mirror of
https://github.com/obarthel/amiga-smbfs.git
synced 2025-12-08 14:58:35 +00:00
Please keep in mind that this is still a development version and might surprise you (not necessarily in a good way). Do not let me discourage you to build and test this version, although there will be some risks involved such as data corruption or loss of data.
4539 lines
150 KiB
C
4539 lines
150 KiB
C
/*
|
|
* :ts=4
|
|
*
|
|
* dump_smb.c
|
|
*
|
|
* Copyright (C) 2016-2018 by Olaf `Olsen' Barthel <obarthel -at- gmx -dot- net>
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, write to the Free Software
|
|
* Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
|
*/
|
|
|
|
#if defined(DUMP_SMB)
|
|
|
|
/*****************************************************************************/
|
|
|
|
#include "smbfs.h"
|
|
|
|
/*****************************************************************************/
|
|
|
|
#include "dump_smb.h"
|
|
#include "quad_math.h"
|
|
|
|
/*****************************************************************************/
|
|
|
|
/* The following is an attempt to decode the data that is received
|
|
* and sent. Because so much of smbfs was created by reverse-engineering
|
|
* the protocol it is difficult to say what works, and how.
|
|
*/
|
|
|
|
/*****************************************************************************/
|
|
|
|
extern VOID VARARGS68K SPrintf(STRPTR buffer, STRPTR formatString,...);
|
|
|
|
/*****************************************************************************/
|
|
|
|
/* This can be used to enable or disable the SMB packet dump output. */
|
|
static int dump_smb_enabled;
|
|
|
|
/* This is for controlling how much output is produced. Higher
|
|
* numbers yield more output.
|
|
*/
|
|
static int dump_smb_level;
|
|
|
|
/* This is where the output should go. It could be a file. */
|
|
static BPTR dump_smb_file;
|
|
static BOOL dump_smb_stdout;
|
|
|
|
/*****************************************************************************/
|
|
|
|
/* This keeps track of which SMB_COM_TRANSACTION2 subcommand was last
|
|
* sent to the server. The server will respond to it, but the message does
|
|
* not contain the subcommand code of the request which started it.
|
|
*/
|
|
static int last_smb_com_transaction_subcommand = -1;
|
|
|
|
/* This keeps track of the information level specified when directory
|
|
* contents were to be retrieved by the TRANS2_FIND_FIRST2 command.
|
|
* The data will be returned, but it's not repeated in the
|
|
* server response message.
|
|
*/
|
|
static int last_trans2_find_information_level = -1;
|
|
|
|
/*****************************************************************************/
|
|
|
|
static unsigned long next_data_dword(const unsigned char * data,int * offset_ptr)
|
|
{
|
|
int offset = (*offset_ptr);
|
|
unsigned long result;
|
|
|
|
result =
|
|
(((unsigned long)data[offset + 3]) << 24) |
|
|
(((unsigned long)data[offset + 2]) << 16) |
|
|
(((unsigned long)data[offset + 1]) << 8) |
|
|
(unsigned long)data[offset + 0];
|
|
|
|
(*offset_ptr) = offset + 4;
|
|
|
|
return(result);
|
|
}
|
|
|
|
static void next_data_qword(const unsigned char * data,unsigned long *qwords,int * offset_ptr)
|
|
{
|
|
qwords[1] = next_data_dword(data,offset_ptr);
|
|
qwords[0] = next_data_dword(data,offset_ptr);
|
|
}
|
|
|
|
static unsigned short next_data_word(const unsigned char * data,int * offset_ptr)
|
|
{
|
|
int offset = (*offset_ptr);
|
|
unsigned short result;
|
|
|
|
result =
|
|
(((unsigned short)data[offset+1]) << 8) |
|
|
(unsigned short)data[offset+0];
|
|
|
|
(*offset_ptr) = offset + 2;
|
|
|
|
return(result);
|
|
}
|
|
|
|
static unsigned char next_data_byte(const unsigned char * data,int * offset_ptr)
|
|
{
|
|
int offset = (*offset_ptr);
|
|
unsigned char result;
|
|
|
|
result = data[offset];
|
|
|
|
(*offset_ptr) = offset + 1;
|
|
|
|
return(result);
|
|
}
|
|
|
|
static const unsigned char * next_data_bytes(const unsigned char * data,int num_bytes,int * offset_ptr)
|
|
{
|
|
int offset = (*offset_ptr);
|
|
const unsigned char * result;
|
|
|
|
result = &data[offset];
|
|
|
|
(*offset_ptr) = offset + num_bytes;
|
|
|
|
return(result);
|
|
}
|
|
|
|
static const unsigned char * next_data_words(const unsigned char * data,int num_words,int * offset_ptr)
|
|
{
|
|
return(next_data_bytes(data,2 * num_words,offset_ptr));
|
|
}
|
|
|
|
static void skip_data_bytes(const unsigned char * data,int num_bytes,int * offset_ptr)
|
|
{
|
|
(*offset_ptr) = (*offset_ptr) + num_bytes;
|
|
}
|
|
|
|
static void skip_data_words(const unsigned char * data,int num_words,int * offset_ptr)
|
|
{
|
|
skip_data_bytes(data,2 * num_words,offset_ptr);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static int
|
|
fill_header(const unsigned char * packet,int length,struct smb_header * header)
|
|
{
|
|
int num_bytes_read;
|
|
int offset = 0;
|
|
|
|
memset(header,0,sizeof(header));
|
|
|
|
header->raw_packet_size = length;
|
|
header->raw_packet = (char *)packet;
|
|
|
|
memmove(header->signature,next_data_bytes(packet,4,&offset),4);
|
|
header->command = next_data_byte(packet,&offset);
|
|
header->status = next_data_dword(packet,&offset);
|
|
header->flags = next_data_byte(packet,&offset);
|
|
header->flags2 = next_data_word(packet,&offset);
|
|
header->extra.pid_high = next_data_word(packet,&offset);
|
|
memmove(header->extra.signature,next_data_words(packet,4,&offset),sizeof(unsigned short) * 4);
|
|
skip_data_words(packet,1,&offset);
|
|
header->tid = next_data_word(packet,&offset);
|
|
header->pid = next_data_word(packet,&offset);
|
|
header->uid = next_data_word(packet,&offset);
|
|
header->mid = next_data_word(packet,&offset);
|
|
|
|
header->num_parameter_words = next_data_byte(packet,&offset);
|
|
header->parameter_offset = offset;
|
|
header->parameters = (unsigned char *)next_data_words(packet,header->num_parameter_words,&offset);
|
|
|
|
header->num_data_bytes = next_data_word(packet,&offset);
|
|
header->data_offset = offset;
|
|
header->data = (unsigned char *)next_data_bytes(packet,header->num_data_bytes,&offset);
|
|
|
|
num_bytes_read = offset;
|
|
|
|
return(num_bytes_read);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static int
|
|
is_smb_andx_command(unsigned char command)
|
|
{
|
|
static const unsigned char andx_commands[9] =
|
|
{
|
|
SMB_COM_LOCKING_ANDX,
|
|
SMB_COM_OPEN_ANDX,
|
|
SMB_COM_READ_ANDX,
|
|
SMB_COM_WRITE_ANDX,
|
|
SMB_COM_SESSION_SETUP_ANDX,
|
|
SMB_COM_LOGOFF_ANDX,
|
|
SMB_COM_TREE_CONNECT_ANDX,
|
|
SMB_COM_SECURITY_PACKAGE_ANDX,
|
|
SMB_COM_NT_CREATE_ANDX
|
|
};
|
|
|
|
int result = 0;
|
|
int i;
|
|
|
|
for(i = 0 ; i < 9 ; i++)
|
|
{
|
|
if(command == andx_commands[i])
|
|
{
|
|
result = 1;
|
|
break;
|
|
}
|
|
}
|
|
|
|
return(result);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
get_smb_transaction2_subcommand_name(int command)
|
|
{
|
|
static const struct { int code ; const char * name; } code_name_tab[] =
|
|
{
|
|
{ TRANS2_OPEN2, "TRANS2_OPEN2" },
|
|
{ TRANS2_FIND_FIRST2, "TRANS2_FIND_FIRST2" },
|
|
{ TRANS2_FIND_NEXT2, "TRANS2_FIND_NEXT2" },
|
|
{ TRANS2_QUERY_FS_INFORMATION, "TRANS2_QUERY_FS_INFORMATION" },
|
|
{ TRANS2_QUERY_PATH_INFORMATION, "TRANS2_QUERY_PATH_INFORMATION" },
|
|
{ TRANS2_SET_PATH_INFORMATION, "TRANS2_SET_PATH_INFORMATION" },
|
|
{ TRANS2_QUERY_FILE_INFORMATION, "TRANS2_QUERY_FILE_INFORMATION" },
|
|
{ TRANS2_SET_FILE_INFORMATION, "TRANS2_SET_FILE_INFORMATION" },
|
|
{ TRANS2_FSCTL, "TRANS2_FSCTL" },
|
|
{ TRANS2_IOCTL2, "TRANS2_IOCTL2" },
|
|
{ TRANS2_FIND_NOTIFY_FIRST, "TRANS2_FIND_NOTIFY_FIRST" },
|
|
{ TRANS2_FIND_NOTIFY_NEXT, "TRANS2_FIND_NOTIFY_NEXT" },
|
|
{ TRANS2_CREATE_DIRECTORY, "TRANS2_CREATE_DIRECTORY" },
|
|
{ TRANS2_SESSION_SETUP, "TRANS2_SESSION_SETUP" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
const char * result = NULL;
|
|
int i;
|
|
|
|
for(i = 0 ; code_name_tab[i].code != -1 ; i++)
|
|
{
|
|
if(command == code_name_tab[i].code)
|
|
{
|
|
result = code_name_tab[i].name;
|
|
break;
|
|
}
|
|
}
|
|
|
|
return(result);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
get_smb_command_name(unsigned char command)
|
|
{
|
|
static const struct { int code; const char * name; } code_name_tab[] =
|
|
{
|
|
{ SMB_COM_CREATE_DIRECTORY, "CREATE_DIRECTORY" },
|
|
{ SMB_COM_DELETE_DIRECTORY, "DELETE_DIRECTORY" },
|
|
{ SMB_COM_OPEN, "OPEN" },
|
|
{ SMB_COM_CREATE, "CREATE" },
|
|
{ SMB_COM_CLOSE, "CLOSE" },
|
|
{ SMB_COM_FLUSH, "FLUSH" },
|
|
{ SMB_COM_DELETE, "DELETE" },
|
|
{ SMB_COM_RENAME, "RENAME" },
|
|
{ SMB_COM_QUERY_INFORMATION, "QUERY_INFORMATION" },
|
|
{ SMB_COM_SET_INFORMATION, "SET_INFORMATION" },
|
|
{ SMB_COM_READ, "READ" },
|
|
{ SMB_COM_WRITE, "WRITE" },
|
|
{ SMB_COM_LOCK_BYTE_RANGE, "LOCK_BYTE_RANGE" },
|
|
{ SMB_COM_UNLOCK_BYTE_RANGE, "UNLOCK_BYTE_RANGE" },
|
|
{ SMB_COM_CREATE_TEMPORARY, "CREATE_TEMPORARY" },
|
|
{ SMB_COM_CREATE_NEW, "CREATE_NEW" },
|
|
{ SMB_COM_CHECK_DIRECTORY, "CHECK_DIRECTORY" },
|
|
{ SMB_COM_PROCESS_EXIT, "PROCESS_EXIT" },
|
|
{ SMB_COM_SEEK, "SEEK" },
|
|
{ SMB_COM_LOCK_AND_READ, "LOCK_AND_READ" },
|
|
{ SMB_COM_WRITE_AND_UNLOCK, "WRITE_AND_UNLOCK" },
|
|
{ SMB_COM_READ_RAW, "READ_RAW" },
|
|
{ SMB_COM_READ_MPX, "READ_MPX" },
|
|
{ SMB_COM_READ_MPX_SECONDARY, "READ_MPX_SECONDARY" },
|
|
{ SMB_COM_WRITE_RAW, "WRITE_RAW" },
|
|
{ SMB_COM_WRITE_MPX, "WRITE_MPX" },
|
|
{ SMB_COM_WRITE_MPX_SECONDARY, "WRITE_MPX_SECONDARY" },
|
|
{ SMB_COM_WRITE_COMPLETE, "WRITE_COMPLETE" },
|
|
{ SMB_COM_QUERY_SERVER, "QUERY_SERVER" },
|
|
{ SMB_COM_SET_INFORMATION2, "SET_INFORMATION2" },
|
|
{ SMB_COM_QUERY_INFORMATION2, "QUERY_INFORMATION2" },
|
|
{ SMB_COM_LOCKING_ANDX, "LOCKING_ANDX" },
|
|
{ SMB_COM_TRANSACTION, "TRANSACTION" },
|
|
{ SMB_COM_TRANSACTION_SECONDARY, "TRANSACTION_SECONDARY" },
|
|
{ SMB_COM_IOCTL, "IOCTL" },
|
|
{ SMB_COM_IOCTL_SECONDARY, "IOCTL_SECONDARY" },
|
|
{ SMB_COM_COPY, "COPY" },
|
|
{ SMB_COM_MOVE, "MOVE" },
|
|
{ SMB_COM_ECHO, "ECHO" },
|
|
{ SMB_COM_WRITE_AND_CLOSE, "WRITE_AND_CLOSE" },
|
|
{ SMB_COM_OPEN_ANDX, "OPEN_ANDX" },
|
|
{ SMB_COM_READ_ANDX, "READ_ANDX" },
|
|
{ SMB_COM_WRITE_ANDX, "WRITE_ANDX" },
|
|
{ SMB_COM_NEW_FILE_SIZE, "NEW_FILE_SIZE" },
|
|
{ SMB_COM_CLOSE_AND_TREE_DISC, "CLOSE_AND_TREE_DISC" },
|
|
{ SMB_COM_TRANSACTION2, "TRANSACTION2" },
|
|
{ SMB_COM_TRANSACTION2_SECONDARY, "TRANSACTION2_SECONDARY" },
|
|
{ SMB_COM_FIND_CLOSE2, "FIND_CLOSE2" },
|
|
{ SMB_COM_FIND_NOTIFY_CLOSE, "FIND_NOTIFY_CLOSE" },
|
|
{ SMB_COM_TREE_CONNECT, "TREE_CONNECT" },
|
|
{ SMB_COM_TREE_DISCONNECT, "TREE_DISCONNECT" },
|
|
{ SMB_COM_NEGOTIATE, "NEGOTIATE" },
|
|
{ SMB_COM_SESSION_SETUP_ANDX, "SESSION_SETUP_ANDX" },
|
|
{ SMB_COM_LOGOFF_ANDX, "LOGOFF_ANDX" },
|
|
{ SMB_COM_TREE_CONNECT_ANDX, "TREE_CONNECT_ANDX" },
|
|
{ SMB_COM_SECURITY_PACKAGE_ANDX, "SECURITY_PACKAGE_ANDX" },
|
|
{ SMB_COM_QUERY_INFORMATION_DISK, "QUERY_INFORMATION_DISK" },
|
|
{ SMB_COM_SEARCH, "SEARCH" },
|
|
{ SMB_COM_FIND, "FIND" },
|
|
{ SMB_COM_FIND_UNIQUE, "FIND_UNIQUE" },
|
|
{ SMB_COM_FIND_CLOSE, "FIND_CLOSE" },
|
|
{ SMB_COM_NT_TRANSACT, "NT_TRANSACT" },
|
|
{ SMB_COM_NT_TRANSACT_SECONDARY, "NT_TRANSACT_SECONDARY" },
|
|
{ SMB_COM_NT_CREATE_ANDX, "NT_CREATE_ANDX" },
|
|
{ SMB_COM_NT_CANCEL, "NT_CANCEL" },
|
|
{ SMB_COM_NT_RENAME, "NT_RENAME" },
|
|
{ SMB_COM_OPEN_PRINT_FILE, "OPEN_PRINT_FILE" },
|
|
{ SMB_COM_WRITE_PRINT_FILE, "WRITE_PRINT_FILE" },
|
|
{ SMB_COM_CLOSE_PRINT_FILE, "CLOSE_PRINT_FILE" },
|
|
{ SMB_COM_GET_PRINT_QUEUE, "GET_PRINT_QUEUE" },
|
|
{ SMB_COM_READ_BULK, "READ_BULK" },
|
|
{ SMB_COM_WRITE_BULK, "WRITE_BULK" },
|
|
{ SMB_COM_WRITE_BULK_DATA, "WRITE_BULK_DATA" },
|
|
{ SMB_COM_INVALID, "INVALID" },
|
|
{ SMB_COM_NO_ANDX_COMMAND, "NO_ANDX_COMMAND" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
const char * result = NULL;
|
|
int i;
|
|
|
|
for(i = 0 ; code_name_tab[i].code != -1 ; i++)
|
|
{
|
|
if(command == code_name_tab[i].code)
|
|
{
|
|
result = code_name_tab[i].name;
|
|
break;
|
|
}
|
|
}
|
|
|
|
return(result);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
struct line_buffer
|
|
{
|
|
char line[512];
|
|
size_t length;
|
|
};
|
|
|
|
/*****************************************************************************/
|
|
|
|
static void
|
|
init_line_buffer(struct line_buffer *lb)
|
|
{
|
|
lb->length = 0;
|
|
lb->line[lb->length] = '\0';
|
|
}
|
|
|
|
static void
|
|
set_line_buffer(struct line_buffer *lb,int c,size_t len)
|
|
{
|
|
if(len > sizeof(lb->line)-1)
|
|
len = sizeof(lb->line)-1;
|
|
|
|
memset(lb->line,c,len);
|
|
|
|
lb->length = len;
|
|
lb->line[lb->length] = '\0';
|
|
}
|
|
|
|
static void
|
|
copy_string_to_line_buffer(struct line_buffer *lb,const char *str,size_t len,size_t pos)
|
|
{
|
|
if(pos+len > sizeof(lb->line)-1)
|
|
{
|
|
if(pos < sizeof(lb->line)-1)
|
|
len = sizeof(lb->line)-1 - pos;
|
|
else
|
|
len = 0;
|
|
}
|
|
|
|
if(len > 0)
|
|
{
|
|
memmove(&lb->line[pos],str,len);
|
|
|
|
if(lb->length < pos+len)
|
|
{
|
|
lb->length = pos+len;
|
|
lb->line[lb->length] = '\0';
|
|
}
|
|
}
|
|
}
|
|
|
|
static void
|
|
add_lb_flag(struct line_buffer *lb,const char * str)
|
|
{
|
|
size_t len = strlen(str);
|
|
|
|
if(lb->length == 0)
|
|
{
|
|
if(lb->length + len < sizeof(lb->line)-1)
|
|
{
|
|
memmove(&lb->line[lb->length],str,len);
|
|
lb->length += len;
|
|
|
|
lb->line[lb->length] = '\0';
|
|
}
|
|
}
|
|
else
|
|
{
|
|
if(lb->length + 2 + len < sizeof(lb->line)-1)
|
|
{
|
|
memmove(&lb->line[lb->length],", ",2);
|
|
lb->length += 2;
|
|
|
|
memmove(&lb->line[lb->length],str,len);
|
|
lb->length += len;
|
|
|
|
lb->line[lb->length] = '\0';
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static void
|
|
print_smb_data(struct line_buffer * lb,int num_data_bytes_left,const unsigned char * data_bytes)
|
|
{
|
|
if(num_data_bytes_left > 0)
|
|
{
|
|
int row_offset = 0;
|
|
char format_buffer[20];
|
|
char dword_buffer[20];
|
|
int num_bytes_per_row,dword_pos;
|
|
size_t dword_buffer_len;
|
|
unsigned char c;
|
|
int c_pos;
|
|
|
|
while(num_data_bytes_left > 0)
|
|
{
|
|
/* The output line should be filled with blank spaces. */
|
|
set_line_buffer(lb,' ',60);
|
|
|
|
/* Print the row offset (in bytes) at the start of the
|
|
* output line.
|
|
*/
|
|
SPrintf(format_buffer,"%04lx:",row_offset);
|
|
|
|
copy_string_to_line_buffer(lb,format_buffer,5,0);
|
|
|
|
/* Print up to 16 bytes per row. */
|
|
if(num_data_bytes_left > 16)
|
|
num_bytes_per_row = 16;
|
|
else
|
|
num_bytes_per_row = num_data_bytes_left;
|
|
|
|
dword_pos = 6;
|
|
dword_buffer[0] = '\0';
|
|
dword_buffer_len = 0;
|
|
c_pos = 45;
|
|
|
|
/* Print the bytes in hex format, followed by a column
|
|
* of the same data bytes interpreted as printable
|
|
* characters.
|
|
*/
|
|
while(num_bytes_per_row > 0)
|
|
{
|
|
c = (*data_bytes++);
|
|
num_bytes_per_row--;
|
|
row_offset++;
|
|
num_data_bytes_left--;
|
|
|
|
/* Convert this data byte to hexadecimal
|
|
* representation.
|
|
*/
|
|
SPrintf(format_buffer,"%02lx",c);
|
|
|
|
strcat(dword_buffer,format_buffer);
|
|
dword_buffer_len += 2;
|
|
|
|
/* Is this not a printable character? If so,
|
|
* substitute it with '.'.
|
|
*/
|
|
if(c < ' ' || c == 127 || (128 <= c && c <= 160))
|
|
c = '.';
|
|
|
|
copy_string_to_line_buffer(lb,(char *)&c,1,c_pos);
|
|
c_pos++;
|
|
|
|
/* If we have converted four bytes to hexadecimal
|
|
* format, put them into the output buffer.
|
|
*/
|
|
if(dword_buffer_len >= 8)
|
|
{
|
|
copy_string_to_line_buffer(lb,dword_buffer,8,dword_pos);
|
|
dword_pos += 9;
|
|
|
|
dword_buffer[0] = '\0';
|
|
dword_buffer_len = 0;
|
|
}
|
|
}
|
|
|
|
/* If we did not convert a multiple of 32 bytes per row,
|
|
* add the last conversion buffer contents.
|
|
*/
|
|
if(dword_buffer_len > 0)
|
|
copy_string_to_line_buffer(lb,dword_buffer,dword_buffer_len,dword_pos);
|
|
|
|
FPrintf(dump_smb_file," %s\n",lb->line);
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const struct tm *
|
|
convert_smb_date_time_to_tm(unsigned short smb_date,unsigned short smb_time)
|
|
{
|
|
static struct tm tm;
|
|
|
|
memset(&tm,0,sizeof(tm));
|
|
|
|
tm.tm_sec = (smb_time & 0x001f) * 2;
|
|
tm.tm_min = (smb_time & 0x07e0) >> 5;
|
|
tm.tm_hour = (smb_time & 0xf800) >> 11;
|
|
|
|
tm.tm_mday = smb_date & 0x001f;
|
|
tm.tm_mon = ((smb_date & 0x01e0) >> 5) - 1;
|
|
tm.tm_year = 80 + ((smb_date & 0xfe00) >> 9);
|
|
|
|
return(&tm);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const struct tm *
|
|
convert_filetime_to_tm(const unsigned long * qword)
|
|
{
|
|
const QUAD adjust_by_369_years = { 0x00000002,0xb6109100 };
|
|
QUAD long_date;
|
|
time_t when;
|
|
|
|
long_date.High = qword[0];
|
|
long_date.Low = qword[1];
|
|
|
|
/* Divide by 10,000,000 to convert the time from 100ns
|
|
* units into seconds.
