From a836ece4e634181f28d966b0695e8072b8b79dea Mon Sep 17 00:00:00 2001 From: Seth Hall Date: Wed, 26 Oct 2016 10:41:08 -0400 Subject: [PATCH] Including a test for raw NTLM in SMB --- .../scripts.base.protocols.smb.raw-ntlm/.stdout | 1 + testing/btest/Traces/smb/raw_ntlm_in_smb.pcap | Bin 0 -> 27214 bytes .../scripts/base/protocols/smb/raw-ntlm.test | 14 ++++++++++++++ 3 files changed, 15 insertions(+) create mode 100644 testing/btest/Baseline/scripts.base.protocols.smb.raw-ntlm/.stdout create mode 100644 testing/btest/Traces/smb/raw_ntlm_in_smb.pcap create mode 100644 testing/btest/scripts/base/protocols/smb/raw-ntlm.test diff --git a/testing/btest/Baseline/scripts.base.protocols.smb.raw-ntlm/.stdout b/testing/btest/Baseline/scripts.base.protocols.smb.raw-ntlm/.stdout new file mode 100644 index 0000000000..054c38f738 --- /dev/null +++ b/testing/btest/Baseline/scripts.base.protocols.smb.raw-ntlm/.stdout @@ -0,0 +1 @@ +\xebr\x96\x86\xfc\xaa\xcf\xad\xb14\x18\xfaIG`\xde diff --git a/testing/btest/Traces/smb/raw_ntlm_in_smb.pcap b/testing/btest/Traces/smb/raw_ntlm_in_smb.pcap new file mode 100644 index 0000000000000000000000000000000000000000..8a40175db43205065dfbccfc3d006cf7146778de GIT binary patch literal 27214 zcmeHPd3;pm)qd|xHbY>NU?2g6fedRPBq6M_Bq0e&O&~}FBoPRksO({J#V9CP_YD=0 zB6R`9h>8eqU_qr)tAJY(tZkuMV+E>~oqW&p-X(LFxfAX8>-W!h^Lyt`?!EK8=bY!9 z^R6==?|kVAkBATrM}$!D&kfrn#zcSU5ySDGB}Q~E?9wDwbe8W6gvfb6GDqY@Ek3hj zeLn?d>VdP$n|t5i+Yb+jO`iJtwjT@OiHO{+c)gK|5)&JnvU(NoMR-*7rLO2_ju5@H zwSj(4+__{$lX@M!SG7C(8y_{uu1ie~VgzMZAbU+z^jXTy8k9E=oPF?g^hJ=r|E9## z$I=_n1!ZTgJQO9uL(6>Ujvgh^X&H$w?mTdA(bw(1Ua}%i5WTR%klhj8yVoP~P#cTQ z?%C0;Xqns}49lo??+^Lg*2Kpry*!n2HrSi;`dtwVt|y}RK?70RI!-|5Z-}_3)Q;G} z74dJ9y{VlI#9$c{AmbD};y_o#)dwl##tZ{7SVkc3DX}9i+}Gd(Haq6jClayvdjs*j z@@8FayDP{u{dddn4VE1J_a&g~EZICPTZyI*#6$r-*u&bw!v@qOoIdvY=c>Fy#J#}C zAWQGNBgRO?NF7o0s&C*`3K943up_qL-yoyS0@<_cX@NgAH7uaAGytB|j=VqpvSHKJ zl#?=!aYY;m&(Dc!8f_q|EGh7$e-QC4WB|=K4a9CAH?U;0V~%oxjHQ#h)`-;efz$!H zU}`*L$=k+Y$uX9u0$pdxZh;H`PI@-A;0EU%ik76I{2_y~&)@uqD) zBHp{%us|?ka(vPgubL47QcyptG;bc>h!|xzPx?_`uZVhPybi)Myxd<>>d#2e%n}|v z?$1ik$S~dx88SpB?1w+`2VTZE5^NWGY~T$h!tOGDO7U55|h86d{Y1 zY~>N93CWK7jfL!0b+!HikbObBdsTg*>%rI*>a0wV`nC{ahXdL0O%YKqCZNJ^MYf{r z=YcS7@yAv_((~&{f7tQbM?WrZc?|!`<00{o7>#$4N*6YwzH&6bqeQvr0j2tie7xp~ zp`sVg1){(30LlFcCF~Oscw)YoDys3?Lrg<0Q}8+oM(&04RMg@P`$UvbJ3&%~G2$vQ z3m~(_B7piuZ^@1j*6UedhJSuhB687Z@=I=Kf!`}pE#jM`Z3k(g-M-{Bo%C#?*-8Bc zfz*r7!|kK5)FMJZsEn1Wc=NOvq$kLPvcBC8H;la{ubgKkH5v*c|9-~CVE(0+5d`z zBg+ylz2(rLu3I9P^>%j(o$fr?Jx^SYG6H{>0NeTS#CCsZ&&f}#rtjUBF@4e40!3;d zM9qc)`T0edK=`xDyNehC1rzt+@T{vmZYHVs`TB;$aiN{14Jl>&Ifn>!^ptnuf&lN?Z;* z+RM#p=;HHrwH>N!l23dw`%+UHf)9!XhW|OHAq-aP#R8dFe`OEC|0p<1pi1cAyzMYU zX=fL6D0Qd~qz+t!;Eb3uQB?)ODMRTN1m}+}eBw#y#9|FjvEuy=L|n|#lRAQueFY6M zIX>d_Ejr?>7pcK1#?v?pfacU!5HVgFhgB)acA^r0ZXQx8ibWaHZvY=b7XqCK%G@g1 zC*zW_X(M!w(o_<<%S`CNMIiJO5PIEkEulc(A7WD|x9DfcY$23w3T2M2hx4MVga25f zMRD0sd`?O;9MXj5WM>yz@V3Ji3w{DlUIr(gal1?w{DJzt3&dxE&SK+a^=}^_;!~Cs z+(AW5j`uwAlo=5qQ>foMys>hk>K7rB$%)K&Jj-K;b`~{w!?=dt@<0|B0-dQ!#P>Yp z$!e6zxJ1eKr})GNc+X;EX1mf%GBe-8%*%DPse`~w!k!3K@*rlG8In6P6Ct|Qi)E-R zN0$!oLmoA}V@Ww4QI94o#IZ_A6fCN8$Dmwjq7$P?OW%fpg$$L{L4njkgKOe_=Pv)$ zObgAmua!^y73eHBqCXzJnuy0gGP{n3m>e%|nqVNdrO5!Yn&#?=H_k*yQu`v_Hd&z@ z*UE(ld0XUMPGZYs*cIR%k4VwP%jfw)I)d&es>v0xdqmbHb6V_I60aRMZ2PRgEax*3 zS1kW^U7O!0{N|e&krrPxkxoO6f7{w8euwugHV4_PU}%C|yx8m@g9gJv4%H<8d+x+? zlY>BOaigKJqk}}E7IflxumhMcUooH&MUf&-YQ>wnRx_Fl(Nt8H6_*uMR?k~ly%2t_ zJ60%-{s4{gfWczpF#F(>q^S&W_z;=8!fT)y9V|3A-f@h(DgVfrw>$ z9TDLbdmlCvUzBt8|OHA6`2I*QgI#d%FvCQ4D1E+)BKeAGqbdD zC0j&+u5CU(SB!y0Kq57juZ$=m%yQ;Jl9_VQ!bfEEX=k;m7or(&;NUqQl23yM3&ae_ z;)nFQKFm!*9EQ#HgWfU?-jat4EcS@}@k_=}dAd1%0*?n$hpa?I9v|HiTFS}ES7lZu zqSDp}y9rrrh*dFZM9g``5fKr&HP?&?psw`42)uF5)6uX=4ue2-{}ZVGDm=?#b$?Nz zB+&h%KQX)ikd<)%_u>9aliH}&Ypp7iW~x!Wqx+Lg8Fwk|+$>o&k9vQ-(xUhKu;kmY z5<+S7oAnK~vELl-}B@yeH|AV@l0TmIJyz8VHQCDRy1$NABF}%ZyKMbna z!G?*_h96sO_%>{K95%e-=^veKC@Xffp;7U7t~T5#yX>niUG~6n*bo!jupxTVnm0-t z-U?OjJlsUQ1hrUfHhl6o5wzikM=dr~5n;nE2n!YQwREl5FoW)ZiflHNSvcl`hAuli zIeeGB6a!r5j$(A&%f)4gea@)p9e8Rm{_jo1Qe0uNk+D!|F3H$xA>*66+KyG27&?}M z!Hbs9&%~xs3o+Qxz(R&1JMb5<13wtaYlC2Cjwva30P<8hW_2hTWx4}0h0YphFQ8RR zy=JR+tO}&&bOTT4Mm}${>Y3YsI6q&AAArunV6LxM*^&!9N0bYNs7WXsqG?$#evQAq z<7OpzYSMTO|6#!DFDxi1EX*$~7&^RQSbkAKLBX(sp#}N*`8XHm|7vKi@D~g(%r7V| zC@UCVP&hQ#`j?9eVZ)l#&rAaJ!JL8XPof;%D6G-lAEC_OSM zNz+6k-Ur0c1MKCqiMXS;BO*9?=7<>)`h^@|tNJzhg#+vv=+OA;f@+UfWbuY(Z~TdmHQ6Lg-*fm z?IbO?6q{-3lm?=YgXlBET9|1e;)ZO+Wq=)kBj-c~#yTQ`=$!QiqMxncETM0M7j#NJ^Kdzcw5!a5%PRvgH;JKqhNiDeYj_3G@({Pj;U(s7}8(_DT z4zkeVAjjb#duozT-5&VLLOe;$b6qh=Oc2kNW%sYL9{ofko!&`v5M zyyERXHm_K3G_jUWsA{98^oDX&X7!44T;;Tjk~1~*0Gl6-Kp98?EEv&V`hbULxA{|k zf`@KndPsdAMV!Vp7F*}*J0)3q$RM+a#pYQj^RkH; zm1OoT4H2F-?NT!$OtHhTt)pi(qeso4%`Ew5hT&N^h4w6d5Ur!?nxgy9_N-)9Y&qy@ zoIvmp4TB(B40)Z!Y8&EwW8DbnLC3ovuS4P43BHEex}XirW;mq^tfiI1SJ^onUaS~n)6lO!*#V?TVhRNz>?pZyayZvSK4#sscYgpvp6BuxR+iPHZa(uZdGcV2R`>;elXtHAOh=A;~BhgSp3s|PABQ=GSdMZ~x3 z9TCCuibFP*Lr!t3y@CYcRkSHiDpWW~G3EuWL5?ZTHj<9_Ep!|L9lJrt9shdSMn}jg zPQ7~Alod}w#i1=Zq8If(^(Twoy925D5wPU>oQa0s9rSov8>EUYUMl+CN5uHij)<`2 zHOR#3^xRH~2r;E9bLj()@sh|pR3&Dxs|_!bHvGNWhWQb&;ZfLd($c$}Z73^tOq52& zS*SR)4S)EE8ecZhqVZAKFiqMJIKdiIl_fxgJhIqqxVY>CBA)ok5fL_gq|}TEphD)H zELzH9Lv@0%x$t>#4-4UZL_0iKdB7);UcG8J)T>aoCPNgl0ykJ}uDV=lE6u#hV&=5E z+HU<}=Hzrt$^>N&a4gCU*(_$(WkY+U%GD1~Cu{9diV$D?*clhlZ|>Y$o|!!a^q`bo zA!TSzu1%u_Kl+Q=g5COqlbgZGxgiV879`?GAcp4Taygbh`n)3|IJy6IGa@7n!^wp@ zCvl`kJ8YapN>09lY!BcO78@r^m3ESoH5N{81}94}yZ^`8&1{^MxN~wLv$@*Dkdq5F zPS9Z2qi0Z$OXNbIV5aqcaOGp!XXN8;%al{MCE(*j@-g@ev-ODBB}c*5MInnVMs8mz z5ug8?g%1@Gd~`TvMx?lg&Wc)?DcpKfe-gN>K(4H+F{B}v43m-S=d)uji>e9f0f#@s{PaY9qWQCZP+~5Et16+dQQ<83(wdM zRKP{JlY>^9c_!k;KwJYoSZtniU*cvW_CDu`NY4Se!TA~>W68=oym8L1Ewt%RkI|#k zjLA=k8Wi@X^=mTPBWY#Tht5LU5AdGF>O*3?(q6`Pl{vNxuyU7{$;G0I7gTB4I-^(H z0U#l#Jk@;LLfcd1f$s|O%X}u<&;}6ZLtlbYl}pNVBlj~TuAHd3|1?vPmKjJbECIP^ z2EJ%ek*aq;GJrT6RkGN~t?K?~BDUegR?y^@h6r-+{=|$3kdPfY)m$xw*Avu{`wG?T z3%oYADwGbAEz91#!V<7G9&GJAGS9>olnT98tyhm{=+x(3ExBhT^}gwKi{AJeMPW58 zd4AwHv))8(HB=FFY8IO%ANuosM7*kvBO)yM`ln_@fK)O}WFzgEVA00+7ZH`%9y=NA z&BVD1Gyiii@SckI)wnWAp6AQm7*+Vc8voD6-iT?M4c>voF2+xl#@`8v^)LKj-KMY_ z#(xXOpX_hxZ2XvP`-Xef__9|*Q`Mp3JP5&JGgbEZ2{hHWmcBvSTd15{F3w-P-)t%( zHp_Qw-S!p{anU@B@l`|^KXBBH2(iMnZYhmw-OhV~WMrnTknvXh&tmiS`AR^VdxOQ? z*q6~g9_CJXcD~Kr1KnG<6t-?W)YeU(5=O4XA^SlGArU!XvGdR;fmTbj%xrg$2M-4% z54mQmk%zbfw_e{}j}Y+LKZJBy75K&Baf=a`sU3ttC3 zg_Y%?9#RL{^P7f-P7xh(SG2&JXb~ZsaVD{R^n@m$%twmi<})=-_jydg&ITciEoN?1 zI!Vqf-w7I)4$gLgvnwXS`az>7$S?Ax?7mPb3d%xq@WzwYP0xqg@`CX~tKJUDLi2R% z7qsfTnHHXQfv1J!slT=^f<8uHy(#|J%We(GfpbKh`GO-Nc>1!T=Qc>=Nj4x<+PRHRW}cEIPnD7~xmwSjJJq7S`4F2w_F;p z?6konjbkU_RX2A2B)8|xv24%j5db^fW_zxGPs8U2>+F06#I2~F#TG@+?m+g=iCS)H zVKhXrbLtv1B0%Q3N6|&XmriX>QN%F8CnY{nvrBfl~>8f$+1 z9+%2l#_O(}b&;GsZq9-R zUyqf6)S@VI)^Cns;UPL_t=?3`E>zEA<7~_4Fs{MN*64nV`S zcJ1&;~R z-Mn(6o8NV#TN$JY9dGrUXu;x2vjuxH-u8i$^L@~#(fW0xbWV-{@mYw)VvD!c|12e9 zg=OwYLj)()-h$xgp$Az>*o3IM};S!G_Plh6|@Z zY_cIL531NQ`)a9pH!2S8$nn3X#{HI9G=46STI`oLZ0M|&>yDgwzt?5RvniH{k6O0s z^i&aH!@O#Pl?_^Qkwcz!w3OqJC)MW2itzAhdDP$)v5yvnhhM$ZoD&1-=%QT(XJ!LG z3-`$X%m=&%{|+>yOByV@-HZKowHZmEA#TxM4H}xm2Oz&ngOe+(vof4DlNCRKibK;d zu#85Fd(%uqMiOWkMjEnJ5jdZqhUayC+}iNwY`( z(d_-j!(jH=SbKP>_-m`#J#mJt7VlTh9$>?}8!n*^Gj}WO*$eRrmPTUKA8W|L&5812 z_<3dRG2_IMHxvnT(EZdS+`P3Fi1-oKi?;vM;o$1Q-YXBio{#!uZVg^j(brhEsE^4} z7TLSz2ov2Gs8 zn3c%In70hSgHeF?KNB^SV72ZNT<5f^I^}Br`dd2sdb1!E4|-Uehuz{UV-=$z*)oF6 zm>o#HWDMf#Xl6s}isregjIR+u+yrzMTYRm1?hPWY{;MUvR7Awrx=W1sl86Ag+VEM& zG}lr1XcTjNb&~OQwT!Q>xNGSjhvJ47ISKjC;}a~_m=nhoG~C3)|E90f8ZB42`A6-GWOHSOg-v`l zxTHD!<8%gAEw%of;UASi+zhQ)Z2s}|qftcM#2L@v{Hr3uKb~pGzq)_SqJ7uVPLBT3 zNoxj^8^3agIVP@;I>#@q;(f&Hww{+MePpEBM@pL4)n<<1dfwfbs?z%0Y!0D^2(zBo zNn6kJGW{C)>ewsZx1I78!+|qGJoMb9HumZ@+pBp!&kyDD@C=KMpzL-pkf5&P%>-qR z0Oe~y`I(;E?351%;%uO?*bu9}>_o(?EgSkYL{L8GpcxS$Vb=3H3$Hh5J?}GAuXkQ; z5nZ8RoQR0tY+-8+*t(JHdAqN-u@!P-mfDJThJ-S?{>#;p{~SfVE3A6o2ur@h&P&fp zX1!&)e$?wS7;17G5eNA#+^C4KjA}LBVnb|OOi0(Lc%*B;V?