Test di Penetrazione SMB — Attacco NTLM Relay
Lab Red Team — Relay NTLM via Avvelenamento LLMNR, CVE-2007-2447, Cracking Hash NTLMv2 e NT AUTHORITY\SYSTEM su Windows 10
Autore
| Campo | Dettagli |
|---|
| Nome | Younes |
| GitHub | @Youneskc |
| Tipo | Lab di Test di Penetrazione |
| Stato | Completato |
Disclaimer Legale
Questo progetto è stato condotto esclusivamente in un ambiente di laboratorio isolato per soli scopi educativi e di ricerca.
Tutti i sistemi testati sono di proprietà privata dell'autore.
Non sono state coinvolte reti esterne, sistemi di produzione o infrastrutture di terze parti.
Tutte le attività sono conformi alle leggi applicabili e alle linee guida etiche che regolano la ricerca sulla sicurezza informatica.
Panoramica del Progetto
Questo lab documenta una catena di attacco SMB completa contro un target Windows 10, coprendo tre fasi:
- Fase 1 — Ricognizione : enumerazione SMB, fingerprinting dei servizi, identificazione delle vulnerabilità
- Fase 2 — Sfruttamento : attacco Relay NTLM tramite Responder + ntlmrelayx, cracking hash NTLMv2
- Fase 3 — Post-Sfruttamento : shell NT AUTHORITY\SYSTEM, dump SAM, Pass-the-Hash, persistenza
Ambiente di Laboratorio
| Macchina | Ruolo | IP |
|---|
| Kali Linux | Attaccante / C2 | 192.168.1.50 |
| Windows 10 Pro Build 19045 | Target | 192.168.1.20 |
| Rete | Host-Only VirtualBox | 192.168.1.0/24 |
Catena di Attacco
LLMNR/NBT-NS Poisoning (Responder)
↓
NTLMv2 Hash Captured
↓
Hash Cracked in 2 seconds (Hashcat + rockyou.txt)
↓
Password Spray → administrateur:younes (Pwn3d!)
↓
Interactive Shell via psexec → NT AUTHORITY\SYSTEM
↓
SAM Database Dumped (secretsdump)
↓
Pass-the-Hash + Persistence (backdoor account)
Vulnerabilità Trovate
Struttura del Repository
SMB-Penetration-Testing-NTLM-Relay/
│
├── reconnaissance/ # Nmap, enum4linux-ng, CrackMapExec screenshots
├── exploit/ # Responder, ntlmrelayx, Hashcat, CME screenshots
├── postexploit/ # psexec, secretsdump, Pass-the-Hash, persistence screenshots
└── report/ # Full penetration test report (DOCX)
Strumenti Utilizzati
Mapping MITRE ATT&CK
Risultato Chiave
Abilitare la Firma dei Messaggi SMB da sola avrebbe impedito l'intera catena di attacco.
Set-SmbServerConfiguration -RequireSecuritySignature $true
Lab educativo — Ambiente isolato — Nessun sistema reale è stato danneggiato