Network Perimeter

Legacy Protocol Abuse

SMBv1, Telnet, and unencrypted management protocols create exploitable paths inside the network.

What it is

Legacy protocols like SMBv1 (exploited by EternalBlue/WannaCry), Telnet, FTP, and unencrypted SNMP remain active in many environments years after vendor end-of-support. These protocols lack modern authentication and encryption, and are exploited both for initial access and lateral movement. LLMNR and NBT-NS poisoning exploits legacy Windows name resolution to capture NTLMv2 hashes passively.

Attack techniques

  • EternalBlue (MS17-010) — SMBv1 exploitation
  • LLMNR/NBT-NS Poisoning (T1557.001)
  • NTLM relay attacks (T1557)
  • Unencrypted Telnet/FTP credential capture

Business impact

Legacy protocol vulnerabilities are trivially exploitable using freely available tools. They are frequently present in network assessments years after the vulnerability was publicly disclosed.