Courseiva

CCNA Attacking Password Hashes Questions

23 questions · Attacking Password Hashes · All types, answers revealed

1
MCQeasy

During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?

A.Hashcat mode 3200 (bcrypt)
B.Hashcat mode 1800 (sha512crypt)
C.Hashcat mode 500 (md5crypt)
D.Hashcat mode 1500 (DEScrypt)
AnswerB

The '$6$' prefix indicates a SHA-512 crypt hash, commonly used on Linux systems. Hashcat mode 1800 is designed for sha512crypt hashes. Using this mode ensures correct parsing of the salt and hash, allowing efficient cracking. It is the standard mode for modern Linux password hashes.

Why this answer

The '$6$' prefix unambiguously identifies a SHA-512 crypt hash. Hashcat mode 1800 is specifically built for this format, ensuring correct salt handling and efficient cracking. Other modes correspond to different hash algorithms and would not successfully crack the hash.

Exam trap

The trap here is misidentifying the hash type based on prefix, leading to the wrong Hashcat mode.

2
MCQhard

Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?

A.GPUs have larger cache sizes for storing wordlists.
B.GPUs have a faster instruction set for MD4 algorithms.
C.GPUs handle massive parallel operations on simple math.
D.GPUs can bypass the salt requirement during the attack.
AnswerC

Because hashing is a simple mathematical function, a GPU's thousands of parallel cores can compute many hashes simultaneously. CPUs are better at sequential, complex logic, but for raw brute-force tasks, the parallel architecture of a GPU is vastly superior, enabling billions of attempts per second.

Why this answer

GPUs feature thousands of small, specialized cores designed for massive parallel processing, which is ideal for the simple, iterative nature of hashing. While a CPU excels at complex, branch-heavy tasks, a GPU can process thousands of password guesses simultaneously. For an unsalted algorithm like NTLM, this parallelism results in a performance increase of several orders of magnitude, allowing testers to exhaust large keyspaces in seconds rather than days.

Exam trap

Candidates often assume CPUs are better because of higher clock speeds, failing to realize that GPU architecture excels at massive parallel operations required by simple hashing algorithms.

3
MCQhard

Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?

A.Lack of mutual authentication allows for relay attacks.
B.The NTLM hash format does not utilize a salt.
C.NTLM requires a connection to a Domain Controller for every login.
D.The protocol uses hard-coded encryption keys for every session.
E.NTLM hashes are vulnerable to pass-the-hash attacks.
AnswerA, B, E

NTLM does not require the server to prove its identity to the client. This architectural flaw enables attackers to capture a client's authentication challenge and relay it to another server, effectively masquerading as the user without ever having to crack the password or hash.

Why this answer

NTLM is inherently insecure because it is a challenge-response protocol that does not provide mutual authentication, making it susceptible to relay attacks. Furthermore, the NTLM hash is stored in a format that does not include a salt, allowing for the use of precomputed tables. Finally, because NTLM hashes are treated as the 'equivalent' of a password in many contexts, once stolen, they can be reused without needing to crack them.

Exam trap

Candidates often mistakenly believe NTLM is insecure primarily because it is 'too old'. The actual technical reasons involve its fundamental design flaws, specifically the lack of salting and lack of mutual authentication.

4
MCQmedium

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

A.Golden Ticket attack using the KRBTGT hash
B.Pass-the-Hash (PtH) using Mimikatz sekurlsa::pth
C.Kerberoasting to request a service ticket
D.Rainbow table lookup to recover the plaintext password
AnswerB

Pass-the-Hash leverages the NTLM hash to authenticate to remote services without knowing the plaintext password. Mimikatz's sekurlsa::pth command injects the hash into a new session, enabling access to SMB shares or other services that accept NTLM authentication. This is a core technique in penetration testing, as it bypasses the need to crack the hash.

Why this answer

Pass-the-Hash allows an attacker to authenticate using the NTLM hash without cracking it. Tools like Mimikatz can inject the hash into a session, enabling lateral movement or access to resources. Other options involve cracking or forging tickets, which are different attack vectors.

The scenario emphasizes using the hash directly, making Pass-the-Hash the correct technique.

Exam trap

The trap here is confusing Pass-the-Hash with other hash-based attacks like Kerberoasting or Golden Ticket, which require different prerequisites and have different goals.

5
MCQmedium

During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?