|
|
*/
|
|
divide_64_by_32(&long_date,10000000,&long_date);
|
|
|
|
/* Adjust by 369 years (11,644,473,600 seconds) to convert
|
|
* from the epoch beginning on January 1st 1601 to the one
|
|
* beginning on January 1st 1970 (the Unix epoch).
|
|
*/
|
|
if(subtract_64_from_64_to_64(&long_date,&adjust_by_369_years,&long_date) == 0)
|
|
when = (time_t)long_date.Low;
|
|
else
|
|
when = (time_t)0;
|
|
|
|
return(gmtime(&when));
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
convert_filetime_to_string(const unsigned long * qword)
|
|
{
|
|
static char string[40];
|
|
const struct tm * tm;
|
|
|
|
tm = convert_filetime_to_tm(qword);
|
|
|
|
SPrintf(string,"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
|
|
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
|
|
tm->tm_hour,tm->tm_min,tm->tm_sec);
|
|
|
|
return(string);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
convert_smb_date_time_to_string(unsigned short smb_date,unsigned short smb_time)
|
|
{
|
|
static char string[40];
|
|
const struct tm * tm;
|
|
|
|
tm = convert_smb_date_time_to_tm(smb_date,smb_time);
|
|
|
|
SPrintf(string,"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
|
|
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
|
|
tm->tm_hour,tm->tm_min,tm->tm_sec);
|
|
|
|
return(string);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
convert_utime_to_string(unsigned long utime)
|
|
{
|
|
static char string[40];
|
|
const struct tm * tm;
|
|
time_t when = (time_t)utime;
|
|
|
|
tm = gmtime(&when);
|
|
|
|
SPrintf(string,"%ld-%02ld-%02ldT%02ld:%02ld:%02ldZ",
|
|
tm->tm_year+1900,tm->tm_mon+1,tm->tm_mday,
|
|
tm->tm_hour,tm->tm_min,tm->tm_sec);
|
|
|
|
return(string);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static const char *
|
|
convert_qword_to_string(const unsigned long *qword)
|
|
{
|
|
static char string[40];
|
|
QUAD number;
|
|
unsigned long n;
|
|
int len;
|
|
|
|
number.High = qword[0];
|
|
number.Low = qword[1];
|
|
|
|
memset(string,0,sizeof(string));
|
|
|
|
for(len = sizeof(string)-2 ; len >= 0 ; )
|
|
{
|
|
n = divide_64_by_32(&number,10,&number);
|
|
|
|
string[len--] = '0'+n;
|
|
|
|
if(number.High == 0 && number.Low == 0)
|
|
break;
|
|
}
|
|
|
|
return(&string[len+1]);
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static void
|
|
print_smb_transaction2_subcommand(int command,enum smb_packet_source_t smb_packet_source,int num_parameter_bytes,
|
|
const unsigned char * parameters,int num_data_bytes,const unsigned char * data)
|
|
{
|
|
if(command == TRANS2_FIND_FIRST2 && smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int search_attributes;
|
|
int search_count;
|
|
int flags;
|
|
int information_level;
|
|
unsigned long search_storage_type;
|
|
const char * file_name;
|
|
int offset = 0;
|
|
|
|
search_attributes = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
|
|
|
|
if(search_attributes & 0x0100)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
|
|
|
|
if(search_attributes & 0x0200)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(search_attributes & 0x0400)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(search_attributes & 0x1000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(search_attributes & 0x2000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
search_count = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
|
|
|
|
flags = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
|
|
|
|
if(flags & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AFTER_REQUEST\n");
|
|
|
|
if(flags & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AT_EOS\n");
|
|
|
|
if(flags & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FIND_RETURN_RESUME_KEYS\n");
|
|
|
|
if(flags & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FIND_CONTINUE_FROM_LAST\n");
|
|
|
|
if(flags & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FIND_WITH_BACKUP_INTENT\n");
|
|
|
|
information_level = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"information level = 0x%04lx\n",information_level);
|
|
|
|
last_trans2_find_information_level = information_level;
|
|
|
|
if (information_level == 0x0001)
|
|
FPrintf(dump_smb_file," SMB_INFO_STANDARD\n");
|
|
else if (information_level == 0x0002)
|
|
FPrintf(dump_smb_file," SMB_INFO_QUERY_EA_SIZE\n");
|
|
else if (information_level == 0x0003)
|
|
FPrintf(dump_smb_file," SMB_INFO_QUERY_EAS_FROM_LIST\n");
|
|
else if (information_level == 0x0101)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_DIRECTORY_INFO\n");
|
|
else if (information_level == 0x0102)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_FULL_DIRECTORY_INFO\n");
|
|
else if (information_level == 0x0103)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_NAMES_INFO\n");
|
|
else if (information_level == 0x0104)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_BOTH_DIRECTORY_INFO\n");
|
|
|
|
search_storage_type = next_data_dword(parameters,&offset);
|
|
FPrintf(dump_smb_file,"search_storage_type = 0x%08lx\n",search_storage_type);
|
|
|
|
if(search_storage_type == 0x00000001)
|
|
FPrintf(dump_smb_file," FILE_DIRECTORY_ONLY\n");
|
|
|
|
if(search_storage_type == 0x00000040)
|
|
FPrintf(dump_smb_file," FILE_NON_DIRECTORY_FILE\n");
|
|
|
|
file_name = next_data_bytes(parameters,0,&offset);
|
|
|
|
FPrintf(dump_smb_file,"file name = '%s'\n",file_name);
|
|
|
|
/* ZZZ need to deal with the 'data' provided if
|
|
* information_level == SMB_INFO_QUERY_EAS_FROM_LIST.
|
|
*/
|
|
}
|
|
else if (command == TRANS2_FIND_NEXT2 && smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int sid;
|
|
int search_count;
|
|
unsigned long resume_key;
|
|
int flags;
|
|
int information_level;
|
|
const char * file_name;
|
|
int offset = 0;
|
|
|
|
sid = next_data_word(parameters,&offset);
|
|
|
|
FPrintf(dump_smb_file,"sid = 0x%04lx\n",sid);
|
|
|
|
search_count = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
|
|
|
|
information_level = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"information level = 0x%04lx\n",information_level);
|
|
|
|
last_trans2_find_information_level = information_level;
|
|
|
|
if (information_level == 0x0001)
|
|
FPrintf(dump_smb_file," SMB_INFO_STANDARD\n");
|
|
else if (information_level == 0x0002)
|
|
FPrintf(dump_smb_file," SMB_INFO_QUERY_EA_SIZE\n");
|
|
else if (information_level == 0x0003)
|
|
FPrintf(dump_smb_file," SMB_INFO_QUERY_EAS_FROM_LIST\n");
|
|
else if (information_level == 0x0101)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_DIRECTORY_INFO\n");
|
|
else if (information_level == 0x0102)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_FULL_DIRECTORY_INFO\n");
|
|
else if (information_level == 0x0103)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_NAMES_INFO\n");
|
|
else if (information_level == 0x0104)
|
|
FPrintf(dump_smb_file," SMB_FIND_FILE_BOTH_DIRECTORY_INFO\n");
|
|
|
|
resume_key = next_data_dword(parameters,&offset);
|
|
FPrintf(dump_smb_file,"resume_key = 0x%08lx\n",resume_key);
|
|
|
|
flags = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
|
|
|
|
if(flags & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AFTER_REQUEST\n");
|
|
|
|
if(flags & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FIND_CLOSE_AT_EOS\n");
|
|
|
|
if(flags & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FIND_RETURN_RESUME_KEYS\n");
|
|
|
|
if(flags & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FIND_CONTINUE_FROM_LAST\n");
|
|
|
|
if(flags & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FIND_WITH_BACKUP_INTENT\n");
|
|
|
|
file_name = next_data_bytes(parameters,0,&offset);
|
|
|
|
FPrintf(dump_smb_file,"file name = '%s'\n",file_name);
|
|
|
|
/* ZZZ need to deal with the 'data' provided if
|
|
* information_level == SMB_INFO_QUERY_EAS_FROM_LIST.
|
|
*/
|
|
}
|
|
else if (smb_packet_source == smb_packet_to_consumer && (command == TRANS2_FIND_FIRST2 || command == TRANS2_FIND_NEXT2))
|
|
{
|
|
int sid;
|
|
int search_count;
|
|
int end_of_search;
|
|
int ea_error_offset;
|
|
int last_name_offset;
|
|
int offset = 0;
|
|
|
|
if(command == TRANS2_FIND_FIRST2)
|
|
{
|
|
sid = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"sid = %ld\n",sid);
|
|
}
|
|
|
|
search_count = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"search count = %ld\n",search_count);
|
|
|
|
end_of_search = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"end of search = 0x%04lx\n",end_of_search);
|
|
|
|
ea_error_offset = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"ea error offset = 0x%04lx\n",ea_error_offset);
|
|
|
|
last_name_offset = next_data_word(parameters,&offset);
|
|
FPrintf(dump_smb_file,"last name offset = 0x%04lx\n",last_name_offset);
|
|
|
|
/* SMB_FIND_FILE_BOTH_DIRECTORY_INFO */
|
|
if(num_data_bytes > 0 && last_trans2_find_information_level == 0x0104)
|
|
{
|
|
unsigned long next_entry_offset;
|
|
unsigned long file_index;
|
|
unsigned long creation_time[2]; // FILETIME
|
|
unsigned long last_access_time[2]; // FILETIME
|
|
unsigned long last_write_time[2]; // FILETIME
|
|
unsigned long last_change_time[2]; // FILETIME
|
|
unsigned long end_of_file[2]; // LARGE_INTEGER
|
|
unsigned long allocation_size[2]; // LARGE_INTEGER
|
|
unsigned long ext_file_attributes; // SMB_EXT_FILE_ATTR
|
|
unsigned long file_name_length;
|
|
unsigned long ea_size;
|
|
int short_name_length; // UCHAR
|
|
int reserved; // UCHAR
|
|
const char * short_name; // WCHAR
|
|
const char * file_name; // SMB_STRING
|
|
struct line_buffer lb;
|
|
int unicode_char;
|
|
int unicode_offset;
|
|
int output_offset;
|
|
int entry_count = 0;
|
|
int entry_offset = 0;
|
|
int next_offset;
|
|
|
|
while(entry_offset < num_data_bytes && entry_count < search_count)
|
|
{
|
|
FPrintf(dump_smb_file,"directory entry [%ld]:\n",entry_count++);
|
|
|
|
next_offset = entry_offset;
|
|
|
|
next_entry_offset = next_data_dword(data,&entry_offset);
|
|
|
|
next_offset += next_entry_offset;
|
|
|
|
file_index = next_data_dword(data,&entry_offset);
|
|
next_data_qword(data,creation_time,&entry_offset);
|
|
next_data_qword(data,last_access_time,&entry_offset);
|
|
next_data_qword(data,last_write_time,&entry_offset);
|
|
next_data_qword(data,last_change_time,&entry_offset);
|
|
next_data_qword(data,end_of_file,&entry_offset);
|
|
next_data_qword(data,allocation_size,&entry_offset);
|
|
ext_file_attributes = next_data_dword(data,&entry_offset);
|
|
file_name_length = next_data_dword(data,&entry_offset);
|
|
ea_size = next_data_dword(data,&entry_offset);
|
|
short_name_length = next_data_byte(data,&entry_offset);
|
|
reserved = next_data_byte(data,&entry_offset);
|
|
short_name = next_data_bytes(data,24,&entry_offset);
|
|
file_name = next_data_bytes(data,0,&entry_offset);
|
|
|
|
FPrintf(dump_smb_file,"\tnext entry offset = %ld\n",next_entry_offset);
|
|
FPrintf(dump_smb_file,"\tfile index = 0x%08lx\n",file_index);
|
|
FPrintf(dump_smb_file,"\tcreation time = 0x%08lx%08lx\n",creation_time[0],creation_time[1]); /* ZZZ this is actually a signed value */
|
|
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(creation_time));
|
|
FPrintf(dump_smb_file,"\tlast access time = 0x%08lx%08lx\n",last_access_time[0],last_access_time[1]);
|
|
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(last_access_time));
|
|
FPrintf(dump_smb_file,"\tlast change time = 0x%08lx%08lx\n",last_change_time[0],last_change_time[1]);
|
|
FPrintf(dump_smb_file,"\t %s\n",convert_filetime_to_string(last_change_time));
|
|
FPrintf(dump_smb_file,"\tend of file = %ls (0x%08lx%08lx)\n",convert_qword_to_string(end_of_file),end_of_file[0],end_of_file[1]);
|
|
FPrintf(dump_smb_file,"\tallocation size = %s (0x%08lx%08lx)\n",convert_qword_to_string(allocation_size),allocation_size[0],allocation_size[1]);
|
|
|
|
FPrintf(dump_smb_file,"\text file attributes = 0x%08lx\n",ext_file_attributes);
|
|
|
|
if(ext_file_attributes & 0x00000001)
|
|
FPrintf(dump_smb_file,"\t ATTR_READONLY\n");
|
|
|
|
if(ext_file_attributes & 0x00000002)
|
|
FPrintf(dump_smb_file,"\t ATTR_HIDDEN\n");
|
|
|
|
if(ext_file_attributes & 0x00000004)
|
|
FPrintf(dump_smb_file,"\t ATTR_SYSTEM\n");
|
|
|
|
if(ext_file_attributes & 0x00000010)
|
|
FPrintf(dump_smb_file,"\t ATTR_DIRECTORY\n");
|
|
|
|
if(ext_file_attributes & 0x00000020)
|
|
FPrintf(dump_smb_file,"\t ATTR_ARCHIVE\n");
|
|
|
|
if(ext_file_attributes & 0x00000080)
|
|
FPrintf(dump_smb_file,"\t ATTR_NORMAL\n");
|
|
|
|
if(ext_file_attributes & 0x00000100)
|
|
FPrintf(dump_smb_file,"\t ATTR_TEMPORARY\n");
|
|
|
|
if(ext_file_attributes & 0x00000800)
|
|
FPrintf(dump_smb_file,"\t ATTR_COMPRESSED\n");
|
|
|
|
if(ext_file_attributes & 0x01000000)
|
|
FPrintf(dump_smb_file,"\t POSIX_SEMANTICS\n");
|
|
|
|
if(ext_file_attributes & 0x02000000)
|
|
FPrintf(dump_smb_file,"\t BACKUP_SEMANTICS\n");
|
|
|
|
if(ext_file_attributes & 0x04000000)
|
|
FPrintf(dump_smb_file,"\t DELETE_ON_CLOSE\n");
|
|
|
|
if(ext_file_attributes & 0x08000000)
|
|
FPrintf(dump_smb_file,"\t SEQUENTIAL_SCAN\n");
|
|
|
|
if(ext_file_attributes & 0x10000000)
|
|
FPrintf(dump_smb_file,"\t RANDOM_ACCESS\n");
|
|
|
|
if(ext_file_attributes & 0x20000000)
|
|
FPrintf(dump_smb_file,"\t NO_BUFFERING\n");
|
|
|
|
if(ext_file_attributes & 0x80000000)
|
|
FPrintf(dump_smb_file,"\t WRITE_THROUGH\n");
|
|
|
|
FPrintf(dump_smb_file,"\tfile name length = %ld\n",file_name_length);
|
|
FPrintf(dump_smb_file,"\tea size = %ld\n",ea_size);
|
|
FPrintf(dump_smb_file,"\tshort name length = %ld\n",short_name_length);
|
|
FPrintf(dump_smb_file,"\treserved = 0x%02lx\n",reserved);
|
|
|
|
if(short_name_length > 0)
|
|
{
|
|
unicode_offset = 0;
|
|
output_offset = 0;
|
|
init_line_buffer(&lb);
|
|
|
|
while(unicode_offset < short_name_length)
|
|
{
|
|
unicode_char = next_data_word(short_name,&unicode_offset);
|
|
if(unicode_char == 0)
|
|
break;
|
|
|
|
if(' ' <= unicode_char && unicode_char < 127)
|
|
{
|
|
char c = unicode_char;
|
|
|
|
copy_string_to_line_buffer(&lb,&c,1,output_offset);
|
|
output_offset++;
|
|
}
|
|
else
|
|
{
|
|
char code_string[40];
|
|
|
|
SPrintf(code_string,"<%02lx%02ld>",unicode_char >> 8,unicode_char & 0xff);
|
|
|
|
copy_string_to_line_buffer(&lb,code_string,strlen(code_string),output_offset);
|
|
output_offset += strlen(code_string);
|
|
}
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"\tshort name = '%s'\n",lb.line);
|
|
}
|
|
|
|
if(file_name_length > 0)
|
|
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
|
|
|
|
entry_offset = next_offset;
|
|
}
|
|
}
|
|
/* SMB_INFO_STANDARD */
|
|
else if (num_data_bytes > 0 && last_trans2_find_information_level == 0x0001)
|
|
{
|
|
unsigned long resume_key;
|
|
unsigned short creation_date;
|
|
unsigned short creation_time;
|
|
unsigned short last_access_date;
|
|
unsigned short last_access_time;
|
|
unsigned short last_write_date;
|
|
unsigned short last_write_time;
|
|
unsigned long file_data_size;
|
|
unsigned long allocation_size;
|
|
unsigned short file_attributes;
|
|
unsigned char file_name_length;
|
|
const char * file_name;
|
|
int entry_count = 0;
|
|
int entry_offset = 0;
|
|
|
|
while(entry_offset < num_data_bytes && entry_count < search_count)
|
|
{
|
|
FPrintf(dump_smb_file,"directory entry [%ld]:\n",entry_count++);
|
|
|
|
resume_key = next_data_dword(data,&entry_offset);
|
|
creation_date = next_data_word(data,&entry_offset);
|
|
creation_time = next_data_word(data,&entry_offset);
|
|
last_access_date = next_data_word(data,&entry_offset);
|
|
last_access_time = next_data_word(data,&entry_offset);
|
|
last_write_date = next_data_word(data,&entry_offset);
|
|
last_write_time = next_data_word(data,&entry_offset);
|
|
file_data_size = next_data_dword(data,&entry_offset);
|
|
allocation_size = next_data_dword(data,&entry_offset);
|
|
file_attributes = next_data_dword(data,&entry_offset);
|
|
file_name_length = next_data_byte(data,&entry_offset);
|
|
file_name = (char *)next_data_bytes(data,file_name_length,&entry_offset);
|
|
|
|
FPrintf(dump_smb_file,"\tresume key = 0x%08lx\n",resume_key);
|
|
FPrintf(dump_smb_file,"\tcreation date = 0x%04lx\n",creation_date);
|
|
FPrintf(dump_smb_file,"\tcreation time = 0x%04lx\n",creation_time);
|
|
FPrintf(dump_smb_file,"\tcreation = %s\n",convert_smb_date_time_to_string(creation_date,creation_time));
|
|
FPrintf(dump_smb_file,"\tlast access date = 0x%04lx\n",last_access_date);
|
|
FPrintf(dump_smb_file,"\tlast access time = 0x%04lx\n",last_access_time);
|
|
FPrintf(dump_smb_file,"\tlast access = %s\n",convert_smb_date_time_to_string(last_access_date,last_access_time));
|
|
FPrintf(dump_smb_file,"\tlast write date = 0x%04lx\n",last_write_date);
|
|
FPrintf(dump_smb_file,"\tlast write time = 0x%04lx\n",last_write_time);
|
|
FPrintf(dump_smb_file,"\tlast write = %s\n",convert_smb_date_time_to_string(last_write_date,last_write_time));
|
|
FPrintf(dump_smb_file,"\tfile data size = %lu\n",file_data_size);
|
|
FPrintf(dump_smb_file,"\tallocation size = %lu\n",allocation_size);
|
|
FPrintf(dump_smb_file,"\tfile attributes = 0x%08lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"\tfile name length = %ld\n",file_name_length);
|
|
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
/* SMB commands used by smbfs 1.60 and beyond
|
|
*
|
|
#define SMBmkdir 0x00 // create directory
|
|
#define SMBrmdir 0x01 // delete directory
|
|
#define SMBopen 0x02 // open file
|
|
#define SMBcreate 0x03 // create file
|
|
#define SMBclose 0x04 // close file
|
|
#define SMBunlink 0x06 // delete file
|
|
#define SMBmv 0x07 // rename file
|
|
#define SMBgetatr 0x08 // get file attributes
|
|
#define SMBsetatr 0x09 // set file attributes
|
|
#define SMBread 0x0A // read from file
|
|
#define SMBwrite 0x0B // write to file
|
|
#define SMBlseek 0x12 // seek
|
|
#define SMBtcon 0x70 // tree connect
|
|
#define SMBtconX 0x75 // tree connect and X
|
|
#define SMBnegprot 0x72 // negotiate protocol
|
|
#define SMBdskattr 0x80 // get disk attributes
|
|
#define SMBsearch 0x81 // search directory
|
|
|
|
// Core+ protocol
|
|
#define SMBreadbraw 0x1a // read a block of data with no smb header
|
|
#define SMBwritebraw 0x1d // write a block of data with no smb header
|
|
#define SMBwritec 0x20 // secondary write request
|
|
|
|
// dos extended protocol
|
|
#define SMBsetattrE 0x22 // set file attributes expanded
|
|
#define SMBgetattrE 0x23 // get file attributes expanded
|
|
#define SMBlockingX 0x24 // lock/unlock byte ranges and X
|
|
#define SMBsesssetupX 0x73 // Session Set Up & X (including User Logon)
|
|
|
|
// Extended 2.0 protocol
|
|
#define SMBtrans2 0x32 // TRANS2 protocol set
|
|
|
|
// these are the TRANS2 sub commands
|
|
#define TRANSACT2_FINDFIRST 1
|
|
#define TRANSACT2_FINDNEXT 2
|
|
*/
|
|
|
|
/*****************************************************************************/
|
|
|
|
/* SMB commands supported so far:
|
|
*
|
|
* CREATE_DIRECTORY (SMBmkdir, 0x00)
|
|
* DELETE_DIRECTORY (SMBrmdir, 0x01)
|
|
* OPEN (SMBopen, 0x02)
|
|
* CREATE (SMBcreate, 0x03)
|
|
* CLOSE (SMBclose, 0x04)
|
|
* DELETE (SMBunlink, 0x06)
|
|
* RENAME (SMBmv, 0x07)
|
|
* QUERY_INFORMATION (SMBgetatr, 0x08)
|
|
* SET_INFORMATION (SMBsetatr, 0x09)
|
|
* READ (SMBread, 0x0A)
|
|
* WRITE (SMBwrite, 0x0B)
|
|
* SEEK (SMBlseek, 0x12)
|
|
* READ_RAW (SMBreadbraw, 0x1A)
|
|
* SMB_COM_WRITE_RAW (SMBwritebraw, 0x1D)
|
|
* SMB_COM_WRITE_COMPLETE (SMBwritec, 0x20)
|
|
* SET_INFORMATION2 (SMBsetattrE, 0x22)
|
|
* QUERY_INFORMATION2 (SMBgetattrE, 0x23)
|
|
* LOCKING_ANDX (SMBlockingX, 0x24)
|
|
* TRANSACTION2 (SMBtrans2, 0x32)
|
|
* TREE_CONNECT (SMBtcon, 0x70)
|
|
* NEGOTIATE (SMBnegprot, 0x72)
|
|
* SESSION_SETUP_AND (SMBsesssetupX, 0x73)
|
|
* TREE_CONNECT_ANDX (SMBtconX, 0x75)
|
|
* QUERY_INFORMATION_DISK (SMBdskattr, 0x80)
|
|
* SEARCH (SMBsearch, 0x81)
|
|
*/
|
|
static void
|
|
print_smb_contents(const struct smb_header * header,int command,enum smb_packet_source_t smb_packet_source,
|
|
int num_parameter_words,const unsigned char * parameters,int num_data_bytes,const unsigned char * data)
|
|
{
|
|
unsigned short vwv[256];
|
|
int i,j;
|
|
|
|
if(num_parameter_words < 0)
|
|
num_parameter_words = 0;
|
|
else if (num_parameter_words > 255)
|
|
num_parameter_words = 255;
|
|
|
|
if(num_data_bytes < 0)
|
|
num_data_bytes = 0;
|
|
|
|
for(i = j = 0 ; i < num_parameter_words ; i++, j += 2)
|
|
vwv[i] = (((int)parameters[j+1]) << 8) + parameters[j];
|
|
|
|
if (command == SMB_COM_CREATE_DIRECTORY)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
|
|
FPrintf(dump_smb_file,"directory name = '%s'\n",filename+1);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_DELETE_DIRECTORY)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
|
|
FPrintf(dump_smb_file,"directory name = '%s'\n",filename+1);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_OPEN)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
int access_mode;
|
|
int search_attribute;
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
access_mode = vwv[0];
|
|
FPrintf(dump_smb_file,"access mode = 0x%04lx\n",access_mode);
|
|
|
|
switch(access_mode & 0x0007)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Open for reading\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Open for writing\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Open for reading and writing\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Open for execution\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
switch((access_mode & 0x0070) >> 4)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Compatibility mode\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Deny read/write/execute others (exclusive use requested)\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Deny write to others\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Deny read/execute to others\n");
|
|
break;
|
|
|
|
case 4:
|
|
|
|
FPrintf(dump_smb_file," Deny nothing to others\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
switch((access_mode & 0x0700) >> 8)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Unknown locality of reference\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Mainly sequential access\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Mainly random access\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Random access with some locality\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
if(access_mode & 0x1000)
|
|
FPrintf(dump_smb_file," Perform caching on file\n");
|
|
else
|
|
FPrintf(dump_smb_file," Do not cache the file\n");
|
|
|
|
if(access_mode & 0x4000)
|
|
FPrintf(dump_smb_file," No read ahead or write behind is allowed on this file or device\n");
|
|
|
|
search_attribute = vwv[1];
|
|
FPrintf(dump_smb_file,"search attribute = 0x%04lx\n",search_attribute);
|
|
|
|
if(search_attribute & 0x0100)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
|
|
|
|
if(search_attribute & 0x0200)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(search_attribute & 0x0400)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(search_attribute & 0x1000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(search_attribute & 0x2000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
|
|
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
|
|
}
|
|
else
|
|
{
|
|
int access_mode;
|
|
int file_attributes;
