Open cardosec

Case FEA989 · Network · L3 Applied

LLMNR and NBT-NS Poisoning

Practise as: Explain it · Interview

Interview questionAn internal pentester captured NetNTLMv2 hashes within minutes of plugging in. What happened and how do you fix it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. When DNS fails, Windows falls back to multicast LLMNR (UDP 5355) and NBT-NS (UDP 137) name resolution
  2. Responder answers those multicast and broadcast queries, so victims authenticate to it and leak NetNTLMv2 responses
  3. Hashes are cracked offline or relayed (ntlmrelayx) to SMB, LDAP or HTTP services that lack signing or EPA
  4. Fix: disable LLMNR and NetBIOS over TCP/IP; require SMB signing, LDAP signing and channel binding, and EPA on HTTP
  5. Also mitigate WPAD abuse and prefer Kerberos; restrict or audit NTLM usage

If the interviewer pushes back

  • Why does SMB signing stop relay but not offline cracking of the captured hash?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.