Skip to main content

Cuando Windows no resuelve un nombre por DNS, hace broadcast LLMNR / NBT-NS preguntando “¿alguien sabe dónde está SHARE\fileserver?”.

Categoría: Reconocimiento 🎯 Trinchera — Cuando Windows no resuelve un nombre por DNS, hace broadcast LLMNR / NBT-NS preguntando “¿alguien sabe dónde está SHARE\fileserver?”. Responder responde “soy yo”, la víctima le envía hash NTLMv2 intentando autenticar. Crackeas offline o relayeas online. 🔗 Kill chainresponder -I eth0 durante working hours → hashes NTLMv2 → hashcat -m 5600. Si tienes --lm y la víctima manda LMv1, tienes la pwd en minutos. 📡 Huella defensiva — Responder genera tráfico anómalo: muchos hosts intentando resolver el atacante, hashes capturados en el log. Defender for Identity tiene detección dedicada. ⚠️ Falso amigo — Hashes NTLMv2 con Negotiate Sign no son relayables a SMB Signing-required servers. Buena pwd policy + AES mata Responder. 🛡️ Remediación — Deshabilitar LLMNR (GPO Turn off Multicast Name Resolution=Enabled) y NBT-NS (NetBIOS over TCP/IP=Disabled). Forzar SMB Signing.

Volver al glosario completo Última actualización: 2026-06-11