diff options
author | Stefan Metzmacher <metze@samba.org> | 2017-10-19 13:23:36 +0200 |
---|---|---|
committer | Anders Broman <a.broman58@gmail.com> | 2020-03-18 15:31:14 +0000 |
commit | 3bf7bfb69e187aeaaed023f5953384ec9756b35d (patch) | |
tree | b1104fce25b5a5d0baf1c53131cee7d2f1098f59 | |
parent | 60378b107146ea02f1f083e5f7701a39a6e4e868 (diff) |
packet-kerberos: dissect AD_TARGET_PRINCIPAL from [MS-KILE]
This is not yet within [MS-KILE], but I'll dochelp@microsoft.com
to document this in the next version.
Change-Id: Ie7017fe31125edc0315653c13831373ac3e67be8
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-on: https://code.wireshark.org/review/36462
Petri-Dish: Anders Broman <a.broman58@gmail.com>
Tested-by: Petri Dish Buildbot
Reviewed-by: Anders Broman <a.broman58@gmail.com>
-rw-r--r-- | epan/dissectors/asn1/kerberos/kerberos.cnf | 3 | ||||
-rw-r--r-- | epan/dissectors/asn1/kerberos/packet-kerberos-template.c | 23 | ||||
-rw-r--r-- | epan/dissectors/packet-kerberos.c | 52 |
3 files changed, 65 insertions, 13 deletions
diff --git a/epan/dissectors/asn1/kerberos/kerberos.cnf b/epan/dissectors/asn1/kerberos/kerberos.cnf index 7723fa1b05..6ea1e3a225 100644 --- a/epan/dissectors/asn1/kerberos/kerberos.cnf +++ b/epan/dissectors/asn1/kerberos/kerberos.cnf @@ -398,6 +398,9 @@ AUTHDATA-TYPE PROT_PREFIX UPPER_CASE case KERBEROS_AD_AP_OPTIONS: offset=dissect_ber_octet_string_wcb(implicit_tag, actx, tree, tvb, offset, hf_index, dissect_kerberos_AD_AP_OPTIONS); break; + case KERBEROS_AD_TARGET_PRINCIPAL: + offset=dissect_ber_octet_string_wcb(implicit_tag, actx, tree, tvb, offset, hf_index, dissect_kerberos_AD_TARGET_PRINCIPAL); + break; default: offset=dissect_ber_octet_string(implicit_tag, actx, tree, tvb, offset, hf_index, NULL); } diff --git a/epan/dissectors/asn1/kerberos/packet-kerberos-template.c b/epan/dissectors/asn1/kerberos/packet-kerberos-template.c index c4fd9cde71..de266063c1 100644 --- a/epan/dissectors/asn1/kerberos/packet-kerberos-template.c +++ b/epan/dissectors/asn1/kerberos/packet-kerberos-template.c @@ -186,6 +186,7 @@ static gint hf_krb_pa_supported_enctypes_claims_supported = -1; static gint hf_krb_pa_supported_enctypes_resource_sid_compression_disabled = -1; static gint hf_krb_ad_ap_options = -1; static gint hf_krb_ad_ap_options_cbt = -1; +static gint hf_krb_ad_target_principal = -1; #include "packet-kerberos-hf.c" /* Initialize the subtree pointers */ @@ -1819,6 +1820,25 @@ dissect_kerberos_AD_AP_OPTIONS(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, return offset; } + +static int +dissect_kerberos_AD_TARGET_PRINCIPAL(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, + int offset _U_, asn1_ctx_t *actx _U_, + proto_tree *tree _U_, int hf_index _U_) +{ + int tp_offset, tp_len; + guint16 bc; + + bc = tvb_reported_length_remaining(tvb, offset); + tp_offset = offset; + tp_len = bc; + proto_tree_add_item(tree, hf_krb_ad_target_principal, tvb, + tp_offset, tp_len, + ENC_UTF_16 | ENC_LITTLE_ENDIAN); + + return offset; +} + /* Dissect a GSSAPI checksum as per RFC1964. This is NOT ASN.1 encoded. */ static int @@ -2685,6 +2705,9 @@ void proto_register_kerberos(void) { { &hf_krb_ad_ap_options_cbt, { "ChannelBindings", "kerberos.ad_ap_options.cbt", FT_BOOLEAN, 32, TFS(&set_tfs), 0x00004000, NULL, HFILL }}, + { &hf_krb_ad_target_principal, { + "Target Principal", "kerberos.ad_target_principal", FT_STRING, BASE_NONE, + NULL, 0, NULL, HFILL }}, #include "packet-kerberos-hfarr.c" }; diff --git