Case 78C4D4 · Identity & AD · L4 Advanced
NTLM Relay
Practise as: Explain it · Interview · Deep dive
Interview questionExplain NTLM relay and the controls that actually break it.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Attacker sits in the middle and forwards a victim NTLM authentication to another server, logging in as the victim
- Victims are often coerced or tricked into authenticating (LLMNR/NBT-NS poisoning, forced auth via printer/EFS RPC)
- SMB signing breaks relay to SMB; LDAP signing breaks relay to LDAP, but only channel binding (EPA) stops it on LDAPS
- Extended Protection for Authentication (EPA) on HTTP services like AD CS web enrollment stops relay to HTTP
- Long-term: disable LLMNR/NBT-NS, restrict NTLM via GPO auditing first, then move services to Kerberos
If the interviewer pushes back
- MS08-068 blocked SMB-to-SMB reflection to the same host. How have cross-protocol reflection bugs since brought it back?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.