{"id":1788,"date":"2023-10-03T06:23:05","date_gmt":"2023-10-02T19:23:05","guid":{"rendered":"https:\/\/gabey.com.au\/gabeyinfo\/?post_type=glossary&#038;p=1788"},"modified":"2023-10-04T08:03:27","modified_gmt":"2023-10-03T21:03:27","slug":"over-pass-the-hash","status":"publish","type":"glossary","link":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/glossary\/over-pass-the-hash\/","title":{"rendered":"Over-pass-the-Hash"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The pass-the-hash and pass-the-ticket episodes are combined into the Overpass-the-Hash assault. Using a user account's NTLM hash, an attacker can obtain a Kerberos ticket that grants them access to network resources. The \"Over-pass-the-Hash\" attack is a variant of the more common Pass-the-Hash (PtH) attack. In an Over-pass-the-Hash attack, the attacker modifies the user's password to their own and then uses that new password to obtain unauthorised access instead of simply stealing and using the hash of the user's password. Because it has the potential to provide the attacker permanent access to the compromised account or system, this attack is risky. The attacker may use a tool like Mimikatz to accomplish this task.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mimikatz is a software tool crafted by Benjamin Delpy, a French developer, and is primarily used for gathering credentials and performing various tasks related to penetration testing. The tool was designed to address a known vulnerability within the Windows system function known as WDigest, allowing critical Windows-based network users to set up login information across multiple LAN or WAN applications. By storing authentication credentials in memory, users only need to enter their login information once, making it a more convenient and efficient process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Discover the power of an Overpass-the-Hash attack utilising the NTLM hash. The NTLM hash is securely encrypted with the robust RC4 algorithm and promptly transmitted to the reliable and trusted Kerberos identity provider. Microsoft can leverage NTLM hashes to generate highly secure encrypted Kerberos keys using the advanced RC4-HMAC-MD5 algorithm. This feature primarily exists to ensure backward compatibility. However, it is crucial to know that hackers can exploit this functionality to access the least secure Kerberos ticket by utilising the user's NTLM hash.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">People who use NTLMv2 security can be hit by the Overpass-the-Hash attack. In this attack, the attacker uses the NTLMv2 hash of a user account to get a Kerberos ticket that they can use to get into network resources. If you need to get to a place that requires Kerberos login but can't get the cleartext password for an account, this method can help. You can use this attack to do things on both local and remote systems. The episode is commonly executed using Mimikatz and Rubeus tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is possible to conduct Overpass-the-Hash attacks on the latest Windows operating systems. Nevertheless, Microsoft has taken measures to reduce the risk of such attacks. One of these measures is the Windows Defender Credential Guard, a newer security feature available for Windows 10 and newer systems. It helps protect sensitive information stored on the system. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other mitigation strategies include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>implementing the least privilege security model,<\/li>\n\n\n\n<li>rebooting systems after logging out,<\/li>\n\n\n\n<li>installing anti-malware software and<\/li>\n\n\n\n<li>regularly updating operating systems.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most essential security features in Windows 11 is blocking outbound NTLM over SMB. This means that Windows will no longer send NTLM hashes to remote SMB servers, which can help prevent Overpass-the-Hash attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To summarise, attackers may carry out the following steps:<br>First, the attacker acquires access to a system or network by social engineering, phishing, or exploiting vulnerabilities. Once on the network, the attacker's objective is to get the credentials (username and password) of a valid user, usually one with enhanced access. They might employ various techniques to obtain login credentials, such as keylogging, credential theft, or other strategies. The attacker may expand their privileges within the network if they still need to acquire enough access, which could compromise administrator or high-level account credentials.<br>Using their enhanced access, the attacker modifies the password of the authentic user account whose credentials they have obtained. This is an essential step since it guarantees that the attacker has total control over the account and that the legitimate user's previous password will no longer function.<br>Now that the attacker has modified the user's password to their own, they can use that new password to log in as that user. They now have continuous, authorised access to the account and its resources.<br>By gaining control of this compromised account, the attacker can navigate freely within the network, effortlessly accessing various systems, services, and sensitive data. This unrestricted access allows them to carry out their malicious activities with ease, posing a significant threat to the security and integrity of your network.<br>The attacker must implement additional measures to ensure uninterrupted access and evade detection. These may include creating backdoors, using rootkits, or implementing various techniques to conceal their presence on the compromised system effectively.<br>By gaining long-term access to the network, the attacker gains the ability to engage in a wide range of malicious activities that can have severe consequences. These activities may involve stealing valuable data, launching devastating attacks, or exploiting the network for further nefarious opportunities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><br><br><br><br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The pass-the-hash and pass-the-ticket episodes are combined into the Overpass-the-Hash assault. Using a user account&#8217;s NTLM hash, an attacker can obtain a Kerberos ticket that grants them access to network resources. The &#8220;Over-pass-the-Hash&#8221; attack is a variant of the more common Pass-the-Hash (PtH) attack. In an Over-pass-the-Hash attack, the attacker modifies the user&#8217;s password to &hellip; <a href=\"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/glossary\/over-pass-the-hash\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Over-pass-the-Hash&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"menu_order":0,"template":"","meta":{"footnotes":""},"class_list":["post-1788","glossary","type-glossary","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary\/1788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":0,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/glossary\/1788\/revisions"}],"wp:attachment":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/media?parent=1788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}