2012-12-17 14:07:35 +00:00
|
|
|
##
|
2014-10-17 16:47:33 +00:00
|
|
|
# This module requires Metasploit: http://metasploit.com/download
|
2013-10-15 18:50:46 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2012-12-17 14:07:35 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
require 'rex'
|
2012-12-19 09:06:58 +00:00
|
|
|
require 'msf/core'
|
|
|
|
require 'msf/core/auxiliary/report'
|
2012-12-17 14:07:35 +00:00
|
|
|
|
|
|
|
class Metasploit3 < Msf::Post
|
|
|
|
|
2013-09-05 21:19:05 +00:00
|
|
|
include Msf::Auxiliary::Report
|
2013-11-23 21:42:09 +00:00
|
|
|
include Msf::Post::Windows::LDAP
|
2013-09-05 21:19:05 +00:00
|
|
|
|
|
|
|
def initialize(info={})
|
|
|
|
super( update_info( info,
|
|
|
|
'Name' => 'Windows Gather Active Directory Computers',
|
|
|
|
'Description' => %Q{
|
|
|
|
This module will enumerate computers in the default AD directory.
|
|
|
|
|
|
|
|
Optional Attributes to use in ATTRIBS:
|
|
|
|
objectClass, cn, description, distinguishedName, instanceType, whenCreated,
|
|
|
|
whenChanged, uSNCreated, uSNChanged, name, objectGUID,
|
|
|
|
userAccountControl, badPwdCount, codePage, countryCode,
|
|
|
|
badPasswordTime, lastLogoff, lastLogon, localPolicyFlags,
|
|
|
|
pwdLastSet, primaryGroupID, objectSid, accountExpires,
|
|
|
|
logonCount, sAMAccountName, sAMAccountType, operatingSystem,
|
|
|
|
operatingSystemVersion, operatingSystemServicePack, serverReferenceBL,
|
|
|
|
dNSHostName, rIDSetPreferences, servicePrincipalName, objectCategory,
|
|
|
|
netbootSCPBL, isCriticalSystemObject, frsComputerReferenceBL,
|
|
|
|
lastLogonTimestamp, msDS-SupportedEncryptionTypes
|
|
|
|
|
|
|
|
ActiveDirectory has a MAX_SEARCH limit of 1000 by default. Split search up
|
|
|
|
if you hit that limit.
|
|
|
|
|
|
|
|
Possible filters:
|
|
|
|
(objectClass=computer) # All Computers
|
|
|
|
(primaryGroupID=516) # All Domain Controllers
|
|
|
|
(&(objectCategory=computer)(operatingSystem=*server*)) # All Servers
|
|
|
|
},
|
|
|
|
'License' => MSF_LICENSE,
|
2014-04-09 15:46:10 +00:00
|
|
|
'Author' => [ 'Ben Campbell' ],
|
2013-09-05 21:19:05 +00:00
|
|
|
'Platform' => [ 'win' ],
|
|
|
|
'SessionTypes' => [ 'meterpreter' ],
|
|
|
|
'References' =>
|
|
|
|
[
|
|
|
|
['URL', 'http://social.technet.microsoft.com/wiki/contents/articles/5392.active-directory-ldap-syntax-filters.aspx'],
|
|
|
|
]
|
|
|
|
))
|
|
|
|
|
|
|
|
register_options([
|
|
|
|
OptBool.new('STORE_LOOT', [true, 'Store file in loot.', false]),
|
2014-01-07 12:20:44 +00:00
|
|
|
OptBool.new('STORE_DB', [true, 'Store file in DB (performance hit resolving IPs).', false]),
|
2013-12-19 18:18:47 +00:00
|
|
|
OptString.new('FIELDS', [true, 'FIELDS to retrieve.', 'dNSHostName,distinguishedName,description,operatingSystem,operatingSystemServicePack']),
|
2013-09-05 21:19:05 +00:00
|
|
|
OptString.new('FILTER', [true, 'Search filter.', '(&(objectCategory=computer)(operatingSystem=*server*))'])
|
|
|
|
], self.class)
|
|
|
|
end
|
|
|
|
|
|
|
|
def run
|
2013-12-19 18:18:47 +00:00
|
|
|
fields = datastore['FIELDS'].gsub(/\s+/,"").split(',')
|
2013-09-05 21:19:05 +00:00
|
|
|
search_filter = datastore['FILTER']
|
2013-12-19 16:46:09 +00:00
|
|
|
max_search = datastore['MAX_SEARCH']
|
2015-09-21 19:33:00 +00:00
|
|
|
|
|
|
|
begin
|
|
|
|
q = query(search_filter, max_search, fields)
|
|
|
|
rescue ::RuntimeError, ::Rex::Post::Meterpreter::RequestError => e
|
|
|
|
print_error(e.message)
|
|
|
|
return
|
|
|
|
end
|
2013-09-05 21:19:05 +00:00
|
|
|
|
2014-01-23 23:34:42 +00:00
|
|
|
return if q.nil? or q[:results].empty?
