Skip to main content
AD Academy
Attacks on AD
Advanced18 minLast updated: Topic 7 of 7

NTLM Relay and LLMNR — Impersonating Without Cracking

Why crack a hash when you can simply pass it along? LLMNR poisoning and relaying NTLM authentication to unsigned services.

Not read

What you will learn here

  • How LLMNR/NBT-NS poisoning delivers authentications «for free»
  • What NTLM Relay is and why SMB signing stops it
  • The dangerous patterns (relay to LDAP, to AD CS, to SMB)

Worth reading first:Pass-the-Hash and Pass-the-Ticket

Theory — LLMNR poisoning

When a computer cannot resolve a name on the network (a typo, a non-existent server), Windows asks the whole network via /NBT-NS: «does anyone know this name?». The attacker answers: «yes, me» — and the victim sends them their authentication.

This is where relay comes in: instead of cracking the hash (which can take time), the attacker forwards the authentication in real time to another service — a file server, the DC's , or the HTTP interface (that is ESC8). The service receives a perfectly valid authentication — belonging to someone else.

The main defender is signing: and Signing/Channel Binding require the authentication to arrive directly from the source — relay breaks the signature and the service rejects the connection.

Practice — lab only

# 1. Listening and Poisoning with Responder
responder -I eth0 -rdw
# Waiting for someone to type a wrong name — and getting NTLM authentication
bash
# 2. Relay of authentication to unsigned SMB server
ntlmrelayx.py -t smb://10.0.0.25 -smb2support
# 3. Relay to LDAP — creating a computer account (to combine with RBCD)
ntlmrelayx.py -t ldap://dc01.corp.local --delegate-access
bash

Detection

  • Event ID 4624 type 3 (network logon) from computers with no reason to connect to the target — relay produces an «odd» logon.
  • /NBT-NS answers from a single address for many different names — the signature of .
  • /SMB connections to the DC itself from computers that are not DCs/servers.
  • Defender for Identity detects relay and poisoning — enable the alerts.

Mitigation

  • Disable and NBT-NS across the organization (: Computer Configuration → Administrative Templates → Network → DNS Client → Turn off multicast name resolution).
  • Enforce on all servers and workstations (: Microsoft network server/client: Digitally sign communications → Always).
  • Enforce Signing and Channel Binding on the domain controllers.
  • Enable on the HTTP interfaces (blocks ESC8).
  • Put sensitive accounts in Protected Users — is blocked there entirely.
  • Make sure users do not have broad local admin rights — an SMB relay is worth exactly as much as the victim is worth.

Check yourself

What does the attacker do in LLMNR poisoning?

What is the difference between NTLM Relay and hash cracking?

Which setting stops relay to SMB?

Which attack is relay to the AD CS HTTP interface linked to?

Was this page helpful?