Added NTLM relays leveraging Webdav authentications #652
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Added a new flag (--serve-image) to ntlmrealyx.py to allow NTLM relays leveraging WebDAV authentications. Useful for attacks like "Case Study 2: Windows 10/2016/2019 LPE" explained in the post "Wagging the Dog" from Elad Shamir:
• https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html
PS: this new flag in conjunction with the tool "change-lockscreen" that we will release soon allows to perform this attack without having GUI access on the victim
Thanks to 3xocyte, elad shamir and dirkjanm for their previous work.
Authors: Simone Salucci & Daniel López Jiménez (NCC Group)