logo

An SMB Relay Race – How To Exploit LLMNR and SMB Message Signing for Fun and Profit

ID: f7cd3f0d-6eff-5ae8-99e4-ff775da3acff

STIX ID: report--f7cd3f0d-6eff-5ae8-99e4-ff775da3acff

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2019-04-08

Date Updated: 2026-04-27

Author: BHIS

...
...

This write-up demonstrates a practical NTLM relay attack chain: harvesting credentials via OWA (password spray and GAL extraction), using LLMNR/NBNS poisoning and SMB relay (Responder + Impacket ntlmrelayx) to reflect NetNTLMv2 hashes to systems with SMB signing disabled, and leveraging those hashes to dump SAM/LSA and obtain domain admin access; mitigations recommended include enabling SMB message signing, disabling LLMNR/NBNS, and improving DNS and network configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.