CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester has obtained a password hash from a compromised system and needs to crack it using a wordlist. The hash is identified as an NTLM hash. Which hashcat mode would be used to perform this cracking operation?

  1. Ahashcat -m 1000 -a 0 <hash_file> <wordlist>
  2. Bhashcat -m 500 -a 0 <hash_file> <wordlist>
  3. Chashcat -m 1800 -a 0 <hash_file> <wordlist>
  4. Dhashcat -m 0 -a 0 <hash_file> <wordlist>
Show answer & explanation

Correct answer: A. hashcat -m 1000 -a 0 <hash_file> <wordlist>

Hashcat mode 1000 is specifically designated for NTLM hashes. The '-a 0' flag specifies a dictionary (wordlist) attack, which is appropriate for cracking hashes with a given wordlist.

Why the other options are wrong

  • B. Mode 500 is for SHA-1 hashes.
  • C. Mode 1800 is for SHA-512crypt (Unix) hashes.
  • D. Mode 0 is for MD5 hashes.

Hashcat NTLM Cracking

Using Hashcat, a powerful password cracking utility, to break NTLM (NT LAN Manager) password hashes, typically through dictionary attacks, brute-force, or hybrid attacks.

  • NTLM hashes are commonly found in Windows environments.
  • Hashcat mode '1000' is used for NTLM hashes.
  • The '-a 0' flag specifies a dictionary attack.
  • Requires a wordlist for dictionary attacks.

Memory trick: Hashcat's modes unlock secrets.

More Reconnaissance and Enumeration questions