2022-02-27 07:53:44 -05:00
|
|
|
#include <STDInclude.hpp>
|
2023-01-03 07:16:44 -05:00
|
|
|
#include <proto/rcon.pb.h>
|
|
|
|
|
2023-05-15 18:27:37 -04:00
|
|
|
#include "Events.hpp"
|
2022-12-26 07:07:24 -05:00
|
|
|
#include "RCon.hpp"
|
2023-01-03 07:16:44 -05:00
|
|
|
#include "Party.hpp"
|
2017-01-19 16:23:59 -05:00
|
|
|
|
|
|
|
namespace Components
|
|
|
|
{
|
2022-12-16 16:48:52 -05:00
|
|
|
std::unordered_map<std::uint32_t, int> RCon::RateLimit;
|
|
|
|
|
2023-03-04 12:40:28 -05:00
|
|
|
std::vector<std::size_t> RCon::RconAddresses;
|
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
RCon::Container RCon::RconContainer;
|
|
|
|
Utils::Cryptography::ECC::Key RCon::RconKey;
|
2017-01-19 16:23:59 -05:00
|
|
|
|
|
|
|
std::string RCon::Password;
|
|
|
|
|
2022-03-03 11:37:18 -05:00
|
|
|
Dvar::Var RCon::RconPassword;
|
|
|
|
Dvar::Var RCon::RconLogRequests;
|
2023-02-10 10:04:19 -05:00
|
|
|
Dvar::Var RCon::RconTimeout;
|
2022-03-03 11:37:18 -05:00
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
void RCon::AddCommands()
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2023-05-06 09:20:56 -04:00
|
|
|
Command::Add("rcon", [](const Command::Params* params)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-03-17 14:50:20 -04:00
|
|
|
if (params->size() < 2) return;
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-03-17 14:50:20 -04:00
|
|
|
const auto* operation = params->get(1);
|
|
|
|
if (std::strcmp(operation, "login") == 0)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-03-17 14:50:20 -04:00
|
|
|
if (params->size() < 3) return;
|
2022-10-19 10:28:53 -04:00
|
|
|
Password = params->get(2);
|
|
|
|
return;
|
2017-01-19 16:23:59 -05:00
|
|
|
}
|
2022-10-19 10:28:53 -04:00
|
|
|
|
|
|
|
if (std::strcmp(operation, "logout") == 0)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
Password.clear();
|
|
|
|
return;
|
2017-01-19 16:23:59 -05:00
|
|
|
}
|
2022-10-19 10:28:53 -04:00
|
|
|
|
2022-11-16 12:25:21 -05:00
|
|
|
auto* addr = reinterpret_cast<Game::netadr_t*>(0xA5EA44);
|
2022-10-19 10:28:53 -04:00
|
|
|
if (Password.empty())
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
Logger::Print("You need to be logged in and connected to a server!\n");
|
|
|
|
}
|
|
|
|
|
|
|
|
Network::Address target(addr);
|
|
|
|
if (!target.isValid() || target.getIP().full == 0)
|
|
|
|
{
|
|
|
|
target = Party::Target();
|
|
|
|
}
|
|
|
|
|
|
|
|
if (target.isValid())
|
|
|
|
{
|
|
|
|
Network::SendCommand(target, "rcon", Password + " " + params->join(1));
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
Logger::Print("You are connected to an invalid server\n");
|
|
|
|
});
|
|
|
|
|
2023-05-06 09:20:56 -04:00
|
|
|
Command::Add("remoteCommand", [](const Command::Params* params)
|
2022-10-19 10:28:53 -04:00
|
|
|
{
|
|
|
|
if (params->size() < 2) return;
|
|
|
|
|
|
|
|
RconContainer.command = params->get(1);
|
|
|
|
|
2022-11-16 12:25:21 -05:00
|
|
|
auto* addr = reinterpret_cast<Game::netadr_t*>(0xA5EA44);
|
2022-10-19 10:28:53 -04:00
|
|
|
Network::Address target(addr);
|
|
|
|
if (!target.isValid() || target.getIP().full == 0)
|
|
|
|
{
|
|
|
|
target = Party::Target();
|
|
|
|
}
|
|
|
|
|
|
|
|
if (target.isValid())
|
|
|
|
{
|
|
|
|
Network::SendCommand(target, "rconRequest");
|
2017-01-19 16:23:59 -05:00
|
|
|
}
|
|
|
|
});
|
2023-03-04 12:40:28 -05:00
|
|
|
|
2023-05-06 09:20:56 -04:00
|
|
|
Command::AddSV("RconWhitelistAdd", [](const Command::Params* params)
|
2023-03-04 12:40:28 -05:00
|
|
|
{
|
|
|
|
if (params->size() < 2)
|
|
|
|
{
|
|
|
|
Logger::Print("Usage: %s <ip-address>\n", params->get(0));
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
Network::Address address(params->get(1));
|
2023-03-04 15:08:43 -05:00
|
|
|
const auto hash = std::hash<std::uint32_t>()(*reinterpret_cast<const std::uint32_t*>(&address.getIP().bytes[0]));
|
2023-03-04 12:40:28 -05:00
|
|
|
|
|
|
|
if (address.isValid() && std::ranges::find(RconAddresses, hash) == RconAddresses.end())
|
|
|
|
{
|
|
|
|
RconAddresses.push_back(hash);
|
|
|
|
}
|
|
|
|
});
|
2022-10-19 10:28:53 -04:00
|
|
|
}
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2023-02-10 10:04:19 -05:00
|
|
|
bool RCon::IsRateLimitCheckDisabled()
|
|
|
|
{
|
|
|
|
static std::optional<bool> flag;
|
|
|
|
if (!flag.has_value())
|
|
|
|
{
|
|
|
|
flag.emplace(Flags::HasFlag("disable-rate-limit-check"));
|
|
|
|
}
|
|
|
|
return flag.value();
|
|
|
|
}
|
|
|
|
|
2022-12-16 16:48:52 -05:00
|
|
|
bool RCon::RateLimitCheck(const Network::Address& address, const int time)
|
|
|
|
{
|
2022-12-28 07:37:03 -05:00
|
|
|
const auto ip = address.getIP();
|
2022-12-16 16:48:52 -05:00
|
|
|
const auto lastTime = RateLimit[ip.full];
|
|
|
|
|
2023-02-10 10:04:19 -05:00
|
|
|
if (lastTime && (time - lastTime) < RconTimeout.get<int>())
|
2022-12-16 16:48:52 -05:00
|
|
|
{
|
|
|
|
return false; // Flooding
|
|
|
|
}
|
|
|
|
|
|
|
|
RateLimit[ip.full] = time;
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
void RCon::RateLimitCleanup(const int time)
|
|
|
|
{
|
|
|
|
for (auto i = RateLimit.begin(); i != RateLimit.end();)
|
|
|
|
{
|
|
|
|
// No longer at risk of flooding, remove
|
2023-02-10 10:04:19 -05:00
|
|
|
if ((time - i->second) > RconTimeout.get<int>())
|
2022-12-16 16:48:52 -05:00
|
|
|
{
|
|
|
|
i = RateLimit.erase(i);
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
++i;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-21 14:14:11 -04:00
|
|
|
void RCon::RconExecuter(const Network::Address& address, std::string data)
|
|
|
|
{
|
|
|
|
Utils::String::Trim(data);
|
|
|
|
|
|
|
|
const auto pos = data.find_first_of(' ');
|
|
|
|
if (pos == std::string::npos)
|
|
|
|
{
|
|
|
|
Logger::Print(Game::CON_CHANNEL_NETWORK, "Invalid RCon request from {}\n", address.getString());
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
auto password = data.substr(0, pos);
|
|
|
|
auto command = data.substr(pos + 1);
|
|
|