|
2013-09-05 21:19:05 +00:00
|
|
|
|
2013-09-24 18:58:09 +00:00
|
|
|
# Results table holds raw string data
|
2013-09-05 21:19:05 +00:00
|
|
|
results_table = Rex::Ui::Text::Table.new(
|
2014-08-26 19:42:28 +00:00
|
|
|
'Header' => "Domain Computers",
|
|
|
|
'Indent' => 1,
|
|
|
|
'SortIndex' => -1,
|
|
|
|
'Columns' => fields
|
|
|
|
)
|
2013-09-05 21:19:05 +00:00
|
|
|
|
2013-09-24 18:58:09 +00:00
|
|
|
# Hostnames holds DNS Names to Resolve
|
|
|
|
hostnames = []
|
|
|
|
# Reports are collections for easy database insertion
|
|
|
|
reports = []
|
2013-12-19 18:18:47 +00:00
|
|
|
q[:results].each do |result|
|
2013-09-05 21:19:05 +00:00
|
|
|
row = []
|
|
|
|
|
|
|
|
report = {}
|
2013-12-19 18:18:47 +00:00
|
|
|
0.upto(fields.length-1) do |i|
|
2014-12-13 18:13:36 +00:00
|
|
|
field = result[i][:value] || ""
|
2014-08-26 19:42:28 +00:00
|
|
|
|
|
|
|
# Only perform these actions if the database is connected and we want
|
|
|
|
# to store in the DB.
|
|
|
|
if db && datastore['STORE_DB']
|
|
|
|
case fields[i]
|
|
|
|
when 'dNSHostName'
|
2014-12-13 18:31:29 +00:00
|
|
|
dns = field
|
2014-08-26 19:42:28 +00:00
|
|
|
report[:name] = dns
|
|
|
|
hostnames << dns
|
|
|
|
when 'operatingSystem'
|
2014-12-13 18:35:31 +00:00
|
|
|
report[:os_name] = field.gsub("\xAE",'')
|
2014-08-26 19:42:28 +00:00
|
|
|
when 'distinguishedName'
|
|
|
|
if field =~ /Domain Controllers/i
|
|
|
|
# TODO: Find another way to mark a host as being a domain controller
|
|
|
|
# The 'purpose' field should be server, client, device, printer, etc
|
|
|
|
#report[:purpose] = "DC"
|
|
|
|
report[:purpose] = "server"
|
2013-09-05 21:19:05 +00:00
|
|
|
end
|
2014-08-26 19:42:28 +00:00
|
|
|
when 'operatingSystemServicePack'
|
|
|
|
# XXX: Does this take into account the leading 'SP' string?
|
|
|
|
|
|
|
|
if field.to_i > 0
|
|
|
|
report[:os_sp] = 'SP' + field
|
|
|
|
end
|
|
|
|
if field =~ /(Service Pack|SP)\s?(\d+)/
|
|
|
|
report[:os_sp] = 'SP' + $2
|
|
|
|
end
|
|
|
|
|
|
|
|
when 'description'
|
|
|
|
report[:info] = field
|
2013-09-05 21:19:05 +00:00
|
|
|
end
|
|
|
|
end
|
2013-12-19 18:18:47 +00:00
|
|
|
|
|
|
|
row << field
|
2013-09-05 21:19:05 +00:00
|
|
|
end
|
|
|
|
|
2013-09-24 18:58:09 +00:00
|
|
|
reports << report
|
2013-09-05 21:19:05 +00:00
|
|
|
results_table << row
|
2013-09-24 18:58:09 +00:00
|
|
|
end
|
2013-09-05 21:19:05 +00:00
|
|
|
|
2014-08-26 19:42:28 +00:00
|
|
|
if db && datastore['STORE_DB']
|
2013-09-24 18:58:09 +00:00
|
|
|
print_status("Resolving IP addresses...")
|
|
|
|
ip_results = client.net.resolve.resolve_hosts(hostnames, AF_INET)
|
|
|
|
|
|
|
|
# Merge resolved array with reports
|
|
|
|
reports.each do |report|
|
|
|
|
ip_results.each do |ip_result|
|
|
|
|
if ip_result[:hostname] == report[:name]
|
|
|
|
report[:host] = ip_result[:ip]
|
|
|
|
vprint_good("Database report: #{report.inspect}")
|
|
|
|
report_host(report)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2013-09-05 21:19:05 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
print_line results_table.to_s
|
|
|
|
if datastore['STORE_LOOT']
|
|
|
|
stored_path = store_loot('ad.computers', 'text/plain', session, results_table.to_csv)
|
|
|
|
print_status("Results saved to: #{stored_path}")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-12-17 14:07:35 +00:00
|
|
|
end
|
2013-02-10 17:03:32 +00:00
|
|
|
|