Commit Graph
16 Commits
Author SHA1 Message Date
Jacob Paullus 703070cbd1 registry: add tests for resident-length guards
Cover the GetValueData guard added in the previous commit with two
table-driven tests: the rejection path (dataLen ∈ {5, 8, 0xFF,
0x7FFFFFFF} with resident bit set) confirms the guard fires without
panicking and surfaces a helpful error; the happy path (dataLen ∈
{1, 2, 3, 4}) confirms the inline DataOffset bytes are returned
correctly so the guard didn't regress valid hives.

The matching guards in SetValueData (resident + non-resident write
paths) and enumSubKeys (riSig branch) require full NK/VK/sub-list
hive synthesis to exercise end-to-end; they're structurally identical
to the read-path guard and are validated by build/vet plus the lab
regression check on secretsdump. Worth a follow-up to extend the
synth helpers and cover them directly.
2026-05-11 23:54:22 -05:00
Jacob Paullus d6089390bd registry: harden hive parser against malformed inputs
Four parser-panic / silent-corruption bugs in pkg/registry/hive.go,
all reachable from attacker-controlled hive bytes:

1. GetValueData resident branch: VKRecord.DataLen lower 31 bits are
   read verbatim and used to slice a 4-byte buffer at [:dataLen]. A
   DataLen of 0x80000005 panics with "slice bounds out of range".
   Found by kajaaz using Zorya (issue #25); fix matches her suggested
   one-line bounds check.

2. SetValueData resident branch (structurally identical to #1): the
   existing len(newData) == dataLen check doesn't enforce the 4-byte
   cap, so a hostile dataLen=5 with a matching 5-byte newData slices
   one byte past the DataOffset field into the adjacent cell. Same
   guard.

3. SetValueData non-resident branch: vk.DataOffset is attacker-
   controlled and the code does copy(h.data[dataPos:dataPos+dataLen],
   newData) without ever validating the destination. Hostile offsets
   either panic on out-of-bounds or silently scribble over arbitrary
   hive bytes (a value of 0xFFFFF000 lands near the regf header). Route
   through readCell (which validates the cell header and bounds) and
   verify dataLen fits before mutating.

4. enumSubKeys riSig branch: readCell can return a slice shorter than
   the 4-byte cell header (minimum-size cell with no usable bytes), so
   the immediate subCell[0:2] / subCell[2:4] reads can panic on a
   malformed sub-list. The sibling code at line 397/437 already guards
   the analogous index; mirror it here.

Fixes #25 plus three structurally similar bugs surfaced while patching.
2026-05-11 23:48:10 -05:00
Jacob Paullus 3a8420dc5b Merge pull request #24 from Jah-yee/fix-ace-parsepanic
security: reject ACE with AceSize below minimum header size
2026-05-11 23:31:51 -05:00
Jacob Paullus 33758f735c Merge pull request #26 from mandiant/kerberos-proxy-leak
kerberos, dcerpc: tunnel KDC traffic through pkg/transport
2026-05-11 23:24:03 -05:00
Jacob Paullus 8eea029431 kerberos, dcerpc: tunnel KDC traffic through pkg/transport
The embedded gokrb5/v8 library hard-coded net.DialTimeout for AS/TGS
exchanges, bypassing -proxy and leaking the operator's source IP to the
KDC (UDP/88 first, TCP/88 fallback). The DCERPC Kerberos auth path used
a separate library (oiweiwei/gokrb5.fork/v9 via go-msrpc) that leaked the
same way.

Vendor jcmturner/gokrb5/v8 in-tree at pkg/third_party/gokrb5 with a
required KDCDialer first argument on every client constructor, so
proxy-bypass becomes a compile error. Wire kerberos.TransportKDCDialer
everywhere a gokrb5 client is built. Stamp udp_preference_limit=1 and
dns_lookup_kdc/realm=false unconditionally so KRB5 is TCP-only and the
OS resolver is never consulted; /etc/krb5.conf and $KRB5_CONFIG are
deliberately not read.

For DCERPC: set krbConfig.KDCDialer on every krb5.Config, pass
dcerpc.WithDialer(transport.ContextDialer{}) on every dcerpc.Dial, and
use the "ncacn_ip_tcp:" StringBinding prefix on the OXID-pivot dial so
go-msrpc's hard-coded pre-dial net.LookupIP is skipped (defers FQDN
resolution to the SOCKS5 proxy).

Verified against a live GOAD lab: 8 Kerberos-touching tools plus 5
NTLM/password/PtH regressions all operate through SOCKS5 with zero
direct packets to the AD subnet. Negative control (no -proxy)
immediately emits direct SYNs to the KDC, confirming both the leak
class and the fix.
2026-05-11 23:23:21 -05:00
Jacob Paullus 5d927b8e6b Merge pull request #18 from mandiant/dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
build(deps): bump github.com/Azure/go-ntlmssp from 0.0.0-20221128193559-754e69321358 to 0.1.1
2026-04-24 11:38:50 -05:00
Jacob Paullus 8d16dfe1b0 Merge pull request #20 from mandiant/fix-restore-svcctl-tree
relay: re-TreeConnect IPC$ in RemoteRegistry restore
2026-04-24 11:33:19 -05:00
Jacob Paullus 2a36bf72eb Merge pull request #19 from mandiant/match-impacket-access-mask
relay: retire two known-issue bogeys (samdump ACCESS_DENIED and winreg PIPE_NOT_AVAILABLE)
2026-04-24 11:25:43 -05:00
Jacob Paullus af32683775 Merge pull request #17 from mandiant/fix-hive-readcell-panic
registry/hive: reject malformed cell sizes instead of panicking
2026-04-23 15:30:16 -05:00
Jacob Paullus 4b90cdefd0 Merge pull request #16 from mandiant/drsuapi-ndr-rewrite
drsuapi: fix DsGetNCChanges V6 parser to actually extract NTDS hashes
2026-04-23 14:59:37 -05:00
Jacob Paullus 5c03c57191 Merge pull request #15 from mandiant/smbclient-list-snapshots
smbclient: add list_snapshots command
2026-04-22 13:51:55 -05:00
Jacob Paullus a0afb8d5b9 Merge pull request #14 from mandiant/version-centralize
version: centralize banner through flags.Banner()
2026-04-22 13:33:23 -05:00
Jacob Paullus dd189fbad1 Merge pull request #13 from mandiant/dist-prefix
install.sh: prefix cross-compile outputs with gopacket-
2026-04-22 12:36:12 -05:00
Jacob Paullus 38474ef821 Merge pull request #12 from mandiant/windows-build
build: support Windows and CGO_ENABLED=0 targets
2026-04-22 12:11:08 -05:00
Jacob Paullus 4890b97162 Merge pull request #11 from mandiant/module-rename
module: rename to github.com/mandiant/gopacket
2026-04-22 10:29:58 -05:00
Jacob Paullus 8f997a5157 Merge pull request #10 from mandiant/proxy-support
transport: add SOCKS5 -proxy flag with UDP guard and test coverage
2026-04-22 10:15:36 -05:00