<aside> <img src="/icons/ticket-admission_red.svg" alt="/icons/ticket-admission_red.svg" width="40px" />
</aside>
A Pass the Hash (PtH) attack is a technique where an attacker uses a password hash instead of the plain text password for authentication. The attacker doesn't need to decrypt the hash to obtain a plaintext password. PtH attacks exploit the authentication protocol, as the password hash remains static for every session until the password is changed.
Hashes can be obtained in several ways, including:
With NTLM, passwords stored on the server and domain controller are not "salted," which means that an adversary with a password hash can authenticate a session without knowing the original password. We call this a Pass the Hash (PtH) Attack.
The first tool we will use to perform a Pass the Hash attack is Mimikatz. Mimikatz has a module named sekurlsa::pth that allows us to perform a Pass the Hash attack by starting a process using the hash of the user's password. To use this module, we will need the following:
/user - The user name we want to impersonate./rc4 or /NTLM - NTLM hash of the user's password./domain - Domain the user to impersonate belongs to. In the case of a local user account, we can use the computer name, localhost, or a dot (.)./run - The program we want to run with the user's context (if not specified, it will launch cmd.exe).Pass the Hash = Token Impersonation
First, let’s search another hashes using mimikatz