caterpillar/server.py

310 lines
11 KiB
Python
Raw Normal View History

# gnh1201/php-httpproxy
2024-02-17 08:44:19 +00:00
# Namyheon Go (Catswords Research) <gnh1201@gmail.com>
# https://github.com/gnh1201
# Created at: 2022-10-06
2024-02-17 19:30:10 +00:00
# Updated at: 2024-12-18
2022-10-05 17:19:38 +00:00
import argparse
import socket
import sys
2022-11-24 09:02:32 +00:00
import os
2022-10-05 17:19:38 +00:00
from _thread import *
import base64
2022-10-08 04:03:15 +00:00
import json
2022-11-24 09:02:32 +00:00
import ssl
2022-11-25 08:12:58 +00:00
import time
2024-02-17 12:21:24 +00:00
import re
2024-02-17 17:38:46 +00:00
import traceback
2022-11-25 08:12:58 +00:00
from subprocess import Popen, PIPE
2022-10-05 17:19:38 +00:00
from datetime import datetime
2022-10-06 12:09:34 +00:00
from platform import python_version
2022-10-05 17:19:38 +00:00
2022-10-06 12:09:34 +00:00
import requests
2022-10-05 17:19:38 +00:00
from decouple import config
try:
listening_port = config('PORT', cast=int)
2022-11-24 09:05:58 +00:00
server_url = config('SERVER_URL')
2022-11-25 12:35:02 +00:00
cakey = config('CA_KEY')
cacert = config('CA_CERT')
certkey = config('CERT_KEY')
certdir = config('CERT_DIR')
2022-11-25 12:54:25 +00:00
openssl_binpath = config('OPENSSL_BINPATH')
2022-11-25 12:35:02 +00:00
client_encoding = config('CLIENT_ENCODING')
2024-02-17 19:04:02 +00:00
local_domain = config('LOCAL_DOMAIN')
proxy_pass = config('PROXY_PASS')
2022-10-05 17:19:38 +00:00
except KeyboardInterrupt:
print("\n[*] User has requested an interrupt")
print("[*] Application Exiting.....")
sys.exit()
parser = argparse.ArgumentParser()
2024-02-17 09:35:35 +00:00
parser.add_argument('--max_conn', help="Maximum allowed connections", default=255, type=int)
2024-02-17 09:39:11 +00:00
parser.add_argument('--buffer_size', help="Number of samples to be used", default=8192, type=int)
2022-10-05 17:19:38 +00:00
args = parser.parse_args()
max_connection = args.max_conn
buffer_size = args.buffer_size
def start(): #Main Program
try:
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.bind(('', listening_port))
sock.listen(max_connection)
print("[*] Server started successfully [ %d ]" %(listening_port))
except Exception:
print("[*] Unable to Initialize Socket")
print(Exception)
sys.exit(2)
while True:
try:
conn, addr = sock.accept() #Accept connection from client browser
data = conn.recv(buffer_size) #Recieve client data
2022-11-25 08:12:58 +00:00
start_new_thread(conn_string, (conn, data, addr)) #Starting a thread
2022-10-05 17:19:38 +00:00
except KeyboardInterrupt:
sock.close()
print("\n[*] Graceful Shutdown")
sys.exit(1)
def conn_string(conn, data, addr):
2022-11-25 10:32:17 +00:00
try:
first_line = data.split(b'\n')[0]
method, url = first_line.split()[0:2]
http_pos = url.find(b'://') #Finding the position of ://
scheme = b'http' # check http/https or other protocol
if http_pos == -1:
temp = url
else:
temp = url[(http_pos+3):]
scheme = url[0:http_pos]
port_pos = temp.find(b':')
webserver_pos = temp.find(b'/')
if webserver_pos == -1:
webserver_pos = len(temp)
2024-02-17 19:04:02 +00:00
webserver = b''
2022-11-25 10:32:17 +00:00
port = -1
if port_pos == -1 or webserver_pos < port_pos:
port = 80
webserver = temp[:webserver_pos]
else:
port = int((temp[(port_pos+1):])[:webserver_pos-port_pos-1])
