2017-11-02 09:43:08 +00:00
|
|
|
from cme.helpers.misc import validate_ntlm
|
|
|
|
from cme.cmedb import DatabaseNavigator
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
class navigator(DatabaseNavigator):
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
def display_creds(self, creds):
|
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['CredID', 'Admin On', 'CredType', 'Domain', 'UserName', 'Password']]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
for cred in creds:
|
2017-11-02 09:43:08 +00:00
|
|
|
|
2016-12-15 07:28:00 +00:00
|
|
|
credID = cred[0]
|
2017-11-02 09:43:08 +00:00
|
|
|
domain = cred[1]
|
|
|
|
username = cred[2]
|
|
|
|
password = cred[3]
|
|
|
|
credtype = cred[4]
|
|
|
|
# pillaged_from = cred[5]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
links = self.db.get_admin_relations(userID=credID)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([credID, str(len(links)) + ' Host(s)', credtype, domain, username, password])
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
self.print_table(data, title='Credentials')
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
def display_hosts(self, hosts):
|
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['HostID', 'Admins', 'IP', 'Hostname', 'Domain', 'OS', 'DB Instances']]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
for host in hosts:
|
2017-11-02 09:43:08 +00:00
|
|
|
|
2016-12-15 07:28:00 +00:00
|
|
|
hostID = host[0]
|
|
|
|
ip = host[1]
|
|
|
|
hostname = host[2]
|
|
|
|
domain = host[3]
|
|
|
|
os = host[4]
|
2017-11-02 09:43:08 +00:00
|
|
|
instances = host[5]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
links = self.db.get_admin_relations(hostID=hostID)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([hostID, str(len(links)) + ' Cred(s)', ip, hostname, domain, os, instances])
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
self.print_table(data, title='Hosts')
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
def do_hosts(self, line):
|
|
|
|
|
|
|
|
filterTerm = line.strip()
|
|
|
|
|
|
|
|
if filterTerm == "":
|
2017-11-02 09:43:08 +00:00
|
|
|
hosts = self.db.get_computers()
|
2016-12-15 07:28:00 +00:00
|
|
|
self.display_hosts(hosts)
|
|
|
|
else:
|
2017-11-02 09:43:08 +00:00
|
|
|
hosts = self.db.get_computers(filterTerm=filterTerm)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
if len(hosts) > 1:
|
|
|
|
self.display_hosts(hosts)
|
|
|
|
elif len(hosts) == 1:
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['HostID', 'IP', 'Hostname', 'Domain', 'OS']]
|
2016-12-15 07:28:00 +00:00
|
|
|
hostIDList = []
|
|
|
|
|
|
|
|
for host in hosts:
|
|
|
|
hostID = host[0]
|
|
|
|
hostIDList.append(hostID)
|
|
|
|
|
|
|
|
ip = host[1]
|
|
|
|
hostname = host[2]
|
|
|
|
domain = host[3]
|
|
|
|
os = host[4]
|
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([hostID, ip, hostname, domain, os])
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
self.print_table(data, title='Host(s)')
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['CredID', 'CredType', 'Domain', 'UserName', 'Password']]
|
2016-12-15 07:28:00 +00:00
|
|
|
for hostID in hostIDList:
|
2017-11-02 09:43:08 +00:00
|
|
|
links = self.db.get_admin_relations(hostID=hostID)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
for link in links:
|
|
|
|
linkID, credID, hostID = link
|
|
|
|
creds = self.db.get_credentials(filterTerm=credID)
|
|
|
|
|
|
|
|
for cred in creds:
|
|
|
|
credID = cred[0]
|
2017-11-02 09:43:08 +00:00
|
|
|
domain = cred[1]
|
|
|
|
username = cred[2]
|
|
|
|
password = cred[3]
|
|
|
|
credtype = cred[4]
|
|
|
|
# pillaged_from = cred[5]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([credID, credtype, domain, username, password])
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
