-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathComputer.ps1
More file actions
113 lines (93 loc) · 3.54 KB
/
Copy pathComputer.ps1
File metadata and controls
113 lines (93 loc) · 3.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
function Invoke-SmbShare {
param(
[int]$ThrottleLimit = 10,
[int]$MinDelayMs = 300,
[int]$MaxDelayMs = 1500,
[int]$TimeoutMs = 800
)
$Searcher = New-Object DirectoryServices.DirectorySearcher
$Searcher.Filter = "(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"
$Searcher.PageSize = 1000
$Searcher.PropertiesToLoad.Add("dnshostname") | Out-Null
$Computers = $Searcher.FindAll() |
ForEach-Object { $_.Properties["dnshostname"] } |
Where-Object { $_ } |
ForEach-Object { $_[0] } |
Sort-Object -Unique
Write-Host "[+] Found $($Computers.Count) domain computers" -ForegroundColor Green
$Pool = [runspacefactory]::CreateRunspacePool(1, $ThrottleLimit)
$Pool.Open()
$Jobs = @()
foreach ($Computer in $Computers) {
$PS = [powershell]::Create()
$PS.RunspacePool = $Pool
[void]$PS.AddScript({
param($Computer, $MinDelayMs, $MaxDelayMs, $TimeoutMs)
Start-Sleep -Milliseconds (Get-Random -Minimum $MinDelayMs -Maximum $MaxDelayMs)
function Test-Port445 {
param($HostName, $TimeoutMs)
try {
$Client = New-Object System.Net.Sockets.TcpClient
$Async = $Client.BeginConnect($HostName, 445, $null, $null)
$Connected = $Async.AsyncWaitHandle.WaitOne($TimeoutMs, $false)
if ($Connected -and $Client.Connected) {
$Client.EndConnect($Async)
$Client.Close()
return $true
}
$Client.Close()
return $false
}
catch {
return $false
}
}
if (-not (Test-Port445 -HostName $Computer -TimeoutMs $TimeoutMs)) {
return
}
try {
$Shares = Get-WmiObject Win32_Share -ComputerName $Computer -ErrorAction Stop
foreach ($Share in $Shares) {
[PSCustomObject]@{
Computer = $Computer
ShareName = $Share.Name
Path = $Share.Path
Description = $Share.Description
Type = $Share.Type
Method = "WMI"
}
}
}
catch {
$Output = cmd /c "net view \\$Computer" 2>$null
foreach ($Line in $Output) {
if ($Line -match "^\s*(\S+)\s+Disk") {
[PSCustomObject]@{
Computer = $Computer
ShareName = $Matches[1]
Path = "\\$Computer\$($Matches[1])"
Description = "Enumerated via net view"
Type = "Disk"
Method = "NetView"
}
}
}
}
}).AddArgument($Computer).AddArgument($MinDelayMs).AddArgument($MaxDelayMs).AddArgument($TimeoutMs)
$Jobs += [PSCustomObject]@{
PS = $PS
Handle = $PS.BeginInvoke()
}
}
foreach ($Job in $Jobs) {
try {
$Job.PS.EndInvoke($Job.Handle)
}
catch {}
finally {
$Job.PS.Dispose()
}
}
$Pool.Close()
$Pool.Dispose()
}