Skip to content
OnlineHashCrack

How to Extract Windows LM and NTLM Password Hashes

Where Windows stores LM and NTLM hashes, how to read a SAM dump and which hashcat mode to use to recover the password.

Extracting LM and NTLM password hashes from Windows

The short answer

  • LM is the legacy pre-NT 3.1 hash format; NTLM replaced it and is what modern Windows (Vista and later) stores by default.
  • A SAM dump line has four colon-separated fields: username, SID (RID), LM hash, NTLM hash. On modern Windows the LM field reads NO PASSWORD*********************.
  • Submit the NTLM field (hashcat mode 1000) for recovery; an enabled LM hash, when present, is far weaker and worth submitting too.
  • Extraction (from a SAM you administer, or from memory on a system you are authorized to test) requires local admin or physical access — this guide does not cover bypassing that.

LM and NTLM basics

/!\ This is for educational purposes only, and should not be used for unauthorized access, tampering or accessed illegally without owner permission.

The LM hash is the old style hash used in Microsoft OS before NT 3.1. Then, NTLM was introduced and supports password length greater than 14.
On Vista, 7, 8 and 10 LM hash is supported for backward compatibility but is disabled by default.

The goal is to extract LM and/or NTLM hashes from the system, either live or dead. These hashes are stored in memory (RAM) and in flat files (registry hives).

Extracting the hashes from the SAM (locally)

If LM hashes are enabled on your system (Win XP and lower), a hash dump will look like:

Administrator:500:01FC5A6BE7BC6929AAD3B435B51404EE:0CB6948805F797BF2A82807973B89537:::

If LM hashes are disabled on your system (Win Vista, 7, 8+), a hash dump will look like:

Administrator:500:NO PASSWORD*********************:0CB6948805F797BF2A82807973B89537:::

The first field is the username. The second field is the unique Security IDentifier for that username. The third field is the LM hash and the forth is the NTLM hash.

Extracting Windows Password hashes from memory (RAM)

You can use :

A Note on Extraction Accuracy

A large number of -old- tools, which extract hashes from the registry were confirmed as producing corrupted hashes when using the registry extraction method were as follows :

  • Metasploit Hashdump Script
  • Creddump
  • Samdump2 1.0.1
  • Cain and Abel
  • Pwdump
  • Pwdump5
  • Pwdump7
  • FGDump 3.0
  • l0phtcrack 6.0

More information about this issue : Stamp Out Hash Corruption, Crack All the Things! - BlackHat 2012

Hash extracted?Submit the NTLM (or LM) hash and OHC runs GPU-accelerated recovery on it.

Windows password hashes: frequently asked questions

What is the difference between an LM hash and an NTLM hash?

LM is the original, weak hash format used before Windows NT 3.1. NTLM replaced it, supports passwords longer than 14 characters, and is what current Windows versions store; LM is disabled by default since Vista.

How do I read a SAM dump line?

Each line has four colon-separated fields: username, security identifier (RID), LM hash, and NTLM hash. A disabled LM hash shows as a fixed placeholder rather than a real value.

Which hashcat mode matches a Windows NTLM hash?

Mode 1000. Submit just the NTLM hash field, not the whole SAM line.

Do I need administrator access to get these hashes?

Yes. Reading the SAM database or dumping credentials from memory both require local administrator privileges or physical access to the machine, and must only be done on systems you own or are explicitly authorized to test.

Can OnlineHashCrack recover an NTLM password?

Yes, submit the extracted NTLM hash and OHC runs wordlist, rule and mask attacks against it on GPU.

Further reading

Related guides on Online Hash Crack: