logo

MITM6 Strikes Again: The Dark Side of IPv6  

ID: 0c2ee84e-13ba-5d71-8d6a-48ca494c43aa

STIX ID: report--0c2ee84e-13ba-5d71-8d6a-48ca494c43aa

Feed Name: Black Hills Infosec Blog

Date Published: 2023-02-14

Date Updated: 2026-04-27

Author: BHIS

...
...

This article outlines how MITM6 attacks exploit unmanaged IPv6 in predominantly IPv4 networks to hijack DNS and relay NTLM authentication (using tools like mitm6 and Impacket) to gain domain privileges and exfiltrate password hashes via DCSync, and it provides practical defenses including disabling unused IPv6, turning off WPAD auto-detection or explicitly configuring PAC, enforcing SMB/LDAP signing, and enabling Extended Protection for Authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.