NTLMv1 Downgrade
Last updated
Last updated
Client sends NTLMv1 response when LmCompatibilityLevel
exists and is 2
or lower, which can be downgraded to "NTLMv1 w/o SSP" when NtlmMinClientSec
is 0x20
or lower:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
Check with PowerShell:
Check with ():
Exploit with Responder with a known challenge of 1122334455667788
(see Authentication Coercion to trigger callbacks):
Calculate the token:
Check the final 2 bytes (4 characters) of the NT hash: