Project

General

Profile

Actions

Bug #5258

closed

smb/ntlmssp: parser incorrectly assumes fixed field order

Added by Victor Julien about 2 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-nlmp/033d32cc-88f9-4483-9bf2-b273055038ce

"Payload (variable): A byte array that contains the data referred to by the LmChallengeResponseBufferOffset, NtChallengeResponseBufferOffset, DomainNameBufferOffset, UserNameBufferOffset, WorkstationBufferOffset, and EncryptedRandomSessionKeyBufferOffset message fields. Payload data can be present in any order within the Payload field, with variable-length padding before or after the data. The data that can be present in the Payload field of this message, in no particular order, are:"

Currently we assume a strict ordering.


Subtasks 1 (0 open1 closed)

Bug #5810: smb/ntlmssp: parser incorrectly assumes fixed field order (6.0.x backport)ClosedPhilippe AntoineActions
Actions #1

Updated by Victor Julien over 1 year ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Philippe Antoine
  • Target version changed from TBD to 7.0.0-rc1
Actions #2

Updated by Philippe Antoine over 1 year ago

Do you have pcaps ?

Actions #3

Updated by Victor Julien over 1 year ago

  • Priority changed from Normal to High
Actions #4

Updated by Philippe Antoine over 1 year ago

  • Status changed from Assigned to In Review
Actions #5

Updated by Victor Julien over 1 year ago

  • Status changed from In Review to Closed
  • Priority changed from High to Normal
  • Label Needs backport to 6.0 added
Actions #6

Updated by Shivani Bhardwaj over 1 year ago

  • Status changed from Closed to Resolved
Actions #7

Updated by Shivani Bhardwaj over 1 year ago

  • Subtask #5810 added
Actions #8

Updated by Shivani Bhardwaj over 1 year ago

  • Label deleted (Needs backport to 6.0)
Actions #9

Updated by Philippe Antoine over 1 year ago

  • Status changed from Resolved to Closed
Actions #10

Updated by Victor Julien about 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF