Repository navigation
Validate the SPNEGO NegTokenResp before parsing an NTLM Type 3 - #306
Pushpenderrathore wants to merge 1 commit into
Conversation
RFC 4178 section 4.2.2 marks every NegTokenResp field OPTIONAL, so a response may legitimately omit the response_token or wrap it with an empty value. The previous flow assumed a tag-[2] field was always present and that every tagged element wrapped exactly one child, so a token missing the response_token, a token carrying only a mech_list_mic, or a tag [2] with no value raised a NoMethodError that escaped the server-client thread and dropped the connection with no reply. Walk the inner sequence with a nil-safe accessor and bail out when the response_token is absent. Wrap the Net::NTLM parse so bytes that are not a valid Type 3 message produce a logged error and a nil return rather than killing the thread.
|
The red CI run here is a pre-existing flake, not a regression from this change. Only one job actually failed: The failing test is Across the 16-bit PID space and 100 iterations, this collides occasionally; the collision is in Could someone re-trigger the failed jobs when convenient? I do not have the admin bit to rerun from my side. Happy to open a separate PR to either widen the PID space in that spec or to seed its random source, if that would help. |
Description
Gss::Provider::NTLM::Authenticator#process_gss_type3assumed every SPNEGO NegTokenResp carries a tag-[2] response_token and that each tagged element wraps exactly one child. RFC 4178 section 4.2.2 marks every NegTokenResp field OPTIONAL, so this is not true. A legitimate NegTokenResp carrying onlyneg_resultor onlymech_list_mic, or one with an empty-constructed tag [2], raised a NoMethodError that escaped the server-client thread and dropped the connection with no SMB reply.Walk the inner sequence with a nil-safe accessor, bail out when the response_token is absent, and wrap the Net::NTLM parse so bytes that are not a valid Type 3 message produce a logged error and a nil return instead of killing the thread.
Lab PoC
Reproducer handed to
RubySMB::Gss::Provider::NTLM::Authenticator#processwith four DER-valid NegTokenResp shapes.Before (upstream/master at b303067):
After (this branch):
Verification Steps
bundle exec rspec spec/lib/ruby_smb/gss/provider/ntlm/authenticator_spec.rbpasses locally (22 examples in the Authenticator spec, 0 failures)bundle exec rspec spec/lib/ruby_smb/gss/passes locally (103 examples, 0 failures)Authenticator#processreturnsnilfor all four malformed-NegTokenResp shapes shown in Lab PoC (upstream crashed on each)Test Evidence
103 examples in
spec/lib/ruby_smb/gss/, 0 failures. New context#process when the NegTokenResp is malformedcovers five shapes: empty inner sequence, response_token absent, mech_list_mic only, empty response_token, non-NTLM response_token.