NTLM
NTLM
MD4 of a password in UTF-16LE, no salt at all.
- Digest
- 128-bit · 16 bytes
- HMAC
- no key mode
- Security
- BROKEN as a password hash: no salt and no cost
- Used by
- Windows
Sample
- hex
- e1cf2a4200eecdf14a4691bbf1ba255a
- base64
- 4c8qQgDuzfFKRpG78bolWg==
Options
Access
- Create
create("ntlm") - CLI
hashes ntlm 'hello world' - Tryplayground with the sample above
- Kinmd5, md4
The hash in a Windows SAM dump and the one pass-the-hash replays. It's MD4 over the password's UTF-16LE bytes, and that's the whole recipe. No salt. No cost. No rounds.
create("ntlm").hash("password").digest; // "8846f7eaee8fb117ad06bdd830b7586c"
create("ntlm").hash("Password").digest; // "a4f49c406510bdcab6824ee7c30fd852"
create("md4").hash("password").digest; // "8a9d093f14f8701df17732b2bb182c74"
The last line is the usual mistake. MD4 of the UTF-8 bytes isn't the NT hash, every character needs its second byte.
So what does ntlm read? Text. Bytes go in as UTF-8 and come out as UTF-16LE, a BOM included. Bytes that aren't UTF-8 get a HashError, because there's no password they could spell. Hex input in a tool call or the CLI works the same way: 70617373776f7264 is password, and it gives 8846f7ea… too.
Same password, same hash, on every machine. One precomputed table covers every account that picked it. Hashcat calls this mode 1000. Here it's for checking what you found, not for storing anything.