SecuraBV / CVE-2020-1472

Test tool for CVE-2020-1472
MIT License
1.73k stars 360 forks source link

Event 5805 expected behavior with Secura Script #30

Open ngc5128Centaurus opened 3 years ago

ngc5128Centaurus commented 3 years ago

Hi Guys, This is not an issue, more a question. I used your script to test updated Domain Controller and it works well. I also test it on unpatched DC.

On both case I have triggered 2 logs Event 5805 for each script launched. Is it what is expected ?

Can i use event Log 5805 + my DC name appears in the message ("the from Computer") of the log to conclude to a Zerologon attack ?

Moreover i found a small difference between a patched and not patched:

My test with a patched result is: 2000 requests from the script resulting on 2000 packets TCP/port 135 + 2000 packets TCP/65xxx on Firewall (the RPC calls) On the DC event log I can find 2 5805 events:

Now when I take a non patched DC:
Success! DC can be fully compromised by a Zerologon attack.