{"id":1765,"date":"2023-10-03T04:43:51","date_gmt":"2023-10-02T17:43:51","guid":{"rendered":"https:\/\/gabey.com.au\/gabeyinfo\/?post_type=glossary&#038;p=1765"},"modified":"2023-10-04T08:02:53","modified_gmt":"2023-10-03T21:02:53","slug":"pass-the-hash-pth","status":"publish","type":"glossary","link":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/glossary\/pass-the-hash-pth\/","title":{"rendered":"Pass-the-Hash (PtH)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Pass-the-Hash (PtH)<\/strong> refers to a cybersecurity attack wherein an unauthorised individual acquires a \"hashed\" user credential and exploits it to establish a fresh user session within the same network. In contrast to other methods of credential theft, a pass-the-hash attack does not necessitate the attacker's knowledge or cracking of the password in order to gain unauthorised access to the system. Instead, the system utilises a stored password version to initiate a new session.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A password hash is a mathematical function that converts a user's password into an irreversible string of characters. The attackers cannot decode this string of characters to reveal the original password. The passwords are securely stored using nondescript hash symbols rather than being stored in plain text or characters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a pass-the-hash attack, the perpetrator commonly gains unauthorised entry into the network by employing social engineering tactics, such as phishing. After successfully infiltrating the user's account, the attacker uses various tools and techniques to extract data from the active memory. This extracted data is then utilised to identify the hashes. With one or more valid password hashes, the attacker can acquire complete system access, facilitating lateral movement throughout the network. In their effort to impersonate the user across multiple applications, the attacker frequently employs a technique known as hash harvesting. This involves gathering additional hashes from various parts of the system. These harvested hashes can then be leveraged to access different network areas, elevate account privileges, target privileged accounts, and establish backdoors and other gateways that facilitate future unauthorised access.<br>Windows server clients and organisations utilising Windows New Technology LAN Manager (NTLM) are susceptible to pass hash attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pass-the-Hash (PtH) refers to a cybersecurity attack wherein an unauthorised individual acquires a &#8220;hashed&#8221; user credential and exploits it to establish a fresh user session within the same network. In contrast to other methods of credential theft, a pass-the-hash attack does not necessitate the attacker&#8217;s knowledge or cracking of the password in order to gain &hellip; <a href=\"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/glossary\/pass-the-hash-pth\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Pass-the-Hash (PtH)&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"menu_order":0,"template":"","meta":{"footnotes":""},"class_list":["post-1765","glossary","type-glossary","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary\/1765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":0,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary\/1765\/revisions"}],"wp:attachment":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/media?parent=1765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}