Class: Rex::Post::Meterpreter::Extensions::Stdapi::Sys::Process

Inherits:
Process
  • Object
show all
Includes:
ObjectAliasesContainer
Defined in:
lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb

Overview

This class implements the Rex::Post::Process interface.

Class Attribute Summary collapse

Instance Attribute Summary collapse

Attributes included from ObjectAliasesContainer

#aliases

Class Method Summary collapse

Instance Method Summary collapse

Methods included from ObjectAliasesContainer

#dump_alias_tree, #initialize_aliases, #method_missing

Methods inherited from Process

[], _open, capture_output, each_process, execute, get_processes, getpid, kill, memory_search, open, processes

Constructor Details

#initialize(pid, handle, channel = nil) ⇒ Process

Initializes the process instance and its aliases.



351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 351

def initialize(pid, handle, channel = nil)
  self.client  = self.class.client
  self.handle  = handle
  self.channel = channel

  # If the process identifier is zero, then we must lookup the current
  # process identifier
  if (pid == 0)
    self.pid = client.sys.process.getpid
  else
    self.pid = pid
  end

  initialize_aliases(
    {
      'image'  => Rex::Post::Meterpreter::Extensions::Stdapi::Sys::ProcessSubsystem::Image.new(self),
      'io'     => Rex::Post::Meterpreter::Extensions::Stdapi::Sys::ProcessSubsystem::IO.new(self),
      'memory' => Rex::Post::Meterpreter::Extensions::Stdapi::Sys::ProcessSubsystem::Memory.new(self),
      'thread' => Rex::Post::Meterpreter::Extensions::Stdapi::Sys::ProcessSubsystem::Thread.new(self),
    })

  # Ensure the remote object is closed when all references are removed
  ObjectSpace.define_finalizer(self, self.class.finalize(client, handle))
end

Dynamic Method Handling

This class handles dynamic methods through the method_missing method in the class Rex::Post::Meterpreter::ObjectAliasesContainer

Class Attribute Details

.client ⇒ Object

Returns the value of attribute client.



37
38
39
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 37

def client
  @client
end

Instance Attribute Details

#channel ⇒ Object

:nodoc:



444
445
446
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 444

def channel
  @channel
end

#client ⇒ Object

:nodoc:



444
445
446
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 444

def client
  @client
end

#handle ⇒ Object

:nodoc:



444
445
446
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 444

def handle
  @handle
end

#pid ⇒ Object

:nodoc:



444
445
446
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 444

def pid
  @pid
end

Class Method Details

.close(client, handle) ⇒ Object

Closes the handle to the process that was opened.



408
409
410
411
412
413
414
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 408

def self.close(client, handle)
  request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_CLOSE)
  request.add_tlv(TLV_TYPE_HANDLE, handle)
  client.send_request(request, nil)
  handle = nil
  return true
end

.finalize(client, handle) ⇒ Object



376
377
378
379
380
381
382
383
384
385
386
387
388
389
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 376

def self.finalize(client, handle)
  proc do
    deferred_close_proc = proc do
      begin
        self.close(client, handle)
      rescue => e
        elog("finalize method for Process failed", error: e)
      end
    end

    # Schedule the finalizing logic out-of-band; as this logic might be called in the context of a Signal.trap, which can't synchronize mutexes
    client.framework.sessions.schedule(deferred_close_proc)
  end
end

Instance Method Details

#close(handle = self.handle) ⇒ Object

Instance method



419
420
421
422
423
424
425
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 419

def close(handle = self.handle)
  unless self.pid.nil?
    ObjectSpace.undefine_finalizer(self)
    self.class.close(self.client, handle)
    self.pid = nil
  end
end

#get_info ⇒ Object (protected)

Gathers information about the process and returns a hash.



451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 451

def get_info
  request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_GET_INFO)
  info    = {}

  request.add_tlv(TLV_TYPE_HANDLE, handle)

  # Send the request
  response = client.send_request(request)

  # Populate the hash
  info['name'] = client.unicode_filter_encode( response.get_tlv_value(TLV_TYPE_PROCESS_NAME) )
  info['path'] = client.unicode_filter_encode( response.get_tlv_value(TLV_TYPE_PROCESS_PATH) )

  return info
end

#name ⇒ Object

Returns the executable name of the process.



394
395
396
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 394

def name
  return get_info()['name']
end

#path ⇒ Object

Returns the path to the process' executable.



401
402
403
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 401

def path
  return get_info()['path']
end

#wait(timeout = -1 )) ⇒ Object

Block until this process terminates on the remote side. By default we choose not to allow a packet response timeout to occur as we may be waiting indefinatly for the process to terminate.



432
433
434
435
436
437
438
439
440
441
442
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/process.rb', line 432

def wait( timeout = -1 )
  request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_WAIT)

  request.add_tlv(TLV_TYPE_HANDLE, self.handle)

  self.client.send_request(request, timeout)

  self.handle = nil

  return true
end