Network Perimeter
Legacy Protocol Abuse
SMBv1, Telnet, and unencrypted management protocols create exploitable paths inside the network.
What it is
Legacy protocols like SMBv1 (exploited by EternalBlue/WannaCry), Telnet, FTP, and unencrypted SNMP remain active in many environments years after vendor end-of-support. These protocols lack modern authentication and encryption, and are exploited both for initial access and lateral movement. LLMNR and NBT-NS poisoning exploits legacy Windows name resolution to capture NTLMv2 hashes passively.
Attack techniques
- EternalBlue (MS17-010) — SMBv1 exploitation
- LLMNR/NBT-NS Poisoning (T1557.001)
- NTLM relay attacks (T1557)
- Unencrypted Telnet/FTP credential capture
Business impact
Legacy protocol vulnerabilities are trivially exploitable using freely available tools. They are frequently present in network assessments years after the vulnerability was publicly disclosed.