a/epan/dissectors/packet-kerberos.c b/epan/dissectors/packet-kerberos.c index a302148aca..998408a518 100644 --- a/epan/dissectors/packet-kerberos.c +++ b/epan/dissectors/packet-kerberos.c @@ -194,6 +194,7 @@ static gint hf_krb_pa_supported_enctypes_claims_supported = -1; static gint hf_krb_pa_supported_enctypes_resource_sid_compression_disabled = -1; static gint hf_krb_ad_ap_options = -1; static gint hf_krb_ad_ap_options_cbt = -1; +static gint hf_krb_ad_target_principal = -1; /*--- Included file: packet-kerberos-hf.c ---*/ #line 1 "./asn1/kerberos/packet-kerberos-hf.c" @@ -408,7 +409,7 @@ static int hf_kerberos_PAC_OPTIONS_FLAGS_forward_to_full_dc = -1; static int hf_kerberos_PAC_OPTIONS_FLAGS_resource_based_constrained_delegation = -1; /*--- End of included file: packet-kerberos-hf.c ---*/ -#line 190 "./asn1/kerberos/packet-kerberos-template.c" +#line 191 "./asn1/kerberos/packet-kerberos-template.c" /* Initialize the subtree pointers */ static gint ett_kerberos = -1; @@ -500,7 +501,7 @@ static gint ett_kerberos_PA_FX_FAST_REPLY = -1; static gint ett_kerberos_KrbFastArmoredRep = -1; /*--- End of included file: packet-kerberos-ett.c ---*/ -#line 206 "./asn1/kerberos/packet-kerberos-template.c" +#line 207 "./asn1/kerberos/packet-kerberos-template.c" static expert_field ei_kerberos_decrypted_keytype = EI_INIT; static expert_field ei_kerberos_address = EI_INIT; @@ -620,7 +621,7 @@ typedef enum _KERBEROS_PADATA_TYPE_enum { } KERBEROS_PADATA_TYPE_enum; /*--- End of included file: packet-kerberos-val.h ---*/ -#line 218 "./asn1/kerberos/packet-kerberos-template.c" +#line 219 "./asn1/kerberos/packet-kerberos-template.c" static void call_kerberos_callbacks(packet_info *pinfo, proto_tree *tree, tvbuff_t *tvb, int tag, kerberos_callbacks *cb) @@ -2225,6 +2226,25 @@ dissect_kerberos_AD_AP_OPTIONS(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, return offset; } + +static int +dissect_kerberos_AD_TARGET_PRINCIPAL(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, + int offset _U_, asn1_ctx_t *actx _U_, + proto_tree *tree _U_, int hf_index _U_) +{ + int tp_offset, tp_len; + guint16 bc; + + bc = tvb_reported_length_remaining(tvb, offset); + tp_offset = offset; + tp_len = bc; + proto_tree_add_item(tree, hf_krb_ad_target_principal, tvb, + tp_offset, tp_len, + ENC_UTF_16 | ENC_LITTLE_ENDIAN); + + return offset; +} + /* Dissect a GSSAPI checksum as per RFC1964. This is NOT ASN.1 encoded. */ static int @@ -3168,6 +3188,9 @@ dissect_kerberos_T_ad_data(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int off case KERBEROS_AD_AP_OPTIONS: offset=dissect_ber_octet_string_wcb(implicit_tag, actx, tree, tvb, offset, hf_index, dissect_kerberos_AD_AP_OPTIONS); break; + case KERBEROS_AD_TARGET_PRINCIPAL: + offset=dissect_ber_octet_string_wcb(implicit_tag, actx, tree, tvb, offset, hf_index, dissect_kerberos_AD_TARGET_PRINCIPAL); + break; default: offset=dissect_ber_octet_string(implicit_tag, actx, tree, tvb, offset, hf_index, NULL); } @@ -3309,7 +3332,7 @@ static const value_string kerberos_ADDR_TYPE_vals[] = { static int dissect_kerberos_ADDR_TYPE(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 409 "./asn1/kerberos/kerberos.cnf" +#line 412 "./asn1/kerberos/kerberos.cnf" kerberos_private_data_t *private_data = kerberos_get_private_data(actx); offset = dissect_ber_integer(implicit_tag, actx, tree, tvb, offset, hf_index, &(private_data->addr_type)); @@ -3818,7 +3841,7 @@ static const ber_sequence_t KDC_REQ_BODY_sequence[] = { static int dissect_kerberos_KDC_REQ_BODY(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 413 "./asn1/kerberos/kerberos.cnf" +#line 416 "./asn1/kerberos/kerberos.cnf" conversation_t *conversation; /* @@ -4070,7 +4093,7 @@ dissect_kerberos_AP_REP(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset static int dissect_kerberos_T_kRB_SAFE_BODY_user_data(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 436 "./asn1/kerberos/kerberos.cnf" +#line 439 "./asn1/kerberos/kerberos.cnf" kerberos_private_data_t* private_data = kerberos_get_private_data(actx); tvbuff_t *new_tvb; offset=dissect_ber_octet_string(FALSE, actx, tree, tvb, offset, hf_index, &new_tvb); @@ -4320,14 +4343,14 @@ dissect_kerberos_METHOD_DATA(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int o static int dissect_kerberos_T_encrypted_pa_data(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 452 "./asn1/kerberos/kerberos.cnf" +#line 455 "./asn1/kerberos/kerberos.cnf" kerberos_private_data_t* private_data = kerberos_get_private_data(actx); private_data->is_enc_padata = TRUE; offset = dissect_kerberos_METHOD_DATA(implicit_tag, tvb, offset, actx, tree, hf_index); -#line 456 "./asn1/kerberos/kerberos.cnf" +#line 459 "./asn1/kerberos/kerberos.cnf" private_data->is_enc_padata = FALSE; @@ -4411,7 +4434,7 @@ dissect_kerberos_EncAPRepPart(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int static int dissect_kerberos_T_encKrbPrivPart_user_data(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 444 "./asn1/kerberos/kerberos.cnf" +#line 447 "./asn1/kerberos/kerberos.cnf" kerberos_private_data_t* private_data = kerberos_get_private_data(actx); tvbuff_t *new_tvb; offset=dissect_ber_octet_string(FALSE, actx, tree, tvb, offset, hf_index, &new_tvb); @@ -4912,7 +4935,7 @@ dissect_kerberos_PA_S4U2Self(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int o static int dissect_kerberos_T_subject_certificate(gboolean implicit_tag _U_, tvbuff_t *tvb _U_, int offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { -#line 406 "./asn1/kerberos/kerberos.cnf" +#line 409 "./asn1/kerberos/kerberos.cnf" offset=dissect_ber_octet_string_wcb(implicit_tag, actx, tree, tvb, offset,hf_index, dissect_x509af_Certificate); @@ -5175,7 +5198,7 @@ dissect_kerberos_EncryptedChallenge(gboolean implicit_tag _U_, tvbuff_t *tvb _U_ /*--- End of included file: packet-kerberos-fn.c ---*/ -#line 2264 "./asn1/kerberos/packet-kerberos-template.c" +#line 2284 "./asn1/kerberos/packet-kerberos-template.c" /* Make wrappers around exported functions for now */ int @@ -5600,6 +5623,9 @@ void proto_register_kerberos(void) { { &hf_krb_ad_ap_options_cbt, { "ChannelBindings", "kerberos.ad_ap_options.cbt", FT_BOOLEAN, 32, TFS(&set_tfs), 0x00004000, NULL, HFILL }}, + { &hf_krb_ad_target_principal, { + "Target Principal", "kerberos.ad_target_principal", FT_STRING, BASE_NONE, + NULL, 0, NULL, HFILL }}, /*--- Included file: packet-kerberos-hfarr.c ---*/ @@ -6438,7 +6464,7 @@ void proto_register_kerberos(void) { NULL, HFILL }}, /*--- End of included file: packet-kerberos-hfarr.c ---*/ -#line 2690 "./asn1/kerberos/packet-kerberos-template.c" +#line 2713 "./asn1/kerberos/packet-kerberos-template.c" }; /* List of subtrees */ @@ -6532,7 +6558,7 @@ void proto_register_kerberos(void) { &ett_kerberos_KrbFastArmoredRep, /*--- End of included file: packet-kerberos-ettarr.c ---*/ -#line 2708 "./asn1/kerberos/packet-kerberos-template.c" +#line 2731 "./asn1/kerberos/packet-kerberos-template.c" }; static ei_register_info ei[] = { |