CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester has gained initial access to a Windows server and discovered a password hash in the NTLM format. They need to crack this hash to potentially gain access to other systems or escalate privileges. Which tool is specifically designed for high-performance password cracking and supports the NTLM hash type?

  1. AHashcat
  2. BMetasploit's `auxiliary/analyze/jtr_smb_hashdump`
  3. CJohn the Ripper
  4. DCain & Abel
Show answer & explanation

Correct answer: A. Hashcat

Hashcat is a highly optimized, GPU-accelerated password cracking tool that supports a vast array of hash types, including NTLM. It is widely recognized for its speed and efficiency in cracking hashes.

Why the other options are wrong

  • B. Metasploit's jtr_smb_hashdump is a module for *dumping* NTLM hashes, not for cracking them.
  • C. John the Ripper is an excellent password cracker, but Hashcat is generally preferred for its GPU acceleration and broader support for modern hash types.
  • D. Cain & Abel is an older Windows-only tool primarily for network sniffing and local password cracking, but it's largely deprecated and not as powerful or versatile as Hashcat.

Hashcat NTLM Cracking

Hashcat is a powerful, GPU-accelerated password recovery utility that can efficiently crack NTLM (NT LAN Manager) hashes using various attack modes like dictionary, brute-force, and hybrid attacks.

  • GPU-accelerated for high performance.
  • Supports numerous hash types, including NTLM.
  • Offers various attack modes (dictionary, brute-force, hybrid, mask).
  • Widely used in penetration testing for password cracking.

Memory trick: HASHCAT Cracks NTLM Fast

More Reconnaissance and Enumeration questions