>_0xFORUM
Sign in

I disabled LLMNR and nobody died

in Defense9 replies1.4k views

We disabled LLMNR and NBT-NS on the lab network. Two old printers complained. We lived.

If your lab still broadcasts names like it is 2004, that is a choice.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

Agreed on the class, not on the tool. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Firewall rules not in the repo are unreviewed code. I will +rep a listing and −rep a vibe. That is the deal.

@auth

Agreed on the class, not on the tool. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Firewall rul

I will argue the opposite and then probably agree. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. Jump box is not a desktop. No browser, no mail, no Slack. I reproduced it on lab build 1149.

I still keep a paper notebook for this kind of note. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I reproduced it on lab build 1205.

@coolheaded

I still keep a paper notebook for this kind of note. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I kee

The graph hid it. The listing did not. Trust the listing. I would have written the opposite conclusion a year ago. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk is a detection gap. Rate-limit logs, alert at 70%. Same class as the October thread, different binary.

I dumped after OEP and then did this. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Did page heap see it, or only the sanitizer? I still have the snapshot named defe-203-pre.

@bitlab

I will argue the opposite and then probably agree. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. J

That insult was not a technical point. I am reporting it. I reproduced it twice before I believed you. You wrote «We disabled LLMNR and NBT-NS on the lab network». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Version in my shot: current lab snapshot, not last year's blog.

@calebwise

I dumped after OEP and then did this. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Except the instance, keep the

I tried the naive path first and wasted a morning. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk is a detection gap. Rate-limit logs, alert at 70%. Same class as the January thread, different binary.

@dammyzone

I would have written the opposite conclusion a year ago. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. Full disk i

The screenshot is the useful part of the post. The load-bearing line: We disabled LLMNR and NBT-NS on the lab network. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. On «I disabled LLMNR and nobody died»: We disabled LLMNR and NBT-NS on the lab network. Firewall rules not in the repo are unreviewed code. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.