CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
Path: blob/master/lib/rex/post/meterpreter/extensions/stdapi/tlv.rb
Views: 1904
# -*- coding: binary -*-12module Rex3module Post4module Meterpreter5module Extensions6module Stdapi78##9#10# General11#12##1314TLV_TYPE_HANDLE = TLV_META_TYPE_QWORD | 60015TLV_TYPE_INHERIT = TLV_META_TYPE_BOOL | 60116TLV_TYPE_PROCESS_HANDLE = TLV_META_TYPE_QWORD | 63017TLV_TYPE_THREAD_HANDLE = TLV_META_TYPE_QWORD | 63118TLV_TYPE_PRIVILEGE = TLV_META_TYPE_STRING | 6321920##21#22# Fs23#24##2526TLV_TYPE_DIRECTORY_PATH = TLV_META_TYPE_STRING | 120027TLV_TYPE_FILE_NAME = TLV_META_TYPE_STRING | 120128TLV_TYPE_FILE_PATH = TLV_META_TYPE_STRING | 120229TLV_TYPE_FILE_MODE = TLV_META_TYPE_STRING | 120330TLV_TYPE_FILE_SIZE = TLV_META_TYPE_UINT | 120431TLV_TYPE_FILE_SHORT_NAME = TLV_META_TYPE_STRING | 120532TLV_TYPE_FILE_HASH = TLV_META_TYPE_RAW | 12063334TLV_TYPE_MOUNT = TLV_META_TYPE_GROUP | 120735TLV_TYPE_MOUNT_NAME = TLV_META_TYPE_STRING | 120836TLV_TYPE_MOUNT_TYPE = TLV_META_TYPE_UINT | 120937TLV_TYPE_MOUNT_SPACE_USER = TLV_META_TYPE_QWORD | 121038TLV_TYPE_MOUNT_SPACE_TOTAL = TLV_META_TYPE_QWORD | 121139TLV_TYPE_MOUNT_SPACE_FREE = TLV_META_TYPE_QWORD | 121240TLV_TYPE_MOUNT_UNCPATH = TLV_META_TYPE_STRING | 12134142TLV_TYPE_STAT_BUF32 = TLV_META_TYPE_COMPLEX | 122043TLV_TYPE_STAT_BUF = TLV_META_TYPE_COMPLEX | 12214445TLV_TYPE_SEARCH_RECURSE = TLV_META_TYPE_BOOL | 123046TLV_TYPE_SEARCH_GLOB = TLV_META_TYPE_STRING | 123147TLV_TYPE_SEARCH_ROOT = TLV_META_TYPE_STRING | 123248TLV_TYPE_SEARCH_RESULTS = TLV_META_TYPE_GROUP | 123349TLV_TYPE_SEARCH_MTIME = TLV_META_TYPE_UINT | 123550TLV_TYPE_SEARCH_M_START_DATE= TLV_META_TYPE_UINT | 123651TLV_TYPE_SEARCH_M_END_DATE = TLV_META_TYPE_UINT | 1237525354TLV_TYPE_FILE_MODE_T = TLV_META_TYPE_UINT | 12345556##57#58# Net59#60##6162TLV_TYPE_HOST_NAME = TLV_META_TYPE_STRING | 140063TLV_TYPE_PORT = TLV_META_TYPE_UINT | 140164TLV_TYPE_INTERFACE_MTU = TLV_META_TYPE_UINT | 140265TLV_TYPE_INTERFACE_FLAGS = TLV_META_TYPE_STRING | 140366TLV_TYPE_INTERFACE_INDEX = TLV_META_TYPE_UINT | 14046768TLV_TYPE_SUBNET = TLV_META_TYPE_RAW | 142069TLV_TYPE_NETMASK = TLV_META_TYPE_RAW | 142170TLV_TYPE_GATEWAY = TLV_META_TYPE_RAW | 142271TLV_TYPE_NETWORK_ROUTE = TLV_META_TYPE_GROUP | 142372TLV_TYPE_IP_PREFIX = TLV_META_TYPE_UINT | 142473TLV_TYPE_ARP_ENTRY = TLV_META_TYPE_GROUP | 14257475TLV_TYPE_IP = TLV_META_TYPE_RAW | 143076TLV_TYPE_MAC_ADDRESS = TLV_META_TYPE_RAW | 143177TLV_TYPE_MAC_NAME = TLV_META_TYPE_STRING | 143278TLV_TYPE_NETWORK_INTERFACE = TLV_META_TYPE_GROUP | 143379TLV_TYPE_IP6_SCOPE = TLV_META_TYPE_RAW | 14348081TLV_TYPE_SUBNET_STRING = TLV_META_TYPE_STRING | 144082TLV_TYPE_NETMASK_STRING = TLV_META_TYPE_STRING | 144183TLV_TYPE_GATEWAY_STRING = TLV_META_TYPE_STRING | 144284TLV_TYPE_ROUTE_METRIC = TLV_META_TYPE_UINT | 14438586# Resolve87TLV_TYPE_ADDR_TYPE = TLV_META_TYPE_UINT | 14448889# Proxy configuration90TLV_TYPE_PROXY_CFG_AUTODETECT = TLV_META_TYPE_BOOL | 144591TLV_TYPE_PROXY_CFG_AUTOCONFIGURL = TLV_META_TYPE_STRING | 144692TLV_TYPE_PROXY_CFG_PROXY = TLV_META_TYPE_STRING | 144793TLV_TYPE_PROXY_CFG_PROXYBYPASS = TLV_META_TYPE_STRING | 14489495# Socket96TLV_TYPE_PEER_HOST = TLV_META_TYPE_STRING | 150097TLV_TYPE_PEER_PORT = TLV_META_TYPE_UINT | 150198TLV_TYPE_LOCAL_HOST = TLV_META_TYPE_STRING | 150299TLV_TYPE_LOCAL_PORT = TLV_META_TYPE_UINT | 1503100TLV_TYPE_CONNECT_RETRIES = TLV_META_TYPE_UINT | 1504101TLV_TYPE_NETSTAT_ENTRY = TLV_META_TYPE_GROUP | 1505102TLV_TYPE_PEER_HOST_RAW = TLV_META_TYPE_RAW | 1506103TLV_TYPE_LOCAL_HOST_RAW = TLV_META_TYPE_RAW | 1507104105TLV_TYPE_SHUTDOWN_HOW = TLV_META_TYPE_UINT | 1530106107##108#109# Sys110#111##112113PROCESS_EXECUTE_FLAG_HIDDEN = (1 << 0)114PROCESS_EXECUTE_FLAG_CHANNELIZED = (1 << 1)115PROCESS_EXECUTE_FLAG_SUSPENDED = (1 << 2)116PROCESS_EXECUTE_FLAG_USE_THREAD_TOKEN = (1 << 3)117PROCESS_EXECUTE_FLAG_DESKTOP = (1 << 4)118PROCESS_EXECUTE_FLAG_SESSION = (1 << 5)119PROCESS_EXECUTE_FLAG_SUBSHELL = (1 << 6)120PROCESS_EXECUTE_FLAG_PTY = (1 << 7)121122# Registry123TLV_TYPE_HKEY = TLV_META_TYPE_QWORD | 1000124TLV_TYPE_ROOT_KEY = TLV_TYPE_HKEY125TLV_TYPE_BASE_KEY = TLV_META_TYPE_STRING | 1001126TLV_TYPE_PERMISSION = TLV_META_TYPE_UINT | 1002127TLV_TYPE_KEY_NAME = TLV_META_TYPE_STRING | 1003128TLV_TYPE_VALUE_NAME = TLV_META_TYPE_STRING | 1010129TLV_TYPE_VALUE_TYPE = TLV_META_TYPE_UINT | 1011130TLV_TYPE_VALUE_DATA = TLV_META_TYPE_RAW | 1012131TLV_TYPE_TARGET_HOST = TLV_META_TYPE_STRING | 1013132133# Config134TLV_TYPE_COMPUTER_NAME = TLV_META_TYPE_STRING | 1040135TLV_TYPE_OS_NAME = TLV_META_TYPE_STRING | 1041136TLV_TYPE_USER_NAME = TLV_META_TYPE_STRING | 1042137TLV_TYPE_ARCHITECTURE = TLV_META_TYPE_STRING | 1043138TLV_TYPE_LANG_SYSTEM = TLV_META_TYPE_STRING | 1044139TLV_TYPE_SID = TLV_META_TYPE_STRING | 1045140TLV_TYPE_DOMAIN = TLV_META_TYPE_STRING | 1046141TLV_TYPE_LOGGED_ON_USER_COUNT = TLV_META_TYPE_UINT | 1047142TLV_TYPE_LOCAL_DATETIME = TLV_META_TYPE_STRING | 1048143TLV_TYPE_BUILD_TUPLE = TLV_META_TYPE_STRING | 1049144145# Environment146TLV_TYPE_ENV_VARIABLE = TLV_META_TYPE_STRING | 1100147TLV_TYPE_ENV_VALUE = TLV_META_TYPE_STRING | 1101148TLV_TYPE_ENV_GROUP = TLV_META_TYPE_GROUP | 1102149150DELETE_KEY_FLAG_RECURSIVE = (1 << 0)151152# Process153TLV_TYPE_BASE_ADDRESS = TLV_META_TYPE_QWORD | 2000154TLV_TYPE_ALLOCATION_TYPE = TLV_META_TYPE_UINT | 2001155TLV_TYPE_PROTECTION = TLV_META_TYPE_UINT | 2002156TLV_TYPE_PROCESS_PERMS = TLV_META_TYPE_UINT | 2003157TLV_TYPE_PROCESS_MEMORY = TLV_META_TYPE_RAW | 2004158TLV_TYPE_ALLOC_BASE_ADDRESS = TLV_META_TYPE_QWORD | 2005159TLV_TYPE_MEMORY_STATE = TLV_META_TYPE_UINT | 2006160TLV_TYPE_MEMORY_TYPE = TLV_META_TYPE_UINT | 2007161TLV_TYPE_ALLOC_PROTECTION = TLV_META_TYPE_UINT | 2008162TLV_TYPE_PID = TLV_META_TYPE_UINT | 2300163TLV_TYPE_PROCESS_NAME = TLV_META_TYPE_STRING | 2301164TLV_TYPE_PROCESS_PATH = TLV_META_TYPE_STRING | 2302165TLV_TYPE_PROCESS_GROUP = TLV_META_TYPE_GROUP | 2303166TLV_TYPE_PROCESS_FLAGS = TLV_META_TYPE_UINT | 2304167TLV_TYPE_PROCESS_ARGUMENTS = TLV_META_TYPE_STRING | 2305168TLV_TYPE_PROCESS_ARCH = TLV_META_TYPE_UINT | 2306169TLV_TYPE_PARENT_PID = TLV_META_TYPE_UINT | 2307170TLV_TYPE_PROCESS_SESSION = TLV_META_TYPE_UINT | 2308171TLV_TYPE_PROCESS_ARCH_NAME = TLV_META_TYPE_STRING | 2309172173TLV_TYPE_DRIVER_ENTRY = TLV_META_TYPE_GROUP | 2320174TLV_TYPE_DRIVER_BASENAME = TLV_META_TYPE_STRING | 2321175TLV_TYPE_DRIVER_FILENAME = TLV_META_TYPE_STRING | 2322176177TLV_TYPE_IMAGE_FILE = TLV_META_TYPE_STRING | 2400178TLV_TYPE_IMAGE_FILE_PATH = TLV_META_TYPE_STRING | 2401179TLV_TYPE_PROCEDURE_NAME = TLV_META_TYPE_STRING | 2402180TLV_TYPE_PROCEDURE_ADDRESS = TLV_META_TYPE_QWORD | 2403181TLV_TYPE_IMAGE_BASE = TLV_META_TYPE_QWORD | 2404182TLV_TYPE_IMAGE_GROUP = TLV_META_TYPE_GROUP | 2405183TLV_TYPE_IMAGE_NAME = TLV_META_TYPE_STRING | 2406184185TLV_TYPE_THREAD_ID = TLV_META_TYPE_UINT | 2500186TLV_TYPE_THREAD_PERMS = TLV_META_TYPE_UINT | 2502187TLV_TYPE_EXIT_CODE = TLV_META_TYPE_UINT | 2510188TLV_TYPE_ENTRY_POINT = TLV_META_TYPE_QWORD | 2511189TLV_TYPE_ENTRY_PARAMETER = TLV_META_TYPE_QWORD | 2512190TLV_TYPE_CREATION_FLAGS = TLV_META_TYPE_UINT | 2513191192TLV_TYPE_REGISTER_NAME = TLV_META_TYPE_STRING | 2540193TLV_TYPE_REGISTER_SIZE = TLV_META_TYPE_UINT | 2541194TLV_TYPE_REGISTER_VALUE_32 = TLV_META_TYPE_UINT | 2542195TLV_TYPE_REGISTER = TLV_META_TYPE_GROUP | 2550196197TLV_TYPE_TERMINAL_ROWS = TLV_META_TYPE_UINT | 2600198TLV_TYPE_TERMINAL_COLUMNS = TLV_META_TYPE_UINT | 2601199200##201#202# Memory203#204##205206TLV_TYPE_MEMORY_SEARCH_NEEDLE = TLV_META_TYPE_STRING | 2650207TLV_TYPE_MEMORY_SEARCH_RESULTS = TLV_META_TYPE_GROUP | 2651208TLV_TYPE_MEMORY_SEARCH_MATCH_LEN = TLV_META_TYPE_UINT | 2652209TLV_TYPE_MEMORY_SEARCH_START_ADDR = TLV_META_TYPE_QWORD | 2653210TLV_TYPE_MEMORY_SEARCH_SECT_LEN = TLV_META_TYPE_QWORD | 2654211TLV_TYPE_MEMORY_SEARCH_MATCH_ADDR = TLV_META_TYPE_QWORD | 2655212TLV_TYPE_MEMORY_SEARCH_MATCH_STR = TLV_META_TYPE_STRING | 2656213214##215#216# Ui217#218##219220TLV_TYPE_IDLE_TIME = TLV_META_TYPE_UINT | 3000221TLV_TYPE_KEYS_DUMP = TLV_META_TYPE_STRING | 3001222TLV_TYPE_DESKTOP_SCREENSHOT = TLV_META_TYPE_RAW | 3002223TLV_TYPE_DESKTOP_SWITCH = TLV_META_TYPE_BOOL | 3003224TLV_TYPE_DESKTOP = TLV_META_TYPE_GROUP | 3004225TLV_TYPE_DESKTOP_SESSION = TLV_META_TYPE_UINT | 3005226TLV_TYPE_DESKTOP_STATION = TLV_META_TYPE_STRING | 3006227TLV_TYPE_DESKTOP_NAME = TLV_META_TYPE_STRING | 3007228TLV_TYPE_DESKTOP_SCREENSHOT_QUALITY = TLV_META_TYPE_UINT | 3008229TLV_TYPE_DESKTOP_SCREENSHOT_PE32DLL_BUFFER = TLV_META_TYPE_RAW | 3010230TLV_TYPE_DESKTOP_SCREENSHOT_PE64DLL_BUFFER = TLV_META_TYPE_RAW | 3012231TLV_TYPE_KEYSCAN_TRACK_ACTIVE_WINDOW = TLV_META_TYPE_BOOL | 3013232TLV_TYPE_KEYS_SEND = TLV_META_TYPE_STRING | 3014233TLV_TYPE_MOUSE_ACTION = TLV_META_TYPE_UINT | 3015234TLV_TYPE_MOUSE_X = TLV_META_TYPE_UINT | 3016235TLV_TYPE_MOUSE_Y = TLV_META_TYPE_UINT | 3017236TLV_TYPE_KEYEVENT_SEND = TLV_META_TYPE_RAW | 3018237238##239#240# Event Log241#242##243244TLV_TYPE_EVENT_SOURCENAME = TLV_META_TYPE_STRING | 4000245TLV_TYPE_EVENT_HANDLE = TLV_META_TYPE_QWORD | 4001246TLV_TYPE_EVENT_NUMRECORDS = TLV_META_TYPE_UINT | 4002247248TLV_TYPE_EVENT_READFLAGS = TLV_META_TYPE_UINT | 4003249TLV_TYPE_EVENT_RECORDOFFSET = TLV_META_TYPE_UINT | 4004250251TLV_TYPE_EVENT_RECORDNUMBER = TLV_META_TYPE_UINT | 4006252TLV_TYPE_EVENT_TIMEGENERATED= TLV_META_TYPE_UINT | 4007253TLV_TYPE_EVENT_TIMEWRITTEN = TLV_META_TYPE_UINT | 4008254TLV_TYPE_EVENT_ID = TLV_META_TYPE_UINT | 4009255TLV_TYPE_EVENT_TYPE = TLV_META_TYPE_UINT | 4010256TLV_TYPE_EVENT_CATEGORY = TLV_META_TYPE_UINT | 4011257TLV_TYPE_EVENT_STRING = TLV_META_TYPE_STRING | 4012258TLV_TYPE_EVENT_DATA = TLV_META_TYPE_RAW | 4013259260##261#262# Power263#264##265266TLV_TYPE_POWER_FLAGS = TLV_META_TYPE_UINT | 4100267TLV_TYPE_POWER_REASON = TLV_META_TYPE_UINT | 4101268269##270#271# Webcam272#273##274275TLV_TYPE_WEBCAM_IMAGE = TLV_META_TYPE_RAW | (TLV_EXTENSIONS + 1)276TLV_TYPE_WEBCAM_INTERFACE_ID= TLV_META_TYPE_UINT | (TLV_EXTENSIONS + 2)277TLV_TYPE_WEBCAM_QUALITY = TLV_META_TYPE_UINT | (TLV_EXTENSIONS + 3)278TLV_TYPE_WEBCAM_NAME = TLV_META_TYPE_STRING | (TLV_EXTENSIONS + 4)279280##281#282# Audio283#284##285286TLV_TYPE_AUDIO_DURATION = TLV_META_TYPE_UINT | (TLV_EXTENSIONS + 10)287TLV_TYPE_AUDIO_DATA = TLV_META_TYPE_RAW | (TLV_EXTENSIONS + 11)288TLV_TYPE_AUDIO_INTERFACE_ID = TLV_META_TYPE_UINT | (TLV_EXTENSIONS + 12)289TLV_TYPE_AUDIO_INTERFACE_NAME = TLV_META_TYPE_STRING | (TLV_EXTENSIONS + 13)290291end; end; end; end; end292293294295