a „oeÙã @sÒdZddlZddlZddlZddlZddlZddlZddlZddl Z dZ dd„Z dd„Z dd„Z Gd d „d ejƒZd d „Zd d„Zedk�rÎejded�Zejdddddd�ejddddd�ejdddddd�ejdddd d�e ¡\Z Zzee jƒe _Wn"eef�y$e d!¡Yn0z”zFe�s6dgZedd"k�rLeƒn edd#k�rbeƒn e d$¡Wn8e�y‚Yn&e�y”Yne ¡Yn0We j �rÎe!d%ƒne j �rÌe!d%ƒ0dS)&a#A sample socket server and client using SSPI authentication and encryption. You must run with either 'client' or 'server' as arguments. A server must be running before a client can connect. To use with Kerberos you should include in the client options --target-spn=username, where 'username' is the user under which the server is being run. Running either the client or server as a different user can be informative. A command-line such as the following may be useful: `runas /user:{user} {fqp}\python.exe {fqp}\socket_server.py --wait client|server` {fqp} should specify the relevant fully-qualified path names. To use 'runas' with Kerberos, the client program will need to specify --target-spn with the username under which the *server* is running. See the SSPI documentation for more details. éNc CsFz t ¡WStjy@}ztt tj¡ƒWYd}~Sd}~00dS©N)Úwin32apiÚ GetUserNameÚerrorÚreprZ GetUserNameExZNameSamCompatible)Údetails©rúHC:\Program Files\Certbot\pkgs\win32\Demos\security\sspi\socket_server.pyr$s rcCs$| t dt|ƒ¡¡| |¡dS)NÚi)ÚsendÚstructÚpackÚlen)ÚsÚmrrr Ú _send_msg2srcCs2| t d¡¡}|sdSt d|¡d}| |¡S)Nr r)Zrecvr ÚcalcsizeÚunpack)rZ size_dataÚcbrrr Ú_get_msg7s rc@s$eZdZdd„Zdd„Zdd„ZdS)ÚSSPISocketServercOs,tjj|g|¢Ri|¤Žt tj¡|_dSr)Ú socketserverÚ TCPServerÚ__init__ÚsspiZ ServerAuthÚoptionsÚpackageÚsa)ÚselfÚargsÚkwrrr r@szSSPISocketServer.__init__c Cs†|j ¡t|ƒ}|durdSz|j |¡\}}Wn2tjyd}ztd|ƒWYd}~dSd}~00|dkrpq‚t||djƒq dS)NFzFAILED to authorize client:rT) rÚresetrÚ authorizerrÚprintrÚBuffer)rÚsockÚcaÚdataÚerrZ sec_bufferrrrr Úverify_requestDs  zSSPISocketServer.verify_requestcCsžtdtƒƒ|jj ¡z\tdtƒƒt|ƒ}t|ƒ}|dusf|durHqf|j ||¡}tdt|ƒƒq&W|jj ¡n|jj ¡0|  |¡tdtƒƒdS)NzThe server is running as userz'Having conversation with client as userz Client sent:zThe server is back to user) r#rrZctxtZImpersonateSecurityContextrZdecryptrZRevertSecurityContextZ close_request)rZrequestZclient_addressr'Úkeyrrr Úprocess_requestVs    z SSPISocketServer.process_requestN)Ú__name__Ú __module__Ú __qualname__rr)r+rrrr r?srcCs$tdtjfdƒ}tdƒ| ¡dS)NÚ localhostzRunning test server...)rrÚportr#Z serve_forever)rrrr Úserveksr1cCs¶tj dtj¡}| ¡tjtjtj d�}d}|  |¡\}}t |j |dj ƒ|dkrXqdt|j ƒ}q.tdƒd ¡D]*}| |¡\}}t |j |ƒt |j |ƒqt|j  ¡tdƒdS)Nr/)Z targetspnrz5Auth dance complete - sending a few encryted messageszHello from the clientzClient completed.)ÚhttpÚclientZHTTPConnectionrr0ZconnectrZ ClientAuthrZ target_spnr"rr%r$rr#ÚsplitZencryptÚclose)Úcr&r'r(Zout_bufZblobr*rrr Ú sspi_clientqs     r7Ú__main__z%prog [options] client|server)Ú descriptionÚz --packageÚstoreZNTLMz8The SSPI package to use (eg, Kerberos) - default is NTLM)ÚactionÚdefaultÚhelpz --target-spnaLThe target security provider name to use. The string contents are security-package specific. For example, 'Kerberos' or 'Negotiate' require the server principal name (SPN) (ie, the username) of the remote process. For NTLM this must be blank.)r<r>z--portZ8181z%The port number to use (default=8181)z--waitÚ store_truezÞCause the program to wait for input just before terminating. Useful when using via runas to see any error messages before termination. z--port must be an integerr3Zserverz=You must supply 'client' or 'server' - use --help for detailszPress enter to continue)"Ú__doc__Z http.clientr2Zoptparserr Ú tracebackrrZ win32securityrrrrrrr1r7r,Z OptionParserÚparserZ add_optionÚ parse_argsrÚintr0Ú ValueErrorÚ TypeErrorrÚKeyboardInterruptÚ SystemExitÚ print_excÚwaitÚinputrrrr ÚsŠ, ûü ûü ÿ ÿ