CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy

A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to quickly obtain password hashes from the local system for offline cracking. Which 'Metasploit' command would achieve this MOST efficiently?

  1. A'getsystem'
  2. B'mimikatz'
  3. C'hashdump'
  4. D'upload /etc/shadow C:\temp\shadow.txt'
Show answer & explanation

Correct answer: C. 'hashdump'

The 'hashdump' command in Meterpreter is specifically designed to extract password hashes from the local SAM database on a Windows system, provided the session has sufficient privileges.

Why the other options are wrong

  • A. 'getsystem' is used for privilege escalation to SYSTEM, not for dumping hashes directly.
  • B. 'mimikatz' is a separate tool for extracting cleartext passwords and hashes, but it's typically loaded as a module or run as an external command, not a direct Meterpreter command for hash dumping.
  • D. This command is for uploading files and '/etc/shadow' is a Linux file, not relevant for a Windows system.

Meterpreter 'hashdump'

A Meterpreter command used to extract NTLM password hashes from the Security Account Manager (SAM) database on a compromised Windows system.

  • Requires SYSTEM privileges or equivalent.
  • Outputs hashes in a format suitable for cracking tools like Hashcat.
  • Automates the process of extracting local user hashes.

Memory trick: Meterpreter helps you unlock the computer's secrets with commands.

More Post-exploitation and Lateral Movement questions