summaryrefslogtreecommitdiff
path: root/server/apps/agentcomm.py
blob: f9b11d16b9290bb35cb3adbf134f4286751a5c2e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
# 代理通信与注册接口
import random
import re
import requests

from apiflask import APIBlueprint, Schema
from apiflask.fields import String, Integer, List, Nested, Boolean, DateTime, Float
from apiflask.validators import OneOf
from flask import request

from .util import error

from model import Agent, TaskLog, Policy, TaskPolicy
from exts import db
from sqlalchemy.exc import SQLAlchemyError

bp = APIBlueprint("代理管理接口集合", __name__, url_prefix="/agent")


class AgentOutput(Schema):
    id = String()
    ipaddr = List(String())
    atype = String(validate=OneOf(["攻击渗透", "状态感知", "参数感知"]))
    status = Boolean()
    idle = Boolean()
    port = Integer()
    sys = String()
    cpu_num = Integer()
    mem = String()
    start_time = DateTime()


# 代理注册接口
@bp.post("/register")
@bp.doc("代理注册接口", "返回分配给代理的编号值,用于代理和主控端通信注册,前端界面无需调用")
@bp.input({
    "atype": String(validate=OneOf(["gjst", "ztgz", "csgz"])),
    'v6addr': List(String()),
    'lat': String(),
    'lng': String(),
    'cpu_num': Integer(),
    'ram_size': Integer(),
    'ram_per': Float(),
    'sys': String(),
    "port": Integer()
}, example={'atype': "gjst", 'v6addr': ["2001::1"], 'lat': "-1.111", 'lng': "1.1111", 'cpu_num': 4,
            'ram_size': 16, 'ram_per': 0.55,
            'sys': "linux", "port": 2525})
# 参数说明
# 代理类型
# "type": String(required=True, validate=OneOf(["gjst", "mbgz", "ztgz"])),
# 代理的通信端口
# "port": Integer(required=True),
# # 代理所在的操作系统
# "sys": String(),
# # IPv6地址
# # "v6addr": List(String()),
# # 经度
# "lat": String(),
# # 纬度
# "lng": String(),
# # cpu核心数
# "cpu_num": Integer(),
# # 内存大小
# "ram_size": Integer(),
# # 已用内存比例
# "ram_per": Float()
def register_agent(json_data):
    data = dict(json_data)
    agent = Agent(
        agent_id = "".join(random.sample('1234567890zyxwvutsrqponmlkjihgfedcba', 8)),
        ipaddr = "|".join([request.remote_addr] + [i for i in data["v6addr"]]),
        lat = data["lat"],
        lng = data["lng"],
        agent_type = data["atype"],
        sys = data["sys"],
        port = data["port"],
        cpu_num = data["cpu_num"],
        status = True,
        mem = str(data["ram_size"]) + "GB" + "(" + str('{:.2f}'.format(100 * (1 - float(data["ram_per"])))) + "%" + "可用)",
        idle = True
    )
    try:
        db.session.add(agent)
        db.session.commit()
        return {"code": 200, "msg": "ok", "id":agent.agent_id}
    except SQLAlchemyError as e:
        db.session.rollback()
        error(str(e))
        return {"code": 500, "msg": str(e)}


# 代理任务下发
def deliver_task(task_policy):
    agent = db.session.query(Agent).get(task_policy.task.agent_id)
    ip, port = agent.ipaddr.split("|")[0], agent.port
    payload = task_policy.Policy.p_payload
    # 使得param应该未以空格分隔的多个参数
    param = task_policy.policy_param.split(' ')
    # 使用正则表达式逐个替换策略中的<***>(还未填充的内容)
    param = re.sub(r'<[^>]*>', lambda _: param.pop(0), payload)
    try:
        res = requests.post("http://%s:%s/script/execute" % (ip, port), timeout=3,
                            json={'policy': task_policy.Policy.p_exe,
                                  'param': param,
                                  'id' : str(task_policy.tp_id),
                                  })
        if res.status_code == 200:
            task_policy.task.status = "working"
            return None
        error("任务分发错误,code: " + str(res.status_code) + " err: " + str(res.text))
        return res.text
    except Exception as e:
        error(str(e))
        return str(e)

def stop_task(task_policy):
    agent = db.session.query(Agent).get(task_policy.task.agent_id)
    ip, port = agent.ipaddr.split("|")[0], agent.port
    try:
        res = requests.post(f"http://{ip}:{port}/script/stop/{str(task_policy.tp_id)}", timeout=3)
        if res.status_code == 200:
            task_policy.task.status = "stopped"
            return None
        error("任务停止错误,code: " + str(res.status_code) + " err: " + str(res.text))
        return res.text
    except Exception as e:
        error(str(e))
        return str(e)

@bp.post("/res")
@bp.doc("代理输出消息接收接口", hide=True)
@bp.input({
    "id" : String(),
    "taskpolicy" : Integer(),
    "level" : String(validate=OneOf(["INFO", "WARNING", "ERROR"])),
    "info" : String()
})
def task_ret(json_data):
    if json_data["info"] == "finish":
        task_policy = db.session.query(TaskPolicy).get(json_data["taskpolicy"])
        task_policy.task.status = "stopped"
        db.session.commit()
        return {"code": 200, "msg": "ok"}
    task_log = TaskLog(
            # created_by_agent = json_data["id"],
            tlog_level = json_data["level"],
            tlog_info = json_data["info"],
            tlog_tp = json_data["taskpolicy"]
    )
    try:
        db.session.add(task_log)
        db.session.commit()
        return {"code": 200, "msg": "ok"}
    except SQLAlchemyError as e:
        db.session.rollback()
        error(str(e))
        return {"code": 500, "msg": str(e)}


@bp.get("/")
@bp.doc("代理信息获取接口", description="输入参数说明:</br>"
                                        + "atype:能力类型,可选参数范围及对应含义为:all-全部(默认),gjst-攻击渗透,ztgz-状态感知,csgz-参数感知 </br>"
                                        + "status:当前状态,可选参数范围及对应含义为:2-全部(默认),1-在线,0-离线 </br>"
                                        + "idle:是否空闲,可选参数范围及对应含义为:2-全部(默认),1-空闲,0-执行中 </br>")
@bp.input({
    "atype": String(load_default="all", validate=OneOf(["all", "gjst", "ztgz", "csgz"])),
    "status": Integer(load_default=2, validate=OneOf([0, 1, 2])),
    "idle": Integer(load_default=2, validate=OneOf([0, 1, 2])),
    "page": Integer(load_default=1),
    "per_page": Integer(load_default=10)
}, location="query")
@bp.output({
    "code": Integer(),
    "agent_data": List(Nested(AgentOutput())),
    "total": Integer()
})
def agent_info(query_data):
    per_page = query_data["per_page"]
    page = query_data["page"]
    agent_type = query_data["atype"]
    status = query_data["status"]
    idle = query_data["idle"]
    agent_list = []
    query = db.session.query(Agent)
    if agent_type != "all":
        query = query.filter(Agent.agent_type == agent_type)
    if status != 2:
        query = query.filter(Agent.status == bool(status))
    if idle != 2:
        query = query.filter(Agent.idle == bool(idle))
    # 分页
    agents = query.offset((page - 1) * per_page).limit(per_page).all()
    # 查询总数
    agent_count = query.count()
    for agent in agents:
        agent_r = {}
        agent_r["id"] = agent.agent_id
        agent_r["ipaddr"] = agent.ipaddr.split("|") if agent.ipaddr else []
        agent_r["atype"] = agent.agent_type
        agent_r["status"] = agent.status
        agent_r["idle"] = agent.idle
        agent_r["port"] = agent.port
        agent_r["sys"] = agent.sys
        agent_r["cpu_num"] = agent.cpu_num
        agent_r["mem"] = agent.mem
        agent_r["start_time"] = agent.start_time
        agent_list.append(agent_r)
    return {"code": 200, "agent_data": agent_list, "total": agent_count}


@bp.doc("代理删除接口", "输入参数说明:</br>"
        + "id: 代理编号")
@bp.post("/del")
@bp.input({
    "id": String(required=True)
})
@bp.output({
    "code": Integer(),
    "msg": String()
})
def del_agent(json_data):
    try:
        agent = db.session.query(Agent).get(json_data["id"])
        if agent:
            db.session.delete(agent)
            db.session.commit()
            return {"code": "200", "msg": "代理删除成功"}
        else:
            return {"code": "404", "msg": "该代理id未找到!"}
    except SQLAlchemyError as e:
        db.session.rollback()
        error(str(e))
        return {"code": 500, "msg": str(e)}