Brent Cook
9ff7339644
move ntds parser from priv to extapi
2015-06-22 03:58:24 -05:00
Brent Cook
bfe1060b40
Merge branch 'master' into land-154-ntds
2015-06-04 13:47:44 -05:00
Brent Cook
905f25a03b
compile error
2015-06-04 13:16:05 -05:00
Brent Cook
25731fee03
free utf8 conversion strings and avoid non-null terminated values
2015-06-04 09:00:24 -05:00
Brent Cook
c47c973b83
logon names can actually be up to 104 characters
...
practical limit is 64, this gives us margin
2015-06-04 08:53:09 -05:00
Brent Cook
773008d921
whitespace tweaks
2015-06-04 08:50:24 -05:00
David Maloney
2b07377328
fix copy error
...
use strncpy not memcpy to transfer the re-encoded
name and description into our account object.
also use sizeof for precise copy size. eliminates lingering
errors
MSP-12356
2015-06-02 12:44:49 -05:00
David Maloney
84cea10260
use all unicode for ntds account struct
...
force convert account name and description
to unicode for transport over the wire
MSP-12356
2015-06-02 12:35:30 -05:00
Brent Cook
94a814fbc9
Land #166 , fix IE proxy detection whether or not Auto is enabled
2015-05-26 09:08:30 -05:00
OJ
ddd82d20fc
Fix check for auto detect proxy settings
...
This setting doesn't appear to have any bearing at all on the way the proxy stuff is managed, as a result looking for this flag doesn't make sense. Instead, we just look for presence of the URLs to use, and if found, that's what we use.
This also uses the WinHttpSetOption function for setting credentials which allows for independenc use of user and password.
2015-05-25 16:35:31 +10:00
David Maloney
37e7ab2fc9
just a little more cleanup
...
this should hpefully address the last of Juan's code review
feedback appropriately.
MSP-12356
2015-05-18 11:21:10 -05:00
David Maloney
a3b4b53029
size and signedness issue fixes
...
fixes several size and signedness issues caught
during code review
MSP-12356
2015-05-18 11:08:58 -05:00
David Maloney
7c0c78d766
more missing garbage collection
...
pek structures also were not being garbage collected properly
MSP-12356
2015-05-18 10:46:43 -05:00
David Maloney
6c15c0c0a0
better garbage collection on initial setup
...
the ntds_parse method that gets everything started
was missing garbage collection for accountColumns.
MSP-12356
2015-05-18 10:43:27 -05:00
Brent Cook
c0a908fad0
Land #162 , UUID is a binary blob, not a string
2015-05-17 09:30:11 -05:00
Brent Cook
bb00b00b2c
do not log UUID as a string
2015-05-17 09:25:33 -05:00
OJ
5f7c2e7207
Fix handling of UUIDs in Meterpreter
...
The original implementation assumed that the UUIDs were coming through a strings, but this was changed at some point to use the 16-byte UUID format straight out of MSF.
This was causing issues when UUIDs had null bytes in them because the UUID was being truncated and the result was that UUIDs that were being parsed in MSF were too small, resulting in exceptions.
2015-05-17 17:43:59 +10:00
Brent Cook
68a24e3a47
Land #159 , user proxy settings support with winhttp
2015-05-15 16:41:22 -05:00
Brent Cook
5e7d7cee5d
Land #161 , user and domain information for sysinfo
2015-05-15 16:02:35 -05:00
Brent Cook
602e18591c
fixup build for posix, fix memory leak in utf conversion
2015-05-15 16:01:59 -05:00
David Maloney
e8449a1698
Merge branch 'master' into feature/MSP-12715/sysinfo-upgrade
2015-05-15 15:14:23 -05:00
David Maloney
30a1ecbbcb
add domain and loggedonusers to sysinfo
...
added the domain name and logged on user counts
to the sysinfo command
MSP-12715
2015-05-15 15:10:35 -05:00
Brent Cook
ed1bccd0fc
Land #160 , fix the bare example extension
2015-05-15 15:04:14 -05:00
OJ
7ff8263ce0
Actually set the result to success
2015-05-15 15:03:47 -05:00
OJ
f6c1485ebe
Add support for the sleep command
2015-05-15 15:03:47 -05:00
Meatballs
fded7311c4
Fixup bare met_svc var name
2015-05-15 20:43:47 +01:00
Brent Cook
807005a39f
Land #157 , use RAW rather than string for binary hashes
2015-05-15 11:59:14 -05:00
Brent Cook
f390649c46
Merge branch 'master' into land-157-
2015-05-14 11:30:56 -05:00
Brent Cook
d9ce138eed
remove hash sizeof workaround
2015-05-14 11:29:44 -05:00
David Maloney
1bfd8526b6
Merge branch 'master' into feature/MSP-12356/ntds-parser
2015-05-14 10:55:55 -05:00
David Maloney
7e0c23e228
fixed missing type cast
...
needed explicit typecast for x64
MSP-12356
2015-05-13 14:54:32 -05:00
OJ
a7c2b4fcdd
Utilise IE configuration for proxies where possible
2015-05-13 15:46:33 +10:00
Brent Cook
e158093b38
Land #156 , final tweaks for multi-transport support
2015-05-12 22:35:59 -05:00
Brent Cook
567fc73bbc
Land #156 , multi transport support
2015-05-12 21:42:06 -05:00
Brent Cook
595d975337
quit concatenating serials after the first one
2015-05-12 21:31:36 -05:00
Brent Cook
716330ee7c
make machine_id on POSIX more resilient
...
Only compute the value once, this prevents changing if drive topology changes.
Consider ata and md drive prefixes.
Always set a MACHINE_ID value, upstream expects it in the reply.
2015-05-12 21:25:39 -05:00
OJ
6ee3b53786
Tweak transport change
...
Cosmetic stuff really.
2015-05-13 09:15:03 +10:00
OJ
98822709b5
Slight tweaks to proxy config function
2015-05-11 17:22:37 +10:00
Tim
caf6c0c6c8
add TLV_TYPE_FILE_HASH
2015-05-10 14:57:03 +01:00
OJ
44f581c0e7
Merge branch 'multi-transport-support' of github.com:OJ/meterpreter into multi-transport-support
2015-05-08 14:33:35 +10:00
OJ
70397a5c42
Only write socket when SSL comms in place
2015-05-08 14:32:12 +10:00
David Maloney
f3d0a7bdde
enable compression on our channel
...
since we will be sending lots of null bytes,
we want to make sure we make good use of compression
still doesn't solve our crash problems though
MSP-12356
2015-05-07 14:26:54 -05:00
David Maloney
f288256e19
remove all unneccsary callback stubs
...
channels seem to work fine without stubbed callbacks
removed all of these to eliminate them as a source
of this madness. evrything still works exactly as it did
before, which to say badly.
MSP-12356
2015-05-07 13:47:58 -05:00
David Maloney
7595156c90
make jet instance name unique
...
use date and time to make sure the Jet
Instance name is unique. Hasn't actually
solved our issue, but that name is supposed
to be unique anyways.
MSP-12356
2015-05-07 12:39:46 -05:00
David Maloney
2fa794f1c9
more cleanup/split up
...
split the date stuff up into their own subfunction tooo
MSP-12356
2015-05-06 14:00:15 -05:00
David Maloney
1daa927175
split off hash reading functions
...
moved the reading o the nt and lm hash records
into seperate sub functions. more cleanup/readability work
MSP-12356
2015-05-06 13:30:44 -05:00
David Maloney
bc5b6a1554
split off hash history reading
...
moved the hash history read into a seperate sub function
to make it easier to read
MSP-12356
2015-05-06 13:20:21 -05:00
David Maloney
879d062aa0
un typedef structs
...
bcook says to not typedef structs and just use them as
raw structs, so i have made that conversion here
MSP-12356
2015-05-06 11:24:06 -05:00
David Maloney
dff1a12c38
some more code cleanup
...
just some various bits and bobs here to make
the code a little cleaner and easier to read
MSP-12356
2015-05-06 10:42:03 -05:00
David Maloney
a8b4010ed0
cleanup #get_column_info a bit
...
bcook showed me how to do this the way i originally
wanted to but didn't know how. This is much cleaner to read
MSP-12356
2015-05-06 10:31:18 -05:00