Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[enhancement] Add MS-EVEN methods (CheeseOunce) #14

Closed
edermi opened this issue Sep 7, 2022 · 5 comments
Closed

[enhancement] Add MS-EVEN methods (CheeseOunce) #14

edermi opened this issue Sep 7, 2022 · 5 comments
Assignees
Labels
enhancement New feature or request minor-feature new-method Adding a new method to coerce authentication
Milestone

Comments

@edermi
Copy link

edermi commented Sep 7, 2022

https://github.com/evilashz/CheeseOunce

@p0dalirius
Copy link
Owner

It's in the plans ;)

@p0dalirius p0dalirius self-assigned this Sep 14, 2022
@p0dalirius p0dalirius added enhancement New feature or request new-method Adding a new method to coerce authentication minor-feature labels Sep 14, 2022
@p0dalirius p0dalirius added this to the 2.2 milestone Dec 2, 2022
@p0dalirius p0dalirius changed the title [enhancement] Add CheeseOunce [enhancement] Add MS-EVEN methods (CheeseOunce) Dec 2, 2022
@p0dalirius
Copy link
Owner

Added in a8fd037

image

@benji1000
Copy link

Hello,

the author of the CheeseOunce recently noted on the repo: The MS-EVEN runing under the NT AUTHORITY\LOCAL SERVICE account, and this account can't provide valid credentials during network authentication so, in the NTLMRelay attacking, it can't work.

Is he/she right? Or maybe partially, as it does seem to sometimes provide authentication if I believe your screenshot?

If the person is right, is this still a protocol that is interesting to test for coercions? If not, shouldn't it be described in the windows-coerced-authentication-methods repo? Or maybe it is just a lack of time to do so, which I can understand!

@p0dalirius
Copy link
Owner

Hi,

He is absolutely right and that checks out with my tests

It is a lack of time, but It should be added yes :)
windows-coerced-authentication-methods in MS-EVEN
Hopefully I will have more time soon, as I have many things to append in here

Best regards,

@benji1000
Copy link

Oops, I didn't see that the repo had a "possible-working-calls" folder, I was only looking in the "methods" folder. Great!
Thank you for your quick answer, for the documentation, and for the tool in itself 👍

So, maybe that Coercer shouldn't test for MS-EVEN? To prevent users of the tool from thinking that this could lead to an authentication received, where in fact it does not provide authentication, and is therefore useless if I'm not mistaken.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
enhancement New feature or request minor-feature new-method Adding a new method to coerce authentication
Projects
None yet
Development

No branches or pull requests

3 participants