MITM6 Strikes Again: The Dark Side of IPv6
ID: 0c2ee84e-13ba-5d71-8d6a-48ca494c43aa
STIX ID: report--0c2ee84e-13ba-5d71-8d6a-48ca494c43aa
Feed Name: Black Hills Infosec Blog
This article outlines how MITM6 attacks exploit unmanaged IPv6 in predominantly IPv4 networks to hijack DNS and relay NTLM authentication (using tools like mitm6 and Impacket) to gain domain privileges and exfiltrate password hashes via DCSync, and it provides practical defenses including disabling unused IPv6, turning off WPAD auto-detection or explicitly configuring PAC, enforcing SMB/LDAP signing, and enabling Extended Protection for Authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
