Johnny Complete Guide || Graphical Interface for John the Ripper
Password Cracking

Johnny Complete Guide || Graphical Interface for John the Ripper

October 08, 2026 • 16 min read • 32 views • 0 discussions
Table of Contents

    In our previous video, we learned about John the Ripper, a tool used for password auditing and password recovery.

    John The Ripper Guide

    john the ripperjtr

    Click to visit this external resource.

    Visit Site

    We also saw how John can be operated from the command line.

    But what if we want to manage John through a graphical interface? That's where Johnny comes in.

    Johnny can make the process more visual and easier to understand, especially for beginners.

    However, for practical penetration-testing walkthroughs and CTF challenges, I prefer using the command-line version of John the Ripper.

    So, in this video, we'll use Johnny mainly to understand its graphical interface and how it works.

    Hello everyone, and welcome to a new video.

    Johnny

    In this video, we'll understand and demonstrate the main features of Johnny, the graphical user interface, or GUI, frontend for John the Ripper, also known as JTR. In simple terms, Johnny provides a graphical interface through which we can configure and interact with John the Ripper, instead of entering every command manually in the terminal.

    Now, let's install Johnny and take a look at it.

    Installation Steps

    Johnny may not be installed by default on every Kali Linux installation. So, first, we'll check whether it is already available on our system.

    Let's open a terminal and run:

    ┌──(kali㉿kali)-[~]
    └─$ sudo apt install johnny
    [sudo] password for kali: 
    Reading package lists... Done
    Building dependency tree... Done
    Reading state information... Done
    The following packages were automatically installed and are no longer required:
      figlet finger firebird3.0-common firebird3.0-common-doc libavutil57 libbson-1.0-0 libcodec2-1.0 libfbclient2 libhashkit2
      libmemcached11 libmongoc-1.0-0 libmongocrypt0 libplacebo208 libpostproc56 libswscale6 libwinpr2-2 medusa numba-doc
      python-odf-doc python-odf-tools python-tables-data python3-aioredis python3-apscheduler python3-bottleneck python3-git
      python3-gitdb python3-llvmlite python3-numba python3-numexpr python3-odf python3-pandas python3-pandas-lib python3-pyexploitdb
      python3-pyfiglet python3-pyshodan python3-quamash python3-smmap python3-tables python3-tables-lib python3-tld python3-yaswfp
      rwho rwhod sparta-scripts toilet-fonts wapiti
    Use 'sudo apt autoremove' to remove them.
    The following NEW packages will be installed:
      johnny
    0 upgraded, 1 newly installed, 0 to remove and 852 not upgraded.
    Need to get 541 kB of archives.
    After this operation, 923 kB of additional disk space will be used.
    Get:1 http://http.kali.org/kali kali-rolling/main amd64 johnny amd64 2.2+git20160807-0kali2 [541 kB]
    Fetched 541 kB in 18s (30.9 kB/s)                                                                                                
    Selecting previously unselected package johnny.
    (Reading database ... 400753 files and directories currently installed.)
    Preparing to unpack .../johnny_2.2+git20160807-0kali2_amd64.deb ...
    Unpacking johnny (2.2+git20160807-0kali2) ...
    Setting up johnny (2.2+git20160807-0kali2) ...
    Processing triggers for kali-menu (2023.2.3) ...
    ┌──(kali㉿kali)-[~]
    └─$ 

    With Johnny successfully installed, you can launch it effortlessly. Simply locate Johnny in your application menu and click on it. 

    As you do, the intuitive GUI interface of Johnny will open up, ready for use. 

    Now, let's take a look at the different components of this interface and understand what each one does.

    At the top, we have the menu bar.

    It contains four main menus:

    • File
    • Attack
    • Passwords
    • Help

    Let's start with the File menu.

    The File menu provides options for loading password or hash data into Johnny. This is where we can either load a password file or load another file format to be used by the *2john utility.

    Once the appropriate file has been loaded, its contents and status can be displayed in the main working area.

    Next is the Attack menu.

    This menu provides controls for starting, resuming, pausing, and managing password-auditing operations.

    The Passwords menu contains functions related to the password entries currently loaded into Johnny.

    Depending on the version, these functions can include filtering, including or excluding entries from an attack, copying selected information, and exporting results.

    Finally, we have the Help menu.

    This provides access to information and documentation related to Johnny and its usage.

    Now, just below the menu bar, we have the main toolbar.

    You can think of the toolbar as a collection of shortcuts for some of the most commonly used functions.

    The first option is Open Password File.

    This performs essentially the same function as the corresponding option in the File menu.

    It allows us to load our password or hash file into Johnny.

    Next, we have Open Session.

    This allows us to open a previously saved John session and continue working with it.

    Then we have Start New Attack.

    This starts a new password-auditing task using the configuration we've selected.

    The Resume Attack option allows us to continue a previously paused or saved operation.

    Next is Pause Attack.

    As the name suggests, this temporarily pauses the current operation.

    We also have Guess Password, which provides access to password-guessing functionality within Johnny.

    The Copy option allows us to copy selected information from the interface.

    And finally, we have Export, which allows us to export available information or results.


    Now, let's move to the left side of the window. Here, we have the main navigation panel.

    The first section is Passwords.

    This is where we can view the password or hash entries that have been loaded into Johnny.

    Next, we have Options.

    This section is used to configure the current session and select how John the Ripper should perform the password-auditing operation.

    We also have Statistics.

    This section provides information about the current operation, such as progress and other available statistics.

    Next is Settings.

    This contains configuration options related to Johnny and its environment.

    And finally, we have Console Log.

    The console log displays messages generated during the operation, which can help us understand what Johnny and John the Ripper are doing in the background.

    Now, let's move to the Options section.

    This section is used to configure the current Johnny session and choose how John the Ripper should perform the password-auditing task.

    At the top, we have Session Details.

    We'll look at these options and the available attack modes in the next part of the demonstration.

    The first field is Session Name.

    This allows us to give the current session a name. A session name is useful when we want to identify, save, or resume a particular John the Ripper task later.

    Next, we have Input Password Files.

    This shows the password or hash files that will be used as input for the current session.

    Next is Current Hash Format.

    This setting tells John what type of hash it should expect in the input file. At the moment, it is set to Default.

    John may try to identify the hash format automatically, but when we already know the format, specifying it explicitly can help avoid detection problems.

    For example, our previous laboratory example used a raw MD5 hash.

    One useful message displayed here is:

    “Modified attack options come into effect only when starting a new attack.”

    This means that if we change an attack setting, the new configuration will be applied when we start a new attack. Changing an option does not automatically modify an attack that is already running.

    Now, let's look at the Attack Mode section.

    Johnny provides several attack modes, and each mode uses a different method for generating or testing password candidates.


    Let's go through them one by one.

    Default

    The Default mode uses John's normal sequence of attack modes with the default configuration.

    As shown in Johnny, John may run Single Crack mode, followed by Wordlist mode, and then Incremental mode.

    This is useful when we want John to use its standard workflow instead of selecting one specific method manually.

    Single Crack

    Next is Single Crack mode.

    This mode is designed to generate password candidates from information associated with the input account or password entry, and then apply John's cracking rules to those candidates.

    The idea is to test likely password variations before moving to broader password-search methods.

    For a demonstration, this mode helps us understand how John can generate candidates from available account information rather than relying only on an external wordlist.

    Wordlist

    Next, we have Wordlist mode.

    This is one of the most commonly used modes in practical password auditing.

    Here, John takes password candidates from a wordlist and tests them against the target hashes.

    For example, we can provide our own laboratory wordlist, such as:

    passwords.txt

    John then processes the candidates from that file and checks for matches.

    This mode is especially useful when we have a relevant and authorized candidate list.

    Incremental

    Next is Incremental mode.

    This mode is designed for a much broader password search.

    Instead of taking candidates only from a predefined wordlist, John generates candidate passwords according to the incremental configuration and tests them.

    The search can become very large, depending on the character set, length, and configuration.

    So, while this mode can be useful for password auditing, it may also require significantly more time and computing resources.

    External

    Next is External mode.

    This mode allows John to use an external program or custom candidate-generation logic to produce password candidates.

    In other words, instead of relying entirely on John's built-in candidate-generation methods, an external mode can provide customized input.

    This is mainly useful for advanced users who need specialized password-generation behavior.

    Mask

    Next is Mask mode.

    Mask-based attacks allow us to describe the expected structure of a password.

    For example, we can specify that certain positions should contain numbers, letters, or other character types.

    This can greatly reduce the search space when we already know something about the password's structure.

    For example, if an authorized test password is known to contain a specific number of characters and a particular character pattern, a mask can represent that pattern.

    Markov

    Next is Markov mode.

    Markov-based password generation uses statistical information about character sequences to prioritize password candidates that are more likely to occur.

    Instead of treating every possible combination equally, it can favor combinations based on learned character-transition probabilities.

    This allows John to focus its search on candidates that are statistically more likely.

    PRINCE

    Finally, we have PRINCE.

    PRINCE is a password-candidate generation technique that works by combining and rearranging words from an input wordlist to create new candidates.

    The name stands for PRobability INfinite Chained Elements.

    This can be useful when passwords are composed of multiple words or word combinations.

    For example, a password might be constructed from several recognizable words rather than being a completely random string.

    So, these are the main attack modes available in the Johnny interface shown here.

    Each mode has a different purpose.

    • Default uses John's standard sequence.
    • Single Crack focuses on candidates derived from account-related information.
    • Wordlist tests candidates from a supplied list.
    • Incremental generates a broader set of candidates.
    • External allows customized candidate generation.
    • Mask searches according to a defined password pattern.
    • Markov prioritizes candidates using statistical character relationships.
    • And PRINCE generates candidates by combining elements from a wordlist.

    For our practical demonstrations, we'll mainly focus on Wordlist mode, because it is straightforward to understand and works well with the controlled laboratory examples we're using.

    Now, let's look at the main working area in the center of the window.

    At the top, we have the Filter field.

    We can use this field to filter the entries displayed in the main list.

    Next, we have Select Columns.

    This allows us to choose which columns should be visible in the results table.

    We also have options such as Show only checked and Show only cracked.

    These options help us narrow down the entries displayed in the list.

    The large area below is where the loaded password hashes and their current status are displayed.

    At the bottom, we have the progress indicator.

    At the moment, it shows zero percent because we haven't started a new attack yet.

    Advantages of Using Johnny over the Command-line Version

    Let’s talk about the Advantages of using Johnny over the Command-line Version:

    • Johnny offers a visually appealing and straightforward user interface, reducing the learning curve for newcomers.
    • The GUI streamlines configuration, letting users adjust settings without dealing with complex command-line options.
    • Johnny provides real-time progress updates during the cracking process, making it easier to monitor and manage ongoing tasks.
    • Johnny features a wizard mode that guides users through the necessary steps to start password cracking without requiring in-depth technical knowledge.
    • The GUI may offer clearer error messages and easier troubleshooting, enhancing the overall user experience.

    So, this gives us a basic understanding of the Johnny interface.

    The graphical interface provides a visual way to configure and interact with many of John the Ripper's functions.

    Now, let's move to the practical part.

    To load our hash file, we'll click on Open Password File. From the menu, we'll select the PASSWD format, which is one of the input formats supported by Johnny.

    Then, a file browser will open, and from here, we'll locate and select our laboratory hash file. Once we click Open, Johnny loads the hashes from the file.

    As you can see, the entries are now displayed in the main working area.

    Now, let's click Start New Attack and see what happens.

    At this point, you may notice that the attack doesn't proceed as expected.

    Why? In our laboratory file, we now have hashes using different algorithms. John needs to know which hash format it should use for the current attack.

    So, we need to select the appropriate hash format.

    Let's go back to Options.

    Under Current Hash Format, we can select the format that matches the hash we want to process.

    For our earlier hashes, that format was raw-MD5. 

    Once we've selected the correct format, we can start a new attack again.

    As you can see, Johnny is now showing the previously recovered passwords.

    You may wonder why it displays passwords even though we haven't selected a wordlist for this new attack?

    The reason is that John keeps previously recovered passwords in its .pot file. So, Johnny can display those stored results instead of needing to recover them again.

    Rather than deleting the .pot file again, let's demonstrate this with a new hash format.

    This time, we'll create a bcrypt password hash. We'll generate it from the terminal using the mkpasswd command.

    Now, change the directory to the /john-lab directory and then run the command to generate the hash:

     ┌──(kali㉿kali)-[~]
    └─$ cd john-lab
    ┌──(kali㉿kali)-[~/john-lab]
    └─$ mkpasswd --method=bcrypt 'CybersecLab123'
    $2b$05$KDq0zNV/iRhdsTV3j9PZ2uPY127yC4SpDRqE8MyBwK1NZagy5bgMe
    ┌──(kali㉿kali)-[~]
    └─$

    The resulting bcrypt value also contains a salt, which is generated as part of the bcrypt process.

    Now we have our bcrypt hash, but it needs to add it to our existing hash.txt file. So, we can run:

    ┌──(kali㉿kali)-[~]
    └─$ mkpasswd method-bcrypt 'CybersecLab123 >> hash.txt
    ┌──(kali㉿kali)-[~]
    └─$ cat hash.txt
    5f4dcc3b5aa765d61d8327deb882cf99
    593ed296028cd517e7e68b5f534cc8c5
    $2b$05$tsBgWbHchen/rajwSKRA1.B/qm6vNu.T3xY2Uh6jNvacFGd6VETWE
    ┌──(kali㉿kali)-[~]
    └─$ 

    Now, let's return to Johnny and load the updated hash file. Once the file is loaded, we can see the entries in the main working area.

    As you can see, a new hash has been added to the list. Johnny has also identified it as a bcrypt hash.

    If we try to start a new attack at this point, we won't get a result. Why?

    Because the password we used to generate this bcrypt hash is not present in our current wordlist.

    So, instead of creating a completely new wordlist, we'll modify our existing passwords.txt file and add the required password candidate.

    Let's create a small custom wordlist for our laboratory. We'll use the cat command together with a here-document using EOF, and then we'll enter our candidate passwords, one per line. And finally, we'll type: EOF

    The final EOF tells the shell that we've reached the end of the input.

    ┌──(kali㉿kali)-[~]
    └─$ cat >> passwords.txt << EOF
    heredoc> CybersecLab
    heredoc> CybersecLab1
    heredoc> CybersecLab123
    heredoc> EOF
    ┌──(kali㉿kali)-[~]
    └─$ 

    Now our custom wordlist has been created; our wordlist is ready, and we're ready to use it.

    Before starting the attack, let's configure the options. Go back to Options and check the Current Hash Format. We can select bcrypt explicitly. Alternatively, if Johnny has already identified the hash correctly, we can leave the format set to Default.

    Next, we need to add our wordlist. Click Browse, locate our passwords.txt file, and select it. 

    Once the wordlist is loaded, we're almost ready to start the attack.

    But first, there's one more thing we need to do. Our hash.txt file contains multiple hashes, and they use different hashing algorithms. We don't want John to process all of them in this particular demonstration.

    So, in the Passwords section, we'll deselect the previously loaded hashes and keep only our bcrypt hash selected.

    This ensures that the current attack is performed only against the bcrypt entry. Now, everything is configured.

    We have selected the correct hash, loaded our wordlist, and deselected the unrelated hashes. We're now ready to start the new attack and see the result.

    As you can see, John processes the candidates from our wordlist, and this time, we have a successful match.

    The password has been recovered for our controlled laboratory hash. This demonstrates an important point about John the Ripper.

    The same John installation can work with many different password formats, but each individual attack needs to use the appropriate format and input configuration, and that is how we can use Johnny to manage a practical password-auditing task through a graphical interface.

    If you still have any doubts or questions about Johnny or John the Ripper, write them in the comments below.

    Community Q&A