Skip to main content

rusthound_ce/modules/webclient/
scanner.rs

1//! The WebDAV detection itself: on an already-authenticated IPC$ session, CREATE
2//! the WebClient named pipe and read the NTSTATUS. The pipe's presence is the
3//! whole signal; no DCE/RPC bind, no opnum, read-only (the CREATE only opens the
4//! pipe). The connection + SESSION_SETUP live in `mod.rs` (shared SMB transport,
5//! all three auth paths), exactly like `samr.rs` operates on a connected client
6//! for the LocalGroups module.
7
8use log::trace;
9use smb2_client::{SmbClient, SmbError};
10
11use crate::modules::webclient::types::{classify, status, Outcome, PIPE_NAME, PIPE_NAME_DISPLAY};
12
13/// Probe the WebClient pipe on a connected IPC$ session.
14///
15/// Uses the raw `open_pipe` (not the `open_rpc_pipe` anyhow wrapper) so the
16/// NTSTATUS survives for [`classify`]: `Ok` => running, `Status(code)` => the
17/// reason, anything else => a transport-level error carried verbatim.
18pub async fn probe(smb: &mut SmbClient, host: &str) -> Outcome {
19    trace!("[{host}] CREATE {PIPE_NAME_DISPLAY}");
20    match smb.open_pipe(PIPE_NAME).await {
21        Ok(_file_id) => classify(status::SUCCESS),
22        Err(SmbError::Status(code, _)) => classify(code),
23        Err(other) => Outcome::Error(format!("open {PIPE_NAME_DISPLAY}: {other}")),
24    }
25}