Новичок
Профиль
Группа: Участник
Сообщений: 15
Регистрация: 15.4.2014
Репутация: нет Всего: нет
|
при удаленном запуске win32_process=server.exe с использованием утилиты wmi вылетает ошибка "Первый этап обработки исключения по адресу 0x7559C41F (KernelBase.dll) в WMI_TEST.exe: 0x80070721: Ошибка в пакете безопасности." подключение к удаленному компу происходит, домена нет, pClass указывает на NULL , значит не найден класс win32_process? | Код | #include "stdafx.h" #include <comdef.h> #include <iostream> #pragma comment (lib, "E:/work/zarnitsa/Railway/common-unmanaged/inc/cpp/native/ntos/thread/WbemUuid.lib") #pragma comment (lib, "E:/work/zarnitsa/Railway/common-unmanaged/inc/cpp/native/ntos/thread/credui.lib") #include "WbemIdl.h" #include <strsafe.h> #include <wincred.h>
HRESULT hr; hr=CoInitializeEx(0, COINIT_APARTMENTTHREADED/* COINIT_MULTITHREADED*/); if (FAILED(hr)) { std::cout << "Failed to initialize COM library. Error code = 0x"<<std::hex << hr<<std::endl; return hr; }
hr = CoInitializeSecurity( NULL, // Security descriptor -1, // COM negotiates authentication service NULL, // Authentication services NULL, // Reserved RPC_C_AUTHN_LEVEL_DEFAULT, // Default authentication level for proxies RPC_C_IMP_LEVEL_DELEGATE/*RPC_C_IMP_LEVEL_IMPERSONATE*/, // Default Impersonation level for proxies NULL, // Authentication info EOAC_NONE, // Additional capabilities of the client or server NULL); // Reserved
if (FAILED(hr)) { std::cout << "Failed to initialize security. Error code = 0x" << std::hex << hr << std::endl; CoUninitialize(); system("pause"); return hr; // Program has failed. } IWbemLocator *pLoc = nullptr;
hr = CoCreateInstance( CLSID_WbemLocator, 0, CLSCTX_INPROC_SERVER, IID_IWbemLocator, (LPVOID *) &pLoc);
if (FAILED(hr)) { std::cout << "Failed to create IWbemLocator object. Err code = 0x"<<std::hex << hr<<std::endl ; CoUninitialize(); system("pause"); return hr; // Program has failed. } /////////////////////////////////////////////////////////// IWbemServices *pSvc = NULL;
// Get the user name and password for the remote computer
CREDUI_INFO cui; bool useToken = false; bool useNTLM = true; wchar_t pszName1[CREDUI_MAX_USERNAME_LENGTH+1] = {0}; wchar_t pszPwd2[CREDUI_MAX_PASSWORD_LENGTH+1] = {0}; wchar_t pszDomain2[CREDUI_MAX_USERNAME_LENGTH+1]; wchar_t pszUserName[CREDUI_MAX_USERNAME_LENGTH+1]; wchar_t pszAuthority[CREDUI_MAX_USERNAME_LENGTH+1]; BOOL fSave; DWORD dwErr; memset(&cui,0,sizeof(CREDUI_INFO)); cui.cbSize = sizeof(CREDUI_INFO); cui.hwndParent = NULL; cui.pszMessageText = TEXT("Press cancel to use process token"); cui.pszCaptionText = TEXT("Enter Account Information"); cui.hbmBanner = NULL; fSave = FALSE; SecureZeroMemory(pszName1, sizeof(pszName1)); SecureZeroMemory(pszPwd2, sizeof(pszPwd2));
dwErr = CredUIPromptForCredentials( &cui, // CREDUI_INFO structure TEXT(""), // Target for credentials NULL, // Reserved 0, // Reason pszName1, // User name CREDUI_MAX_USERNAME_LENGTH+1, // Max number for user name pszPwd2, // Password CREDUI_MAX_PASSWORD_LENGTH+1, // Max number for password &fSave, // State of save check box CREDUI_FLAGS_GENERIC_CREDENTIALS |// flags CREDUI_FLAGS_ALWAYS_SHOW_UI | CREDUI_FLAGS_DO_NOT_PERSIST);
if(dwErr == ERROR_CANCELLED) { useToken = true; } else if (dwErr) { std::cout << "Did not get credentials " << dwErr <<std::endl; system("pause"); pLoc->Release(); CoUninitialize(); return 1; }
// change the computerName strings below to the full computer name // of the remote computer if(!useNTLM) { StringCchPrintf(pszAuthority, CREDUI_MAX_USERNAME_LENGTH+1, L"kERBEROS:%s", L"TEST4PC"); }
hr = pLoc->ConnectServer( _bstr_t(L"\\\\TEST4PC\\root\\cimv2"), bstr_t(useToken ? NULL : pszName1), // User name _bstr_t(useToken ? NULL : pszPwd2), // User password NULL, // Locale NULL, // Security flags _bstr_t(useNTLM ? NULL : pszAuthority),// Authority NULL, // Context object &pSvc // IWbemServices proxy
); if (FAILED(hr)) { std::cout << "Could not connect. Error code = 0x" << std::hex << hr << std::endl; system("pause"); pLoc->Release(); CoUninitialize(); return 1; // Program has failed. }
std::cout << "Connected to ROOT\\CIMV2 WMI namespace" << std::endl; COAUTHIDENTITY *userAcct = NULL ; hr = CoSetProxyBlanket( pSvc, // Indicates the proxy to set RPC_C_AUTHN_DEFAULT, // RPC_C_AUTHN_xxx RPC_C_AUTHZ_DEFAULT, // RPC_C_AUTHZ_xxx COLE_DEFAULT_PRINCIPAL, // Server principal name RPC_C_AUTHN_LEVEL_PKT_PRIVACY, // RPC_C_AUTHN_LEVEL_xxx RPC_C_IMP_LEVEL_DELEGATE/*RPC_C_IMP_LEVEL_IMPERSONATE*/, // RPC_C_IMP_LEVEL_xxx userAcct, // client identity EOAC_NONE // proxy capabilities );
if (FAILED(hr)) { std::cout << "Could not set proxy blanket. Error code = 0x" << std::hex << hr << std::endl; system("pause"); pSvc->Release(); pLoc->Release(); CoUninitialize(); return 1; // Program has failed. }
IWbemClassObject* pClass ; bstr_t path_my = SysAllocString(L"\\\\TEST4PC\ROOT\CIMV2:Win32_Process"); BSTR MethodName = SysAllocString(L"Create"); hr = pSvc->GetObjectW( //здесь ошибка path_my, // [IN] Path of the object to retrieve. 0, // [IN] The following flags affect the behavior of this method. NULL, // [IN] Otherwise, this is a pointer to an IWbemContext object that may be used by the provider that is producing the requested class or instance.Otherwise, this is a pointer to an IWbemContext object that may be used by the provider that is producing the requested class or instance. &pClass, // [OUT] The returned object has a positive reference count. NULL // [OUT] The ppCallResult parameter receives a pointer to a new IWbemCallResult object, which can then be polled to obtain the result using the GetCallStatus method. ); if (pClass == NULL) { //не нашли класс L"Win32_Process" //system("pause"); return hr; } IWbemClassObject* pInParamsDefinition = NULL; hr = pClass->GetMethod(MethodName, 0, &pInParamsDefinition, NULL); IWbemClassObject* pClassInstance = NULL; hr = pInParamsDefinition->SpawnInstance(0, &pClassInstance); // значения входных параметров VARIANT varCommand; varCommand.vt = VT_BSTR; varCommand.bstrVal = L"server.exe"; // Store the value for the in parameters hr = pClassInstance->Put(L"CommandLine", 0, &varCommand, 0); IWbemClassObject* pOutParams = NULL; IWbemCallResult* pRes = 0; hr = pSvc->ExecMethod(path_my, MethodName, 0, NULL, pClassInstance, &pOutParams, &pRes); if (FAILED(hr)) { std::cout << "Could not execute method. Error code = 0x"<< std::hex << hr << std::endl; system("pause"); VariantClear(&varCommand); SysFreeString(path_my); SysFreeString(MethodName); pClass->Release(); pInParamsDefinition->Release(); pOutParams->Release(); pSvc->Release(); pLoc->Release(); CoUninitialize(); return 1; // Program has failed. }
|
|