| | 1 | | using System.Collections.Generic; |
| | 2 | | using System.Linq; |
| | 3 | | using Microsoft.Extensions.Logging; |
| | 4 | | using SharpHoundCommonLib.Enums; |
| | 5 | | using SharpHoundCommonLib.OutputTypes; |
| | 6 | |
|
| | 7 | | namespace SharpHoundCommonLib.Processors { |
| | 8 | | public class SPNProcessors { |
| | 9 | | private const string MSSQLSPNString = "mssqlsvc"; |
| | 10 | | private readonly ILogger _log; |
| | 11 | | private readonly ILdapUtils _utils; |
| | 12 | |
|
| 12 | 13 | | public SPNProcessors(ILdapUtils utils, ILogger log = null) { |
| 6 | 14 | | _utils = utils; |
| 6 | 15 | | _log = log ?? Logging.LogProvider.CreateLogger("SPNProc"); |
| 6 | 16 | | } |
| | 17 | |
|
| | 18 | | public IAsyncEnumerable<SPNPrivilege> ReadSPNTargets(ResolvedSearchResult result, |
| 0 | 19 | | IDirectoryObject entry) { |
| 0 | 20 | | if (entry.TryGetArrayProperty(LDAPProperties.ServicePrincipalNames, out var members)) { |
| 0 | 21 | | return ReadSPNTargets(members, result.Domain, result.DisplayName); |
| | 22 | | } |
| | 23 | |
|
| 0 | 24 | | return AsyncEnumerable.Empty<SPNPrivilege>(); |
| 0 | 25 | | } |
| | 26 | |
|
| | 27 | | public async IAsyncEnumerable<SPNPrivilege> ReadSPNTargets(string[] servicePrincipalNames, |
| 6 | 28 | | string domainName, string objectName = "") { |
| 7 | 29 | | if (servicePrincipalNames.Length == 0) { |
| 1 | 30 | | _log.LogTrace("SPN Array is empty for {Name}", objectName); |
| 1 | 31 | | yield break; |
| | 32 | | } |
| | 33 | |
|
| 5 | 34 | | _log.LogDebug("Processing SPN targets for {ObjectName}", objectName); |
| | 35 | |
|
| 30 | 36 | | foreach (var spn in servicePrincipalNames) { |
| | 37 | | //This SPN format isn't useful for us right now (username@domain) |
| 6 | 38 | | if (spn.Contains("@")) { |
| 1 | 39 | | _log.LogTrace("Skipping spn without @ {SPN} for {Name}", spn, objectName); |
| 1 | 40 | | continue; |
| | 41 | | } |
| | 42 | |
|
| 4 | 43 | | _log.LogTrace("Processing SPN {SPN} for {Name}", spn, objectName); |
| | 44 | |
|
| 7 | 45 | | if (spn.ToLower().Contains(MSSQLSPNString)) { |
| 3 | 46 | | _log.LogTrace("Matched SQL SPN {SPN} for {Name}", spn, objectName); |
| 3 | 47 | | var port = 1433; |
| | 48 | |
|
| 3 | 49 | | if (spn.Contains(":")) |
| 2 | 50 | | if (!int.TryParse(spn.Split(':')[1], out port)) |
| 1 | 51 | | port = 1433; |
| | 52 | |
|
| 6 | 53 | | if (await _utils.ResolveHostToSid(spn, domainName) is (true, var host) && host.StartsWith("S-1")) { |
| 3 | 54 | | _log.LogTrace("Resolved {SPN} to {Hostname}", spn, host); |
| 3 | 55 | | yield return new SPNPrivilege { |
| 3 | 56 | | ComputerSID = host, |
| 3 | 57 | | Port = port, |
| 3 | 58 | | Service = EdgeNames.SQLAdmin |
| 3 | 59 | | }; |
| 3 | 60 | | } |
| 3 | 61 | | } |
| 4 | 62 | | } |
| 6 | 63 | | } |
| | 64 | | } |
| | 65 | | } |