Skip to main content

Module scanner

Module scanner 

Source
Expand description

The WebDAV detection itself: on an already-authenticated IPC$ session, CREATE the WebClient named pipe and read the NTSTATUS. The pipe’s presence is the whole signal; no DCE/RPC bind, no opnum, read-only (the CREATE only opens the pipe). The connection + SESSION_SETUP live in mod.rs (shared SMB transport, all three auth paths), exactly like samr.rs operates on a connected client for the LocalGroups module.

Functions§

probe
Probe the WebClient pipe on a connected IPC$ session.