2012-11-28 07:03:05 +04:00
|
|
|
/**
|
|
|
|
* FreeRDP: A Remote Desktop Protocol Implementation
|
|
|
|
* RPC over HTTP (ncacn_http)
|
|
|
|
*
|
|
|
|
* Copyright 2012 Marc-Andre Moreau <marcandre.moreau@gmail.com>
|
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
* you may not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifdef HAVE_CONFIG_H
|
|
|
|
#include "config.h"
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#include "ncacn_http.h"
|
|
|
|
|
|
|
|
#include <winpr/crt.h>
|
|
|
|
#include <winpr/tchar.h>
|
2012-12-14 05:23:37 +04:00
|
|
|
#include <winpr/stream.h>
|
2012-11-28 07:03:05 +04:00
|
|
|
#include <winpr/dsparse.h>
|
2013-12-13 19:11:36 +04:00
|
|
|
#include <winpr/winhttp.h>
|
2012-11-28 07:03:05 +04:00
|
|
|
|
|
|
|
#include <openssl/rand.h>
|
|
|
|
|
2015-02-03 02:50:26 +03:00
|
|
|
#define TAG FREERDP_TAG("core.gateway.ntlm")
|
2015-01-13 21:50:46 +03:00
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
wStream* rpc_ntlm_http_request(rdpRpc* rpc, HttpContext* http, const char* method, int contentLength, SecBuffer* ntlmToken)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2012-12-14 05:23:37 +04:00
|
|
|
wStream* s;
|
2015-02-11 23:26:22 +03:00
|
|
|
HttpRequest* request;
|
|
|
|
char* base64NtlmToken = NULL;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
request = http_request_new();
|
2015-01-14 00:35:34 +03:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
if (ntlmToken)
|
|
|
|
base64NtlmToken = crypto_base64_encode(ntlmToken->pvBuffer, ntlmToken->cbBuffer);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
http_request_set_method(request, method);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
request->ContentLength = contentLength;
|
|
|
|
http_request_set_uri(request, http->URI);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
if (base64NtlmToken)
|
2015-01-14 00:35:34 +03:00
|
|
|
{
|
2015-02-11 23:26:22 +03:00
|
|
|
http_request_set_auth_scheme(request, "NTLM");
|
|
|
|
http_request_set_auth_param(request, base64NtlmToken);
|
2015-01-14 00:35:34 +03:00
|
|
|
}
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
s = http_request_write(http, request);
|
|
|
|
http_request_free(request);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
free(base64NtlmToken);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
|
|
|
return s;
|
|
|
|
}
|
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
int rpc_ncacn_http_send_in_channel_request(rdpRpc* rpc, RpcInChannel* inChannel)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2012-12-14 05:23:37 +04:00
|
|
|
wStream* s;
|
2015-02-02 04:47:43 +03:00
|
|
|
int status;
|
|
|
|
int contentLength;
|
|
|
|
BOOL continueNeeded;
|
2015-02-11 23:26:22 +03:00
|
|
|
rdpNtlm* ntlm = inChannel->ntlm;
|
|
|
|
HttpContext* http = inChannel->http;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-02 04:47:43 +03:00
|
|
|
continueNeeded = ntlm_authenticate(ntlm);
|
|
|
|
|
|
|
|
contentLength = (continueNeeded) ? 0 : 0x40000000;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
s = rpc_ntlm_http_request(rpc, http, "RPC_IN_DATA", contentLength, &ntlm->outputBuffer[0]);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-02 04:47:43 +03:00
|
|
|
if (!s)
|
|
|
|
return -1;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-12 22:08:38 +03:00
|
|
|
status = rpc_in_channel_write(inChannel, Stream_Buffer(s), Stream_Length(s));
|
2015-02-03 22:44:31 +03:00
|
|
|
|
2012-12-14 05:23:37 +04:00
|
|
|
Stream_Free(s, TRUE);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-02 04:47:43 +03:00
|
|
|
return (status > 0) ? 1 : -1;
|
2012-11-28 07:03:05 +04:00
|
|
|
}
|
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
int rpc_ncacn_http_recv_in_channel_response(rdpRpc* rpc, RpcInChannel* inChannel, HttpResponse* response)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2015-02-03 22:44:31 +03:00
|
|
|
char* token64 = NULL;
|
|
|
|
int ntlmTokenLength = 0;
|
|
|
|
BYTE* ntlmTokenData = NULL;
|
2015-02-11 23:26:22 +03:00
|
|
|
rdpNtlm* ntlm = inChannel->ntlm;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-03 22:44:31 +03:00
|
|
|
if (ListDictionary_Contains(response->Authenticates, "NTLM"))
|
2013-12-13 19:11:36 +04:00
|
|
|
{
|
2015-02-03 22:44:31 +03:00
|
|
|
token64 = ListDictionary_GetItemValue(response->Authenticates, "NTLM");
|
2014-12-12 01:08:22 +03:00
|
|
|
|
2014-04-19 01:08:34 +04:00
|
|
|
if (!token64)
|
2015-02-04 04:39:47 +03:00
|
|
|
return -1;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-03 22:44:31 +03:00
|
|
|
crypto_base64_decode(token64, strlen(token64), &ntlmTokenData, &ntlmTokenLength);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ntlmTokenData && ntlmTokenLength)
|
|
|
|
{
|
|
|
|
ntlm->inputBuffer[0].pvBuffer = ntlmTokenData;
|
|
|
|
ntlm->inputBuffer[0].cbBuffer = ntlmTokenLength;
|
2013-12-13 19:11:36 +04:00
|
|
|
}
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-04 04:39:47 +03:00
|
|
|
return 1;
|
2012-11-28 07:03:05 +04:00
|
|
|
}
|
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
int rpc_ncacn_http_ntlm_init(rdpRpc* rpc, RpcChannel* channel)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2015-02-12 20:03:15 +03:00
|
|
|
rdpTls* tls = channel->tls;
|
|
|
|
rdpNtlm* ntlm = channel->ntlm;
|
2015-02-11 22:27:29 +03:00
|
|
|
rdpContext* context = rpc->context;
|
2013-12-07 07:15:45 +04:00
|
|
|
rdpSettings* settings = rpc->settings;
|
2015-02-11 22:27:29 +03:00
|
|
|
freerdp* instance = context->instance;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2014-05-21 19:32:14 +04:00
|
|
|
if (!settings->GatewayPassword || !settings->GatewayUsername ||
|
|
|
|
!strlen(settings->GatewayPassword) || !strlen(settings->GatewayUsername))
|
2013-12-07 07:15:45 +04:00
|
|
|
{
|
|
|
|
if (instance->GatewayAuthenticate)
|
|
|
|
{
|
2014-05-21 19:32:14 +04:00
|
|
|
BOOL proceed = instance->GatewayAuthenticate(instance, &settings->GatewayUsername,
|
2014-12-12 01:08:22 +03:00
|
|
|
&settings->GatewayPassword, &settings->GatewayDomain);
|
2013-12-07 07:15:45 +04:00
|
|
|
|
|
|
|
if (!proceed)
|
2013-12-13 19:11:36 +04:00
|
|
|
{
|
2015-02-11 22:27:29 +03:00
|
|
|
freerdp_set_last_error(context, FREERDP_ERROR_CONNECT_CANCELLED);
|
2013-12-07 07:15:45 +04:00
|
|
|
return 0;
|
2013-12-13 19:11:36 +04:00
|
|
|
}
|
2013-12-07 07:15:45 +04:00
|
|
|
|
|
|
|
if (settings->GatewayUseSameCredentials)
|
|
|
|
{
|
2015-06-17 23:08:02 +03:00
|
|
|
if (settings->GatewayUsername)
|
|
|
|
{
|
|
|
|
free(settings->Username);
|
|
|
|
if (!(settings->Username = _strdup(settings->GatewayUsername)))
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
if (settings->GatewayDomain)
|
|
|
|
{
|
|
|
|
free(settings->Domain);
|
|
|
|
if (!(settings->Domain = _strdup(settings->GatewayDomain)))
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
if (settings->GatewayPassword)
|
|
|
|
{
|
|
|
|
free(settings->Password);
|
|
|
|
if (!(settings->Password = _strdup(settings->GatewayPassword)))
|
|
|
|
return -1;
|
|
|
|
}
|
2013-12-07 07:15:45 +04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2013-12-13 19:11:36 +04:00
|
|
|
if (!ntlm_client_init(ntlm, TRUE, settings->GatewayUsername,
|
2015-02-11 22:27:29 +03:00
|
|
|
settings->GatewayDomain, settings->GatewayPassword, tls->Bindings))
|
2013-12-13 19:11:36 +04:00
|
|
|
{
|
|
|
|
return 0;
|
|
|
|
}
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2013-12-13 19:11:36 +04:00
|
|
|
if (!ntlm_client_make_spn(ntlm, _T("HTTP"), settings->GatewayHostname))
|
|
|
|
{
|
|
|
|
return 0;
|
|
|
|
}
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2013-12-13 19:11:36 +04:00
|
|
|
return 1;
|
2012-11-28 07:03:05 +04:00
|
|
|
}
|
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
void rpc_ncacn_http_ntlm_uninit(rdpRpc* rpc, RpcChannel* channel)
|
2015-02-03 22:44:31 +03:00
|
|
|
{
|
2015-02-12 20:03:15 +03:00
|
|
|
ntlm_client_uninit(channel->ntlm);
|
|
|
|
ntlm_free(channel->ntlm);
|
|
|
|
channel->ntlm = NULL;
|
2015-02-03 22:44:31 +03:00
|
|
|
}
|
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
int rpc_ncacn_http_send_out_channel_request(rdpRpc* rpc, RpcOutChannel* outChannel, BOOL replacement)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2012-12-14 05:23:37 +04:00
|
|
|
wStream* s;
|
2015-02-02 04:47:43 +03:00
|
|
|
int status;
|
2015-02-03 22:44:31 +03:00
|
|
|
int contentLength;
|
|
|
|
BOOL continueNeeded;
|
2015-02-11 23:26:22 +03:00
|
|
|
rdpNtlm* ntlm = outChannel->ntlm;
|
|
|
|
HttpContext* http = outChannel->http;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-03 22:44:31 +03:00
|
|
|
continueNeeded = ntlm_authenticate(ntlm);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
if (!replacement)
|
|
|
|
contentLength = (continueNeeded) ? 0 : 76;
|
|
|
|
else
|
|
|
|
contentLength = (continueNeeded) ? 0 : 120;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-12 20:03:15 +03:00
|
|
|
s = rpc_ntlm_http_request(rpc, http, "RPC_OUT_DATA", contentLength, &ntlm->outputBuffer[0]);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-02 04:47:43 +03:00
|
|
|
if (!s)
|
|
|
|
return -1;
|
|
|
|
|
2015-02-12 22:08:38 +03:00
|
|
|
status = rpc_out_channel_write(outChannel, Stream_Buffer(s), Stream_Length(s));
|
2015-02-03 22:44:31 +03:00
|
|
|
|
2012-12-14 05:23:37 +04:00
|
|
|
Stream_Free(s, TRUE);
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-02 04:47:43 +03:00
|
|
|
return (status > 0) ? 1 : -1;
|
2012-11-28 07:03:05 +04:00
|
|
|
}
|
|
|
|
|
2015-02-11 23:26:22 +03:00
|
|
|
int rpc_ncacn_http_recv_out_channel_response(rdpRpc* rpc, RpcOutChannel* outChannel, HttpResponse* response)
|
2012-11-28 07:03:05 +04:00
|
|
|
{
|
2015-02-03 22:44:31 +03:00
|
|
|
char* token64 = NULL;
|
|
|
|
int ntlmTokenLength = 0;
|
|
|
|
BYTE* ntlmTokenData = NULL;
|
2015-02-11 23:26:22 +03:00
|
|
|
rdpNtlm* ntlm = outChannel->ntlm;
|
2012-11-28 07:03:05 +04:00
|
|
|
|
2015-02-03 01:16:32 +03:00
|
|
|
if (ListDictionary_Contains(response->Authenticates, "NTLM"))
|
2013-12-07 07:15:45 +04:00
|
|
|
{
|
2015-02-03 01:16:32 +03:00
|
|
|
token64 = ListDictionary_GetItemValue(response->Authenticates, "NTLM");
|
2015-02-02 04:47:43 +03:00
|
|
|
|
|
|
|
if (!token64)
|
2015-02-04 04:39:47 +03:00
|
|
|
return -1;
|
2015-02-02 04:47:43 +03:00
|
|
|
|
2015-02-03 22:44:31 +03:00
|
|
|
crypto_base64_decode(token64, strlen(token64), &ntlmTokenData, &ntlmTokenLength);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ntlmTokenData && ntlmTokenLength)
|
|
|
|
{
|
|
|
|
ntlm->inputBuffer[0].pvBuffer = ntlmTokenData;
|
|
|
|
ntlm->inputBuffer[0].cbBuffer = ntlmTokenLength;
|
2013-12-07 07:15:45 +04:00
|
|
|
}
|
2014-12-11 19:25:34 +03:00
|
|
|
|
2015-02-04 04:39:47 +03:00
|
|
|
return 1;
|
2012-11-28 07:03:05 +04:00
|
|
|
}
|