Password Attacks Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Password Attacks flashcards as text
Which tool is used to extract password hashes and plaintext credentials from Windows LSASS process memory?
Answer: Mimikatz
Mimikatz uses its sekurlsa module to extract plaintext passwords, NTLM hashes, and Kerberos tickets directly from LSASS memory.
What Hashcat attack mode number (-a) is used for mask (pattern-based brute force) attacks?
Answer: -a 3
Hashcat's -a 3 performs mask attacks where character placeholders like ?u, ?l, and ?d define the password pattern to enumerate.
Which Hashcat hash mode number (-m) is used to crack NTLM hashes?
Answer: 1000
Hashcat mode 1000 (-m 1000) targets NTLM hashes, the standard Windows password hash format stored in the SAM database and LSASS.
What is a pass-the-hash (PtH) attack?
Answer: Authenticating with a captured NTLM hash without needing the plaintext password
Pass-the-hash exploits NTLM by supplying the captured hash directly as the authentication credential, completely bypassing the need to crack it.
Which Impacket script is commonly used to perform pass-the-hash attacks and obtain a remote shell on Windows systems?
Answer: impacket-psexec
impacket-psexec (psexec.py) accepts an NTLM hash via the -hashes flag (format: LM:NT) to authenticate and execute commands remotely.
Which command combines /etc/passwd and /etc/shadow into a format suitable for cracking with John the Ripper?
Answer: unshadow
The 'unshadow' utility merges /etc/passwd and /etc/shadow into a single file that John the Ripper can parse and crack.
In a Hashcat mask attack, what character set does the placeholder '?d' represent?
Answer: Any digit 0-9
In Hashcat mask syntax, ?d represents any single digit from 0 through 9, enabling targeted pattern-based enumeration.