Avatar

Labs / Office Password Cracker

  • Challenge
  • Released 29 Oct 2025

🔐 Can you crack into this locked corporate document?

A password-protected Word document stands between you and critical information. The file is encrypted, the contents hidden behind a corporate password. Armed with the right tools and techniques, can you break through the protection and uncover what lies within? Time to put your password cracking skills to the test.

1
Flags
1
Points
Challenge
Free Access
Start Lab Environment

Launch your dedicated AWS machine to begin hacking

~1-2 min setup
AWS dedicated
Private instance
Industry standard
Challenge

Challenge Overview

Password-protected Microsoft Office documents are commonly used in corporate environments to secure sensitive information. However, weak passwords can be cracked using specialized tools and techniques.

Learning Objectives
  • Understanding Office document encryption mechanisms
  • Learning to use password cracking tools like john and hashcat
  • Extracting hashes from Office documents
  • Performing offline password attacks
  • Recognizing the importance of strong passwords
Challenge Scenario

During a security assessment, you have obtained a password-protected Word document from a corporate file server. The document contains confidential information that you need to access. Your task is to crack the password and retrieve the sensitive data inside.

Required Tools
  • office2john - Extract password hashes from Office documents (part of John the Ripper)
  • john - Password cracking tool with support for Office formats
  • hashcat - Alternative GPU-accelerated password cracker
  • LibreOffice/Microsoft Office - To open the document after cracking
Skills Required
  • Basic command-line usage
  • Understanding of password cracking concepts
  • Familiarity with hash extraction tools

First Blood 🩸
Malekith
Recent flags ⛳️