System hacking involves gaining unauthorized access to target systems and maintaining that access. This module covers password cracking methods, privilege escalation techniques, file system attacks, service exploitation, malware deployment, steganography, and post-exploitation cover-your-tracks activities.
The CEHStudy app carries 32 flashcards for Module 6 across 7 sections — work the Windows password-storage deck first, then move through cracking, buffer overflows, and privilege escalation in order.
Privilege escalation techniques: token manipulation, UAC bypass, service exploitation
File system attacks: NTFS permissions, alternative data streams (ADS), fileless techniques
Service exploitation and backdoor installation
Password hashing: LM hashes, NTLM hashes, SAM database
Masking access: log clearing, rootkit installation, process hiding
Steganography and stegotography techniques
Post-exploitation: credential dumping, lateral movement
Important Terms & Concepts
Password Cracking: The process of recovering passwords from encrypted/hashed data using methods like brute-force (trying all combinations), dictionary (common words), rainbow tables (precomputed hashes), and hybrid attacks.
Rainbow Table: A precomputed table of hash values for every possible password combination. Used to reverse cryptographic hash functions quickly — defeated by password salting.
Privilege Escalation: Exploiting a bug or design flaw to gain higher access levels (e.g., standard user → Administrator). Can be vertical (more privileges) or horizontal (same level, different account).
UAC Bypass: Techniques to bypass Windows User Account Control: DLL side-loading, job objects, replace existing process, trusted developer policies.
LM Hash: Legacy Windows password hash — extremely weak, max 14 chars split into two 7-char halves. Easily cracked with tools like John the Ripper.
NTDS.dit: Active Directory database file containing all domain account hashes. Extracted using tools like ntdsutil or volume shadow copy exploitation.
Alternative Data Streams (ADS): NTFS feature allowing hidden data within files. Commonly used by malware for persistence: echo secret > file.txt:hidden.txt
Rootkit: Malicious software designed to hide the existence of other malware by intercepting and modifying OS calls at the kernel level.
How to Study This Module
Understand each password cracking method and when to use it (brute-force vs dictionary vs rainbow tables)
Memorize privilege escalation techniques, especially UAC bypass methods
Know the difference between LM and NTLM hash formats
Understand how rootkits hide malicious processes and files at the kernel level
Frequently Asked Questions
What is the most common password attack? Dictionary attacks are the most commonly used because they balance speed and effectiveness. Most users choose weak, dictionary-based passwords.
How do you prevent privilege escalation? Apply security patches promptly, disable unnecessary services, configure proper NTFS permissions, enable LSA protection, and restrict administrator privileges.
Related Modules
Module 4: Enumeration — enumeration data feeds into password cracking and system access
System Hacking is a critical domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers gaining access to target systems, maintaining that access through persistence mechanisms, and escalating privileges to maximum control — password cracking, UAC bypass and token manipulation, NTFS permissions and alternate data streams, credential dumping from SAM and NTDS.dit, rootkits, lateral movement and cover-your-tracks. Module 6 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in System Hacking
Password Cracking Methodologies: Brute-force tries every character combination (2^length for the character set). Dictionary attacks use pre-compiled word lists — far faster against weak passwords. Hybrid attacks combine dictionary words with numeric suffixes or leet-speak substitutions. Rainbow tables precompute hash chains for O(1) reverse lookups but are defeated by salting — random data added to each password before hashing. Know when to use each method and how to defend.
Privilege Escalation & UAC Bypass: Vertical privilege escalation (user → admin) is the primary goal after initial access. UAC bypass techniques include DLL side-loading (a malicious DLL with the same name as a trusted one), Job Object abuse, FOD (Files on Demand) hijacking, and unquoted service paths. UAC is not full protection — it only asks for user consent on elevation, and multiple techniques can trick or avoid that prompt.
Credential Dumping & Pass-the-Hash: The SAM database (C:\Windows\System32\config\SAM) stores local account NTLM hashes; NTDS.dit on domain controllers stores all domain account hashes. Mimikatz extracts them in memory via lsass.exe process injection. Pass-the-hash then authenticates to other systems with the hash alone — no plaintext password needed. A high-frequency lateral movement topic.
Rootkits & Process Hiding: Rootkits intercept system calls to hide malicious processes, files, registry keys and network connections from users and security software. User-mode rootkits patch specific functions in memory; kernel-mode rootkits hook the SSDT (System Service Descriptor Table) or use kernel modules. Detection compares in-memory data structures with disk-based ones — tools like RootkitRevealer or GMER.
