
Protocollo Desktop Remoto in Twisted Python

Protocollo Remote Desktop in twisted python.
RDPY è un'implementazione puramente Python del protocollo Microsoft RDP (Remote Desktop Protocol) (lato client e server). RDPY è costruito sul motore di rete basato su eventi Twisted. RDPY supporta il livello di sicurezza RDP standard, RDP su SSL e autenticazione NLA (tramite il protocollo di autenticazione ntlmv2).
RDPY fornisce i seguenti binari RDP e VNC:
RDPY è interamente implementato in python, eccetto l'algoritmo di decompressione bitmap che è implementato in C per motivi di prestazioni.
Le dipendenze sono necessarie solo per i binari pyqt4:
Esempio per sistemi basati su Debian:
sudo apt-get install python-qt4
Esempio per OS X per installare PyQt con homebrew
$ brew install qt sip pyqt
$ git clone https://github.com/citronneur/rdpy.git rdpy
$ pip install twisted pyopenssl qt4reactor service_identity rsa pyasn1
$ python rdpy/setup.py install
Oppure usa PIP:
$ pip install rdpy
Per virtualenv, dovrai collegare la libreria qt4 ad esso:
$ ln -s /usr/lib/python2.7/dist-packages/PyQt4/ $VIRTUAL_ENV/lib/python2.7/site-packages/
$ ln -s /usr/lib/python2.7/dist-packages/sip.so $VIRTUAL_ENV/lib/python2.7/site-packages/
RDPY viene fornito con alcuni binari molto utili. Questi binari sono compatibili con Linux e Windows.
rdpy-rdpclient è un semplice client RDP Qt4.
$ rdpy-rdpclient.py [-u username] [-p password] [-d domain] [-r rss_ouput_file] [...] XXX.XXX.XXX.XXX[:3389]
Puoi usare rdpy-rdpclient in uno scenario di Recorder Session, utilizzato in rdpy-rdphoneypot.
rdpy-vncclient è un semplice client VNC Qt4.
$ rdpy-vncclient.py [-p password] XXX.XXX.XXX.XXX[:5900]
rdpy-rdpscreenshot salva la schermata di login in un file.
$ rdpy-rdpscreenshot.py [-w width] [-l height] [-o output_file_path] XXX.XXX.XXX.XXX[:3389]
rdpy-vncscreenshot salva il primo aggiornamento dello schermo in un file.
$ rdpy-vncscreenshot.py [-p password] [-o output_file_path] XXX.XXX.XXX.XXX[:5900]
rdpy-rdpmitm è un proxy RDP che ti permette di eseguire un attacco Man In The Middle sul protocollo RDP. Registra uno scenario di sessione in un file rss che può essere riprodotto da rdpy-rssplayer.
$ rdpy-rdpmitm.py -o output_dir [-l listen_port] [-k private_key_file_path] [-c certificate_file_path] [-r (for XP or server 2003 client)] target_host[:target_port]
La directory di output viene utilizzata per salvare il file rss con il seguente formato (YYYYMMDDHHMMSS_ip_index.rss). Il file della chiave privata e il file del certificato sono file crittografici classici per connessioni SSL. Il protocollo RDP può negoziare il proprio livello di sicurezza. Se uno dei due parametri viene omesso, il server utilizza RDP standard come livello di sicurezza.
rdpy-rdphoneypot è un Honeypot RDP. Utilizza scenari di sessione registrati per riprodurli attraverso il protocollo RDP.
$ rdpy-rdphoneypot.py [-l listen_port] [-k private_key_file_path] [-c certificate_file_path] rss_file_path_1 ... rss_file_path_N
Il file della chiave privata e il file del certificato sono file crittografici classici per connessioni SSL. Il protocollo RDP può negoziare il proprio livello di sicurezza. Se uno dei due parametri viene omesso, il server utilizza RDP standard come livello di sicurezza. Puoi specificare più di un file per adattarsi a dimensioni dello schermo più comuni.
rdpy-rssplayer viene utilizzato per riprodurre file Record Session Scenario (rss) generati dai binari rdpy-rdpmitm o rdpy-rdpclient.
$ rdpy-rssplayer.py rss_file_path
RDPY può anche essere utilizzato come widget Qt tramite la classe rdpy.ui.qt4.QRemoteDesktop. Può essere integrato nella tua applicazione Qt. qt4reactor deve essere usato nella tua app per far funzionare Twisted e Qt insieme. Per maggiori dettagli, vedi i sorgenti di rdpy-rdpclient.
In poche parole, RDPY può essere utilizzato come libreria di protocollo con un motore twisted.
from rdpy.protocol.rdp import rdp
class MyRDPFactory(rdp.ClientFactory):
def clientConnectionLost(self, connector, reason):
reactor.stop()
def clientConnectionFailed(self, connector, reason):
reactor.stop()
def buildObserver(self, controller, addr):
class MyObserver(rdp.RDPClientObserver):
def onReady(self):
"""
@summary: Call when stack is ready
"""
#send 'r' key
self._controller.sendKeyEventUnicode(ord(unicode("r".toUtf8(), encoding="UTF-8")), True)
#mouse move and click at pixel 200x200
self._controller.sendPointerEvent(200, 200, 1, true)
def onUpdate(self, destLeft, destTop, destRight, destBottom, width, height, bitsPerPixel, isCompress, data):
"""
@summary: Notify bitmap update
@param destLeft: xmin position
@param destTop: ymin position
@param destRight: xmax position because RDP can send bitmap with padding
@param destBottom: ymax position because RDP can send bitmap with padding
@param width: width of bitmap
@param height: height of bitmap
@param bitsPerPixel: number of bit per pixel
@param isCompress: use RLE compression
@param data: bitmap data
"""
def onSessionReady(self):
"""
@summary: Windows session is ready
"""
def onClose(self):
"""
@summary: Call when stack is close
"""
return MyObserver(controller)
from twisted.internet import reactor
reactor.connectTCP("XXX.XXX.XXX.XXX", 3389, MyRDPFactory())
reactor.run()
from rdpy.protocol.rdp import rdp
class MyRDPFactory(rdp.ServerFactory):
def buildObserver(self, controller, addr):
class MyObserver(rdp.RDPServerObserver):
def onReady(self):
"""
@summary: Call when server is ready
to send and receive messages
"""
def onKeyEventScancode(self, code, isPressed):
"""
@summary: Event call when a keyboard event is catch in scan code format
@param code: scan code of key
@param isPressed: True if key is down
@see: rdp.RDPServerObserver.onKeyEventScancode
"""
def onKeyEventUnicode(self, code, isPressed):
"""
@summary: Event call when a keyboard event is catch in unicode format
@param code: unicode of key
@param isPressed: True if key is down
@see: rdp.RDPServerObserver.onKeyEventUnicode
"""
def onPointerEvent(self, x, y, button, isPressed):
"""
@summary: Event call on mouse event
@param x: x position
@param y: y position
@param button: 1, 2, 3, 4 or 5 button
@param isPressed: True if mouse button is pressed
@see: rdp.RDPServerObserver.onPointerEvent
"""
def onClose(self):
"""
@summary: Call when human client close connection
@see: rdp.RDPServerObserver.onClose
"""
return MyObserver(controller)
from twisted.internet import reactor
reactor.listenTCP(3389, MyRDPFactory())
reactor.run()
from rdpy.protocol.rfb import rfb
class MyRFBFactory(rfb.ClientFactory):
def clientConnectionLost(self, connector, reason):
reactor.stop()
def clientConnectionFailed(self, connector, reason):
reactor.stop()
def buildObserver(self, controller, addr):
class MyObserver(rfb.RFBClientObserver):
def onReady(self):
"""
@summary: Event when network stack is ready to receive or send event
"""
def onUpdate(self, width, height, x, y, pixelFormat, encoding, data):
"""
@summary: Implement RFBClientObserver interface
@param width: width of new image
@param height: height of new image
@param x: x position of new image
@param y: y position of new image
@param pixelFormat: pixefFormat structure in rfb.message.PixelFormat
@param encoding: encoding type rfb.message.Encoding
@param data: image data in accordance with pixel format and encoding
"""
def onCutText(self, text):
"""
@summary: event when server send cut text event
@param text: text received
"""
def onBell(self):
"""
@summary: event when server send biiip
"""
def onClose(self):
"""
@summary: Call when stack is close
"""
return MyObserver(controller)
from twisted.internet import reactor
reactor.connectTCP("XXX.XXX.XXX.XXX", 3389, MyRFBFactory())
reactor.run()