CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has obtained several NTLM hashes from a Windows server. The tester wants to crack these hashes using a GPU-accelerated tool. Which of the following 'hashcat' commands would be used to perform a dictionary attack against NTLM hashes?
- A'hashcat -m 1000 -a 0 hashes.txt wordlist.txt'
- B'hashcat -m 500 -a 3 hashes.txt ?a?a?a?a'
- C'hashcat -m 0 -a 0 hashes.txt wordlist.txt'
- D'hashcat -m 1800 -a 0 hashes.txt wordlist.txt'
Show answer & explanationAnswer & explanation
Correct answer: A. 'hashcat -m 1000 -a 0 hashes.txt wordlist.txt'
For NTLM hashes, 'hashcat' uses mode 1000. The '-a 0' specifies a dictionary attack, and 'hashes.txt' and 'wordlist.txt' are the input files for hashes and the wordlist, respectively.
Why the other options are wrong
- B. Mode 500 is for LM hashes, not NTLM, and '-a 3' specifies a brute-force attack with a mask, not a dictionary attack.
- C. Mode 0 is for MD5, not NTLM hashes.
- D. Mode 1800 is for SHA-512 crypt, not NTLM hashes.
Hashcat NTLM Dictionary Attack
Using the 'hashcat' tool to crack NTLM password hashes by comparing them against a list of words or phrases from a dictionary file.
- Requires 'hashcat -m 1000' for NTLM hash type.
- Uses '-a 0' for straight/dictionary attack mode.
- Input files are the hash list and the wordlist.
Memory trick: Hashcat hammers keys; remember the mode and attack type.