/src/wireshark/epan/dissectors/packet-dcerpc-efs.c
Line | Count | Source |
1 | | /* DO NOT EDIT |
2 | | This file was automatically generated by Pidl |
3 | | from efs.idl and efs.cnf. |
4 | | |
5 | | Pidl is a perl based IDL compiler for DCE/RPC idl files. |
6 | | It is maintained by the Samba team, not the Wireshark team. |
7 | | Instructions on how to download and install Pidl can be |
8 | | found at https://wiki.wireshark.org/Pidl |
9 | | */ |
10 | | |
11 | | |
12 | | #include "config.h" |
13 | | #include <string.h> |
14 | | #include <wsutil/array.h> |
15 | | #include <epan/packet.h> |
16 | | #include <epan/tfs.h> |
17 | | |
18 | | #include "packet-dcerpc.h" |
19 | | #include "packet-dcerpc-nt.h" |
20 | | #include "packet-windows-common.h" |
21 | | #include "packet-dcerpc-efs.h" |
22 | | void proto_register_dcerpc_efs(void); |
23 | | void proto_reg_handoff_dcerpc_efs(void); |
24 | | |
25 | | /* Ett declarations */ |
26 | | static int ett_dcerpc_efs; |
27 | | static int ett_efs_EFS_HASH_BLOB; |
28 | | static int ett_efs_ENCRYPTION_CERTIFICATE_HASH; |
29 | | static int ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST; |
30 | | static int ett_efs_EFS_CERTIFICATE_BLOB; |
31 | | static int ett_efs_ENCRYPTION_CERTIFICATE; |
32 | | |
33 | | |
34 | | /* Header field declarations */ |
35 | | static int hf_efs_EFS_CERTIFICATE_BLOB_cbData; |
36 | | static int hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType; |
37 | | static int hf_efs_EFS_CERTIFICATE_BLOB_pbData; |
38 | | static int hf_efs_EFS_HASH_BLOB_cbData; |
39 | | static int hf_efs_EFS_HASH_BLOB_pbData; |
40 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash; |
41 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers; |
42 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength; |
43 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation; |
44 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash; |
45 | | static int hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid; |
46 | | static int hf_efs_ENCRYPTION_CERTIFICATE_TotalLength; |
47 | | static int hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob; |
48 | | static int hf_efs_ENCRYPTION_CERTIFICATE_pUserSid; |
49 | | static int hf_efs_EfsRpcAddUsersToFile_FileName; |
50 | | static int hf_efs_EfsRpcCloseRaw_pvContext; |
51 | | static int hf_efs_EfsRpcDecryptFileSrv_FileName; |
52 | | static int hf_efs_EfsRpcDecryptFileSrv_Reserved; |
53 | | static int hf_efs_EfsRpcEncryptFileSrv_Filename; |
54 | | static int hf_efs_EfsRpcOpenFileRaw_FileName; |
55 | | static int hf_efs_EfsRpcOpenFileRaw_Flags; |
56 | | static int hf_efs_EfsRpcOpenFileRaw_pvContext; |
57 | | static int hf_efs_EfsRpcQueryRecoveryAgents_FileName; |
58 | | static int hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents; |
59 | | static int hf_efs_EfsRpcQueryUsersOnFile_FileName; |
60 | | static int hf_efs_EfsRpcQueryUsersOnFile_pUsers; |
61 | | static int hf_efs_EfsRpcReadFileRaw_pvContext; |
62 | | static int hf_efs_EfsRpcRemoveUsersFromFile_FileName; |
63 | | static int hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate; |
64 | | static int hf_efs_EfsRpcWriteFileRaw_pvContext; |
65 | | static int hf_efs_opnum; |
66 | | static int hf_efs_werror; |
67 | | |
68 | | static int proto_dcerpc_efs; |
69 | | /* Version information */ |
70 | | |
71 | | |
72 | | static e_guid_t uuid_dcerpc_efs = { |
73 | | 0xc681d488, 0xd850, 0x11d0, |
74 | | { 0x8c, 0x52, 0x00, 0xc0, 0x4f, 0xd9, 0x0f, 0x7e } |
75 | | }; |
76 | | static uint16_t ver_dcerpc_efs = 1; |
77 | | |
78 | | static unsigned efs_dissect_element_EFS_HASH_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
79 | | static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
80 | | static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
81 | | static unsigned efs_dissect_element_EFS_HASH_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
82 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
83 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
84 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
85 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
86 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
87 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
88 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
89 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
90 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
91 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
92 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
93 | | static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
94 | | static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
95 | | static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
96 | | static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
97 | | static unsigned efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
98 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
99 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
100 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
101 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
102 | | static unsigned efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
103 | | static unsigned efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
104 | | static unsigned efs_dissect_element_EfsRpcOpenFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
105 | | static unsigned efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
106 | | static unsigned efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
107 | | static unsigned efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
108 | | static unsigned efs_dissect_element_EfsRpcReadFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
109 | | static unsigned efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
110 | | static unsigned efs_dissect_element_EfsRpcWriteFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
111 | | static unsigned efs_dissect_element_EfsRpcCloseRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
112 | | static unsigned efs_dissect_element_EfsRpcCloseRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
113 | | static unsigned efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
114 | | static unsigned efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
115 | | static unsigned efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
116 | | static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
117 | | static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
118 | | static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
119 | | static unsigned efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
120 | | static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
121 | | static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
122 | | static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
123 | | static unsigned efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
124 | | static unsigned efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
125 | | static unsigned efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
126 | | static unsigned efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
127 | | static unsigned efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_); |
128 | | static unsigned |
129 | | efs_dissect_struct_dom_sid(tvbuff_t *tvb, unsigned offset, packet_info *pinfo, proto_tree *tree, dcerpc_info* di, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
130 | 0 | { |
131 | 0 | if(di->conformant_run){ |
132 | | /* just a run to handle conformant arrays, no scalars to dissect */ |
133 | 0 | return offset; |
134 | 0 | } |
135 | 0 | offset=dissect_nt_sid(tvb, pinfo, offset, tree, "SID", NULL, -1); |
136 | 0 | return offset; |
137 | 0 | } |
138 | | |
139 | | |
140 | | /* IDL: struct { */ |
141 | | /* IDL: uint32 cbData; */ |
142 | | /* IDL: [size_is(cbData)] [unique(1)] uint8 *pbData; */ |
143 | | /* IDL: } */ |
144 | | |
145 | | static unsigned |
146 | | efs_dissect_element_EFS_HASH_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
147 | 0 | { |
148 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_HASH_BLOB_cbData, 0); |
149 | |
|
150 | 0 | return offset; |
151 | 0 | } |
152 | | |
153 | | static unsigned |
154 | | efs_dissect_element_EFS_HASH_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
155 | 0 | { |
156 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_HASH_BLOB_pbData_, NDR_POINTER_UNIQUE, "Pointer to PbData (uint8)",hf_efs_EFS_HASH_BLOB_pbData); |
157 | |
|
158 | 0 | return offset; |
159 | 0 | } |
160 | | |
161 | | static unsigned |
162 | | efs_dissect_element_EFS_HASH_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
163 | 0 | { |
164 | 0 | offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_HASH_BLOB_pbData__); |
165 | |
|
166 | 0 | return offset; |
167 | 0 | } |
168 | | |
169 | | static unsigned |
170 | | efs_dissect_element_EFS_HASH_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
171 | 0 | { |
172 | 0 | offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_HASH_BLOB_pbData, 0); |
173 | |
|
174 | 0 | return offset; |
175 | 0 | } |
176 | | |
177 | | unsigned |
178 | | efs_dissect_struct_EFS_HASH_BLOB(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
179 | 0 | { |
180 | 0 | proto_item *item = NULL; |
181 | 0 | proto_tree *tree = NULL; |
182 | 0 | unsigned old_offset; |
183 | |
|
184 | 0 | ALIGN_TO_5_BYTES; |
185 | |
|
186 | 0 | old_offset = offset; |
187 | |
|
188 | 0 | if (parent_tree) { |
189 | 0 | item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA); |
190 | 0 | tree = proto_item_add_subtree(item, ett_efs_EFS_HASH_BLOB); |
191 | 0 | } |
192 | |
|
193 | 0 | offset = efs_dissect_element_EFS_HASH_BLOB_cbData(tvb, offset, pinfo, tree, di, drep); |
194 | |
|
195 | 0 | offset = efs_dissect_element_EFS_HASH_BLOB_pbData(tvb, offset, pinfo, tree, di, drep); |
196 | | |
197 | |
|
198 | 0 | proto_item_set_len(item, offset-old_offset); |
199 | | |
200 | |
|
201 | 0 | if (di->call_data->flags & DCERPC_IS_NDR64) { |
202 | 0 | ALIGN_TO_5_BYTES; |
203 | 0 | } |
204 | |
|
205 | 0 | return offset; |
206 | 0 | } |
207 | | |
208 | | |
209 | | /* IDL: struct { */ |
210 | | /* IDL: uint32 cbTotalLength; */ |
211 | | /* IDL: [unique(1)] dom_sid *pUserSid; */ |
212 | | /* IDL: [unique(1)] EFS_HASH_BLOB *pHash; */ |
213 | | /* IDL: [charset(UTF16)] [unique(1)] uint16 *lpDisplayInformation; */ |
214 | | /* IDL: } */ |
215 | | |
216 | | static unsigned |
217 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
218 | 0 | { |
219 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength, 0); |
220 | |
|
221 | 0 | return offset; |
222 | 0 | } |
223 | | |
224 | | static unsigned |
225 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
226 | 0 | { |
227 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_, NDR_POINTER_UNIQUE, "Pointer to PUserSid (dom_sid)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid); |
228 | |
|
229 | 0 | return offset; |
230 | 0 | } |
231 | | |
232 | | static unsigned |
233 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
234 | 0 | { |
235 | 0 | offset = efs_dissect_struct_dom_sid(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid,0); |
236 | |
|
237 | 0 | return offset; |
238 | 0 | } |
239 | | |
240 | | static unsigned |
241 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
242 | 0 | { |
243 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_, NDR_POINTER_UNIQUE, "Pointer to PHash (EFS_HASH_BLOB)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash); |
244 | |
|
245 | 0 | return offset; |
246 | 0 | } |
247 | | |
248 | | static unsigned |
249 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
250 | 0 | { |
251 | 0 | offset = efs_dissect_struct_EFS_HASH_BLOB(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash,0); |
252 | |
|
253 | 0 | return offset; |
254 | 0 | } |
255 | | |
256 | | static unsigned |
257 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
258 | 0 | { |
259 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_, NDR_POINTER_UNIQUE, "Pointer to LpDisplayInformation (uint16)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation); |
260 | |
|
261 | 0 | return offset; |
262 | 0 | } |
263 | | |
264 | | static unsigned |
265 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
266 | 0 | { |
267 | 0 | char *data; |
268 | |
|
269 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation, false, &data); |
270 | 0 | proto_item_append_text(tree, ": %s", data); |
271 | |
|
272 | 0 | return offset; |
273 | 0 | } |
274 | | |
275 | | unsigned |
276 | | efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
277 | 0 | { |
278 | 0 | proto_item *item = NULL; |
279 | 0 | proto_tree *tree = NULL; |
280 | 0 | unsigned old_offset; |
281 | |
|
282 | 0 | ALIGN_TO_5_BYTES; |
283 | |
|
284 | 0 | old_offset = offset; |
285 | |
|
286 | 0 | if (parent_tree) { |
287 | 0 | item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA); |
288 | 0 | tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE_HASH); |
289 | 0 | } |
290 | |
|
291 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength(tvb, offset, pinfo, tree, di, drep); |
292 | |
|
293 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pUserSid(tvb, offset, pinfo, tree, di, drep); |
294 | |
|
295 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_pHash(tvb, offset, pinfo, tree, di, drep); |
296 | |
|
297 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation(tvb, offset, pinfo, tree, di, drep); |
298 | | |
299 | |
|
300 | 0 | proto_item_set_len(item, offset-old_offset); |
301 | | |
302 | |
|
303 | 0 | if (di->call_data->flags & DCERPC_IS_NDR64) { |
304 | 0 | ALIGN_TO_5_BYTES; |
305 | 0 | } |
306 | |
|
307 | 0 | return offset; |
308 | 0 | } |
309 | | |
310 | | |
311 | | /* IDL: struct { */ |
312 | | /* IDL: uint32 nCert_Hash; */ |
313 | | /* IDL: [size_is(nCert_Hash)] [unique(1)] ENCRYPTION_CERTIFICATE_HASH *pUsers[*]; */ |
314 | | /* IDL: } */ |
315 | | |
316 | | static unsigned |
317 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
318 | 0 | { |
319 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash, 0); |
320 | |
|
321 | 0 | return offset; |
322 | 0 | } |
323 | | |
324 | | static unsigned |
325 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
326 | 0 | { |
327 | 0 | offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_); |
328 | |
|
329 | 0 | return offset; |
330 | 0 | } |
331 | | |
332 | | static unsigned |
333 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
334 | 0 | { |
335 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__, NDR_POINTER_UNIQUE, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH)",hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers); |
336 | |
|
337 | 0 | return offset; |
338 | 0 | } |
339 | | |
340 | | static unsigned |
341 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
342 | 0 | { |
343 | 0 | offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers,0); |
344 | |
|
345 | 0 | return offset; |
346 | 0 | } |
347 | | |
348 | | unsigned |
349 | | efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
350 | 0 | { |
351 | 0 | proto_item *item = NULL; |
352 | 0 | proto_tree *tree = NULL; |
353 | 0 | unsigned old_offset; |
354 | |
|
355 | 0 | ALIGN_TO_5_BYTES; |
356 | |
|
357 | 0 | old_offset = offset; |
358 | |
|
359 | 0 | if (parent_tree) { |
360 | 0 | item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA); |
361 | 0 | tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST); |
362 | 0 | } |
363 | |
|
364 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash(tvb, offset, pinfo, tree, di, drep); |
365 | |
|
366 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers(tvb, offset, pinfo, tree, di, drep); |
367 | | |
368 | |
|
369 | 0 | proto_item_set_len(item, offset-old_offset); |
370 | | |
371 | |
|
372 | 0 | if (di->call_data->flags & DCERPC_IS_NDR64) { |
373 | 0 | ALIGN_TO_5_BYTES; |
374 | 0 | } |
375 | |
|
376 | 0 | return offset; |
377 | 0 | } |
378 | | |
379 | | |
380 | | /* IDL: struct { */ |
381 | | /* IDL: uint32 dwCertEncodingType; */ |
382 | | /* IDL: uint32 cbData; */ |
383 | | /* IDL: [size_is(cbData)] [unique(1)] uint8 *pbData; */ |
384 | | /* IDL: } */ |
385 | | |
386 | | static unsigned |
387 | | efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
388 | 0 | { |
389 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType, 0); |
390 | |
|
391 | 0 | return offset; |
392 | 0 | } |
393 | | |
394 | | static unsigned |
395 | | efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
396 | 0 | { |
397 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_cbData, 0); |
398 | |
|
399 | 0 | return offset; |
400 | 0 | } |
401 | | |
402 | | static unsigned |
403 | | efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
404 | 0 | { |
405 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_, NDR_POINTER_UNIQUE, "Pointer to PbData (uint8)",hf_efs_EFS_CERTIFICATE_BLOB_pbData); |
406 | |
|
407 | 0 | return offset; |
408 | 0 | } |
409 | | |
410 | | static unsigned |
411 | | efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
412 | 0 | { |
413 | 0 | offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__); |
414 | |
|
415 | 0 | return offset; |
416 | 0 | } |
417 | | |
418 | | static unsigned |
419 | | efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
420 | 0 | { |
421 | 0 | offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, di, drep, hf_efs_EFS_CERTIFICATE_BLOB_pbData, 0); |
422 | |
|
423 | 0 | return offset; |
424 | 0 | } |
425 | | |
426 | | unsigned |
427 | | efs_dissect_struct_EFS_CERTIFICATE_BLOB(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
428 | 0 | { |
429 | 0 | proto_item *item = NULL; |
430 | 0 | proto_tree *tree = NULL; |
431 | 0 | unsigned old_offset; |
432 | |
|
433 | 0 | ALIGN_TO_5_BYTES; |
434 | |
|
435 | 0 | old_offset = offset; |
436 | |
|
437 | 0 | if (parent_tree) { |
438 | 0 | item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA); |
439 | 0 | tree = proto_item_add_subtree(item, ett_efs_EFS_CERTIFICATE_BLOB); |
440 | 0 | } |
441 | |
|
442 | 0 | offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_dwCertEncodingType(tvb, offset, pinfo, tree, di, drep); |
443 | |
|
444 | 0 | offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_cbData(tvb, offset, pinfo, tree, di, drep); |
445 | |
|
446 | 0 | offset = efs_dissect_element_EFS_CERTIFICATE_BLOB_pbData(tvb, offset, pinfo, tree, di, drep); |
447 | | |
448 | |
|
449 | 0 | proto_item_set_len(item, offset-old_offset); |
450 | | |
451 | |
|
452 | 0 | if (di->call_data->flags & DCERPC_IS_NDR64) { |
453 | 0 | ALIGN_TO_5_BYTES; |
454 | 0 | } |
455 | |
|
456 | 0 | return offset; |
457 | 0 | } |
458 | | |
459 | | |
460 | | /* IDL: struct { */ |
461 | | /* IDL: uint32 TotalLength; */ |
462 | | /* IDL: [unique(1)] dom_sid *pUserSid; */ |
463 | | /* IDL: [unique(1)] EFS_CERTIFICATE_BLOB *pCertBlob; */ |
464 | | /* IDL: } */ |
465 | | |
466 | | static unsigned |
467 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
468 | 0 | { |
469 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_ENCRYPTION_CERTIFICATE_TotalLength, 0); |
470 | |
|
471 | 0 | return offset; |
472 | 0 | } |
473 | | |
474 | | static unsigned |
475 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
476 | 0 | { |
477 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_, NDR_POINTER_UNIQUE, "Pointer to PUserSid (dom_sid)",hf_efs_ENCRYPTION_CERTIFICATE_pUserSid); |
478 | |
|
479 | 0 | return offset; |
480 | 0 | } |
481 | | |
482 | | static unsigned |
483 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
484 | 0 | { |
485 | 0 | offset = efs_dissect_struct_dom_sid(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_pUserSid,0); |
486 | |
|
487 | 0 | return offset; |
488 | 0 | } |
489 | | |
490 | | static unsigned |
491 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
492 | 0 | { |
493 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_, NDR_POINTER_UNIQUE, "Pointer to PCertBlob (EFS_CERTIFICATE_BLOB)",hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob); |
494 | |
|
495 | 0 | return offset; |
496 | 0 | } |
497 | | |
498 | | static unsigned |
499 | | efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
500 | 0 | { |
