mirror of
https://github.com/mandiant/gopacket
synced 2026-06-21 13:57:02 +00:00
8eea029431
The embedded gokrb5/v8 library hard-coded net.DialTimeout for AS/TGS
exchanges, bypassing -proxy and leaking the operator's source IP to the
KDC (UDP/88 first, TCP/88 fallback). The DCERPC Kerberos auth path used
a separate library (oiweiwei/gokrb5.fork/v9 via go-msrpc) that leaked the
same way.
Vendor jcmturner/gokrb5/v8 in-tree at pkg/third_party/gokrb5 with a
required KDCDialer first argument on every client constructor, so
proxy-bypass becomes a compile error. Wire kerberos.TransportKDCDialer
everywhere a gokrb5 client is built. Stamp udp_preference_limit=1 and
dns_lookup_kdc/realm=false unconditionally so KRB5 is TCP-only and the
OS resolver is never consulted; /etc/krb5.conf and $KRB5_CONFIG are
deliberately not read.
For DCERPC: set krbConfig.KDCDialer on every krb5.Config, pass
dcerpc.WithDialer(transport.ContextDialer{}) on every dcerpc.Dial, and
use the "ncacn_ip_tcp:" StringBinding prefix on the OXID-pivot dial so
go-msrpc's hard-coded pre-dial net.LookupIP is skipped (defers FQDN
resolution to the SOCKS5 proxy).
Verified against a live GOAD lab: 8 Kerberos-touching tools plus 5
NTLM/password/PtH regressions all operate through SOCKS5 with zero
direct packets to the AD subnet. Negative control (no -proxy)
immediately emits direct SYNs to the KDC, confirming both the leak
class and the fix.
35 lines
908 B
Go
35 lines
908 B
Go
package pac
|
|
|
|
import (
|
|
"bytes"
|
|
"fmt"
|
|
|
|
"github.com/jcmturner/rpc/v2/mstypes"
|
|
"github.com/jcmturner/rpc/v2/ndr"
|
|
)
|
|
|
|
// Claims reference: https://msdn.microsoft.com/en-us/library/hh553895.aspx
|
|
|
|
// DeviceClaimsInfo implements https://msdn.microsoft.com/en-us/library/hh554226.aspx
|
|
type DeviceClaimsInfo struct {
|
|
ClaimsSetMetadata mstypes.ClaimsSetMetadata
|
|
ClaimsSet mstypes.ClaimsSet
|
|
}
|
|
|
|
// Unmarshal bytes into the ClientClaimsInfo struct
|
|
func (k *DeviceClaimsInfo) Unmarshal(b []byte) (err error) {
|
|
dec := ndr.NewDecoder(bytes.NewReader(b))
|
|
m := new(mstypes.ClaimsSetMetadata)
|
|
err = dec.Decode(m)
|
|
if err != nil {
|
|
err = fmt.Errorf("error unmarshaling ClientClaimsInfo ClaimsSetMetadata: %v", err)
|
|
return
|
|
}
|
|
k.ClaimsSetMetadata = *m
|
|
k.ClaimsSet, err = k.ClaimsSetMetadata.ClaimsSet()
|
|
if err != nil {
|
|
err = fmt.Errorf("error unmarshaling ClientClaimsInfo ClaimsSet: %v", err)
|
|
}
|
|
return
|
|
}
|