Module: PWN::Plugins::ProcessTube
- Defined in:
- lib/pwn/plugins/process_tube.rb
Overview
PTY.spawn tube: sendline/recvuntil/recvline, persisted across pwn_eval.
Constant Summary collapse
- BUF_MAX =
1_048_576
Class Method Summary collapse
- .authors ⇒ Object
- .close(opts = {}) ⇒ Object
- .connect(opts = {}) ⇒ Object
- .expect(opts = {}) ⇒ Object
- .help ⇒ Object
- .kill(opts = {}) ⇒ Object
- .list(opts = {}) ⇒ Object
- .reap_orphans(opts = {}) ⇒ Object
- .recv(opts = {}) ⇒ Object
- .recvline(opts = {}) ⇒ Object
- .recvuntil(opts = {}) ⇒ Object
- .register(opts = {}) ⇒ Object
- .required_bins ⇒ Object
- .send_line(opts = {}) ⇒ Object
- .send_raw(opts = {}) ⇒ Object
- .sendline(opts = {}) ⇒ Object
- .spawn(opts = {}) ⇒ Object
- .stream(opts = {}) ⇒ Object
- .write_line(opts = {}) ⇒ Object
Class Method Details
.authors ⇒ Object
216 217 218 |
# File 'lib/pwn/plugins/process_tube.rb', line 216 public_class_method def self. "AUTHOR(S):\n 0day Inc. <[email protected]>\n" end |
.close(opts = {}) ⇒ Object
113 114 115 116 117 118 119 120 121 122 123 124 |
# File 'lib/pwn/plugins/process_tube.rb', line 113 public_class_method def self.close(opts = {}) t = tube!(opts) dump_scrollback(tube: t, id: opts[:id] || opts[:name]) t[:w].close t[:r].close Process.kill('TERM', t[:pid]) if t[:pid] @tubes.delete((opts[:id] || opts[:name]).to_s) true rescue StandardError @tubes.delete((opts[:id] || opts[:name]).to_s) false end |
.connect(opts = {}) ⇒ Object
39 40 41 42 43 44 45 46 47 48 |
# File 'lib/pwn/plugins/process_tube.rb', line 39 public_class_method def self.connect(opts = {}) host = (opts[:host] || opts[:target]).to_s port = opts[:port].to_i raise 'ERROR: host and port are required' if host.empty? || port <= 0 sock = TCPSocket.new(host, port) id = "sock_#{sock.object_id}" @tubes[id] = { r: sock, w: sock, pid: nil, buf: +'', scrollback: +'', started_at: Time.now, last_io: Time.now } { id: id, host: host, port: port } end |
.expect(opts = {}) ⇒ Object
148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 |
# File 'lib/pwn/plugins/process_tube.rb', line 148 public_class_method def self.expect(opts = {}) t = tube!(opts) pattern = opts[:pattern] || opts[:until] raise ArgumentError, 'pattern is required' if pattern.nil? || pattern.to_s.empty? timeout = (opts[:timeout] || 5).to_f Timeout.timeout(timeout) do loop do hay = t[:buf].to_s hay = hay.gsub(/\e\[[0-9;]*[A-Za-z]/, '') if opts[:strip_ansi] if pattern.is_a?(Regexp) if (m = hay.match(pattern)) consume_buf(tube: t, bytes: m.end(0)) return { matched: m[0], offset: m.begin(0), id: (opts[:id] || opts[:name]).to_s } end elsif (idx = hay.index(pattern.to_s)) take = consume_buf(tube: t, bytes: idx + pattern.to_s.bytesize) return { matched: take, offset: idx, id: (opts[:id] || opts[:name]).to_s } end ch = t[:r].read_nonblock(4_096) append_buf(tube: t, data: ch) rescue IO::WaitReadable t[:r].wait_readable(0.2) retry end end end |
.help ⇒ Object
220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 |
# File 'lib/pwn/plugins/process_tube.rb', line 220 public_class_method def self.help puts "USAGE: # List host binaries this module expects to be installed. #{self}.required_bins # Run spawn and return its result #{self}.spawn( cmd: 'required - command string to run (defaults to opts[:command])', command: 'optional - command value consumed by #spawn', name: 'optional - persistent session name reused across tool calls', pty: 'optional - false uses pipes for binary IO (defaults to PTY)' ) # Connect a TCP tube with the same write_line/recvuntil API as spawn. #{self}.connect( host: 'required - hostname or IP address (defaults to opts[:target])', target: 'optional - hostname, IP, or CIDR to scan', port: 'required - TCP/UDP port number' ) # Expect-style alias of write_line. #{self}.send_line( id: 'required - tube id from spawn or connect', name: 'optional - alias for id', line: 'optional - line to write (newline appended)', data: 'optional - alias for line' ) # Run write line and return its result #{self}.write_line( line: 'optional - line value consumed by #write_line', data: 'optional - data value consumed by #write_line' ) # Run recvuntil and return its result #{self}.recvuntil( until: 'required - until value consumed by #recvuntil', timeout: 'optional - seconds to wait before giving up' ) # Run recvline and return its result #{self}.recvline # pwntools-style alias of write_line. #{self}.sendline( id: 'required - tube id from spawn or connect', line: 'optional - line to write', data: 'optional - alias for line' ) # Read up to n bytes from a tube. #{self}.recv( id: 'required - tube id from spawn or connect', n: 'optional - byte count (defaults to 4096)', bytes: 'optional - alias for n', timeout: 'optional - seconds to wait before giving up' ) # Close a session previously returned by #open. #{self}.close( id: 'optional - id value consumed by #close' ) # Expect a regex or substring, optionally stripping ANSI. #{self}.expect( id: 'required - tube id from spawn or connect', name: 'optional - alias for id', until: 'optional - substring to wait for', pattern: 'optional - regex or string to wait for', timeout: 'optional - seconds to wait before giving up', strip_ansi: 'optional - true removes CSI sequences before matching' ) # Write raw bytes without appending a newline. #{self}.send_raw( id: 'required - tube id from spawn or connect', name: 'optional - alias for id', bytes: 'required - String or byte Array to write', data: 'optional - alias for bytes' ) # Register an existing IO as a named tube. #{self}.register( io: 'required - readable/writable IO object', r: 'optional - alias for io', w: 'optional - write IO when split from r', id: 'optional - tube name to assign', pid: 'optional - associated process id' ) # Tail the PTY buffer since a prior offset. #{self}.stream( id: 'required - tube id from spawn or connect', offset: 'optional - byte offset to start from (defaults to 0)' ) # Close every open tube (session end / orphan GC). #{self}.reap_orphans( session_id: 'optional - agent session id for transcript grouping' ) # List live tubes with age. #{self}.list( idle: 'optional - unused reserved idle-seconds filter' ) # SIGTERM then close a tube by id. #{self}.kill( id: 'required - tube id from spawn or connect' ) # Print the AUTHOR(S) string for this module. #{self}.authors " constants.sort end |
.kill(opts = {}) ⇒ Object
204 205 206 207 208 209 210 211 212 213 214 |
# File 'lib/pwn/plugins/process_tube.rb', line 204 public_class_method def self.kill(opts = {}) id = opts[:id].to_s t = @tubes[id] return { ok: false, id: id } unless t Process.kill('TERM', t[:pid]) if t[:pid] close(id: id) { ok: true, id: id } rescue StandardError => e { ok: false, id: id, error: e. } end |
.list(opts = {}) ⇒ Object
196 197 198 199 200 201 202 |
# File 'lib/pwn/plugins/process_tube.rb', line 196 public_class_method def self.list(opts = {}) _idle = opts[:idle] now = Time.now @tubes.map do |id, t| { id: id, pid: t[:pid], started_at: t[:started_at], last_io: t[:last_io], age_s: (now - (t[:started_at] || now)).to_i } end end |
.reap_orphans(opts = {}) ⇒ Object
188 189 190 191 192 193 194 |
# File 'lib/pwn/plugins/process_tube.rb', line 188 public_class_method def self.reap_orphans(opts = {}) _sid = opts[:session_id] n = @tubes.length @tubes.each_key { |id| close(id: id) } @tubes.clear n end |
.recv(opts = {}) ⇒ Object
58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 |
# File 'lib/pwn/plugins/process_tube.rb', line 58 public_class_method def self.recv(opts = {}) t = tube!(opts) want = (opts[:n] || opts[:bytes] || 4_096).to_i timeout = (opts[:timeout] || 5).to_f Timeout.timeout(timeout) do loop do return consume_buf(tube: t, bytes: want) if t[:buf].bytesize >= want || (opts[:n].nil? && !t[:buf].empty? && !t[:r].wait_readable(0)) ch = t[:r].read_nonblock(4_096) append_buf(tube: t, data: ch) rescue IO::WaitReadable t[:r].wait_readable(0.2) retry rescue EOFError return consume_buf(tube: t, bytes: t[:buf].bytesize) end end end |
.recvline(opts = {}) ⇒ Object
