An incident responder identifies a compromised workstation using a hash-based NTLM relay attack. Which specific protocol vulnerability is being exploited by the attacker to intercept and pass authentication tokens to a target server without cracking the password?
Trap 1: Kerberos TGT pass-the-ticket
Pass-the-ticket involves extracting valid Kerberos tickets from memory, usually via mimikatz. This differs from NTLM relaying, which focuses on intercepting a challenge-response exchange to impersonate a client against a target server that does not require SMB signing or Kerberos authentication.
Trap 2: LLMNR poisoning
LLMNR poisoning is a technique used to capture hashes by responding to name resolution requests. While often a precursor to a relay attack, it is the method of acquisition, not the protocol vulnerability allowing the relaying of authentication tokens to a target server.
Trap 3: NetBIOS broadcast vulnerability
NetBIOS broadcasts are an information disclosure issue where devices announce their existence. While attackers use these to perform spoofing, they do not inherently provide the mechanism to relay NTLM authentication tokens to a target server without the underlying lack of signing.
- A
Kerberos TGT pass-the-ticket
Why it fails: Pass-the-ticket involves extracting valid Kerberos tickets from memory, usually via mimikatz. This differs from NTLM relaying, which focuses on intercepting a challenge-response exchange to impersonate a client against a target server that does not require SMB signing or Kerberos authentication.
- B
LLMNR poisoning
Why it fails: LLMNR poisoning is a technique used to capture hashes by responding to name resolution requests. While often a precursor to a relay attack, it is the method of acquisition, not the protocol vulnerability allowing the relaying of authentication tokens to a target server.
- C
Lack of SMB signing
SMB signing enforces cryptographic integrity checks on packets, preventing man-in-the-middle relay attacks. When disabled, an attacker can capture an NTLM authentication attempt and forward it to a target resource, successfully authenticating as the original user because the server fails to verify the session's authenticity.
- D
NetBIOS broadcast vulnerability
Why it fails: NetBIOS broadcasts are an information disclosure issue where devices announce their existence. While attackers use these to perform spoofing, they do not inherently provide the mechanism to relay NTLM authentication tokens to a target server without the underlying lack of signing.