|
|
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
|
|
file_attributes = vwv[1];
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"last modified = 0x%08lx\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
|
|
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[3]) << 16) | vwv[2]));
|
|
|
|
FPrintf(dump_smb_file,"file size = %lu\n",(((unsigned long )vwv[5]) << 16) | vwv[4]);
|
|
|
|
access_mode = vwv[6];
|
|
FPrintf(dump_smb_file,"access mode = 0x%04lx\n",access_mode);
|
|
|
|
switch(access_mode & 0x0007)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Open for reading\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Open for writing\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Open for reading and writing\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Open for execution\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
switch((access_mode & 0x0070) >> 4)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Compatibility mode\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Deny read/write/execute others (exclusive use requested)\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Deny write to others\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Deny read/execute to others\n");
|
|
break;
|
|
|
|
case 4:
|
|
|
|
FPrintf(dump_smb_file," Deny nothing to others\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
switch((access_mode & 0x0700) >> 8)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Unknown locality of reference\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Mainly sequential access\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Mainly random access\n");
|
|
break;
|
|
|
|
case 3:
|
|
|
|
FPrintf(dump_smb_file," Random access with some locality\n");
|
|
break;
|
|
|
|
default:
|
|
|
|
break;
|
|
}
|
|
|
|
if(access_mode & 0x1000)
|
|
FPrintf(dump_smb_file," Perform caching on file\n");
|
|
else
|
|
FPrintf(dump_smb_file," Do not cache the file\n");
|
|
|
|
if(access_mode & 0x4000)
|
|
FPrintf(dump_smb_file," No read ahead or write behind is allowed on this file or device\n");
|
|
}
|
|
}
|
|
else if (command == SMB_COM_CREATE)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
int file_attributes;
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
file_attributes = vwv[0];
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"creation time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
|
|
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
|
|
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
|
|
}
|
|
else
|
|
{
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_CLOSE)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"last time modified = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
|
|
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
|
|
}
|
|
}
|
|
else if (command == SMB_COM_DELETE)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
int search_attributes;
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
search_attributes = vwv[0];
|
|
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
|
|
|
|
if(search_attributes & 0x0100)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
|
|
|
|
if(search_attributes & 0x0200)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(search_attributes & 0x0400)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(search_attributes & 0x1000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(search_attributes & 0x2000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",filename[0]);
|
|
FPrintf(dump_smb_file,"file name = '%s'\n",filename+1);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_RENAME)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int search_attributes;
|
|
const char * old_file_name;
|
|
const char * new_file_name;
|
|
int len;
|
|
|
|
search_attributes = vwv[0];
|
|
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
|
|
|
|
if(search_attributes & 0x0100)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
|
|
|
|
if(search_attributes & 0x0200)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(search_attributes & 0x0400)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(search_attributes & 0x1000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(search_attributes & 0x2000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
old_file_name = data;
|
|
len = strlen(old_file_name);
|
|
|
|
new_file_name = &old_file_name[len+1];
|
|
|
|
FPrintf(dump_smb_file,"buffer format 1 = %ld\n",old_file_name[0]);
|
|
FPrintf(dump_smb_file,"old file name = '%s'\n",old_file_name+1);
|
|
|
|
FPrintf(dump_smb_file,"buffer format 2 = %ld\n",new_file_name[0]);
|
|
FPrintf(dump_smb_file,"new file name = '%s'\n",new_file_name+1);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_QUERY_INFORMATION)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
FPrintf(dump_smb_file,"buffer format = 0x%02lx\n",filename[0]);
|
|
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
|
|
}
|
|
else
|
|
{
|
|
int file_attributes;
|
|
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
file_attributes = vwv[0];
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"last write time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
|
|
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
|
|
FPrintf(dump_smb_file,"file size = %lu\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_SET_INFORMATION)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char filename[256];
|
|
int file_attributes;
|
|
|
|
if(num_data_bytes > 255)
|
|
num_data_bytes = 255;
|
|
|
|
memmove(filename,data,num_data_bytes);
|
|
filename[num_data_bytes] = '\0';
|
|
|
|
file_attributes = vwv[0];
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
FPrintf(dump_smb_file,"creation time = 0x%08lx\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
|
|
FPrintf(dump_smb_file," %s\n",convert_utime_to_string((((unsigned long)vwv[2]) << 16) | vwv[1]));
|
|
FPrintf(dump_smb_file,"file pathname = '%s'\n",filename+1);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_READ)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",(signed short)vwv[0]);
|
|
FPrintf(dump_smb_file,"count of bytes to read = %ld\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"read offset in bytes = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
|
|
FPrintf(dump_smb_file,"estimate of remaining bytes to be read = %ld\n",vwv[4]);
|
|
}
|
|
else
|
|
{
|
|
unsigned char buffer_format;
|
|
unsigned short count_of_bytes_read;
|
|
int offset = 0;
|
|
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"count of bytes returned = %ld\n",vwv[0]);
|
|
|
|
buffer_format = next_data_byte(data,&offset);
|
|
count_of_bytes_read = next_data_word(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %lu\n",buffer_format);
|
|
FPrintf(dump_smb_file,"count of bytes read = %lu\n",count_of_bytes_read);
|
|
|
|
if(dump_smb_level > 1 && count_of_bytes_read > 0)
|
|
{
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",count_of_bytes_read);
|
|
|
|
print_smb_data(&lb,count_of_bytes_read,next_data_bytes(data,count_of_bytes_read,&offset));
|
|
}
|
|
}
|
|
}
|
|
else if (command == SMB_COM_WRITE)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
unsigned char buffer_format;
|
|
unsigned short data_length;
|
|
int offset = 0;
|
|
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"count of bytes to write = %ld\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"write offset in bytes = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
|
|
FPrintf(dump_smb_file,"estimate of remaining bytes to be written = %ld\n",vwv[4]);
|
|
|
|
buffer_format = next_data_byte(data,&offset);
|
|
data_length = next_data_word(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %lu\n",buffer_format);
|
|
FPrintf(dump_smb_file,"data length = %lu\n",data_length);
|
|
|
|
if(dump_smb_level > 1 && data_length > 0)
|
|
{
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",data_length);
|
|
|
|
print_smb_data(&lb,data_length,next_data_bytes(data,data_length,&offset));
|
|
}
|
|
}
|
|
else
|
|
{
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"count of bytes written = %ld\n",vwv[0]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_SEEK)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int mode;
|
|
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
|
|
mode = vwv[1];
|
|
FPrintf(dump_smb_file,"mode = 0x%04lx\n",mode);
|
|
|
|
switch(mode)
|
|
{
|
|
case 0:
|
|
|
|
FPrintf(dump_smb_file," Seek from the start of the file\n");
|
|
break;
|
|
|
|
case 1:
|
|
|
|
FPrintf(dump_smb_file," Seek from the current position\n");
|
|
break;
|
|
|
|
case 2:
|
|
|
|
FPrintf(dump_smb_file," Seek from the end of the file\n");
|
|
break;
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"offset = %ld\n",(long)((((unsigned long)vwv[3]) << 16) | vwv[2]));
|
|
}
|
|
else
|
|
{
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"absolute position = %lu\n",(((unsigned long)vwv[1]) << 16) | vwv[0]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_READ_RAW)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",(signed short)vwv[0]);
|
|
FPrintf(dump_smb_file,"offset = %lu\n",(((unsigned long)vwv[2]) << 16) | vwv[1]);
|
|
FPrintf(dump_smb_file,"maximum count of bytes to return = %ld\n",vwv[3]);
|
|
FPrintf(dump_smb_file,"minimum count of byte to return = %ld\n",vwv[4]);
|
|
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[6]) << 16) | vwv[5]);
|
|
|
|
if(num_parameter_words == 0x0A)
|
|
FPrintf(dump_smb_file,"offset high = %lu\n",(((unsigned long)vwv[9]) << 16) | vwv[8]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_WRITE_RAW)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
unsigned short data_length;
|
|
unsigned short data_offset;
|
|
|
|
FPrintf(dump_smb_file,"file handle = 0x%04lx\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"count of bytes = %lu\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"offset = %lu\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
|
|
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[6]) << 16) | vwv[5]);
|
|
FPrintf(dump_smb_file,"write mode = %ld\n",vwv[7]);
|
|
|
|
if(vwv[7] & 0x0001)
|
|
FPrintf(dump_smb_file," Writethrough mode\n");
|
|
|
|
if(vwv[7] & 0x0002)
|
|
FPrintf(dump_smb_file," Read bytes available\n");
|
|
|
|
if(vwv[7] & 0x0004)
|
|
FPrintf(dump_smb_file," Named pipe raw\n");
|
|
|
|
if(vwv[7] & 0x0008)
|
|
FPrintf(dump_smb_file," Named pipe start\n");
|
|
|
|
data_length = vwv[8];
|
|
data_offset = vwv[9];
|
|
|
|
FPrintf(dump_smb_file,"data length = %lu\n",data_length);
|
|
FPrintf(dump_smb_file,"data offset = %lu\n",data_offset);
|
|
|
|
if(num_parameter_words == 0x0E)
|
|
FPrintf(dump_smb_file,"offset high = %lu\n",(((unsigned long)vwv[11]) << 16) | vwv[10]);
|
|
|
|
if(data_length > 0)
|
|
{
|
|
if(header->data_offset < data_offset)
|
|
FPrintf(dump_smb_file,"padding bytes = %ld\n",data_offset - header->data_offset);
|
|
|
|
if(dump_smb_level > 1)
|
|
{
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",data_length);
|
|
|
|
print_smb_data(&lb,num_data_bytes,&header->raw_packet[data_offset]);
|
|
}
|
|
}
|
|
}
|
|
else
|
|
{
|
|
/* The number of bytes remaining to be written is valid only
|
|
* if it's not 0xFFFF.
|
|
*/
|
|
if(num_parameter_words > 0 && vwv[0] != 0xFFFF)
|
|
FPrintf(dump_smb_file,"number of bytes remaining to be written = %lu\n",vwv[0]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_WRITE_COMPLETE)
|
|
{
|
|
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 0)
|
|
FPrintf(dump_smb_file,"total number of bytes written = %lu\n",vwv[0]);
|
|
}
|
|
else if (command == SMB_COM_SET_INFORMATION2)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"creation date = 0x%04lx\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"creation time = 0x%04lx\n",vwv[2]);
|
|
FPrintf(dump_smb_file,"creation = %s\n",convert_smb_date_time_to_string(vwv[1],vwv[2]));
|
|
FPrintf(dump_smb_file,"last access date = 0x%04lx\n",vwv[3]);
|
|
FPrintf(dump_smb_file,"last access time = 0x%04lx\n",vwv[4]);
|
|
FPrintf(dump_smb_file,"last access = %s\n",convert_smb_date_time_to_string(vwv[3],vwv[4]));
|
|
FPrintf(dump_smb_file,"last write date = 0x%04lx\n",vwv[5]);
|
|
FPrintf(dump_smb_file,"last write time = 0x%04lx\n",vwv[6]);
|
|
FPrintf(dump_smb_file,"last write = %s\n",convert_smb_date_time_to_string(vwv[5],vwv[6]));
|
|
}
|
|
}
|
|
else if (command == SMB_COM_QUERY_INFORMATION2)
|
|
{
|
|
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 0x11)
|
|
{
|
|
int file_attributes;
|
|
|
|
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"creation date = 0x%04lx\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"creation time = 0x%04lx\n",vwv[2]);
|
|
FPrintf(dump_smb_file,"creation = %s\n",convert_smb_date_time_to_string(vwv[1],vwv[2]));
|
|
FPrintf(dump_smb_file,"last access date = 0x%04lx\n",vwv[3]);
|
|
FPrintf(dump_smb_file,"last access time = 0x%04lx\n",vwv[4]);
|
|
FPrintf(dump_smb_file,"last access = %s\n",convert_smb_date_time_to_string(vwv[3],vwv[4]));
|
|
FPrintf(dump_smb_file,"last write date = 0x%04lx\n",vwv[5]);
|
|
FPrintf(dump_smb_file,"last write time = 0x%04lx\n",vwv[6]);
|
|
FPrintf(dump_smb_file,"last write = %s\n",convert_smb_date_time_to_string(vwv[5],vwv[6]));
|
|
FPrintf(dump_smb_file,"file data size = %lu\n",(((unsigned long)vwv[8]) << 16) | vwv[7]);
|
|
FPrintf(dump_smb_file,"file allocation size = %lu\n",(((unsigned long)vwv[10]) << 16) | vwv[9]);
|
|
|
|
file_attributes = vwv[11];
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file," SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
}
|
|
}
|
|
else if (command == SMB_COM_LOCKING_ANDX)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int type_of_lock;
|
|
int number_of_requested_unlocks;
|
|
int number_of_requested_locks;
|
|
int offset;
|
|
int i;
|
|
|
|
FPrintf(dump_smb_file,"fid = %ld\n",vwv[0]);
|
|
|
|
type_of_lock = vwv[1] & 0xff;
|
|
FPrintf(dump_smb_file,"type of lock = %ld\n",type_of_lock);
|
|
|
|
if(type_of_lock & 0x01)
|
|
FPrintf(dump_smb_file," SHARED_LOCK\n");
|
|
else
|
|
FPrintf(dump_smb_file," READ_WRITE_LOCK\n");
|
|
|
|
if(type_of_lock & 0x02)
|
|
FPrintf(dump_smb_file," OPLOCK_RELEASE\n");
|
|
|
|
if(type_of_lock & 0x04)
|
|
FPrintf(dump_smb_file," CHANGE_LOCK_TYPE\n");
|
|
|
|
if(type_of_lock & 0x08)
|
|
FPrintf(dump_smb_file," CANCEL_LOCK\n");
|
|
|
|
if(type_of_lock & 0x10)
|
|
FPrintf(dump_smb_file," LARGE_FILES\n");
|
|
|
|
FPrintf(dump_smb_file,"new oplock level = 0x%02lx\n",(vwv[1] >> 8) & 0xff);
|
|
|
|
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[3]) << 16) | vwv[2]);
|
|
|
|
number_of_requested_unlocks = vwv[4];
|
|
|
|
FPrintf(dump_smb_file,"number of requested unlocks = %ld\n",number_of_requested_unlocks);
|
|
|
|
number_of_requested_locks = vwv[5];
|
|
|
|
FPrintf(dump_smb_file,"number of requested locks = %ld\n",number_of_requested_locks);
|
|
|
|
offset = 0;
|
|
|
|
for(i = 0 ; i < number_of_requested_unlocks ; i++)
|
|
{
|
|
FPrintf(dump_smb_file,"unlock range[%ld] pid=%ld, byte offset = %lu, length in bytes = %lu\n",
|
|
i,next_data_word(data,&offset),next_data_dword(data,&offset),next_data_dword(data,&offset));
|
|
}
|
|
|
|
for(i = 0 ; i < number_of_requested_locks ; i++)
|
|
{
|
|
FPrintf(dump_smb_file,"lock range[%ld] pid=%ld, byte offset = %lu, length in bytes = %lu\n",
|
|
i,next_data_word(data,&offset),next_data_dword(data,&offset),next_data_dword(data,&offset));
|
|
}
|
|
}
|
|
}
|
|
else if (command == SMB_COM_TRANSACTION2)
|
|
{
|
|
const unsigned short * setup_words;
|
|
const char * subcommand_name;
|
|
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int transaction_parameter_count;
|
|
int transaction_parameter_offset;
|
|
int transaction_data_count;
|
|
int transaction_data_offset;
|
|
int flags;
|
|
int setup_count;
|
|
int i;
|
|
|
|
FPrintf(dump_smb_file,"total parameter count = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"total data count = %ld\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"max parameter count = %ld\n",vwv[2]);
|
|
FPrintf(dump_smb_file,"max data count = %ld\n",vwv[3]);
|
|
FPrintf(dump_smb_file,"max setup count = %ld\n",vwv[4] & 0xff);
|
|
|
|
flags = vwv[5];
|
|
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
|
|
|
|
if(flags & 0x0001)
|
|
FPrintf(dump_smb_file," DISCONNECT_TID\n");
|
|
|
|
if(flags & 0x0002)
|
|
FPrintf(dump_smb_file," NO_RESPONSE\n");
|
|
|
|
FPrintf(dump_smb_file,"timeout = %lu\n",(((unsigned long)vwv[7]) << 16) | vwv[6]);
|
|
|
|
transaction_parameter_count = vwv[9];
|
|
FPrintf(dump_smb_file,"parameter count = %ld\n",transaction_parameter_count);
|
|
|
|
transaction_parameter_offset = vwv[10];
|
|
FPrintf(dump_smb_file,"parameter offset = %ld (header parameter offset = %ld)\n",transaction_parameter_offset,header->parameter_offset);
|
|
|
|
transaction_data_count = vwv[11];
|
|
FPrintf(dump_smb_file,"data count = %ld\n",transaction_data_count);
|
|
|
|
transaction_data_offset = vwv[12];
|
|
FPrintf(dump_smb_file,"data offset = %ld (header data offset = %ld)\n",transaction_data_offset,header->data_offset);
|
|
|
|
setup_count = vwv[13] & 0xff;
|
|
FPrintf(dump_smb_file,"setup count = %ld\n",setup_count);
|
|
|
|
setup_words = &vwv[14];
|
|
|
|
if(setup_count > 0)
|
|
{
|
|
last_smb_com_transaction_subcommand = setup_words[0];
|
|
|
|
subcommand_name = get_smb_transaction2_subcommand_name(setup_words[0]);
|
|
if(subcommand_name != NULL)
|
|
FPrintf(dump_smb_file,"subcommand = %s\n",subcommand_name);
|
|
else
|
|
FPrintf(dump_smb_file,"subcommand = %ld\n",setup_words[0]);
|
|
|
|
for(i = 0 ; i < setup_count ; i++)
|
|
FPrintf(dump_smb_file,"setup word [%ld] = 0x%04lx\n",i,setup_words[i]);
|
|
}
|
|
else
|
|
{
|
|
last_smb_com_transaction_subcommand = -1;
|
|
}
|
|
|
|
if(dump_smb_level > 1 && transaction_parameter_count > 0 && transaction_parameter_offset + transaction_parameter_count <= header->raw_packet_size)
|
|
{
|
|
const unsigned char * transaction_parameter_contents = (unsigned char *)&header->raw_packet[transaction_parameter_offset];
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"transaction parameters =\n");
|
|
|
|
print_smb_data(&lb,transaction_parameter_count,transaction_parameter_contents);
|
|
}
|
|
|
|
if(dump_smb_level > 1 && transaction_data_count > 0 && transaction_data_offset + transaction_data_count <= header->raw_packet_size)
|
|
{
|
|
const unsigned char * transaction_data_contents = (unsigned char *)&header->raw_packet[transaction_data_offset];
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"transaction data =\n");
|
|
|
|
print_smb_data(&lb,transaction_data_count,transaction_data_contents);
|
|
}
|
|
|
|
print_smb_transaction2_subcommand(last_smb_com_transaction_subcommand,smb_packet_source,
|
|
transaction_parameter_count,(unsigned char *)&header->raw_packet[transaction_parameter_offset],
|
|
transaction_data_count,(unsigned char *)&header->raw_packet[transaction_data_offset]);
|
|
}
|
|
else if (num_parameter_words > 0 || num_data_bytes > 0)
|
|
{
|
|
int transaction_parameter_count;
|
|
int transaction_parameter_offset;
|
|
int transaction_data_count;
|
|
int transaction_data_offset;
|
|
int setup_count;
|
|
int i;
|
|
|
|
FPrintf(dump_smb_file,"total parameter count = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"total data count = %ld\n",vwv[1]);
|
|
|
|
transaction_parameter_count = vwv[3];
|
|
FPrintf(dump_smb_file,"parameter count = %ld\n",transaction_parameter_count);
|
|
|
|
transaction_parameter_offset = vwv[4];
|
|
FPrintf(dump_smb_file,"parameter offset = %ld\n",transaction_parameter_offset);
|
|
|
|
FPrintf(dump_smb_file,"parameter displacement = %ld\n",vwv[5]);
|
|
|
|
transaction_data_count = vwv[6];
|
|
FPrintf(dump_smb_file,"data count = %ld\n",transaction_data_count);
|
|
|
|
transaction_data_offset = vwv[7];
|
|
FPrintf(dump_smb_file,"data offset = %ld\n",transaction_data_offset);
|
|
|
|
setup_count = vwv[8] & 0xff;
|
|
FPrintf(dump_smb_file,"setup count = %ld\n",setup_count);
|
|
|
|
setup_words = &vwv[9];
|
|
|
|
if(setup_count > 0)
|
|
{
|
|
subcommand_name = get_smb_transaction2_subcommand_name(setup_words[0]);
|
|
if(subcommand_name != NULL)
|
|
FPrintf(dump_smb_file,"subcommand = %s\n",subcommand_name);
|
|
else
|
|
FPrintf(dump_smb_file,"subcommand = %ld\n",setup_words[0]);
|
|
|
|
for(i = 0 ; i < setup_count ; i++)
|
|
FPrintf(dump_smb_file,"setup word [%ld] = 0x%04lx\n",i,setup_words[i]);
|
|
}
|
|
|
|
if(dump_smb_level > 1 && transaction_parameter_count > 0 && transaction_parameter_offset + transaction_parameter_count <= header->raw_packet_size)
|
|
{
|
|
const unsigned char * transaction_parameter_contents = (unsigned char *)&header->raw_packet[transaction_parameter_offset];
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"transaction parameters =\n");
|
|
|
|
print_smb_data(&lb,transaction_parameter_count,transaction_parameter_contents);
|
|
}
|
|
|
|
if(dump_smb_level > 1 && transaction_data_count > 0 && transaction_data_offset + transaction_data_count <= header->raw_packet_size)
|
|
{
|
|
const unsigned char * transaction_data_contents = (unsigned char *)&header->raw_packet[transaction_data_offset];
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"transaction data =\n");
|
|
|
|
print_smb_data(&lb,transaction_data_count,transaction_data_contents);
|
|
}
|
|
|
|
print_smb_transaction2_subcommand(last_smb_com_transaction_subcommand,smb_packet_source,
|
|
transaction_parameter_count,(unsigned char *)&header->raw_packet[transaction_parameter_offset],
|
|
transaction_data_count,(unsigned char *)&header->raw_packet[transaction_data_offset]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_TREE_CONNECT)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
const char * path;
|
|
const char * password;
|
|
const char * service;
|
|
int len;
|
|
|
|
path = (char *)data;
|
|
len = strlen(path);
|
|
|
|
password = &path[len+1];
|
|
len = strlen(password);
|
|
|
|
service = &password[len+1];
|
|
|
|
FPrintf(dump_smb_file,"buffer format 1 = %ld\n",path[0]);
|
|
FPrintf(dump_smb_file,"path = '%s'\n",path+1);
|
|
FPrintf(dump_smb_file,"buffer format 2 = %ld\n",password[0]);
|
|
FPrintf(dump_smb_file,"password = '%s'\n",password+1);
|
|
FPrintf(dump_smb_file,"buffer format 3 = %ld\n",service[0]);
|
|
FPrintf(dump_smb_file,"service = '%s'\n",service+1);
|
|
}
|
|
else
|
|
{
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"max buffer size = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"tid = %ld\n",vwv[1]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_NEGOTIATE)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
char args[1024];
|
|
const char * dialect;
|
|
int dialect_index;
|
|
int len;
|
|
|
|
if(num_data_bytes > 1023)
|
|
num_data_bytes = 1023;
|
|
|
|
memmove(args,data,num_data_bytes);
|
|
args[num_data_bytes] = '\0';
|
|
|
|
dialect = args;
|
|
dialect_index = 0;
|
|
|
|
while(dialect < &args[num_data_bytes])
|
|
{
|
|
FPrintf(dump_smb_file,"dialect[%ld] = '%s'\n",dialect_index++,&dialect[1]);
|
|
|
|
len = strlen(&dialect[1]);
|
|
|
|
dialect = &dialect[1+len+1];
|
|
}
|
|
}
|
|
else
|
|
{
|
|
/* Assuming that the data returned is for
|
|
* the "NT LAN MANAGER" dialect.
|
|
*/
|
|
if(num_parameter_words == 0x11)
|
|
{
|
|
int offset = 0;
|
|
int challenge_length;
|
|
int security_mode;
|
|
unsigned long capabilities;
|
|
struct line_buffer lb;
|
|
int unicode_char;
|
|
int output_offset;
|
|
unsigned long system_time[2];
|
|
|
|
FPrintf(dump_smb_file,"dialect index = %ld\n",next_data_word(parameters,&offset));
|
|
|
|
security_mode = next_data_byte(parameters,&offset);
|
|
FPrintf(dump_smb_file,"security mode = %ld\n",security_mode);
|
|
|
|
if(security_mode & 0x01)
|
|
FPrintf(dump_smb_file," NEGOTIATE_USER_SECURITY\n");
|
|
|
|
if(security_mode & 0x02)
|
|
FPrintf(dump_smb_file," NEGOTIATE_ENCRYPT_PASSWORDS\n");
|
|
|
|
if(security_mode & 0x04)
|
|
FPrintf(dump_smb_file," NEGOTIATE_SECURITY_SIGNATURES_ENABLE\n");
|
|
|
|
if(security_mode & 0x08)
|
|
FPrintf(dump_smb_file," NEGOTIATE_SECURITY_SIGNATURES_REQUIRED\n");
|
|
|
|
if(security_mode & 0xF0)
|
|
FPrintf(dump_smb_file," Reserved = 0x%lx\n",security_mode >> 4);
|
|
|
|
FPrintf(dump_smb_file,"max mpx count = %ld\n",next_data_word(parameters,&offset));
|
|
FPrintf(dump_smb_file,"max number cvs = %ld\n",next_data_word(parameters,&offset));
|
|
FPrintf(dump_smb_file,"max buffer size = %lu\n",next_data_dword(parameters,&offset));
|
|
FPrintf(dump_smb_file,"max raw size = %lu\n",next_data_dword(parameters,&offset));
|
|
FPrintf(dump_smb_file,"session key = %lu\n",next_data_dword(parameters,&offset));
|
|
|
|
capabilities = next_data_dword(parameters,&offset);
|
|
FPrintf(dump_smb_file,"capabilities = 0x%08lx\n",capabilities);
|
|
|
|
if(capabilities & 0x00000001)
|
|
FPrintf(dump_smb_file," CAP_RAW_MODE\n");
|
|
|
|
if(capabilities & 0x00000002)
|
|
FPrintf(dump_smb_file," CAP_MPX_MODE\n");
|
|
|
|
if(capabilities & 0x00000004)
|
|
FPrintf(dump_smb_file," CAP_UNICODE\n");
|
|
|
|
if(capabilities & 0x00000008)
|
|
FPrintf(dump_smb_file," CAP_LARGE_FILES\n");
|
|
|
|
if(capabilities & 0x00000010)
|
|
FPrintf(dump_smb_file," CAP_NT_SMBS\n");
|
|
|
|
if(capabilities & 0x00000020)
|
|
FPrintf(dump_smb_file," CAP_RPC_REMOTE_APIS\n");
|
|
|
|
if(capabilities & 0x00000040)
|
|
FPrintf(dump_smb_file," CAP_STATUS32\n");
|
|
|
|
if(capabilities & 0x00000080)
|
|
FPrintf(dump_smb_file," CAP_LEVEL_II_OPLOCKS\n");
|
|
|
|
if(capabilities & 0x00000100)
|
|
FPrintf(dump_smb_file," CAP_LOCK_AND_READ\n");
|
|
|
|
if(capabilities & 0x00000200)
|
|
FPrintf(dump_smb_file," CAP_NT_FIND\n");
|
|
|
|
if(capabilities & 0x00000400)
|
|
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
|
|
|
|
if(capabilities & 0x00000800)
|
|
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
|
|
|
|
if(capabilities & 0x00001000)
|
|
FPrintf(dump_smb_file," CAP_DFS\n");
|
|
|
|
if(capabilities & 0x00002000)
|
|
FPrintf(dump_smb_file," CAP_QUADWORD_ALIGNED\n");
|
|
|
|
if(capabilities & 0x00004000)
|
|
FPrintf(dump_smb_file," CAP_LARGE_READX\n");
|
|
|
|
if(capabilities & 0x00008000)
|
|
FPrintf(dump_smb_file," CAP_LARGE_WRITEX\n");
|
|
|
|
if(capabilities & 0x00800000)
|
|
FPrintf(dump_smb_file," CAP_UNIX\n");
|
|
|
|
if(capabilities & 0x20000000)
|
|
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
|
|
|
|
if(capabilities & 0x40000000)
|
|
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
|
|
|
|
if(capabilities & 0x80000000)
|
|
FPrintf(dump_smb_file," CAP_EXTENDED_SECURITY\n");
|
|
|
|
next_data_qword(parameters,system_time,&offset);
|
|
|
|
FPrintf(dump_smb_file,"system time = 0x%08lx%08lx\n",system_time[0],system_time[1]);
|
|
FPrintf(dump_smb_file," %s\n",convert_filetime_to_string(system_time));
|
|
FPrintf(dump_smb_file,"server time zone = %ld\n",(signed short)next_data_word(parameters,&offset)); /* ZZZ this is a signed 16 bit integer */
|
|
|
|
challenge_length = next_data_byte(parameters,&offset);
|
|
FPrintf(dump_smb_file,"challenge length = %ld\n",challenge_length);
|
|
|
|
if(challenge_length > 0)
|
|
{
|
|
if(challenge_length == 8)
|
|
{
|
|
FPrintf(dump_smb_file,"challenge = %02lx %02lx %02lx %02lx %02lx %02lx %02lx %02lx\n",
|
|
data[0],data[1],data[2],data[3],
|
|
data[4],data[5],data[6],data[7]);
|
|
}
|
|
}
|
|
|
|
init_line_buffer(&lb);
|
|
|
|
offset = challenge_length;
|
|
output_offset = 0;
|
|
|
|
while(offset < num_data_bytes)
|
|
{
|
|
unicode_char = next_data_word(data,&offset);
|
|
if(unicode_char == 0)
|
|
break;
|
|
|
|
if(' ' <= unicode_char && unicode_char < 127)
|
|
{
|
|
char c = unicode_char;
|
|
|
|
copy_string_to_line_buffer(&lb,&c,1,output_offset);
|
|
output_offset++;
|
|
}
|
|
else
|
|
{
|
|
char code_string[40];
|
|
|
|
SPrintf(code_string,"<%02lx%02ld>",unicode_char >> 8,unicode_char & 0xff);
|
|
|
|
copy_string_to_line_buffer(&lb,code_string,strlen(code_string),output_offset);
|
|
output_offset += strlen(code_string);
|
|
}
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"Domain name = '%s'\n",lb.line);
|
|
}
|
|
else
|
|
{
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
FPrintf(dump_smb_file,"dialect index = %ld\n",vwv[0]);
|
|
}
|
|
}
|
|
}
|
|
else if (command == SMB_COM_SESSION_SETUP_ANDX)
|
|
{
|
|
char args[1024];
|
|
char * args_end;
|
|
int len;
|
|
const char * oem_password = "";
|
|
const char * unicode_password = "";
|
|
const char * account_name = "";
|
|
const char * primary_domain = "";
|
|
const char * native_os = "";
|
|
const char * native_lan_man = "";
|
|
|
|
if(num_data_bytes > 1023)
|
|
num_data_bytes = 1023;
|
|
|
|
memmove(args,data,num_data_bytes);
|
|
args[num_data_bytes] = '\0';
|
|
|
|
args_end = &args[num_data_bytes];
|
|
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int oem_password_length;
|
|
int unicode_password_length;
|
|
unsigned long capabilities;
|
|
|
|
FPrintf(dump_smb_file,"consumer's maximum buffer size = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"actual maximum multiplexed pending requests = %ld\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"vc number = %ld\n",vwv[2]);
|
|
FPrintf(dump_smb_file,"session key = 0x%08lx\n",(((unsigned long)vwv[4]) << 16) | vwv[3]);
|
|
|
|
oem_password_length = vwv[5];
|
|
FPrintf(dump_smb_file,"oem password length = %ld\n",oem_password_length);
|
|
|
|
unicode_password_length = vwv[6];
|
|
FPrintf(dump_smb_file,"unicode password length = %ld\n",unicode_password_length);
|
|
|
|
capabilities = (((unsigned long)vwv[10]) << 16) | vwv[9];
|
|
|
|
FPrintf(dump_smb_file,"capabilities = 0x%08lx\n",capabilities);
|
|
|
|
if(capabilities & 0x00000001)
|
|
FPrintf(dump_smb_file," CAP_RAW_MODE\n");
|
|
|
|
if(capabilities & 0x00000002)
|
|
FPrintf(dump_smb_file," CAP_MPX_MODE\n");
|
|
|
|
if(capabilities & 0x00000004)
|
|
FPrintf(dump_smb_file," CAP_UNICODE\n");
|
|
|
|
if(capabilities & 0x00000008)
|
|
FPrintf(dump_smb_file," CAP_LARGE_FILES\n");
|
|
|
|
if(capabilities & 0x00000010)
|
|
FPrintf(dump_smb_file," CAP_NT_SMBS\n");
|
|
|
|
if(capabilities & 0x00000020)
|
|
FPrintf(dump_smb_file," CAP_RPC_REMOTE_APIS\n");
|
|
|
|
if(capabilities & 0x00000040)
|
|
FPrintf(dump_smb_file," CAP_STATUS32\n");
|
|
|
|
if(capabilities & 0x00000080)
|
|
FPrintf(dump_smb_file," CAP_LEVEL_II_OPLOCKS\n");
|
|
|
|
if(capabilities & 0x00000100)
|
|
FPrintf(dump_smb_file," CAP_LOCK_AND_READ\n");
|
|
|
|
if(capabilities & 0x00000200)
|
|
FPrintf(dump_smb_file," CAP_NT_FIND\n");
|
|
|
|
if(capabilities & 0x00000400)
|
|
FPrintf(dump_smb_file," CAP_BULK_TRANSFER\n");
|
|
|
|
if(capabilities & 0x00000800)
|
|
FPrintf(dump_smb_file," CAP_COMPRESSED_DATA\n");
|
|
|
|
if(capabilities & 0x00001000)
|
|
FPrintf(dump_smb_file," CAP_DFS\n");
|
|
|
|
if(capabilities & 0x00002000)
|
|
FPrintf(dump_smb_file," CAP_QUADWORD_ALIGNED\n");
|
|
|
|
if(capabilities & 0x00004000)
|
|
FPrintf(dump_smb_file," CAP_LARGE_READX\n");
|
|
|
|
if(capabilities & 0x00800000)
|
|
FPrintf(dump_smb_file," CAP_UNIX\n");
|
|
|
|
if(capabilities & 0x80000000)
|
|
FPrintf(dump_smb_file," CAP_EXTENDED_SECURITY\n");
|
|
|
|
if(num_data_bytes > 0)
|
|
{
|
|
oem_password = args;
|
|
|
|
len = oem_password_length;
|
|
|
|
unicode_password = &oem_password[len];
|
|
if(unicode_password < args_end)
|
|
{
|
|
len = unicode_password_length;
|
|
|
|
/* There could be a padding byte here which
|
|
* aligns the account name to a word
|
|
* boundary.
|
|
*/
|
|
if((header->flags2 & SMB_FLAGS2_UNICODE_STRINGS) && (len % 2) == 1)
|
|
len++;
|
|
|
|
account_name = &unicode_password[len];
|
|
if(account_name < args_end)
|
|
{
|
|
len = strlen(account_name);
|
|
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
primary_domain = &account_name[len+1];
|
|
if(primary_domain < args_end)
|
|
{
|
|
len = strlen(primary_domain);
|
|
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
native_os = &primary_domain[len+1];
|
|
if(native_os < args_end)
|
|
{
|
|
len = strlen(native_os);
|
|
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
native_lan_man = &native_os[len+1];
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"account name = '%s'\n",account_name);
|
|
FPrintf(dump_smb_file,"primary domain = '%s'\n",primary_domain);
|
|
FPrintf(dump_smb_file,"native os = '%s'\n",native_os);
|
|
FPrintf(dump_smb_file,"native lan man = '%s'\n",native_lan_man);
|
|
}
|
|
else
|
|
{
|
|
int request_mode;
|
|
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
request_mode = vwv[0];
|
|
FPrintf(dump_smb_file,"request mode = 0x%04lx\n",request_mode);
|
|
|
|
if(request_mode & 0x0001)
|
|
FPrintf(dump_smb_file," SMB_SETUP_GUEST\n");
|
|
|
|
if(request_mode & 0x0002)
|
|
FPrintf(dump_smb_file," SMB_SETUP_USE_LANMAN_KEY\n");
|
|
|
|
if(num_data_bytes > 0)
|
|
{
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
native_os = args;
|
|
|
|
len = strlen(native_os);
|
|
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
native_lan_man = &native_os[len+1];
|
|
if(native_lan_man < args_end)
|
|
{
|
|
len = strlen(native_lan_man);
|
|
|
|
/* ZZZ could be Unicode if SMB_FLAGS2_UNICODE_STRINGS is set. */
|
|
primary_domain = &native_lan_man[len+1];
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"native os = '%s'\n",native_os);
|
|
FPrintf(dump_smb_file,"native lan man = '%s'\n",native_lan_man);
|
|
FPrintf(dump_smb_file,"primary domain = '%s'\n",primary_domain);
|
|
}
|
|
}
|
|
}
|
|
else if (command == SMB_COM_TREE_CONNECT_ANDX)
|
|
{
|
|
char args[1024];
|
|
|
|
if(num_data_bytes > 1023)
|
|
num_data_bytes = 1023;
|
|
|
|
memmove(args,data,num_data_bytes);
|
|
args[num_data_bytes] = '\0';
|
|
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
const char * path;
|
|
const char * password;
|
|
const char * dev_name;
|
|
int len;
|
|
int flags;
|
|
int password_length;
|
|
|
|
flags = vwv[0];
|
|
FPrintf(dump_smb_file,"flags = 0x%04lx\n",flags);
|
|
|
|
if(flags & 0x0001)
|
|
FPrintf(dump_smb_file," TREE_CONNECT_ANDX_DISCONNECT_TID\n");
|
|
|
|
password_length = vwv[1];
|
|
|
|
FPrintf(dump_smb_file,"password length = %ld\n",password_length);
|
|
|
|
password = args;
|
|
len = password_length;
|
|
|
|
/* There could be a padding byte here which
|
|
* aligns the account name to a word
|
|
* boundary.
