From afac2ac20f2caf7216954ebcaefbf663130c2fa2 Mon Sep 17 00:00:00 2001 From: Julien Wallior Date: Tue, 8 May 2018 14:46:35 -0400 Subject: [PATCH] Add krb unit test --- .../.stdout | 1 + testing/btest/Traces/krb/smb2_krb.keytab | Bin 0 -> 102 bytes testing/btest/Traces/krb/smb2_krb.pcap | Bin 0 -> 44485 bytes .../scripts/base/protocols/krb/smb2_krb.test | 19 ++++++++++++++++++ 4 files changed, 20 insertions(+) create mode 100644 testing/btest/Baseline/scripts.base.protocols.krb.smb2_krb/.stdout create mode 100644 testing/btest/Traces/krb/smb2_krb.keytab create mode 100755 testing/btest/Traces/krb/smb2_krb.pcap create mode 100644 testing/btest/scripts/base/protocols/krb/smb2_krb.test diff --git a/testing/btest/Baseline/scripts.base.protocols.krb.smb2_krb/.stdout b/testing/btest/Baseline/scripts.base.protocols.krb.smb2_krb/.stdout new file mode 100644 index 0000000000..cd2430defe --- /dev/null +++ b/testing/btest/Baseline/scripts.base.protocols.krb.smb2_krb/.stdout @@ -0,0 +1 @@ +wallior@DS.SUSQ.COM diff --git a/testing/btest/Traces/krb/smb2_krb.keytab b/testing/btest/Traces/krb/smb2_krb.keytab new file mode 100644 index 0000000000000000000000000000000000000000..0f637c1ef07b1df7d1cd11de45d1054333a606e9 GIT binary patch literal 102 zcmZQ&VqjoMU|?e4b_v!C4h;^}bN2UTV9CfYE@6-;$f(FkOiD`3u`n{!ODWbXE-fz9 zOU};)YGI7nZ!5;cAjF{Xq9ofgF)lmD+Ua=L(bl^++r8R3`l6o;C;Kiv5g>9|9;lcJ E0A=tV-2eap literal 0 HcmV?d00001 diff --git a/testing/btest/Traces/krb/smb2_krb.pcap b/testing/btest/Traces/krb/smb2_krb.pcap new file mode 100755 index 0000000000000000000000000000000000000000..0f726f45d7b9d2e0c5d69a54c67ddcb1d57019f9 GIT binary patch literal 44485 zcmd6Q2V51$^Y|V-P{D#7D^H_XLBNL31}gS~6)XWk5wQRwDq?$L*JvzJQDej!do*@q z&{(3V6g#$95)Jl-B`Wxv*}Hk=c;$@W|M&Y}K6`U}x3@DpJ3BMm9v6@OyxNAT7=9pihKsgxm&{sYDET?akjK0!PVywTD zz~=sqG+@B8>?b;~OK^`dPgy6!Q?aadpG=nJEU;fwupGAHQ}<3SV(`wn`zZtzK7IO> z%kSfujekpZXTKf+UAlEp`*-WorkigkwWqrWv+3yDxsz{aej5-GIWTI>NcEto7vuq?$}A~;qD2Kfe5viJI^8BHgDdX zSJDA0*#PLkn1}tfzBXsftHs`vNtmw@r9kOt7)xx6{R22gs!o z5*pgrIIOMdQ9a4ET$RYE*x-R-gCZis1_nn&26t=SvYux{Z=dL4VId>Kf+NBsqhi8P zsD2+?h^+x!81o3#cj0MVKs{wbwKqu9G|=CfeM;Gbbh5$5oZ`>;g{mZpmi~q8t_ri! zad%{q&gGvM{k!Pw>T$KsY+IZ~S#4~bcn3`diY-XUYAzuMjoY?qU}nJW$|NB(q29Zz z3zj5g4VREhCQDHuAxi6w65^ylLf)@R`JYG#a_Sp*fjzWiJjx}+?nZbzO311#V+pxk zIY`s2iN6!e9k2!4&taP=AtGM{=0c4M?Jfpu5>f_qK5;dW^>m;D`X@Ma)%B7D2S1Ml z2j3(Q4|l6QrJ}t-uUV7e;HXM)$Oom_8gwjyMJ5z@>5)+2X_BptV7D4Bh1cY>wPR{P zzcwNN1RD(Bd$yLIc;QWbWF1+Z`A*KG=qFH_} zZ22_DfFkSH9c`eW0Q+2L#W?K$4A z@K;$~hTZx)MKdDAeLz6D-tIB?Tyxp>XRfgR=Vb|@e>wXKeUe zf3i0T(>b6={YTBqe0m8sf=MP5O#5BH{ zcy-D7f=5Q(EIXoCLwDQl>vlTajlFujeZ2-<3ZJ>~Y544G^R`q_&nxYrZuInMpM*tA zO7;46N!R*W*{_CH=xtLzH8ZHAz3rxq-!4vUd3#Mrm;H{Po~)Y}vj6*WZCiFN{`1tF zC-?0ho|$!W^0DCl_dH`>H#py|&&l!uuie_%?kv&j=Ap@df4iyuPkwhERhT%t&-fb2 z`!lEYEMBkdxbYR2bRS=S+{1Mlo6nbg{+sW(b`gIRz8+Spz_@Ewub#Q@k>syVt}y$L ze&s6t?)O`(D}`7SkK?x!(^b`D-joWf`*vr^JDJZ0W!Ju0Zei?>9tFcjCrtk9_QyKe zhw8k4SM}7%(48;7`lrkLi5>R0+?yQz{`*%Yqdc0Pon7icd(`|3LGxR%v}?Jg<&HIK zf6*0g)+96F-erF$pNr^=VJXX?l)7L)Fy^rzRl_sTekA>1Y(MT@=Jvyx<$Ba&>{$Pj z8wVb~^?UVw=fdXqXxA>{V4+LpHqTwx<9<-Wjplx9*$MBsS{-Iau($WKY8Uxt?DiKO z8g)L=q}`tr+8^Ig?8Q8LTkoqQ_RUkp*6>;Jlh1|KnP;3jYZ{Dg)ik%}l=zhB`ZuD7 zpK#c>HDkl$@yRwj*Pm(o zjF&ye4}Ru#@YRgNt9K3FS+VDq`;{844ZJxv=J@^{p%VsWeVY*Se(Td&Ssq^>N|-QY z{Idcv&+}j3v0&gY!-p(85jVM8pGMt$tIgXPUiWx2Ro8X7zw}!0@) zx{IznyYXzEUBP<|r(HaFC~4d4dT(8uUVL~Zan06NRn^+Xr_{~=e6jU(c*n|PSG+uA zuX(Y~xlK^j(hIwMdcVHGQ~T}-`G3+D8M-`Ub&YO*?!G@w?0dQHl8nhUF7$G_Ga~w@ zwXLhJb!l;IZPwLN`SW|NJ6B@KFWDUqWG!qT)Am-@6_jR?3?fzZMzbGI!n&ngvnu6^|Y8oqtCdTR*MM=(g4O{Tdn<wfywPxpBv_7>mzq~`FT4^EA;96CI$`sawU=gxN=vE-*! zC#&`@{kF`}V|8K|KDm|V@bJ#a?6*y4_bOE)_KzYTYfm`y%Ybn+hpOW4F8=e<)>Fg2 zJF_I_@3=vQj?