Files
amiga-smbfs/source_code/dump_smb.c
T
obarthel d058085b8a Updated to version 2.13
The ACTION_CREATE_DIR, ACTION_DELETE_OBJECT, ACTION_FINDOUTPUT, ACTION_RENAME_OBJECT, ACTION_SET_DATE, ACTION_SET_FILE_SIZE, ACTION_SET_PROTECT and ACTION_WRITE operations now set use more appropriate error codes instead of always translating an unspecific "access denied" error into "ERROR_READ_PROTECTED". For example, for ACTION_DELETE_OBJECT the new translation of "access denied" will be "ERROR_DELETE_PROTECTED".

Added the ErrorOutput option, which can be either "stderr" (default) or "stdout". Its purpose is to allow error messages written by smbfs to be redirected to a file, which will not work for AmigaDOS shell versions 36-40 if smbfs uses "stderr". Use ErrorOutput=stdout to be able to redirect all smbfs output, including any error messages, to a file.

Updated the copyright text.

Output to console or log files is now line-buffered.
2019-02-09 11:58:20 +01:00

4537 lines
150 KiB
C

/*
* :ts=4
*
* dump_smb.c
*
* Copyright (C) 2016-2019 by Olaf `Olsen' Barthel <obarthel -at- gmx -dot- net>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
*/
#if defined(DUMP_SMB)
/*****************************************************************************/
#include "smbfs.h"
/*****************************************************************************/
#include "dump_smb.h"
#include "quad_math.h"
/*****************************************************************************/
/* The following is an attempt to decode the data that is received
* and sent. Because so much of smbfs was created by reverse-engineering
* the protocol it is difficult to say what works, and how.
*/
/*****************************************************************************/
/* This can be used to enable or disable the SMB packet dump output. */
static int dump_smb_enabled;
/* This is for controlling how much output is produced. Higher
* numbers yield more output.
*/
static int dump_smb_level;
/* This is where the output should go. It could be a file. */
static BPTR dump_smb_file;
static BOOL dump_smb_stdout;
/*****************************************************************************/
/* This keeps track of which SMB_COM_TRANSACTION2 subcommand was last
* sent to the server. The server will respond to it, but the message does
* not contain the subcommand code of the request which started it.
*/
static int last_smb_com_transaction_subcommand = -1;
/* This keeps track of the information level specified when directory
* contents were to be retrieved by the TRANS2_FIND_FIRST2 command.
* The data will be returned, but it's not repeated in the
* server response message.
*/
static int last_trans2_find_information_level = -1;
/*****************************************************************************/
static unsigned long next_data_dword(const unsigned char * data,int * offset_ptr)
{
int offset = (*offset_ptr);
unsigned long result;
result =
(((unsigned long)data[offset + 3]) << 24) |
(((unsigned long)data[offset + 2]) << 16) |
(((unsigned long)data[offset + 1]) << 8) |
(unsigned long)data[offset + 0];
(*offset_ptr) = offset + 4;
return(result);
}
static void next_data_qword(const unsigned char * data,unsigned long *qwords,int * offset_ptr)
{
qwords[1] = next_data_dword(data,offset_ptr);
qwords[0] = next_data_dword(data,offset_ptr);
}
static unsigned short next_data_word(const unsigned char * data,int * offset_ptr)
{
int offset = (*offset_ptr);
unsigned short result;
result =
(((unsigned short)data[offset+1]) << 8) |
(unsigned short)data[offset+0];
(*offset_ptr) = offset + 2;
return(result);
}
static unsigned char next_data_byte(const unsigned char * data,int * offset_ptr)
{
int offset = (*offset_ptr);
unsigned char result;
result = data[offset];
(*offset_ptr) = offset + 1;
return(result);
}
static const unsigned char * next_data_bytes(const unsigned char * data,int num_bytes,int * offset_ptr)
{
int offset = (*offset_ptr);
const unsigned char * result;
result = &data[offset];
(*offset_ptr) = offset + num_bytes;
return(result);
}
static const unsigned char * next_data_words(const unsigned char * data,int num_words,int * offset_ptr)
{
return(next_data_bytes(data,2 * num_words,offset_ptr));
}
static void skip_data_bytes(const unsigned char * data,int num_bytes,int * offset_ptr)
{
(*offset_ptr) = (*offset_ptr) + num_bytes;
}
static void skip_data_words(const unsigned char * data,int num_words,int * offset_ptr)
{
skip_data_bytes(data,2 * num_words,offset_ptr);
}
/*****************************************************************************/
static int
fill_header(const unsigned char * packet,int length,struct smb_header * header)
{
int num_bytes_read;
int offset = 0;
memset(header,0,sizeof(header));
header->raw_packet_size = length;
header->raw_packet = (char *)packet;
memmove(header->signature,next_data_bytes(packet,4,&offset),4);
header->command = next_data_byte(packet,&offset);
header->status = next_data_dword(packet,&offset);
header->flags = next_data_byte(packet,&offset);
header->flags2 = next_data_word(packet,&offset);
header->extra.pid_high = next_data_word(packet,&offset);
memmove(header->extra.signature,next_data_words(packet,4,&offset),sizeof(unsigned short) * 4);
skip_data_words(packet,1,&offset);
header->tid = next_data_word(packet,&offset);
header->pid = next_data_word(packet,&offset);
header->uid = next_data_word(packet,&offset);
header->mid = next_data_word(packet,&offset);
header->num_parameter_words = next_data_byte(packet,&offset);
header->parameter_offset = offset;
header->parameters = (unsigned char *)next_data_words(packet,header->num_parameter_words,&offset);
header->num_data_bytes = next_data_word(packet,&offset);
header->data_offset = offset;
header->data = (unsigned char *)next_data_bytes(packet,header->num_data_bytes,&offset);
num_bytes_read = offset;
return(num_bytes_read);
}
/*****************************************************************************/
static int
is_smb_andx_command(unsigned char command)
{
static const unsigned char andx_commands[9] =
{
SMB_COM_LOCKING_ANDX,
SMB_COM_OPEN_ANDX,
SMB_COM_READ_ANDX,
SMB_COM_WRITE_ANDX,
SMB_COM_SESSION_SETUP_ANDX,
SMB_COM_LOGOFF_ANDX,
SMB_COM_TREE_CONNECT_ANDX,
SMB_COM_SECURITY_PACKAGE_ANDX,
SMB_COM_NT_CREATE_ANDX
};
int result = 0;
int i;
for(i = 0 ; i < 9 ; i++)
{
if(command == andx_commands[i])
{
result = 1;
break;
}
}
return(result);
}
/*****************************************************************************/
static const char *
get_smb_transaction2_subcommand_name(int command)
{
static const struct { int code ; const char * name; } code_name_tab[] =
{
{ TRANS2_OPEN2, "TRANS2_OPEN2" },
{ TRANS2_FIND_FIRST2, "TRANS2_FIND_FIRST2" },
{ TRANS2_FIND_NEXT2, "TRANS2_FIND_NEXT2" },
{ TRANS2_QUERY_FS_INFORMATION, "TRANS2_QUERY_FS_INFORMATION" },
{ TRANS2_QUERY_PATH_INFORMATION, "TRANS2_QUERY_PATH_INFORMATION" },
{ TRANS2_SET_PATH_INFORMATION, "TRANS2_SET_PATH_INFORMATION" },
{ TRANS2_QUERY_FILE_INFORMATION, "TRANS2_QUERY_FILE_INFORMATION" },
{ TRANS2_SET_FILE_INFORMATION, "TRANS2_SET_FILE_INFORMATION" },
{ TRANS2_FSCTL, "TRANS2_FSCTL" },
{ TRANS2_IOCTL2, "TRANS2_IOCTL2" },
{ TRANS2_FIND_NOTIFY_FIRST, "TRANS2_FIND_NOTIFY_FIRST" },
{ TRANS2_FIND_NOTIFY_NEXT, "TRANS2_FIND_NOTIFY_NEXT" },
{ TRANS2_CREATE_DIRECTORY, "TRANS2_CREATE_DIRECTORY" },
{ TRANS2_SESSION_SETUP, "TRANS2_SESSION_SETUP" },
{ -1, NULL }
};
const char * result = NULL;
int i;
for(i = 0 ; code_name_tab[i].code != -1 ; i++)
{
if(command == code_name_tab[i].code)
{
result = code_name_tab[i].name;
break;
}
}
return(result);
}
/*****************************************************************************/
static const char *
get_smb_command_name(unsigned char command)
{
static const struct { int code; const char * name; } code_name_tab[] =
{
{ SMB_COM_CREATE_DIRECTORY, "CREATE_DIRECTORY" },
{ SMB_COM_DELETE_DIRECTORY, "DELETE_DIRECTORY" },
{ SMB_COM_OPEN, "OPEN" },
{ SMB_COM_CREATE, "CREATE" },
{ SMB_COM_CLOSE, "CLOSE" },
{ SMB_COM_FLUSH, "FLUSH" },
{ SMB_COM_DELETE, "DELETE" },
{ SMB_COM_RENAME, "RENAME" },
{ SMB_COM_QUERY_INFORMATION, "QUERY_INFORMATION" },
{ SMB_COM_SET_INFORMATION, "SET_INFORMATION" },
{ SMB_COM_READ, "READ" },
{ SMB_COM_WRITE, "WRITE" },
{ SMB_COM_LOCK_BYTE_RANGE, "LOCK_BYTE_RANGE" },
{ SMB_COM_UNLOCK_BYTE_RANGE, "UNLOCK_BYTE_RANGE" },
{ SMB_COM_CREATE_TEMPORARY, "CREATE_TEMPORARY" },
{ SMB_COM_CREATE_NEW, "CREATE_NEW" },
{ SMB_COM_CHECK_DIRECTORY, "CHECK_DIRECTORY" },
{ SMB_COM_PROCESS_EXIT, "PROCESS_EXIT" },
{ SMB_COM_SEEK, "SEEK" },
{ SMB_COM_LOCK_AND_READ, "LOCK_AND_READ" },
{ SMB_COM_WRITE_AND_UNLOCK, "WRITE_AND_UNLOCK" },
{ SMB_COM_READ_RAW, "READ_RAW" },
{ SMB_COM_READ_MPX, "READ_MPX" },
{ SMB_COM_READ_MPX_SECONDARY, "READ_MPX_SECONDARY" },
{ SMB_COM_WRITE_RAW, "WRITE_RAW" },
{ SMB_COM_WRITE_MPX, "WRITE_MPX" },
{ SMB_COM_WRITE_MPX_SECONDARY, "WRITE_MPX_SECONDARY" },
{ SMB_COM_WRITE_COMPLETE, "WRITE_COMPLETE" },
{ SMB_COM_QUERY_SERVER, "QUERY_SERVER" },
{ SMB_COM_SET_INFORMATION2, "SET_INFORMATION2" },
{ SMB_COM_QUERY_INFORMATION2, "QUERY_INFORMATION2" },
{ SMB_COM_LOCKING_ANDX, "LOCKING_ANDX" },
{ SMB_COM_TRANSACTION, "TRANSACTION" },
{ SMB_COM_TRANSACTION_SECONDARY, "TRANSACTION_SECONDARY" },
{ SMB_COM_IOCTL, "IOCTL" },
{ SMB_COM_IOCTL_SECONDARY, "IOCTL_SECONDARY" },
{ SMB_COM_COPY, "COPY" },
{ SMB_COM_MOVE, "MOVE" },
{ SMB_COM_ECHO, "ECHO" },
{ SMB_COM_WRITE_AND_CLOSE, "WRITE_AND_CLOSE" },
{ SMB_COM_OPEN_ANDX, "OPEN_ANDX" },
{ SMB_COM_READ_ANDX, "READ_ANDX" },
{ SMB_COM_WRITE_ANDX, "WRITE_ANDX" },
{ SMB_COM_NEW_FILE_SIZE, "NEW_FILE_SIZE" },
{ SMB_COM_CLOSE_AND_TREE_DISC, "CLOSE_AND_TREE_DISC" },
{ SMB_COM_TRANSACTION2, "TRANSACTION2" },
{ SMB_COM_TRANSACTION2_SECONDARY, "TRANSACTION2_SECONDARY" },
{ SMB_COM_FIND_CLOSE2, "FIND_CLOSE2" },
{ SMB_COM_FIND_NOTIFY_CLOSE, "FIND_NOTIFY_CLOSE" },
{ SMB_COM_TREE_CONNECT, "TREE_CONNECT" },
{ SMB_COM_TREE_DISCONNECT, "TREE_DISCONNECT" },
{ SMB_COM_NEGOTIATE, "NEGOTIATE" },
{ SMB_COM_SESSION_SETUP_ANDX, "SESSION_SETUP_ANDX" },
{ SMB_COM_LOGOFF_ANDX, "LOGOFF_ANDX" },
{ SMB_COM_TREE_CONNECT_ANDX, "TREE_CONNECT_ANDX" },
{ SMB_COM_SECURITY_PACKAGE_ANDX, "SECURITY_PACKAGE_ANDX" },
{ SMB_COM_QUERY_INFORMATION_DISK, "QUERY_INFORMATION_DISK" },
{ SMB_COM_SEARCH, "SEARCH" },
{ SMB_COM_FIND, "FIND" },
{ SMB_COM_FIND_UNIQUE, "FIND_UNIQUE" },
{ SMB_COM_FIND_CLOSE, "FIND_CLOSE" },
{ SMB_COM_NT_TRANSACT, "NT_TRANSACT" },
{ SMB_COM_NT_TRANSACT_SECONDARY, "NT_TRANSACT_SECONDARY" },
{ SMB_COM_NT_CREATE_ANDX, "NT_CREATE_ANDX" },
{ SMB_COM_NT_CANCEL, "NT_CANCEL" },
{ SMB_COM_NT_RENAME, "NT_RENAME" },
{ SMB_COM_OPEN_PRINT_FILE, "OPEN_PRINT_FILE" },
{ SMB_COM_WRITE_PRINT_FILE, "WRITE_PRINT_FILE" },
{ SMB_COM_CLOSE_PRINT_FILE, "CLOSE_PRINT_FILE" },
{ SMB_COM_GET_PRINT_QUEUE, "GET_PRINT_QUEUE" },
{ SMB_COM_READ_BULK, "READ_BULK" },
{ SMB_COM_WRITE_BULK, "WRITE_BULK" },
{ SMB_COM_WRITE_BULK_DATA, "WRITE_BULK_DATA" },
{ SMB_COM_INVALID, "INVALID" },
{ SMB_COM_NO_ANDX_COMMAND, "NO_ANDX_COMMAND" },
{ -1, NULL }
};
const char * result = NULL;
int i;
for(i = 0 ; code_name_tab[i].code != -1 ; i++)
{
if(command == code_name_tab[i].code)
{
result = code_name_tab[i].name;
break;
}
}
return(result);
}
/*****************************************************************************/
struct line_buffer
{
char line[512];
size_t length;
};
/*****************************************************************************/
static void
init_line_buffer(struct line_buffer *lb)
{
lb->length = 0;
lb->line[lb->length] = '\0';
}
static void
set_line_buffer(struct line_buffer *lb,int c,size_t len)
{
if(len > sizeof(lb->line)-1)
len = sizeof(lb->line)-1;
memset(lb->line,c,len);
lb->length = len;
lb->line[lb->length] = '\0';
}
static void
copy_string_to_line_buffer(struct line_buffer *lb,const char *str,size_t len,size_t pos)
{
if(pos+len > sizeof(lb->line)-1)
{
if(pos < sizeof(lb->line)-1)
len = sizeof(lb->line)-1 - pos;
else
len = 0;
}
if(len > 0)
{
memmove(&lb->line[pos],str,len);
if(lb->length < pos+len)
{
lb->length = pos+len;
lb->line[lb->length] = '\0';
}
}
}
static void
add_lb_flag(struct line_buffer *lb,const char * str)
{
size_t len = strlen(str);
if(lb->length == 0)
{
if(lb->length + len < sizeof(lb->line)-1)
{
memmove(&lb->line[lb->length],str,len);
lb->length += len;
lb->line[lb->length] = '\0';
}
}
else
{
if(lb->length + 2 + len < sizeof(lb->line)-1)
{
memmove(&lb->line[lb->length],", ",2);
lb->length += 2;
memmove(&lb->line[lb->length],str,len);
lb->length += len;
lb->line[lb->length] = '\0';
}
}
}
/*****************************************************************************/
static void
print_smb_data(struct line_buffer * lb,int num_data_bytes_left,const unsigned char * data_bytes)
{
if(num_data_bytes_left > 0)
{
int row_offset = 0;
char format_buffer[20];
char dword_buffer[20];
int num_bytes_per_row,dword_pos;
size_t dword_buffer_len;
unsigned char c;
int c_pos;
while(num_data_bytes_left > 0)
{
/* The output line should be filled with blank spaces. */
set_line_buffer(lb,' ',60);
/* Print the row offset (in bytes) at the start of the
* output line.
*/
LocalSNPrintf(format_buffer,sizeof(format_buffer),"%04lx:",row_offset);
copy_string_to_line_buffer(lb,format_buffer,5,0);
/* Print up to 16 bytes per row. */
if(num_data_bytes_left > 16)
num_bytes_per_row = 16;
else
num_bytes_per_row = num_data_bytes_left;
dword_pos = 6;
dword_buffer[0] = '\0';
dword_buffer_len = 0;
c_pos = 45;
/* Print the bytes in hex format, followed by a column
* of the same data bytes interpreted as printable
* characters.
*/
while(num_bytes_per_row > 0)
{
c = (*data_bytes++);
num_bytes_per_row--;
row_offset++;
num_data_bytes_left--;
/* Convert this data byte to hexadecimal
* representation.
*/
LocalSNPrintf(format_buffer,sizeof(format_buffer),"%02lx",c);
strcat(dword_buffer,format_buffer);
dword_buffer_len += 2;
/* Is this not a printable character? If so,
* substitute it with '.'.
*/
if(c < ' ' || c == 127 || (128 <= c && c <= 160))
c = '.';
copy_string_to_line_buffer(lb,(char *)&c,1,c_pos);
c_pos++;
/* If we have converted four bytes to hexadecimal
* format, put them into the output buffer.
*/
if(dword_buffer_len >= 8)
{
copy_string_to_line_buffer(lb,dword_buffer,8,dword_pos);
dword_pos += 9;
dword_buffer[0] = '\0';
dword_buffer_len = 0;
}
}
/* If we did not convert a multiple of 32 bytes per row,
* add the last conversion buffer contents.
*/
if(dword_buffer_len > 0)
copy_string_to_line_buffer(lb,dword_buffer,dword_buffer_len,dword_pos);
FPrintf(dump_smb_file," %s\n",lb->line);
}
}
}
/*****************************************************************************/
static const struct tm *
convert_smb_date_time_to_tm(unsigned short smb_date,unsigned short smb_time)
{
static struct tm tm;
memset(&tm,0,sizeof(tm));
tm.tm_sec = (smb_time & 0x001f) * 2;
tm.tm_min = (smb_time & 0x07e0) >> 5;
tm.tm_hour = (smb_time & 0xf800) >> 11;
tm.tm_mday = smb_date & 0x001f;
tm.tm_mon = ((smb_date & 0x01e0) >> 5) - 1;
tm.tm_year = 80 + ((smb_date & 0xfe00) >> 9);
return(&tm);
}
/*****************************************************************************/
static const struct tm *
convert_filetime_to_tm(const unsigned long * qword)
{
const QUAD adjust_by_369_years = { 0x00000002,0xb6109100 };
QUAD long_date;
time_t when;
long_date.High = qword[0];
long_date.Low = qword[1];
/* Divide by 10,000,000 to convert the time from 100ns
* units into seconds.
*/
divide_64_by_32(&long_date,10000000,&long_date);
/* Adjust by 369 years (11,644,473,600 seconds) to convert
* from the epoch beginning on January 1st 1601 to the one
* beginning on January 1st 1970 (the Unix epoch).
*/
if(subtract_64_from_64_to_64(&long_date,&adjust_by_369_years,&long_date) == 0)
when = (time_t)long_date.Low;
else
when = (time_t)0;
return(gmtime(&when));
}
/*****************************************************************************/
static const char *
convert_filetime_to_string(const unsigned long * qword)
{
static char string[40];
const struct tm * tm;
tm = convert_filetime_to_tm(qword);
LocalSNPrintf(string,sizeof(string),"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
tm->tm_hour,tm->tm_min,tm->tm_sec);
return(string);
}
/*****************************************************************************/
static const char *
convert_smb_date_time_to_string(unsigned short smb_date,unsigned short smb_time)
{
static char string[40];
const struct tm * tm;
tm = convert_smb_date_time_to_tm(smb_date,smb_time);
LocalSNPrintf(string,sizeof(string),"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
tm->tm_hour,tm->tm_min,tm->tm_sec);
return(string);
}
/*****************************************************************************/
static const char *
convert_utime_to_string(unsigned long utime)
{
static char string[40];
const struct tm * tm;
time_t when = (time_t)utime;
tm = gmtime(&when);
LocalSNPrintf(string,sizeof(string),"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
tm->tm_hour,tm->tm_min,tm->tm_sec);
return(string);
}
/*****************************************************************************/
static const char *
convert_qword_to_string(const unsigned long *qword)
{
static char string[40];
QUAD number;
unsigned long n;
int len;
number.High = qword[0];
number.Low = qword[1];
memset(string,0,sizeof(string));
for(len = sizeof(string)-2 ; len >= 0 ; )
{
n = divide_64_by_32(&number,10,&number);
string[len--] = '0'+n;
if(number.High == 0 && number.Low == 0)
break;
}
return(&string[len+1]);
}
/*****************************************************************************/
static void
print_smb_transaction2_subcommand(int command,enum smb_packet_source_t smb_packet_source,int num_parameter_bytes,
const unsigned char * parameters,int num_data_bytes,const unsigned char * data)
{
if(command == TRANS2_FIND_FIRST2 && smb_packet_source == smb_packet_from_consumer)
{
int search_attributes;
int search_count;
int flags;
int information_level;
unsigned long search_storage_type;
const char * file_name;
int offset = 0;
search_attributes = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
if(search_attributes & 0x0100)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
if(search_attributes & 0x0200)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
if(search_attributes & 0x0400)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
if(search_attributes & 0x1000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
if(search_attributes & 0x2000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
search_count = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
flags = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
if(flags & 0x0001)
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AFTER_REQUEST\n");
if(flags & 0x0002)
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AT_EOS\n");
if(flags & 0x0004)
FPrintf(dump_smb_file," SMB_FIND_RETURN_RESUME_KEYS\n");
if(flags & 0x0008)
FPrintf(dump_smb_file," SMB_FIND_CONTINUE_FROM_LAST\n");
if(flags & 0x0010)
FPrintf(dump_smb_file," SMB_FIND_WITH_BACKUP_INTENT\n");
information_level = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"information level = 0x%04lx\n",information_level);
last_trans2_find_information_level = information_level;
if (information_level == 0x0001)
FPrintf(dump_smb_file," SMB_INFO_STANDARD\n");
else if (information_level == 0x0002)
FPrintf(dump_smb_file," SMB_INFO_QUERY_EA_SIZE\n");
else if (information_level == 0x0003)
FPrintf(dump_smb_file," SMB_INFO_QUERY_EAS_FROM_LIST\n");
else if (information_level == 0x0101)
FPrintf(dump_smb_file," SMB_FIND_FILE_DIRECTORY_INFO\n");
else if (information_level == 0x0102)
FPrintf(dump_smb_file," SMB_FIND_FILE_FULL_DIRECTORY_INFO\n");
else if (information_level == 0x0103)
FPrintf(dump_smb_file," SMB_FIND_FILE_NAMES_INFO\n");
else if (information_level == 0x0104)
FPrintf(dump_smb_file," SMB_FIND_FILE_BOTH_DIRECTORY_INFO\n");
search_storage_type = next_data_dword(parameters,&offset);
FPrintf(dump_smb_file,"search_storage_type = 0x%08lx\n",search_storage_type);
if(search_storage_type == 0x00000001)
FPrintf(dump_smb_file," FILE_DIRECTORY_ONLY\n");
if(search_storage_type == 0x00000040)
FPrintf(dump_smb_file," FILE_NON_DIRECTORY_FILE\n");
file_name = next_data_bytes(parameters,0,&offset);
FPrintf(dump_smb_file,"file name = '%s'\n",file_name);
/* ZZZ need to deal with the 'data' provided if
* information_level == SMB_INFO_QUERY_EAS_FROM_LIST.
*/
}
else if (command == TRANS2_FIND_NEXT2 && smb_packet_source == smb_packet_from_consumer)
{
int sid;
int search_count;
unsigned long resume_key;
int flags;
int information_level;
const char * file_name;
int offset = 0;
sid = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"sid = 0x%04lx\n",sid);
search_count = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
information_level = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"information level = 0x%04lx\n",information_level);
last_trans2_find_information_level = information_level;
if (information_level == 0x0001)
FPrintf(dump_smb_file," SMB_INFO_STANDARD\n");
else if (information_level == 0x0002)
FPrintf(dump_smb_file," SMB_INFO_QUERY_EA_SIZE\n");
else if (information_level == 0x0003)
FPrintf(dump_smb_file," SMB_INFO_QUERY_EAS_FROM_LIST\n");
else if (information_level == 0x0101)
FPrintf(dump_smb_file," SMB_FIND_FILE_DIRECTORY_INFO\n");
else if (information_level == 0x0102)
FPrintf(dump_smb_file," SMB_FIND_FILE_FULL_DIRECTORY_INFO\n");
else if (information_level == 0x0103)
FPrintf(dump_smb_file," SMB_FIND_FILE_NAMES_INFO\n");
else if (information_level == 0x0104)
FPrintf(dump_smb_file," SMB_FIND_FILE_BOTH_DIRECTORY_INFO\n");
resume_key = next_data_dword(parameters,&offset);
FPrintf(dump_smb_file,"resume_key = 0x%08lx\n",resume_key);
flags = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
if(flags & 0x0001)
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AFTER_REQUEST\n");
if(flags & 0x0002)
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AT_EOS\n");
if(flags & 0x0004)
FPrintf(dump_smb_file," SMB_FIND_RETURN_RESUME_KEYS\n");
if(flags & 0x0008)
FPrintf(dump_smb_file," SMB_FIND_CONTINUE_FROM_LAST\n");
if(flags & 0x0010)
FPrintf(dump_smb_file," SMB_FIND_WITH_BACKUP_INTENT\n");
file_name = next_data_bytes(parameters,0,&offset);
FPrintf(dump_smb_file,"file name = '%s'\n",file_name);
/* ZZZ need to deal with the 'data' provided if
* information_level == SMB_INFO_QUERY_EAS_FROM_LIST.
*/
}
else if (smb_packet_source == smb_packet_to_consumer && (command == TRANS2_FIND_FIRST2 || command == TRANS2_FIND_NEXT2))
{
int sid;
int search_count;
int end_of_search;
int ea_error_offset;
int last_name_offset;
int offset = 0;
if(command == TRANS2_FIND_FIRST2)
{
sid = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"sid = %ld\n",sid);
}
search_count = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
end_of_search = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"end of search = 0x%04lx\n",end_of_search);
ea_error_offset = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"ea error offset = 0x%04lx\n",ea_error_offset);
last_name_offset = next_data_word(parameters,&offset);
FPrintf(dump_smb_file,"last name offset = 0x%04lx\n",last_name_offset);
/* SMB_FIND_FILE_BOTH_DIRECTORY_INFO */
if(num_data_bytes > 0 && last_trans2_find_information_level == 0x0104)
{
unsigned long next_entry_offset;
unsigned long file_index;
unsigned long creation_time[2]; // FILETIME
unsigned long last_access_time[2]; // FILETIME
unsigned long last_write_time[2]; // FILETIME
unsigned long last_change_time[2]; // FILETIME
unsigned long end_of_file[2]; // LARGE_INTEGER
unsigned long allocation_size[2]; // LARGE_INTEGER
unsigned long ext_file_attributes; // SMB_EXT_FILE_ATTR
unsigned long file_name_length;
unsigned long ea_size;
int short_name_length; // UCHAR
int reserved; // UCHAR
const char * short_name; // WCHAR
const char * file_name; // SMB_STRING
struct line_buffer lb;
int unicode_char;
int unicode_offset;
int output_offset;
int entry_count = 0;
int entry_offset = 0;
int next_offset;
while(entry_offset < num_data_bytes && entry_count < search_count)
{
FPrintf(dump_smb_file,"directory entry [%ld]:\n",entry_count++);
next_offset = entry_offset;
next_entry_offset = next_data_dword(data,&entry_offset);
next_offset += next_entry_offset;
file_index = next_data_dword(data,&entry_offset);
next_data_qword(data,creation_time,&entry_offset);
next_data_qword(data,last_access_time,&entry_offset);
next_data_qword(data,last_write_time,&entry_offset);
next_data_qword(data,last_change_time,&entry_offset);
next_data_qword(data,end_of_file,&entry_offset);
next_data_qword(data,allocation_size,&entry_offset);
ext_file_attributes = next_data_dword(data,&entry_offset);
file_name_length = next_data_dword(data,&entry_offset);
ea_size = next_data_dword(data,&entry_offset);
short_name_length = next_data_byte(data,&entry_offset);
reserved = next_data_byte(data,&entry_offset);
short_name = next_data_bytes(data,24,&entry_offset);
file_name = next_data_bytes(data,0,&entry_offset);
FPrintf(dump_smb_file,"\tnext entry offset = %ld\n",next_entry_offset);
FPrintf(dump_smb_file,"\tfile index = 0x%08lx\n",file_index);
FPrintf(dump_smb_file,"\tcreation time = 0x%08lx%08lx\n",creation_time[0],creation_time[1]); /* ZZZ this is actually a signed value */
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(creation_time));
FPrintf(dump_smb_file,"\tlast access time = 0x%08lx%08lx\n",last_access_time[0],last_access_time[1]);
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(last_access_time));
FPrintf(dump_smb_file,"\tlast change time = 0x%08lx%08lx\n",last_change_time[0],last_change_time[1]);
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(last_change_time));
FPrintf(dump_smb_file,"\tend of file = %s (0x%08lx%08lx)\n",convert_qword_to_string(end_of_file),end_of_file[0],end_of_file[1]);
FPrintf(dump_smb_file,"\tallocation size = %s (0x%08lx%08lx)\n",convert_qword_to_string(allocation_size),allocation_size[0],allocation_size[1]);
FPrintf(dump_smb_file,"\text file attributes = 0x%08lx\n",ext_file_attributes);
if(ext_file_attributes & 0x00000001)
FPrintf(dump_smb_file,"\t ATTR_READONLY\n");
if(ext_file_attributes & 0x00000002)
FPrintf(dump_smb_file,"\t ATTR_HIDDEN\n");
if(ext_file_attributes & 0x00000004)
FPrintf(dump_smb_file,"\t ATTR_SYSTEM\n");
if(ext_file_attributes & 0x00000010)
FPrintf(dump_smb_file,"\t ATTR_DIRECTORY\n");
if(ext_file_attributes & 0x00000020)
FPrintf(dump_smb_file,"\t ATTR_ARCHIVE\n");
if(ext_file_attributes & 0x00000080)
FPrintf(dump_smb_file,"\t ATTR_NORMAL\n");
if(ext_file_attributes & 0x00000100)
FPrintf(dump_smb_file,"\t ATTR_TEMPORARY\n");
if(ext_file_attributes & 0x00000800)
FPrintf(dump_smb_file,"\t ATTR_COMPRESSED\n");
if(ext_file_attributes & 0x01000000)
FPrintf(dump_smb_file,"\t POSIX_SEMANTICS\n");
if(ext_file_attributes & 0x02000000)
FPrintf(dump_smb_file,"\t BACKUP_SEMANTICS\n");
if(ext_file_attributes & 0x04000000)
FPrintf(dump_smb_file,"\t DELETE_ON_CLOSE\n");
if(ext_file_attributes & 0x08000000)
FPrintf(dump_smb_file,"\t SEQUENTIAL_SCAN\n");
if(ext_file_attributes & 0x10000000)
FPrintf(dump_smb_file,"\t RANDOM_ACCESS\n");
if(ext_file_attributes & 0x20000000)
FPrintf(dump_smb_file,"\t NO_BUFFERING\n");
if(ext_file_attributes & 0x80000000)
FPrintf(dump_smb_file,"\t WRITE_THROUGH\n");
FPrintf(dump_smb_file,"\tfile name length = %ld\n",file_name_length);
FPrintf(dump_smb_file,"\tea size = %ld\n",ea_size);
FPrintf(dump_smb_file,"\tshort name length = %ld\n",short_name_length);
FPrintf(dump_smb_file,"\treserved = 0x%02lx\n",reserved);
if(short_name_length > 0)
{
unicode_offset = 0;
output_offset = 0;
init_line_buffer(&lb);
while(unicode_offset < short_name_length)
{
unicode_char = next_data_word(short_name,&unicode_offset);
if(unicode_char == 0)
break;
if(' ' <= unicode_char && unicode_char < 127)
{
char c = unicode_char;
copy_string_to_line_buffer(&lb,&c,1,output_offset);
output_offset++;
}
else
{
char code_string[40];
LocalSNPrintf(code_string,sizeof(code_string),"<%02lx%02ld>",unicode_char >> 8,unicode_char & 0xff);
copy_string_to_line_buffer(&lb,code_string,strlen(code_string),output_offset);
output_offset += strlen(code_string);
}
}
FPrintf(dump_smb_file,"\tshort name = '%s'\n",lb.line);
}
if(file_name_length > 0)
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
entry_offset = next_offset;
}
}
/* SMB_INFO_STANDARD */
else if (num_data_bytes > 0 && last_trans2_find_information_level == 0x0001)
{
unsigned long resume_key;
unsigned short creation_date;
unsigned short creation_time;
unsigned short last_access_date;
unsigned short last_access_time;
unsigned short last_write_date;
unsigned short last_write_time;
unsigned long file_data_size;
unsigned long allocation_size;
unsigned short file_attributes;
unsigned char file_name_length;
const char * file_name;
int entry_count = 0;
int entry_offset = 0;
while(entry_offset < num_data_bytes && entry_count < search_count)
{
FPrintf(dump_smb_file,"directory entry [%ld]:\n",entry_count++);
resume_key = next_data_dword(data,&entry_offset);
creation_date = next_data_word(data,&entry_offset);
creation_time = next_data_word(data,&entry_offset);
last_access_date = next_data_word(data,&entry_offset);
last_access_time = next_data_word(data,&entry_offset);
last_write_date = next_data_word(data,&entry_offset);
last_write_time = next_data_word(data,&entry_offset);
file_data_size = next_data_dword(data,&entry_offset);
allocation_size = next_data_dword(data,&entry_offset);
file_attributes = next_data_dword(data,&entry_offset);
file_name_length = next_data_byte(data,&entry_offset);
file_name = (char *)next_data_bytes(data,file_name_length,&entry_offset);
FPrintf(dump_smb_file,"\tresume key = 0x%08lx\n",resume_key);
FPrintf(dump_smb_file,"\tcreation date = 0x%04lx\n",creation_date);
FPrintf(dump_smb_file,"\tcreation time = 0x%04lx\n",creation_time);
FPrintf(dump_smb_file,"\tcreation = %s\n",convert_smb_date_time_to_string(creation_date,creation_time));
FPrintf(dump_smb_file,"\tlast access date = 0x%04lx\n",last_access_date);
FPrintf(dump_smb_file,"\tlast access time = 0x%04lx\n",last_access_time);
FPrintf(dump_smb_file,"\tlast access = %s\n",convert_smb_date_time_to_string(last_access_date,last_access_time));
FPrintf(dump_smb_file,"\tlast write date = 0x%04lx\n",last_write_date);
FPrintf(dump_smb_file,"\tlast write time = 0x%04lx\n",last_write_time);
FPrintf(dump_smb_file,"\tlast write = %s\n",convert_smb_date_time_to_string(last_write_date,last_write_time));
FPrintf(dump_smb_file,"\tfile data size = %lu\n",file_data_size);
FPrintf(dump_smb_file,"\tallocation size = %lu\n",allocation_size);
FPrintf(dump_smb_file,"\tfile attributes = 0x%08lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"\tfile name length = %ld\n",file_name_length);
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
}
}
}
}
/*****************************************************************************/
/* SMB commands used by smbfs 1.60 and beyond
*
#define SMBmkdir 0x00 // create directory
#define SMBrmdir 0x01 // delete directory
#define SMBopen 0x02 // open file
#define SMBcreate 0x03 // create file
#define SMBclose 0x04 // close file
#define SMBunlink 0x06 // delete file
#define SMBmv 0x07 // rename file
#define SMBgetatr 0x08 // get file attributes
#define SMBsetatr 0x09 // set file attributes
#define SMBread 0x0A // read from file
#define SMBwrite 0x0B // write to file
#define SMBlseek 0x12 // seek
#define SMBtcon 0x70 // tree connect
#define SMBtconX 0x75 // tree connect and X
#define SMBnegprot 0x72 // negotiate protocol
#define SMBdskattr 0x80 // get disk attributes
#define SMBsearch 0x81 // search directory
// Core+ protocol
#define SMBreadbraw 0x1a // read a block of data with no smb header
#define SMBwritebraw 0x1d // write a block of data with no smb header
#define SMBwritec 0x20 // secondary write request
// dos extended protocol
#define SMBsetattrE 0x22 // set file attributes expanded
#define SMBgetattrE 0x23 // get file attributes expanded
#define SMBlockingX 0x24 // lock/unlock byte ranges and X
#define SMBsesssetupX 0x73 // Session Set Up & X (including User Logon)
// Extended 2.0 protocol
#define SMBtrans2 0x32 // TRANS2 protocol set
// these are the TRANS2 sub commands
#define TRANSACT2_FINDFIRST 1
#define TRANSACT2_FINDNEXT 2
*/
/*****************************************************************************/
/* SMB commands supported so far:
*
* CREATE_DIRECTORY (SMBmkdir, 0x00)
* DELETE_DIRECTORY (SMBrmdir, 0x01)
* OPEN (SMBopen, 0x02)
* CREATE (SMBcreate, 0x03)
* CLOSE (SMBclose, 0x04)
* DELETE (SMBunlink, 0x06)
* RENAME (SMBmv, 0x07)
* QUERY_INFORMATION (SMBgetatr, 0x08)
* SET_INFORMATION (SMBsetatr, 0x09)
* READ (SMBread, 0x0A)
* WRITE (SMBwrite, 0x0B)
* SEEK (SMBlseek, 0x12)
* READ_RAW (SMBreadbraw, 0x1A)
* SMB_COM_WRITE_RAW (SMBwritebraw, 0x1D)
* SMB_COM_WRITE_COMPLETE (SMBwritec, 0x20)
* SET_INFORMATION2 (SMBsetattrE, 0x22)
* QUERY_INFORMATION2 (SMBgetattrE, 0x23)
* LOCKING_ANDX (SMBlockingX, 0x24)
* TRANSACTION2 (SMBtrans2, 0x32)
* TREE_CONNECT (SMBtcon, 0x70)
* NEGOTIATE (SMBnegprot, 0x72)
* SESSION_SETUP_AND (SMBsesssetupX, 0x73)
* TREE_CONNECT_ANDX (SMBtconX, 0x75)
* QUERY_INFORMATION_DISK (SMBdskattr, 0x80)
* SEARCH (SMBsearch, 0x81)
*/
static void
print_smb_contents(const struct smb_header * header,int command,enum smb_packet_source_t smb_packet_source,
int num_parameter_words,const unsigned char * parameters,int num_data_bytes,const unsigned char * data)
{
unsigned short vwv[256];
int i,j;
if(num_parameter_words < 0)
num_parameter_words = 0;
else if (num_parameter_words > 255)
num_parameter_words = 255;
if(num_data_bytes < 0)
num_data_bytes = 0;
memset(vwv,0,sizeof(vwv));
for(i = j = 0 ; i < num_parameter_words ; i++, j += 2)
vwv[i] = (((int)parameters[j+1]) << 8) + parameters[j];
if (command == SMB_COM_CREATE_DIRECTORY)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
FPrintf(dump_smb_file,"directory name = '%s'\n",filename+1);
}
}
else if (command == SMB_COM_DELETE_DIRECTORY)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
FPrintf(dump_smb_file,"directory name = '%s'\n",filename+1);
}
}
else if (command == SMB_COM_OPEN)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
int access_mode;
int search_attribute;
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
access_mode = vwv[0];
FPrintf(dump_smb_file,"access mode = 0x%04lx\n",access_mode);
switch(access_mode & 0x0007)
{
case 0:
FPrintf(dump_smb_file," Open for reading\n");
break;
case 1:
FPrintf(dump_smb_file," Open for writing\n");
break;
case 2:
FPrintf(dump_smb_file," Open for reading and writing\n");
break;
case 3:
FPrintf(dump_smb_file," Open for execution\n");
break;
default:
break;
}
switch((access_mode & 0x0070) >> 4)
{
case 0:
FPrintf(dump_smb_file," Compatibility mode\n");
break;
case 1:
FPrintf(dump_smb_file," Deny read/write/execute others (exclusive use requested)\n");
break;
case 2:
FPrintf(dump_smb_file," Deny write to others\n");
break;
case 3:
FPrintf(dump_smb_file," Deny read/execute to others\n");
break;
case 4:
FPrintf(dump_smb_file," Deny nothing to others\n");
break;
default:
break;
}
switch((access_mode & 0x0700) >> 8)
{
case 0:
FPrintf(dump_smb_file," Unknown locality of reference\n");
break;
case 1:
FPrintf(dump_smb_file," Mainly sequential access\n");
break;
case 2:
FPrintf(dump_smb_file," Mainly random access\n");
break;
case 3:
FPrintf(dump_smb_file," Random access with some locality\n");
break;
default:
break;
}
if(access_mode & 0x1000)
FPrintf(dump_smb_file," Perform caching on file\n");
else
FPrintf(dump_smb_file," Do not cache the file\n");
if(access_mode & 0x4000)
FPrintf(dump_smb_file," No read ahead or write behind is allowed on this file or device\n");
search_attribute = vwv[1];
FPrintf(dump_smb_file,"search attribute = 0x%04lx\n",search_attribute);
if(search_attribute & 0x0100)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
if(search_attribute & 0x0200)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
if(search_attribute & 0x0400)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
if(search_attribute & 0x1000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
if(search_attribute & 0x2000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
}
else
{
int access_mode;
int file_attributes;
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
file_attributes = vwv[1];
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"last modified = 0x%08lx\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[3]) << 16) | vwv[2]));
FPrintf(dump_smb_file,"file size = %lu\n",(((unsigned long )vwv[5]) << 16) | vwv[4]);
access_mode = vwv[6];
FPrintf(dump_smb_file,"access mode = 0x%04lx\n",access_mode);
switch(access_mode & 0x0007)
{
case 0:
FPrintf(dump_smb_file," Open for reading\n");
break;
case 1:
FPrintf(dump_smb_file," Open for writing\n");
break;
case 2:
FPrintf(dump_smb_file," Open for reading and writing\n");
break;
case 3:
FPrintf(dump_smb_file," Open for execution\n");
break;
default:
break;
}
switch((access_mode & 0x0070) >> 4)
{
case 0:
FPrintf(dump_smb_file," Compatibility mode\n");
break;
case 1:
FPrintf(dump_smb_file," Deny read/write/execute others (exclusive use requested)\n");
break;
case 2:
FPrintf(dump_smb_file," Deny write to others\n");
break;
case 3:
FPrintf(dump_smb_file," Deny read/execute to others\n");
break;
case 4:
FPrintf(dump_smb_file," Deny nothing to others\n");
break;
default:
break;
}
switch((access_mode & 0x0700) >> 8)
{
case 0:
FPrintf(dump_smb_file," Unknown locality of reference\n");
break;
case 1:
FPrintf(dump_smb_file," Mainly sequential access\n");
break;
case 2:
FPrintf(dump_smb_file," Mainly random access\n");
break;
case 3:
FPrintf(dump_smb_file," Random access with some locality\n");
break;
default:
break;
}
if(access_mode & 0x1000)
FPrintf(dump_smb_file," Perform caching on file\n");
else
FPrintf(dump_smb_file," Do not cache the file\n");
if(access_mode & 0x4000)
FPrintf(dump_smb_file," No read ahead or write behind is allowed on this file or device\n");
}
}
else if (command == SMB_COM_CREATE)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
int file_attributes;
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
file_attributes = vwv[0];
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"creation time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
}
else
{
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
}
}
else if (command == SMB_COM_CLOSE)
{
if(smb_packet_source == smb_packet_from_consumer)
{
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
FPrintf(dump_smb_file,"last time modified = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
}
}
else if (command == SMB_COM_DELETE)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
int search_attributes;
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
search_attributes = vwv[0];
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
if(search_attributes & 0x0100)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
if(search_attributes & 0x0200)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
if(search_attributes & 0x0400)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
if(search_attributes & 0x1000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
if(search_attributes & 0x2000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
FPrintf(dump_smb_file,"file name = '%s'\n",filename+1);
}
}
else if (command == SMB_COM_RENAME)
{
if(smb_packet_source == smb_packet_from_consumer)
{
int search_attributes;
const char * old_file_name;
const char * new_file_name;
int len;
search_attributes = vwv[0];
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
if(search_attributes & 0x0100)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
if(search_attributes & 0x0200)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
if(search_attributes & 0x0400)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
if(search_attributes & 0x1000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
if(search_attributes & 0x2000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
old_file_name = data;
len = strlen(old_file_name);
new_file_name = &old_file_name[len+1];
FPrintf(dump_smb_file,"buffer format 1 = %ld\n",old_file_name[0]);
FPrintf(dump_smb_file,"old file name = '%s'\n",old_file_name+1);
FPrintf(dump_smb_file,"buffer format 2 = %ld\n",new_file_name[0]);
FPrintf(dump_smb_file,"new file name = '%s'\n",new_file_name+1);
}
}
else if (command == SMB_COM_QUERY_INFORMATION)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
FPrintf(dump_smb_file,"buffer format = 0x%02lx\n",filename[0]);
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
}
else
{
int file_attributes;
if(num_parameter_words <= 0)
return;
file_attributes = vwv[0];
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"last write time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
FPrintf(dump_smb_file,"file size = %lu\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
}
}
else if (command == SMB_COM_SET_INFORMATION)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char filename[256];
int file_attributes;
if(num_data_bytes > 255)
num_data_bytes = 255;
memmove(filename,data,num_data_bytes);
filename[num_data_bytes] = '\0';
file_attributes = vwv[0];
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
FPrintf(dump_smb_file,"creation time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
}
}
else if (command == SMB_COM_READ)
{
if(smb_packet_source == smb_packet_from_consumer)
{
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",(signed short)vwv[0]);
FPrintf(dump_smb_file,"count of bytes to read = %ld\n",vwv[1]);
FPrintf(dump_smb_file,"read offset in bytes = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
FPrintf(dump_smb_file,"estimate of remaining bytes to be read = %ld\n",vwv[4]);
}
else
{
unsigned char buffer_format;
unsigned short count_of_bytes_read;
int offset = 0;
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"count of bytes returned = %ld\n",vwv[0]);
buffer_format = next_data_byte(data,&offset);
count_of_bytes_read = next_data_word(data,&offset);
FPrintf(dump_smb_file,"buffer format = %lu\n",buffer_format);
FPrintf(dump_smb_file,"count of bytes read = %lu\n",count_of_bytes_read);
if(dump_smb_level > 1 && count_of_bytes_read > 0)
{
struct line_buffer lb;
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",count_of_bytes_read);
print_smb_data(&lb,count_of_bytes_read,next_data_bytes(data,count_of_bytes_read,&offset));
}
}
}
else if (command == SMB_COM_WRITE)
{
if(smb_packet_source == smb_packet_from_consumer)
{
unsigned char buffer_format;
unsigned short data_length;
int offset = 0;
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
FPrintf(dump_smb_file,"count of bytes to write = %ld\n",vwv[1]);
FPrintf(dump_smb_file,"write offset in bytes = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
FPrintf(dump_smb_file,"estimate of remaining bytes to be written = %ld\n",vwv[4]);
buffer_format = next_data_byte(data,&offset);
data_length = next_data_word(data,&offset);
FPrintf(dump_smb_file,"buffer format = %lu\n",buffer_format);
FPrintf(dump_smb_file,"data length = %lu\n",data_length);
if(dump_smb_level > 1 && data_length > 0)
{
struct line_buffer lb;
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",data_length);
print_smb_data(&lb,data_length,next_data_bytes(data,data_length,&offset));
}
}
else
{
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"count of bytes written = %ld\n",vwv[0]);
}
}
else if (command == SMB_COM_SEEK)
{
if(smb_packet_source == smb_packet_from_consumer)
{
int mode;
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
mode = vwv[1];
FPrintf(dump_smb_file,"mode = 0x%04lx\n",mode);
switch(mode)
{
case 0:
FPrintf(dump_smb_file," Seek from the start of the file\n");
break;
case 1:
FPrintf(dump_smb_file," Seek from the current position\n");
break;
case 2:
FPrintf(dump_smb_file," Seek from the end of the file\n");
break;
}
FPrintf(dump_smb_file,"offset = %ld\n",(long)((((unsigned long)vwv[3]) << 16) | vwv[2]));
}
else
{
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"absolute position = %lu\n",(((unsigned long)vwv[1]) << 16) | vwv[0]);
}
}
else if (command == SMB_COM_READ_RAW)
{
if(smb_packet_source == smb_packet_from_consumer)
{
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",(signed short)vwv[0]);
FPrintf(dump_smb_file,"offset = %lu\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
FPrintf(dump_smb_file,"maximum count of bytes to return = %ld\n",vwv[3]);
FPrintf(dump_smb_file,"minimum count of byte to return = %ld\n",vwv[4]);
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[6]) << 16) | vwv[5]);
if(num_parameter_words == 0x0A)
FPrintf(dump_smb_file,"offset high = %lu\n",(((unsigned long)vwv[9]) << 16) | vwv[8]);
}
}
else if (command == SMB_COM_WRITE_RAW)
{
if(smb_packet_source == smb_packet_from_consumer)
{
unsigned short data_length;
unsigned short data_offset;
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
FPrintf(dump_smb_file,"count of bytes = %lu\n",vwv[1]);
FPrintf(dump_smb_file,"offset = %lu\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[6]) << 16) | vwv[5]);
FPrintf(dump_smb_file,"write mode = %ld\n",vwv[7]);
if(vwv[7] & 0x0001)
FPrintf(dump_smb_file," Writethrough mode\n");
if(vwv[7] & 0x0002)
FPrintf(dump_smb_file," Read bytes available\n");
if(vwv[7] & 0x0004)
FPrintf(dump_smb_file," Named pipe raw\n");
if(vwv[7] & 0x0008)
FPrintf(dump_smb_file," Named pipe start\n");
data_length = vwv[8];
data_offset = vwv[9];
FPrintf(dump_smb_file,"data length = %lu\n",data_length);
FPrintf(dump_smb_file,"data offset = %lu\n",data_offset);
if(num_parameter_words == 0x0E)
FPrintf(dump_smb_file,"offset high = %lu\n",(((unsigned long)vwv[11]) << 16) | vwv[10]);
if(data_length > 0)
{
if(header->data_offset < data_offset)
FPrintf(dump_smb_file,"padding bytes = %ld\n",data_offset - header->data_offset);
if(dump_smb_level > 1)
{
struct line_buffer lb;
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",data_length);
print_smb_data(&lb,num_data_bytes,&header->raw_packet[data_offset]);
}
}
}
else
{
/* The number of bytes remaining to be written is valid only
* if it's not 0xFFFF.
*/
if(num_parameter_words > 0 && vwv[0] != 0xFFFF)
FPrintf(dump_smb_file,"number of bytes remaining to be written = %lu\n",vwv[0]);
}
}
else if (command == SMB_COM_WRITE_COMPLETE)
{
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 0)
FPrintf(dump_smb_file,"total number of bytes written = %lu\n",vwv[0]);
}
else if (command == SMB_COM_SET_INFORMATION2)
{
if(smb_packet_source == smb_packet_from_consumer)
{
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"creation date = 0x%04lx\n",vwv[1]);
FPrintf(dump_smb_file,"creation time = 0x%04lx\n",vwv[2]);
FPrintf(dump_smb_file,"creation = %s\n",convert_smb_date_time_to_string(vwv[1],vwv[2]));
FPrintf(dump_smb_file,"last access date = 0x%04lx\n",vwv[3]);
FPrintf(dump_smb_file,"last access time = 0x%04lx\n",vwv[4]);
FPrintf(dump_smb_file,"last access = %s\n",convert_smb_date_time_to_string(vwv[3],vwv[4]));
FPrintf(dump_smb_file,"last write date = 0x%04lx\n",vwv[5]);
FPrintf(dump_smb_file,"last write time = 0x%04lx\n",vwv[6]);
FPrintf(dump_smb_file,"last write = %s\n",convert_smb_date_time_to_string(vwv[5],vwv[6]));
}
}
else if (command == SMB_COM_QUERY_INFORMATION2)
{
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 0x11)
{
int file_attributes;
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"creation date = 0x%04lx\n",vwv[1]);
FPrintf(dump_smb_file,"creation time = 0x%04lx\n",vwv[2]);
FPrintf(dump_smb_file,"creation = %s\n",convert_smb_date_time_to_string(vwv[1],vwv[2]));
FPrintf(dump_smb_file,"last access date = 0x%04lx\n",vwv[3]);
FPrintf(dump_smb_file,"last access time = 0x%04lx\n",vwv[4]);
FPrintf(dump_smb_file,"last access = %s\n",convert_smb_date_time_to_string(vwv[3],vwv[4]));
FPrintf(dump_smb_file,"last write date = 0x%04lx\n",vwv[5]);
FPrintf(dump_smb_file,"last write time = 0x%04lx\n",vwv[6]);
FPrintf(dump_smb_file,"last write = %s\n",convert_smb_date_time_to_string(vwv[5],vwv[6]));
FPrintf(dump_smb_file,"file data size = %lu\n",(((unsigned long)vwv[8]) << 16) | vwv[7]);
FPrintf(dump_smb_file,"file allocation size = %lu\n",(((unsigned long)vwv[10]) << 16) | vwv[9]);
file_attributes = vwv[11];
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
}
}
else if (command == SMB_COM_LOCKING_ANDX)
{
if(smb_packet_source == smb_packet_from_consumer)
{
int type_of_lock;
int number_of_requested_unlocks;
int number_of_requested_locks;
int offset;
int i;
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
type_of_lock = vwv[1] & 0xff;
FPrintf(dump_smb_file,"type of lock = %ld\n",type_of_lock);
if(type_of_lock & 0x01)
FPrintf(dump_smb_file," SHARED_LOCK\n");
else
FPrintf(dump_smb_file," READ_WRITE_LOCK\n");
if(type_of_lock & 0x02)
FPrintf(dump_smb_file," OPLOCK_RELEASE\n");
if(type_of_lock & 0x04)
FPrintf(dump_smb_file," CHANGE_LOCK_TYPE\n");
if(type_of_lock & 0x08)
FPrintf(dump_smb_file," CANCEL_LOCK\n");
if(type_of_lock & 0x10)
FPrintf(dump_smb_file," LARGE_FILES\n");
FPrintf(dump_smb_file,"new oplock level = 0x%02lx\n",(vwv[1] >> 8) & 0xff);
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
number_of_requested_unlocks = vwv[4];
FPrintf(dump_smb_file,"number of requested unlocks = %ld\n",number_of_requested_unlocks);
number_of_requested_locks = vwv[5];
FPrintf(dump_smb_file,"number of requested locks = %ld\n",number_of_requested_locks);
offset = 0;
for(i = 0 ; i < number_of_requested_unlocks ; i++)
{
FPrintf(dump_smb_file,"unlock range[%ld] pid=%ld, byte offset = %lu, length in bytes = %lu\n",
i,next_data_word(data,&offset),next_data_dword(data,&offset),next_data_dword(data,&offset));
}
for(i = 0 ; i < number_of_requested_locks ; i++)
{
FPrintf(dump_smb_file,"lock range[%ld] pid=%ld, byte offset = %lu, length in bytes = %lu\n",
i,next_data_word(data,&offset),next_data_dword(data,&offset),next_data_dword(data,&offset));
}
}
}
else if (command == SMB_COM_TRANSACTION2)
{
const unsigned short * setup_words;
const char * subcommand_name;
if(smb_packet_source == smb_packet_from_consumer)
{
int transaction_parameter_count;
int transaction_parameter_offset;
int transaction_data_count;
int transaction_data_offset;
int flags;
int setup_count;
int i;
FPrintf(dump_smb_file,"total parameter count = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"total data count = %ld\n",vwv[1]);
FPrintf(dump_smb_file,"max parameter count = %ld\n",vwv[2]);
FPrintf(dump_smb_file,"max data count = %ld\n",vwv[3]);
FPrintf(dump_smb_file,"max setup count = %ld\n",vwv[4] & 0xff);
flags = vwv[5];
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
if(flags & 0x0001)
FPrintf(dump_smb_file," DISCONNECT_TID\n");
if(flags & 0x0002)
FPrintf(dump_smb_file," NO_RESPONSE\n");
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[7]) << 16) | vwv[6]);
transaction_parameter_count = vwv[9];
FPrintf(dump_smb_file,"parameter count = %ld\n",transaction_parameter_count);
transaction_parameter_offset = vwv[10];
FPrintf(dump_smb_file,"parameter offset = %ld (header parameter offset = %ld)\n",transaction_parameter_offset,header->parameter_offset);
transaction_data_count = vwv[11];
FPrintf(dump_smb_file,"data count = %ld\n",transaction_data_count);
transaction_data_offset = vwv[12];
FPrintf(dump_smb_file,"data offset = %ld (header data offset = %ld)\n",transaction_data_offset,header->data_offset);
setup_count = vwv[13] & 0xff;
FPrintf(dump_smb_file,"setup count = %ld\n",setup_count);
setup_words = &vwv[14];
if(setup_count > 0)
{
last_smb_com_transaction_subcommand = setup_words[0];
subcommand_name = get_smb_transaction2_subcommand_name(setup_words[0]);
if(subcommand_name != NULL)
FPrintf(dump_smb_file,"subcommand = %s\n",subcommand_name);
else
FPrintf(dump_smb_file,"subcommand = %ld\n",setup_words[0]);
for(i = 0 ; i < setup_count ; i++)
FPrintf(dump_smb_file,"setup word [%ld] = 0x%04lx\n",i,setup_words[i]);
}
else
{
last_smb_com_transaction_subcommand = -1;
}
if(dump_smb_level > 1 && transaction_parameter_count > 0 && transaction_parameter_offset + transaction_parameter_count <= header->raw_packet_size)
{
const unsigned char * transaction_parameter_contents = (unsigned char *)&header->raw_packet[transaction_parameter_offset];
struct line_buffer lb;
FPrintf(dump_smb_file,"transaction parameters =\n");
print_smb_data(&lb,transaction_parameter_count,transaction_parameter_contents);
}
if(dump_smb_level > 1 && transaction_data_count > 0 && transaction_data_offset + transaction_data_count <= header->raw_packet_size)
{
const unsigned char * transaction_data_contents = (unsigned char *)&header->raw_packet[transaction_data_offset];
struct line_buffer lb;
FPrintf(dump_smb_file,"transaction data =\n");
print_smb_data(&lb,transaction_data_count,transaction_data_contents);
}
print_smb_transaction2_subcommand(last_smb_com_transaction_subcommand,smb_packet_source,
transaction_parameter_count,(unsigned char *)&header->raw_packet[transaction_parameter_offset],
transaction_data_count,(unsigned char *)&header->raw_packet[transaction_data_offset]);
}
else if (num_parameter_words > 0 || num_data_bytes > 0)
{
int transaction_parameter_count;
int transaction_parameter_offset;
int transaction_data_count;
int transaction_data_offset;
int setup_count;
int i;
FPrintf(dump_smb_file,"total parameter count = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"total data count = %ld\n",vwv[1]);
transaction_parameter_count = vwv[3];
FPrintf(dump_smb_file,"parameter count = %ld\n",transaction_parameter_count);
transaction_parameter_offset = vwv[4];
FPrintf(dump_smb_file,"parameter offset = %ld\n",transaction_parameter_offset);
FPrintf(dump_smb_file,"parameter displacement = %ld\n",vwv[5]);
transaction_data_count = vwv[6];
FPrintf(dump_smb_file,"data count = %ld\n",transaction_data_count);
transaction_data_offset = vwv[7];
FPrintf(dump_smb_file,"data offset = %ld\n",transaction_data_offset);
setup_count = vwv[8] & 0xff;
FPrintf(dump_smb_file,"setup count = %ld\n",setup_count);
setup_words = &vwv[9];
if(setup_count > 0)
{
subcommand_name = get_smb_transaction2_subcommand_name(setup_words[0]);
if(subcommand_name != NULL)
FPrintf(dump_smb_file,"subcommand = %s\n",subcommand_name);
else
FPrintf(dump_smb_file,"subcommand = %ld\n",setup_words[0]);
for(i = 0 ; i < setup_count ; i++)
FPrintf(dump_smb_file,"setup word [%ld] = 0x%04lx\n",i,setup_words[i]);
}
if(dump_smb_level > 1 && transaction_parameter_count > 0 && transaction_parameter_offset + transaction_parameter_count <= header->raw_packet_size)
{
const unsigned char * transaction_parameter_contents = (unsigned char *)&header->raw_packet[transaction_parameter_offset];
struct line_buffer lb;
FPrintf(dump_smb_file,"transaction parameters =\n");
print_smb_data(&lb,transaction_parameter_count,transaction_parameter_contents);
}
if(dump_smb_level > 1 && transaction_data_count > 0 && transaction_data_offset + transaction_data_count <= header->raw_packet_size)
{
const unsigned char * transaction_data_contents = (unsigned char *)&header->raw_packet[transaction_data_offset];
struct line_buffer lb;
FPrintf(dump_smb_file,"transaction data =\n");
print_smb_data(&lb,transaction_data_count,transaction_data_contents);
}
print_smb_transaction2_subcommand(last_smb_com_transaction_subcommand,smb_packet_source,
transaction_parameter_count,(unsigned char *)&header->raw_packet[transaction_parameter_offset],
transaction_data_count,(unsigned char *)&header->raw_packet[transaction_data_offset]);
}
}
else if (command == SMB_COM_TREE_CONNECT)
{
if(smb_packet_source == smb_packet_from_consumer)
{
const char * path;
const char * password;
const char * service;
int len;
path = (char *)data;
len = strlen(path);
password = &path[len+1];
len = strlen(password);
service = &password[len+1];
FPrintf(dump_smb_file,"buffer format 1 = %ld\n",path[0]);
FPrintf(dump_smb_file,"path = '%s'\n",path+1);
FPrintf(dump_smb_file,"buffer format 2 = %ld\n",password[0]);
FPrintf(dump_smb_file,"password = '%s'\n",password+1);
FPrintf(dump_smb_file,"buffer format 3 = %ld\n",service[0]);
FPrintf(dump_smb_file,"service = '%s'\n",service+1);
}
else
{
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"max buffer size = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"tid = %ld\n",vwv[1]);
}
}
else if (command == SMB_COM_NEGOTIATE)
{
if(smb_packet_source == smb_packet_from_consumer)
{
char args[1024];
const char * dialect;
int dialect_index;
int len;
if(num_data_bytes > 1023)
num_data_bytes = 1023;
memmove(args,data,num_data_bytes);
args[num_data_bytes] = '\0';
dialect = args;
dialect_index = 0;
while(dialect < &args[num_data_bytes])
{
FPrintf(dump_smb_file,"dialect[%ld] = '%s'\n",dialect_index++,&dialect[1]);
len = strlen(&dialect[1]);
dialect = &dialect[1+len+1];
}
}
else
{
/* Assuming that the data returned is for
* the "NT LAN MANAGER" dialect.
*/
if(num_parameter_words == 0x11)
{
int offset = 0;
int challenge_length;
int security_mode;
unsigned long capabilities;
struct line_buffer lb;
int unicode_char;
int output_offset;
unsigned long system_time[2];
FPrintf(dump_smb_file,"dialect index = %ld\n",next_data_word(parameters,&offset));
security_mode = next_data_byte(parameters,&offset);
FPrintf(dump_smb_file,"security mode = %ld\n",security_mode);
if(security_mode & 0x01)
FPrintf(dump_smb_file," NEGOTIATE_USER_SECURITY\n");
if(security_mode & 0x02)
FPrintf(dump_smb_file," NEGOTIATE_ENCRYPT_PASSWORDS\n");
if(security_mode & 0x04)
FPrintf(dump_smb_file," NEGOTIATE_SECURITY_SIGNATURES_ENABLE\n");
if(security_mode & 0x08)
FPrintf(dump_smb_file," NEGOTIATE_SECURITY_SIGNATURES_REQUIRED\n");
if(security_mode & 0xF0)
FPrintf(dump_smb_file," Reserved = 0x%lx\n",security_mode >> 4);
FPrintf(dump_smb_file,"max mpx count = %ld\n",next_data_word(parameters,&offset));
FPrintf(dump_smb_file,"max number cvs = %ld\n",next_data_word(parameters,&offset));
FPrintf(dump_smb_file,"max buffer size = %lu\n",next_data_dword(parameters,&offset));
FPrintf(dump_smb_file,"max raw size = %lu\n",next_data_dword(parameters,&offset));
FPrintf(dump_smb_file,"session key = %lu\n",next_data_dword(parameters,&offset));
capabilities = next_data_dword(parameters,&offset);
FPrintf(dump_smb_file,"capabilities = 0x%08lx\n",capabilities);
if(capabilities & 0x00000001)
FPrintf(dump_smb_file," CAP_RAW_MODE\n");
if(capabilities & 0x00000002)
FPrintf(dump_smb_file," CAP_MPX_MODE\n");
if(capabilities & 0x00000004)
FPrintf(dump_smb_file," CAP_UNICODE\n");
if(capabilities & 0x00000008)
FPrintf(dump_smb_file," CAP_LARGE_FILES\n");
if(capabilities & 0x00000010)
FPrintf(dump_smb_file," CAP_NT_SMBS\n");
if(capabilities & 0x00000020)
FPrintf(dump_smb_file," CAP_RPC_REMOTE_APIS\n");
if(capabilities & 0x00000040)
FPrintf(dump_smb_file," CAP_STATUS32\n");
if(capabilities & 0x00000080)
FPrintf(dump_smb_file," CAP_LEVEL_II_OPLOCKS\n");
if(capabilities & 0x00000100)
FPrintf(dump_smb_file," CAP_LOCK_AND_READ\n");
if(capabilities & 0x00000200)
FPrintf(dump_smb_file," CAP_NT_FIND\n");
if(capabilities & 0x00000400)
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
if(capabilities & 0x00000800)
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
if(capabilities & 0x00001000)
FPrintf(dump_smb_file," CAP_DFS\n");
if(capabilities & 0x00002000)
FPrintf(dump_smb_file," CAP_QUADWORD_ALIGNED\n");
if(capabilities & 0x00004000)
FPrintf(dump_smb_file," CAP_LARGE_READX\n");
if(capabilities & 0x00008000)
FPrintf(dump_smb_file," CAP_LARGE_WRITEX\n");
if(capabilities & 0x00800000)
FPrintf(dump_smb_file," CAP_UNIX\n");
if(capabilities & 0x20000000)
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
if(capabilities & 0x40000000)
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
if(capabilities & 0x80000000)
FPrintf(dump_smb_file," CAP_EXTENDED_SECURITY\n");
next_data_qword(parameters,system_time,&offset);
FPrintf(dump_smb_file,"system time = 0x%08lx%08lx\n",system_time[0],system_time[1]);
FPrintf(dump_smb_file," %s\n",convert_filetime_to_string(system_time));
FPrintf(dump_smb_file,"server time zone = %ld\n",(signed short)next_data_word(parameters,&offset)); /* ZZZ this is a signed 16 bit integer */
challenge_length = next_data_byte(parameters,&offset);
FPrintf(dump_smb_file,"challenge length = %ld\n",challenge_length);
if(challenge_length > 0)
{
if(challenge_length == 8)
{
FPrintf(dump_smb_file,"challenge = %02lx %02lx %02lx %02lx %02lx %02lx %02lx %02lx\n",
data[0],data[1],data[2],data[3],
data[4],data[5],data[6],data[7]);
}
}
init_line_buffer(&lb);
offset = challenge_length;
output_offset = 0;
while(offset < num_data_bytes)
{
unicode_char = next_data_word(data,&offset);
if(unicode_char == 0)
break;
if(' ' <= unicode_char && unicode_char < 127)
{
char c = unicode_char;
copy_string_to_line_buffer(&lb,&c,1,output_offset);
output_offset++;
}
else
{
char code_string[40];
LocalSNPrintf(code_string,sizeof(code_string),"<%02lx%02ld>",unicode_char >> 8,unicode_char & 0xff);
copy_string_to_line_buffer(&lb,code_string,strlen(code_string),output_offset);
output_offset += strlen(code_string);
}
}
FPrintf(dump_smb_file,"Domain name = '%s'\n",lb.line);
}
else
{
if(num_parameter_words <= 0)
return;
FPrintf(dump_smb_file,"dialect index = %ld\n",vwv[0]);
}
}
}
else if (command == SMB_COM_SESSION_SETUP_ANDX)
{
char args[1024];
char * args_end;
int len;
const char * oem_password = "";
const char * unicode_password = "";
const char * account_name = "";
const char * primary_domain = "";
const char * native_os = "";
const char * native_lan_man = "";
if(num_data_bytes > 1023)
num_data_bytes = 1023;
memmove(args,data,num_data_bytes);
args[num_data_bytes] = '\0';
args_end = &args[num_data_bytes];
if(smb_packet_source == smb_packet_from_consumer)
{
int oem_password_length;
int unicode_password_length;
unsigned long capabilities;
FPrintf(dump_smb_file,"consumer's maximum buffer size = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"actual maximum multiplexed pending requests = %ld\n",vwv[1]);
FPrintf(dump_smb_file,"vc number = %ld\n",vwv[2]);
FPrintf(dump_smb_file,"session key = 0x%08lx\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
oem_password_length = vwv[5];
FPrintf(dump_smb_file,"oem password length = %ld\n",oem_password_length);
unicode_password_length = vwv[6];
FPrintf(dump_smb_file,"unicode password length = %ld\n",unicode_password_length);
capabilities = (((unsigned long)vwv[10]) << 16) | vwv[9];
FPrintf(dump_smb_file,"capabilities = 0x%08lx\n",capabilities);
if(capabilities & 0x00000001)
FPrintf(dump_smb_file," CAP_RAW_MODE\n");
if(capabilities & 0x00000002)
FPrintf(dump_smb_file," CAP_MPX_MODE\n");
if(capabilities & 0x00000004)
FPrintf(dump_smb_file," CAP_UNICODE\n");
if(capabilities & 0x00000008)
FPrintf(dump_smb_file," CAP_LARGE_FILES\n");
if(capabilities & 0x00000010)
FPrintf(dump_smb_file," CAP_NT_SMBS\n");
if(capabilities & 0x00000020)
FPrintf(dump_smb_file," CAP_RPC_REMOTE_APIS\n");
if(capabilities & 0x00000040)
FPrintf(dump_smb_file," CAP_STATUS32\n");
if(capabilities & 0x00000080)
FPrintf(dump_smb_file," CAP_LEVEL_II_OPLOCKS\n");
if(capabilities & 0x00000100)
FPrintf(dump_smb_file," CAP_LOCK_AND_READ\n");
if(capabilities & 0x00000200)
FPrintf(dump_smb_file," CAP_NT_FIND\n");
if(capabilities & 0x00000400)
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
if(capabilities & 0x00000800)
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
if(capabilities & 0x00001000)
FPrintf(dump_smb_file," CAP_DFS\n");
if(capabilities & 0x00002000)
FPrintf(dump_smb_file," CAP_QUADWORD_ALIGNED\n");
if(capabilities & 0x00004000)
FPrintf(dump_smb_file," CAP_LARGE_READX\n");
if(capabilities & 0x00800000)
FPrintf(dump_smb_file," CAP_UNIX\n");
if(capabilities & 0x80000000)
FPrintf(dump_smb_file," CAP_EXTENDED_SECURITY\n");
if(num_data_bytes > 0)
{
oem_password = args;
len = oem_password_length;
unicode_password = &oem_password[len];
if(unicode_password < args_end)
{
len = unicode_password_length;
/* There could be a padding byte here which
* aligns the account name to a word
* boundary.
*/
if((header->flags2 & SMB_FLAGS2_UNICODE_STRINGS) && (len % 2) == 1)
len++;
account_name = &unicode_password[len];
if(account_name < args_end)
{
len = strlen(account_name);
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
primary_domain = &account_name[len+1];
if(primary_domain < args_end)
{
len = strlen(primary_domain);
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
native_os = &primary_domain[len+1];
if(native_os < args_end)
{
len = strlen(native_os);
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
native_lan_man = &native_os[len+1];
}
}
}
}
}
FPrintf(dump_smb_file,"account name = '%s'\n",account_name);
FPrintf(dump_smb_file,"primary domain = '%s'\n",primary_domain);
FPrintf(dump_smb_file,"native os = '%s'\n",native_os);
FPrintf(dump_smb_file,"native lan man = '%s'\n",native_lan_man);
}
else
{
int request_mode;
if(num_parameter_words <= 0)
return;
request_mode = vwv[0];
FPrintf(dump_smb_file,"request mode = 0x%04lx\n",request_mode);
if(request_mode & 0x0001)
FPrintf(dump_smb_file," SMB_SETUP_GUEST\n");
if(request_mode & 0x0002)
FPrintf(dump_smb_file," SMB_SETUP_USE_LANMAN_KEY\n");
if(num_data_bytes > 0)
{
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
native_os = args;
len = strlen(native_os);
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
native_lan_man = &native_os[len+1];
if(native_lan_man < args_end)
{
len = strlen(native_lan_man);
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
primary_domain = &native_lan_man[len+1];
}
FPrintf(dump_smb_file,"native os = '%s'\n",native_os);
FPrintf(dump_smb_file,"native lan man = '%s'\n",native_lan_man);
FPrintf(dump_smb_file,"primary domain = '%s'\n",primary_domain);
}
}
}
else if (command == SMB_COM_TREE_CONNECT_ANDX)
{
char args[1024];
if(num_data_bytes > 1023)
num_data_bytes = 1023;
memmove(args,data,num_data_bytes);
args[num_data_bytes] = '\0';
if(smb_packet_source == smb_packet_from_consumer)
{
const char * path;
const char * password;
const char * dev_name;
int len;
int flags;
int password_length;
flags = vwv[0];
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
if(flags & 0x0001)
FPrintf(dump_smb_file," TREE_CONNECT_ANDX_DISCONNECT_TID\n");
password_length = vwv[1];
FPrintf(dump_smb_file,"password length = %ld\n",password_length);
password = args;
len = password_length;
/* There could be a padding byte here which
* aligns the account name to a word
* boundary.
