rusthound_ce/objects/
ou.rs1use serde_json::value::Value;
2use serde::{Deserialize, Serialize};
3use ldap3::SearchEntry;
4use log::{debug, trace};
5use std::collections::HashMap;
6use std::error::Error;
7
8use crate::objects::common::{LdapObject, AceTemplate, GPOChange, Link, SPNTarget, Member};
9use crate::enums::acl::parse_ntsecuritydescriptor;
10use crate::enums::gplink::parse_gplink;
11use crate::enums::sid::decode_guid_le;
12use crate::utils::date::string_to_epoch;
13
14#[derive(Debug, Clone, Deserialize, Serialize, Default)]
16pub struct Ou {
17 #[serde(rename = "GPOChanges")]
18 gpo_changes: GPOChange,
19 #[serde(rename = "ObjectIdentifier")]
20 object_identifier: String,
21 #[serde(rename = "Properties")]
22 properties: OuProperties,
23 #[serde(rename = "Aces")]
24 aces: Vec<AceTemplate>,
25 #[serde(rename = "Links")]
26 links: Vec<Link>,
27 #[serde(rename = "ChildObjects")]
28 child_objects: Vec<Member>,
29 #[serde(rename = "IsDeleted")]
30 is_deleted: bool,
31 #[serde(rename = "IsACLProtected")]
32 is_acl_protected: bool,
33 #[serde(rename = "ContainedBy")]
34 contained_by: Option<Member>,
35}
36
37impl Ou {
38 pub fn new() -> Self {
40 Self { ..Default::default() }
41 }
42
43 pub fn properties(&self) -> &OuProperties {
45 &self.properties
46 }
47
48 pub fn gpo_changes_mut(&mut self) -> &mut GPOChange {
50 &mut self.gpo_changes
51 }
52 pub fn child_objects_mut(&mut self) -> &mut Vec<Member> {
53 &mut self.child_objects
54 }
55
56 pub fn parse(
59 &mut self,
60 result: SearchEntry,
61 domain: &str,
62 dn_sid: &mut HashMap<String, String>,
63 sid_type: &mut HashMap<String, String>,
64 domain_sid: &str,
65 schema_guid_map: &HashMap<String, String>,
66 ) -> Result<(), Box<dyn Error>> {
67 let result_dn: String = result.dn.to_uppercase();
68 let result_attrs: HashMap<String, Vec<String>> = result.attrs;
69 let result_bin: HashMap<String, Vec<Vec<u8>>> = result.bin_attrs;
70
71 debug!("Parse OU: {result_dn}");
73
74 for (key, value) in &result_attrs {
76 trace!(" {key:?}:{value:?}");
77 }
78 for (key, value) in &result_bin {
80 trace!(" {key:?}:{value:?}");
81 }
82
83 self.properties.domain = domain.to_uppercase();
85 self.properties.distinguishedname = result_dn;
86 self.properties.domainsid = domain_sid.to_string();
87
88 for (key, value) in &result_attrs {
90 match key.as_str() {
91 "name" => {
92 let name = &value[0];
93 let email = format!("{}@{}", name.to_owned(), domain);
94 self.properties.name = email.to_uppercase();
95 }
96 "description" => {
97 self.properties.description = value.first().cloned();
98 }
99 "whenCreated" => {
100 let epoch = string_to_epoch(&value[0])?;
101 if epoch.is_positive() {
102 self.properties.whencreated = epoch;
103 }
104 }
105 "gPLink" => {
106 self.links = parse_gplink(value[0].to_string())?;
107 }
108 "gPOtions" => {
109 self.properties.blocksinheritance = value[0].parse::<i64>().unwrap_or(0) == 1;
110 }
111 "isDeleted" => {
112 self.is_deleted = true;
113 }
114 _ => {}
115 }
116 }
117
118 for (key, value) in &result_bin {
120 match key.as_str() {
121 "objectGUID" => {
122 let guid = decode_guid_le(&value[0]);
124 self.object_identifier = guid.to_owned();
125 self.properties.objectguid = guid;
126 }
127 "nTSecurityDescriptor" => {
128 let relations_ace = parse_ntsecuritydescriptor(
131 self,
132 &value[0],
133 "OU",
134 &result_attrs,
135 &result_bin,
136 domain,
137 schema_guid_map,
138 );
139 self.aces = relations_ace;
140 }
141 _ => {}
142 }
143 }
144 dn_sid.insert(
146 self.properties.distinguishedname.to_string(),
147 self.object_identifier.to_string(),
148 );
149 sid_type.insert(
151 self.object_identifier.to_string(),
152 "OU".to_string(),
153 );
154
155 Ok(())
158 }
159}
160
161impl LdapObject for Ou {
162 fn to_json(&self) -> Value {
164 serde_json::to_value(self).unwrap()
165 }
166
167 fn get_object_identifier(&self) -> &String {
169 &self.object_identifier
170 }
171 fn get_is_acl_protected(&self) -> &bool {
172 &self.is_acl_protected
173 }
174 fn get_aces(&self) -> &Vec<AceTemplate> {
175 &self.aces
176 }
177 fn get_spntargets(&self) -> &Vec<SPNTarget> {
178 panic!("Not used by current object.");
179 }
180 fn get_allowed_to_delegate(&self) -> &Vec<Member> {
181 panic!("Not used by current object.");
182 }
183 fn get_links(&self) -> &Vec<Link> {
184 &self.links
185 }
186 fn get_contained_by(&self) -> &Option<Member> {
187 &self.contained_by
188 }
189 fn get_child_objects(&self) -> &Vec<Member> {
190 &self.child_objects
191 }
192 fn get_haslaps(&self) -> &bool {
193 &false
194 }
195
196 fn get_aces_mut(&mut self) -> &mut Vec<AceTemplate> {
198 &mut self.aces
199 }
200 fn get_spntargets_mut(&mut self) -> &mut Vec<SPNTarget> {
201 panic!("Not used by current object.");
202 }
203 fn get_allowed_to_delegate_mut(&mut self) -> &mut Vec<Member> {
204 panic!("Not used by current object.");
205 }
206
207 fn set_is_acl_protected(&mut self, is_acl_protected: bool) {
209 self.is_acl_protected = is_acl_protected;
210 self.properties.isaclprotected = is_acl_protected;
211 }
212 fn set_aces(&mut self, aces: Vec<AceTemplate>) {
213 self.aces = aces;
214 }
215 fn set_spntargets(&mut self, _spn_targets: Vec<SPNTarget>) {
216 }
218 fn set_allowed_to_delegate(&mut self, _allowed_to_delegate: Vec<Member>) {
219 }
221 fn set_links(&mut self, links: Vec<Link>) {
222 self.links = links;
223 }
224 fn set_contained_by(&mut self, contained_by: Option<Member>) {
225 self.contained_by = contained_by;
226 }
227 fn set_child_objects(&mut self, child_objects: Vec<Member>) {
228 self.child_objects = child_objects
229 }
230 fn set_owner_rights_flags(&mut self, any: bool, any_inherited: bool) {
231 self.properties.doesanyacegrantownerrights = any;
232 self.properties.doesanyinheritedacegrantownerrights = any_inherited;
233 }
234}
235
236#[derive(Debug, Clone, Deserialize, Serialize, Default)]
238pub struct OuProperties {
239 domain: String,
240 name: String,
241 distinguishedname: String,
242 domainsid: String,
243 objectguid: String,
244 doesanyacegrantownerrights: bool,
245 doesanyinheritedacegrantownerrights: bool,
246 isaclprotected: bool,
247 highvalue: bool,
248 description: Option<String>,
249 whencreated: i64,
250 blocksinheritance: bool
251}
252
253impl OuProperties {
254 pub fn name(&self) -> &String {
256 &self.name
257 }
258 pub fn distinguishedname(&self) -> &String {
259 &self.distinguishedname
260 }
261
262 pub fn isaclprotected_mut(&mut self) -> &mut bool {
264 &mut self.isaclprotected
265 }
266}