CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester has gained initial access to a Windows server and discovered a password hash, 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:6b5b15b5e3c3b5d2e0c089c0b73c59d7'. They need to crack this hash to potentially gain access to other accounts. Which tool and mode would be most appropriate for attempting to crack this specific NTLM hash, assuming no salt is present in a standard format?
- ABurp Suite's Intruder function.
- BHashcat with mode 1000 (NTLM).
- CNmap with the 'smb-brute' script.
- DMetasploit with the 'hashdump' module.
Show answer & explanationAnswer & explanation
Correct answer: B. Hashcat with mode 1000 (NTLM).
The provided hash format is characteristic of an NTLM hash (often found in SAM or NTDS.dit). Hashcat is a powerful password cracking tool, and mode 1000 is specifically designated for cracking NTLM hashes. The '31d6...' part is the NTLM hash, and 'aad3...' is often the LM hash, which is usually empty on modern systems.
Why the other options are wrong
- A. Burp Suite's Intruder is for web application brute-forcing, not for cracking standalone password hashes.
- C. Nmap's 'smb-brute' script is for brute-forcing SMB login credentials, not for cracking extracted hashes.
- D. Metasploit's 'hashdump' module is for extracting hashes, not cracking them.
Hashcat NTLM Cracking
Hashcat is a GPU-accelerated password cracker that supports numerous hash types, including NTLM (mode 1000), for offline brute-force or dictionary attacks.
- Mode 1000 is specifically for NTLM hashes.
- Requires a wordlist or rules for effective cracking.
- Leverages GPU acceleration for speed.
Memory trick: Crack passwords with Hashcat, not exploits or scans.