Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Pass The Hash?
Articles

Pass The Hash?

ISBuzz TeamBy ISBuzz TeamMarch 5, 20145 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
pass-the-hash
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

There was a time many moons ago when in an age of innocence “Pass The Hash” had a whole other meaning. For some of us old enough to remember, or that still have our wits about us, “Pass The Hash” was something you did at the back of the school on a Friday night. But times move on, and suddenly it seems that “Pass The Hash” is in vogue again.

But like so many other things, the meaning has changed. I recently heard Craig Groeschel talking about how words have changed. Ridiculous now means “really good”, sick means “cool”, bad means “good”. And by the way if you’re wondering how someone who played “Pass the Hash” knows about Craig Groeschel, well that’s a cool – as in nice not cold – story. Anyway I digress.

Suddenly it seems that “Pass The Hash” is back in vogue. You’d think it had only just been discovered, and that this is suddenly the latest exploit that is about to be unleashed on the corporate landscape. Yes, within a week or two you’ll be having the inside sales departments calling to ask if you have “PTH” problems. In fact come April, we can expect to see every vendor in the security space having “PTH” solutions on their stands at tradeshows. This of course will be followed by the PTH User Groups sponsored by vendors desperately trying to save you from PTH attacks. APTs will have become a distant memory as that was all solved in 2013. 2014 – The year of PTH!

What Is It?

Unfortunately it is not as interesting as the original, and it certainly is not going to give you a mellow feeling.

Now if like me you haven’t graduated much beyond understanding the “original hash”, it has loads to do with maths – which is probably why I should ask my wife to write this, since she has the math’s degree.

A “pass the hash” (PTH) attack can happen when just the password hash is sufficient to authenticate a user to a system.  This is more of an issue on older windows systems such as XP and 2003. Because of the way in which administrative accounts were set up and stored on a system, it means that very often the local administrator account is vulnerable. And because it is used for many administrative tasks such backups, patching, installing software, etc., it becomes a security risk. If one of the machines is compromised, and the local hashes can be dumped out of the Security Account Manager (SAM) database which is present on servers running Windows Server 2003. The SAM stores user accounts for users on the local computer, so if an attacker has now gained administrative access to that machine, other machines on the networks become easy targets.

Newer versions of Windows are less vulnerable because of the way in which a machine acts when added to a domain, but it still carries risk. If you’d like a more intelligent description, you should have a look at “Still Passing the Hash 15 Years Later” at http://passing-the-hash.blogspot.nl/2012/12/wth-is-pth.html. At this point I should confess that imitation is the best form of flattery. and you will see that much of my “research” came from the site! My thanks to the authors!

Where Does It Leave Us?

Contrary to the claims of certain security vendors, PTH is neither new, nor solved by simply changing administrative passwords.

That is unless by administrative passwords you mean, administrators, service accounts, scheduled tasks, and all the other accounts in a system that are likely to be using the Administrative password. Simply changing your administrator user password is not going to protect you. It may give you that nice feeling that the original PTH gave, but you can be sure that one of these days you are going to wake up with a terrible headache, and discover that changing your admin accounts didn’t offer any real satisfaction.

Ultimately you need to have a complete inventory of everything from your registry onwards. And it’s no good having last week’s inventory!

Constantly Vigilant

Vigilance was key in the original PTH scenario. Someone had to be constantly on the lookout for “hackers”, be they teachers, parents or the dreaded “I am the law”. And the same applies with the 21st century PTH. Organizations need to have continuous monitoring in place for the complete Windows environment, and be dynamically discovering every location throughout the environment that an account is referenced by a Windows service, task, COM/DCOM object, or AT account.

Discovering where the accounts are used is half the battle. And snapshots in time are not going to do it. It didn’t work in the old PTH days, and it doesn’t work now. You can’t manage what you don’t know, and unless you are checking continuously you will get caught. I know from past experience!! And of course should you decide to change the passwords regularly, don’t end up starting some process to change passwords by creating yet another password on that system so that you can logon on to change the passwords. Ah yes, you’re saying to yourself this doesn’t make any sense. And you’d be right, it doesn’t.. But that’s another story.

Is There A Moral?

I suppose you could say that PTH has never been good for anyone, and both variants can be life changing, and not necessarily for the better. Pass The Hash in IT terms has been around for close to fifteen years, and exploits were available several years ago. It’s not a new vulnerability, but it is something that you should be aware of. Taking proper precautions such as ensuring that passwords are changed regularly will help. It is also important to ensure that services and scheduled tasks are not using the same passwords across your infrastructure. For example segment your environment in such a way that a breach can be contained, and always be vigilant. Now please “Pass the Hash”

Calum McLeod, VP of EMEA at Lieberman Software

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}