2 Unix SMB/CIFS implementation.
5 Copyright (C) Andrew Tridgell 1992-2000,
6 Copyright (C) Luke Kenneth Casson Leighton 1996-2000,
7 Copyright (C) Elrond 2000,
8 Copyright (C) Tim Potter 2000
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 2 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program; if not, write to the Free Software
22 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
26 #include "rpcclient.h"
28 extern DOM_SID domain_sid
;
30 /****************************************************************************
31 display sam_user_info_21 structure
32 ****************************************************************************/
33 static void display_sam_user_info_21(SAM_USER_INFO_21
*usr
)
37 unistr2_to_ascii(temp
, &usr
->uni_user_name
, sizeof(temp
)-1);
38 printf("\tUser Name :\t%s\n", temp
);
40 unistr2_to_ascii(temp
, &usr
->uni_full_name
, sizeof(temp
)-1);
41 printf("\tFull Name :\t%s\n", temp
);
43 unistr2_to_ascii(temp
, &usr
->uni_home_dir
, sizeof(temp
)-1);
44 printf("\tHome Drive :\t%s\n", temp
);
46 unistr2_to_ascii(temp
, &usr
->uni_dir_drive
, sizeof(temp
)-1);
47 printf("\tDir Drive :\t%s\n", temp
);
49 unistr2_to_ascii(temp
, &usr
->uni_profile_path
, sizeof(temp
)-1);
50 printf("\tProfile Path:\t%s\n", temp
);
52 unistr2_to_ascii(temp
, &usr
->uni_logon_script
, sizeof(temp
)-1);
53 printf("\tLogon Script:\t%s\n", temp
);
55 unistr2_to_ascii(temp
, &usr
->uni_acct_desc
, sizeof(temp
)-1);
56 printf("\tDescription :\t%s\n", temp
);
58 unistr2_to_ascii(temp
, &usr
->uni_workstations
, sizeof(temp
)-1);
59 printf("\tWorkstations:\t%s\n", temp
);
61 unistr2_to_ascii(temp
, &usr
->uni_unknown_str
, sizeof(temp
)-1);
62 printf("\tUnknown Str :\t%s\n", temp
);
64 unistr2_to_ascii(temp
, &usr
->uni_munged_dial
, sizeof(temp
)-1);
65 printf("\tRemote Dial :\t%s\n", temp
);
67 printf("\tLogon Time :\t%s\n",
68 http_timestring(nt_time_to_unix(&usr
->logon_time
)));
69 printf("\tLogoff Time :\t%s\n",
70 http_timestring(nt_time_to_unix(&usr
->logoff_time
)));
71 printf("\tKickoff Time :\t%s\n",
72 http_timestring(nt_time_to_unix(&usr
->kickoff_time
)));
73 printf("\tPassword last set Time :\t%s\n",
74 http_timestring(nt_time_to_unix(&usr
->pass_last_set_time
)));
75 printf("\tPassword can change Time :\t%s\n",
76 http_timestring(nt_time_to_unix(&usr
->pass_can_change_time
)));
77 printf("\tPassword must change Time:\t%s\n",
78 http_timestring(nt_time_to_unix(&usr
->pass_must_change_time
)));
80 printf("\tunknown_2[0..31]...\n"); /* user passwords? */
82 printf("\tuser_rid :\t0x%x\n" , usr
->user_rid
); /* User ID */
83 printf("\tgroup_rid:\t0x%x\n" , usr
->group_rid
); /* Group ID */
84 printf("\tacb_info :\t0x%04x\n", usr
->acb_info
); /* Account Control Info */
86 printf("\tunknown_3:\t0x%08x\n", usr
->unknown_3
); /* 0x00ff ffff */
87 printf("\tlogon_divs:\t%d\n", usr
->logon_divs
); /* 0x0000 00a8 which is 168 which is num hrs in a week */
88 printf("\tunknown_5:\t0x%08x\n", usr
->unknown_5
); /* 0x0002 0000 */
90 printf("\tpadding1[0..7]...\n");
92 if (usr
->ptr_logon_hrs
) {
93 printf("\tlogon_hrs[0..%d]...\n", usr
->logon_hrs
.len
);
97 static char *display_time(NTTIME nttime
)
99 static fstring string
;
104 int days
, hours
, mins
, secs
;
106 if (nttime
.high
==0 && nttime
.low
==0)
109 if (nttime
.high
==0x80000000 && nttime
.low
==0)
116 high
= high
* (~nttime
.high
);
119 low
= low
/(1000*1000*10);
124 hours
=(sec
- (days
*60*60*24)) / (60*60);
125 mins
=(sec
- (days
*60*60*24) - (hours
*60*60) ) / 60;
126 secs
=sec
- (days
*60*60*24) - (hours
*60*60) - (mins
*60);
128 snprintf(string
, sizeof(string
)-1, "%u days, %u hours, %u minutes, %u seconds", days
, hours
, mins
, secs
);
132 static void display_sam_unk_info_1(SAM_UNK_INFO_1
*info1
)
135 printf("Minimum password length: %d\n", info1
->min_length_password
);
136 printf("Password uniqueness (remember x passwords): %d\n", info1
->password_history
);
138 if(info1
->flag
&&2==2) printf("users must open a session to change password ");
