Class: RubySMB::Client

Inherits:
Object
  • Object
show all
Includes:
Authentication, Echo, Negotiation, Signing, TreeConnect, Utils
Defined in:
lib/ruby_smb/client.rb,
lib/ruby_smb/client/echo.rb,
lib/ruby_smb/client/utils.rb,
lib/ruby_smb/client/signing.rb,
lib/ruby_smb/client/negotiation.rb,
lib/ruby_smb/client/tree_connect.rb,
lib/ruby_smb/client/authentication.rb

Overview

This module holds all of the methods backing the #open_file method

Defined Under Namespace

Modules: Authentication, Echo, Negotiation, Signing, TreeConnect, Utils

Constant Summary collapse

SMB1_DIALECT_SMB1_DEFAULT =

The Default SMB1 Dialect string used in an SMB1 Negotiate Request

'NT LM 0.12'.freeze
SMB1_DIALECT_SMB2_DEFAULT =

The Default SMB2 Dialect string used in an SMB1 Negotiate Request

'SMB 2.002'.freeze
SMB2_DIALECT_DEFAULT =

Dialect value for SMB2 Default (Version 2.02)

0x0202
MAX_BUFFER_SIZE =

The default maximum size of a SMB message that the Client accepts (in bytes)

4356

Instance Attribute Summary collapse

Attributes included from Utils

#auth_user, #evasion_opts, #last_file_id, #native_lm, #native_os, #open_files, #send_lm, #send_ntlm, #spnopt, #tree_connects, #use_lanman_key, #use_ntlmv2, #usentlm2_session, #verify_signature

Attributes included from Signing

#session_key

Instance Method Summary collapse

Methods included from Utils

#close, #create_pipe, #last_file, #last_tree, #last_tree_id, #open, #read, #tree_disconnect, #write

Methods included from Echo

#smb1_echo, #smb2_echo

Methods included from TreeConnect

#smb1_tree_connect, #smb1_tree_from_response, #smb2_tree_connect, #smb2_tree_from_response

Methods included from Signing

#smb1_sign, #smb2_sign

Methods included from Authentication

#authenticate, #extract_os_version, #smb1_anonymous_auth, #smb1_anonymous_auth_request, #smb1_anonymous_auth_response, #smb1_authenticate, #smb1_ntlmssp_auth_packet, #smb1_ntlmssp_authenticate, #smb1_ntlmssp_challenge_packet, #smb1_ntlmssp_final_packet, #smb1_ntlmssp_negotiate, #smb1_ntlmssp_negotiate_packet, #smb1_type2_message, #smb2_authenticate, #smb2_ntlmssp_auth_packet, #smb2_ntlmssp_authenticate, #smb2_ntlmssp_challenge_packet, #smb2_ntlmssp_final_packet, #smb2_ntlmssp_negotiate, #smb2_ntlmssp_negotiate_packet, #smb2_type2_message, #store_target_info

Methods included from Negotiation

#negotiate, #negotiate_request, #negotiate_response, #parse_negotiate_response, #smb1_negotiate_request, #smb2_negotiate_request

Constructor Details

#initialize(dispatcher, smb1: true, smb2: true, username:, password:, domain: '.', local_workstation: 'WORKSTATION') ⇒ Client

Returns a new instance of Client.

Parameters:

  • the packet dispatcher to use

  • (defaults to: true)

    whether or not to enable SMB1 support

  • (defaults to: true)

    whether or not to enable SMB2 support

Raises:



158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
# File 'lib/ruby_smb/client.rb', line 158

def initialize(dispatcher, smb1: true, smb2: true, username:, password:, domain: '.', local_workstation: 'WORKSTATION')
  raise ArgumentError, 'No Dispatcher provided' unless dispatcher.is_a? RubySMB::Dispatcher::Base
  if smb1 == false && smb2 == false
    raise ArgumentError, 'You must enable at least one Protocol'
  end
  @dispatcher        = dispatcher
  @domain            = domain
  @local_workstation = local_workstation
  @password          = password.encode('utf-8') || ''.encode('utf-8')
  @sequence_counter  = 0
  @session_id        = 0x00
  @session_key       = ''
  @signing_required  = false
  @smb1              = smb1
  @smb2              = smb2
  @username          = username.encode('utf-8') || ''.encode('utf-8')
  @max_buffer_size   = MAX_BUFFER_SIZE

  negotiate_version_flag = 0x02000000
  flags = Net::NTLM::Client::DEFAULT_FLAGS |
    Net::NTLM::FLAGS[:TARGET_INFO] |
    negotiate_version_flag

  @ntlm_client = Net::NTLM::Client.new(
    @username,
    @password,
    workstation: @local_workstation,
    domain: @domain,
    flags: flags
  )
  
  @tree_connects = []
  @open_files = {}

  @smb2_message_id = 0
end

Instance Attribute Details

#default_domain ⇒ String

Returns:



80
81
82
# File 'lib/ruby_smb/client.rb', line 80

def default_domain
  @default_domain
end

#default_name ⇒ String

Returns:



75
76
77
# File 'lib/ruby_smb/client.rb', line 75

def default_name
  @default_name
end

#dialect ⇒ Integer

Returns:



105
106
107
# File 'lib/ruby_smb/client.rb', line 105

def dialect
  @dialect
end

#dispatcher ⇒ RubySMB::Dispatcher::Socket

Returns:



31
32
33
# File 'lib/ruby_smb/client.rb', line 31

def dispatcher
  @dispatcher
end

#dns_domain_name ⇒ String

Returns:



90
91
92
# File 'lib/ruby_smb/client.rb', line 90

def dns_domain_name
  @dns_domain_name
end

#dns_host_name ⇒ String

Returns:



85
86
87
# File 'lib/ruby_smb/client.rb', line 85

def dns_host_name
  @dns_host_name
end

#dns_tree_name ⇒ String

Returns:



95
96
97
# File 'lib/ruby_smb/client.rb', line 95

def dns_tree_name
  @dns_tree_name
end

#domain ⇒ String

Returns:



36
37
38
# File 'lib/ruby_smb/client.rb', line 36

def domain
  @domain
end

#local_workstation ⇒ String

Returns:



41
42
43
# File 'lib/ruby_smb/client.rb', line 41

def local_workstation
  @local_workstation
end

#max_buffer_size ⇒ Integer

Returns:



153
154
155
# File 'lib/ruby_smb/client.rb', line 153

def max_buffer_size
  @max_buffer_size
end

#ntlm_client ⇒ String

Returns:



46
47
48
# File 'lib/ruby_smb/client.rb', line 46

def ntlm_client
  @ntlm_client
end

#os_version ⇒ String

Returns:



100
101
102
# File 'lib/ruby_smb/client.rb', line 100

def os_version
  @os_version
end

#password ⇒ String

Returns:



51
52
53
# File 'lib/ruby_smb/client.rb', line 51

def password
  @password
end

#peer_native_lm ⇒ String

Returns:



63
64
65
# File 'lib/ruby_smb/client.rb', line 63

def peer_native_lm
  @peer_native_lm
end

#peer_native_os ⇒ String

Returns:



57
58
59
# File 'lib/ruby_smb/client.rb', line 57

def peer_native_os
  @peer_native_os
end

#primary_domain ⇒ String

Returns:



70
71
72
# File 'lib/ruby_smb/client.rb', line 70

def primary_domain
  @primary_domain
end

#sequence_counter ⇒ Integer

Returns:



112
113
114
# File 'lib/ruby_smb/client.rb', line 112

def sequence_counter
  @sequence_counter
end

#session_id ⇒ Integer

Returns:



117
118
119
# File 'lib/ruby_smb/client.rb', line 117

def session_id
  @session_id
end

#signing_enabled ⇒ Boolean

Returns:



122
# File 'lib/ruby_smb/client.rb', line 122

attr_accessor :signing_required

#signing_required ⇒ Object

Whether or not the Server requires signing



122
123
124
# File 'lib/ruby_smb/client.rb', line 122

def signing_required
  @signing_required
end

#smb1 ⇒ Boolean

Returns:



127
128
129
# File 'lib/ruby_smb/client.rb', line 127

def smb1
  @smb1
end

#smb2 ⇒ Boolean

Returns:



132
133
134
# File 'lib/ruby_smb/client.rb', line 132

def smb2
  @smb2
end

#smb2_message_id ⇒ Integer

Returns:



137
138
139
# File 'lib/ruby_smb/client.rb', line 137

def smb2_message_id
  @smb2_message_id
end

#user_id ⇒ String

Returns:



147
148
149
# File 'lib/ruby_smb/client.rb', line 147

def user_id
  @user_id
end

#username ⇒ String

Returns:



142
143
144
# File 'lib/ruby_smb/client.rb', line 142

def username
  @username
end

Instance Method Details

#disconnect! ⇒ void

This method returns an undefined value.

Logs off any currently open session on the server and closes the TCP socket connection.



199
200
201
202
203
204
205
206
# File 'lib/ruby_smb/client.rb', line 199

def disconnect!
  begin
    logoff!
  rescue
    wipe_state!
  end
  dispatcher.tcp_socket.close
end

#echo(count: 1, data: '') ⇒ WindowsError::ErrorCode

Sends an Echo request to the server and returns the NTStatus of the last response packet received.

Parameters:

  • the number of times the server should echo (ignored in SMB2)

  • (defaults to: '')

    the data the server should echo back (ignored in SMB2)

Returns:

  • the NTStatus of the last response received



214
215
216
217
218
219
220
221
# File 'lib/ruby_smb/client.rb', line 214

def echo(count: 1, data: '')
  response = if smb2
               smb2_echo
             else
               smb1_echo(count: count, data: data)
             end
  response.status_code
end

#increment_smb_message_id(packet) ⇒ RubySMB::GenericPacket

Sets the message id field in an SMB2 packet's header to the one tracked by the client. It then increments the counter on the client.

Parameters:

  • the packet to set the message id for

Returns:

  • the modified packet



229
230
231
232
233
234
235
# File 'lib/ruby_smb/client.rb', line 229

def increment_smb_message_id(packet)
  if packet.smb2_header.message_id.zero? && smb2_message_id != 0
    packet.smb2_header.message_id = smb2_message_id
    self.smb2_message_id += 1
  end
  packet
end

#login(username: self.username, password: self.password, domain: self.domain, local_workstation: self.local_workstation) ⇒ Object

Performs protocol negotiation and session setup. It defaults to using the credentials supplied during initialization, but can take a new set of credentials if needed.



239
240
241
242
243
# File 'lib/ruby_smb/client.rb', line 239

def (username: self.username, password: self.password, domain: self.domain, local_workstation: self.local_workstation)
  negotiate
  session_setup(username, password, domain, true,
                local_workstation: local_workstation)
end

#logoff! ⇒ WindowsError::ErrorCode

Sends a LOGOFF command to the remote server to terminate the session

Returns:

  • the NTStatus of the response



271
272
273
274
275
276
277
278
279
280
281
282
283
# File 'lib/ruby_smb/client.rb', line 271

def logoff!
  if smb2
    request      = RubySMB::SMB2::Packet::LogoffRequest.new
    raw_response = send_recv(request)
    response     = RubySMB::SMB2::Packet::LogoffResponse.read(raw_response)
  else
    request      = RubySMB::SMB1::Packet::LogoffRequest.new
    raw_response = send_recv(request)
    response     = RubySMB::SMB1::Packet::LogoffResponse.read(raw_response)
  end
  wipe_state!
  response.status_code
end

#nb_name_encode(name) ⇒ Object



407
408
409
410
411
412
413
414
415
416
# File 'lib/ruby_smb/client.rb', line 407

def nb_name_encode(name)
  encoded_name = ''
  name.each_byte do |char|
    first_half = (char >> 4) + 'A'.ord
    second_half = (char & 0xF) + 'A'.ord
    encoded_name << first_half.chr
    encoded_name << second_half.chr
  end
  encoded_name
end

#net_share_enum_all(host) ⇒ Array

Returns array of shares

Parameters:

Returns:

  • of shares



330
331
332
333
334
335
336
# File 'lib/ruby_smb/client.rb', line 330

def net_share_enum_all(host)
  if smb2
    smb2_net_share_enum_all(host)
  else
    smb1_net_share_enum_all(host)
  end
end

#send_recv(packet) ⇒ String

Sends a packet and receives the raw response through the Dispatcher. It will also sign the packet if neccessary.

Parameters:

  • the request to be sent

Returns:

  • the raw response data received



290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
# File 'lib/ruby_smb/client.rb', line 290

def send_recv(packet)
  case packet.packet_smb_version
  when 'SMB1'
    packet.smb_header.uid = user_id if user_id
    packet = smb1_sign(packet)
  when 'SMB2'
    packet = increment_smb_message_id(packet)
    packet.smb2_header.session_id = session_id
    unless packet.is_a?(RubySMB::SMB2::Packet::SessionSetupRequest)
      packet = smb2_sign(packet)
    end
  else
    packet = packet
  end
  dispatcher.send_packet(packet)
  raw_response = dispatcher.recv_packet

  self.sequence_counter += 1 if signing_required && !session_key.empty?
  raw_response
end

#session_request(name = '*SMBSERVER') ⇒ TrueClass

Requests a NetBIOS Session Service using the provided name.

Parameters:

  • (defaults to: '*SMBSERVER')

    the NetBIOS name to request

Returns:

  • if session request is granted

Raises:

  • if session request is refused



386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
# File 'lib/ruby_smb/client.rb', line 386

def session_request(name = '*SMBSERVER')
  encoded_called_name = nb_name_encode("#{name.upcase.ljust(15)}\x20")
  encoded_calling_name = nb_name_encode("#{''.ljust(15)}\x00")

  session_request = RubySMB::Nbss::SessionRequest.new
  session_request.session_header.session_packet_type = RubySMB::Nbss::SESSION_REQUEST
  session_request.called_name  = "\x20#{encoded_called_name}\x00"
  session_request.calling_name = "\x20#{encoded_calling_name}\x00"
  session_request.session_header.packet_length = session_request.do_num_bytes - session_request.session_header.do_num_bytes

  dispatcher.send_packet(session_request, nbss_header: false)
  raw_response = dispatcher.recv_packet(full_response: true)
  session_header =  RubySMB::Nbss::SessionHeader.read(raw_response)
  if session_header.session_packet_type == RubySMB::Nbss::NEGATIVE_SESSION_RESPONSE
    negative_session_response =  RubySMB::Nbss::NegativeSessionResponse.read(raw_response)
    raise RubySMB::Error::NetBiosSessionService, "Session Request failed: #{negative_session_response.error_msg}"
  end

  return true
end

#session_setup(user, pass, domain, do_recv = true, local_workstation: self.local_workstation) ⇒ Object



245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
# File 'lib/ruby_smb/client.rb', line 245

def session_setup(user, pass, domain, do_recv=true,
                  local_workstation: self.local_workstation)
  @domain            = domain
  @local_workstation = local_workstation
  @password          = pass.encode('utf-8') || ''.encode('utf-8')
  @username          = user.encode('utf-8') || ''.encode('utf-8')

  negotiate_version_flag = 0x02000000
  flags = Net::NTLM::Client::DEFAULT_FLAGS |
    Net::NTLM::FLAGS[:TARGET_INFO] |
    negotiate_version_flag
  
  @ntlm_client = Net::NTLM::Client.new(
      @username,
      @password,
      workstation: @local_workstation,
      domain: @domain,
      flags: flags
  )

  authenticate
end

#smb2_net_share_enum_all(host) ⇒ Array

Sends a request to connect to a remote host and returns the Array of shares

Parameters:

Returns:

  • List of shares



347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
# File 'lib/ruby_smb/client.rb', line 347

def smb2_net_share_enum_all(host)

  tree = tree_connect("\\\\#{host}\\IPC$")

  named_pipe = tree.open_file(filename: "srvsvc",
                              write: true,
                              read: true,
                              disposition: RubySMB::Dispositions::FILE_OPEN_IF)

  handle = Dcerpc::Handle.new(named_pipe)

  handle.bind(endpoint: Dcerpc::Srvsvc)
  handle.request(
      opnum: Dcerpc::Srvsvc::NetShareEnumAll::Opnum,
      stub: Dcerpc::Srvsvc::NetShareEnumAll,
      options:{host: host}
  )
  shares = Dcerpc::Srvsvc::NetShareEnumAll.parse_response(handle.response)
  shares.map{|s|{name: s[0], type: s[1], comment: s[2]}}
end

#tree_connect(share) ⇒ RubySMB::SMB1::Tree, RubySMB::SMB2::Tree

Connects to the supplied share

Parameters:

  • the path to the share in \\server\share_name format

Returns:

  • if talking over SMB1

  • if talking over SMB2



316
317
318
319
320
321
322
323
324
# File 'lib/ruby_smb/client.rb', line 316

def tree_connect(share)
  connected_tree = if smb2
    smb2_tree_connect(share)
  else
    smb1_tree_connect(share)
  end
  @tree_connects << connected_tree
  connected_tree
end

#wipe_state! ⇒ void

This method returns an undefined value.

Resets all of the session state on the client, setting it back to scratch. Should only be called when a session is no longer valid.



373
374
375
376
377
378
379
# File 'lib/ruby_smb/client.rb', line 373

def wipe_state!
  self.session_id       = 0x00
  self.user_id          = 0x00
  self.session_key      = ''
  self.sequence_counter = 0
  self.smb2_message_id  = 0
end