CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester has obtained a password hash from a compromised system and needs to crack it using a wordlist. The hash is identified as an NTLM hash. Which hashcat mode would be used to perform this cracking operation?
- Ahashcat -m 1000 -a 0 <hash_file> <wordlist>
- Bhashcat -m 500 -a 0 <hash_file> <wordlist>
- Chashcat -m 1800 -a 0 <hash_file> <wordlist>
- Dhashcat -m 0 -a 0 <hash_file> <wordlist>
Show answer & explanationAnswer & explanation
Correct answer: A. hashcat -m 1000 -a 0 <hash_file> <wordlist>
Hashcat mode 1000 is specifically designated for NTLM hashes. The '-a 0' flag specifies a dictionary (wordlist) attack, which is appropriate for cracking hashes with a given wordlist.
Why the other options are wrong
- B. Mode 500 is for SHA-1 hashes.
- C. Mode 1800 is for SHA-512crypt (Unix) hashes.
- D. Mode 0 is for MD5 hashes.
Hashcat NTLM Cracking
Using Hashcat, a powerful password cracking utility, to break NTLM (NT LAN Manager) password hashes, typically through dictionary attacks, brute-force, or hybrid attacks.
- NTLM hashes are commonly found in Windows environments.
- Hashcat mode '1000' is used for NTLM hashes.
- The '-a 0' flag specifies a dictionary attack.
- Requires a wordlist for dictionary attacks.
Memory trick: Hashcat's modes unlock secrets.