|
1 | 1 | from ctypes import CDLL, POINTER, Structure, byref |
2 | 2 | from ctypes import c_char_p, c_int |
3 | 3 | from ctypes.util import find_library |
| 4 | +from flask import Flask, request, redirect |
4 | 5 |
|
5 | 6 |
|
6 | 7 | class PamHandle(Structure): |
@@ -38,26 +39,57 @@ class PamConv(Structure): |
38 | 39 | pam_acct_mgmt.argtypes = [PamHandle, c_int] |
39 | 40 |
|
40 | 41 |
|
41 | | -class pam(): |
| 42 | +def authenticate_bad_but_no_alert(self, username, service='login'): |
| 43 | + # This is not OK, but since we don't have flow from a remote-flow-source, we |
| 44 | + # don't give an alert. |
| 45 | + handle = PamHandle() |
| 46 | + conv = PamConv(None, 0) |
| 47 | + retval = pam_start(service, username, byref(conv), byref(handle)) |
| 48 | + retval = pam_authenticate(handle, 0) |
| 49 | + # NOT OK: no call to `pam_acct_mgmt` |
| 50 | + auth_success = retval == 0 |
42 | 51 |
|
43 | | - def authenticate_bad(self, username, service='login'): |
44 | | - handle = PamHandle() |
45 | | - conv = PamConv(None, 0) |
46 | | - retval = pam_start(service, username, byref(conv), byref(handle)) |
| 52 | + return auth_success |
47 | 53 |
|
48 | | - retval = pam_authenticate(handle, 0) |
49 | | - auth_success = retval == 0 |
50 | 54 |
|
51 | | - return auth_success |
| 55 | +def authenticate_good(self, username, service='login'): |
| 56 | + handle = PamHandle() |
| 57 | + conv = PamConv(None, 0) |
| 58 | + retval = pam_start(service, username, byref(conv), byref(handle)) |
52 | 59 |
|
53 | | - def authenticate_good(self, username, service='login'): |
54 | | - handle = PamHandle() |
55 | | - conv = PamConv(None, 0) |
56 | | - retval = pam_start(service, username, byref(conv), byref(handle)) |
| 60 | + retval = pam_authenticate(handle, 0) |
| 61 | + if retval == 0: |
| 62 | + retval = pam_acct_mgmt(handle, 0) |
| 63 | + auth_success = retval == 0 |
57 | 64 |
|
58 | | - retval = pam_authenticate(handle, 0) |
59 | | - if retval == 0: |
60 | | - retval = pam_acct_mgmt(handle, 0) |
61 | | - auth_success = retval == 0 |
| 65 | + return auth_success |
62 | 66 |
|
63 | | - return auth_success |
| 67 | + |
| 68 | +app = Flask(__name__) |
| 69 | +@app.route('/bad') |
| 70 | +def bad(): |
| 71 | + username = request.args.get('username', '') |
| 72 | + handle = PamHandle() |
| 73 | + conv = PamConv(None, 0) |
| 74 | + retval = pam_start(service, username, byref(conv), byref(handle)) |
| 75 | + |
| 76 | + retval = pam_authenticate(handle, 0) |
| 77 | + # NOT OK: no call to `pam_acct_mgmt` |
| 78 | + auth_success = retval == 0 |
| 79 | + |
| 80 | + return auth_success |
| 81 | + |
| 82 | + |
| 83 | +@app.route('/good') |
| 84 | +def good(): |
| 85 | + username = request.args.get('username', '') |
| 86 | + handle = PamHandle() |
| 87 | + conv = PamConv(None, 0) |
| 88 | + retval = pam_start(service, username, byref(conv), byref(handle)) |
| 89 | + |
| 90 | + retval = pam_authenticate(handle, 0) |
| 91 | + if retval == 0: |
| 92 | + retval = pam_acct_mgmt(handle, 0) |
| 93 | + auth_success = retval == 0 |
| 94 | + |
| 95 | + return auth_success |
0 commit comments