Size: a a a

2020 October 30

AS

Andrey Shcherbakov in CyberOff
D P
У них есть ОТЧЁТ КВОЛИСА
Обзовите их вульвопроебилити шканнерами, корсарами и мальчишками.
источник

V

ViolentOr in CyberOff
D P
Я ж написал что они недопентестеры
У них есть скоп тестирования и итоговая задача? Задача достигнута?
источник

TE

Te Erevia in CyberOff
D P
Расскажите как бравым пыньтестерам доказать, что null session на контроллерах домена win2016, во-первых, не страшный и толком никакой enum сделать не позволяет, а во-вторых, его точно нельзя лечить "блокировкой доступа по портам 139,445"
Им это QUALYS сказал, ёпта, так что мои потуги с rpcclient в качестве пруфов расценят как нищеебство видать
«Попробуйте проэксплуатировать а потом приходите»
источник

A

Andre in CyberOff
D P
Расскажите как бравым пыньтестерам доказать, что null session на контроллерах домена win2016, во-первых, не страшный и толком никакой enum сделать не позволяет, а во-вторых, его точно нельзя лечить "блокировкой доступа по портам 139,445"
Им это QUALYS сказал, ёпта, так что мои потуги с rpcclient в качестве пруфов расценят как нищеебство видать
Никак лол кек
источник

A

Andre in CyberOff
Пусть пок делают
источник

DP

D P in CyberOff
ViolentOr
У них есть скоп тестирования и итоговая задача? Задача достигнута?
Это в рамках прохождения аудита на соответствие, а не нормальный пентест
источник

DP

D P in CyberOff
Такая говнина
источник

AS

Andrey Shcherbakov in CyberOff
А вы им знаете чо... "Воспроизвести и эксплуатировать уязвимость не удалось".
источник

DP

D P in CyberOff
Te Erevia
«Попробуйте проэксплуатировать а потом приходите»
Но я по этому пути примерно и пошел. Покежьте импакт, животные
источник

V

ViolentOr in CyberOff
ну тогда это не пентест, а некий vulnerability assesment. Отбрыкивайся неактуальностью угроз и спецификой бизнес-процесса
источник

АС

Андрей Слободчиков... in CyberOff
D P
Но я по этому пути примерно и пошел. Покежьте импакт, животные
Агрессия какая-то, спокойнее
источник

DP

D P in CyberOff
Андрей Слободчиков
Агрессия какая-то, спокойнее
В письме все дипломатично
источник

DP

D P in CyberOff
Would you be so kind и все такое
источник

A

Andre in CyberOff
D P
В письме все дипломатично
На, тока это для 2012 кажись, не думаю что что-то поменялось
источник

A

Andre in CyberOff
First, you could go through the following article to get more information about Null Session enumeration.
Null Session Domain Controller Enumeration
http://inner-tech.blogspot.sg/2015/09/null-session-domain-controller.html
Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

By default null sessions (unauthenticated ) are enabled on windows 2000 and 2003 servers . As a result anyone can use these NULL connections to enumerate potentially sensitive information from the servers. Null session vulnerability is disabled on fresh Windows 2008 and earlier versions.

Please refer to the following steps to disable SMB/NETBIOS NULL Session on domain controllers using group policy.
Applies to : Windows 2008, windows 2008 r2 and Windows 2012/R2
Step 1 : Apply below group policy settings to Default Domain Controller policy object or to the GPO object that is applied to your domain controllers.
Edit GPO- Go to Computer configuration\Policies\Windows settings\Security Settings\Local Policies\SecurityOptions
Enable: Network access: Restrict Anonymous access to Named Pipes and Shares Network access: Do not allow anonymous enumeration of SAM accounts Network access: Do not allow anonymous enumeration of SAM accounts and shares Network access: Shares that can be accessed anonymously Disable: Network access: Let Everyone permissions apply to anonymous users Network access: Allow anonymous SID/Name translation
Step 2 : Update the registry key values to restrict null session as below:
HKEY\SYSTEM\CurrentControlSet\Control\Lsa: RestrictAnonymous = 1 Restrict AnonymousSAM = 1 EveryoneIncludesAnonymous = 0

Best Regards,
Alvin Wang

Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.
источник

DP

D P in CyberOff
Andre
First, you could go through the following article to get more information about Null Session enumeration.
Null Session Domain Controller Enumeration
http://inner-tech.blogspot.sg/2015/09/null-session-domain-controller.html
Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

By default null sessions (unauthenticated ) are enabled on windows 2000 and 2003 servers . As a result anyone can use these NULL connections to enumerate potentially sensitive information from the servers. Null session vulnerability is disabled on fresh Windows 2008 and earlier versions.

Please refer to the following steps to disable SMB/NETBIOS NULL Session on domain controllers using group policy.
Applies to : Windows 2008, windows 2008 r2 and Windows 2012/R2
Step 1 : Apply below group policy settings to Default Domain Controller policy object or to the GPO object that is applied to your domain controllers.
Edit GPO- Go to Computer configuration\Policies\Windows settings\Security Settings\Local Policies\SecurityOptions
Enable: Network access: Restrict Anonymous access to Named Pipes and Shares Network access: Do not allow anonymous enumeration of SAM accounts Network access: Do not allow anonymous enumeration of SAM accounts and shares Network access: Shares that can be accessed anonymously Disable: Network access: Let Everyone permissions apply to anonymous users Network access: Allow anonymous SID/Name translation
Step 2 : Update the registry key values to restrict null session as below:
HKEY\SYSTEM\CurrentControlSet\Control\Lsa: RestrictAnonymous = 1 Restrict AnonymousSAM = 1 EveryoneIncludesAnonymous = 0

Best Regards,
Alvin Wang

Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.
Да я видел это, часть включена, оставшееся не хочется городить без весомой причины
источник

A

Andre in CyberOff
D P
Да я видел это, часть включена, оставшееся не хочется городить без весомой причины
А чому ты решил что никаких энумов там не сделать ?
источник

DP

D P in CyberOff
В текущем конфиге они могут посмотреть имя домена и привилегии анонимуса через эту дырку. И чо?
источник

A

Andre in CyberOff
Значит принимай риск )
источник

DP

D P in CyberOff
Andre
А чому ты решил что никаких энумов там не сделать ?
rpcclientом потыкал
источник