A.Mode 1000, targeting local SAM database NTLM hashes.
B.Mode 1300, targeting legacy Windows NT hashes.
C.Mode 5600, targeting NetNTLMv2 network authentication captures.
D.Mode 3000, targeting LM hashes with challenge data.
AnswerC

Mode 5600 is engineered precisely for cracking NetNTLMv2 hashes gathered via protocol coercion or LLMNR poisoning. It correctly structures the username, domain, server challenge, client challenge, and response fields so Hashcat can execute the required HMAC-MD5 cryptographic validation loops during brute-forcing.

Why this answer

Hashcat mode 5600 specifically targets NetNTLMv2 authentication exchanges captured during network sniffing or LLMNR/NBT-NS poisoning attacks. Using the correct mode ensures Hashcat formats the challenge, username, domain, and response fields properly for structural verification and decryption. Selecting incorrect modes results in immediate errors or zero matches during computation, making accurate identification of authentication protocols a vital pentesting skill.

Exam trap

Candidates frequently confuse NTLM (mode 1000, representing the static password hash stored in the Active Directory database) with NetNTLMv2 (mode 5600, representing dynamic network authentication traffic), leading to failed offline attacks.

6
Multi-Selecthard

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)

Select 2 answers
A.Employing a hybrid attack that combines a wordlist with a mask for appending digits.
B.Using a rule-based attack with Hashcat, such as best64.rule, to mutate a wordlist.
C.Using a distributed cracking setup with multiple GPUs to increase hash rate.
D.Performing a brute-force attack with a mask that covers all possible 8-character combinations.
E.Utilizing a precomputed rainbow table for NTLM hashes.
AnswersA, B

A hybrid attack merges dictionary words with a mask, such as appending two digits to each word. This is highly effective against passwords that follow common patterns like 'password123'. Since NTLM hashes are fast to compute, hybrid attacks can quickly test a large number of combinations derived from common words. This technique balances efficiency and coverage, making it a preferred method for penetration testers aiming to recover passwords within a reasonable timeframe. It targets the human tendency to use predictable variations.

Why this answer

Rule-based attacks and hybrid attacks are the most effective because they leverage common password patterns and mutations, which are prevalent in real-world environments. Rule-based attacks apply transformations to wordlists, while hybrid attacks combine words with masks to cover predictable suffixes like digits. Both methods efficiently target likely passwords without the impractical computational cost of full brute-force.

Distributed cracking only increases speed, not the likelihood of success, and rainbow tables are limited and outdated.

Exam trap

The trap here is assuming that brute-force or rainbow tables are the best approaches, when in fact targeted rule-based and hybrid attacks are far more efficient for recovering real-world passwords.

7
MCQhard

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

A.The hash is a salt-based hash requiring a rainbow table.
B.The value represents the plaintext password in hex format.
C.The hash can be used directly for Pass-the-Hash authentication.
D.The session has expired and the hash is now unusable.
AnswerC

In an NTLM authentication flow, the hash is the credential. If an attacker possesses the hash, they can present it to an authentication service, and the service will accept it as proof of identity. This bypasses the need to know the plaintext password entirely.

Why this answer

The exhibit displays a captured NTLM hash. In modern Windows environments, the 'LM' (LAN Manager) portion is often empty or disabled for security, leaving only the NTLM hash. The value shown is a hexadecimal representation of the NTLM hash, which acts as the equivalent of a password for authentication.

A penetration tester can use this specific string to perform a Pass-the-Hash attack without needing to crack it to plaintext.

Exam trap

Candidates often assume they must crack the hash to gain access. They fail to recognize that the NTLM hash itself is sufficient for authentication, making cracking an unnecessary and time-consuming step.

8
MCQeasy

A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?

A.Hashcat mode 0 (MD5)
B.Hashcat mode 5600 (NetNTLMv2)
C.Hashcat mode 13100 (Kerberos 5 TGS-REP)
D.Hashcat mode 1000 (NTLM)
AnswerB

Hashcat mode 5600 is specifically designed for NetNTLMv2 (also called NTLMv2) challenge-response pairs captured from network traffic. It correctly parses the username, domain, server challenge, and response fields to perform an offline dictionary or brute-force attack. This is the correct mode because the scenario involves a captured challenge-response pair, not a raw NT hash. Using the wrong mode would result in errors or no cracks.

Why this answer

Hashcat mode 5600 is the correct choice because it is tailored for NetNTLMv2 challenge-response pairs, which are commonly captured during penetration tests. This mode understands the structure of the NTLMv2 response, including the server challenge and the HMAC-MD5 computation. Other modes target different hash types, such as raw NT hashes or Kerberos tickets, and would not correctly parse or crack the captured NTLMv2 data.

Using the right mode ensures efficient and successful cracking.

Exam trap

The trap here is confusing raw NT hashes (mode 1000) with network-captured NTLMv2 challenge-response pairs (mode 5600), as both relate to NTLM but require different cracking approaches.

9
MCQeasy

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

A.Password policies are easily bypassed by users sharing credentials.
B.Weak algorithms allow rapid recovery of passwords once a breach occurs.
C.Passwords are always transmitted in plain text over the network.
D.The password policy is only effective for local accounts.
AnswerB

If the hashing algorithm is weak or lacks a salt, an attacker can crack the database in bulk regardless of the complexity enforced by the policy. A strong hashing algorithm acts as the final line of defense, rendering stolen hash files useless even when the database is fully compromised.

Why this answer

Even with a strong password policy, an organization remains vulnerable if the hashing algorithm is cryptographically broken or lacks proper salting. A weak algorithm like MD5 or NTLM allows attackers to crack even complex passwords almost instantaneously using modern hardware. Evaluating the hashing implementation ensures that the organization is protected against offline attacks, providing a necessary layer of defense that policies alone cannot guarantee if the underlying data storage mechanism is compromised.

Exam trap

Candidates often assume that if a password policy is sufficiently strict, the underlying hashing algorithm becomes irrelevant. They fail to realize that offline attacks bypass policy enforcement entirely by targeting stored hashes.

10
MCQhard

During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?

A.The TGS ticket contains the service account's plaintext password, which can be read directly from the ticket.
B.The TGS ticket is encrypted with the KRBTGT account's hash, allowing the attacker to forge golden tickets.
C.The TGS ticket is encrypted with the service account's NT hash, which can be cracked offline without contacting the domain controller.
D.The TGS ticket is signed with the domain's private key, which can be cracked to reveal the domain administrator's password.
AnswerC

Kerberoasting is effective because the TGS ticket is encrypted with the service account's NT hash (for RC4-HMAC). An attacker who requests a service ticket can extract it and attempt to crack the encryption offline, without further interaction with the domain controller. This allows stealthy password recovery. The scenario specifies RC4-HMAC encryption, which is particularly vulnerable because it uses the NT hash directly as the key, making it a prime target for offline cracking.

Why this answer

Kerberoasting works by requesting a TGS ticket for a service account with a registered SPN. The ticket is encrypted with the service account's NT hash, and because RC4-HMAC uses the NT hash directly as the encryption key, an attacker can extract the ticket and crack it offline. This avoids detection and does not require further domain controller interaction.

The other options misidentify the encryption key or the attack's goal, such as forging golden tickets or extracting plaintext passwords, which are not part of Kerberoasting.

Exam trap

The trap here is confusing Kerberoasting with Golden Ticket attacks, where the former targets service account TGS tickets encrypted with the service account's hash, while the latter forges TGTs using the KRBTGT hash.

11
MCQmedium

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

A.Use the hashes to perform a Pass-the-Hash attack on every server.
B.Submit the hashes to an online cloud-based cracking service.
C.Run Hashcat with a combination of wordlists and mask attacks.
D.Reverse the MD4 algorithm to recover the original string.
AnswerC

Hashcat is the industry standard for offline cracking. By using dictionary files for common passwords and mask attacks for complexity patterns, a tester can efficiently find the password. This method is highly scalable and leverages GPU hardware to test millions of variations per second.

Why this answer

Once NTLM hashes are acquired, the most efficient method to recover the password is using an optimized GPU-based cracking tool like Hashcat. By employing a hybrid attack strategy—starting with a dictionary list supplemented by mask-based brute forcing—the tester can maximize the likelihood of recovering passwords that follow common corporate complexity patterns. This is significantly faster than manual analysis and allows for rapid testing against high-value target accounts.

Exam trap

Candidates often select manual analysis or basic dictionary attacks alone, overlooking the efficiency of hybrid wordlist and mask attacks executed via optimized GPU tools like Hashcat.

12
MCQhard

A penetration tester captures a NetNTLMv2 hash from a network segment using Responder. The tester wants to crack this hash using Hashcat. Which Hashcat mode should be used?

A.2500
B.1000
C.13100
D.5600
AnswerD

Hashcat mode 5600 is specifically for NetNTLMv2 hashes. NetNTLMv2 is the challenge-response protocol used in NTLMv2 authentication, and captured hashes from tools like Responder are in this format. Using mode 5600 ensures Hashcat correctly parses the hash and applies the appropriate cracking algorithm, which involves HMAC-MD5 operations.

Why this answer

NetNTLMv2 hashes captured from network traffic require Hashcat mode 5600. This mode is tailored to the NetNTLMv2 challenge-response format, which uses HMAC-MD5. Other modes correspond to different hash types: 1000 for NTLM, 2500 for NetNTLMv1, and 13100 for Kerberos TGS-REP.

Using the correct mode is essential for successful cracking.

Exam trap

The trap here is assuming all NTLM-related hashes use the same Hashcat mode, but NetNTLMv2, NTLM, and NetNTLMv1 each have distinct modes.

13
MCQmedium

A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?

A.Pass-the-Ticket by injecting a forged Kerberos TGT into memory
B.Kerberoasting the target service account to obtain its TGS ticket
C.Pass-the-Hash using the NT hash directly in an authentication request
D.Rainbow table lookup against the NT hash to recover the plaintext password
AnswerC

Pass-the-Hash exploits the fact that Windows authentication protocols accept the NT hash itself as proof of identity, so a tester can authenticate to SMB, WMI, or other services without cracking the hash. The NT hash is the actual credential material stored in SAM or LSASS, so it can be used directly with tools like Mimikatz or Impacket. This is the correct approach here because the scenario explicitly requires authentication without the plaintext password.

Why this answer

Pass-the-Hash is the correct technique because Windows authentication protocols accept the NT hash as a valid credential. An attacker who extracts the hash can use it to authenticate to remote services without cracking the plaintext. The other options either aim at password recovery or rely on different credential material, such as Kerberos tickets, which are not present in this scenario.

The key distinction is that Pass-the-Hash uses the hash directly for authentication.

Exam trap

The trap here is assuming that an extracted NT hash must be cracked before it can be used for authentication, when in fact the hash itself can be replayed to access resources.

14
MCQmedium

A penetration tester has obtained a set of Linux shadow file hashes. The hashes begin with $6$ and the tester intends to perform an offline brute-force attack using Hashcat. Which mode should the tester select to ensure Hashcat correctly interprets these hashes?

A.500 (md5crypt)
B.1800 (sha512crypt)
C.3200 (bcrypt)
D.1000 (NTLM)
AnswerB

Hashcat mode 1800 corresponds to sha512crypt, which is the algorithm identified by the $6$ prefix in the shadow file hash. This is the correct mode to use because the hash format matches exactly, allowing Hashcat to properly parse and attack the hash. Using any other mode would result in incorrect parsing and failed cracking attempts.

Why this answer

The $6$ prefix in a Linux shadow file indicates the sha512crypt algorithm, which is supported by Hashcat mode 1800. Choosing the correct mode is essential because Hashcat must parse the hash structure, including salt and iteration count, to perform the attack. Other modes correspond to different algorithms and will not work with this hash type.

Exam trap

The trap here is assuming that any hash with a dollar sign prefix is md5crypt, but the number after the dollar sign specifies the algorithm, and $6$ is sha512crypt.

15
MCQmedium

You are conducting an internal penetration test and have obtained a set of NTLM hashes from a compromised server. You want to crack them using Hashcat on a dedicated GPU rig. Which hash mode should you use?

A.Hashcat mode 1800 (sha512crypt)
B.Hashcat mode 13100 (Kerberos 5 TGS-REP)
C.Hashcat mode 1000 (NTLM)
D.Hashcat mode 5500 (NetNTLMv2)
AnswerC

Hashcat mode 1000 is specifically for NTLM (NT LAN Manager) hashes, which are the format of Windows password hashes stored in SAM or extracted from LSASS. This mode correctly parses the 32-character hexadecimal NTLM hash and applies the appropriate cracking algorithms. Using this mode ensures compatibility and optimal performance for cracking NTLM hashes.

Why this answer

NTLM hashes are stored in Windows systems and are commonly extracted during penetration tests. Hashcat mode 1000 is designed to crack these hashes efficiently. Other modes correspond to different hash types, such as NetNTLMv2, Kerberos, or Linux crypt formats, and would not correctly process NTLM hashes.

Exam trap

The trap here is confusing NTLM hashes with NetNTLMv2 challenge-response pairs, which require different hash modes.

16
Multi-Selecthard

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Select 2 answers
A.NTLMv2 hashes can be cracked using precomputed rainbow tables.
B.Hashcat mode 5600 is used for NTLMv2 hashes.
C.Cracking NTLMv2 requires the original server challenge to be included in the hash file.
D.Hashcat can crack NTLMv2 hashes without specifying a wordlist or mask.
E.NTLMv2 hashes are salted with the username, making them more resistant to cracking.
AnswersB, C

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are the challenge-response pairs captured from network traffic. This mode correctly handles the format of NTLMv2 responses, including the server challenge and the HMAC-MD5 construction. Using the correct mode ensures that Hashcat can perform the necessary computations to test candidate passwords against the captured challenge-response.

Why this answer

NTLMv2 challenge-response pairs are cracked using Hashcat mode 5600, and the captured hash must include the server challenge for the computation to be possible. The challenge is unique per authentication, so precomputed tables are useless. The username is part of the hash but does not act as a salt.

An attack mode must always be specified.

Exam trap

The trap here is thinking that NTLMv2 hashes can be cracked with rainbow tables, but the inclusion of a unique server challenge per session prevents precomputation.

17
MCQeasy

During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?

A.John the Ripper
B.Mimikatz
C.Hashcat
D.secretsdump.py
AnswerD

secretsdump.py is part of the Impacket suite and is designed to extract secrets, including password hashes, from Windows systems. It can parse SAM, SYSTEM, and SECURITY registry hives offline to extract NTLM hashes. In this scenario, after extracting the SAM file, the tester can use secretsdump.py to retrieve the hashes, making it the correct tool for this purpose.

Why this answer

secretsdump.py is specifically designed to extract password hashes from Windows registry hives, including SAM, SYSTEM, and SECURITY. It can operate offline on extracted files, making it ideal for this scenario. Mimikatz is more for live memory extraction, while Hashcat and John the Ripper are cracking tools.

Thus, secretsdump.py is the correct choice for extracting hashes from a SAM file.

Exam trap

The trap here is confusing extraction tools with cracking tools, or assuming Mimikatz is always the go-to for any hash extraction, even offline.

18
MCQmedium

A penetration tester is performing an offline attack against a Kerberos TGS-REP hash obtained via Kerberoasting. Which of the following Hashcat modes should be used?

A.19600
B.7500
C.13100
D.1000
AnswerC

Hashcat mode 13100 is specifically for Kerberos 5 TGS-REP etype 23 hashes, which are obtained through Kerberoasting. This mode implements the RC4-HMAC-MD5 algorithm used in etype 23. Using mode 13100 ensures Hashcat correctly parses the TGS-REP hash and performs the appropriate cracking operations, which involve decrypting the ticket with candidate passwords.

Why this answer

Kerberoasting produces a Kerberos 5 TGS-REP hash, typically using RC4 (etype 23). Hashcat mode 13100 is designed for this hash type. Other modes correspond to different Kerberos or NTLM hashes: 19600 for AES TGS-REP, 7500 for AS-REP, and 1000 for NTLM.

Using the correct mode is essential for efficient cracking.

Exam trap

The trap here is confusing Kerberoasting with AS-REP Roasting or assuming all Kerberos hashes use the same mode, but TGS-REP and AS-REP have distinct modes.

19
MCQmedium

Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?

A.Cached credentials only store the user's username.
B.They allow offline authentication, but are stored in plain text.
C.They provide a target for offline cracking to recover domain passwords.
D.They are automatically wiped upon every system reboot.
AnswerC

Cached domain credentials (MSCASH or Domain Cached Credentials) can be dumped from the system and cracked offline. Since these are often cached for many users, an attacker can obtain a large number of domain hashes, significantly increasing the probability of compromising accounts within the target environment.

Why this answer

Windows caches credentials for domain accounts that have previously logged into a machine to allow users to sign in when the domain controller is unavailable. These cached entries, often stored in the registry, can be extracted by an attacker with administrative privileges. This provides a persistent source of credentials that, if cracked, could grant an attacker access to the domain even when the targeted user is not currently logged on.

Exam trap

Candidates often assume cached credentials are encrypted and therefore safe. They underestimate the ease with which an administrator can extract these hashes from the registry for offline cracking.

20
MCQmedium

During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?

