LLMNR / NBT-NS / mDNS Poisoning
When a Windows machine can’t resolve a name via DNS, it falls back to legacy broadcast/multicast resolution protocols: LLMNR, NBT-NS, and mDNS. The client asks the whole local network “who is FILESERVR?” and trusts the first answer. There’s no authentication. An attacker on the same segment answers “that’s me,” the victim sends its NTLM authentication attempt, and the attacker captures the Net-NTLM hash. It’s the most reliable initial-access vector on a domain LAN.
sequenceDiagram
participant V as Victim
participant A as Attacker (Responder)
participant T as Target
V->>A: failed name lookup (LLMNR/NBT-NS), attacker answers by spoofing
V->>A: authenticates (Net-NTLMv2)
A->>A: capture and crack offline (hashcat -m 5600)
A->>T: or relay the auth (ntlmrelayx)
Threat model
Section titled “Threat model”The flaw is by design: these protocols don’t verify the responder’s identity. Any host on the L2 segment can impersonate any name. Since typos, stale resources, and web proxy auto-discovery (WPAD) generate failed queries constantly, the attacker only has to listen and answer to harvest credentials without touching any server.
Red Team
Section titled “Red Team”Poisoning and capture (Responder)
Section titled “Poisoning and capture (Responder)”# listen and answer LLMNR/NBT-NS/mDNS, stand up trap serversresponder -I eth0 -wv# Net-NTLMv2 hashes arrive from whoever resolved a nonexistent nameResponder also stands up fake SMB/HTTP/WPAD servers: when the victim tries to authenticate, its client sends a Net-NTLMv2 that gets logged. Also WPAD: if the browser looks for a proxy via WPAD, it’s served a malicious one that forces auth.
What you get: Net-NTLMv2
Section titled “What you get: Net-NTLMv2”The captured hash is not the NT hash (useless for Pass-the-Hash), but it’s good for:
- Cracking it offline (hashcat mode 5600) → cleartext password if weak.
hashcat -m 5600 hashes.txt rockyou.txt- Relaying (see NTLM Relay): forwarding it live to another service without cracking.
Two paths after capture
Section titled “Two paths after capture”- Crack → domain credentials → from here to full enumeration (Active Directory Enumeration) and spraying.
- Relay → execution/dump on a target where that account is local admin (NTLM Relay).
Forcing coercion (not just waiting)
Section titled “Forcing coercion (not just waiting)”Instead of waiting for resolution failures, you can force a victim to authenticate to you:
- Files/links with UNC paths (
\\attacker\share) in documents, descriptions, email signatures. - PetitPotam, PrinterBug (SpoolSample), Coerce → force a server (including a DC) to authenticate to the attacker (chains into relay to AD CS, see AD CS (Active Directory Certificate Services)).
- Responder — LLMNR/NBT-NS/mDNS poisoning + trap servers + WPAD.
- Inveigh — PowerShell/C# equivalent for Windows.
- hashcat/john — Net-NTLMv2 cracking (mode 5600).
- mitm6 — poisoning via DHCPv6/IPv6 DNS (IPv6 is usually on and unwatched): classic mitm6 + ntlmrelayx.
Impact
Section titled “Impact”Domain credentials (after cracking) or direct execution (after relay) starting from zero, just by being on the LAN. It’s the starting gun of most internal AD compromises.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- LLMNR/NBT-NS answers from a host that isn’t the legitimate one; appearance of an unexpected WPAD.
- Honeypot: queries for decoy names that don’t exist → if someone answers, there’s a Responder on the network.
- Anomalous DHCPv6/router-advertisement traffic (mitm6).
- NTLM authentications to unusual hosts; coercion (EFSRPC/MS-RPRN calls to odd machines).
Telemetry
Section titled “Telemetry”Monitor NBT-NS/LLMNR in the IDS, NTLM logon events (4624 type 3) to unusual destinations, and DHCPv6 activity. Deploy resolution honeytokens.
Hardening
Section titled “Hardening”- Disable LLMNR (GPO: “Turn off multicast name resolution”) and NBT-NS (per adapter or DHCP option 001), and mDNS where unused. The root mitigation.
- Disable WPAD if unused; create a DNS
wpadentry to neutralize discovery. - Disable IPv6 if unused, or protect it (RA Guard, DHCPv6 Guard) against mitm6.
- Enforce SMB signing and, where possible, LDAP signing/channel binding (cuts relay — see NTLM Relay).
- L2 segmentation, 802.1X, and strong passwords (defeats offline cracking).
Response
Section titled “Response”Identify the attacker host on the segment, isolate it, rotate the credentials that may have been captured/cracked, and deploy the disabling GPOs if not already in place.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- LLMNR/NBT-NS poisoning isn’t a CVE: it’s a protocol weakness (MITRE T1557.001), present by default on nearly every Windows network.
- Responder + crack/relay is the documented opening of countless internal pentests and real intrusions.
- mitm6 (IPv6/WPAD) and coercion (PetitPotam CVE-2021-36942, PrinterBug) extend the vector into relay to AD CS → full domain compromise.
Testing checklist
Section titled “Testing checklist”- Are LLMNR/NBT-NS/mDNS active? (Responder captures hashes on listen)
- Captured Net-NTLMv2 crackable offline?
- WPAD exploitable (no
wpadDNS entry)? - IPv6 on and unprotected (mitm6)?
- SMB signing not enforced (relay viable)?
- Coercion possible (PetitPotam/PrinterBug) toward relay?
- Blue: resolution honeytokens deployed?
- LLMNR/NBT-NS disabling GPO applied?