webserver = temp[:port_pos]
if port == 443:
scheme = b'https'
except Exception as e:
conn.close()
print("[*] Exception on parsing the header of %s. Because of %s" % (str(addr[0]), str(e)))
return
2022-11-25 08:12:58 +00:00
2024-02-17 19:04:02 +00:00
# if it is reverse proxy
2024-02-17 19:19:54 +00:00
if local_domain != '' and data.find(b'\nHost: ' + local_domain.encode(client_encoding)) > -1:
2024-02-17 19:04:02 +00:00
print ("[*] ** Detected the reverse proxy request: %s" % (local_domain))
scheme, _webserver, _port = proxy_pass.encode(client_encoding).split(b':')
webserver = _webserver[2:]
port = int(_port.decode(client_encoding))
2022-11-25 08:12:58 +00:00
proxy_server(webserver, port, scheme, method, url, conn, addr, data)
def proxy_connect(webserver, conn):
2022-11-25 12:35:02 +00:00
hostname = webserver.decode(client_encoding)
2022-11-25 08:12:58 +00:00
certpath = "%s/%s.crt" % (certdir.rstrip('/'), hostname)
2022-11-25 10:32:17 +00:00
# https://stackoverflow.com/questions/24055036/handle-https-request-in-proxy-server-by-c-sharp-connect-tunnel
conn.send(b'HTTP/1.1 200 Connection Established\r\n\r\n')
2022-11-25 08:12:58 +00:00
2022-11-25 10:32:17 +00:00
# https://github.com/inaz2/proxy2/blob/master/proxy2.py
2022-10-05 17:19:38 +00:00
try:
2022-11-25 08:12:58 +00:00
if not os.path.isfile(certpath):
epoch = "%d" % (time.time() * 1000)
2022-11-25 12:54:25 +00:00
p1 = Popen([openssl_binpath, "req", "-new", "-key", certkey, "-subj", "/CN=%s" % hostname], stdout=PIPE)
p2 = Popen([openssl_binpath, "x509", "-req", "-days", "3650", "-CA", cacert, "-CAkey", cakey, "-set_serial", epoch, "-out", certpath], stdin=p1.stdout, stderr=PIPE)
2022-11-25 08:12:58 +00:00
p2.communicate()
2022-10-06 02:24:19 +00:00
except Exception as e:
2022-11-25 12:38:31 +00:00
print("[*] Skipped generating the certificate. Because of %s" % (str(e)))
2022-11-25 08:12:58 +00:00
2022-11-25 10:32:17 +00:00
# https://stackoverflow.com/questions/11255530/python-simple-ssl-socket-server
# https://docs.python.org/3/library/ssl.html
2022-11-25 08:12:58 +00:00
context = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER)
context.load_cert_chain(certpath, certkey)
2022-11-25 10:32:17 +00:00
# https://stackoverflow.com/questions/11255530/python-simple-ssl-socket-server
2022-11-25 08:12:58 +00:00
conn = context.wrap_socket(conn, server_side=True)
2022-11-25 10:32:17 +00:00
data = conn.recv(buffer_size)
2022-10-05 17:19:38 +00:00
2022-11-25 10:32:17 +00:00
return (conn, data)
2022-11-24 09:02:32 +00:00
2024-02-17 19:19:54 +00:00
def proxy_check_filtered(data, webserver, port, scheme, method, url):
2024-02-17 12:50:36 +00:00
filtered = False
2024-02-17 12:21:24 +00:00
2024-02-17 19:04:02 +00:00
# allowed conditions
2024-02-17 19:24:33 +00:00
if method == b'GET' or url.find(b'/api') > -1:
2024-02-17 19:04:02 +00:00
return filtered
2024-02-17 17:10:01 +00:00
# convert to text
2024-02-17 17:20:33 +00:00
text = ''
2024-02-17 19:04:02 +00:00
if len(data) > buffer_size * 10:
2024-02-17 17:20:33 +00:00
# maybe it is a multimedia data
2024-02-17 19:04:02 +00:00
text = data[0:buffer_size].decode(client_encoding, errors='ignore')
2024-02-17 17:20:33 +00:00
else:
# maybe it is a text only data
2024-02-17 19:04:02 +00:00
text = data.decode(client_encoding, errors='ignore')
2024-02-17 12:53:55 +00:00
2024-02-17 19:04:02 +00:00
# dump data
2024-02-17 16:49:29 +00:00
#print ("****************************")
#print (text)
#print ("****************************")
#filtered = text.find('@misskey.io') > -1
#filtered = filtered or text.find("https://misskey.io") > -1
filtered = filtered or text.find('ctkpaarr') > -1
filtered = filtered or bool(re.search(r'\b\w{10}@(?:\w+\.)+\w+\b', text))
filtered = filtered or bool(re.search(r"https://[^\s/@]+@([a-zA-Z0-9]{10})", text))
filtered = filtered or bool(re.search(r'https://[a-zA-Z0-9.-]+/users/[a-zA-Z0-9]{10}/statuses/[0-9]+', text))
2024-02-17 12:53:55 +00:00
if filtered:
2024-02-17 19:19:54 +00:00
print ("[*] Filtered data from %s:%s" % (webserver.decode(client_encoding), str(port)))
2024-02-17 19:04:02 +00:00
#print ("[*] ====== start preview data =====")
2024-02-17 12:53:55 +00:00
#print ("%s" % (text))
2024-02-17 19:04:02 +00:00
#print ("[*] ====== end preview data =====")
2024-02-17 08:44:19 +00:00
return filtered
2024-02-17 05:40:33 +00:00
2022-11-24 09:02:32 +00:00
def proxy_server(webserver, port, scheme, method, url, conn, addr, data):
2022-10-05 17:19:38 +00:00
try:
2024-02-17 05:26:27 +00:00
print("[*] Started the request. %s" % (str(addr[0])))
2022-10-08 04:23:40 +00:00
2024-02-17 11:13:17 +00:00
retry = False
2024-02-17 10:50:36 +00:00
try:
if scheme in [b'https', b'tls', b'ssl'] and method == b'CONNECT':
conn, data = proxy_connect(webserver, conn)
2024-02-17 11:13:17 +00:00
except OSError as e:
if not retry:
2024-02-17 17:38:46 +00:00
print ("[*] Retrying SSL negotiation... (%s:%s) %s" % (webserver.decode(client_encoding), str(port), str(e)))
2024-02-17 11:13:17 +00:00
retry = True
else:
raise Exception("SSL negotiation failed. (%s:%s) %s" % (webserver.decode(client_encoding), str(port), str(e)))
2024-02-17 10:50:36 +00:00
except Exception as e:
raise Exception("SSL negotiation failed. (%s:%s) %s" % (webserver.decode(client_encoding), str(port), str(e)))
2022-11-24 09:02:32 +00:00
2024-02-17 21:23:58 +00:00
# Wait to see if there is more data to transmit
if len(data) == buffer_size:
2024-02-17 22:41:17 +00:00
conn.settimeout(1)
2024-02-17 21:23:58 +00:00
while True:
try:
chunk = conn.recv(buffer_size)
if not chunk:
break
data += chunk
except:
break
# check requested data
2024-02-17 19:19:54 +00:00
if proxy_check_filtered(data, webserver, port, scheme, method, url):
2024-02-17 19:04:02 +00:00
conn.sendall(b"HTTP/1.1 403 Forbidden\n\n{\"status\":403}")
conn.close()
return
2024-02-17 08:44:19 +00:00
2024-02-17 19:04:02 +00:00
# make response data
response = b''
2024-02-17 05:23:51 +00:00
if server_url == "localhost":
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
2024-02-17 05:40:33 +00:00
2024-02-17 08:44:19 +00:00
if scheme in [b'https', b'tls', b'ssl']:
context = ssl.create_default_context()
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE
2024-02-17 05:40:33 +00:00
2024-02-17 08:44:19 +00:00
sock = context.wrap_socket(sock, server_hostname=webserver.decode(client_encoding))
sock.connect((webserver, port))
sock.sendall(data)
else:
sock.connect((webserver, port))
sock.sendall(data)
2024-02-17 05:23:51 +00:00
2024-02-17 05:26:27 +00:00
i = 0
2024-02-17 05:23:51 +00:00
while True:
2024-02-17 08:44:19 +00:00
chunk = sock.recv(buffer_size)
2024-02-17 05:26:27 +00:00
if not chunk:
2024-02-17 05:23:51 +00:00
break
