o
    ju:                     @   s~  d dl Z d dlZd dlZd dlZd dlZd dlZd dlmZ d dlm	Z	 d dl
mZmZ d dlmZ d dlmZ d dlmZ d dlmZmZ i d	d
dddddddddddddddddddddd d!d"d#d$d%d&d'd(d)d*i d+d,d-d.d/d0d1d2d3d4d5d6d7d8d9d:d;d<d=d>d?d@dAdBdCdDdEdDdFdGdHd(dId(i dJdKdLdMdNdOdPdQdRdSdTdUdVdWdXdYdZd[d\d]d^d_d`dadbdcdddedfdgdhdidjdki dldmdndodpdqdrdsdtdudvdwdxdydzd{d|d}d~ddddddddddddddddddddddZG dd deZdd Zdd Zedkr=e  dS dS )    N)
format_sid)version)loggerutils)	ldaptypes)escape_filter_chars)security_descriptor_control)init_ldap_sessionparse_identityzS-1-0zNull AuthorityzS-1-0-0NobodyzS-1-1zWorld AuthorityzS-1-1-0EveryonezS-1-2zLocal AuthorityzS-1-2-0LocalzS-1-2-1zConsole LogonzS-1-3zCreator AuthorityzS-1-3-0zCreator OwnerzS-1-3-1zCreator GroupzS-1-3-2zCreator Owner ServerzS-1-3-3zCreator Group ServerzS-1-3-4zOwner Rightsz
S-1-5-80-0zAll ServiceszS-1-4zNon-unique AuthorityzS-1-5zNT AuthorityzS-1-5-1DialupzS-1-5-2NetworkzS-1-5-3BatchzS-1-5-4InteractivezS-1-5-6ServicezS-1-5-7	AnonymouszS-1-5-8ProxyzS-1-5-9zEnterprise Domain ControllerszS-1-5-10zPrincipal SelfzS-1-5-11zAuthenticated UserszS-1-5-12zRestricted CodezS-1-5-13zTerminal Server UserszS-1-5-14zRemote Interactive LogonzS-1-5-15zThis OrganizationzS-1-5-17zS-1-5-18zLocal SystemzS-1-5-19zS-1-5-20zS-1-5-32-544AdministratorszS-1-5-32-545UserszS-1-5-32-546GuestszS-1-5-32-547zPower UserszS-1-5-32-548zAccount OperatorszS-1-5-32-549zServer OperatorszS-1-5-32-550zPrint OperatorszS-1-5-32-551zBackup OperatorszS-1-5-32-552ReplicatorszS-1-5-64-10zNTLM AuthenticationzS-1-5-64-14zSChannel AuthenticationzS-1-5-64-21zDigest AuthorityzS-1-5-80z
NT Servicez
S-1-5-83-0z#NT VIRTUAL MACHINE\Virtual MachineszS-1-16-0zUntrusted Mandatory LevelzS-1-16-4096zLow Mandatory LevelzS-1-16-8192zMedium Mandatory LevelzS-1-16-8448zMedium Plus Mandatory LevelzS-1-16-12288zHigh Mandatory LevelzS-1-16-16384zSystem Mandatory LevelzS-1-16-20480z!Protected Process Mandatory LevelzS-1-16-28672zSecure Process Mandatory LevelzS-1-5-32-554z*BUILTIN\Pre-Windows 2000 Compatible AccesszS-1-5-32-555zBUILTIN\Remote Desktop UserszS-1-5-32-557z&BUILTIN\Incoming Forest Trust BuilderszS-1-5-32-556z'BUILTIN\Network Configuration OperatorszS-1-5-32-558z!BUILTIN\Performance Monitor UserszS-1-5-32-559zBUILTIN\Performance Log UserszS-1-5-32-560z*BUILTIN\Windows Authorization Access GroupzS-1-5-32-561z'BUILTIN\Terminal Server License ServerszS-1-5-32-562zBUILTIN\Distributed COM UserszS-1-5-32-569zBUILTIN\Cryptographic OperatorszS-1-5-32-573zBUILTIN\Event Log ReaderszS-1-5-32-574z'BUILTIN\Certificate Service DCOM Accessz!BUILTIN\RDS Remote Access ServerszBUILTIN\RDS Endpoint ServerszBUILTIN\RDS Management ServerszBUILTIN\Hyper-V Administratorsz+BUILTIN\Access Control Assistance OperatorszBUILTIN\Remote Management Users)zS-1-5-32-575zS-1-5-32-576zS-1-5-32-577zS-1-5-32-578zS-1-5-32-579zS-1-5-32-580c                       s<   e Zd Z fddZdd Zdd Zdd Zd	d
 Z  ZS )	OwnerEditc                    s  t t|   || _|| _|j| _|j| _|j| _|j| _|j	| _	|j
| _
td t }d |_t| j| j|| _| jsD| jsD| jrY|   | jd jd | _tj| jd| _| j	d u rc| jd ush| j
d urd}| jd ur| j}| jj| jjdt| dgd n| j
d ur| j
}| jj|d	| dgd zt| jjd d jd | _	td
| j	  W d S  ty   td|  t d Y d S w d S )NzInitializing domainDumper()nTSecurityDescriptorr   )data (sAMAccountName=%s)	objectSid
attributes(distinguishedName=%s)zFound new owner SID: %sz$New owner SID not found in LDAP (%s)   )!superr   __init__ldap_serverldap_sessiontarget_sAMAccountName
target_SID	target_DNnew_owner_sAMAccountNamenew_owner_SIDnew_owner_DNloggingdebugldapdomaindumpdomainDumpConfigbasepathdomainDumperdomain_dumper+search_target_principal_security_descriptortarget_principal
raw_values(target_principal_raw_security_descriptorr   SR_SECURITY_DESCRIPTOR$target_principal_security_descriptorsearchrootr   r   entries
IndexErrorerrorexit)selfr%   r&   argscnf_lookedup_owner	__class__ /root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/../../../bin/owneredit.pyr$   s   sB   

"
zOwnerEdit.__init__c                 C   s|   t | jd  }td td|  td| |  | jj| jj	d| dgd | jj
d }td	|d   d S )
NOwnerSidzCurrent owner information belowz	- SID: %sz- sAMAccountName: %s(objectSid=%s)distinguishedNamer   r   z- distinguishedName: %s)r   r9   formatCanonicalr-   info
resolveSIDr&   r:   r3   r;   r<   )r@   current_owner_SID current_owner_distinguished_namerF   rF   rG   read   s   
zOwnerEdit.readc                 C   s   t d t }|| j || jd< | jj| j	j
dtj| j gfitddd | jjd dkr:t d	 d S | jjd d
krNt d| jjd  d S | jjd dkrbt d| jjd  d S t d| jjd  d S )NzAttempt to modify the OwnerSidrH   r   r"   sdflags)controlsresultr   zOwnerSid modified successfully!2   zCCould not modify object, the server reports insufficient rights: %smessage   zGCould not modify object, the server reports a constrained violation: %sz The server returned an error: %s)r-   r.   r   LDAP_SIDfromCanonicalr+   r9   r&   modifyr5   entry_dnldap3MODIFY_REPLACEgetDatar   rT   rL   r>   )r@   _new_owner_SIDrF   rF   rG   write   s,   



zOwnerEdit.writec                 C   s   d}t dd}| jd ur!| j}| jj| jjdt| dg|d n-| jd ur9| j}| jj| jjd| dg|d n| jd urN| j}| jj|d| dg|d z| jj	d	 | _
td
|  W d S  tyt   td|  td	 Y d S w )Nr   r"   rQ   r   r   )r    rS   rI   r!   r   z#Target principal found in LDAP (%s)z'Target principal not found in LDAP (%s))r   r'   r&   r:   r3   r;   r   r(   r)   r<   r5   r-   r.   r=   r>   r?   )r@   _lookedup_principalrS   rF   rF   rG   r4      s$   

$
 
z5OwnerEdit.search_target_principal_security_descriptorc                 C   sz   |t  v snt | S | jj| jjd| dgd z| jjd j}| jjd d }|W S  ty<   t	
d|  Y dS w )NFrI   samaccountnamer   r   zSID not found in LDAP: %sr   )WELL_KNOWN_SIDSkeysr&   r:   r3   r;   r<   r[   r=   r-   r.   )r@   siddnsamnamerF   rF   rG   rM      s   zOwnerEdit.resolveSID)	__name__
__module____qualname__r$   rP   r`   r4   rM   __classcell__rF   rF   rD   rG   r   r   s    )	r   c                  C   s  t jddd} | jdddd | jdd	d
d | jdd	dd | jdd	dd | d}|jddddd |jdd	dd |jdd	dd |jddddd |jddddd |jdddd d | jd!d"d#}|jd$d%d&td'd(d) |jd*d+d,td'd-d) |jd.d/d0td'd1d) | jd2d3d#}|jd4d5d&td'd(d) |jd6d7d,td'd-d) |jd8d9d0td'd1d) | d:}|jd;d<d=gd>d<d?d@ ttjdAkr|   t	dA | 
 S )BNTz%Python editor for a principal's DACL.)add_helpdescriptionidentitystorez domain.local/username[:password])actionhelpz
-use-ldaps
store_truezUse LDAPS instead of LDAPz-tsz&Adds timestamp to every logging outputz-debugzTurn DEBUG output ONzauthentication & connectionz-hasheszLMHASH:NTHASHz$NTLM hashes, format is LMHASH:NTHASH)rp   metavarrq   z-no-passz&don't ask for password (useful for -k)z-kzUse Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the command linez-aesKeyzhex keyz<AES key to use for Kerberos Authentication (128 or 256 bits)z-dc-ipz
ip addresszIP Address of the domain controller or KDC (Key Distribution Center) for Kerberos. If omitted it will use the domain part (FQDN) specified in the identity parameterz-dc-hosthostnamezpHostname of the domain controller or KDC (Key Distribution Center) for Kerberos. If omitted, -dc-ip will be usedownerzHObject, controlled by the attacker, to set as owner of the target object)rm   z
-new-ownerr*   NAMEFsAMAccountName)destrs   typerequiredrq   z-new-owner-sidr+   SIDzSecurity IDentifierz-new-owner-dnr,   DNzDistinguished Nametargetz"Target object to edit the owner ofz-targetr'   z-target-sidr(   z
-target-dnr)   zdacl editorz-actionrP   r`   ?z(Action to operate on the owner attribute)choicesnargsdefaultrq   r"   )argparseArgumentParseradd_argumentadd_argument_groupstrlensysargv
print_helpr?   
parse_args)parserauth_connew_owner_parsertarget_parserdacl_parserrF   rF   rG   r      s<   



r   c            
      C   s^  t tj t } t| j| j | jdkr.| j	d u r.| j
d u r.| jd u r.td td | jdkr;| js;td t| j| j| j| j| j\}}}}}| _z9t|||||| j| j| j| j| j
\}}t||| }| jdkrv|  W d S | jdkr|  |  W d S W d S  ty }	 zt j tj!krt"#  t$t%|	 W Y d }	~	d S d }	~	ww )Nr`   zM-owner, -owner-sid, or -owner-dn should be specified when using -action writer"   restorez,-file is required when using -action restorerP   )&printr   BANNERr   r   inittsr.   rp   r*   r+   r,   r-   criticalr   r?   filenamer
   rn   hashesno_passaesKeykr	   dc_ipdc_host	use_ldapsr   rP   r`   	Exception	getLoggerlevelDEBUG	traceback	print_excr>   r   )
rA   domainusernamepasswordlmhashnthashr%   r&   	ownerediterF   rF   rG   main
  s0   
(


((

r   __main__)r   r-   r   r   r\   r/   $ldap3.protocol.formatters.formattersr   impacketr   impacket.examplesr   r   impacket.ldapr   ldap3.utils.convr   ldap3.protocol.microsoftr   impacket.examples.utilsr	   r
   rc   objectr   r   r   rh   rF   rF   rF   rG   <module>   sF  	
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEMs%

