CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester has gained initial access to a Windows server and discovered a password hash in the NTLM format. They need to crack this hash to potentially gain access to other systems or escalate privileges. Which tool is specifically designed for high-performance password cracking and supports the NTLM hash type?
- AHashcat
- BMetasploit's `auxiliary/analyze/jtr_smb_hashdump`
- CJohn the Ripper
- DCain & Abel
Show answer & explanationAnswer & explanation
Correct answer: A. Hashcat
Hashcat is a highly optimized, GPU-accelerated password cracking tool that supports a vast array of hash types, including NTLM. It is widely recognized for its speed and efficiency in cracking hashes.
Why the other options are wrong
- B. Metasploit's jtr_smb_hashdump is a module for *dumping* NTLM hashes, not for cracking them.
- C. John the Ripper is an excellent password cracker, but Hashcat is generally preferred for its GPU acceleration and broader support for modern hash types.
- D. Cain & Abel is an older Windows-only tool primarily for network sniffing and local password cracking, but it's largely deprecated and not as powerful or versatile as Hashcat.
Hashcat NTLM Cracking
Hashcat is a powerful, GPU-accelerated password recovery utility that can efficiently crack NTLM (NT LAN Manager) hashes using various attack modes like dictionary, brute-force, and hybrid attacks.
- GPU-accelerated for high performance.
- Supports numerous hash types, including NTLM.
- Offers various attack modes (dictionary, brute-force, hybrid, mask).
- Widely used in penetration testing for password cracking.
Memory trick: HASHCAT Cracks NTLM Fast