ALL PASS, NO FAIL!

CEH v13 Module 6: System Hacking

System hacking involves gaining unauthorized access to target systems and maintaining that access. This module covers password cracking methods, privilege escalation techniques, file system attacks, service exploitation, malware deployment, steganography, and post-exploitation cover-your-tracks activities.

The CEHStudy app carries 32 flashcards for Module 6 across 7 sections — work the Windows password-storage deck first, then move through cracking, buffer overflows, and privilege escalation in order.

Key Topics Covered

Important Terms & Concepts

Password Cracking: The process of recovering passwords from encrypted/hashed data using methods like brute-force (trying all combinations), dictionary (common words), rainbow tables (precomputed hashes), and hybrid attacks.
Rainbow Table: A precomputed table of hash values for every possible password combination. Used to reverse cryptographic hash functions quickly — defeated by password salting.
Privilege Escalation: Exploiting a bug or design flaw to gain higher access levels (e.g., standard user → Administrator). Can be vertical (more privileges) or horizontal (same level, different account).
UAC Bypass: Techniques to bypass Windows User Account Control: DLL side-loading, job objects, replace existing process, trusted developer policies.
LM Hash: Legacy Windows password hash — extremely weak, max 14 chars split into two 7-char halves. Easily cracked with tools like John the Ripper.
NTDS.dit: Active Directory database file containing all domain account hashes. Extracted using tools like ntdsutil or volume shadow copy exploitation.
Alternative Data Streams (ADS): NTFS feature allowing hidden data within files. Commonly used by malware for persistence: echo secret > file.txt:hidden.txt
Rootkit: Malicious software designed to hide the existence of other malware by intercepting and modifying OS calls at the kernel level.

How to Study This Module

Frequently Asked Questions

What is the most common password attack?
Dictionary attacks are the most commonly used because they balance speed and effectiveness. Most users choose weak, dictionary-based passwords.

How do you prevent privilege escalation?
Apply security patches promptly, disable unnecessary services, configure proper NTFS permissions, enable LSA protection, and restrict administrator privileges.

Related Modules

What is System Hacking in Ethical Hacking?

System Hacking is a critical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers gaining access to target systems, maintaining that access through persistence mechanisms, and escalating privileges to maximum control — password cracking, UAC bypass and token manipulation, NTFS permissions and alternate data streams, credential dumping from SAM and NTDS.dit, rootkits, lateral movement and cover-your-tracks. Module 6 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in System Hacking

Common Exam Mistakes in Module 6

Mixing up where hashes actually live: SAM holds only the local machine's account hashes in %SystemRoot%\system32\config\SAM (registry hive HKEY_LOCAL_MACHINE\SAM), and the file cannot be copied while Windows is running — memory dumping with Mimikatz is the standard move. Domain account hashes live in ntds.dit on the domain controller, so "dump SAM to get every user" is a wrong answer.
Swapping Golden Ticket for Silver Ticket: a Golden Ticket forges the TGT and requires the KRBTGT account hash — opening every service in the domain, indefinitely. A Silver Ticket forges a single service ticket (TGS) from a specific service — blast radius: one service. The exam pairs both with Mimikatz; the KRBTGT detail is the usual give-away clue.
Treating spraying as just slow brute force: password spraying tries one common password against many accounts at a time to stay under per-account lockout thresholds — the opposite of hammering a single account. Likewise, AS-REP roasting only works on users with Kerberos pre-authentication DISABLED; the negation is the part the exam tests.

Tools Used in System Hacking

Tools the CEH v13 exam references for this domain, by job:

Worked Example: From a Standard-User Shell to Domain Hashes

You have a standard-user shell on a workstation joined to the corp.local domain. You start Responder on the link; a legacy application issues an LLMNR query, the poisoned response points the host at your machine, and an NTLMv2 hash lands in your capture. Rather than cracking it, you pass-the-hash directly to authenticate against a domain resource, then — once you hold an account with replication rights — run lsadump::dcsync against the domain controller to extract NTLM hashes at scale.

Why this order matters: each hop is an exam answer — LLMNR poisoning for the first hash, PtH for access without cracking, DCSync for mass extraction. The follow-up is usually persistence: with a KRBTGT hash, a forged Golden Ticket gives indefinite, domain-wide access — which is why defenders rotate that account.

How to Study System Hacking for the CEH v13 Exam

To study Module 6:

  1. Know the cracking methods and defenses: brute-force (lockout policies), dictionary (complexity requirements), rainbow table (salting), hybrid (strong complexity + length)
  2. Trace the credential chain: SAM → NTLM hash → lsass.exe in memory → Mimikatz extraction → pass-the-hash to other systems
  3. Hands-on: in a VirtualBox Windows 10 VM, enable anonymous SID/Name resolution in Local Security Policy, extract SAM with samdump2, crack NTLM hashes offline with Hashcat, and document the process
  4. Review Module 5 (Vulnerability Analysis) — the vulnerabilities that enable system hacking — and Module 7 (Malware Threats) — malware deployment after initial access

Frequently Asked Questions About System Hacking

What is pass-the-hash and why is it significant on the CEH exam?

Pass-the-hash is a lateral movement technique: authenticate to other systems with a stolen NTLM or NTLMv2 hash, without ever knowing the plaintext password. Windows authentication compares hashes — it never requires the password over the network — so valid admin hashes from one system work on every system where that account has admin rights. High-frequency exam topic: know NTLM challenge-response, hash storage (SAM, NTDS.dit, lsass memory), and detection/prevention (disable NTLM, enforce SMB signing, monitor for anomalous logon types 3).

How does UAC differ from a full privilege separation model?

UAC (User Account Control) is not a true privilege separation model — it is a prompt-based system that asks for consent when an application requests elevation. The user's token holds both a filtered (standard user) and an elevated (admin) portion, and UAC chooses between them per request; in a real separation model, processes run as standard user by default and must explicitly request elevated operations. The exam tests why this matters: UAC can be bypassed by techniques (DLL hijacking, FOD abuse, COM Elevation Moniker) that trick the prompt or avoid it entirely.

Related CEH v13 Modules

Related Glossary Terms