When a Windows host tries to reach a name that DNS cannot resolve (a typo, a decommissioned share, a WPAD lookup), it falls back to broadcast name-resolution protocols: LLMNR, NBT-NS, and mDNS. These have no authentication: any host on the segment can answer "that's me". By answering, you make the victim connect to you and authenticate, handing you a NetNTLMv2 challenge-response you can crack offline or relay.
Why it works#
- LLMNR (UDP 5355) and NBT-NS (UDP 137) are multicast/broadcast fallbacks with no source validation.
- mDNS (UDP 5353) behaves similarly for
.localnames. - A mistyped share, a stale drive mapping, or WPAD proxy auto-discovery produces a constant stream of failed lookups to poison.
- When the victim connects to your fake SMB/HTTP service, Windows sends a NetNTLMv2 response automatically, often for a logged-on user and sometimes for a privileged account.
Capturing#
# Responder: answer LLMNR/NBT-NS/mDNS and run rogue SMB/HTTP/etc. to capture NetNTLMv2
responder -I eth0 -wv
# Responder writes captured hashes to per-module files under logs/ (not the
# session log), e.g. logs/SMB-NTLMv2-SSP-<ip>.txt, in hashcat -m 5600 format
hashcat -m 5600 logs/SMB-NTLMv2-SSP-10.0.0.5.txt wordlist.txt -r rules/best64.rule
Target WPAD specifically: many networks never set a real wpad DNS record, so every browser's proxy lookup can be answered, capturing authentication broadly.
From capture to impact#
A captured NetNTLMv2 response has two uses:
- Crack it (
-m 5600) to recover the plaintext, then reuse the credential for spraying and authenticated access. Feasible only if the password is weak. - Relay it without cracking: forward the authentication in real time to another service and act as the victim there. This is the higher-value path, because it works regardless of password strength, as long as the target does not enforce signing.
Exploitation notes#
- NetNTLMv2 is not reusable like an NT hash: it is bound to a server challenge, so it only cracks or relays, never pass-the-hash.
- Machine-account responses (
HOST$) are common and useful: a machine account's NetNTLM can be relayed even though its password is random and uncrackable. mitm6abuses IPv6 autoconfiguration (rogue DHCPv6 + DNS) to redirect name resolution more reliably than broadcast poisoning in IPv6-enabled networks, and pairs with relay.
Tools#
- Responder: LLMNR/NBT-NS/mDNS poisoning with rogue capture servers.
- mitm6: IPv6 DNS takeover to redirect and capture/relay authentication.
- Inveigh: PowerShell/C# poisoner for Windows attack hosts.
References#
- The Hacker Recipes: LLMNR/NBT-NS/mDNS poisoning
- Microsoft: name-resolution order and LLMNR