o
    Žõ±j  ã                   @   sJ   d dl Z d dlZd dlmZ d dlmZ G dd„ dƒZG dd„ deƒZdS )é    N)ÚPackageDecryptor)ÚLSA_UNICODE_STRINGc                   @   s,   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	S )
ÚWdigestCredentialc                 C   s(   d| _ d | _d | _d | _d| _d | _d S )NÚwdigestó    ©ÚcredtypeÚusernameÚ
domainnameÚpasswordÚpassword_rawÚluid©Úself© r   ú¤/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/pypykatz/alsadecryptor/packages/wdigest/decryptor.pyÚ__init__   s   
zWdigestCredential.__init__c                 C   sD   i }| j |d< | j|d< | j|d< | j|d< | j|d< | j|d< |S )Nr   r	   r
   r   r   r   r   ©r   Útr   r   r   Úto_dict   s   





zWdigestCredential.to_dictc                 C   s   t  |  ¡ ¡S )N)ÚjsonÚdumpsr   r   r   r   r   Úto_json   s   zWdigestCredential.to_jsonc                 C   sJ   d| j  }|d| j 7 }|d| j 7 }|d| j 7 }|d| j ¡  7 }|S )Nz	== WDIGEST [%x]==
z		username %s
z		domainname %s
z		password %s
z		password (hex)%s
)r   r	   r
   r   r   Úhexr   r   r   r   Ú__str__!   s   
zWdigestCredential.__str__N)Ú__name__Ú
__module__Ú__qualname__r   r   r   r   r   r   r   r   r      s
    	r   c                       s4   e Zd Z‡ fdd„Zdd„ Zdd„ Zdd„ Z‡  ZS )	ÚWdigestDecryptorc                    s"   t ƒ  d|||¡ || _g | _d S )NÚWdigest)Úsuperr   Údecryptor_templateÚcredentials)r   Úreaderr!   Úlsa_decryptorÚsysinfo©Ú	__class__r   r   r   *   s   
zWdigestDecryptor.__init__c                 Ã   sL   �|   d| jj¡I d H }| j || jj ¡I d H }| j |¡I d H }||fS )Nzwdigest.dll)Úfind_signaturer!   Ú	signaturer#   Úget_ptr_with_offsetÚfirst_entry_offsetÚget_ptr)r   ÚpositionÚptr_entry_locÚ	ptr_entryr   r   r   Úfind_first_entry/   s
   €z!WdigestDecryptor.find_first_entryc                 Ã   s&  �t ƒ }|j|_| j |jj| jj ¡I dH  t 	| j¡I dH }t 	| j¡I dH }t 	| j¡I dH }| 
| j¡I dH |_| 
| j¡I dH |_| | j¡I dH |_|j d¡du rp| j|jdd�\|_|_|jduro|j ¡ |_n
|  |j¡\|_|_|jdkr‹|jdkr‹|jdu r‹dS | j |¡ dS )z«
		Changed the wdigest parsing, the struct only contains the pointers in the linked list, the actual data is read by 
		adding an offset to the current entry's position
		Nú$T)Úbytes_expectedÚ )r   r   r#   ÚmoveÚ
this_entryÚvaluer!   Úprimary_offsetr   ÚloadÚread_stringr	   r
   Úread_maxdataÚencrypted_passwordÚendswithÚdecrypt_passwordr   r   r   r"   Úappend)r   Úwdigest_entryÚwcÚUserNameÚ
DomainNameÚPasswordr   r   r   Ú	add_entry5   s&   €
€zWdigestDecryptor.add_entryc              
   Ã   sŽ   �z|   ¡ I d H \}}W n ty& } z|  d| ¡ W Y d }~d S d }~ww | j |¡I d H  | jj | j¡I d H }|  || j	¡I d H  d S )Nz*Failed to find Wdigest structs! Reason: %s)
r0   Ú	ExceptionÚlogr#   r4   r!   Ú
list_entryr8   Ú	walk_listrD   )r   Úentry_ptr_valueÚentry_ptr_locÚeÚ	entry_ptrr   r   r   ÚstartR   s   €€þzWdigestDecryptor.start)r   r   r   r   r0   rD   rM   Ú__classcell__r   r   r&   r   r   )   s
    r   )Úior   Ú&pypykatz.alsadecryptor.package_commonsr   Ú$pypykatz.alsadecryptor.win_datatypesr   r   r   r   r   r   r   Ú<module>   s   