2020-01-06 15:11:57 +01:00
|
|
|
|
/*
|
2023-03-08 00:30:20 +01:00
|
|
|
|
* Copyright (c) 2023 ETH Zürich, Educational Development and Technology (LET)
|
2020-01-06 15:11:57 +01:00
|
|
|
|
*
|
|
|
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
|
|
|
*/
|
|
|
|
|
|
2020-09-29 14:37:54 +02:00
|
|
|
|
using System.Linq;
|
2023-04-01 16:25:56 +02:00
|
|
|
|
using System.Management;
|
2020-01-06 15:11:57 +01:00
|
|
|
|
using SafeExamBrowser.Logging.Contracts;
|
|
|
|
|
using SafeExamBrowser.SystemComponents.Contracts;
|
2023-07-17 16:40:33 +02:00
|
|
|
|
using SafeExamBrowser.SystemComponents.Contracts.Registry;
|
2023-04-01 16:25:56 +02:00
|
|
|
|
using Microsoft.Win32;
|
2023-07-17 16:40:33 +02:00
|
|
|
|
using System.Collections;
|
|
|
|
|
using System.Collections.Generic;
|
|
|
|
|
using System;
|
2020-01-06 15:11:57 +01:00
|
|
|
|
|
|
|
|
|
namespace SafeExamBrowser.SystemComponents
|
|
|
|
|
{
|
|
|
|
|
public class VirtualMachineDetector : IVirtualMachineDetector
|
|
|
|
|
{
|
2023-05-02 14:56:15 +02:00
|
|
|
|
private const string QEMU_MAC_PREFIX = "525400";
|
|
|
|
|
private const string VIRTUALBOX_MAC_PREFIX = "080027";
|
|
|
|
|
|
|
|
|
|
private static readonly string[] DeviceBlacklist =
|
2023-02-23 16:40:26 +01:00
|
|
|
|
{
|
2023-03-07 23:41:56 +01:00
|
|
|
|
// Hyper-V
|
|
|
|
|
"PROD_VIRTUAL", "HYPER_V",
|
|
|
|
|
// QEMU
|
|
|
|
|
"qemu", "ven_1af4", "ven_1b36", "subsys_11001af4",
|
|
|
|
|
// VirtualBox
|
|
|
|
|
"vbox", "vid_80ee",
|
|
|
|
|
// VMware
|
|
|
|
|
"PROD_VMWARE", "VEN_VMWARE", "VMWARE_IDE"
|
2023-02-23 16:40:26 +01:00
|
|
|
|
};
|
2023-05-02 14:56:15 +02:00
|
|
|
|
|
|
|
|
|
private static readonly string[] DeviceWhitelist =
|
|
|
|
|
{
|
2023-05-30 15:28:21 +02:00
|
|
|
|
// Microsoft Virtual Disk Device
|
|
|
|
|
"PROD_VIRTUAL_DISK",
|
|
|
|
|
// Microsoft Virtual DVD Device
|
|
|
|
|
"PROD_VIRTUAL_DVD"
|
2023-05-02 14:56:15 +02:00
|
|
|
|
};
|
2022-07-29 13:49:26 +02:00
|
|
|
|
|
|
|
|
|
private readonly ILogger logger;
|
2023-07-17 16:40:33 +02:00
|
|
|
|
private readonly IRegistry registry;
|
2022-07-29 13:49:26 +02:00
|
|
|
|
private readonly ISystemInfo systemInfo;
|
2020-05-06 18:44:08 +02:00
|
|
|
|
|
2023-07-17 16:40:33 +02:00
|
|
|
|
public VirtualMachineDetector(ILogger logger, IRegistry registry, ISystemInfo systemInfo)
|
2020-01-06 15:11:57 +01:00
|
|
|
|
{
|
|
|
|
|
this.logger = logger;
|
2023-07-17 16:40:33 +02:00
|
|
|
|
this.registry = registry;
|
2020-01-06 15:11:57 +01:00
|
|
|
|
this.systemInfo = systemInfo;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
public bool IsVirtualMachine()
|
|
|
|
|
{
|
|
|
|
|
var isVirtualMachine = false;
|
2023-07-18 15:20:10 +02:00
|
|
|
|
|
|
|
|
|
var biosInfo = systemInfo.BiosInfo;
|
2022-07-29 13:49:26 +02:00
|
|
|
|
var macAddress = systemInfo.MacAddress;
|
2023-04-14 19:56:22 +02:00
|
|
|
|
var manufacturer = systemInfo.Manufacturer;
|
|
|
|
|
var model = systemInfo.Model;
|
2023-03-07 23:41:56 +01:00
|
|
|
|
var devices = systemInfo.PlugAndPlayDeviceIds;
|
2020-05-07 13:21:57 +02:00
|
|
|
|
|
2023-04-14 19:56:22 +02:00
|
|
|
|
// redundancy: registry check does this aswell (systemInfo may be using different methods)
|
|
|
|
|
isVirtualMachine |= IsVirtualSystemInfo(biosInfo, manufacturer, model);
|
2023-07-22 14:19:42 +02:00
|
|
|
|
isVirtualMachine |= IsVirtualCpu();
|
2023-04-14 19:56:22 +02:00
|
|
|
|
isVirtualMachine |= IsVirtualRegistry();
|
|
|
|
|
|
|
|
|
|
if (macAddress != null && macAddress.Count() > 2)
|
|
|
|
|
{
|
|
|
|
|
isVirtualMachine |= macAddress.StartsWith(QEMU_MAC_PREFIX);
|
|
|
|
|
isVirtualMachine |= macAddress.StartsWith(VIRTUALBOX_MAC_PREFIX);
|
|
|
|
|
isVirtualMachine |= macAddress.StartsWith("000000000000"); // indicates tampering
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
foreach (var device in devices)
|
|
|
|
|
{
|
2023-07-18 16:33:55 +02:00
|
|
|
|
isVirtualMachine |= DeviceBlacklist.Any(d => device.ToLower().Contains(d.ToLower())) && DeviceWhitelist.All(d => !device.ToLower().Contains(d.ToLower()));
|
2023-04-14 19:56:22 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
logger.Debug($"Computer '{systemInfo.Name}' appears {(isVirtualMachine ? "" : "not ")}to be a virtual machine.");
|
|
|
|
|
|
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
|
2023-04-01 16:25:56 +02:00
|
|
|
|
private bool IsVirtualSystemInfo(string biosInfo, string manufacturer, string model)
|
2020-01-06 15:11:57 +01:00
|
|
|
|
{
|
2023-04-14 20:13:29 +02:00
|
|
|
|
var isVirtualMachine = false;
|
2023-04-01 16:25:56 +02:00
|
|
|
|
|
|
|
|
|
biosInfo = biosInfo.ToLower();
|
|
|
|
|
manufacturer = manufacturer.ToLower();
|
|
|
|
|
model = model.ToLower();
|
2020-05-07 13:21:57 +02:00
|
|
|
|
|
2023-03-07 23:41:56 +01:00
|
|
|
|
isVirtualMachine |= biosInfo.Contains("hyper-v");
|
2022-07-29 13:49:26 +02:00
|
|
|
|
isVirtualMachine |= biosInfo.Contains("virtualbox");
|
2023-03-07 23:41:56 +01:00
|
|
|
|
isVirtualMachine |= biosInfo.Contains("vmware");
|
2023-04-01 16:25:56 +02:00
|
|
|
|
isVirtualMachine |= biosInfo.Contains("ovmf");
|
|
|
|
|
isVirtualMachine |= biosInfo.Contains("edk ii unknown"); // qemu
|
2020-01-06 15:11:57 +01:00
|
|
|
|
isVirtualMachine |= manufacturer.Contains("microsoft corporation") && !model.Contains("surface");
|
|
|
|
|
isVirtualMachine |= manufacturer.Contains("parallels software");
|
2020-04-28 13:28:59 +02:00
|
|
|
|
isVirtualMachine |= manufacturer.Contains("qemu");
|
2023-03-07 23:41:56 +01:00
|
|
|
|
isVirtualMachine |= manufacturer.Contains("vmware");
|
|
|
|
|
isVirtualMachine |= model.Contains("virtualbox");
|
2023-04-01 20:14:24 +02:00
|
|
|
|
isVirtualMachine |= model.Contains("Q35 +"); // qemu
|
2020-05-07 13:21:57 +02:00
|
|
|
|
|
2023-04-01 16:25:56 +02:00
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private bool IsVirtualRegistry()
|
|
|
|
|
{
|
2023-04-14 20:13:29 +02:00
|
|
|
|
var isVirtualMachine = false;
|
2023-04-01 16:25:56 +02:00
|
|
|
|
|
2023-07-17 17:33:21 +02:00
|
|
|
|
// the resulting IsVirtualRegistry() would be massive so split it
|
2023-07-18 15:11:44 +02:00
|
|
|
|
isVirtualMachine |= HasHistoricVirtualMachineHardwareConfiguration();
|
|
|
|
|
isVirtualMachine |= HasLocalVirtualMachineDeviceCache();
|
2023-07-17 17:33:21 +02:00
|
|
|
|
|
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
|
2023-07-18 15:11:44 +02:00
|
|
|
|
private bool HasHistoricVirtualMachineHardwareConfiguration()
|
2023-07-17 17:33:21 +02:00
|
|
|
|
{
|
2023-07-18 14:32:54 +02:00
|
|
|
|
var isVirtualMachine = false;
|
2023-07-17 17:33:21 +02:00
|
|
|
|
|
2023-07-17 16:40:33 +02:00
|
|
|
|
/**
|
2023-07-17 17:33:21 +02:00
|
|
|
|
* scanned registry format:
|
2023-07-17 16:40:33 +02:00
|
|
|
|
*
|
2023-07-18 15:20:10 +02:00
|
|
|
|
* HKLM\SYSTEM\HardwareConfig\{configId=uuid}
|
|
|
|
|
* - BIOSVendor
|
|
|
|
|
* - SystemManufacturer
|
|
|
|
|
* - ...
