Case FEA989 · Network · L3 Applied
LLMNR and NBT-NS Poisoning
Practise as: Explain it · Interview
Interview questionAn internal pentester captured NetNTLMv2 hashes within minutes of plugging in. What happened and how do you fix it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- When DNS fails, Windows falls back to multicast LLMNR (UDP 5355) and NBT-NS (UDP 137) name resolution
- Responder answers those multicast and broadcast queries, so victims authenticate to it and leak NetNTLMv2 responses
- Hashes are cracked offline or relayed (ntlmrelayx) to SMB, LDAP or HTTP services that lack signing or EPA
- Fix: disable LLMNR and NetBIOS over TCP/IP; require SMB signing, LDAP signing and channel binding, and EPA on HTTP
- Also mitigate WPAD abuse and prefer Kerberos; restrict or audit NTLM usage
If the interviewer pushes back
- Why does SMB signing stop relay but not offline cracking of the captured hash?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.