The implementation of the domain controller in Samba was found to be vulnerable to the ZeroLogin exploit

Samba project developers warned users that recently identified a vulnerability ZeroLogin in Windows (CVE-2020-1472) manifests ) and in the implementation of the domain controller based on Samba. The vulnerability is caused by lies in the shortcomings of the MS-NRPC protocol and the AES-CFB8 cryptographic algorithm, and when successfully exploited, allows the attacker to gain administrator access to the domain controller.

The essence of the vulnerability is that the MS-NRPC (Netlogon Remote Protocol) protocol allows during the authentication data exchange to revert to using an unencrypted RPC connection. After that, an attacker can exploit a flaw in the AES-CFB8 algorithm to spoof a successful system login. On average, about 256 spoofing attempts are required to log in with administrative rights. A working account on the domain controller is not necessary for the attack — spoofing attempts can be made using an incorrect password. An authentication request via NTLM will be redirected to the domain controller, which will return an access denial, but the attacker can spoof this response, and the targeted system will consider the login successful.

In Samba, the vulnerability manifests only in systems not using the configuration 'server schannel = yes', which has been the default since Samba 4.8. In particular, systems with 'server schannel = no' and 'server schannel = auto' settings could be compromised, which allow Samba to use the same flaws in the AES-CFB8 algorithm as Windows.

When using a reference exploit prototype prepared for Windows, in Samba, only the ServerAuthenticate3 call is triggered, while the ServerPasswordSet2 operation fails (the exploit requires adaptation for Samba). There is no information regarding the functionality of alternative exploits (). Attempts to trace attacks on the systems can be done by analyzing the presence of logs mentioning ServerAuthenticate3 and ServerPasswordSet in the Samba audit logs.1, 2, 3, 4Samba project developers warned users that recently

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster