Hide keyboard shortcuts

Hot-keys on this page

r m x p   toggle line displays

j k   next/prev highlighted chunk

0   (zero) top of page

1   (one) first highlighted chunk

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

37

38

39

40

41

42

43

44

45

46

47

48

49

50

51

52

53

54

55

56

57

58

59

60

61

62

63

64

65

66

67

68

69

70

71

72

73

74

75

76

77

78

79

80

81

82

83

84

85

86

87

88

89

90

91

92

93

94

95

96

97

98

99

100

101

102

103

104

105

106

107

108

109

110

111

112

113

114

115

116

117

118

119

120

121

122

123

124

125

126

127

128

129

130

131

132

133

134

135

136

137

138

139

140

141

142

143

144

145

146

147

148

149

150

151

152

153

154

155

156

157

158

159

160

161

162

163

164

165

166

167

168

169

170

171

172

173

174

175

176

177

178

179

180

181

182

183

184

185

186

187

188

189

190

191

192

193

194

195

196

197

198

199

200

201

202

203

204

205

206

207

208

209

210

211

212

213

214

215

216

217

218

219

220

221

222

223

224

225

226

227

228

229

230

231

232

233

234

235

236

237

238

239

240

241

242

243

244

245

246

247

248

249

250

251

252

253

254

255

256

257

258

259

260

261

262

263

264

265

266

267

268

269

270

271

272

273

274

275

276

277

278

279

280

281

282

283

284

285

286

287

288

289

290

291

292

293

294

295

296

297

298

299

300

301

302

303

304

305

306

307

308

309

310

311

312

313

314

315

316

317

318

319

320

321

322

323

324

325

326

327

328

329

330

331

332

333

334

335

336

337

338

339

340

341

342

343

344

345

346

347

348

349

350

351

352

353

354

355

356

357

358

359

360

361

362

363

364

365

366

367

368

369

370

371

372

373

374

375

376

377

378

379

380

381

382

383

384

385

386

387

388

389

390

391

392

393

394

395

396

397

398

399

400

401

402

403

404

405

406

407

408

409

410

411

412

413

414

415

416

417

418

419

420

421

422

423

424

425

426

427

428

429

430

431

432

433

434

435

436

437

438

439

440

441

442

443

444

445

446

447

448

449

450

451

452

453

454

455

456

457

458

459

460

461

462

463

464

465

466

467

468

469

470

471

472

473

474

475

476

477

478

479

480

# SECUREAUTH LABS. Copyright 2018 SecureAuth Corporation. All rights reserved. 

# 

# This software is provided under under a slightly modified version 

# of the Apache Software License. See the accompanying LICENSE file 

# for more information. 

# 

# Author: Alberto Solino (@agsolino) 

# 

# Description: 

# Transport implementations for the DCE/RPC protocol. 

# 

from __future__ import division 

from __future__ import print_function 

 

import binascii 

import os 

import re 

import socket 

 

from impacket import ntlm 

from impacket.dcerpc.v5.rpcrt import DCERPCException, DCERPC_v5, DCERPC_v4 

from impacket.smbconnection import SMBConnection 

 

 

class DCERPCStringBinding: 

parser = re.compile(r'(?:([a-fA-F0-9-]{8}(?:-[a-fA-F0-9-]{4}){3}-[a-fA-F0-9-]{12})@)?' # UUID (opt.) 

+'([_a-zA-Z0-9]*):' # Protocol Sequence 

+'([^\[]*)' # Network Address (opt.) 

+'(?:\[([^\]]*)\])?') # Endpoint and options (opt.) 

 

def __init__(self, stringbinding): 

match = DCERPCStringBinding.parser.match(stringbinding) 

self.__uuid = match.group(1) 

self.__ps = match.group(2) 

self.__na = match.group(3) 

options = match.group(4) 

if options: 

options = options.split(',') 

self.__endpoint = options[0] 

try: 

self.__endpoint.index('endpoint=') 

self.__endpoint = self.__endpoint[len('endpoint='):] 

except: 

pass 

self.__options = options[1:] 

else: 

self.__endpoint = '' 

self.__options = [] 

 

def get_uuid(self): 

return self.__uuid 

 

def get_protocol_sequence(self): 

return self.__ps 

 

def get_network_address(self): 

return self.__na 

 

def get_endpoint(self): 

return self.__endpoint 

 

def get_options(self): 

return self.__options 

 

def __str__(self): 

return DCERPCStringBindingCompose(self.__uuid, self.__ps, self.__na, self.__endpoint, self.__options) 

 

def DCERPCStringBindingCompose(uuid=None, protocol_sequence='', network_address='', endpoint='', options=[]): 

s = '' 

if uuid: 

s += uuid + '@' 

s += protocol_sequence + ':' 

if network_address: 

s += network_address 

if endpoint or options: 

s += '[' + endpoint 

if options: 

s += ',' + ','.join(options) 

s += ']' 

 

return s 

 

def DCERPCTransportFactory(stringbinding): 

sb = DCERPCStringBinding(stringbinding) 

 

na = sb.get_network_address() 

ps = sb.get_protocol_sequence() 

88 ↛ 89line 88 didn't jump to line 89, because the condition on line 88 was never true if 'ncadg_ip_udp' == ps: 

port = sb.get_endpoint() 

if port: 

return UDPTransport(na, int(port)) 

else: 

return UDPTransport(na) 

elif 'ncacn_ip_tcp' == ps: 

port = sb.get_endpoint() 

if port: 

return TCPTransport(na, int(port)) 

else: 

return TCPTransport(na) 

100 ↛ 101line 100 didn't jump to line 101, because the condition on line 100 was never true elif 'ncacn_http' == ps: 

port = sb.get_endpoint() 

if port: 

return HTTPTransport(na, int(port)) 

else: 

return HTTPTransport(na) 

106 ↛ 113line 106 didn't jump to line 113, because the condition on line 106 was never false elif 'ncacn_np' == ps: 

named_pipe = sb.get_endpoint() 

108 ↛ 112line 108 didn't jump to line 112, because the condition on line 108 was never false if named_pipe: 

named_pipe = named_pipe[len(r'\pipe'):] 

return SMBTransport(na, filename = named_pipe) 

else: 

return SMBTransport(na) 

elif 'ncalocal' == ps: 

named_pipe = sb.get_endpoint() 

return LOCALTransport(filename = named_pipe) 

else: 

raise DCERPCException("Unknown protocol sequence.") 

 

 

class DCERPCTransport: 

 

DCERPC_class = DCERPC_v5 

 

def __init__(self, remoteName, dstport): 

self.__remoteName = remoteName 

self.__remoteHost = remoteName 

self.__dstport = dstport 

self._max_send_frag = None 

self._max_recv_frag = None 

self._domain = '' 

self._lmhash = '' 

self._nthash = '' 

self.__connect_timeout = None 

self._doKerberos = False 

self._username = '' 

self._password = '' 

self._domain = '' 

self._aesKey = None 

self._TGT = None 

self._TGS = None 

self._kdcHost = None 

self.set_credentials('','') 

 

def connect(self): 

raise RuntimeError('virtual function') 

def send(self,data=0, forceWriteAndx = 0, forceRecv = 0): 

raise RuntimeError('virtual function') 

def recv(self, forceRecv = 0, count = 0): 

raise RuntimeError('virtual function') 

def disconnect(self): 

raise RuntimeError('virtual function') 

def get_socket(self): 

raise RuntimeError('virtual function') 

 

def get_connect_timeout(self): 

return self.__connect_timeout 

def set_connect_timeout(self, timeout): 

self.__connect_timeout = timeout 

 

def getRemoteName(self): 

return self.__remoteName 

 

def setRemoteName(self, remoteName): 

"""This method only makes sense before connection for most protocols.""" 

self.__remoteName = remoteName 

 

def getRemoteHost(self): 

return self.__remoteHost 

 

def setRemoteHost(self, remoteHost): 

"""This method only makes sense before connection for most protocols.""" 

self.__remoteHost = remoteHost 

 

def get_dport(self): 

return self.__dstport 

def set_dport(self, dport): 

"""This method only makes sense before connection for most protocols.""" 

self.__dstport = dport 

 

def get_addr(self): 

return self.getRemoteHost(), self.get_dport() 

def set_addr(self, addr): 

"""This method only makes sense before connection for most protocols.""" 

self.setRemoteHost(addr[0]) 

self.set_dport(addr[1]) 

 

def set_kerberos(self, flag, kdcHost = None): 

self._doKerberos = flag 

self._kdcHost = kdcHost 

 

def get_kerberos(self): 

return self._doKerberos 

 

def get_kdcHost(self): 

return self._kdcHost 

 

def set_max_fragment_size(self, send_fragment_size): 

# -1 is default fragment size: 0 (don't fragment) 

# 0 is don't fragment 

# other values are max fragment size 

201 ↛ 202line 201 didn't jump to line 202, because the condition on line 201 was never true if send_fragment_size == -1: 

self.set_default_max_fragment_size() 

else: 

self._max_send_frag = send_fragment_size 

 

def set_default_max_fragment_size(self): 

# default is 0: don't fragment. 

# subclasses may override this method 

self._max_send_frag = 0 

 

def get_credentials(self): 

return ( 

self._username, 

self._password, 

self._domain, 

self._lmhash, 

self._nthash, 

self._aesKey, 

self._TGT, 

self._TGS) 

 

def set_credentials(self, username, password, domain='', lmhash='', nthash='', aesKey='', TGT=None, TGS=None): 

self._username = username 

self._password = password 

self._domain = domain 

self._aesKey = aesKey 

self._TGT = TGT 

self._TGS = TGS 

if lmhash != '' or nthash != '': 

230 ↛ 231line 230 didn't jump to line 231, because the condition on line 230 was never true if len(lmhash) % 2: 

lmhash = '0%s' % lmhash 

232 ↛ 233line 232 didn't jump to line 233, because the condition on line 232 was never true if len(nthash) % 2: 

nthash = '0%s' % nthash 

try: # just in case they were converted already 

self._lmhash = binascii.unhexlify(lmhash) 

self._nthash = binascii.unhexlify(nthash) 

except: 

self._lmhash = lmhash 

self._nthash = nthash 

pass 

 

def doesSupportNTLMv2(self): 

# By default we'll be returning the library's default. Only on SMB Transports we might be able to know it beforehand 

return ntlm.USE_NTLMv2 

 

def get_dce_rpc(self): 

return DCERPC_v5(self) 

 

class UDPTransport(DCERPCTransport): 

"Implementation of ncadg_ip_udp protocol sequence" 

 

DCERPC_class = DCERPC_v4 

 

def __init__(self, remoteName, dstport = 135): 

DCERPCTransport.__init__(self, remoteName, dstport) 

self.__socket = 0 

self.set_connect_timeout(30) 

self.__recv_addr = '' 

 

def connect(self): 

try: 

af, socktype, proto, canonname, sa = socket.getaddrinfo(self.getRemoteHost(), self.get_dport(), 0, socket.SOCK_DGRAM)[0] 

self.__socket = socket.socket(af, socktype, proto) 

self.__socket.settimeout(self.get_connect_timeout()) 

except socket.error as msg: 

self.__socket = None 

raise DCERPCException("Could not connect: %s" % msg) 

 

return 1 

 

def disconnect(self): 

try: 

self.__socket.close() 

except socket.error: 

self.__socket = None 

return 0 

return 1 

 

def send(self,data, forceWriteAndx = 0, forceRecv = 0): 

self.__socket.sendto(data, (self.getRemoteHost(), self.get_dport())) 

 

def recv(self, forceRecv = 0, count = 0): 

buffer, self.__recv_addr = self.__socket.recvfrom(8192) 

return buffer 

 

def get_recv_addr(self): 

return self.__recv_addr 

 

def get_socket(self): 

return self.__socket 

 

class TCPTransport(DCERPCTransport): 

"""Implementation of ncacn_ip_tcp protocol sequence""" 

 

def __init__(self, remoteName, dstport = 135): 

DCERPCTransport.__init__(self, remoteName, dstport) 

self.__socket = 0 

self.set_connect_timeout(30) 

 

def connect(self): 

af, socktype, proto, canonname, sa = socket.getaddrinfo(self.getRemoteHost(), self.get_dport(), 0, socket.SOCK_STREAM)[0] 

self.__socket = socket.socket(af, socktype, proto) 

try: 

self.__socket.settimeout(self.get_connect_timeout()) 

self.__socket.connect(sa) 

except socket.error as msg: 

self.__socket.close() 

raise DCERPCException("Could not connect: %s" % msg) 

return 1 

 

def disconnect(self): 

try: 

self.__socket.close() 

except socket.error: 

self.__socket = None 

return 0 

return 1 

 

def send(self,data, forceWriteAndx = 0, forceRecv = 0): 

if self._max_send_frag: 

offset = 0 

while 1: 

toSend = data[offset:offset+self._max_send_frag] 

if not toSend: 

break 

self.__socket.send(toSend) 

offset += len(toSend) 

else: 

self.__socket.send(data) 

 

def recv(self, forceRecv = 0, count = 0): 

if count: 

buffer = b'' 

while len(buffer) < count: 

buffer += self.__socket.recv(count-len(buffer)) 

else: 

buffer = self.__socket.recv(8192) 

return buffer 

 

def get_socket(self): 

return self.__socket 

 

class HTTPTransport(TCPTransport): 

"""Implementation of ncacn_http protocol sequence""" 

 

def connect(self): 

TCPTransport.connect(self) 

 

self.get_socket().send('RPC_CONNECT ' + self.getRemoteHost() + ':593 HTTP/1.0\r\n\r\n') 

data = self.get_socket().recv(8192) 

if data[10:13] != '200': 

raise DCERPCException("Service not supported.") 

 

class SMBTransport(DCERPCTransport): 

"""Implementation of ncacn_np protocol sequence""" 

 

def __init__(self, remoteName, dstport=445, filename='', username='', password='', domain='', lmhash='', nthash='', 

aesKey='', TGT=None, TGS=None, remote_host='', smb_connection=0, doKerberos=False, kdcHost=None): 

DCERPCTransport.__init__(self, remoteName, dstport) 

self.__socket = None 

self.__tid = 0 

self.__filename = filename 

self.__handle = 0 

self.__pending_recv = 0 

self.set_credentials(username, password, domain, lmhash, nthash, aesKey, TGT, TGS) 

self._doKerberos = doKerberos 

self._kdcHost = kdcHost 

 

369 ↛ 370line 369 didn't jump to line 370, because the condition on line 369 was never true if remote_host != '': 

self.setRemoteHost(remote_host) 

 

if smb_connection == 0: 

self.__existing_smb = False 

else: 

self.__existing_smb = True 

self.set_credentials(*smb_connection.getCredentials()) 

 

self.__prefDialect = None 

self.__smb_connection = smb_connection 

 

def preferred_dialect(self, dialect): 

self.__prefDialect = dialect 

 

def setup_smb_connection(self): 

385 ↛ exitline 385 didn't return from function 'setup_smb_connection', because the condition on line 385 was never false if not self.__smb_connection: 

self.__smb_connection = SMBConnection(self.getRemoteName(), self.getRemoteHost(), sess_port=self.get_dport(), 

preferredDialect=self.__prefDialect) 

 

def connect(self): 

# Check if we have a smb connection already setup 

if self.__smb_connection == 0: 

self.setup_smb_connection() 

if self._doKerberos is False: 

self.__smb_connection.login(self._username, self._password, self._domain, self._lmhash, self._nthash) 

else: 

self.__smb_connection.kerberosLogin(self._username, self._password, self._domain, self._lmhash, 

self._nthash, self._aesKey, kdcHost=self._kdcHost, TGT=self._TGT, 

TGS=self._TGS) 

self.__tid = self.__smb_connection.connectTree('IPC$') 

self.__handle = self.__smb_connection.openFile(self.__tid, self.__filename) 

self.__socket = self.__smb_connection.getSMBServer().get_socket() 

return 1 

 

def disconnect(self): 

self.__smb_connection.disconnectTree(self.__tid) 

# If we created the SMB connection, we close it, otherwise 

# that's up for the caller 

if self.__existing_smb is False: 

self.__smb_connection.logoff() 

self.__smb_connection.close() 

self.__smb_connection = 0 

 

def send(self,data, forceWriteAndx = 0, forceRecv = 0): 

if self._max_send_frag: 

offset = 0 

while 1: 

toSend = data[offset:offset+self._max_send_frag] 

if not toSend: 

break 

self.__smb_connection.writeFile(self.__tid, self.__handle, toSend, offset = offset) 

offset += len(toSend) 

else: 

self.__smb_connection.writeFile(self.__tid, self.__handle, data) 

if forceRecv: 

self.__pending_recv += 1 

 

def recv(self, forceRecv = 0, count = 0 ): 

if self._max_send_frag or self.__pending_recv: 

# _max_send_frag is checked because it's the same condition we checked 

# to decide whether to use write_andx() or send_trans() in send() above. 

if self.__pending_recv: 

self.__pending_recv -= 1 

return self.__smb_connection.readFile(self.__tid, self.__handle, bytesToRead = self._max_recv_frag) 

else: 

return self.__smb_connection.readFile(self.__tid, self.__handle) 

 

def get_smb_connection(self): 

return self.__smb_connection 

 

def set_smb_connection(self, smb_connection): 

self.__smb_connection = smb_connection 

self.set_credentials(*smb_connection.getCredentials()) 

self.__existing_smb = True 

 

def get_smb_server(self): 

# Raw Access to the SMBServer (whatever type it is) 

return self.__smb_connection.getSMBServer() 

 

def get_socket(self): 

return self.__socket 

 

def doesSupportNTLMv2(self): 

return self.__smb_connection.doesSupportNTLMv2() 

 

class LOCALTransport(DCERPCTransport): 

""" 

Implementation of ncalocal protocol sequence, not the same 

as ncalrpc (I'm not doing LPC just opening the local pipe) 

""" 

 

def __init__(self, filename = ''): 

DCERPCTransport.__init__(self, '', 0) 

self.__filename = filename 

self.__handle = 0 

 

def connect(self): 

if self.__filename.upper().find('PIPE') < 0: 

self.__filename = '\\PIPE\\%s' % self.__filename 

self.__handle = os.open('\\\\.\\%s' % self.__filename, os.O_RDWR|os.O_BINARY) 

return 1 

 

def disconnect(self): 

os.close(self.__handle) 

 

def send(self,data, forceWriteAndx = 0, forceRecv = 0): 

os.write(self.__handle, data) 

 

def recv(self, forceRecv = 0, count = 0 ): 

data = os.read(self.__handle, 65535) 

return data