Victim tries to access a share
\\\\fileserver\\share or an application references that UNC path.fileserver, Windows falls back to LLMNR.Victim broadcasts query
Who has FILESERVER? (LLMNR request)
Attacker (Responder) replies
I am FILESERVER, my IP is 192.168.1.50
Victim connects to attacker
\\\\fileserver.\\\\192.168.1.50\\share.Windows automatically sends NTLM authentication
CORP\\alice)Example captured by Responder:
Username: CORP\\alice
Hostname: VICTIM-PC
NTLMv2 Hash: alice::CORP:1122334455667788:99aabbccddeeff...
Attacker now has the hash
hashcat