2024-02-17 08:44:19 +00:00
response += chunk
2024-02-17 19:19:54 +00:00
#if proxy_check_filtered(response, webserver, port, scheme, method, url):
2024-02-17 12:21:24 +00:00
# break
#conn.send(chunk)
2024-02-17 05:40:33 +00:00
i += 1
2024-02-17 05:26:27 +00:00
2024-02-17 19:19:54 +00:00
if not proxy_check_filtered(response, webserver, port, scheme, method, url):
2024-02-17 12:21:24 +00:00
conn.sendall(response)
2024-02-17 16:49:29 +00:00
else:
#add_domain_route(webserver.decode(client_encoding), '127.0.0.1')
2024-02-17 17:10:01 +00:00
conn.sendall(b"HTTP/1.1 403 Forbidden\n\n{\"status\":403}")
2024-02-17 12:21:24 +00:00
2024-02-17 12:08:02 +00:00
print("[*] Received %s chunks. (%s bytes per chunk)" % (str(i), str(buffer_size)))
2024-02-17 08:44:19 +00:00
2024-02-17 05:23:51 +00:00
else:
2024-02-17 08:44:19 +00:00
2024-02-17 05:23:51 +00:00
proxy_data = {
'headers': {
2024-02-17 17:10:01 +00:00
"User-Agent": "php-httpproxy/0.1.4 (Client; Python " + python_version() + "; abuse@catswords.net)",
2024-02-17 05:23:51 +00:00
},
'data': {
"data": base64.b64encode(data).decode(client_encoding),
"client": str(addr[0]),
"server": webserver.decode(client_encoding),
"port": str(port),
"scheme": scheme.decode(client_encoding),
"url": url.decode(client_encoding),
"length": str(len(data)),
"chunksize": str(buffer_size),
"datetime": datetime.now().strftime("%Y-%m-%d %H:%M:%S.%f")
}
2022-11-24 09:02:32 +00:00
}
2024-02-17 05:23:51 +00:00
raw_data = json.dumps(proxy_data['data'])
2024-02-17 05:40:33 +00:00
2024-02-17 05:23:51 +00:00
print("[*] Sending %s bytes..." % (str(len(raw_data))))
2024-02-17 05:40:33 +00:00
2024-02-17 05:23:51 +00:00
i = 0
relay = requests.post(server_url, headers=proxy_data['headers'], data=raw_data, stream=True)
for chunk in relay.iter_content(chunk_size=buffer_size):
2024-02-17 12:08:02 +00:00
response += chunk
2024-02-17 19:19:54 +00:00
#if proxy_check_filtered(response, webserver, port, scheme, method, url):
2024-02-17 12:21:24 +00:00
# break
#conn.send(chunk)
2024-02-17 05:40:33 +00:00
i += 1
2024-02-17 19:19:54 +00:00
if not proxy_check_filtered(response, webserver, port, scheme, method, url):
2024-02-17 12:21:24 +00:00
conn.sendall(response)
2024-02-17 16:49:29 +00:00
else:
#add_domain_route(webserver.decode(client_encoding), '127.0.0.1')
2024-02-17 17:10:01 +00:00
conn.sendall(b"HTTP/1.1 403 Forbidden\n\n{\"status\":403}")
2024-02-17 12:21:24 +00:00
2024-02-17 12:08:02 +00:00
print("[*] Received %s chunks. (%s bytes per chunk)" % (str(i), str(buffer_size)))
2022-10-05 17:19:38 +00:00
2024-02-17 05:26:27 +00:00
print("[*] Request and received. Done. %s" % (str(addr[0])))
2022-10-05 17:19:38 +00:00
conn.close()
2022-11-25 08:12:58 +00:00
except Exception as e:
2024-02-17 17:38:46 +00:00
print(traceback.format_exc())
2022-11-25 10:32:17 +00:00
print("[*] Exception on requesting the data. Because of %s" % (str(e)))
2022-10-05 17:19:38 +00:00
conn.close()
2024-02-17 16:49:29 +00:00
'''
def add_domain_route(domain, ip_address):
hosts_path = '/etc/hosts'
with open(hosts_path, 'r') as file:
lines = file.readlines()
domain_exists = any(domain in line for line in lines)
if not domain_exists:
lines.append(f"{ip_address}\t{domain}\n")
with open(hosts_path, 'w') as file:
file.writelines(lines)
'''
2022-10-05 17:19:38 +00:00
if __name__== "__main__":
start()