Summary
Future work (defer until John the Ripper agent support lands; aligns with the engine-routing roadmap). The keyspace calculator currently assumes hashcat mask/charset semantics. JtR masks, charsets, and incremental modes differ, so a single hardcoded calculator will produce wrong keyspaces for JtR attacks.
What's needed
- Abstract keyspace computation per engine so hashcat vs JtR masks compute correctly (e.g. an engine-keyed strategy:
keyspaceFor(engine, attack)).
- Keep
packages/backend/src/services/keyspace.ts (currently hashcat charset map + mask parser) behind that abstraction.
- JtR specifics to research: JtR mask syntax + custom charsets,
--mask vs --incremental keyspace, and how JtR reports/estimates keyspace.
Dependencies
- Requires the JtR engine integration (agent engine selection / engine-aware routing) to exist first.
- Builds on the hashcat masklist-keyspace follow-up.
Context
Raised during a live /critique of PR #226 ("we also need to think about supporting JtR agents"). Deferred per project owner since there is a later plan to implement John.
Summary
Future work (defer until John the Ripper agent support lands; aligns with the engine-routing roadmap). The keyspace calculator currently assumes hashcat mask/charset semantics. JtR masks, charsets, and incremental modes differ, so a single hardcoded calculator will produce wrong keyspaces for JtR attacks.
What's needed
keyspaceFor(engine, attack)).packages/backend/src/services/keyspace.ts(currently hashcat charset map + mask parser) behind that abstraction.--maskvs--incrementalkeyspace, and how JtR reports/estimates keyspace.Dependencies
Context
Raised during a live
/critiqueof PR #226 ("we also need to think about supporting JtR agents"). Deferred per project owner since there is a later plan to implement John.