如何通过Crunch生成包含指定单词的可变长度密码字典?
我用Crunch工具生成暴力破解用的密码字典,它支持自定义字符集,但当用指定单词生成字典时(用-p参数),没法设置生成的密码不需要包含所有指定单词——不管我给的长度范围是多少,它只会输出所有指定单词的全排列组合。
示例:
执行命令:crunch 1 3 -p this a test
返回结果:
atestthis athistest testathis testthisa thisatest thistesta
而我期望的返回结果是包含1个、2个、3个单词的所有排列组合:
a test this atest athis testa testthis thisa thistest atestthis athistest testathis testthisa thisatest thistesta
我自己写了一段Python脚本来实现这个需求(如下),想问下有没有办法直接用Crunch命令实现这个功能,不用额外写脚本?
import os import argparse as arg parser = arg.ArgumentParser() parser.add_argument('words', help='list of words inside parentheses', type = str) parser.add_argument('--extra', type = str, help = 'all the extra arguments instide parentheses excluding -p, -t and -o') args = parser.parse_args() list_words = args.words.split() pattern = '' wordlist_amount = '' for word in range(1,len(list_words)+1): pattern = pattern + 'a' command = f'crunch {word} {word} {args.extra} -o temporary_wordlist{word}.txt -t {pattern} -p {args.words}' wordlist_amount = wordlist_amount + f'temporary_wordlist{word}.txt ' os.system(command) os.system(f'cat {wordlist_amount} > tmp.txt') os.system('uniq tmp.txt > wordlist.txt') os.system('rm temporary_wordlist* | rm tmp.txt')
Crunch原生不支持通过单条命令生成指定单词的所有非全量排列组合(即包含1个、2个直到全部单词的排列)。因为-p参数的设计逻辑是强制使用所有给定单词生成全排列,完全忽略命令开头的长度参数——无论你指定的长度范围是多少,只要加了-p,Crunch只会输出所有单词的全排列结果。
你可以用Shell循环配合Crunch实现需求,逻辑和你的Python脚本一致,但无需额外编写Python代码:
# 定义目标单词列表 WORDS="this a test" WORDS_ARR=($WORDS) TMP_PREFIX="tmp_wordlist_" # 循环生成1到单词总数的排列组合 for ((i=1; i<=${#WORDS_ARR[@]}; i++)); do # 生成对应长度的模式串(如i=2时为"aa") PATTERN=$(printf 'a%.0s' $(seq 1 $i)) # 调用Crunch生成对应长度的排列 crunch $i $i -t "$PATTERN" -p $WORDS > "${TMP_PREFIX}${i}.txt" done # 合并去重得到最终字典 cat ${TMP_PREFIX}*.txt | uniq > final_wordlist.txt # 清理临时文件 rm ${TMP_PREFIX}*.txt
这段脚本会依次生成1个、2个、3个单词的所有排列,合并后去重得到你期望的结果,功能和你写的Python脚本完全一致,但直接基于Crunch和Shell命令实现,无需依赖Python环境。
内容的提问来源于stack exchange,提问作者alessio

