Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I have a setup whereby a batch file runs on a task to extract and store the output of a Windows command (quser), which PHP then picks up via reading a text file (where the batch file outputs the return to), but this approach is rather awkward as there are additional processes in place (such as the batch file scripts) that surely could be bypassed in favour of a more native PHP approach.

 

Whilst I can do exec, system, passthru etc in PHP to get the output of various commands (such as ping, ipconfig etc), when I try to execute the quser /server: command, it either doesn't give me an output or returns "array", which I then can't seem to get anything from when cycling through it in a loop.

 

Is there any reason this doesn't just output in the same way as more conventional commands do? Is it just our server which doesn't output as expected for quser or do others not see the same output when done in PHP?

 

As the script's objective is to get a list of users logged in to our remote desktop (citrix) server, it would perform better if I could do it all within php, whereas right now I am having to run php files to sync into a mysql database, after running a batch file to get the info in the first place!

Posted

How about,

   ob_start();
   passthru("quser");
   $user = ob_get_contents();
   ob_end_clean();
   echo "";
   print_r($user);
   echo "";

 

That will give you an output to play with, you'll just need to do the formatting.

 

Or you could do it in PowerShell,

$computername = "whs-web"

$regexa = '.+Domain="(.+)",Name="(.+)"$'
$regexd = '.+LogonId="(\d+)"$'

$logontype = @{
"0"="Local System"
"2"="Interactive" #(Local logon)
"3"="Network" # (Remote logon)
"4"="Batch" # (Scheduled task)
"5"="Service" # (Service account logon)
"7"="Unlock" #(Screen saver)
"8"="NetworkCleartext" # (Cleartext network logon)
"9"="NewCredentials" #(RunAs using alternate credentials)
"10"="RemoteInteractive" #(RDP\TS\RemoteAssistance)
"11"="CachedInteractive" #(Local w\cached credentials)
}

$logon_sessions = @(gwmi win32_logonsession -ComputerName $computername)
$logon_users = @(gwmi win32_loggedonuser -ComputerName $computername)

$session_user = @{}

$logon_users |% {
$_.antecedent -match $regexa > $nul
$username = $matches[1] + "\" + $matches[2]
$_.dependent -match $regexd > $nul
$session = $matches[1]
$session_user[$session] += $username
}


$logon_sessions |%{
$starttime = [management.managementdatetimeconverter]::todatetime($_.starttime)

$loggedonuser = New-Object -TypeName psobject

$loggedonuser | Add-Member -MemberType NoteProperty -Name "User" -Value $session_user[$_.logonid]

$loggedonuser
}

Posted

The code (first php one) works, but not for outputting quser! I can do "quser /?" and it'll output the help docs in an appropriate format, but nothing for quser, even when it clearly outputs users when done directly on the command prompt.

Am I missing something really obvious, or can syntax have variation if executed under a different circumstance?

Posted
Not sure what you mean? I have copied this to a test php file then running that in a browser to determine the output, though in practice it would be run via the php.exe on a schedule (if I ever get this working).
Posted

When I run the quser on the command line of the server (even when querying a remote server) it returns the data as expected. My current setup is running this command on a batch file and outputting the result to a text file, so I know it does work, I just can't seem to be get this specific quser command to return anything from a php exec!

If I knew of another way I could somehow get the active remote sessions on a server then i'd look at doing that (i.e. if that data is easily stored somewhere already) but the only way I can see is through quser.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...