Conversation
s3inlc
added this pull request to stack #2501
September 18, 2026 12:49
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
4 times, most recently
from
September 22, 2026 13:03
e269582 to
9d021d6
Compare
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
from
September 22, 2026 13:53
9d021d6 to
c8a1918
Compare
s3inlc
marked this pull request as ready for review
September 22, 2026 14:28
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
from
September 23, 2026 07:29
c8a1918 to
30163c7
Compare
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
2 times, most recently
from
September 23, 2026 09:13
535f20a to
8a04aec
Compare
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
from
September 23, 2026 09:43
8a04aec to
025b5ae
Compare
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
2 times, most recently
from
September 23, 2026 13:03
4b1373f to
a6e187f
Compare
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
3 times, most recently
from
September 24, 2026 10:00
68f0b48 to
44a6360
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical archive execution, path traversal, cleanup, and resource-safety issues remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 5
Open (10)
tempnam failure can trigger deletion from filesystem root · New Symlinked directories enable cleanup outside temp directory · New Unbounded archive extraction permits compression bombs · New User-controlled binaries execute with worker privileges · New binaryName path traversal enables execution outside temp directory · New ACL bypass in hashcat binary classification · New Initial hashcat scan lacks a stored archive · New Unread stdout pipe can deadlock archive extraction · New Blocking pipe reads bypass scan timeout enforcement · New Running scan jobs can be deleted while still executing · New
What changed in this PR
Adds background scanning of hashcat binaries to detect supported hash modes and synchronize associations.
Changes:
- Adds scan jobs, migration/startup seeding, and cleanup.
- Extracts archives, executes binaries, parses modes, and updates associations.
- Restricts manual hashcat edits and adds tests and Docker support.
| File | Description |
|---|---|
src/migrations/postgres/20260918091600_cracker-binary-hashtypes.sql |
Queues PostgreSQL scans. |
src/migrations/mysql/20260918091600_cracker-binary-hashtypes.sql |
Queues MySQL scans. |
src/inc/utils/HashtypeUtils.php |
Supports system-created hash types. |
src/inc/utils/CrackerUtils.php |
Manages scan jobs and associations. |
src/inc/utils/CrackerScanUtils.php |
Extracts archives and scans binaries. |
src/inc/startup/setup.php |
Queues initial scans. |
src/inc/jobs/handlers/ScanCrackerJob.php |
Executes scan jobs. |
src/inc/jobs/BackgroundJobRegistry.php |
Registers the scan handler. |
src/inc/handlers/CrackerHandler.php |
Passes user context on updates. |
src/inc/defines/DBackgroundJobType.php |
Defines the scan job type. |
src/inc/apiv2/model/CrackerBinaryAPI.php |
Restricts manual hashcat associations. |
Dockerfile |
Installs 7-Zip. |
ci/phpunit/inc/utils/HashtypeUtilsTest.php |
Updates hash type tests. |
ci/phpunit/inc/utils/CrackerUtilsTest.php |
Tests scan queuing and synchronization. |
ci/phpunit/inc/utils/CrackerScanUtilsTest.php |
Tests output parsing. |
ci/phpunit/inc/jobs/ScanCrackerJobTest.php |
Tests scan execution. |
ci/phpunit/fixtures/crackerscan/hashcat_example_hashes.json |
Provides parser fixture data. |
ci/apiv2/utils.py |
Adjusts background-job cleanup. |
ci/apiv2/test_cracker.py |
Adds API and scan tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
from
October 1, 2026 06:45
826807a to
4151699
Compare
… link outside of the archive)
…pply associations for hashcat
…atches the supported ones from the cracker binary
…ixed the missing hashtypes to fix inconsistency
… the currently actual hashcat release we ship with hashtopolis
s3inlc
force-pushed
the
886-stack-5-hashcat-scan
branch
from
October 1, 2026 12:59
4c0e73d to
4c66bcf
Compare
jessevz
approved these changes
Oct 2, 2026
jessevz
reviewed
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Adds automatic detection of the hash types supported by hashcat binaries.
When a hashcat binary is added or updated, a background scan reads its supported hash modes and updates its hash type associations accordingly. Re-scanning reflects changes between binary versions by adding newly supported modes and removing modes that are no longer available.
Hash modes that do not yet exist in Hashtopolis are created automatically using the name, salted status, and slow-hash information reported by hashcat. Existing hash types are left unchanged.
Because hashcat associations are determined by the binary itself, they cannot be edited manually. Other cracker types are not scanned and continue to support manually managed associations.
Existing hashcat binaries are queued for scanning during migration, and pending scan jobs are cleaned up when their associated binaries are deleted.