ShuckNT 是 Shuck.sh 在线服务用于本地部署的脚本(在线试用!)。它旨在降级、转换、剖析和脱壳基于数据加密标准(DES)的身份验证令牌。
支持的算法 / 格式:
$99$ShuckNT 依赖哈希脱壳原理来优化挑战-响应破解和可利用性。
密码脱壳是一种从更新后的密码哈希中剥离分层的方法,移除其新密码哈希算法带来的优势,并将其还原为较弱的算法。攻击者可以针对旧的重新哈希密码或预哈希密码使用密码脱壳,从而剥离或“脱去”强外层密码哈希算法。
从输入令牌列表中,ShuckNT 提供:
在 Shuck.sh 脚本 ShuckNT 的背后,本质上是在自定义的反转二进制 HIBP 数据库中,针对候选 NT-hash 子集(其最后两个字节已知)进行高效且优化的 DES 密钥碰撞二分搜索。
在(时间有限的)安全评估期间,如果你通过 Responder 等工具捕获约 100 个 NetNTLMv1(无论是否使用 ESS),通过 Shuck.sh/ShuckNT 搜索对应的 NT-Hash(若已泄露到 HIBP)只需几秒钟(约 10 秒)。
Shuck.sh 的脚本 ShuckNT 负责通过将加密算法转换为较弱形式来进行简化(在可能的情况下去除 ESS,转换为 Crack.Sh 的免费格式,或者如果已在 HIBP 中泄露则直接转换为 NT-Hash 格式)。因此,NetNTLMv1-ESS/SSP、PPTP VPN 或 MSCHAPv2 挑战值(在 Crack.Sh 上既不免费又耗时)有可能被即时免费脱壳!
Shuck.sh/ShuckNT 的最初想法源于在为客户进行安全评估时节省时间的愿望,不依赖可用性不一定持续的第三方在线服务,并且能够在本地自主运行。
安装过程包括:
安装命令:
# Install dependencies
apt install p7zip-full php git
# Get ShuckNT tool
git clone https://github.com/yanncam/ShuckNT
cd ShuckNT
# Prepare HaveIBeenPwned database (one time only, takes several minutes)
## Download latest HIBP-DB (can take severals minutes...)
wget https://downloads.pwnedpasswords.com/passwords/pwned-passwords-ntlm-ordered-by-hash-v8.7z
## Extract HIBP-DB (can take severals minutes...)
7z e pwned-passwords-ntlm-ordered-by-hash-v8.7z
## Reverse all hashes (can take severals minutes...)
php shucknt.php -r pwned-passwords-ntlm-ordered-by-hash-v8.txt -t pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed
## Sort all reversed-hashes (can take severals minutes...)
sort pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed -o pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed-sorted
## Convert to binary format (can take severals minutes...)
php shucknt.php -b pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed-sorted -t pwned-passwords-ntlm-reversed-ordered-by-hash-v8.bin
## Free space to keep only pwned-passwords-ntlm-reversed-ordered-by-hash-v8.bin
rm -f pwned-passwords-ntlm-ordered-by-hash-v8.7z
rm -f pwned-passwords-ntlm-ordered-by-hash-v8.txt
rm -f pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed
rm -f pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed-sorted
# Enjoy ShuckNT via commandline, or web http://[HOST]/shucknt.php
php shucknt.php -h
以 ShuckNT 所期望的格式生成数据库需要在 Unix/Linux 系统下完成。
ShuckNT 与有效数据库一起使用已在 Windows/Linux 上通过 PHP7/8+ 测试过。
请注意,ShuckNT 使用 PHP-OpenSSL 扩展的 DES-ECB 算法。因此,对于使用 OpenSSL3 的新版 PHP,请启用 legacy provider。
每一步的校验和:
$ sha1sum pwned-passwords-ntlm-*
225a993a908e3d73ffa68859c4f128e17359358e pwned-passwords-ntlm-ordered-by-hash-v8.7z
4b6c4728c21f64d6a58c7b63d98dcf342c068407 pwned-passwords-ntlm-ordered-by-hash-v8.txt
88094c4a332ecfac9a15c23ba886194d1810b0b2 pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed
d5486dfbf960f36ff0e1cf313a1b80db5cd4137f pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed-sorted
31a5c1b605cca5bcf71196c70f291c05aa3fe86c pwned-passwords-ntlm-reversed-ordered-by-hash-v8.bin
$ sha256sum pwned-passwords-ntlm-*
ea83d536387e6b149f2e362bf7dfbf521523812611359f47620fd44dae9770ee pwned-passwords-ntlm-ordered-by-hash-v8.7z
916cfd1772d24f2fe99aa5f37d4a465359c7b6f7d39f45ffbf27deca697b7116 pwned-passwords-ntlm-ordered-by-hash-v8.txt
76f9e101801dfc44489cad4edec5f14d634c2b4676bb9ffbc7e9968c9a5356a5 pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed
6ee13a35ed88e8073be088a20560cb9fefcc6d08e599241244eaee01dc053a44 pwned-passwords-ntlm-ordered-by-hash-v8.txt-reversed-sorted
ac2f6bf681fbe636b94f3ce3f2b594ef3d0af7671375478db1153874e8a5d873 pwned-passwords-ntlm-reversed-ordered-by-hash-v8.bin
ShuckNT 是一个无任何依赖的独立 PHP 脚本。它可以通过 CLI 命令行 或 Web 浏览器 使用。
帮助、参数和语法:
$ php shucknt.php -h
__ _ _ __ _____
/ _\ |__ _ _ ___| | __ /\ \ \/__ \
\ \| '_ \| | | |/ __| |/ // \/ / / /\/
_\ \ | | | |_| | (__| </ /\ / / /
\__/_| |_|\__,_|\___|_|\_\_\ \/ \/ v1.0
DES-based authentication token shucker (https://shuck.sh)
@author : ycam | @asafety.fr / @yann.cam
ShuckNT is design to dowgrade, convert, dissect and shuck authentication token based on Data Encryption Standard (DES).
Algorithms / formats supported :
- NetNTLMv1(-ESS/SSP)
- MSCHAPv2
- NET(NT)LM
- (LM|NT)HASH
- PPTP-VPN $99$
- All with any challenge value!
ShuckNT rely on "hash shucking" principle to optimize challenge-response cracking and exploitability.
From a list of input tokens, ShuckNT provides :
- The NT-hash instantly (pass-the-hash ready) through a smart-research in the HaveIBeenPwned latest database (if present);
- The Crack.Sh ready-to-use optimized token, to pay less or nothing if NT-hash not found in HIBP-DB;
- Several converted formats to try to crack them via other tools (hashcat, jtr, CloudCracker, etc.) :
- Hashcat mode 5500 : to crack NetNTLMv1 to plaintext (unpredictable result, depend on wordlists, masks, rules...);
- Hashcat mode 27000: to shuck NetNTLMv1 to NT-hash (unpredictable result / depend on NT-wordlists...);
- Hashcat mode 14000: to shuck NetNTLMv1 to DES-keys then NT-hash (100% result / time needed);
- All the details of the dissection of the challenge-response (PT1/2/3, K1/2/3, CT1/2/3, HIBP occurences/candidates, LMresp, NTresp, challenges, etc.).
Use '-h' to print help.
usage: php shucknt.php [-h] [-f tokens.txt] [-i 'tokenValue'] [-w wordlist.bin] [-o json|stdout|web] [-v]
[-r input_wordlist.txt] [-b input_wordlist_reversed_sorted.txt] [-r output_wordlist] [-j]
Arguments details: