mirror of
https://github.com/RedTeamPentesting/adauth
synced 2026-06-08 12:20:46 +00:00
Update linter and formatter config
This commit is contained in:
+35
-28
@@ -1,5 +1,16 @@
|
|||||||
|
version: "2"
|
||||||
|
formatters:
|
||||||
|
enable:
|
||||||
|
- gci
|
||||||
|
- gofmt
|
||||||
|
- gofumpt
|
||||||
|
- goimports
|
||||||
|
- golines
|
||||||
|
settings:
|
||||||
|
golines:
|
||||||
|
max-len: 120
|
||||||
linters:
|
linters:
|
||||||
disable-all: true
|
default: none
|
||||||
enable:
|
enable:
|
||||||
- asasalint
|
- asasalint
|
||||||
- asciicheck
|
- asciicheck
|
||||||
@@ -24,13 +35,10 @@ linters:
|
|||||||
- gocyclo
|
- gocyclo
|
||||||
- godot
|
- godot
|
||||||
- godox
|
- godox
|
||||||
- gofmt
|
|
||||||
- goheader
|
- goheader
|
||||||
- goimports
|
|
||||||
- gosec
|
- gosec
|
||||||
- gomodguard
|
- gomodguard
|
||||||
- goprintffuncname
|
- goprintffuncname
|
||||||
- gosimple
|
|
||||||
- gosmopolitan
|
- gosmopolitan
|
||||||
- govet
|
- govet
|
||||||
- grouper
|
- grouper
|
||||||
@@ -76,27 +84,26 @@ linters:
|
|||||||
- whitespace
|
- whitespace
|
||||||
- wsl
|
- wsl
|
||||||
- zerologlint
|
- zerologlint
|
||||||
linters-settings:
|
settings:
|
||||||
godox:
|
godox:
|
||||||
keywords:
|
keywords:
|
||||||
- FIXME # FIXME generates a linter warning
|
- FIXME # FIXME generates a linter warning
|
||||||
goconst:
|
goconst:
|
||||||
min-occurrences: 5
|
min-occurrences: 5
|
||||||
tagliatelle:
|
tagliatelle:
|
||||||
# check the struck tag name case
|
# check the struck tag name case
|
||||||
case:
|
case:
|
||||||
rules:
|
rules:
|
||||||
json: snake
|
json: snake
|
||||||
yaml: snake
|
yaml: snake
|
||||||
gosec:
|
gosec:
|
||||||
excludes:
|
excludes:
|
||||||
- G304 # command execution
|
- G304 # command execution
|
||||||
- G204 # file inclusion
|
- G204 # file inclusion
|
||||||
- G115 # integer overflow
|
- G115 # integer overflow
|
||||||
- G401 # weak cryptographic primitive (tell Microsoft, not me)
|
- G401 # weak cryptographic primitive (tell Microsoft, not me)
|
||||||
- G501 # weak cryptographic primitive (tell Microsoft, not me)
|
- G501 # weak cryptographic primitive (tell Microsoft, not me)
|
||||||
- G505 # weak cryptographic primitive (tell Microsoft, not me)
|
- G505 # weak cryptographic primitive (tell Microsoft, not me)
|
||||||
- G402 # InsecureSkipVerify may be true
|
- G402 # InsecureSkipVerify may be true
|
||||||
|
gocyclo:
|
||||||
issues:
|
min-complexity: 35
|
||||||
exclude-use-default: false
|
|
||||||
|
|||||||
+1
-2
@@ -5,11 +5,10 @@ package compat
|
|||||||
import (
|
import (
|
||||||
"github.com/jcmturner/gokrb5/v8/config"
|
"github.com/jcmturner/gokrb5/v8/config"
|
||||||
"github.com/jcmturner/gokrb5/v8/credentials"
|
"github.com/jcmturner/gokrb5/v8/credentials"
|
||||||
|
"github.com/jcmturner/gokrb5/v8/types"
|
||||||
gokrb5ForkConfig "github.com/oiweiwei/gokrb5.fork/v9/config"
|
gokrb5ForkConfig "github.com/oiweiwei/gokrb5.fork/v9/config"
|
||||||
gokrb5ForkCredentials "github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
gokrb5ForkCredentials "github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
||||||
gokrb5ForkTypes "github.com/oiweiwei/gokrb5.fork/v9/types"
|
gokrb5ForkTypes "github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||||
|
|
||||||
"github.com/jcmturner/gokrb5/v8/types"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func Gokrb5ForkV9KerberosConfig(cfg *config.Config) *gokrb5ForkConfig.Config {
|
func Gokrb5ForkV9KerberosConfig(cfg *config.Config) *gokrb5ForkConfig.Config {
|
||||||
|
|||||||
@@ -9,14 +9,13 @@ import (
|
|||||||
|
|
||||||
"github.com/RedTeamPentesting/adauth"
|
"github.com/RedTeamPentesting/adauth"
|
||||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
|
||||||
|
|
||||||
"github.com/oiweiwei/go-msrpc/dcerpc"
|
"github.com/oiweiwei/go-msrpc/dcerpc"
|
||||||
"github.com/oiweiwei/go-msrpc/smb2"
|
"github.com/oiweiwei/go-msrpc/smb2"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp"
|
"github.com/oiweiwei/go-msrpc/ssp"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp/credential"
|
"github.com/oiweiwei/go-msrpc/ssp/credential"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
||||||
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Options holds options that modify the behavior of the AuthenticationOptions
|
// Options holds options that modify the behavior of the AuthenticationOptions
|
||||||
|
|||||||
@@ -40,7 +40,12 @@ func AsContextDialer(d Dialer) ContextDialer {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// SOCKS5Dialer returns a SOCKS5 dialer.
|
// SOCKS5Dialer returns a SOCKS5 dialer.
|
||||||
func SOCKS5Dialer(network string, address string, auth *proxy.Auth, forward *net.Dialer) ContextDialer {
|
func SOCKS5Dialer(
|
||||||
|
network string,
|
||||||
|
address string,
|
||||||
|
auth *proxy.Auth,
|
||||||
|
forward *net.Dialer,
|
||||||
|
) ContextDialer {
|
||||||
proxyDialer, err := proxy.SOCKS5(network, address, auth, forward)
|
proxyDialer, err := proxy.SOCKS5(network, address, auth, forward)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nopContextDialer(func(s1, s2 string) (net.Conn, error) {
|
return nopContextDialer(func(s1, s2 string) (net.Conn, error) {
|
||||||
|
|||||||
@@ -6,9 +6,8 @@ import (
|
|||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
|
||||||
"github.com/RedTeamPentesting/adauth/smbauth"
|
|
||||||
|
|
||||||
"github.com/RedTeamPentesting/adauth"
|
"github.com/RedTeamPentesting/adauth"
|
||||||
|
"github.com/RedTeamPentesting/adauth/smbauth"
|
||||||
"github.com/spf13/pflag"
|
"github.com/spf13/pflag"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
+10
-13
@@ -15,23 +15,19 @@ import (
|
|||||||
"github.com/RedTeamPentesting/adauth/compat"
|
"github.com/RedTeamPentesting/adauth/compat"
|
||||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||||
"github.com/jcmturner/gokrb5/v8/config"
|
"github.com/jcmturner/gokrb5/v8/config"
|
||||||
|
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
||||||
|
"github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
||||||
|
krb5Crypto "github.com/oiweiwei/gokrb5.fork/v9/crypto"
|
||||||
|
krb5GSSAPI "github.com/oiweiwei/gokrb5.fork/v9/gssapi"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/chksumtype"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/chksumtype"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
||||||
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/keyusage"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/nametype"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/nametype"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/krberror"
|
"github.com/oiweiwei/gokrb5.fork/v9/krberror"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
|
||||||
|
|
||||||
krb5GSSAPI "github.com/oiweiwei/gokrb5.fork/v9/gssapi"
|
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/spnego"
|
|
||||||
|
|
||||||
krb5Crypto "github.com/oiweiwei/gokrb5.fork/v9/crypto"
|
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/keyusage"
|
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/messages"
|
"github.com/oiweiwei/gokrb5.fork/v9/messages"
|
||||||
|
"github.com/oiweiwei/gokrb5.fork/v9/spnego"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/credentials"
|
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||||
)
|
)
|
||||||
|
|
||||||
type gssapiClient struct {
|
type gssapiClient struct {
|
||||||
@@ -97,7 +93,7 @@ func newPKINITClient(
|
|||||||
|
|
||||||
// Close deletes any established secure context and closes the client.
|
// Close deletes any established secure context and closes the client.
|
||||||
func (client *gssapiClient) Close() error {
|
func (client *gssapiClient) Close() error {
|
||||||
client.Client.Destroy()
|
client.Destroy()
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
@@ -127,7 +123,7 @@ func (client *gssapiClient) getServiceTicket(target string) (tkt messages.Ticket
|
|||||||
return tkt, entry.Key, tkt.Unmarshal(entry.Ticket)
|
return tkt, entry.Key, tkt.Unmarshal(entry.Ticket)
|
||||||
}
|
}
|
||||||
|
|
||||||
return client.Client.GetServiceTicket(target)
|
return client.GetServiceTicket(target)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (client *gssapiClient) newKRB5TokenAPREQ(
|
func (client *gssapiClient) newKRB5TokenAPREQ(
|
||||||
@@ -320,7 +316,8 @@ func unmarshalWrapToken(wt *krb5GSSAPI.WrapToken, data []byte, expectFromAccepto
|
|||||||
|
|
||||||
// Sanity check on the checksum length
|
// Sanity check on the checksum length
|
||||||
if int(checksumL) > len(data)-krb5GSSAPI.HdrLen {
|
if int(checksumL) > len(data)-krb5GSSAPI.HdrLen {
|
||||||
return fmt.Errorf("inconsistent checksum length: %d bytes to parse, checksum length is %d", len(data), checksumL)
|
return fmt.Errorf("inconsistent checksum length: %d bytes to parse, checksum length is %d",
|
||||||
|
len(data), checksumL)
|
||||||
}
|
}
|
||||||
|
|
||||||
payloadStart := 16 + checksumL
|
payloadStart := 16 + checksumL
|
||||||
|
|||||||
+1
-2
@@ -23,14 +23,13 @@ import (
|
|||||||
"github.com/RedTeamPentesting/adauth/compat"
|
"github.com/RedTeamPentesting/adauth/compat"
|
||||||
"github.com/RedTeamPentesting/adauth/othername"
|
"github.com/RedTeamPentesting/adauth/othername"
|
||||||
"github.com/RedTeamPentesting/adauth/pkinit"
|
"github.com/RedTeamPentesting/adauth/pkinit"
|
||||||
"software.sslmate.com/src/go-pkcs12"
|
|
||||||
|
|
||||||
"github.com/go-ldap/ldap/v3"
|
"github.com/go-ldap/ldap/v3"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
"github.com/oiweiwei/gokrb5.fork/v9/client"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/etypeID"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
"github.com/oiweiwei/gokrb5.fork/v9/iana/flags"
|
||||||
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
"github.com/oiweiwei/gokrb5.fork/v9/types"
|
||||||
"github.com/spf13/pflag"
|
"github.com/spf13/pflag"
|
||||||
|
"software.sslmate.com/src/go-pkcs12"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Options holds LDAP specific options.
|
// Options holds LDAP specific options.
|
||||||
|
|||||||
+2
-1
@@ -48,7 +48,8 @@ func (opts *Options) RegisterFlags(flagset *pflag.FlagSet) {
|
|||||||
ccacheHint = " (defaults to $KRB5CCNAME, currently unset)"
|
ccacheHint = " (defaults to $KRB5CCNAME, currently unset)"
|
||||||
}
|
}
|
||||||
|
|
||||||
flagset.StringVarP(&opts.User, "user", "u", "", "Username ('`user@domain`', 'domain\\user', 'domain/user' or 'user')")
|
flagset.StringVarP(&opts.User, "user", "u", "",
|
||||||
|
"Username ('`user@domain`', 'domain\\user', 'domain/user' or 'user')")
|
||||||
flagset.StringVarP(&opts.Password, "password", "p", "", "Password")
|
flagset.StringVarP(&opts.Password, "password", "p", "", "Password")
|
||||||
flagset.StringVarP(&opts.NTHash, "nt-hash", "H", "", "NT `hash` ('NT', ':NT' or 'LM:NT')")
|
flagset.StringVarP(&opts.NTHash, "nt-hash", "H", "", "NT `hash` ('NT', ':NT' or 'LM:NT')")
|
||||||
flagset.StringVar(&opts.AESKey, "aes-key", "", "Kerberos AES `hex key`")
|
flagset.StringVar(&opts.AESKey, "aes-key", "", "Kerberos AES `hex key`")
|
||||||
|
|||||||
@@ -104,7 +104,8 @@ func UnPACTheHash(
|
|||||||
|
|
||||||
tgsReq, err := messages.NewUser2UserTGSReq(
|
tgsReq, err := messages.NewUser2UserTGSReq(
|
||||||
types.NewPrincipalName(nametype.KRB_NT_PRINCIPAL, user), strings.ToUpper(asRep.CRealm), krbConfig,
|
types.NewPrincipalName(nametype.KRB_NT_PRINCIPAL, user), strings.ToUpper(asRep.CRealm), krbConfig,
|
||||||
asRep.Ticket, asRep.DecryptedEncPart.Key, types.NewPrincipalName(nametype.KRB_NT_UNKNOWN, user), false, asRep.Ticket)
|
asRep.Ticket, asRep.DecryptedEncPart.Key, types.NewPrincipalName(nametype.KRB_NT_UNKNOWN, user),
|
||||||
|
false, asRep.Ticket)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return ccache, nil, fmt.Errorf("generate TGSReq: %w", err)
|
return ccache, nil, fmt.Errorf("generate TGSReq: %w", err)
|
||||||
}
|
}
|
||||||
@@ -238,7 +239,9 @@ func generatePAData(
|
|||||||
|
|
||||||
apb, err := apReq.Marshal()
|
apb, err := apReq.Marshal()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return paData, krberror.Errorf(err, krberror.EncodingError, "error marshaling AP_REQ for pre-authentication data")
|
return paData, krberror.Errorf(err, krberror.EncodingError,
|
||||||
|
"error marshaling AP_REQ for pre-authentication data",
|
||||||
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
return types.PADataSequence{types.PAData{
|
return types.PADataSequence{types.PAData{
|
||||||
|
|||||||
+2
-2
@@ -59,7 +59,7 @@ func (r *resolver) LookupFirstService(ctx context.Context, protocol string, doma
|
|||||||
func (r *resolver) LookupDCByDomain(ctx context.Context, domain string) (string, error) {
|
func (r *resolver) LookupDCByDomain(ctx context.Context, domain string) (string, error) {
|
||||||
// Unfortunately, Go does not implement SOA lookups, so we lookup the domain
|
// Unfortunately, Go does not implement SOA lookups, so we lookup the domain
|
||||||
// for DC IPs and reverse lookup their hostnames instead.
|
// for DC IPs and reverse lookup their hostnames instead.
|
||||||
dcAddrs, err := r.Resolver.LookupIP(context.Background(), "ip", domain)
|
dcAddrs, err := r.LookupIP(context.Background(), "ip", domain)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", fmt.Errorf("lookup domain itself: %w", err)
|
return "", fmt.Errorf("lookup domain itself: %w", err)
|
||||||
}
|
}
|
||||||
@@ -70,7 +70,7 @@ func (r *resolver) LookupDCByDomain(ctx context.Context, domain string) (string,
|
|||||||
|
|
||||||
dcAddr := dcAddrs[0].String()
|
dcAddr := dcAddrs[0].String()
|
||||||
|
|
||||||
names, err := r.Resolver.LookupAddr(context.Background(), dcAddr)
|
names, err := r.LookupAddr(context.Background(), dcAddr)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
domain, names = splitResultsInDomainAndHostname(names, domain)
|
domain, names = splitResultsInDomainAndHostname(names, domain)
|
||||||
|
|
||||||
|
|||||||
+1
-3
@@ -6,13 +6,11 @@ import (
|
|||||||
|
|
||||||
"github.com/RedTeamPentesting/adauth"
|
"github.com/RedTeamPentesting/adauth"
|
||||||
"github.com/RedTeamPentesting/adauth/dcerpcauth"
|
"github.com/RedTeamPentesting/adauth/dcerpcauth"
|
||||||
|
|
||||||
"github.com/oiweiwei/go-smb2.fork"
|
|
||||||
|
|
||||||
msrpcSMB2 "github.com/oiweiwei/go-msrpc/smb2"
|
msrpcSMB2 "github.com/oiweiwei/go-msrpc/smb2"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp"
|
"github.com/oiweiwei/go-msrpc/ssp"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
|
||||||
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
"github.com/oiweiwei/go-msrpc/ssp/krb5"
|
||||||
|
"github.com/oiweiwei/go-smb2.fork"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Options holds options that modify the behavior of the Dialer function.
|
// Options holds options that modify the behavior of the Dialer function.
|
||||||
|
|||||||
Reference in New Issue
Block a user