141 printf("password expire in: %s\n", display_time(info1
->expire
));
142 printf("Min password age (allow changing in x days): %s\n", display_time(info1
->min_passwordage
));
145 static void display_sam_unk_info_2(SAM_UNK_INFO_2
*info2
)
149 unistr2_to_ascii(name
, &info2
->uni_domain
, sizeof(name
) - 1);
150 printf("Domain:\t%s\n", name
);
152 unistr2_to_ascii(name
, &info2
->uni_server
, sizeof(name
) - 1);
153 printf("Server:\t%s\n", name
);
155 printf("Total Users:\t%d\n", info2
->num_domain_usrs
);
156 printf("Total Groups:\t%d\n", info2
->num_domain_grps
);
157 printf("Total Aliases:\t%d\n", info2
->num_local_grps
);
159 printf("Sequence No:\t%d\n", info2
->seq_num
);
161 printf("Unknown 0:\t0x%x\n", info2
->unknown_0
);
162 printf("Unknown 1:\t0x%x\n", info2
->unknown_1
);
163 printf("Unknown 2:\t0x%x\n", info2
->unknown_2
);
164 printf("Unknown 3:\t0x%x\n", info2
->unknown_3
);
165 printf("Unknown 4:\t0x%x\n", info2
->unknown_4
);
166 printf("Unknown 5:\t0x%x\n", info2
->unknown_5
);
167 printf("Unknown 6:\t0x%x\n", info2
->unknown_6
);
170 static void display_sam_info_1(SAM_ENTRY1
*e1
, SAM_STR1
*s1
)
174 printf("index: 0x%x ", e1
->user_idx
);
175 printf("RID: 0x%x ", e1
->rid_user
);
176 printf("acb: 0x%x ", e1
->acb_info
);
178 unistr2_to_ascii(tmp
, &s1
->uni_acct_name
, sizeof(tmp
)-1);
179 printf("Account: %s\t", tmp
);
181 unistr2_to_ascii(tmp
, &s1
->uni_full_name
, sizeof(tmp
)-1);
182 printf("Name: %s\t", tmp
);
184 unistr2_to_ascii(tmp
, &s1
->uni_acct_desc
, sizeof(tmp
)-1);
185 printf("Desc: %s\n", tmp
);
188 static void display_sam_info_2(SAM_ENTRY2
*e2
, SAM_STR2
*s2
)
192 printf("index: 0x%x ", e2
->user_idx
);
193 printf("RID: 0x%x ", e2
->rid_user
);
194 printf("acb: 0x%x ", e2
->acb_info
);
196 unistr2_to_ascii(tmp
, &s2
->uni_srv_name
, sizeof(tmp
)-1);
197 printf("Account: %s\t", tmp
);
199 unistr2_to_ascii(tmp
, &s2
->uni_srv_desc
, sizeof(tmp
)-1);
200 printf("Name: %s\n", tmp
);
204 static void display_sam_info_3(SAM_ENTRY3
*e3
, SAM_STR3
*s3
)
208 printf("index: 0x%x ", e3
->grp_idx
);
209 printf("RID: 0x%x ", e3
->rid_grp
);
210 printf("attr: 0x%x ", e3
->attr
);
212 unistr2_to_ascii(tmp
, &s3
->uni_grp_name
, sizeof(tmp
)-1);
213 printf("Account: %s\t", tmp
);
215 unistr2_to_ascii(tmp
, &s3
->uni_grp_desc
, sizeof(tmp
)-1);
216 printf("Name: %s\n", tmp
);
220 static void display_sam_info_4(SAM_ENTRY4
*e4
, SAM_STR4
*s4
)
224 printf("index: %d ", e4
->user_idx
);
227 for (i
=0; i
<s4
->acct_name
.str_str_len
; i
++)
228 printf("%c", s4
->acct_name
.buffer
[i
]);
233 static void display_sam_info_5(SAM_ENTRY5
*e5
, SAM_STR5
*s5
)
237 printf("index: 0x%x ", e5
->grp_idx
);
240 for (i
=0; i
<s5
->grp_name
.str_str_len
; i
++)
241 printf("%c", s5
->grp_name
.buffer
[i
]);
246 /****************************************************************************
247 Try samr_connect4 first, then samr_conenct if it fails
248 ****************************************************************************/
249 static NTSTATUS
try_samr_connects(struct cli_state
*cli
, TALLOC_CTX
*mem_ctx
,
250 uint32 access_mask
, POLICY_HND
*connect_pol
)
252 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
254 result
= cli_samr_connect4(cli
, mem_ctx
, access_mask
, connect_pol
);
255 if (!NT_STATUS_IS_OK(result
)) {
256 result
= cli_samr_connect(cli
, mem_ctx
, access_mask
,
262 /**********************************************************************
263 * Query user information
265 static NTSTATUS
cmd_samr_query_user(struct cli_state
*cli
,
267 int argc
, char **argv
)
269 POLICY_HND connect_pol
, domain_pol
, user_pol
;
270 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
271 uint32 info_level
= 21;
272 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
273 SAM_USERINFO_CTR
*user_ctr
;
277 if ((argc
< 2) || (argc
> 4)) {
278 printf("Usage: %s rid [info level] [access mask] \n", argv
[0]);
282 sscanf(argv
[1], "%i", &user_rid
);
285 sscanf(argv
[2], "%i", &info_level
);
288 sscanf(argv
[3], "%x", &access_mask
);
291 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
294 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
297 if (!NT_STATUS_IS_OK(result
))
300 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
301 MAXIMUM_ALLOWED_ACCESS
,
302 &domain_sid
, &domain_pol
);
304 if (!NT_STATUS_IS_OK(result
))
307 result
= cli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
309 user_rid
, &user_pol
);
311 if (!NT_STATUS_IS_OK(result
))
314 ZERO_STRUCT(user_ctr
);
316 result
= cli_samr_query_userinfo(cli
, mem_ctx
, &user_pol
,
317 info_level
, &user_ctr
);
319 if (!NT_STATUS_IS_OK(result
))
322 display_sam_user_info_21(user_ctr
->info
.id21
);
328 /****************************************************************************
330 ****************************************************************************/
331 static void display_group_info1(GROUP_INFO1
*info1
)
335 unistr2_to_ascii(temp
, &info1
->uni_acct_name
, sizeof(temp
)-1);
336 printf("\tGroup Name:\t%s\n", temp
);
337 unistr2_to_ascii(temp
, &info1
->uni_acct_desc
, sizeof(temp
)-1);
338 printf("\tDescription:\t%s\n", temp
);
339 printf("\tunk1:%d\n", info1
->unknown_1
);
340 printf("\tNum Members:%d\n", info1
->num_members
);
343 /****************************************************************************
345 ****************************************************************************/
346 static void display_group_info4(GROUP_INFO4
*info4
)
350 unistr2_to_ascii(desc
, &info4
->uni_acct_desc
, sizeof(desc
)-1);
351 printf("\tGroup Description:%s\n", desc
);
354 /****************************************************************************
355 display sam sync structure
356 ****************************************************************************/
357 static void display_group_info_ctr(GROUP_INFO_CTR
*ctr
)
359 switch (ctr
->switch_value1
) {
361 display_group_info1(&ctr
->group
.info1
);
365 display_group_info4(&ctr
->group
.info4
);
371 /***********************************************************************
372 * Query group information
374 static NTSTATUS
cmd_samr_query_group(struct cli_state
*cli
,
376 int argc
, char **argv
)
378 POLICY_HND connect_pol
, domain_pol
, group_pol
;
379 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
380 uint32 info_level
= 1;
381 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
382 GROUP_INFO_CTR group_ctr
;
386 if ((argc
< 2) || (argc
> 4)) {
387 printf("Usage: %s rid [info level] [access mask]\n", argv
[0]);
391 sscanf(argv
[1], "%i", &group_rid
);
394 sscanf(argv
[2], "%i", &info_level
);
397 sscanf(argv
[3], "%x", &access_mask
);
399 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
402 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
405 if (!NT_STATUS_IS_OK(result
))
408 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
409 MAXIMUM_ALLOWED_ACCESS
,
410 &domain_sid
, &domain_pol
);
412 if (!NT_STATUS_IS_OK(result
))
415 result
= cli_samr_open_group(cli
, mem_ctx
, &domain_pol
,
417 group_rid
, &group_pol
);
419 if (!NT_STATUS_IS_OK(result
))
422 ZERO_STRUCT(group_ctr
);
424 result
= cli_samr_query_groupinfo(cli
, mem_ctx
, &group_pol
,
425 info_level
, &group_ctr
);
426 if (!NT_STATUS_IS_OK(result
)) {
430 display_group_info_ctr(&group_ctr
);
436 /* Query groups a user is a member of */
438 static NTSTATUS
cmd_samr_query_usergroups(struct cli_state
*cli
,
440 int argc
, char **argv
)
442 POLICY_HND connect_pol
,
445 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
448 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
453 if ((argc
< 2) || (argc
> 3)) {
454 printf("Usage: %s rid [access mask]\n", argv
[0]);
458 sscanf(argv
[1], "%i", &user_rid
);
461 sscanf(argv
[2], "%x", &access_mask
);
463 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
466 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
469 if (!NT_STATUS_IS_OK(result
))
472 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
473 MAXIMUM_ALLOWED_ACCESS
,
474 &domain_sid
, &domain_pol
);
476 if (!NT_STATUS_IS_OK(result
))
479 result
= cli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
