Collected research
NTLM Relay via HTTP to internet or stealing windows user hashes while using java client
SMBRelay Bible 7: SSRF + Java + Windows = Love
Java's built-in HTTP client performs NTLM authentication automatically to any host, without the Intranet-zone restriction browsers apply. So an SSRF in a Java application on Windows, often running under a user account, can be aimed at an attacker's web server to capture or relay NTLM credentials, using Metasploit's http_ntlmrelay and http_ntlm modules.
Record
- Document
- SMBRelay Bible 7: SSRF + Java + Windows = Love
- Researcher
- Alexey Tyurin
- Published by
- erpscan.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Alexey Tyurin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .