Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-dcerpc-efs.c
Line
Count
Source
1
/* DO NOT EDIT
2
  This file was automatically generated by Pidl
3
  from efs.idl and efs.cnf.
4
5
  Pidl is a perl based IDL compiler for DCE/RPC idl files.
6
  It is maintained by the Samba team, not the Wireshark team.
7
  Instructions on how to download and install Pidl can be
8
  found at https://wiki.wireshark.org/Pidl
9
*/
10
11
12
#include "config.h"
13
#include <string.h>
14
#include <wsutil/array.h>
15
#include <epan/packet.h>
16
#include <epan/tfs.h>
17
18
#include "packet-dcerpc.h"
19
#include "packet-dcerpc-nt.h"
20
#include "packet-windows-common.h"
21
#include "packet-dcerpc-efs.h"
22
void proto_register_dcerpc_efs(void);
23
void proto_reg_handoff_dcerpc_efs(void);
24
25
/* Ett declarations */
26
static int ett_dcerpc_efs;
27
static int ett_efs_EFS_HASH_BLOB;
28
static int ett_efs_ENCRYPTION_CERTIFICATE_HASH;
29
static int ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST;
30
static int ett_efs_EFS_CERTIFICATE_BLOB;
31
static int ett_efs_ENCRYPTION_CERTIFICATE;
32
33
34
/* Header field declarations */
35
static int hf_efs_EFS_CERTIFICATE_BLOB_cbData;
36
static int hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType;
37
static int hf_efs_EFS_CERTIFICATE_BLOB_pbData;
38
static int hf_efs_EFS_HASH_BLOB_cbData;
39
static int hf_efs_EFS_HASH_BLOB_pbData;
40
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash;
41
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers;
42
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength;
43
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation;
44
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash;
45
static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid;
46
static int hf_efs_ENCRYPTION_CERTIFICATE_TotalLength;
47
static int hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob;
48
static int hf_efs_ENCRYPTION_CERTIFICATE_pUserSid;
49
static int hf_efs_EfsRpcAddUsersToFile_FileName;
50
static int hf_efs_EfsRpcCloseRaw_pvContext;
51
static int hf_efs_EfsRpcDecryptFileSrv_FileName;
52
static int hf_efs_EfsRpcDecryptFileSrv_Reserved;
53
static int hf_efs_EfsRpcEncryptFileSrv_Filename;
54
static int hf_efs_EfsRpcOpenFileRaw_FileName;
55
static int hf_efs_EfsRpcOpenFileRaw_Flags;
56
static int hf_efs_EfsRpcOpenFileRaw_pvContext;
57
static int hf_efs_EfsRpcQueryRecoveryAgents_FileName;
58
static int hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents;
59
static int hf_efs_EfsRpcQueryUsersOnFile_FileName;
60
static int hf_efs_EfsRpcQueryUsersOnFile_pUsers;
61
static int hf_efs_EfsRpcReadFileRaw_pvContext;
62
static int hf_efs_EfsRpcRemoveUsersFromFile_FileName;
63
static int hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate;
64
static int hf_efs_EfsRpcWriteFileRaw_pvContext;
65
static int hf_efs_opnum;
66
static int hf_efs_werror;
67
68
static int proto_dcerpc_efs;
69
/* Version information */
70
71
72
static e_guid_t uuid_dcerpc_efs = {
73
  0xc681d488, 0xd850, 0x11d0,
74
  { 0x8c, 0x52, 0x00, 0xc0, 0x4f, 0xd9, 0x0f, 0x7e }
75
};
76
static uint16_t ver_dcerpc_efs = 1;
77
78
static unsigned efs_dissect_element_EFS_HASH_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
79
static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
80
static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
81
static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
82
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
83
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
84
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
85
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
86
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
87
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
88
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
89
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
90
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
91
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
92
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
93
static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
94
static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
95
static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
96
static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
97
static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
98
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
99
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
100
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
101
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
102
static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
103
static unsigned efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
104
static unsigned efs_dissect_element_EfsRpcOpenFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
105
static unsigned efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
106
static unsigned efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
107
static unsigned efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
108
static unsigned efs_dissect_element_EfsRpcReadFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
109
static unsigned efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
110
static unsigned efs_dissect_element_EfsRpcWriteFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
111
static unsigned efs_dissect_element_EfsRpcCloseRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
112
static unsigned efs_dissect_element_EfsRpcCloseRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
113
static unsigned efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
114
static unsigned efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
115
static unsigned efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
116
static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
117
static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
118
static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
119
static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
120
static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
121
static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
122
static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
123
static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
124
static unsigned efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
125
static unsigned efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
126
static unsigned efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
127
static unsigned efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_);
128
static unsigned
129
efs_dissect_struct_dom_sid(tvbuff_t *tvb, unsigned offset, packet_info *pinfo, proto_tree *tree, dcerpc_info* di, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
130
0
{
131
0
  if(di->conformant_run){
132
    /* just a run to handle conformant arrays, no scalars to dissect */
133
0
    return offset;
134
0
  }
135
0
  offset=dissect_nt_sid(tvb, pinfo, offset, tree, "SID", NULL, -1);
136
0
  return offset;
137
0
}
138
139
140
/* IDL: struct { */
141
/* IDL:   uint32 cbData; */
142
/* IDL:   [size_is(cbData)] [unique(1)] uint8 *pbData; */
143
/* IDL: } */
144
145
static unsigned
146
efs_dissect_element_EFS_HASH_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
147
0
{
148
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_HASH_BLOB_cbData, 0);
149
150
0
  return offset;
151
0
}
152
153
static unsigned
154
efs_dissect_element_EFS_HASH_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
155
0
{
156
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_HASH_BLOB_pbData_, NDR_POINTER_UNIQUE, "Pointer to PbData (uint8)",hf_efs_EFS_HASH_BLOB_pbData);
157
158
0
  return offset;
159
0
}
160
161
static unsigned
162
efs_dissect_element_EFS_HASH_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
163
0
{
164
0
  offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_HASH_BLOB_pbData__);
165
166
0
  return offset;
167
0
}
168
169
static unsigned
170
efs_dissect_element_EFS_HASH_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
171
0
{
172
0
  offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_HASH_BLOB_pbData, 0);
173
174
0
  return offset;
175
0
}
176
177
unsigned
178
efs_dissect_struct_EFS_HASH_BLOB(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
179
0
{
180
0
  proto_item *item = NULL;
181
0
  proto_tree *tree = NULL;
182
0
  unsigned old_offset;
183
184
0
  ALIGN_TO_5_BYTES;
185
186
0
  old_offset = offset;
187
188
0
  if (parent_tree) {
189
0
    item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA);
190
0
    tree = proto_item_add_subtree(item, ett_efs_EFS_HASH_BLOB);
191
0
  }
192
193
0
  offset = efs_dissect_element_EFS_HASH_BLOB_cbData(tvb, offset, pinfo, tree, di, drep);
194
195
0
  offset = efs_dissect_element_EFS_HASH_BLOB_pbData(tvb, offset, pinfo, tree, di, drep);
196
197
198
0
  proto_item_set_len(item, offset-old_offset);
199
200
201
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
202
0
    ALIGN_TO_5_BYTES;
203
0
  }
204
205
0
  return offset;
206
0
}
207
208
209
/* IDL: struct { */
210
/* IDL:   uint32 cbTotalLength; */
211
/* IDL:   [unique(1)] dom_sid *pUserSid; */
212
/* IDL:   [unique(1)] EFS_HASH_BLOB *pHash; */
213
/* IDL:   [charset(UTF16)] [unique(1)] uint16 *lpDisplayInformation; */
214
/* IDL: } */
215
216
static unsigned
217
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
218
0
{
219
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength, 0);
220
221
0
  return offset;
222
0
}
223
224
static unsigned
225
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
226
0
{
227
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_, NDR_POINTER_UNIQUE, "Pointer to PUserSid (dom_sid)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid);
228
229
0
  return offset;
230
0
}
231
232
static unsigned
233
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
234
0
{
235
0
  offset = efs_dissect_struct_dom_sid(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid,0);
236
237
0
  return offset;
238
0
}
239
240
static unsigned
241
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
242
0
{
243
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_, NDR_POINTER_UNIQUE, "Pointer to PHash (EFS_HASH_BLOB)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash);
244
245
0
  return offset;
246
0
}
247
248
static unsigned
249
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
250
0
{
251
0
  offset = efs_dissect_struct_EFS_HASH_BLOB(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash,0);
252
253
0
  return offset;
254
0
}
255
256
static unsigned
257
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
258
0
{
259
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_, NDR_POINTER_UNIQUE, "Pointer to LpDisplayInformation (uint16)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation);
260
261
0
  return offset;
262
0
}
263
264
static unsigned
265
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
266
0
{
267
0
  char *data;
268
269
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation, false, &data);
270
0
  proto_item_append_text(tree, ": %s", data);
271
272
0
  return offset;
273
0
}
274
275
unsigned
276
efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
277
0
{
278
0
  proto_item *item = NULL;
279
0
  proto_tree *tree = NULL;
280
0
  unsigned old_offset;
281
282
0
  ALIGN_TO_5_BYTES;
283
284
0
  old_offset = offset;
285
286
0
  if (parent_tree) {
287
0
    item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA);
288
0
    tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE_HASH);
289
0
  }
290
291
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvb, offset, pinfo, tree, di, drep);
292
293
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvb, offset, pinfo, tree, di, drep);
294
295
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvb, offset, pinfo, tree, di, drep);
296
297
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvb, offset, pinfo, tree, di, drep);
298
299
300
0
  proto_item_set_len(item, offset-old_offset);
301
302
303
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
304
0
    ALIGN_TO_5_BYTES;
305
0
  }
306
307
0
  return offset;
308
0
}
309
310
311
/* IDL: struct { */
312
/* IDL:   uint32 nCert_Hash; */
313
/* IDL:   [size_is(nCert_Hash)] [unique(1)] ENCRYPTION_CERTIFICATE_HASH *pUsers[*]; */
314
/* IDL: } */
315
316
static unsigned
317
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
318
0
{
319
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash, 0);
320
321
0
  return offset;
322
0
}
323
324
static unsigned
325
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
326
0
{
327
0
  offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_);
328
329
0
  return offset;
330
0
}
331
332
static unsigned
333
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
334
0
{
335
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__, NDR_POINTER_UNIQUE, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers);
336
337
0
  return offset;
338
0
}
339
340
static unsigned
341
efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
342
0
{
343
0
  offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers,0);
344
345
0
  return offset;
346
0
}
347
348
unsigned
349
efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
350
0
{
351
0
  proto_item *item = NULL;
352
0
  proto_tree *tree = NULL;
353
0
  unsigned old_offset;
354
355
0
  ALIGN_TO_5_BYTES;
356
357
0
  old_offset = offset;
358
359
0
  if (parent_tree) {
360
0
    item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA);
361
0
    tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST);
362
0
  }
363
364
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvb, offset, pinfo, tree, di, drep);
365
366
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvb, offset, pinfo, tree, di, drep);
367
368
369
0
  proto_item_set_len(item, offset-old_offset);
370
371
372
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
373
0
    ALIGN_TO_5_BYTES;
374
0
  }
375
376
0
  return offset;
377
0
}
378
379
380
/* IDL: struct { */
381
/* IDL:   uint32 dwCertEncodingType; */
382
/* IDL:   uint32 cbData; */
383
/* IDL:   [size_is(cbData)] [unique(1)] uint8 *pbData; */
384
/* IDL: } */
385
386
static unsigned
387
efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
388
0
{
389
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType, 0);
390
391
0
  return offset;
392
0
}
393
394
static unsigned
395
efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
396
0
{
397
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_cbData, 0);
398
399
0
  return offset;
400
0
}
401
402
static unsigned
403
efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
404
0
{
405
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_, NDR_POINTER_UNIQUE, "Pointer to PbData (uint8)",hf_efs_EFS_CERTIFICATE_BLOB_pbData);
406
407
0
  return offset;
408
0
}
409
410
static unsigned
411
efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
412
0
{
413
0
  offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__);
414
415
0
  return offset;
416
0
}
417
418
static unsigned
419
efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
420
0
{
421
0
  offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_pbData, 0);
422
423
0
  return offset;
424
0
}
425
426
unsigned
427
efs_dissect_struct_EFS_CERTIFICATE_BLOB(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
428
0
{
429
0
  proto_item *item = NULL;
430
0
  proto_tree *tree = NULL;
431
0
  unsigned old_offset;
432
433
0
  ALIGN_TO_5_BYTES;
434
435
0
  old_offset = offset;
436
437
0
  if (parent_tree) {
438
0
    item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA);
439
0
    tree = proto_item_add_subtree(item, ett_efs_EFS_CERTIFICATE_BLOB);
440
0
  }
441
442
0
  offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvb, offset, pinfo, tree, di, drep);
443
444
0
  offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvb, offset, pinfo, tree, di, drep);
445
446
0
  offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvb, offset, pinfo, tree, di, drep);
447
448
449
0
  proto_item_set_len(item, offset-old_offset);
450
451
452
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
453
0
    ALIGN_TO_5_BYTES;
454
0
  }
455
456
0
  return offset;
457
0
}
458
459
460
/* IDL: struct { */
461
/* IDL:   uint32 TotalLength; */
462
/* IDL:   [unique(1)] dom_sid *pUserSid; */
463
/* IDL:   [unique(1)] EFS_CERTIFICATE_BLOB *pCertBlob; */
464
/* IDL: } */
465
466
static unsigned
467
efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
468
0
{
469
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_TotalLength, 0);
470
471
0
  return offset;
472
0
}
473
474
static unsigned
475
efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
476
0
{
477
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_, NDR_POINTER_UNIQUE, "Pointer to PUserSid (dom_sid)",hf_efs_ENCRYPTION_CERTIFICATE_pUserSid);
478
479
0
  return offset;
480
0
}
481
482
static unsigned
483
efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
484
0
{
485
0
  offset = efs_dissect_struct_dom_sid(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_pUserSid,0);
486
487
0
  return offset;
488
0
}
489
490
static unsigned
491
efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
492
0
{
493
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_, NDR_POINTER_UNIQUE, "Pointer to PCertBlob (EFS_CERTIFICATE_BLOB)",hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob);
494
495
0
  return offset;
496
0
}
497
498
static unsigned
499
efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
500
0
{
501
0
  offset = efs_dissect_struct_EFS_CERTIFICATE_BLOB(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob,0);
502
503
0
  return offset;
504
0
}
505
506
unsigned
507
efs_dissect_struct_ENCRYPTION_CERTIFICATE(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_)
508
0
{
509
0
  proto_item *item = NULL;
510
0
  proto_tree *tree = NULL;
511
0
  unsigned old_offset;
512
513
0
  ALIGN_TO_5_BYTES;
514
515
0
  old_offset = offset;
516
517
0
  if (parent_tree) {
518
0
    item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA);
519
0
    tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE);
520
0
  }
521
522
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvb, offset, pinfo, tree, di, drep);
523
524
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvb, offset, pinfo, tree, di, drep);
525
526
0
  offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvb, offset, pinfo, tree, di, drep);
527
528
529
0
  proto_item_set_len(item, offset-old_offset);
530
531
532
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
533
0
    ALIGN_TO_5_BYTES;
534
0
  }
535
536
0
  return offset;
537
0
}
538
539
static unsigned
540
efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
541
0
{
542
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcOpenFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcOpenFileRaw_pvContext);
543
544
0
  return offset;
545
0
}
546
547
static unsigned
548
efs_dissect_element_EfsRpcOpenFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
549
0
{
550
0
  offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcOpenFileRaw_pvContext, PIDL_POLHND_OPEN);
551
552
0
  return offset;
553
0
}
554
555
static unsigned
556
efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
557
0
{
558
0
  char *data;
559
560
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcOpenFileRaw_FileName, false, &data);
561
0
  proto_item_append_text(tree, ": %s", data);
562
563
0
  return offset;
564
0
}
565
566
static unsigned
567
efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
568
0
{
569
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcOpenFileRaw_Flags, 0);
570
571
0
  return offset;
572
0
}
573
574
/* IDL: WERROR EfsRpcOpenFileRaw( */
575
/* IDL: [out] [ref] policy_handle *pvContext, */
576
/* IDL: [charset(UTF16)] [in] uint16 FileName[*], */
577
/* IDL: [in] uint32 Flags */
578
/* IDL: ); */
579
580
static unsigned
581
efs_dissect_EfsRpcOpenFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
582
0
{
583
0
  uint32_t status;
584
585
0
  di->dcerpc_procedure_name="EfsRpcOpenFileRaw";
586
0
  offset = efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep);
587
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
588
589
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
590
591
0
  if (status != 0)
592
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
593
594
0
  return offset;
595
0
}
596
597
static unsigned
598
efs_dissect_EfsRpcOpenFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
599
0
{
600
0
  di->dcerpc_procedure_name="EfsRpcOpenFileRaw";
601
0
  offset = efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvb, offset, pinfo, tree, di, drep);
602
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
603
0
  offset = efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvb, offset, pinfo, tree, di, drep);
604
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
605
0
  return offset;
606
0
}
607
608
static unsigned
609
efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
610
0
{
611
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcReadFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcReadFileRaw_pvContext);
612
613
0
  return offset;
614
0
}
615
616
static unsigned
617
efs_dissect_element_EfsRpcReadFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
618
0
{
619
0
  offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcReadFileRaw_pvContext, 0);
620
621
0
  return offset;
622
0
}
623
624
/* IDL: WERROR EfsRpcReadFileRaw( */
625
/* IDL: [in] [ref] policy_handle *pvContext */
626
/* IDL: ); */
627
628
static unsigned
629
efs_dissect_EfsRpcReadFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
630
0
{
631
0
  uint32_t status;
632
633
0
  di->dcerpc_procedure_name="EfsRpcReadFileRaw";
634
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
635
636
0
  if (status != 0)
637
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
638
639
0
  return offset;
640
0
}
641
642
static unsigned
643
efs_dissect_EfsRpcReadFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
644
0
{
645
0
  di->dcerpc_procedure_name="EfsRpcReadFileRaw";
646
0
  offset = efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep);
647
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
648
0
  return offset;
649
0
}
650
651
static unsigned
652
efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
653
0
{
654
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcWriteFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcWriteFileRaw_pvContext);
655
656
0
  return offset;
657
0
}
658
659
static unsigned
660
efs_dissect_element_EfsRpcWriteFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
661
0
{
662
0
  offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcWriteFileRaw_pvContext, 0);
663
664
0
  return offset;
665
0
}
666
667
/* IDL: WERROR EfsRpcWriteFileRaw( */
668
/* IDL: [in] [ref] policy_handle *pvContext */
669
/* IDL: ); */
670
671
static unsigned
672
efs_dissect_EfsRpcWriteFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
673
0
{
674
0
  uint32_t status;
675
676
0
  di->dcerpc_procedure_name="EfsRpcWriteFileRaw";
677
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
678
679
0
  if (status != 0)
680
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
681
682
0
  return offset;
683
0
}
684
685
static unsigned
686
efs_dissect_EfsRpcWriteFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
687
0
{
688
0
  di->dcerpc_procedure_name="EfsRpcWriteFileRaw";
689
0
  offset = efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep);
690
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
691
0
  return offset;
692
0
}
693
694
static unsigned
695
efs_dissect_element_EfsRpcCloseRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
696
0
{
697
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcCloseRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcCloseRaw_pvContext);
698
699
0
  return offset;
700
0
}
701
702
static unsigned
703
efs_dissect_element_EfsRpcCloseRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
704
0
{
705
0
  offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcCloseRaw_pvContext, PIDL_POLHND_CLOSE);
706
707
0
  return offset;
708
0
}
709
710
/* IDL: void EfsRpcCloseRaw( */
711
/* IDL: [in] [out] [ref] policy_handle *pvContext */
712
/* IDL: ); */
713
714
static unsigned
715
efs_dissect_EfsRpcCloseRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
716
0
{
717
0
  di->dcerpc_procedure_name="EfsRpcCloseRaw";
718
0
  offset = efs_dissect_element_EfsRpcCloseRaw_pvContext(tvb, offset, pinfo, tree, di, drep);
719
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
720
721
0
  return offset;
722
0
}
723
724
static unsigned
725
efs_dissect_EfsRpcCloseRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
726
0
{
727
0
  di->dcerpc_procedure_name="EfsRpcCloseRaw";
728
0
  offset = efs_dissect_element_EfsRpcCloseRaw_pvContext(tvb, offset, pinfo, tree, di, drep);
729
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
730
0
  return offset;
731
0
}
732
733
static unsigned
734
efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
735
0
{
736
0
  char *data;
737
738
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcEncryptFileSrv_Filename, false, &data);
739
0
  proto_item_append_text(tree, ": %s", data);
740
741
0
  return offset;
742
0
}
743
744
/* IDL: WERROR EfsRpcEncryptFileSrv( */
745
/* IDL: [charset(UTF16)] [in] uint16 Filename[*] */
746
/* IDL: ); */
747
748
static unsigned
749
efs_dissect_EfsRpcEncryptFileSrv_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
750
0
{
751
0
  uint32_t status;
752
753
0
  di->dcerpc_procedure_name="EfsRpcEncryptFileSrv";
754
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
755
756
0
  if (status != 0)
757
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
758
759
0
  return offset;
760
0
}
761
762
static unsigned
763
efs_dissect_EfsRpcEncryptFileSrv_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
764
0
{
765
0
  di->dcerpc_procedure_name="EfsRpcEncryptFileSrv";
766
0
  offset = efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvb, offset, pinfo, tree, di, drep);
767
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
768
0
  return offset;
769
0
}
770
771
static unsigned
772
efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
773
0
{
774
0
  char *data;
775
776
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcDecryptFileSrv_FileName, false, &data);
777
0
  proto_item_append_text(tree, ": %s", data);
778
779
0
  return offset;
780
0
}
781
782
static unsigned
783
efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
784
0
{
785
0
  offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcDecryptFileSrv_Reserved, 0);
786
787
0
  return offset;
788
0
}
789
790
/* IDL: WERROR EfsRpcDecryptFileSrv( */
791
/* IDL: [charset(UTF16)] [in] uint16 FileName[*], */
792
/* IDL: [in] uint32 Reserved */
793
/* IDL: ); */
794
795
static unsigned
796
efs_dissect_EfsRpcDecryptFileSrv_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
797
0
{
798
0
  uint32_t status;
799
800
0
  di->dcerpc_procedure_name="EfsRpcDecryptFileSrv";
801
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
802
803
0
  if (status != 0)
804
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
805
806
0
  return offset;
807
0
}
808
809
static unsigned
810
efs_dissect_EfsRpcDecryptFileSrv_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
811
0
{
812
0
  di->dcerpc_procedure_name="EfsRpcDecryptFileSrv";
813
0
  offset = efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvb, offset, pinfo, tree, di, drep);
814
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
815
0
  offset = efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvb, offset, pinfo, tree, di, drep);
816
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
817
0
  return offset;
818
0
}
819
820
static unsigned
821
efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
822
0
{
823
0
  char *data;
824
825
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcQueryUsersOnFile_FileName, false, &data);
826
0
  proto_item_append_text(tree, ": %s", data);
827
828
0
  return offset;
829
0
}
830
831
static unsigned
832
efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
833
0
{
834
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_, NDR_POINTER_REF, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryUsersOnFile_pUsers);
835
836
0
  return offset;
837
0
}
838
839
static unsigned
840
efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
841
0
{
842
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__, NDR_POINTER_UNIQUE, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryUsersOnFile_pUsers);
843
844
0
  return offset;
845
0
}
846
847
static unsigned
848
efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
849
0
{
850
0
  offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcQueryUsersOnFile_pUsers,0);
851
852
0
  return offset;
853
0
}
854
855
/* IDL: WERROR EfsRpcQueryUsersOnFile( */
856
/* IDL: [charset(UTF16)] [in] uint16 FileName[*], */
857
/* IDL: [out] [ref] [unique(1)] ENCRYPTION_CERTIFICATE_HASH_LIST **pUsers */
858
/* IDL: ); */
859
860
static unsigned
861
efs_dissect_EfsRpcQueryUsersOnFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
862
0
{
863
0
  uint32_t status;
864
865
0
  di->dcerpc_procedure_name="EfsRpcQueryUsersOnFile";
866
0
  offset = efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvb, offset, pinfo, tree, di, drep);
867
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
868
869
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
870
871
0
  if (status != 0)
872
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
873
874
0
  return offset;
875
0
}
876
877
static unsigned
878
efs_dissect_EfsRpcQueryUsersOnFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
879
0
{
880
0
  di->dcerpc_procedure_name="EfsRpcQueryUsersOnFile";
881
0
  offset = efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvb, offset, pinfo, tree, di, drep);
882
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
883
0
  return offset;
884
0
}
885
886
static unsigned
887
efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
888
0
{
889
0
  char *data;
890
891
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcQueryRecoveryAgents_FileName, false, &data);
892
0
  proto_item_append_text(tree, ": %s", data);
893
894
0
  return offset;
895
0
}
896
897
static unsigned
898
efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
899
0
{
900
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_, NDR_POINTER_REF, "Pointer to PRecoveryAgents (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents);
901
902
0
  return offset;
903
0
}
904
905
static unsigned
906
efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
907
0
{
908
0
  offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__, NDR_POINTER_UNIQUE, "Pointer to PRecoveryAgents (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents);
909
910
0
  return offset;
911
0
}
912
913
static unsigned
914
efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
915
0
{
916
0
  offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents,0);
917
918
0
  return offset;
919
0
}
920
921
/* IDL: WERROR EfsRpcQueryRecoveryAgents( */
922
/* IDL: [charset(UTF16)] [in] uint16 FileName[*], */
923
/* IDL: [out] [ref] [unique(1)] ENCRYPTION_CERTIFICATE_HASH_LIST **pRecoveryAgents */
924
/* IDL: ); */
925
926
static unsigned
927
efs_dissect_EfsRpcQueryRecoveryAgents_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
928
0
{
929
0
  uint32_t status;
930
931
0
  di->dcerpc_procedure_name="EfsRpcQueryRecoveryAgents";
932
0
  offset = efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvb, offset, pinfo, tree, di, drep);
933
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
934
935
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
936
937
0
  if (status != 0)
938
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
939
940
0
  return offset;
941
0
}
942
943
static unsigned
944
efs_dissect_EfsRpcQueryRecoveryAgents_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
945
0
{
946
0
  di->dcerpc_procedure_name="EfsRpcQueryRecoveryAgents";
947
0
  offset = efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvb, offset, pinfo, tree, di, drep);
948
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
949
0
  return offset;
950
0
}
951
952
static unsigned
953
efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
954
0
{
955
0
  char *data;
956
957
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcRemoveUsersFromFile_FileName, false, &data);
958
0
  proto_item_append_text(tree, ": %s", data);
959
960
0
  return offset;
961
0
}
962
963
/* IDL: WERROR EfsRpcRemoveUsersFromFile( */
964
/* IDL: [charset(UTF16)] [in] uint16 FileName[*] */
965
/* IDL: ); */
966
967
static unsigned
968
efs_dissect_EfsRpcRemoveUsersFromFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
969
0
{
970
0
  uint32_t status;
971
972
0
  di->dcerpc_procedure_name="EfsRpcRemoveUsersFromFile";
973
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
974
975
0
  if (status != 0)
976
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
977
978
0
  return offset;
979
0
}
980
981
static unsigned
982
efs_dissect_EfsRpcRemoveUsersFromFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
983
0
{
984
0
  di->dcerpc_procedure_name="EfsRpcRemoveUsersFromFile";
985
0
  offset = efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvb, offset, pinfo, tree, di, drep);
986
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
987
0
  return offset;
988
0
}
989
990
static unsigned
991
efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
992
0
{
993
0
  char *data;
994
995
0
  offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcAddUsersToFile_FileName, false, &data);
996
0
  proto_item_append_text(tree, ": %s", data);
997
998
0
  return offset;
999
0
}
1000
1001
/* IDL: WERROR EfsRpcAddUsersToFile( */
1002
/* IDL: [charset(UTF16)] [in] uint16 FileName[*] */
1003
/* IDL: ); */
1004
1005
static unsigned
1006
efs_dissect_EfsRpcAddUsersToFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1007
0
{
1008
0
  uint32_t status;
1009
1010
0
  di->dcerpc_procedure_name="EfsRpcAddUsersToFile";
1011
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
1012
1013
0
  if (status != 0)
1014
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
1015
1016
0
  return offset;
1017
0
}
1018
1019
static unsigned
1020
efs_dissect_EfsRpcAddUsersToFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1021
0
{
1022
0
  di->dcerpc_procedure_name="EfsRpcAddUsersToFile";
1023
0
  offset = efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvb, offset, pinfo, tree, di, drep);
1024
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
1025
0
  return offset;
1026
0
}
1027
1028
static unsigned
1029
efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1030
0
{
1031
0
  offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_, NDR_POINTER_UNIQUE, "Pointer to PEncryptionCertificate (ENCRYPTION_CERTIFICATE)",hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate);