481 user_rid
, &user_pol
);
483 if (!NT_STATUS_IS_OK(result
))
486 result
= cli_samr_query_usergroups(cli
, mem_ctx
, &user_pol
,
487 &num_groups
, &user_gids
);
489 if (!NT_STATUS_IS_OK(result
))
492 for (i
= 0; i
< num_groups
; i
++) {
493 printf("\tgroup rid:[0x%x] attr:[0x%x]\n",
494 user_gids
[i
].g_rid
, user_gids
[i
].attr
);
501 /* Query aliases a user is a member of */
503 static NTSTATUS
cmd_samr_query_useraliases(struct cli_state
*cli
,
505 int argc
, char **argv
)
507 POLICY_HND connect_pol
, domain_pol
;
508 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
509 uint32 user_rid
, num_aliases
, *alias_rids
;
510 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
515 DOM_SID global_sid_Builtin
;
517 string_to_sid(&global_sid_Builtin
, "S-1-5-32");
519 if ((argc
< 3) || (argc
> 4)) {
520 printf("Usage: %s builtin|domain rid [access mask]\n", argv
[0]);
524 sscanf(argv
[2], "%i", &user_rid
);
527 sscanf(argv
[3], "%x", &access_mask
);
529 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
532 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
535 if (!NT_STATUS_IS_OK(result
))
538 if (StrCaseCmp(argv
[1], "domain")==0)
539 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
541 &domain_sid
, &domain_pol
);
542 else if (StrCaseCmp(argv
[1], "builtin")==0)
543 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
545 &global_sid_Builtin
, &domain_pol
);
549 if (!NT_STATUS_IS_OK(result
))
552 sid_copy(&tmp_sid
, &domain_sid
);
553 sid_append_rid(&tmp_sid
, user_rid
);
554 init_dom_sid2(&sid
, &tmp_sid
);
556 result
= cli_samr_query_useraliases(cli
, mem_ctx
, &domain_pol
, 1, &sid
, &num_aliases
, &alias_rids
);
558 if (!NT_STATUS_IS_OK(result
))
561 for (i
= 0; i
< num_aliases
; i
++) {
562 printf("\tgroup rid:[0x%x]\n", alias_rids
[i
]);
569 /* Query members of a group */
571 static NTSTATUS
cmd_samr_query_groupmem(struct cli_state
*cli
,
573 int argc
, char **argv
)
575 POLICY_HND connect_pol
, domain_pol
, group_pol
;
576 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
577 uint32 num_members
, *group_rids
, *group_attrs
, group_rid
;
578 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
582 if ((argc
< 2) || (argc
> 3)) {
583 printf("Usage: %s rid [access mask]\n", argv
[0]);
587 sscanf(argv
[1], "%i", &group_rid
);
590 sscanf(argv
[2], "%x", &access_mask
);
592 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
595 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
598 if (!NT_STATUS_IS_OK(result
))
601 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
602 MAXIMUM_ALLOWED_ACCESS
,
603 &domain_sid
, &domain_pol
);
605 if (!NT_STATUS_IS_OK(result
))
608 result
= cli_samr_open_group(cli
, mem_ctx
, &domain_pol
,
610 group_rid
, &group_pol
);
612 if (!NT_STATUS_IS_OK(result
))
615 result
= cli_samr_query_groupmem(cli
, mem_ctx
, &group_pol
,
616 &num_members
, &group_rids
,
619 if (!NT_STATUS_IS_OK(result
))
622 for (i
= 0; i
< num_members
; i
++) {
623 printf("\trid:[0x%x] attr:[0x%x]\n", group_rids
[i
],
631 /* Enumerate domain groups */
633 static NTSTATUS
cmd_samr_enum_dom_groups(struct cli_state
*cli
,
635 int argc
, char **argv
)
637 POLICY_HND connect_pol
, domain_pol
;
638 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
639 uint32 start_idx
, size
, num_dom_groups
, i
;
640 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
641 struct acct_info
*dom_groups
;
642 BOOL got_connect_pol
= False
, got_domain_pol
= False
;
644 if ((argc
< 1) || (argc
> 2)) {
645 printf("Usage: %s [access_mask]\n", argv
[0]);
650 sscanf(argv
[1], "%x", &access_mask
);
652 /* Get sam policy handle */
654 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
657 if (!NT_STATUS_IS_OK(result
))
660 got_connect_pol
= True
;
662 /* Get domain policy handle */
664 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
666 &domain_sid
, &domain_pol
);
668 if (!NT_STATUS_IS_OK(result
))
671 got_domain_pol
= True
;
673 /* Enumerate domain groups */
679 result
= cli_samr_enum_dom_groups(
680 cli
, mem_ctx
, &domain_pol
