2010-11-25 06:02:35 +00:00
|
|
|
##
|
|
|
|
# $Id$
|
|
|
|
##
|
|
|
|
|
|
|
|
##
|
|
|
|
#
|
|
|
|
# This Auxiliary Mixin provides functionality for dealing with BSD R*Services
|
|
|
|
#
|
|
|
|
##
|
|
|
|
|
|
|
|
module Msf
|
|
|
|
module Auxiliary::RServices
|
|
|
|
|
|
|
|
def initialize(info = {})
|
|
|
|
super
|
|
|
|
|
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
OptString.new('FROMUSER', [ false, 'The username to login from' ]),
|
|
|
|
OptPath.new( 'FROMUSER_FILE', [ false, 'File containing from usernames, one per line',
|
|
|
|
File.join(Msf::Config.data_directory, "wordlists", "rservices_from_users.txt") ])
|
|
|
|
], Msf::Auxiliary::RServices)
|
|
|
|
|
|
|
|
register_advanced_options(
|
|
|
|
[
|
|
|
|
OptBool.new('REMOVE_FROMUSER_FILE', [ true, "Automatically delete the FROMUSER_FILE on module completion", false])
|
|
|
|
], Msf::Auxiliary::RServices)
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def connect_from_privileged_port(start_port = 1023)
|
|
|
|
cport = start_port
|
2010-11-30 02:00:58 +00:00
|
|
|
sd = nil
|
2010-11-25 06:02:35 +00:00
|
|
|
while cport > 512
|
|
|
|
#vprint_status("Trying to connect from port #{cport} ...")
|
|
|
|
sd = nil
|
|
|
|
begin
|
|
|
|
sd = connect(true, { 'CPORT' => cport })
|
|
|
|
|
|
|
|
rescue Rex::AddressInUse
|
|
|
|
# Ignore and try again
|
2010-11-30 02:00:58 +00:00
|
|
|
#vprint_error("Unable to connect: #{$!}")
|
2010-11-25 06:02:35 +00:00
|
|
|
|
2010-11-30 02:00:58 +00:00
|
|
|
rescue Rex::ConnectionError => e
|
2010-11-25 06:02:35 +00:00
|
|
|
vprint_error("Unable to connect: #{$!}")
|
2010-11-30 02:00:58 +00:00
|
|
|
return :refused if e.class == Rex::ConnectionRefused
|
|
|
|
return :connection_error
|
2010-11-25 06:02:35 +00:00
|
|
|
|
|
|
|
end
|
|
|
|
|
|
|
|
break if sd
|
|
|
|
cport -= 1
|
|
|
|
end
|
|
|
|
|
2010-11-30 02:00:58 +00:00
|
|
|
if not sd
|
2010-11-25 06:02:35 +00:00
|
|
|
print_error("#{target_host}:#{rport} - Unable to bind to privileged port")
|
2010-11-30 02:00:58 +00:00
|
|
|
return :bind_error
|
2010-11-25 06:02:35 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
#vprint_status("Connected from #{cport}")
|
2010-11-30 02:00:58 +00:00
|
|
|
return :connected
|
2010-11-25 06:02:35 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def load_fromuser_vars
|
|
|
|
fromusers = extract_words(datastore['FROMUSER_FILE'])
|
|
|
|
if datastore['FROMUSER']
|
|
|
|
fromusers.unshift datastore['FROMUSER']
|
|
|
|
end
|
|
|
|
fromusers
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def cleanup_files
|
|
|
|
super
|
|
|
|
|
|
|
|
path = datastore['FROMUSER_FILE']
|
|
|
|
if path and datastore['REMOVE_FROMUSER_FILE']
|
|
|
|
::File.unlink(path) rescue nil
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
end
|
|
|
|
end
|