|
|
|
|
|
* \ComputerIds
|
|
|
|
|
* - {computerId=uuid}: {computerSummary=hardwareInfo}
|
|
|
|
|
*
|
2023-07-17 16:40:33 +02:00
|
|
|
|
*/
|
2023-07-18 15:20:10 +02:00
|
|
|
|
const string hardwareRootKey = "HKEY_LOCAL_MACHINE\\SYSTEM\\HardwareConfig";
|
|
|
|
|
if (!registry.TryGetSubKeys(hardwareRootKey, out var hardwareConfigSubkeys))
|
2020-05-07 13:21:57 +02:00
|
|
|
|
{
|
2023-07-17 16:40:33 +02:00
|
|
|
|
return false;
|
2020-05-07 13:21:57 +02:00
|
|
|
|
}
|
|
|
|
|
|
2023-07-18 15:11:44 +02:00
|
|
|
|
foreach (var configId in hardwareConfigSubkeys)
|
2020-05-06 21:45:04 +02:00
|
|
|
|
{
|
2023-07-18 15:20:10 +02:00
|
|
|
|
var hardwareConfigKey = $"{hardwareRootKey}\\{configId}";
|
2023-07-18 15:11:44 +02:00
|
|
|
|
var didReadKeys = true;
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-17 17:06:46 +02:00
|
|
|
|
// collect system values for IsVirtualSystemInfo()
|
2023-07-18 15:20:10 +02:00
|
|
|
|
didReadKeys &= registry.TryRead(hardwareConfigKey, "BIOSVendor", out var biosVendor);
|
|
|
|
|
didReadKeys &= registry.TryRead(hardwareConfigKey, "BIOSVersion", out var biosVersion);
|
|
|
|
|
didReadKeys &= registry.TryRead(hardwareConfigKey, "SystemManufacturer", out var systemManufacturer);
|
|
|
|
|
didReadKeys &= registry.TryRead(hardwareConfigKey, "SystemProductName", out var systemProductName);
|
2023-07-18 14:32:54 +02:00
|
|
|
|
if (!didReadKeys)
|
2023-07-18 15:02:02 +02:00
|
|
|
|
{
|
2023-07-17 16:40:33 +02:00
|
|
|
|
continue;
|
2023-07-18 15:02:02 +02:00
|
|
|
|
}
|
2023-07-17 16:40:33 +02:00
|
|
|
|
|
|
|
|
|
// reconstruct the systemInfo.biosInfo string
|
2023-07-18 14:32:54 +02:00
|
|
|
|
var biosInfo = $"{(string) biosVendor} {(string) biosVersion}";
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-17 16:40:33 +02:00
|
|
|
|
isVirtualMachine |= IsVirtualSystemInfo(biosInfo, (string) systemManufacturer, (string) systemProductName);
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-17 17:06:46 +02:00
|
|
|
|
// check even more hardware information
|
2023-07-18 15:20:10 +02:00
|
|
|
|
var computerIdsKey = $"{hardwareConfigKey}\\ComputerIds";
|
2023-07-18 14:21:49 +02:00
|
|
|
|
if (!registry.TryGetNames(computerIdsKey, out var computerIdNames))
|
2023-07-18 15:02:02 +02:00
|
|
|
|
{
|
2023-07-17 17:06:46 +02:00
|
|
|
|
continue;
|
2023-07-18 15:02:02 +02:00
|
|
|
|
}
|
2023-04-01 16:25:56 +02:00
|
|
|
|
|
2023-07-17 17:06:46 +02:00
|
|
|
|
foreach (var computerIdName in computerIdNames)
|
2023-07-17 16:40:33 +02:00
|
|
|
|
{
|
2023-07-17 17:06:46 +02:00
|
|
|
|
// collect computer hardware summary (e.g. manufacturer&version&sku&...)
