@stewart_sec@techspence A funny story, we had a client that had several ESC1 temps. We reported it and provided docs and details on remediation. I did their test the next year and they had several ESC1 temps.. but these were new temps created after our last test.
You know I was just telling someone that the likelihood of me ever running this would be so slim because what sort of network has NTLM disabled but not LLMNR? Being able to use DNS is really good to know.
The LLMNR response name spoofing pioneered by @tiraniddo and @Synacktiv does not seem to work with mDNS & NetBIOS ๐ข
But guess what! It works with DNS๐ฏ
๐ฅณ Here's the new pretender release supporting Kerberos relaying via DHCPv6-DNS-Takeover: ๐
https://t.co/2zhJlpBRvn
#infosec