SMB Relay
What is SMB Relay?
Capture hashes
Relay them to other hosts to authenticate
No need to crack hashes with hashcat
Requirements
SMB signing must be disabled on the target
SMB signing checks authenticity of SMB packets
Relayed user credentials must be admin on target machine
Exploitation
Mitigation
Enable SMB signing on all devices (may cause performance issues with file copies)
Disable NTLM authentication on the network but Windows can default back to it if Kerberos stops working
Account tiering: limit domain admins to specific tasks
Local admin restriction (can increase service deskt tickets)
Last updated