logo

mitm6 – compromising IPv4 networks via IPv6

ID: 91b5bf7f-b83a-56ab-8c60-b24bb993fd96

STIX ID: report--91b5bf7f-b83a-56ab-8c60-b24bb993fd96

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2018-01-11

Date Updated: 2026-04-27

...
...

This report describes mitm6, an IPv6-based DNS spoofing and WPAD abuse technique targeting Windows hosts that prefer IPv6 DNS: the attacker answers DHCPv6 requests to set themselves as the victim's DNS server, spoofs WPAD to force proxy usage, triggers HTTP proxy authentication, captures NTLM challenge/response, and uses ntlmrelayx to relay credentials and access internal services. The blog explains attack phases, demonstrates automation with mitm6 and ntlmrelayx, provides Snort/Suricata detection signatures, and recommends mitigations including disabling unused IPv6, disabling WPAD, and moving away from NTLM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.