Class: Msf::RPC::RPC_Session
- Defined in:
- lib/msf/core/rpc/v10/rpc_session.rb
Instance Attribute Summary
Attributes inherited from RPC_Base
#framework, #job_status_tracker, #service, #tokens, #users
Instance Method Summary collapse
-
#rpc_compatible_modules(sid) ⇒ Hash
Returns all the compatible modules for this session.
-
#rpc_interactive_read(sid) ⇒ Hash
Reads the output from an interactive session (meterpreter, DB sessions, SMB, shell, powershell).
-
#rpc_interactive_write(sid, data) ⇒ Hash
Sends an input to an interactive prompt (meterpreter, DB sessions, SMB, shell, powershell) You may want to use #rpc_interactive_read to retrieve the output.
-
#rpc_list ⇒ Hash
Returns a list of sessions that belong to the framework instance used by the RPC service.
-
#rpc_meterpreter_directory_separator(sid) ⇒ Hash
Returns the separator used by the meterpreter.
-
#rpc_meterpreter_read(sid) ⇒ Hash
deprecated
Deprecated.
in favour of #rpc_interactive_read
-
#rpc_meterpreter_run_single(sid, data) ⇒ Hash
Runs a meterpreter command even if interacting with a shell or other channel.
-
#rpc_meterpreter_script(sid, data) ⇒ Hash
deprecated
Deprecated.
Metasploit no longer maintains or accepts meterpreter scripts. Please try to use post modules instead.
-
#rpc_meterpreter_session_detach(sid) ⇒ Hash
Detaches from a meterpreter session.
-
#rpc_meterpreter_session_kill(sid) ⇒ Hash
Kills a meterpreter session.
-
#rpc_meterpreter_tabs(sid, line) ⇒ Hash
Returns a tab-completed version of your meterpreter prompt input.
-
#rpc_meterpreter_transport_change(sid, opts = {}) ⇒ Boolean
Changes the Transport of a given Meterpreter Session.
-
#rpc_meterpreter_write(sid, data) ⇒ Hash
deprecated
Deprecated.
in favour of #rpc_interactive_write
-
#rpc_ring_clear(sid) ⇒ Hash
Clears a shell session.
-
#rpc_ring_last(sid) ⇒ Hash
Returns the last sequence (last issued ReadPointer) for a shell session.
-
#rpc_ring_put(sid, data) ⇒ Hash
Sends an input to a session (such as a command).
-
#rpc_ring_read(sid, ptr = nil) ⇒ Hash
Reads from a session (such as a command output).
-
#rpc_shell_read(sid, ptr = nil) ⇒ Hash
Reads the output of a shell session (such as a command output).
-
#rpc_shell_upgrade(sid, lhost, lport) ⇒ Hash
Upgrades a shell to a meterpreter.
-
#rpc_shell_write(sid, data) ⇒ Hash
Writes to a shell session (such as a command).
-
#rpc_stop(sid) ⇒ Hash
Stops a session - alias for killing a session in ‘msfconsole`.
Methods inherited from RPC_Base
Constructor Details
This class inherits a constructor from Msf::RPC::RPC_Base
Instance Method Details
#rpc_compatible_modules(sid) ⇒ Hash
Returns all the compatible modules for this session.
531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 531 def rpc_compatible_modules(sid) session = self.framework.sessions[sid] compatible_modules = [] if session session_type = session.type search_params = { 'session_type' => [[session_type], []] } cached_modules = Msf::Modules::Metadata::Cache.instance.find(search_params) cached_modules.each do |cached_module| m = _find_module(cached_module.type, cached_module.fullname) compatible_modules << m.fullname if m.session_compatible?(sid) end end { "modules" => compatible_modules } end |
#rpc_interactive_read(sid) ⇒ Hash
Multiple concurrent callers writing and reading the same Meterperter session can lead to a conflict, where one caller gets the others output and vice versa. Concurrent access to a Meterpreter session is best handled by post modules.
Reads the output from an interactive session (meterpreter, DB sessions, SMB, shell, powershell)
199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 199 def rpc_interactive_read(sid) session = _valid_interactive_session(sid) if SHELL_SESSION_TYPES.include?(session.type) begin return { 'data' => session.shell_read.to_s } rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end unless session.user_output.respond_to?(:dump_buffer) session.init_ui(Rex::Ui::Text::Input::Buffer.new, Rex::Ui::Text::Output::Buffer.new) end data = session.user_output.dump_buffer { 'data' => data } end |
#rpc_interactive_write(sid, data) ⇒ Hash
Multiple concurrent callers writing and reading the same Meterperter session can lead to a conflict, where one caller gets the others output and vice versa. Concurrent access to a Meterpreter session is best handled by post modules.
