2014-04-06 18:31:53 +00:00
|
|
|
/* Benjamin DELPY `gentilkiwi`
|
|
|
|
http://blog.gentilkiwi.com
|
|
|
|
benjamin@gentilkiwi.com
|
2015-08-25 09:19:01 +00:00
|
|
|
Licence : https://creativecommons.org/licenses/by/4.0/
|
2014-04-06 18:31:53 +00:00
|
|
|
*/
|
|
|
|
#pragma once
|
|
|
|
#include <ntstatus.h>
|
|
|
|
#define WIN32_NO_STATUS
|
|
|
|
#define SECURITY_WIN32
|
2016-07-10 22:32:51 +00:00
|
|
|
#define CINTERFACE
|
|
|
|
#define COBJMACROS
|
2014-04-06 18:31:53 +00:00
|
|
|
#include <windows.h>
|
|
|
|
#include <sspi.h>
|
|
|
|
#include <sddl.h>
|
|
|
|
#include <wincred.h>
|
|
|
|
#include <ntsecapi.h>
|
|
|
|
#include <ntsecpkg.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <wchar.h>
|
|
|
|
#include "../modules/kull_m_output.h"
|
|
|
|
//#define KERBEROS_TOOLS
|
|
|
|
//#define LSASS_DECRYPT
|
2014-04-25 00:03:55 +00:00
|
|
|
#define NET_MODULE
|
2016-06-23 00:16:36 +00:00
|
|
|
#define SQLITE3_OMIT
|
2014-04-06 18:31:53 +00:00
|
|
|
#ifdef _M_X64
|
|
|
|
#define MIMIKATZ_ARCH L"x64"
|
|
|
|
#else ifdef _M_IX86
|
|
|
|
#define MIMIKATZ_ARCH L"x86"
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#define MIMIKATZ L"mimikatz"
|
2016-01-12 02:13:12 +00:00
|
|
|
#define MIMIKATZ_VERSION L"2.1"
|
2016-01-06 01:46:28 +00:00
|
|
|
#define MIMIKATZ_CODENAME L"A La Vie, A L\'Amour"
|
2016-01-12 02:13:12 +00:00
|
|
|
#define MIMIKATZ_FULL MIMIKATZ L" " MIMIKATZ_VERSION L" (" MIMIKATZ_ARCH L") built on " TEXT(__DATE__) L" " TEXT(__TIME__)
|
2016-09-28 20:12:35 +00:00
|
|
|
#define MIMIKATZ_SECOND L"\"" MIMIKATZ_CODENAME L"\" - CQURE Edition"
|
2014-11-20 07:57:04 +00:00
|
|
|
#define MIMIKATZ_SPECIAL L" "
|
2014-04-23 20:00:29 +00:00
|
|
|
#define MIMIKATZ_DEFAULT_LOG MIMIKATZ L".log"
|
2014-04-06 18:31:53 +00:00
|
|
|
#define MIMIKATZ_DRIVER L"mimidrv"
|
|
|
|
#define MIMIKATZ_KERBEROS_EXT L"kirbi"
|
|
|
|
|
2014-05-04 23:24:54 +00:00
|
|
|
#ifdef _WINDLL
|
|
|
|
#define MIMIKATZ_AUTO_COMMAND_START 0
|
|
|
|
#define MIMIKATZ_AUTO_COMMAND_STRING L"powershell"
|
|
|
|
#else
|
|
|
|
#define MIMIKATZ_AUTO_COMMAND_START 1
|
|
|
|
#define MIMIKATZ_AUTO_COMMAND_STRING L"commandline"
|
|
|
|
#endif
|
|
|
|
|
2014-04-06 18:31:53 +00:00
|
|
|
#ifndef NT_SUCCESS
|
|
|
|
#define NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifndef PRINT_ERROR
|
|
|
|
#define PRINT_ERROR(...) (kprintf(L"ERROR " TEXT(__FUNCTION__) L" ; " __VA_ARGS__))
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifndef PRINT_ERROR_AUTO
|
|
|
|
#define PRINT_ERROR_AUTO(func) (kprintf(L"ERROR " TEXT(__FUNCTION__) L" ; " func L" (0x%08x)\n", GetLastError()))
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifndef W00T
|
|
|
|
#define W00T(...) (kprintf(TEXT(__FUNCTION__) L" w00t! ; " __VA_ARGS__))
|
|
|
|
#endif
|
|
|
|
|
|
|
|
DWORD MIMIKATZ_NT_MAJOR_VERSION, MIMIKATZ_NT_MINOR_VERSION, MIMIKATZ_NT_BUILD_NUMBER;
|
|
|
|
|
|
|
|
#ifndef MS_ENH_RSA_AES_PROV_XP
|
|
|
|
#define MS_ENH_RSA_AES_PROV_XP L"Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype)"
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#define RtlEqualGuid(L1, L2) (RtlEqualMemory(L1, L2, sizeof(GUID)))
|
2015-06-03 00:13:43 +00:00
|
|
|
|
2016-07-19 15:48:55 +00:00
|
|
|
#define SIZE_ALIGN(size, alignment) (size + ((size % alignment) ? (alignment - (size % alignment)) : 0))
|
|
|
|
|
2014-04-06 18:31:53 +00:00
|
|
|
#define LM_NTLM_HASH_LENGTH 16
|
|
|
|
|
|
|
|
#define KULL_M_WIN_BUILD_XP 2600
|
|
|
|
#define KULL_M_WIN_BUILD_2K3 3790
|
|
|
|
#define KULL_M_WIN_BUILD_VISTA 6000
|
|
|
|
#define KULL_M_WIN_BUILD_7 7600
|
|
|
|
#define KULL_M_WIN_BUILD_8 9200
|
|
|
|
#define KULL_M_WIN_BUILD_BLUE 9600
|
2016-03-27 17:22:36 +00:00
|
|
|
#define KULL_M_WIN_BUILD_10_1507 10240
|
|
|
|
#define KULL_M_WIN_BUILD_10_1511 10586
|
2016-08-08 01:35:01 +00:00
|
|
|
#define KULL_M_WIN_BUILD_10_1607 14393
|
2014-04-06 18:31:53 +00:00
|
|
|
|
|
|
|
#define KULL_M_WIN_MIN_BUILD_XP 2500
|
|
|
|
#define KULL_M_WIN_MIN_BUILD_2K3 3000
|
2015-01-13 21:08:23 +00:00
|
|
|
#define KULL_M_WIN_MIN_BUILD_VISTA 5000
|
2014-04-06 18:31:53 +00:00
|
|
|
#define KULL_M_WIN_MIN_BUILD_7 7000
|
|
|
|
#define KULL_M_WIN_MIN_BUILD_8 8000
|
2014-10-10 08:53:03 +00:00
|
|
|
#define KULL_M_WIN_MIN_BUILD_BLUE 9400
|
|
|
|
#define KULL_M_WIN_MIN_BUILD_10 9800
|