a library that is responsible of modeling objects to connect to another host via one or more intermediaries, offering a variety of modes (FOR and TOR) and options (TRANSFER and COMMAND)
Project description
This package contains building blocks to make an encrypted connection via one or more intermediate hosts possible. The underlying foundation is SSH with the ProxyJump directive enabled. This package also contains modules that provides a variety of services. For simplicity, all modules are designed in a functional manner.
The power of SSH is harnessed by the transferagent.py and tunnel.py modules. These modules are responsible for copying the Agent (agent.py) to the destination host and setting up tunneling. Once tunneling is established, the Agent is executed by the Bootstrap Agent (bootstrapagent.py) by utilizing the stdin of Tunnel. The Instructor (instructor.py) is responsible for starting and stopping services provided by the Agent. These services includes: redirection of internet traffic (TOR mode), copying files (FILE option), and issuing commands (COMMAND option). For port forwarding (FOR mode), the program simply relies on SSH itself. The Instructor communicates with the Agent by sending JSON messages over the forwarded connection provided by Tunnel. The Agent also responds to heartbeats send by localhost to check if connection is still intact.
Use the package powermolecli or powermolegui to interact with this library.
How it works
Terminology
Tunnel is an established connection from localhost to the target destination host through intermediate hosts (called Gateways).
Agent is a python module running on the target destination host. It performs various functions.
Instructor sends instructions to the Agent by utilizing a forwarded connection provided by Tunnel.
The program uses ssh to connect to the last host via one or more intermediaries.
Through port forwarding, the program can communicate with the agent on the last host.
The Instructor in conjuction with the Agent provides two modes:
TOR mode
FOR(warding) mode
Regardless which mode is enabled, several options are presented when the the tunnel is established:
COMMAND: this option provides a rudimentary terminal interface to provide access to OS services on the target destination host.
TRANSFER: this options allows selected files to be transferred to the target destination host.
See cli package for applications (uses).
Logging
Consult the log file in /tmp on destination host when the bootstrap process of the Agent fails. In addition, consider to start powermolecli with log-level = ‘debug’.
Development Workflow
The workflow supports the following steps
lint
test
build
document
upload
graph
These actions are supported out of the box by the corresponding scripts under _CI/scripts directory with sane defaults based on best practices. Sourcing setup_aliases.ps1 for windows powershell or setup_aliases.sh in bash on Mac or Linux will provide with handy aliases for the shell of all those commands prepended with an underscore.
The bootstrap script creates a .venv directory inside the project directory hosting the virtual environment. It uses pipenv for that. It is called by all other scripts before they do anything. So one could simple start by calling _lint and that would set up everything before it tried to actually lint the project
Once the code is ready to be delivered the _tag script should be called accepting one of three arguments, patch, minor, major following the semantic versioning scheme. So for the initial delivery one would call
$ _tag –minor
which would bump the version of the project to 0.1.0 tag it in git and do a push and also ask for the change and automagically update HISTORY.rst with the version and the change provided.
So the full workflow after git is initialized is:
repeat as necessary (of course it could be test - code - lint :) ) * code * lint * test
commit and push
develop more through the code-lint-test cycle
tag (with the appropriate argument)
build
upload (if you want to host your package in pypi)
document (of course this could be run at any point)
Important Information
This template is based on pipenv. In order to be compatible with requirements.txt so the actual created package can be used by any part of the existing python ecosystem some hacks were needed. So when building a package out of this do not simple call
$ python setup.py sdist bdist_egg
as this will produce an unusable artifact with files missing. Instead use the provided build and upload scripts that create all the necessary files in the artifact.
Documentation
Documentation: https://powermolelib.readthedocs.org/en/latest
Contributing
Please read CONTRIBUTING.md for details on our code of conduct, and the process for submitting pull requests to us.
License
This project is licensed under the MIT License - see the LICENSE.md file for details
Acknowledgments
rofl0r (developer of proxychains-ng)
Costas Tyfoxylos
History
0.0.1 (13-05-2020)
First code creation
0.1.0 (13-05-2020)
first commit
0.1.1 (13-05-2020)
pypi complains filename has been used, increment version
0.1.2 (15-05-2020)
debug mode added + logger_basename given a correct name
1.0.0 (16-05-2020)
tunnel.py is heavily refactored: 1) instead of assigning individual ports to the instance a dictionary is used, 2) a new method is created named periodically_purge_buffer() which should be called once from the cli + agentassistant.py is renamed to instructor.py
1.0.1 (16-05-2020)
_run_purger() modified to include try block + text updated
2.0.0 (16-05-2020)
Assistant() renamed to Instructor() and start() of transferagent modified (due to bugfix: the agent module could never be copied successfully)
2.0.1 (04-07-2020)
scp versions released after 21 Apr 2020 breaks when using the ProxyJump directive. this error is shown during execution of powermole when user has a newer scp installed. at this moment no solution how to deal with this issue.
2.1.0 (04-07-2020)
bug fixed: powermole crashed when using 1 intermediary host
2.2.0 (04-07-2020)
bug fixed: program didn’t work using >1 intermediary hosts
2.2.1 (31-10-2020)
forwardering string enclosed with quotes (for IPv6), timeout for establishing SSH conn. increased to 10s, requirements updated for prospector
3.0.0 (26-03-2021)
PLAIN mode added and COMMAND and TRANSFER (previously FILE) modes are turned into methods + Tunnel() and TransferAgent() are refactored to appened authenticated hosts to the instance variable authenticated_hosts.
3.0.1 (30-03-2021)
_issue_command() in agent.py refactored: finally in try/except block added
3.0.2 (11-04-2021)
SocketServer, DataProtocol and related components in instructor.py and agent.py completely refactored + created new Logging module
3.1.0 (26-04-2021)
Refactor the code to make bootstrapping the Agent more robust
3.1.1 (17-05-2021)
Refactor SOCKS proxy server code for readability
3.1.2 (17-05-2021)
Change version of Python interpreter
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file powermolelib-3.1.2.tar.gz
.
File metadata
- Download URL: powermolelib-3.1.2.tar.gz
- Upload date:
- Size: 106.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/1.13.0 pkginfo/1.6.1 requests/2.24.0 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.51.0 CPython/3.7.8
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | f9182762939c80b83ffab01477b2cea804c2a5c47449f1d8dfd1ed8d762220e4 |
|
MD5 | 1aa364457e9ec0083b02aab321401ee3 |
|
BLAKE2b-256 | dae6cfa77bb11829835f933781588f672eb5e1d7b87dce8efbb9411d97a94c3a |
File details
Details for the file powermolelib-3.1.2-py3.7.egg
.
File metadata
- Download URL: powermolelib-3.1.2-py3.7.egg
- Upload date:
- Size: 97.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/1.13.0 pkginfo/1.6.1 requests/2.24.0 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.51.0 CPython/3.7.8
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 55e65fc474c68d599661c19cc16cc8ea6d19e8031f7d318a734e95207f1dc584 |
|
MD5 | 3a0c1a2a35203968fe349feda34a643e |
|
BLAKE2b-256 | a2878d8ed78c259c1ae80ca2f3ae27902c3977d0d2eff441644e2c1fe49f048d |