October 1, 2026
How Easily Can a Weak Password Be Cracked?
Passwords are an important part of information security, but weak and predictable passwords can be vulnerable to dictionary-based attacks…

By mciggles
3 min read
Passwords are an important part of information security, but weak and predictable passwords can be vulnerable to dictionary-based attacks. Instead of trying every possible combination of characters like a brute-force attack, a dictionary attack starts with a list of passwords that people have actually used.
For this lab, I set up a controlled Linux environment and used RockYou and John the Ripper explore how attackers use dictionary attack to break weak passwords and its security implications.
rockyou.txt is a well-known password wordlist originally derived from passwords exposed during the 2009 RockYou data breach. The list contains more than 14 million plaintext password entries and is commonly used in cybersecurity training, capture-the-flag exercises, penetration testing, and password auditing. Entries include passwords such as 123456, password, sunshine, and dragon.
On Kali Linux, the file is commonly provided in compressed form at /usr/share/wordlists.
John the Ripper is a password-cracking program designed to identify weak passwords from password hashes. Its documentation supports a wordlist mode in which candidate passwords are taken from a specified dictionary.
Setting Up the Experiment
A dedicated Linux test account was created for the experiment so that no real user account or password was involved.The goal was to create a password hash and then see whether John the Ripper could recover the password using only the RockYou dictionary.
After creating the test account, the password information was combined into a hash file using unshadow.
John the Ripper was then run against the hash using the RockYou wordlist:
john --wordlist=/usr/share/wordlists/rockyou.txt hashfile.txtjohn --wordlist=/usr/share/wordlists/rockyou.txt hashfile.txtHowever, this ran into an issue. My Linux system was hashing passwords using yescrypt, which produces hashes beginning with $y$.
My installed version of John the Ripper did not list yescrypt as a supported format. So instead, a SHA-512 crypt test hash was generated, a format supported by the installed version.
The Attack
Once I had a compatible test hash, I ran:
john --format=sha512crypt --wordlist=/usr/share/wordlists/rockyou.txt hashfile.txtjohn --format=sha512crypt --wordlist=/usr/share/wordlists/rockyou.txt hashfile.txtJohn worked through the entries in RockYou and reached the password in less than 1 second.
The speed of the attack demonstrated that a weak password can be recovered without needing to test every possible password combination.
Password-Mangling Rules
A basic dictionary attack only tests the words or passwords that are directly contained in the wordlist. People often try to make passwords stronger by modifying common words such as P4ssw0rd, Dragon123, $unShine.
John the Ripper addresses this problem through wordlist rules, which consist of commands that modify words before they are tested against a password hash.
For example, rules can perform operations such as:
- Capitalizing letters
- Adding numbers
- Replacing characters
- Inserting characters
- Deleting characters
- Modifying parts of a word
Taking a look at /etc/john/john.conf we can see some examples of rulesets
One example used with John the Ripper is d3ad0ne. It can be applied to a wordlist with -rules=d3ad0ne.
This makes rule-based attacks significantly more useful against passwords that are based on common words but have been modified. A password such as Dragon123 may appear more complicated than dragon, but a password-mangling attack can generate common variations of dictionary words.
What This Means
The lesson isn't that every password containing a number or symbol is weak.
The problem with a lot of passwords is predictability.
Comparing Dragon123 with raeT-qP2!di@VR we see that the first has a common word and follows a predictable pattern while the latter has no obvious relationship.
This small experiment highlighted several important lessons.
1. Length matters
Longer passwords and passphrases increase the number of possible combinations an attacker has to consider.
2. Password reuse is dangerous
If someone uses the same password across multiple services, a password exposed in one breach can potentially be tested against another account.
3. Use password managers
Password managers make it easy to create unique, randomly generated passwords without requiring users to memorize them.
4. Use MFA
Even if a password is compromised, multi-factor authentication provides another layer of protection.
Before doing the experiment, it is easy to think of password cracking as an attacker trying millions or billions of random combinations.
Good password security is less about making passwords complicated and more about making them long, unique, and difficult to predict.
References
John the Ripper. "John the Ripper Password Cracker." Openwall, https://www.openwall.com/john/doc/.
Openwall. "John the Ripper — Wordlist Rules Syntax." Openwall, https://www.openwall.com/john/doc/RULES.shtml.
Zach Eller. "rockyou.txt Wordlist." GitHub, https://github.com/zacheller/rockyou.
Weakpass. "RockYou.txt." Weakpass, https://weakpass.com/wordlists/rockyou.txt. Accessed 29 Sept. 2026
HackerDNA Team. "rockyou.txt: How to Find and Use the Wordlist (2026)." HackerDNA, 9 Sept. 2026, https://hackerdna.com/blog/rockyou-txt. Accessed 29 Sept. 2026
Hashcat. GitHub, https://github.com/hashcat/hashcat