Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. SQL Server
  3. Question
SQL Server

What is Windows local password NTLM hashes

Asked by Aashish Chaursiya Nov 29, 2021 1.9K views 1 answer
Share

About this question

Recently I have dumped some hashes from my local machine because I'm trying to understand the process in which Windows 7 hashes its passwords. There, I had discovered my local password hash that looks (similar) to this: Jason:502:aad3c435b514a4eeaad3b935b51304fe:c46b9e588fa0d112de6f59fd6d58eae3:::

Now what I would like to know is the meaning of the different sections, so We have this hash: Jason:502:aad3c435b514a4eeaad3b935b51304fe:c46b9e588fa0d112de6f59fd6d58eae3:::

that looks to be separated by : if we separate this by the : we end up with this:

[Jason, :, 502, :, aad3c435b514a4eeaad3b935b51304fe, :, c46b9e588fa0d112de6f59fd6d58eae3, :, :, :]


  • I'm assuming the first part Jason is the username, that's the most logical to me.
  • The third part aad3c435b514a4eeaad3b935b51304fe is the ntlm hash would be my best guess.
  • If i have assumed coreectly then that leaves c46b9e588fa0d112de6f59fd6d58eae3 and 502 left.
  • I'd guess that the other hash (c46b9e588fa0d112de6f59fd6d58eae3) is the derived key, that is created from the password itself.
  • The 502 would be the binary data of the user.
  • And the: is just a separator or padding.

Now i want to confirm, am I correct in my assumptions on what each part of the hash represents? If not can someone please explain to me what each section represents?

 

Your answer

1 Answer

More SQL Server discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest SQL Server Blogs

Guides, tips and career advice on SQL Server from JanBask experts.