403Webshell
Server IP : 3.96.16.70  /  Your IP : 216.73.216.15
Web Server : Apache
System : Linux ip-172-31-26-103.ca-central-1.compute.internal 6.1.163-186.299.amzn2023.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Feb 24 16:35:42 UTC 2026 x86_64
User : ec2-user ( 1000)
PHP Version : 8.4.18
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /lib/python3.9/site-packages/cloudinit/__pycache__/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /lib/python3.9/site-packages/cloudinit/__pycache__/ssh_util.cpython-39.pyc
a

ꬊh�N�@s�ddlZddlZddlmZddlmZe�e�ZdZ	dZ
dZdee�dZ
Gd	d
�d
e�ZGdd�de�Zd
d�Zdd�Zdd�Zdd�Zdd�Zdd�Ze	fdd�Zd)dd�ZGdd�de�Zdd �Zd!d"�Zd#d$�Ze	fd%d&�Zd'd(�ZdS)*�N)�log)�utilz/etc/ssh/sshd_config)ZdsaZrsaZecdsaZed25519z(ecdsa-sha2-nistp256-cert-v01@openssh.comzecdsa-sha2-nistp256z(ecdsa-sha2-nistp384-cert-v01@openssh.comzecdsa-sha2-nistp384z(ecdsa-sha2-nistp521-cert-v01@openssh.comzecdsa-sha2-nistp521z+sk-ecdsa-sha2-nistp256-cert-v01@openssh.comz"sk-ecdsa-sha2-nistp256@openssh.comz#sk-ssh-ed25519-cert-v01@openssh.comzsk-ssh-ed25519@openssh.comzssh-dss-cert-v01@openssh.comzssh-dssz ssh-ed25519-cert-v01@openssh.comzssh-ed25519zssh-rsa-cert-v01@openssh.comzssh-rsazssh-xmss-cert-v01@openssh.comzssh-xmss@openssh.com�z�no-port-forwarding,no-agent-forwarding,no-X11-forwarding,command="echo 'Please login as the user \"$USER\" rather than the user \"$DISABLE_USER\".';echo;sleep 10;exit �"c@s&eZdZddd�Zdd�Zdd�ZdS)	�AuthKeyLineNcCs"||_||_||_||_||_dS�N)�base64�comment�options�keytype�source)�selfrrrr	r
�r�6/usr/lib/python3.9/site-packages/cloudinit/ssh_util.py�__init__Fs
zAuthKeyLine.__init__cCs|jo
|jSr)rr�r
rrr�validOszAuthKeyLine.validcCsdg}|jr|�|j�|jr(|�|j�|jr:|�|j�|jrL|�|j�|sV|jSd�|�SdS�N� )r
�appendrrr	r�join)r
�toksrrr�__str__RszAuthKeyLine.__str__)NNNN)�__name__�
__module__�__qualname__rrrrrrrrEs�
	rc@s"eZdZdZdd�Zddd�ZdS)�AuthKeyLineParsera�
    AUTHORIZED_KEYS FILE FORMAT
     AuthorizedKeysFile specifies the file containing public keys for public
     key authentication; if none is specified, the default is
     ~/.ssh/authorized_keys.  Each line of the file contains one key (empty
     (because of the size of the public key encoding) up to a limit of 8 kilo-
     bytes, which permits DSA keys up to 8 kilobits and RSA keys up to 16
     kilobits.  You don't want to type them in; instead, copy the
     identity.pub, id_dsa.pub, or the id_rsa.pub file and edit it.

     sshd enforces a minimum RSA key modulus size for protocol 1 and protocol
     2 keys of 768 bits.

     The options (if present) consist of comma-separated option specifica-
     tions.  No spaces are permitted, except within double quotes.  The fol-
     lowing option specifications are supported (note that option keywords are
     case-insensitive):
    cCs�d}d}|t|�kr�|s$||dvr�||}|dt|�krF|d}q�||d}|dkrl|dkrl|d}n|dkrz|}|d}q|d|�}||d���}||fS)z�
        The options (if present) consist of comma-separated option specifica-
         tions.  No spaces are permitted, except within double quotes.
         Note that option keywords are case-insensitive.
        Fr)r�	��\rN)�len�lstrip)r
�entZquoted�iZcurcZnextcr
�remainrrr�_extract_optionsvs 