Sends an input to an interactive prompt (meterpreter, DB sessions, SMB, shell, powershell) You may want to use #rpc_interactive_read to retrieve the output. rpc.call(‘session.interactive_write’, 2, “sysinfo”)
331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 331 def rpc_interactive_write(sid, data) error(400, 'Data must be a String') unless data.is_a?(String) session = _valid_interactive_session(sid) if SHELL_SESSION_TYPES.include?(session.type) begin payload = data.end_with?("\n") ? data : "#{data}\n" session.shell_write(payload) return { 'result' => 'success' } rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end unless session.user_output.respond_to? :dump_buffer session.init_ui(Rex::Ui::Text::Input::Buffer.new, Rex::Ui::Text::Output::Buffer.new) end interacting = false if session.respond_to? :channels session.channels.each_value do |ch| interacting ||= ch.respond_to?('interacting') && ch.interacting end else interacting = session.interacting end if interacting session.user_input.put(data + "\n") else framework.threads.spawn("InteractiveRunSingle-#{session.sid}-#{session.type}", false, session) do |s| s.console.run_single(data) end end { 'result' => 'success' } end |
#rpc_list ⇒ Hash
Returns a list of sessions that belong to the framework instance used by the RPC service.
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 29 def rpc_list res = {} self.framework.sessions.each do |sess| i,s = sess res[s.sid] = { 'type' => s.type.to_s, 'tunnel_local' => s.tunnel_local.to_s, 'tunnel_peer' => s.tunnel_peer.to_s, 'via_exploit' => s.via_exploit.to_s, 'via_payload' => s.via_payload.to_s, 'desc' => s.desc.to_s, 'info' => s.info.to_s, 'workspace' => s.workspace.to_s, 'session_host' => s.session_host.to_s, 'session_port' => s.session_port.to_i, 'target_host' => s.target_host.to_s, 'username' => s.username.to_s, 'uuid' => s.uuid.to_s, 'exploit_uuid' => s.exploit_uuid.to_s, 'routes' => s.routes.join(","), 'arch' => s.arch.to_s } if(s.type.to_s == "meterpreter") res[s.sid]['platform'] = s.platform.to_s end end res end |
#rpc_meterpreter_directory_separator(sid) ⇒ Hash
Returns the separator used by the meterpreter.
517 518 519 520 521 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 517 def rpc_meterpreter_directory_separator(sid) s = _valid_session(sid,"meterpreter") { "separator" => s.fs.file.separator } end |
#rpc_meterpreter_read(sid) ⇒ Hash
in favour of #rpc_interactive_read
Multiple concurrent callers writing and reading the same Meterperter session can lead to a conflict, where one caller gets the others output and vice versa. Concurrent access to a Meterpreter session is best handled by post modules.
Reads the output from a meterpreter session (such as a command output).
181 182 183 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 181 def rpc_meterpreter_read(sid) rpc_interactive_read(sid) end |
#rpc_meterpreter_run_single(sid, data) ⇒ Hash
Runs a meterpreter command even if interacting with a shell or other channel. You will want to use the #rpc_meterpreter_read to retrieve the output.
445 446 447 448 449 450 451 452 453 454 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 445 def rpc_meterpreter_run_single( sid, data) s = _valid_session(sid,"meterpreter") if not s.user_output.respond_to? :dump_buffer s.init_ui(Rex::Ui::Text::Input::Buffer.new, Rex::Ui::Text::Output::Buffer.new) end self.framework.threads.spawn("MeterpreterRunSingle", false, s) { |sess| sess.console.run_single(data) } { "result" => "success" } end |
#rpc_meterpreter_script(sid, data) ⇒ Hash
Metasploit no longer maintains or accepts meterpreter scripts. Please try to use post modules instead.
Runs a meterpreter script.
468 469 470 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 468 def rpc_meterpreter_script( sid, data) rpc_meterpreter_run_single( sid, "run #{data}") end |
#rpc_meterpreter_session_detach(sid) ⇒ Hash
Detaches from a meterpreter session. Serves the same purpose as [CTRL]+.
379 380 381 382 383 384 385 386 387 388 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 379 def rpc_meterpreter_session_detach(sid) s = _valid_session(sid,"meterpreter") s.channels.each_value do |ch| if(ch.respond_to?('interacting') && ch.interacting) ch.detach() return { "result" => "success" } end end { "result" => "failure" } end |
#rpc_meterpreter_session_kill(sid) ⇒ Hash
Kills a meterpreter session. Serves the same purpose as [CTRL]+.
* 'result' [String] Either 'success' or 'failure'.
402 403 404 405 406 407 408 409 410 411 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 402 def rpc_meterpreter_session_kill(sid) s = _valid_session(sid,"meterpreter") s.channels.each_value do |ch| if(ch.respond_to?('interacting') && ch.interacting) ch._close return { "result" => "success" } end end { "result" => "failure" } end |
#rpc_meterpreter_tabs(sid, line) ⇒ Hash
Returns a tab-completed version of your meterpreter prompt input.