Common Exam Mistakes in Module 6
Mixing up where hashes actually live: SAM holds only the local machine's account hashes in %SystemRoot%\system32\config\SAM (registry hive HKEY_LOCAL_MACHINE\SAM), and the file cannot be copied while Windows is running — memory dumping with Mimikatz is the standard move. Domain account hashes live in ntds.dit on the domain controller, so "dump SAM to get every user" is a wrong answer.
Swapping Golden Ticket for Silver Ticket: a Golden Ticket forges the TGT and requires the KRBTGT account hash — opening every service in the domain, indefinitely. A Silver Ticket forges a single service ticket (TGS) from a specific service — blast radius: one service. The exam pairs both with Mimikatz; the KRBTGT detail is the usual give-away clue.
Treating spraying as just slow brute force: password spraying tries one common password against many accounts at a time to stay under per-account lockout thresholds — the opposite of hammering a single account. Likewise, AS-REP roasting only works on users with Kerberos pre-authentication DISABLED; the negation is the part the exam tests.
Tools Used in System Hacking
Tools the CEH v13 exam references for this domain, by job:
Mimikatz: credential dumping from memory, pass-the-hash, DCSync (lsadump::dcsync), Golden/Silver Ticket forgery — the most cited tool in this module
Hashcat / John the Ripper: offline cracking of captured LM/NTLM and Kerberos hashes — Hashcat needs the right mode flag (e.g., -m 0 for MD5); L0phtCrack and RainbowCrack cover Microsoft hash recovery and precomputed rainbow tables
Responder: poisons LLMNR, NBT-NS and mDNS name-resolution requests to capture NTLMv2 hashes; Vindicate and got-responded are the detection-side counterparts
Metasploit Framework: exploit, payload (stager/stage/singles), auxiliary, NOP, encoder, evasion and post-exploitation modules; pattern_create and pattern_offset locate the exact EIP-overwrite offset in a fuzzer run
CrackMapExec / Rubeus / adfsbrute: domain attack utilities — Rubeus drives Kerberos operations, adfsbrute attacks ADFS, CrackMapExec sweeps for weak credentials and misconfigurations at scale
THC-Hydra: online dictionary and brute-force attacks against login services with wordlist files
Spartacus / Dylib Hijack Scanner: DLL hijacking (Windows) and dylib hijacking (macOS) utilities for privilege escalation; Dependency Walker spots the missing-library condition first
WinPEAS / PEASS-ng / PowerSploit and PowerView: post-exploitation enumeration scripts that sweep a host or domain for privesc paths across Windows, Linux and PowerShell environments
Worked Example: From a Standard-User Shell to Domain Hashes
You have a standard-user shell on a workstation joined to the corp.local domain. You start Responder on the link; a legacy application issues an LLMNR query, the poisoned response points the host at your machine, and an NTLMv2 hash lands in your capture. Rather than cracking it, you pass-the-hash directly to authenticate against a domain resource, then — once you hold an account with replication rights — run lsadump::dcsync against the domain controller to extract NTLM hashes at scale.
Why this order matters: each hop is an exam answer — LLMNR poisoning for the first hash, PtH for access without cracking, DCSync for mass extraction. The follow-up is usually persistence: with a KRBTGT hash, a forged Golden Ticket gives indefinite, domain-wide access — which is why defenders rotate that account.
How to Study System Hacking for the CEH v13 Exam
To study Module 6:
Know the cracking methods and defenses: brute-force (lockout policies), dictionary (complexity requirements), rainbow table (salting), hybrid (strong complexity + length)
Trace the credential chain: SAM → NTLM hash → lsass.exe in memory → Mimikatz extraction → pass-the-hash to other systems
Hands-on: in a VirtualBox Windows 10 VM, enable anonymous SID/Name resolution in Local Security Policy, extract SAM with samdump2, crack NTLM hashes offline with Hashcat, and document the process
What is pass-the-hash and why is it significant on the CEH exam?
Pass-the-hash is a lateral movement technique: authenticate to other systems with a stolen NTLM or NTLMv2 hash, without ever knowing the plaintext password. Windows authentication compares hashes — it never requires the password over the network — so valid admin hashes from one system work on every system where that account has admin rights. High-frequency exam topic: know NTLM challenge-response, hash storage (SAM, NTDS.dit, lsass memory), and detection/prevention (disable NTLM, enforce SMB signing, monitor for anomalous logon types 3).
How does UAC differ from a full privilege separation model?
UAC (User Account Control) is not a true privilege separation model — it is a prompt-based system that asks for consent when an application requests elevation. The user's token holds both a filtered (standard user) and an elevated (admin) portion, and UAC chooses between them per request; in a real separation model, processes run as standard user by default and must explicitly request elevated operations. The exam tests why this matters: UAC can be bypassed by techniques (DLL hijacking, FOD abuse, COM Elevation Moniker) that trick the prompt or avoid it entirely.