Showing posts with label DOS. Show all posts
Showing posts with label DOS. Show all posts

Opening a command prompt in a SmartCard security context

In a computing environment with very high security access to many resources requires a physical credential. I’ve only seen this in 2 places: back while working for a bank and at Microsoft. I imagine a similar story in defense related work but I’ve never done defense related contracting so can’t speak from experience.

Anywho, physical credentials are great. Except when you lose them. Or leave them in the computer. Especially if the credential serves double duty; it’s your way to enter the building and to access secured resources.

Windows has a wonderful feature that lets you start a command prompt with the credential. As long as that command prompt remains open it has access to secured resources. So you can take your physical credential out, leave the window open and do what you need to in that command prompt window.

Enter the “runas” command. Introduced in Windows 7 or Vista IIRC, it lets you run a command under different security contexts. One of those contexts is SmartCard. So I created a shortcut on the desktop with the following command:

C:\Windows\System32\runas.exe /smartcard "C:\Windows\System32\cmd.exe /k cd C:\Users\XXX\YYY && C:\Users\XXX\YYY\YYY.cmd"



This opens a command prompt, asks for your credential password then runs the command prompt under the smartcard security context. In this case there’s a bat (.cmd) file that sets up the target command prompt with a bunch of stuff not relevant to this discussion. The /k option to cmd.exe keeps the window open.

Command Prompts with Date and Time

I spend a lot of time in command prompts and have found it useful to have the date and time associated with a given command. It’s great for comparing “how long does this take” especially after the fact. To add this to your command prompt on Windows 7 (and probably XP and earlier versions), change the PROMPT environment variable ala:

PROMPT=$d $t$_$p$g

I usually set this as a user environment variable. These can be set by typing Start then entering “sys env” (no quotes). The first option should be “Edit the system environment variables”. Add a new user environment variable named PROMPT with the value specified above.

PROMPT syntax is described at the online docs for the prompt command.

While the date and time displayed don’t account for the amount of time it takes to type in the command (with very long commands this can be a few minutes) it’s usually a good indicator.

Environment Variables in FOR loops

Let’s say you want to run a program multiple times. The output of each execution should be stored in a separate file to allow for easy comparison. The output filename has useful information so it would be nice to simply append a counter to indicate which run a given output file is associated with. In other words run 1 produces output-1, run 2 produces output-2, …, run N produces output-N.

If you’ve ever tried this using .bat files on windows you might have come up with something along the lines of the following:

@echo off
set f=%1

for /l %%i in (1,1,5) do (
set nf=%f%-%%i

if not exist %nf% (
echo %nf% does not exist
) else (
echo %nf% does exist
)
)


Which surprisingly produces output along the lines of output-5, output-5, output-5, ….



By default the command interpreter CMD only evaluates environment variables (nf in this case) once. To evaluate environment variables more than once it is necessary to enable “delayed environment variable expansion".



This can be enabled when the CMD is started with /v:on. (e.g., cmd /v:on). Alternatively, it can be enabled via setlocal enabledelayedexpansion in an already running CMD prompt.



However, %nf% must replaced with !nf! to get the value of the variable based on the current iteration of the enclosing FOR loop.



So the corrected code is:



@echo off
set f=%1

setlocal enabledelayedexpansion

for /l %%i in (1,1,5) do (
REM set nf=!f!-%%i
set nf=%f%-%%i

if not exist !nf! (
echo !nf! does not exist
) else (
echo !nf! does exist
)
)

endlocal

Using Window’s FOR command to replace unix find -exec

Finding all directories within a directory recursively:

dir /a:d /s /b <dirname pattern>

e.g.,

dir /a:d /s /b tmpdir*

the /a:d flag restricts the results to directories, /s does a recursive search and /b prints the results in bare format.

Why bare format?  Because that makes it suitable as input to the FOR /F command.  Putting them together, you can delete all these directories with:

FOR /F “delims=” %i IN (‘dir /a:d /s /b tmpdir*’) DO rd /s /q “%i”

FOR’s /F allows, among other things, using the output of a command (in between the single quoted parentheses) as input to a command that’s repeated (the part after the DO).  In this case we’re executing RD (remove directory) on each directory that starts with the name tmpdir.

Booting DOS from a USB flash drive

I wanted to boot into DOS from a USB flash drive (lexar jumpdrive) to run a memory tester (I believe it needs to run in real mode, windows runs in protected mode, but not sure on that). There are several pages out there describing a procedure that, unfortunately for me, requires the presence of a floppy drive. I don't have a floppy drive :( I also don't happen to have a copy of Windows 98 or MSDOS lying around. And I really didn't want to have to install FreeDOS (or any version of DOS).



So, from my Windows XP machine, these are the steps I took to create a bootable USB flash drive.


  1. Download Virtual Floppy Drive. There is no installer. Extract it to a directory then double-click on "vfdwin.exe" to open the user interface (called VFD Control Panel).
  2. Create a virtual a: drive by doing the following:

    1. From the Driver tab leave the Start Type at "Manual".
    2. click Install (if it's not grayed out). This installs the vfd driver.
    3. click Start. This starts the driver.
    4. Switch to the Drive0 tab.
    5. Click "Change" to choose a drive letter then select A from the drop-down (if it's available). This is the drive letter windows will think is a floppy drive. Make sure Persistent/Global is checked.
    6. Click "Open" then browse to a directory.
    7. Type floppy.img then click OK. This is where the floppy image will be stored when you create it.
    8. Choose Media Type (I leave it at 3.5" 1.44MB but you may want to emulate a different sized floppy).
    9. Click "Create".

  3. Create a startup disk on the virtual floppy drive.

    1. Windows now thinks you have a floppy drive at a: (or whatever you selected).
    2. Using Windows Explorer (or my computer), right click the a: drive and choose Format.
    3. Make sure "Create an MS-DOS Startup Disk" is checked.
    4. Click Start.

  4. Copy whatever DOS utilities/.exe files you want onto the virtual floppy drive.

    1. You can do this with Windows Explorer (drag them onto the a: drive) or command prompt.
    2. Remember - you will only have 1.44MB to work with, so choose carefully.

  5. Save the virtual floppy drive image.

    1. Close any windows explorer or my computer windows that currently have the a: drive open. Same goes for command prompts.
    2. In the VFD Control Panel switch to tab Drive0 if it's not still there.
    3. Click "Save".
    4. Check "Overwrite an existing file" then click "Save".

  6. Download the HP Drive Key Boot Utility. It works for many brands of flash drive, not just HP drives.
  7. Plug in the USB flash drive.
  8. Install the HP Drive Key Boot Utility.
  9. Start the HP Drive Key Boot Utility.
  10. Choose the letter currently assigned to your USB flash drive. Click Next.
  11. Leave "Create New or Replace Existing Configuration" selected. Click Next.
  12. Choose "Floppy Disk". Click Next.
  13. Choose "Image from file" then browse to the file you saved in step 1.7 (e.g., floppy.img). Click Next.

You should now have a USB flash drive that you can boot from.

Plug the key into whatever machine you want to test. Boot the machine, go into its BIOS settings screen (usually by pressing DEL or F2 or F10 during boot), disable all boot devices except for the USB key. You may have to try USB-FDD, USB-ZIP or USB-HDD to get it to work. Save the changes then reboot. You should be greeted with an A: prompt!