Compare commits
5 Commits
1669156158
...
1669761100
Author | SHA1 | Date | |
---|---|---|---|
2680f78cd6 | |||
d62fa3b79f | |||
86eeb716ac | |||
f6cc6b6fef | |||
b4a46ad253 |
2
auth.py
2
auth.py
@ -8,7 +8,7 @@ import bcrypt
|
||||
def login(config, user, password, sysid):
|
||||
fprint("Attempting to login as " + user)
|
||||
filename = sysid + "login.csv"
|
||||
|
||||
#return True
|
||||
#hashpasswd = bcrypt.hashpw(password.encode('utf-8'), user).decode()
|
||||
with open(find_data_file(filename), "w", newline="") as f:
|
||||
writer = csv.writer(f)
|
||||
|
18
block.py
18
block.py
@ -10,7 +10,7 @@ import time
|
||||
import csv
|
||||
import ssh
|
||||
|
||||
def get_blocklist(config):
|
||||
def get_blocklist(config, appendbad):
|
||||
setup_child()
|
||||
fprint("Downloading deny list from server")
|
||||
data = ssh.check_for_file(config, "BadIPs.csv", "receive")
|
||||
@ -21,13 +21,9 @@ def get_blocklist(config):
|
||||
data2.append(row)
|
||||
data2 = [i for i in data2 if i]
|
||||
#fprint(data2)
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "20.112.52.29", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "20.81.111.85", "80", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "100.115.71.78", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "100.115.71.78", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "174.143.130.167", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "216.47.134.203", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
data2.append(["N/A", "TCP", "N/A", "N/A", "34.111.83.189", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
for line in appendbad:
|
||||
data2.append(line)
|
||||
|
||||
|
||||
|
||||
fprint(data2)
|
||||
@ -61,7 +57,9 @@ def block_conn(config, datafile, res):
|
||||
continue
|
||||
|
||||
srcip = line[2].split(":")[0]
|
||||
srcport = line[2].split(":")[1]
|
||||
destip = line[3].split(":")[0]
|
||||
destport = line[3].split(":")[1]
|
||||
pid = line[5]
|
||||
try:
|
||||
pid = int(pid)
|
||||
@ -71,10 +69,12 @@ def block_conn(config, datafile, res):
|
||||
for line in baddata:
|
||||
#fprint(destip + " " + line[4])
|
||||
badsrcip = line[2]
|
||||
badsrcport = line[3]
|
||||
baddestip = line[4]
|
||||
baddestport = line[5]
|
||||
badpid = line[11]
|
||||
|
||||
if srcip == badsrcip or destip == baddestip and not pid in badapps:
|
||||
if ((srcip == badsrcip and srcport == badsrcport) or (destip == baddestip and destport == baddestport)) and not pid in badapps:
|
||||
found = True
|
||||
fprint("FLAG " + srcip + " " + destip + " " + str(pid))
|
||||
badapps.append(pid)
|
||||
|
@ -1,7 +1,7 @@
|
||||
core:
|
||||
autostart: true
|
||||
clockspeed: 20
|
||||
interval: 5
|
||||
interval: 10
|
||||
level: 3
|
||||
localadmin: true
|
||||
sftp:
|
||||
|
41
ippigeon.py
41
ippigeon.py
@ -10,6 +10,7 @@ from util import find_data_file
|
||||
from util import fprint
|
||||
from util import kill
|
||||
from util import run_cmd
|
||||
from notification import send_notification
|
||||
import taskbartool
|
||||
import util
|
||||
import netstat
|
||||
@ -18,8 +19,8 @@ import auth
|
||||
import panel
|
||||
import block
|
||||
|
||||
badapps = [756, 278670]
|
||||
badips = ["208.59.79.12",]
|
||||
|
||||
history = list()
|
||||
displaydata = None
|
||||
settings = None
|
||||
netdata_res = None
|
||||
@ -66,7 +67,7 @@ def netstat_done(res):
|
||||
def process_done(res):
|
||||
if settings["running"] == True:
|
||||
fprint("uploading to sftp...")
