mirror of
https://github.com/shadow1ng/fscan.git
synced 2026-09-26 21:21:53 +08:00
fix mssql login client metadata
This commit is contained in:
@@ -9,7 +9,6 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net"
|
"net"
|
||||||
"os"
|
|
||||||
"sort"
|
"sort"
|
||||||
"time"
|
"time"
|
||||||
"unicode/utf16"
|
"unicode/utf16"
|
||||||
@@ -190,17 +189,16 @@ func mssqlParsePreloginFields(payload []byte) (map[byte][]byte, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func mssqlSendLogin7(w io.Writer, host, username, password string) error {
|
func mssqlSendLogin7(w io.Writer, host, username, password string) error {
|
||||||
hostname, _ := os.Hostname()
|
|
||||||
values := []struct {
|
values := []struct {
|
||||||
text string
|
text string
|
||||||
password bool
|
password bool
|
||||||
}{
|
}{
|
||||||
{hostname, false},
|
{"", false},
|
||||||
{username, false},
|
{username, false},
|
||||||
{password, true},
|
{password, true},
|
||||||
{"fscan", false},
|
{"", false},
|
||||||
{host, false},
|
{"", false},
|
||||||
{"fscan", false},
|
{"", false},
|
||||||
{"", false},
|
{"", false},
|
||||||
{"master", false},
|
{"master", false},
|
||||||
{"", false},
|
{"", false},
|
||||||
@@ -233,7 +231,7 @@ func mssqlSendLogin7(w io.Writer, host, username, password string) error {
|
|||||||
put32(tdsVersion74)
|
put32(tdsVersion74)
|
||||||
put32(tdsDefaultPacketLen)
|
put32(tdsDefaultPacketLen)
|
||||||
put32(0)
|
put32(0)
|
||||||
put32(uint32(os.Getpid()))
|
put32(0)
|
||||||
put32(0)
|
put32(0)
|
||||||
body.WriteByte(tdsOptionUseDB | tdsOptionSetLang)
|
body.WriteByte(tdsOptionUseDB | tdsOptionSetLang)
|
||||||
body.WriteByte(tdsOptionODBC)
|
body.WriteByte(tdsOptionODBC)
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
//go:build plugin_mssql || !plugin_selective
|
||||||
|
|
||||||
|
package services
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/binary"
|
||||||
|
"os"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestMSSQLLogin7DoesNotExposeClientIdentity(t *testing.T) {
|
||||||
|
var packet bytes.Buffer
|
||||||
|
if err := mssqlSendLogin7(&packet, "target-host", "sa", "password"); err != nil {
|
||||||
|
t.Fatalf("mssqlSendLogin7() error = %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
data := packet.Bytes()
|
||||||
|
if len(data) < 8+20 {
|
||||||
|
t.Fatalf("login packet too short: %d", len(data))
|
||||||
|
}
|
||||||
|
|
||||||
|
payload := data[8:]
|
||||||
|
if pid := binary.LittleEndian.Uint32(payload[16:20]); pid != 0 {
|
||||||
|
t.Fatalf("client pid = %d, want 0", pid)
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, value := range []string{"fscan", "target-host"} {
|
||||||
|
if bytes.Contains(payload, mssqlUCS2(value)) {
|
||||||
|
t.Fatalf("login packet contains client-identifying value %q", value)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if hostname, err := os.Hostname(); err == nil && hostname != "" {
|
||||||
|
if bytes.Contains(payload, mssqlUCS2(hostname)) {
|
||||||
|
t.Fatalf("login packet contains local hostname %q", hostname)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user