|
2023-07-18 14:21:49 +02:00
|
|
|
|
if (!registry.TryRead(computerIdsKey, computerIdName, out var computerSummary))
|
2023-07-18 15:02:02 +02:00
|
|
|
|
{
|
2023-04-01 20:14:24 +02:00
|
|
|
|
continue;
|
2023-07-18 15:02:02 +02:00
|
|
|
|
}
|
2023-07-17 16:40:33 +02:00
|
|
|
|
|
|
|
|
|
isVirtualMachine |= IsVirtualSystemInfo((string) computerSummary, (string) systemManufacturer, (string) systemProductName);
|
2023-04-01 19:09:01 +02:00
|
|
|
|
}
|
2020-05-06 21:45:04 +02:00
|
|
|
|
}
|
2020-05-07 13:21:57 +02:00
|
|
|
|
|
2023-07-17 17:33:21 +02:00
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
|
2023-07-18 15:11:44 +02:00
|
|
|
|
private bool HasLocalVirtualMachineDeviceCache()
|
2023-07-17 17:33:21 +02:00
|
|
|
|
{
|
2023-07-18 14:32:54 +02:00
|
|
|
|
var isVirtualMachine = false;
|
2023-07-17 16:40:33 +02:00
|
|
|
|
|
2023-07-17 17:33:21 +02:00
|
|
|
|
// device cache contains hardware about other devices logged into as well, so lock onto this device in case an innocent VM was logged into.
|
|
|
|
|
// in the future, try to improve this check somehow since DeviceCache only gives ComputerName
|
|
|
|
|
var deviceName = System.Environment.GetEnvironmentVariable("COMPUTERNAME");
|
2023-07-17 16:40:33 +02:00
|
|
|
|
|
2023-07-17 17:33:21 +02:00
|
|
|
|
// check Windows timeline caches for current hardware config
|
2023-07-18 14:32:54 +02:00
|
|
|
|
const string deviceCacheParentKey = "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\TaskFlow\\DeviceCache";
|
|
|
|
|
var hasDeviceCacheKeys = registry.TryGetSubKeys(deviceCacheParentKey, out var deviceCacheKeys);
|
2023-04-14 21:18:08 +02:00
|
|
|
|
|
2023-07-18 14:32:54 +02:00
|
|
|
|
if (deviceName != null && hasDeviceCacheKeys)
|
2023-04-01 19:09:01 +02:00
|
|
|
|
{
|
2023-07-18 14:32:54 +02:00
|
|
|
|
foreach (var cacheId in deviceCacheKeys)
|
2023-04-01 19:09:01 +02:00
|
|
|
|
{
|
2023-07-17 17:33:21 +02:00
|
|
|
|
var cacheIdKey = $"{deviceCacheParentKey}\\{cacheId}";
|
2023-07-18 14:32:54 +02:00
|
|
|
|
var didReadKeys = true;
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-18 14:32:54 +02:00
|
|
|
|
didReadKeys &= registry.TryRead(cacheIdKey, "DeviceName", out var cacheDeviceName);
|
|
|
|
|
if (!didReadKeys || deviceName.ToLower() != ((string) cacheDeviceName).ToLower())
|
2023-07-18 15:02:02 +02:00
|
|
|
|
{
|
2023-07-17 17:33:21 +02:00
|
|
|
|
continue;
|
2023-07-18 15:02:02 +02:00
|
|
|
|
}
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-18 14:32:54 +02:00
|
|
|
|
didReadKeys &= registry.TryRead(cacheIdKey, "DeviceMake", out var cacheDeviceManufacturer);
|
|
|
|
|
didReadKeys &= registry.TryRead(cacheIdKey, "DeviceModel", out var cacheDeviceModel);
|
|
|
|
|
if (!didReadKeys)
|
2023-07-18 15:02:02 +02:00
|
|
|
|
{
|
2023-07-17 17:33:21 +02:00
|
|
|
|
continue;
|
2023-07-18 15:02:02 +02:00
|
|
|
|
}
|
2023-04-01 19:09:01 +02:00
|
|
|
|
|
2023-07-17 17:33:21 +02:00
|
|
|
|
isVirtualMachine |= IsVirtualSystemInfo("", (string) cacheDeviceManufacturer, (string) cacheDeviceModel);
|
2023-04-01 19:09:01 +02:00
|
|
|
|
}
|
2023-04-01 16:25:56 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
|
2023-07-22 14:19:42 +02:00
|
|
|
|
private bool IsVirtualCpu()
|
2023-04-01 16:25:56 +02:00
|
|
|
|
{
|
2023-04-14 20:13:29 +02:00
|
|
|
|
var isVirtualMachine = false;
|
2023-04-01 16:25:56 +02:00
|
|
|
|
|
2023-07-22 14:19:42 +02:00
|
|
|
|
isVirtualMachine |= systemInfo.Cpu.ToLower().Contains(" kvm "); // qemu (KVM specifically)
|
2020-01-06 15:11:57 +01:00
|
|
|
|
|
|
|
|
|
return isVirtualMachine;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|