|
||||
#ssh.sftp_send_data(res, config, datafile)
|
||||
#ssh.sftp_send_data(config, datafile, 'send')
|
||||
|
||||
procdata_res = pool.apply_async(ssh.sftp_send_data, (config, datafile, 'send'), callback=upload_done)
|
||||
|
||||
@ -192,7 +193,7 @@ def mainloop(pool):
|
||||
|
||||
|
||||
if settings["block"] == True and settings["running"] == True:
|
||||
blockdata_res = pool.apply_async(block.get_blocklist, (config,), callback=blockdata_done)
|
||||
blockdata_res = pool.apply_async(block.get_blocklist, (config, settings["appendbad"]), callback=blockdata_done)
|
||||
#block.get_blocklist(config)
|
||||
settings["block"] = False
|
||||
|
||||
@ -216,9 +217,11 @@ def mainloop(pool):
|
||||
tmplist = settings["badapps"]
|
||||
settings["badapps"] = list()
|
||||
for x in tmplist:
|
||||
send_notification("Killing PID " + str(x))
|
||||
kill(x)
|
||||
|
||||
if settings["fwll"] == True:
|
||||
global history
|
||||
tmplist = settings["badlines"]
|
||||
tmpstat = settings["stats"]
|
||||
tmpstat[0] += len(tmplist)
|
||||
@ -228,13 +231,19 @@ def mainloop(pool):
|
||||
badproto = line[1]
|
||||
badip = line[4]
|
||||
badport = line[5]
|
||||
fprint("Firewalling " + badip + ":" + str(badport))
|
||||
if win32:
|
||||
cmd = 'New-NetFirewallRule -DisplayName "IPPigeon Security Rule ' + badip + ':' + str(badport) + '" -Group "IPPigeon" -Direction Outbound -LocalPort Any -Protocol ' + badproto + ' -Action Block -RemoteAddress ' + badip + ' -RemotePort ' + str(badport)
|
||||
run_cmd(cmd)
|
||||
if linux:
|
||||
cmd = "nft add rule ip ippigeon output ip daddr " + badip + " " + badproto.lower() + " dport " + str(badport) + " drop"
|
||||
run_cmd(cmd)
|
||||
|
||||
if (badip, badport) not in history:
|
||||
fprint("Firewalling " + badip + ":" + str(badport))
|
||||
send_notification("Firewalling " + badip + ":" + str(badport))
|
||||
if win32:
|
||||
cmd = 'New-NetFirewallRule -DisplayName "IPPigeon Security Rule ' + badip + ':' + str(badport) + '" -Group "IPPigeon" -Direction Outbound -LocalPort Any -Protocol ' + badproto + ' -Action Block -RemoteAddress ' + badip + ' -RemotePort ' + str(badport)
|
||||
run_cmd(cmd)
|
||||
if linux:
|
||||
cmd = "nft add rule ip ippigeon output ip daddr " + badip + " " + badproto.lower() + " dport " + str(badport) + " drop"
|
||||
run_cmd(cmd)
|
||||
else:
|
||||
history.append((badip, badport))
|
||||
settings["badapps"] = list()
|
||||
|
||||
|
||||
if settings["applyconfig"] == True:
|
||||
@ -302,6 +311,16 @@ if __name__ == '__main__':
|
||||
settings["fwll"] = 0
|
||||
settings["running"] = config["core"]["autostart"]
|
||||
settings["newdata"] = False
|
||||
settings["appendbad"] = list()
|
||||
tmp = list()
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "20.112.52.29", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "20.81.111.85", "80", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "100.115.71.78", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "100.115.71.78", "5000", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "174.143.130.167", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "216.47.134.203", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
tmp.append(["N/A", "TCP", "N/A", "N/A", "34.111.83.189", "443", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
settings["appendbad"] = tmp
|
||||
# connections blocked, total connections allowed, count of data sent, data recieved, ratio blocked-unblocked
|
||||
settings["stats"] = [0, 0, 0, 0, 0.0]
|
||||
|
||||
|
46
panel.py
46
panel.py
@ -149,6 +149,7 @@ class ServerPanel(wx.Panel):
|
||||
self.sub_sizer_left = wx.BoxSizer(wx.VERTICAL)
|
||||
self.sub_sizer_right = wx.BoxSizer(wx.VERTICAL)
|
||||
self.sub_sizer_stats = wx.BoxSizer(wx.VERTICAL)
|
||||
self.sub_sizer_filter = wx.BoxSizer(wx.VERTICAL)
|
||||
self.row_obj_dict = {}
|
||||
self.list_ctrl = wx.ListCtrl(
|
||||
self, size=(-1, 400),
|
||||
@ -184,6 +185,7 @@ class ServerPanel(wx.Panel):
|
