Commit Graph
742 Commits
Author SHA1 Message Date
Justin BollingerandClaude e49be6122a build(deps): declare instructor, openai, and pydantic explicitly
hate_crack/llm.py imports all three directly, but only atomic-agents was
declared -- they were available purely as transitive deps. A future
atomic-agents release that loosened its coupling to any of them would make
`uv sync` silently omit it and break `import hate_crack.llm` at runtime.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-24 17:07:19 -04:00
Justin BollingerandClaude 81577ae060 Merge branch 'main' into feature/llm-atomic-agents
Conflicts resolved:
- CHANGELOG.md: kept both [2.12.0] (branch) and [2.11.4] (main), newest first
- pyproject.toml: kept main's tighter version pins (click>=8.4.2, requests>=2.34.2,
  packaging>=26.2, pytest-cov==7.1.0) and the branch's atomic-agents>=2.0.0 dep

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-24 16:57:24 -04:00
Justin BollingerandGitHub a99b36369a Merge pull request #125 from trustedsec/dependabot/uv/click-gte-8.4.2
chore(deps): update click requirement from >=8.0.0 to >=8.4.2
2026-07-24 16:51:02 -04:00
Justin BollingerandGitHub 9674f991b3 Merge pull request #124 from trustedsec/dependabot/uv/requests-gte-2.34.2
chore(deps): update requests requirement from >=2.31.0 to >=2.34.2
2026-07-24 16:50:47 -04:00
Justin BollingerandGitHub 8906636ec4 Merge pull request #123 from trustedsec/dependabot/uv/packaging-gte-26.2
chore(deps): update packaging requirement from >=21.0 to >=26.2
2026-07-24 16:50:31 -04:00
Justin BollingerandGitHub 6a7a2a5f47 Merge pull request #122 from trustedsec/dependabot/uv/pytest-cov-7.1.0
chore(deps-dev): bump pytest-cov from 7.0.0 to 7.1.0
2026-07-24 16:50:15 -04:00
Justin BollingerandGitHub cf6c9c2f8b Merge pull request #121 from trustedsec/dependabot/github_actions/softprops/action-gh-release-3.0.2
chore(ci): bump softprops/action-gh-release from 2.6.2 to 3.0.2
2026-07-24 16:49:55 -04:00
dependabot[bot]andGitHub b385f391a4 chore(deps): update click requirement from >=8.0.0 to >=8.4.2
Updates the requirements on [click](https://github.com/pallets/click) to permit the latest version.
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](https://github.com/pallets/click/compare/8.0.0...8.4.2)

---
updated-dependencies:
- dependency-name: click
  dependency-version: 8.4.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 20:48:13 +00:00
dependabot[bot]andGitHub 9297670980 chore(deps): update requests requirement from >=2.31.0 to >=2.34.2
Updates the requirements on [requests](https://github.com/psf/requests) to permit the latest version.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.31.0...v2.34.2)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 20:48:08 +00:00
dependabot[bot]andGitHub 14c332d2b1 chore(deps): update packaging requirement from >=21.0 to >=26.2
Updates the requirements on [packaging](https://github.com/pypa/packaging) to permit the latest version.
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/packaging/compare/21.0...26.2)

---
updated-dependencies:
- dependency-name: packaging
  dependency-version: '26.2'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 20:48:07 +00:00
dependabot[bot]andGitHub 415255e1ec chore(deps-dev): bump pytest-cov from 7.0.0 to 7.1.0
Bumps [pytest-cov](https://github.com/pytest-dev/pytest-cov) from 7.0.0 to 7.1.0.
- [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest-cov/compare/v7.0.0...v7.1.0)

---
updated-dependencies:
- dependency-name: pytest-cov
  dependency-version: 7.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 20:48:01 +00:00
dependabot[bot]andGitHub ba6bb999bb chore(ci): bump softprops/action-gh-release from 2.6.2 to 3.0.2
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2.6.2 to 3.0.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/3bb12739c298aeb8a4eeaf626c5b8d85266b0e65...3d0d9888cb7fd7b750713d6e236d1fcb99157228)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 20:47:32 +00:00
Justin BollingerandGitHub ca1eea6d5e Merge pull request #120 from trustedsec/fix/ci-hardening
fix(ci): add test CI, repair auto-tag releases, harden action pins (2.11.4)
v2.11.4
2026-07-24 16:47:01 -04:00
Justin BollingerandClaude 665c8ab47c fix(ci): add test CI, repair auto-tag releases, harden action pins (2.11.4)
The repo had no CI: ruff/ty/pytest ran only in local prek pre-push hooks, so
a commit pushed without hooks installed reached main unvalidated -- and
auto-tag would then cut a release from it. Adds ci.yml (ruff, ty, pytest on
3.13) and gates tagging on it.

Auto-tagged versions also never produced a release. The tag is pushed with
the default GITHUB_TOKEN, and GitHub suppresses workflow triggers for
GITHUB_TOKEN-created events, so the tag-triggered release.yml never fired --
v2.11.3 was tagged with no release. auto-tag now creates the release itself,
idempotently; release.yml stays as the manual-tag path.

Also fixes version logic that matched the `!` breaking marker but only ever
bumped minor (and never saw BREAKING CHANGE: footers, since only subjects
were inspected), serializes concurrent merges that both computed the same
tag, and repins softprops/action-gh-release from an arbitrary master commit
to v2.6.2 with all workflows on one actions/checkout version.

Clears the pre-existing ty error in notify/tailer.py that would have made
the new type-check step red: _read_new_lines read self._file_pos
(int | None) while its only None-guard lived in the caller, so the position
is passed in explicitly as an int. Behavior unchanged.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-24 16:39:59 -04:00
Justin BollingerandClaude Opus 4.8 f424783eb2 style(llm): drop vestigial global hcatProcess in hcatOllama
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 12:15:10 -04:00
Justin BollingerandClaude Opus 4.8 519d395708 docs(llm): document Atomic Agents refactor, new default model, wordlist mode (2.12.0)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 12:11:26 -04:00
Justin BollingerandClaude Opus 4.8 bcea02b2e7 test(llm): cover wordlist-mode abort when no wordlist picked
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 12:10:39 -04:00
Justin BollingerandClaude Sonnet 4.6 a4da571ab4 feat(llm): add wordlist (denylist) mode to LLM attack menu
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-24 12:08:20 -04:00
Justin BollingerandClaude Opus 4.8 d6da721414 feat(llm): default Ollama model to qwen2.5:32b for structured output
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 12:06:29 -04:00
Justin BollingerandClaude Opus 4.8 93960e2d58 test(llm): cover per-rule hashcat loop and hash:password stripping
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 12:06:12 -04:00
Justin BollingerandClaude Sonnet 4.6 4df1121051 refactor(llm): delegate candidate generation to llm module; drop auto-pull
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-24 11:59:04 -04:00
Justin BollingerandClaude Opus 4.8 9dd6ad746f style(llm): drop noise Any annotation on agent result
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 11:52:32 -04:00
Justin BollingerandClaude Sonnet 4.6 a57a4165f1 refactor(llm): validate AgentConfig in prod; spec-mock the client in tests
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-24 11:50:19 -04:00
Justin BollingerandClaude Sonnet 4.6 1cc71abfef feat(llm): structured candidate generation module via Atomic Agents
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-24 11:48:19 -04:00
Justin Bollinger 66e6d593c4 build(deps): add atomic-agents for structured LLM candidate generation 2026-07-24 11:45:24 -04:00
Justin BollingerandGitHub a0dc56ce08 Merge pull request #117 from trustedsec/fix/cleanup-rules-mode
fix(rules): pass required mode arg to cleanup-rules.bin (2.11.3)
v2.11.3
2026-07-24 11:29:20 -04:00
Justin BollingerandClaude Opus 4.8 fe206420e9 fix(rules): pass required mode arg to cleanup-rules.bin (2.11.3)
cleanup-rules.bin requires a mode argument (1=CPU, 2=GPU) and exits with
usage text otherwise, so Rule File Tools cleanup always failed. Pass the
mode (defaulting to GPU) so cleanup actually runs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 11:28:56 -04:00
Justin Bollinger 04be489c60 Merge branch 'fix/upload-counts' (2.11.2) v2.11.2 2026-07-23 14:26:31 -04:00
Justin BollingerandClaude Opus 4.8 a15860a63e feat(hashview): report cracked-hash upload counts (2.11.2)
The upload previously printed only "✓ Success: OK", so there was no way
to tell how many hashes were accepted. upload_cracked_hashes now surfaces
client-side uploaded/skipped counts in its return value, and the CLI
prints them plus the server's verified/updated/unmatched breakdown when a
newer Hashview reports them (see hashview #355/#356).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 14:26:26 -04:00
Justin Bollinger a14272a058 Merge remote-tracking branch 'origin/main'
# Conflicts:
#	CHANGELOG.md
v2.11.1
2026-07-23 14:00:58 -04:00
Justin Bollinger 4c70185270 Merge branch 'fix/upload-hex-decode' (2.10.11) 2026-07-23 13:59:22 -04:00
Justin BollingerandClaude Opus 4.8 a3ca2a19e8 docs(changelog): add 2.10.11 (Hashview $HEX upload fix + client-side validation)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 13:59:15 -04:00
Justin BollingerandClaude Opus 4.8 2ed9cc28e6 fix(hashview): decode $HEX[...] before upload for older servers
hate_crack forwarded hashcat's $HEX[...] plaintext verbatim. A Hashview
that verifies plaintext literally hashes the string "$HEX[..]" and
rejects the batch. Decode $HEX to the exact bytes the server must
re-hash and send those on the wire (body is now bytes):

