CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester has gained access to a Windows workstation and extracted several NTLM hashes using Mimikatz. The tester wants to use these hashes to authenticate to other systems on the network without knowing the plaintext passwords. Which attack technique is the tester planning to use?
- APass-the-Hash
- BPassword Spraying
- CGolden Ticket
- DCredential Stuffing
Show answer & explanationAnswer & explanation
Correct answer: A. Pass-the-Hash
Pass-the-Hash (PtH) is an attack technique that allows an attacker to authenticate to a remote server or service using a user's NTLM hash instead of the plaintext password. Since the tester has already extracted NTLM hashes, PtH is the direct method to reuse these hashes for authentication.
Why the other options are wrong
- B. Password spraying attempts a few common passwords against many accounts to avoid lockout.
- C. Golden Ticket involves forging Kerberos TGTs after compromising the KDC, which is a different attack targeting Kerberos, not directly using extracted NTLM hashes for NTLM authentication.
- D. Credential stuffing involves re-using leaked plaintext username/password pairs across different services.
Pass-the-Hash (PtH)
An attack technique where an attacker authenticates to a remote system or service using a user's NTLM hash (or other password hash) instead of the plaintext password, bypassing the need for cracking the hash.
- Leverages the fact that Windows authentication can use hashes directly.
- Does not require the plaintext password to be known.
- Commonly used after extracting hashes from memory (e.g., with Mimikatz).
- Effective in NTLM-based environments.
Memory trick: Pass-the-Hash: The hash is enough to get through.