||||
self.main_sizer.Add(self.secondary_sizer, 0, wx.ALL | wx.EXPAND, 20)
|
||||
self.secondary_sizer.Add(self.sub_sizer_left, 0, wx.ALL | wx.CENTER, 20)
|
||||
self.secondary_sizer.Add(self.sub_sizer_right, 0, wx.ALL | wx.CENTER, 20)
|
||||
self.secondary_sizer.Add(self.sub_sizer_filter, 0, wx.ALL | wx.CENTER, 20)
|
||||
self.secondary_sizer.Add(self.sub_sizer_stats, 0, wx.ALL | wx.CENTER, 20)
|
||||
self.start_button = wx.Button(self, label='Start IPPigeon')
|
||||
self.start_button.SetBackgroundColour((205, 215, 206))
|
||||
@ -199,6 +201,13 @@ class ServerPanel(wx.Panel):
|
||||
self.login_button = wx.Button(self, label='Login')
|
||||
#self.login_button.SetBackgroundColour((205, 215, 206))
|
||||
self.login_button.Bind(wx.EVT_BUTTON, self.on_login)
|
||||
self.quit_button = wx.Button(self, label='Quit IPPigeon')
|
||||
#self.login_button.SetBackgroundColour((205, 215, 206))
|
||||
self.quit_button.Bind(wx.EVT_BUTTON, self.on_quit)
|
||||
|
||||
self.blacklist_button = wx.Button(self, label='Add to blacklist')
|
||||
#self.login_button.SetBackgroundColour((205, 215, 206))
|
||||
self.blacklist_button.Bind(wx.EVT_BUTTON, self.on_blacklist)
|
||||
|
||||
self.sub_sizer_right.Add(self.statustext, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_right.Add(self.logintext, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
@ -206,7 +215,9 @@ class ServerPanel(wx.Panel):
|
||||
self.sub_sizer_left.Add(self.stop_button, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_left.Add(self.secondary_frame_button, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_right.Add(self.login_button, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_right.Add(self.quit_button, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_stats.Add(self.stattext, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.sub_sizer_filter.Add(self.blacklist_button, 0, wx.CENTER | wx.ALL | 100, 5)
|
||||
self.SetSizer(self.main_sizer)
|
||||
self.start_button.Enable(enable=settings["loggedin"])
|
||||
self.stop_button.Enable(enable=settings["loggedin"])
|
||||
@ -224,13 +235,17 @@ class ServerPanel(wx.Panel):
|
||||
self.start_button.Enable(enable=settings["loggedin"])
|
||||
self.stop_button.Enable(enable=settings["loggedin"])
|
||||
self.secondary_frame_button.Enable(enable=settings["loggedin"])
|
||||
self.quit_button.Enable(enable=settings["loggedin"])
|
||||
if self.list_ctrl.GetFirstSelected() < 0:
|
||||
self.blacklist_button.Enable(enable=False)
|
||||
else:
|
||||
self.blacklist_button.Enable(enable=settings["loggedin"])
|
||||
def updatedata(self):
|
||||
global settings
|
||||
if settings["running"] == True:
|
||||
txt = "Status: Running (" + str(settings["config"]["core"]["level"]) + ")"
|
||||
else:
|
||||
txt = "Status: Not running"
|
||||
|
||||
#self.list_ctrl.SetSize(self.GetSize()[0] - 50, self.GetSize()[1] - 200)
|
||||
self.checklogin()
|
||||
if settings["loggedin"] == True:
|
||||
@ -252,6 +267,10 @@ class ServerPanel(wx.Panel):
|
||||
return
|
||||
fprint("updatedata called")
|
||||
loaddata()
|
||||
list_total = self.list_ctrl.GetItemCount()
|
||||
list_top = self.list_ctrl.GetTopItem()
|
||||
list_pp = self.list_ctrl.GetCountPerPage()
|
||||
list_bottom = min(list_top + list_pp, list_total - 1)
|
||||
if self.list_ctrl.DeleteAllItems():
|
||||
fprint("Items deleted")
|
||||
else:
|
||||
@ -260,10 +279,11 @@ class ServerPanel(wx.Panel):
|
||||
if str(TEST_FILE.iloc[i, 4]).find("TIME_WAIT") >= 0 or str(TEST_FILE.iloc[i, 4]).find("FIN_WAIT_2") >= 0:
|
||||
continue
|
||||
idx = 0
|
||||
for ip in settings["badips"]:
|
||||
for app in settings["badapps"]:
|
||||
#fprint(pid)
|
||||
idx = i
|
||||
if str(TEST_FILE.iloc[i, 3]).find(ip) >= 0 and str(TEST_FILE.iloc[i, 4]).find("TIME_WAIT") < 0: # "bad" pid, highlight in red at the top
|
||||
if TEST_FILE.iloc[i, 5] == app: # "bad" pid, highlight in red at the top
|
||||
fprint("BAD APP UI: " + str(app))
|
||||
idx = self.list_ctrl.InsertItem(0, TEST_FILE.iloc[i, 0])
|
||||
self.list_ctrl.SetItemBackgroundColour(idx, wx.Colour(200, 51, 51))
|
||||
break
|
||||
@ -276,10 +296,12 @@ class ServerPanel(wx.Panel):
|
||||
for j in range(1, 6):
|
||||
#fprint(str(idx) + " " + str(TEST_FILE.iloc[i, 0]))
|
||||
self.list_ctrl.SetItem(idx, j, str(TEST_FILE.iloc[i, j]))
|
||||
|
||||
|
||||
#fprint(i, j, TEST_FILE.iloc[i, j])
|
||||
#self.SetSizer(self.main_sizer)
|
||||
|
||||
self.list_ctrl.EnsureVisible((list_bottom - 1))
|
||||
wx.CallLater(100, self.updatedata)
|
||||
|
||||
def on_start(self, event):
|
||||
@ -304,7 +326,25 @@ class ServerPanel(wx.Panel):
|
||||
dg2 = ServerFrame()
|
||||
|
||||
#dg2.ShowModal()
|
||||
def on_quit(self, event):
|
||||
global killme
|
||||
killme.value += 1
|
||||
self.Close()
|
||||
self.Parent.Close()
|
||||
|
||||
def on_blacklist(self, event):
|
||||
global settings
|
||||
tmp = settings["appendbad"]
|
||||
idx = self.list_ctrl.GetFirstSelected()
|
||||
if idx < 0:
|
||||
return
|
||||
proto = self.list_ctrl.GetItem(idx, 1).GetText()
|
||||
dest = self.list_ctrl.GetItem(idx, 3).GetText()
|
||||
destip, destport = dest.split(":")
|
||||
fprint([proto, destip, destport])
|
||||
tmp.append(["N/A", proto, "N/A", "N/A", destip, destport, "N/A", "N/A", "N/A", "N/A", "N/A", "N/A", "N/A"])
|
||||
settings["appendbad"] = tmp
|
||||
|
||||
def ShowImage(self, imageFile):
|
||||
if imageFile == "":
|
||||
self.bitmap = wx.StaticBitmap(self, -1, size=(0, 0))
|
||||
|
@ -5,4 +5,6 @@ cx_Freeze
|
||||
pandas
|
||||
pyyaml
|
||||
numpy
|
||||
bcrypt
|
||||
bcrypt
|
||||
plyer
|
||||
playsound
|
25
ssh.py
25
ssh.py
@ -3,23 +3,32 @@ from fabric import Connection
|
||||
from util import find_data_file
|
||||
from util import setup_child
|
||||
from util import fprint
|
||||
from util import macos
|
||||
from invoke import exceptions
|
||||
import sys
|
||||
|
||||
c = None
|
||||
|
||||
def sftp_send_data(config, filename, filetype):
|
||||
setup_child()
|
||||
fprint("Connecting over SSH to " + config['sftp']['host'])
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
fprint("Sending data over SFTP: " + filename)
|
||||
fprint(c.put(find_data_file(filename), remote=config['sftp']['filepath'][filetype]))
|
||||
fprint("Data sent over SFTP successfully")
|
||||
if not macos:
|
||||
fprint("Connecting over SSH to " + config['sftp']['host'])
|
||||
global c
|
||||
if c is None:
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
|
||||
fprint("Sending data over SFTP: " + filename)
|
||||
fprint(c.put(find_data_file(filename), remote=config['sftp']['filepath'][filetype]))
|
||||
fprint("Data sent over SFTP successfully")
|
||||
#command = 'ls ' + config['sftp']['filepath'][filetype]
|
||||
#fprint(c.run(command))
|
||||
|
||||
def check_for_file(config, filename, location):
|
||||
setup_child()
|
||||
fprint("Connecting over SSH to " + config['sftp']['host'])
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
global c
|
||||
if c is None:
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
fprint("Checking for existence of file " + config['sftp']['filepath'][location] + "/" + filename)
|
||||
try:
|
||||
res = c.run("ls -l " + config['sftp']['filepath'][location] + "/" + filename, hide=True)
|
||||
@ -31,7 +40,9 @@ def check_for_file(config, filename, location):
|
||||
def run_ssh(config, command, location):
|
||||
setup_child()
|
||||
fprint("Connecting over SSH to " + config['sftp']['host'])
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
global c
|
||||
if c is None:
|
||||
c = Connection(host=config['sftp']['host'], user=config['sftp']['user'], port=config['sftp']['port'], connect_kwargs={"key_filename": find_data_file(config['sftp']['keyfile']),})
|
||||
fprint("cd to " + config['sftp']['filepath'][location])
|
||||
with c.cd(config['sftp']['filepath'][location]):
|
||||
fprint("Running ssh command: " + command)
|
||||
|
Reference in New Issue
Block a user