Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Event 5805 expected behavior with Secura Script #30

Open
ngc5128Centaurus opened this issue Nov 17, 2020 · 0 comments
Open

Event 5805 expected behavior with Secura Script #30

ngc5128Centaurus opened this issue Nov 17, 2020 · 0 comments

Comments

@ngc5128Centaurus
Copy link

Hi Guys,
This is not an issue, more a question.
I used your script to test updated Domain Controller and it works well. I also test it on unpatched DC.

On both case I have triggered 2 logs Event 5805 for each script launched.
Is it what is expected ?

Can i use event Log 5805 + my DC name appears in the message ("the from Computer") of the log to conclude to a Zerologon attack ?

Moreover i found a small difference between a patched and not patched:

  • In unpatched case the 2 event are the same.
  • In patched case in one of the event i got the attack computer in the message of the event (and not the DC)

My test with a patched result is:
2000 requests from the script resulting on 2000 packets TCP/port 135 + 2000 packets TCP/65xxx on Firewall (the RPC calls)
On the DC event log I can find 2 5805 events:

  • 2020-11-10T09:30:12.000Z MyDC1234.ADS.LOCAL AttkCp888 5805 The session setup from the computer AttkCp888
    failed to authenticate. The following error occurred: \r\nAccess is denied.
  • 2020-11-10T09:30:12.000Z MyDC1234.ADS.LOCAL mydc1234 5805 The session setup from the computer mydc1234 failed to authenticate. The following error occurred: \r\nAccess is denied.

Now when I take a non patched DC:
Success! DC can be fully compromised by a Zerologon attack.

  • 2020-11-10T09:42:23.000Z MyDC1234.ADS.LOCAL mydc1234 5805 The session setup from the computer mydc1234 failed to authenticate. The following error occurred: \r\nAccess is denied.
  • 2020-11-10T09:42:23.000Z MyDC1234.ADS.LOCAL mydc1234 5805 The session setup from the computer mydc1234 failed to authenticate. The following error occurred: \r\nAccess is denied.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant