1997-12-13 14:16:07 +00:00
/*
2002-01-30 06:08:46 +00:00
Unix SMB / CIFS implementation .
1997-12-13 14:16:07 +00:00
NBT netbios routines and daemon - version 2
1998-01-22 13:27:43 +00:00
Copyright ( C ) Andrew Tridgell 1994 - 1998
Copyright ( C ) Luke Kenneth Casson Leighton 1994 - 1998
2003-08-27 01:25:01 +00:00
Copyright ( C ) Jeremy Allison 1994 - 2003
2003-08-01 15:30:44 +00:00
Copyright ( C ) Jim McDonough < jmcd @ us . ibm . com > 2002
1997-12-13 14:16:07 +00:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-09 19:25:36 +00:00
the Free Software Foundation ; either version 3 of the License , or
1997-12-13 14:16:07 +00:00
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program ; if not , write to the Free Software
Foundation , Inc . , 675 Mass Ave , Cambridge , MA 0213 9 , USA .
Revision History :
*/
# include "includes.h"
2001-08-24 19:28:08 +00:00
struct sam_database_info {
uint32 index ;
uint32 serial_lo , serial_hi ;
uint32 date_lo , date_hi ;
} ;
/****************************************************************************
2001-08-28 06:08:31 +00:00
Send a message to smbd to do a sam delta sync
2001-08-24 19:28:08 +00:00
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2003-08-27 01:25:01 +00:00
2001-08-28 06:08:31 +00:00
static void send_repl_message ( uint32 low_serial )
2001-08-24 19:28:08 +00:00
{
2001-08-28 06:08:31 +00:00
DEBUG ( 3 , ( " sending replication message, serial = 0x%04x \n " ,
low_serial ) ) ;
2007-05-15 15:49:55 +00:00
message_send_all ( nmbd_messaging_context ( ) , MSG_SMB_SAM_REPL ,
2007-05-21 22:17:13 +00:00
& low_serial , sizeof ( low_serial ) , NULL ) ;
2001-08-24 19:28:08 +00:00
}
1997-12-13 14:16:07 +00:00
/****************************************************************************
Process a domain logon packet
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2003-01-03 08:28:12 +00:00
void process_logon_packet ( struct packet_struct * p , char * buf , int len ,
const char * mailslot )
1997-12-13 14:16:07 +00:00
{
2003-08-27 01:25:01 +00:00
struct dgram_packet * dgram = & p - > packet . dgram ;
pstring my_name ;
fstring reply_name ;
pstring outbuf ;
int code ;
uint16 token = 0 ;
uint32 ntversion = 0 ;
uint16 lmnttoken = 0 ;
uint16 lm20token = 0 ;
uint32 domainsidsize ;
BOOL short_request = False ;
char * getdc ;
char * uniuser ; /* Unicode user name. */
pstring ascuser ;
char * unicomp ; /* Unicode computer name. */
memset ( outbuf , 0 , sizeof ( outbuf ) ) ;
if ( ! lp_domain_logons ( ) ) {
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: Logon packet received from IP %s and domain \
1997-12-13 14:16:07 +00:00
logons are not enabled . \ n " , inet_ntoa(p->ip) ));
2003-08-27 01:25:01 +00:00
return ;
}
pstrcpy ( my_name , global_myname ( ) ) ;
r22042: Try and clean up my own mess using the API Volker
suggested. I now use :
BOOL is_offset_safe(const char *buf_base, size_t buf_len, char *ptr, size_t off)
char *get_safe_ptr(const char *buf_base, size_t buf_len, char *ptr, size_t off)
char *get_safe_str_ptr(const char *buf_base, size_t buf_len, char *ptr, size_t off)
int get_safe_SVAL(const char *buf_base, size_t buf_len, char *ptr, size_t off, int failval)
int get_safe_IVAL(const char *buf_base, size_t buf_len, char *ptr, size_t off, int failval)
Volker, please criticize and comment. Thanks,
Jeremy.
