Class: Rex::Post::Meterpreter::Extensions::Stdapi::Sys::Registry

Inherits:
Object
  • Object
show all
Defined in:
lib/rex/post/meterpreter/extensions/stdapi/sys/registry.rb

Overview

This class provides access to the Windows registry on the remote machine.

Class Attribute Summary collapse

Class Method Summary collapse

Class Attribute Details

.client ⇒ Object

Returns the value of attribute client.



28
29
30
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/registry.rb', line 28

def client
  @client
end

Class Method Details

.key2str(key) ⇒ Object

Return the key value associated with the supplied string. This is useful for converting HKLM as a string into its actual integer representation.



350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/registry.rb', line 350

def self.key2str(key)
  if (key == 'HKLM' or key == 'HKEY_LOCAL_MACHINE')
    return HKEY_LOCAL_MACHINE
  elsif (key == 'HKCU' or key == 'HKEY_CURRENT_USER')
    return HKEY_CURRENT_USER
  elsif (key == 'HKU' or key == 'HKEY_USERS')
    return HKEY_USERS
  elsif (key == 'HKCR' or key == 'HKEY_CLASSES_ROOT')
    return HKEY_CLASSES_ROOT
  elsif (key == 'HKEY_CURRENT_CONFIG')
    return HKEY_CURRENT_CONFIG
  elsif (key == 'HKEY_PERFORMANCE_DATA')
    return HKEY_PERFORMANCE_DATA
  elsif (key == 'HKEY_DYN_DATA')
    return HKEY_DYN_DATA
  else
    raise ArgumentError, "Unknown key: #{key}"
  end
end

.splitkey(str) ⇒ Object

Split the supplied full registry key into its root key and base key. For instance, passing HKLMSoftwareDog will return [ HKEY_LOCAL_MACHINE, 'SoftwareDog' ]



396
397
398
399
400
401
402
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/registry.rb', line 396

def self.splitkey(str)
  if (str =~ /^(.+?)[\\]{1,}(.*)$/)
    [ key2str($1), $2 ]
  else
    [ key2str(str), nil ]
  end
end

.type2str(type) ⇒ Integer

Returns the integer value associated with the supplied registry value type (like REG_SZ).

Parameters:

  • type (String) —

    A Windows registry type constant name, e.g. 'REG_SZ'

Returns:

  • (Integer) —

    one of the REG_* constants

See Also:



377
378
379
380
381
382
383
384
385
386
387
388
389
# File 'lib/rex/post/meterpreter/extensions/stdapi/sys/registry.rb', line 377

def self.type2str(type)
  case type
  when 'REG_BINARY'    then REG_BINARY
  when 'REG_DWORD'     then REG_DWORD
  when 'REG_EXPAND_SZ' then REG_EXPAND_SZ
  when 'REG_MULTI_SZ'  then REG_MULTI_SZ
  when 'REG_NONE'      then REG_NONE
  when 'REG_QWORD'     then REG_QWORD
  when 'REG_SZ'        then REG_SZ
  else
    nil
  end
end