self.print_table(data, title='Credential(s) with Admin Access')
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
def do_creds(self, line):
|
|
|
|
|
|
|
|
filterTerm = line.strip()
|
|
|
|
|
|
|
|
if filterTerm == "":
|
|
|
|
creds = self.db.get_credentials()
|
|
|
|
self.display_creds(creds)
|
|
|
|
|
|
|
|
elif filterTerm.split()[0].lower() == "add":
|
|
|
|
args = filterTerm.split()[1:]
|
|
|
|
|
|
|
|
if len(args) == 3:
|
|
|
|
domain, username, password = args
|
|
|
|
if validate_ntlm(password):
|
|
|
|
self.db.add_credential("hash", domain, username, password)
|
|
|
|
else:
|
|
|
|
self.db.add_credential("plaintext", domain, username, password)
|
|
|
|
|
|
|
|
else:
|
2019-11-12 21:39:26 +00:00
|
|
|
print("[!] Format is 'add domain username password")
|
2016-12-15 07:28:00 +00:00
|
|
|
return
|
|
|
|
|
|
|
|
elif filterTerm.split()[0].lower() == "remove":
|
|
|
|
|
|
|
|
args = filterTerm.split()[1:]
|
2017-11-02 09:43:08 +00:00
|
|
|
if len(args) != 1:
|
2019-11-12 21:39:26 +00:00
|
|
|
print("[!] Format is 'remove <credID>'")
|
2016-12-15 07:28:00 +00:00
|
|
|
return
|
|
|
|
else:
|
|
|
|
self.db.remove_credentials(args)
|
|
|
|
self.db.remove_links(credIDs=args)
|
|
|
|
|
|
|
|
elif filterTerm.split()[0].lower() == "plaintext":
|
|
|
|
creds = self.db.get_credentials(credtype="plaintext")
|
|
|
|
self.display_creds(creds)
|
|
|
|
|
|
|
|
elif filterTerm.split()[0].lower() == "hash":
|
|
|
|
creds = self.db.get_credentials(credtype="hash")
|
|
|
|
self.display_creds(creds)
|
|
|
|
|
|
|
|
else:
|
|
|
|
creds = self.db.get_credentials(filterTerm=filterTerm)
|
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['CredID', 'CredType', 'Domain', 'UserName', 'Password']]
|
2016-12-15 07:28:00 +00:00
|
|
|
credIDList = []
|
|
|
|
|
|
|
|
for cred in creds:
|
|
|
|
credID = cred[0]
|
|
|
|
credIDList.append(credID)
|
|
|
|
|
|
|
|
credType = cred[1]
|
|
|
|
domain = cred[2]
|
|
|
|
username = cred[3]
|
|
|
|
password = cred[4]
|
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([credID, credType, domain, username, password])
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
self.print_table(data, title='Credential(s)')
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
data = [['HostID', 'IP', 'Hostname', 'Domain', 'OS']]
|
2016-12-15 07:28:00 +00:00
|
|
|
for credID in credIDList:
|
2017-11-02 09:43:08 +00:00
|
|
|
links = self.db.get_admin_relations(userID=credID)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
for link in links:
|
2017-11-02 09:43:08 +00:00
|
|
|
linkID, credID, hostID = link
|
|
|
|
hosts = self.db.get_computers(hostID)
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
for host in hosts:
|
|
|
|
hostID = host[0]
|
|
|
|
ip = host[1]
|
|
|
|
hostname = host[2]
|
|
|
|
domain = host[3]
|
|
|
|
os = host[4]
|
|
|
|
|
2019-11-10 23:12:35 +00:00
|
|
|
data.append([hostID, ip, hostname, domain, os])
|
2017-11-02 09:43:08 +00:00
|
|
|
|
|
|
|
self.print_table(data, title='Admin Access to Host(s)')
|
|
|
|
|
|
|
|
def complete_hosts(self, text, line, begidx, endidx):
|
|
|
|
"Tab-complete 'creds' commands."
|
|
|
|
|
|
|
|
commands = ["add", "remove"]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
mline = line.partition(' ')[2]
|
|
|
|
offs = len(mline) - len(text)
|
|
|
|
return [s[offs:] for s in commands if s.startswith(mline)]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
def complete_creds(self, text, line, begidx, endidx):
|
|
|
|
"Tab-complete 'creds' commands."
|
|
|
|
|
2017-11-02 09:43:08 +00:00
|
|
|
commands = ["add", "remove", "hash", "plaintext"]
|
2016-12-15 07:28:00 +00:00
|
|
|
|
|
|
|
mline = line.partition(' ')[2]
|
|
|
|
offs = len(mline) - len(text)
|
|
|
|
return [s[offs:] for s in commands if s.startswith(mline)]
|