{"id":632,"date":"2021-03-10T13:44:38","date_gmt":"2021-03-10T13:44:38","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=632"},"modified":"2021-03-11T13:02:02","modified_gmt":"2021-03-11T13:02:02","slug":"responder-ntlm-relaying","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/responder-ntlm-relaying\/","title":{"rendered":"Responder &#038; NTLM Relaying"},"content":{"rendered":"<h1>Lab: Lateral Movement<\/h1>\n<h2>Step 12 &#8211; Responder &amp; NTLM Relaying<\/h2>\n<p><strong>Teamwork &#8211; Team DaMa<\/strong><\/p>\n<h2>Description<\/h2>\n<blockquote>\n<p>At this point of the lab, you have successfully elevated your privileges from a regular domain user to a domain administrator by abusing a combination of different vulnerabilities and techniques. However, would the same have been possible if we did not have access to a compromised user (tmassie) and client?<\/p>\n<\/blockquote>\n<p>This exercise covers a different approach commonly exploited in Windows network, called NTLM Relaying.<\/p>\n<h2>Questions to Answer<\/h2>\n<p><strong><em>Q1:<\/em><\/strong><br \/>\nWhat does responder actually do under the hood?<\/p>\n<p><strong><em>A1:<\/em><\/strong><br \/>\nIf a windows client cannot resolve a hostname using DNS, it will use the Link-Local Multicast Name Resolution (LLMNR) protocol or NBT-NS to ask neighbouring computers. The <code>responder<\/code> tool can answer LLMNR and NBT-NS queries giving its own IP address as the destination for any hostname requested.<\/p>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.4armed.com\/blog\/llmnr-nbtns-poisoning-using-responder\/\">https:\/\/www.4armed.com\/blog\/llmnr-nbtns-poisoning-using-responder\/<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q2:<\/em><\/strong><br \/>\nWhat does ntlmrelayx.py actually do under the hood?<\/p>\n<p><strong><em>A2:<\/em><\/strong><br \/>\nThe <code>ntlmrelayx.py<\/code> tool performs the following steps.<\/p>\n<ol>\n<li>listen to the NTLM authentication negotiation messages from victim (man-in-the-middle position between a client and a server)<\/li>\n<li>send the negotiation messages to the server (acts as the client)<\/li>\n<li>interacts as the legitime client with the server for the authentication<\/li>\n<li>disconnects the connection with the victim<\/li>\n<li>dumps the contents of the SAM file (which contains the password hashes of local users)<\/li>\n<\/ol>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Abusing-NTLM.png\" alt=\"\" \/><\/p>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/en.hackndo.com\/ntlm-relay\/\">https:\/\/en.hackndo.com\/ntlm-relay\/<\/a><\/li>\n<li><a href=\"https:\/\/blog.fox-it.com\/2017\/05\/09\/relaying-credentials-everywhere-with-ntlmrelayx\/\">https:\/\/blog.fox-it.com\/2017\/05\/09\/relaying-credentials-everywhere-with-ntlmrelayx\/<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q3:<\/em><\/strong><br \/>\nWhy can we impersonate the victims and inject malicious commands into the session we\u2019re relaying?<\/p>\n<p><strong><em>A3:<\/em><\/strong>  <\/p>\n<p><em>Message Relaying:<\/em><br \/>\nAs the attacker sent this same challenge to the real client, the real client encrypted this challenge with its secret, and responded with a valid response. The attacker can therefore send this valid response to the server.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Message-Relaying.png\" alt=\"\" \/><\/p>\n<p>The attacker is authenticated on the server with the client\u2019s credentials. Therefore the attacker is allowed to inject malicious commands into this relayed session.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Message-Relaying_Server.png\" alt=\"\" \/><\/p>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/en.hackndo.com\/ntlm-relay\/\">https:\/\/en.hackndo.com\/ntlm-relay\/<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q4:<\/em><\/strong><br \/>\nHow do we prevent this attack?<\/p>\n<p><strong><em>A4:<\/em><\/strong><br \/>\n<em>Prevention technics<\/em>:  <\/p>\n<ul>\n<li>Enable SMB signing<\/li>\n<li>Enable LDAP signing:<\/li>\n<li>Disable automatic intranet detection<\/li>\n<li>Disable Windows Proxy Auto Detection<\/li>\n<li>Disable LLMNR\/NBNS<\/li>\n<\/ul>\n<p>Note:<\/p>\n<ul>\n<li>Many organizations however have legacy products or operating systems that do not support Kerberos authentication, and thus disabling NTLM would have a considerate business impact.<\/li>\n<\/ul>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/blog.fox-it.com\/2017\/05\/09\/relaying-credentials-everywhere-with-ntlmrelayx\/\">https:\/\/blog.fox-it.com\/2017\/05\/09\/relaying-credentials-everywhere-with-ntlmrelayx\/<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q5:<\/em><\/strong><br \/>\nCould you attack the domain controller as well?<\/p>\n<p><strong><em>A5:<\/em><\/strong><br \/>\nNo, by default doamin controllers requires <code>SMB signing<\/code> when a client authenticates to them.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/SMB_Signied.png\" alt=\"\" \/><\/p>\n<p>PDF Report:<br \/>\n<a href=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Readme-Step12.pdf\" class=\"mtli_attachment mtli_pdf\" title=\"Readme-Step12\">Readme-Step12<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lab: Lateral Movement Step 12 &#8211; Responder &amp; NTLM Relaying Teamwork &#8211; Team DaMa Description At this point of the lab, you have successfully elevated your privileges from a regular domain user to a domain administrator by abusing a combination of different vulnerabilities and techniques. However, would the same have been possible if we did [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-632","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=632"}],"version-history":[{"count":2,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/632\/revisions"}],"predecessor-version":[{"id":744,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/632\/revisions\/744"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}