+3nDAE{36tE@Y8NgvF%r~;rcT;6iZomS z6knR5=;5J<%K$L|-~7%;(^`%~i$_1^77bnMXmNiBi^UHIQcJlp>}*#{}3_`1;@}a|78&a(KOLAp7I4 zrGad0CxRAgztSt3!J;fyX0fu8Et%!d9|jH4O0k(NYZ8`24&9q!Vir1y-G)An4Q5w1 zm`kNb{qVX}Y9hq_NO2Ag=Kp0Ui`L13bwX#;{2^pJf?fEa<}Paz{O1Jx=Twj3X10lV zGZ1${aTc5ZY?*Nj5f556&T5G8p9d`-2@pAfybf=i8_;fA1KOqW4Je|lve6w;>Xfz0 zwL$GIeW=vpLnq)v$PT9}>et$QC`^NjP5$yncOqni8qP=jv`su;Fl_Xw=bzD_mO;7D zE)d&-gbhAnaRCJU@LSoScE^0U)`v1u$ZQ~nZcvNfBBHP)r7RT@E^t+q84(JFX;9OI zHzKG(tw;4P4Qe0B)+RGs!*8vt?Ueww(toFUAoHP`7sG9kfjg-UYU|Z*mfT-Ny%%t2 zPEauQN`NIdut81x#;i9TFCU1n0iDGbOdGdtBjP<@I3mK5Zzh`&0W#l6UXIDQyYM05 z33G#*Aye3V*`W5qU7vh>1IC%{@J(B2%2u}Nb zXhsAbVfF_0&=O?u-at)Ve3nC~pm6^8@KJaz~yp3zsL6uhH z4K@fjmgu3SzDSw+^zr1{%Z_~-JeF|ZPul3cfnP(p(5Y{`96sJ*89w$p0&=;j>P)wQ zLB;brxoy^Y#Us#?#TKx43|dceo5WklRS`k%(Z|e)02#@EU5hvN){ocHMN8h(j?F&( zo%tLQA%-=@*O_v7nR(^1QIUq?)=m+&68D#^er#bC`>L`B)Wn~R%-w0QnuHX&k%<0f zQ6d#xEEcQcN>VZ68{Nhq&5CCakfwyD4SNQk zkOwL@jvBmc@M>*d4^2{IoBaWf8w5)*cg6L{$(RG=9%TMDAAi1yBk^?n+UOj-npNHznqXw@H?E8hh^RqjBz7hyh&>Rmd010`FQpFJZAif65Sy~A5y6zD z1yl5YBbaiaT&1xWIXKBRW26CX6mH4~U_IY4uG++&IY*5iT(9 zRWoAvVCp5j(LurVEvk13roob}^%l0ygRSep*1NBcR;v$UD@-uSQ3drr?`p~CU!mTs zEW0WCTo*_k*^witjyZv2>FD7j;V|=@ro{=3v z&l#=(^__0e(*nT+y~6Ez%Elv&+w+tK$wEiM+RXSo(@p8&iM1X`D0ryr%z~<@5h7qv*O>OIRWV&$TZ!%b8 zPjMm PH_u1DLe^5pnQi<(yueRy literal 0 HcmV?d00001 diff --git a/testing/btest/scripts/base/protocols/smb/raw-ntlm.test b/testing/btest/scripts/base/protocols/smb/raw-ntlm.test new file mode 100644 index 0000000000..6e09ef7ded --- /dev/null +++ b/testing/btest/scripts/base/protocols/smb/raw-ntlm.test @@ -0,0 +1,14 @@ +#@TEST-EXEC: bro -b -C -r $TRACES/smb/raw_ntlm_in_smb.pcap %INPUT +#@TEST-EXEC: btest-diff .stdout + +@load base/protocols/ntlm +@load policy/protocols/smb + +# Just verify that the session key is grabbed correctly from NTLM +# carried raw over SMB. + +event ntlm_authenticate(c: connection, request: NTLM::Authenticate) + { + if ( request?$session_key ) + print request$session_key; + } \ No newline at end of file