|
|
*/
|
|
if((header->flags2 & SMB_FLAGS2_UNICODE_STRINGS) && (len % 2) == 1)
|
|
len++;
|
|
|
|
/* ZZZ could be a Unicode string. */
|
|
path = &password[len];
|
|
len = (int)strlen(path)+1;
|
|
|
|
dev_name = &path[len];
|
|
|
|
FPrintf(dump_smb_file,"path = '%s'\n",path);
|
|
// FPrintf(dump_smb_file,"password = '%s'\n",password);
|
|
FPrintf(dump_smb_file,"dev name = '%s'\n",dev_name);
|
|
}
|
|
else
|
|
{
|
|
int len;
|
|
const char * service;
|
|
const char * native_file_system;
|
|
|
|
if(num_data_bytes <= 0)
|
|
return;
|
|
|
|
service = args;
|
|
len = strlen(service)+1;
|
|
|
|
/* ZZZ this could be Unicode text. */
|
|
native_file_system = &service[len];
|
|
|
|
FPrintf(dump_smb_file,"service = '%s'\n",service);
|
|
FPrintf(dump_smb_file,"native file system = '%s'\n",native_file_system);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_QUERY_INFORMATION_DISK)
|
|
{
|
|
if(smb_packet_source == smb_packet_to_consumer && num_parameter_words > 3)
|
|
{
|
|
FPrintf(dump_smb_file,"allocation units/server = %ld\n",vwv[0]);
|
|
FPrintf(dump_smb_file,"blocks/allocation unit = %ld\n",vwv[1]);
|
|
FPrintf(dump_smb_file,"block size (in bytes) = %ld\n",vwv[2]);
|
|
FPrintf(dump_smb_file,"free allocation units = %ld\n",vwv[3]);
|
|
}
|
|
}
|
|
else if (command == SMB_COM_SEARCH)
|
|
{
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
{
|
|
int search_attributes;
|
|
const char * file_name;
|
|
const unsigned char * resume_key_data;
|
|
int resume_key_length;
|
|
int len;
|
|
int offset;
|
|
|
|
FPrintf(dump_smb_file,"max count = %ld\n",vwv[0]);
|
|
|
|
search_attributes = vwv[1];
|
|
FPrintf(dump_smb_file,"search attributes = 0x%04lx\n",search_attributes);
|
|
|
|
if(search_attributes & 0x0100)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_READONLY\n");
|
|
|
|
if(search_attributes & 0x0200)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(search_attributes & 0x0400)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(search_attributes & 0x1000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(search_attributes & 0x2000)
|
|
FPrintf(dump_smb_file," SMB_SEARCH_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
file_name = (char *)data;
|
|
len = strlen(file_name);
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",file_name[0]);
|
|
FPrintf(dump_smb_file,"file name = '%s'\n",file_name+1);
|
|
|
|
resume_key_data = (unsigned char *)&file_name[len+1];
|
|
offset = 0;
|
|
|
|
resume_key_length = next_data_word(resume_key_data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"resume key length = %ld\n",resume_key_length);
|
|
|
|
if(resume_key_length == 21)
|
|
{
|
|
unsigned char reserved;
|
|
const unsigned char * server_state;
|
|
const unsigned char * client_state;
|
|
|
|
reserved = next_data_byte(resume_key_data,&offset);
|
|
server_state = next_data_bytes(resume_key_data,16,&offset);
|
|
client_state = next_data_bytes(resume_key_data,4,&offset);
|
|
|
|
FPrintf(dump_smb_file,"resume key reserved = %02lx\n",reserved);
|
|
|
|
FPrintf(dump_smb_file,"resume key server state = ");
|
|
|
|
for(i = 0 ; i < 16 ; i++)
|
|
FPrintf(dump_smb_file,"%02lx",server_state[i]);
|
|
|
|
FPrintf(dump_smb_file,"\n");
|
|
|
|
FPrintf(dump_smb_file,"resume key client state = ");
|
|
|
|
for(i = 0 ; i < 4 ; i++)
|
|
FPrintf(dump_smb_file,"%02lx",client_state[i]);
|
|
|
|
FPrintf(dump_smb_file,"\n");
|
|
}
|
|
}
|
|
else
|
|
{
|
|
unsigned char reserved;
|
|
const unsigned char * server_state;
|
|
const unsigned char * client_state;
|
|
|
|
unsigned short last_write_date;
|
|
unsigned short last_write_time;
|
|
int count;
|
|
int offset;
|
|
int buffer_format;
|
|
int data_length;
|
|
int i,j;
|
|
int file_attributes;
|
|
const char * file_name;
|
|
|
|
if(num_parameter_words <= 0)
|
|
return;
|
|
|
|
count = vwv[0];
|
|
|
|
FPrintf(dump_smb_file,"count = %ld\n",count);
|
|
|
|
offset = 0;
|
|
|
|
buffer_format = next_data_byte(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"buffer format = %ld\n",buffer_format);
|
|
|
|
data_length = next_data_word(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"data length = %ld\n",data_length);
|
|
|
|
for(j = 0 ; j < count ; j++)
|
|
{
|
|
FPrintf(dump_smb_file,"directory entry [%ld]:\n",j);
|
|
|
|
reserved = next_data_byte(data,&offset);
|
|
server_state = next_data_bytes(data,16,&offset);
|
|
client_state = next_data_bytes(data,4,&offset);
|
|
|
|
FPrintf(dump_smb_file,"\tresume key reserved = %02lx\n",reserved);
|
|
|
|
FPrintf(dump_smb_file,"\tresume key server state = ");
|
|
|
|
for(i = 0 ; i < 16 ; i++)
|
|
FPrintf(dump_smb_file,"%02lx",server_state[i]);
|
|
|
|
FPrintf(dump_smb_file,"\n");
|
|
|
|
FPrintf(dump_smb_file,"\tresume key client state = ");
|
|
|
|
for(i = 0 ; i < 4 ; i++)
|
|
FPrintf(dump_smb_file,"%02lx",client_state[i]);
|
|
|
|
FPrintf(dump_smb_file,"\n");
|
|
|
|
file_attributes = next_data_byte(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"file attributes = 0x%04lx\n",file_attributes);
|
|
|
|
if((file_attributes & 0x001f) == 0)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_NORMAL\n");
|
|
|
|
if(file_attributes & 0x0001)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_READ_ONLY\n");
|
|
|
|
if(file_attributes & 0x0002)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_HIDDEN\n");
|
|
|
|
if(file_attributes & 0x0004)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_SYSTEM\n");
|
|
|
|
if(file_attributes & 0x0008)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_VOLUME\n");
|
|
|
|
if(file_attributes & 0x0010)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_DIRECTORY\n");
|
|
|
|
if(file_attributes & 0x0020)
|
|
FPrintf(dump_smb_file,"\t SMB_FILE_ATTRIBUTE_ARCHIVE\n");
|
|
|
|
last_write_time = next_data_word(data,&offset);
|
|
last_write_date = next_data_word(data,&offset);
|
|
|
|
FPrintf(dump_smb_file,"\tlast write time = 0x%04lx\n",last_write_time);
|
|
FPrintf(dump_smb_file,"\tlast write date = 0x%04lx\n",last_write_date);
|
|
FPrintf(dump_smb_file,"\tlast write = %s\n",convert_smb_date_time_to_string(last_write_date,last_write_time));
|
|
FPrintf(dump_smb_file,"\tfile size = %lu\n",next_data_dword(data,&offset));
|
|
|
|
file_name = (const char *)next_data_bytes(data,13,&offset);
|
|
|
|
FPrintf(dump_smb_file,"\tfile name = '%s'\n",file_name);
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static void
|
|
print_smb_parameters(int num_parameter_words,const unsigned char *parameters)
|
|
{
|
|
if(num_parameter_words > 0)
|
|
{
|
|
int word_value;
|
|
int i,j;
|
|
|
|
for(i = j = 0 ; i < num_parameter_words ; i++, j++)
|
|
{
|
|
word_value = parameters[j] + (((int)parameters[j+1]) << 8);
|
|
|
|
FPrintf(dump_smb_file," %04lx: %04lx (bytes: %02lx%02lx)\n",i,word_value,parameters[j],parameters[j+1]);
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
static void
|
|
print_smb_header(const struct smb_header * header,int header_length,const unsigned char *packet,
|
|
int packet_size,enum smb_packet_source_t smb_packet_source,int max_buffer_size)
|
|
{
|
|
enum errdos_t
|
|
{
|
|
errdos_badfunc=1,
|
|
errdos_badfile=2,
|
|
errdos_badpath=3,
|
|
errdos_nofids=4,
|
|
errdos_noaccess=5,
|
|
errdos_badfid=6,
|
|
errdos_badmcb=7,
|
|
errdos_nomem=8,
|
|
errdos_badmem=9,
|
|
errdos_badenv=10,
|
|
errdos_badformat=11,
|
|
errdos_badaccess=12,
|
|
errdos_baddata=13,
|
|
errdos_baddrive=15,
|
|
errdos_remcd=16,
|
|
errdos_diffdevice=17,
|
|
errdos_nofiles=18,
|
|
errdos_badshare=32,
|
|
errdos_lock=33,
|
|
errdos_filexists=80,
|
|
errdos_quota=512,
|
|
errdos_notALink=513,
|
|
};
|
|
|
|
enum errsrv_t
|
|
{
|
|
errsrv_error=1,
|
|
errsrv_badpw=2,
|
|
errsrv_access=4,
|
|
errsrv_invtid=5,
|
|
errsrv_invnetname=6,
|
|
errsrv_invdevice=7,
|
|
errsrv_qfull=49,
|
|
errsrv_qtoobig=50,
|
|
errsrv_qeof=51,
|
|
errsrv_invpfid=52,
|
|
errsrv_smbcmd=64,
|
|
errsrv_srverror=65,
|
|
errsrv_badBID=66,
|
|
errsrv_filespecs=67,
|
|
errsrv_badLink=68,
|
|
errsrv_badpermits=69,
|
|
errsrv_badPID=70,
|
|
errsrv_setattrmode=71,
|
|
errsrv_paused=81,
|
|
errsrv_msgoff=82,
|
|
errsrv_noroom=83,
|
|
errsrv_rmuns=87,
|
|
errsrv_timeout=88,
|
|
errsrv_noresource=89,
|
|
errsrv_toomanyuids=90,
|
|
errsrv_baduid=91,
|
|
errsrv_usempx=250,
|
|
errsrv_usestd=251,
|
|
errsrv_contmpx=252,
|
|
errsrv_badPassword=254,
|
|
errsrv_notifyEnumDir=1024,
|
|
errsrv_accountExpired=2239,
|
|
errsrv_badClient=2240,
|
|
errsrv_badLogonTime=2241,
|
|
errsrv_passwordExpired=2242,
|
|
errsrv_nosupport=65535,
|
|
};
|
|
|
|
enum errhrd_t
|
|
{
|
|
errhrd_nowrite=19,
|
|
errhrd_badunit=20,
|
|
errhrd_notready=21,
|
|
errhrd_badcmd=22,
|
|
errhrd_data=23,
|
|
errhrd_badreq=24,
|
|
errhrd_seek=25,
|
|
errhrd_badmedia=26,
|
|
errhrd_badsector=27,
|
|
errhrd_nopaper=28,
|
|
errhrd_write=29,
|
|
errhrd_read=30,
|
|
errhrd_general=31,
|
|
errhrd_badshare=32,
|
|
errhrd_lock=33,
|
|
errhrd_wrongdisk=34,
|
|
errhrd_FCBUnavail=35,
|
|
errhrd_sharebufexc=36,
|
|
};
|
|
|
|
enum nt_status_t
|
|
{
|
|
nt_status_unsuccessful=1,
|
|
nt_status_not_implemented=2,
|
|
nt_status_invalid_info_class=3,
|
|
nt_status_info_length_mismatch=4,
|
|
nt_status_access_violation=5,
|
|
nt_status_in_page_error=6,
|
|
nt_status_pagefile_quota=7,
|
|
nt_status_invalid_handle=8,
|
|
nt_status_bad_initial_stack=9,
|
|
nt_status_bad_initial_pc=10,
|
|
nt_status_invalid_cid=11,
|
|
nt_status_timer_not_canceled=12,
|
|
nt_status_invalid_parameter=13,
|
|
nt_status_no_such_device=14,
|
|
nt_status_no_such_file=15,
|
|
nt_status_invalid_device_request=16,
|
|
nt_status_end_of_file=17,
|
|
nt_status_wrong_volume=18,
|
|
nt_status_no_media_in_device=19,
|
|
nt_status_unrecognized_media=20,
|
|
nt_status_nonexistent_sector=21,
|
|
nt_status_more_processing_required=22,
|
|
nt_status_no_memory=23,
|
|
nt_status_conflicting_addresses=24,
|
|
nt_status_not_mapped_view=25,
|
|
nt_status_unable_to_free_vm=26,
|
|
nt_status_unable_to_delete_section=27,
|
|
nt_status_invalid_system_service=28,
|
|
nt_status_illegal_instruction=29,
|
|
nt_status_invalid_lock_sequence=30,
|
|
nt_status_invalid_view_size=31,
|
|
nt_status_invalid_file_for_section=32,
|
|
nt_status_already_committed=33,
|
|
nt_status_access_denied=34,
|
|
nt_status_buffer_too_small=35,
|
|
nt_status_object_type_mismatch=36,
|
|
nt_status_noncontinuable_exception=37,
|
|
nt_status_invalid_disposition=38,
|
|
nt_status_unwind=39,
|
|
nt_status_bad_stack=40,
|
|
nt_status_invalid_unwind_target=41,
|
|
nt_status_not_locked=42,
|
|
nt_status_parity_error=43,
|
|
nt_status_unable_to_decommit_vm=44,
|
|
nt_status_not_committed=45,
|
|
nt_status_invalid_port_attributes=46,
|
|
nt_status_port_message_too_long=47,
|
|
nt_status_invalid_parameter_mix=48,
|
|
nt_status_invalid_quota_lower=49,
|
|
nt_status_disk_corrupt_error=50,
|
|
nt_status_object_name_invalid=51,
|
|
nt_status_object_name_not_found=52,
|
|
nt_status_object_name_collision=53,
|
|
nt_status_handle_not_waitable=54,
|
|
nt_status_port_disconnected=55,
|
|
nt_status_device_already_attached=56,
|
|
nt_status_object_path_invalid=57,
|
|
nt_status_object_path_not_found=58,
|
|
nt_status_object_path_syntax_bad=59,
|
|
nt_status_data_overrun=60,
|
|
nt_status_data_late_error=61,
|
|
nt_status_data_error=62,
|
|
nt_status_crc_error=63,
|
|
nt_status_section_too_big=64,
|
|
nt_status_port_connection_refused=65,
|
|
nt_status_invalid_port_handle=66,
|
|
nt_status_sharing_violation=67,
|
|
nt_status_quota_exceeded=68,
|
|
nt_status_invalid_page_protection=69,
|
|
nt_status_mutant_not_owned=70,
|
|
nt_status_semaphore_limit_exceeded=71,
|
|
nt_status_port_already_set=72,
|
|
nt_status_section_not_image=73,
|
|
nt_status_suspend_count_exceeded=74,
|
|
nt_status_thread_is_terminating=75,
|
|
nt_status_bad_working_set_limit=76,
|
|
nt_status_incompatible_file_map=77,
|
|
nt_status_section_protection=78,
|
|
nt_status_eas_not_supported=79,
|
|
nt_status_ea_too_large=80,
|
|
nt_status_nonexistent_ea_entry=81,
|
|
nt_status_no_eas_on_file=82,
|
|
nt_status_ea_corrupt_error=83,
|
|
nt_status_file_lock_conflict=84,
|
|
nt_status_lock_not_granted=85,
|
|
nt_status_delete_pending=86,
|
|
nt_status_ctl_file_not_supported=87,
|
|
nt_status_unknown_revision=88,
|
|
nt_status_revision_mismatch=89,
|
|
nt_status_invalid_owner=90,
|
|
nt_status_invalid_primary_group=91,
|
|
nt_status_no_impersonation_token=92,
|
|
nt_status_cant_disable_mandatory=93,
|
|
nt_status_no_logon_servers=94,
|
|
nt_status_no_such_logon_session=95,
|
|
nt_status_no_such_privilege=96,
|
|
nt_status_privilege_not_held=97,
|
|
nt_status_invalid_account_name=98,
|
|
nt_status_user_exists=99,
|
|
nt_status_no_such_user=100,
|
|
nt_status_group_exists=101,
|
|
nt_status_no_such_group=102,
|
|
nt_status_member_in_group=103,
|
|
nt_status_member_not_in_group=104,
|
|
nt_status_last_admin=105,
|
|
nt_status_wrong_password=106,
|
|
nt_status_ill_formed_password=107,
|
|
nt_status_password_restriction=108,
|
|
nt_status_logon_failure=109,
|
|
nt_status_account_restriction=110,
|
|
nt_status_invalid_logon_hours=111,
|
|
nt_status_invalid_workstation=112,
|
|
nt_status_password_expired=113,
|
|
nt_status_account_disabled=114,
|
|
nt_status_none_mapped=115,
|
|
nt_status_too_many_luids_requested=116,
|
|
nt_status_luids_exhausted=117,
|
|
nt_status_invalid_sub_authority=118,
|
|
nt_status_invalid_acl=119,
|
|
nt_status_invalid_sid=120,
|
|
nt_status_invalid_security_descr=121,
|
|
nt_status_procedure_not_found=122,
|
|
nt_status_invalid_image_format=123,
|
|
nt_status_no_token=124,
|
|
nt_status_bad_inheritance_acl=125,
|
|
nt_status_range_not_locked=126,
|
|
nt_status_disk_full=127,
|
|
nt_status_server_disabled=128,
|
|
nt_status_server_not_disabled=129,
|
|
nt_status_too_many_guids_requested=130,
|
|
nt_status_guids_exhausted=131,
|
|
nt_status_invalid_id_authority=132,
|
|
nt_status_agents_exhausted=133,
|
|
nt_status_invalid_volume_label=134,
|
|
nt_status_section_not_extended=135,
|
|
nt_status_not_mapped_data=136,
|
|
nt_status_resource_data_not_found=137,
|
|
nt_status_resource_type_not_found=138,
|
|
nt_status_resource_name_not_found=139,
|
|
nt_status_array_bounds_exceeded=140,
|
|
nt_status_float_denormal_operand=141,
|
|
nt_status_float_divide_by_zero=142,
|
|
nt_status_float_inexact_result=143,
|
|
nt_status_float_invalid_operation=144,
|
|
nt_status_float_overflow=145,
|
|
nt_status_float_stack_check=146,
|
|
nt_status_float_underflow=147,
|
|
nt_status_integer_divide_by_zero=148,
|
|
nt_status_integer_overflow=149,
|
|
nt_status_privileged_instruction=150,
|
|
nt_status_too_many_paging_files=151,
|
|
nt_status_file_invalid=152,
|
|
nt_status_allotted_space_exceeded=153,
|
|
nt_status_insufficient_resources=154,
|
|
nt_status_dfs_exit_path_found=155,
|
|
nt_status_device_data_error=156,
|
|
nt_status_device_not_connected=157,
|
|
nt_status_device_power_failure=158,
|
|
nt_status_free_vm_not_at_base=159,
|
|
nt_status_memory_not_allocated=160,
|
|
nt_status_working_set_quota=161,
|
|
nt_status_media_write_protected=162,
|
|
nt_status_device_not_ready=163,
|
|
nt_status_invalid_group_attributes=164,
|
|
nt_status_bad_impersonation_level=165,
|
|
nt_status_cant_open_anonymous=166,
|
|
nt_status_bad_validation_class=167,
|
|
nt_status_bad_token_type=168,
|
|
nt_status_bad_master_boot_record=169,
|
|
nt_status_instruction_misalignment=170,
|
|
nt_status_instance_not_available=171,
|
|
nt_status_pipe_not_available=172,
|
|
nt_status_invalid_pipe_state=173,
|
|
nt_status_pipe_busy=174,
|
|
nt_status_illegal_function=175,
|
|
nt_status_pipe_disconnected=176,
|
|
nt_status_pipe_closing=177,
|
|
nt_status_pipe_connected=178,
|
|
nt_status_pipe_listening=179,
|
|
nt_status_invalid_read_mode=180,
|
|
nt_status_io_timeout=181,
|
|
nt_status_file_forced_closed=182,
|
|
nt_status_profiling_not_started=183,
|
|
nt_status_profiling_not_stopped=184,
|
|
nt_status_could_not_interpret=185,
|
|
nt_status_file_is_a_directory=186,
|
|
nt_status_not_supported=187,
|
|
nt_status_remote_not_listening=188,
|
|
nt_status_duplicate_name=189,
|
|
nt_status_bad_network_path=190,
|
|
nt_status_network_busy=191,
|
|
nt_status_device_does_not_exist=192,
|
|
nt_status_too_many_commands=193,
|
|
nt_status_adapter_hardware_error=194,
|
|
nt_status_invalid_network_response=195,
|
|
nt_status_unexpected_network_error=196,
|
|
nt_status_bad_remote_adapter=197,
|
|
nt_status_print_queue_full=198,
|
|
nt_status_no_spool_space=199,
|
|
nt_status_print_cancelled=200,
|
|
nt_status_network_name_deleted=201,
|
|
nt_status_network_access_denied=202,
|
|
nt_status_bad_device_type=203,
|
|
nt_status_bad_network_name=204,
|
|
nt_status_too_many_names=205,
|
|
nt_status_too_many_sessions=206,
|
|
nt_status_sharing_paused=207,
|
|
nt_status_request_not_accepted=208,
|
|
nt_status_redirector_paused=209,
|
|
nt_status_net_write_fault=210,
|
|
nt_status_profiling_at_limit=211,
|
|
nt_status_not_same_device=212,
|
|
nt_status_file_renamed=213,
|
|
nt_status_virtual_circuit_closed=214,
|
|
nt_status_no_security_on_object=215,
|
|
nt_status_cant_wait=216,
|
|
nt_status_pipe_empty=217,
|
|
nt_status_cant_access_domain_info=218,
|
|
nt_status_cant_terminate_self=219,
|
|
nt_status_invalid_server_state=220,
|
|
nt_status_invalid_domain_state=221,
|
|
nt_status_invalid_domain_role=222,
|
|
nt_status_no_such_domain=223,
|
|
nt_status_domain_exists=224,
|
|
nt_status_domain_limit_exceeded=225,
|
|
nt_status_oplock_not_granted=226,
|
|
nt_status_invalid_oplock_protocol=227,
|
|
nt_status_internal_db_corruption=228,
|
|
nt_status_internal_error=229,
|
|
nt_status_generic_not_mapped=230,
|
|
nt_status_bad_descriptor_format=231,
|
|
nt_status_invalid_user_buffer=232,
|
|
nt_status_unexpected_io_error=233,
|
|
nt_status_unexpected_mm_create_err=234,
|
|
nt_status_unexpected_mm_map_error=235,
|
|
nt_status_unexpected_mm_extend_err=236,
|
|
nt_status_not_logon_process=237,
|
|
nt_status_logon_session_exists=238,
|
|
nt_status_invalid_parameter_1=239,
|
|
nt_status_invalid_parameter_2=240,
|
|
nt_status_invalid_parameter_3=241,
|
|
nt_status_invalid_parameter_4=242,
|
|
nt_status_invalid_parameter_5=243,
|
|
nt_status_invalid_parameter_6=244,
|
|
nt_status_invalid_parameter_7=245,
|
|
nt_status_invalid_parameter_8=246,
|
|
nt_status_invalid_parameter_9=247,
|
|
nt_status_invalid_parameter_10=248,
|
|
nt_status_invalid_parameter_11=249,
|
|
nt_status_invalid_parameter_12=250,
|
|
nt_status_redirector_not_started=251,
|
|
nt_status_redirector_started=252,
|
|
nt_status_stack_overflow=253,
|
|
nt_status_no_such_package=254,
|
|
nt_status_bad_function_table=255,
|
|
nt_status_directory_not_empty=257,
|
|
nt_status_file_corrupt_error=258,
|
|
nt_status_not_a_directory=259,
|
|
nt_status_bad_logon_session_state=260,
|
|
nt_status_logon_session_collision=261,
|
|
nt_status_name_too_long=262,
|
|
nt_status_files_open=263,
|
|
nt_status_connection_in_use=264,
|
|
nt_status_message_not_found=265,
|
|
nt_status_process_is_terminating=266,
|
|
nt_status_invalid_logon_type=267,
|
|
nt_status_no_guid_translation=268,
|
|
nt_status_cannot_impersonate=269,
|
|
nt_status_image_already_loaded=270,
