Python impacket.dcerpc.v5.tsch.TASK_LOGON_NONE Examples
The following are 6
code examples of impacket.dcerpc.v5.tsch.TASK_LOGON_NONE().
You can vote up the ones you like or vote down the ones you don't like,
and go to the original project or source file by following the links above each example.
You may also want to check out all available functions/classes of the module
impacket.dcerpc.v5.tsch
, or try the search function
.
Example #1
Source File: taskexe.py From lsassy with MIT License | 6 votes |
def execute(self, commands): dce = self._rpctransport.get_dce_rpc() dce.set_credentials(*self._rpctransport.get_credentials()) if self._conn.kerberos: dce.set_auth_type(RPC_C_AUTHN_GSS_NEGOTIATE) dce.connect() dce.bind(tsch.MSRPC_UUID_TSCHS) xml = self.gen_xml(commands) tmpName = ''.join(random.choice(string.ascii_letters + string.digits) for _ in range(8)) self._log.debug("Register random task {}".format(tmpName)) tsch.hSchRpcRegisterTask(dce, '\\%s' % tmpName, xml, tsch.TASK_CREATE, NULL, tsch.TASK_LOGON_NONE) tsch.hSchRpcRun(dce, '\\%s' % tmpName) done = False while not done: resp = tsch.hSchRpcGetLastRunInfo(dce, '\\%s' % tmpName) if resp['pLastRuntime']['wYear'] != 0: done = True else: time.sleep(2) time.sleep(3) tsch.hSchRpcDelete(dce, '\\%s' % tmpName) dce.disconnect()
Example #2
Source File: test_tsch.py From CVE-2017-7494 with GNU General Public License v3.0 | 5 votes |
def tes_SchRpcRegisterTask(self): dce, rpctransport = self.connect(self.stringBindingAtSvc, tsch.MSRPC_UUID_TSCHS) xml = """ <!-- Task --> <xs:complexType name="taskType"> <xs:all> <xs:element name="RegistrationInfo" type="registrationInfoType" minOccurs="0"/> <xs:element name="Triggers" type="triggersType" minOccurs="0"/> <xs:element name="Settings" type="settingsType" minOccurs="0"/> <xs:element name="Data" type="dataType" minOccurs="0"/> <xs:element name="Principals" type="principalsType" minOccurs="0"/> <xs:element name="Actions" type="actionsType"/> </xs:all> <xs:attribute name="version" type="versionType" use="optional"/> </xs:complexType>\x00 """ request = tsch.SchRpcRegisterTask() request['path'] =NULL request['xml'] = xml request['flags'] = 1 request['sddl'] = NULL request['logonType'] = tsch.TASK_LOGON_NONE request['cCreds'] = 0 request['pCreds'] = NULL resp = dce.request(request) resp.dump()
Example #3
Source File: test_tsch.py From cracke-dit with MIT License | 5 votes |
def tes_SchRpcRegisterTask(self): dce, rpctransport = self.connect(self.stringBindingAtSvc, tsch.MSRPC_UUID_TSCHS) xml = """ <!-- Task --> <xs:complexType name="taskType"> <xs:all> <xs:element name="RegistrationInfo" type="registrationInfoType" minOccurs="0"/> <xs:element name="Triggers" type="triggersType" minOccurs="0"/> <xs:element name="Settings" type="settingsType" minOccurs="0"/> <xs:element name="Data" type="dataType" minOccurs="0"/> <xs:element name="Principals" type="principalsType" minOccurs="0"/> <xs:element name="Actions" type="actionsType"/> </xs:all> <xs:attribute name="version" type="versionType" use="optional"/> </xs:complexType>\x00 """ request = tsch.SchRpcRegisterTask() request['path'] =NULL request['xml'] = xml request['flags'] = 1 request['sddl'] = NULL request['logonType'] = tsch.TASK_LOGON_NONE request['cCreds'] = 0 request['pCreds'] = NULL resp = dce.request(request) resp.dump()
Example #4
Source File: test_tsch.py From Slackor with GNU General Public License v3.0 | 5 votes |
def tes_SchRpcRegisterTask(self): dce, rpctransport = self.connect(self.stringBindingAtSvc, tsch.MSRPC_UUID_TSCHS) xml = """ <!-- Task --> <xs:complexType name="taskType"> <xs:all> <xs:element name="RegistrationInfo" type="registrationInfoType" minOccurs="0"/> <xs:element name="Triggers" type="triggersType" minOccurs="0"/> <xs:element name="Settings" type="settingsType" minOccurs="0"/> <xs:element name="Data" type="dataType" minOccurs="0"/> <xs:element name="Principals" type="principalsType" minOccurs="0"/> <xs:element name="Actions" type="actionsType"/> </xs:all> <xs:attribute name="version" type="versionType" use="optional"/> </xs:complexType>\x00 """ request = tsch.SchRpcRegisterTask() request['path'] =NULL request['xml'] = xml request['flags'] = 1 request['sddl'] = NULL request['logonType'] = tsch.TASK_LOGON_NONE request['cCreds'] = 0 request['pCreds'] = NULL resp = dce.request(request) resp.dump()
Example #5
Source File: test_tsch.py From PiBunny with MIT License | 5 votes |
def tes_SchRpcRegisterTask(self): dce, rpctransport = self.connect(self.stringBindingAtSvc, tsch.MSRPC_UUID_TSCHS) xml = """ <!-- Task --> <xs:complexType name="taskType"> <xs:all> <xs:element name="RegistrationInfo" type="registrationInfoType" minOccurs="0"/> <xs:element name="Triggers" type="triggersType" minOccurs="0"/> <xs:element name="Settings" type="settingsType" minOccurs="0"/> <xs:element name="Data" type="dataType" minOccurs="0"/> <xs:element name="Principals" type="principalsType" minOccurs="0"/> <xs:element name="Actions" type="actionsType"/> </xs:all> <xs:attribute name="version" type="versionType" use="optional"/> </xs:complexType>\x00 """ request = tsch.SchRpcRegisterTask() request['path'] =NULL request['xml'] = xml request['flags'] = 1 request['sddl'] = NULL request['logonType'] = tsch.TASK_LOGON_NONE request['cCreds'] = 0 request['pCreds'] = NULL resp = dce.request(request) resp.dump()
Example #6
Source File: atexec.py From ActiveReign with GNU General Public License v3.0 | 4 votes |
def doStuff(self, command): dce = self.__rpctransport.get_dce_rpc() dce.set_credentials(*self.__rpctransport.get_credentials()) dce.connect() #dce.set_auth_level(ntlm.NTLM_AUTH_PKT_PRIVACY) dce.bind(tsch.MSRPC_UUID_TSCHS) tmpName = gen_random_string(8) tmpFileName = tmpName + '.tmp' xml = self.gen_xml(command) taskCreated = False self.logger.debug('Creating task \\{}'.format(tmpName)) tsch.hSchRpcRegisterTask(dce, '\\{}'.format(tmpName), xml, tsch.TASK_CREATE, NULL, tsch.TASK_LOGON_NONE) taskCreated = True self.logger.debug('Running task \\{}'.format(tmpName)) tsch.hSchRpcRun(dce, '\\{}'.format(tmpName)) done = False while not done: self.logger.debug('Calling SchRpcGetLastRunInfo for \\{}'.format(tmpName)) resp = tsch.hSchRpcGetLastRunInfo(dce, '\\{}'.format(tmpName)) if resp['pLastRuntime']['wYear'] != 0: done = True else: sleep(2) self.logger.debug('Deleting task \\{}'.format(tmpName)) tsch.hSchRpcDelete(dce, '\\{}'.format(tmpName)) taskCreated = False if taskCreated is True: tsch.hSchRpcDelete(dce, '\\{}'.format(tmpName)) # Get output if self.noOutput: self.__outputBuffer = "Command executed with no output" elif self.fileless_output: self.get_output_fileless() else: self.get_output() dce.disconnect()