(This used to be commit d47af7c9263f519e7307859b6a696d854c5dfca3)
2007-04-02 19:04:57 +00:00
code = get_safe_SVAL ( buf , len , buf , 0 , - 1 ) ;
2004-01-24 10:46:55 +00:00
DEBUG ( 4 , ( " process_logon_packet: Logon from %s: code = 0x%x \n " , inet_ntoa ( p - > ip ) , code ) ) ;
2003-08-27 01:25:01 +00:00
switch ( code ) {
case 0 :
{
fstring mach_str , user_str , getdc_str ;
char * q = buf + 2 ;
char * machine = q ;
2007-04-02 20:10:21 +00:00
char * user = skip_string ( buf , len , machine ) ;
2003-08-27 01:25:01 +00:00
2007-03-30 22:25:08 +00:00
if ( ! user | | PTR_DIFF ( user , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2007-04-02 20:10:21 +00:00
getdc = skip_string ( buf , len , user ) ;
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! getdc | | PTR_DIFF ( getdc , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2007-04-02 20:10:21 +00:00
q = skip_string ( buf , len , getdc ) ;
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! q | | PTR_DIFF ( q + 5 , buf ) > len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
token = SVAL ( q , 3 ) ;
fstrcpy ( reply_name , my_name ) ;
pull_ascii_fstring ( mach_str , machine ) ;
pull_ascii_fstring ( user_str , user ) ;
pull_ascii_fstring ( getdc_str , getdc ) ;
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: Domain login request from %s at IP %s user=%s token=%x \n " ,
2003-08-27 01:25:01 +00:00
mach_str , inet_ntoa ( p - > ip ) , user_str , token ) ) ;
q = outbuf ;
SSVAL ( q , 0 , 6 ) ;
q + = 2 ;
fstrcpy ( reply_name , " \\ \\ " ) ;
fstrcat ( reply_name , my_name ) ;
push_ascii_fstring ( q , reply_name ) ;
2007-04-02 20:10:21 +00:00
q = skip_string ( outbuf , sizeof ( outbuf ) , q ) ; /* PDC name */
2003-08-27 01:25:01 +00:00
SSVAL ( q , 0 , token ) ;
q + = 2 ;
2007-03-28 13:34:59 +00:00
dump_data ( 4 , ( uint8 * ) outbuf , PTR_DIFF ( q , outbuf ) ) ;
2003-08-27 01:25:01 +00:00
send_mailslot ( True , getdc_str ,
outbuf , PTR_DIFF ( q , outbuf ) ,
global_myname ( ) , 0x0 ,
mach_str ,
dgram - > source_name . name_type ,
p - > ip , * iface_ip ( p - > ip ) , p - > port ) ;
break ;
}
case QUERYFORPDC :
{
fstring mach_str , getdc_str ;
2004-03-13 02:16:21 +00:00
fstring source_name ;
2003-08-27 01:25:01 +00:00
char * q = buf + 2 ;
char * machine = q ;
if ( ! lp_domain_master ( ) ) {
/* We're not Primary Domain Controller -- ignore this */
return ;
}
2007-04-02 20:10:21 +00:00
getdc = skip_string ( buf , len , machine ) ;
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! getdc | | PTR_DIFF ( getdc , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2007-04-02 20:10:21 +00:00
q = skip_string ( buf , len , getdc ) ;
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! q | | PTR_DIFF ( q , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
q = ALIGN2 ( q , buf ) ;
/* At this point we can work out if this is a W9X or NT style
request . Experiments show that the difference is wether the
packet ends here . For a W9X request we now end with a pair of
bytes ( usually 0xFE 0xFF ) whereas with NT we have two further
strings - the following is a simple way of detecting this */
if ( len - PTR_DIFF ( q , buf ) < = 3 ) {
short_request = True ;
} else {
unicomp = q ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
/* A full length (NT style) request */
q = skip_unibuf ( unicomp , PTR_DIFF ( buf + len , unicomp ) ) ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
if ( len - PTR_DIFF ( q , buf ) > 8 ) {
/* with NT5 clients we can sometimes
get additional data - a length specificed string
containing the domain name , then 16 bytes of
data ( no idea what it is ) */
int dom_len = CVAL ( q , 0 ) ;
q + + ;
if ( dom_len ! = 0 ) {
q + = dom_len + 1 ;
}
q + = 16 ;
}
2004-09-04 01:57:16 +00:00
2004-09-09 01:46:20 +00:00
if ( PTR_DIFF ( q + 8 , buf ) > len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
ntversion = IVAL ( q , 0 ) ;
lmnttoken = SVAL ( q , 4 ) ;
lm20token = SVAL ( q , 6 ) ;
}
/* Construct reply. */
q = outbuf ;
