybersecurity Career

  1. Get certified: You already have your John certification.
  2. Explore career paths: Research pen tester, analyst, consultant, etc.
  3. Continue learning: Take courses, read books, and practise.
  4. Consider other certifications: Look into CEH, CISSP, etc.
  5. Build your network: Join communities, attend events.
  6. Build your brand: Share knowledge and be active.
  7. Find a mentor: Learn from experienced professionals.
  8. Apply for jobs: Use your certification to get opportunities.
  9. Make an impact: Help others and protect data.
  10. Grow as a leader: Guide and inspire others.

Illustration (flowchart):

        Start
          |
          v
        Get certified
          |
          v
        Explore career paths
          |
          v
        Continue learning
          |
          v
        Consider other certs
          |
          v
        Build network
          |
          v
        Build brand
          |
          v
        Find mentor
          |
          v
        Apply for jobs
          |
          v
        Make impact
          |
          v
        Grow as leader
          |
          v
        End
    

🌍 Real‑life Examples

  • A professional uses their John certification to get a job as a pen tester.
  • A security analyst uses John to test company passwords.
  • A consultant advises a company on password policies.
  • An engineer builds secure systems.
  • A forensics expert investigates a breach.

🇳🇬 Nigerian Examples

  • A Nigerian professional uses their certification to get a job in Lagos.
  • A security analyst works for a Nigerian bank.
  • A consultant advises Nigerian companies.
  • An engineer builds security for Nigerian businesses.
  • A forensics expert works with Nigerian law enforcement.

🧸 Fun Examples for Kids

  • Imagine you are a superhero with a special power.
  • Your certification is your superhero badge.
  • Different careers are like different superhero missions.
  • Learning new things is like unlocking new powers.
  • Helping others is like being a superhero for the digital world.

🏠 Everyday Examples

  • You use your skills to help your family stay safe online.
  • You teach a friend about strong passwords.
  • You test your own passwords with John.
  • You read cybersecurity news.
  • You plan your career path.

🧑‍🏫 Teacher Notes

  • Emphasise that certification is just the beginning.
  • Encourage students to explore different career paths.
  • Discuss the importance of lifelong learning.
  • Highlight the value of networking and mentorship.
  • Use Nigerian examples to make it relatable.

👪 Parent Tips

  • Support your child's career exploration.
  • Encourage continuous learning.
  • Help them build a network.
  • Celebrate their achievements.
  • Be proud of their journey.

🤯 Interesting Facts

  • Cybersecurity jobs are expected to grow 30% in the next decade.
  • There are over 4 million unfilled cybersecurity jobs worldwide.
  • Nigeria has a growing cybersecurity market.
  • Ethical hacking is one of the highest‑paid IT jobs.
  • Continuous learning is key to staying relevant.
  • Many cybersecurity professionals have diverse backgrounds.

💡 Did You Know?

  • Did you know that you can work remotely in cybersecurity?
  • Did you know that cybersecurity is a global field?
  • Did you know that many companies sponsor certifications?
  • Did you know that there are free resources to learn cybersecurity?
  • Did you know that you can become a leader in cybersecurity?

🔔 Remember This

  • Your certification is valuable.
  • There are many career paths.
  • Lifelong learning is essential.
  • Networking and mentorship help.
  • A personal brand attracts opportunities.
  • You can make a positive impact.
  • You can become a leader.

❌ Common Mistakes

  • Mistake: Stopping learning after certification.
    Fix: Keep learning and growing.
  • Mistake: Not building a network.
    Fix: Connect with others in the field.
  • Mistake: Ignoring personal branding.
    Fix: Share your knowledge and skills.
  • Mistake: Not considering entrepreneurship.
    Fix: Explore starting your own business.
  • Mistake: Forgetting to make a positive impact.
    Fix: Help others and protect data.

✅ Best Practices

  • Continue learning throughout your career.
  • Build a strong professional network.
  • Develop a personal brand.
  • Consider entrepreneurship if it suits you.
  • Make a positive impact with your skills.
  • Stay ethical and responsible.

📊 Diagrams & Tables

Timeline: Your Career Journey

        Year 1  ── Get certified (John)
        Year 2  ── Start your first job
        Year 3  ── Earn more certifications
        Year 5  ── Become a senior professional
        Year 7  ── Consider leadership or entrepreneurship
        Year 10 ── Become a leader in the field
    

Comparison Table: Career Paths

Career Role Key Skills
Pen Tester Ethical hacker John, network security, web security
Security Analyst Defender Monitoring, incident response, John
Security Consultant Advisor Assessment, policy, John
Security Engineer Builder Firewalls, encryption, John
Digital Forensics Investigator Analysis, recovery, John

ASCII Flowchart: Career Paths

        Start
          |
          v
        Certified John User
          |
          +---> Pen Tester
          |
          +---> Security Analyst
          |
          +---> Security Consultant
          |
          +---> Security Engineer
          |
          +---> Digital Forensics
          |
          +---> Entrepreneurship
          |
          v
        Leader/Expert
    

Comparison Table: Certifications

Certification Focus Level
Certified John Ripper User Password testing Entry
CEH Ethical hacking Intermediate
CISSP Security management Advanced
OSCP Offensive security Intermediate
Security+ Foundational Entry



📌 Module 8 Summary

Congratulations! You have completed the final module of the Certified John Ripper User course. Here is what we explored:

  • The value of your certification.
  • Advanced career paths in cybersecurity.
  • The importance of lifelong learning.
  • Other certifications you can earn.
  • Entrepreneurship opportunities.
  • Networking and mentorship.
  • Building your personal brand.
  • The global cybersecurity landscape.
  • Making a positive impact.
  • Becoming a cybersecurity leader.

You are now ready to take on the world of cybersecurity. Go out there and make a difference!


❓ Frequently Asked Questions

  1. Q: What can I do with my certification?
    A: You can apply for jobs in cybersecurity.
  2. Q: Do I need other certifications?
    A: They can help, but they are not always required.
  3. Q: How do I find a job?
    A: Use job boards, network, and apply.
  4. Q: Can I work remotely?
    A: Yes, many cybersecurity jobs are remote.
  5. Q: How much can I earn?
    A> Salaries vary, but cybersecurity is well‑paid.
  6. Q: Is entrepreneurship a good option?
    A: Yes, if you are motivated and have skills.
  7. Q: How do I stay updated?
    A: Read blogs, take courses, and attend events.
  8. Q: What if I cannot find a job?
    A: Keep learning, network, and consider volunteering.
  9. Q: Can I work abroad?
    A: Yes, cybersecurity is a global field.
  10. Q: What is the most important skill?
    A: The ability to keep learning.

📝 Review Questions

  1. What is the value of your certification?
  2. What does a penetration tester do?
  3. What does a security analyst do?
  4. What does a security consultant do?
  5. What does a security engineer do?
  6. What is digital forensics?
  7. Why is lifelong learning important?
  8. What are some other certifications?
  9. What is entrepreneurship?
  10. Why is networking important?
  11. What is a personal brand?
  12. What is the global cybersecurity landscape?
  13. How can you make a positive impact?
  14. What are some future trends?
  15. What is a cybersecurity leader?

✍️ Fill‑in‑the‑Blank

  1. Your ________ is proof of your skills.
  2. A ________ tester is an ethical hacker.
  3. A ________ analyst monitors and defends systems.
  4. A ________ consultant advises on security.
  5. A ________ engineer builds security systems.
  6. ________ forensics investigates cybercrimes.
  7. ________ learning is essential in cybersecurity.
  8. Other ________ can boost your career.
  9. ________ is starting your own business.
  10. ________ helps you build relationships.

✅ True or False

  1. Certification is not valuable. (False)
  2. Pen testers are ethical hackers. (True)
  3. Security analysts are defenders. (True)
  4. Consultants do not give advice. (False)
  5. Engineers build security systems. (True)
  6. Digital forensics is not important. (False)
  7. Lifelong learning is not needed. (False)
  8. Other certifications are helpful. (True)
  9. Entrepreneurship is a good option. (True)
  10. Networking is not useful. (False)

