CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy
A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to quickly obtain password hashes from the local system for offline cracking. Which 'Metasploit' command would achieve this MOST efficiently?
- A'getsystem'
- B'mimikatz'
- C'hashdump'
- D'upload /etc/shadow C:\temp\shadow.txt'
Show answer & explanationAnswer & explanation
Correct answer: C. 'hashdump'
The 'hashdump' command in Meterpreter is specifically designed to extract password hashes from the local SAM database on a Windows system, provided the session has sufficient privileges.
Why the other options are wrong
- A. 'getsystem' is used for privilege escalation to SYSTEM, not for dumping hashes directly.
- B. 'mimikatz' is a separate tool for extracting cleartext passwords and hashes, but it's typically loaded as a module or run as an external command, not a direct Meterpreter command for hash dumping.
- D. This command is for uploading files and '/etc/shadow' is a Linux file, not relevant for a Windows system.
Meterpreter 'hashdump'
A Meterpreter command used to extract NTLM password hashes from the Security Account Manager (SAM) database on a compromised Windows system.
- Requires SYSTEM privileges or equivalent.
- Outputs hashes in a format suitable for cracking tools like Hashcat.
- Automates the process of extracting local user hashes.
Memory trick: Meterpreter helps you unlock the computer's secrets with commands.