Repository navigation
Expand file tree
/
Copy pathsecurity_descriptor.rb
More file actions
232 lines (185 loc) · 7.3 KB
/
Copy pathsecurity_descriptor.rb
File metadata and controls
232 lines (185 loc) · 7.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
require 'spec_helper'
RSpec.describe RubySMB::Field::SecurityDescriptor do
subject(:descriptor) {
struct = described_class.new
struct.owner_sid = 'ABCD'
struct.group_sid = 'ABCD'
struct.sacl = 'ABCD'
struct.dacl = 'ABCD'
struct
}
it { is_expected.to respond_to :revision }
it { is_expected.to respond_to :sbz1 }
it { is_expected.to respond_to :control }
it { is_expected.to respond_to :offset_owner }
it { is_expected.to respond_to :offset_group }
it { is_expected.to respond_to :offset_sacl }
it { is_expected.to respond_to :offset_dacl }
it { is_expected.to respond_to :owner_sid }
it { is_expected.to respond_to :group_sid }
it { is_expected.to respond_to :sacl }
it { is_expected.to respond_to :dacl }
it 'is little endian' do
expect(described_class.fields.instance_variable_get(:@hints)[:endian]).to eq :little
end
it 'tracks the offset to the #owner_sid' do
expect(descriptor.offset_owner).to eq descriptor.owner_sid.rel_offset
end
it 'tracks the offset to the #group_sid' do
expect(descriptor.offset_group).to eq descriptor.group_sid.rel_offset
end
it 'tracks the offset to the #sacl' do
expect(descriptor.offset_sacl).to eq descriptor.sacl.rel_offset
end
it 'tracks the offset to the #dacl' do
expect(descriptor.offset_dacl).to eq descriptor.dacl.rel_offset
end
# Regression for rapid7/ruby_smb#289: a self-relative security descriptor
# returned by the server (Control word 0x9404, little-endian bytes
# "\x04\x94") was parsed with dacl_present and self_relative cleared because
# the Control bit1 fields did not follow the MS-DTYP 2.4.6 bit numbering.
describe 'parsing a self-relative descriptor (issue #289)' do
let(:byte_stream) do
[
0x01, # Revision
0x00, # Sbz1
0x04, 0x94, # Control = 0x9404 (LE): SR + PD + DI + DP
0x8c, 0x00, 0x00, 0x00, # OffsetOwner
0x9c, 0x00, 0x00, 0x00, # OffsetGroup
0x00, 0x00, 0x00, 0x00, # OffsetSacl
0x14, 0x00, 0x00, 0x00 # OffsetDacl
].pack('C*')
end
subject(:control) { described_class.read(byte_stream).control }
it 'reports the DACL as present' do
expect(control.dacl_present).to eq 1
end
it 'reports the descriptor as self-relative' do
expect(control.self_relative).to eq 1
end
it 'sets exactly the SR, PD, DI and DP flags' do
set_flags = control.field_names.select { |name| control.send(name) == 1 }
expect(set_flags).to contain_exactly(
:self_relative, :dacl_protected, :dacl_auto_inherited, :dacl_present
)
end
it 'reads the DACL offset' do
expect(described_class.read(byte_stream).offset_dacl).to eq 20
end
end
describe '#control' do
subject(:control) { descriptor.control }
it { is_expected.to respond_to :owner_defaulted }
it { is_expected.to respond_to :group_defaulted }
it { is_expected.to respond_to :dacl_present }
it { is_expected.to respond_to :dacl_defaulted }
it { is_expected.to respond_to :sacl_present }
it { is_expected.to respond_to :sacl_defaulted }
it { is_expected.to respond_to :server_security }
it { is_expected.to respond_to :dacl_trusted }
it { is_expected.to respond_to :dacl_computed_inheritance }
it { is_expected.to respond_to :sacl_computed_inheritance }
it { is_expected.to respond_to :dacl_auto_inherited }
it { is_expected.to respond_to :sacl_auto_inherited }
it { is_expected.to respond_to :dacl_protected }
it { is_expected.to respond_to :sacl_protected }
it { is_expected.to respond_to :rm_control_valid }
it { is_expected.to respond_to :self_relative }
describe '#self_relative' do
it 'is a 1-bit flag' do
expect(control.self_relative).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :self_relative, 'v', 0x8000
end
describe '#rm_control_valid' do
it 'is a 1-bit flag' do
expect(control.rm_control_valid).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :rm_control_valid, 'v', 0x4000
end
describe '#sacl_protected' do
it 'is a 1-bit flag' do
expect(control.sacl_protected).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :sacl_protected, 'v', 0x2000
end
describe '#dacl_protected' do
it 'is a 1-bit flag' do
expect(control.dacl_protected).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_protected, 'v', 0x1000
end
describe '#sacl_auto_inherited' do
it 'is a 1-bit flag' do
expect(control.sacl_auto_inherited).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :sacl_auto_inherited, 'v', 0x0800
end
describe '#dacl_auto_inherited' do
it 'is a 1-bit flag' do
expect(control.dacl_auto_inherited).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_auto_inherited, 'v', 0x0400
end
describe '#sacl_computed_inheritance' do
it 'is a 1-bit flag' do
expect(control.sacl_computed_inheritance).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :sacl_computed_inheritance, 'v', 0x0200
end
describe '#dacl_computed_inheritance' do
it 'is a 1-bit flag' do
expect(control.dacl_computed_inheritance).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_computed_inheritance, 'v', 0x0100
end
describe '#dacl_trusted' do
it 'is a 1-bit flag' do
expect(control.dacl_trusted).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_trusted, 'v', 0x0040
end
describe '#server_security' do
it 'is a 1-bit flag' do
expect(control.server_security).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :server_security, 'v', 0x0080
end
describe '#sacl_defaulted' do
it 'is a 1-bit flag' do
expect(control.sacl_defaulted).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :sacl_defaulted, 'v', 0x0020
end
describe '#sacl_present' do
it 'is a 1-bit flag' do
expect(control.sacl_present).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :sacl_present, 'v', 0x0010
end
describe '#dacl_defaulted' do
it 'is a 1-bit flag' do
expect(control.dacl_defaulted).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_defaulted, 'v', 0x0008
end
describe '#dacl_present' do
it 'is a 1-bit flag' do
expect(control.dacl_present).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :dacl_present, 'v', 0x0004
end
describe '#group_defaulted' do
it 'is a 1-bit flag' do
expect(control.group_defaulted).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :group_defaulted, 'v', 0x0002
end
describe '#owner_defaulted' do
it 'is a 1-bit flag' do
expect(control.owner_defaulted).to be_a BinData::Bit1
end
it_behaves_like 'bit field with one flag set', :owner_defaulted, 'v', 0x0001
end
end
end