mirror of
https://github.com/RedTeamPentesting/adauth
synced 2026-06-08 12:20:46 +00:00
Update linter and formatter config
This commit is contained in:
+35
-28
@@ -1,5 +1,16 @@
|
||||
version: "2"
|
||||
formatters:
|
||||
enable:
|
||||
- gci
|
||||
- gofmt
|
||||
- gofumpt
|
||||
- goimports
|
||||
- golines
|
||||
settings:
|
||||
golines:
|
||||
max-len: 120
|
||||
linters:
|
||||
disable-all: true
|
||||
default: none
|
||||
enable:
|
||||
- asasalint
|
||||
- asciicheck
|
||||
@@ -24,13 +35,10 @@ linters:
|
||||
- gocyclo
|
||||
- godot
|
||||
- godox
|
||||
- gofmt
|
||||
- goheader
|
||||
- goimports
|
||||
- gosec
|
||||
- gomodguard
|
||||
- goprintffuncname
|
||||
- gosimple
|
||||
- gosmopolitan
|
||||
- govet
|
||||
- grouper
|
||||
@@ -76,27 +84,26 @@ linters:
|
||||
- whitespace
|
||||
- wsl
|
||||
- zerologlint
|
||||
linters-settings:
|
||||
godox:
|
||||
keywords:
|
||||
- FIXME # FIXME generates a linter warning
|
||||
goconst:
|
||||
min-occurrences: 5
|
||||
tagliatelle:
|
||||
# check the struck tag name case
|
||||
case:
|
||||
rules:
|
||||
json: snake
|
||||
yaml: snake
|
||||
gosec:
|
||||
excludes:
|
||||
- G304 # command execution
|
||||
- G204 # file inclusion
|
||||
- G115 # integer overflow
|
||||
- G401 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G501 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G505 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G402 # InsecureSkipVerify may be true
|
||||
|
||||
issues:
|
||||
exclude-use-default: false
|
||||
settings:
|
||||
godox:
|
||||
keywords:
|
||||
- FIXME # FIXME generates a linter warning
|
||||
goconst:
|
||||
min-occurrences: 5
|
||||
tagliatelle:
|
||||
# check the struck tag name case
|
||||
case:
|
||||
rules:
|
||||
json: snake
|
||||
yaml: snake
|
||||
gosec:
|
||||
excludes:
|
||||
- G304 # command execution
|
||||
- G204 # file inclusion
|
||||
- G115 # integer overflow
|
||||
- G401 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G501 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G505 # weak cryptographic primitive (tell Microsoft, not me)
|
||||
- G402 # InsecureSkipVerify may be true
|
||||
gocyclo:
|
||||
min-complexity: 35
|
||||
|
||||
+1
-2
@@ -5,11 +5,10 @@ package compat
|
||||
import (
|
||||
"github.com/jcmturner/gokrb5/v8/config"
|
||||
"github.com/jcmturner/gokrb5/v8/credentials"
|
||||
"github.com/jcmturner/gokrb5/v8/types"
|
||||
gokrb5ForkConfig "github.com/oiweiwei/gokrb5.fork/v9/config"
|
||||
gokrb5ForkCredentials "github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
||||
gokrb5ForkTypes "github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||
|
||||
"github.com/jcmturner/gokrb5/v8/types"
|
||||
)
|
||||
|
||||
func Gokrb5ForkV9KerberosConfig(cfg *config.Config) *gokrb5ForkConfig.Config {
|
||||
|
||||
@@ -9,14 +9,13 @@ import (
|
||||
|
||||
"github.com/RedTeamPentesting/adauth"
|
||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||
|
||||
"github.com/oiweiwei/go-msrpc/dcerpc"
|
||||
"github.com/oiweiwei/go-msrpc/smb2"
|
||||
"github.com/oiweiwei/go-msrpc/ssp"
|
||||
"github.com/oiweiwei/go-msrpc/ssp/credential"
|
||||
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
||||
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||
)
|
||||
|
||||
// Options holds options that modify the behavior of the AuthenticationOptions
|
||||
|
||||
@@ -40,7 +40,12 @@ func AsContextDialer(d Dialer) ContextDialer {
|
||||
}
|
||||
|
||||
// SOCKS5Dialer returns a SOCKS5 dialer.
|
||||
func SOCKS5Dialer(network string, address string, auth *proxy.Auth, forward *net.Dialer) ContextDialer {
|
||||
func SOCKS5Dialer(
|
||||
network string,
|
||||
address string,
|
||||
auth *proxy.Auth,
|
||||
forward *net.Dialer,
|
||||
) ContextDialer {
|
||||
proxyDialer, err := proxy.SOCKS5(network, address, auth, forward)
|
||||
if err != nil {
|
||||
return nopContextDialer(func(s1, s2 string) (net.Conn, error) {
|
||||
|
||||
@@ -6,9 +6,8 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/RedTeamPentesting/adauth/smbauth"
|
||||
|
||||
"github.com/RedTeamPentesting/adauth"
|
||||
"github.com/RedTeamPentesting/adauth/smbauth"
|
||||
"github.com/spf13/pflag"
|
||||
)
|
||||
|
||||
|
||||
+10
-13
@@ -15,23 +15,19 @@ import (
|
||||
"github.com/RedTeamPentesting/adauth/compat"
|
||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||
"github.com/jcmturner/gokrb5/v8/config"
|
||||
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
||||
krb5Crypto "github.com/oiweiwei/gokrb5.fork/v9/crypto"
|
||||
krb5GSSAPI "github.com/oiweiwei/gokrb5.fork/v9/gssapi"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/chksumtype"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/keyusage"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/nametype"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/krberror"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||
|
||||
krb5GSSAPI "github.com/oiweiwei/gokrb5.fork/v9/gssapi"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/spnego"
|
||||
|
||||
krb5Crypto "github.com/oiweiwei/gokrb5.fork/v9/crypto"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/keyusage"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/messages"
|
||||
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/spnego"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||
)
|
||||
|
||||
type gssapiClient struct {
|
||||
@@ -97,7 +93,7 @@ func newPKINITClient(
|
||||
|
||||
// Close deletes any established secure context and closes the client.
|
||||
func (client *gssapiClient) Close() error {
|
||||
client.Client.Destroy()
|
||||
client.Destroy()
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -127,7 +123,7 @@ func (client *gssapiClient) getServiceTicket(target string) (tkt messages.Ticket
|
||||
return tkt, entry.Key, tkt.Unmarshal(entry.Ticket)
|
||||
}
|
||||
|
||||
return client.Client.GetServiceTicket(target)
|
||||
return client.GetServiceTicket(target)
|
||||
}
|
||||
|
||||
func (client *gssapiClient) newKRB5TokenAPREQ(
|
||||
@@ -320,7 +316,8 @@ func unmarshalWrapToken(wt *krb5GSSAPI.WrapToken, data []byte, expectFromAccepto
|
||||
|
||||
// Sanity check on the checksum length
|
||||
if int(checksumL) > len(data)-krb5GSSAPI.HdrLen {
|
||||
return fmt.Errorf("inconsistent checksum length: %d bytes to parse, checksum length is %d", len(data), checksumL)
|
||||
return fmt.Errorf("inconsistent checksum length: %d bytes to parse, checksum length is %d",
|
||||
len(data), checksumL)
|
||||
}
|
||||
|
||||
payloadStart := 16 + checksumL
|
||||
|
||||
+1
-2
@@ -23,14 +23,13 @@ import (
|
||||
"github.com/RedTeamPentesting/adauth/compat"
|
||||
"github.com/RedTeamPentesting/adauth/othername"
|
||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||
"software.sslmate.com/src/go-pkcs12"
|
||||
|
||||
"github.com/go-ldap/ldap/v3"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
||||
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||
"github.com/spf13/pflag"
|
||||
"software.sslmate.com/src/go-pkcs12"
|
||||
)
|
||||
|
||||
// Options holds LDAP specific options.
|
||||
|
||||
+2
-1
@@ -48,7 +48,8 @@ func (opts *Options) RegisterFlags(flagset *pflag.FlagSet) {
|
||||
ccacheHint = " (defaults to $KRB5CCNAME, currently unset)"
|
||||
}
|
||||
|
||||
flagset.StringVarP(&opts.User, "user", "u", "", "Username ('`user@domain`', 'domain\\user', 'domain/user' or 'user')")
|
||||
flagset.StringVarP(&opts.User, "user", "u", "",
|
||||
"Username ('`user@domain`', 'domain\\user', 'domain/user' or 'user')")
|
||||
flagset.StringVarP(&opts.Password, "password", "p", "", "Password")
|
||||
flagset.StringVarP(&opts.NTHash, "nt-hash", "H", "", "NT `hash` ('NT', ':NT' or 'LM:NT')")
|
||||
flagset.StringVar(&opts.AESKey, "aes-key", "", "Kerberos AES `hex key`")
|
||||
|
||||
@@ -104,7 +104,8 @@ func UnPACTheHash(
|
||||
|
||||
tgsReq, err := messages.NewUser2UserTGSReq(
|
||||
types.NewPrincipalName(nametype.KRB_NT_PRINCIPAL, user), strings.ToUpper(asRep.CRealm), krbConfig,
|
||||
asRep.Ticket, asRep.DecryptedEncPart.Key, types.NewPrincipalName(nametype.KRB_NT_UNKNOWN, user), false, asRep.Ticket)
|
||||
asRep.Ticket, asRep.DecryptedEncPart.Key, types.NewPrincipalName(nametype.KRB_NT_UNKNOWN, user),
|
||||
false, asRep.Ticket)
|
||||
if err != nil {
|
||||
return ccache, nil, fmt.Errorf("generate TGSReq: %w", err)
|
||||
}
|
||||
@@ -238,7 +239,9 @@ func generatePAData(
|
||||
|
||||
apb, err := apReq.Marshal()
|
||||
if err != nil {
|
||||
return paData, krberror.Errorf(err, krberror.EncodingError, "error marshaling AP_REQ for pre-authentication data")
|
||||
return paData, krberror.Errorf(err, krberror.EncodingError,
|
||||
"error marshaling AP_REQ for pre-authentication data",
|
||||
)
|
||||
}
|
||||
|
||||
return types.PADataSequence{types.PAData{
|
||||
|
||||
+2
-2
@@ -59,7 +59,7 @@ func (r *resolver) LookupFirstService(ctx context.Context, protocol string, doma
|
||||
func (r *resolver) LookupDCByDomain(ctx context.Context, domain string) (string, error) {
|
||||
// Unfortunately, Go does not implement SOA lookups, so we lookup the domain
|
||||
// for DC IPs and reverse lookup their hostnames instead.
|
||||
dcAddrs, err := r.Resolver.LookupIP(context.Background(), "ip", domain)
|
||||
dcAddrs, err := r.LookupIP(context.Background(), "ip", domain)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("lookup domain itself: %w", err)
|
||||
}
|
||||
@@ -70,7 +70,7 @@ func (r *resolver) LookupDCByDomain(ctx context.Context, domain string) (string,
|
||||
|
||||
dcAddr := dcAddrs[0].String()
|
||||
|
||||
names, err := r.Resolver.LookupAddr(context.Background(), dcAddr)
|
||||
names, err := r.LookupAddr(context.Background(), dcAddr)
|
||||
if err == nil {
|
||||
domain, names = splitResultsInDomainAndHostname(names, domain)
|
||||
|
||||
|
||||
+1
-3
@@ -6,13 +6,11 @@ import (
|
||||
|
||||
"github.com/RedTeamPentesting/adauth"
|
||||
"github.com/RedTeamPentesting/adauth/dcerpcauth"
|
||||
|
||||
"github.com/oiweiwei/go-smb2.fork"
|
||||
|
||||
msrpcSMB2 "github.com/oiweiwei/go-msrpc/smb2"
|
||||
"github.com/oiweiwei/go-msrpc/ssp"
|
||||
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
||||
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
||||
"github.com/oiweiwei/go-smb2.fork"
|
||||
)
|
||||
|
||||
// Options holds options that modify the behavior of the Dialer function.
|
||||
|
||||
Reference in New Issue
Block a user