|p|sb_ka-@x}7wws?ux3HPmu%COt$6w}-cTveJ#7)e4xb8sf5h(sbLSMXNeK39~6vw$DF8 z>HO0M?)9h|E-{*6F zw?ErEd$E6yE|ELG+0nCa=$bRjd>4QBecJ`6IvkGaexXi-F5bygy45JNJJO?0p&G8a zYr=$2{%f<4^ zyDODj(DvPmKZo=#8NAbNRMjKBqM!5*jc@*BL*pX-rk&U{&{rt(gKwAqE&dqm`%C1p zPK7_LTXnk5@PXb|MhSg{j@-b(8YW0+g!%AF!Q~ctC+XK2Z zxxZ@K+o#uV*AKJ58?&dif9IRsOS;d?j6T@sedYRIQ_HkpX^Sd!jb%l=jw|AQ#)B19 z#1Aj{JGGukiny_diZuow8e^V8v0L(bKIGYHvJ~gmGha->uLMEv$QQuJ5af=0dU)9j z`27CS;v;XT^lx*kjiz~SHTOi!-hx3-^_qV?F@zK z2aSr&21+o>g^7(%{*jl`-()EuOwVEB4T8U%16(rUg&_yt9BcijISx1(aP5=e!t3|3 zv5FOgf-uV4Mo@)c#I{-Yi*egLY6oqz7~AG%b52>NA!T+3SZEp&+r|=Qji4Cn61+s| zqGe9}4(EWdwrYrR5Va5kAu{I6Izp@tcTNnkIrA@CwTqZ#oNMT>VjJNdM!9UU<>8ljzpr8}TaT*-X?$jZY<;XQ z>dHt%&KdT5aFBUW*6&@d^!s+qpS5IFc#F^PYO%L&;=MJDL5nZN7Pr=04e9o| zGHs#x-m32rn_vzIIohhbiX}s>G3Mduj_}KzqlIJ~T?!n%i5y+Hoil8zAx8~+t37`$ zYEny-nd_~qgkrn|>aD;h=&c2%QW@yg7&aQNquBsno1uX!hN?|eZ?eUML(MtIav@Fj%S*x{KzZias?RBfS%F=xC z72aOejoa&qOOVEQEVS2$II;6e^TlGl40X6TGj6@TYB0eLHQ!)E^59-hIZ|AxkBTja zcNpc`j(wB7g||sZ<2Laf3vDt7+vNFO{#k#+HbIK1O_Wkx0GuAAm@9K$qT zE5ony{#3!Z&7ZCc(zNjOhef@0M|n{r4BI@vjxNSTgQKL){q=?$inP||TwF7N^fbtf zF;B-jlDv&GwUjYaTX<#$JS%}reNl>k_MMz`VyaToi-MVJ#fuUzcB~*5M|?)&_`Ew~ zg;+oTcK&|-M#hXDIT~Cf!edGlv0*}jRjd?b!YFSTA%FNa-WhiqH_WpV&@d_3Fq4XN zYHk?T&QXUG7DOb9t#w8;Or?($&C?)p@SOW|0P&s&@Vuy2V3Ii(Fb{H}BhP^S(grvo z288B@4VZ&e8$!cD1inK&$ff4}_0G0j1_V{|c9enH=VUUF0y2>8@BDS(i#}KuGjg_( zOH>P`T*6gVQ(TJX#bYgvO@$q^;oL#=H2wrQsO{YyscR7KfEP zP>yEHW~o|L%?x<)jlc7Ng4TwWN?U-OUm8vlq~Rn%k#7AJxs4&nt7k)mBX7mOK$r*- zTSyI&S_TdNe{xtEvt7leK$#fx^uSTcJ9!WM+PDY$l_AbOKf^z3C$=#teh@BfV{(G1 zjR~3?o{`0^gpC>hlgiS@rJG!B%`@&!FTM%V_zi+p|C|`HCO{XKH6lgD`T$WF^K{LQ z;eYV18DX+4n30*y9R)#cD8ke=vEqe!?L`%6Wkv=!;I97_y2Z(VX z%$tp5LtzFj3Ji%mi(ruu*%!~yI71mEP;jf8hroM!u7>+=BRX==o{f7`I_ce~PmP_x zzkoo-2k$W;r>mc~C`dnZLFy+Hq(PYhFL(Gm4?bcnNCK`a+(B5)Cy-+ z%nM4un5Xfpgx}(gKi|0VU+w@w+68(!