LLMNR / NBT-NS poisoning

intermediateInternal & Active Directory

TL;DR

When Windows can’t resolve a name normally it falls back to broadcast protocols (LLMNR, NBT-NS, mDNS) that anyone on the network can answer. An attacker who answers can capture authentication material. The fix is to turn these fallbacks off and enforce SMB signing.

What it is

LLMNR and NBT-NS are legacy name-resolution fallbacks. If a machine mistypes a share name or DNS fails, it shouts “who is FILESERVR?” to the whole local network. Nothing verifies who answers.

How it works

A tool like Responder simply replies “that’s me” to those broadcasts. The victim then tries to authenticate to the attacker, handing over a challenge/response that can be taken away and cracked offline, or relayed onward. It’s one of the most reliable ways to get a first foothold on an internal test.

How to detect it

How to defend

Reference: MITRE ATT&CK T1557.001.

← Back to Internal & Active Directory