CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A tester on an internal engagement captures NTLM authentication traffic using Responder and then relays the intercepted authentication attempt to a target server using ntlmrelayx, gaining access without ever cracking the password hash. Which attack technique is being demonstrated?
- ANTLM relay attack
- BGolden ticket attack
- CKerberoasting
- DPass-the-hash
Show answer & explanationAnswer & explanation
Correct answer: A. NTLM relay attack
An NTLM relay attack forwards a captured authentication attempt to another server in real time, allowing the attacker to authenticate as the victim without ever decrypting or cracking the hash, distinct from pass-the-hash which reuses an already-obtained hash.
Why the other options are wrong
- B. A golden ticket attack forges Kerberos TGTs using the krbtgt hash, not NTLM traffic.
- C. Kerberoasting extracts and cracks service ticket hashes offline, unrelated to NTLM relay.
- D. Pass-the-hash reuses a previously extracted hash for authentication, not a live relay of captured traffic.
NTLM Relay Attack
An attack where captured NTLM authentication attempts are forwarded to another server in real time to authenticate as the victim, bypassing the need to crack the hash.
- Often initiated with Responder for poisoning/capture
- ntlmrelayx forwards the captured auth session
- Effective when SMB signing is not enforced
Memory trick: Relay it live before it goes cold — no cracking needed.