CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A penetration tester is performing an internal network assessment. They discover that several legacy Windows servers are configured to use LM hashes for authentication, in addition to NTLM. The tester captures an LM hash from network traffic. Which of the following tools is most effective for quickly cracking this LM hash?

  1. AMimikatz
  2. BResponder
  3. CJohn the Ripper
  4. DHashcat
Show answer & explanation

Correct answer: D. Hashcat

LM hashes are notoriously weak due to their design (case-insensitivity, fixed-size chunks, lack of salt) and are easily cracked. Hashcat is a highly optimized password cracking tool that can crack LM hashes very quickly, often in seconds.

Why the other options are wrong

  • A. Mimikatz is used for extracting credentials from memory, not for cracking hashes captured from network traffic.
  • B. Responder is used for LLMNR/NBT-NS poisoning and capturing hashes, not for cracking them.
  • C. John the Ripper can crack LM hashes but Hashcat is generally faster and more versatile for modern GPU-accelerated cracking.

LM Hash Cracking

The process of recovering plaintext passwords from Lan Manager (LM) hashes, which are very weak and susceptible to rapid cracking due to their design flaws.

  • Case-insensitive passwords are converted to uppercase.
  • Passwords longer than 7 characters are split into two 7-character halves.
  • No salt is used, making them vulnerable to rainbow table attacks.
  • Modern cracking tools like Hashcat can crack them in seconds.

Memory trick: Hashcat cracks fast, John rips, Mimikatz extracts, Responder sniffs.

More Attacks and Exploits questions