, &start_idx
, size
,
681 &dom_groups
, &num_dom_groups
);
683 if (NT_STATUS_IS_OK(result
) ||
684 NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
)) {
686 for (i
= 0; i
< num_dom_groups
; i
++)
687 printf("group:[%s] rid:[0x%x]\n",
688 dom_groups
[i
].acct_name
,
692 } while (NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
));
696 cli_samr_close(cli
, mem_ctx
, &domain_pol
);
699 cli_samr_close(cli
, mem_ctx
, &connect_pol
);
704 /* Enumerate alias groups */
706 static NTSTATUS
cmd_samr_enum_als_groups(struct cli_state
*cli
,
708 int argc
, char **argv
)
710 POLICY_HND connect_pol
, domain_pol
;
711 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
712 uint32 start_idx
, size
, num_als_groups
, i
;
713 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
714 struct acct_info
*als_groups
;
715 DOM_SID global_sid_Builtin
;
716 BOOL got_connect_pol
= False
, got_domain_pol
= False
;
718 string_to_sid(&global_sid_Builtin
, "S-1-5-32");
720 if ((argc
< 2) || (argc
> 3)) {
721 printf("Usage: %s builtin|domain [access mask]\n", argv
[0]);
726 sscanf(argv
[2], "%x", &access_mask
);
728 /* Get sam policy handle */
730 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
733 if (!NT_STATUS_IS_OK(result
))
736 got_connect_pol
= True
;
738 /* Get domain policy handle */
740 if (StrCaseCmp(argv
[1], "domain")==0)
741 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
743 &domain_sid
, &domain_pol
);
744 else if (StrCaseCmp(argv
[1], "builtin")==0)
745 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
747 &global_sid_Builtin
, &domain_pol
);
751 if (!NT_STATUS_IS_OK(result
))
754 got_domain_pol
= True
;
756 /* Enumerate alias groups */
759 size
= 0xffff; /* Number of groups to retrieve */
762 result
= cli_samr_enum_als_groups(
763 cli
, mem_ctx
, &domain_pol
, &start_idx
, size
,
764 &als_groups
, &num_als_groups
);
766 if (NT_STATUS_IS_OK(result
) ||
767 NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
)) {
769 for (i
= 0; i
< num_als_groups
; i
++)
770 printf("group:[%s] rid:[0x%x]\n",
771 als_groups
[i
].acct_name
,
774 } while (NT_STATUS_V(result
) == NT_STATUS_V(STATUS_MORE_ENTRIES
));
778 cli_samr_close(cli
, mem_ctx
, &domain_pol
);
781 cli_samr_close(cli
, mem_ctx
, &connect_pol
);
786 /* Query alias membership */
788 static NTSTATUS
cmd_samr_query_aliasmem(struct cli_state
*cli
,
790 int argc
, char **argv
)
792 POLICY_HND connect_pol
, domain_pol
, alias_pol
;
793 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
794 uint32 alias_rid
, num_members
, i
;
795 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
797 DOM_SID global_sid_Builtin
;
799 string_to_sid(&global_sid_Builtin
, "S-1-5-32");
801 if ((argc
< 3) || (argc
> 4)) {
802 printf("Usage: %s builtin|domain rid [access mask]\n", argv
[0]);
806 sscanf(argv
[2], "%i", &alias_rid
);
809 sscanf(argv
[3], "%x", &access_mask
);
811 /* Open SAMR handle */
813 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
816 if (!NT_STATUS_IS_OK(result
))
819 /* Open handle on domain */
821 if (StrCaseCmp(argv
[1], "domain")==0)
822 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
823 MAXIMUM_ALLOWED_ACCESS
,
824 &domain_sid
, &domain_pol
);
825 else if (StrCaseCmp(argv
[1], "builtin")==0)
826 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
827 MAXIMUM_ALLOWED_ACCESS
,
828 &global_sid_Builtin
, &domain_pol
);
832 if (!NT_STATUS_IS_OK(result
))
835 /* Open handle on alias */
837 result
= cli_samr_open_alias(cli
, mem_ctx
, &domain_pol
,
839 alias_rid
, &alias_pol
);
840 if (!NT_STATUS_IS_OK(result
))
843 result
= cli_samr_query_aliasmem(cli
, mem_ctx
, &alias_pol
,
844 &num_members
, &alias_sids
);
846 if (!NT_STATUS_IS_OK(result
))
849 for (i
= 0; i
< num_members
; i
++) {
852 sid_to_string(sid_str
, &alias_sids
[i
]);
853 printf("\tsid:[%s]\n", sid_str
);
860 /* Query display info */
862 static NTSTATUS
cmd_samr_query_dispinfo(struct cli_state
*cli
,
864 int argc
, char **argv
)
866 POLICY_HND connect_pol
, domain_pol
;
867 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
868 uint32 start_idx
=0, max_entries
=250, num_entries
, i
;
869 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
870 uint32 info_level
= 1;
871 SAM_DISPINFO_CTR ctr
;
872 SAM_DISPINFO_1 info1
;
873 SAM_DISPINFO_2 info2
;
874 SAM_DISPINFO_3 info3
;
875 SAM_DISPINFO_4 info4
;
876 SAM_DISPINFO_5 info5
;
879 printf("Usage: %s [info level] [start index] [max entries] [access mask]\n", argv
[0]);
884 sscanf(argv
[1], "%i", &info_level
);
887 sscanf(argv
[2], "%i", &start_idx
);
890 sscanf(argv
[3], "%i", &max_entries
);
893 sscanf(argv
[4], "%x", &access_mask
);
895 /* Get sam policy handle */
897 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
900 if (!NT_STATUS_IS_OK(result
))
903 /* Get domain policy handle */
905 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
907 &domain_sid
, &domain_pol
);
909 if (!NT_STATUS_IS_OK(result
))
912 /* Query display info */
917 switch (info_level
) {
920 ctr
.sam
.info1
= &info1
;
924 ctr
.sam
.info2
= &info2
;
928 ctr
.sam
.info3
= &info3
;
932 ctr
.sam
.info4
= &info4
;
936 ctr
.sam
.info5
= &info5
;
943 result
= cli_samr_query_dispinfo(cli
, mem_ctx
, &domain_pol
,
944 &start_idx
, info_level
,
945 &num_entries
, max_entries
, &ctr
);
947 if (!NT_STATUS_IS_OK(result
) && !NT_STATUS_EQUAL(result
, STATUS_MORE_ENTRIES
))
950 if (num_entries
== 0)
953 for (i
= 0; i
< num_entries
; i
++) {
954 switch (info_level
) {
956 display_sam_info_1(&ctr
.sam
.info1
->sam
[i
], &ctr
.sam
.info1
->str
[i
]);
959 display_sam_info_2(&ctr
.sam
.info2
->sam
[i
], &ctr
.sam
.info2
->str
[i
]);
962 display_sam_info_3(&ctr
.sam
.info3
->sam
[i
], &ctr
.sam
.info3
->str
[i
]);
965 display_sam_info_4(&ctr
.sam
.info4
->sam
[i
], &ctr
.sam
.info4
->str
[i
]);
968 display_sam_info_5(&ctr
.sam
.info5
->sam
[i
], &ctr
.sam
.info5
->str
[i
]);
978 /* Query domain info */
980 static NTSTATUS
cmd_samr_query_dominfo(struct cli_state
*cli
,
982 int argc
, char **argv
)
984 POLICY_HND connect_pol
, domain_pol
;
985 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
986 uint32 switch_level
= 2;
987 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
991 printf("Usage: %s [info level] [access mask]\n", argv
[0]);
996 sscanf(argv
[1], "%i", &switch_level
);
999 sscanf(argv
[2], "%x", &access_mask
);
1001 /* Get sam policy handle */
1003 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1006 if (!NT_STATUS_IS_OK(result
))
1009 /* Get domain policy handle */
1011 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1013 &domain_sid
, &domain_pol
);
1015 if (!NT_STATUS_IS_OK(result
))
1018 /* Query domain info */
1020 result
= cli_samr_query_dom_info(cli
, mem_ctx
, &domain_pol
,
1021 switch_level
, &ctr
);
1023 if (!NT_STATUS_IS_OK(result
))
1026 /* Display domain info */
1028 switch (switch_level
) {
1030 display_sam_unk_info_1(&ctr
.info
.inf1
);
1033 display_sam_unk_info_2(&ctr
.info
.inf2
);
1036 printf("cannot display domain info for switch value %d\n",
1043 cli_samr_close(cli
, mem_ctx
, &domain_pol
);
1044 cli_samr_close(cli
, mem_ctx
, &connect_pol
);
1048 /* Create domain user */
1050 static NTSTATUS
cmd_samr_create_dom_user(struct cli_state
*cli
,
1051 TALLOC_CTX
*mem_ctx
,
1052 int argc
, char **argv
)
1054 POLICY_HND connect_pol
, domain_pol
, user_pol
;
1055 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1058 uint32 unknown
, user_rid
;
1059 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1061 if ((argc
< 2) || (argc
> 3)) {
1062 printf("Usage: %s username [access mask]\n", argv
[0]);
1063 return NT_STATUS_OK
;
1066 acct_name
= argv
[1];
1069 sscanf(argv
[2], "%x", &access_mask
);
1071 /* Get sam policy handle */
1073 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1076 if (!NT_STATUS_IS_OK(result
))
1079 /* Get domain policy handle */
1081 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1083 &domain_sid
, &domain_pol
);
1085 if (!NT_STATUS_IS_OK(result
))
1088 /* Create domain user */
1090 acb_info
= ACB_NORMAL
;
1091 unknown
= 0xe005000b; /* No idea what this is - a permission mask? */
1093 result
= cli_samr_create_dom_user(cli
, mem_ctx
, &domain_pol
,
1094 acct_name
, acb_info
, unknown
,
1095 &user_pol
, &user_rid
);
1097 if (!NT_STATUS_IS_OK(result
))
1104 /* Lookup sam names */
1106 static NTSTATUS
cmd_samr_lookup_names(struct cli_state
*cli
,
1107 TALLOC_CTX
*mem_ctx
,
1108 int argc
, char **argv
)
1110 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1111 POLICY_HND connect_pol
, domain_pol
;
1112 uint32 flags
= 0x000003e8; /* Unknown */
1113 uint32 num_rids
, num_names
, *name_types
, *rids
;
1116 DOM_SID global_sid_Builtin
;
1118 string_to_sid(&global_sid_Builtin
, "S-1-5-32");
1121 printf("Usage: %s domain|builtin name1 [name2 [name3] [...]]\n", argv
[0]);
1122 printf("check on the domain SID: S-1-5-21-x-y-z\n");
1123 printf("or check on the builtin SID: S-1-5-32\n");
1124 return NT_STATUS_OK
;
1127 /* Get sam policy and domain handles */
1129 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1132 if (!NT_STATUS_IS_OK(result
))
1135 if (StrCaseCmp(argv
[1], "domain")==0)
1136 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1137 MAXIMUM_ALLOWED_ACCESS
,
1138 &domain_sid
, &domain_pol
);
1139 else if (StrCaseCmp(argv
[1], "builtin")==0)
1140 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1141 MAXIMUM_ALLOWED_ACCESS
,
1142 &global_sid_Builtin
, &domain_pol
);
1144 return NT_STATUS_OK
;
1146 if (!NT_STATUS_IS_OK(result
))
1151 num_names
= argc
- 2;
1152 names
= (const char **)talloc(mem_ctx
, sizeof(char *) * num_names
);
1154 for (i
= 0; i
< argc
- 2; i
++)
1155 names
[i
] = argv
[i
+ 2];
1157 result
= cli_samr_lookup_names(cli
, mem_ctx
, &domain_pol
,
1158 flags
, num_names
, names
,
1159 &num_rids
, &rids
, &name_types
);
1161 if (!NT_STATUS_IS_OK(result
))
1164 /* Display results */
1166 for (i
= 0; i
< num_names
; i
++)
1167 printf("name %s: 0x%x (%d)\n", names
[i
], rids
[i
],
1174 /* Lookup sam rids */
1176 static NTSTATUS
cmd_samr_lookup_rids(struct cli_state
*cli
,
1177 TALLOC_CTX
*mem_ctx
,
1178 int argc
, char **argv
)
1180 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1181 POLICY_HND connect_pol
, domain_pol
;
1182 uint32 flags
= 0x000003e8; /* Unknown */
1183 uint32 num_rids
, num_names
, *rids
, *name_types
;
1188 printf("Usage: %s rid1 [rid2 [rid3] [...]]\n", argv
[0]);
1189 return NT_STATUS_OK
;
1192 /* Get sam policy and domain handles */
1194 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1197 if (!NT_STATUS_IS_OK(result
))
1200 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1201 MAXIMUM_ALLOWED_ACCESS
,
1202 &domain_sid
, &domain_pol
);
1204 if (!NT_STATUS_IS_OK(result
))
1209 num_rids
= argc
- 1;
1210 rids
= (uint32
*)talloc(mem_ctx
, sizeof(uint32
) * num_rids
);
1212 for (i
= 0; i
< argc
- 1; i
++)
1213 sscanf(argv
[i
+ 1], "%i", &rids
[i
]);
1215 result
= cli_samr_lookup_rids(cli
, mem_ctx
, &domain_pol
,
1216 flags
, num_rids
, rids
,
1217 &num_names
, &names
, &name_types
);
1219 if (!NT_STATUS_IS_OK(result
))
1222 /* Display results */
1224 for (i
= 0; i
< num_names
; i
++)
1225 printf("rid 0x%x: %s (%d)\n", rids
[i
], names
[i
], name_types
[i
]);
1231 /* Delete domain user */
1233 static NTSTATUS
cmd_samr_delete_dom_user(struct cli_state
*cli
,
1234 TALLOC_CTX
*mem_ctx
,
1235 int argc
, char **argv
)
1237 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1238 POLICY_HND connect_pol
, domain_pol
, user_pol
;
1239 uint32 access_mask
= MAXIMUM_ALLOWED_ACCESS
;
1241 if ((argc
< 2) || (argc
> 3)) {
1242 printf("Usage: %s username\n", argv
[0]);
1243 return NT_STATUS_OK
;
1247 sscanf(argv
[2], "%x", &access_mask
);
1249 /* Get sam policy and domain handles */
1251 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1254 if (!NT_STATUS_IS_OK(result
))
1257 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1258 MAXIMUM_ALLOWED_ACCESS
,
1259 &domain_sid
, &domain_pol
);
1261 if (!NT_STATUS_IS_OK(result
))
1264 /* Get handle on user */
1267 uint32
*user_rids
, num_rids
, *name_types
;
1268 uint32 flags
= 0x000003e8; /* Unknown */
1270 result
= cli_samr_lookup_names(cli
, mem_ctx
, &domain_pol
,
1271 flags
, 1, (const char **)&argv
[1],
1272 &num_rids
, &user_rids
,
1275 if (!NT_STATUS_IS_OK(result
))
1278 result
= cli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
1280 user_rids
[0], &user_pol
);
1282 if (!NT_STATUS_IS_OK(result
))
1288 result
= cli_samr_delete_dom_user(cli
, mem_ctx
, &user_pol
);
1290 if (!NT_STATUS_IS_OK(result
))
1293 /* Display results */
1299 /**********************************************************************
1300 * Query user security object
1302 static NTSTATUS
cmd_samr_query_sec_obj(struct cli_state
*cli
,
1303 TALLOC_CTX
*mem_ctx
,
1304 int argc
, char **argv
)
1306 POLICY_HND connect_pol
, domain_pol
, user_pol
, *pol
;
1307 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1308 uint32 info_level
= 4;
1310 uint32 user_rid
= 0;
1311 TALLOC_CTX
*ctx
= NULL
;
1312 SEC_DESC_BUF
*sec_desc_buf
=NULL
;
1313 BOOL domain
= False
;
1317 if ((argc
< 1) || (argc
> 2)) {
1318 printf("Usage: %s [rid|-d]\n", argv
[0]);
1319 printf("\tSpecify rid for security on user, -d for security on domain\n");
1320 return NT_STATUS_OK
;
1324 if (strcmp(argv
[1], "-d") == 0)
1327 sscanf(argv
[1], "%i", &user_rid
);
1330 slprintf (server
, sizeof(fstring
)-1, "\\\\%s", cli
->desthost
);
1332 result
= try_samr_connects(cli
, mem_ctx
, MAXIMUM_ALLOWED_ACCESS
,
1335 if (!NT_STATUS_IS_OK(result
))
1338 if (domain
|| user_rid
)
1339 result
= cli_samr_open_domain(cli
, mem_ctx
, &connect_pol
,
1340 MAXIMUM_ALLOWED_ACCESS
,
1341 &domain_sid
, &domain_pol
);
1343 if (!NT_STATUS_IS_OK(result
))
1347 result
= cli_samr_open_user(cli
, mem_ctx
, &domain_pol
,
1348 MAXIMUM_ALLOWED_ACCESS
,
1349 user_rid
, &user_pol
);
1351 if (!NT_STATUS_IS_OK(result
))
1354 /* Pick which query pol to use */
1364 /* Query SAM security object */
1366 result
= cli_samr_query_sec_obj(cli
, mem_ctx
, pol
, info_level
, ctx
,
1369 if (!NT_STATUS_IS_OK(result
))
1372 display_sec_desc(sec_desc_buf
->sec
);
1375 talloc_destroy(ctx
);
1379 static NTSTATUS
cmd_samr_get_dom_pwinfo(struct cli_state
*cli
,
1380 TALLOC_CTX
*mem_ctx
,
1381 int argc
, char **argv
)
1383 NTSTATUS result
= NT_STATUS_UNSUCCESSFUL
;
1384 uint16 unk_0
, unk_1
, unk_2
;
1387 printf("Usage: %s\n", argv
[0]);
1388 return NT_STATUS_OK
;
1391 result
= cli_samr_get_dom_pwinfo(cli
, mem_ctx
, &unk_0
, &unk_1
, &unk_2
);
1393 if (NT_STATUS_IS_OK(result
)) {
1394 printf("unk_0 = 0x%08x\n", unk_0
);
1395 printf("unk_1 = 0x%08x\n", unk_1
);
1396 printf("unk_2 = 0x%08x\n", unk_2
);
1403 /* List of commands exported by this module */
1405 struct cmd_set samr_commands
[] = {
1409 { "queryuser", cmd_samr_query_user
, PI_SAMR
, "Query user info", "" },
1410 { "querygroup", cmd_samr_query_group
, PI_SAMR
, "Query group info", "" },
1411 { "queryusergroups", cmd_samr_query_usergroups
, PI_SAMR
, "Query user groups", "" },
1412 { "queryuseraliases", cmd_samr_query_useraliases
, PI_SAMR
, "Query user aliases", "" },
1413 { "querygroupmem", cmd_samr_query_groupmem
, PI_SAMR
, "Query group membership", "" },
1414 { "queryaliasmem", cmd_samr_query_aliasmem
, PI_SAMR
, "Query alias membership", "" },
1415 { "querydispinfo", cmd_samr_query_dispinfo
, PI_SAMR
, "Query display info", "" },
1416 { "querydominfo", cmd_samr_query_dominfo
, PI_SAMR
, "Query domain info", "" },
1417 { "enumdomgroups", cmd_samr_enum_dom_groups
, PI_SAMR
, "Enumerate domain groups", "" },
1418 { "enumalsgroups", cmd_samr_enum_als_groups
, PI_SAMR
, "Enumerate alias groups", "" },
1420 { "createdomuser", cmd_samr_create_dom_user
, PI_SAMR
, "Create domain user", "" },
1421 { "samlookupnames", cmd_samr_lookup_names
, PI_SAMR
, "Look up names", "" },
1422 { "samlookuprids", cmd_samr_lookup_rids
, PI_SAMR
, "Look up names", "" },
1423 { "deletedomuser", cmd_samr_delete_dom_user
, PI_SAMR
, "Delete domain user", "" },
1424 { "samquerysecobj", cmd_samr_query_sec_obj
, PI_SAMR
, "Query SAMR security object", "" },
1425 { "getdompwinfo", cmd_samr_get_dom_pwinfo
, PI_SAMR
, "Retrieve domain password info", "" },