-
Notifications
You must be signed in to change notification settings - Fork 13.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add Group Policy Preferences (creds) support to db_import #10507
Changes from all commits
b1c633f
6fa0495
1e4eb0e
2891255
9b3e0d8
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,41 @@ | ||
require 'rex/parser/group_policy_preferences' | ||
|
||
module Msf::DBManager::Import::GPP | ||
def import_gpp_xml(args = {}, &block) | ||
return unless args && args[:data] && !args[:data].empty? | ||
|
||
gpp = Rex::Parser::GPP.parse(args[:data]) | ||
|
||
return unless gpp && gpp.any? | ||
|
||
wspace = find_workspace(args[:workspace]) | ||
|
||
return unless wspace && wspace.respond_to?(:id) | ||
|
||
gpp.each do |p| | ||
# Skip incomplete creds | ||
next unless p[:USER] && p[:PASS] | ||
|
||
# Store decrypted creds | ||
create_credential( | ||
workspace_id: wspace.id, | ||
origin_type: :import, | ||
filename: args[:filename], | ||
username: p[:USER], | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
|
||
private_data: p[:PASS], | ||
private_type: :password | ||
) | ||
end | ||
|
||
# Store entire file as loot, including metadata | ||
report_loot( | ||
workspace: wspace, | ||
path: args[:filename], | ||
name: File.basename(args[:filename]), | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Not sure I see the point of this if it's just the basename. But it fills in a column. |
||
data: args[:data], | ||
type: 'microsoft.windows.gpp', | ||
ctype: 'text/xml', | ||
info: gpp | ||
) | ||
end | ||
end |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
RSpec.shared_examples_for 'Msf::DBManager::Import::GPP' do | ||
it { is_expected.to respond_to :import_gpp_xml } | ||
end |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm leaving the name as
GPP
for future expansion... and I'm more liable to screw up the rename now.