CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A penetration tester is performing an internal network assessment. They identify a critical server that uses NTLM authentication. The tester wants to capture NTLMv2 hashes from a legitimate user when they authenticate to this server without being on the same subnet as the user. Which of the following techniques would be most effective for this scenario?

  1. ASetting up a rogue DHCP server to assign a malicious DNS server.
  2. BARP spoofing on the user's subnet to redirect traffic.
  3. CUsing a tool like Inveigh to perform a Man-in-the-Middle attack via LLMNR/NBT-NS poisoning.
  4. DPerforming an NTLM relay attack using Responder on a different segment.
Show answer & explanation

Correct answer: C. Using a tool like Inveigh to perform a Man-in-the-Middle attack via LLMNR/NBT-NS poisoning.

The key constraints are 'without being on the same subnet as the user' and capturing NTLMv2 hashes. LLMNR/NBT-NS poisoning (often done with tools like Inveigh or Responder) is effective across different subnets because it exploits local name resolution broadcasts. When a user tries to access a resource that doesn't resolve via DNS, their machine broadcasts an LLMNR/NBT-NS request. An attacker's tool can respond to this and trick the user's machine into authenticating, capturing their NTLMv2 hash, even if the attacker is not on the same local subnet as the user.

Why the other options are wrong

  • A. A rogue DHCP server would affect DNS resolution but might not directly lead to NTLM hash capture without further steps, and it's a broader network attack, not specifically targeting NTLM over subnet boundaries.
  • B. ARP spoofing is a Layer 2 attack and requires the attacker to be on the same subnet as the target.
  • D. An NTLM relay attack typically requires the attacker to intercept traffic or trick the client into connecting directly to the attacker, often implying local network presence or a specific vulnerability. While Responder performs LLMNR/NBT-NS poisoning, the 'relay' part is about forwarding the hash, not just capturing it, and the 'different segment' part is crucial.

LLMNR/NBT-NS Poisoning

A network attack that exploits vulnerabilities in Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) protocols to intercept name resolution requests and trick clients into authenticating to an attacker-controlled server, thereby capturing NTLM hashes.

  • Works by responding to broadcast name resolution queries.
  • Effective for capturing NTLMv2 hashes.
  • Can be performed across network segments if broadcasts are routed or attacker has presence.
  • Tools like Responder and Inveigh are commonly used.

Memory trick: LLMNR/NBT-NS poisoning: Broadcasts betray, hashes convey.

More Attacks and Exploits questions