Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 59 guests and 4 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Linnarrow [Article]-Video Tutorial: Pass-The-Hash Toolkit
EH-Net
February 09, 2012, 08:59:36 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Video Tutorial: Pass-The-Hash Toolkit  (Read 13596 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3843


Editor-In-Chief


View Profile WWW
« on: April 06, 2009, 03:16:33 PM »

Another video by Ryan Linn. Same technical goodness. Enjoy!

Permanent link: [Article]-Video Tutorial: Pass-The-Hash Toolkit

Quote



Ryan Linn is back with another video for your learning pleasure. This time he gives a video tutorial of an existing toolset, the Pass-The-Hash Toolkit by Core Security. Core describes it as, "The Pass-The-Hash Toolkit contains utilities to manipulate the Windows Logon Sessions mantained by the LSA (Local Security Authority) component. These tools allow you to list the current logon sessions with its corresponding NTLM credentials (e.g.: users remotely logged in thru Remote Desktop/Terminal Services), and also change in runtime the current username, domain name, and NTLM hashes (YES, PASS-THE-HASH on Windows!)."

So what does all that mean? As with his other videos, Ryan tackles this topic in a very easy to follow process. So watch along as he integrates the PTH Toolkit in a makeshift penetration test, and shows how an attacker can utilize credentials without ever having to crack a single password. Oh by the way, he cracks them, too. This way he can impersonate a legitimate user without knowing their password, and then again while knowing their password. Ryan then goes one step further with his talk at ChicagoCon 2009s on May 9 with fellow EH-Net Columnists, Brian Wilson, when they team up for Cain BeEF Hash: Snagging Passwords without Popping Boxes. They not only show you some of their cutting-edge research results, but also perform it in a live demo! Click for Conference Details.


Let us know what you think and/or what else you'd like to see from Ryan,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #1 on: April 06, 2009, 03:31:02 PM »

i'd like to see Ryan do some Middler and SSL strip demos, if he has some time Wink
Logged

sommersb
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #2 on: April 06, 2009, 04:30:47 PM »

Good stuff - I like the hands-on example method in the video...

Thanks!
Logged
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #3 on: April 06, 2009, 07:15:15 PM »

Nice one Linn, just finished watching it. Couldn't expect anything less then another excellent tool from core. Keep up the good work, I'd also like to see those demos Jhaddix mentioned when whoever has time! -Coughs- Gates -Coughs- joking... Tongue
Logged

OSCP, OWSP, eCPPT
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1166


View Profile WWW
« Reply #4 on: April 06, 2009, 08:12:48 PM »

i'm slacking...what videos are you talking about?
Logged

...tests i took go here...

http://carnal0wnage.attackresearch.com/
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #5 on: April 07, 2009, 10:16:24 AM »

The Middler  & SSL Strip  Cool
Logged

OSCP, OWSP, eCPPT
Ignatius
Jr. Member
**
Offline Offline

Posts: 90


View Profile
« Reply #6 on: April 08, 2009, 12:48:37 PM »

I posted this question in a different thread but, following advice, I split the post and here's the question about which I'm confused:

There's an administrator logged on locally and don is logged onto the domain (how can this occur on the same XP SP3 PC?).  I'm not sure how it's possible to do the Pass the Hash attack.  I didn't hear specifically how the network was set up (I assume it was a domain in VMWare).  It appears that hashes are retrieved from the local SAM (I realise that a user logged on locally has the hashes stored there, so how would that help in gaining access to the DC?  As far as I understand, when the user logs onto the domain, the username and password are checked against the DC and the local SAM is of no relevance.  Are don's hashes retrieved from RAM using the utilities in the toolkit?

Sorry if my misunderstanding spreads to others, but maybe it's my interpretation of what you (Ryan) said.

Thanks for your time.
Logged
apollo
Moderator
Full Member
*****
Offline Offline

Posts: 142


View Profile WWW
« Reply #7 on: April 08, 2009, 03:17:44 PM »

Let me setup a slightly different scenario that may help this make more sense. 

You are at your workstation, and you are logged in via your domain account.  You have a patch missing on your machine, and while I am on your network performing a pen test, I scan your machine and notice that it is vulnerable.  By exploiting that vulnerability, I am able to get a session that has the privilege of SYSTEM.  At this point, you are logged into your workstation with your credentials and I am logged on via SYSTEM.  Because windows helps you by ensuring you don't have to enter your password each time you access a resource, I can take your domain credentials, which are stored in memory,  and assign them to my session as SYSTEM using iam.exe.  Once I have taken your in-memory credentials, I can present them as my own without having to know your password at all.

Once I have your credentials and can impersonate you, then I would use them to go to other machines on the network.  If you were a Domain Admin for example, I could use them to perform actions on the domain controllers, or if you had access to a machine that a domain admin was logged in on, then I might move to that machine and perform the same attack again to gain the Domain Admin's credentials. 

All of this happens outside the SAM, and for clarity when you log into a machine, your credentials many times are stored locally however.  The cached credential feature of windows allows for disconnected use of machines, but also allows for your domain credentials to be stored locally on machines that you have logged into.   These credentials can also be attacked and cracked even when you are not on the machine.

If you have any more questions, please let me know.
-Ryan
Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Ignatius
Jr. Member
**
Offline Offline

Posts: 90


View Profile
« Reply #8 on: April 08, 2009, 03:59:58 PM »

Thank you Ryan - that's crystal clear now.  My confusion was about the terminology.  When you mentioned logged in, I interpreted "logged into the PC" as if it were standalone and not connected to the domain (hence my mentioning SAM).  I appreciate now that I (as the victim of your attack) am actually logged onto the domain via the PC on my desk.  I realise that you are somewhere else on the network and compromise my system.  I was unaware that my domain credentials would be stored in RAM and that Windows uses them every time that I access a resource.  When you've explained it as clearly as you have, it all makes perfect sense and it would be a real pain to have an annoying username/password dialogue every time I wanted to access something!

Thank you for your efforts and, like others, I am looking forward to your future video tutorials.
Logged
jason
Hero Member
*****
Offline Offline

Posts: 923



View Profile
« Reply #9 on: April 08, 2009, 08:39:48 PM »

Hey cool stuff Ryan. You da man!
Logged
impelse
Sr. Member
****
Offline Offline

Posts: 465


View Profile
« Reply #10 on: April 10, 2009, 02:12:17 PM »

Great video.

Everything looks very easy, but I know we have to lern to much to do it and understand how to get the box. Hopely after my MCSA and Linux+ I will go for CEH.

Great video again and thanks.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security, Working Windows 7 70-680
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #11 on: April 15, 2009, 02:58:30 AM »

Maybe I'm late on this one (not sure if anyone's posted anything on it) but I just saw a video on SSLStrip on John Strands page:

http://vimeo.com/3970303

It's a damn good video too, very well explained. Hope it helps! Cool
Logged

OSCP, OWSP, eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.57 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.