🔢 Multiple Choice

  1. What is the value of certification?
    a) It opens doors
    b) It is useless
    c) It is a game
    Answer: a
  2. What does a penetration tester do?
    a) Test systems
    b) Cook food
    c) Play games
    Answer: a
  3. What does a security analyst do?
    a) Monitor systems
    b) Build houses
    c) Teach school
    Answer: a
  4. What does a security consultant do?
    a) Advise on security
    b) Drive cars
    c) Paint pictures
    Answer: a
  5. What does a security engineer do?
    a) Build security systems
    b) Cook meals
    c) Write books
    Answer: a
  6. What is digital forensics?
    a) Investigating cybercrimes
    b) Playing games
    c) Watching movies
    Answer: a
  7. Why is lifelong learning important?
    a) Technology changes
    b) It is boring
    c) It is not needed
    Answer: a
  8. What are other certifications?
    a) Additional credentials
    b) Games
    c) Food
    Answer: a
  9. What is entrepreneurship?
    a) Starting a business
    b) Playing games
    c) Sleeping
    Answer: a
  10. Why is networking important?
    a) It builds relationships
    b) It is not useful
    c) It is a waste of time
    Answer: a
  11. What is a personal brand?
    a) How others see you
    b) A type of food
    c) A game
    Answer: a
  12. What is the global cybersecurity landscape?
    a) State of security worldwide
    b) A painting
    c) A book
    Answer: a
  13. How can you make a positive impact?
    a) By helping others
    b) By ignoring others
    c) By playing games
    Answer: a
  14. What are future trends?
    a) AI and cloud
    b) Games and movies
    c) Books and music
    Answer: a
  15. What is a cybersecurity leader?
    a) Someone who guides others
    b) Someone who plays games
    c) Someone who sleeps
    Answer: a

🔗 Matching Exercise

Match the term on the left with its description on the right.

Term Description
1. Penetration tester A. Builds security systems
2. Security analyst B. Ethical hacker
3. Security consultant C. Investigates cybercrimes
4. Security engineer D. Monitors systems
5. Digital forensics E. Advises on security

Answers: 1‑B, 2‑D, 3‑E, 4‑A, 5‑C


📝 Short Answer

  1. What is the value of your certification?
  2. What are some career paths in cybersecurity?
  3. Why is lifelong learning important?
  4. What are some other certifications?
  5. How can you make a positive impact?

🎭 Scenario‑based Exercises

Scenario 1: You have just become certified. You are looking for a job.

  • What should you do? (Update your CV, network, apply for jobs.)
  • What careers can you consider? (Pen tester, analyst, consultant.)

Scenario 2: You have been working for a few years and want to start your own business.

  • What should you do? (Create a business plan, get clients, offer services.)
  • What services can you offer? (Password testing, security assessments.)

👥 Group Activity

Activity: In groups, create a career roadmap for a certified John Ripper User. Include short‑term and long‑term goals.


🧑 Individual Activity

Activity: Write a one‑page plan for your next steps after certification. Include career goals, learning goals, and networking goals.


💬 Classroom Discussion Questions

  1. What is the most important thing you learned in this course?
  2. What are your career goals?
  3. How will you stay updated in cybersecurity?
  4. What challenges do you expect?
  5. How can you help others with your skills?

🛠️ Mini Project

Project: Create a portfolio website showcasing your skills, certification, and projects. Include a blog section where you share your knowledge.


📋 Practical Assignment

Assignment: Write a cover letter and CV tailored to a cybersecurity job. Include your certification and relevant skills.


🏆 Challenge Exercise

Challenge: Conduct a mock interview for a cybersecurity role. Prepare answers to common questions and showcase your skills.


🔑 Quiz Answers

(Answers to Fill-in-the-Blank, True/False, and Multiple Choice are provided within each section.)


🎁 Key Takeaways

  • You are now a Certified John Ripper User.
  • There are many career paths in cybersecurity.
  • Lifelong learning is essential.
  • Your certification is valuable.
  • You can make a positive impact.
  • You can become a leader.
  • Your journey has just begun!

🔜 What’s Next?

You have completed the Certified John Ripper User course. This is the end of this course, but it is the beginning of your cybersecurity journey.

We hope you enjoyed the course and learned a lot. Remember, you are now a guardian of cybersecurity. Go out there and make the world a safer place!

Thank you for being part of this course. We are proud of you!


End of Module 8 – The End of the Course

🏆 Get Certified

🔒

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it — ₦4,000/month.

🎓 Sign Up & Unlock for ₦4,000/month
🛠️ Practice Tools
Hands-on simulators & labs - subscription required.
→
🎯 Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
→