aboutsummaryrefslogtreecommitdiff
path: root/internal/exec
diff options
context:
space:
mode:
Diffstat (limited to 'internal/exec')
-rw-r--r--internal/exec/exec.go10
-rw-r--r--internal/exec/scmr/exec.go13
-rw-r--r--internal/exec/tsch/exec.go11
3 files changed, 15 insertions, 19 deletions
diff --git a/internal/exec/exec.go b/internal/exec/exec.go
index 56edead..f3fe7ae 100644
--- a/internal/exec/exec.go
+++ b/internal/exec/exec.go
@@ -2,7 +2,9 @@ package exec
import (
"context"
+ "fmt"
"github.com/RedTeamPentesting/adauth"
+ "strings"
)
const (
@@ -42,8 +44,12 @@ type Module interface {
}
func (cfg *ExecutionConfig) GetRawCommand() string {
+ executable := cfg.ExecutablePath
+ if strings.Contains(executable, " ") {
+ executable = fmt.Sprintf("%q", executable)
+ }
if cfg.ExecutableArgs != "" {
- return cfg.ExecutablePath + " " + cfg.ExecutableArgs
+ return executable + " " + cfg.ExecutableArgs
}
- return cfg.ExecutablePath
+ return executable
}
diff --git a/internal/exec/scmr/exec.go b/internal/exec/scmr/exec.go
index c47fcee..588c580 100644
--- a/internal/exec/scmr/exec.go
+++ b/internal/exec/scmr/exec.go
@@ -9,18 +9,13 @@ import (
"github.com/FalconOpsLLC/goexec/internal/util"
"github.com/FalconOpsLLC/goexec/internal/windows"
"github.com/RedTeamPentesting/adauth"
- "github.com/oiweiwei/go-msrpc/dcerpc"
- "github.com/oiweiwei/go-msrpc/midl/uuid"
"github.com/oiweiwei/go-msrpc/msrpc/scmr/svcctl/v2"
"github.com/rs/zerolog"
)
const (
- DefaultEndpoint = "ncacn_np:[srvsvc]"
-)
-
-var (
- ScmrRpcUuid = uuid.MustParse("367ABB81-9844-35F1-AD32-98F038001003")
+ ScmrDefaultEndpoint = "ncacn_np:[svcctl]"
+ ScmrDefaultObject = "367ABB81-9844-35F1-AD32-98F038001003"
)
func (mod *Module) Connect(ctx context.Context, creds *adauth.Credential, target *adauth.Target, ccfg *exec.ConnectionConfig) (err error) {
@@ -41,7 +36,7 @@ func (mod *Module) Connect(ctx context.Context, creds *adauth.Credential, target
}
connect := func(ctx context.Context) error {
// Create DCE connection
- if mod.dce, err = cfg.GetDce(ctx, creds, target, dcerpc.WithObjectUUID(ScmrRpcUuid)); err != nil {
+ if mod.dce, err = cfg.GetDce(ctx, creds, target, ScmrDefaultEndpoint, ScmrDefaultObject); err != nil {
log.Error().Err(err).Msg("Failed to initialize DCE dialer")
return fmt.Errorf("create DCE dialer: %w", err)
}
@@ -191,7 +186,7 @@ func (mod *Module) Exec(ctx context.Context, ecfg *exec.ExecutionConfig) (err er
ServiceManager: mod.scm,
ServiceName: serviceName,
DisplayName: util.RandomStringIfBlank(cfg.DisplayName),
- BinaryPathName: util.CheckNullString(ecfg.GetRawCommand()),
+ BinaryPathName: ecfg.GetRawCommand(),
ServiceType: windows.SERVICE_WIN32_OWN_PROCESS,
StartType: windows.SERVICE_DEMAND_START,
DesiredAccess: ServiceAllAccess, // TODO: Replace
diff --git a/internal/exec/tsch/exec.go b/internal/exec/tsch/exec.go
index 44f11d1..1996f27 100644
--- a/internal/exec/tsch/exec.go
+++ b/internal/exec/tsch/exec.go
@@ -8,19 +8,14 @@ import (
"github.com/FalconOpsLLC/goexec/internal/exec"
"github.com/FalconOpsLLC/goexec/internal/util"
"github.com/RedTeamPentesting/adauth"
- "github.com/oiweiwei/go-msrpc/dcerpc"
- "github.com/oiweiwei/go-msrpc/midl/uuid"
"github.com/oiweiwei/go-msrpc/msrpc/tsch/itaskschedulerservice/v1"
"github.com/rs/zerolog"
"time"
)
const (
- DefaultEndpoint = "ncacn_np:[atsvc]"
-)
-
-var (
- TschRpcUuid = uuid.MustParse("86D35949-83C9-4044-B424-DB363231FD0C")
+ TschDefaultEndpoint = "ncacn_np:[atsvc]"
+ TschDefaultObject = "86D35949-83C9-4044-B424-DB363231FD0C"
)
// Connect to the target & initialize DCE & TSCH clients
@@ -34,7 +29,7 @@ func (mod *Module) Connect(ctx context.Context, creds *adauth.Credential, target
return fmt.Errorf("invalid configuration for DCE connection method")
} else {
// Create DCERPC dialer
- mod.dce, err = cfg.GetDce(ctx, creds, target, dcerpc.WithObjectUUID(TschRpcUuid))
+ mod.dce, err = cfg.GetDce(ctx, creds, target, TschDefaultEndpoint, TschDefaultObject)
if err != nil {
log.Error().Err(err).Msg("Failed to create DCERPC dialer")
return fmt.Errorf("create DCERPC dialer: %w", err)