501 | 0 | offset = efs_dissect_struct_EFS_CERTIFICATE_BLOB(tvb,offset,pinfo,tree,di,drep,hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob,0); |
502 | |
|
503 | 0 | return offset; |
504 | 0 | } |
505 | | |
506 | | unsigned |
507 | | efs_dissect_struct_ENCRYPTION_CERTIFICATE(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_, int hf_index _U_, uint32_t param _U_) |
508 | 0 | { |
509 | 0 | proto_item *item = NULL; |
510 | 0 | proto_tree *tree = NULL; |
511 | 0 | unsigned old_offset; |
512 | |
|
513 | 0 | ALIGN_TO_5_BYTES; |
514 | |
|
515 | 0 | old_offset = offset; |
516 | |
|
517 | 0 | if (parent_tree) { |
518 | 0 | item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, ENC_NA); |
519 | 0 | tree = proto_item_add_subtree(item, ett_efs_ENCRYPTION_CERTIFICATE); |
520 | 0 | } |
521 | |
|
522 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_TotalLength(tvb, offset, pinfo, tree, di, drep); |
523 | |
|
524 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_pUserSid(tvb, offset, pinfo, tree, di, drep); |
525 | |
|
526 | 0 | offset = efs_dissect_element_ENCRYPTION_CERTIFICATE_pCertBlob(tvb, offset, pinfo, tree, di, drep); |
527 | | |
528 | |
|
529 | 0 | proto_item_set_len(item, offset-old_offset); |
530 | | |
531 | |
|
532 | 0 | if (di->call_data->flags & DCERPC_IS_NDR64) { |
533 | 0 | ALIGN_TO_5_BYTES; |
534 | 0 | } |
535 | |
|
536 | 0 | return offset; |
537 | 0 | } |
538 | | |
539 | | static unsigned |
540 | | efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
541 | 0 | { |
542 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcOpenFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcOpenFileRaw_pvContext); |
543 | |
|
544 | 0 | return offset; |
545 | 0 | } |
546 | | |
547 | | static unsigned |
548 | | efs_dissect_element_EfsRpcOpenFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
549 | 0 | { |
550 | 0 | offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcOpenFileRaw_pvContext, PIDL_POLHND_OPEN); |
551 | |
|
552 | 0 | return offset; |
553 | 0 | } |
554 | | |
555 | | static unsigned |
556 | | efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
557 | 0 | { |
558 | 0 | char *data; |
559 | |
|
560 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcOpenFileRaw_FileName, false, &data); |
561 | 0 | proto_item_append_text(tree, ": %s", data); |
562 | |
|
563 | 0 | return offset; |
564 | 0 | } |
565 | | |
566 | | static unsigned |
567 | | efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
568 | 0 | { |
569 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcOpenFileRaw_Flags, 0); |
570 | |
|
571 | 0 | return offset; |
572 | 0 | } |
573 | | |
574 | | /* IDL: WERROR EfsRpcOpenFileRaw( */ |
575 | | /* IDL: [out] [ref] policy_handle *pvContext, */ |
576 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*], */ |
577 | | /* IDL: [in] uint32 Flags */ |
578 | | /* IDL: ); */ |
579 | | |
580 | | static unsigned |
581 | | efs_dissect_EfsRpcOpenFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
582 | 0 | { |
583 | 0 | uint32_t status; |
584 | |
|
585 | 0 | di->dcerpc_procedure_name="EfsRpcOpenFileRaw"; |
586 | 0 | offset = efs_dissect_element_EfsRpcOpenFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep); |
587 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
588 | |
|
589 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
590 | |
|
591 | 0 | if (status != 0) |
592 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
593 | |
|
594 | 0 | return offset; |
595 | 0 | } |
596 | | |
597 | | static unsigned |
598 | | efs_dissect_EfsRpcOpenFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
599 | 0 | { |
600 | 0 | di->dcerpc_procedure_name="EfsRpcOpenFileRaw"; |
601 | 0 | offset = efs_dissect_element_EfsRpcOpenFileRaw_FileName(tvb, offset, pinfo, tree, di, drep); |
602 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
603 | 0 | offset = efs_dissect_element_EfsRpcOpenFileRaw_Flags(tvb, offset, pinfo, tree, di, drep); |
604 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
605 | 0 | return offset; |
606 | 0 | } |
607 | | |
608 | | static unsigned |
609 | | efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
610 | 0 | { |
611 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcReadFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcReadFileRaw_pvContext); |
612 | |
|
613 | 0 | return offset; |
614 | 0 | } |
615 | | |
616 | | static unsigned |
617 | | efs_dissect_element_EfsRpcReadFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
618 | 0 | { |
619 | 0 | offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcReadFileRaw_pvContext, 0); |
620 | |
|
621 | 0 | return offset; |
622 | 0 | } |
623 | | |
624 | | /* IDL: WERROR EfsRpcReadFileRaw( */ |
625 | | /* IDL: [in] [ref] policy_handle *pvContext */ |
626 | | /* IDL: ); */ |
627 | | |
628 | | static unsigned |
629 | | efs_dissect_EfsRpcReadFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
630 | 0 | { |
631 | 0 | uint32_t status; |
632 | |
|
633 | 0 | di->dcerpc_procedure_name="EfsRpcReadFileRaw"; |
634 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
635 | |
|
636 | 0 | if (status != 0) |
637 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
638 | |
|
639 | 0 | return offset; |
640 | 0 | } |
641 | | |
642 | | static unsigned |
643 | | efs_dissect_EfsRpcReadFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
644 | 0 | { |
645 | 0 | di->dcerpc_procedure_name="EfsRpcReadFileRaw"; |
646 | 0 | offset = efs_dissect_element_EfsRpcReadFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep); |
647 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
648 | 0 | return offset; |
649 | 0 | } |
650 | | |
651 | | static unsigned |
652 | | efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
653 | 0 | { |
654 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcWriteFileRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcWriteFileRaw_pvContext); |
655 | |
|
656 | 0 | return offset; |
657 | 0 | } |
658 | | |
659 | | static unsigned |
660 | | efs_dissect_element_EfsRpcWriteFileRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
661 | 0 | { |
662 | 0 | offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcWriteFileRaw_pvContext, 0); |
663 | |
|
664 | 0 | return offset; |
665 | 0 | } |
666 | | |
667 | | /* IDL: WERROR EfsRpcWriteFileRaw( */ |
668 | | /* IDL: [in] [ref] policy_handle *pvContext */ |
669 | | /* IDL: ); */ |
670 | | |
671 | | static unsigned |
672 | | efs_dissect_EfsRpcWriteFileRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
673 | 0 | { |
674 | 0 | uint32_t status; |
675 | |
|
676 | 0 | di->dcerpc_procedure_name="EfsRpcWriteFileRaw"; |
677 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
678 | |
|
679 | 0 | if (status != 0) |
680 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
