Skip to main content

rusthound_ce/objects/
ou.rs

1use serde_json::value::Value;
2use serde::{Deserialize, Serialize};
3use ldap3::SearchEntry;
4use log::{debug, trace};
5use std::collections::HashMap;
6use std::error::Error;
7
8use crate::objects::common::{LdapObject, AceTemplate, GPOChange, Link, SPNTarget, Member};
9use crate::enums::acl::parse_ntsecuritydescriptor;
10use crate::enums::gplink::parse_gplink;
11use crate::enums::sid::decode_guid_le;
12use crate::utils::date::string_to_epoch;
13
14/// Ou structure
15#[derive(Debug, Clone, Deserialize, Serialize, Default)]
16pub struct Ou {
17    #[serde(rename = "GPOChanges")]
18    gpo_changes: GPOChange,
19    #[serde(rename = "ObjectIdentifier")]
20    object_identifier: String,
21    #[serde(rename = "Properties")]
22    properties: OuProperties,
23    #[serde(rename = "Aces")]
24    aces: Vec<AceTemplate>,
25    #[serde(rename = "Links")]
26    links: Vec<Link>,
27    #[serde(rename = "ChildObjects")]
28    child_objects: Vec<Member>,
29    #[serde(rename = "IsDeleted")]
30    is_deleted: bool,
31    #[serde(rename = "IsACLProtected")]
32    is_acl_protected: bool,
33    #[serde(rename = "ContainedBy")]
34    contained_by: Option<Member>,
35}
36
37impl Ou {
38    // New computer.
39    pub fn new() -> Self { 
40        Self { ..Default::default() } 
41    }
42
43    // Immutable access.
44    pub fn properties(&self) -> &OuProperties {
45        &self.properties
46    }
47
48    // Mutable access.
49    pub fn gpo_changes_mut(&mut self) -> &mut GPOChange {
50        &mut self.gpo_changes
51    }
52    pub fn child_objects_mut(&mut self) -> &mut Vec<Member> {
53        &mut self.child_objects
54    }
55
56    /// Function to parse and replace value for OU object.
57    /// <https://bloodhound.readthedocs.io/en/latest/further-reading/json.html#ous>
58    pub fn parse(
59        &mut self,
60        result: SearchEntry,
61        domain: &str,
62        dn_sid: &mut HashMap<String, String>,
63        sid_type: &mut HashMap<String, String>,
64        domain_sid: &str,
65        schema_guid_map: &HashMap<String, String>,
66    ) -> Result<(), Box<dyn Error>> {
67        let result_dn: String = result.dn.to_uppercase();
68        let result_attrs: HashMap<String, Vec<String>> = result.attrs;
69        let result_bin: HashMap<String, Vec<Vec<u8>>> = result.bin_attrs;
70
71        // Debug for current object
72        debug!("Parse OU: {result_dn}");
73
74        // Trace all result attributes
75        for (key, value) in &result_attrs {
76            trace!("  {key:?}:{value:?}");
77        }
78        // Trace all bin result attributes
79        for (key, value) in &result_bin {
80            trace!("  {key:?}:{value:?}");
81        }
82
83        // Change all values...
84        self.properties.domain = domain.to_uppercase();
85        self.properties.distinguishedname = result_dn;
86        self.properties.domainsid = domain_sid.to_string();
87
88        // Check and replace value
89        for (key, value) in &result_attrs {
90             match key.as_str() {
91                 "name" => {
92                     let name = &value[0];
93                     let email = format!("{}@{}", name.to_owned(), domain);
94                     self.properties.name = email.to_uppercase();
95                 }
96                 "description" => {
97                     self.properties.description = value.first().cloned();
98                 }
99                 "whenCreated" => {
100                     let epoch = string_to_epoch(&value[0])?;
101                     if epoch.is_positive() {
102                          self.properties.whencreated = epoch;
103                     }
104                 }
105                 "gPLink" => {
106                     self.links = parse_gplink(value[0].to_string())?;
107                 }
108                 "gPOtions" => {
109                     self.properties.blocksinheritance = value[0].parse::<i64>().unwrap_or(0) == 1;
110                 }
111                 "isDeleted" => {
112                     self.is_deleted = true;
113                 }
114                 _ => {}
115             }
116        }
117
118          // For all, bins attributes
119        for (key, value) in &result_bin {
120             match key.as_str() {
121                "objectGUID" => {
122                    // objectGUID raw to string
123                    let guid = decode_guid_le(&value[0]);
124                    self.object_identifier = guid.to_owned();
125                    self.properties.objectguid = guid;
126                }
127                 "nTSecurityDescriptor" => {
128                     // trace!("nTSecurityDescriptor ACES ACLS ?");
129                     // nTSecurityDescriptor raw to string
130                     let relations_ace = parse_ntsecuritydescriptor(
131                          self,
132                          &value[0],
133                          "OU",
134                          &result_attrs,
135                          &result_bin,
136                          domain,
137                          schema_guid_map,
138                     );
139                     self.aces = relations_ace;
140                 }
141                 _ => {}
142             }
143        }
144        // Push DN and SID in HashMap
145        dn_sid.insert(
146             self.properties.distinguishedname.to_string(),
147             self.object_identifier.to_string(),
148        );
149        // Push DN and Type
150        sid_type.insert(
151            self.object_identifier.to_string(),
152             "OU".to_string(),
153        );
154
155        // Trace and return Ou struct
156        // trace!("JSON OUTPUT: {:?}",serde_json::to_string(&self).unwrap());
157        Ok(())
158    }
159}
160
161impl LdapObject for Ou {
162    // To JSON
163    fn to_json(&self) -> Value {
164        serde_json::to_value(self).unwrap()
165    }
166    
167    // Get values
168    fn get_object_identifier(&self) -> &String {
169        &self.object_identifier
170    }
171    fn get_is_acl_protected(&self) -> &bool {
172        &self.is_acl_protected
173    }
174    fn get_aces(&self) -> &Vec<AceTemplate> {
175        &self.aces
176    }
177    fn get_spntargets(&self) -> &Vec<SPNTarget> {
178        panic!("Not used by current object.");
179    }
180    fn get_allowed_to_delegate(&self) -> &Vec<Member> {
181        panic!("Not used by current object.");
182    }
183    fn get_links(&self) -> &Vec<Link> {
184        &self.links
185    }
186    fn get_contained_by(&self) -> &Option<Member> {
187        &self.contained_by
188    }
189    fn get_child_objects(&self) -> &Vec<Member> {
190        &self.child_objects
191    }
192    fn get_haslaps(&self) -> &bool {
193        &false
194    }
195    
196    // Get mutable values
197    fn get_aces_mut(&mut self) -> &mut Vec<AceTemplate> {
198        &mut self.aces
199    }
200    fn get_spntargets_mut(&mut self) -> &mut Vec<SPNTarget> {
201        panic!("Not used by current object.");
202    }
203    fn get_allowed_to_delegate_mut(&mut self) -> &mut Vec<Member> {
204        panic!("Not used by current object.");
205    }
206    
207    // Edit values
208    fn set_is_acl_protected(&mut self, is_acl_protected: bool) {
209        self.is_acl_protected = is_acl_protected;
210        self.properties.isaclprotected = is_acl_protected;
211    }
212    fn set_aces(&mut self, aces: Vec<AceTemplate>) {
213        self.aces = aces;
214    }
215    fn set_spntargets(&mut self, _spn_targets: Vec<SPNTarget>) {
216        // Not used by current object.
217    }
218    fn set_allowed_to_delegate(&mut self, _allowed_to_delegate: Vec<Member>) {
219        // Not used by current object.
220    }
221    fn set_links(&mut self, links: Vec<Link>) {
222        self.links = links;
223    }
224    fn set_contained_by(&mut self, contained_by: Option<Member>) {
225        self.contained_by = contained_by;
226    }
227    fn set_child_objects(&mut self, child_objects: Vec<Member>) {
228        self.child_objects = child_objects
229    }
230    fn set_owner_rights_flags(&mut self, any: bool, any_inherited: bool) {
231        self.properties.doesanyacegrantownerrights = any;
232        self.properties.doesanyinheritedacegrantownerrights = any_inherited;
233    }
234}
235
236// Ou properties structure
237#[derive(Debug, Clone, Deserialize, Serialize, Default)]
238pub struct OuProperties {
239    domain: String,
240    name: String,
241    distinguishedname: String,
242    domainsid: String,
243    objectguid: String,
244    doesanyacegrantownerrights: bool,
245    doesanyinheritedacegrantownerrights: bool,
246    isaclprotected: bool,
247    highvalue: bool,
248    description: Option<String>,
249    whencreated: i64,
250    blocksinheritance: bool
251}
252
253impl OuProperties {
254    // Immutable access.
255    pub fn name(&self) -> &String {
256        &self.name
257    }
258    pub fn distinguishedname(&self) -> &String {
259        &self.distinguishedname
260    }
261
262    // Mutable access.
263    pub fn isaclprotected_mut(&mut self) -> &mut bool {
264        &mut self.isaclprotected
265    }
266}