NTLMv2 Password Cracking
Siege T.V.

Windows NTLM Relay Attack

A Windows NTLM (NT LAN Manager) relay attack is a sophisticated cybersecurity attack that takes advantage of the NTLM authentication protocol used in Windows environments. Here’s a summary of a Windows NTLM Relay attack:

  1. Objective: The primary goal of a Windows NTLM Relay attack is to intercept and relay authentication attempts between two parties, often a client and a server, to gain unauthorised access to a target system or network resource.
  2. NTLM Authentication: NTLM is an authentication protocol used in Windows for validating user credentials. When users attempt to access a network resource, their client system communicates with the server to authenticate using NTLM.
  3. Attack Method:
    • Interception: The attacker positions themselves as an intermediary between a client and a server. This can be done through various means, such as man-in-the-middle (MITM) attacks or by compromising a system on the network.
    • Relay: When the client initiates an authentication request, the attacker intercepts it and relays it to the target server. This relay can involve passing the request to multiple systems within the network.
    • Response Modification: The attacker also intercepts the server’s response to the client’s authentication request. They may modify this response to achieve various objectives, such as gaining access to a specific resource.
    • Authentication: The attacker’s ultimate goal is to convince the target server that the client’s authentication is successful. This can lead to unauthorised access to the target system or resource.
  4. Consequences: A successful NTLM Relay attack can have severe consequences, including unauthorised access to sensitive systems, data theft, privilege escalation, and lateral movement within a network.
  5. Detection Challenges: NTLM Relay attacks can be challenging to detect because they often occur without altering the authentication traffic significantly. Traditional intrusion detection systems may not easily identify these attacks.
  6. Mitigation and Prevention: To defend against NTLM Relay attacks, organisations should consider the following measures:
    • Disable NTLM: Limit or disable the use of NTLM authentication in favour of more secure protocols like Kerberos or modern authentication mechanisms.
    • Network Segmentation: Implement network segmentation to minimise the attacker’s ability to move laterally within the network.
    • Encryption: Use encryption protocols like SMB signing and IPsec to protect authentication traffic from interception and modification.
    • Strong Authentication: Implement multi-factor authentication (MFA) to add an extra layer of security, making it more challenging for attackers to relay authentication attempts.
    • Patch and Update: Keep systems and software up to date to patch vulnerabilities that attackers might exploit to gain access.

In conclusion, a Windows NTLM Relay attack is a serious security threat that can lead to unauthorised access and data compromise. Defending against these attacks requires a combination of technical measures, strong authentication practices, and network security hygiene.

How to detect it

Relay attacks are noisy if you are watching the right things, and almost invisible if you are not.

  • Monitor for NTLM authentication where Kerberos is expected. Relay depends on NTLM, so a baseline of normal NTLM use in your environment makes the anomalies visible. Windows can be configured to audit NTLM usage before you restrict it.
  • Watch for LLMNR, NBT-NS and mDNS traffic. These name resolution fallbacks are what supply the credentials in the first place, and in most corporate environments they carry no legitimate traffic at all.
  • Alert on a single source authenticating to many hosts in quick succession, and on machine accounts authenticating in unusual directions.
  • Look for unexpected authentication to LDAP or SMB on domain controllers from workstations.

How to prevent it

Several controls stack here, and the first two remove most of the exposure on their own.

Disable LLMNR and NBT-NS. These legacy name resolution protocols answer failed DNS lookups by broadcasting to the local network, and a listener on that network can answer and collect the authentication attempt. Almost no modern environment needs them. Disable LLMNR by Group Policy and NBT-NS on your adapters or via DHCP options.

Enforce SMB signing. Signing is what breaks the relay itself, because a relayed session cannot be signed correctly. Require it on clients and servers, not just on domain controllers where it is on by default.

Enable LDAP signing and channel binding on domain controllers, which closes the equivalent path against LDAP.

Enable Extended Protection for Authentication on web services that use Windows authentication, including certificate services if you run them.

Restrict NTLM. The long-term answer is to reduce NTLM use towards zero. Audit first to find what still depends on it, then restrict progressively. This takes time in an older environment, which is why the controls above matter in the meantime.

If you are planning remediation, the order that usually delivers the most risk reduction fastest is: disable LLMNR and NBT-NS, then enforce SMB signing, then LDAP signing and channel binding, then work on reducing NTLM.

Siege Cyber is a CREST-accredited provider of penetration testing across Australia. Get a Fixed-Price Quote.