Courseiva

CCNA Password Attacks Questions

23 questions · Password Attacks topic · All types, answers revealed

1
MCQeasy

When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?

A.It increases the number of accounts that can be compromised simultaneously.
B.It is faster for the tool to process a single password.
C.It prevents the detection of the attack by network firewalls.
D.It guarantees that the password will be found for every user.
AnswerA

Spraying a single common password across many accounts increases the statistical likelihood of hitting at least one user who utilizes that password. This method is specifically designed to maximize credential acquisition while staying beneath the radar of lockout policies that are configured to monitor individual account failures.

Why this answer

Password spraying leverages the low frequency of attempts per account to evade account lockout thresholds while maximizing the probability of finding at least one compromised credential. This approach is highly effective in enterprise environments where account policies restrict the number of failed login attempts per user. By spreading attempts, an attacker bypasses these security controls, whereas targeted brute-forcing of a single user would quickly trigger a lockout and alert security teams.

Exam trap

Test-takers frequently confuse password spraying with brute-forcing, incorrectly assuming the goal is to guess one user's password through massive volume.

2
MCQmedium

You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?

A.Attempt to relay the hash to another system that has SMB signing disabled.
B.Use the hash directly in a pass-the-hash attack against an RDP session.
C.The hash can be used to authenticate to the Domain Controller for domain persistence.
D.Directly inject the hash into the LSASS process to create a new user session.
AnswerA

NetNTLMv2 hashes are highly effective when used in SMB relay attacks. If the target system has SMB signing disabled, an attacker can relay the hash to authenticate as the victim, gaining immediate access to the system without ever needing to know the user's actual password.

Why this answer

NetNTLMv2 hashes are challenge-response hashes, not password hashes. They cannot be used in a pass-the-hash attack. Instead, they must be cracked offline to obtain the plaintext password or relayed to a target that supports NTLM authentication.

Recognizing the distinction between NetNTLM and NTLM is a critical concept in OSCP-level testing, as it prevents the misuse of these credentials during lateral movement.

Exam trap

Students commonly attempt a direct pass-the-hash attack using a captured NetNTLMv2 challenge-response hash, failing to realize these cannot be used like local NTLM password hashes.

3
MCQmedium

During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?

A.John the Ripper with the krb5tgs format
B.Hydra with the kerberos module
C.Hashcat with mode 13100
D.Aircrack-ng with the -K option
AnswerC

Hashcat mode 13100 is specifically for cracking Kerberos 5 TGS-REP etype 23 (RC4) hashes. These hashes are obtained through Kerberoasting. Using this mode allows efficient offline cracking with wordlists or brute-force, making it the correct choice for this scenario.

Why this answer

Kerberoasting yields TGS-REP hashes that can be cracked offline. Hashcat mode 13100 is designed for RC4-encrypted TGS-REP hashes, providing efficient GPU-accelerated cracking. John the Ripper can also do it but is less optimized.

Aircrack-ng and Hydra are not appropriate for offline Kerberos hash cracking. Therefore, Hashcat with mode 13100 is the best choice.

Exam trap

The trap here is selecting a tool that can attack Kerberos online rather than one designed for offline cracking of captured TGS-REP hashes.

4
MCQhard

Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?

A.The vault is vulnerable to dictionary attacks due to the lack of a salt in the local file.
B.The encryption keys are stored in a predictable location or memory, allowing for easy extraction.
C.The lack of a master password prevents the use of multi-factor authentication for the vault.
D.The file format will be incompatible with standard password cracking software like John the Ripper.
AnswerB

When a master password is not required, the application must derive the decryption key from static sources, such as registry keys, machine GUIDs, or environment variables. An attacker with access to the system can easily locate these sources to decrypt the vault, rendering the 'encryption' effectively transparent to them.

Why this answer

Password managers are designed to consolidate credentials, but they are only as secure as their master secret. Without a master password, the vault relies on the security of the host filesystem. If an attacker gains local access or performs a memory dump, the keys are easily extractable.

This concept is vital for understanding how credential storage mechanisms can be exploited when the primary authentication factor is absent or bypassed.

Exam trap

Candidates often assume that local file encryption is sufficient for security. They ignore that if the master key is stored in memory or a predictable location, it can be easily extracted.

5
MCQeasy

You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?

A.MD5crypt
B.SHA-512crypt
C.SHA-256crypt
D.bcrypt
AnswerB

The `$6$` prefix in /etc/shadow indicates SHA-512crypt, a widely used password hashing algorithm on Linux systems. It is based on the SHA-512 algorithm and includes a salt to protect against rainbow table attacks. Knowing the algorithm is crucial for selecting the correct cracking mode in tools like Hashcat (mode 1800) or John the Ripper (format sha512crypt). This prefix is part of the modular crypt format used by many Unix-like systems.

Why this answer

In the modular crypt format, the prefix before the second `$` indicates the hashing algorithm. `$6$` is the standard identifier for SHA-512crypt, which is commonly used on modern Linux systems for storing password hashes in /etc/shadow. Recognizing this prefix allows a penetration tester to choose the correct cracking tool and mode, such as Hashcat mode 1800 or John the Ripper's sha512crypt format, to efficiently recover plaintext passwords.

Exam trap

The trap here is mixing up the numeric prefixes for different crypt algorithms, such as `$5$` for SHA-256crypt or `$1$` for MD5crypt.

6
MCQmedium

During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?

A.hashcat -m 0 -a 0 hashes.txt wordlist.txt
B.hashcat -m 5600 -a 0 hashes.txt wordlist.txt
C.hashcat -m 1000 -a 0 hashes.txt wordlist.txt
D.hashcat -m 3000 -a 0 hashes.txt wordlist.txt
AnswerC

Mode 1000 directs Hashcat to target NTLM hashes, which matches the format of password hashes dumped directly from the Windows NTDS.dit database. Combining this mode with attack mode 0 enables a standard dictionary attack using your specified wordlist against the collected credentials.

Why this answer

Hashcat mode 1000 specifically targets Windows NTLM password hashes extracted from Active Directory or SAM databases. Specifying the correct hash mode is essential because Hashcat uses specialized algorithms and optimization routines tailored to the exact cryptographic structure of each supported hash format during the attack.

Exam trap

Candidates frequently confuse NTLM mode 1000 with NetNTLMv2 challenge-response mode 5600, wasting valuable attack time by supplying the wrong hash algorithm flag to Hashcat.

7
MCQmedium

Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?

A.It indicates that the account is currently locked and will not accept further attempts.
B.It confirms that the application uses a weak hashing algorithm that ignores complexity.
C.It reveals information that allows you to prune your wordlist to only relevant password candidates.
D.It implies that the application is vulnerable to SQL injection because of poor error handling.
AnswerC

Knowing the exact password policy allows you to filter your wordlists to exclude passwords that would be rejected by the application's validation logic. This optimization significantly speeds up the brute-forcing process by ensuring that every password tested is at least theoretically compliant with the target organization's security policy.

Why this answer

This error message provides actionable intelligence regarding the target's password policy. By confirming the complexity requirements, you can refine your wordlists or mask attacks to target only valid password formats, drastically reducing the search space. This minimizes the time spent on invalid attempts and increases the probability of finding a match.

Understanding how to leverage application feedback is a hallmark of efficient password-based exploitation.

Exam trap

Candidates often ignore verbose web application error messages during brute-force attacks, missing valuable clues regarding password complexity rules that can optimize wordlists.

8
MCQmedium

Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?

A.The hash type was incorrectly specified for NTLM.
B.The password is not present in the provided wordlist.
C.The GPU memory limit was exceeded during processing.
D.The hash format is corrupted or invalid.
AnswerB

The 'Exhausted' status explicitly confirms that every entry in wordlist.txt was processed against the loaded hash. Since no match was found, the password is simply not included in the dictionary, necessitating a shift to other techniques like brute-forcing or rule-based mangling to find the cleartext.

Why this answer

The 'Exhausted' status in Hashcat indicates that all candidates in the provided wordlist were tested against the hash, but none resulted in a match. In a penetration test, this suggests that the password complexity exceeds the provided dictionary content. The attacker must now pivot to alternative strategies such as rule-based attacks, mask attacks, or using a more extensive, custom-generated wordlist tailored to the target organization's password policies.

Exam trap

Students mistakenly assume that an exhausted hashcat session means the hash is entirely uncrackable, rather than recognizing the wordlist was simply insufficient.

9
MCQhard

You compromise a Windows host and dump local account hashes with secretsdump, obtaining the NTLM hash of a local administrator. That same local administrator password was reused across every workstation in the environment. Which technique most directly allows lateral movement to other hosts using that hash without ever recovering the cleartext password?

A.Kerberoasting the local administrator account to request a service ticket
B.AS-REP roasting the local account to recover its hash offline
C.Pass-the-Hash using the NTLM hash to authenticate to SMB on other hosts
D.Downgrading NTLM to LM and replaying the resulting LM hash
AnswerC

Pass-the-Hash abuses the NTLM challenge-response protocol: because the stored NTLM hash is itself the credential used to compute the response, an attacker can authenticate to SMB, WMI, or other services by supplying the hash directly, without cracking it. When the local administrator password is reused, the same hash grants access on every affected workstation, enabling rapid lateral movement.

Why this answer

Pass-the-Hash works because NTLM authentication relies on the stored hash to compute the challenge response, so possessing the hash equals possessing the credential for that account. With the local administrator password reused across workstations, feeding the hash to tools that support hash-based SMB authentication lets you move laterally to each host without cracking anything. Kerberos-based roasting techniques do not apply to local SAM accounts.

Exam trap

The trap here is assuming any hash must be cracked to cleartext before it can be used; NTLM hashes are directly replayable, so cracking is unnecessary for lateral movement.

10
MCQeasy

In the context of password cracking, what is a 'rule' in tools like Hashcat or John the Ripper?

A.A predefined security policy set by the organization to ensure password complexity.
B.A transformation applied to dictionary words to simulate common password modifications.
C.A configuration setting that defines the maximum length of the cracked password.
D.A list of known leaked passwords that the tool compares against the hash directly.
AnswerB

Rules are a set of instructions applied to words in a dictionary. For example, a rule might convert 'password' into 'Password123!'. This significantly increases the effectiveness of a dictionary attack by covering common user habits like capitalizing the first letter or appending special characters to a base word.

Why this answer

Rules allow attackers to transform wordlist entries into more complex passwords, such as adding numbers, changing casing, or substituting characters. This is a critical technique because it allows a small wordlist to cover a much larger search space of possible passwords. Mastering rules is essential for efficient credential recovery, as it enables the simulation of common user password creation habits without needing massive, unmanageable wordlists.

11
MCQmedium

You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?

A.The target system must have the Kerberos pre-authentication disabled for the user account.
B.The victim machine must have the 'Restricted Admin' mode enabled in the RDP configuration.
C.The authentication protocol must permit NTLM or legacy authentication methods to facilitate the hash usage.
D.The target machine must be running a version of Windows older than Windows Server 2012.
AnswerC

Pass-the-hash depends on the target service or system accepting NTLM authentication. If an environment is strictly configured to use Kerberos-only authentication and NTLM is disabled via Group Policy or security settings, the hash will fail to authenticate because the system will reject the NTLM challenge-response sequence entirely.

Why this answer

Pass-the-hash (PtH) relies on the fact that authentication protocols like NTLM require the hash itself rather than the cleartext password. Understanding this mechanism is vital because it allows attackers to impersonate users without needing to crack complex passwords. The technique effectively bypasses the need for plaintext credentials, making it a staple for lateral movement in internal penetration tests when local administrator or service account access is achieved.

Exam trap

Test-takers frequently assume that obtaining an NTLM hash guarantees successful lateral movement, forgetting that legacy protocol restrictions or hardening can block pass-the-hash entirely.

12
MCQeasy

You have obtained a copy of a Windows SAM file from a compromised host. You want to extract the NTLM hashes for offline cracking. Which of the following tools is specifically designed for this task?

A.secretsdump.py
B.Mimikatz
C.Responder
D.Hydra
AnswerA

secretsdump.py, part of Impacket, is designed to extract secrets from Windows systems, including SAM files, LSA secrets, and NTDS.dit. It can parse a standalone SAM file and output NTLM hashes for offline cracking. This makes it the appropriate tool for the task described.

Why this answer

Extracting NTLM hashes from a SAM file is a common post-exploitation step. secretsdump.py from Impacket is specifically built to parse SAM, SYSTEM, and other registry hives to recover local account hashes. Mimikatz focuses on memory extraction, Responder captures network traffic, and Hydra performs online brute force. Therefore, secretsdump.py is the correct tool for offline SAM parsing.

Exam trap

The trap here is assuming that any credential dumping tool can handle an offline SAM file, when some tools are designed for live memory extraction or network attacks.

13
MCQhard

You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?

A.The hash is a SHA-512 crypt hash and can be cracked with tools like John the Ripper or Hashcat.
B.The hash is a bcrypt hash and requires the Blowfish algorithm to crack.
C.The hash is a DES hash and can be cracked quickly due to its short key length.
D.The hash is encrypted with AES-256 and requires a key to decrypt.
AnswerA

The $6$ prefix denotes SHA-512 crypt, a key derivation function used in Linux shadow files. It is designed to be slow to resist brute-force attacks. Tools like John the Ripper and Hashcat support this format and can perform dictionary or brute-force attacks to recover the plaintext password.

Why this answer

The $6$ prefix in /etc/shadow indicates SHA-512 crypt, a secure password hashing algorithm. It is not encryption, so it cannot be decrypted; it must be cracked. John the Ripper and Hashcat both support SHA-512 crypt and are commonly used for this purpose.

The other options misidentify the algorithm or misunderstand the nature of password hashing.

Exam trap

The trap here is misinterpreting the $6$ prefix as encryption or as a different hashing algorithm, leading to incorrect cracking strategies.

14
MCQmedium

You are conducting a penetration test and have obtained a list of usernames. You want to perform a password spray against an OWA (Outlook Web Access) portal. Which tool is specifically designed to automate password spraying against OWA while respecting lockout policies?

A.Hydra
B.MailSniper
C.Medusa
D.CrackMapExec
AnswerB

MailSniper is a PowerShell tool designed for penetration testing against Exchange and OWA. It includes a `Invoke-PasswordSprayOWA` function that automates password spraying while allowing control over the delay between attempts to avoid lockouts. It is specifically tailored for OWA and Exchange environments, making it the ideal choice for this scenario. Other tools may support spraying but are not as specialized for OWA.

Why this answer

MailSniper is a dedicated tool for attacking Exchange and OWA environments. Its `Invoke-PasswordSprayOWA` cmdlet automates the process of trying a single password against multiple OWA accounts while allowing the tester to specify a delay to avoid lockouts. This specialization makes it more effective and safer than generic brute-force tools like Hydra or Medusa, which are not tailored for OWA.

CrackMapExec does not support OWA, so MailSniper is the correct choice.

Exam trap

The trap here is assuming that any password spraying tool can target OWA, when in fact specialized tools like MailSniper are designed for it.

15
MCQmedium

You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?

A.Try all passwords against one username before moving to the next username.
B.Use a tool like Hydra to perform a dictionary attack with a high thread count to speed up the process.
C.Spray each password against a small subset of usernames, then rotate to another subset without waiting.
D.Spray one password against all usernames, then wait 30 minutes before trying the next password.
AnswerD

Password spraying involves trying a single password against many accounts to avoid lockouts. Waiting between attempts (e.g., 30 minutes) ensures that the account lockout threshold is not triggered, as most lockout policies count failed attempts within a time window. This approach balances efficiency and stealth, directly addressing the scenario's goal of avoiding lockouts while testing common passwords.

Why this answer

Password spraying avoids lockouts by trying a single password against many accounts, then waiting before the next password. This keeps the number of failed attempts per account below the lockout threshold within the observation window. Trying all passwords against one account or using high concurrency increases lockout risk.

Rotating subsets without waiting can also accumulate attempts. Thus, spraying one password at a time with a delay is the correct approach.

Exam trap

The trap here is confusing password spraying with brute-forcing, leading to techniques that concentrate attempts on few accounts and trigger lockouts.

16
MCQmedium

You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?

A.Use `crackmapexec smb <target> -u <user> -H <hash>` to authenticate with the NTLM hash.
B.Use `john --format=NT <hashfile>` to crack the hash and then log in with the recovered password.
C.Use `smbclient -U <user>%<hash> //<target>/share` to authenticate with the hash.
D.Use `hydra -l <user> -P <hashfile> smb://<target>` to replay the hash as a password.
AnswerA

CrackMapExec (now NetExec) supports pass-the-hash via the `-H` flag, allowing SMB authentication with an NTLM hash without cracking it. It sends the hash in the NTLM authentication exchange, which the server accepts because it only verifies the hash. This is the standard method for lateral movement when only the hash is available, and it works against SMB services that permit NTLM authentication.

Why this answer

Pass-the-hash allows an attacker to authenticate using the NTLM hash directly, bypassing the need to crack it. CrackMapExec (NetExec) is specifically designed for this and includes the `-H` flag to supply the hash. The other options either attempt to crack the hash, use tools that do not support hash authentication, or misconfigure the syntax.

The correct approach leverages the hash as a credential in the NTLM challenge-response protocol.

Exam trap

The trap here is confusing pass-the-hash with password cracking or assuming any tool that handles SMB can accept a hash directly.

17
MCQmedium

Refer to the exhibit. What is the primary purpose of the command provided?

A.Performing a brute-force attack on a SHA-256 encrypted archive.
B.Cracking NTLM hashes using a dictionary-based approach.
C.Attempting a mask attack to guess passwords based on a specific pattern.
D.Extracting domain user hashes from a SAM database file.
AnswerB

Mode 1000 identifies the hash type as NTLM, and -a 0 specifies the dictionary attack mode. This combination is the standard method for attempting to recover plaintext passwords from NTLM hashes using a predefined list of words, which is the most efficient starting point for offline password recovery in Windows environments.

Why this answer

This command initiates a dictionary attack against NTLM hashes. Mode 1000 is specifically designated for NTLM authentication hashes, while -a 0 denotes a straight dictionary attack using a wordlist. Knowing how to map hash formats to their corresponding Hashcat mode is a fundamental skill for password cracking.

Incorrectly identifying the mode or the attack type will result in an inability to recover the plaintext credentials during a penetration test.

Exam trap

Candidates frequently confuse Hashcat mode numbers, mistakenly applying modes meant for Kerberos or salted hashes when attempting to crack standard NTLM authentication hashes.

18
MCQeasy

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

A.The credentials are secure because base64 is difficult to reverse without the secret key.
B.The credentials are protected from casual inspection but vulnerable to automated tools.
C.The implementation is insecure because base64 is an encoding, not a cryptographic protection.
D.The implementation is acceptable if the connection is encrypted with TLS.
AnswerC

Base64 is designed to represent binary data in an ASCII string format. It offers no confidentiality or integrity. Using it to store credentials is a critical vulnerability because it exposes plaintext passwords to anyone who can view the cookie, allowing for trivial credential theft and subsequent unauthorized account access by an attacker.

Why this answer

Base64 is an encoding scheme, not an encryption or hashing algorithm. It is completely reversible and provides zero confidentiality for sensitive data. An attacker can easily decode these values to reveal plaintext credentials.

This is a common finding in penetration tests that highlights a lack of understanding of the difference between obfuscation and actual security controls, requiring immediate remediation to protect session integrity.

19
MCQhard

During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?

A.Hashcat with mode 1000 (NTLM)
B.Hashcat with mode 5600 (NetNTLMv2)
C.Cain & Abel with the NTLMv2 sniffer
D.John the Ripper with the --format=NT option
AnswerB

Hashcat mode 5600 is specifically designed for NetNTLMv2 (NTLMv2 challenge-response) hashes. These are network captures that include the server challenge, username, and domain, and are cracked as a challenge-response pair. This mode correctly handles the format and cryptographic operations needed to test candidate passwords against the captured NTLMv2 response, making it the appropriate choice for this scenario.

Why this answer

NTLMv2 challenge-response captures from tools like Responder are network authentication attempts, not raw password hashes. They must be cracked using a tool that supports the NetNTLMv2 format, such as Hashcat mode 5600. Raw NTLM hashes require different modes (e.g., 1000).

Using the correct mode ensures the cracking process properly computes the HMAC-MD5 response for each candidate password.

Exam trap

The trap here is confusing NetNTLMv2 challenge-response hashes with raw NTLM password hashes, leading to the selection of an incorrect cracking mode.

20
MCQhard

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?

A.Hashcat with mode 1000 and a mask attack targeting eight-character passwords.
B.John the Ripper with `--format=netntlmv2` and the `--incremental` mode.
C.Use `responder` to relay the hash to another host and gain access without cracking.
D.Hashcat with mode 5600 and a wordlist combined with rule-based mutations.
AnswerD

Hashcat mode 5600 is specifically for NetNTLMv2 hashes. Using a wordlist with rule-based mutations (e.g., best64.rule) increases the likelihood of cracking common password patterns. This approach is efficient because it leverages GPU acceleration and targets the exact hash format. The challenge-response nature of NetNTLMv2 means the hash cannot be used directly for pass-the-hash, so cracking is often necessary to obtain the plaintext for further access.

Why this answer

NetNTLMv2 hashes are challenge-response pairs that cannot be used directly for pass-the-hash. To recover the plaintext, offline cracking is required. Hashcat mode 5600 is designed for NetNTLMv2, and combining a wordlist with rules significantly improves success rates by mimicking common password transformations.

Other modes or tools may work but are less efficient or incorrect for this hash type.

Exam trap

The trap here is selecting the wrong Hashcat mode (e.g., 1000 for NTLM) or assuming that relaying the hash recovers the password.

21
Multi-Selectmedium

You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)

Select 2 answers
A.Use a large list of common passwords for each account.
B.Attempt multiple passwords per account in quick succession.
C.Use a single password attempt per account per lockout window.
D.Target only accounts that have never logged in.
E.Monitor the domain's lockout policy and adjust attempts accordingly.
AnswersC, E

Password spraying aims to avoid lockouts by trying one password against many accounts, then waiting before trying another password. Using a single attempt per account per lockout window respects the lockout threshold, minimizing the risk of locking accounts. This is a core principle of password spraying.

Why this answer

Password spraying avoids lockouts by limiting attempts per account. Using a single attempt per lockout window and monitoring the lockout policy are both critical. Attempting multiple passwords per account or using large password lists increases lockout risk.

Targeting only never-logged-in accounts is irrelevant to lockout avoidance. Thus, the correct practices are to use one attempt per window and to monitor the policy.

Exam trap

The trap here is confusing password spraying with brute-forcing, leading to the selection of practices that actually increase lockout risk.

22
MCQmedium

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

A.The account must have a Service Principal Name (SPN) set in the domain properties.
B.The account must have the 'Do not require Kerberos pre-authentication' option enabled.
C.The user must be a member of the Domain Admins or Enterprise Admins group.
D.The account must be configured with a password that has never been rotated.
AnswerB

This setting is the primary vulnerability that makes AS-REP Roasting possible. When disabled, the domain controller sends an encrypted TGT without verifying the user's password first. This encrypted ticket can then be captured and cracked offline, making it a highly effective method for gaining access to user accounts.

Why this answer

AS-REP Roasting is possible when a user account has the 'Do not require Kerberos pre-authentication' attribute enabled in Active Directory. This allows an attacker to request a ticket for the user without needing the correct password, which can then be cracked offline. Understanding this specific AD attribute is critical for identifying vulnerable accounts during internal reconnaissance, as it represents a significant misconfiguration that simplifies the path to credential recovery.

Exam trap

Students frequently confuse AS-REP Roasting with Kerberoasting, incorrectly looking for Service Principal Names (SPNs) instead of checking for the specific pre-authentication disabled attribute on user accounts.

23
MCQeasy

You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?

A.Mode 7400 (sha256crypt)
B.Mode 1800 (sha512crypt)
C.Mode 3200 (bcrypt)
D.Mode 500 (md5crypt)
AnswerB

Mode 1800 in hashcat is specifically for sha512crypt, which corresponds to the '$6$' prefix in /etc/shadow. This is the correct mode to crack the hash. It supports the SHA-512 based crypt(3) algorithm used by most modern Linux systems. Using this mode ensures the hash is processed correctly and efficiently.

Why this answer

The '$6$' prefix in /etc/shadow denotes SHA-512 crypt, which is handled by hashcat mode 1800 (sha512crypt). The other modes correspond to different algorithms: mode 500 for md5crypt ('$1$'), mode 3200 for bcrypt ('$2a$'), and mode 7400 for sha256crypt ('$5$'). Using the correct mode is essential for successful cracking.

Therefore, mode 1800 is the right choice.

Exam trap

The trap here is confusing the various '$id$' prefixes in crypt(3) hashes, leading to selection of the wrong hashcat mode.

Ready to test yourself?

Try a timed practice session using only Password Attacks questions.