|
|
nt_status_abios_not_present=271,
|
|
nt_status_abios_lid_not_exist=272,
|
|
nt_status_abios_lid_already_owned=273,
|
|
nt_status_abios_not_lid_owner=274,
|
|
nt_status_abios_invalid_command=275,
|
|
nt_status_abios_invalid_lid=276,
|
|
nt_status_abios_selector_not_available=277,
|
|
nt_status_abios_invalid_selector=278,
|
|
nt_status_no_ldt=279,
|
|
nt_status_invalid_ldt_size=280,
|
|
nt_status_invalid_ldt_offset=281,
|
|
nt_status_invalid_ldt_descriptor=282,
|
|
nt_status_invalid_image_ne_format=283,
|
|
nt_status_rxact_invalid_state=284,
|
|
nt_status_rxact_commit_failure=285,
|
|
nt_status_mapped_file_size_zero=286,
|
|
nt_status_too_many_opened_files=287,
|
|
nt_status_cancelled=288,
|
|
nt_status_cannot_delete=289,
|
|
nt_status_invalid_computer_name=290,
|
|
nt_status_file_deleted=291,
|
|
nt_status_special_account=292,
|
|
nt_status_special_group=293,
|
|
nt_status_special_user=294,
|
|
nt_status_members_primary_group=295,
|
|
nt_status_file_closed=296,
|
|
nt_status_too_many_threads=297,
|
|
nt_status_thread_not_in_process=298,
|
|
nt_status_token_already_in_use=299,
|
|
nt_status_pagefile_quota_exceeded=300,
|
|
nt_status_commitment_limit=301,
|
|
nt_status_invalid_image_le_format=302,
|
|
nt_status_invalid_image_not_mz=303,
|
|
nt_status_invalid_image_protect=304,
|
|
nt_status_invalid_image_win_16=305,
|
|
nt_status_logon_server_conflict=306,
|
|
nt_status_time_difference_at_dc=307,
|
|
nt_status_synchronization_required=308,
|
|
nt_status_dll_not_found=309,
|
|
nt_status_open_failed=310,
|
|
nt_status_io_privilege_failed=311,
|
|
nt_status_ordinal_not_found=312,
|
|
nt_status_entrypoint_not_found=313,
|
|
nt_status_control_c_exit=314,
|
|
nt_status_local_disconnect=315,
|
|
nt_status_remote_disconnect=316,
|
|
nt_status_remote_resources=317,
|
|
nt_status_link_failed=318,
|
|
nt_status_link_timeout=319,
|
|
nt_status_invalid_connection=320,
|
|
nt_status_invalid_address=321,
|
|
nt_status_dll_init_failed=322,
|
|
nt_status_missing_systemfile=323,
|
|
nt_status_unhandled_exception=324,
|
|
nt_status_app_init_failure=325,
|
|
nt_status_pagefile_create_failed=326,
|
|
nt_status_no_pagefile=327,
|
|
nt_status_invalid_level=328,
|
|
nt_status_wrong_password_core=329,
|
|
nt_status_illegal_float_context=330,
|
|
nt_status_pipe_broken=331,
|
|
nt_status_registry_corrupt=332,
|
|
nt_status_registry_io_failed=333,
|
|
nt_status_no_event_pair=334,
|
|
nt_status_unrecognized_volume=335,
|
|
nt_status_serial_no_device_inited=336,
|
|
nt_status_no_such_alias=337,
|
|
nt_status_member_not_in_alias=338,
|
|
nt_status_member_in_alias=339,
|
|
nt_status_alias_exists=340,
|
|
nt_status_logon_not_granted=341,
|
|
nt_status_too_many_secrets=342,
|
|
nt_status_secret_too_long=343,
|
|
nt_status_internal_db_error=344,
|
|
nt_status_fullscreen_mode=345,
|
|
nt_status_too_many_context_ids=346,
|
|
nt_status_logon_type_not_granted=347,
|
|
nt_status_not_registry_file=348,
|
|
nt_status_nt_cross_encryption_required=349,
|
|
nt_status_domain_ctrlr_config_error=350,
|
|
nt_status_ft_missing_member=351,
|
|
nt_status_ill_formed_service_entry=352,
|
|
nt_status_illegal_character=353,
|
|
nt_status_unmappable_character=354,
|
|
nt_status_undefined_character=355,
|
|
nt_status_floppy_volume=356,
|
|
nt_status_floppy_id_mark_not_found=357,
|
|
nt_status_floppy_wrong_cylinder=358,
|
|
nt_status_floppy_unknown_error=359,
|
|
nt_status_floppy_bad_registers=360,
|
|
nt_status_disk_recalibrate_failed=361,
|
|
nt_status_disk_operation_failed=362,
|
|
nt_status_disk_reset_failed=363,
|
|
nt_status_shared_irq_busy=364,
|
|
nt_status_ft_orphaning=365,
|
|
nt_status_partition_failure=370,
|
|
nt_status_invalid_block_length=371,
|
|
nt_status_device_not_partitioned=372,
|
|
nt_status_unable_to_lock_media=373,
|
|
nt_status_unable_to_unload_media=374,
|
|
nt_status_eom_overflow=375,
|
|
nt_status_no_media=376,
|
|
nt_status_no_such_member=378,
|
|
nt_status_invalid_member=379,
|
|
nt_status_key_deleted=380,
|
|
nt_status_no_log_space=381,
|
|
nt_status_too_many_sids=382,
|
|
nt_status_lm_cross_encryption_required=383,
|
|
nt_status_key_has_children=384,
|
|
nt_status_child_must_be_volatile=385,
|
|
nt_status_device_configuration_error=386,
|
|
nt_status_driver_internal_error=387,
|
|
nt_status_invalid_device_state=388,
|
|
nt_status_io_device_error=389,
|
|
nt_status_device_protocol_error=390,
|
|
nt_status_backup_controller=391,
|
|
nt_status_log_file_full=392,
|
|
nt_status_too_late=393,
|
|
nt_status_no_trust_lsa_secret=394,
|
|
nt_status_no_trust_sam_account=395,
|
|
nt_status_trusted_domain_failure=396,
|
|
nt_status_trusted_relationship_failure=397,
|
|
nt_status_eventlog_file_corrupt=398,
|
|
nt_status_eventlog_cant_start=399,
|
|
nt_status_trust_failure=400,
|
|
nt_status_mutant_limit_exceeded=401,
|
|
nt_status_netlogon_not_started=402,
|
|
nt_status_account_expired=403,
|
|
nt_status_possible_deadlock=404,
|
|
nt_status_network_credential_conflict=405,
|
|
nt_status_remote_session_limit=406,
|
|
nt_status_eventlog_file_changed=407,
|
|
nt_status_nologon_interdomain_trust_account=408,
|
|
nt_status_nologon_workstation_trust_account=409,
|
|
nt_status_nologon_server_trust_account=410,
|
|
nt_status_domain_trust_inconsistent=411,
|
|
nt_status_fs_driver_required=412,
|
|
nt_status_no_user_session_key=514,
|
|
nt_status_user_session_deleted=515,
|
|
nt_status_resource_lang_not_found=516,
|
|
nt_status_insuff_server_resources=517,
|
|
nt_status_invalid_buffer_size=518,
|
|
nt_status_invalid_address_component=519,
|
|
nt_status_invalid_address_wildcard=520,
|
|
nt_status_too_many_addresses=521,
|
|
nt_status_address_already_exists=522,
|
|
nt_status_address_closed=523,
|
|
nt_status_connection_disconnected=524,
|
|
nt_status_connection_reset=525,
|
|
nt_status_too_many_nodes=526,
|
|
nt_status_transaction_aborted=527,
|
|
nt_status_transaction_timed_out=528,
|
|
nt_status_transaction_no_release=529,
|
|
nt_status_transaction_no_match=530,
|
|
nt_status_transaction_responded=531,
|
|
nt_status_transaction_invalid_id=532,
|
|
nt_status_transaction_invalid_type=533,
|
|
nt_status_not_server_session=534,
|
|
nt_status_not_client_session=535,
|
|
nt_status_cannot_load_registry_file=536,
|
|
nt_status_debug_attach_failed=537,
|
|
nt_status_system_process_terminated=538,
|
|
nt_status_data_not_accepted=539,
|
|
nt_status_no_browser_servers_found=540,
|
|
nt_status_vdm_hard_error=541,
|
|
nt_status_driver_cancel_timeout=542,
|
|
nt_status_reply_message_mismatch=543,
|
|
nt_status_mapped_alignment=544,
|
|
nt_status_image_checksum_mismatch=545,
|
|
nt_status_lost_writebehind_data=546,
|
|
nt_status_client_server_parameters_invalid=547,
|
|
nt_status_password_must_change=548,
|
|
nt_status_not_found=549,
|
|
nt_status_not_tiny_stream=550,
|
|
nt_status_recovery_failure=551,
|
|
nt_status_stack_overflow_read=552,
|
|
nt_status_fail_check=553,
|
|
nt_status_duplicate_objectid=554,
|
|
nt_status_objectid_exists=555,
|
|
nt_status_convert_to_large=556,
|
|
nt_status_retry=557,
|
|
nt_status_found_out_of_scope=558,
|
|
nt_status_allocate_bucket=559,
|
|
nt_status_propset_not_found=560,
|
|
nt_status_marshall_overflow=561,
|
|
nt_status_invalid_variant=562,
|
|
nt_status_domain_controller_not_found=563,
|
|
nt_status_account_locked_out=564,
|
|
nt_status_handle_not_closable=565,
|
|
nt_status_connection_refused=566,
|
|
nt_status_graceful_disconnect=567,
|
|
nt_status_address_already_associated=568,
|
|
nt_status_address_not_associated=569,
|
|
nt_status_connection_invalid=570,
|
|
nt_status_connection_active=571,
|
|
nt_status_network_unreachable=572,
|
|
nt_status_host_unreachable=573,
|
|
nt_status_protocol_unreachable=574,
|
|
nt_status_port_unreachable=575,
|
|
nt_status_request_aborted=576,
|
|
nt_status_connection_aborted=577,
|
|
nt_status_bad_compression_buffer=578,
|
|
nt_status_user_mapped_file=579,
|
|
nt_status_audit_failed=580,
|
|
nt_status_timer_resolution_not_set=581,
|
|
nt_status_connection_count_limit=582,
|
|
nt_status_login_time_restriction=583,
|
|
nt_status_login_wksta_restriction=584,
|
|
nt_status_image_mp_up_mismatch=585,
|
|
nt_status_insufficient_logon_info=592,
|
|
nt_status_bad_dll_entrypoint=593,
|
|
nt_status_bad_service_entrypoint=594,
|
|
nt_status_lpc_reply_lost=595,
|
|
nt_status_ip_address_conflict1=596,
|
|
nt_status_ip_address_conflict2=597,
|
|
nt_status_registry_quota_limit=598,
|
|
nt_status_path_not_covered=599,
|
|
nt_status_no_callback_active=600,
|
|
nt_status_license_quota_exceeded=601,
|
|
nt_status_pwd_too_short=602,
|
|
nt_status_pwd_too_recent=603,
|
|
nt_status_pwd_history_conflict=604,
|
|
nt_status_plugplay_no_device=606,
|
|
nt_status_unsupported_compression=607,
|
|
nt_status_invalid_hw_profile=608,
|
|
nt_status_invalid_plugplay_device_path=609,
|
|
nt_status_driver_ordinal_not_found=610,
|
|
nt_status_driver_entrypoint_not_found=611,
|
|
nt_status_resource_not_owned=612,
|
|
nt_status_too_many_links=613,
|
|
nt_status_quota_list_inconsistent=614,
|
|
nt_status_file_is_offline=615,
|
|
// nt_status_notify_enum_dir=268,
|
|
};
|
|
|
|
struct error_label_entry
|
|
{
|
|
int code;
|
|
const char * label;
|
|
};
|
|
|
|
static const struct error_label_entry dos_errors[] =
|
|
{
|
|
{ 0, "not specified" },
|
|
{ errdos_badfunc, "bad func" },
|
|
{ errdos_badfile, "bad file" },
|
|
{ errdos_badpath, "bad path" },
|
|
{ errdos_nofids, "no fids" },
|
|
{ errdos_noaccess, "no access" },
|
|
{ errdos_badfid, "bad fid" },
|
|
{ errdos_badmcb, "bad mcb" },
|
|
{ errdos_nomem, "no mem" },
|
|
{ errdos_badmem, "bad mem" },
|
|
{ errdos_badenv, "bad env" },
|
|
{ errdos_badformat, "bad format" },
|
|
{ errdos_badaccess, "bad access" },
|
|
{ errdos_baddata, "bad data" },
|
|
{ errdos_baddrive, "bad drive" },
|
|
{ errdos_remcd, "rem cd" },
|
|
{ errdos_diffdevice, "diff device" },
|
|
{ errdos_nofiles, "no files" },
|
|
{ errdos_badshare, "bad share" },
|
|
{ errdos_lock, "lock" },
|
|
{ errdos_filexists, "file exists" },
|
|
{ errdos_quota, "quota" },
|
|
{ errdos_notALink, "not a link" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
static const struct error_label_entry server_errors[] =
|
|
{
|
|
{ 0, "not specified" },
|
|
{ errsrv_error, "error" },
|
|
{ errsrv_badpw, "bad pw" },
|
|
{ errsrv_access, "access" },
|
|
{ errsrv_invtid, "inv tid" },
|
|
{ errsrv_invnetname, "inv net name" },
|
|
{ errsrv_invdevice, "inv device" },
|
|
{ errsrv_qfull, "q full" },
|
|
{ errsrv_qtoobig, "q toobig" },
|
|
{ errsrv_qeof, "q eof" },
|
|
{ errsrv_invpfid, "inv pfid" },
|
|
{ errsrv_smbcmd, "smb cmd" },
|
|
{ errsrv_srverror, "srv error" },
|
|
{ errsrv_badBID, "bad BID" },
|
|
{ errsrv_filespecs, "file specs" },
|
|
{ errsrv_badLink, "bad link" },
|
|
{ errsrv_badpermits, "bad permits" },
|
|
{ errsrv_badPID, "bad PID" },
|
|
{ errsrv_setattrmode, "setattr mode" },
|
|
{ errsrv_paused, "paused" },
|
|
{ errsrv_msgoff, "msg off" },
|
|
{ errsrv_noroom, "no room" },
|
|
{ errsrv_rmuns, "rmuns" },
|
|
{ errsrv_timeout, "timeout" },
|
|
{ errsrv_noresource, "no resource" },
|
|
{ errsrv_toomanyuids, "too many uids" },
|
|
{ errsrv_baduid, "bad uid" },
|
|
{ errsrv_usempx, "use mpx" },
|
|
{ errsrv_usestd, "use std" },
|
|
{ errsrv_contmpx, "cont mpx" },
|
|
{ errsrv_badPassword, "ba DPassword" },
|
|
{ errsrv_notifyEnumDir, "notify enum dir" },
|
|
{ errsrv_accountExpired, "account expired" },
|
|
{ errsrv_badClient, "bad client" },
|
|
{ errsrv_badLogonTime, "bad logon time" },
|
|
{ errsrv_passwordExpired, "password expired" },
|
|
{ errsrv_nosupport, "no support" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
static const struct error_label_entry hardware_errors[] =
|
|
{
|
|
{ 0, "not specified" },
|
|
{ errhrd_nowrite, "no write" },
|
|
{ errhrd_badunit, "bad unit" },
|
|
{ errhrd_notready, "not ready" },
|
|
{ errhrd_badcmd, "bad cmd" },
|
|
{ errhrd_data, "data" },
|
|
{ errhrd_badreq, "bad req" },
|
|
{ errhrd_seek, "seek" },
|
|
{ errhrd_badmedia, "bad media" },
|
|
{ errhrd_badsector, "bad sector" },
|
|
{ errhrd_nopaper, "no paper" },
|
|
{ errhrd_write, "write" },
|
|
{ errhrd_read, "read" },
|
|
{ errhrd_general, "general" },
|
|
{ errhrd_badshare, "bad share" },
|
|
{ errhrd_lock, "lock" },
|
|
{ errhrd_wrongdisk, "wrong disk" },
|
|
{ errhrd_FCBUnavail, "FCB unavail" },
|
|
{ errhrd_sharebufexc, "share buf exc" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
static const struct error_label_entry nt_error_codes[] =
|
|
{
|
|
{ 0, "not specified" },
|
|
{ nt_status_unsuccessful, "unsuccessful" },
|
|
{ nt_status_not_implemented, "not implemented" },
|
|
{ nt_status_invalid_info_class, "invalid info class" },
|
|
{ nt_status_info_length_mismatch, "info length mismatch" },
|
|
{ nt_status_access_violation, "access violation" },
|
|
{ nt_status_in_page_error, "in page error" },
|
|
{ nt_status_pagefile_quota, "pagefile quota" },
|
|
{ nt_status_invalid_handle, "invalid handle" },
|
|
{ nt_status_bad_initial_stack, "bad initial stack" },
|
|
{ nt_status_bad_initial_pc, "bad initial pc" },
|
|
{ nt_status_invalid_cid, "invalid cid" },
|
|
{ nt_status_timer_not_canceled, "timer not canceled" },
|
|
{ nt_status_invalid_parameter, "invalid parameter" },
|
|
{ nt_status_no_such_device, "no such device" },
|
|
{ nt_status_no_such_file, "no such file" },
|
|
{ nt_status_invalid_device_request, "invalid device request" },
|
|
{ nt_status_end_of_file, "end of file" },
|
|
{ nt_status_wrong_volume, "wrong volume" },
|
|
{ nt_status_no_media_in_device, "no media in device" },
|
|
{ nt_status_unrecognized_media, "unrecognized media" },
|
|
{ nt_status_nonexistent_sector, "nonexistent sector" },
|
|
{ nt_status_more_processing_required, "more processing required" },
|
|
{ nt_status_no_memory, "no memory" },
|
|
{ nt_status_conflicting_addresses, "conflicting addresses" },
|
|
{ nt_status_not_mapped_view, "not mapped view" },
|
|
{ nt_status_unable_to_free_vm, "unable to free vm" },
|
|
{ nt_status_unable_to_delete_section, "unable to delete section" },
|
|
{ nt_status_invalid_system_service, "invalid system service" },
|
|
{ nt_status_illegal_instruction, "illegal instruction" },
|
|
{ nt_status_invalid_lock_sequence, "invalid lock sequence" },
|
|
{ nt_status_invalid_view_size, "invalid view size" },
|
|
{ nt_status_invalid_file_for_section, "invalid file for section" },
|
|
{ nt_status_already_committed, "already committed" },
|
|
{ nt_status_access_denied, "access denied" },
|
|
{ nt_status_buffer_too_small, "buffer too small" },
|
|
{ nt_status_object_type_mismatch, "object type mismatch" },
|
|
{ nt_status_noncontinuable_exception, "noncontinuable exception" },
|
|
{ nt_status_invalid_disposition, "invalid disposition" },
|
|
{ nt_status_unwind, "unwind" },
|
|
{ nt_status_bad_stack, "bad stack" },
|
|
{ nt_status_invalid_unwind_target, "invalid unwind target" },
|
|
{ nt_status_not_locked, "not locked" },
|
|
{ nt_status_parity_error, "parity error" },
|
|
{ nt_status_unable_to_decommit_vm, "unable to decommit vm" },
|
|
{ nt_status_not_committed, "not committed" },
|
|
{ nt_status_invalid_port_attributes, "invalid port attributes" },
|
|
{ nt_status_port_message_too_long, "port message too long" },
|
|
{ nt_status_invalid_parameter_mix, "invalid parameter mix" },
|
|
{ nt_status_invalid_quota_lower, "invalid quota lower" },
|
|
{ nt_status_disk_corrupt_error, "disk corrupt error" },
|
|
{ nt_status_object_name_invalid, "object name invalid" },
|
|
{ nt_status_object_name_not_found, "object name not found" },
|
|
{ nt_status_object_name_collision, "object name collision" },
|
|
{ nt_status_handle_not_waitable, "handle not waitable" },
|
|
{ nt_status_port_disconnected, "port disconnected" },
|
|
{ nt_status_device_already_attached, "device already attached" },
|
|
{ nt_status_object_path_invalid, "object path invalid" },
|
|
{ nt_status_object_path_not_found, "object path not found" },
|
|
{ nt_status_object_path_syntax_bad, "object path syntax bad" },
|
|
{ nt_status_data_overrun, "data overrun" },
|
|
{ nt_status_data_late_error, "data late error" },
|
|
{ nt_status_data_error, "data error" },
|
|
{ nt_status_crc_error, "crc error" },
|
|
{ nt_status_section_too_big, "section too big" },
|
|
{ nt_status_port_connection_refused, "port connection refused" },
|
|
{ nt_status_invalid_port_handle, "invalid port handle" },
|
|
{ nt_status_sharing_violation, "sharing violation" },
|
|
{ nt_status_quota_exceeded, "quota exceeded" },
|
|
{ nt_status_invalid_page_protection, "invalid page protection" },
|
|
{ nt_status_mutant_not_owned, "mutant not owned" },
|
|
{ nt_status_semaphore_limit_exceeded, "semaphore limit exceeded" },
|
|
{ nt_status_port_already_set, "port already set" },
|
|
{ nt_status_section_not_image, "section not image" },
|
|
{ nt_status_suspend_count_exceeded, "suspend count exceeded" },
|
|
{ nt_status_thread_is_terminating, "thread is terminating" },
|
|
{ nt_status_bad_working_set_limit, "bad working set limit" },
|
|
{ nt_status_incompatible_file_map, "incompatible file map" },
|
|
{ nt_status_section_protection, "section protection" },
|
|
{ nt_status_eas_not_supported, "eas not supported" },
|
|
{ nt_status_ea_too_large, "ea too large" },
|
|
{ nt_status_nonexistent_ea_entry, "nonexistent ea entry" },
|
|
{ nt_status_no_eas_on_file, "no eas on file" },
|
|
{ nt_status_ea_corrupt_error, "ea corrupt error" },
|
|
{ nt_status_file_lock_conflict, "file lock conflict" },
|
|
{ nt_status_lock_not_granted, "lock not granted" },
|
|
{ nt_status_delete_pending, "delete pending" },
|
|
{ nt_status_ctl_file_not_supported, "ctl file not supported" },
|
|
{ nt_status_unknown_revision, "unknown revision" },
|
|
{ nt_status_revision_mismatch, "revision mismatch" },
|
|
{ nt_status_invalid_owner, "invalid owner" },
|
|
{ nt_status_invalid_primary_group, "invalid primary group" },
|
|
{ nt_status_no_impersonation_token, "no impersonation token" },
|
|
{ nt_status_cant_disable_mandatory, "cant disable mandatory" },
|
|
{ nt_status_no_logon_servers, "no logon servers" },
|
|
{ nt_status_no_such_logon_session, "no such logon session" },
|
|
{ nt_status_no_such_privilege, "no such privilege" },
|
|
{ nt_status_privilege_not_held, "privilege not held" },
|
|
{ nt_status_invalid_account_name, "invalid account name" },
|
|
{ nt_status_user_exists, "user exists" },
|
|
{ nt_status_no_such_user, "no such user" },
|
|
{ nt_status_group_exists, "group exists" },
|
|
{ nt_status_no_such_group, "no such group" },
|
|
{ nt_status_member_in_group, "member in group" },
|
|
{ nt_status_member_not_in_group, "member not in group" },
|
|
{ nt_status_last_admin, "last admin" },
|
|
{ nt_status_wrong_password, "wrong password" },
|
|
{ nt_status_ill_formed_password, "ill formed password" },
|
|
{ nt_status_password_restriction, "password restriction" },
|
|
{ nt_status_logon_failure, "logon failure" },
|
|
{ nt_status_account_restriction, "account restriction" },
|
|
{ nt_status_invalid_logon_hours, "invalid logon hours" },
|
|
{ nt_status_invalid_workstation, "invalid workstation" },
|
|