=hP@(w|C|mzX*T*?;BsPm(@^S97L@Inbi3I zNxiIwvZ+yb9NEjTQ8gACH6m5TUcxsR^Js^^l6P^v`dHSeyD|e_ZS{AKjD4ZupY4}( zkQ!Af2Ya(mTo6c~5+r>}kYh8rkY2sC=~x0jZo6^e9fYV?)p!Ge#NCu$MX?S`S1}b3 zj8QH_>`nM>E%h0Q>L7LW4AVVLA!dDPZ8*-qqB-DdBcK)6Zj4dgUN~|i+D6dI> zhH6D%HCd-V^Fiy%@sO=8Dx&!!JX$EDChu3lS5&NGHINE-EY^6c$^Eb7-6$3P9vMqT z>!{3t?0A3Y*y=8g@hf*Dsle`ytQrg@Qma|>3vgPaEaZ>I;vkSz5G1J}DCW{%5sxXQ ztj{6dX{86evT#rMwC_eVJnEY!=-}O~*7sYT7qk+TKGOljNA00|XyOKGvH@{)hd&Ic z6EI9oD(+V!Bvl}IZt&~T%^su+1jStXE8?S3jQ(lfJF=Gpzz+-obAxh;f$(a3mtXI8 zFI8ZplQZvOeWf(P#>+#+4px3N}hfYJ9puAwjr-Z*1)eS4)x3SQo(UR-t1`DF@5HTe2D`R&qjCg%=%Q=DI z>UTNyQz1>Tf5$W_X9kB_xQZo6kIewV^(Wp8W4JsGhyEM|GLDk%1-;A@7GOPCeSk<& zEJ#2Mz)%*iE1UYg&EnmK9&Jt)%)y@Zi2&q`Xi=5Oea^|Ty#2>Oe;Wq4<2j%7diBlM zQ%gPuyacQDb<<#)AYmn_R1WUVUhRzE420eu0g^!Vv}@aD?h`1V;GhP%iEkiHknj*h zd`k3cu0cJA1D_+M0<;ob{cPeYhb^gsIoQu#$|z}5H6;0XgdUrL2c_rHu=qX<{z9OY zaS7fXq;V{~qk6j(8?z1Z6Wsgf)IyGsCMYjnX}xDo2;lBU1aKNH$^faL=Tu;PhX)rI zfjuz;+qR-!jTl9Jm_XlJfc5T(ay5vJVQ#Se7zG@U1i2powGU)<;TdYYVF0~A>wCgq zFz*Q-aCKvy;0w%!{lXX0fsk$iIea1Q2G{y?kPJ4f4CgP{kcez(2BJ zB9X*rRg+U;f9y;Z2!2d$vw|h33k2m=!dffoM-8R=;sy(BV;n4whHnY)=8PjV-T_{7 z&=g*gAEeBmBA-^yofzSkN5F~8IOJjyb^4+qu@+T6LdL9UXZ?hmDIO>ad)oQ z!U0z_U>7%;z~ECNZ|bfO6I!247YN?1IH38uAI}Q}FLtAPhITd?DFOY+cbm z3I?4T!RwC}8~YRnEx*DZr*4ar?JlGW1V6ei49s^CP)+HnGG(;4JG=l@V<23F@0GNzD=aN zR7SJ}w+|X}!|PS5K+rXJ+bv8JG(gF35ifZ#@^^;mVAsW*PZ3btcz7{idf8*(<6`AL zqzVKdoco8T31+)eDTqmIpX&6;0vym#3(ZZHO`4w8p@tp>EdJ7|L_7Otab;m`X^ zXWOO;1h-v#whPk)f|iTmav=H^sEJSmdFbSzR^R5A zkCaLi2o8HIrU{y&M@c_yk-LJohq!(d4KzdnNA&%W9caCOXduXcc4GgP71IPt>!1uV z@g7kW6u0@0zp&wD$5_5NEfZVxi~(K1nrLg zs~g``7Y2NH1KU#%>fH$9Af5lFmC8tpoA5MoK$<|%Co!u_hcRgaK`EOKU^_VLQs!?? ztW|S891XO@0A777phxM!XIJ>wiyc>;Xp|;Yeb=VLCZK~!X&scIK>W33&rBsR`)}iF zTeS0DQ1^O()f>2BXy5C?Gqmzv+)iLQq#qj;NG$C+EKMMIDP=296WrsSB%$5Gp&G78 zo3-%#cyZ1b9K}X){UDBK#Znk^%l)-&^6)f)VB7i~+hLlZ<|r3$KqF$)!d(k%Na6iG zyV4vl_6y`dG+>Y6y+ZW&(ev>DuOIaUdO98;FK)m!sqUaxVnMQoNw~CxvtAL~ zzi_-%w%j2gEn*N`Us4(gdFjx*~mXn?p5RmDr8n)`@xp z_2x*hUO4g$gKuZ@QW(2&{hlfZ@R@@hIMtY0-`;BJTT8$;sG8J2hC|N`0Xf6Do>*vc zQR;9MjFPZJD&&)@bBUy>X#&AQp)n;fO>ovFUL54s)6v2b0n)o5$J!DdmilQ!=#`$l zhobJneu{k-$0hQ9O6@hJf4ed2FL?pZ4bo~a$I}q>=foN& zxm-^Z%)zCBRFH^I4M`>aVT*(>1UMW8+5l}j1}(qBdWrqjoj05^1cC=Hr=??>pp;Dq z5W5mR=(c(cU#&uYjh=+)#h@k-1J(QC{1O%H(lP{sv-dSyG%GzrAh@=zxCqNw2LDhC zS0(jcxY?TZhh4`B#2a0mpwC;bnLg6_gBl~ zum(UCj>A0JZ7Sr}``PI;fDSWo<4{_(*7F1Bajb<(Qz~&zDx2>T{b9T+o9{w@k!H6% zrC#92Iz!DwuU0?qaY~GB=nD3R;H>ijZ0)f$fuOt|O8LFJPgPz&%ltad{%u6MKyc8Kx;GktJ|bue zuM)qh==gB%=%Q8}3H@;x$UN#El6P%0JFhdbsRF^@Smjy=N2dz}P2sH~e`qQlzk%yP zw8MDVU=+7fIJR)(e>kU&{SQZh7^0;zwA~-{{u=5X+c)9phWK=W(gdY!I)L(^WZWGw zr!6;Yc%%$5YNZlpIi&D;KY}YOUE^tjQZ^kxT~kVzGJo?-H}5xy`vsBE=2%~xS4O{; z}>SJbi!?}$Y<2{k$FL3!zj zUoC%VBJDIyl=p!!vlEU3XCRA&d?uYX$lqUH8Jz*EQpoXLpeejo=c@~^G zz_}B#mav;PZb28sOYrC1{{EOISfl_sKq7uEeA@z|wQ%1IesNyM6RfrQc^;hYF*km! zoWJ&;Ye%FB=HM=!bEcenEn9o0@FIG{Ley z#1TE-R`kdMJZf^D!40UOk-r<)AgD?3urjXcp-uCE85s2Kk&`sHk7$x4T=yI9@%R?j z=LueUA5j<61l^jaNjWn()WX$EdSVeMT(3t-M~YGB7_QeN9t?|q$t=?KmvaKaJ^R+~ z#xy}Om;Q=eRbmfpboAk>xi|(8$EuBh5>K5S-1DK?l6&*c3k18idG9uN>3M;m92MaN z5lD!>94yeWS)=a70KX}SI|xf$wYZ)64&Tl^+js|Ic6^W~^cDUNV>dg*fdR{!V7aWj zysTMy%Ze?6W%)ed1xaQ3UAK5Tnme{?bff|j$af!&y`?h&$(-;0GQMxg z40zpw^WEr7fWY9_4v!cfTUAOijf%P8&uMItiT5}Y%NjHBbqiqPJ78k2r?|domWiYe z{*z4H1r$$#hQXLect<54=1lA&W8ynt;&vrWR7$ZC6EDJ!!3-b!m4X0#tNv9DOx62l&Ec&?DPV_IWkBf##=ism`b69>=5cGCN{@QCjVM(D^i@UsIw zB;U0Yj0jqTJq!cy5XWUGw?b2kEI-0o-r1Ptqx~`i-n8|19(zN61mSy-Tf-B9O6zCD z@(Aw&md>*L&E1gtYK)=~qhjPIa_&T;c(j(cQ)}`gT~5X3TU@F*%n` z0y!3rOVE)&Ycfj5CFC4XdRzi!3d5J+(ZcuQaf!Vz99cKm5{Xf635vE#K8n&5Kfzd< z#!Sx)c&G7qn&2v|z^}?0ok7FtBb-FYfQ@)cd4k6!rbGT{EDi!m6G4(Df?_WH6{U&> zuKK5W??_7ArB{THj%5&}V;KbHB_TeQ{Go}oR(d8sF2VNgdfe)1s&4xWr3nf;#~Lw- z(?ZBsYvFgP7qo=Q34hj`Pd&7OkF@mRZ&kaDDWl(Z!=yC9&iN>#9xrJGdSeQnl<;G@9m zoQg07PfPf57#PX99uAb?WV}1H1a2G<1N9?4CkwIw!L3!Cog^ncoOM`T!gWILy zZwz45Zr;KD;BNO+ipPlxv$D;3r*P3Yfg60g5jN)wc_ z>i}X`BIgx~KI9`q+)j;4U9@puhxdAC&UYPNDXo>D4xx0T6mN>Ot<6x*u!v|XFuC&Y z*xpGG#QHKRt%HPNaCt?KpY#dgr!>KR3#d1X_|@<&O|1}Rrr#wB!&zrz+IPFXQeO0$v9G^M3dWNk;fWH1p{D?~uesMw-EgK%w z()T}?;9odig16Qk=4pZni;e58hNKexe$iyT#mVqk(6zXu&~<-%EBy3!f>$drQJA))=>bx_UYhoR>Qkh-np5=59yl_IKi(vj=3AtYCm9*{+i7rE_ zH{>tjCp-ju=B9Ca2nHVbcliI1@Z)$Ie~iGm&*`PBT&oKlAHjaN#WcYq$$9ZBkuIjQ z4us#Z_Ims)$6w_53I5@HiKhuho3H}TM3Mz4NceG!1j+$QfFTd&OWzV6f_GG5`L?75o^%uQGeXqn8z@X(<#&VOgI6i_l z#UAlA!FS@`ImoTYucZC+nZYmG9R29%w^0u{K7v!*KjvwI*G%A7(*F64@SEzDA_IsI zEw_vHCfLU1DW`*A*Vw#XyAnPWFrq_ld-d&LKjjI>NAOgDIEo|+AIlKMLu;g?${ef?>)MDXk>5kJ9mb@TFHN&O3&#ZQtb%0b*3 zPd;iP*mz7`o+kL$@VxkGky|Xm^tG^r-~6aW?2)t>50g;Z!mvI=T94{zZ3RoWSS^u( z-qiJ1j+WM}AM!Qp$;NAV?=(T0dA)FxQRTZ-BP{D=wxgw=pnb&4lKs~LENj7LTn{WU znwMpElMyUu@nEf%#0~j+AX4b|+R@S`qm$@6&M9H+J1*D^zT*;H>$SGYNGXL)q?-I2 zfVFT@6=dHg7yy3Y<<#a%;EzhS#Ph@g9zV`%;7)Rmk9TP5Y-TgGE931eT38n?Zq?9MPcfcF+M`Ljq{>9o5jZee^OkYV#+@;rqkJeNP(jEnZ^3qTjaE8fW z$kHdI(Py5$1Jc^6uGdIuTJyN!O9de&(Hjx(=(%ZlPFnjyzZ#ELia%d6Qa9Jg9(5Pj zx~R8GX?k9NDa|y09^Ug3Uh#M{{xBFGf7kz143&TTjkMM$!&_-NEpmMx-U||5ocqPK zJ#j|Q0IwuRI=r$q#t+~9yZT-e7dZTWsqCfA|sS{Nk#OSs7B@Nh4Z;C4r*uL1rJfY+6S3q; zZ7gEZlX}i&cAK%xe)JB~Bn|>k>eH$=NT>N9trq`}ops$no|K#eNAYirn#$&-2qu7*;cpeMB* z@<(HF5dMu+DeCC`m^>wF15@@;fPn7C;q zt={8!G!EWtDbMl}ho4M1t=omhq%^_$>nJ1EOdLOv&7?P`;AzQ|Fx1lSu=i2)8AmF{ z?RCG)^%Oyb9%9|+~-YKdqo^)Hprc>W8&@A|JuZ_sW)N)z;HMtMIEZ@PpRcR%6}qT!lUG!#X8Pwv60B{bIj7gHW=i{chN z*caS`t!Qkea_oaND}P4M>O*~w+N=j#Ng-v_8|79CJ=i3ma4(dDQEoHf0AeclU<(`D zjFmrw%?MTE!78QjOFh`0WeZyR_f#*rH_%kZ=g=U{4_?UU!1Gvl)Bm0d-&Dp61ZxuT zc^<4g|3A0$pc5{CS z(yVetPxh*)cFg|!m9Kzu4Ax|qJXtvhlzOscguVoi7U&c`*(1P{pJ6nLQLdGQb;;>m znw*TKX_aecz$fu^+I##;h$D@TDe`3Ds4i2=6ZB+nz_(}}c#!s^e~wfs@nlI#$de^> zWa$VWr3q3#f=+OwqJ#yg_nbwH#3#AsQ`)AcET6ZFMa!4XEuZX2_$N3em$U|?I;XTa z({0xBRh4RIP1?xv$)y@C-(sN9g5}HLme0{x#*$!1)u&TRET2*eztr+YSF&jNUUTiC zG1eZRP6cUJS4KYHvP!HiS>q!