Systems rarely store passwords in plain text; they store hashes, one-way transformations of the password. When a tester recovers these hashes during an authorized engagement, password cracking attempts to discover the original passwords by hashing guesses and comparing. Tools like Hashcat and John the Ripper make this fast and flexible. Understanding cracking reveals why weak passwords and poor hashing are dangerous, and, crucially, why strong hashing and good policy are the defenses that render it impractical.
Analogy🏏Cricket
🏏 Think of it like cricket: Active recon is the captain walking out to inspect the pitch on match morning, pressing the surface, checking the grass, watching how the ball behaves in the nets. Unlike studying old footage from afar, this inspection happens on the ground itself and is visible to everyone. Just as that inspection reveals conditions no video could, active scanning reveals live services no public record shows, and just as it happens with the ground's permission, scanning happens only within authorized scope.