diff --git a/accounts.json b/accounts.json new file mode 100644 index 0000000..f60de16 --- /dev/null +++ b/accounts.json @@ -0,0 +1,4 @@ +{ + "guest":"", + "user1":"secretpw" +} \ No newline at end of file diff --git a/ssh_server.py b/ssh_server.py index 86579a6..0067d68 100644 --- a/ssh_server.py +++ b/ssh_server.py @@ -2,22 +2,26 @@ # private key in it to use as a server host key. An SSH host certificate # can optionally be provided in the file ``ssh_host_key-cert.pub``. -import asyncio, asyncssh, crypt, sys +import asyncio +import asyncssh +import sys +import json from typing import Optional - -passwords = {'guest': '', # guest account with no password - 'user123': 'qV2iEadIGV2rw' # password of 'secretpw' - } +import logging +import datetime async def handle_client(process: asyncssh.SSHServerProcess) -> None: +# This is the main loop for handling SSH client connections. +# Any user interaction should be done here. + process.stdout.write('Welcome to my SSH server, %s!\n' % process.get_extra_info('username')) try: async for line in process.stdin: line = line.rstrip('\n') - if line: - process.stdout.write('You entered: %s\n' % line) + logging.info(f"INPUT: {line}") + process.stdout.write('You entered: %s\n' % line) except asyncssh.BreakReceived: pass @@ -25,36 +29,60 @@ async def handle_client(process: asyncssh.SSHServerProcess) -> None: class MySSHServer(asyncssh.SSHServer): def connection_made(self, conn: asyncssh.SSHServerConnection) -> None: - print('SSH connection received from %s.' % - conn.get_extra_info('peername')[0]) + logging.info(f"SSH connection received from {conn.get_extra_info('peername')[0]}.") def connection_lost(self, exc: Optional[Exception]) -> None: if exc: print('SSH connection error: ' + str(exc), file=sys.stderr) + logging.error('SSH connection error: ' + str(exc), file=sys.stderr) + else: print('SSH connection closed.') + logging.info("SSH connection closed.") def begin_auth(self, username: str) -> bool: # If the user's password is the empty string, no auth is required - return passwords.get(username) != '' + return accounts.get(username) != '' def password_auth_supported(self) -> bool: return True def validate_password(self, username: str, password: str) -> bool: - pw = passwords.get(username, '*') - return crypt.crypt(password, pw) == pw + pw = accounts.get(username, '*') + return ((pw != '*') and (password == pw)) async def start_server() -> None: await asyncssh.create_server(MySSHServer, '', 8022, server_host_keys=['ssh_host_key'], process_factory=handle_client) -loop = asyncio.get_event_loop() -try: - loop.run_until_complete(start_server()) -except (OSError, asyncssh.Error) as exc: - sys.exit('Error starting server: ' + str(exc)) +def read_accounts() -> dict: + accounts = dict() + + with open('accounts.json', 'r') as f: + accounts = json.loads(f.read()) + + return accounts + +#### MAIN #### + +# Set up the logging +logging.basicConfig( + filename="ssh_log.log", + level=logging.INFO, + format="%(asctime)s %(levelname)s:%(message)s", + datefmt="%Y-%m-%d %H:%M:%S. %Z" +) + +logging.Formatter.formatTime = (lambda self, record, datefmt=None: datetime.datetime.fromtimestamp(record.created, datetime.timezone.utc).astimezone().isoformat(sep="T",timespec="milliseconds")) + +# Read the valid accounts +accounts = read_accounts() + +# Kick off the server! +loop = asyncio.new_event_loop() +asyncio.set_event_loop(loop) +loop.run_until_complete(start_server()) +loop.run_forever() -loop.run_forever() \ No newline at end of file