Skip to main content

Module webclient

Module webclient 

Source
Expand description

WebClient / WebDAV service probe for RustHound-CE (issue #72 - IsWebClientRunning) https://github.com/g0h4n/IsWebClientRunning-rs

Runs AFTER the LDAP phase, from modules::run_modules, and only when the collection method contacts machines (NOT DCOnly / LdapOnly).

SMB / CREATE \PIPE\DAV RPC SERVICE on IPC$ -> Computer.IsWebClientRunning

A host with the WebClient (WebDAV) service running can be coerced to authenticate over HTTP and relayed to AD CS web enrollment: it is an ESC8 relay candidate. Combined with the HttpEnrollmentEndpoints probe, this closes the two preconditions BloodHound needs to light up the coercion/ESC8 path.

Same SharpHound-style behaviour as the sessions and local-group modules: 445 pre-check (transport::smb::is_reachable), active-computer filter (Computer::is_active), bounded concurrency, no machine contact under DCOnly. Authentication reuses the SMB transport (password, pass the hash, pass the ticket), so nothing new is needed there. The detection stops one step earlier than LocalGroups: no DCE/RPC bind, no opnum, just the CREATE.

Modules§

scanner
The WebDAV detection itself: on an already-authenticated IPC$ session, CREATE the WebClient named pipe and read the NTSTATUS. The pipe’s presence is the whole signal; no DCE/RPC bind, no opnum, read-only (the CREATE only opens the pipe). The connection + SESSION_SETUP live in mod.rs (shared SMB transport, all three auth paths), exactly like samr.rs operates on a connected client for the LocalGroups module.
types
What the WebClient scanner collects: the WebDAV pipe name, the NTSTATUS values we branch on, the per-host Outcome, and the classify that maps one onto the other. Kept free of any SMB types so it unit-tests with no Domain Controller (like LocalGroups-rs tests its NDR decoders).

Functions§

run
Entry point called by run_modules.