{ nt_status_password_expired, "password expired" },
|
|
{ nt_status_account_disabled, "account disabled" },
|
|
{ nt_status_none_mapped, "none mapped" },
|
|
{ nt_status_too_many_luids_requested, "too many luids requested" },
|
|
{ nt_status_luids_exhausted, "luids exhausted" },
|
|
{ nt_status_invalid_sub_authority, "invalid sub authority" },
|
|
{ nt_status_invalid_acl, "invalid acl" },
|
|
{ nt_status_invalid_sid, "invalid sid" },
|
|
{ nt_status_invalid_security_descr, "invalid security descr" },
|
|
{ nt_status_procedure_not_found, "procedure not found" },
|
|
{ nt_status_invalid_image_format, "invalid image format" },
|
|
{ nt_status_no_token, "no token" },
|
|
{ nt_status_bad_inheritance_acl, "bad inheritance acl" },
|
|
{ nt_status_range_not_locked, "range not locked" },
|
|
{ nt_status_disk_full, "disk full" },
|
|
{ nt_status_server_disabled, "server disabled" },
|
|
{ nt_status_server_not_disabled, "server not disabled" },
|
|
{ nt_status_too_many_guids_requested, "too many guids requested" },
|
|
{ nt_status_guids_exhausted, "guids exhausted" },
|
|
{ nt_status_invalid_id_authority, "invalid id authority" },
|
|
{ nt_status_agents_exhausted, "agents exhausted" },
|
|
{ nt_status_invalid_volume_label, "invalid volume label" },
|
|
{ nt_status_section_not_extended, "section not extended" },
|
|
{ nt_status_not_mapped_data, "not mapped data" },
|
|
{ nt_status_resource_data_not_found, "resource data not found" },
|
|
{ nt_status_resource_type_not_found, "resource type not found" },
|
|
{ nt_status_resource_name_not_found, "resource name not found" },
|
|
{ nt_status_array_bounds_exceeded, "array bounds exceeded" },
|
|
{ nt_status_float_denormal_operand, "float denormal operand" },
|
|
{ nt_status_float_divide_by_zero, "float divide by zero" },
|
|
{ nt_status_float_inexact_result, "float inexact result" },
|
|
{ nt_status_float_invalid_operation, "float invalid operation" },
|
|
{ nt_status_float_overflow, "float overflow" },
|
|
{ nt_status_float_stack_check, "float stack check" },
|
|
{ nt_status_float_underflow, "float underflow" },
|
|
{ nt_status_integer_divide_by_zero, "integer divide by zero" },
|
|
{ nt_status_integer_overflow, "integer overflow" },
|
|
{ nt_status_privileged_instruction, "privileged instruction" },
|
|
{ nt_status_too_many_paging_files, "too many paging files" },
|
|
{ nt_status_file_invalid, "file invalid" },
|
|
{ nt_status_allotted_space_exceeded, "allotted space exceeded" },
|
|
{ nt_status_insufficient_resources, "insufficient resources" },
|
|
{ nt_status_dfs_exit_path_found, "dfs exit path found" },
|
|
{ nt_status_device_data_error, "device data error" },
|
|
{ nt_status_device_not_connected, "device not connected" },
|
|
{ nt_status_device_power_failure, "device power failure" },
|
|
{ nt_status_free_vm_not_at_base, "free vm not at base" },
|
|
{ nt_status_memory_not_allocated, "memory not allocated" },
|
|
{ nt_status_working_set_quota, "working set quota" },
|
|
{ nt_status_media_write_protected, "media write protected" },
|
|
{ nt_status_device_not_ready, "device not ready" },
|
|
{ nt_status_invalid_group_attributes, "invalid group attributes" },
|
|
{ nt_status_bad_impersonation_level, "bad impersonation level" },
|
|
{ nt_status_cant_open_anonymous, "cant open anonymous" },
|
|
{ nt_status_bad_validation_class, "bad validation class" },
|
|
{ nt_status_bad_token_type, "bad token type" },
|
|
{ nt_status_bad_master_boot_record, "bad master boot record" },
|
|
{ nt_status_instruction_misalignment, "instruction misalignment" },
|
|
{ nt_status_instance_not_available, "instance not available" },
|
|
{ nt_status_pipe_not_available, "pipe not available" },
|
|
{ nt_status_invalid_pipe_state, "invalid pipe state" },
|
|
{ nt_status_pipe_busy, "pipe busy" },
|
|
{ nt_status_illegal_function, "illegal function" },
|
|
{ nt_status_pipe_disconnected, "pipe disconnected" },
|
|
{ nt_status_pipe_closing, "pipe closing" },
|
|
{ nt_status_pipe_connected, "pipe connected" },
|
|
{ nt_status_pipe_listening, "pipe listening" },
|
|
{ nt_status_invalid_read_mode, "invalid read mode" },
|
|
{ nt_status_io_timeout, "io timeout" },
|
|
{ nt_status_file_forced_closed, "file forced closed" },
|
|
{ nt_status_profiling_not_started, "profiling not started" },
|
|
{ nt_status_profiling_not_stopped, "profiling not stopped" },
|
|
{ nt_status_could_not_interpret, "could not interpret" },
|
|
{ nt_status_file_is_a_directory, "file is a directory" },
|
|
{ nt_status_not_supported, "not supported" },
|
|
{ nt_status_remote_not_listening, "remote not listening" },
|
|
{ nt_status_duplicate_name, "duplicate name" },
|
|
{ nt_status_bad_network_path, "bad network path" },
|
|
{ nt_status_network_busy, "network busy" },
|
|
{ nt_status_device_does_not_exist, "device does not exist" },
|
|
{ nt_status_too_many_commands, "too many commands" },
|
|
{ nt_status_adapter_hardware_error, "adapter hardware error" },
|
|
{ nt_status_invalid_network_response, "invalid network response" },
|
|
{ nt_status_unexpected_network_error, "unexpected network error" },
|
|
{ nt_status_bad_remote_adapter, "bad remote adapter" },
|
|
{ nt_status_print_queue_full, "print queue full" },
|
|
{ nt_status_no_spool_space, "no spool space" },
|
|
{ nt_status_print_cancelled, "print cancelled" },
|
|
{ nt_status_network_name_deleted, "network name deleted" },
|
|
{ nt_status_network_access_denied, "network access denied" },
|
|
{ nt_status_bad_device_type, "bad device type" },
|
|
{ nt_status_bad_network_name, "bad network name" },
|
|
{ nt_status_too_many_names, "too many names" },
|
|
{ nt_status_too_many_sessions, "too many sessions" },
|
|
{ nt_status_sharing_paused, "sharing paused" },
|
|
{ nt_status_request_not_accepted, "request not accepted" },
|
|
{ nt_status_redirector_paused, "redirector paused" },
|
|
{ nt_status_net_write_fault, "net write fault" },
|
|
{ nt_status_profiling_at_limit, "profiling at limit" },
|
|
{ nt_status_not_same_device, "not same device" },
|
|
{ nt_status_file_renamed, "file renamed" },
|
|
{ nt_status_virtual_circuit_closed, "virtual circuit closed" },
|
|
{ nt_status_no_security_on_object, "no security on object" },
|
|
{ nt_status_cant_wait, "cant wait" },
|
|
{ nt_status_pipe_empty, "pipe empty" },
|
|
{ nt_status_cant_access_domain_info, "cant access domain info" },
|
|
{ nt_status_cant_terminate_self, "cant terminate self" },
|
|
{ nt_status_invalid_server_state, "invalid server state" },
|
|
{ nt_status_invalid_domain_state, "invalid domain state" },
|
|
{ nt_status_invalid_domain_role, "invalid domain role" },
|
|
{ nt_status_no_such_domain, "no such domain" },
|
|
{ nt_status_domain_exists, "domain exists" },
|
|
{ nt_status_domain_limit_exceeded, "domain limit exceeded" },
|
|
{ nt_status_oplock_not_granted, "oplock not granted" },
|
|
{ nt_status_invalid_oplock_protocol, "invalid oplock protocol" },
|
|
{ nt_status_internal_db_corruption, "internal db corruption" },
|
|
{ nt_status_internal_error, "internal error" },
|
|
{ nt_status_generic_not_mapped, "generic not mapped" },
|
|
{ nt_status_bad_descriptor_format, "bad descriptor format" },
|
|
{ nt_status_invalid_user_buffer, "invalid user buffer" },
|
|
{ nt_status_unexpected_io_error, "unexpected io error" },
|
|
{ nt_status_unexpected_mm_create_err, "unexpected mm create err" },
|
|
{ nt_status_unexpected_mm_map_error, "unexpected mm map error" },
|
|
{ nt_status_unexpected_mm_extend_err, "unexpected mm extend err" },
|
|
{ nt_status_not_logon_process, "not logon process" },
|
|
{ nt_status_logon_session_exists, "logon session exists" },
|
|
{ nt_status_invalid_parameter_1, "invalid parameter 1" },
|
|
{ nt_status_invalid_parameter_2, "invalid parameter 2" },
|
|
{ nt_status_invalid_parameter_3, "invalid parameter 3" },
|
|
{ nt_status_invalid_parameter_4, "invalid parameter 4" },
|
|
{ nt_status_invalid_parameter_5, "invalid parameter 5" },
|
|
{ nt_status_invalid_parameter_6, "invalid parameter 6" },
|
|
{ nt_status_invalid_parameter_7, "invalid parameter 7" },
|
|
{ nt_status_invalid_parameter_8, "invalid parameter 8" },
|
|
{ nt_status_invalid_parameter_9, "invalid parameter 9" },
|
|
{ nt_status_invalid_parameter_10, "invalid parameter 10" },
|
|
{ nt_status_invalid_parameter_11, "invalid parameter 11" },
|
|
{ nt_status_invalid_parameter_12, "invalid parameter 12" },
|
|
{ nt_status_redirector_not_started, "redirector not started" },
|
|
{ nt_status_redirector_started, "redirector started" },
|
|
{ nt_status_stack_overflow, "stack overflow" },
|
|
{ nt_status_no_such_package, "no such package" },
|
|
{ nt_status_bad_function_table, "bad function table" },
|
|
{ nt_status_directory_not_empty, "directory not empty" },
|
|
{ nt_status_file_corrupt_error, "file corrupt error" },
|
|
{ nt_status_not_a_directory, "not a directory" },
|
|
{ nt_status_bad_logon_session_state, "bad logon session state" },
|
|
{ nt_status_logon_session_collision, "logon session collision" },
|
|
{ nt_status_name_too_long, "name too long" },
|
|
{ nt_status_files_open, "files open" },
|
|
{ nt_status_connection_in_use, "connection in use" },
|
|
{ nt_status_message_not_found, "message not found" },
|
|
{ nt_status_process_is_terminating, "process is terminating" },
|
|
{ nt_status_invalid_logon_type, "invalid logon type" },
|
|
{ nt_status_no_guid_translation, "no guid translation" },
|
|
{ nt_status_cannot_impersonate, "cannot impersonate" },
|
|
{ nt_status_image_already_loaded, "image already loaded" },
|
|
{ nt_status_abios_not_present, "abios not present" },
|
|
{ nt_status_abios_lid_not_exist, "abios lid not exist" },
|
|
{ nt_status_abios_lid_already_owned, "abios lid already owned" },
|
|
{ nt_status_abios_not_lid_owner, "abios not lid owner" },
|
|
{ nt_status_abios_invalid_command, "abios invalid command" },
|
|
{ nt_status_abios_invalid_lid, "abios invalid lid" },
|
|
{ nt_status_abios_selector_not_available, "abios selector not available" },
|
|
{ nt_status_abios_invalid_selector, "abios invalid selector" },
|
|
{ nt_status_no_ldt, "no ldt" },
|
|
{ nt_status_invalid_ldt_size, "invalid ldt size" },
|
|
{ nt_status_invalid_ldt_offset, "invalid ldt offset" },
|
|
{ nt_status_invalid_ldt_descriptor, "invalid ldt descriptor" },
|
|
{ nt_status_invalid_image_ne_format, "invalid image ne format" },
|
|
{ nt_status_rxact_invalid_state, "rxact invalid state" },
|
|
{ nt_status_rxact_commit_failure, "rxact commit failure" },
|
|
{ nt_status_mapped_file_size_zero, "mapped file size zero" },
|
|
{ nt_status_too_many_opened_files, "too many opened files" },
|
|
{ nt_status_cancelled, "cancelled" },
|
|
{ nt_status_cannot_delete, "cannot delete" },
|
|
{ nt_status_invalid_computer_name, "invalid computer name" },
|
|
{ nt_status_file_deleted, "file deleted" },
|
|
{ nt_status_special_account, "special account" },
|
|
{ nt_status_special_group, "special group" },
|
|
{ nt_status_special_user, "special user" },
|
|
{ nt_status_members_primary_group, "members primary group" },
|
|
{ nt_status_file_closed, "file closed" },
|
|
{ nt_status_too_many_threads, "too many threads" },
|
|
{ nt_status_thread_not_in_process, "thread not in process" },
|
|
{ nt_status_token_already_in_use, "token already in use" },
|
|
{ nt_status_pagefile_quota_exceeded, "pagefile quota exceeded" },
|
|
{ nt_status_commitment_limit, "commitment limit" },
|
|
{ nt_status_invalid_image_le_format, "invalid image le format" },
|
|
{ nt_status_invalid_image_not_mz, "invalid image not mz" },
|
|
{ nt_status_invalid_image_protect, "invalid image protect" },
|
|
{ nt_status_invalid_image_win_16, "invalid image win 16" },
|
|
{ nt_status_logon_server_conflict, "logon server conflict" },
|
|
{ nt_status_time_difference_at_dc, "time difference at dc" },
|
|
{ nt_status_synchronization_required, "synchronization required" },
|
|
{ nt_status_dll_not_found, "dll not found" },
|
|
{ nt_status_open_failed, "open failed" },
|
|
{ nt_status_io_privilege_failed, "io privilege failed" },
|
|
{ nt_status_ordinal_not_found, "ordinal not found" },
|
|
{ nt_status_entrypoint_not_found, "entrypoint not found" },
|
|
{ nt_status_control_c_exit, "control c exit" },
|
|
{ nt_status_local_disconnect, "local disconnect" },
|
|
{ nt_status_remote_disconnect, "remote disconnect" },
|
|
{ nt_status_remote_resources, "remote resources" },
|
|
{ nt_status_link_failed, "link failed" },
|
|
{ nt_status_link_timeout, "link timeout" },
|
|
{ nt_status_invalid_connection, "invalid connection" },
|
|
{ nt_status_invalid_address, "invalid address" },
|
|
{ nt_status_dll_init_failed, "dll init failed" },
|
|
{ nt_status_missing_systemfile, "missing systemfile" },
|
|
{ nt_status_unhandled_exception, "unhandled exception" },
|
|
{ nt_status_app_init_failure, "app init failure" },
|
|
{ nt_status_pagefile_create_failed, "pagefile create failed" },
|
|
{ nt_status_no_pagefile, "no pagefile" },
|
|
{ nt_status_invalid_level, "invalid level" },
|
|
{ nt_status_wrong_password_core, "wrong password core" },
|
|
{ nt_status_illegal_float_context, "illegal float context" },
|
|
{ nt_status_pipe_broken, "pipe broken" },
|
|
{ nt_status_registry_corrupt, "registry corrupt" },
|
|
{ nt_status_registry_io_failed, "registry io failed" },
|
|
{ nt_status_no_event_pair, "no event pair" },
|
|
{ nt_status_unrecognized_volume, "unrecognized volume" },
|
|
{ nt_status_serial_no_device_inited, "serial no device inited" },
|
|
{ nt_status_no_such_alias, "no such alias" },
|
|
{ nt_status_member_not_in_alias, "member not in alias" },
|
|
{ nt_status_member_in_alias, "member in alias" },
|
|
{ nt_status_alias_exists, "alias exists" },
|
|
{ nt_status_logon_not_granted, "logon not granted" },
|
|
{ nt_status_too_many_secrets, "too many secrets" },
|
|
{ nt_status_secret_too_long, "secret too long" },
|
|
{ nt_status_internal_db_error, "internal db error" },
|
|
{ nt_status_fullscreen_mode, "fullscreen mode" },
|
|
{ nt_status_too_many_context_ids, "too many context ids" },
|
|
{ nt_status_logon_type_not_granted, "logon type not granted" },
|
|
{ nt_status_not_registry_file, "not registry file" },
|
|
{ nt_status_nt_cross_encryption_required, "nt cross encryption required" },
|
|
{ nt_status_domain_ctrlr_config_error, "domain ctrlr config error" },
|
|
{ nt_status_ft_missing_member, "ft missing member" },
|
|
{ nt_status_ill_formed_service_entry, "ill formed service entry" },
|
|
{ nt_status_illegal_character, "illegal character" },
|
|
{ nt_status_unmappable_character, "unmappable character" },
|
|
{ nt_status_undefined_character, "undefined character" },
|
|
{ nt_status_floppy_volume, "floppy volume" },
|
|
{ nt_status_floppy_id_mark_not_found, "floppy id mark not found" },
|
|
{ nt_status_floppy_wrong_cylinder, "floppy wrong cylinder" },
|
|
{ nt_status_floppy_unknown_error, "floppy unknown error" },
|
|
{ nt_status_floppy_bad_registers, "floppy bad registers" },
|
|
{ nt_status_disk_recalibrate_failed, "disk recalibrate failed" },
|
|
{ nt_status_disk_operation_failed, "disk operation failed" },
|
|
{ nt_status_disk_reset_failed, "disk reset failed" },
|
|
{ nt_status_shared_irq_busy, "shared irq busy" },
|
|
{ nt_status_ft_orphaning, "ft orphaning" },
|
|
{ nt_status_partition_failure, "partition failure" },
|
|
{ nt_status_invalid_block_length, "invalid block length" },
|
|
{ nt_status_device_not_partitioned, "device not partitioned" },
|
|
{ nt_status_unable_to_lock_media, "unable to lock media" },
|
|
{ nt_status_unable_to_unload_media, "unable to unload media" },
|
|
{ nt_status_eom_overflow, "eom overflow" },
|
|
{ nt_status_no_media, "no media" },
|
|
{ nt_status_no_such_member, "no such member" },
|
|
{ nt_status_invalid_member, "invalid member" },
|
|
{ nt_status_key_deleted, "key deleted" },
|
|
{ nt_status_no_log_space, "no log space" },
|
|
{ nt_status_too_many_sids, "too many sids" },
|
|
{ nt_status_lm_cross_encryption_required, "lm cross encryption required" },
|
|
{ nt_status_key_has_children, "key has children" },
|
|
{ nt_status_child_must_be_volatile, "child must be volatile" },
|
|
{ nt_status_device_configuration_error, "device configuration error" },
|
|
{ nt_status_driver_internal_error, "driver internal error" },
|
|
{ nt_status_invalid_device_state, "invalid device state" },
|
|
{ nt_status_io_device_error, "io device error" },
|
|
{ nt_status_device_protocol_error, "device protocol error" },
|
|
{ nt_status_backup_controller, "backup controller" },
|
|
{ nt_status_log_file_full, "log file full" },
|
|
{ nt_status_too_late, "too late" },
|
|
{ nt_status_no_trust_lsa_secret, "no trust lsa secret" },
|
|
{ nt_status_no_trust_sam_account, "no trust sam account" },
|
|
{ nt_status_trusted_domain_failure, "trusted domain failure" },
|
|
{ nt_status_trusted_relationship_failure, "trusted relationship failure" },
|
|
{ nt_status_eventlog_file_corrupt, "eventlog file corrupt" },
|
|
{ nt_status_eventlog_cant_start, "eventlog cant start" },
|
|
{ nt_status_trust_failure, "trust failure" },
|
|
{ nt_status_mutant_limit_exceeded, "mutant limit exceeded" },
|
|
{ nt_status_netlogon_not_started, "netlogon not started" },
|
|
{ nt_status_account_expired, "account expired" },
|
|
{ nt_status_possible_deadlock, "possible deadlock" },
|
|
{ nt_status_network_credential_conflict, "network credential conflict" },
|
|
{ nt_status_remote_session_limit, "remote session limit" },
|
|
{ nt_status_eventlog_file_changed, "eventlog file changed" },
|
|
{ nt_status_nologon_interdomain_trust_account, "nologon interdomain trust account" },
|
|
{ nt_status_nologon_workstation_trust_account, "nologon workstation trust account" },
|
|
{ nt_status_nologon_server_trust_account, "nologon server trust account" },
|
|
{ nt_status_domain_trust_inconsistent, "domain trust inconsistent" },
|
|
{ nt_status_fs_driver_required, "fs driver required" },
|
|
{ nt_status_no_user_session_key, "no user session key" },
|
|
{ nt_status_user_session_deleted, "user session deleted" },
|
|
{ nt_status_resource_lang_not_found, "resource lang not found" },
|
|
{ nt_status_insuff_server_resources, "insuff server resources" },
|
|
{ nt_status_invalid_buffer_size, "invalid buffer size" },
|
|
{ nt_status_invalid_address_component, "invalid address component" },
|
|
{ nt_status_invalid_address_wildcard, "invalid address wildcard" },
|
|
{ nt_status_too_many_addresses, "too many addresses" },
|
|
{ nt_status_address_already_exists, "address already exists" },
|
|
{ nt_status_address_closed, "address closed" },
|
|
{ nt_status_connection_disconnected, "connection disconnected" },
|
|
{ nt_status_connection_reset, "connection reset" },
|
|
{ nt_status_too_many_nodes, "too many nodes" },
|
|
{ nt_status_transaction_aborted, "transaction aborted" },
|
|
{ nt_status_transaction_timed_out, "transaction timed out" },
|
|
{ nt_status_transaction_no_release, "transaction no release" },
|
|
{ nt_status_transaction_no_match, "transaction no match" },
|
|
{ nt_status_transaction_responded, "transaction responded" },
|
|
{ nt_status_transaction_invalid_id, "transaction invalid id" },
