Mind Maps

<aside> <img src="/icons/ticket-admission_red.svg" alt="/icons/ticket-admission_red.svg" width="40px" />

Pass the Hash (PtH)

</aside>

A Pass the Hash (PtH) attack is a technique where an attacker uses a password hash instead of the plain text password for authentication. The attacker doesn't need to decrypt the hash to obtain a plaintext password. PtH attacks exploit the authentication protocol, as the password hash remains static for every session until the password is changed.

Hashes can be obtained in several ways, including:

NTLM

With NTLM, passwords stored on the server and domain controller are not "salted," which means that an adversary with a password hash can authenticate a session without knowing the original password. We call this a Pass the Hash (PtH) Attack.

Pass the Hash with Mimikatz (Windows)

The first tool we will use to perform a Pass the Hash attack is Mimikatz. Mimikatz has a module named sekurlsa::pth that allows us to perform a Pass the Hash attack by starting a process using the hash of the user's password. To use this module, we will need the following:

Pass the Hash = Token Impersonation

First, let’s search another hashes using mimikatz