Linux anchor 4.4.0-210-generic #242-Ubuntu SMP Fri Apr 16 09:57:56 UTC 2021 x86_64
Apache/2.4.18 (Ubuntu)
Server IP : 10.10.100.4 & Your IP : 216.73.217.150
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
lib /
python2.7 /
dist-packages /
samba /
netcmd /
Delete
Unzip
Name
Size
Permission
Date
Action
__init__.py
7.78
KB
-rw-r--r--
2015-07-21 11:47
__init__.pyc
8.27
KB
-rw-r--r--
2021-05-01 07:33
common.py
2.38
KB
-rw-r--r--
2015-07-21 11:47
common.pyc
2.28
KB
-rw-r--r--
2021-05-01 07:33
dbcheck.py
5.76
KB
-rw-r--r--
2015-07-21 11:47
dbcheck.pyc
4.56
KB
-rw-r--r--
2021-05-01 07:33
delegation.py
10.88
KB
-rw-r--r--
2015-07-21 11:47
delegation.pyc
9.22
KB
-rw-r--r--
2021-05-01 07:33
dns.py
47.6
KB
-rw-r--r--
2015-07-21 11:47
dns.pyc
42.92
KB
-rw-r--r--
2021-05-01 07:33
domain.py
168.08
KB
-rw-r--r--
2016-02-22 10:36
domain.pyc
103.79
KB
-rw-r--r--
2021-05-01 07:33
drs.py
21.21
KB
-rw-r--r--
2015-07-21 11:47
drs.pyc
19.73
KB
-rw-r--r--
2021-05-01 07:33
dsacl.py
7.37
KB
-rw-r--r--
2015-07-21 11:47
dsacl.pyc
6.67
KB
-rw-r--r--
2021-05-01 07:33
fsmo.py
19.43
KB
-rw-r--r--
2016-06-14 09:37
fsmo.pyc
14.09
KB
-rw-r--r--
2021-05-01 07:33
gpo.py
39.7
KB
-rw-r--r--
2015-07-21 11:47
gpo.pyc
33.57
KB
-rw-r--r--
2021-05-01 07:33
group.py
17.99
KB
-rw-r--r--
2015-07-21 11:47
group.pyc
16.38
KB
-rw-r--r--
2021-05-01 07:33
ldapcmp.py
40.44
KB
-rw-r--r--
2015-07-21 11:47
ldapcmp.pyc
31.27
KB
-rw-r--r--
2021-05-01 07:33
main.py
2.53
KB
-rw-r--r--
2015-07-21 11:47
main.pyc
2.46
KB
-rw-r--r--
2021-05-01 07:33
ntacl.py
9.92
KB
-rw-r--r--
2015-07-21 11:47
ntacl.pyc
8.89
KB
-rw-r--r--
2021-05-01 07:33
processes.py
2.71
KB
-rw-r--r--
2015-07-21 11:47
processes.pyc
2.03
KB
-rw-r--r--
2021-05-01 07:33
rodc.py
3.97
KB
-rw-r--r--
2015-07-21 11:47
rodc.pyc
3.6
KB
-rw-r--r--
2021-05-01 07:33
sites.py
3.35
KB
-rw-r--r--
2015-07-21 11:47
sites.pyc
3.34
KB
-rw-r--r--
2021-05-01 07:33
spn.py
7.42
KB
-rw-r--r--
2015-07-21 11:47
spn.pyc
6.08
KB
-rw-r--r--
2021-05-01 07:33
testparm.py
8.34
KB
-rw-r--r--
2015-07-21 11:47
testparm.pyc
6.2
KB
-rw-r--r--
2021-05-01 07:33
time.py
1.96
KB
-rw-r--r--
2015-07-21 11:47
time.pyc
1.8
KB
-rw-r--r--
2021-05-01 07:33
user.py
29.61
KB
-rw-r--r--
2021-04-14 17:48
user.pyc
27.37
KB
-rw-r--r--
2021-05-01 07:33
vampire.py
1.9
KB
-rw-r--r--
2015-07-21 11:47
vampire.pyc
1.78
KB
-rw-r--r--
2021-05-01 07:33
Save
Rename
# Changes a FSMO role owner # # Copyright Nadezhda Ivanova 2009 # Copyright Jelmer Vernooij 2009 # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see <http://www.gnu.org/licenses/>. # import samba import samba.getopt as options import ldb from ldb import LdbError from samba.dcerpc import drsuapi, misc from samba.auth import system_session from samba.netcmd import ( Command, CommandError, SuperCommand, Option, ) from samba.samdb import SamDB def get_fsmo_roleowner(samdb, roledn, role): """Gets the owner of an FSMO role :param roledn: The DN of the FSMO role :param role: The FSMO role """ try: res = samdb.search(roledn, scope=ldb.SCOPE_BASE, attrs=["fSMORoleOwner"]) except LdbError, (num, msg): if num == ldb.ERR_NO_SUCH_OBJECT: return "* The '%s' role is not present in this domain" % role raise if 'fSMORoleOwner' in res[0]: master_owner = res[0]["fSMORoleOwner"][0] return master_owner else: master_owner = "* The '%s' role does not have an FSMO roleowner" % role return master_owner def