- UTF-16LE modes (NTLM 1000, MSSQL 1731): latin-1 code points -> UTF-8
- raw-byte modes (0/100/300/900/1400/1700): the decoded bytes as-is
- unsafe (embedded CR/LF) or unknown modes: keep the $HEX token verbatim
  and rely on a $HEX-aware server

Also fixes the NTLM validation digest to use latin-1 -> UTF-16LE so
high-byte $HEX plaintexts verify instead of being silently unverifiable.
Verified end-to-end: the emitted wire verifies against both the old
(literal) and new ($HEX-aware) Hashview verifiers.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 13:26:09 -04:00
Justin BollingerandGitHub 0a6dfd26fc Merge pull request #116 from trustedsec/feature/shard-multi-part
feat(wordlist): shard into all N parts in one run with numbered filenames
v2.11.0
2026-07-23 13:15:38 -04:00
Justin Bollinger d716f04c86 Merge branch 'fix/upload-hash-validation' 2026-07-23 13:12:41 -04:00
Justin BollingerandClaude Opus 4.8 ecedcbf7dc fix(hashview): validate cracked pairs client-side before upload
upload_cracked_hashes sent every hash:plaintext pair to Hashview
untouched. A single line whose plaintext doesn't match the declared
hash mode (e.g. a stray MD5 hash mixed into an NTLM list) made
Hashview reject the entire batch with an opaque
"Plaintext for hash ... was found to be invalid" error.

Add two client-side guards (default on, disable via validate=False):
1. Length filter — drop hashes whose hex width is wrong for the mode.
2. Plaintext verification — for reproducible fast modes (MD5, SHA1,
   MD4, NTLM, SHA2-256/512) recompute the digest from the plaintext
   ($HEX[...] decoded) and skip pairs that don't match.

Skipped lines are reported with line number and reason instead of
failing the whole upload; raise clearly if nothing valid remains.
Ships a pure-Python MD4 since OpenSSL 3 dropped it from hashlib.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 12:52:55 -04:00
Justin BollingerandClaude Opus 4.8 5510755c12 feat(wordlist): shard into all N parts in one run with numbered filenames
Shard Wordlist (option 7) now prompts for an output base path and a shard
count, then writes all N interleaved parts as base.001..base.00N in a single
pass instead of one file per modulus/offset invocation. Matches the intended
distributed-cracking workflow: split once, copy one part per node.

