[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feBH8P80skd1TL8pGba1UbQeGmtjhI88RCM56HFwAXNg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},891,"What are the prerequisites for obtaining a client's Net-NTLM hash via the HTTP protocol?","The client's user authentication method must be set to \"Automatic logon with current user name and password\" (registry value `1A00` set to `0`), or the client and server must be in the same Intranet zone with the default setting. Without these conditions, the client will prompt for credentials instead of automatically sending the hash. These constraints also apply to tools like Responder and Inveigh when capturing HTTP-based hashes.","\u003Cp>The client&#39;s user authentication method must be set to &quot;Automatic logon with current user name and password&quot; (registry value `1A00` set to `0`), or the client and server must be in the same Intranet zone with the default setting. Without these conditions, the client will prompt for credentials instead of automatically sending the hash. These constraints also apply to tools like Responder and Inveigh when capturing HTTP-based hashes.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-prerequisites-for-obtaining-a-clients-net-ntlm-hash-via-the-http-pr-1777481394562","Intranet zone, registry modification, automatic logon, Responder, Inveigh",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},217,"Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol","penetration-techniques-obtaining-net-ntlm-hash-via-http-protocol","Learn how to capture Net-NTLM hash via HTTP protocol, analyze exploitation prerequisites, and implement defense strategies in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles such as 'Introduction to Password Hashes in Windows - NTLM Hash and Net-NTLM Hash', 'Penetration Techniques - Capturing NTLMv2 Hash of File Server Connections Using netsh', and 'Penetration Techniques - Obtaining NTLMv2 Hash of File Server Connections via Icon Files', methods for obtaining the Net-NTLM hash of logged-in users through the SMB protocol were introduced. The premise of these methods is that when a client connects to a server via the SMB protocol through the interface, it defaults to attempting login using the local machine's username and password hash.\u003C\u002Fp>\u003Cp>The HTTP protocol also supports NTLM authentication. So, can the Net-NTLM hash of the currently logged-in user be similarly obtained via the HTTP protocol? What are the constraints? How can it be defended against? This article will address these questions one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to NTLM Over HTTP Protocol\u003C\u002Fli>\u003Cli>Identifying the Prerequisites for Exploitation\u003C\u002Fli>\u003Cli>How to Specifically Exploit\u003C\u002Fli>\u003Cli>Defense Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to NTLM Over HTTP Protocol\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc237488.aspx\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.innovation.ch\u002Fpersonal\u002Fronald\u002Fntlm.html\u003C\u002Fp>\u003Cp>NTLM Authentication Process Using HTTP Protocol:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a GET request to the server to obtain webpage content.\u003C\u002Fli>\u003Cli>Since NTLM authentication is enabled, the server returns a 401 status, indicating that NTLM authentication is required.\u003C\u002Fli>\u003Cli>The client initiates NTLM authentication by sending a negotiation message to the server.\u003C\u002Fli>\u003Cli>Upon receiving the message, the server generates a 16-bit random number (known as the Challenge) and sends it back to the client in plaintext.\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the input password hash to generate a response, which is then sent to the server.\u003C\u002Fli>\u003Cli>The server receives the encrypted response from the client, performs the same computation, and compares the results. If they match, subsequent services are provided; otherwise, authentication fails.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>An intuitive flowchart is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017352624_0_a7a5bbe39f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The image is captured from https:\u002F\u002Fwww.innovation.ch\u002Fpersonal\u002Fronald\u002Fntlm.html. For specific message formats, refer to the introduction in the link.