CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is conducting an internal assessment and has gained access to a Windows workstation. They dump credentials from memory using Mimikatz and obtain the following NTLM hash for the `Administrator` account: `Administrator:::1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::`. The tester wants to quickly use this hash to authenticate to other systems without needing the plaintext password. Which technique should the tester employ?

  1. AAS-REP Roasting
  2. BKerberoasting
  3. CGolden Ticket
  4. DPass-the-Hash (PtH)
Show answer & explanation

Correct answer: D. Pass-the-Hash (PtH)

Pass-the-Hash (PtH) is a post-exploitation technique where an attacker uses a user's NTLM hash to authenticate to other network services or systems without ever needing to know the plaintext password. Since the tester already has the NTLM hash, PtH is the direct method to reuse it for authentication.

Why the other options are wrong

  • A. AS-REP Roasting is for retrieving hashes of users that don't require Kerberos preauthentication, not for using an existing hash.
  • B. Kerberoasting is for retrieving service account hashes, not using an already obtained hash for authentication.
  • C. Golden Ticket requires the `krbtgt` hash and is used to forge Kerberos TGTs, which is a different scenario.

Pass-the-Hash (PtH)

A post-exploitation technique where an attacker authenticates to a remote system or service using the NTLM hash of a user's password, rather than the plaintext password. This bypasses the need for cracking the hash.

  • Uses NTLM hash directly for authentication.
  • Bypasses plaintext password requirement.
  • Effective in Windows environments, especially with NTLM authentication.

Memory trick: Windows auth: Hash reuse, Ticket forge, Service crack, Preauth grab.

More Attacks and Exploits questions