Skip to content

Release 2.14.213.78.21.9: bounded PPTP control check - #84

Draft
netanelcyber wants to merge 1 commit into
release/pypi-2.14.213.78.21.8from
codex/smbv1-inventory-2.14.213.78.21.5
Draft

netanelcyber wants to merge 1 commit into
release/pypi-2.14.213.78.21.8from
codex/smbv1-inventory-2.14.213.78.21.5

Conversation

@netanelcyber

@netanelcyber netanelcyber commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Adds an explicit --pptp-check / pptp_control diagnostic for one PPTP Start-Control-Connection exchange on TCP/1723. The Python standard-library worker uses one pinned endpoint and one total deadline, validates a bounded reply, records accepted/rejected result codes and server metadata, and closes its newly opened control connection.

Results, including refusals, timeouts, malformed replies, blocked attempts and dry runs, are saved in domain-linked ORM history and the information report. Authentication, GRE/IP protocol 47 and VPN tunnel connectivity remain explicitly untested. Control acceptance creates a manual configuration-review finding, not a confirmed vulnerability. No runtime dependency is added.

Validation: 755 tests and 271 subtests passed from source and the built sdist; strict Twine checks, complete Git/archive comparisons and an isolated installed-wheel smoke check passed. Python 3.12 CI passed on Ubuntu 24.04, Ubuntu 26.04 and Windows: https://github.com/netanelcyber/AdPentestAI-Python/actions/runs/37766539724 and https://github.com/netanelcyber/AdPentestAI-Python/actions/runs/37766545250. Tests use synthetic protocol packets and mocked sockets; no remote PPTP target was used.

Release commit: dc9ffeb84285298f42da488ee9c2a5c90a31b697; tree: 9f7fb3d0128fa1eda7e8d180985e48a5201ef758. The release branch release/pypi-2.14.213.78.21.9 points to this exact commit. The authorized publish workflow and release CI both passed: https://github.com/netanelcyber/AdPentestAI-Python/actions/runs/37767010996 and https://github.com/netanelcyber/AdPentestAI-Python/actions/runs/37767010899. The Python 3.10 release matrix passed 755 tests and 271 subtests on all three operating systems.

Published to https://pypi.org/project/adpentest/2.14.213.78.21.9/ on 2026-10-08 at 11:00 UTC. Independently downloaded both PyPI artifacts: all 14 package files and 40 authored sdist files match Git; wheel RECORD, metadata, entry point, strict Twine checks, isolated wheel installation, and isolated sdist build/installation passed. All 20 wheel file payloads and 48 sdist file payloads match the locally verified build. Archive timestamp and tar owner differences are understood; no unexplained source/package differences remain.

Published SHA-256:

  • Wheel: c7202f91584cc2c9a23ee32cb8789a3f1b30632313ebb0ab122122be37d92f7b
  • sdist: 1208eff2d5c7aba832311093919b6eb2b65858563e5aca5bc4ed5687b010c92a

Compared with published .8, the package changes are the new PPTP worker and diagnostic/report integration plus version declarations. Domain ORM, DNS/XML history, required Impacket, SMBv1 inventory/access and existing diagnostic selections are preserved. This PR remains a draft and now compares the .9 change against the published .8 branch.

@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.5: SMBv1 host, user and UNC export inventory Release 2.14.213.78.21.5: SMBv1 XML/JSON inventory, ORM tables and verbose Nmap Oct 6, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.5: SMBv1 XML/JSON inventory, ORM tables and verbose Nmap Release 2.14.213.78.21.6: SMBv1 XML/JSON inventory, ORM tables and verbose Nmap Oct 6, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.6: SMBv1 XML/JSON inventory, ORM tables and verbose Nmap Release 2.14.213.78.21.6: DNS/FQDN targets, XML inventory and ORM relations Oct 7, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.6: DNS/FQDN targets, XML inventory and ORM relations Release 2.14.213.78.21.6: DNS/ORM inventory, required SMB and VPN port checks Oct 7, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.6: DNS/ORM inventory, required SMB and VPN port checks Release 2.14.213.78.21.6: required SMB, VPN inventory and metadata reports Oct 7, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.6: required SMB, VPN inventory and metadata reports Release 2.14.213.78.21.7: domain ORM and verified package contents Oct 7, 2026
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.7: domain ORM and verified package contents Prepare 2.14.213.78.21.8: domain ORM and metadata reports Oct 8, 2026
@netanelcyber netanelcyber changed the title Prepare 2.14.213.78.21.8: domain ORM and metadata reports Release 2.14.213.78.21.8: domain ORM and metadata reports Oct 8, 2026
Add an explicit TCP/1723 protocol check with a pinned endpoint, a shared deadline, reply evidence, cleanup and domain-linked ORM/report results. Leave authentication, GRE and VPN tunnel connectivity untested.

Validation: 755 tests and 271 subtests, strict package checks, Git/archive equality and isolated installed-wheel smoke checks.
@netanelcyber netanelcyber changed the title Release 2.14.213.78.21.8: domain ORM and metadata reports Release 2.14.213.78.21.9: bounded PPTP control check Oct 8, 2026
@netanelcyber
netanelcyber changed the base branch from release/pypi-2.14.213.78.21.4 to release/pypi-2.14.213.78.21.8 October 8, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant