Class: Msf::Handler::ReverseTcpDoubleSSL::TcpReverseDoubleSSLSessionChannel

Inherits:
Object
  • Object
show all
Includes:
Rex::IO::StreamAbstraction
Defined in:
lib/msf/core/handler/reverse_tcp_double_ssl.rb

Overview

This class wrappers the communication channel built over the two inbound connections, allowing input and output to be split across both.

Instance Attribute Summary

Attributes included from Rex::IO::StreamAbstraction

#lsock, #rsock

Instance Method Summary collapse

Methods included from Rex::IO::StreamAbstraction

#cleanup_abstraction, #initialize_abstraction, #localinfo, #peerinfo, #shutdown, #sysread, #syswrite

Constructor Details

#initialize(framework, inp, out) ⇒ TcpReverseDoubleSSLSessionChannel


229
230
231
232
233
234
235
236
237
238
239
240
241
# File 'lib/msf/core/handler/reverse_tcp_double_ssl.rb', line 229

def initialize(framework, inp, out)
  @framework = framework
  @sock_inp  = inp
  @sock_out  = out

  initialize_abstraction

  self.lsock.extend(TcpReverseDoubleSSLChannelExt)
  self.lsock.peerinfo  = @sock_inp.getpeername[1,2].map{|x| x.to_s}.join(":")
  self.lsock.localinfo = @sock_inp.getsockname[1,2].map{|x| x.to_s}.join(":")

  monitor_shell_stdout
end

Instance Method Details

#closeObject

Closes the stream abstraction and kills the monitor thread.


287
288
289
290
291
292
# File 'lib/msf/core/handler/reverse_tcp_double_ssl.rb', line 287

def close
  @monitor_thread.kill if (@monitor_thread)
  @monitor_thread = nil

  cleanup_abstraction
end

#monitor_shell_stdoutObject

Funnel data from the shell's stdout to rsock

StreamAbstraction#monitor_rsock will deal with getting data from the client (user input). From there, it calls our write() below, funneling the data to the shell's stdin on the other side.


250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
# File 'lib/msf/core/handler/reverse_tcp_double_ssl.rb', line 250

def monitor_shell_stdout

  # Start a thread to pipe data between stdin/stdout and the two sockets
  @monitor_thread = @framework.threads.spawn("ReverseTcpDoubleSSLHandlerMonitor", false) {
    begin
      while true
        # Handle data from the server and write to the client
        if (@sock_out.has_read_data?(0.50))
          buf = @sock_out.get_once
          break if buf.nil?
          rsock.put(buf)
        end
      end
    rescue ::Exception => e
      ilog("ReverseTcpDoubleSSL monitor thread raised #{e.class}: #{e}")
    end

    # Clean up the sockets...
    begin
      @sock_inp.close
      @sock_out.close
    rescue ::Exception
    end
  }
end

#read(length = 0, opts = {}) ⇒ Object


280
281
282
# File 'lib/msf/core/handler/reverse_tcp_double_ssl.rb', line 280

def read(length=0, opts={})
  @sock_out.read(length, opts)
end

#write(buf, opts = {}) ⇒ Object


276
277
278
# File 'lib/msf/core/handler/reverse_tcp_double_ssl.rb', line 276

def write(buf, opts={})
  @sock_inp.write(buf, opts)
end