o
    j7                  
   @   s  d dl mZ d dl mZ d dlZd dlZd dlZd dlmZ d dlm	Z	m
Z
mZ d dlmZ d dlmZmZ d dlmZmZ d d	lmZ d
d ZG dd dZedkrSeej ejdddZejdddd ejdddd ejdddd ejdddd ejdddd ejddd d ed!Zejd"dd#d$d% ejd&dd'd ejd(dd)d ejd*dd+d,d% ed-Zejd.dd/d0d% ejd1dd2d3d% eej d4kre!  e"d4 e# Z$e%e$j&e$j' ee$j(e$j)e$j*e$j+e$j,\Z-Z.Z/Z0Z0e$_,e-d5kre1d6 e"d4 e$j2re$j2Z3ne-Z3zee.e/e-e3e$Z4e45  W dS  e6yR Z7 ze8 j9ej:kr@d dl;Z;e;<  e=e>e7 W Y dZ7[7dS dZ7[7ww dS )7    )division)print_functionN)version)UF_ACCOUNTDISABLEUF_TRUSTED_FOR_DELEGATION)UF_TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION)logger)parse_identity
ldap_login)ldapldapasn1)	ldaptypesc                 C   sb   d}|dkrd| d }nd| }| j|ddgdd	}d
d |D }t|dkr-d}|S d}|S )N-N/Az(servicePrincipalName=HOST/%s)$z(servicePrincipalName=%s)servicePrincipalNamedistinguishedName   searchFilter
attributes	sizeLimitc                 S   s   g | ]
}t |tjr|qS  )
isinstancer   SearchResultEntry).0itemr   r   /root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/../../../bin/findDelegation.py
<listcomp>4       z$checkIfSPNExists.<locals>.<listcomp>r   YesNo)rstripsearchlen)ldapConnectionsAMAccountNamerights	spnExistsqueryrespSpnExistsresultsr   r   r   checkIfSPNExists'   s   r,   c                   @   s(   e Zd Zedd Zdd Zdd ZdS )FindDelegationc                    s   g }t |D ]\ }t fdd| D }|t|t| qddd t |D }t|j|  tddd |D  | D ]	}t|j|  qAd S )Nc                    s   g | ]}t |  qS r   )r$   )r   rowir   r   r   B   s    z-FindDelegation.printTable.<locals>.<listcomp> c                 S   s   g | ]
\}}d ||f qS )z	{%d:%ds} r   )r   numwidthr   r   r   r   E   r   z  c                 S   s   g | ]}d | qS )r   r   )r   itemLenr   r   r   r   I   s    )	enumeratemaxappendr$   joinprintformat)itemsheadercolLencol	rowMaxLenoutputFormatr.   r   r/   r   
printTable>   s   zFindDelegation.printTablec                 C   s   || _ || _|| _d | _|| _d| _d| _|j| _|j	| _
|j| _|j| _|j| _|j| _|jd ur<|jd\| _| _| jd}d| _|D ]}|  jd| 7  _qG| jd d | _|| jkrs| jsf| jrutd d | _d | _d S d S d S )N :.zdc=%s,zNKDC IP address and hostname will be ignored because of cross-domain targeting.)_FindDelegation__username_FindDelegation__password_FindDelegation__domain_FindDelegation__target_FindDelegation__targetDomain_FindDelegation__lmhash_FindDelegation__nthashaesKey_FindDelegation__aesKeyk_FindDelegation__doKerberosdc_ip_FindDelegation__kdcIPdc_host_FindDelegation__kdcHostuser_FindDelegation__requestUserdisabled_FindDelegation__disabledhashessplitbaseDNloggingwarning)selfusernamepassworduser_domaintarget_domaincmdLineOptionsdomainPartsr0   r   r   r   __init__O   s2   


zFindDelegation.__init__c                 C   s6  t | j| j| j| j| j| j| j| j| j	| j
| j| jdd}|j| _d}| jr+|d7 }n|d7 }| jd ur<|d| j 7 }n|d7 }z|j|g dd	d
}W n' tjys } z| ddkrhtd | }n W Y d }~nd }~ww g }tdt|  |D ]|}t|tjdurqd}d}d}	d}
d}g }d}zF|d D ]}t|d dkrt|d d }d}nct|d dkrt|d d }	t|	t@ rd}
|d nEt|	t @ rd}
d}n:t|d dkrt|d d !dd !dd }nt|d dkr|dkrd}
|d D ]
}|t| qt|d dkrg }g }d }t"j#t$|d d d!}|d" j%D ]}|d#|d$ d% &  d 7 }q:| jrU|d&7 }n|d'7 }|j|ddgd	d
}|D ]6}t|tjdurrqe|t|d d d d  |t|d d d d !dd !dd  qe|du rt'||D ]\}}t(|||}|||d(|t|g qq|
d)v r|du r|D ]}t(|||}||||
|t|g qW q t)y } zt*d*t|  W Y d }~qd }~ww t|dkr| j+|g d+d, t,d- d S t,d. d S )/NT)rb   fqdnz(&(|(UserAccountControl:1.2.840.113556.1.4.803:=16777216)(UserAccountControl:1.2.840.113556.1.4.803:=524288)(msDS-AllowedToDelegateTo=*)(msDS-AllowedToActOnBehalfOfOtherIdentity=*)z/)(UserAccountControl:1.2.840.113556.1.4.803:=2)z2)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))z(sAMAccountName:=%s))))r&   
pwdLastSetuserAccountControlobjectCategory(msDS-AllowedToActOnBehalfOfOtherIdentitymsDS-AllowedToDelegateToi  r   sizeLimitExceededr   zNsizeLimitExceeded exception caught, giving up and processing the data receivedzTotal of records returned %dFrB   r   typer&   valsri   Unconstrainedr   "Constrained w/ Protocol Transitionr   rj   =,rl   #Constrained w/o Protocol Transitionrk   z(&(|)dataDaclz(objectSid=AceSidz0)(UserAccountControl:1.2.840.113556.1.4.803:=2))z3)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))zResource-Based Constrained)rp   rt   rq   z-Skipping item, cannot process due to error %s)AccountNameAccountTypeDelegationTypeDelegationRightsToz
SPN Exists)r<   z

zNo entries found!)-r
   rI   r[   rR   rT   rP   rF   rG   rH   rK   rL   rN   rJ   _dstHostrX   rV   r#   r   LDAPSearchErrorgetErrorStringfindr\   debug
getAnswersr$   r   r   r   strintr   r7   r   rZ   r   SR_SECURITY_DESCRIPTORbytesacesformatCanonicalzipr,   	ExceptionerrorrA   r9   )r^   r%   r   respeanswersr   
mustCommitr&   ri   
delegation
objectTyperightsToprotocolTransition	attributedelegRights
rbcdRightsrbcdObjTypesdacedelegUserRespitem2r'   objTyper(   r   r   r   runp   s   :





&
 
6


zFindDelegation.runN)__name__
__module____qualname__staticmethodrA   re   r   r   r   r   r   r-   =   s
    
!r-   __main__Tz3Queries target domain for delegation relationships )add_helpdescriptiontargetstorezdomain[/username[:password]])actionhelpz-target-domainzvDomain to query/request if different than the domain of the user. Allows for retrieving delegation info across trusts.z-ts
store_truez&Adds timestamp to every logging outputz-debugzTurn DEBUG output ONz-userzRequests data for specific userz	-disabledzQuery disabled users tooauthenticationz-hasheszLMHASH:NTHASHz$NTLM hashes, format is LMHASH:NTHASH)r   metavarr   z-no-passz&don't ask for password (useful for -k)z-kzUse Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the command linez-aesKeyzhex keyz<AES key to use for Kerberos Authentication (128 or 256 bits)
connectionz-dc-ipz
ip addresszIP Address of the domain controller. If ommited it use the domain part (FQDN) specified in the target parameter. Ignoredif -target-domain is specified.z-dc-hosthostnamez|Hostname of the domain controller to use. If ommited, the domain part (FQDN) specified in the account parameter will be usedr   rB   zuserDomain should be specified!)?
__future__r   r   argparser\   sysimpacketr   impacket.dcerpc.v5.samrr   r   r   impacket.examplesr   impacket.examples.utilsr	   r
   impacket.ldapr   r   r   r,   r-   r   r9   BANNERArgumentParserparseradd_argumentadd_argument_groupgroupr$   argv
print_helpexit
parse_argsoptionsinittsr   r   rY   no_passrM   rO   
userDomainr_   r`   _criticalrb   targetDomainexecuterr   r   r   	getLoggerlevelDEBUG	traceback	print_excr   r   r   r   r   r   <module>   sl    
&



(


