diff --git a/.gitignore b/.gitignore index 743e88b..a81c8ee 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,138 @@ +# Byte-compiled / optimized / DLL files __pycache__/ +*.py[cod] +*$py.class + +# C extensions +*.so + +# Distribution / packaging +.Python +build/ +develop-eggs/ +dist/ +downloads/ +eggs/ +.eggs/ +lib/ +lib64/ +parts/ +sdist/ +var/ +wheels/ +share/python-wheels/ +*.egg-info/ +.installed.cfg +*.egg +MANIFEST + +# PyInstaller +# Usually these files are written by a python script from a template +# before PyInstaller builds the exe, so as to inject date/other infos into it. +*.manifest +*.spec + +# Installer logs +pip-log.txt +pip-delete-this-directory.txt + +# Unit test / coverage reports +htmlcov/ +.tox/ +.nox/ +.coverage +.coverage.* +.cache +nosetests.xml +coverage.xml +*.cover +*.py,cover +.hypothesis/ +.pytest_cache/ +cover/ + +# Translations +*.mo +*.pot + +# Django stuff: +*.log +local_settings.py +db.sqlite3 +db.sqlite3-journal + +# Flask stuff: +instance/ +.webassets-cache + +# Scrapy stuff: +.scrapy + +# Sphinx documentation +docs/_build/ + +# PyBuilder +.pybuilder/ +target/ + +# Jupyter Notebook +.ipynb_checkpoints + +# IPython +profile_default/ +ipython_config.py + +# pyenv +# For a library or package, you might want to ignore these files since the code is +# intended to run in multiple environments; otherwise, check them in: +# .python-version + +# pipenv +# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control. +# However, in case of collaboration, if having platform-specific dependencies or dependencies +# having no cross-platform support, pipenv may install dependencies that don't work, or not +# install all needed dependencies. +#Pipfile.lock + +# PEP 582; used by e.g. github.com/David-OConnor/pyflow +__pypackages__/ + +# Celery stuff +celerybeat-schedule +celerybeat.pid + +# SageMath parsed files +*.sage.py + +# Environments +.env +.venv env/ +venv/ +ENV/ +env.bak/ +venv.bak/ + +# Spyder project settings +.spyderproject +.spyproject + +# Rope project settings +.ropeproject + +# mkdocs documentation +/site + +# mypy +.mypy_cache/ +.dmypy.json +dmypy.json + +# Pyre type checker +.pyre/ + +# pytype static type analyzer +.pytype/ + +# Cython debug symbols +cython_debug/ diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..e03fac3 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2021 Jamie Hill-Daniel + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/pyproject.toml b/pyproject.toml new file mode 100644 index 0000000..374b58c --- /dev/null +++ b/pyproject.toml @@ -0,0 +1,6 @@ +[build-system] +requires = [ + "setuptools>=42", + "wheel" +] +build-backend = "setuptools.build_meta" diff --git a/setup.py b/setup.py new file mode 100644 index 0000000..8e974dd --- /dev/null +++ b/setup.py @@ -0,0 +1,26 @@ +import setuptools + +with open("README.md", "r", encoding="utf-8") as fh: + long_description = fh.read() + +setuptools.setup( + name="wsshuttle", + version="0.0.1", + author="Jamie Hill-Daniel", + author_email="clubby789@gmail.com", + description="A tool to tunnel TCP via WinRM", + long_description=long_description, + long_description_content_type="text/markdown", + url="https://github.com/clubby789/wsshuttle", + project_urls={ + "Bug Tracker": "https://github.com/clubby789/wsshuttle/issues", + }, + classifiers=[ + "Programming Language :: Python :: 3", + "License :: OSI Approved :: MIT License", + "Operating System :: OS Independent", + ], + packages=["wsshuttle"], + python_requires=">=3.5", + install_requires=["pywinrm==0.4.2", "requests-ntlm"], +) diff --git a/wsshuttle/cmdline.py b/wsshuttle/cmdline.py index 484f5bb..ba0b952 100644 --- a/wsshuttle/cmdline.py +++ b/wsshuttle/cmdline.py @@ -1,6 +1,7 @@ import argparse import getpass import re +import warnings from .listener import WsshuttleListener @@ -8,12 +9,12 @@ def main() -> int: parser = argparse.ArgumentParser(prog="wsshuttle") - parser.add_argument("-u", "--username", required=True) - parser.add_argument("-p", "--password", default=None) + parser.add_argument("-u", "--username", required=True, help="Target username") + parser.add_argument("-p", "--password", default=None, help="Target user's password") parser.add_argument("-b", "--host", required=True, help="IP of this machine to backconnect to") parser.add_argument("-i", "--dest", required=True, help="Host to connect to") - parser.add_argument("-H", "--hash", default=None) - parser.add_argument("-m", "--mask", required=True) + parser.add_argument("-H", "--hash", default=None, help="NTLM hash") + parser.add_argument("-m", "--mask", required=True, help="Subnet mask to tunnel into") args = parser.parse_args() if args.hash and args.password: @@ -21,12 +22,14 @@ def main() -> int: return -1 if args.hash is not None: + print("WARNING: Using hash authentication currently requires installing an extra dependency - \n" + "pip3 install git+https://github.com/clubby789/requests-ntlm@pyspnego") ntlm = args.hash.lower() - if re.match("[a-z0-9]{32}"): + if re.match("[a-z0-9]{32}", ntlm): args.password = "0" * 32 + ":" + ntlm - elif re.match(":[a-z0-9]{32}"): + elif re.match(":[a-z0-9]{32}", ntlm): args.password = "0" * 32 + ntlm - elif re.match("[a-z0-9]{32}:[a-z0-9]{32}"): + elif re.match("[a-z0-9]{32}:[a-z0-9]{32}", ntlm): args.password = ntlm else: print("Invalid hash format")