Passing the hash
Passing the hash or hashdump is the process of extracting the Windows logon hash files. Hashdump meterpreter script extracts and dumps the password hashes from the target machine. Hashes can be used to crack the logon passwords and gain authorized entry into other systems on the LAN for future pen tests.
Getting ready
Before starting with the recipe, let us first understand about Windows passwords and their storage format.
When you type your password into the Windows Logon screen, it encrypts your password using an encryption scheme that turns your password into something that looks like this:
7524248b4d2c9a9eadd3b435c51404ee
This is a password hash. This is what is actually being checked against when you type your password in. It encrypts what you typed and bounces it against what is stored in the registry and/or SAM file.
The SAM file holds the usernames and password hashes for every account on the local machine, or domain if it is a domain controller. It can be found on the...