Skip to main content

powermole(gui) allows you to connect to a target destination host via one or more intermediaries, offering a variety of modes (FOR and TOR) and options (TRANSFER and COMMAND) to perform a variety of tasks

Project description

This program will let you perform port forwarding, redirect internet traffic, and transfer files to, and issue commands on, a host without making a direct connection (ie. via one or more intermediate hosts), which would undoubtedly compromise your privacy. This solution can only work when you or your peers own one or more hosts as this program communicates with SSH servers. This program can be viewed as a multi-versatile wrapper around SSH with the ProxyJump directive enabled. Powermole creates automatically a ssh/scp configuration file to enable key-based authentication with the intermediate hosts.

How it works

Terminology

  • Tunnel is an established connection from localhost to target destination host through intermediate hosts (called gateways).

  • Agent is a python module running on the target destination host. It performs various functions.

  • Instructor sends data and instructions to the Agent by utilizing a forwarded connection provided by Tunnel.

This cli package uses the lib package to create a Tunnel and models the specific Instructor to communicate with the Agent (on the target destination host). The Agent communicates directly with the operating system of the host on which it resides. The Agent is responsible to redirect internet traffic (TOR mode), put files (TRANSFER option), and issue commands (COMMAND option). For port forwarding (FOR mode), the program simply relies on SSH itself. The Agent also responds to heartbeats send by localhost to check if connection is still intact.

../img/illustration_how_it_works.png

For more details, including illustrations, please consult the powermole library on GitHub.

Requirements (functional)

  • The client program only works on macOS and Linux (tested Red Hat, CentOS, Fedora).

  • The intermediate hosts (gateways) must be Linux.

  • The client and all hosts have Python >3.6 as their default interpreter.

  • You need at least 1 gateway.

  • You have the associated SSH identification file (i.e. the private key) for these intermediaries.

  • Due to security reasons, SSH password login is not supported.

  • This program doesn’t require root privileges on the client (to be confirmed).

Requirements (software)

For Linux, install the following package on the client.

  • Tk interface library

    • dnf install python3-tkinter

For macOS, install the following package on the client

  • Tk interface library

    • brew install tcl-tk

Installation

If you use the standard packet manager:

$ pip install powermolegui

or if you use pipx:

$ pipx install powermolegui

Usage

Issue this command to actually execute the program.

$ powermolegui

Powermole allows you to enter one of the modes listed below. This is done by opening a Configuration file.

The JSON file contains directives to enter one of the modes listed below:

  • TOR mode

  • FOR(warding) mode

In TOR mode, the target destination host acts as an exit node (in TOR terminology).

../img/illustration_tor.png

In FOR(warding) mode, connections are forwarded to the target destination host, on which, for example, an email server (e.g. Postfix) is running and a local email client want to connect to its listening ports.

../img/illustration_forwarding.png

Configuration

To enable TOR mode

Edit the JSON document in the configuration file to incorporate the keywords mode, proxies, destination, and optionally application. When application is specified, then powermole will start the application of choice once the tunnel is ready. Please note, if an instance of that application (eg. Firefox) is already running, powermole will terminate immediately. In the example below, powermole drills through 2 intermediate hosts and ends at host #3. Hitting ctrl + c in terminal will dismantle the tunnel (and stop application)

{
"mode":         "TOR",
"gateways":    [{"host_ip": "192.168.10.2",
                 "user": "root",
                 "identity_file": "/Users/vincent/.ssh/id_rsa_pl"},
                {"host_ip": "192.168.10.3",
                 "user": "root",
                 "identity_file": "/Users/vincent/.ssh/id_rsa_cz"}],
"destination": {"host_ip": "192.168.10.4",
                "user": "root",
                "identity_file": "/Users/vincent/.ssh/id_rsa_nl"},
"application": {"binary_name": "firefox",
                "binary_location": "/usr/bin/firefox"}
}

To enable FOR(warding) mode

Edit the JSON document to incorporate the keywords mode, proxies, destination, forwarders, and optionally application. When application is specified, then powermole will start this application once the tunnel is ready. Please note, if an instance of that application (eg. Thunderbird) is already running, powermole will terminate immediately. In the example below, powermole drills through 1 intermediate host and ends at host #2. Hitting ctrl + c in terminal will dismantle the tunnel (and abort application).

{
"mode":         "FOR",
"gateways":    [{"host_ip": "192.168.10.2",
                 "user": "root",
                 "identity_file": "/Users/vincent/.ssh/id_rsa_pl"}],
"destination": {"host_ip": "192.168.10.3",
                "user": "root",
                "identity_file": "/Users/vincent/.ssh/id_rsa_cz"},
"forwarders": [{"local_port": 1587,
                "remote_interface": "localhost",
                "remote_port": 587},
               {"local_port": 1995,
                "remote_interface": "localhost",
                "remote_port": 995}]
}

Error

When running into issues, consider to investigate the log messages of type ‘debug’ sent to the shell and/or consult the log file in /tmp on destination host.

