forked from Gilks/enumerid
-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathenumerid.py
More file actions
executable file
·199 lines (167 loc) · 6.67 KB
/
Copy pathenumerid.py
File metadata and controls
executable file
·199 lines (167 loc) · 6.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
#!/usr/bin/python2
#
# hostmap.py
#
# Copyright 2017 Corey Gilks <CoreyGilks [at] gmail [dot] com>
# Twitter: @CoreyGilks
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 3 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
# MA 02110-1301, USA.
#
#
# This script was inspired by this article:
# https://www.blackhillsinfosec.com/password-spraying-other-fun-with-rpcclient/
from __future__ import print_function
import argparse
import logging
import os
import re
import socket
import sys
from threading import Thread, Lock
try:
from impacket.dcerpc.v5 import transport, samr
except ImportError:
print("You must install impacket before continuing")
sys.exit(os.EX_SOFTWARE)
HELP_EPILOG = """
Enumerate the specified RID. If no password is entered, you will be prompted for one. Target IP must be the domain
controller. In order to resolve DNS, you must specify the -d option.
Common RIDs:
Domain Computers: 515
Domain Controllers: 516
Domain Users: 513
Domain Admins: 512
Domain Guests: 514
Enterprise Admins: 519
"""
def impacket_compatibility(opts):
opts.domain, opts.username, opts.password, opts.target = re.compile('(?:(?:([^/@:]*)/)?([^@:]*)(?::([^@]*))?@)?(.*)').match(opts.target).groups('')
#In case the password contains '@'
if '@' in opts.target:
opts.password = opts.password + '@' + opts.target.rpartition('@')[0]
opts.target = opts.target.rpartition('@')[2]
if opts.domain is None:
opts.domain = ''
if not opts.password and opts.username and not opts.no_pass:
from getpass import getpass
opts.password = getpass("Password:")
class SAMRGroupDump:
def __init__(self, username, password, domain, target, rid, dns_lookup, output):
self.username = username
self.password = password
self.domain = domain
self.port = 445
self.target = target
self.rid = rid
self.dns_lookup = dns_lookup
self.log = logging.getLogger('')
self.output_file = ""
self.data = []
if output:
if not (output).endswith(".txt"):
output += ".txt"
self.output_file = output
@classmethod
def from_args(cls, args):
return cls(args.username, args.password, args.domain, args.target, args.rid, args.dns_lookup, args.output)
def dump(self):
self.log.info('[*] Retrieving endpoint list from {0}'.format(self.target))
stringbinding = r'ncacn_np:{0}[\pipe\samr]'.format(self.target)
logging.debug('StringBinding {0}'.format(stringbinding))
rpctransport = transport.DCERPCTransportFactory(stringbinding)
rpctransport.set_dport(self.port)
rpctransport.setRemoteHost(self.target)
if hasattr(rpctransport, 'set_credentials'):
rpctransport.set_credentials(self.username, self.password, self.domain)
self.__fetchlist(rpctransport)
def __fetchlist(self, rpctransport):
dce = rpctransport.get_dce_rpc()
dce.connect()
dce.bind(samr.MSRPC_UUID_SAMR)
resp = samr.hSamrConnect(dce)
serverHandle = resp['ServerHandle']
resp = samr.hSamrEnumerateDomainsInSamServer(dce, serverHandle)
domains = resp['Buffer']['Buffer']
self.log.info('[+] Found domain: {0}'.format(domains[0]['Name']))
self.log.info("[*] Enumerating RID {0} in the {1} domain..\n".format(self.rid, domains[0]['Name']))
resp = samr.hSamrLookupDomainInSamServer(dce, serverHandle, domains[0]['Name'])
resp = samr.hSamrOpenDomain(dce, serverHandle=serverHandle, domainId=resp['DomainId'])
domainHandle = resp['DomainHandle']
request = samr.SamrOpenGroup()
request['DomainHandle'] = domainHandle
request['DesiredAccess'] = samr.MAXIMUM_ALLOWED
request['GroupId'] = self.rid
try:
resp = dce.request(request)
except samr.DCERPCSessionError:
raise
request = samr.SamrGetMembersInGroup()
request['GroupHandle'] = resp['GroupHandle']
resp = dce.request(request)
rids = resp.fields['Members'].fields['Data'].fields['Members'].fields['Data'].fields['Data']
mutex = Lock()
for rid in rids:
try:
resp = samr.hSamrOpenUser(dce, domainHandle, samr.MAXIMUM_ALLOWED, rid.fields['Data'])
rid_data = samr.hSamrQueryInformationUser2(dce, resp['UserHandle'], samr.USER_INFORMATION_CLASS.UserAllInformation)
except samr.DCERPCSessionError as e:
# Occasionally an ACCESS_DENIED is rasied even though the user has permissions?
# Other times a STATUS_NO_SUCH_USER is raised when a rid apparently doesn't exist, even though it reported back as existing.
self.log.debug(e)
continue
rid_data = rid_data['Buffer']['All']['UserName'].replace('$', '')
samr.hSamrCloseHandle(dce, resp['UserHandle'])
if self.dns_lookup:
# Threading because DNS lookups are slow
t = Thread(target=self.get_ip, args=(rid_data, mutex,))
t.start()
else:
self.log.info(rid_data)
self.data.append(rid_data)
dce.disconnect()
def get_ip(self, hostname, mutex):
try:
ip = socket.gethostbyname(hostname)
rid_info = '{0}:{1}'.format(hostname, ip)
except socket.error:
rid_info = hostname
with mutex:
self.log.info(rid_info)
self.data.append(rid_info)
if __name__ == '__main__':
parser = argparse.ArgumentParser(epilog=HELP_EPILOG, formatter_class=argparse.RawTextHelpFormatter)
parser.add_argument('-L', dest='loglvl', action='store', choices=['DEBUG', 'INFO', 'WARNING', 'ERROR', 'CRITICAL'], default='INFO', help='set the logging level')
parser.add_argument('target', action='store', help='[[domain/]username[:password]@]<DC IP>')
parser.add_argument('-o', dest='output', help='Output filename')
parser.add_argument('-r', dest='rid', type=int, required=True, help='Enumerate the specified rid')
parser.add_argument('-d', dest='dns_lookup', default=False, action='store_true', help='Perform DNS lookup')
parser.add_argument('-n', '--no-pass', dest='no_pass', action="store_true", help='don\'t ask for password')
options = parser.parse_args()
impacket_compatibility(options)
logging.getLogger(logging.basicConfig(level=getattr(logging, options.loglvl), format=""))
try:
dumper = SAMRGroupDump.from_args(options)
dumper.dump()
except KeyboardInterrupt:
print("Exiting...")
except Exception as e:
print(e)
finally:
if not options.output:
sys.exit(os.EX_SOFTWARE)
output_file = open(options.output, 'a+')
for data in dumper.data:
output_file.write(str(data) + '\n')