\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Server2012 R2\u003C\u002Fli>\u003Cli>IP: 192.168.62.136\u003C\u002Fli>\u003Cli>Install IIS service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Win7 x86\u003C\u002Fli>\u003Cli>IP: 192.168.62.134\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Enable NTLM authentication on the server\u003C\u002Fh4>\u003Cp>Access the IIS management page, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017386506_1_ec9ee05e67.jpeg\">\u003C\u002Fp>\u003Cp>Select Authentication\u003C\u002Fp>\u003Cp>Disable other authentication methods, enable only Windows Authentication\u003C\u002Fp>\u003Cp>Add Provider: NTLM\u003C\u002Fp>\u003Cp>Configure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017412351_2_12cd35f68b.jpeg\">\u003C\u002Fp>\u003Ch4>2. The server runs Wireshark to capture packets\u003C\u002Fh4>\u003Cp>Extract only HTTP\u003C\u002Fp>\u003Ch4>3. The client accesses the server\u003C\u002Fh4>\u003Cp>A dialog box prompts for username and password, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017459009_3_c02aa82482.jpeg\">\u003C\u002Fp>\u003Cp>The HTTP packets captured by the server at this point are shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017475524_4_5a5a13ece4.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding to steps 1 and 2\u003C\u002Fp>\u003Ch4>4. The client enters the correct username and password\u003C\u002Fh4>\u003Cp>The HTTP packets captured by the server at this point are shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017486096_5_f13f7d57fc.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding to steps 3-6\u003C\u002Fp>\u003Ch4>5. Use Hashcat to crack this Net-NTLM hash\u003C\u002Fh4>\u003Cp>The format of NTLMv2 is:\u003C\u002Fp>\u003Cp>username::domain:challenge:HMAC-MD5:blob\u003C\u002Fp>\u003Cp>Obtain the challenge from the data packet, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017496518_6_2f786ff0a8.jpeg\">\u003C\u002Fp>\u003Cp>Obtain username, domain, HMAC-MD5, and blob from the data packet\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017505125_7_600ff5986f.jpeg\">\u003C\u002Fp>\u003Cp>Concatenate in the specified format and crack using hash\u003C\u002Fp>\u003Cp>For detailed information, refer to:\u003C\u002Fp>\u003Cp>Section 0x03 in 'Introduction to Windows Password Hashes – NTLM Hash and Net-NTLM Hash'\u003C\u002Fp>\u003Ch2>0x03 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above tests, it can be seen that cracking the HTTP protocol is similar to the SMB protocol. But are the exploitation methods the same?\u003C\u002Fp>\u003Cp>We know that when connecting to a server via the SMB protocol through the interface, the local username and password hash are used by default for login attempts. However, the previous tests did not reveal that the HTTP protocol shares this characteristic.\u003C\u002Fp>\u003Cp>This means that as long as the user does not enter the correct password, the server cannot obtain the correct Net-NTLM hash, making further exploitation impossible.\u003C\u002Fp>\u003Cp>Additionally, the HTTP authentication interception features of Responder and Inveigh mention the ability to obtain user hashes. The addresses are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FSpiderLabs\u002FResponder#features\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Cp>How do I use this feature? What kind of hash can be obtained? Can I get the hash of the currently logged-in user on the client?\u003C\u002Fp>\u003Cp>I found the answer in the IE browser configuration\u003C\u002Fp>\u003Cp>Open the IE browser and navigate to the following location:\u003C\u002Fp>\u003Cp>Tools -&gt; Internet Options -&gt; Security -&gt; Custom Level -&gt; User Authentication\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017510262_8_99b94cd1a8.jpeg\">\u003C\u002Fp>\u003Cp>By default, the login method for user authentication is 'Automatic logon only in Intranet zone'\u003C\u002Fp>\u003Cp>So, two tests need to be performed next\u003C\u002Fp>\u003Ch4>Test one\u003C\u002Fh4>\u003Cp>Change the login method to 'Automatic logon with current user name and password'\u003C\u002Fp>\u003Cp>Restart the IE browser and test again\u003C\u002Fp>\u003Cp>The client accesses the server via IE, a login verification dialog pops up, then check the server's packet capture\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017516526_9_1e25d5983b.jpeg\">\u003C\u002Fp>\u003Cp>It was discovered that the client automatically attempts to log in using the local machine's username and password hash first, allowing us to further crack and recover the user's password, similar to the exploitation approach for SMB.