Development Workflow

The workflow supports the following steps

  • lint

  • test

  • build

  • document

  • upload

  • graph

These actions are supported out of the box by the corresponding scripts under _CI/scripts directory with sane defaults based on best practices. Sourcing setup_aliases.ps1 for windows powershell or setup_aliases.sh in bash on Mac or Linux will provide with handy aliases for the shell of all those commands prepended with an underscore.

The bootstrap script creates a .venv directory inside the project directory hosting the virtual environment. It uses pipenv for that. It is called by all other scripts before they do anything. So one could simple start by calling _lint and that would set up everything before it tried to actually lint the project

Once the code is ready to be delivered the _tag script should be called accepting one of three arguments, patch, minor, major following the semantic versioning scheme. So for the initial delivery one would call

$ _tag –minor

which would bump the version of the project to 0.1.0 tag it in git and do a push and also ask for the change and automagically update HISTORY.rst with the version and the change provided.

So the full workflow after git is initialized is:

  • repeat as necessary (of course it could be test - code - lint :) ) * code * lint * test

  • commit and push

  • develop more through the code-lint-test cycle

  • tag (with the appropriate argument)

  • build

  • upload (if you want to host your package in pypi)

  • document (of course this could be run at any point)

Important Information

This template is based on pipenv. In order to be compatible with requirements.txt so the actual created package can be used by any part of the existing python ecosystem some hacks were needed. So when building a package out of this do not simple call

$ python setup.py sdist bdist_egg

as this will produce an unusable artifact with files missing. Instead use the provided build and upload scripts that create all the necessary files in the artifact.

Documentation

Contributing

Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.

Authors

  • Vincent Schouten - Initial work - LINK

See also the list of contributors who participated in this project.

License

This project is licensed under the MIT License - see the LICENSE.md file for details

Acknowledgments

  • Costas Tyfoxylos

  • MisterDaneel (developer of pysoxy)

History

0.0.1 (08-10-2020)

  • First code creation

0.1.0 (26-03-2021)

  • Add several modules, add feature to create effects for canvas items, reword documentation, refactor two main window canvas attributes

0.2.0 (30-03-2021)

  • Add feature for a user to send commands, add code for changing the state of menu bar entries, document more comments and docstrings

0.2.1 (11-04-2021)

  • Add docstrings for adapter classes, bump dependency to latest powermole library package

0.2.2 (18-05-2021)

  • Refactor main window code for simplicity and readability

0.2.3 (25-05-2021)

  • Redraw Agent’s movement to be more accurate, refactor a bunch of public methods into protected ones, add docstrings for all canvas items, remove the creation of the canvas item objects during initialization, remove the scaling feature

0.2.4 (01-06-2021)

  • Reword status messages in status banner, reword documentation, bump dependency to latest powermole library package, add feature to set heartbeat interval value

0.2.5 (06-06-2021)

  • Bump dependency to latest powermole library package, fix bug to terminate the right thread, redraw animation for demo purposes, reword commit messages, add instructions how to execute powermolegui, reword list of keywords for PyPi

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

powermolegui-0.2.5.tar.gz (115.5 kB view details)

Uploaded Source

Built Distribution

powermolegui-0.2.5-py3.7.egg (105.7 kB view details)

Uploaded Source

File details

Details for the file powermolegui-0.2.5.tar.gz.

File metadata

  • Download URL: powermolegui-0.2.5.tar.gz
  • Upload date:
  • Size: 115.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.7.0 requests/2.25.1 setuptools/56.2.0 requests-toolbelt/0.9.1 tqdm/4.61.0 CPython/3.7.8

File hashes

Hashes for powermolegui-0.2.5.tar.gz
Algorithm Hash digest
SHA256 401ac9884dacabd06f033c0bd950ef334be4dbb8c422964346ab013aae5b954a
MD5 cfc19a7ac69f8d7126d3a8c1a6d818c3
BLAKE2b-256 64c03de483d464c8ea7e968e251c0a3992479a16c9edfb81da69e14ff5dfaa3a

See more details on using hashes here.

File details

Details for the file powermolegui-0.2.5-py3.7.egg.

File metadata

  • Download URL: powermolegui-0.2.5-py3.7.egg
  • Upload date:
  • Size: 105.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.7.0 requests/2.25.1 setuptools/56.2.0 requests-toolbelt/0.9.1 tqdm/4.61.0 CPython/3.7.8

File hashes

Hashes for powermolegui-0.2.5-py3.7.egg
Algorithm Hash digest
SHA256 eb602e3530d2a14df784c270390efe434432426022b7bc5f1dc7c9c6389f40f5
MD5 a1544d825e58106742c2be759959ff26
BLAKE2b-256 b72f41da16b9f3f444b4f233206fc5045b31be2e7c8ff546326a51c2e7431344

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page