681 | |
|
682 | 0 | return offset; |
683 | 0 | } |
684 | | |
685 | | static unsigned |
686 | | efs_dissect_EfsRpcWriteFileRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
687 | 0 | { |
688 | 0 | di->dcerpc_procedure_name="EfsRpcWriteFileRaw"; |
689 | 0 | offset = efs_dissect_element_EfsRpcWriteFileRaw_pvContext(tvb, offset, pinfo, tree, di, drep); |
690 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
691 | 0 | return offset; |
692 | 0 | } |
693 | | |
694 | | static unsigned |
695 | | efs_dissect_element_EfsRpcCloseRaw_pvContext(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
696 | 0 | { |
697 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcCloseRaw_pvContext_, NDR_POINTER_REF, "Pointer to PvContext (policy_handle)",hf_efs_EfsRpcCloseRaw_pvContext); |
698 | |
|
699 | 0 | return offset; |
700 | 0 | } |
701 | | |
702 | | static unsigned |
703 | | efs_dissect_element_EfsRpcCloseRaw_pvContext_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
704 | 0 | { |
705 | 0 | offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcCloseRaw_pvContext, PIDL_POLHND_CLOSE); |
706 | |
|
707 | 0 | return offset; |
708 | 0 | } |
709 | | |
710 | | /* IDL: void EfsRpcCloseRaw( */ |
711 | | /* IDL: [in] [out] [ref] policy_handle *pvContext */ |
712 | | /* IDL: ); */ |
713 | | |
714 | | static unsigned |
715 | | efs_dissect_EfsRpcCloseRaw_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
716 | 0 | { |
717 | 0 | di->dcerpc_procedure_name="EfsRpcCloseRaw"; |
718 | 0 | offset = efs_dissect_element_EfsRpcCloseRaw_pvContext(tvb, offset, pinfo, tree, di, drep); |
719 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
720 | |
|
721 | 0 | return offset; |
722 | 0 | } |
723 | | |
724 | | static unsigned |
725 | | efs_dissect_EfsRpcCloseRaw_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
726 | 0 | { |
727 | 0 | di->dcerpc_procedure_name="EfsRpcCloseRaw"; |
728 | 0 | offset = efs_dissect_element_EfsRpcCloseRaw_pvContext(tvb, offset, pinfo, tree, di, drep); |
729 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
730 | 0 | return offset; |
731 | 0 | } |
732 | | |
733 | | static unsigned |
734 | | efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
735 | 0 | { |
736 | 0 | char *data; |
737 | |
|
738 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcEncryptFileSrv_Filename, false, &data); |
739 | 0 | proto_item_append_text(tree, ": %s", data); |
740 | |
|
741 | 0 | return offset; |
742 | 0 | } |
743 | | |
744 | | /* IDL: WERROR EfsRpcEncryptFileSrv( */ |
745 | | /* IDL: [charset(UTF16)] [in] uint16 Filename[*] */ |
746 | | /* IDL: ); */ |
747 | | |
748 | | static unsigned |
749 | | efs_dissect_EfsRpcEncryptFileSrv_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
750 | 0 | { |
751 | 0 | uint32_t status; |
752 | |
|
753 | 0 | di->dcerpc_procedure_name="EfsRpcEncryptFileSrv"; |
754 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
755 | |
|
756 | 0 | if (status != 0) |
757 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
758 | |
|
759 | 0 | return offset; |
760 | 0 | } |
761 | | |
762 | | static unsigned |
763 | | efs_dissect_EfsRpcEncryptFileSrv_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
764 | 0 | { |
765 | 0 | di->dcerpc_procedure_name="EfsRpcEncryptFileSrv"; |
766 | 0 | offset = efs_dissect_element_EfsRpcEncryptFileSrv_Filename(tvb, offset, pinfo, tree, di, drep); |
767 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
768 | 0 | return offset; |
769 | 0 | } |
770 | | |
771 | | static unsigned |
772 | | efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
773 | 0 | { |
774 | 0 | char *data; |
775 | |
|
776 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcDecryptFileSrv_FileName, false, &data); |
777 | 0 | proto_item_append_text(tree, ": %s", data); |
778 | |
|
779 | 0 | return offset; |
780 | 0 | } |
781 | | |
782 | | static unsigned |
783 | | efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
784 | 0 | { |
785 | 0 | offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_EfsRpcDecryptFileSrv_Reserved, 0); |
786 | |
|
787 | 0 | return offset; |
788 | 0 | } |
789 | | |
790 | | /* IDL: WERROR EfsRpcDecryptFileSrv( */ |
791 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*], */ |
792 | | /* IDL: [in] uint32 Reserved */ |
793 | | /* IDL: ); */ |
794 | | |
795 | | static unsigned |
796 | | efs_dissect_EfsRpcDecryptFileSrv_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
797 | 0 | { |
798 | 0 | uint32_t status; |
799 | |
|
800 | 0 | di->dcerpc_procedure_name="EfsRpcDecryptFileSrv"; |
801 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
802 | |
|
803 | 0 | if (status != 0) |
804 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
805 | |
|
806 | 0 | return offset; |
807 | 0 | } |
808 | | |
809 | | static unsigned |
810 | | efs_dissect_EfsRpcDecryptFileSrv_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
811 | 0 | { |
812 | 0 | di->dcerpc_procedure_name="EfsRpcDecryptFileSrv"; |
813 | 0 | offset = efs_dissect_element_EfsRpcDecryptFileSrv_FileName(tvb, offset, pinfo, tree, di, drep); |
814 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
815 | 0 | offset = efs_dissect_element_EfsRpcDecryptFileSrv_Reserved(tvb, offset, pinfo, tree, di, drep); |
816 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
817 | 0 | return offset; |
818 | 0 | } |
819 | | |
820 | | static unsigned |
821 | | efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
822 | 0 | { |
823 | 0 | char *data; |
824 | |
|
825 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcQueryUsersOnFile_FileName, false, &data); |
826 | 0 | proto_item_append_text(tree, ": %s", data); |
827 | |
|
828 | 0 | return offset; |
829 | 0 | } |
830 | | |
831 | | static unsigned |
832 | | efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
833 | 0 | { |
834 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_, NDR_POINTER_REF, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryUsersOnFile_pUsers); |
835 | |
|
836 | 0 | return offset; |
837 | 0 | } |
838 | | |
839 | | static unsigned |
840 | | efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
841 | 0 | { |
842 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__, NDR_POINTER_UNIQUE, "Pointer to PUsers (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryUsersOnFile_pUsers); |
843 | |
|
844 | 0 | return offset; |
845 | 0 | } |
846 | | |
847 | | static unsigned |
848 | | efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
849 | 0 | { |
850 | 0 | offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcQueryUsersOnFile_pUsers,0); |
851 | |
|
852 | 0 | return offset; |
853 | 0 | } |
854 | | |
855 | | /* IDL: WERROR EfsRpcQueryUsersOnFile( */ |
856 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*], */ |