1032
1033
0
  return offset;
1034
0
}
1035
1036
static unsigned
1037
efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1038
0
{
1039
0
  offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate,0);
1040
1041
0
  return offset;
1042
0
}
1043
1044
/* IDL: WERROR EfsRpcSetFileEncryptionKey( */
1045
/* IDL: [in] [unique(1)] ENCRYPTION_CERTIFICATE *pEncryptionCertificate */
1046
/* IDL: ); */
1047
1048
static unsigned
1049
efs_dissect_EfsRpcSetFileEncryptionKey_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1050
0
{
1051
0
  uint32_t status;
1052
1053
0
  di->dcerpc_procedure_name="EfsRpcSetFileEncryptionKey";
1054
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
1055
1056
0
  if (status != 0)
1057
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
1058
1059
0
  return offset;
1060
0
}
1061
1062
static unsigned
1063
efs_dissect_EfsRpcSetFileEncryptionKey_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1064
0
{
1065
0
  di->dcerpc_procedure_name="EfsRpcSetFileEncryptionKey";
1066
0
  offset = efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvb, offset, pinfo, tree, di, drep);
1067
0
  offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep);
1068
0
  return offset;
1069
0
}
1070
1071
/* IDL: WERROR EfsRpcNotSupported( */
1072
/* IDL:  */
1073
/* IDL: ); */
1074
1075
static unsigned
1076
efs_dissect_EfsRpcNotSupported_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1077
0
{
1078
0
  uint32_t status;
1079
1080
0
  di->dcerpc_procedure_name="EfsRpcNotSupported";
1081
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
1082
1083
0
  if (status != 0)
1084
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
1085
1086
0
  return offset;
1087
0
}
1088
1089
static unsigned
1090
efs_dissect_EfsRpcNotSupported_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1091
0
{
1092
0
  di->dcerpc_procedure_name="EfsRpcNotSupported";
1093
0
  return offset;
1094
0
}
1095
1096
/* IDL: WERROR EfsRpcFileKeyInfo( */
1097
/* IDL:  */
1098
/* IDL: ); */
1099
1100
static unsigned
1101
efs_dissect_EfsRpcFileKeyInfo_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1102
0
{
1103
0
  uint32_t status;
1104
1105
0
  di->dcerpc_procedure_name="EfsRpcFileKeyInfo";
1106
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
1107
1108
0
  if (status != 0)
1109
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
1110
1111
0
  return offset;
1112
0
}
1113
1114
static unsigned
1115
efs_dissect_EfsRpcFileKeyInfo_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1116
0
{
1117
0
  di->dcerpc_procedure_name="EfsRpcFileKeyInfo";
1118
0
  return offset;
1119
0
}
1120
1121
/* IDL: WERROR EfsRpcDuplicateEncryptionInfoFile( */
1122
/* IDL:  */
1123
/* IDL: ); */
1124
1125
static unsigned
1126
efs_dissect_EfsRpcDuplicateEncryptionInfoFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1127
0
{
1128
0
  uint32_t status;
1129
1130
0
  di->dcerpc_procedure_name="EfsRpcDuplicateEncryptionInfoFile";
1131
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status);
1132
1133
0
  if (status != 0)
1134
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x"));
1135
1136
0
  return offset;
1137
0
}
1138
1139
static unsigned
1140
efs_dissect_EfsRpcDuplicateEncryptionInfoFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_)
1141
0
{
1142
0
  di->dcerpc_procedure_name="EfsRpcDuplicateEncryptionInfoFile";
1143
0
  return offset;
1144
0
}
1145
1146
1147
static const dcerpc_sub_dissector efs_dissectors[] = {
1148
  { 0, "EfsRpcOpenFileRaw",
1149
     efs_dissect_EfsRpcOpenFileRaw_request, efs_dissect_EfsRpcOpenFileRaw_response},
1150
  { 1, "EfsRpcReadFileRaw",
1151
     efs_dissect_EfsRpcReadFileRaw_request, efs_dissect_EfsRpcReadFileRaw_response},
1152
  { 2, "EfsRpcWriteFileRaw",
1153
     efs_dissect_EfsRpcWriteFileRaw_request, efs_dissect_EfsRpcWriteFileRaw_response},
1154
  { 3, "EfsRpcCloseRaw",
1155
     efs_dissect_EfsRpcCloseRaw_request, efs_dissect_EfsRpcCloseRaw_response},
1156
  { 4, "EfsRpcEncryptFileSrv",
1157
     efs_dissect_EfsRpcEncryptFileSrv_request, efs_dissect_EfsRpcEncryptFileSrv_response},
1158
  { 5, "EfsRpcDecryptFileSrv",
1159
     efs_dissect_EfsRpcDecryptFileSrv_request, efs_dissect_EfsRpcDecryptFileSrv_response},
1160
  { 6, "EfsRpcQueryUsersOnFile",
1161
     efs_dissect_EfsRpcQueryUsersOnFile_request, efs_dissect_EfsRpcQueryUsersOnFile_response},
1162
  { 7, "EfsRpcQueryRecoveryAgents",
1163
     efs_dissect_EfsRpcQueryRecoveryAgents_request, efs_dissect_EfsRpcQueryRecoveryAgents_response},
1164
  { 8, "EfsRpcRemoveUsersFromFile",
1165
     efs_dissect_EfsRpcRemoveUsersFromFile_request, efs_dissect_EfsRpcRemoveUsersFromFile_response},
1166
  { 9, "EfsRpcAddUsersToFile",
1167
     efs_dissect_EfsRpcAddUsersToFile_request, efs_dissect_EfsRpcAddUsersToFile_response},
1168
  { 10, "EfsRpcSetFileEncryptionKey",
1169
     efs_dissect_EfsRpcSetFileEncryptionKey_request, efs_dissect_EfsRpcSetFileEncryptionKey_response},
1170
  { 11, "EfsRpcNotSupported",
1171
     efs_dissect_EfsRpcNotSupported_request, efs_dissect_EfsRpcNotSupported_response},
1172
  { 12, "EfsRpcFileKeyInfo",
1173
     efs_dissect_EfsRpcFileKeyInfo_request, efs_dissect_EfsRpcFileKeyInfo_response},
1174
  { 13, "EfsRpcDuplicateEncryptionInfoFile",
1175
     efs_dissect_EfsRpcDuplicateEncryptionInfoFile_request, efs_dissect_EfsRpcDuplicateEncryptionInfoFile_response},
1176
  { 0, NULL, NULL, NULL }
1177
};
1178
1179
void proto_register_dcerpc_efs(void)
1180
16
{
1181
16
  static hf_register_info hf[] = {
1182
16
  { &hf_efs_EFS_CERTIFICATE_BLOB_cbData,
1183
16
    { "CbData", "efs.EFS_CERTIFICATE_BLOB.cbData", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1184
16
  { &hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType,
1185
16
    { "DwCertEncodingType", "efs.EFS_CERTIFICATE_BLOB.dwCertEncodingType", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1186