|
|
|
|
|
// B3 sends the password inside quotes :S
|
|
|
|
if (!password.empty() && password[0] == '"' && password.back() == '"')
|
|
|
|
{
|
|
|
|
password.pop_back();
|
|
|
|
password.erase(password.begin());
|
|
|
|
}
|
|
|
|
|
|
|
|
const auto svPassword = RconPassword.get<std::string>();
|
|
|
|
if (svPassword.empty())
|
|
|
|
{
|
|
|
|
Logger::Print(Game::CON_CHANNEL_NETWORK, "RCon request from {} dropped. No password set!\n", address.getString());
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (svPassword != password)
|
|
|
|
{
|
|
|
|
Logger::Print(Game::CON_CHANNEL_NETWORK, "Invalid RCon password sent from {}\n", address.getString());
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
static std::string outputBuffer;
|
|
|
|
outputBuffer.clear();
|
|
|
|
|
|
|
|
#ifndef _DEBUG
|
|
|
|
if (RconLogRequests.get<bool>())
|
|
|
|
#endif
|
|
|
|
{
|
|
|
|
Logger::Print(Game::CON_CHANNEL_NETWORK, "Executing RCon request from {}: {}\n", address.getString(), command);
|
|
|
|
}
|
|
|
|
|
|
|
|
Logger::PipeOutput([](const std::string& output)
|
|
|
|
{
|
|
|
|
outputBuffer.append(output);
|
|
|
|
});
|
|
|
|
|
|
|
|
Command::Execute(command, true);
|
|
|
|
|
|
|
|
Logger::PipeOutput(nullptr);
|
|
|
|
|
|
|
|
Network::SendCommand(address, "print", outputBuffer);
|
|
|
|
outputBuffer.clear();
|
|
|
|
}
|
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
RCon::RCon()
|
|
|
|
{
|
2023-03-04 14:37:48 -05:00
|
|
|
Events::OnSVInit(AddCommands);
|
2022-10-19 10:28:53 -04:00
|
|
|
|
|
|
|
if (!Dedicated::IsEnabled())
|
|
|
|
{
|
|
|
|
Network::OnClientPacket("rconAuthorization", [](const Network::Address& address, [[maybe_unused]] const std::string& data)
|
|
|
|
{
|
|
|
|
if (RconContainer.command.empty())
|
|
|
|
{
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
const auto& key = CryptoKey::Get();
|
|
|
|
const auto signedMsg = Utils::Cryptography::ECC::SignMessage(key, data);
|
|
|
|
|
|
|
|
Proto::RCon::Command rconExec;
|
2022-10-20 10:06:29 -04:00
|
|
|
rconExec.set_command(RconContainer.command);
|
2022-10-19 10:28:53 -04:00
|
|
|
rconExec.set_signature(signedMsg);
|
|
|
|
|
|
|
|
Network::SendCommand(address, "rconExecute", rconExec.SerializeAsString());
|
|
|
|
});
|
|
|
|
|
|
|
|
return;
|
|
|
|
}
|
2017-01-19 16:23:59 -05:00
|
|
|
|
|
|
|
// Load public key
|
2022-10-19 10:28:53 -04:00
|
|
|
static std::uint8_t publicKey[] =
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
|
|
|
0x04, 0x01, 0x9D, 0x18, 0x7F, 0x57, 0xD8, 0x95, 0x4C, 0xEE, 0xD0, 0x21,
|
|
|
|
0xB5, 0x00, 0x53, 0xEC, 0xEB, 0x54, 0x7C, 0x4C, 0x37, 0x18, 0x53, 0x89,
|
|
|
|
0x40, 0x12, 0xF7, 0x08, 0x8D, 0x9A, 0x8D, 0x99, 0x9C, 0x79, 0x79, 0x59,
|
|
|
|
0x6E, 0x32, 0x06, 0xEB, 0x49, 0x1E, 0x00, 0x99, 0x71, 0xCB, 0x4A, 0xE1,
|
|
|
|
0x90, 0xF1, 0x7C, 0xB7, 0x4D, 0x60, 0x88, 0x0A, 0xB7, 0xF3, 0xD7, 0x0D,
|
|
|
|
0x4F, 0x08, 0x13, 0x7C, 0xEB, 0x01, 0xFF, 0x00, 0x32, 0xEE, 0xE6, 0x23,
|
|
|
|