SSVAL ( q , 0 , QUERYFORPDC_R ) ;
q + = 2 ;
fstrcpy ( reply_name , my_name ) ;
push_ascii_fstring ( q , reply_name ) ;
2007-04-02 20:10:21 +00:00
q = skip_string ( outbuf , sizeof ( outbuf ) , q ) ; /* PDC name */
2003-08-27 01:25:01 +00:00
/* PDC and domain name */
if ( ! short_request ) {
/* Make a full reply */
q = ALIGN2 ( q , outbuf ) ;
q + = dos_PutUniCode ( q , my_name , sizeof ( pstring ) , True ) ; /* PDC name */
q + = dos_PutUniCode ( q , lp_workgroup ( ) , sizeof ( pstring ) , True ) ; /* Domain name*/
SIVAL ( q , 0 , 1 ) ; /* our nt version */
SSVAL ( q , 4 , 0xffff ) ; /* our lmnttoken */
SSVAL ( q , 6 , 0xffff ) ; /* our lm20token */
q + = 8 ;
}
/* RJS, 21-Feb-2000, we send a short reply if the request was short */
pull_ascii_fstring ( mach_str , machine ) ;
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: GETDC request from %s at IP %s, \
2003-08-27 01:25:01 +00:00
reporting % s domain % s 0 x % x ntversion = % x lm_nt token = % x lm_20 token = % x \ n " ,
mach_str , inet_ntoa ( p - > ip ) , reply_name , lp_workgroup ( ) ,
QUERYFORPDC_R , ( uint32 ) ntversion , ( uint32 ) lmnttoken ,
( uint32 ) lm20token ) ) ;
2007-03-28 13:34:59 +00:00
dump_data ( 4 , ( uint8 * ) outbuf , PTR_DIFF ( q , outbuf ) ) ;
2003-08-27 01:25:01 +00:00
pull_ascii_fstring ( getdc_str , getdc ) ;
2004-03-13 02:16:21 +00:00
pull_ascii_nstring ( source_name , sizeof ( source_name ) , dgram - > source_name . name ) ;
2003-08-27 01:25:01 +00:00
send_mailslot ( True , getdc_str ,
outbuf , PTR_DIFF ( q , outbuf ) ,
global_myname ( ) , 0x0 ,
source_name ,
dgram - > source_name . name_type ,
p - > ip , * iface_ip ( p - > ip ) , p - > port ) ;
return ;
}
case SAMLOGON :
{
fstring getdc_str ;
2004-03-15 21:45:45 +00:00
fstring source_name ;
2003-08-27 01:25:01 +00:00
char * q = buf + 2 ;
fstring asccomp ;
q + = 2 ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
unicomp = q ;
uniuser = skip_unibuf ( unicomp , PTR_DIFF ( buf + len , unicomp ) ) ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( uniuser , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
getdc = skip_unibuf ( uniuser , PTR_DIFF ( buf + len , uniuser ) ) ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( getdc , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2007-04-02 20:10:21 +00:00
q = skip_string ( buf , len , getdc ) ;
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! q | | PTR_DIFF ( q + 8 , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
q + = 4 ; /* Account Control Bits - indicating username type */
domainsidsize = IVAL ( q , 0 ) ;
q + = 4 ;
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: SAMLOGON sidsize %d, len = %d \n " , domainsidsize , len ) ) ;
2003-08-27 01:25:01 +00:00
if ( domainsidsize < ( len - PTR_DIFF ( q , buf ) ) & & ( domainsidsize ! = 0 ) ) {
q + = domainsidsize ;
q = ALIGN4 ( q , buf ) ;
}
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: len = %d PTR_DIFF(q, buf) = %ld \n " , len , ( unsigned long ) PTR_DIFF ( q , buf ) ) ) ;
2003-08-27 01:25:01 +00:00
if ( len - PTR_DIFF ( q , buf ) > 8 ) {
2000-03-27 12:19:58 +00:00
/* with NT5 clients we can sometimes
2003-08-27 01:25:01 +00:00
get additional data - a length specificed string
containing the domain name , then 16 bytes of
data ( no idea what it is ) */
2000-03-27 12:19:58 +00:00
int dom_len = CVAL ( q , 0 ) ;
q + + ;
2003-08-27 01:25:01 +00:00
if ( dom_len < ( len - PTR_DIFF ( q , buf ) ) & & ( dom_len ! = 0 ) ) {
2000-03-27 12:19:58 +00:00
q + = dom_len + 1 ;
}
q + = 16 ;
2003-08-27 01:25:01 +00:00
}
2004-09-09 01:46:20 +00:00
if ( PTR_DIFF ( q + 8 , buf ) > len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
ntversion = IVAL ( q , 0 ) ;
lmnttoken = SVAL ( q , 4 ) ;
lm20token = SVAL ( q , 6 ) ;
q + = 8 ;
DEBUG ( 3 , ( " process_logon_packet: SAMLOGON sidsize %d ntv %d \n " , domainsidsize , ntversion ) ) ;
/*
* we respond regadless of whether the machine is in our password
* database . If it isn ' t then we let smbd send an appropriate error .
* Let ' s ignore the SID .
*/
pull_ucs2_pstring ( ascuser , uniuser ) ;
pull_ucs2_fstring ( asccomp , unicomp ) ;
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: SAMLOGON user %s \n " , ascuser ) ) ;
2003-08-27 01:25:01 +00:00
fstrcpy ( reply_name , " \\ \\ " ) ; /* Here it wants \\LOGONSERVER. */
fstrcat ( reply_name , my_name ) ;
2004-01-24 10:46:55 +00:00
DEBUG ( 5 , ( " process_logon_packet: SAMLOGON request from %s(%s) for %s, returning logon svr %s domain %s code %x token=%x \n " ,
2003-08-27 01:25:01 +00:00
asccomp , inet_ntoa ( p - > ip ) , ascuser , reply_name , lp_workgroup ( ) ,
SAMLOGON_R , lmnttoken ) ) ;
/* Construct reply. */
q = outbuf ;
/* we want the simple version unless we are an ADS PDC..which means */
/* never, at least for now */
if ( ( ntversion < 11 ) | | ( SEC_ADS ! = lp_security ( ) ) | | ( ROLE_DOMAIN_PDC ! = lp_server_role ( ) ) ) {
if ( SVAL ( uniuser , 0 ) = = 0 ) {
SSVAL ( q , 0 , SAMLOGON_UNK_R ) ; /* user unknown */
} else {
SSVAL ( q , 0 , SAMLOGON_R ) ;
}
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
q + = 2 ;
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
q + = dos_PutUniCode ( q , reply_name , sizeof ( pstring ) , True ) ;
q + = dos_PutUniCode ( q , ascuser , sizeof ( pstring ) , True ) ;
q + = dos_PutUniCode ( q , lp_workgroup ( ) , sizeof ( pstring ) , True ) ;
}
2002-08-17 17:00:51 +00:00
# ifdef HAVE_ADS
2003-08-27 01:25:01 +00:00
else {
2006-09-19 00:39:21 +00:00
struct GUID domain_guid ;
2004-04-13 14:39:48 +00:00
UUID_FLAT flat_guid ;
2003-08-27 01:25:01 +00:00
pstring domain ;
pstring hostname ;
char * component , * dc , * q1 ;
uint8 size ;
char * q_orig = q ;
int str_offset ;
2004-01-30 18:38:48 +00:00
get_mydnsdomname ( domain ) ;
2003-08-27 01:25:01 +00:00
get_myname ( hostname ) ;
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
if ( SVAL ( uniuser , 0 ) = = 0 ) {
SIVAL ( q , 0 , SAMLOGON_AD_UNK_R ) ; /* user unknown */
} else {
SIVAL ( q , 0 , SAMLOGON_AD_R ) ;
}
q + = 4 ;
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
SIVAL ( q , 0 , ADS_PDC | ADS_GC | ADS_LDAP | ADS_DS |
ADS_KDC | ADS_TIMESERV | ADS_CLOSEST | ADS_WRITABLE ) ;
q + = 4 ;
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
/* Push Domain GUID */
if ( False = = secrets_fetch_domain_guid ( domain , & domain_guid ) ) {
DEBUG ( 2 , ( " Could not fetch DomainGUID for %s \n " , domain ) ) ;
return ;
}
2004-04-13 14:39:48 +00:00
smb_uuid_pack ( domain_guid , & flat_guid ) ;
memcpy ( q , & flat_guid . info , UUID_FLAT_SIZE ) ;
q + = UUID_FLAT_SIZE ;
2003-08-27 01:25:01 +00:00
/* Forest */
str_offset = q - q_orig ;
dc = domain ;
q1 = q ;
while ( ( component = strtok ( dc , " . " ) ) ) {
dc = NULL ;
size = push_ascii ( & q [ 1 ] , component , - 1 , 0 ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
}
2003-05-20 13:49:53 +00:00
2003-08-27 01:25:01 +00:00
/* Unk0 */
SCVAL ( q , 0 , 0 ) ;
q + + ;
2002-08-17 17:00:51 +00:00
