This article will detail how to use Hashcat to crack Word document passwords, including preparation, the basic principles of Hashcat, specific operation steps, and how to improve the success rate of cracking. Even if you're a tech novice, you can follow this guide step by step to recover your lost password.
Microsoft Word (2010 and later versions) uses AES-256 encryption by default, which is highly secure. Earlier versions of Word 97-2003 used RC4 encryption, which was relatively easy to crack.
When a user sets a password, Word:
hashes the password (converts it to a fixed-length string).
Use this hash to encrypt the document contents.
Therefore, the essence of cracking a Word password is:
Extract the password hash value of the document (similar to a "fingerprint").
Use Hashcat to try different password combinations until a successful match occurs.
Hashcat cannot directly read .docx or .doc files; the hash value of the password needs to be extracted first. We can do this using the office2john.py tool (from the John the Ripper toolset).
Visit Python official website Download and install Python (version 3.8+ recommended).
Download the office2john.py script (available on GitHub by searching for "John the Ripper").
Open the command line (Windows: cmd / macOS/Linux: Terminal) and run:
bash
copy
download
python office2john.py yourfile.docx > hash.txt
After execution, the hash.txt file will contain hash values similar to the following:
copy
download
$Office$*2013*100000*256*16*...*your hash value
This hash value is the target we want to crack.
Download from the official website:https://hashcat.net/hashcat/
支持Windows/Linux/macOS,建议使用NVIDIA显卡(CUDA加速)或AMD显卡(OpenCL加速)。
Hashcat supports multiple cracking modes, the most common of which are:
Dictionary Attack: Try using a list of common passwords (such as rockyou.txt).
Mask Attack: A known partial password structure (e.g., "Pass123?").
Brute-Force: Try all possible combinations (for short passwords).
bash
copy
download
hashcat -m 9600 hash.txt rockyou.txt
-m 9600 represents the hash pattern of Word 2013+.
rockyou.txt is a commonly used password dictionary (available for download online).
If you remember that the password starts with "Pass" followed by a number, you can try:
bash
copy
download
hashcat -m 9600 hash.txt -a 3 "Pass? d? d? d"
? d represents a number (0-9).
? l represents lowercase letters (a-z).
? u represents a capital letter (A-Z).
bash
copy
download
hashcat -m 9600 hash.txt -a 3 ? l? l? l? l? l? l
This will try all 6-digit lowercase letter combinations for simple passwords.
rockyou.txt (which contains tens of millions of common passwords).
Custom dictionary: Combines personal information (such as birthday, name, commonly used words).
Hashcat supports "rules" to transform the dictionary, such as:
case conversion (password → password, password).
Add numbers/symbols (pass → pass123, pass!).
Example:
bash
copy
download
hashcat -m 9600 hash.txt dict.txt -r rules/best64.rule
GPU cracking is more than 100 times faster than CPU. It is recommended to use high-end graphics cards such as NVIDIA RTX 4090.
If your computer is underperforming, consider a cloud server (such as an AWS GPU instance) or a proxy service (to save time).
The user forgets a 6-digit plain numeric password (such as "198504"), and uses a mask attack:
bash
copy
download
hashcat -m 9600 hash.txt -a 3 ? d? d? d? d? d? d
successfully recovered the password in just 10 seconds.
The password may be "Company2024!", but the case and symbols are uncertain. Use rules:
bash
copy
download
hashcat -m 9600 hash.txt dict.txt -r rules/leetspeak.rule
2 hours later it matches "COMPANY2024!".
Extract hash: Use office2john.py to obtain the hash value of the Word password.
Select attack mode: dictionary attack (recommended first attempt), mask attack (partially known), brute force attack (short password).
Optimization strategy: Use stronger dictionaries, rules, and GPU acceleration.
Consider a running service: If the hardware is insufficient, you can find a professional team to run it for you to save time.
If you encounter the problem of forgetting your Word password, you may want to try to crack it by following this tutorial. If you have a high technical skill level, you can also choose a professional Hashcat service to retrieve your password efficiently and securely!