Web Hack List

Collected research

NTLM Relay via HTTP to internet or stealing windows user hashes while using java client

SMBRelay Bible 7: SSRF + Java + Windows = Love

Java's built-in HTTP client performs NTLM authentication automatically to any host, without the Intranet-zone restriction browsers apply. So an SSRF in a Java application on Windows, often running under a user account, can be aimed at an attacker's web server to capture or relay NTLM credentials, using Metasploit's http_ntlmrelay and http_ntlm modules.

Record

Document
SMBRelay Bible 7: SSRF + Java + Windows = Love
Researcher
Alexey Tyurin
Published by
erpscan.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Alexey Tyurin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .