Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 46 guests and 1 member online
You are here:
Home
Columns
Linn
[Article]-Video Tutorial: Pass-The-Hash Toolkit
EH-Net
May 22, 2013, 08:38:32 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Columns
>
Linn
(Moderator:
apollo
) >
[Article]-Video Tutorial: Pass-The-Hash Toolkit
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: [Article]-Video Tutorial: Pass-The-Hash Toolkit (Read 16247 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Online
Posts: 4165
Editor-In-Chief
[Article]-Video Tutorial: Pass-The-Hash Toolkit
«
on:
April 06, 2009, 03:16:33 PM »
Another video by Ryan Linn. Same technical goodness. Enjoy!
Permanent link:
[Article]-Video Tutorial: Pass-The-Hash Toolkit
Quote
Ryan Linn
is back with another video for your learning pleasure. This time he gives a video tutorial of an existing toolset, the
Pass-The-Hash Toolkit by Core Security
. Core describes it as, "The Pass-The-Hash Toolkit contains utilities to manipulate the Windows Logon Sessions mantained by the LSA (Local Security Authority) component. These tools allow you to list the current logon sessions with its corresponding NTLM credentials (e.g.: users remotely logged in thru Remote Desktop/Terminal Services), and also change in runtime the current username, domain name, and NTLM hashes (YES, PASS-THE-HASH on Windows!)."
So what does all that mean? As with his other videos, Ryan tackles this topic in a very easy to follow process. So watch along as he integrates the PTH Toolkit in a makeshift penetration test, and shows how an attacker can utilize credentials without ever having to crack a single password. Oh by the way, he cracks them, too. This way he can impersonate a legitimate user without knowing their password, and then again while knowing their password. Ryan then goes one step further with his talk at
ChicagoCon 2009s
on May 9 with fellow EH-Net Columnists, Brian Wilson, when they team up for
Cain BeEF Hash: Snagging Passwords without Popping Boxes
. They not only show you some of their cutting-edge research results, but also perform it in a live demo! Click for
Conference Details
.
Let us know what you think and/or what else you'd like to see from Ryan,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
Jhaddix
Sr. Member
Offline
Posts: 317
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #1 on:
April 06, 2009, 03:31:02 PM »
i'd like to see Ryan do some Middler and SSL strip demos, if he has some time
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
sommersb
Newbie
Offline
Posts: 6
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #2 on:
April 06, 2009, 04:30:47 PM »
Good stuff - I like the hands-on example method in the video...
Thanks!
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #3 on:
April 06, 2009, 07:15:15 PM »
Nice one Linn, just finished watching it. Couldn't expect anything less then another excellent tool from core. Keep up the good work, I'd also like to see those demos Jhaddix mentioned when whoever has time! -Coughs- Gates -Coughs- joking...
Logged
eCPPT, GCIH, OSCP, OSWP
LSOChris
Guest
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #4 on:
April 06, 2009, 08:12:48 PM »
i'm slacking...what videos are you talking about?
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #5 on:
April 07, 2009, 10:16:24 AM »
The Middler & SSL Strip
Logged
eCPPT, GCIH, OSCP, OSWP
Ignatius
Jr. Member
Offline
Posts: 91
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #6 on:
April 08, 2009, 12:48:37 PM »
I posted this question in a different thread but, following advice, I split the post and here's the question about which I'm confused:
There's an administrator logged on locally and don is logged onto the domain (how can this occur on the same XP SP3 PC?). I'm not sure how it's possible to do the Pass the Hash attack. I didn't hear specifically how the network was set up (I assume it was a domain in VMWare). It appears that hashes are retrieved from the local SAM (I realise that a user logged on locally has the hashes stored there, so how would that help in gaining access to the DC? As far as I understand, when the user logs onto the domain, the username and password are checked against the DC and the local SAM is of no relevance. Are don's hashes retrieved from RAM using the utilities in the toolkit?
Sorry if my misunderstanding spreads to others, but maybe it's my interpretation of what you (Ryan) said.
Thanks for your time.
Logged
apollo
Moderator
Full Member
Offline
Posts: 146
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #7 on:
April 08, 2009, 03:17:44 PM »
Let me setup a slightly different scenario that may help this make more sense.
You are at your workstation, and you are logged in via your domain account. You have a patch missing on your machine, and while I am on your network performing a pen test, I scan your machine and notice that it is vulnerable. By exploiting that vulnerability, I am able to get a session that has the privilege of SYSTEM. At this point, you are logged into your workstation with your credentials and I am logged on via SYSTEM. Because windows helps you by ensuring you don't have to enter your password each time you access a resource, I can take your domain credentials, which are stored in memory, and assign them to my session as SYSTEM using iam.exe. Once I have taken your in-memory credentials, I can present them as my own without having to know your password at all.
Once I have your credentials and can impersonate you, then I would use them to go to other machines on the network. If you were a Domain Admin for example, I could use them to perform actions on the domain controllers, or if you had access to a machine that a domain admin was logged in on, then I might move to that machine and perform the same attack again to gain the Domain Admin's credentials.
All of this happens outside the SAM, and for clarity when you log into a machine, your credentials many times are stored locally however. The cached credential feature of windows allows for disconnected use of machines, but also allows for your domain credentials to be stored locally on machines that you have logged into. These credentials can also be attacked and cracked even when you are not on the machine.
If you have any more questions, please let me know.
-Ryan
Logged
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Ignatius
Jr. Member
Offline
Posts: 91
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #8 on:
April 08, 2009, 03:59:58 PM »
Thank you Ryan - that's crystal clear now. My confusion was about the terminology. When you mentioned logged in, I interpreted "logged into the PC" as if it were standalone and not connected to the domain (hence my mentioning SAM). I appreciate now that I (as the victim of your attack) am actually logged onto the domain via the PC on my desk. I realise that you are somewhere else on the network and compromise my system. I was unaware that my domain credentials would be stored in RAM and that Windows uses them every time that I access a resource. When you've explained it as clearly as you have, it all makes perfect sense and it would be a real pain to have an annoying username/password dialogue every time I wanted to access something!
Thank you for your efforts and, like others, I am looking forward to your future video tutorials.
Logged
jason
Hero Member
Offline
Posts: 1012
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #9 on:
April 08, 2009, 08:39:48 PM »
Hey cool stuff Ryan. You da man!
Logged
impelse
Hero Member
Offline
Posts: 565
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #10 on:
April 10, 2009, 02:12:17 PM »
Great video.
Everything looks very easy, but I know we have to lern to much to do it and understand how to get the box. Hopely after my MCSA and Linux+ I will go for CEH.
Great video again and thanks.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: [Article]-Video Tutorial: Pass-The-Hash Toolkit
«
Reply #11 on:
April 15, 2009, 02:58:30 AM »
Maybe I'm late on this one (not sure if anyone's posted anything on it) but I just saw a video on SSLStrip on John Strands page:
http://vimeo.com/3970303
It's a damn good video too, very well explained. Hope it helps!
Logged
eCPPT, GCIH, OSCP, OSWP
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ldlxnqk
(2) by
ROMETORMEPT
News Items and General Discussion About EH-Net
: happy-birthday-cards-19.txt
(0) by
Agighgype
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.