2

In one CTF, I encountered a task that is solved by getting NetNTLM \ NTLM or just getting username.

Tell me, please, is there any protocol that automatically sends NetNTLM / NTLM or username, when the connection is initialized?

The victim uses Windows 10.

Sp1nal
  • 21
  • 2

1 Answers1

1

UNC paths:

\\myserver\resource

The types of attacks that use this is sending a word document with an image embedded in it using a UNC path as the reference

\\192.168.0.1\image.jpg

Your machine will try to authenticate to the share to get the image and in doing so pass along the NetNTLM hash.

Joe
  • 2,734
  • 2
  • 12
  • 22
McMatty
  • 3,192
  • 1
  • 7
  • 16