LLMNR Poisoning
What is LLMNR?
Attack Overview
Steps
1. Run Responder
sudo responder -I tun0 -dwP2. Wait for Hashes
3. Crack the Hash
Mitigation
Primary Defense: Disable LLMNR and NBT-NS
Disable LLMNR
Disable NBT-NS
Alternative: If LLMNR/NBT-NS Cannot Be Disabled
Network Segmentation
Strong Password Policy
Additional Measures
Summary
Last updated