166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

Pass-the-Hash

Pretnja u centru, tehnike kojima se izvodi levo, odbrane koje je suzbijaju desno. Ispod — mapa faza napada: kojom tehnikom se ulazi i koja odbrana je presreće.

↘ Techniques used to carry it out3

Techniques used to carry it out. Klik vodi na stranicu pojma.

threat · № 023 · identity

Pass-the-Hash

So that it does not keep the password in readable form, Windows remembers its cryptographic fingerprint — the hash. With older Windows authentication (NTLM), the password is not required to prove identity; the hash is enough. Pass-the-hash abuses exactly that: if the attacker obtains a user's hash, they can log in with it without ever learning the real password.

↓ izvor: prvi po vezama Najčešći ulaz: Credential Abuse. Ključna odbrana: Logging & Monitoring.

↗ How it is defended against4