\u003C\u002Fp>\u003Ch4>Test Two\u003C\u002Fh4>\u003Cp>Switch to a domain environment, with all other settings unchanged\u003C\u002Fp>\u003Cp>The client will also first attempt to log in using the local machine's username and password hash\u003C\u002Fp>\u003Cp>Thus, we have identified the limiting conditions: obtaining the current logged-in user's Net-NTLM hash via the HTTP protocol is applicable in the following two scenarios:\u003C\u002Fp>\u003Col>\u003Cli>The client user authentication method is set to 'Automatic logon with current user name and password'\u003C\u002Fli>\u003Cli>The user authentication method remains unchanged by default, and the client and server must be within the same Intranet zone\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Similarly, this is also the prerequisite for tools like Responder and Inveigh to exploit HTTP protocol user hash acquisition\u003C\u002Fp>\u003Ch2>0x04 Specific Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Using Responder and Inveigh within the Intranet zone\u003C\u002Fp>\u003Cp>If in a workgroup environment, obtaining the current logged-in user's Net-NTLM hash is not possible; it can be used in a domain environment\u003C\u002Fp>\u003Cp>2. After gaining client permissions, modify the user authentication method\u003C\u002Fp>\u003Cp>Corresponds to the registry key 1A00 under HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\u003C\u002Fp>\u003Cul>\u003Cli>A value of 0 indicates automatic logon with the current username and password\u003C\u002Fli>\u003Cli>10000 indicates username and password prompt\u003C\u002Fli>\u003Cli>20000 indicates automatic logon only in Intranet zone, default value\u003C\u002Fli>\u003Cli>30000 indicates anonymous logon\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If the client user authentication logon method is changed to Automatic logon with current user name and password, then the client will first attempt to log in using the local username and password hash when accessing any website requiring login authentication\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on exploitation approaches, defense recommendations are proposed here:\u003C\u002Fp>\u003Cp>User authentication method should be prohibited from being set to Automatic logon with current user name and password, and the corresponding registry key value should be prevented from being modified to 0\u003C\u002Fp>\u003Cp>The query command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\" \u002Fv 1A00\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Otherwise, there is a high possibility that the password of the client's currently logged-in user could be cracked\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods to obtain the client's currently logged-in user Net-NTLM hash through HTTP protocol, identifies constraints (under Intranet zone or when user authentication method is modified to Automatic logon with current user name and password), which also apply to Responder and Inveigh's HTTP authentication interception functions, and finally provides defense recommendations: User authentication method should be prohibited from being set to Automatic logon with current user name and password\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles such as 'Introduction to Password Hashes in Windows - NTLM Hash and Net-NTLM Hash', 'Penetration Techniques - Capturing NTLMv2 Hash of File Server Connections Using netsh', and 'Penetration Techniques - Obtaining NTLMv2 Hash of File Server Connections via Icon Files', methods for obtaining the Net-NTLM hash of logged-in users through the SMB protocol were introduced. The premise of these methods is that when a client connects to a server via the SMB protocol through the interface, it defaults to attempting login using the local machine's username and password hash.\u003C\u002Fp>\u003Cp>The HTTP protocol also supports NTLM authentication. So, can the Net-NTLM hash of the currently logged-in user be similarly obtained via the HTTP protocol? What are the constraints? How can it be defended against? This article will address these questions one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to NTLM Over HTTP Protocol\u003C\u002Fli>\u003Cli>Identifying the Prerequisites for Exploitation\u003C\u002Fli>\u003Cli>How to Specifically Exploit\u003C\u002Fli>\u003Cli>Defense Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to NTLM Over HTTP Protocol\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc237488.aspx\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.innovation.ch\u002Fpersonal\u002Fronald\u002Fntlm.html\u003C\u002Fp>\u003Cp>NTLM Authentication Process Using HTTP Protocol:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a GET request to the server to obtain webpage content.\u003C\u002Fli>\u003Cli>Since NTLM authentication is enabled, the server returns a 401 status, indicating that NTLM authentication is required.\u003C\u002Fli>\u003Cli>The client initiates NTLM authentication by sending a negotiation message to the server.\u003C\u002Fli>\u003Cli>Upon receiving the message, the server generates a 16-bit random number (known as the Challenge) and sends it back to the client in plaintext.\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the input password hash to generate a response, which is then sent to the server.\u003C\u002Fli>\u003Cli>The server receives the encrypted response from the client, performs the same computation, and compares the results. If they match, subsequent services are provided; otherwise, authentication fails.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>An intuitive flowchart is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017352624_0_a7a5bbe39f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The image is captured from https:\u002F\u002Fwww.innovation.ch\u002Fpersonal\u002Fronald\u002Fntlm.html. For specific message formats, refer to the introduction in the link.\u003C\u002Fp>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Server2012 R2\u003C\u002Fli>\u003Cli>IP: 192.168.62.136\u003C\u002Fli>\u003Cli>Install IIS service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>OS: Win7 x86\u003C\u002Fli>\u003Cli>IP: 192.168.62.134\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Enable NTLM authentication on the server\u003C\u002Fh4>\u003Cp>Access the IIS management page, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017386506_1_ec9ee05e67-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Authentication\u003C\u002Fp>\u003Cp>Disable other authentication methods, enable only Windows Authentication\u003C\u002Fp>\u003Cp>Add Provider: NTLM\u003C\u002Fp>\u003Cp>Configure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017412351_2_12cd35f68b-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. The server runs Wireshark to capture packets\u003C\u002Fh4>\u003Cp>Extract only HTTP\u003C\u002Fp>\u003Ch4>3. The client accesses the server\u003C\u002Fh4>\u003Cp>A dialog box prompts for username and password, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017459009_3_c02aa82482-1.jpeg\">\u003C\u002Fp>\u003Cp>The HTTP packets captured by the server at this point are shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017475524_4_5a5a13ece4-1.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding to steps 1 and 2\u003C\u002Fp>\u003Ch4>4. The client enters the correct username and password\u003C\u002Fh4>\u003Cp>The HTTP packets captured by the server at this point are shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017486096_5_f13f7d57fc-1.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding to steps 3-6\u003C\u002Fp>\u003Ch4>5. Use Hashcat to crack this Net-NTLM hash\u003C\u002Fh4>\u003Cp>The format of NTLMv2 is:\u003C\u002Fp>\u003Cp>username::domain:challenge:HMAC-MD5:blob\u003C\u002Fp>\u003Cp>Obtain the challenge from the data packet, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017496518_6_2f786ff0a8-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtain username, domain, HMAC-MD5, and blob from the data packet\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017505125_7_600ff5986f-1.jpeg\">\u003C\u002Fp>\u003Cp>Concatenate in the specified format and crack using hash\u003C\u002Fp>\u003Cp>For detailed information, refer to:\u003C\u002Fp>\u003Cp>Section 0x03 in 'Introduction to Windows Password Hashes – NTLM Hash and Net-NTLM Hash'\u003C\u002Fp>\u003Ch2>0x03 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above tests, it can be seen that cracking the HTTP protocol is similar to the SMB protocol. But are the exploitation methods the same?\u003C\u002Fp>\u003Cp>We know that when connecting to a server via the SMB protocol through the interface, the local username and password hash are used by default for login attempts. However, the previous tests did not reveal that the HTTP protocol shares this characteristic.\u003C\u002Fp>\u003Cp>This means that as long as the user does not enter the correct password, the server cannot obtain the correct Net-NTLM hash, making further exploitation impossible.\u003C\u002Fp>\u003Cp>Additionally, the HTTP authentication interception features of Responder and Inveigh mention the ability to obtain user hashes. The addresses are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FSpiderLabs\u002FResponder#features\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Cp>How do I use this feature? What kind of hash can be obtained? Can I get the hash of the currently logged-in user on the client?\u003C\u002Fp>\u003Cp>I found the answer in the IE browser configuration\u003C\u002Fp>\u003Cp>Open the IE browser and navigate to the following location:\u003C\u002Fp>\u003Cp>Tools -&gt; Internet Options -&gt; Security -&gt; Custom Level -&gt; User Authentication\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017510262_8_99b94cd1a8-1.jpeg\">\u003C\u002Fp>\u003Cp>By default, the login method for user authentication is 'Automatic logon only in Intranet zone'\u003C\u002Fp>\u003Cp>So, two tests need to be performed next\u003C\u002Fp>\u003Ch4>Test one\u003C\u002Fh4>\u003Cp>Change the login method to 'Automatic logon with current user name and password'\u003C\u002Fp>\u003Cp>Restart the IE browser and test again\u003C\u002Fp>\u003Cp>The client accesses the server via IE, a login verification dialog pops up, then check the server's packet capture\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017516526_9_1e25d5983b-1.jpeg\">\u003C\u002Fp>\u003Cp>It was discovered that the client automatically attempts to log in using the local machine's username and password hash first, allowing us to further crack and recover the user's password, similar to the exploitation approach for SMB.\u003C\u002Fp>\u003Ch4>Test Two\u003C\u002Fh4>\u003Cp>Switch to a domain environment, with all other settings unchanged\u003C\u002Fp>\u003Cp>The client will also first attempt to log in using the local machine's username and password hash\u003C\u002Fp>\u003Cp>Thus, we have identified the limiting conditions: obtaining the current logged-in user's Net-NTLM hash via the HTTP protocol is applicable in the following two scenarios:\u003C\u002Fp>\u003Col>\u003Cli>The client user authentication method is set to 'Automatic logon with current user name and password'\u003C\u002Fli>\u003Cli>The user authentication method remains unchanged by default, and the client and server must be within the same Intranet zone\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Similarly, this is also the prerequisite for tools like Responder and Inveigh to exploit HTTP protocol user hash acquisition\u003C\u002Fp>\u003Ch2>0x04 Specific Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Using Responder and Inveigh within the Intranet zone\u003C\u002Fp>\u003Cp>If in a workgroup environment, obtaining the current logged-in user's Net-NTLM hash is not possible; it can be used in a domain environment\u003C\u002Fp>\u003Cp>2. After gaining client permissions, modify the user authentication method\u003C\u002Fp>\u003Cp>Corresponds to the registry key 1A00 under HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\u003C\u002Fp>\u003Cul>\u003Cli>A value of 0 indicates automatic logon with the current username and password\u003C\u002Fli>\u003Cli>10000 indicates username and password prompt\u003C\u002Fli>\u003Cli>20000 indicates automatic logon only in Intranet zone, default value\u003C\u002Fli>\u003Cli>30000 indicates anonymous logon\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If the client user authentication logon method is changed to Automatic logon with current user name and password, then the client will first attempt to log in using the local username and password hash when accessing any website requiring login authentication\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on exploitation approaches, defense recommendations are proposed here:\u003C\u002Fp>\u003Cp>User authentication method should be prohibited from being set to Automatic logon with current user name and password, and the corresponding registry key value should be prevented from being modified to 0\u003C\u002Fp>\u003Cp>The query command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\" \u002Fv 1A00\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Otherwise, there is a high possibility that the password of the client's currently logged-in user could be cracked\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods to obtain the client's currently logged-in user Net-NTLM hash through HTTP protocol, identifies constraints (under Intranet zone or when user authentication method is modified to Automatic logon with current user name and password), which also apply to Responder and Inveigh's HTTP authentication interception functions, and finally provides defense recommendations: User authentication method should be prohibited from being set to Automatic logon with current user name and password\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",693,"Onedaysec",6,"published","2026-02-02T07:38:21.177Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Obtain Net-NTLM Hash via HTTP Protocol: Penetration Techniques","Net-NTLM hash, HTTP protocol, NTLM authentication, penetration testing, Windows security, hash capture, IIS, NTLMv2, security exploitation, defense strategies",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],894,893,892,890,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.977Z","2026-07-23T16:02:14.763Z","draft","2026-07-23T16:15:22.167Z"]