|
|
{ nt_status_transaction_invalid_type, "transaction invalid type" },
|
|
{ nt_status_not_server_session, "not server session" },
|
|
{ nt_status_not_client_session, "not client session" },
|
|
{ nt_status_cannot_load_registry_file, "cannot load registry file" },
|
|
{ nt_status_debug_attach_failed, "debug attach failed" },
|
|
{ nt_status_system_process_terminated, "system process terminated" },
|
|
{ nt_status_data_not_accepted, "data not accepted" },
|
|
{ nt_status_no_browser_servers_found, "no browser servers found" },
|
|
{ nt_status_vdm_hard_error, "vdm hard error" },
|
|
{ nt_status_driver_cancel_timeout, "driver cancel timeout" },
|
|
{ nt_status_reply_message_mismatch, "reply message mismatch" },
|
|
{ nt_status_mapped_alignment, "mapped alignment" },
|
|
{ nt_status_image_checksum_mismatch, "image checksum mismatch" },
|
|
{ nt_status_lost_writebehind_data, "lost writebehind data" },
|
|
{ nt_status_client_server_parameters_invalid, "client server parameters invalid" },
|
|
{ nt_status_password_must_change, "password must change" },
|
|
{ nt_status_not_found, "not found" },
|
|
{ nt_status_not_tiny_stream, "not tiny stream" },
|
|
{ nt_status_recovery_failure, "recovery failure" },
|
|
{ nt_status_stack_overflow_read, "stack overflow read" },
|
|
{ nt_status_fail_check, "fail check" },
|
|
{ nt_status_duplicate_objectid, "duplicate objectid" },
|
|
{ nt_status_objectid_exists, "objectid exists" },
|
|
{ nt_status_convert_to_large, "convert to large" },
|
|
{ nt_status_retry, "retry" },
|
|
{ nt_status_found_out_of_scope, "found out of scope" },
|
|
{ nt_status_allocate_bucket, "allocate bucket" },
|
|
{ nt_status_propset_not_found, "propset not found" },
|
|
{ nt_status_marshall_overflow, "marshall overflow" },
|
|
{ nt_status_invalid_variant, "invalid variant" },
|
|
{ nt_status_domain_controller_not_found, "domain controller not found" },
|
|
{ nt_status_account_locked_out, "account locked out" },
|
|
{ nt_status_handle_not_closable, "handle not closable" },
|
|
{ nt_status_connection_refused, "connection refused" },
|
|
{ nt_status_graceful_disconnect, "graceful disconnect" },
|
|
{ nt_status_address_already_associated, "address already associated" },
|
|
{ nt_status_address_not_associated, "address not associated" },
|
|
{ nt_status_connection_invalid, "connection invalid" },
|
|
{ nt_status_connection_active, "connection active" },
|
|
{ nt_status_network_unreachable, "network unreachable" },
|
|
{ nt_status_host_unreachable, "host unreachable" },
|
|
{ nt_status_protocol_unreachable, "protocol unreachable" },
|
|
{ nt_status_port_unreachable, "port unreachable" },
|
|
{ nt_status_request_aborted, "request aborted" },
|
|
{ nt_status_connection_aborted, "connection aborted" },
|
|
{ nt_status_bad_compression_buffer, "bad compression buffer" },
|
|
{ nt_status_user_mapped_file, "user mapped file" },
|
|
{ nt_status_audit_failed, "audit failed" },
|
|
{ nt_status_timer_resolution_not_set, "timer resolution not set" },
|
|
{ nt_status_connection_count_limit, "connection count limit" },
|
|
{ nt_status_login_time_restriction, "login time restriction" },
|
|
{ nt_status_login_wksta_restriction, "login wksta restriction" },
|
|
{ nt_status_image_mp_up_mismatch, "image mp up mismatch" },
|
|
{ nt_status_insufficient_logon_info, "insufficient logon info" },
|
|
{ nt_status_bad_dll_entrypoint, "bad dll entrypoint" },
|
|
{ nt_status_bad_service_entrypoint, "bad service entrypoint" },
|
|
{ nt_status_lpc_reply_lost, "lpc reply lost" },
|
|
{ nt_status_ip_address_conflict1, "ip address conflict1" },
|
|
{ nt_status_ip_address_conflict2, "ip address conflict2" },
|
|
{ nt_status_registry_quota_limit, "registry quota limit" },
|
|
{ nt_status_path_not_covered, "path not covered" },
|
|
{ nt_status_no_callback_active, "no callback active" },
|
|
{ nt_status_license_quota_exceeded, "license quota exceeded" },
|
|
{ nt_status_pwd_too_short, "pwd too short" },
|
|
{ nt_status_pwd_too_recent, "pwd too recent" },
|
|
{ nt_status_pwd_history_conflict, "pwd history conflict" },
|
|
{ nt_status_plugplay_no_device, "plugplay no device" },
|
|
{ nt_status_unsupported_compression, "unsupported compression" },
|
|
{ nt_status_invalid_hw_profile, "invalid hw profile" },
|
|
{ nt_status_invalid_plugplay_device_path, "invalid plugplay device path" },
|
|
{ nt_status_driver_ordinal_not_found, "driver ordinal not found" },
|
|
{ nt_status_driver_entrypoint_not_found, "driver entrypoint not found" },
|
|
{ nt_status_resource_not_owned, "resource not owned" },
|
|
{ nt_status_too_many_links, "too many links" },
|
|
{ nt_status_quota_list_inconsistent, "quota list inconsistent" },
|
|
{ nt_status_file_is_offline, "file is offline" },
|
|
//{ nt_status_notify_enum_dir, "notify enum dir" },
|
|
{ -1, NULL }
|
|
};
|
|
|
|
const char * command_name;
|
|
struct line_buffer lb;
|
|
|
|
if(smb_packet_source == smb_packet_from_consumer)
|
|
FPrintf(dump_smb_file,"message type = Request (client --> server)\n");
|
|
else
|
|
FPrintf(dump_smb_file,"message type = Response (server --> client)\n");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_32BIT_STATUS)
|
|
{
|
|
int severity,facility,error_code;
|
|
const char * error_code_name = "?";
|
|
int i;
|
|
|
|
severity = (header->status >> 30) & 1;
|
|
facility = (header->status >> 16) & 0x0fff;
|
|
error_code = header->status & 0xffff;
|
|
|
|
for(i = 0 ; nt_error_codes[i].code != -1 ; i++)
|
|
{
|
|
if(nt_error_codes[i].code == error_code)
|
|
{
|
|
error_code_name = nt_error_codes[i].label;
|
|
break;
|
|
}
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"status = [%08lx] severity:%s, facility:%s (%ld), code:%s (%ld)\n",header->status,
|
|
severity ? "failure" : "success",facility ? "?" : "default",facility,error_code_name,error_code);
|
|
}
|
|
else
|
|
{
|
|
const char * error_class_name;
|
|
int error_class_value;
|
|
const char * error_code_name = "?";
|
|
int error_code_value;
|
|
int i;
|
|
|
|
error_class_value = header->status & 0xff;
|
|
error_code_value = (header->status >> 16) & 0xffff;
|
|
|
|
switch(error_class_value)
|
|
{
|
|
case 0:
|
|
|
|
error_class_name = "success";
|
|
error_code_name = "no error";
|
|
break;
|
|
|
|
case 1:
|
|
|
|
error_class_name = "DOS error";
|
|
|
|
for(i = 0 ; dos_errors[i].code != -1 ; i++)
|
|
{
|
|
if(dos_errors[i].code == error_code_value)
|
|
{
|
|
error_code_name = dos_errors[i].label;
|
|
break;
|
|
}
|
|
}
|
|
|
|
break;
|
|
|
|
case 2:
|
|
|
|
error_class_name = "server error";
|
|
|
|
for(i = 0 ; server_errors[i].code != -1 ; i++)
|
|
{
|
|
if(server_errors[i].code == error_code_value)
|
|
{
|
|
error_code_name = server_errors[i].label;
|
|
break;
|
|
}
|
|
}
|
|
|
|
break;
|
|
|
|
case 3:
|
|
|
|
error_class_name = "hardware error";
|
|
|
|
for(i = 0 ; hardware_errors[i].code != -1 ; i++)
|
|
{
|
|
if(hardware_errors[i].code == error_code_value)
|
|
{
|
|
error_code_name = hardware_errors[i].label;
|
|
break;
|
|
}
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
error_class_name = "Command error";
|
|
break;
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"status = [%08lx] error:%s (%ld), code:%s (%ld)\n",header->status,
|
|
error_class_name,error_class_value,
|
|
error_code_name,error_code_value);
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"flags = ");
|
|
|
|
init_line_buffer(&lb);
|
|
|
|
if(header->flags & SMB_FLAGS_SERVER_TO_REDIR)
|
|
add_lb_flag(&lb,"type=reply");
|
|
else
|
|
add_lb_flag(&lb,"type=request");
|
|
|
|
if(header->flags & SMB_FLAGS_REQUEST_BATCH_OPLOCK)
|
|
add_lb_flag(&lb,"request-batch-oplock=batch");
|
|
else
|
|
add_lb_flag(&lb,"request-batch-oplock=exclusive");
|
|
|
|
if(header->flags & SMB_FLAGS_REQUEST_OPLOCK)
|
|
add_lb_flag(&lb,"request-oplock=yes");
|
|
else
|
|
add_lb_flag(&lb,"request-oplock=no");
|
|
|
|
if(header->flags & SMB_FLAGS_CANONICAL_PATHNAMES)
|
|
add_lb_flag(&lb,"canonical-pathnames=canonical");
|
|
else
|
|
add_lb_flag(&lb,"canonical-pathnames=host format");
|
|
|
|
if(header->flags & SMB_FLAGS_CASELESS_PATHNAMES)
|
|
add_lb_flag(&lb,"caseless-pathnames=yes");
|
|
else
|
|
add_lb_flag(&lb,"caseless-pathnames=no");
|
|
|
|
if(header->flags & SMB_FLAGS_CLIENT_BUF_AVAIL)
|
|
add_lb_flag(&lb,"client-buf-avail=yes");
|
|
else
|
|
add_lb_flag(&lb,"client-buf-avail=no");
|
|
|
|
if(header->flags & SMB_FLAGS_SUPPORT_LOCKREAD)
|
|
add_lb_flag(&lb,"support-lockread=yes");
|
|
else
|
|
add_lb_flag(&lb,"support-lockread=no");
|
|
|
|
FPrintf(dump_smb_file,"%s\n",lb.line);
|
|
|
|
FPrintf(dump_smb_file,"flags2 = ");
|
|
|
|
init_line_buffer(&lb);
|
|
|
|
if(header->flags2 & SMB_FLAGS2_UNICODE_STRINGS)
|
|
add_lb_flag(&lb,"string-format=Unicode");
|
|
else
|
|
add_lb_flag(&lb,"string-format=ASCII");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_32BIT_STATUS)
|
|
add_lb_flag(&lb,"status-code=NT_STATUS format");
|
|
else
|
|
add_lb_flag(&lb,"status-code=DOS error format");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_READ_IF_EXECUTE)
|
|
add_lb_flag(&lb,"read-if-execute=yes");
|
|
else
|
|
add_lb_flag(&lb,"read-if-execute=no");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_DFS_PATHNAME)
|
|
add_lb_flag(&lb,"pathname=DFS");
|
|
else
|
|
add_lb_flag(&lb,"pathname=normal");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_EXTENDED_SECURITY)
|
|
add_lb_flag(&lb,"security=extended");
|
|
else
|
|
add_lb_flag(&lb,"security=normal");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_IS_LONG_NAME)
|
|
add_lb_flag(&lb,"name-format=long");
|
|
else
|
|
add_lb_flag(&lb,"name-format=8.3");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_SECURITY_SIGNATURE)
|
|
add_lb_flag(&lb,"security-signature=MAC");
|
|
else
|
|
add_lb_flag(&lb,"security-signature=none");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_EAS)
|
|
add_lb_flag(&lb,"extended-attributes=yes");
|
|
else
|
|
add_lb_flag(&lb,"extended-attributes=no");
|
|
|
|
if(header->flags2 & SMB_FLAGS2_KNOWS_LONG_NAMES)
|
|
add_lb_flag(&lb,"client-names-supported=long");
|
|
else
|
|
add_lb_flag(&lb,"client-names-supported=8.3");
|
|
|
|
FPrintf(dump_smb_file,"%s\n",lb.line);
|
|
|
|
FPrintf(dump_smb_file,"signature = %04lx%04lx%04lx%04lx\n",header->extra.signature[0],header->extra.signature[1],
|
|
header->extra.signature[2],header->extra.signature[3]);
|
|
|
|
FPrintf(dump_smb_file,"tid = %04lx\n",header->tid);
|
|
FPrintf(dump_smb_file,"pid = %04lx\n",header->pid);
|
|
FPrintf(dump_smb_file,"uid = %04lx\n",header->uid);
|
|
FPrintf(dump_smb_file,"mid = %04lx\n",header->mid);
|
|
|
|
FPrintf(dump_smb_file,"length = %ld (packet size:%ld, buffer size:%ld)\n",header_length,packet_size,max_buffer_size);
|
|
|
|
if(is_smb_andx_command(header->command))
|
|
{
|
|
const unsigned char * andx_header = (const unsigned char *)header->parameters;
|
|
int offset = (((int)andx_header[3]) << 8) + andx_header[2];
|
|
int num_parameter_words,num_data_bytes;
|
|
|
|
command_name = get_smb_command_name(header->command);
|
|
|
|
if(command_name != NULL)
|
|
FPrintf(dump_smb_file,"command = %s (ANDX)\n",command_name);
|
|
else
|
|
FPrintf(dump_smb_file,"command = 0x%02lx (ANDX)\n",header->command);
|
|
|
|
FPrintf(dump_smb_file,"parameter words = %ld\n",header->num_parameter_words - 2);
|
|
|
|
if(header->num_parameter_words - 2 > 0)
|
|
print_smb_parameters(header->num_parameter_words - 2,&header->parameters[4]);
|
|
|
|
FPrintf(dump_smb_file,"data bytes = %ld\n",header->num_data_bytes);
|
|
|
|
/* If there are any data bytes, print them like "type hex .." would. */
|
|
if(dump_smb_level > 0 && header->num_data_bytes > 0)
|
|
print_smb_data(&lb,header->num_data_bytes,header->data);
|
|
|
|
print_smb_contents(header, header->command, smb_packet_source, header->num_parameter_words - 2,
|
|
&header->parameters[4], header->num_data_bytes, header->data);
|
|
|
|
while(andx_header[0] != 0xff && offset > 0 && offset < packet_size)
|
|
{
|
|
andx_header = &packet[offset];
|
|
|
|
num_parameter_words = (*andx_header++);
|
|
|
|
command_name = get_smb_command_name(andx_header[0]);
|
|
|
|
if(command_name != NULL)
|
|
FPrintf(dump_smb_file,"command = %s (ANDX)\n",command_name);
|
|
else
|
|
FPrintf(dump_smb_file,"command = 0x%02lx (ANDX)\n",header->command);
|
|
|
|
FPrintf(dump_smb_file,"andx_offset = 0x%02lx\n",(((int)andx_header[3]) << 8) + andx_header[2]);
|
|
|
|
FPrintf(dump_smb_file,"parameter words = %ld\n",num_parameter_words);
|
|
|
|
if(num_parameter_words > 0)
|
|
print_smb_parameters(num_parameter_words,&andx_header[4]);
|
|
|
|
num_data_bytes = andx_header[4 + num_parameter_words * 2] + (((int)andx_header[4 + num_parameter_words * 2 + 1]) << 8);
|
|
|
|
FPrintf(dump_smb_file,"data bytes = %ld\n",num_data_bytes);
|
|
|
|
if(dump_smb_level > 0 && num_data_bytes > 0)
|
|
print_smb_data(&lb,num_data_bytes,&andx_header[4 + num_parameter_words * 2 + 2]);
|
|
|
|
print_smb_contents(header, andx_header[0], smb_packet_source, num_parameter_words, &andx_header[4],
|
|
num_data_bytes, &andx_header[4 + num_parameter_words * 2 + 2]);
|
|
|
|
offset = (((int)andx_header[3]) << 8) + andx_header[2];
|
|
}
|
|
}
|
|
else
|
|
{
|
|
command_name = get_smb_command_name(header->command);
|
|
|
|
if(command_name != NULL)
|
|
FPrintf(dump_smb_file,"command = %s\n",command_name);
|
|
else
|
|
FPrintf(dump_smb_file,"command = 0x%02lx\n",header->command);
|
|
|
|
FPrintf(dump_smb_file,"parameter words = %ld\n",header->num_parameter_words);
|
|
|
|
if(header->num_parameter_words > 0)
|
|
print_smb_parameters(header->num_parameter_words,(unsigned char *)header->parameters);
|
|
|
|
FPrintf(dump_smb_file,"data bytes = %ld\n",header->num_data_bytes);
|
|
|
|
/* If there are any data bytes, print them like "type hex .." would. */
|
|
if(dump_smb_level > 0 && header->num_data_bytes > 0)
|
|
print_smb_data(&lb,header->num_data_bytes,header->data);
|
|
|
|
print_smb_contents(header, header->command, smb_packet_source, header->num_parameter_words, header->parameters,
|
|
header->num_data_bytes, header->data);
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
void
|
|
dump_netbios_header(const char *file_name,int line_number,const unsigned char *netbios_session_header,
|
|
const unsigned char *netbios_payload,int netbios_payload_size)
|
|
{
|
|
if(dump_smb_enabled)
|
|
{
|
|
unsigned char session_type = netbios_session_header[0];
|
|
unsigned char session_flags = netbios_session_header[1] & 0xfe;
|
|
unsigned long session_length =
|
|
((netbios_session_header[1] & 1) ? 0x10000 : 0) |
|
|
(((unsigned long)netbios_session_header[2]) << 8) |
|
|
netbios_session_header[3];
|
|
|
|
const char * session_type_label;
|
|
|
|
switch(session_type)
|
|
{
|
|
case 0x00:
|
|
|
|
session_type_label = "session message";
|
|
break;
|
|
|
|
case 0x81:
|
|
|
|
session_type_label = "session request";
|
|
break;
|
|
|
|
case 0x82:
|
|
|
|
session_type_label = "positive session response";
|
|
break;
|
|
|
|
case 0x83:
|
|
|
|
session_type_label = "negative session response";
|
|
break;
|
|
|
|
case 0x84:
|
|
|
|
session_type_label = "retarget session response";
|
|
break;
|
|
|
|
case 0x85:
|
|
|
|
session_type_label = "session keep alive";
|
|
break;
|
|
|
|
default:
|
|
|
|
session_type_label = "?";
|
|
break;
|
|
}
|
|
|
|
FPrintf(dump_smb_file,"---\n");
|
|
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
|
|
|
|
FPrintf(dump_smb_file,"netbios session type=%s (0x%02lx), flags=0x%02lx, length=%ld\n",
|
|
session_type_label,session_type,session_flags,session_length);
|
|
|
|
if (session_type == 0x83 && netbios_payload != NULL && netbios_payload_size > 0)
|
|
{
|
|
int error_code = *netbios_payload;
|
|
|
|
FPrintf(dump_smb_file,"error code = 0x%02lx\n",error_code);
|
|
|
|
switch(error_code)
|
|
{
|
|
case 0x80:
|
|
|
|
FPrintf(dump_smb_file," Not listening on called name\n");
|
|
break;
|
|
|
|
case 0x81:
|
|
|
|
FPrintf(dump_smb_file," Not listening for calling name\n");
|
|
break;
|
|
|
|
case 0x82:
|
|
|
|
FPrintf(dump_smb_file," Called name not present\n");
|
|
break;
|
|
|
|
case 0x83:
|
|
|
|
FPrintf(dump_smb_file," Insufficient resources\n");
|
|
break;
|
|
|
|
case 0x8f:
|
|
|
|
FPrintf(dump_smb_file," Unspecific error\n");
|
|
break;
|
|
}
|
|
}
|
|
else if (session_type != 0x00 && netbios_payload != NULL && netbios_payload_size > 0)
|
|
{
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"session data (%ld bytes) =\n",netbios_payload_size);
|
|
|
|
print_smb_data(&lb,netbios_payload_size,netbios_payload);
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
void
|
|
dump_smb(const char *file_name,int line_number,int is_raw_data,
|
|
const void * packet,int length,enum smb_packet_source_t smb_packet_source,
|
|
int max_buffer_size)
|
|
{
|
|
if(dump_smb_enabled)
|
|
{
|
|
if(is_raw_data)
|
|
{
|
|
if(dump_smb_level > 1)
|
|
{
|
|
struct line_buffer lb;
|
|
|
|
FPrintf(dump_smb_file,"---\n");
|
|
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
|
|
|
|
FPrintf(dump_smb_file,"raw data (%ld bytes) =\n",length);
|
|
|
|
print_smb_data(&lb,length,packet);
|
|
|
|
FPrintf(dump_smb_file,"---\n\n");
|
|
}
|
|
}
|
|
else
|
|
{
|
|
if(length > 4 && memcmp(packet,"\xffSMB",4) == 0)
|
|
{
|
|
struct smb_header header;
|
|
int num_bytes_read;
|
|
|
|
num_bytes_read = fill_header(packet,length,&header);
|
|
if(num_bytes_read <= length)
|
|
{
|
|
FPrintf(dump_smb_file,"---\n");
|
|
FPrintf(dump_smb_file,"%s:%ld\n",file_name,line_number);
|
|
|
|
print_smb_header(&header,num_bytes_read,packet,length,
|
|
smb_packet_source,max_buffer_size);
|
|
|
|
FPrintf(dump_smb_file,"---\n\n");
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
void
|
|
control_smb_dump(int enable,int level,const char * file_name)
|
|
{
|
|
/* Close the output file if necessary. */
|
|
if(!enable && !dump_smb_stdout && dump_smb_file != (BPTR)NULL)
|
|
Close(dump_smb_file);
|
|
|
|
dump_smb_file = (BPTR)NULL;
|
|
|
|
dump_smb_enabled = enable;
|
|
dump_smb_level = level;
|
|
|
|
if(enable)
|
|
{
|
|
dump_smb_stdout = TRUE;
|
|
|
|
/* Write the output to a file? */
|
|
if(file_name != NULL)
|
|
{
|
|
/* Try to append the output to an existing file. */
|
|
dump_smb_file = Open(file_name,MODE_OLDFILE);
|
|
if(dump_smb_file == (BPTR)NULL)
|
|
{
|
|
/* File does not exist? Then create a new file. */
|
|
if(IoErr() == ERROR_OBJECT_NOT_FOUND)
|
|
{
|
|
dump_smb_file = Open(file_name,MODE_NEWFILE);
|
|
if(dump_smb_file != (BPTR)NULL)
|
|
ChangeMode(CHANGE_FH,dump_smb_file,SHARED_LOCK);
|
|
}
|
|
}
|
|
else
|
|
{
|
|
/* File exists; seek to the end of it. */
|
|
Seek(dump_smb_file,0,OFFSET_END);
|
|
}
|
|
|
|
/* If a file was created or opened for appending
|
|
* output to it, make sure it will get closed
|
|
* eventually.
|
|
*/
|
|
if(dump_smb_file != (BPTR)NULL)
|
|
dump_smb_stdout = FALSE;
|
|
}
|
|
|
|
/* No file was opened: output to STDOUT. */
|
|
if(dump_smb_file == (BPTR)NULL)
|
|
dump_smb_file = Output();
|
|
}
|
|
}
|
|
|
|
/*****************************************************************************/
|
|
|
|
#endif /* DUMP_SMB */
|