995 lines
57 KiB
HTML
995 lines
57 KiB
HTML
<!DOCTYPE html>
|
|
<html>
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<title>
|
|
Class: Msf::Util::WindowsRegistry::RemoteRegistry
|
|
|
|
— Documentation by YARD 0.9.37
|
|
|
|
</title>
|
|
|
|
<link rel="stylesheet" href="../../../css/style.css" type="text/css" />
|
|
|
|
<link rel="stylesheet" href="../../../css/common.css" type="text/css" />
|
|
|
|
<script type="text/javascript">
|
|
pathId = "Msf::Util::WindowsRegistry::RemoteRegistry";
|
|
relpath = '../../../';
|
|
</script>
|
|
|
|
|
|
<script type="text/javascript" charset="utf-8" src="../../../js/jquery.js"></script>
|
|
|
|
<script type="text/javascript" charset="utf-8" src="../../../js/app.js"></script>
|
|
|
|
|
|
</head>
|
|
<body>
|
|
<div class="nav_wrap">
|
|
<iframe id="nav" src="../../../class_list.html?1"></iframe>
|
|
<div id="resizer"></div>
|
|
</div>
|
|
|
|
<div id="main" tabindex="-1">
|
|
<div id="header">
|
|
<div id="menu">
|
|
|
|
<a href="../../../_index.html">Index (R)</a> »
|
|
<span class='title'><span class='object_link'><a href="../../../Msf.html" title="Msf (module)">Msf</a></span></span> » <span class='title'><span class='object_link'><a href="../../Util.html" title="Msf::Util (module)">Util</a></span></span> » <span class='title'><span class='object_link'><a href="../WindowsRegistry.html" title="Msf::Util::WindowsRegistry (module)">WindowsRegistry</a></span></span>
|
|
»
|
|
<span class="title">RemoteRegistry</span>
|
|
|
|
</div>
|
|
|
|
<div id="search">
|
|
|
|
<a class="full_list_link" id="class_list_link"
|
|
href="../../../class_list.html">
|
|
|
|
<svg width="24" height="24">
|
|
<rect x="0" y="4" width="24" height="4" rx="1" ry="1"></rect>
|
|
<rect x="0" y="12" width="24" height="4" rx="1" ry="1"></rect>
|
|
<rect x="0" y="20" width="24" height="4" rx="1" ry="1"></rect>
|
|
</svg>
|
|
</a>
|
|
|
|
</div>
|
|
<div class="clear"></div>
|
|
</div>
|
|
|
|
<div id="content"><h1>Class: Msf::Util::WindowsRegistry::RemoteRegistry
|
|
|
|
|
|
|
|
</h1>
|
|
<div class="box_info">
|
|
|
|
<dl>
|
|
<dt>Inherits:</dt>
|
|
<dd>
|
|
<span class="inheritName">Object</span>
|
|
|
|
<ul class="fullTree">
|
|
<li>Object</li>
|
|
|
|
<li class="next">Msf::Util::WindowsRegistry::RemoteRegistry</li>
|
|
|
|
</ul>
|
|
<a href="#" class="inheritanceTree">show all</a>
|
|
|
|
</dd>
|
|
</dl>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<dl>
|
|
<dt>Defined in:</dt>
|
|
<dd>lib/msf/util/windows_registry/remote_registry.rb</dd>
|
|
</dl>
|
|
|
|
</div>
|
|
|
|
|
|
|
|
<h2>
|
|
Constant Summary
|
|
<small><a href="#" class="constants_summary_toggle">collapse</a></small>
|
|
</h2>
|
|
|
|
<dl class="constants">
|
|
|
|
<dt id="ROOT_KEY-constant" class="">ROOT_KEY =
|
|
<div class="docstring">
|
|
<div class="discussion">
|
|
|
|
<p>Constants</p>
|
|
|
|
|
|
</div>
|
|
</div>
|
|
<div class="tags">
|
|
|
|
|
|
</div>
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x2c</span></pre></dd>
|
|
|
|
<dt id="REG_NONE-constant" class="">REG_NONE =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x00</span></pre></dd>
|
|
|
|
<dt id="REG_SZ-constant" class="">REG_SZ =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x01</span></pre></dd>
|
|
|
|
<dt id="REG_EXPAND_SZ-constant" class="">REG_EXPAND_SZ =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x02</span></pre></dd>
|
|
|
|
<dt id="REG_BINARY-constant" class="">REG_BINARY =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x03</span></pre></dd>
|
|
|
|
<dt id="REG_DWORD-constant" class="">REG_DWORD =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x04</span></pre></dd>
|
|
|
|
<dt id="REG_MULTISZ-constant" class="">REG_MULTISZ =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x07</span></pre></dd>
|
|
|
|
<dt id="REG_QWORD-constant" class="">REG_QWORD =
|
|
|
|
</dt>
|
|
<dd><pre class="code"><span class='int'>0x0b</span></pre></dd>
|
|
|
|
</dl>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<h2>
|
|
Instance Method Summary
|
|
<small><a href="#" class="summary_toggle">collapse</a></small>
|
|
</h2>
|
|
|
|
<ul class="summary">
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#backup_file_path-instance_method" title="#backup_file_path (instance method)">#<strong>backup_file_path</strong> ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#change_dacl-instance_method" title="#change_dacl (instance method)">#<strong>change_dacl</strong>(key, sid) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#create_ace-instance_method" title="#create_ace (instance method)">#<strong>create_ace</strong>(sid) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#delete_backup_file-instance_method" title="#delete_backup_file (instance method)">#<strong>delete_backup_file</strong>(path = backup_file_path) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#enum_key-instance_method" title="#enum_key (instance method)">#<strong>enum_key</strong>(key) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#enum_values-instance_method" title="#enum_values (instance method)">#<strong>enum_values</strong>(key) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#get_value-instance_method" title="#get_value (instance method)">#<strong>get_value</strong>(key, value_name = nil) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#initialize-instance_method" title="#initialize (instance method)">#<strong>initialize</strong>(winreg, name: nil, inline: false) ⇒ RemoteRegistry </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
<span class="note title constructor">constructor</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'>
|
|
<p>A new instance of RemoteRegistry.</p>
|
|
</div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#read_from_file-instance_method" title="#read_from_file (instance method)">#<strong>read_from_file</strong>(filepath) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#restore_dacl-instance_method" title="#restore_dacl (instance method)">#<strong>restore_dacl</strong>(key, security_descriptor) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
<li class="public ">
|
|
<span class="summary_signature">
|
|
|
|
<a href="#save_to_file-instance_method" title="#save_to_file (instance method)">#<strong>save_to_file</strong>(key, security_descriptor, security_information, path = backup_file_path) ⇒ Object </a>
|
|
|
|
|
|
|
|
</span>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<span class="summary_desc"><div class='inline'></div></span>
|
|
|
|
</li>
|
|
|
|
|
|
</ul>
|
|
|
|
|
|
<div id="constructor_details" class="method_details_list">
|
|
<h2>Constructor Details</h2>
|
|
|
|
<div class="method_details first">
|
|
<h3 class="signature first" id="initialize-instance_method">
|
|
|
|
#<strong>initialize</strong>(winreg, name: nil, inline: false) ⇒ <tt><span class='object_link'><a href="" title="Msf::Util::WindowsRegistry::RemoteRegistry (class)">RemoteRegistry</a></span></tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><div class="docstring">
|
|
<div class="discussion">
|
|
|
|
<p>Returns a new instance of RemoteRegistry.</p>
|
|
|
|
|
|
</div>
|
|
</div>
|
|
<div class="tags">
|
|
|
|
|
|
</div><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
16
|
|
17
|
|
18
|
|
19
|
|
20
|
|
21
|
|
22
|
|
23
|
|
24
|
|
25
|
|
26
|
|
27
|
|
28
|
|
29</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 16</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_initialize'>initialize</span><span class='lparen'>(</span><span class='id identifier rubyid_winreg'>winreg</span><span class='comma'>,</span> <span class='label'>name:</span> <span class='kw'>nil</span><span class='comma'>,</span> <span class='label'>inline:</span> <span class='kw'>false</span><span class='rparen'>)</span>
|
|
<span class='ivar'>@winreg</span> <span class='op'>=</span> <span class='id identifier rubyid_winreg'>winreg</span>
|
|
<span class='ivar'>@inline</span> <span class='op'>=</span> <span class='id identifier rubyid_inline'>inline</span>
|
|
<span class='kw'>case</span> <span class='id identifier rubyid_name'>name</span>
|
|
<span class='kw'>when</span> <span class='symbol'>:sam</span>
|
|
<span class='id identifier rubyid_require_relative'>require_relative</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>sam</span><span class='tstring_end'>'</span></span>
|
|
<span class='id identifier rubyid_extend'>extend</span> <span class='const'><span class='object_link'><a href="Sam.html" title="Msf::Util::WindowsRegistry::Sam (module)">Sam</a></span></span>
|
|
<span class='kw'>when</span> <span class='symbol'>:security</span>
|
|
<span class='id identifier rubyid_require_relative'>require_relative</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>security</span><span class='tstring_end'>'</span></span>
|
|
<span class='id identifier rubyid_extend'>extend</span> <span class='const'><span class='object_link'><a href="Security.html" title="Msf::Util::WindowsRegistry::Security (module)">Security</a></span></span>
|
|
<span class='kw'>else</span>
|
|
<span class='id identifier rubyid_wlog'><span class='object_link'><a href="../../../top-level-namespace.html#wlog-instance_method" title="#wlog (method)">wlog</a></span></span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] Unknown :name argument: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_name'>name</span><span class='embexpr_end'>}</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span> <span class='kw'>unless</span> <span class='id identifier rubyid_name'>name</span><span class='period'>.</span><span class='id identifier rubyid_blank?'>blank?</span>
|
|
<span class='kw'>end</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
|
|
<div id="instance_method_details" class="method_details_list">
|
|
<h2>Instance Method Details</h2>
|
|
|
|
|
|
<div class="method_details first">
|
|
<h3 class="signature first" id="backup_file_path-instance_method">
|
|
|
|
#<strong>backup_file_path</strong> ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
50
|
|
51
|
|
52
|
|
53
|
|
54
|
|
55
|
|
56
|
|
57
|
|
58
|
|
59
|
|
60</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 50</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_backup_file_path'>backup_file_path</span>
|
|
<span class='kw'>return</span> <span class='ivar'>@backup_file_path</span> <span class='kw'>if</span> <span class='ivar'>@backup_file_path</span>
|
|
|
|
<span class='kw'>if</span> <span class='op'>!</span> <span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_directory?'>directory?</span><span class='lparen'>(</span><span class='const'><span class='object_link'><a href="../../../Msf.html" title="Msf (module)">Msf</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../Config.html" title="Msf::Config (class)">Config</a></span></span><span class='period'>.</span><span class='id identifier rubyid_local_directory'><span class='object_link'><a href="../../Config.html#local_directory-class_method" title="Msf::Config.local_directory (method)">local_directory</a></span></span><span class='rparen'>)</span>
|
|
<span class='const'>FileUtils</span><span class='period'>.</span><span class='id identifier rubyid_mkdir_p'>mkdir_p</span><span class='lparen'>(</span><span class='const'><span class='object_link'><a href="../../../Msf.html" title="Msf (module)">Msf</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../Config.html" title="Msf::Config (class)">Config</a></span></span><span class='period'>.</span><span class='id identifier rubyid_local_directory'><span class='object_link'><a href="../../Config.html#local_directory-class_method" title="Msf::Config.local_directory (method)">local_directory</a></span></span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span>
|
|
<span class='id identifier rubyid_remote_host'>remote_host</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_tree'>tree</span><span class='period'>.</span><span class='id identifier rubyid_client'>client</span><span class='period'>.</span><span class='id identifier rubyid_dns_host_name'>dns_host_name</span>
|
|
<span class='id identifier rubyid_remote_host'>remote_host</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_tree'>tree</span><span class='period'>.</span><span class='id identifier rubyid_client'>client</span><span class='period'>.</span><span class='id identifier rubyid_dispatcher'>dispatcher</span><span class='period'>.</span><span class='id identifier rubyid_tcp_socket'>tcp_socket</span><span class='period'>.</span><span class='id identifier rubyid_peerhost'>peerhost</span> <span class='kw'>if</span> <span class='id identifier rubyid_remote_host'>remote_host</span><span class='period'>.</span><span class='id identifier rubyid_blank?'>blank?</span>
|
|
<span class='id identifier rubyid_path'>path</span> <span class='op'>=</span> <span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_join'>join</span><span class='lparen'>(</span><span class='const'><span class='object_link'><a href="../../../Msf.html" title="Msf (module)">Msf</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../Config.html" title="Msf::Config (class)">Config</a></span></span><span class='period'>.</span><span class='id identifier rubyid_local_directory'><span class='object_link'><a href="../../Config.html#local_directory-class_method" title="Msf::Config.local_directory (method)">local_directory</a></span></span><span class='comma'>,</span> <span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>remote_registry_sd_backup_</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_remote_host'>remote_host</span><span class='embexpr_end'>}</span><span class='tstring_content'>_</span><span class='embexpr_beg'>#{</span><span class='const'>Time</span><span class='period'>.</span><span class='id identifier rubyid_now'>now</span><span class='period'>.</span><span class='id identifier rubyid_strftime'>strftime</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>%Y%m%d%H%M%S</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span><span class='embexpr_end'>}</span><span class='tstring_content'>.</span><span class='embexpr_beg'>#{</span><span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'>Text</span><span class='period'>.</span><span class='id identifier rubyid_rand_text_alpha'>rand_text_alpha</span><span class='lparen'>(</span><span class='int'>6</span><span class='rparen'>)</span><span class='embexpr_end'>}</span><span class='tstring_content'>.yml</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span>
|
|
<span class='ivar'>@backup_file_path</span> <span class='op'>=</span> <span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_expand_path'>expand_path</span><span class='lparen'>(</span><span class='id identifier rubyid_path'>path</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="change_dacl-instance_method">
|
|
|
|
#<strong>change_dacl</strong>(key, sid) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
83
|
|
84
|
|
85
|
|
86
|
|
87
|
|
88
|
|
89
|
|
90
|
|
91
|
|
92
|
|
93
|
|
94
|
|
95
|
|
96
|
|
97
|
|
98
|
|
99
|
|
100
|
|
101
|
|
102
|
|
103
|
|
104
|
|
105</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 83</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_change_dacl'>change_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_sid'>sid</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_security_information'>security_information</span> <span class='op'>=</span>
|
|
<span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>OWNER_SECURITY_INFORMATION</span> <span class='op'>|</span>
|
|
<span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>GROUP_SECURITY_INFORMATION</span> <span class='op'>|</span>
|
|
<span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>DACL_SECURITY_INFORMATION</span>
|
|
|
|
<span class='id identifier rubyid_security_descriptor'>security_descriptor</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_get_key_security_descriptor'>get_key_security_descriptor</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_security_information'>security_information</span><span class='comma'>,</span> <span class='label'>bind:</span> <span class='kw'>false</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_dlog'><span class='object_link'><a href="../../../top-level-namespace.html#dlog-instance_method" title="#dlog (method)">dlog</a></span></span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] Security descriptor for </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_key'>key</span><span class='embexpr_end'>}</span><span class='tstring_content'>: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='period'>.</span><span class='id identifier rubyid_b'>b</span><span class='period'>.</span><span class='id identifier rubyid_bytes'>bytes</span><span class='period'>.</span><span class='id identifier rubyid_map'>map</span> <span class='lbrace'>{</span> <span class='op'>|</span><span class='id identifier rubyid_c'>c</span><span class='op'>|</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>%02x</span><span class='tstring_end'>'</span></span> <span class='op'>%</span> <span class='id identifier rubyid_c'>c</span><span class='period'>.</span><span class='id identifier rubyid_ord'>ord</span> <span class='rbrace'>}</span><span class='period'>.</span><span class='id identifier rubyid_join'><span class='object_link'><a href="../../../top-level-namespace.html#join-instance_method" title="#join (method)">join</a></span></span><span class='embexpr_end'>}</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_save_to_file'>save_to_file</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='comma'>,</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>DACL_SECURITY_INFORMATION</span><span class='rparen'>)</span>
|
|
|
|
<span class='id identifier rubyid_parsed_sd'>parsed_sd</span> <span class='op'>=</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp.html" title="Rex::Proto::MsDtyp (module)">MsDtyp</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp/MsDtypSecurityDescriptor.html" title="Rex::Proto::MsDtyp::MsDtypSecurityDescriptor (class)">MsDtypSecurityDescriptor</a></span></span><span class='period'>.</span><span class='id identifier rubyid_read'>read</span><span class='lparen'>(</span><span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_ace'>ace</span> <span class='op'>=</span> <span class='id identifier rubyid_create_ace'>create_ace</span><span class='lparen'>(</span><span class='id identifier rubyid_sid'>sid</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_parsed_sd'>parsed_sd</span><span class='period'>.</span><span class='id identifier rubyid_dacl'>dacl</span><span class='period'>.</span><span class='id identifier rubyid_aces'>aces</span> <span class='op'><<</span> <span class='id identifier rubyid_ace'>ace</span>
|
|
<span class='id identifier rubyid_parsed_sd'>parsed_sd</span><span class='period'>.</span><span class='id identifier rubyid_dacl'>dacl</span><span class='period'>.</span><span class='id identifier rubyid_acl_count'>acl_count</span> <span class='op'>+=</span> <span class='int'>1</span>
|
|
<span class='id identifier rubyid_parsed_sd'>parsed_sd</span><span class='period'>.</span><span class='id identifier rubyid_dacl'>dacl</span><span class='period'>.</span><span class='id identifier rubyid_acl_size'>acl_size</span> <span class='op'>+=</span> <span class='id identifier rubyid_ace'>ace</span><span class='period'>.</span><span class='id identifier rubyid_num_bytes'>num_bytes</span>
|
|
<span class='id identifier rubyid_dlog'><span class='object_link'><a href="../../../top-level-namespace.html#dlog-instance_method" title="#dlog (method)">dlog</a></span></span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] New security descriptor for </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_key'>key</span><span class='embexpr_end'>}</span><span class='tstring_content'>: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_parsed_sd'>parsed_sd</span><span class='period'>.</span><span class='id identifier rubyid_to_binary_s'>to_binary_s</span><span class='period'>.</span><span class='id identifier rubyid_b'>b</span><span class='period'>.</span><span class='id identifier rubyid_bytes'>bytes</span><span class='period'>.</span><span class='id identifier rubyid_map'>map</span> <span class='lbrace'>{</span> <span class='op'>|</span><span class='id identifier rubyid_c'>c</span><span class='op'>|</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>%02x</span><span class='tstring_end'>'</span></span> <span class='op'>%</span> <span class='id identifier rubyid_c'>c</span><span class='period'>.</span><span class='id identifier rubyid_ord'>ord</span> <span class='rbrace'>}</span><span class='period'>.</span><span class='id identifier rubyid_join'><span class='object_link'><a href="../../../top-level-namespace.html#join-instance_method" title="#join (method)">join</a></span></span><span class='embexpr_end'>}</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span>
|
|
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_set_key_security_descriptor'>set_key_security_descriptor</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_parsed_sd'>parsed_sd</span><span class='period'>.</span><span class='id identifier rubyid_to_binary_s'>to_binary_s</span><span class='comma'>,</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>DACL_SECURITY_INFORMATION</span><span class='comma'>,</span> <span class='label'>bind:</span> <span class='kw'>false</span><span class='rparen'>)</span>
|
|
|
|
<span class='id identifier rubyid_security_descriptor'>security_descriptor</span>
|
|
<span class='kw'>rescue</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Dcerpc</span><span class='op'>::</span><span class='const'>Error</span><span class='op'>::</span><span class='const'>WinregError</span> <span class='op'>=></span> <span class='id identifier rubyid_e'>e</span>
|
|
<span class='id identifier rubyid_elog'><span class='object_link'><a href="../../../top-level-namespace.html#elog-instance_method" title="#elog (method)">elog</a></span></span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] Error while changing DACL on key `</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_key'>key</span><span class='embexpr_end'>}</span><span class='tstring_content'>`: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_e'>e</span><span class='embexpr_end'>}</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="create_ace-instance_method">
|
|
|
|
#<strong>create_ace</strong>(sid) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
31
|
|
32
|
|
33
|
|
34
|
|
35
|
|
36
|
|
37
|
|
38
|
|
39
|
|
40
|
|
41
|
|
42
|
|
43
|
|
44
|
|
45
|
|
46
|
|
47
|
|
48</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 31</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_create_ace'>create_ace</span><span class='lparen'>(</span><span class='id identifier rubyid_sid'>sid</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_access_mask'>access_mask</span> <span class='op'>=</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Dcerpc</span><span class='op'>::</span><span class='const'>Winreg</span><span class='op'>::</span><span class='const'>Regsam</span><span class='period'>.</span><span class='id identifier rubyid_new'>new</span><span class='lparen'>(</span><span class='lbrace'>{</span>
|
|
<span class='label'>write_dac:</span> <span class='int'>1</span><span class='comma'>,</span>
|
|
<span class='label'>read_control:</span> <span class='int'>1</span><span class='comma'>,</span>
|
|
<span class='label'>key_enumerate_sub_keys:</span> <span class='int'>1</span><span class='comma'>,</span>
|
|
<span class='label'>key_query_value:</span> <span class='int'>1</span>
|
|
<span class='rbrace'>}</span><span class='rparen'>)</span>
|
|
<span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp.html" title="Rex::Proto::MsDtyp (module)">MsDtyp</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp/MsDtypAce.html" title="Rex::Proto::MsDtyp::MsDtypAce (class)">MsDtypAce</a></span></span><span class='period'>.</span><span class='id identifier rubyid_new'>new</span><span class='lparen'>(</span><span class='lbrace'>{</span>
|
|
<span class='label'>header:</span> <span class='lbrace'>{</span>
|
|
<span class='label'>ace_type:</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp.html" title="Rex::Proto::MsDtyp (module)">MsDtyp</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp/MsDtypAceType.html" title="Rex::Proto::MsDtyp::MsDtypAceType (class)">MsDtypAceType</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp/MsDtypAceType.html#ACCESS_ALLOWED_ACE_TYPE-constant" title="Rex::Proto::MsDtyp::MsDtypAceType::ACCESS_ALLOWED_ACE_TYPE (constant)">ACCESS_ALLOWED_ACE_TYPE</a></span></span><span class='comma'>,</span>
|
|
<span class='label'>ace_flags:</span> <span class='lbrace'>{</span> <span class='label'>container_inherit_ace:</span> <span class='int'>1</span> <span class='rbrace'>}</span>
|
|
<span class='rbrace'>}</span><span class='comma'>,</span>
|
|
<span class='label'>body:</span> <span class='lbrace'>{</span>
|
|
<span class='label'>access_mask:</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp.html" title="Rex::Proto::MsDtyp (module)">MsDtyp</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/MsDtyp/MsDtypAccessMask.html" title="Rex::Proto::MsDtyp::MsDtypAccessMask (class)">MsDtypAccessMask</a></span></span><span class='period'>.</span><span class='id identifier rubyid_read'>read</span><span class='lparen'>(</span><span class='id identifier rubyid_access_mask'>access_mask</span><span class='period'>.</span><span class='id identifier rubyid_to_binary_s'>to_binary_s</span><span class='rparen'>)</span><span class='comma'>,</span>
|
|
<span class='label'>sid:</span> <span class='id identifier rubyid_sid'>sid</span>
|
|
<span class='rbrace'>}</span>
|
|
<span class='rbrace'>}</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="delete_backup_file-instance_method">
|
|
|
|
#<strong>delete_backup_file</strong>(path = backup_file_path) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
79
|
|
80
|
|
81</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 79</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_delete_backup_file'>delete_backup_file</span><span class='lparen'>(</span><span class='id identifier rubyid_path'>path</span> <span class='op'>=</span> <span class='id identifier rubyid_backup_file_path'>backup_file_path</span><span class='rparen'>)</span>
|
|
<span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_delete'>delete</span><span class='lparen'>(</span><span class='id identifier rubyid_path'>path</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_file?'>file?</span><span class='lparen'>(</span><span class='id identifier rubyid_path'>path</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="enum_key-instance_method">
|
|
|
|
#<strong>enum_key</strong>(key) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
136
|
|
137
|
|
138
|
|
139
|
|
140
|
|
141
|
|
142
|
|
143</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 136</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_enum_key'>enum_key</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_backup'>sd_backup</span> <span class='op'>=</span> <span class='id identifier rubyid_change_dacl'>change_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz.html" title="Rex::Proto::Secauthz (module)">Secauthz</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html" title="Rex::Proto::Secauthz::WellKnownSids (module)">WellKnownSids</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html#DOMAIN_ALIAS_SID_ADMINS-constant" title="Rex::Proto::Secauthz::WellKnownSids::DOMAIN_ALIAS_SID_ADMINS (constant)">DOMAIN_ALIAS_SID_ADMINS</a></span></span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span>
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_enum_registry_key'>enum_registry_key</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='label'>bind:</span> <span class='kw'>false</span><span class='rparen'>)</span><span class='period'>.</span><span class='id identifier rubyid_map'>map</span> <span class='kw'>do</span> <span class='op'>|</span><span class='id identifier rubyid_key'>key</span><span class='op'>|</span>
|
|
<span class='id identifier rubyid_key'>key</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='period'>.</span><span class='id identifier rubyid_encode'>encode</span><span class='lparen'>(</span><span class='op'>::</span><span class='const'>Encoding</span><span class='op'>::</span><span class='const'>ASCII_8BIT</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span>
|
|
<span class='kw'>ensure</span>
|
|
<span class='id identifier rubyid_restore_dacl'>restore_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span> <span class='op'>&&</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="enum_values-instance_method">
|
|
|
|
#<strong>enum_values</strong>(key) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
127
|
|
128
|
|
129
|
|
130
|
|
131
|
|
132
|
|
133
|
|
134</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 127</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_enum_values'>enum_values</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_backup'>sd_backup</span> <span class='op'>=</span> <span class='id identifier rubyid_change_dacl'>change_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz.html" title="Rex::Proto::Secauthz (module)">Secauthz</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html" title="Rex::Proto::Secauthz::WellKnownSids (module)">WellKnownSids</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html#DOMAIN_ALIAS_SID_ADMINS-constant" title="Rex::Proto::Secauthz::WellKnownSids::DOMAIN_ALIAS_SID_ADMINS (constant)">DOMAIN_ALIAS_SID_ADMINS</a></span></span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span>
