NTTransactHelper.cs 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166
  1. /* Copyright (C) 2014-2017 Tal Aloni <tal.aloni.il@gmail.com>. All rights reserved.
  2. *
  3. * You can redistribute this program and/or modify it under the terms of
  4. * the GNU Lesser Public License as published by the Free Software Foundation,
  5. * either version 3 of the License, or (at your option) any later version.
  6. */
  7. using System;
  8. using System.Collections.Generic;
  9. using System.Text;
  10. using SMBLibrary.SMB1;
  11. using Utilities;
  12. namespace SMBLibrary.Server.SMB1
  13. {
  14. internal class NTTransactHelper
  15. {
  16. /// <summary>
  17. /// The client MUST send as many secondary requests as are needed to complete the transfer of the transaction request.
  18. /// </summary>
  19. internal static List<SMB1Command> GetNTTransactResponse(SMB1Header header, NTTransactRequest request, ISMBShare share, SMB1ConnectionState state)
  20. {
  21. if (request.TransParameters.Length < request.TotalParameterCount ||
  22. request.TransData.Length < request.TotalDataCount)
  23. {
  24. // A secondary transaction request is pending
  25. ProcessStateObject processState = state.CreateProcessState(header.PID);
  26. processState.SubcommandID = (ushort)request.Function;
  27. processState.MaxDataCount = request.MaxDataCount;
  28. processState.TransactionSetup = request.Setup;
  29. processState.TransactionParameters = new byte[request.TotalParameterCount];
  30. processState.TransactionData = new byte[request.TotalDataCount];
  31. ByteWriter.WriteBytes(processState.TransactionParameters, 0, request.TransParameters);
  32. ByteWriter.WriteBytes(processState.TransactionData, 0, request.TransData);
  33. processState.TransactionParametersReceived += request.TransParameters.Length;
  34. processState.TransactionDataReceived += request.TransData.Length;
  35. return new NTTransactInterimResponse();
  36. }
  37. else
  38. {
  39. // We have a complete command
  40. return GetCompleteNTTransactResponse(header, request.MaxDataCount, request.Function, request.Setup, request.TransParameters, request.TransData, share, state);
  41. }
  42. }
  43. /// <summary>
  44. /// There are no secondary response messages.
  45. /// The client MUST send as many secondary requests as are needed to complete the transfer of the transaction request.
  46. /// </summary>
  47. internal static List<SMB1Command> GetNTTransactResponse(SMB1Header header, NTTransactSecondaryRequest request, ISMBShare share, SMB1ConnectionState state)
  48. {
  49. ProcessStateObject processState = state.GetProcessState(header.PID);
  50. if (processState == null)
  51. {
  52. throw new InvalidRequestException();
  53. }
  54. ByteWriter.WriteBytes(processState.TransactionParameters, (int)request.ParameterDisplacement, request.TransParameters);
  55. ByteWriter.WriteBytes(processState.TransactionData, (int)request.DataDisplacement, request.TransData);
  56. processState.TransactionParametersReceived += request.TransParameters.Length;
  57. processState.TransactionDataReceived += request.TransData.Length;
  58. if (processState.TransactionParametersReceived < processState.TransactionParameters.Length ||
  59. processState.TransactionDataReceived < processState.TransactionData.Length)
  60. {
  61. return new List<SMB1Command>();
  62. }
  63. else
  64. {
  65. // We have a complete command
  66. state.RemoveProcessState(header.PID);
  67. return GetCompleteNTTransactResponse(header, processState.MaxDataCount, (NTTransactSubcommandName)processState.SubcommandID, processState.TransactionSetup, processState.TransactionParameters, processState.TransactionData, share, state);
  68. }
  69. }
  70. internal static List<SMB1Command> GetCompleteNTTransactResponse(SMB1Header header, uint maxDataCount, NTTransactSubcommandName subcommandName, byte[] requestSetup, byte[] requestParameters, byte[] requestData, ISMBShare share, SMB1ConnectionState state)
  71. {
  72. NTTransactSubcommand subcommand = NTTransactSubcommand.GetSubcommandRequest(subcommandName, requestSetup, requestParameters, requestData, header.UnicodeFlag);
  73. NTTransactSubcommand subcommandResponse = null;
  74. if (subcommand is NTTransactCreateRequest)
  75. {
  76. header.Status = NTStatus.STATUS_NOT_IMPLEMENTED;
  77. }
  78. else if (subcommand is NTTransactIOCTLRequest)
  79. {
  80. subcommandResponse = GetSubcommandResponse(header, maxDataCount, (NTTransactIOCTLRequest)subcommand, share, state);
  81. }
  82. else if (subcommand is NTTransactSetSecurityDescriptor)
  83. {
  84. header.Status = NTStatus.STATUS_NOT_IMPLEMENTED;
  85. }
  86. else if (subcommand is NTTransactNotifyChangeRequest)
  87. {
  88. // [MS-CIFS] If the server does not support the NT_TRANSACT_NOTIFY_CHANGE subcommand, it can return an
  89. // error response with STATUS_NOT_IMPLEMENTED [..] in response to an NT_TRANSACT_NOTIFY_CHANGE Request.
