LM and NT are unsalted hash algorithms used to store password credentials. NTLMv1 and NTLMv2 are authentication protocols built on these hashes; Kerberos is the preferred authentication method.

LM Hashes

LAN Manager (LM) hashes are stored in the SAM database and have been disabled since 2008. They can be disallowed through Group Policy.

  • Maximum password length: 14 characters.
  • The algorithm splits the password into two seven-character chunks, allowing an attacker to brute-force each chunk separately rather than all 14 characters.

NT Hashes and NTLM Authentication

NTLM uses a challenge-response exchange with three messages:

StepMessageDescription
1NEGOTIATE_MESSAGESent by the client to the server.
2CHALLENGE_MESSAGEServer response containing an eight-byte random number.
3AUTHENTICATE_MESSAGEClient response containing a 24-byte response.

NT hashes can still be brute-forced and are vulnerable to pass-the-hash attacks.

Hash Format

Rachel:500:aad3c435b514a4eeaad3b935b51304fe:e46b9e548fa0d122de7f59fb6d48eaa2:::
FieldDescription
RachelUsername.
500Administrator RID.
aad3c435b514a4eeaad3b935b51304feLM hash; not useful when LM hashes are disabled.
e46b9e548fa0d122de7f59fb6d48eaa2NT hash.

NTLMv2

Unlike NTLMv1, NTLMv2 sends two responses to the server’s eight-byte challenge to prevent spoofing attacks:

  • A 16-byte HMAC-MD5 of the challenge.
  • A variable-length client challenge containing the current time, an eight-byte random value, and the domain name.

Domain Cached Credentials

Domain Cached Credentials (MSCache2) allow logon when a domain-joined host cannot communicate with a domain controller. The host saves the last ten hashes for domain users in HKEY_LOCAL_MACHINE\SECURITY\Cache.

MSCache2 hashes cannot be used for pass-the-hash attacks and are difficult to crack.