427 428 429 430 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 427 def rpc_meterpreter_tabs(sid, line) s = _valid_session(sid,"meterpreter") { "tabs" => s.console.tab_complete(line) } end |
#rpc_meterpreter_transport_change(sid, opts = {}) ⇒ Boolean
Changes the Transport of a given Meterpreter Session
490 491 492 493 494 495 496 497 498 499 500 501 502 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 490 def rpc_meterpreter_transport_change(sid,opts={}) session = _valid_session(sid,"meterpreter") real_opts = {} opts.each_pair do |key, value| real_opts[key.to_sym] = value end real_opts[:uuid] = session.payload_uuid result = session.core.transport_change(real_opts) if result == true rpc_stop(sid) end result end |
#rpc_meterpreter_write(sid, data) ⇒ Hash
in favour of #rpc_interactive_write
Multiple concurrent callers writing and reading the same Meterperter session can lead to a conflict, where one caller gets the others output and vice versa. Concurrent access to a Meterpreter session is best handled by post modules.
Sends an input to a meterpreter prompt. You may want to use #rpc_meterpreter_read to retrieve the output.
312 313 314 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 312 def rpc_meterpreter_write(sid, data) rpc_interactive_write(sid, data) end |
#rpc_ring_clear(sid) ⇒ Hash
Clears a shell session. This may be useful to reclaim memory for idle background sessions.
291 292 293 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 291 def rpc_ring_clear(sid) { "result" => "success" } end |
#rpc_ring_last(sid) ⇒ Hash
Returns the last sequence (last issued ReadPointer) for a shell session.
275 276 277 278 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 275 def rpc_ring_last(sid) s = _valid_session(sid,"ring") { "seq" => 0 } end |
#rpc_ring_put(sid, data) ⇒ Hash
Sends an input to a session (such as a command).
254 255 256 257 258 259 260 261 262 263 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 254 def rpc_ring_put(sid, data) error(400, 'Data must be a String') unless data.is_a?(String) s = _valid_session(sid,"ring") begin res = s.shell_write(data) { "write_count" => res.to_s} rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end |
#rpc_ring_read(sid, ptr = nil) ⇒ Hash
Reads from a session (such as a command output).
231 232 233 234 235 236 237 238 239 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 231 def rpc_ring_read(sid, ptr = nil) s = _valid_session(sid,"ring") begin res = s.shell_read() { "seq" => 0, "data" => res.to_s } rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end |
#rpc_shell_read(sid, ptr = nil) ⇒ Hash
Reads the output of a shell session (such as a command output).
112 113 114 115 116 117 118 119 120 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 112 def rpc_shell_read( sid, ptr=nil) s = _valid_session(sid,"shell") begin res = s.shell_read() { "seq" => 0, "data" => res.to_s} rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end |
#rpc_shell_upgrade(sid, lhost, lport) ⇒ Hash
This uses post/multi/manage/shell_to_meterpreter.
Upgrades a shell to a meterpreter.
159 160 161 162 163 164 165 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 159 def rpc_shell_upgrade( sid, lhost, lport) s = _valid_session(sid,"shell") s.exploit_datastore['LHOST'] = lhost s.exploit_datastore['LPORT'] = lport s.execute_script('post/multi/manage/shell_to_meterpreter') { "result" => "success" } end |
#rpc_shell_write(sid, data) ⇒ Hash
Writes to a shell session (such as a command). Note that you will to manually add a newline at the enf of your input so the system will process it. You may want to use #rpc_shell_read to retrieve the output.
137 138 139 140 141 142 143 144 145 146 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 137 def rpc_shell_write( sid, data) error(400, 'Data must be a String') unless data.is_a?(String) s = _valid_session(sid,"shell") begin res = s.shell_write(data) { "write_count" => res.to_s} rescue ::Exception => e error(500, "Session Disconnected: #{e.class} #{e}") end end |
#rpc_stop(sid) ⇒ Hash
Stops a session - alias for killing a session in ‘msfconsole`
>> rpc.call(‘session.list’)
{7=>
{"type"=>"meterpreter",
"tunnel_local"=>"192.168.xxx.xxx:4444",
"tunnel_peer"=>"192.168.xxx.xxx:64688",
"via_exploit"=>"exploit/windows/smb/ms17_010_eternalblue",
"via_payload"=>"payload/windows/x64/meterpreter/reverse_tcp",
"desc"=>"Meterpreter",
"info"=>"NT AUTHORITY\\SYSTEM @ DC1",
"workspace"=>"default",
"session_host"=>"192.168.xxx.xxx",
"session_port"=>445,
"target_host"=>"192.168.xxx.xxx",
"username"=>"foo",
"uuid"=>"h9pbmuoh",
"exploit_uuid"=>"tcjj1fqo",
"routes"=>"",
"arch"=>"x86",
"platform"=>"windows"}}
>> rpc.call(‘session.stop’, 7)
> “result”=>“success”
88 89 90 91 92 93 94 95 96 |
# File 'lib/msf/core/rpc/v10/rpc_session.rb', line 88 def rpc_stop( sid) s = self.framework.sessions[sid.to_i] if(not s) error(500, "Unknown Session ID") end s.kill rescue nil { "result" => "success" } end |