CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A penetration tester is performing an internal network assessment. They identify a critical server that uses NetBIOS Name Service (NBT-NS) for name resolution. The tester observes that when the server attempts to resolve a non-existent host, it broadcasts LLMNR and NBT-NS queries. Which tool and technique should the tester use to capture these requests and potentially obtain credentials?

  1. AMetasploit for SMB relay
  2. BResponder for LLMNR/NBT-NS poisoning
  3. CWireshark for passive packet capture
  4. DNmap for NetBIOS enumeration
Show answer & explanation

Correct answer: B. Responder for LLMNR/NBT-NS poisoning

Responder is the primary tool used for LLMNR/NBT-NS poisoning attacks. It listens for these broadcast queries for non-existent hosts and responds as if it is the legitimate host. When the target attempts to authenticate, Responder captures the NetNTLMv2 hash, which can then be cracked offline.

Why the other options are wrong

  • A. Metasploit can perform SMB relay, but Responder is the tool of choice for the initial LLMNR/NBT-NS poisoning to get the hashes.
  • C. Wireshark can capture packets, but it is a passive tool for analysis, not an active tool for poisoning and credential capture.
  • D. Nmap can enumerate NetBIOS, but it doesn't perform poisoning attacks to capture credentials from name resolution queries.

LLMNR/NBT-NS Poisoning

An attack where an attacker responds to Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) broadcast queries for non-existent hosts. The attacker impersonates the requested host, causing the victim to send authentication credentials (NetNTLMv2 hashes) to the attacker.

  • Targets Windows name resolution protocols (LLMNR, NBT-NS).
  • Exploits broadcast nature of these protocols.
  • Attacker responds as the requested host.
  • Captures NetNTLMv2 hashes for offline cracking.

Memory trick: Internal network: Nmap scans, Responder poisons, Wireshark sniffs, Metasploit exploits.

More Attacks and Exploits questions