A.Hashcat mode 1000 represents standard NTLM password hashes extracted from the Windows SAM database or NTDS.dit.
B.Hashcat mode 3000 handles LANMAN hashes, which are legacy Windows password hashes stored for backwards compatibility on older systems.
C.Hashcat mode 5600 targets NetNTLMv2 hashes captured during network authentication processes like SMB or HTTP challenges.
D.Hashcat mode 13100 is utilized for Kerberos 5 TGS-REP etype 23 hashes gathered through service ticket requests.
AnswerC

Mode 5600 is dedicated to NetNTLMv2, the challenge-response format captured during SMB or HTTP authentication after LLMNR/NBT-NS poisoning. The captured hash contains the server challenge, username and HMAC-MD5 response, which 5600 parses directly, matching the scenario's hash type.

Why this answer

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are generated during SMB authentication challenges captured through poisoning tools like Responder. Understanding these specific hash modes is critical for pentesters to quickly transition from passive or active credential capture to offline brute-forcing and dictionary attacks against Windows domain environments.

Exam trap

Candidates frequently confuse mode 5600 with mode 1000, which is standard NTLM, leading to immediate cracking failures because Hashcat cannot parse the challenge-response structure of NetNTLMv2.

21
MCQmedium

During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?

A.Attempt a brute-force attack on the Kerberos TGT.
B.Perform a Pass-the-Hash attack using the captured hash.
C.Use a social engineering attack to reset the password.
D.Re-run the cracking attack with a longer wordlist.
AnswerB

Pass-the-Hash allows an attacker to authenticate as the user without needing the plaintext password. If the hash was obtained from a valid source, it can be injected into an authentication request, allowing the attacker to access services as if they had successfully cracked the password.

Why this answer

When an NTLM hash cannot be cracked, the most effective alternative is a Pass-the-Hash (PtH) attack. Because NTLM authentication verifies the user based on the knowledge of the hash rather than the plaintext password, an attacker can use the captured hash to authenticate to various network services directly. This approach is highly effective for lateral movement, bypassing the need for plaintext recovery while maintaining the ability to compromise the target system.

Exam trap

Candidates often think an uncrackable hash renders the asset secure, forgetting that authentication mechanisms accept the hash directly without requiring plaintext recovery.

22
MCQmedium

Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?

A.Monitoring for high CPU usage on all workstations.
B.Logging access to the LSASS process and SAM hives.
C.Scanning for the use of the Hashcat tool on the network.
D.Monitoring for network traffic to known cracking websites.
AnswerB

Credential dumping tools must interact with the LSASS process or read the SAM registry hive to obtain hashes. Monitoring these specific, high-risk actions provides a direct alert for the activity that enables offline cracking, allowing security teams to respond before the hashes are successfully exfiltrated from the network.

Why this answer

Detecting an offline attack is challenging because the actual computation happens on the attacker's hardware. However, the initial phase—dumping the hashes from memory or the SAM file—requires access to sensitive system files or processes. By monitoring for access to the LSASS process or reading the SAM/SYSTEM registry hives, security teams can identify the signature of a credential dumping attempt, which is the necessary precursor to any offline attack.

Exam trap

Candidates mistakenly look for network traffic indicators of offline cracking, forgetting that the actual password guessing computation occurs entirely offline on the attacker's isolated machine.

23
MCQmedium

During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?

A.Mode 1000, which targets local Windows SAM NT hashes extracted from a compromised registry hive export.
B.Mode 5500, which is designed exclusively for cracking legacy NTLMv1 network authentication challenge-response pairs.
C.Mode 5600, which targets NetNTLMv2 hashes captured during network authentication events or LLMNR/NBT-NS spoofing attacks.
D.Mode 3000, which processes LanMan hashes historically found on very old Windows NT and 95 operating systems.
AnswerC

Mode 5600 targets the NetNTLMv2 challenge-response format, which is exactly what a captured NTLMv2 pair represents — not the stored NTLM hash (mode 1000). Hashcat reconstructs the HMAC-MD5 response using the captured server challenge, so GPU cracking proceeds efficiently against the network-captured pair.

Why this answer

Hashcat utilizes mode 5600 specifically for NetNTLMv2 hashes, which allows leveraging high-speed GPU acceleration to perform dictionary and mask attacks against captured enterprise authentication handshakes. Selecting the correct mode ensures hashcat parses the challenge, username, domain, and response fields accurately according to the standard NTLMv2 response format specification.

Exam trap

Candidates frequently confuse NTLMv1 and NTLMv2 modes in Hashcat, or attempt to use mode 1000 which is meant for the local SAM NT hash rather than network authentication captures.

Ready to test yourself?

Try a timed practice session using only Attacking Password Hashes questions.