2018-04-11 08:14:33 +00:00
|
|
|
#!/usr/bin/env python3.5
|
2016-02-05 15:03:37 +00:00
|
|
|
# -*-coding:UTF-8 -*
|
2017-05-09 09:13:16 +00:00
|
|
|
|
2016-02-05 15:03:37 +00:00
|
|
|
"""
|
2017-05-09 09:13:16 +00:00
|
|
|
The Keys Module
|
|
|
|
======================
|
|
|
|
|
|
|
|
This module is consuming the Redis-list created by the Global module.
|
|
|
|
|
2018-04-05 09:40:34 +00:00
|
|
|
It is looking for PGP, private and encrypted private,
|
|
|
|
RSA private key, certificate messages
|
2017-05-09 09:13:16 +00:00
|
|
|
|
2016-02-05 15:03:37 +00:00
|
|
|
"""
|
|
|
|
|
|
|
|
import time
|
|
|
|
from pubsublogger import publisher
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
from bin.packages import Paste
|
|
|
|
from bin.Helper import Process
|
2016-02-05 15:03:37 +00:00
|
|
|
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
def search_key(paste):
|
2016-02-05 15:03:37 +00:00
|
|
|
content = paste.get_p_content()
|
2018-04-05 09:40:34 +00:00
|
|
|
find = False
|
2018-04-11 08:14:33 +00:00
|
|
|
if b'-----BEGIN PGP MESSAGE-----' in content:
|
2016-02-05 15:03:37 +00:00
|
|
|
publisher.warning('{} has a PGP enc message'.format(paste.p_name))
|
2018-04-05 09:40:34 +00:00
|
|
|
find = True
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
if b'-----BEGIN CERTIFICATE-----' in content:
|
2018-04-05 09:40:34 +00:00
|
|
|
publisher.warning('{} has a certificate message'.format(paste.p_name))
|
|
|
|
find = True
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
if b'-----BEGIN RSA PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has a RSA private key message'.format(paste.p_name))
|
2018-04-05 09:40:34 +00:00
|
|
|
find = True
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
if b'-----BEGIN PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has a private key message'.format(paste.p_name))
|
2018-04-05 09:40:34 +00:00
|
|
|
find = True
|
|
|
|
|
2018-04-11 08:14:33 +00:00
|
|
|
if b'-----BEGIN ENCRYPTED PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has an encrypted private key message'.format(paste.p_name))
|
|
|
|
find = True
|
|
|
|
|
|
|
|
if b'-----BEGIN OPENSSH PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has an openssh private key message'.format(paste.p_name))
|
|
|
|
find = True
|
|
|
|
|
|
|
|
if b'-----BEGIN DSA PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has a dsa private key message'.format(paste.p_name))
|
|
|
|
find = True
|
|
|
|
|
|
|
|
if b'-----BEGIN EC PRIVATE KEY-----' in content:
|
|
|
|
publisher.warning('{} has an ec private key message'.format(paste.p_name))
|
|
|
|
find = True
|
|
|
|
|
|
|
|
if b'-----BEGIN PGP PRIVATE KEY BLOCK-----' in content:
|
|
|
|
publisher.warning('{} has a pgp private key block message'.format(paste.p_name))
|
2018-04-05 09:40:34 +00:00
|
|
|
find = True
|
|
|
|
|
|
|
|
if find :
|
|
|
|
|
2016-07-18 14:22:33 +00:00
|
|
|
#Send to duplicate
|
2016-08-08 07:17:44 +00:00
|
|
|
p.populate_set_out(message, 'Duplicate')
|
|
|
|
#send to Browse_warning_paste
|
2017-11-15 15:15:43 +00:00
|
|
|
p.populate_set_out('keys;{}'.format(message), 'alertHandler')
|
2016-02-05 15:03:37 +00:00
|
|
|
|
|
|
|
|
|
|
|
if __name__ == '__main__':
|
|
|
|
# If you wish to use an other port of channel, do not forget to run a subscriber accordingly (see launch_logs.sh)
|
|
|
|
# Port of the redis instance used by pubsublogger
|
|
|
|
publisher.port = 6380
|
|
|
|
# Script is the default channel used for the modules.
|
|
|
|
publisher.channel = 'Script'
|
|
|
|
|
|
|
|
# Section name in bin/packages/modules.cfg
|
|
|
|
config_section = 'Keys'
|
|
|
|
|
|
|
|
# Setup the I/O queues
|
|
|
|
p = Process(config_section)
|
|
|
|
|
|
|
|
# Sent to the logging a description of the module
|
|
|
|
publisher.info("Run Keys module ")
|
|
|
|
|
|
|
|
# Endless loop getting messages from the input queue
|
|
|
|
while True:
|
|
|
|
# Get one message from the input queue
|
|
|
|
message = p.get_from_set()
|
|
|
|
if message is None:
|
|
|
|
publisher.debug("{} queue is empty, waiting".format(config_section))
|
|
|
|
time.sleep(1)
|
|
|
|
continue
|
|
|
|
|
|
|
|
# Do something with the message from the queue
|
2018-04-11 08:14:33 +00:00
|
|
|
paste = Paste.Paste(message)
|
|
|
|
search_key(paste)
|
2016-02-05 15:03:37 +00:00
|
|
|
|
|
|
|
# (Optional) Send that thing to the next queue
|