-
Notifications
You must be signed in to change notification settings - Fork 10
/
Copy pathnetlogon.go
80 lines (63 loc) · 1.83 KB
/
netlogon.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
//go:build exclude
package main
// netlogon.go script gets the domain info from the remote server.
import (
"context"
"encoding/json"
"fmt"
"os"
"github.com/oiweiwei/go-msrpc/dcerpc"
"github.com/oiweiwei/go-msrpc/msrpc/epm/epm/v3"
"github.com/oiweiwei/go-msrpc/msrpc/nrpc/logon/v1"
"github.com/rs/zerolog"
"github.com/oiweiwei/go-msrpc/ssp"
"github.com/oiweiwei/go-msrpc/ssp/credential"
"github.com/oiweiwei/go-msrpc/ssp/gssapi"
_ "github.com/oiweiwei/go-msrpc/msrpc/erref/win32"
)
func init() {
// add credentials.
gssapi.AddCredential(credential.NewFromPassword(os.Getenv("USERNAME"), os.Getenv("PASSWORD")))
// add mechanism.
gssapi.AddMechanism(ssp.SPNEGO)
gssapi.AddMechanism(ssp.NTLM)
}
func j(v any) string {
b, _ := json.MarshalIndent(v, "", " ")
return string(b)
}
func main() {
ctx := gssapi.NewSecurityContext(context.Background())
cc, err := dcerpc.Dial(ctx, os.Getenv("SERVER"), dcerpc.WithLogger(zerolog.New(os.Stdout)), epm.EndpointMapper(ctx, os.Getenv("SERVER"), dcerpc.WithLogger(zerolog.New(os.Stdout))))
if err != nil {
fmt.Fprintln(os.Stderr, err)
return
}
cli, err := logon.NewLogonClient(ctx, cc, dcerpc.WithSign())
if err != nil {
fmt.Fprintln(os.Stderr, err)
return
}
resp, err := cli.GetDCName(ctx, &logon.GetDCNameRequest{
ComputerName: "PC$",
Flags: logon.DSReturnDNSName | logon.DSIPRequired,
})
if err != nil {
fmt.Fprintln(os.Stderr, err)
return
}
fmt.Printf("%s\n", j(resp.DomainControllerInfo))
// do valid call.
trusts, err := cli.EnumerateDomainTrusts(ctx, &logon.EnumerateDomainTrustsRequest{
ServerName: resp.DomainControllerInfo.DomainControllerName,
Flags: logon.TrustTypeForestMember,
})
if err != nil {
fmt.Println(j(trusts))
fmt.Fprintln(os.Stderr, err)
return
}
for _, dom := range trusts.Domains.Domains {
fmt.Println(j(dom))
}
}