2007-02-18 00:10:39 +00:00
|
|
|
##
|
2007-04-24 06:27:39 +00:00
|
|
|
# $Id$
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
##
|
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
|
|
|
# Framework web site for more information on licensing and terms of use.
|
|
|
|
# http://metasploit.com/projects/Framework/
|
|
|
|
##
|
|
|
|
|
|
|
|
|
2006-08-12 08:52:54 +00:00
|
|
|
require 'msf/core'
|
|
|
|
|
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Auxiliary
|
2006-08-12 08:52:54 +00:00
|
|
|
|
2007-04-24 06:27:39 +00:00
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
# Exploit mixins should be called first
|
2008-10-02 05:23:59 +00:00
|
|
|
include Msf::Exploit::Remote::Tcp
|
2007-04-24 06:27:39 +00:00
|
|
|
|
|
|
|
# We can't use SMB here, since the SMB mixin
|
|
|
|
# is not thread-safe and will not become so
|
|
|
|
# without a ton of work (self.sock, etc).
|
2006-08-12 08:52:54 +00:00
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
# Scanner mixin should be near last
|
2008-10-02 05:23:59 +00:00
|
|
|
include Msf::Auxiliary::Scanner
|
2007-04-24 06:27:39 +00:00
|
|
|
|
|
|
|
# Aliases for common classes
|
|
|
|
SIMPLE = Rex::Proto::SMB::SimpleClient
|
|
|
|
XCEPT = Rex::Proto::SMB::Exceptions
|
|
|
|
CONST = Rex::Proto::SMB::Constants
|
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
|
2006-08-12 08:52:54 +00:00
|
|
|
def initialize
|
|
|
|
super(
|
|
|
|
'Name' => 'SMB Version Detection',
|
2007-02-18 00:10:39 +00:00
|
|
|
'Version' => '$Revision$',
|
2006-08-12 08:52:54 +00:00
|
|
|
'Description' => 'Display version information about each system',
|
|
|
|
'Author' => 'hdm',
|
|
|
|
'License' => MSF_LICENSE
|
|
|
|
)
|
2006-08-13 00:08:40 +00:00
|
|
|
|
|
|
|
deregister_options('RPORT')
|
|
|
|
end
|
2006-08-12 08:52:54 +00:00
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
# Fingerprint a single host
|
2006-08-12 08:52:54 +00:00
|
|
|
def run_host(ip)
|
2006-08-13 02:06:27 +00:00
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
[[139, false], [445, true]].each do |info|
|
|
|
|
|
2007-04-24 06:27:39 +00:00
|
|
|
self.target_port = info[0]
|
|
|
|
direct = info[1]
|
|
|
|
|
|
|
|
soc = nil
|
2006-08-12 08:52:54 +00:00
|
|
|
|
|
|
|
begin
|
2007-04-24 06:27:39 +00:00
|
|
|
# print_status("Trying to connect to #{target_host()}:#{target_port()}...")
|
|
|
|
soc = connect(false)
|
|
|
|
smb = SIMPLE.new(soc, direct)
|
|
|
|
|
|
|
|
smb.login('*SMBSERVER')
|
2006-08-13 00:08:40 +00:00
|
|
|
|
2007-04-24 06:27:39 +00:00
|
|
|
smb.connect('IPC$')
|
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
os = 'Unknown'
|
|
|
|
sp = ''
|
2007-04-24 06:27:39 +00:00
|
|
|
|
|
|
|
case smb.client.peer_native_os
|
2006-08-13 00:08:40 +00:00
|
|
|
when 'Windows NT 4.0'
|
|
|
|
os = 'Windows NT 4.0'
|
|
|
|
when 'Windows 5.0'
|
|
|
|
os = 'Windows 2000'
|
|
|
|
when 'Windows 5.1'
|
|
|
|
os = 'Windows XP'
|
|
|
|
when /Windows Server 2003 (\d+)$/
|
|
|
|
os = 'Windows 2003'
|
|
|
|
sp = 'No Service Pack'
|
|
|
|
when /Windows Server 2003 (\d+) Service Pack (\d+)/
|
|
|
|
os = 'Windows 2003'
|
|
|
|
sp = 'Service Pack ' + $2
|
2007-05-23 14:51:20 +00:00
|
|
|
when /Windows Server 2003 R2 (\d+) Service Pack (\d+)/
|
|
|
|
os = 'Windows 2003 R2'
|
|
|
|
sp = 'Service Pack ' + $2
|
2007-01-31 00:08:52 +00:00
|
|
|
when /Windows Vista \(TM\) (\w+) (\d+)/
|
|
|
|
os = 'Windows Vista ' + $1
|
|
|
|
sp = '(Build ' + $2 + ')'
|
2006-08-13 00:08:40 +00:00
|
|
|
when 'Unix'
|
|
|
|
os = 'Unix'
|
2007-04-24 06:27:39 +00:00
|
|
|
sv = smb.client.peer_native_lm
|
2006-08-13 00:08:40 +00:00
|
|
|
case sv
|
|
|
|
when /Samba\s+(.*)/i
|
2007-04-24 06:27:39 +00:00
|
|
|
sp = 'Samba ' + $1
|
2006-08-13 00:08:40 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
if (os == 'Windows XP' and sp.length == 0)
|
|
|
|
# SRVSVC was blocked in SP2
|
|
|
|
begin
|
2007-04-24 06:27:39 +00:00
|
|
|
smb.create_pipe("\\SRVSVC")
|
2006-08-13 00:08:40 +00:00
|
|
|
sp = 'Service Pack 0 / Service Pack 1'
|
|
|
|
rescue ::Rex::Proto::SMB::Exceptions::ErrorCode => e
|
|
|
|
if (e.error_code == 0xc0000022)
|
|
|
|
sp = 'Service Pack 2+'
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
if (os == 'Windows 2000' and sp.length == 0)
|
|
|
|
# LLSRPC was blocked in a post-SP4 update
|
|
|
|
begin
|
2007-04-24 06:27:39 +00:00
|
|
|
smb.create_pipe("\\LLSRPC")
|
2006-08-13 00:08:40 +00:00
|
|
|
sp = 'Service Pack 0 - Service Pack 4'
|
|
|
|
rescue ::Rex::Proto::SMB::Exceptions::ErrorCode => e
|
|
|
|
if (e.error_code == 0xc0000022)
|
|
|
|
sp = 'Service Pack 4 with MS05-010+'
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
print_status("#{ip} is running #{os} #{sp}")
|
2007-01-31 00:08:52 +00:00
|
|
|
|
|
|
|
if (os == 'Unknown')
|
2007-04-24 06:27:39 +00:00
|
|
|
print_status("NativeOS: #{smb.client.peer_native_os()}")
|
|
|
|
print_status("NativeLM: #{smb.client.peer_native_lm()}")
|
2007-01-31 00:08:52 +00:00
|
|
|
end
|
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
return
|
2007-04-24 06:27:39 +00:00
|
|
|
|
|
|
|
rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout
|
|
|
|
next
|
|
|
|
|
|
|
|
# rescue => e
|
|
|
|
# p e.class
|
|
|
|
# p e.to_s
|
|
|
|
|
|
|
|
ensure
|
|
|
|
soc.close if soc
|
|
|
|
soc = nil
|
|
|
|
|
2006-08-13 00:08:40 +00:00
|
|
|
end
|
2006-08-12 08:52:54 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
end
|
2008-10-02 05:23:59 +00:00
|
|
|
|