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_enum_registry_values'>enum_registry_values</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='label'>bind:</span> <span class='kw'>false</span><span class='rparen'>)</span><span class='period'>.</span><span class='id identifier rubyid_map'>map</span> <span class='kw'>do</span> <span class='op'>|</span><span class='id identifier rubyid_value'>value</span><span class='op'>|</span>
|
|
<span class='id identifier rubyid_value'>value</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='period'>.</span><span class='id identifier rubyid_encode'>encode</span><span class='lparen'>(</span><span class='op'>::</span><span class='const'>Encoding</span><span class='op'>::</span><span class='const'>ASCII_8BIT</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span>
|
|
<span class='kw'>ensure</span>
|
|
<span class='id identifier rubyid_restore_dacl'>restore_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span> <span class='op'>&&</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="get_value-instance_method">
|
|
|
|
#<strong>get_value</strong>(key, value_name = nil) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
145
|
|
146
|
|
147
|
|
148
|
|
149
|
|
150
|
|
151
|
|
152
|
|
153
|
|
154
|
|
155
|
|
156
|
|
157
|
|
158
|
|
159
|
|
160</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 145</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_get_value'>get_value</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_value_name'>value_name</span> <span class='op'>=</span> <span class='kw'>nil</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_backup'>sd_backup</span> <span class='op'>=</span> <span class='id identifier rubyid_change_dacl'>change_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='const'><span class='object_link'><a href="../../../Rex.html" title="Rex (module)">Rex</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto.html" title="Rex::Proto (module)">Proto</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz.html" title="Rex::Proto::Secauthz (module)">Secauthz</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html" title="Rex::Proto::Secauthz::WellKnownSids (module)">WellKnownSids</a></span></span><span class='op'>::</span><span class='const'><span class='object_link'><a href="../../../Rex/Proto/Secauthz/WellKnownSids.html#DOMAIN_ALIAS_SID_ADMINS-constant" title="Rex::Proto::Secauthz::WellKnownSids::DOMAIN_ALIAS_SID_ADMINS (constant)">DOMAIN_ALIAS_SID_ADMINS</a></span></span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span>
|
|
<span class='id identifier rubyid_root_key'>root_key</span><span class='comma'>,</span> <span class='id identifier rubyid_sub_key'>sub_key</span> <span class='op'>=</span> <span class='id identifier rubyid_key'>key</span><span class='period'>.</span><span class='id identifier rubyid_gsub'>gsub</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>/</span><span class='tstring_end'>'</span></span><span class='comma'>,</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>\\</span><span class='tstring_end'>'</span></span><span class='rparen'>)</span><span class='period'>.</span><span class='id identifier rubyid_split'>split</span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>\\</span><span class='tstring_end'>'</span></span><span class='comma'>,</span> <span class='int'>2</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_root_key_handle'>root_key_handle</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_open_root_key'>open_root_key</span><span class='lparen'>(</span><span class='id identifier rubyid_root_key'>root_key</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_subkey_handle'>subkey_handle</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_open_key'>open_key</span><span class='lparen'>(</span><span class='id identifier rubyid_root_key_handle'>root_key_handle</span><span class='comma'>,</span> <span class='id identifier rubyid_sub_key'>sub_key</span><span class='rparen'>)</span>
|
|
<span class='kw'>begin</span>
|
|
<span class='id identifier rubyid_reg_value'>reg_value</span> <span class='op'>=</span> <span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_query_value'>query_value</span><span class='lparen'>(</span><span class='id identifier rubyid_subkey_handle'>subkey_handle</span><span class='comma'>,</span> <span class='id identifier rubyid_value_name'>value_name</span><span class='period'>.</span><span class='id identifier rubyid_nil?'>nil?</span> <span class='op'>?</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_end'>'</span></span> <span class='op'>:</span> <span class='id identifier rubyid_value_name'>value_name</span><span class='rparen'>)</span>
|
|
<span class='lbracket'>[</span><span class='id identifier rubyid_reg_value'>reg_value</span><span class='period'>.</span><span class='id identifier rubyid_type'>type</span><span class='period'>.</span><span class='id identifier rubyid_to_i'>to_i</span><span class='comma'>,</span> <span class='id identifier rubyid_reg_value'>reg_value</span><span class='period'>.</span><span class='id identifier rubyid_data'>data</span><span class='period'>.</span><span class='id identifier rubyid_to_s'>to_s</span><span class='period'>.</span><span class='id identifier rubyid_b'>b</span><span class='rbracket'>]</span>
|
|
<span class='kw'>rescue</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Dcerpc</span><span class='op'>::</span><span class='const'>Error</span><span class='op'>::</span><span class='const'>WinregError</span>
|
|
<span class='kw'>nil</span>
|
|
<span class='kw'>end</span>
|
|
<span class='kw'>ensure</span>
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_close_key'>close_key</span><span class='lparen'>(</span><span class='id identifier rubyid_subkey_handle'>subkey_handle</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='id identifier rubyid_subkey_handle'>subkey_handle</span>
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_close_key'>close_key</span><span class='lparen'>(</span><span class='id identifier rubyid_root_key_handle'>root_key_handle</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='id identifier rubyid_root_key_handle'>root_key_handle</span>
|
|
<span class='id identifier rubyid_restore_dacl'>restore_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span><span class='rparen'>)</span> <span class='kw'>if</span> <span class='ivar'>@inline</span> <span class='op'>&&</span> <span class='id identifier rubyid_sd_backup'>sd_backup</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="read_from_file-instance_method">
|
|
|
|
#<strong>read_from_file</strong>(filepath) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
73
|
|
74
|
|
75
|
|
76
|
|
77</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 73</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_read_from_file'>read_from_file</span><span class='lparen'>(</span><span class='id identifier rubyid_filepath'>filepath</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_info'>sd_info</span> <span class='op'>=</span> <span class='const'>YAML</span><span class='period'>.</span><span class='id identifier rubyid_safe_load_file'>safe_load_file</span><span class='lparen'>(</span><span class='id identifier rubyid_filepath'>filepath</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_info'>sd_info</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>security_info</span><span class='tstring_end'>'</span></span><span class='rbracket'>]</span> <span class='op'>=</span> <span class='id identifier rubyid_sd_info'>sd_info</span><span class='lbracket'>[</span><span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>security_info</span><span class='tstring_end'>'</span></span><span class='rbracket'>]</span><span class='period'>.</span><span class='id identifier rubyid_to_i'>to_i</span>
|
|
<span class='id identifier rubyid_sd_info'>sd_info</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="restore_dacl-instance_method">
|
|
|
|
#<strong>restore_dacl</strong>(key, security_descriptor) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
107
|
|
108
|
|
109
|
|
110
|
|
111
|
|
112
|
|
113
|
|
114
|
|
115
|
|
116
|
|
117
|
|
118
|
|
119
|
|
120
|
|
121
|
|
122
|
|
123
|
|
124
|
|
125</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 107</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_restore_dacl'>restore_dacl</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='rparen'>)</span>
|
|
<span class='kw'>begin</span>
|
|
<span class='id identifier rubyid_dlog'><span class='object_link'><a href="../../../top-level-namespace.html#dlog-instance_method" title="#dlog (method)">dlog</a></span></span><span class='lparen'>(</span><span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] Restoring DACL on key `</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_key'>key</span><span class='embexpr_end'>}</span><span class='tstring_content'>`</span><span class='tstring_end'>"</span></span><span class='rparen'>)</span>
|
|
<span class='ivar'>@winreg</span><span class='period'>.</span><span class='id identifier rubyid_set_key_security_descriptor'>set_key_security_descriptor</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='comma'>,</span> <span class='const'>RubySMB</span><span class='op'>::</span><span class='const'>Field</span><span class='op'>::</span><span class='const'>SecurityDescriptor</span><span class='op'>::</span><span class='const'>DACL_SECURITY_INFORMATION</span><span class='comma'>,</span> <span class='label'>bind:</span> <span class='kw'>false</span><span class='rparen'>)</span>
|
|
<span class='kw'>rescue</span> <span class='const'>StandardError</span> <span class='op'>=></span> <span class='id identifier rubyid_e'>e</span>
|
|
<span class='id identifier rubyid_elog'><span class='object_link'><a href="../../../top-level-namespace.html#elog-instance_method" title="#elog (method)">elog</a></span></span><span class='lparen'>(</span>
|
|
<span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>[Msf::Util::WindowsRegistry::RemoteRegistry] Error while restoring DACL on key `</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_key'>key</span><span class='embexpr_end'>}</span><span class='tstring_content'>`: </span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_e'>e</span><span class='embexpr_end'>}</span><span class='tstring_content'>\n</span><span class='tstring_end'>"</span></span>\
|
|
<span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>The original security descriptor has been saved in `</span><span class='embexpr_beg'>#{</span><span class='id identifier rubyid_backup_file_path'>backup_file_path</span><span class='embexpr_end'>}</span><span class='tstring_content'>`. </span><span class='tstring_end'>"</span></span>\
|
|
<span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>The auxiliary module `admin/registry_security_descriptor` can be used to </span><span class='tstring_end'>"</span></span>\
|
|
<span class='tstring'><span class='tstring_beg'>"</span><span class='tstring_content'>restore the security descriptor from this file.</span><span class='tstring_end'>"</span></span>
|
|
<span class='rparen'>)</span>
|
|
<span class='comment'># Reset the `backup_file_path` instance variable to make sure a new
|
|
</span> <span class='comment'># backup filename will be generated. This way, this backup file won't
|
|
</span> <span class='comment'># be deleted the next time `#restore_dacl` is called.
|
|
</span> <span class='ivar'>@backup_file_path</span> <span class='op'>=</span> <span class='kw'>nil</span>
|
|
<span class='kw'>return</span>
|
|
<span class='kw'>end</span>
|
|
<span class='id identifier rubyid_delete_backup_file'>delete_backup_file</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
<div class="method_details ">
|
|
<h3 class="signature " id="save_to_file-instance_method">
|
|
|
|
#<strong>save_to_file</strong>(key, security_descriptor, security_information, path = backup_file_path) ⇒ <tt>Object</tt>
|
|
|
|
|
|
|
|
|
|
|
|
</h3><table class="source_code">
|
|
<tr>
|
|
<td>
|
|
<pre class="lines">
|
|
|
|
|
|
62
|
|
63
|
|
64
|
|
65
|
|
66
|
|
67
|
|
68
|
|
69
|
|
70
|
|
71</pre>
|
|
</td>
|
|
<td>
|
|
<pre class="code"><span class="info file"># File 'lib/msf/util/windows_registry/remote_registry.rb', line 62</span>
|
|
|
|
<span class='kw'>def</span> <span class='id identifier rubyid_save_to_file'>save_to_file</span><span class='lparen'>(</span><span class='id identifier rubyid_key'>key</span><span class='comma'>,</span> <span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='comma'>,</span> <span class='id identifier rubyid_security_information'>security_information</span><span class='comma'>,</span> <span class='id identifier rubyid_path'>path</span> <span class='op'>=</span> <span class='id identifier rubyid_backup_file_path'>backup_file_path</span><span class='rparen'>)</span>
|
|
<span class='id identifier rubyid_sd_info'>sd_info</span> <span class='op'>=</span> <span class='lbrace'>{</span>
|
|
<span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>key</span><span class='tstring_end'>'</span></span> <span class='op'>=></span> <span class='id identifier rubyid_key'>key</span><span class='comma'>,</span>
|
|
<span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>security_info</span><span class='tstring_end'>'</span></span> <span class='op'>=></span> <span class='id identifier rubyid_security_information'>security_information</span><span class='comma'>,</span>
|
|
<span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>sd</span><span class='tstring_end'>'</span></span> <span class='op'>=></span> <span class='id identifier rubyid_security_descriptor'>security_descriptor</span><span class='period'>.</span><span class='id identifier rubyid_b'>b</span><span class='period'>.</span><span class='id identifier rubyid_bytes'>bytes</span><span class='period'>.</span><span class='id identifier rubyid_map'>map</span> <span class='lbrace'>{</span> <span class='op'>|</span><span class='id identifier rubyid_c'>c</span><span class='op'>|</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>%02x</span><span class='tstring_end'>'</span></span> <span class='op'>%</span> <span class='id identifier rubyid_c'>c</span><span class='period'>.</span><span class='id identifier rubyid_ord'>ord</span> <span class='rbrace'>}</span><span class='period'>.</span><span class='id identifier rubyid_join'><span class='object_link'><a href="../../../top-level-namespace.html#join-instance_method" title="#join (method)">join</a></span></span>
|
|
<span class='rbrace'>}</span>
|
|
<span class='const'>File</span><span class='period'>.</span><span class='id identifier rubyid_open'>open</span><span class='lparen'>(</span><span class='id identifier rubyid_path'>path</span><span class='comma'>,</span> <span class='tstring'><span class='tstring_beg'>'</span><span class='tstring_content'>w</span><span class='tstring_end'>'</span></span><span class='rparen'>)</span> <span class='kw'>do</span> <span class='op'>|</span><span class='id identifier rubyid_fd'>fd</span><span class='op'>|</span>
|
|
<span class='id identifier rubyid_fd'>fd</span><span class='period'>.</span><span class='id identifier rubyid_write'>write</span><span class='lparen'>(</span><span class='id identifier rubyid_sd_info'>sd_info</span><span class='period'>.</span><span class='id identifier rubyid_to_yaml'>to_yaml</span><span class='rparen'>)</span>
|
|
<span class='kw'>end</span>
|
|
<span class='kw'>end</span></pre>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
<div id="footer">
|
|
Generated on Fri May 8 17:03:43 2026 by
|
|
<a href="https://yardoc.org" title="Yay! A Ruby Documentation Tool" target="_parent">yard</a>
|
|
0.9.37 (ruby-3.1.5).
|
|
</div>
|
|
|
|
</div>
|
|
</body>
|
|
</html> |