Project

General

Profile

Actions

Bug #5258

closed
VJ PA

smb/ntlmssp: parser incorrectly assumes fixed field order

Bug #5258: smb/ntlmssp: parser incorrectly assumes fixed field order

Added by Victor Julien almost 4 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-nlmp/033d32cc-88f9-4483-9bf2-b273055038ce

"Payload (variable): A byte array that contains the data referred to by the LmChallengeResponseBufferOffset, NtChallengeResponseBufferOffset, DomainNameBufferOffset, UserNameBufferOffset, WorkstationBufferOffset, and EncryptedRandomSessionKeyBufferOffset message fields. Payload data can be present in any order within the Payload field, with variable-length padding before or after the data. The data that can be present in the Payload field of this message, in no particular order, are:"

Currently we assume a strict ordering.


Subtasks 1 (0 open1 closed)

Bug #5810: smb/ntlmssp: parser incorrectly assumes fixed field order (6.0.x backport)ClosedPhilippe AntoineActions

VJ Updated by Victor Julien over 3 years ago Actions #1

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Philippe Antoine
  • Target version changed from TBD to 7.0.0-rc1

PA Updated by Philippe Antoine over 3 years ago Actions #2

Do you have pcaps ?

VJ Updated by Victor Julien over 3 years ago Actions #3

  • Priority changed from Normal to High

PA Updated by Philippe Antoine over 3 years ago Actions #4

  • Status changed from Assigned to In Review

VJ Updated by Victor Julien over 3 years ago Actions #5

  • Status changed from In Review to Closed
  • Priority changed from High to Normal
  • Label Needs backport to 6.0 added

SB Updated by Shivani Bhardwaj about 3 years ago Actions #6

  • Status changed from Closed to Resolved

SB Updated by Shivani Bhardwaj about 3 years ago Actions #7

  • Subtask #5810 added

SB Updated by Shivani Bhardwaj about 3 years ago Actions #8

  • Label deleted (Needs backport to 6.0)

PA Updated by Philippe Antoine about 3 years ago Actions #9

  • Status changed from Resolved to Closed

VJ Updated by Victor Julien about 3 years ago Actions #10

  • Private changed from Yes to No
Actions

Also available in: PDF Atom