*/
if((header->flags2 & SMB_FLAGS2_UNICODE_STRINGS) && (len % 2) == 1)
len++;
/* ZZZ could be a Unicode string. */
path = &password[len];
len = (int)strlen(path)+1;
dev_name = &path[len];
FPrintf(dump_smb_file,"path = '%s'\n",path);
// FPrintf(dump_smb_file,"password = '%s'\n",password);
FPrintf(dump_smb_file,"dev name = '%s'\n",dev_name);
}
else
{
int len;
const char * service;
const char * native_file_system;
if(num_data_bytes <= 0)
return;
service = args;
len = strlen(service)+1;
/* ZZZ this could be Unicode text. */
native_file_system = &service[len];
FPrintf(dump_smb_file,"service = '%s'\n",service);
FPrintf(dump_smb_file,"native file system = '%s'\n",native_file_system);
}
}
else if (command == SMB_COM_QUERY_INFORMATION_DISK)
{
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 3)
{
FPrintf(dump_smb_file,"allocation units/server = %ld\n",vwv[0]);
FPrintf(dump_smb_file,"blocks/allocation unit = %ld\n",vwv[1]);
FPrintf(dump_smb_file,"block size (in bytes) = %ld\n",vwv[2]);
FPrintf(dump_smb_file,"free allocation units = %ld\n",vwv[3]);
}
}
else if (command == SMB_COM_SEARCH)
{
if(smb_packet_source == smb_packet_from_consumer)
{
int search_attributes;
const char * file_name;
const unsigned char * resume_key_data;
int resume_key_length;
int len;
int offset;
FPrintf(dump_smb_file,"max count = %ld\n",vwv[0]);
search_attributes = vwv[1];
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
if(search_attributes & 0x0100)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
if(search_attributes & 0x0200)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
if(search_attributes & 0x0400)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
if(search_attributes & 0x1000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
if(search_attributes & 0x2000)
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
file_name = (char *)data;
len = strlen(file_name);
FPrintf(dump_smb_file,"buffer format = %ld\n",file_name[0]);
FPrintf(dump_smb_file,"file name = '%s'\n",file_name+1);
resume_key_data = (unsigned char *)&file_name[len+1];
offset = 0;
resume_key_length = next_data_word(resume_key_data,&offset);
FPrintf(dump_smb_file,"resume key length = %ld\n",resume_key_length);
if(resume_key_length == 21)
{
unsigned char reserved;
const unsigned char * server_state;
const unsigned char * client_state;
reserved = next_data_byte(resume_key_data,&offset);
server_state = next_data_bytes(resume_key_data,16,&offset);
client_state = next_data_bytes(resume_key_data,4,&offset);
FPrintf(dump_smb_file,"resume key reserved = %02lx\n",reserved);
FPrintf(dump_smb_file,"resume key server state = ");
for(i = 0 ; i < 16 ; i++)
FPrintf(dump_smb_file,"%02lx",server_state[i]);
FPrintf(dump_smb_file,"\n");
FPrintf(dump_smb_file,"resume key client state = ");
for(i = 0 ; i < 4 ; i++)
FPrintf(dump_smb_file,"%02lx",client_state[i]);
FPrintf(dump_smb_file,"\n");
}
}
else
{
unsigned char reserved;
const unsigned char * server_state;
const unsigned char * client_state;
unsigned short last_write_date;
unsigned short last_write_time;
int count;
int offset;
int buffer_format;
int data_length;
int i,j;
int file_attributes;
const char * file_name;
if(num_parameter_words <= 0)
return;
count = vwv[0];
FPrintf(dump_smb_file,"count = %ld\n",count);
offset = 0;
buffer_format = next_data_byte(data,&offset);
FPrintf(dump_smb_file,"buffer format = %ld\n",buffer_format);
data_length = next_data_word(data,&offset);
FPrintf(dump_smb_file,"data length = %ld\n",data_length);
for(j = 0 ; j < count ; j++)
{
FPrintf(dump_smb_file,"directory entry [%ld]:\n",j);
reserved = next_data_byte(data,&offset);
server_state = next_data_bytes(data,16,&offset);
client_state = next_data_bytes(data,4,&offset);
FPrintf(dump_smb_file,"\tresume key reserved = %02lx\n",reserved);
FPrintf(dump_smb_file,"\tresume key server state = ");
for(i = 0 ; i < 16 ; i++)
FPrintf(dump_smb_file,"%02lx",server_state[i]);
FPrintf(dump_smb_file,"\n");
FPrintf(dump_smb_file,"\tresume key client state = ");
for(i = 0 ; i < 4 ; i++)
FPrintf(dump_smb_file,"%02lx",client_state[i]);
FPrintf(dump_smb_file,"\n");
file_attributes = next_data_byte(data,&offset);
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
if((file_attributes & 0x001f) == 0)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_NORMAL\n");
if(file_attributes & 0x0001)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_READ_ONLY\n");
if(file_attributes & 0x0002)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_HIDDEN\n");
if(file_attributes & 0x0004)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_SYSTEM\n");
if(file_attributes & 0x0008)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_VOLUME\n");
if(file_attributes & 0x0010)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_DIRECTORY\n");
if(file_attributes & 0x0020)
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_ARCHIVE\n");
last_write_time = next_data_word(data,&offset);
last_write_date = next_data_word(data,&offset);
FPrintf(dump_smb_file,"\tlast write time = 0x%04lx\n",last_write_time);
FPrintf(dump_smb_file,"\tlast write date = 0x%04lx\n",last_write_date);
FPrintf(dump_smb_file,"\tlast write = %s\n",convert_smb_date_time_to_string(last_write_date,last_write_time));
FPrintf(dump_smb_file,"\tfile size = %lu\n",next_data_dword(data,&offset));
file_name = (const char *)next_data_bytes(data,13,&offset);
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
}
}
}
}
/*****************************************************************************/
static void
print_smb_parameters(int num_parameter_words,const unsigned char *parameters)
{
if(num_parameter_words > 0)
{
int word_value;
int i,j;
for(i = j = 0 ; i < num_parameter_words ; i++, j++)
{
word_value = parameters[j] + (((int)parameters[j+1]) << 8);
FPrintf(dump_smb_file," %04lx: %04lx (bytes: %02lx%02lx)\n",i,word_value,parameters[j],parameters[j+1]);
}
}
}
/*****************************************************************************/
static void
print_smb_header(const struct smb_header * header,int header_length,const unsigned char *packet,
int packet_size,enum smb_packet_source_t smb_packet_source,int max_buffer_size)
{
enum errdos_t
{
errdos_badfunc=1,
errdos_badfile=2,
errdos_badpath=3,
errdos_nofids=4,
errdos_noaccess=5,
errdos_badfid=6,
errdos_badmcb=7,
errdos_nomem=8,
errdos_badmem=9,
errdos_badenv=10,
errdos_badformat=11,
errdos_badaccess=12,
errdos_baddata=13,
errdos_baddrive=15,
errdos_remcd=16,
errdos_diffdevice=17,
errdos_nofiles=18,
errdos_badshare=32,
errdos_lock=33,
errdos_filexists=80,
errdos_quota=512,
errdos_notALink=513,
};
enum errsrv_t
{
errsrv_error=1,
errsrv_badpw=2,
errsrv_access=4,
errsrv_invtid=5,
errsrv_invnetname=6,
errsrv_invdevice=7,
errsrv_qfull=49,
errsrv_qtoobig=50,
errsrv_qeof=51,
errsrv_invpfid=52,
errsrv_smbcmd=64,
errsrv_srverror=65,
errsrv_badBID=66,
errsrv_filespecs=67,
errsrv_badLink=68,
errsrv_badpermits=69,
errsrv_badPID=70,
errsrv_setattrmode=71,
errsrv_paused=81,
errsrv_msgoff=82,
errsrv_noroom=83,
errsrv_rmuns=87,
errsrv_timeout=88,
errsrv_noresource=89,
errsrv_toomanyuids=90,
errsrv_baduid=91,
errsrv_usempx=250,
errsrv_usestd=251,
errsrv_contmpx=252,
errsrv_badPassword=254,
errsrv_notifyEnumDir=1024,
errsrv_accountExpired=2239,
errsrv_badClient=2240,
errsrv_badLogonTime=2241,
errsrv_passwordExpired=2242,
errsrv_nosupport=65535,
};
enum errhrd_t
{
errhrd_nowrite=19,
errhrd_badunit=20,
errhrd_notready=21,
errhrd_badcmd=22,
errhrd_data=23,
errhrd_badreq=24,
errhrd_seek=25,
errhrd_badmedia=26,
errhrd_badsector=27,
errhrd_nopaper=28,
errhrd_write=29,
errhrd_read=30,
errhrd_general=31,
errhrd_badshare=32,
errhrd_lock=33,
errhrd_wrongdisk=34,
errhrd_FCBUnavail=35,
errhrd_sharebufexc=36,
};
enum nt_status_t
{
nt_status_unsuccessful=1,
nt_status_not_implemented=2,
nt_status_invalid_info_class=3,
nt_status_info_length_mismatch=4,
nt_status_access_violation=5,
nt_status_in_page_error=6,
nt_status_pagefile_quota=7,
nt_status_invalid_handle=8,
nt_status_bad_initial_stack=9,
nt_status_bad_initial_pc=10,
nt_status_invalid_cid=11,
nt_status_timer_not_canceled=12,
nt_status_invalid_parameter=13,
nt_status_no_such_device=14,
nt_status_no_such_file=15,
nt_status_invalid_device_request=16,
nt_status_end_of_file=17,
nt_status_wrong_volume=18,
nt_status_no_media_in_device=19,
nt_status_unrecognized_media=20,
nt_status_nonexistent_sector=21,
nt_status_more_processing_required=22,
nt_status_no_memory=23,
nt_status_conflicting_addresses=24,
nt_status_not_mapped_view=25,
nt_status_unable_to_free_vm=26,
nt_status_unable_to_delete_section=27,
nt_status_invalid_system_service=28,
nt_status_illegal_instruction=29,
nt_status_invalid_lock_sequence=30,
nt_status_invalid_view_size=31,
nt_status_invalid_file_for_section=32,
nt_status_already_committed=33,
nt_status_access_denied=34,
nt_status_buffer_too_small=35,
nt_status_object_type_mismatch=36,
nt_status_noncontinuable_exception=37,
nt_status_invalid_disposition=38,
nt_status_unwind=39,
nt_status_bad_stack=40,
nt_status_invalid_unwind_target=41,
nt_status_not_locked=42,
nt_status_parity_error=43,
nt_status_unable_to_decommit_vm=44,
nt_status_not_committed=45,
nt_status_invalid_port_attributes=46,
nt_status_port_message_too_long=47,
nt_status_invalid_parameter_mix=48,
nt_status_invalid_quota_lower=49,
nt_status_disk_corrupt_error=50,
nt_status_object_name_invalid=51,
nt_status_object_name_not_found=52,
nt_status_object_name_collision=53,
nt_status_handle_not_waitable=54,
nt_status_port_disconnected=55,
nt_status_device_already_attached=56,
nt_status_object_path_invalid=57,
nt_status_object_path_not_found=58,
nt_status_object_path_syntax_bad=59,
nt_status_data_overrun=60,
nt_status_data_late_error=61,
nt_status_data_error=62,
nt_status_crc_error=63,
nt_status_section_too_big=64,
nt_status_port_connection_refused=65,
nt_status_invalid_port_handle=66,
nt_status_sharing_violation=67,
nt_status_quota_exceeded=68,
nt_status_invalid_page_protection=69,
nt_status_mutant_not_owned=70,
nt_status_semaphore_limit_exceeded=71,
nt_status_port_already_set=72,
nt_status_section_not_image=73,
nt_status_suspend_count_exceeded=74,
nt_status_thread_is_terminating=75,
nt_status_bad_working_set_limit=76,
nt_status_incompatible_file_map=77,
nt_status_section_protection=78,
nt_status_eas_not_supported=79,
nt_status_ea_too_large=80,
nt_status_nonexistent_ea_entry=81,
nt_status_no_eas_on_file=82,
nt_status_ea_corrupt_error=83,
nt_status_file_lock_conflict=84,
nt_status_lock_not_granted=85,
nt_status_delete_pending=86,
nt_status_ctl_file_not_supported=87,
nt_status_unknown_revision=88,
nt_status_revision_mismatch=89,
nt_status_invalid_owner=90,
nt_status_invalid_primary_group=91,
nt_status_no_impersonation_token=92,
nt_status_cant_disable_mandatory=93,
nt_status_no_logon_servers=94,
nt_status_no_such_logon_session=95,
nt_status_no_such_privilege=96,
nt_status_privilege_not_held=97,
nt_status_invalid_account_name=98,
nt_status_user_exists=99,
nt_status_no_such_user=100,
nt_status_group_exists=101,
nt_status_no_such_group=102,
nt_status_member_in_group=103,
nt_status_member_not_in_group=104,
nt_status_last_admin=105,
nt_status_wrong_password=106,
nt_status_ill_formed_password=107,
nt_status_password_restriction=108,
nt_status_logon_failure=109,
nt_status_account_restriction=110,
nt_status_invalid_logon_hours=111,
nt_status_invalid_workstation=112,
nt_status_password_expired=113,
nt_status_account_disabled=114,
nt_status_none_mapped=115,
nt_status_too_many_luids_requested=116,
nt_status_luids_exhausted=117,
nt_status_invalid_sub_authority=118,
nt_status_invalid_acl=119,
nt_status_invalid_sid=120,
nt_status_invalid_security_descr=121,
nt_status_procedure_not_found=122,
nt_status_invalid_image_format=123,
nt_status_no_token=124,
nt_status_bad_inheritance_acl=125,
nt_status_range_not_locked=126,
nt_status_disk_full=127,
nt_status_server_disabled=128,
nt_status_server_not_disabled=129,
nt_status_too_many_guids_requested=130,
nt_status_guids_exhausted=131,
nt_status_invalid_id_authority=132,
nt_status_agents_exhausted=133,
nt_status_invalid_volume_label=134,
nt_status_section_not_extended=135,
nt_status_not_mapped_data=136,
nt_status_resource_data_not_found=137,
nt_status_resource_type_not_found=138,
nt_status_resource_name_not_found=139,
nt_status_array_bounds_exceeded=140,
nt_status_float_denormal_operand=141,
nt_status_float_divide_by_zero=142,
nt_status_float_inexact_result=143,
nt_status_float_invalid_operation=144,
nt_status_float_overflow=145,
nt_status_float_stack_check=146,
nt_status_float_underflow=147,
nt_status_integer_divide_by_zero=148,
nt_status_integer_overflow=149,
nt_status_privileged_instruction=150,
nt_status_too_many_paging_files=151,
nt_status_file_invalid=152,
nt_status_allotted_space_exceeded=153,
nt_status_insufficient_resources=154,
nt_status_dfs_exit_path_found=155,
nt_status_device_data_error=156,
nt_status_device_not_connected=157,
nt_status_device_power_failure=158,
nt_status_free_vm_not_at_base=159,
nt_status_memory_not_allocated=160,
nt_status_working_set_quota=161,
nt_status_media_write_protected=162,
nt_status_device_not_ready=163,
nt_status_invalid_group_attributes=164,
nt_status_bad_impersonation_level=165,
nt_status_cant_open_anonymous=166,
nt_status_bad_validation_class=167,
nt_status_bad_token_type=168,
nt_status_bad_master_boot_record=169,
nt_status_instruction_misalignment=170,
nt_status_instance_not_available=171,
nt_status_pipe_not_available=172,
nt_status_invalid_pipe_state=173,
nt_status_pipe_busy=174,
nt_status_illegal_function=175,
nt_status_pipe_disconnected=176,
nt_status_pipe_closing=177,
nt_status_pipe_connected=178,
nt_status_pipe_listening=179,
nt_status_invalid_read_mode=180,
nt_status_io_timeout=181,
nt_status_file_forced_closed=182,
nt_status_profiling_not_started=183,
nt_status_profiling_not_stopped=184,
nt_status_could_not_interpret=185,
nt_status_file_is_a_directory=186,
nt_status_not_supported=187,
nt_status_remote_not_listening=188,
nt_status_duplicate_name=189,
nt_status_bad_network_path=190,
nt_status_network_busy=191,
nt_status_device_does_not_exist=192,
nt_status_too_many_commands=193,
nt_status_adapter_hardware_error=194,
nt_status_invalid_network_response=195,
nt_status_unexpected_network_error=196,
nt_status_bad_remote_adapter=197,
nt_status_print_queue_full=198,
nt_status_no_spool_space=199,
nt_status_print_cancelled=200,
nt_status_network_name_deleted=201,
nt_status_network_access_denied=202,
nt_status_bad_device_type=203,
nt_status_bad_network_name=204,
nt_status_too_many_names=205,
nt_status_too_many_sessions=206,
nt_status_sharing_paused=207,
nt_status_request_not_accepted=208,
nt_status_redirector_paused=209,
nt_status_net_write_fault=210,
nt_status_profiling_at_limit=211,
nt_status_not_same_device=212,
nt_status_file_renamed=213,
nt_status_virtual_circuit_closed=214,
nt_status_no_security_on_object=215,
nt_status_cant_wait=216,
nt_status_pipe_empty=217,
nt_status_cant_access_domain_info=218,
nt_status_cant_terminate_self=219,
nt_status_invalid_server_state=220,
nt_status_invalid_domain_state=221,
nt_status_invalid_domain_role=222,
nt_status_no_such_domain=223,
nt_status_domain_exists=224,
nt_status_domain_limit_exceeded=225,
nt_status_oplock_not_granted=226,
nt_status_invalid_oplock_protocol=227,
nt_status_internal_db_corruption=228,
nt_status_internal_error=229,
nt_status_generic_not_mapped=230,
nt_status_bad_descriptor_format=231,
nt_status_invalid_user_buffer=232,
nt_status_unexpected_io_error=233,
nt_status_unexpected_mm_create_err=234,
nt_status_unexpected_mm_map_error=235,
nt_status_unexpected_mm_extend_err=236,
nt_status_not_logon_process=237,
nt_status_logon_session_exists=238,
nt_status_invalid_parameter_1=239,
nt_status_invalid_parameter_2=240,
nt_status_invalid_parameter_3=241,
nt_status_invalid_parameter_4=242,
nt_status_invalid_parameter_5=243,
nt_status_invalid_parameter_6=244,
nt_status_invalid_parameter_7=245,
nt_status_invalid_parameter_8=246,
nt_status_invalid_parameter_9=247,
nt_status_invalid_parameter_10=248,
nt_status_invalid_parameter_11=249,
nt_status_invalid_parameter_12=250,
nt_status_redirector_not_started=251,
nt_status_redirector_started=252,
nt_status_stack_overflow=253,
nt_status_no_such_package=254,
nt_status_bad_function_table=255,
nt_status_directory_not_empty=257,
nt_status_file_corrupt_error=258,
nt_status_not_a_directory=259,
nt_status_bad_logon_session_state=260,
nt_status_logon_session_collision=261,
nt_status_name_too_long=262,
nt_status_files_open=263,
nt_status_connection_in_use=264,
nt_status_message_not_found=265,
nt_status_process_is_terminating=266,
nt_status_invalid_logon_type=267,
nt_status_no_guid_translation=268,
nt_status_cannot_impersonate=269,
nt_status_image_already_loaded=270,
nt_status_abios_not_present=271,
nt_status_abios_lid_not_exist=272,
nt_status_abios_lid_already_owned=273,
nt_status_abios_not_lid_owner=274,
nt_status_abios_invalid_command=275,
nt_status_abios_invalid_lid=276,
nt_status_abios_selector_not_available=277,
nt_status_abios_invalid_selector=278,
nt_status_no_ldt=279,
nt_status_invalid_ldt_size=280,
nt_status_invalid_ldt_offset=281,
nt_status_invalid_ldt_descriptor=282,
nt_status_invalid_image_ne_format=283,
nt_status_rxact_invalid_state=284,
nt_status_rxact_commit_failure=285,
nt_status_mapped_file_size_zero=286,
nt_status_too_many_opened_files=287,
nt_status_cancelled=288,
nt_status_cannot_delete=289,
nt_status_invalid_computer_name=290,
nt_status_file_deleted=291,
nt_status_special_account=292,
nt_status_special_group=293,
nt_status_special_user=294,
nt_status_members_primary_group=295,
nt_status_file_closed=296,
nt_status_too_many_threads=297,
nt_status_thread_not_in_process=298,
nt_status_token_already_in_use=299,
nt_status_pagefile_quota_exceeded=300,
nt_status_commitment_limit=301,
nt_status_invalid_image_le_format=302,
nt_status_invalid_image_not_mz=303,
nt_status_invalid_image_protect=304,
nt_status_invalid_image_win_16=305,
nt_status_logon_server_conflict=306,
nt_status_time_difference_at_dc=307,
nt_status_synchronization_required=308,
nt_status_dll_not_found=309,
nt_status_open_failed=310,
nt_status_io_privilege_failed=311,
nt_status_ordinal_not_found=312,
nt_status_entrypoint_not_found=313,
nt_status_control_c_exit=314,
nt_status_local_disconnect=315,
nt_status_remote_disconnect=316,
nt_status_remote_resources=317,
nt_status_link_failed=318,
nt_status_link_timeout=319,
nt_status_invalid_connection=320,
nt_status_invalid_address=321,
nt_status_dll_init_failed=322,
nt_status_missing_systemfile=323,
nt_status_unhandled_exception=324,
nt_status_app_init_failure=325,
nt_status_pagefile_create_failed=326,
nt_status_no_pagefile=327,
nt_status_invalid_level=328,
nt_status_wrong_password_core=329,
nt_status_illegal_float_context=330,
nt_status_pipe_broken=331,
nt_status_registry_corrupt=332,
nt_status_registry_io_failed=333,
nt_status_no_event_pair=334,
nt_status_unrecognized_volume=335,
nt_status_serial_no_device_inited=336,
nt_status_no_such_alias=337,
nt_status_member_not_in_alias=338,
nt_status_member_in_alias=339,
nt_status_alias_exists=340,
nt_status_logon_not_granted=341,
nt_status_too_many_secrets=342,
nt_status_secret_too_long=343,
nt_status_internal_db_error=344,
nt_status_fullscreen_mode=345,
nt_status_too_many_context_ids=346,
nt_status_logon_type_not_granted=347,
nt_status_not_registry_file=348,
nt_status_nt_cross_encryption_required=349,
nt_status_domain_ctrlr_config_error=350,
nt_status_ft_missing_member=351,
nt_status_ill_formed_service_entry=352,
nt_status_illegal_character=353,
nt_status_unmappable_character=354,
nt_status_undefined_character=355,
nt_status_floppy_volume=356,
nt_status_floppy_id_mark_not_found=357,
nt_status_floppy_wrong_cylinder=358,
nt_status_floppy_unknown_error=359,
nt_status_floppy_bad_registers=360,
nt_status_disk_recalibrate_failed=361,
nt_status_disk_operation_failed=362,
nt_status_disk_reset_failed=363,
nt_status_shared_irq_busy=364,
nt_status_ft_orphaning=365,
nt_status_partition_failure=370,
nt_status_invalid_block_length=371,
nt_status_device_not_partitioned=372,
nt_status_unable_to_lock_media=373,
nt_status_unable_to_unload_media=374,
nt_status_eom_overflow=375,
nt_status_no_media=376,
nt_status_no_such_member=378,
nt_status_invalid_member=379,
nt_status_key_deleted=380,
nt_status_no_log_space=381,
nt_status_too_many_sids=382,
nt_status_lm_cross_encryption_required=383,
nt_status_key_has_children=384,
nt_status_child_must_be_volatile=385,
nt_status_device_configuration_error=386,
nt_status_driver_internal_error=387,
nt_status_invalid_device_state=388,
nt_status_io_device_error=389,
nt_status_device_protocol_error=390,
nt_status_backup_controller=391,
nt_status_log_file_full=392,
nt_status_too_late=393,
nt_status_no_trust_lsa_secret=394,
nt_status_no_trust_sam_account=395,
nt_status_trusted_domain_failure=396,
nt_status_trusted_relationship_failure=397,
nt_status_eventlog_file_corrupt=398,
nt_status_eventlog_cant_start=399,
nt_status_trust_failure=400,
nt_status_mutant_limit_exceeded=401,
nt_status_netlogon_not_started=402,
nt_status_account_expired=403,
nt_status_possible_deadlock=404,
nt_status_network_credential_conflict=405,
nt_status_remote_session_limit=406,
nt_status_eventlog_file_changed=407,
nt_status_nologon_interdomain_trust_account=408,
nt_status_nologon_workstation_trust_account=409,
nt_status_nologon_server_trust_account=410,
nt_status_domain_trust_inconsistent=411,
nt_status_fs_driver_required=412,
nt_status_no_user_session_key=514,
nt_status_user_session_deleted=515,
nt_status_resource_lang_not_found=516,
nt_status_insuff_server_resources=517,
nt_status_invalid_buffer_size=518,
nt_status_invalid_address_component=519,
nt_status_invalid_address_wildcard=520,
nt_status_too_many_addresses=521,
nt_status_address_already_exists=522,
nt_status_address_closed=523,
nt_status_connection_disconnected=524,
nt_status_connection_reset=525,
nt_status_too_many_nodes=526,
nt_status_transaction_aborted=527,
nt_status_transaction_timed_out=528,
nt_status_transaction_no_release=529,
nt_status_transaction_no_match=530,
nt_status_transaction_responded=531,
nt_status_transaction_invalid_id=532,
nt_status_transaction_invalid_type=533,
nt_status_not_server_session=534,
nt_status_not_client_session=535,
nt_status_cannot_load_registry_file=536,
nt_status_debug_attach_failed=537,
nt_status_system_process_terminated=538,
nt_status_data_not_accepted=539,
nt_status_no_browser_servers_found=540,
nt_status_vdm_hard_error=541,
nt_status_driver_cancel_timeout=542,
nt_status_reply_message_mismatch=543,
nt_status_mapped_alignment=544,
nt_status_image_checksum_mismatch=545,
nt_status_lost_writebehind_data=546,
nt_status_client_server_parameters_invalid=547,
nt_status_password_must_change=548,
nt_status_not_found=549,
nt_status_not_tiny_stream=550,
nt_status_recovery_failure=551,
nt_status_stack_overflow_read=552,
nt_status_fail_check=553,
nt_status_duplicate_objectid=554,
nt_status_objectid_exists=555,
nt_status_convert_to_large=556,
nt_status_retry=557,
nt_status_found_out_of_scope=558,
nt_status_allocate_bucket=559,
nt_status_propset_not_found=560,
nt_status_marshall_overflow=561,
nt_status_invalid_variant=562,
nt_status_domain_controller_not_found=563,
nt_status_account_locked_out=564,
nt_status_handle_not_closable=565,
nt_status_connection_refused=566,
nt_status_graceful_disconnect=567,
nt_status_address_already_associated=568,
nt_status_address_not_associated=569,
nt_status_connection_invalid=570,
nt_status_connection_active=571,
nt_status_network_unreachable=572,
nt_status_host_unreachable=573,
nt_status_protocol_unreachable=574,
nt_status_port_unreachable=575,
nt_status_request_aborted=576,
nt_status_connection_aborted=577,
nt_status_bad_compression_buffer=578,
nt_status_user_mapped_file=579,
nt_status_audit_failed=580,
nt_status_timer_resolution_not_set=581,
nt_status_connection_count_limit=582,
nt_status_login_time_restriction=583,
nt_status_login_wksta_restriction=584,
nt_status_image_mp_up_mismatch=585,
nt_status_insufficient_logon_info=592,
nt_status_bad_dll_entrypoint=593,
nt_status_bad_service_entrypoint=594,
nt_status_lpc_reply_lost=595,
nt_status_ip_address_conflict1=596,
nt_status_ip_address_conflict2=597,
nt_status_registry_quota_limit=598,
nt_status_path_not_covered=599,
nt_status_no_callback_active=600,
nt_status_license_quota_exceeded=601,
nt_status_pwd_too_short=602,
nt_status_pwd_too_recent=603,
nt_status_pwd_history_conflict=604,
nt_status_plugplay_no_device=606,
nt_status_unsupported_compression=607,
nt_status_invalid_hw_profile=608,
nt_status_invalid_plugplay_device_path=609,
nt_status_driver_ordinal_not_found=610,
nt_status_driver_entrypoint_not_found=611,
nt_status_resource_not_owned=612,
nt_status_too_many_links=613,
nt_status_quota_list_inconsistent=614,
nt_status_file_is_offline=615,
// nt_status_notify_enum_dir=268,
};
struct error_label_entry
{
int code;
const char * label;
};
static const struct error_label_entry dos_errors[] =
{
{ 0, "not specified" },
{ errdos_badfunc, "bad func" },
{ errdos_badfile, "bad file" },
{ errdos_badpath, "bad path" },
{ errdos_nofids, "no fids" },
{ errdos_noaccess, "no access" },
{ errdos_badfid, "bad fid" },
{ errdos_badmcb, "bad mcb" },
{ errdos_nomem, "no mem" },
{ errdos_badmem, "bad mem" },
{ errdos_badenv, "bad env" },
{ errdos_badformat, "bad format" },
{ errdos_badaccess, "bad access" },
{ errdos_baddata, "bad data" },
{ errdos_baddrive, "bad drive" },
{ errdos_remcd, "rem cd" },
{ errdos_diffdevice, "diff device" },
{ errdos_nofiles, "no files" },
{ errdos_badshare, "bad share" },
{ errdos_lock, "lock" },
{ errdos_filexists, "file exists" },
{ errdos_quota, "quota" },
{ errdos_notALink, "not a link" },
{ -1, NULL }
};
static const struct error_label_entry server_errors[] =
{
{ 0, "not specified" },
{ errsrv_error, "error" },
{ errsrv_badpw, "bad pw" },
{ errsrv_access, "access" },
{ errsrv_invtid, "inv tid" },
{ errsrv_invnetname, "inv net name" },
{ errsrv_invdevice, "inv device" },
{ errsrv_qfull, "q full" },
{ errsrv_qtoobig, "q toobig" },
{ errsrv_qeof, "q eof" },
{ errsrv_invpfid, "inv pfid" },
{ errsrv_smbcmd, "smb cmd" },
{ errsrv_srverror, "srv error" },
{ errsrv_badBID, "bad BID" },
{ errsrv_filespecs, "file specs" },
{ errsrv_badLink, "bad link" },
{ errsrv_badpermits, "bad permits" },
{ errsrv_badPID, "bad PID" },
{ errsrv_setattrmode, "setattr mode" },
{ errsrv_paused, "paused" },
{ errsrv_msgoff, "msg off" },
{ errsrv_noroom, "no room" },
{ errsrv_rmuns, "rmuns" },
{ errsrv_timeout, "timeout" },
{ errsrv_noresource, "no resource" },
{ errsrv_toomanyuids, "too many uids" },
{ errsrv_baduid, "bad uid" },
{ errsrv_usempx, "use mpx" },
{ errsrv_usestd, "use std" },
{ errsrv_contmpx, "cont mpx" },
{ errsrv_badPassword, "ba DPassword" },
{ errsrv_notifyEnumDir, "notify enum dir" },
{ errsrv_accountExpired, "account expired" },
{ errsrv_badClient, "bad client" },
{ errsrv_badLogonTime, "bad logon time" },
{ errsrv_passwordExpired, "password expired" },
{ errsrv_nosupport, "no support" },
{ -1, NULL }
};
static const struct error_label_entry hardware_errors[] =
{
{ 0, "not specified" },
{ errhrd_nowrite, "no write" },
{ errhrd_badunit, "bad unit" },
{ errhrd_notready, "not ready" },
{ errhrd_badcmd, "bad cmd" },
{ errhrd_data, "data" },
{ errhrd_badreq, "bad req" },
{ errhrd_seek, "seek" },
{ errhrd_badmedia, "bad media" },
{ errhrd_badsector, "bad sector" },
{ errhrd_nopaper, "no paper" },
{ errhrd_write, "write" },
{ errhrd_read, "read" },
{ errhrd_general, "general" },
{ errhrd_badshare, "bad share" },
{ errhrd_lock, "lock" },
{ errhrd_wrongdisk, "wrong disk" },
{ errhrd_FCBUnavail, "FCB unavail" },
{ errhrd_sharebufexc, "share buf exc" },
{ -1, NULL }
};
static const struct error_label_entry nt_error_codes[] =
{
{ 0, "not specified" },
{ nt_status_unsuccessful, "unsuccessful" },
{ nt_status_not_implemented, "not implemented" },
{ nt_status_invalid_info_class, "invalid info class" },
{ nt_status_info_length_mismatch, "info length mismatch" },
{ nt_status_access_violation, "access violation" },
{ nt_status_in_page_error, "in page error" },
{ nt_status_pagefile_quota, "pagefile quota" },
{ nt_status_invalid_handle, "invalid handle" },
{ nt_status_bad_initial_stack, "bad initial stack" },
{ nt_status_bad_initial_pc, "bad initial pc" },
{ nt_status_invalid_cid, "invalid cid" },
{ nt_status_timer_not_canceled, "timer not canceled" },
{ nt_status_invalid_parameter, "invalid parameter" },
{ nt_status_no_such_device, "no such device" },
{ nt_status_no_such_file, "no such file" },
{ nt_status_invalid_device_request, "invalid device request" },
{ nt_status_end_of_file, "end of file" },
{ nt_status_wrong_volume, "wrong volume" },
{ nt_status_no_media_in_device, "no media in device" },
{ nt_status_unrecognized_media, "unrecognized media" },
{ nt_status_nonexistent_sector, "nonexistent sector" },
{ nt_status_more_processing_required, "more processing required" },
{ nt_status_no_memory, "no memory" },
{ nt_status_conflicting_addresses, "conflicting addresses" },
{ nt_status_not_mapped_view, "not mapped view" },
{ nt_status_unable_to_free_vm, "unable to free vm" },
{ nt_status_unable_to_delete_section, "unable to delete section" },
{ nt_status_invalid_system_service, "invalid system service" },
{ nt_status_illegal_instruction, "illegal instruction" },
{ nt_status_invalid_lock_sequence, "invalid lock sequence" },
{ nt_status_invalid_view_size, "invalid view size" },
{ nt_status_invalid_file_for_section, "invalid file for section" },
{ nt_status_already_committed, "already committed" },
{ nt_status_access_denied, "access denied" },
{ nt_status_buffer_too_small, "buffer too small" },
{ nt_status_object_type_mismatch, "object type mismatch" },
{ nt_status_noncontinuable_exception, "noncontinuable exception" },
{ nt_status_invalid_disposition, "invalid disposition" },
{ nt_status_unwind, "unwind" },
{ nt_status_bad_stack, "bad stack" },
{ nt_status_invalid_unwind_target, "invalid unwind target" },
{ nt_status_not_locked, "not locked" },
{ nt_status_parity_error, "parity error" },
{ nt_status_unable_to_decommit_vm, "unable to decommit vm" },
{ nt_status_not_committed, "not committed" },
{ nt_status_invalid_port_attributes, "invalid port attributes" },
{ nt_status_port_message_too_long, "port message too long" },
{ nt_status_invalid_parameter_mix, "invalid parameter mix" },
{ nt_status_invalid_quota_lower, "invalid quota lower" },
{ nt_status_disk_corrupt_error, "disk corrupt error" },
{ nt_status_object_name_invalid, "object name invalid" },
{ nt_status_object_name_not_found, "object name not found" },
{ nt_status_object_name_collision, "object name collision" },
{ nt_status_handle_not_waitable, "handle not waitable" },
{ nt_status_port_disconnected, "port disconnected" },
{ nt_status_device_already_attached, "device already attached" },
{ nt_status_object_path_invalid, "object path invalid" },
{ nt_status_object_path_not_found, "object path not found" },
{ nt_status_object_path_syntax_bad, "object path syntax bad" },
{ nt_status_data_overrun, "data overrun" },
{ nt_status_data_late_error, "data late error" },
{ nt_status_data_error, "data error" },
{ nt_status_crc_error, "crc error" },
{ nt_status_section_too_big, "section too big" },
{ nt_status_port_connection_refused, "port connection refused" },
{ nt_status_invalid_port_handle, "invalid port handle" },
{ nt_status_sharing_violation, "sharing violation" },
{ nt_status_quota_exceeded, "quota exceeded" },
{ nt_status_invalid_page_protection, "invalid page protection" },
{ nt_status_mutant_not_owned, "mutant not owned" },
{ nt_status_semaphore_limit_exceeded, "semaphore limit exceeded" },
{ nt_status_port_already_set, "port already set" },
{ nt_status_section_not_image, "section not image" },
{ nt_status_suspend_count_exceeded, "suspend count exceeded" },
{ nt_status_thread_is_terminating, "thread is terminating" },
{ nt_status_bad_working_set_limit, "bad working set limit" },
{ nt_status_incompatible_file_map, "incompatible file map" },
{ nt_status_section_protection, "section protection" },
{ nt_status_eas_not_supported, "eas not supported" },
{ nt_status_ea_too_large, "ea too large" },
{ nt_status_nonexistent_ea_entry, "nonexistent ea entry" },
{ nt_status_no_eas_on_file, "no eas on file" },
{ nt_status_ea_corrupt_error, "ea corrupt error" },
{ nt_status_file_lock_conflict, "file lock conflict" },
{ nt_status_lock_not_granted, "lock not granted" },
{ nt_status_delete_pending, "delete pending" },
{ nt_status_ctl_file_not_supported, "ctl file not supported" },
{ nt_status_unknown_revision, "unknown revision" },
{ nt_status_revision_mismatch, "revision mismatch" },
{ nt_status_invalid_owner, "invalid owner" },
{ nt_status_invalid_primary_group, "invalid primary group" },
{ nt_status_no_impersonation_token, "no impersonation token" },
{ nt_status_cant_disable_mandatory, "cant disable mandatory" },
{ nt_status_no_logon_servers, "no logon servers" },
{ nt_status_no_such_logon_session, "no such logon session" },
{ nt_status_no_such_privilege, "no such privilege" },
{ nt_status_privilege_not_held, "privilege not held" },
{ nt_status_invalid_account_name, "invalid account name" },
{ nt_status_user_exists, "user exists" },
{ nt_status_no_such_user, "no such user" },
{ nt_status_group_exists, "group exists" },
{ nt_status_no_such_group, "no such group" },
{ nt_status_member_in_group, "member in group" },
{ nt_status_member_not_in_group, "member not in group" },
{ nt_status_last_admin, "last admin" },
{ nt_status_wrong_password, "wrong password" },
{ nt_status_ill_formed_password, "ill formed password" },
{ nt_status_password_restriction, "password restriction" },
{ nt_status_logon_failure, "logon failure" },
{ nt_status_account_restriction, "account restriction" },
{ nt_status_invalid_logon_hours, "invalid logon hours" },
{ nt_status_invalid_workstation, "invalid workstation" },
{ nt_status_password_expired, "password expired" },
{ nt_status_account_disabled, "account disabled" },
{ nt_status_none_mapped, "none mapped" },
{ nt_status_too_many_luids_requested, "too many luids requested" },
{ nt_status_luids_exhausted, "luids exhausted" },