=MXMmV)k+)!k zA(*v%HTY}m(ngj~E^TP}z5xm?SiTF~^5r*{v9${`18v-uSU#l`eyQafS>58Q#XGJ& znj7=k#yv>0t{C$9Y*%EY`BjUW3ixyLt+VVLAYZgx_=gH#HX;__?tl*R^Hg37?!#5zDdm!Qp!bFH)V)5uyttE?B ztCmHJ_YarZb;dGl3-c7~VTPW4+TIQ6G;i@}B2K9#l5;?*#iKJxUxG&q6%j3-U+scS z1H%@K^0A((cJd{ZrWpyw(zM<_Gf?G$+9*2#zf$RD?=VGUy&W(ytCS~b@j@X#jrIPG zR4Ezjk(7|dBYd>)gCOnuAc*xc3`)m(CuI9Sv{E6~>bF{l3^9qb(Mo2uD@tdr@su;3 zE5|cfhCjU?CzWdre?e#qG3fDQyIKn_I{bLP1b1Z^pE0d7!YiN4 z6VE#9=hx>;MOdR_unv`;4jPZ^UYWS5WR?zbWdkW04K0HwtPF!SdKT-1Tck$~A3GQp zVCKHEL=T>c#NYBDtmft%l2A^Uy39Qm!ni}VQp zz^zy-8K2?5*KeAQp4ao6$RMFQNdTq{_luBbw8rPp^Sml@`;NU&-b3{}adDO*^uO+L z(SM$|v`?f#eTyE~74C7(m&wiS%s{*Sd{h{NJZ8`39EaxPK`F<{y)e!&9>^l9fhb52eW&?{J*GDd^tBqyVZhw$w^F;Kx zu88xHW@p#y0Oc60$tsQgO7&5suN?Wc2T zvNFe@lqcrq7(Pd;bVfLQ+n7$kQT7o)$sMM-Zi$yQuWQ43v9Z)azhiZ*+b| zX`7m|bRWGfTDlx=>53Ukwf*!U&6f8d)wzXQanj9NI!~!))})#&om{HX(gilMXz8wU zOJ`#&V_V*XjNMgY>6B9VrIzl##-gRm<=Vqn#^<|1nyvA`=bU}7k&)&totHvBf1agN zE3kCm@l<-^b2X`EZzSB4}Hxm literal 0 HcmV?d00001 diff --git a/testing/btest/scripts/base/protocols/krb/smb2_krb.test b/testing/btest/scripts/base/protocols/krb/smb2_krb.test new file mode 100644 index 0000000000..7aa78567b5 --- /dev/null +++ b/testing/btest/scripts/base/protocols/krb/smb2_krb.test @@ -0,0 +1,19 @@ +# This test verifies that given the proper keytab file, the +# Kerberos analyzer can open the AD ticket in the Negociate +# Protocol Request and find the user. + +# @TEST-COPY-FILE: ${TRACES}/krb/smb2_krb.keytab +# @TEST-EXEC: bro -b -C -r $TRACES/krb/smb2_krb.pcap %INPUT +# @TEST-EXEC: btest-diff .stdout + +redef KRB::keytab = "smb2_krb.keytab"; +global monitor_ports: set[port] = { 445/tcp, 139/tcp } &redef; + +event bro_init() &priority=5{ + Analyzer::register_for_ports(Analyzer::ANALYZER_SMB, monitor_ports); +} + +event krb_ap_request(c: connection, ticket: KRB::Ticket, opts: KRB::AP_Options){ + print ticket$authenticationinfo; +} +