Description
This is an exploit for Squid\'s NTLM authenticate overflow (libntlmssp.c). Due to improper bounds checking in ntlm_check_auth, it is possible to overflow the 'pass' variable on the stack with user controlled data of a user defined length. Props to iDEFENSE for the advisory.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/proxy/squid/ntlm_authenticatemsf undefined(ntlm_authenticate) > show actions ...actions...msf undefined(ntlm_authenticate) > set ACTION < action-name >msf undefined(ntlm_authenticate) > show options ...show and set options...msf undefined(ntlm_authenticate) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub