Skip to content
Wireshark Wiki 中文翻译整理专题首页原始页面

SMB2/SMB2_SEC_INFO_00

SMB2/GetInfo 和 SMB2/SetInfo 都会使用它来获取/设置 security descriptor。SMB2/GetInfo 命令采用 4 个标志,用于控制要读取 security descriptor 的哪些部分。SMB2/SetInfo 始终指定完整的 security descriptor。

GetInfo Parameter Block

+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| | | | |+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| | | | |+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| :S:D:G:O| | | |+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| | | | |+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

S

返回 SACL

D

返回 DACL

G

返回 Group

O

返回 Owner

Security Descriptor Structure

+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| Revision | Type |+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+| +-+-+-+-+...

Revision

security descriptor 结构的修订版本。到目前为止,唯一已知的修订版本是 0x0001。本说明将涵盖此结构的 0x0001 修订版本。

Type

这是一个 16 位的位掩码,用于描述此结构。

0x8000 Self Relative0x4000 RM Control valid0x2000 SACL Protected0x1000 DACL Protected0x0800 SACL Auto Inherited0x0400 DACL Auto Inherited0x0200 SACL Auto Inherit Required0x0100 DACL Auto Inherit Required0x0080 Server Security0x0040 DACL trusted0x0020 SACL Defaulted0x0010 SACL Present0x0008 DACL Defaulted0x0004 DACL Present0x0002 Group Defaulted0x0001 Owner Defaulted

Discussion

请有人用其余结构以及 ACL ACE SID 的页面来补全此内容。

导入自 https://wiki.wireshark.org/SMB2/SMB2_SEC_INFO_00 ,时间为 2020-08-11 23:25:40 UTC

相关 Wireshark Wiki 页面

网络分析技术档案