857 | | /* IDL: [out] [ref] [unique(1)] ENCRYPTION_CERTIFICATE_HASH_LIST **pUsers */ |
858 | | /* IDL: ); */ |
859 | | |
860 | | static unsigned |
861 | | efs_dissect_EfsRpcQueryUsersOnFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
862 | 0 | { |
863 | 0 | uint32_t status; |
864 | |
|
865 | 0 | di->dcerpc_procedure_name="EfsRpcQueryUsersOnFile"; |
866 | 0 | offset = efs_dissect_element_EfsRpcQueryUsersOnFile_pUsers(tvb, offset, pinfo, tree, di, drep); |
867 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
868 | |
|
869 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
870 | |
|
871 | 0 | if (status != 0) |
872 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
873 | |
|
874 | 0 | return offset; |
875 | 0 | } |
876 | | |
877 | | static unsigned |
878 | | efs_dissect_EfsRpcQueryUsersOnFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
879 | 0 | { |
880 | 0 | di->dcerpc_procedure_name="EfsRpcQueryUsersOnFile"; |
881 | 0 | offset = efs_dissect_element_EfsRpcQueryUsersOnFile_FileName(tvb, offset, pinfo, tree, di, drep); |
882 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
883 | 0 | return offset; |
884 | 0 | } |
885 | | |
886 | | static unsigned |
887 | | efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
888 | 0 | { |
889 | 0 | char *data; |
890 | |
|
891 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcQueryRecoveryAgents_FileName, false, &data); |
892 | 0 | proto_item_append_text(tree, ": %s", data); |
893 | |
|
894 | 0 | return offset; |
895 | 0 | } |
896 | | |
897 | | static unsigned |
898 | | efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
899 | 0 | { |
900 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_, NDR_POINTER_REF, "Pointer to PRecoveryAgents (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents); |
901 | |
|
902 | 0 | return offset; |
903 | 0 | } |
904 | | |
905 | | static unsigned |
906 | | efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
907 | 0 | { |
908 | 0 | offset = dissect_ndr_embedded_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__, NDR_POINTER_UNIQUE, "Pointer to PRecoveryAgents (ENCRYPTION_CERTIFICATE_HASH_LIST)",hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents); |
909 | |
|
910 | 0 | return offset; |
911 | 0 | } |
912 | | |
913 | | static unsigned |
914 | | efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents__(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
915 | 0 | { |
916 | 0 | offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE_HASH_LIST(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents,0); |
917 | |
|
918 | 0 | return offset; |
919 | 0 | } |
920 | | |
921 | | /* IDL: WERROR EfsRpcQueryRecoveryAgents( */ |
922 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*], */ |
923 | | /* IDL: [out] [ref] [unique(1)] ENCRYPTION_CERTIFICATE_HASH_LIST **pRecoveryAgents */ |
924 | | /* IDL: ); */ |
925 | | |
926 | | static unsigned |
927 | | efs_dissect_EfsRpcQueryRecoveryAgents_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
928 | 0 | { |
929 | 0 | uint32_t status; |
930 | |
|
931 | 0 | di->dcerpc_procedure_name="EfsRpcQueryRecoveryAgents"; |
932 | 0 | offset = efs_dissect_element_EfsRpcQueryRecoveryAgents_pRecoveryAgents(tvb, offset, pinfo, tree, di, drep); |
933 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
934 | |
|
935 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
936 | |
|
937 | 0 | if (status != 0) |
938 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
939 | |
|
940 | 0 | return offset; |
941 | 0 | } |
942 | | |
943 | | static unsigned |
944 | | efs_dissect_EfsRpcQueryRecoveryAgents_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
945 | 0 | { |
946 | 0 | di->dcerpc_procedure_name="EfsRpcQueryRecoveryAgents"; |
947 | 0 | offset = efs_dissect_element_EfsRpcQueryRecoveryAgents_FileName(tvb, offset, pinfo, tree, di, drep); |
948 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
949 | 0 | return offset; |
950 | 0 | } |
951 | | |
952 | | static unsigned |
953 | | efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
954 | 0 | { |
955 | 0 | char *data; |
956 | |
|
957 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcRemoveUsersFromFile_FileName, false, &data); |
958 | 0 | proto_item_append_text(tree, ": %s", data); |
959 | |
|
960 | 0 | return offset; |
961 | 0 | } |
962 | | |
963 | | /* IDL: WERROR EfsRpcRemoveUsersFromFile( */ |
964 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*] */ |
965 | | /* IDL: ); */ |
966 | | |
967 | | static unsigned |
968 | | efs_dissect_EfsRpcRemoveUsersFromFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
969 | 0 | { |
970 | 0 | uint32_t status; |
971 | |
|
972 | 0 | di->dcerpc_procedure_name="EfsRpcRemoveUsersFromFile"; |
973 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
974 | |
|
975 | 0 | if (status != 0) |
976 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
977 | |
|
978 | 0 | return offset; |
979 | 0 | } |
980 | | |
981 | | static unsigned |
982 | | efs_dissect_EfsRpcRemoveUsersFromFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
983 | 0 | { |
984 | 0 | di->dcerpc_procedure_name="EfsRpcRemoveUsersFromFile"; |
985 | 0 | offset = efs_dissect_element_EfsRpcRemoveUsersFromFile_FileName(tvb, offset, pinfo, tree, di, drep); |
986 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
987 | 0 | return offset; |
988 | 0 | } |
989 | | |
990 | | static unsigned |
991 | | efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
992 | 0 | { |
993 | 0 | char *data; |
994 | |
|
995 | 0 | offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t), hf_efs_EfsRpcAddUsersToFile_FileName, false, &data); |
996 | 0 | proto_item_append_text(tree, ": %s", data); |
997 | |
|
998 | 0 | return offset; |
999 | 0 | } |
1000 | | |
1001 | | /* IDL: WERROR EfsRpcAddUsersToFile( */ |
1002 | | /* IDL: [charset(UTF16)] [in] uint16 FileName[*] */ |
1003 | | /* IDL: ); */ |
1004 | | |
1005 | | static unsigned |
1006 | | efs_dissect_EfsRpcAddUsersToFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1007 | 0 | { |
1008 | 0 | uint32_t status; |
1009 | |
|
1010 | 0 | di->dcerpc_procedure_name="EfsRpcAddUsersToFile"; |
1011 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
1012 | |
|
1013 | 0 | if (status != 0) |
1014 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
1015 | |
|
1016 | 0 | return offset; |
1017 | 0 | } |
1018 | | |
1019 | | static unsigned |
1020 | | efs_dissect_EfsRpcAddUsersToFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1021 | 0 | { |
1022 | 0 | di->dcerpc_procedure_name="EfsRpcAddUsersToFile"; |
1023 | 0 | offset = efs_dissect_element_EfsRpcAddUsersToFile_FileName(tvb, offset, pinfo, tree, di, drep); |
1024 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
1025 | 0 | return offset; |
1026 | 0 | } |
1027 | | |
1028 | | static unsigned |
1029 | | efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1030 | 0 | { |
1031 | 0 | offset = dissect_ndr_toplevel_pointer(tvb, offset, pinfo, tree, di, drep, efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_, NDR_POINTER_UNIQUE, "Pointer to PEncryptionCertificate (ENCRYPTION_CERTIFICATE)",hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate); |
1032 | |
|
1033 | 0 | return offset; |
1034 | 0 | } |
1035 | | |
1036 | | static unsigned |
1037 | | efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate_(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1038 | 0 | { |
1039 | 0 | offset = efs_dissect_struct_ENCRYPTION_CERTIFICATE(tvb,offset,pinfo,tree,di,drep,hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate,0); |
1040 | |
|
1041 | 0 | return offset; |
1042 | 0 | } |
1043 | | |
1044 | | /* IDL: WERROR EfsRpcSetFileEncryptionKey( */ |
1045 | | /* IDL: [in] [unique(1)] ENCRYPTION_CERTIFICATE *pEncryptionCertificate */ |
1046 | | /* IDL: ); */ |
1047 | | |
1048 | | static unsigned |
1049 | | efs_dissect_EfsRpcSetFileEncryptionKey_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1050 | 0 | { |
1051 | 0 | uint32_t status; |
1052 | |
|
1053 | 0 | di->dcerpc_procedure_name="EfsRpcSetFileEncryptionKey"; |
1054 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
1055 | |
|
1056 | 0 | if (status != 0) |
1057 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
1058 | |
|
1059 | 0 | return offset; |
1060 | 0 | } |
1061 | | |
1062 | | static unsigned |
1063 | | efs_dissect_EfsRpcSetFileEncryptionKey_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1064 | 0 | { |
1065 | 0 | di->dcerpc_procedure_name="EfsRpcSetFileEncryptionKey"; |
1066 | 0 | offset = efs_dissect_element_EfsRpcSetFileEncryptionKey_pEncryptionCertificate(tvb, offset, pinfo, tree, di, drep); |
1067 | 0 | offset = dissect_deferred_pointers(pinfo, tvb, offset, di, drep); |
1068 | 0 | return offset; |
1069 | 0 | } |
1070 | | |
1071 | | /* IDL: WERROR EfsRpcNotSupported( */ |
1072 | | /* IDL: */ |
1073 | | /* IDL: ); */ |
1074 | | |
1075 | | static unsigned |
1076 | | efs_dissect_EfsRpcNotSupported_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1077 | 0 | { |
1078 | 0 | uint32_t status; |
1079 | |
|
1080 | 0 | di->dcerpc_procedure_name="EfsRpcNotSupported"; |
1081 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
1082 | |
|
1083 | 0 | if (status != 0) |
1084 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
1085 | |
|
1086 | 0 | return offset; |
1087 | 0 | } |
1088 | | |
1089 | | static unsigned |
1090 | | efs_dissect_EfsRpcNotSupported_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1091 | 0 | { |
1092 | 0 | di->dcerpc_procedure_name="EfsRpcNotSupported"; |
1093 | 0 | return offset; |
1094 | 0 | } |
1095 | | |
1096 | | /* IDL: WERROR EfsRpcFileKeyInfo( */ |
1097 | | /* IDL: */ |
1098 | | /* IDL: ); */ |
1099 | | |
1100 | | static unsigned |
1101 | | efs_dissect_EfsRpcFileKeyInfo_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1102 | 0 | { |
1103 | 0 | uint32_t status; |
1104 | |
|
1105 | 0 | di->dcerpc_procedure_name="EfsRpcFileKeyInfo"; |
1106 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
1107 | |
|
1108 | 0 | if (status != 0) |
1109 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
1110 | |
|
1111 | 0 | return offset; |
1112 | 0 | } |
1113 | | |
1114 | | static unsigned |
1115 | | efs_dissect_EfsRpcFileKeyInfo_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1116 | 0 | { |
1117 | 0 | di->dcerpc_procedure_name="EfsRpcFileKeyInfo"; |
1118 | 0 | return offset; |
1119 | 0 | } |
1120 | | |
1121 | | /* IDL: WERROR EfsRpcDuplicateEncryptionInfoFile( */ |
1122 | | /* IDL: */ |
1123 | | /* IDL: ); */ |
1124 | | |
1125 | | static unsigned |
1126 | | efs_dissect_EfsRpcDuplicateEncryptionInfoFile_response(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1127 | 0 | { |
1128 | 0 | uint32_t status; |
1129 | |
|
1130 | 0 | di->dcerpc_procedure_name="EfsRpcDuplicateEncryptionInfoFile"; |
1131 | 0 | offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep, hf_efs_werror, &status); |
1132 | |
|
1133 | 0 | if (status != 0) |
1134 | 0 | col_append_fstr(pinfo->cinfo, COL_INFO, ", Error: %s", val_to_str_ext(pinfo->pool, status, &WERR_errors_ext, "Unknown DOS error 0x%08x")); |
1135 | |
|
1136 | 0 | return offset; |
1137 | 0 | } |
1138 | | |
1139 | | static unsigned |
1140 | | efs_dissect_EfsRpcDuplicateEncryptionInfoFile_request(tvbuff_t *tvb _U_, unsigned offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, dcerpc_info* di _U_, uint8_t *drep _U_) |
1141 | 0 | { |
1142 | 0 | di->dcerpc_procedure_name="EfsRpcDuplicateEncryptionInfoFile"; |
1143 | 0 | return offset; |
1144 | 0 | } |
1145 | | |
1146 | | |
1147 | | static const dcerpc_sub_dissector efs_dissectors[] = { |
1148 | | { 0, "EfsRpcOpenFileRaw", |
1149 | | efs_dissect_EfsRpcOpenFileRaw_request, efs_dissect_EfsRpcOpenFileRaw_response}, |
1150 | | { 1, "EfsRpcReadFileRaw", |
1151 | | efs_dissect_EfsRpcReadFileRaw_request, efs_dissect_EfsRpcReadFileRaw_response}, |
1152 | | { 2, "EfsRpcWriteFileRaw", |
1153 | | efs_dissect_EfsRpcWriteFileRaw_request, efs_dissect_EfsRpcWriteFileRaw_response}, |
1154 | | { 3, "EfsRpcCloseRaw", |
1155 | | efs_dissect_EfsRpcCloseRaw_request, efs_dissect_EfsRpcCloseRaw_response}, |
1156 | | { 4, "EfsRpcEncryptFileSrv", |
1157 | | efs_dissect_EfsRpcEncryptFileSrv_request, efs_dissect_EfsRpcEncryptFileSrv_response}, |
1158 | | { 5, "EfsRpcDecryptFileSrv", |
1159 | | efs_dissect_EfsRpcDecryptFileSrv_request, efs_dissect_EfsRpcDecryptFileSrv_response}, |
1160 | | { 6, "EfsRpcQueryUsersOnFile", |
1161 | | efs_dissect_EfsRpcQueryUsersOnFile_request, efs_dissect_EfsRpcQueryUsersOnFile_response}, |
1162 | | { 7, "EfsRpcQueryRecoveryAgents", |
1163 | | efs_dissect_EfsRpcQueryRecoveryAgents_request, efs_dissect_EfsRpcQueryRecoveryAgents_response}, |
1164 | | { 8, "EfsRpcRemoveUsersFromFile", |
1165 | | efs_dissect_EfsRpcRemoveUsersFromFile_request, efs_dissect_EfsRpcRemoveUsersFromFile_response}, |
1166 | | { 9, "EfsRpcAddUsersToFile", |
1167 | | efs_dissect_EfsRpcAddUsersToFile_request, efs_dissect_EfsRpcAddUsersToFile_response}, |
1168 | | { 10, "EfsRpcSetFileEncryptionKey", |
1169 | | efs_dissect_EfsRpcSetFileEncryptionKey_request, efs_dissect_EfsRpcSetFileEncryptionKey_response}, |
1170 | | { 11, "EfsRpcNotSupported", |
1171 | | efs_dissect_EfsRpcNotSupported_request, efs_dissect_EfsRpcNotSupported_response}, |
1172 | | { 12, "EfsRpcFileKeyInfo", |
1173 | | efs_dissect_EfsRpcFileKeyInfo_request, efs_dissect_EfsRpcFileKeyInfo_response}, |
1174 | | { 13, "EfsRpcDuplicateEncryptionInfoFile", |
1175 | | efs_dissect_EfsRpcDuplicateEncryptionInfoFile_request, efs_dissect_EfsRpcDuplicateEncryptionInfoFile_response}, |
1176 | | { 0, NULL, NULL, NULL } |
1177 | | }; |
1178 | | |
1179 | | void proto_register_dcerpc_efs(void) |
1180 | 16 | { |
1181 | 16 | static hf_register_info hf[] = { |
1182 | 16 | { &hf_efs_EFS_CERTIFICATE_BLOB_cbData, |
1183 | 16 | { "CbData", "efs.EFS_CERTIFICATE_BLOB.cbData", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1184 | 16 | { &hf_efs_EFS_CERTIFICATE_BLOB_dwCertEncodingType, |
1185 | 16 | { "DwCertEncodingType", "efs.EFS_CERTIFICATE_BLOB.dwCertEncodingType", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1186 | 16 | { &hf_efs_EFS_CERTIFICATE_BLOB_pbData, |
1187 | 16 | { "PbData", "efs.EFS_CERTIFICATE_BLOB.pbData", FT_UINT8, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1188 | 16 | { &hf_efs_EFS_HASH_BLOB_cbData, |
1189 | 16 | { "CbData", "efs.EFS_HASH_BLOB.cbData", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1190 | 16 | { &hf_efs_EFS_HASH_BLOB_pbData, |
1191 | 16 | { "PbData", "efs.EFS_HASH_BLOB.pbData", FT_UINT8, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1192 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_nCert_Hash, |
1193 | 16 | { "NCert Hash", "efs.ENCRYPTION_CERTIFICATE_HASH_LIST.nCert_Hash", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1194 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_LIST_pUsers, |
1195 | 16 | { "PUsers", "efs.ENCRYPTION_CERTIFICATE_HASH_LIST.pUsers", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1196 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_cbTotalLength, |
1197 | 16 | { "CbTotalLength", "efs.ENCRYPTION_CERTIFICATE_HASH.cbTotalLength", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1198 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_lpDisplayInformation, |
1199 | 16 | { "LpDisplayInformation", "efs.ENCRYPTION_CERTIFICATE_HASH.lpDisplayInformation", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1200 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_pHash, |
1201 | 16 | { "PHash", "efs.ENCRYPTION_CERTIFICATE_HASH.pHash", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1202 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_HASH_pUserSid, |
1203 | 16 | { "PUserSid", "efs.ENCRYPTION_CERTIFICATE_HASH.pUserSid", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1204 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_TotalLength, |
1205 | 16 | { "TotalLength", "efs.ENCRYPTION_CERTIFICATE.TotalLength", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1206 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_pCertBlob, |
1207 | 16 | { "PCertBlob", "efs.ENCRYPTION_CERTIFICATE.pCertBlob", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1208 | 16 | { &hf_efs_ENCRYPTION_CERTIFICATE_pUserSid, |
1209 | 16 | { "PUserSid", "efs.ENCRYPTION_CERTIFICATE.pUserSid", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1210 | 16 | { &hf_efs_EfsRpcAddUsersToFile_FileName, |
1211 | 16 | { "FileName", "efs.EfsRpcAddUsersToFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1212 | 16 | { &hf_efs_EfsRpcCloseRaw_pvContext, |
1213 | 16 | { "PvContext", "efs.EfsRpcCloseRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1214 | 16 | { &hf_efs_EfsRpcDecryptFileSrv_FileName, |
1215 | 16 | { "FileName", "efs.EfsRpcDecryptFileSrv.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1216 | 16 | { &hf_efs_EfsRpcDecryptFileSrv_Reserved, |
1217 | 16 | { "Reserved", "efs.EfsRpcDecryptFileSrv.Reserved", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1218 | 16 | { &hf_efs_EfsRpcEncryptFileSrv_Filename, |
1219 | 16 | { "Filename", "efs.EfsRpcEncryptFileSrv.Filename", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1220 | 16 | { &hf_efs_EfsRpcOpenFileRaw_FileName, |
1221 | 16 | { "FileName", "efs.EfsRpcOpenFileRaw.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1222 | 16 | { &hf_efs_EfsRpcOpenFileRaw_Flags, |
1223 | 16 | { "Flags", "efs.EfsRpcOpenFileRaw.Flags", FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1224 | 16 | { &hf_efs_EfsRpcOpenFileRaw_pvContext, |
1225 | 16 | { "PvContext", "efs.EfsRpcOpenFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1226 | 16 | { &hf_efs_EfsRpcQueryRecoveryAgents_FileName, |
1227 | 16 | { "FileName", "efs.EfsRpcQueryRecoveryAgents.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1228 | 16 | { &hf_efs_EfsRpcQueryRecoveryAgents_pRecoveryAgents, |
1229 | 16 | { "PRecoveryAgents", "efs.EfsRpcQueryRecoveryAgents.pRecoveryAgents", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1230 | 16 | { &hf_efs_EfsRpcQueryUsersOnFile_FileName, |
1231 | 16 | { "FileName", "efs.EfsRpcQueryUsersOnFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1232 | 16 | { &hf_efs_EfsRpcQueryUsersOnFile_pUsers, |
1233 | 16 | { "PUsers", "efs.EfsRpcQueryUsersOnFile.pUsers", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1234 | 16 | { &hf_efs_EfsRpcReadFileRaw_pvContext, |
1235 | 16 | { "PvContext", "efs.EfsRpcReadFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1236 | 16 | { &hf_efs_EfsRpcRemoveUsersFromFile_FileName, |
1237 | 16 | { "FileName", "efs.EfsRpcRemoveUsersFromFile.FileName", FT_STRING, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1238 | 16 | { &hf_efs_EfsRpcSetFileEncryptionKey_pEncryptionCertificate, |
1239 | 16 | { "PEncryptionCertificate", "efs.EfsRpcSetFileEncryptionKey.pEncryptionCertificate", FT_NONE, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1240 | 16 | { &hf_efs_EfsRpcWriteFileRaw_pvContext, |
1241 | 16 | { "PvContext", "efs.EfsRpcWriteFileRaw.pvContext", FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }}, |
1242 | 16 | { &hf_efs_opnum, |
1243 | 16 | { "Operation", "efs.opnum", FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }}, |
1244 | 16 | { &hf_efs_werror, |
1245 | 16 | { "Windows Error", "efs.werror", FT_UINT32, BASE_HEX|BASE_EXT_STRING, &WERR_errors_ext, 0, NULL, HFILL }}, |
1246 | 16 | }; |
1247 | | |
1248 | | |
1249 | 16 | static int *ett[] = { |
1250 | 16 | &ett_dcerpc_efs, |
1251 | 16 | &ett_efs_EFS_HASH_BLOB, |
1252 | 16 | &ett_efs_ENCRYPTION_CERTIFICATE_HASH, |
1253 | 16 | &ett_efs_ENCRYPTION_CERTIFICATE_HASH_LIST, |
1254 | 16 | &ett_efs_EFS_CERTIFICATE_BLOB, |
1255 | 16 | &ett_efs_ENCRYPTION_CERTIFICATE, |
1256 | 16 | }; |
1257 | | |
1258 | 16 | proto_dcerpc_efs = proto_register_protocol("EFS (pidl)", "EFS", "efs"); |
1259 | 16 | proto_register_field_array(proto_dcerpc_efs, hf, array_length (hf)); |
1260 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
1261 | 16 | } |
1262 | | |
1263 | | void proto_reg_handoff_dcerpc_efs(void) |
1264 | 16 | { |
1265 | 16 | dcerpc_init_uuid(proto_dcerpc_efs, ett_dcerpc_efs, |
1266 | 16 | &uuid_dcerpc_efs, ver_dcerpc_efs, |
1267 | 16 | efs_dissectors, hf_efs_opnum); |
1268 | 16 | } |