CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has obtained several NTLM hashes from a Windows server. The tester wants to crack these hashes using a GPU-accelerated tool. Which of the following 'hashcat' commands would be used to perform a dictionary attack against NTLM hashes?

  1. A'hashcat -m 1000 -a 0 hashes.txt wordlist.txt'
  2. B'hashcat -m 500 -a 3 hashes.txt ?a?a?a?a'
  3. C'hashcat -m 0 -a 0 hashes.txt wordlist.txt'
  4. D'hashcat -m 1800 -a 0 hashes.txt wordlist.txt'
Show answer & explanation

Correct answer: A. 'hashcat -m 1000 -a 0 hashes.txt wordlist.txt'

For NTLM hashes, 'hashcat' uses mode 1000. The '-a 0' specifies a dictionary attack, and 'hashes.txt' and 'wordlist.txt' are the input files for hashes and the wordlist, respectively.

Why the other options are wrong

  • B. Mode 500 is for LM hashes, not NTLM, and '-a 3' specifies a brute-force attack with a mask, not a dictionary attack.
  • C. Mode 0 is for MD5, not NTLM hashes.
  • D. Mode 1800 is for SHA-512 crypt, not NTLM hashes.

Hashcat NTLM Dictionary Attack

Using the 'hashcat' tool to crack NTLM password hashes by comparing them against a list of words or phrases from a dictionary file.

  • Requires 'hashcat -m 1000' for NTLM hash type.
  • Uses '-a 0' for straight/dictionary attack mode.
  • Input files are the hash list and the wordlist.

Memory trick: Hashcat hammers keys; remember the mode and attack type.

More Post-exploitation and Lateral Movement questions