What is Pass-the-Hash?
A hacking technique that allows an attacker to authenticate to a remote server or service by using the underlying NTLM or LanMan hash of a user’s password, instead of requiring the associated plaintext password.
Why it matters
Understanding this concept helps in grasping how modern networks and security systems operate, providing a foundation for more advanced topics.
Real-world Analogy
Like showing the bouncer a perfect photocopy of a VIP stamp on your hand, rather than showing him the actual ID required to get the stamp.
Other Dictionary Terms
Access Control List (ACL)
A list of rules that specifies which users or systems are granted or denied access to a particular object or system resource.
Dictionary TermAdvanced Persistent Threat (APT)
A stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.
Dictionary TermARP Spoofing
A type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network.