2003-08-27 01:25:01 +00:00
/* Domain */
SCVAL ( q , 0 , 0xc0 | ( ( str_offset > > 8 ) & 0x3F ) ) ;
SCVAL ( q , 1 , str_offset & 0xFF ) ;
q + = 2 ;
/* Hostname */
size = push_ascii ( & q [ 1 ] , hostname , - 1 , 0 ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
SCVAL ( q , 0 , 0xc0 | ( ( str_offset > > 8 ) & 0x3F ) ) ;
SCVAL ( q , 1 , str_offset & 0xFF ) ;
q + = 2 ;
/* NETBIOS of domain */
size = push_ascii ( & q [ 1 ] , lp_workgroup ( ) , - 1 , STR_UPPER ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
/* Unk1 */
SCVAL ( q , 0 , 0 ) ;
q + + ;
/* NETBIOS of hostname */
size = push_ascii ( & q [ 1 ] , my_name , - 1 , 0 ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
/* Unk2 */
SCVAL ( q , 0 , 0 ) ;
q + + ;
/* User name */
if ( SVAL ( uniuser , 0 ) ! = 0 ) {
size = push_ascii ( & q [ 1 ] , ascuser , - 1 , 0 ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
}
q_orig = q ;
/* Site name */
size = push_ascii ( & q [ 1 ] , " Default-First-Site-Name " , - 1 , 0 ) ;
SCVAL ( q , 0 , size ) ;
q + = ( size + 1 ) ;
/* Site name (2) */
str_offset = q - q_orig ;
SCVAL ( q , 0 , 0xc0 | ( ( str_offset > > 8 ) & 0x3F ) ) ;
SCVAL ( q , 1 , str_offset & 0xFF ) ;
q + = 2 ;
SCVAL ( q , 0 , PTR_DIFF ( q , q1 ) ) ;
SCVAL ( q , 1 , 0x10 ) ; /* unknown */
SIVAL ( q , 0 , 0x00000002 ) ;
q + = 4 ; /* unknown */
SIVAL ( q , 0 , ( iface_ip ( p - > ip ) ) - > s_addr ) ;
q + = 4 ;
SIVAL ( q , 0 , 0x00000000 ) ;
q + = 4 ; /* unknown */
SIVAL ( q , 0 , 0x00000000 ) ;
q + = 4 ; /* unknown */
}
2002-08-17 17:00:51 +00:00
# endif
1998-09-29 17:16:15 +00:00
2003-08-27 01:25:01 +00:00
/* tell the client what version we are */
SIVAL ( q , 0 , ( ( ntversion < 11 ) | | ( SEC_ADS ! = lp_security ( ) ) ) ? 1 : 13 ) ;
/* our ntversion */
SSVAL ( q , 4 , 0xffff ) ; /* our lmnttoken */
SSVAL ( q , 6 , 0xffff ) ; /* our lm20token */
q + = 8 ;
2007-03-28 13:34:59 +00:00
dump_data ( 4 , ( uint8 * ) outbuf , PTR_DIFF ( q , outbuf ) ) ;
2003-08-27 01:25:01 +00:00
pull_ascii_fstring ( getdc_str , getdc ) ;
2004-03-13 02:16:21 +00:00
pull_ascii_nstring ( source_name , sizeof ( source_name ) , dgram - > source_name . name ) ;
2003-08-27 01:25:01 +00:00
send_mailslot ( True , getdc ,
outbuf , PTR_DIFF ( q , outbuf ) ,
global_myname ( ) , 0x0 ,
2004-03-15 21:45:45 +00:00
source_name ,
2003-08-27 01:25:01 +00:00
dgram - > source_name . name_type ,
p - > ip , * iface_ip ( p - > ip ) , p - > port ) ;
break ;
}
/* Announce change to UAS or SAM. Send by the domain controller when a
replication event is required . */
case SAM_UAS_CHANGE :
{
struct sam_database_info * db_info ;
char * q = buf + 2 ;
int i , db_count ;
uint32 low_serial ;
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
/* Header */
2001-08-24 19:28:08 +00:00
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q + 16 , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
low_serial = IVAL ( q , 0 ) ; q + = 4 ; /* Low serial number */
