Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

easy_win: false positives in brute force when null session is enabled #2

Open
sowdust opened this issue Aug 16, 2018 · 0 comments
Open

Comments

@sowdust
Copy link

sowdust commented Aug 16, 2018

When brute forcing a share with null session enabled, the tool attempts to login and then enumerate the shares:

  • in case of a valid user name and a wrong password, this results in an error (hence the possibility of enumerating users this way)
  • in case of an invalid username, the shares might be provided, and the tool will mark the non-existing user and the password used as valid credentials.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant