NTLMv2 (NT LAN Manager version 2) is a widely used authentication protocol in Windows-based environments. However, it is not immune to password cracking attempts when weak or easily guessable passwords are in use. Here’s a summary of NTLMv2 password cracking:
- NTLMv2 Overview: NTLMv2 is a more secure version of the NTLM authentication protocol, used for verifying the identity of users and machines in Windows domains.
- Password Hashes: In NTLMv2, passwords are not stored in plain text; instead, they are stored as cryptographic hashes. This makes it challenging for attackers to directly retrieve passwords from the system.
- Password Cracking Techniques: Attackers employ various techniques to crack NTLMv2 password hashes, including:
- Brute Force: Attempting all possible password combinations until a match is found.
- Dictionary Attacks: Trying a list of commonly used passwords or words from a dictionary.
- Rainbow Tables: Using precomputed tables of password hashes to look up the corresponding plaintext passwords.
- Pass the Hash: Exploiting vulnerabilities to use captured password hashes for authentication without knowing the actual passwords.
- Salting: NTLMv2 hashes are salted, which means that a random value (the salt) is added to the password before hashing. This adds complexity to password cracking, as attackers need to know the salt value to crack the hash successfully.
- Complex Passwords: To defend against password cracking, users and organisations should enforce strong, complex passwords. These passwords should be lengthy, contain a mix of character types (uppercase, lowercase, numbers, symbols), and should not be easily guessable.
- Password Policies: Windows domains often have password policies in place, which can enforce password complexity requirements, password expiration, and account lockout policies to mitigate password-related attacks.
- Security Best Practices: Organisations should implement multi-factor authentication (MFA) to add an extra layer of security, monitor for unusual login activities, and regularly audit password policies to ensure they meet security standards.
- Regular Password Changes: Encouraging users to change their passwords periodically can help reduce the risk associated with stolen password hashes.
In summary, NTLMv2 password cracking is a significant security concern when weak passwords are in use. Employing strong password policies, educating users, and implementing additional security measures are crucial steps in defending against NTLMv2 password cracking attempts.
What this tells you about your password policy
The reason offline cracking of captured authentication material is worth understanding is not the technique itself. It is what the results say about the passwords in your environment.
An attacker working offline is not slowed down by account lockout, rate limiting or alerting. None of the controls that protect a login form apply. The only thing standing between a captured hash and a usable password is how expensive that password is to guess, and expense is driven overwhelmingly by length rather than by character variety.
This is why the modern guidance from the ACSC and from NIST has moved away from forced complexity and rotation towards longer passphrases. A short password with a substituted character and a number on the end is easy for a person to forget and cheap for a machine to guess. A long passphrase is the reverse.
What to change
- Increase minimum length substantially, and stop forcing periodic rotation without cause. Rotation pushes people towards predictable patterns, which makes guessing easier rather than harder.
- Screen against known breached passwords. Most credential attacks reuse passwords that have already appeared in public breach corpora. Blocking those is a larger practical win than any complexity rule.
- Treat service accounts differently. Nobody types them, so there is no reason for them to be short. Use group managed service accounts where possible, so the password is long, random and rotated automatically.
- Enable multi-factor authentication on anything internet-facing. A cracked password that is not sufficient on its own is a much smaller problem.
- Audit your own environment. A controlled password audit performed as part of an internal penetration test tells you how many accounts would fall, and to what kind of guess, which is a far more persuasive argument for policy change than a general recommendation.
Reduce what can be captured in the first place
Cracking only matters if authentication material can be collected. Disabling LLMNR and NBT-NS, enforcing SMB signing, enabling Credential Guard on supported systems and tiering administrative accounts all reduce the opportunity to capture it, which is a more durable fix than assuming every password will hold.
Siege Cyber is a CREST-accredited provider of penetration testing across Australia. Get a Fixed-Price Quote.
