SMB.java 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227
  1. package de.tudarmstadt.informatik.hostage.protocol;
  2. import java.security.SecureRandom;
  3. import java.util.ArrayList;
  4. import java.util.List;
  5. import android.content.SharedPreferences;
  6. import android.preference.PreferenceManager;
  7. import de.tudarmstadt.informatik.hostage.Hostage;
  8. import de.tudarmstadt.informatik.hostage.R;
  9. import de.tudarmstadt.informatik.hostage.commons.HelperUtils;
  10. import de.tudarmstadt.informatik.hostage.protocol.smbutils.NBNS;
  11. import de.tudarmstadt.informatik.hostage.protocol.smbutils.NMB;
  12. import de.tudarmstadt.informatik.hostage.protocol.smbutils.SMBPacket;
  13. import de.tudarmstadt.informatik.hostage.wrapper.Packet;
  14. /**
  15. * SMB protocol. It can handle the following requests: Negotiate Protocol
  16. * Request, Session Setup AndX Request, Tree Connect AndX Request, NT Create
  17. * AndX Request, Bind, NetShareEnumAll, Close Request, Tree Disconnect Request,
  18. * Echo Request, Trans2 Request.
  19. *
  20. * @author Wulf Pfeiffer
  21. */
  22. public class SMB implements Protocol {
  23. // message constants
  24. private static final byte SMB_COM_CLOSE = 0x04;
  25. private static final byte SMB_COM_TRANSACTION = 0x25;
  26. private static final byte SMB_COM_ECHO = 0x2B;
  27. private static final byte SMB_COM_TRANSACTION2 = 0x32;
  28. private static final byte SMB_COM_TREE_DISCONNECT = 0x71;
  29. private static final byte SMB_COM_NEGOTIATE = 0x72;
  30. private static final byte SMB_COM_SESSION_SETUP_ANDX = 0x73;
  31. private static final byte SMB_COM_TREE_CONNECT_ANDX = 0x75;
  32. private static final byte SMB_COM_NT_CREATE_ANDX = (byte) 0xA2;
  33. /**
  34. * Denotes in which state the protocol is right now
  35. */
  36. private STATE state = STATE.NONE;
  37. private byte[] lastMessage;
  38. private NMB nmb;
  39. // version stuff
  40. private String[][] possibleSmbVersions = {
  41. { "Windows 7 Professional 7600", "Windows 7 Professional 6.1" },
  42. { "Windows 8 Enterprise 9200", "Windows 8 Enterprise 9200" },
  43. { "Windows Server 2008 R2 Enterprise 7600", "Windows Server 2008 R2 Enterprise 6.1" },
  44. { "Windows Server 2012 Standard 6.2", "Windows Server 2012 Standard 6.2" },
  45. { "Unix", "Samba" },
  46. { "Windows 2002 Service Pack 2", "Windows 2002 5.1" }
  47. };
  48. /**
  49. * Represents the states of the protocol
  50. */
  51. private static enum STATE {
  52. NONE, CONNECTED, AUTHENTICATED, LISTING, DISCONNECTED, CLOSED
  53. }
  54. public void setIP(String ip) {
  55. // TODO if porthack is working for UDP uncomment
  56. // nmb = new NMB(ip, new String(serverName), workgroup);
  57. // nmb.start();
  58. }
  59. private String[] initServerVersion() {
  60. String sharedPreferencePath = Hostage.getContext().getString(
  61. R.string.shared_preference_path);
  62. String profile = Hostage
  63. .getContext()
  64. .getSharedPreferences(sharedPreferencePath,
  65. Hostage.MODE_PRIVATE).getString("os", "");
  66. if(profile.equals("Windows XP")) {
  67. workgroup = "MSHOME";
  68. } else {
  69. workgroup = "WORKGROUP";
  70. }
  71. if (profile.equals("Windows 7")) {
  72. return possibleSmbVersions[0];
  73. } else if (profile.equals("Windows 8")) {
  74. return possibleSmbVersions[1];
  75. } else if (profile.equals("Windows Server 2008")) {
  76. return possibleSmbVersions[2];
  77. } else if (profile.equals("Windows Server 2012")) {
  78. return possibleSmbVersions[3];
  79. } else if (profile.equals("Linux")) {
  80. return possibleSmbVersions[4];
  81. } else if (profile.equals("Windows XP")) {
  82. return possibleSmbVersions[5];
  83. } else {
  84. return possibleSmbVersions[new SecureRandom().nextInt(possibleSmbVersions.length)];
  85. }
  86. }
  87. //required to be declared down here, do not change position over initServerVersion() and possibleServerVersions!!
  88. private String[] serverVersion = initServerVersion();
  89. private static byte[] serverName = HelperUtils.fillWithZero(HelperUtils
  90. .getRandomString(16, true).getBytes());
  91. private static String workgroup;
  92. private SMBPacket smbPacket = new SMBPacket(serverVersion, new String(serverName), workgroup);
  93. private int maxEchoPackets = initMaxPackets();
  94. private int receivedEchoPackets = 0;
  95. private int initMaxPackets() {
  96. int maxPackets;
  97. SharedPreferences prefs = PreferenceManager.getDefaultSharedPreferences(Hostage.getContext());
  98. maxPackets = prefs.getInt("timeout", 30) / 5;
  99. return maxPackets;
  100. }
  101. @Override
  102. public int getPort() {
  103. return 445;
  104. }
  105. @Override
  106. public boolean isClosed() {
  107. return (state == STATE.CLOSED);
  108. }
  109. @Override
  110. public boolean isSecure() {
  111. return false;
  112. }
  113. @Override
  114. public List<Packet> processMessage(Packet requestPacket) {
  115. if (requestPacket != null)
  116. lastMessage = requestPacket.getBytes();
  117. smbPacket.prepareNextResponse(lastMessage);
  118. byte smbCommand = smbPacket.getSmbCommand();
  119. byte[] response;
  120. List<Packet> responsePackets = new ArrayList<Packet>();
  121. if (smbCommand == SMB_COM_ECHO) {
  122. receivedEchoPackets++;
  123. } else {
  124. receivedEchoPackets = 0;
  125. }
  126. if (receivedEchoPackets == maxEchoPackets) {
  127. state = STATE.CLOSED;
  128. response = smbPacket.getTreeDisc();
  129. responsePackets.add(new Packet(response, toString()));
  130. return responsePackets;
  131. }
  132. switch (state) {
  133. case NONE:
  134. if (smbCommand == SMB_COM_NEGOTIATE) {
  135. state = STATE.CONNECTED;
  136. response = smbPacket.getNego();
  137. } else {
  138. state = STATE.DISCONNECTED;
  139. response = smbPacket.getTreeDisc();
  140. }
  141. break;
  142. case CONNECTED:
  143. if (smbCommand == SMB_COM_SESSION_SETUP_ANDX) {
  144. response = smbPacket.getSessSetup();
  145. } else if (smbCommand == SMB_COM_TREE_CONNECT_ANDX) {
  146. state = STATE.AUTHENTICATED;
  147. response = smbPacket.getTreeCon();
  148. } else {
  149. state = STATE.DISCONNECTED;
  150. response = smbPacket.getTreeDisc();
  151. }
  152. break;
  153. case AUTHENTICATED:
  154. if (smbCommand == SMB_COM_NT_CREATE_ANDX) {
  155. state = STATE.LISTING;
  156. response = smbPacket.getNTCreate();
  157. } else if (smbCommand == SMB_COM_ECHO) {
  158. response = smbPacket.getEcho();
  159. } else if (smbCommand == SMB_COM_TRANSACTION2) {
  160. response = smbPacket.getTrans2();
  161. } else if (smbCommand == SMB_COM_CLOSE) {
  162. response = smbPacket.getClose();
  163. } else if (smbCommand == SMB_COM_TREE_DISCONNECT) {
  164. state = STATE.CLOSED;
  165. response = smbPacket.getTreeDisc();
  166. } else {
  167. state = STATE.DISCONNECTED;
  168. response = smbPacket.getTreeDisc();
  169. }
  170. break;
  171. case LISTING:
  172. if (smbCommand == SMB_COM_TRANSACTION) {
  173. response = smbPacket.getTrans();
  174. } else if (smbCommand == SMB_COM_CLOSE) {
  175. response = smbPacket.getClose();
  176. } else if (smbCommand == SMB_COM_TREE_DISCONNECT) {
  177. state = STATE.CLOSED;
  178. response = smbPacket.getTreeDisc();
  179. } else if (smbCommand == SMB_COM_NEGOTIATE) {
  180. state = STATE.CONNECTED;
  181. response = smbPacket.getNego();
  182. } else {
  183. state = STATE.DISCONNECTED;
  184. response = smbPacket.getTreeDisc();
  185. }
  186. break;
  187. case DISCONNECTED:
  188. state = STATE.CLOSED;
  189. response = smbPacket.getTreeDisc();
  190. break;
  191. default:
  192. state = STATE.CLOSED;
  193. response = smbPacket.getTreeDisc();
  194. }
  195. responsePackets.add(new Packet(response, toString()));
  196. return responsePackets;
  197. }
  198. @Override
  199. public String toString() {
  200. return "SMB";
  201. }
  202. @Override
  203. public TALK_FIRST whoTalksFirst() {
  204. return TALK_FIRST.CLIENT;
  205. }
  206. }