2001-08-28 06:08:31 +00:00
2003-08-27 01:25:01 +00:00
q + = 4 ; /* Date/time */
q + = 4 ; /* Pulse */
q + = 4 ; /* Random */
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
/* Domain info */
2001-08-24 19:28:08 +00:00
2007-04-02 20:10:21 +00:00
q = skip_string ( buf , len , q ) ; /* PDC name */
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! q | | PTR_DIFF ( q , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2007-04-02 20:10:21 +00:00
q = skip_string ( buf , len , q ) ; /* Domain name */
2004-09-04 01:57:16 +00:00
2007-03-30 22:25:08 +00:00
if ( ! q | | PTR_DIFF ( q , buf ) > = len ) {
2004-09-04 01:57:16 +00:00
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
q = skip_unibuf ( q , PTR_DIFF ( buf + len , q ) ) ; /* Unicode PDC name */
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
q = skip_unibuf ( q , PTR_DIFF ( buf + len , q ) ) ; /* Unicode domain name */
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
/* Database info */
2001-08-24 19:28:08 +00:00
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q + 2 , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2003-08-27 01:25:01 +00:00
db_count = SVAL ( q , 0 ) ; q + = 2 ;
2004-09-04 01:57:16 +00:00
if ( PTR_DIFF ( q + ( db_count * 20 ) , buf ) > = len ) {
DEBUG ( 0 , ( " process_logon_packet: bad packet \n " ) ) ;
return ;
}
2004-12-07 18:25:53 +00:00
db_info = SMB_MALLOC_ARRAY ( struct sam_database_info , db_count ) ;
2003-08-27 01:25:01 +00:00
if ( db_info = = NULL ) {
DEBUG ( 3 , ( " out of memory allocating info for %d databases \n " , db_count ) ) ;
return ;
}
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
for ( i = 0 ; i < db_count ; i + + ) {
db_info [ i ] . index = IVAL ( q , 0 ) ;
db_info [ i ] . serial_lo = IVAL ( q , 4 ) ;
db_info [ i ] . serial_hi = IVAL ( q , 8 ) ;
db_info [ i ] . date_lo = IVAL ( q , 12 ) ;
db_info [ i ] . date_hi = IVAL ( q , 16 ) ;
q + = 20 ;
}
/* Domain SID */
2003-10-29 21:28:00 +00:00
#if 0
/* We must range check this. */
2003-08-27 01:25:01 +00:00
q + = IVAL ( q , 0 ) + 4 ; /* 4 byte length plus data */
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
q + = 2 ; /* Alignment? */
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
/* Misc other info */
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
q + = 4 ; /* NT version (0x1) */
q + = 2 ; /* LMNT token (0xff) */
q + = 2 ; /* LM20 token (0xff) */
2003-10-29 21:28:00 +00:00
# endif
2001-08-28 06:08:31 +00:00
2003-08-27 01:25:01 +00:00
SAFE_FREE ( db_info ) ; /* Not sure whether we need to do anything useful with these */
2001-08-28 06:08:31 +00:00
2003-08-27 01:25:01 +00:00
/* Send message to smbd */
2001-08-28 06:08:31 +00:00
2003-08-27 01:25:01 +00:00
send_repl_message ( low_serial ) ;
break ;
}
2001-08-24 19:28:08 +00:00
2003-08-27 01:25:01 +00:00
default :
DEBUG ( 3 , ( " process_logon_packet: Unknown domain request %d \n " , code ) ) ;
return ;
}
1997-12-13 14:16:07 +00:00
}