Updates tests and README usage docs; bumps CHANGELOG to 2.10.11.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 12:51:07 -04:00
Justin Bollinger 1e23199aac Merge branch 'docs/changelog-version-correction' v2.10.10 2026-07-21 18:22:43 -04:00
Justin BollingerandClaude Opus 4.8 eb98103d05 docs: correct CHANGELOG versions (pytest fix is 2.10.10; add 2.10.9)
The auto-tag workflow already published v2.10.9 for Larry's Quick Crack
wordlist fix when main was pushed. Retitle the pytest security bump to
2.10.10 (its actual auto-tag target) and add the missing 2.10.9 entry.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:22:39 -04:00
Justin Bollinger 5dec58d973 Merge branch 'fix/bump-pytest-9.0.3-v2' 2026-07-21 18:21:01 -04:00
Justin BollingerandClaude Opus 4.8 c312259a86 fix(deps): bump pytest 9.0.2 -> 9.0.3 for GHSA-6w46-j5rx-g56g
The pinned dev/test dependency pytest==9.0.2 is affected by the
vulnerable tmpdir-handling advisory GHSA-6w46-j5rx-g56g (pytest < 9.0.3),
Dependabot alert #1. Bump the pin to 9.0.3 to clear it. Development
scope only (test runner); no runtime dependency change. Full test
suite passes under 9.0.3. (uv.lock is gitignored, so only the
pyproject.toml pin is tracked.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:20:55 -04:00
Justin Bollinger 6ed3b7577d Merge remote-tracking branch 'origin/main' v2.10.9 2026-07-21 18:18:15 -04:00
Justin Bollinger 1b888fa63f Merge branch 'docs/readme-2.10.8' v2.10.8 2026-07-21 18:16:41 -04:00
Justin BollingerandClaude Opus 4.8 8ee36d0eab docs: move version history from README into CHANGELOG.md
Consolidate the release notes into a single dedicated CHANGELOG.md
(Keep a Changelog format) and replace the README's inline Version
History with a pointer, so the two no longer drift.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:16:32 -04:00
Justin Bollinger 84d7fdd0ee Merge branch 'chore/changelog-2.10.8' 2026-07-21 18:13:07 -04:00
Justin BollingerandClaude Opus 4.8 b3fd8e1f90 docs: add CHANGELOG for v2.10.8
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:13:03 -04:00
Justin Bollinger 755e43b91c Merge branch 'feat/hashview-rule-download' 2026-07-21 18:06:23 -04:00
Justin BollingerandClaude Opus 4.8 144d1a5334 feat(hashview): download rule files from /v1/rules
Add HashviewAPI.list_rules and download_rules wrapping the Hashview
rule endpoints. The server gzip-compresses plaintext rules on the
fly, so download_rules decompresses before saving, yielding a file
usable directly with hashcat -r. Wired into the interactive Hashview
menu (Download Rule) and the CLI (hashview download-rules
--rules-id/--output). Unknown rule ids surface the real HTTP 404.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 18:06:19 -04:00
Justin Bollinger 201cc37e55 Merge branch 'fix/hashview-hashtype-parsing' 2026-07-21 17:56:34 -04:00
Justin BollingerandClaude Opus 4.8 61b197f10e fix(hashview): correct hash-type parsing for MD5 and hashfile listing
get_hashfile_details used 'or' fallthrough on hash_type, so MD5
(hash_type 0, falsy) resolved to the envelope 'type' string
('message') instead of 0. Select by key presence and drop the
bogus 'type' fallback.

get_hashfile_hash_type looked for file_ids/ids/hashfile_ids keys
that the endpoint never returns; it always yielded []. Read the
actual 'hashfiles' envelope array and extract each file id.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 17:56:27 -04:00