Skip to content

LLMNR / NBT-NS / mDNS Poisoning

When a Windows machine can’t resolve a name via DNS, it falls back to legacy broadcast/multicast resolution protocols: LLMNR, NBT-NS, and mDNS. The client asks the whole local network “who is FILESERVR?” and trusts the first answer. There’s no authentication. An attacker on the same segment answers “that’s me,” the victim sends its NTLM authentication attempt, and the attacker captures the Net-NTLM hash. It’s the most reliable initial-access vector on a domain LAN.

sequenceDiagram
    participant V as Victim
    participant A as Attacker (Responder)
    participant T as Target
    V->>A: failed name lookup (LLMNR/NBT-NS), attacker answers by spoofing
    V->>A: authenticates (Net-NTLMv2)
    A->>A: capture and crack offline (hashcat -m 5600)
    A->>T: or relay the auth (ntlmrelayx)

The flaw is by design: these protocols don’t verify the responder’s identity. Any host on the L2 segment can impersonate any name. Since typos, stale resources, and web proxy auto-discovery (WPAD) generate failed queries constantly, the attacker only has to listen and answer to harvest credentials without touching any server.

# listen and answer LLMNR/NBT-NS/mDNS, stand up trap servers
responder -I eth0 -wv
# Net-NTLMv2 hashes arrive from whoever resolved a nonexistent name

Responder also stands up fake SMB/HTTP/WPAD servers: when the victim tries to authenticate, its client sends a Net-NTLMv2 that gets logged. Also WPAD: if the browser looks for a proxy via WPAD, it’s served a malicious one that forces auth.

The captured hash is not the NT hash (useless for Pass-the-Hash), but it’s good for:

  • Cracking it offline (hashcat mode 5600) → cleartext password if weak.
hashcat -m 5600 hashes.txt rockyou.txt
  • Relaying (see NTLM Relay): forwarding it live to another service without cracking.
  • Crack → domain credentials → from here to full enumeration (Active Directory Enumeration) and spraying.
  • Relay → execution/dump on a target where that account is local admin (NTLM Relay).

Instead of waiting for resolution failures, you can force a victim to authenticate to you:

  • Files/links with UNC paths (\\attacker\share) in documents, descriptions, email signatures.
  • PetitPotam, PrinterBug (SpoolSample), Coerce → force a server (including a DC) to authenticate to the attacker (chains into relay to AD CS, see AD CS (Active Directory Certificate Services)).
  • Responder — LLMNR/NBT-NS/mDNS poisoning + trap servers + WPAD.
  • Inveigh — PowerShell/C# equivalent for Windows.
  • hashcat/john — Net-NTLMv2 cracking (mode 5600).
  • mitm6 — poisoning via DHCPv6/IPv6 DNS (IPv6 is usually on and unwatched): classic mitm6 + ntlmrelayx.

Domain credentials (after cracking) or direct execution (after relay) starting from zero, just by being on the LAN. It’s the starting gun of most internal AD compromises.

  • LLMNR/NBT-NS answers from a host that isn’t the legitimate one; appearance of an unexpected WPAD.
  • Honeypot: queries for decoy names that don’t exist → if someone answers, there’s a Responder on the network.
  • Anomalous DHCPv6/router-advertisement traffic (mitm6).
  • NTLM authentications to unusual hosts; coercion (EFSRPC/MS-RPRN calls to odd machines).

Monitor NBT-NS/LLMNR in the IDS, NTLM logon events (4624 type 3) to unusual destinations, and DHCPv6 activity. Deploy resolution honeytokens.

  • Disable LLMNR (GPO: “Turn off multicast name resolution”) and NBT-NS (per adapter or DHCP option 001), and mDNS where unused. The root mitigation.
  • Disable WPAD if unused; create a DNS wpad entry to neutralize discovery.
  • Disable IPv6 if unused, or protect it (RA Guard, DHCPv6 Guard) against mitm6.
  • Enforce SMB signing and, where possible, LDAP signing/channel binding (cuts relay — see NTLM Relay).
  • L2 segmentation, 802.1X, and strong passwords (defeats offline cracking).

Identify the attacker host on the segment, isolate it, rotate the credentials that may have been captured/cracked, and deploy the disabling GPOs if not already in place.

  • LLMNR/NBT-NS poisoning isn’t a CVE: it’s a protocol weakness (MITRE T1557.001), present by default on nearly every Windows network.
  • Responder + crack/relay is the documented opening of countless internal pentests and real intrusions.
  • mitm6 (IPv6/WPAD) and coercion (PetitPotam CVE-2021-36942, PrinterBug) extend the vector into relay to AD CS → full domain compromise.
  • Are LLMNR/NBT-NS/mDNS active? (Responder captures hashes on listen)
  • Captured Net-NTLMv2 crackable offline?
  • WPAD exploitable (no wpad DNS entry)?
  • IPv6 on and unprotected (mitm6)?
  • SMB signing not enforced (relay viable)?
  • Coercion possible (PetitPotam/PrinterBug) toward relay?
  • Blue: resolution honeytokens deployed?
  • LLMNR/NBT-NS disabling GPO applied?