0x07, 0xB1, 0xC2, 0x9E, 0x45, 0xD6, 0xD7, 0xBD, 0xED, 0x05, 0x23, 0xB5,
|
|
|
|
0xE7, 0x83, 0xEF, 0xD7, 0x8E, 0x36, 0xDC, 0x16, 0x79, 0x74, 0xD1, 0xD5,
|
|
|
|
0xBA, 0x2C, 0x4C, 0x28, 0x61, 0x29, 0x5C, 0x49, 0x7D, 0xD4, 0xB6, 0x56,
|
|
|
|
0x17, 0x75, 0xF5, 0x2B, 0x58, 0xCD, 0x0D, 0x76, 0x65, 0x10, 0xF7, 0x51,
|
|
|
|
0x69, 0x1D, 0xB9, 0x0F, 0x38, 0xF6, 0x53, 0x3B, 0xF7, 0xCE, 0x76, 0x4F,
|
|
|
|
0x08
|
|
|
|
};
|
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
RconKey.set(std::string(reinterpret_cast<char*>(publicKey), sizeof(publicKey)));
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
RconContainer.timestamp = 0;
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2023-01-27 18:05:26 -05:00
|
|
|
Events::OnDvarInit([]
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
RconPassword = Dvar::Register<const char*>("rcon_password", "", Game::DVAR_NONE, "The password for rcon");
|
2023-02-10 10:04:19 -05:00
|
|
|
RconLogRequests = Dvar::Register<bool>("rcon_log_requests", false, Game::DVAR_NONE, "Print remote commands in log");
|
2023-02-10 15:06:42 -05:00
|
|
|
RconTimeout = Dvar::Register<int>("rcon_timeout", 500, 100, 10000, Game::DVAR_NONE, "");
|
2023-01-27 18:05:26 -05:00
|
|
|
});
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-09-24 13:04:37 -04:00
|
|
|
Network::OnClientPacket("rcon", [](const Network::Address& address, [[maybe_unused]] const std::string& data)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2023-03-04 15:08:43 -05:00
|
|
|
const auto hash = std::hash<std::uint32_t>()(*reinterpret_cast<const std::uint32_t*>(&address.getIP().bytes[0]));
|
2023-03-04 13:17:40 -05:00
|
|
|
if (!RconAddresses.empty() && std::ranges::find(RconAddresses, hash) == RconAddresses.end())
|
2023-03-04 12:40:28 -05:00
|
|
|
{
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2022-12-16 16:48:52 -05:00
|
|
|
const auto time = Game::Sys_Milliseconds();
|
2023-02-10 10:04:19 -05:00
|
|
|
if (!IsRateLimitCheckDisabled() && !RateLimitCheck(address, time))
|
2022-12-16 16:48:52 -05:00
|
|
|
{
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
RateLimitCleanup(time);
|
|
|
|
|
2023-03-21 14:14:11 -04:00
|
|
|
auto rconData = data;
|
|
|
|
Scheduler::Once([address, s = std::move(rconData)]
|
2022-10-19 10:28:53 -04:00
|
|
|
{
|
2023-03-21 14:14:11 -04:00
|
|
|
RconExecuter(address, s);
|
|
|
|
}, Scheduler::Pipeline::MAIN);
|
2017-01-19 16:23:59 -05:00
|
|
|
});
|
|
|
|
|
2022-09-24 13:04:37 -04:00
|
|
|
Network::OnClientPacket("rconRequest", [](const Network::Address& address, [[maybe_unused]] const std::string& data)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
RconContainer.address = address;
|
|
|
|
RconContainer.challenge = Utils::Cryptography::Rand::GenerateChallenge();
|
|
|
|
RconContainer.timestamp = Game::Sys_Milliseconds();
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
Network::SendCommand(address, "rconAuthorization", RconContainer.challenge);
|
2017-01-19 16:23:59 -05:00
|
|
|
});
|
|
|
|
|
2022-09-24 13:04:37 -04:00
|
|
|
Network::OnClientPacket("rconExecute", [](const Network::Address& address, [[maybe_unused]] const std::string& data)
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
if (address != RconContainer.address) return; // Invalid IP
|
|
|
|
if (!RconContainer.timestamp || (Game::Sys_Milliseconds() - RconContainer.timestamp) > (1000 * 10)) return; // Timeout
|
|
|
|
|
|
|
|
RconContainer.timestamp = 0;
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-20 10:06:29 -04:00
|
|
|
Proto::RCon::Command rconExec;
|
|
|
|
rconExec.ParseFromString(data);
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-20 10:06:29 -04:00
|
|
|
if (!Utils::Cryptography::ECC::VerifyMessage(RconKey, RconContainer.challenge, rconExec.signature()))
|
2017-01-19 16:23:59 -05:00
|
|
|
{
|
2022-10-19 10:28:53 -04:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
RconContainer.output.clear();
|
|
|
|
Logger::PipeOutput([](const std::string& output)
|
|
|
|
{
|
|
|
|
RconContainer.output.append(output);
|
|
|
|
});
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-20 10:06:29 -04:00
|
|
|
Command::Execute(rconExec.command(), true);
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
Logger::PipeOutput(nullptr);
|
2017-01-19 16:23:59 -05:00
|
|
|
|
2022-10-19 10:28:53 -04:00
|
|
|
Network::SendCommand(address, "print", RconContainer.output);
|
|
|
|
RconContainer.output.clear();
|
2017-01-19 16:23:59 -05:00
|
|
|
});
|
|
|
|
}
|
2022-10-19 10:28:53 -04:00
|
|
|
|
|
|
|
bool RCon::CryptoKey::LoadKey(Utils::Cryptography::ECC::Key& key)
|
|
|
|
{
|
|
|
|
std::string data;
|
|
|
|
if (!Utils::IO::ReadFile("./private.key", &data))
|
|
|
|
{
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
key.deserialize(data);
|
|
|
|
return key.isValid();
|
|
|
|
}
|
|
|
|
|
|
|
|
Utils::Cryptography::ECC::Key RCon::CryptoKey::GenerateKey()
|
|
|
|
{
|
|
|
|
auto key = Utils::Cryptography::ECC::GenerateKey(512);
|
|
|
|
if (!key.isValid())
|
|
|
|
{
|
|
|
|
throw std::runtime_error("Failed to generate server key!");
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!Utils::IO::WriteFile("./private.key", key.serialize()))
|
|
|
|
{
|
|
|
|
throw std::runtime_error("Failed to write server key!");
|
|
|
|
}
|
|
|
|
|
|
|
|
return key;
|
|
|
|
}
|
|
|
|
|
|
|
|
Utils::Cryptography::ECC::Key RCon::CryptoKey::LoadOrGenerateKey()
|
|
|
|
{
|
|
|
|
Utils::Cryptography::ECC::Key key;
|
|
|
|
if (LoadKey(key))
|
|
|
|
{
|
|
|
|
return key;
|
|
|
|
}
|
|
|
|
|
|
|
|
return GenerateKey();
|
|
|
|
}
|
|
|
|
|
|
|
|
Utils::Cryptography::ECC::Key RCon::CryptoKey::GetKeyInternal()
|
|
|
|
{
|
|
|
|
auto key = LoadOrGenerateKey();
|
|
|
|
Utils::IO::WriteFile("./public.key", key.getPublicKey());
|
|
|
|
return key;
|
|
|
|
}
|
|
|
|
|
|
|
|
const Utils::Cryptography::ECC::Key& RCon::CryptoKey::Get()
|
|
|
|
{
|
|
|
|
static auto key = GetKeyInternal();
|
|
|
|
return key;
|
|
|
|
}
|
2017-01-19 16:23:59 -05:00
|
|
|
}
|