transfer_dns_role(outf, sambaopts, credopts, role, samdb): """Transfer dns FSMO role. """ if role == "domaindns": domain_dn = samdb.domain_dn() role_object = "CN=Infrastructure,DC=DomainDnsZones," + domain_dn elif role == "forestdns": forest_dn = samba.dn_from_dns_name(samdb.forest_dns_name()) role_object = "CN=Infrastructure,DC=ForestDnsZones," + forest_dn res = samdb.search(role_object, attrs=["fSMORoleOwner"], scope=ldb.SCOPE_BASE, controls=["extended_dn:1:1"]) if 'fSMORoleOwner' in res[0]: try: master_guid = str(misc.GUID(ldb.Dn(samdb, res[0]['fSMORoleOwner'][0]) .get_extended_component('GUID'))) master_owner = str(ldb.Dn(samdb, res[0]['fSMORoleOwner'][0])) except LdbError, (num, msg): raise CommandError("No GUID found in naming master DN %s : %s \n" % (res[0]['fSMORoleOwner'][0], msg)) else: outf.write("* The '%s' role does not have an FSMO roleowner\n" % role) return False if role == "domaindns": master_dns_name = '%s._msdcs.%s' % (master_guid, samdb.domain_dns_name()) new_dns_name = '%s._msdcs.%s' % (samdb.get_ntds_GUID(), samdb.domain_dns_name()) elif role == "forestdns": master_dns_name = '%s._msdcs.%s' % (master_guid, samdb.forest_dns_name()) new_dns_name = '%s._msdcs.%s' % (samdb.get_ntds_GUID(), samdb.forest_dns_name()) new_owner = samdb.get_dsServiceName() if master_dns_name != new_dns_name: lp = sambaopts.get_loadparm() creds = credopts.get_credentials(lp, fallback_machine=True) samdb = SamDB(url="ldap://%s" % (master_dns_name), session_info=system_session(), credentials=creds, lp=lp) m = ldb.Message() m.dn = ldb.Dn(samdb, role_object) m["fSMORoleOwner"] = ldb.MessageElement(master_owner, ldb.FLAG_MOD_DELETE, "fSMORoleOwner") try: samdb.modify(m) except LdbError, (num, msg): raise CommandError("Failed to delete role '%s': %s" % (role, msg)) m = ldb.Message() m.dn = ldb.Dn(samdb, role_object) m["fSMORoleOwner"]= ldb.MessageElement(new_owner, ldb.FLAG_MOD_ADD, "fSMORoleOwner") try: samdb.modify(m) except LdbError, (num, msg): raise CommandError("Failed to add role '%s': %s" % (role, msg)) try: connection = samba.drs_utils.drsuapi_connect(samdb.host_dns_name(), lp, creds) except samba.drs_utils.drsException, e: raise CommandError("Drsuapi Connect failed", e) try: drsuapi_connection = connection[0] drsuapi_handle = connection[1] req_options = drsuapi.DRSUAPI_DRS_WRIT_REP NC = role_object[18:] samba.drs_utils.sendDsReplicaSync(drsuapi_connection, drsuapi_handle, master_guid, NC, req_options) except samba.drs_utils.drsException, estr: raise CommandError("Replication failed", estr) outf.write("FSMO transfer of '%s' role successful\n" % role) return True else: outf.write("This DC already has the '%s' FSMO role\n" % role) return False def transfer_role(outf, role, samdb): """Transfer standard FSMO role. """ domain_dn = samdb.domain_dn() rid_dn = "CN=RID Manager$,CN=System," + domain_dn naming_dn = "CN=Partitions,%s" % samdb.get_config_basedn() infrastructure_dn = "CN=Infrastructure," + domain_dn schema_dn = str(samdb.get_schema_basedn()) new_owner = samdb.get_dsServiceName() m = ldb.Message() m.dn = ldb.Dn(samdb, "") if role == "rid": master_owner = get_fsmo_roleowner(samdb, rid_dn, role) m["becomeRidMaster"]= ldb.MessageElement( "1", ldb.FLAG_MOD_REPLACE, "becomeRidMaster") elif role == "pdc": master_owner = get_fsmo_roleowner(samdb, domain_dn, role) res = samdb.search(domain_dn, scope=ldb.SCOPE_BASE, attrs=["objectSid"]) assert len(res) == 1 sid = res[0]["objectSid"][0] m["becomePdc"]= ldb.MessageElement( sid, ldb.FLAG_MOD_REPLACE, "becomePdc") elif role == "naming": master_owner = get_fsmo_roleowner(samdb, naming_dn, role) m["becomeDomainMaster"]= ldb.MessageElement( "1", ldb.FLAG_MOD_REPLACE, "becomeDomainMaster") elif role == "infrastructure": master_owner = get_fsmo_roleowner(samdb, infrastructure_dn, role) m["becomeInfrastructureMaster"]= ldb.MessageElement( "1", ldb.FLAG_MOD_REPLACE, "becomeInfrastructureMaster") elif role == "schema": master_owner = get_fsmo_roleowner(samdb, schema_dn, role) m["becomeSchemaMaster"]= ldb.MessageElement( "1", ldb.FLAG_MOD_REPLACE, "becomeSchemaMaster") else: raise CommandError("Invalid FSMO role.") if not '*' in master_owner: if master_owner != new_owner: try: samdb.modify(m) except LdbError, (num, msg): raise CommandError("Transfer of '%s' role failed: %s" % (role, msg)) outf.write("FSMO transfer of '%s' role successful\n" % role) return True else: outf.write("This DC already has the '%s' FSMO role\n" % role) return False else: outf.write("%s\n" % master_owner) return False class cmd_fsmo_seize(Command): """Seize the role.""" synopsis = "%prog [options]" takes_optiongroups = { "sambaopts": options.SambaOptions, "credopts": options.CredentialsOptions, "versionopts": options.VersionOptions, } takes_options = [ Option("-H", "--URL", help="LDB URL for database or target server", type=str, metavar="URL", dest="H"), Option("--force", help="Force seizing of role without attempting to transfer.", action="store_true"), Option("--role", type="choice", choices=["rid", "pdc", "infrastructure", "schema", "naming", "domaindns", "forestdns", "all"], help="""The FSMO role to seize or transfer.\n rid=RidAllocationMasterRole\n schema=SchemaMasterRole\n pdc=PdcEmulationMasterRole\n naming=DomainNamingMasterRole\n infrastructure=InfrastructureMasterRole\n domaindns=DomainDnsZonesMasterRole\n forestdns=ForestDnsZonesMasterRole\n all=all of the above\n You must provide an Admin user and password."""), ] takes_args = [] def seize_role(self, role, samdb, force): """Seize standard fsmo role. """ serviceName = samdb.get_dsServiceName() domain_dn = samdb.domain_dn() self.infrastructure_dn = "CN=Infrastructure," + domain_dn self.naming_dn = "CN=Partitions,%s" % samdb.get_config_basedn() self.schema_dn = str(samdb.get_schema_basedn()) self.rid_dn = "CN=RID Manager$,CN=System," + domain_dn m = ldb.Message() if role == "rid": m.dn = ldb.Dn(samdb, self.rid_dn) elif role == "pdc": m.dn = ldb.Dn(samdb, domain_dn) elif role == "naming": m.dn = ldb.Dn(samdb, self.naming_dn) elif role == "infrastructure": m.dn = ldb.Dn(samdb, self.infrastructure_dn) elif role == "schema": m.dn = ldb.Dn(samdb, self.schema_dn) else: raise CommandError("Invalid FSMO role.") #first try to transfer to avoid problem if the owner is still active seize = False master_owner = get_fsmo_roleowner(samdb, m.dn, role) if not '*' in master_owner: # if there is a different owner if master_owner != serviceName: # if --force isn't given, attempt transfer if force is None: self.message("Attempting transfer...") try: transfer_role(self.outf, role, samdb) except: #transfer failed, use the big axe... seize = True self.message("Transfer unsuccessful, seizing...") else: self.message("Transfer successful, not seizing role") return True else: self.outf.write("This DC already has the '%s' FSMO role\n" % role) return False else: seize = True if force is not None or seize == True: self.message("Seizing %s FSMO role..." % role) m["fSMORoleOwner"]= ldb.MessageElement( serviceName, ldb.FLAG_MOD_REPLACE, "fSMORoleOwner") try: samdb.modify(m) except LdbError, (num, msg): raise CommandError("Failed to seize '%s' role: %s" % (role, msg)) self.outf.write("FSMO seize of '%s' role successful\n" % role) return True def seize_dns_role(self, role, samdb, credopts, sambaopts, versionopts, force): """Seize DNS FSMO role. """ serviceName = samdb.get_dsServiceName() domain_dn = samdb.domain_dn() forest_dn = samba.dn_from_dns_name(samdb.forest_dns_name()) self.domaindns_dn = "CN=Infrastructure,DC=DomainDnsZones," + domain_dn self.forestdns_dn = "CN=Infrastructure,DC=ForestDnsZones," + forest_dn m = ldb.Message() if role == "domaindns": m.dn = ldb.Dn(samdb, self.domaindns_dn) elif role == "forestdns": m.dn = ldb.Dn(samdb, self.forestdns_dn) else: raise CommandError("Invalid FSMO role.") #first try to transfer to avoid problem if the owner is still active seize = False master_owner = get_fsmo_roleowner(samdb, m.dn, role) if not '*' in master_owner: # if there is a different owner if master_owner != serviceName: # if --force isn't given, attempt transfer if force is None: self.message("Attempting transfer...") try: transfer_dns_role(self.outf, sambaopts, credopts, role, samdb) except: #transfer failed, use the big axe... seize = True self.message("Transfer unsuccessful, seizing...") else: self.message("Transfer successful, not seizing role\n") return True else: self.outf.write("This DC already has the '%s' FSMO role\n" % role) return False else: seize = True if force is not None or seize == True: self.message("Seizing %s FSMO role..." % role) m["fSMORoleOwner"]= ldb.MessageElement( serviceName, ldb.FLAG_MOD_REPLACE, "fSMORoleOwner") try: samdb.modify(m) except LdbError, (num, msg): raise CommandError("Failed to seize '%s' role: %s" % (role, msg)) self.outf.write("FSMO seize of '%s' role successful\n" % role) return True def run(self, force=None, H=None, role=None, credopts=None, sambaopts=None, versionopts=None): lp = sambaopts.get_loadparm() creds = credopts.get_credentials(lp, fallback_machine=True) samdb = SamDB(url=H, session_info=system_session(), credentials=creds, lp=lp) if role == "all": self.seize_role("rid", samdb, force) self.seize_role("pdc", samdb, force) self.seize_role("naming", samdb, force) self.seize_role("infrastructure", samdb, force) self.seize_role("schema", samdb, force) self.seize_dns_role("domaindns", samdb, credopts, sambaopts, versionopts, force) self.seize_dns_role("forestdns", samdb, credopts, sambaopts, versionopts, force) else: if role == "domaindns" or role == "forestdns": self.seize_dns_role(role, samdb, credopts, sambaopts, versionopts, force) else: self.seize_role(role, samdb, force) class cmd_fsmo_show(Command): """Show the roles.""" synopsis = "%prog [options]" takes_optiongroups = { "sambaopts": options.SambaOptions, "credopts": options.CredentialsOptions, "versionopts": options.VersionOptions, } takes_options = [ Option("-H", "--URL", help="LDB URL for database or target server", type=str, metavar="URL", dest="H"), ] takes_args = [] def run(self, H=None, credopts=None, sambaopts=None, versionopts=None): lp = sambaopts.get_loadparm() creds = credopts.get_credentials(lp, fallback_machine=True) samdb = SamDB(url=H, session_info=system_session(), credentials=creds, lp=lp) domain_dn = samdb.domain_dn() forest_dn = samba.dn_from_dns_name(samdb.forest_dns_name()) infrastructure_dn = "CN=Infrastructure," + domain_dn naming_dn = "CN=Partitions,%s" % samdb.get_config_basedn() schema_dn = samdb.get_schema_basedn() rid_dn = "CN=RID Manager$,CN=System," + domain_dn domaindns_dn = "CN=Infrastructure,DC=DomainDnsZones," + domain_dn forestdns_dn = "CN=Infrastructure,DC=ForestDnsZones," + forest_dn infrastructureMaster = get_fsmo_roleowner(samdb, infrastructure_dn, "infrastructure") pdcEmulator = get_fsmo_roleowner(samdb, domain_dn, "pdc") namingMaster = get_fsmo_roleowner(samdb, naming_dn, "naming") schemaMaster = get_fsmo_roleowner(samdb, schema_dn, "schema") ridMaster = get_fsmo_roleowner(samdb, rid_dn, "rid") domaindnszonesMaster = get_fsmo_roleowner(samdb, domaindns_dn, "domaindns") forestdnszonesMaster = get_fsmo_roleowner(samdb, forestdns_dn, "forestdns") self.message("SchemaMasterRole owner: " + schemaMaster) self.message("InfrastructureMasterRole owner: " + infrastructureMaster) self.message("RidAllocationMasterRole owner: " + ridMaster) self.message("PdcEmulationMasterRole owner: " + pdcEmulator) self.message("DomainNamingMasterRole owner: " + namingMaster) self.message("DomainDnsZonesMasterRole owner: " + domaindnszonesMaster) self.message("ForestDnsZonesMasterRole owner: " + forestdnszonesMaster) class cmd_fsmo_transfer(Command): """Transfer the role.""" synopsis = "%prog [options]" takes_optiongroups = { "sambaopts": options.SambaOptions, "credopts": options.CredentialsOptions, "versionopts": options.VersionOptions, } takes_options = [ Option("-H", "--URL", help="LDB URL for database or target server", type=str, metavar="URL", dest="H"), Option("--role", type="choice", choices=["rid", "pdc", "infrastructure", "schema", "naming", "domaindns", "forestdns", "all"], help="""The FSMO role to seize or transfer.\n rid=RidAllocationMasterRole\n schema=SchemaMasterRole\n pdc=PdcEmulationMasterRole\n naming=DomainNamingMasterRole\n infrastructure=InfrastructureMasterRole\n domaindns=DomainDnsZonesMasterRole\n forestdns=ForestDnsZonesMasterRole\n all=all of the above\n You must provide an Admin user and password."""), ] takes_args = [] def run(self, force=None, H=None, role=None, credopts=None, sambaopts=None, versionopts=None): lp = sambaopts.get_loadparm() creds = credopts.get_credentials(lp, fallback_machine=True) samdb = SamDB(url=H, session_info=system_session(), credentials=creds, lp=lp) if role == "all": transfer_role(self.outf, "rid", samdb) transfer_role(self.outf, "pdc", samdb) transfer_role(self.outf, "naming", samdb) transfer_role(self.outf, "infrastructure", samdb) transfer_role(self.outf, "schema", samdb) transfer_dns_role(self.outf, sambaopts, credopts, "domaindns", samdb) transfer_dns_role(self.outf, sambaopts, credopts, "forestdns", samdb) else: if role == "domaindns" or role == "forestdns": transfer_dns_role(self.outf, sambaopts, credopts, role, samdb) else: transfer_role(self.outf, role, samdb) class cmd_fsmo(SuperCommand): """Flexible Single Master Operations (FSMO) roles management.""" subcommands = {} subcommands["seize"] = cmd_fsmo_seize() subcommands["show"] = cmd_fsmo_show() subcommands["transfer"] = cmd_fsmo_transfer()