  90. header.Status = NTStatus.STATUS_NOT_IMPLEMENTED;
  91. }
  92. else if (subcommand is NTTransactQuerySecurityDescriptorRequest)
  93. {
  94. header.Status = NTStatus.STATUS_NOT_IMPLEMENTED;
  95. }
  96. else
  97. {
  98. header.Status = NTStatus.STATUS_SMB_BAD_COMMAND;
  99. }
  100. if (subcommandResponse == null)
  101. {
  102. return new ErrorResponse(CommandName.SMB_COM_NT_TRANSACT);
  103. }
  104. byte[] responseSetup = subcommandResponse.GetSetup();
  105. byte[] responseParameters = subcommandResponse.GetParameters(header.UnicodeFlag);
  106. byte[] responseData = subcommandResponse.GetData();
  107. return GetNTTransactResponse(responseSetup, responseParameters, responseData, state.MaxBufferSize);
  108. }
  109. private static NTTransactIOCTLResponse GetSubcommandResponse(SMB1Header header, uint maxDataCount, NTTransactIOCTLRequest subcommand, ISMBShare share, SMB1ConnectionState state)
  110. {
  111. SMB1Session session = state.GetSession(header.UID);
  112. NTTransactIOCTLResponse response = new NTTransactIOCTLResponse();
  113. if (subcommand.IsFsctl)
  114. {
  115. OpenFileObject openFile = session.GetOpenFileObject(subcommand.FID);
  116. if (openFile == null)
  117. {
  118. header.Status = NTStatus.STATUS_INVALID_HANDLE;
  119. return null;
  120. }
  121. int maxOutputLength = (int)maxDataCount;
  122. byte[] output;
  123. header.Status = share.FileStore.DeviceIOControl(openFile.Handle, subcommand.FunctionCode, subcommand.Data, out output, maxOutputLength);
  124. if (header.Status != NTStatus.STATUS_SUCCESS && header.Status != NTStatus.STATUS_BUFFER_OVERFLOW)
  125. {
  126. return null;
  127. }
  128. response.Data = output;
  129. return response;
  130. }
  131. else
  132. {
  133. // [MS-SMB] If the IsFsctl field is set to zero, the server SHOULD fail the request with STATUS_NOT_SUPPORTED
  134. header.Status = NTStatus.STATUS_NOT_SUPPORTED;
  135. return null;
  136. }
  137. }
  138. private static List<SMB1Command> GetNTTransactResponse(byte[] responseSetup, byte[] responseParameters, byte[] responseData, int maxBufferSize)
  139. {
  140. if (NTTransactResponse.CalculateMessageSize(responseSetup.Length, responseParameters.Length, responseData.Length) <= maxBufferSize)
  141. {
  142. NTTransactResponse response = new NTTransactResponse();
  143. response.Setup = responseSetup;
  144. response.TotalParameterCount = (ushort)responseParameters.Length;
  145. response.TotalDataCount = (ushort)responseData.Length;
  146. response.TransParameters = responseParameters;
  147. response.TransData = responseData;
  148. return response;
  149. }
  150. else
  151. {
  152. throw new NotImplementedException();
  153. }
  154. }
  155. }
  156. }