Open cardosec

Case 78C4D4 · Identity & AD · L4 Advanced

NTLM Relay

Practise as: Explain it · Interview · Deep dive

Interview questionExplain NTLM relay and the controls that actually break it.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Attacker sits in the middle and forwards a victim NTLM authentication to another server, logging in as the victim
  2. Victims are often coerced or tricked into authenticating (LLMNR/NBT-NS poisoning, forced auth via printer/EFS RPC)
  3. SMB signing breaks relay to SMB; LDAP signing breaks relay to LDAP, but only channel binding (EPA) stops it on LDAPS
  4. Extended Protection for Authentication (EPA) on HTTP services like AD CS web enrollment stops relay to HTTP
  5. Long-term: disable LLMNR/NBT-NS, restrict NTLM via GPO auditing first, then move services to Kerberos

If the interviewer pushes back

  • MS08-068 blocked SMB-to-SMB reflection to the same host. How have cross-protocol reflection bugs since brought it back?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.