From f7299a794a317472b081373e2daf5197cc8f29a2 Mon Sep 17 00:00:00 2001 From: Lancer Cheng Date: Wed, 1 Feb 2023 10:45:33 +0000 Subject: [PATCH] tests: add test for bug 5783 --- tests/smb2-ntlmssp-negotiateflags/README.md | 7 +++++++ tests/smb2-ntlmssp-negotiateflags/input.pcap | Bin 0 -> 124452 bytes tests/smb2-ntlmssp-negotiateflags/test.yaml | 9 +++++++++ 3 files changed, 16 insertions(+) create mode 100644 tests/smb2-ntlmssp-negotiateflags/README.md create mode 100644 tests/smb2-ntlmssp-negotiateflags/input.pcap create mode 100644 tests/smb2-ntlmssp-negotiateflags/test.yaml diff --git a/tests/smb2-ntlmssp-negotiateflags/README.md b/tests/smb2-ntlmssp-negotiateflags/README.md new file mode 100644 index 000000000..7b78daaf8 --- /dev/null +++ b/tests/smb2-ntlmssp-negotiateflags/README.md @@ -0,0 +1,7 @@ +# Description + +Test SMB2 NTLM Negotiate Flags + +# PCAP + +The pcap comes from https://redmine.openinfosecfoundation.org/issues/5783 diff --git a/tests/smb2-ntlmssp-negotiateflags/input.pcap b/tests/smb2-ntlmssp-negotiateflags/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..3533790690d3095402ad4d286403d25dae24272f GIT binary patch literal 124452 zc-rlK1wd3;)c<`mFhdMwVxSl+*nn7=q!_f_D4-aCU>AtFc8iUPz3RHFt{vF!>YCWy z-Oc}=GrVEmFkB}de(v}GU}uG4?)ja*=iYbY?19ZoB*cVdf0+=D{=Y+YY3uHFOvr8e zGrThKiv+jaOE@#)OUSvZ6$nYP`!s*=s>2+8Ws>pqd*8MycGgdZz4VgyU!mC;} zY>Fa}x!M^>wzK2DB`K*7ytFqU-=*I=5z=nNf zO5<(gZm%6Vh_a=SQ^KltPQ;W*!@OG(Tl!JL)g)#CVSddWt5ji^JgES3HAUCD9m+q71&SE)Iity6_B2c8bPe z3}x_Q4RIK}>BTc>dPOt_V=04&|1=|kv_&8?n0b2IT%sr+{h5OsTb{ zKey$n6%tS@OStb)E95~;C7{(Qq{w~X-$aW%aTLi)#{D3qZL7=(*sUdx#0iibzpEi` z9N84^s73#hEJ_I!}pYMRQlrWyL5tZAlEk%vq%Aw6kL2QPs&smNT1Vpbq>iBTj= zA;gDxbB#S~aGZ<;?f5iLD|Z@x^I!k!njF@(Iw!3s&+=SC-O(TYfBEk*eO7^T*h>OW8}oz5yWd zCO(||`x+7r)x+Q5Gyi*4Z(0L1{;eAAP~>Ku3AmvQ-r;O4d&PDQ?-dc-J3KljQ%if$ za@m@4vXK6~Fgxj}r_XM7?2e63I^CWW=N>fuQ&XFJ5^>T3bVa9F6Bh2JZAQphZ%{Xtz$^e)ImBo8Um@~R-G*W%p||k?`Hdo zr;RFai-Sl?+|k$9*N^7QW`4dj4|;kB`ZeN`Sq8H7T#F21&74UyzGUEp2 z0R0`%gX%KTha$R%5WQL1w9#tl>^!UmJxPV$mUhbeb)S68wAFc4eggILtHmlmftuBt zA5ne+(%PB|(U8`()`A3Ip8<(@Do73bOAU;Sjw&Q9vYZoo(03(`OM$g+(7(;3WJ;5d z5}qP`@AGs@<)tOZqS6zoIDU`HR0XHH3ywFDFVgRR4cvTJB{UXn9YPoPbI? z@s*EMkc`TIxAKwR9Z=vgDQ|kI^+Eg{zj72cB$IFew|j(~G^HPC%4ei6YSCOT@dAC< z?$m~?jPylGy5lpQNPB#e|2JwlVAf=nA$1J2Y(iTya(WErbcgTd^ci_R83ZWLR+;^v zo^H=1g--g!RKe>L-R87fOI4bIxd*;w)?^9JG^l7mONYq{(u_8Om+~`ezFZ#?UXoqL z!K?(tJ@O>gNre+9Zja|wzHBleE<8d#O5rcam3?*V9~qVy-Tr%Km;I1#1&}iS zv}C1^WK19K8tKD6ZH&(8!<&^pu3oeJk?u`yS+d;w8oGCyLGGPdN5RtLNYrCBp&s|s zH0&%&8Xi@bi9QO^-Gt}?vG9`Hq9DmM0wtFx$8fGZc!W+5gf%6lPP}>CuGcQVvLav6wCes5RKt?F4kGiW-TH zx|FlgE(Pe-idw4Xv~$SZFr*~P{0A@dzIs&VN-u-DY{`~c7M&2@H#{zfM(4mvv+GRi zj!1orA=Fc#;z?oJs}xe7FQ&Z!^^H68>BSVZmy^(5^-HCV)p<1H6_iU?0O-dKGBsKT zW!_|nM(0xMBRVtF+ccEzm%NY-(7n^dPH#Zfxw|;&ExInB-X!UHlHP#XC3URGYufs? zHUr#kG#w0ZbFs<*u#Dk!+ypyG+BobX$CDjYzu!#<-!oF6F3T87X<5clDr*@7n9eQd zG6s%xew1Shmsk*~EiL@G7HbHo!2gLgX-_G%*QSENMl-aGw>?berTxnBJ_zFZdHQDfOwmgghC0>2PbIZ_uutUAH$MrWbhl*)_L1?aDu z%ktDHfU&lvjAfLYXq4Y{H_FjgvOINu!1$*%ljmE)$$GZ)1HD7$maOD3Tgy1ipyU8p z7q2k8T3jZdvBr?D7O3AJz#LJgpd=-P{@Q^0tFzJmI-jEVeZ#Q=vJ%R+%;10o2*28L zmZ|1x87diMD!|%v*^JzwE$(Q;I^SqMcAF~%-R6F;@wD3XbaM)j3;jqQ!ua3KY|@`kB9ci~u7Z`}dJ1*wDuQ5_-X8JyDr zBC4ku%RI}pj1LVm4`4-aWtyiZiZfXR^DLrZt*S}Hdmhjzmqly}K$6#&u%2HG!si$H zgwHP?NqLITGc!K{mBD)?*eC%THD3N$|9_}hhx9^7>|Um z-6MO4Csghi7ZX=GHolujL}dTyu8|&%WBNwM$3*sR6y7&-K=>dZ<-3$<0zy-{&j|tQYgwW@wL) z+Gyw{yrDlRsG-YcoDM3zXt{DsevW*N|5!7qZpC7V4M(X7t-I!{4ON>1)}Xj zT1*-2DrF9<>Is#gcP|eRZ6+~uPJM(JE@sXFRB0wN02&C(7u^CNmC|jm;85dd3yq3VS2f|d8H-b$tTv31#QJq;p`Uo+uUIgz= zDBNp~js+w@6nMbw^y9Ga`t7IfyFi2&Y!UjP2pfKC5qeEz<`7>r^Z+q)2%rw;WGuzS zqvF>8)QSt3CC;;?sABxHB-49&@+@g7JSd1^hO-}9`B#I(86a-FXQtLh2r)yy)Vhq) z9mwuS{gLiip6<&iV7=$IhTV1SM**T|eP%*!j1Z#@PpHc&#^-uWF`5W5^cDjkZpSi> z+*CLO(c8!X5%-If6}Jf(x9fh|xCIePm1By~7e!e6Q;Q(G!K^l#p`izfP;IP$(`b&G zvgUdI!g(HRjd`BYX;bu_=UGXyY7JoqNgxU~!r&kQ2xm75OPrl3jzS!9o_%Dd#9-l| zOShDWYFci^l3_Q>U}3xrX)swin3)?xQHG(0=f+hO>mvf#8aS6Bg$dRI!Qw;!TT8+2Sur1o9zeG+)p*J_BWXOq*t}9c6#ez&#k*8Pk9E6({!xI;Q79ABf|H2-cVbTr@jFg zA$6HNKR}*W>E;`#12^Uq>Vp_NCdS7OVEuK0nG{-MQs^y0QdkeUb+MEs*dY{5V!U90 zRXjC&1-C#jZ7aA{+u)#O74?=nZ=2glTb3_i!%}8jRAx^Rl(`8O7Kt?G>vWkP^C`;Z z$(ZkV%It!P)~sWYD&wMn6pdq$%G+5#N%~J7g9IX5)9#kB_TvaH0vM>V_G6@-ByHM% zbL|Jnyl}ZSYwbrBH1k-EwI8LZnUnulto;BLJbTJqCVCXjo~e=Jrln0+&vD;V0OUBp zYWd7swN^`zsc@~9v<6@~C1$C6v~sQ1W%sn{qY2;j=!S)>v=p6jV=?^S0@3B)tW^Uf zEnTaF4r>dy)2`5Az|h63v%5lkpaFgd5Kk#Y_Fis0*+%`rirQXoEe}?*PPX~bQQOHj z9H*oNC`B`^Ndx+~2HN^>*Tjdy{#(iPsj0a#J&Tf~LlJ!Cu!@fq7YI1qTBQ))GU(m@3pb3SyB==}C!M+C=$Wo9Z* zlNm@P!QPI6zRlsuiDPhRP@_=K07q9^*GZar1_pQr;*YJOVD!bEN4F~Y3FVIs8Z7Rx>|kHt~#{i{C7s*&p$5uMDtE%rVp>QXV-%prAqc)u*`h^j3cui4p9)b_Uf{? zuNG$Y=%ZD@<|j>V4~#jW!joow4s@2H1y8dbd=8F9b7`5{+$Ge-Dd`uNGOnduO3I`y zOr-hko5%KyjByN$?iLdr)6FrsUzc9dT^*Z74$}F9TVRh0WeAeq18wepDWo&H`&|up zKf?{0{3+O;eEX#;3cNw+3F>`CmfL@0dqP=ail2o;>^3*OzG}dXdv>V~N>1XiSfnqB zt%OJ=QadToEtf?fYNstB4Bqf*B=rA zE*c)0ufyB3Ykw;do3Q#t{YM2ui=S`XZ>`(P>a&V$IOhD=YI;j!Bf#Y+h=3k)qFRxb zBLbX5!m%TpEsOx`(cGY^yMyh>*D16k11jUxsc3dU&eD3=0sSTPr>VOsr7@IB=9FM1 zm1AsPx*#vJGt)##-Xj z77(Jwpl<~20 zVk@azz-T%l9pk{3NCPT8kKDoV1D-&LzzES(O3(m zhk-y7XH5E#i<`MuGCo$)!-$LNzmq=b?s}anGp+I*t+JH2ic*NXX}JoKQJEPlxIENp zO14#i;YqvnVR(8~V=eK@6fKeH*ESc|dR^7{Sb1ei>TX-;*VZt1JK@H($_up065c9G zf$q-8RiNV4n6ZNEXq}R?tpdz9{MAtAe@igdLU%Jkps2DlcI4t_@qL;4d5QW-Rh_$t zdZh`tB?CWQ&B`%_Co!eB{ITzRR z?9a5sE40L7-V#c3RSxA!&bPnup?8sbFL$c2vtiyluRk+ZaG9`EQnpn9?bjWKqU{?( zSks+dak_JyYSd#!CR{lF%$%R@{PS<&{Lx3|U2~TEKK? zg>5-0ju=W<)147GGHa^AqXnh98fMHIcNcHE6S%oKl(42d8=-vbG~`=NISK`C%xWs9 zJAu*@D$pLHeC3d9Q%EGrWv(GtD5bU@D4iaF#vGkJ-RXTq;~oU%3`mzBFx?5_bfI$n z!zo`mrgip7{XsGJ3TY^2Jr(IPh~r)pBYu`joD}Wi*qIWk1w6E~%bx7{a+^zX=vo7( zX~t!eU`}&RN9?&8SB<%oH=#WXOUE~zw%>f%yeao8&2Ar3w(8V?Mu*o=8QZh8WX~aE z=W1Mkg1MSnqX>a>gAZ!+);~j{&|9S%-g?=#!!SRXwHttUWRUS--URekxt7U!TcUvT z&Q0trvfgfj|36DeY7pt{uQFkMm%6FeE((FkDwsG2Hg6UX78Z=Eo0DvIOLNN4g0zLD z9ya(3$h4ix`l=klbJ0s$wX_; zAm_-E5mQ}8OiGnnaNH6h`vXn-^Xx+xD5KxC=)VP%$KM*abAD_0-8HRvy0z$ceS9{b z1j_(y!iYC%iSw+=pE%V|CaRyLs-NVKi)ibRtb5_fWYTz0C^JDx||b{O6S=CTK&Q;{c3?=W-J z^p15Z@7P2&yV_;MO4RJq5#vopjODc{&6*wVpVeqU*1xUQ{w+bj;a^+&4Sz2N+!@+^+jqirP-JKDQ$v%NlBsq4R3Pc_=`56 zH7{F@m`c&EH4|8iLaQy(i7YARQUr8Fc($IIPYYX{*x{ado-lNUvWH97mM8j#bjLj5 zE%byJZKzxqsZ3vw$dPq_kg1;*Prz=#%mrlfr;f}~sYrYJt@Q2oq%pOLHz^ARA$%#L ze1-O!4mpaDHbpJRX=wQ({WDbQCGjOEjf1^;JD*-f z$VQ@k<`f{rJ+Kno*ApBmww;`07qt#W#!W?h{13Tx)oF`3$Bk7P5l{J~;cZMvZ?> z4K9^7Lk+qLHJDi7!ts|Sf&YMo8vLhd=ifrPJ>3iwUk##sxYK~Bo*rpGl*Jv!7g|>> zRaeDXv5idq_dxyU7wZ3INh-r+%Kw+Qb#>8ya31I%%5302Y?HDMNYSSM@zMa)zrTk5 zCsP^bg8t*`Aw);E{)0jPB~OANc$*kYhbV>4|!t zsG;Y%l-C!*w&Y9lcAE4km0d+FvqwOhRDwf#;X>2aJeBk!)X;S+m6WONuCnOa-`&Nv za$J0Dgd`$X8j%nu=^dwKrRi2!NAAN!>y2ow#6a5y>n4|&8M(M=EO|0Uea#pDK7aZq zp!}+il5-TRWo4Nr>NpbW)maOQBx_|Epi~^j)LaZ|uB8~7`wJenBr?%r5v_$7XuDx4 z%5Y28V&^#YnP!akHxaN5L|h-O83XzZv;}}gC8~jGhIf!O5W_oJBfMWwz`YRO z?Q3g*r7*#ICs~qk`g6E8$-+YVpk(bdB-?A-A*nD(<~LKB6#%SnuKjZyktpvi0>HK- z)BrW53zG(+bi;(wB^9Qik3l-$eHwr%xdJ+60ZvV3dP+QcN~l<#GI+ElE9WJkK1XTj z^D!0CE7*?ayaGy|_o-9K`3yT4m6WETBri(o2|Ni;&Znf(c?^@6zR1f+4PKs5O5T`% zX_vJh?pd``sID)_K_w)lAL=iVr*i!i)nC2V4`-EE+Z)&|5_VI5Ux5eUX628TEV%v% z7a$7ULD*$kn?ADII# zFl4Y$nQ#B4a2{)ao7*%S&Wyr+AL}33JHEt_JulF5@)AS#ygN3<%j@B$Ryw5AcM+~$pa7#dYCK}$~ zl|2h!4B9o=fHjAShS&XMc!_~_ouW-{_jaJU93?#?Co$Vke~oGbfD2oY27dobVWITg;p#*ISh9jPY^-mZBq5 zu3u5EddAE36b_DR&%_#!SaprZdIp7*LDf36{Af_M{t^~n&t}SpmpWzCFa&sSM-6cNCjJ)f-#fuPlQp&&V z$Gs&R|Lu;{swbG{9Q9Dna*ldjkC(fazT-eQ?W3N4JGt9Vt2J(#u29lC%Yrm>OL86c zWXaAR^#HR?3d_}RdRBG_*~~hAms#n@9W;SEO0I5PNiOU+BF`dg*Do(<`emmgjG5ZA3 zJH7cGtbRa#o8Hli6>kTT>*@OBw{_OmKOnyywy|dMosN7@(ie}m8b?;RmXYQTPhZ`Ej6%FQ?v(69`55ZI_6E1IdLJ!n}*9NsSz}6fu%4N`O*3%AE9}cI=~VwAVG}cO30q5RCSMEGGQ_H`&LMV{ZqpMR8o zKYd~H`x^P3`#t@d!jgHh^y{IOUs{0xQZvqi#qS&BH${VAPL1C$K*hwwLbduqOEpyf z`_<6>a_)a>ddN6|nsm4(b33fGi=psBXPs9s_M6h^1>XEFUnNxD&gok*W8 zXQ5Nsf!U7FZP@awT1!=?%zgSaiw3luTi${+qm7!WPoMJQ)Q^OHR(9zLSviz@!m?yd1~b1MPheEplGG%G2)bS_Ei+Sd>LO>*Cern>V~vyC_(5cb1R0ua~c% zZzJD8AAeu}ti$}&FJ4vVdqD52bl(HCl<|Gwds&gh;j^sQ|4Vu-##i0-p(!)u){ zN!Eg%q(Yxv#!|c(cFQH_C;-X5yd^7!-(d{T7RIpfeleg@#9hk;z`V8^Ms`Op?9F@O z)1h!X*ZCnKO}>9S7f=t{YMt{E7M^53SW8%<;e?iym@Tru&G#JVT=z zr~C(0SAf*57n9#l$nSJkbp=$)#K?`zVwXEZs#$KmahVRO<~fC9WU)b*#jN-&rX*do zwoar2+A*u+FQ|{H-_yr}cIH3Ge)F7}l^O0)N$;V5Wd^i^YB2j-+{KaJ&5-^UsCWL| z>PPxa*FUUSJ~IS;#?m04k>6le4!Hj$Jy6Wb;Vnh&x80Eb7FzC$l(KShSV2)z(~9xodfnZ>!6b{AtTkfGiB4`o03QPs43L z>EZhKX+V2n9cG_~dwkM68q%i$^|>j`keP%bQ$v)H0XTAt+40~GqI6#|JD&FxwXcpH zk6;376twg{$5hW`R8MtL)bkPVfs%=mZR5Z2*;cYQPqHmAD`)Fw3hKsP6y1EHaH$=| zj$EKxzn(?T<*~d&2D(<(GN0w~wd#g9`Yw+JtnLjgjC{U*W(hoxmXlU*wLL=zjOq<7 z7|*v8hhouKkS`jQ^oCW)ou0F&u{_^z4H(jnjncI}LkEoMo=l#HA` zMR+l7ig(+5n6F{eDjVJ!V$)*Y#_H#ZFUYgF`N}W3* zo-^QPl@deeUn!TH4c7TEc}_&0^YJ_@>AgzNo!(qui=20S^7MQoar0t&3%=tx{0H3e zS@Y;_a~*G~1&9v83YOcrXqoKtc<;R7otoSDHlgK|7cHl}{Mc?YJ49jR0;cC(V7XDT z^Gjvgmm2{}zfc8Z0aIcU8o`D)f|BBN!lKx*f(^?IxP37_j5ouj0bqtM>7ASEc-1OE z45(tmGJ~6zc{h(;4jVq`drj$QxSppEm#2{c7=05sRwRr-BiQN|2|#c404`564q$`~ zWb&LWbR2fZ0ea5ExIFDe0OPg9gi z5|%i%wakwhS&q!GAK#_tIu0G3#%?-O)}mkzQRG^ z=a~cgsW_moCdzb&RJj<#&wm}8xcFUB z)*YgG1#vdoU4IkYnO<3N?eb~GEIUcs%&cpdcYOESWp9zLT{hqfVvg)R%V|C4Q>wgz z7*sHSC{y7nsPIZ+C_Fz!a~Z}&n~P`_#Xu`a(K@iv<{?@IG0=)owC3BHX!8-RyjW<~ zW#oCZ+Z3n=QtIODHU(;9%E*7fo-;stzRCIrAQh!ZyUWY-c%zI1MF}k?7x{@pNlG

;@1!F79tiw31?=)uL!^OiftB zrIm>0z@uGQ48x^}rPG!eFkGrl;mnIO;nEPUxF~QQ6s}}DCfq87D<&FTbY(NrlQ!(B zZU1VANKCS4UJ3TEHZGM8`&S>i{d4&L-~Fpb?py`c@20BPcjxNDfII zdoj0=ameok*1~+C(lyNT2W$iZq{_{i{7R7D@vMy?KxKN1AEn=YEt&jEk>6jxr(gMD zOIB}!#qgPz!ro+8UFc0#x(p2czuv@%-eeV3y}rFk?cx#*)&E~_!tPBHTPsBAO(K5b zGHaL3}DEsX4~EG>}CSEHx;FfjZ%Jd zVLgiZGk!galJu9aI+33Ez?8Ag!D}t_4)+zpZ4TphAG>e-)*nDOdCEjzhv=3or3h4lj{S%&r-1bE z7?WRIYBYHyt5O6iRZf^2nbqD;gVfV9@Rpknsb?pJV`R03nAINfSxrg$#6X=$4-Nm1 zlmx)+g`I|!1klo9mo>}mmT2}7-!prcUDkR0tO-!I@3Q^@!BCeX1z+cWlp6zFi94+G zJNy=-8$Zz7je&G!dkL$1+<@Jqd0uqRfPSL|6a6${27FFSGAFJI8VUk2JOtFR8*@Y;lmlxdjpuVW95-`ox8p00AnjzlLZO16WSY#%Io z^GSK`;BWYjL_p2&VVJwEG=OUP-khb;ZGd_&Q>f8jsUI4@;~mfkRcD=i=CvKszX{RHQ$I9*$2*|A z?Y1^x3p2Eoe`M{{_xcO@{+btlSf8Sg^OdpuP=TIu%n&~W>aRXCyCo~6eq8@<322)~ zTC()E3-$I%!`rCdoJG;wo8s1@bP!#h@f`%s@OjZe0JFtt@ha{zoCdJ`z+XmM(f3+u zGj3xi8#L~2-nj3JQR7zc9btnri@vX%&1MoA4>O9U<3PnNU1BR`6E zz!2~7f{BzjOvM#I>f4P{9Kd+iXKfAN`wu$DBG8@X+AuOn=8 zjFKy2wQX|*3~w(vW80)(Dvl{%@ncFQy(_M{)ARH;mgl1t5W{hji?;2gfbrIc$@3EA z`6bV@l3r-j-04aB$r<~%oC*nJ?$Zs}zom%y(_6>wXaMo@pjDo$Wm`JyCKkV?sFoMH zt7X;^t2}qVDo2?-FGHT6>+XJ628h$whj-xnddZPI>Fa@6o1J3!_1=`Ktf`chp$=&o ztI7`YOd!p~IJ;2I0#hfJ$o(C=6%8PUC zR}klVkJmGF+{g(Ksk^ON;vCa5@G{6cKCo@%H&YhYaV^6vgH#7tr4yN|b3oN?F<5l~ z5iGS-<)a)BeolCTu5`1ihhIS<+*Vfn%_|#1n$Rmj)-Nt1ylWsRFrH6idKI2}DP1a(R~^1(#Tq8z zA(vAAsAuln5Ev$fuWVS-@L`f4EX!Wa^kqE2QTm5|z6^ACSsQz}@U@%p9Hh#6$I-0k zAX#u*Y*~j3`z^xh;$VFy1Rl~RU2GJ@{xi(32hUiN^0(}8 zm%{+!xXt^rI(9t((Q~Od1MiM?_<^_SqdXaSH>J$}J)7x6xY{A3kQhD$Xdb7S+IJWB zn0jl!8HFet#PlINY)ZPoU>^dAL%t4$^YMqnf0140bJmaBIUl0oLmg zs_DA%Y6_%SL*}r~XY+cDSl7hCYI;=8GD$sQ+CBCNOfq{*{O{`ioG`$oS9JeKl}Umq z-PnJbxdqoUWfT-6w*cDlJxnR;3p2ZJQUp`F4GuBsHW214-ROqGbEga@-G;(Mr5oKa znCfa}%6dw-5w)J5*ZSYy@RZK6-E|)Wp3(u_Ejef!hQ`dH`?2Tx&Kv^P7Eenfr~XgE;HX4js~2h7rs@I1+}n~h^}iAaTTl4G zmXhA1nz_@f=xZ#`2Lk~k(f8SXZI46%qn96(=QQN`G0(G--rHF1^qNz8ww{taQ2QbqEu8YjbCrWw%IL8Uhhr};2 zR4*DIsx4sR{W$Y+&nv{bAP&}+W=u71Mm5@rqQ;gKZt7!ZXW=89$<(d0Xa)PMTQJ4I zMVJ}3qKMHJ&cHb-&d{jUCw^$8sF){1qjs>=avW1PxI{F=Mikw&hvfnW9nA+V!wou` zuM=(gw26#$rp+HhFMce6Gi}~|Y<*haGi^FUHR#F2`cvp?hGT_OtY3#Sv9=0LXE;_D ziZ%9xf;6EmnrI8nx=y|rnzK|V_{LK#=Zn4CsI9g!iHnYlG)?F^C@woVyTS&ekxVIY zWom}C@lpWR(_Ks{{7{OS`brT&DYvU?#iHCuINhr&}Ni zf{WjHbw7pc5$kzgTy)WZbTuB1A9%{lj<}fc;#X1NCcyLR@=WOtBit9!;7T78@4&6e zZn+$|r2wQ$7nuic6~_J3{e=6cA4z$Na6<=BDg4Y*wSPKC)#UFKh*eV(Up4&;Co{WG zoLituwt5t?QBl!dBfIvBj*RJ>i&nO5X72U2M_&7WkJn#*xBdaTod{X{F;go+sFg%x zv@!|yenm1}6W5_${49!V0$l%BOre5NsNu#6HTal9|E+MNp{31ng=Y0CtYai0m10uD9i9FAs5Hrk8?w1zpu@Ge~=BBQ!>kM7a4SMQkExIXa-ef#wv zpn4l9Tb~e6&gKazJA?scEB+w>m8XSHlqbXU)t5}37a`9_)Ocp7SgU5vIP{ei37e9y+iqqjB zt*V4E!|ILO+V36Gm|?AU?1jEFtbp~!jTkw({`W%MbFulWpSH$eFIk@ROk!j# zo;M)RcXa3ZmsnYz`-UQp$@6c*^{?OejYmt&*xdxDt($KERlSK8vDQ>^EbL=T2a9 z{lq8N&#+q1!{_X$Vfv2eX2Z2L2F?CMOTrm483HXsYspkMF6QXU-4)9lk|fzx-eRNo z%eY+w!iVCAlO&F0Yyg~LX1axwO3gUVL;@6>*A`F|cH!<0t$^Z5{&~VEZr6U9@8ZUt zC{^#Ie2(Npy_^)K9x_!0o`Xkc1)QiZb2z2Jqc^46IoOsXt?BR+sJx<7&QSvAv{5;% zScz0zv{JF>$k^9t%=s|ZjmLu;!;T0JY0S)2o)bEdNP@i`1AUvrdQivU(4a=4o&k=o zRa}UqnP*^tXCVIADmo@2c0ht-RBXIstJwIS-Qr{W#U(gatKu3?KNsLy#jUlAiyPm> zt%@s=1U7eU7U1Yo#g)EInQ(Ngf}c?S*q}iJ6w-2@49`RR#N|{z_r#$!2x-|yL;0Pl zptnHC{_ij|?)^rIHdM=$oSuh^!ecB*wzFe?TUI^Mq~VH>5%r6Gn%Gi~e@#-o+W9^% zHQMQ4ZprHnV@J_{lSo5^>YU8gmB}i~I8#$eYBJ~IlFU^~E$U(~v!L&paLF|#k`ih^ zTP#iH6eh`>S)gyDAm7%_!+3t7BZ#A~!JF%(9XkI%?HL*47#7_vCOW2@V{pGN zy`sB1HjNyl^9R8bGN~s#fcX|}?tV#;hVEWm!`*NBE^b;j*q(g5t2~8tgU}Pyd(SMl z|Hk%&vcwcWn@C^9TO6|iHwpNU2|wYEUX;FDMy}A`uV{;&zZI)6dYpvOGi;{s z;sA)AFaD`WY^l?m0zuuV`8OM{8heD-=%J^aG1w=^kRkhbu&zy@S(yiZ1^(GO13)@O`#Xp0fER~Rt?G-8H(K*Sty zL+M)avKAs_FT{&oF0!ILeRIlcjw@SixFyM)CG~cBs?>txmIwtK@zP|(GhQ?xT!Mbr zqW>059)HWa&z51!$Isf%6HKAsE!9Nzq2h#*rgXdzM1o0W`ZrhNM+4P`v>+jrS_#7b z1oz!fn0)sW((iskPRz)_w5OO9KngHW_hT}0n2LK?lG7O_+ZAvkpR8CNp)(Hm@Le33 zNDcJ)Pzf}{q}-fQs-uB~&RAVFmRgc5adkO_tc2Buf;$k$|{8{aygp<@~uV zSw@4{H>2PEvwj~A8~o|_7Y>X$?iO#fL$-qx?1TR7bZ^wVB@qQ8c55onjVjKUsxN@l zB#lTvl0YI!JYjz-w=d_^qi^m{KWH|sp7X$OYvz^arRB|`_|X5wc*{DUlwSSwxr>aL zU{ILRzqzRQSB`|NAJeY4+3F6~{Z|K8O3lBvLG;0|Gut2IHV=ri`S*9zW1NM`9n>Sz znRF%5B#LUaDn+eL^;m`eTZ4vN75u$6{#%Vy6SQmHIyvy*@*#D+*1Ni`9kt@XvV11C zz{hl#%Kf@G^liYq^`_G@GLrs0QrkeGpF=xvYsE=n-U&<`5T0}#a%?qa$KRND>)sl9 zN2*8OAv{ax|7DIe)?nH{E{wFKP2RDX=$gY+`1N- z)BC^rAw}j;jiPU9$xVt|afib$o_86UdHvmoG^ab)PkHYvI4e4E$(ydRkBluchyGMW z=7!^IJiA>V9ykB_S?ROCcguaOi(R|1uUFsHl9zU!deHxC&LUG*SI#OjH(>OX(ukgW zCkvDt0zC8K+G=S-|N$HPF{8-PuK^L`MVtj})2bx~%`` zzo*h&pIw&i?5A(5Q1DKxwDl%F3wUXHbNp4RV#ly{zuEn4MJCVR z&r)QX_bc=MQN=ii=$5O81l$h1$`_eie~p~6vPAm`-mRrxa#oSq35(35!o1^j-cdHw z0o*#jC%ed$=#h6+MP@#4X6dyN(|)=z(q=lGEZ|%QicGf_N-CT`v&h_pMdnr&6*F$v zn1p$8e39AKGG|E`>CY@OJ7bY)rlu;hd0hGlO0^FZnV%}=r1;67Dd}dE^neDBeJItF zP-M2rR7$$CF|)}09jVxAr9z9X5@&ygBC}M3#$Q_A8nvQH$rr0feqC27X!fu@^<4UG zmqxAed*S#H+lcj73bk!oe_*R##uk~weySpK===r?r_4DsaA8pX4K4pXdh%6`zm$zao=eWbQoZ^my+Hhm8Dtw?3Xo&hF%k%%=DI%!}&#Z5!{_7owR(W>+jS z(}j8GsPmYFMQy>YU0Ui_WSZ+zWX|uwEWQ53w7*9fX^YxYw)#Pl8P+39uz}1Xb1N2^ zn^aWHxm_!-ExN=PnboW3ED8GzViuVZSY(>0smi?B)(fjC)yq(1+8)SB@$Dd{q}x!^ zT^c-Irc~EJkr_8zDe0=g%p!9;QnAoVg%(>4OZ^N*W|7-f?;fz5z3bQCyAJAq+isJ0 zg~cQ52EMg@dL;8*ovxG1YAZ6!PGJ_Ak=SM0YS?4V%4>@!f!z7l{MaHh@!XpqQe+O- zDEhvR9a#KILcUu`t^NwhjDJ^aWz*fRMds9T4tDbyG@)H`sIf)n@Sm#4ymi=Y`i?5a zw^ut}cBRM2e4lpC8f9r#vwMnbH@n83s}Bs#S!9ly#w;@b!ssa|jGo1lnr+Qk14U-U znEz6dxq3RY$c(~>*&>XX3>q=1)u71C|3$wd(<-lu%+e*^)Uay*DBpj-$mEj(-}QOV zViuV@u*fVgbjH+b&9+`Ph2A*sf__D&)z4I9_CEG`eEg#BQi<=w@Wiq8i{)jJd8y*u zX3O`kI`^S^d$T@6omJBE=4iI>pZlf0jIH{!6`4GLKTDB$YM=fGx<;^r)@>xgyVc&xb;Ypnwl>jq-o zGahRp#rja5iFFgP?i!D^lwvKgWFA)02N&K)^9%3ymVm=5YKLY%U>{bo40idwW*$Hi zkCeOXOL;k^+&RgdwMXg}>gOh}pGOMVBXz1r{$2*`kpj5g1(_;JKta0cE657CVq^|e zklQH84N(MHN#RD!Wy0M-xa*?9z01$kTVK>$l)idf1uJ_>8L}}CT7E2L$i_Tq`I>F3 zyQsWtq9|`QTpRqwiZxi@hlBMrRW`Pu*|_%fYy4o{^PF&K4HRd6wPFp{g_Y#(wNEe%IjfI;DC92J0nhuK`r{QYwtC90!m}eyvpK zpf&K_PrsD|gsfT6nzfaq4~{b$YAFB6%GxuAgOHOQe(Y8b+lXh690!s=HLllg{)a~Q*gb3#(hR=BDB?0;IwS_;=#U+B02Xq;0MEv0FI~?-^hDN6bwnX?Wzb!9jcf z`NL^jd_(6RT_P%v-cx%#v8!day6x6>J}ui1>}+fVB>hx#Q-7Pb``YtF!5HW2!<#)w zE;FI$+>>`kEXaSQV6UJ}yH?K|C7hcAFEaD6X3b5dYs~Co^vrbGwBsy9&lj6z|COyA zAnP3}D`Rdd0V5_&7%^udVqg(h=IK=ZwsP3z)!fv}Z71qAowlIre}8U@PYNIf7^r<+ zYjTE)dq&&bRJ!62&Q0ahaK`hScAUEpTR9>yLrUiAx|PFDr@1Ll^|`5fF3FPG{M=M= zlVpj#=G@e(thuSZYI9Qs=r=z%H9l)@%1k1hn<~72Z@&{6zqmh%vb8Dv@>dyq)~Pv( zCcSCIHz$!Kfy!X`JXOur(^~D>T6{>4zZx{mI9aeOFF9|T>J8W0oC;i&{s{O z5+L6`{G#8s4!iHoQvpj(4Xs(Dj>FgmY!F7>oPN_}HM=5ta&m1V?MGqG*iZW2#Na3p1wqQ*bJwdojJlsutm@F!tQqw`-$)ZgZD_Q;A z3Z2h1fR-zAo_L|dnFi4EuMnnuPf@-M~6L z4%Qpb#KP+pE}l0YYbV9(yUK#){&+t8#eaFMm*v3yH@vT$Zh-smf-}9BGvV-v_=~4S zf!j^tx*TD`y+*iGqQLEitF=umS#WO1 znRyi4vcbjA74>z?qc~^G#Ck8(q~Tb{DAt5SOso$=H5!g}0tN}6m{=bX>!k5mC*er( zC5EJbXlY_l`aeZmUi-|H?-R;*!g%>EP%NLnEppz;z+-uYd=}1+f2a+2GK55oXWq$h zk<#6Glu7rCaOzk$x*3%2Hd9L$-LFXZs(y4YQ@Sy}OuFBY?iKy$UWesk9hr19k?v*v z=-!404fm}WX$#i#P`U?rx({YS+8SS~T_pq3)*TAB=MEE&L%98-z}> zp5A`Je!;$h^t0Z0y0bt1$q(Lxqn&j**}1Hilby?Eo$L%#aMg33?5rTEJFJN6zEslv z#qfrXL<)n|BuBWu&$}gg4hLKQV#7$}p{7DN{uTj=JmLD0U-eDoFW?T$0!%EK(1#7j zdP%YB6l7w_h0bI+)*FgtUx=`<%n)n0@mL=y*1dvEEOW%#WjxjwidFA5VcaViYJpgP z@mQxS!@Yt}uh-tM|Gk1=DcXR;Of*YG+b#y$Hy96@b1XCkqHPlcjntI39&N%zvqH43 zVxUPWT5X9TXBpC*s`L>dnm%kOgKw-wV$hst zkgF^jgSM2x&xuTfswV6q*xtaGqDN^gT-*HLKJJLi zhicS@cPP`VqB&G?%HXvarZVhN85@jOMk$K5#GrBqT5d6@+$lp_&L1viC6FR0-x}4^ zq$ZF+dNv*yWIzHbOW`v6FyV?K+-gzaegRjGW5N|fxK*OSIYE@JV!{k_S5O>BDwbNQ*mLC2#-D!Q0top>Jo5^QO}GY?Xehru74#7Z zY18+|?pruB=-k*Jv2S67#wzNJ8SOvcvVOm&T1evMcC}Y+dD(s3>|ljO?1RSF-G9G6 z-qzSv+avymS8anQSodXKL2&~2Exgxo_eU#I-Z;X(g_IQW_bpV`d*4Eb{bPFW=xyu0 z$}ZXMVZC67kUastO#7{FVRN-@s#}GBUTW@J0J-1)%DjRCkG-=vAdG-Fj;Tu&3t$y? zg87f#w_thU!q^|NZy{O3BljE`xiNNez=t9i!c(r*oc68Os_?p3o!!PRnB2i`T4v|M z#zsK$PqlAhzuE3XoA32(HM`@7=~a$w&wM=hm%Wnaul#2?{n>EqW}9ikeGA}4qb4)2 zpg4)0g+v%ViUliD-a+(y8QbB%vTp%o-7tlD1qB}QXxU8|G4E)^Sb0IjOzoxLzJ-E$ zwQphIhj)%K<9_*HaBv%+6fluc1KCZJk*iePtJ?N0{G<3A_bm{iGg^7ANO=!ORe!EA z7tOFt*L@2Gb=tSkRDItb zQN+%3SL(15r$@Q-I^c~|Aaec0(228oXWu$gMi$eb7i$|nOmn~^GZn3c+35X{)Fn0#A@deiPOC*~I(w1t zIJ^AnfJxo|EZgp{sHMLyz5b?vG8;LNCB)4`A`c6GV=>6$71T7S*q#PG#AcB+??Jp{gaHWp0p^=Y4Y3xwdvbmxB^+rz_Pyv zsyX&REoCA|P&h?KF3~qGY3o)`IN%|Gmc@j+{ZNZaaTPqHpYkrWR80wrd`E(RQtg5x zPklA{I`q!uHV(C|Tyv2iE~`EK>!McSrDWMn_13X@b@*-^=kopszqIkiSE`ybI6sOf zu(V>K4A%VND~GRcRGikh?N8~eS68HbyaEN3#XKZ5O5M^hXyPM6mW!n|ziO)$Tk2nn zIpr~9a#e}mkov4b_4fqYIrgXj?@!Y@NOOxy^Dlk>Uu`+zpu<+o38jU8`|(QZ61zz7 z+f_G}Zlo!VtDe%d(HMB-`lZoBfg6A{(AFV~hJ%K^+ANZhrBI)1v)4?;zi6+TLVMXo zu1NVb5QfHoVyY+I)g`o5vzJ^)3Ck1C6!KAbEkkQ{&Vl1p$}zafJZ(0a=zzy;D%uEb z@@XLD`ZQ!i7eD2wL6c)wJvla~eT=;popV_);M8%kj5MLYG~sgUmaD5cgVPR^HFSHL zatpEW?IMmEI9qj2&DC^krX#1WG_R#HbgKDfN-U)yRBBcXZL{5Gn_Vt&MI) z>jiKwT>Ie0!M^Pi;`=A`@2Yf9iPogA{L;tOZEVtmb&?9(L^a@^r+DggNRuX>JM%5kW)A&69`}d1w;hbM~ccfk8 zxKltwqg9tMgBFj&R77d`*N4<41)?AwzUsmbS_?gbHbsN8w3W=DJ&!?KL1^m&Q7clu zGy_{-JH`%L%e)NQxoI*|pW2|lwkcj02R!-EVv|s*Uz$<&FGIdb$4*pYl3UPP>JhYC zICVFapc}$_z}NyVyJytqKGN^}p5@7Ezq8+$YP>Jk;8(7in)V?9bQBnvwR^-$<8%D) zp(K*@Cb4+@gClJfL4S)TF{;mLrV;*k?<~638h_`1_o4KnNI2<7dQsYrstKA%jgbw} z_?;iO5)C_P{x0NO*-9I~yf?L8B_q?}e12_#FiLR&1Hnrp5H7Ds`PLk2D?g>qTdRAM zOf3);I(m~mqxu`TPDbc(5nnly$SQ|jm_%v`{ry|>)FlOLg1@)Fj)aG5a_Fijhjon{ zC5@TIJg@X3>Up71&jo8zNzTGk+@u~#D)R!xd6qxscm7#ES2a(b<$FTk`eV3U~%=Y5}C-y)NLA z+hwdp$DTqTq2or_cO3O#fxe55yHYHtT}&)5q0SA*ihxIB!ez?Yn$ng{R3}eE%NIGb ziSV>*iP~w`DjLwz^b1oyZZop2wm*USmj5uzq5w<_e4uhyqM1bj|=?pEmKV!-lgz^m#N50mDnf{Q1{@|mZ zKa8SuuUBB*#T6QiGW0iIhH;P~yECyu5UZc@SQB9=b;gV}R1QU~K0MY(e;6v4u>Etq z0Yl|U6t2)MCR`Z8#fbtp843zETyunr6$Nf8g}YjUbzF653xtai1#TLJ%eUN+^ZuY^ zx#fnO_cxQaOliv$u_cPwTNDxJQ@BBcS=YCPwh|ifN+5(nb?5S}^bLgt@YFqpiPc(Y zJ;SjUQmmb9tTsY58jiIX4)&SL#A=IJy^P0NMzJoPV`8;Kte(bWrBSSU?iQ@dy**-e zSDjwg6e{=m@e}RzuiRHrw15yMS_eeyCI;GSisn9nK{w6^5iOXgOeoA!+M3+S2VfQ^L+DVT2eG{s|io9HbWt-a_jcj&+7& zJ!50V2-Rpf);U-d#>R?8tX9TjWl*fjo0(W~h}F_~tgCQ#uC*1bqQJ|ZFNUcq-HA|9 zSVdZ0)4!s)M$tCEP_WSO0_cmOVxV28X#Ln|cuVue5HZkh!rBlv8s2SuF<1<=yA-W> zRi@qgAzF|aX!j^ueS?xDwCre5l7yE1JZy5#-_i~~=lref@p9MFcO2-Zeg5{5l#_3% zr*Yg=g_71;<%E>Wjmm!GNn8!NZ7rK|a+aE5`zk7KH%Nsf~(eUQQi~eGuy{Bjs`if)pJLPzz kXCGiJs?m|zc}&#|L)A1ALp2{^ZOZ~C+Hgek69eu40mVi_$^ZZW literal 0 Hc-jL100001 diff --git a/tests/smb2-ntlmssp-negotiateflags/test.yaml b/tests/smb2-ntlmssp-negotiateflags/test.yaml new file mode 100644 index 000000000..7d3c479ce --- /dev/null +++ b/tests/smb2-ntlmssp-negotiateflags/test.yaml @@ -0,0 +1,9 @@ +args: +- -k none + +checks: + - filter: + count: 7 + match: + event_type: smb + smb.ntlmssp.version: "10.0 build 10586 rev 15" -- 2.47.2