Skip to content

Fix compatibility with rubyntlm 0.6.8 - #305

Merged
jheysel-r7 merged 1 commit into
rapid7:masterfrom
cdelafuente-r7:fix/rubyntlm_upgrades
Sep 28, 2026
Merged

jheysel-r7 merged 1 commit into
rapid7:masterfrom
cdelafuente-r7:fix/rubyntlm_upgrades

Conversation

@cdelafuente-r7

Copy link
Copy Markdown
Contributor

This PR fixes compatibility with rubyntlm 0.6.8, whose target-info parser rejects empty strings. Server challenges now initialize target info with nil, and clients ignore absent or empty target-info buffers while continuing to reject malformed nonempty data.

The session specs now use actual credentials and validate authentication results, avoiding mocks of is_anonymous? that no longer intercept the gem’s internal calls. Regression coverage includes SMB1, SMB2, DCE/RPC, and serialized server target info.

Initialize server target info with nil and ignore empty client target-info
buffers while preserving validation of malformed nonempty data.

Update session specs to use real credentials instead of mocking
`is_anonymous?`, and add regression coverage for SMB1, SMB2, and DCE/RPC.

@jheysel-r7 jheysel-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @cdelafuente-r7, looks great!

@jheysel-r7
jheysel-r7 merged commit b91e18a into rapid7:master Sep 28, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants