mirror of
https://github.com/cisagov/snafflepy
synced 2026-09-24 18:22:23 +00:00
initial idea of solution
This commit is contained in:
@@ -51,7 +51,7 @@ def begin_snaffle(options):
|
|||||||
for target in options.targets:
|
for target in options.targets:
|
||||||
|
|
||||||
smb_client = SMBClient(
|
smb_client = SMBClient(
|
||||||
target, options.username, options.password, options.domain, options.hash)
|
target, options.username, options.password, options.domain, options.hash, options.shares)
|
||||||
if not smb_client.login():
|
if not smb_client.login():
|
||||||
log.error(f"Unable to login to{target}")
|
log.error(f"Unable to login to{target}")
|
||||||
continue
|
continue
|
||||||
|
|||||||
+6
-1
@@ -20,7 +20,7 @@ class SMBClient:
|
|||||||
Wrapper around impacket's SMBConnection() object
|
Wrapper around impacket's SMBConnection() object
|
||||||
'''
|
'''
|
||||||
|
|
||||||
def __init__(self, server, username, password, domain, nthash):
|
def __init__(self, server, username, password, domain, nthash, share_names):
|
||||||
|
|
||||||
self.server = server
|
self.server = server
|
||||||
|
|
||||||
@@ -30,6 +30,7 @@ class SMBClient:
|
|||||||
self.password = password
|
self.password = password
|
||||||
self.domain = domain
|
self.domain = domain
|
||||||
self.nthash = nthash
|
self.nthash = nthash
|
||||||
|
self.share_names = share_names
|
||||||
if self.nthash:
|
if self.nthash:
|
||||||
# means no password, see https://yougottahackthat.com/blog/339/what-is-aad3b435b51404eeaad3b435b51404ee
|
# means no password, see https://yougottahackthat.com/blog/339/what-is-aad3b435b51404eeaad3b435b51404ee
|
||||||
self.lmhash = 'aad3b435b51404eeaad3b435b51404ee'
|
self.lmhash = 'aad3b435b51404eeaad3b435b51404ee'
|
||||||
@@ -46,6 +47,10 @@ class SMBClient:
|
|||||||
remarkname = resp[i]['shi1_remark'][:-1]
|
remarkname = resp[i]['shi1_remark'][:-1]
|
||||||
# log.info(f'Found share {sharename} on {self.server}, remark {remarkname}')
|
# log.info(f'Found share {sharename} on {self.server}, remark {remarkname}')
|
||||||
|
|
||||||
|
if(self.share_names != "" or self.share_names != None): # if shares are empty, then scan all shares
|
||||||
|
if(not sharename in self.share_names.split(",")): # if share is not in our list of shares to scan, skip it
|
||||||
|
continue
|
||||||
|
|
||||||
share_text = termcolor.colored("[Share]", 'light_yellow')
|
share_text = termcolor.colored("[Share]", 'light_yellow')
|
||||||
|
|
||||||
print(share_text, termcolor.colored(
|
print(share_text, termcolor.colored(
|
||||||
|
|||||||
@@ -41,6 +41,8 @@ def parse_arguments():
|
|||||||
|
|
||||||
parser.add_argument("--no-download", action='store_true', help="Don't download files, just print found file names to stdout - this can only show the top level of files from the share and is unable to recurse into subdirectories.")
|
parser.add_argument("--no-download", action='store_true', help="Don't download files, just print found file names to stdout - this can only show the top level of files from the share and is unable to recurse into subdirectories.")
|
||||||
|
|
||||||
|
parser.add_argument("-s", "--shares", action="store_true", help="Comma separated list of shares to scan. ie: hr,document,test")
|
||||||
|
|
||||||
try:
|
try:
|
||||||
if len(sys.argv) <= 1:
|
if len(sys.argv) <= 1:
|
||||||
parser.print_help()
|
parser.print_help()
|
||||||
|
|||||||
Reference in New Issue
Block a user