An SMB Relay Race – How To Exploit LLMNR and SMB Message Signing for Fun and Profit
ID: f7cd3f0d-6eff-5ae8-99e4-ff775da3acff
STIX ID: report--f7cd3f0d-6eff-5ae8-99e4-ff775da3acff
Feed Name: Black Hills Infosec Blog
This write-up demonstrates a practical NTLM relay attack chain: harvesting credentials via OWA (password spray and GAL extraction), using LLMNR/NBNS poisoning and SMB relay (Responder + Impacket ntlmrelayx) to reflect NetNTLMv2 hashes to systems with SMB signing disabled, and leveraging those hashes to dump SAM/LSA and obtain domain admin access; mitigations recommended include enabling SMB message signing, disabling LLMNR/NBNS, and improving DNS and network configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