16
  { &hf_efs_EFS_CERTIFICATE_BLOB_pbData,
1187
16
    { "PbData", "efs.EFS_CERTIFICATE_BLOB.pbData", FT_UINT8, BASE_DEC, NULL, 0, NULL, HFILL }},
1188
16
  { &hf_efs_EFS_HASH_BLOB_cbData,
1189
16
    { "CbData", "efs.EFS_HASH_BLOB.cbData", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1190
16
  { &hf_efs_EFS_HASH_BLOB_pbData,
1191
16
    { "PbData", "efs.EFS_HASH_BLOB.pbData", FT_UINT8, BASE_DEC, NULL, 0, NULL, HFILL }},
1192
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash,
1193
16
    { "NCert Hash", "efs.ENCRYPTION_CERTIFICATE_HASH_LIST.nCert_Hash", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1194
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers,
1195
16
    { "PUsers", "efs.ENCRYPTION_CERTIFICATE_HASH_LIST.pUsers", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1196
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength,
1197
16
    { "CbTotalLength", "efs.ENCRYPTION_CERTIFICATE_HASH.cbTotalLength", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1198
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation,
1199
16
    { "LpDisplayInformation", "efs.ENCRYPTION_CERTIFICATE_HASH.lpDisplayInformation", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1200
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash,
1201
16
    { "PHash", "efs.ENCRYPTION_CERTIFICATE_HASH.pHash", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1202
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid,
1203
16
    { "PUserSid", "efs.ENCRYPTION_CERTIFICATE_HASH.pUserSid", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1204
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_TotalLength,
1205
16
    { "TotalLength", "efs.ENCRYPTION_CERTIFICATE.TotalLength", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1206
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob,
1207
16
    { "PCertBlob", "efs.ENCRYPTION_CERTIFICATE.pCertBlob", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1208
16
  { &hf_efs_ENCRYPTION_CERTIFICATE_pUserSid,
1209
16
    { "PUserSid", "efs.ENCRYPTION_CERTIFICATE.pUserSid", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1210
16
  { &hf_efs_EfsRpcAddUsersToFile_FileName,
1211
16
    { "FileName", "efs.EfsRpcAddUsersToFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1212
16
  { &hf_efs_EfsRpcCloseRaw_pvContext,
1213
16
    { "PvContext", "efs.EfsRpcCloseRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
1214
16
  { &hf_efs_EfsRpcDecryptFileSrv_FileName,
1215
16
    { "FileName", "efs.EfsRpcDecryptFileSrv.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1216
16
  { &hf_efs_EfsRpcDecryptFileSrv_Reserved,
1217
16
    { "Reserved", "efs.EfsRpcDecryptFileSrv.Reserved", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1218
16
  { &hf_efs_EfsRpcEncryptFileSrv_Filename,
1219
16
    { "Filename", "efs.EfsRpcEncryptFileSrv.Filename", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1220
16
  { &hf_efs_EfsRpcOpenFileRaw_FileName,
1221
16
    { "FileName", "efs.EfsRpcOpenFileRaw.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1222
16
  { &hf_efs_EfsRpcOpenFileRaw_Flags,
1223
16
    { "Flags", "efs.EfsRpcOpenFileRaw.Flags", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
1224
16
  { &hf_efs_EfsRpcOpenFileRaw_pvContext,
1225
16
    { "PvContext", "efs.EfsRpcOpenFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
1226
16
  { &hf_efs_EfsRpcQueryRecoveryAgents_FileName,
1227
16
    { "FileName", "efs.EfsRpcQueryRecoveryAgents.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1228
16
  { &hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents,
1229
16
    { "PRecoveryAgents", "efs.EfsRpcQueryRecoveryAgents.pRecoveryAgents", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1230
16
  { &hf_efs_EfsRpcQueryUsersOnFile_FileName,
1231
16
    { "FileName", "efs.EfsRpcQueryUsersOnFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1232
16
  { &hf_efs_EfsRpcQueryUsersOnFile_pUsers,
1233
16
    { "PUsers", "efs.EfsRpcQueryUsersOnFile.pUsers", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1234
16
  { &hf_efs_EfsRpcReadFileRaw_pvContext,
1235
16
    { "PvContext", "efs.EfsRpcReadFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
1236
16
  { &hf_efs_EfsRpcRemoveUsersFromFile_FileName,
1237
16
    { "FileName", "efs.EfsRpcRemoveUsersFromFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }},
1238
16
  { &hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate,
1239
16
    { "PEncryptionCertificate", "efs.EfsRpcSetFileEncryptionKey.pEncryptionCertificate", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }},
1240
16
  { &hf_efs_EfsRpcWriteFileRaw_pvContext,
1241
16
    { "PvContext", "efs.EfsRpcWriteFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
1242
16
  { &hf_efs_opnum,
1243
16
    { "Operation", "efs.opnum", FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
1244
16
  { &hf_efs_werror,
1245
16
    { "Windows Error", "efs.werror", FT_UINT32, BASE_HEX|BASE_EXT_STRING, &WERR_errors_ext, 0, NULL, HFILL }},
1246
16
  };
1247
1248
1249
16
  static int *ett[] = {
1250
16
    &ett_dcerpc_efs,
1251
16
    &ett_efs_EFS_HASH_BLOB,
1252
16
    &ett_efs_ENCRYPTION_CERTIFICATE_HASH,
1253
16
    &ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST,
1254
16
    &ett_efs_EFS_CERTIFICATE_BLOB,
1255
16
    &ett_efs_ENCRYPTION_CERTIFICATE,
1256
16
  };
1257
1258
16
  proto_dcerpc_efs = proto_register_protocol("EFS (pidl)", "EFS", "efs");
1259
16
  proto_register_field_array(proto_dcerpc_efs, hf, array_length (hf));
1260
16
  proto_register_subtree_array(ett, array_length(ett));
1261
16
}
1262
1263
void proto_reg_handoff_dcerpc_efs(void)
1264
16
{
1265
16
  dcerpc_init_uuid(proto_dcerpc_efs, ett_dcerpc_efs,
1266
16
    &uuid_dcerpc_efs, ver_dcerpc_efs,
1267
16
    efs_dissectors, hf_efs_opnum);
1268
16
}