z"AuthKeyLineParser._extract_optionsNcCs�|�d�}|�d�s |��dkr(t|�Sdd�}|��}z||�\}}}Wn^ty�|�|�\}	}
|durr|	}z||
�\}}}Wnty�t|�YYS0Yn0t|||||d�S)Nz
�#�cSs^|�dd�}t|�dkr(tdt|���|dtvrDtd|d��t|�dkrZ|�d�|S)N�zTo few fields: %srzInvalid keytype %sr')�splitr �	TypeError�VALID_KEY_TYPESr)r"rrrr�
parse_ssh_key�s
z.AuthKeyLineParser.parse.<locals>.parse_ssh_key)rrr	r
)�rstrip�
startswith�striprr*r%)r
Zsrc_liner
�liner,r"rrr	Zkeyoptsr$rrr�parse�s,
�zAuthKeyLineParser.parse)N)rrr�__doc__r%r1rrrrrbsrc
Cszg}t�}g}|D]b}z8tj�|�rLt�|���}|D]}|�|�|��q6Wqt	t
fyrt�td|�Yq0q|S)NzError reading lines from %s)
r�os�path�isfiler�	load_file�
splitlinesrr1�IOError�OSError�logexc�LOG)�fnames�lines�parser�contents�fnamer0rrr�parse_authorized_keys�srAcCs�tdd�|D��}tdt|��D]J}||}|��s6q |D]&}|j|jkr:|}||vr:|�|�q:|||<q |D]}|�|�qpdd�|D�}|�d�d�|�S)NcSsg|]}|��r|�qSr)r��.0�krrr�
<listcomp>��z*update_authorized_keys.<locals>.<listcomp>rcSsg|]}t|��qSr��str)rC�brrrrE�rFr'�
)�list�ranger rr�removerr)Zold_entries�keysZto_addr#r"rD�keyr=rrr�update_authorized_keys�s 

rPcCs4t�|�}|r|js td|��tj�|jd�|fS)Nz"Unable to get SSH info for user %rz.ssh)�pwd�getpwnam�pw_dir�RuntimeErrorr3r4r)�username�pw_entrrr�users_ssh_info�s

rWc	Cspd|fd|fdf}|sd}|��}g}|D]@}|D]\}}|�||�}q2|�d�s`tj�||�}|�|�q*|S)N�%h�%u)z%%�%�%h/.ssh/authorized_keys�/)r)�replacer.r3r4rr)	�value�homedirrUZmacros�pathsZrenderedr4ZmacroZfieldrrr�render_authorizedkeysfile_paths�s
rac
Cs�d}|rd}t�|�}|r@||kr@|dkr@t�d||||�dSt�|�}||kr\|dM}n.t�|�}t�|�}	||	vr�|dM}n|dM}||@d	kr�t�d
|||�dS|r�|d@d	kr�t�d||�dSd
S)aVCheck if the file/folder in @current_path has the right permissions.

    We need to check that:
    1. If StrictMode is enabled, the owner is either root or the user
    2. the user can access the file/folder, otherwise ssh won't use it
    3. If StrictMode is enabled, no write permission is given to group
       and world users (022)
    i�i��rootzXPath %s in %s must be own by user %s or by root, but instead is own by %s. Ignoring key.F��8�rzBPath %s in %s must be accessible by user %s, check its permissions�zRPath %s in %s must not give writepermission to group or world users. Ignoring key.T)rZ	get_ownerr;�debugZget_permissionsZ	get_groupZget_user_groups)
rUZcurrent_path�	full_path�is_file�strictmodesZminimal_permissions�ownerZparent_permissionZgroup_ownerZuser_groupsrrr�check_permissionssJ
�




��rlc
Cst|�d}td�d}�z�|�d�dd�}d}tj�|j�}|D�]}|d|7}tj�|�rvt�d|�WdStj�	|�r�t�d|�WdS|�
|�sD||jkr�qDtj�|��s0t�
|��Zd	}	|j}
|j}|�
|j�r�d
}	|j}
|j}tj||	dd�t�||
|�Wd�n1�s&0Yt|||d|�}|sDWdSqDtj�|��sjtj�|��r|t�d
|�WdStj�|��s�tj|dddd�t�||j|j�t|||d|�}|�s�WdSWn<ttf�y}
zt�tt|
��WYd}
~
dSd}
~
00dS)Nrrbr\���r'z-Invalid directory. Symlink exists in path: %sFz*Invalid directory. File exists in path: %si�rcT)�mode�exist_okz%s is not a file!i�)rnZensure_dir_exists)rWr)r3r4�dirnamerS�islinkr;rgr5r.�existsr�SeLinuxGuardZpw_uidZpw_gid�makedirsZ	chownbyidrl�isdir�
write_filer8r9r:rH)rU�filenamerjZ
user_pwentZ
root_pwentZdirectoriesZ
parent_folderZhome_folderZ	directoryrnZuid�gidZpermissions�errr�check_create_pathHsn
����.
�

�
rzc
Cs4t|�\}}tj�|d�}|}g}tj|dd��vz2t|�}|�dd�}|�dd�}	t||j	|�}Wn2t
tfy�||d<t�t
d	t|d�Yn0Wd�n1s�0Yt|��|�D]J\}
}td
|
vd|
v|�d�|j	��g�r�t|||	dk�}|r�|}�qq�||k�r&t
�d
|�|t|g�fS)NZauthorized_keysT��	recursiveZauthorizedkeysfiler[rjZyesrzhFailed extracting 'AuthorizedKeysFile' in SSH config from %r, using 'AuthorizedKeysFile' file %r insteadrYrXz{}/zAAuthorizedKeysFile has an user-specific authorized_keys, using %s)rWr3r4rrrs�parse_ssh_config_map�getrarSr8r9r:r;�DEF_SSHD_CFG�zipr)�anyr.�formatrzrgrA)
rUZ
sshd_cfg_file�ssh_dirrVZdefault_authorizedkeys_fileZuser_authorizedkeys_fileZauth_key_fnsZssh_cfgZ	key_pathsrjZkey_path�auth_key_fnZpermissions_okrrr�extract_authorized_keys�sV���(
��
�
��r�c
Cs�t�}g}|D]}|�|jt|�|d��qt|�\}}tj�|�}tj	|dd��*t
||�}	tj||	dd�Wd�n1s�0YdS)N)r
Tr{�Z
preserve_mode)rrr1rHr�r3r4rprrsrPrv)
rNrUr
r>Zkey_entriesrDr�Zauth_key_entriesr�Zcontentrrr�setup_user_keys�s
r�c@s*eZdZddd�Zedd��Zdd�ZdS)	�SshdConfigLineNcCs||_||_||_dSr)r0�_keyr^)r
r0rD�vrrrr�szSshdConfigLine.__init__cCs|jdurdS|j��Sr)r��lowerrrrrrO�s
zSshdConfigLine.keycCs>|jdurt|j�St|j�}|jr6|dt|j�7}|SdSr)r�rHr0r^)r
r�rrrr�s


zSshdConfigLine.__str__)NN)rrrr�propertyrOrrrrrr��s

r�cCs"tj�|�sgStt�|����Sr)r3r4r5�parse_ssh_config_linesrr6r7)r@rrr�parse_ssh_config�sr�cCs�g}|D]�}|��}|r"|�d�r2|�t|��qz|�dd�\}}WnLty�z|�dd�\}}Wn$ty�t�d|�YYqYn0Yn0|�t|||��q|S)Nr&r�=z;sshd_config: option "%s" has no key/value pair, skipping it)r/r.rr�r)�
ValueErrorr;rg)r=�retr0rO�valrrrr��s&�r�cCs6t|�}|siSi}|D]}|js$q|j||j<q|Sr)r�rOr^)r@r=r�r0rrrr}sr}cCsHt|�}t||d�}|r<tj|d�dd�|D��ddd�t|�dkS)z�Read fname, and update if changes are necessary.

    @param updates: dictionary of desired values {Option: value}
    @return: boolean indicating if an update was done.)r=�updatesrJcSsg|]}t|��qSrrG)rCr0rrrrE-rFz%update_ssh_config.<locals>.<listcomp>Tr�r)r��update_ssh_config_linesrrvrr )r�r@r=�changedrrr�update_ssh_config#s�r�c	Cst�}g}tdd�|��D��}t|dd�D]v\}}|js<q,|j|vr,||j}||}|�|�|j|kr~t�d|||�q,|�	|�t�d|||j|�||_q,t
|�t
|�k�r|��D]B\}}||vr�q�|�	|�|�	td||��t�dt
|�||�q�|S)	z�Update the SSH config lines per updates.

    @param lines: array of SshdConfigLine.  This array is updated in place.
    @param updates: dictionary of desired values {Option: value}
    @return: A list of keys in updates that were changed.cSsg|]}|��|f�qSr)r�rBrrrrE=rFz+update_ssh_config_lines.<locals>.<listcomp>r)�startz$line %d: option %s already set to %sz#line %d: option %s updated %s -> %sr'z line %d: option %s added with %s)
�set�dictrN�	enumeraterO�addr^r;rgrr �itemsr�)	r=r��foundr�Zcasemapr#r0rOr^rrrr�3sB



�
�
�r�)N)r3rQZ	cloudinitrZloggingrZ	getLoggerrr;rr+Z_DISABLE_USER_SSH_EXITrHZDISABLE_USER_OPTS�objectrrrArPrWrarlrzr�r�r�r�r�r}r�r�rrrr�<module>	s:
���YEO9


Youez - 2016 - github.com/yon3zu
LinuXploit