109 110 111 |
# File 'lib/pwn/plugins/process_tube.rb', line 109 public_class_method def self.recvline(opts = {}) recvuntil(opts.merge(until: "\n")) end |
.recvuntil(opts = {}) ⇒ Object
87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 |
# File 'lib/pwn/plugins/process_tube.rb', line 87 public_class_method def self.recvuntil(opts = {}) t = tube!(opts) needle = opts[:until].to_s raise 'ERROR: until is required' if needle.empty? timeout = (opts[:timeout] || 5).to_f Timeout.timeout(timeout) do loop do idx = t[:buf].index(needle) return consume_buf(tube: t, bytes: idx + needle.bytesize) if idx ch = t[:r].read_nonblock(4_096) append_buf(tube: t, data: ch) rescue IO::WaitReadable t[:r].wait_readable(0.2) retry rescue EOFError return consume_buf(tube: t, bytes: t[:buf].bytesize) end end end |
.register(opts = {}) ⇒ Object
139 140 141 142 143 144 145 146 |
# File 'lib/pwn/plugins/process_tube.rb', line 139 public_class_method def self.register(opts = {}) io = opts[:io] || opts[:r] raise ArgumentError, 'io is required' unless io id = (opts[:id] || "sock_#{SecureRandom.hex(4)}").to_s @tubes[id] = { r: io, w: opts[:w] || io, pid: opts[:pid], buf: +'', scrollback: +'', started_at: Time.now, last_io: Time.now } { id: id } end |
.required_bins ⇒ Object
15 16 17 |
# File 'lib/pwn/plugins/process_tube.rb', line 15 public_class_method def self.required_bins [] end |
.send_line(opts = {}) ⇒ Object
50 51 52 |
# File 'lib/pwn/plugins/process_tube.rb', line 50 public_class_method def self.send_line(opts = {}) write_line(opts) end |
.send_raw(opts = {}) ⇒ Object
126 127 128 129 130 131 132 133 134 135 136 137 |
# File 'lib/pwn/plugins/process_tube.rb', line 126 public_class_method def self.send_raw(opts = {}) t = tube!(opts) bytes = opts[:bytes] || opts[:data] raise ArgumentError, 'bytes is required' if bytes.nil? data = bytes.is_a?(String) ? bytes.b : Array(bytes).pack('C*') t[:w].write(data) t[:w].flush t[:last_io] = Time.now note_scrollback(tube: t, data: data) { written: data.bytesize, id: (opts[:id] || opts[:name]).to_s } end |
.sendline(opts = {}) ⇒ Object
54 55 56 |
# File 'lib/pwn/plugins/process_tube.rb', line 54 public_class_method def self.sendline(opts = {}) write_line(opts) end |
.spawn(opts = {}) ⇒ Object
19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 |
# File 'lib/pwn/plugins/process_tube.rb', line 19 public_class_method def self.spawn(opts = {}) cmd = opts[:cmd] || opts[:command] raise 'ERROR: cmd is required' if cmd.to_s.empty? argv = cmd.is_a?(Array) ? cmd.map(&:to_s) : ['bash', '-lc', cmd.to_s] name = (opts[:name] || "tube_#{SecureRandom.hex(4)}").to_s if opts[:pty] == false stdin, stdout, waiter = Open3.popen2(*argv) stdin.binmode stdout.binmode @tubes[name] = { r: stdout, w: stdin, pid: waiter.pid, buf: +'', started_at: Time.now, last_io: Time.now, name: name, scrollback: +'', wait: waiter } return { id: name, pid: waiter.pid, name: name, pty: false } end r, w, pid = PTY.spawn(*argv) name = (opts[:name] || "tube_#{pid}").to_s @tubes[name] = { r: r, w: w, pid: pid, buf: +'', started_at: Time.now, last_io: Time.now, name: name, scrollback: +'' } { id: name, pid: pid, name: name, pty: true } end |
.stream(opts = {}) ⇒ Object
176 177 178 179 180 181 182 183 184 185 186 |
# File 'lib/pwn/plugins/process_tube.rb', line 176 public_class_method def self.stream(opts = {}) t = tube!(opts) off = opts[:offset].to_i begin t[:buf] << t[:r].read_nonblock(4_096) rescue IO::WaitReadable, EOFError nil end data = t[:buf].to_s.byteslice(off..-1).to_s { data: data, offset: t[:buf].to_s.bytesize, id: opts[:id].to_s } end |
.write_line(opts = {}) ⇒ Object
77 78 79 80 81 82 83 84 85 |
# File 'lib/pwn/plugins/process_tube.rb', line 77 public_class_method def self.write_line(opts = {}) t = tube!(opts) line = opts[:line] || opts[:data] || '' t[:w].write("#{line}\n") t[:w].flush t[:last_io] = Time.now t[:scrollback] = (t[:scrollback].to_s + "#{line}\n")[-65_536, 65_536] || (t[:scrollback].to_s + "#{line}\n") line.to_s end |