- SMBRelay
SMBRelay and SMBRelay2 are
computer program s that can be used to carry out SMB man in the middle (mitm) attacks on Windows machines. They were written bySir Dystic of CULT OF THE DEAD COW (cDc) and releasedMarch 21 ,2001 at the@lantacon convention in Atlanta, Georgia.SMBRelay
SMBrelay receives a connection on UDP port 139 and relays the packets between the client and server of the connecting Windows machine to the originating computer's port 139. It modifies these packets when necessary.
After connecting and authenticating, the target's client is disconnected and SMBRelay binds to port 139 on a new
IP address . This relay address can then be connected to directly using "net use \192.1.1.1" and then used by all of the networking functions built into Windows. The program relays all of the SMB traffic, excluding negotiation and authentication. As long as the target host remains connected, the user can disconnect from and reconnect to thisvirtual IP .SMBRelay collects the
NTLM password hashes and writes them to hashes.txt in a format usable byL0phtCrack for cracking at a later time.As port 139 is a privileged port and requires administrator access for use, SMBRelay must run as an administrator access account. However, since port 139 is needed for
NetBIOS sessions, it is difficult to block.According to Sir Dystic, "The problem is that from a marketing standpoint, Microsoft wants their products to have as much
backward compatibility as possible; but by continuing to use protocols that have known issues, they continue to leave their customers at risk to exploitation... These are, yet again, known issues that have existed since day one of this protocol. This is not a bug but a fundamental design flaw. To assume that nobody has used this method to exploit people is silly; it took me less than two weeks to write SMBRelay." [Greene, Thomas C. " [http://www.theregister.co.uk/2001/04/19/exploit_devastates_winnt_2k_security/ Exploit devastates WinNT/2K security] ." "The Register " online edition,April 19 ,2001 . RetrievedAugust 20 ,2005 .]SMBRelay2
SMBRelay2 works at the NetBIOS level across any protocol to which NetBIOS is bound (such as NBF or NBT). It differs from SMBrelay in that it uses NetBIOS names rather than IP addresses.
SMBRelay2 also supports man in the middling to a third host. However, it only supports listening on one name at a time.
References
External links
* [http://www.xfocus.net/articles/200305/smbrelay.html The SMB Man-In-the-Middle Attack] by Sir Dystic
* [http://securityresponse.symantec.com/avcenter/venc/data/backdoor.smbrelay.html Symantec Security Bulletin]
Wikimedia Foundation. 2010.