{ nt_status_invalid_sub_authority, "invalid sub authority" },
{ nt_status_invalid_acl, "invalid acl" },
{ nt_status_invalid_sid, "invalid sid" },
{ nt_status_invalid_security_descr, "invalid security descr" },
{ nt_status_procedure_not_found, "procedure not found" },
{ nt_status_invalid_image_format, "invalid image format" },
{ nt_status_no_token, "no token" },
{ nt_status_bad_inheritance_acl, "bad inheritance acl" },
{ nt_status_range_not_locked, "range not locked" },
{ nt_status_disk_full, "disk full" },
{ nt_status_server_disabled, "server disabled" },
{ nt_status_server_not_disabled, "server not disabled" },
{ nt_status_too_many_guids_requested, "too many guids requested" },
{ nt_status_guids_exhausted, "guids exhausted" },
{ nt_status_invalid_id_authority, "invalid id authority" },
{ nt_status_agents_exhausted, "agents exhausted" },
{ nt_status_invalid_volume_label, "invalid volume label" },
{ nt_status_section_not_extended, "section not extended" },
{ nt_status_not_mapped_data, "not mapped data" },
{ nt_status_resource_data_not_found, "resource data not found" },
{ nt_status_resource_type_not_found, "resource type not found" },
{ nt_status_resource_name_not_found, "resource name not found" },
{ nt_status_array_bounds_exceeded, "array bounds exceeded" },
{ nt_status_float_denormal_operand, "float denormal operand" },
{ nt_status_float_divide_by_zero, "float divide by zero" },
{ nt_status_float_inexact_result, "float inexact result" },
{ nt_status_float_invalid_operation, "float invalid operation" },
{ nt_status_float_overflow, "float overflow" },
{ nt_status_float_stack_check, "float stack check" },
{ nt_status_float_underflow, "float underflow" },
{ nt_status_integer_divide_by_zero, "integer divide by zero" },
{ nt_status_integer_overflow, "integer overflow" },
{ nt_status_privileged_instruction, "privileged instruction" },
{ nt_status_too_many_paging_files, "too many paging files" },
{ nt_status_file_invalid, "file invalid" },
{ nt_status_allotted_space_exceeded, "allotted space exceeded" },
{ nt_status_insufficient_resources, "insufficient resources" },
{ nt_status_dfs_exit_path_found, "dfs exit path found" },
{ nt_status_device_data_error, "device data error" },
{ nt_status_device_not_connected, "device not connected" },
{ nt_status_device_power_failure, "device power failure" },
{ nt_status_free_vm_not_at_base, "free vm not at base" },
{ nt_status_memory_not_allocated, "memory not allocated" },
{ nt_status_working_set_quota, "working set quota" },
{ nt_status_media_write_protected, "media write protected" },
{ nt_status_device_not_ready, "device not ready" },
{ nt_status_invalid_group_attributes, "invalid group attributes" },
{ nt_status_bad_impersonation_level, "bad impersonation level" },
{ nt_status_cant_open_anonymous, "cant open anonymous" },
{ nt_status_bad_validation_class, "bad validation class" },
{ nt_status_bad_token_type, "bad token type" },
{ nt_status_bad_master_boot_record, "bad master boot record" },
{ nt_status_instruction_misalignment, "instruction misalignment" },
{ nt_status_instance_not_available, "instance not available" },
{ nt_status_pipe_not_available, "pipe not available" },
{ nt_status_invalid_pipe_state, "invalid pipe state" },
{ nt_status_pipe_busy, "pipe busy" },
{ nt_status_illegal_function, "illegal function" },
{ nt_status_pipe_disconnected, "pipe disconnected" },
{ nt_status_pipe_closing, "pipe closing" },
{ nt_status_pipe_connected, "pipe connected" },
{ nt_status_pipe_listening, "pipe listening" },
{ nt_status_invalid_read_mode, "invalid read mode" },
{ nt_status_io_timeout, "io timeout" },
{ nt_status_file_forced_closed, "file forced closed" },
{ nt_status_profiling_not_started, "profiling not started" },
{ nt_status_profiling_not_stopped, "profiling not stopped" },
{ nt_status_could_not_interpret, "could not interpret" },
{ nt_status_file_is_a_directory, "file is a directory" },
{ nt_status_not_supported, "not supported" },
{ nt_status_remote_not_listening, "remote not listening" },
{ nt_status_duplicate_name, "duplicate name" },
{ nt_status_bad_network_path, "bad network path" },
{ nt_status_network_busy, "network busy" },
{ nt_status_device_does_not_exist, "device does not exist" },
{ nt_status_too_many_commands, "too many commands" },
{ nt_status_adapter_hardware_error, "adapter hardware error" },
{ nt_status_invalid_network_response, "invalid network response" },
{ nt_status_unexpected_network_error, "unexpected network error" },
{ nt_status_bad_remote_adapter, "bad remote adapter" },
{ nt_status_print_queue_full, "print queue full" },
{ nt_status_no_spool_space, "no spool space" },
{ nt_status_print_cancelled, "print cancelled" },
{ nt_status_network_name_deleted, "network name deleted" },
{ nt_status_network_access_denied, "network access denied" },
{ nt_status_bad_device_type, "bad device type" },
{ nt_status_bad_network_name, "bad network name" },
{ nt_status_too_many_names, "too many names" },
{ nt_status_too_many_sessions, "too many sessions" },
{ nt_status_sharing_paused, "sharing paused" },
{ nt_status_request_not_accepted, "request not accepted" },
{ nt_status_redirector_paused, "redirector paused" },
{ nt_status_net_write_fault, "net write fault" },
{ nt_status_profiling_at_limit, "profiling at limit" },
{ nt_status_not_same_device, "not same device" },
{ nt_status_file_renamed, "file renamed" },
{ nt_status_virtual_circuit_closed, "virtual circuit closed" },
{ nt_status_no_security_on_object, "no security on object" },
{ nt_status_cant_wait, "cant wait" },
{ nt_status_pipe_empty, "pipe empty" },
{ nt_status_cant_access_domain_info, "cant access domain info" },
{ nt_status_cant_terminate_self, "cant terminate self" },
{ nt_status_invalid_server_state, "invalid server state" },
{ nt_status_invalid_domain_state, "invalid domain state" },
{ nt_status_invalid_domain_role, "invalid domain role" },
{ nt_status_no_such_domain, "no such domain" },
{ nt_status_domain_exists, "domain exists" },
{ nt_status_domain_limit_exceeded, "domain limit exceeded" },
{ nt_status_oplock_not_granted, "oplock not granted" },
{ nt_status_invalid_oplock_protocol, "invalid oplock protocol" },
{ nt_status_internal_db_corruption, "internal db corruption" },
{ nt_status_internal_error, "internal error" },
{ nt_status_generic_not_mapped, "generic not mapped" },
{ nt_status_bad_descriptor_format, "bad descriptor format" },
{ nt_status_invalid_user_buffer, "invalid user buffer" },
{ nt_status_unexpected_io_error, "unexpected io error" },
{ nt_status_unexpected_mm_create_err, "unexpected mm create err" },
{ nt_status_unexpected_mm_map_error, "unexpected mm map error" },
{ nt_status_unexpected_mm_extend_err, "unexpected mm extend err" },
{ nt_status_not_logon_process, "not logon process" },
{ nt_status_logon_session_exists, "logon session exists" },
{ nt_status_invalid_parameter_1, "invalid parameter 1" },
{ nt_status_invalid_parameter_2, "invalid parameter 2" },
{ nt_status_invalid_parameter_3, "invalid parameter 3" },
{ nt_status_invalid_parameter_4, "invalid parameter 4" },
{ nt_status_invalid_parameter_5, "invalid parameter 5" },
{ nt_status_invalid_parameter_6, "invalid parameter 6" },
{ nt_status_invalid_parameter_7, "invalid parameter 7" },
{ nt_status_invalid_parameter_8, "invalid parameter 8" },
{ nt_status_invalid_parameter_9, "invalid parameter 9" },
{ nt_status_invalid_parameter_10, "invalid parameter 10" },
{ nt_status_invalid_parameter_11, "invalid parameter 11" },
{ nt_status_invalid_parameter_12, "invalid parameter 12" },
{ nt_status_redirector_not_started, "redirector not started" },
{ nt_status_redirector_started, "redirector started" },
{ nt_status_stack_overflow, "stack overflow" },
{ nt_status_no_such_package, "no such package" },
{ nt_status_bad_function_table, "bad function table" },
{ nt_status_directory_not_empty, "directory not empty" },
{ nt_status_file_corrupt_error, "file corrupt error" },
{ nt_status_not_a_directory, "not a directory" },
{ nt_status_bad_logon_session_state, "bad logon session state" },
{ nt_status_logon_session_collision, "logon session collision" },
{ nt_status_name_too_long, "name too long" },
{ nt_status_files_open, "files open" },
{ nt_status_connection_in_use, "connection in use" },
{ nt_status_message_not_found, "message not found" },
{ nt_status_process_is_terminating, "process is terminating" },
{ nt_status_invalid_logon_type, "invalid logon type" },
{ nt_status_no_guid_translation, "no guid translation" },
{ nt_status_cannot_impersonate, "cannot impersonate" },
{ nt_status_image_already_loaded, "image already loaded" },
{ nt_status_abios_not_present, "abios not present" },
{ nt_status_abios_lid_not_exist, "abios lid not exist" },
{ nt_status_abios_lid_already_owned, "abios lid already owned" },
{ nt_status_abios_not_lid_owner, "abios not lid owner" },
{ nt_status_abios_invalid_command, "abios invalid command" },
{ nt_status_abios_invalid_lid, "abios invalid lid" },
{ nt_status_abios_selector_not_available, "abios selector not available" },
{ nt_status_abios_invalid_selector, "abios invalid selector" },
{ nt_status_no_ldt, "no ldt" },
{ nt_status_invalid_ldt_size, "invalid ldt size" },
{ nt_status_invalid_ldt_offset, "invalid ldt offset" },
{ nt_status_invalid_ldt_descriptor, "invalid ldt descriptor" },
{ nt_status_invalid_image_ne_format, "invalid image ne format" },
{ nt_status_rxact_invalid_state, "rxact invalid state" },
{ nt_status_rxact_commit_failure, "rxact commit failure" },
{ nt_status_mapped_file_size_zero, "mapped file size zero" },
{ nt_status_too_many_opened_files, "too many opened files" },
{ nt_status_cancelled, "cancelled" },
{ nt_status_cannot_delete, "cannot delete" },
{ nt_status_invalid_computer_name, "invalid computer name" },
{ nt_status_file_deleted, "file deleted" },
{ nt_status_special_account, "special account" },
{ nt_status_special_group, "special group" },
{ nt_status_special_user, "special user" },
{ nt_status_members_primary_group, "members primary group" },
{ nt_status_file_closed, "file closed" },
{ nt_status_too_many_threads, "too many threads" },
{ nt_status_thread_not_in_process, "thread not in process" },
{ nt_status_token_already_in_use, "token already in use" },
{ nt_status_pagefile_quota_exceeded, "pagefile quota exceeded" },
{ nt_status_commitment_limit, "commitment limit" },
{ nt_status_invalid_image_le_format, "invalid image le format" },
{ nt_status_invalid_image_not_mz, "invalid image not mz" },
{ nt_status_invalid_image_protect, "invalid image protect" },
{ nt_status_invalid_image_win_16, "invalid image win 16" },
{ nt_status_logon_server_conflict, "logon server conflict" },
{ nt_status_time_difference_at_dc, "time difference at dc" },
{ nt_status_synchronization_required, "synchronization required" },
{ nt_status_dll_not_found, "dll not found" },
{ nt_status_open_failed, "open failed" },
{ nt_status_io_privilege_failed, "io privilege failed" },
{ nt_status_ordinal_not_found, "ordinal not found" },
{ nt_status_entrypoint_not_found, "entrypoint not found" },
{ nt_status_control_c_exit, "control c exit" },
{ nt_status_local_disconnect, "local disconnect" },
{ nt_status_remote_disconnect, "remote disconnect" },
{ nt_status_remote_resources, "remote resources" },
{ nt_status_link_failed, "link failed" },
{ nt_status_link_timeout, "link timeout" },
{ nt_status_invalid_connection, "invalid connection" },
{ nt_status_invalid_address, "invalid address" },
{ nt_status_dll_init_failed, "dll init failed" },
{ nt_status_missing_systemfile, "missing systemfile" },
{ nt_status_unhandled_exception, "unhandled exception" },
{ nt_status_app_init_failure, "app init failure" },
{ nt_status_pagefile_create_failed, "pagefile create failed" },
{ nt_status_no_pagefile, "no pagefile" },
{ nt_status_invalid_level, "invalid level" },
{ nt_status_wrong_password_core, "wrong password core" },
{ nt_status_illegal_float_context, "illegal float context" },
{ nt_status_pipe_broken, "pipe broken" },
{ nt_status_registry_corrupt, "registry corrupt" },
{ nt_status_registry_io_failed, "registry io failed" },
{ nt_status_no_event_pair, "no event pair" },
{ nt_status_unrecognized_volume, "unrecognized volume" },
{ nt_status_serial_no_device_inited, "serial no device inited" },
{ nt_status_no_such_alias, "no such alias" },
{ nt_status_member_not_in_alias, "member not in alias" },
{ nt_status_member_in_alias, "member in alias" },
{ nt_status_alias_exists, "alias exists" },
{ nt_status_logon_not_granted, "logon not granted" },
{ nt_status_too_many_secrets, "too many secrets" },
{ nt_status_secret_too_long, "secret too long" },
{ nt_status_internal_db_error, "internal db error" },
{ nt_status_fullscreen_mode, "fullscreen mode" },
{ nt_status_too_many_context_ids, "too many context ids" },
{ nt_status_logon_type_not_granted, "logon type not granted" },
{ nt_status_not_registry_file, "not registry file" },
{ nt_status_nt_cross_encryption_required, "nt cross encryption required" },
{ nt_status_domain_ctrlr_config_error, "domain ctrlr config error" },
{ nt_status_ft_missing_member, "ft missing member" },
{ nt_status_ill_formed_service_entry, "ill formed service entry" },
{ nt_status_illegal_character, "illegal character" },
{ nt_status_unmappable_character, "unmappable character" },
{ nt_status_undefined_character, "undefined character" },
{ nt_status_floppy_volume, "floppy volume" },
{ nt_status_floppy_id_mark_not_found, "floppy id mark not found" },
{ nt_status_floppy_wrong_cylinder, "floppy wrong cylinder" },
{ nt_status_floppy_unknown_error, "floppy unknown error" },
{ nt_status_floppy_bad_registers, "floppy bad registers" },
{ nt_status_disk_recalibrate_failed, "disk recalibrate failed" },
{ nt_status_disk_operation_failed, "disk operation failed" },
{ nt_status_disk_reset_failed, "disk reset failed" },
{ nt_status_shared_irq_busy, "shared irq busy" },
{ nt_status_ft_orphaning, "ft orphaning" },
{ nt_status_partition_failure, "partition failure" },
{ nt_status_invalid_block_length, "invalid block length" },
{ nt_status_device_not_partitioned, "device not partitioned" },
{ nt_status_unable_to_lock_media, "unable to lock media" },
{ nt_status_unable_to_unload_media, "unable to unload media" },
{ nt_status_eom_overflow, "eom overflow" },
{ nt_status_no_media, "no media" },
{ nt_status_no_such_member, "no such member" },
{ nt_status_invalid_member, "invalid member" },
{ nt_status_key_deleted, "key deleted" },
{ nt_status_no_log_space, "no log space" },
{ nt_status_too_many_sids, "too many sids" },
{ nt_status_lm_cross_encryption_required, "lm cross encryption required" },
{ nt_status_key_has_children, "key has children" },
{ nt_status_child_must_be_volatile, "child must be volatile" },
{ nt_status_device_configuration_error, "device configuration error" },
{ nt_status_driver_internal_error, "driver internal error" },
{ nt_status_invalid_device_state, "invalid device state" },
{ nt_status_io_device_error, "io device error" },
{ nt_status_device_protocol_error, "device protocol error" },
{ nt_status_backup_controller, "backup controller" },
{ nt_status_log_file_full, "log file full" },
{ nt_status_too_late, "too late" },
{ nt_status_no_trust_lsa_secret, "no trust lsa secret" },
{ nt_status_no_trust_sam_account, "no trust sam account" },
{ nt_status_trusted_domain_failure, "trusted domain failure" },
{ nt_status_trusted_relationship_failure, "trusted relationship failure" },
{ nt_status_eventlog_file_corrupt, "eventlog file corrupt" },
{ nt_status_eventlog_cant_start, "eventlog cant start" },
{ nt_status_trust_failure, "trust failure" },
{ nt_status_mutant_limit_exceeded, "mutant limit exceeded" },
{ nt_status_netlogon_not_started, "netlogon not started" },
{ nt_status_account_expired, "account expired" },
{ nt_status_possible_deadlock, "possible deadlock" },
{ nt_status_network_credential_conflict, "network credential conflict" },
{ nt_status_remote_session_limit, "remote session limit" },
{ nt_status_eventlog_file_changed, "eventlog file changed" },
{ nt_status_nologon_interdomain_trust_account, "nologon interdomain trust account" },
{ nt_status_nologon_workstation_trust_account, "nologon workstation trust account" },
{ nt_status_nologon_server_trust_account, "nologon server trust account" },
{ nt_status_domain_trust_inconsistent, "domain trust inconsistent" },
{ nt_status_fs_driver_required, "fs driver required" },
{ nt_status_no_user_session_key, "no user session key" },
{ nt_status_user_session_deleted, "user session deleted" },
{ nt_status_resource_lang_not_found, "resource lang not found" },
{ nt_status_insuff_server_resources, "insuff server resources" },
{ nt_status_invalid_buffer_size, "invalid buffer size" },
{ nt_status_invalid_address_component, "invalid address component" },
{ nt_status_invalid_address_wildcard, "invalid address wildcard" },
{ nt_status_too_many_addresses, "too many addresses" },
{ nt_status_address_already_exists, "address already exists" },
{ nt_status_address_closed, "address closed" },
{ nt_status_connection_disconnected, "connection disconnected" },
{ nt_status_connection_reset, "connection reset" },
{ nt_status_too_many_nodes, "too many nodes" },
{ nt_status_transaction_aborted, "transaction aborted" },
{ nt_status_transaction_timed_out, "transaction timed out" },
{ nt_status_transaction_no_release, "transaction no release" },
{ nt_status_transaction_no_match, "transaction no match" },
{ nt_status_transaction_responded, "transaction responded" },
{ nt_status_transaction_invalid_id, "transaction invalid id" },
{ nt_status_transaction_invalid_type, "transaction invalid type" },
{ nt_status_not_server_session, "not server session" },
{ nt_status_not_client_session, "not client session" },
{ nt_status_cannot_load_registry_file, "cannot load registry file" },
{ nt_status_debug_attach_failed, "debug attach failed" },
{ nt_status_system_process_terminated, "system process terminated" },
{ nt_status_data_not_accepted, "data not accepted" },
{ nt_status_no_browser_servers_found, "no browser servers found" },
{ nt_status_vdm_hard_error, "vdm hard error" },
{ nt_status_driver_cancel_timeout, "driver cancel timeout" },
{ nt_status_reply_message_mismatch, "reply message mismatch" },
{ nt_status_mapped_alignment, "mapped alignment" },
{ nt_status_image_checksum_mismatch, "image checksum mismatch" },
{ nt_status_lost_writebehind_data, "lost writebehind data" },
{ nt_status_client_server_parameters_invalid, "client server parameters invalid" },
{ nt_status_password_must_change, "password must change" },
{ nt_status_not_found, "not found" },
{ nt_status_not_tiny_stream, "not tiny stream" },
{ nt_status_recovery_failure, "recovery failure" },
{ nt_status_stack_overflow_read, "stack overflow read" },
{ nt_status_fail_check, "fail check" },
{ nt_status_duplicate_objectid, "duplicate objectid" },
{ nt_status_objectid_exists, "objectid exists" },
{ nt_status_convert_to_large, "convert to large" },
{ nt_status_retry, "retry" },
{ nt_status_found_out_of_scope, "found out of scope" },
{ nt_status_allocate_bucket, "allocate bucket" },
{ nt_status_propset_not_found, "propset not found" },
{ nt_status_marshall_overflow, "marshall overflow" },
{ nt_status_invalid_variant, "invalid variant" },
{ nt_status_domain_controller_not_found, "domain controller not found" },
{ nt_status_account_locked_out, "account locked out" },
{ nt_status_handle_not_closable, "handle not closable" },
{ nt_status_connection_refused, "connection refused" },
{ nt_status_graceful_disconnect, "graceful disconnect" },
{ nt_status_address_already_associated, "address already associated" },
{ nt_status_address_not_associated, "address not associated" },
{ nt_status_connection_invalid, "connection invalid" },
{ nt_status_connection_active, "connection active" },
{ nt_status_network_unreachable, "network unreachable" },
{ nt_status_host_unreachable, "host unreachable" },
{ nt_status_protocol_unreachable, "protocol unreachable" },
{ nt_status_port_unreachable, "port unreachable" },
{ nt_status_request_aborted, "request aborted" },
{ nt_status_connection_aborted, "connection aborted" },
{ nt_status_bad_compression_buffer, "bad compression buffer" },
{ nt_status_user_mapped_file, "user mapped file" },
{ nt_status_audit_failed, "audit failed" },
{ nt_status_timer_resolution_not_set, "timer resolution not set" },
{ nt_status_connection_count_limit, "connection count limit" },
{ nt_status_login_time_restriction, "login time restriction" },
{ nt_status_login_wksta_restriction, "login wksta restriction" },
{ nt_status_image_mp_up_mismatch, "image mp up mismatch" },
{ nt_status_insufficient_logon_info, "insufficient logon info" },
{ nt_status_bad_dll_entrypoint, "bad dll entrypoint" },
{ nt_status_bad_service_entrypoint, "bad service entrypoint" },
{ nt_status_lpc_reply_lost, "lpc reply lost" },
{ nt_status_ip_address_conflict1, "ip address conflict1" },
{ nt_status_ip_address_conflict2, "ip address conflict2" },
{ nt_status_registry_quota_limit, "registry quota limit" },
{ nt_status_path_not_covered, "path not covered" },
{ nt_status_no_callback_active, "no callback active" },
{ nt_status_license_quota_exceeded, "license quota exceeded" },
{ nt_status_pwd_too_short, "pwd too short" },
{ nt_status_pwd_too_recent, "pwd too recent" },
{ nt_status_pwd_history_conflict, "pwd history conflict" },
{ nt_status_plugplay_no_device, "plugplay no device" },
{ nt_status_unsupported_compression, "unsupported compression" },
{ nt_status_invalid_hw_profile, "invalid hw profile" },
{ nt_status_invalid_plugplay_device_path, "invalid plugplay device path" },
{ nt_status_driver_ordinal_not_found, "driver ordinal not found" },
{ nt_status_driver_entrypoint_not_found, "driver entrypoint not found" },
{ nt_status_resource_not_owned, "resource not owned" },
{ nt_status_too_many_links, "too many links" },
{ nt_status_quota_list_inconsistent, "quota list inconsistent" },
{ nt_status_file_is_offline, "file is offline" },
//{ nt_status_notify_enum_dir, "notify enum dir" },
{ -1, NULL }
};
const char * command_name;
struct line_buffer lb;
if(smb_packet_source == smb_packet_from_consumer)
FPrintf(dump_smb_file,"message type = Request (client --> server)\n");
else
FPrintf(dump_smb_file,"message type = Response (server --> client)\n");
if(header->flags2 & SMB_FLAGS2_32BIT_STATUS)
{
int severity,facility,error_code;
const char * error_code_name = "?";
int i;
severity = (header->status >> 30) & 1;
facility = (header->status >> 16) & 0x0fff;
error_code = header->status & 0xffff;
for(i = 0 ; nt_error_codes[i].code != -1 ; i++)
{
if(nt_error_codes[i].code == error_code)
{
error_code_name = nt_error_codes[i].label;
break;
}
}
FPrintf(dump_smb_file,"status = [%08lx] severity:%s, facility:%s (%ld), code:%s (%ld)\n",header->status,
severity ? "failure" : "success",facility ? "?" : "default",facility,error_code_name,error_code);
}
else
{
const char * error_class_name;
int error_class_value;
const char * error_code_name = "?";
int error_code_value;
int i;
error_class_value = header->status & 0xff;
error_code_value = (header->status >> 16) & 0xffff;
switch(error_class_value)
{
case 0:
error_class_name = "success";
error_code_name = "no error";
break;
case 1:
error_class_name = "DOS error";
for(i = 0 ; dos_errors[i].code != -1 ; i++)
{
if(dos_errors[i].code == error_code_value)
{
error_code_name = dos_errors[i].label;
break;
}
}
break;
case 2:
error_class_name = "server error";
for(i = 0 ; server_errors[i].code != -1 ; i++)
{
if(server_errors[i].code == error_code_value)
{
error_code_name = server_errors[i].label;
break;
}
}
break;
case 3:
error_class_name = "hardware error";
for(i = 0 ; hardware_errors[i].code != -1 ; i++)
{
if(hardware_errors[i].code == error_code_value)
{
error_code_name = hardware_errors[i].label;
break;
}
}
break;
default:
error_class_name = "Command error";
break;
}
FPrintf(dump_smb_file,"status = [%08lx] error:%s (%ld), code:%s (%ld)\n",header->status,
error_class_name,error_class_value,
error_code_name,error_code_value);
}
FPrintf(dump_smb_file,"flags = ");
init_line_buffer(&lb);
if(header->flags & SMB_FLAGS_SERVER_TO_REDIR)
add_lb_flag(&lb,"type=reply");
else
add_lb_flag(&lb,"type=request");
if(header->flags & SMB_FLAGS_REQUEST_BATCH_OPLOCK)
add_lb_flag(&lb,"request-batch-oplock=batch");
else
add_lb_flag(&lb,"request-batch-oplock=exclusive");
if(header->flags & SMB_FLAGS_REQUEST_OPLOCK)
add_lb_flag(&lb,"request-oplock=yes");
else
add_lb_flag(&lb,"request-oplock=no");
if(header->flags & SMB_FLAGS_CANONICAL_PATHNAMES)
add_lb_flag(&lb,"canonical-pathnames=canonical");
else
add_lb_flag(&lb,"canonical-pathnames=host format");
if(header->flags & SMB_FLAGS_CASELESS_PATHNAMES)
add_lb_flag(&lb,"caseless-pathnames=yes");
else
add_lb_flag(&lb,"caseless-pathnames=no");
if(header->flags & SMB_FLAGS_CLIENT_BUF_AVAIL)
add_lb_flag(&lb,"client-buf-avail=yes");
else
add_lb_flag(&lb,"client-buf-avail=no");
if(header->flags & SMB_FLAGS_SUPPORT_LOCKREAD)
add_lb_flag(&lb,"support-lockread=yes");
else
add_lb_flag(&lb,"support-lockread=no");
FPrintf(dump_smb_file,"%s\n",lb.line);
FPrintf(dump_smb_file,"flags2 = ");
init_line_buffer(&lb);
if(header->flags2 & SMB_FLAGS2_UNICODE_STRINGS)
add_lb_flag(&lb,"string-format=Unicode");
else
add_lb_flag(&lb,"string-format=ASCII");
if(header->flags2 & SMB_FLAGS2_32BIT_STATUS)
add_lb_flag(&lb,"status-code=NT_STATUS format");
else
add_lb_flag(&lb,"status-code=DOS error format");
if(header->flags2 & SMB_FLAGS2_READ_IF_EXECUTE)
add_lb_flag(&lb,"read-if-execute=yes");
else
add_lb_flag(&lb,"read-if-execute=no");
if(header->flags2 & SMB_FLAGS2_DFS_PATHNAME)
add_lb_flag(&lb,"pathname=DFS");
else
add_lb_flag(&lb,"pathname=normal");
if(header->flags2 & SMB_FLAGS2_EXTENDED_SECURITY)
add_lb_flag(&lb,"security=extended");
else
add_lb_flag(&lb,"security=normal");
if(header->flags2 & SMB_FLAGS2_IS_LONG_NAME)
add_lb_flag(&lb,"name-format=long");
else
add_lb_flag(&lb,"name-format=8.3");
if(header->flags2 & SMB_FLAGS2_SECURITY_SIGNATURE)
add_lb_flag(&lb,"security-signature=MAC");
else
add_lb_flag(&lb,"security-signature=none");
if(header->flags2 & SMB_FLAGS2_EAS)
add_lb_flag(&lb,"extended-attributes=yes");
else
add_lb_flag(&lb,"extended-attributes=no");
if(header->flags2 & SMB_FLAGS2_KNOWS_LONG_NAMES)
add_lb_flag(&lb,"client-names-supported=long");
else
add_lb_flag(&lb,"client-names-supported=8.3");
FPrintf(dump_smb_file,"%s\n",lb.line);
FPrintf(dump_smb_file,"signature = %04lx%04lx%04lx%04lx\n",header->extra.signature[0],header->extra.signature[1],
header->extra.signature[2],header->extra.signature[3]);
FPrintf(dump_smb_file,"tid = %04lx\n",header->tid);
FPrintf(dump_smb_file,"pid = %04lx\n",header->pid);
FPrintf(dump_smb_file,"uid = %04lx\n",header->uid);
FPrintf(dump_smb_file,"mid = %04lx\n",header->mid);
FPrintf(dump_smb_file,"length = %ld (packet size:%ld, buffer size:%ld)\n",header_length,packet_size,max_buffer_size);
if(is_smb_andx_command(header->command))
{
const unsigned char * andx_header = (const unsigned char *)header->parameters;
int offset = (((int)andx_header[3]) << 8) + andx_header[2];
int num_parameter_words,num_data_bytes;
command_name = get_smb_command_name(header->command);
if(command_name != NULL)
FPrintf(dump_smb_file,"command = %s (ANDX)\n",command_name);
else
FPrintf(dump_smb_file,"command = 0x%02lx (ANDX)\n",header->command);
FPrintf(dump_smb_file,"parameter words = %ld\n",header->num_parameter_words - 2);
if(header->num_parameter_words - 2 > 0)
print_smb_parameters(header->num_parameter_words - 2,&header->parameters[4]);
FPrintf(dump_smb_file,"data bytes = %ld\n",header->num_data_bytes);
/* If there are any data bytes, print them like "type hex .." would. */
if(dump_smb_level > 0 && header->num_data_bytes > 0)
print_smb_data(&lb,header->num_data_bytes,header->data);
print_smb_contents(header, header->command, smb_packet_source, header->num_parameter_words - 2,
&header->parameters[4], header->num_data_bytes, header->data);
while(andx_header[0] != 0xff && offset > 0 && offset < packet_size)
{
andx_header = &packet[offset];
num_parameter_words = (*andx_header++);
command_name = get_smb_command_name(andx_header[0]);
if(command_name != NULL)
FPrintf(dump_smb_file,"command = %s (ANDX)\n",command_name);
else
FPrintf(dump_smb_file,"command = 0x%02lx (ANDX)\n",header->command);
FPrintf(dump_smb_file,"andx_offset = 0x%02lx\n",(((int)andx_header[3]) << 8) + andx_header[2]);
FPrintf(dump_smb_file,"parameter words = %ld\n",num_parameter_words);
if(num_parameter_words > 0)
print_smb_parameters(num_parameter_words,&andx_header[4]);
num_data_bytes = andx_header[4 + num_parameter_words * 2] + (((int)andx_header[4 + num_parameter_words * 2 + 1]) << 8);
FPrintf(dump_smb_file,"data bytes = %ld\n",num_data_bytes);
if(dump_smb_level > 0 && num_data_bytes > 0)
print_smb_data(&lb,num_data_bytes,&andx_header[4 + num_parameter_words * 2 + 2]);
print_smb_contents(header, andx_header[0], smb_packet_source, num_parameter_words, &andx_header[4],
num_data_bytes, &andx_header[4 + num_parameter_words * 2 + 2]);
offset = (((int)andx_header[3]) << 8) + andx_header[2];
}
}
else
{
command_name = get_smb_command_name(header->command);
if(command_name != NULL)
FPrintf(dump_smb_file,"command = %s\n",command_name);
else
FPrintf(dump_smb_file,"command = 0x%02lx\n",header->command);
FPrintf(dump_smb_file,"parameter words = %ld\n",header->num_parameter_words);
if(header->num_parameter_words > 0)
print_smb_parameters(header->num_parameter_words,(unsigned char *)header->parameters);
FPrintf(dump_smb_file,"data bytes = %ld\n",header->num_data_bytes);
/* If there are any data bytes, print them like "type hex .." would. */
if(dump_smb_level > 0 && header->num_data_bytes > 0)
print_smb_data(&lb,header->num_data_bytes,header->data);
print_smb_contents(header, header->command, smb_packet_source, header->num_parameter_words, header->parameters,
header->num_data_bytes, header->data);
}
}
/*****************************************************************************/
void
dump_netbios_header(const char *file_name,int line_number,const unsigned char *netbios_session_header,
const unsigned char *netbios_payload,int netbios_payload_size)
{
if(dump_smb_enabled)
{
unsigned char session_type = netbios_session_header[0];
unsigned char session_flags = netbios_session_header[1] & 0xfe;
unsigned long session_length =
((netbios_session_header[1] & 1) ? 0x10000 : 0) |
(((unsigned long)netbios_session_header[2]) << 8) |
netbios_session_header[3];
const char * session_type_label;
switch(session_type)
{
case 0x00:
session_type_label = "session message";
break;
case 0x81:
session_type_label = "session request";
break;
case 0x82:
session_type_label = "positive session response";
break;
case 0x83:
session_type_label = "negative session response";
break;
case 0x84:
session_type_label = "retarget session response";
break;
case 0x85:
session_type_label = "session keep alive";
break;
default:
session_type_label = "?";
break;
}
FPrintf(dump_smb_file,"---\n");
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
FPrintf(dump_smb_file,"netbios session type=%s (0x%02lx), flags=0x%02lx, length=%ld\n",
session_type_label,session_type,session_flags,session_length);
if (session_type == 0x83 && netbios_payload != NULL && netbios_payload_size > 0)
{
int error_code = *netbios_payload;
FPrintf(dump_smb_file,"error code = 0x%02lx\n",error_code);
switch(error_code)
{
case 0x80:
FPrintf(dump_smb_file," Not listening on called name\n");
break;
case 0x81:
FPrintf(dump_smb_file," Not listening for calling name\n");
break;
case 0x82:
FPrintf(dump_smb_file," Called name not present\n");
break;
case 0x83:
FPrintf(dump_smb_file," Insufficient resources\n");
break;
case 0x8f:
FPrintf(dump_smb_file," Unspecific error\n");
break;
}
}
else if (session_type != 0x00 && netbios_payload != NULL && netbios_payload_size > 0)
{
struct line_buffer lb;
FPrintf(dump_smb_file,"session data (%ld bytes) =\n",netbios_payload_size);
print_smb_data(&lb,netbios_payload_size,netbios_payload);
}
}
}
/*****************************************************************************/
void
dump_smb(const char *file_name,int line_number,int is_raw_data,
const void * packet,int length,enum smb_packet_source_t smb_packet_source,
int max_buffer_size)
{
if(dump_smb_enabled)
{
if(is_raw_data)
{
if(dump_smb_level > 1)
{
struct line_buffer lb;
FPrintf(dump_smb_file,"---\n");
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",length);
print_smb_data(&lb,length,packet);
FPrintf(dump_smb_file,"---\n\n");
}
}
else
{
if(length > 4 && memcmp(packet,"\xffSMB",4) == SAME)
{
struct smb_header header;
int num_bytes_read;
num_bytes_read = fill_header(packet,length,&header);
if(num_bytes_read <= length)
{
FPrintf(dump_smb_file,"---\n");
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
print_smb_header(&header,num_bytes_read,packet,length,
smb_packet_source,max_buffer_size);
FPrintf(dump_smb_file,"---\n\n");
}
}
}
}
}
/*****************************************************************************/
void
control_smb_dump(int enable,int level,const char * file_name)
{
/* Close the output file if necessary. */
if(!enable && !dump_smb_stdout && dump_smb_file != (BPTR)NULL)
Close(dump_smb_file);
dump_smb_file = (BPTR)NULL;
dump_smb_enabled = enable;
dump_smb_level = level;
if(enable)
{
dump_smb_stdout = TRUE;
/* Write the output to a file? */
if(file_name != NULL)
{
/* Try to append the output to an existing file. */
dump_smb_file = Open(file_name,MODE_OLDFILE);
if(dump_smb_file == (BPTR)NULL)
{
/* File does not exist? Then create a new file. */
if(IoErr() == ERROR_OBJECT_NOT_FOUND)
{
dump_smb_file = Open(file_name,MODE_NEWFILE);
if(dump_smb_file != (BPTR)NULL)
ChangeMode(CHANGE_FH,dump_smb_file,SHARED_LOCK);
}
}
else
{
/* File exists; seek to the end of it. */
Seek(dump_smb_file,0,OFFSET_END);
}
/* If a file was created or opened for appending
* output to it, make sure it will get closed
* eventually.
*/
if(dump_smb_file != (BPTR)NULL)
dump_smb_stdout = FALSE;
}
/* No file was opened: output to STDOUT. */
if(dump_smb_file == (BPTR)NULL)
dump_smb_file = Output();
}
}
/*****************************************************************************/
#endif /* DUMP_SMB */