diff --git a/Api_Server/Api_Server_Main.py b/Api_Server/Api_Server_Main.py new file mode 100644 index 0000000..1f29a61 --- /dev/null +++ b/Api_Server/Api_Server_Main.py @@ -0,0 +1,534 @@ +from Output.output import output +import feedparser +import requests +import urllib3 +import random +import time +import yaml +import os +import re + + +class Api_Server_Main: + def __init__(self): + # 全局header头 + self.headers = { + "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36", + "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9", + "Accept-Language": "zh-CN,zh;q=0.9", + "Accept-Encoding": "gzip, deflate, br", + # 'Connection':'keep-alive' ,#默认时链接一次,多次爬取之后不能产生新的链接就会产生报错Max retries exceeded with url + "Upgrade-Insecure-Requests": "1", + "Pragma": "no-cache", + "Cache-Control": "no-cache", + "Connection": "close", # 解决Max retries exceeded with url报错 + } + # 忽略HTTPS告警 + urllib3.disable_warnings() + # 获取当前文件路径 + current_path = os.path.dirname(__file__) + + # 配置缓存文件夹路径 + current_list_path = current_path.split('\\') + current_list_path.pop() + self.Cache_path = '/'.join(current_list_path) + '/Cache' + # 初始化读取配置文件 + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.system_copyright = config['System_Config']['System_Copyright'] + + # 配置文章变量 + self.news_list = '' + + # 读取配置文件 + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.appid = config['Api_Server']['Api_Config']['Appid'] + self.appsecret = config['Api_Server']['Api_Config']['Appsecret'] + self.key = config['Api_Server']['Api_Config']['Key'] + self.threatbook_key = config['Api_Server']['Api_Config']['ThreatBook_Key'] + + self.pic_apis = config['Api_Server']['Pic_Api'] + self.video_apis = config['Api_Server']['Video_Api'] + self.icp_api = config['Api_Server']['Icp_Api'] + self.extensions_api = config['Api_Server']['Extensions_Api'] + self.attribution_api = config['Api_Server']['Attribution_Api'] + self.whois_api = config['Api_Server']['Whois_Api'] + self.fish_api = config['Api_Server']['Fish_Api'] + self.wether_api = config['Api_Server']['Wether_Api'] + self.dog_api = config['Api_Server']['Dog_Api'] + self.constellation_api = config['Api_Server']['Constellation_Api'] + self.morning_api = config['Api_Server']['Morning_Api'] + self.threatbook_url = config['Api_Server']['ThreatBook_Api'] + + # AI对话接口 + def get_ai(self, keyword): + url = 'https://v.api.aa1.cn/api/api-xiaoai/talk.php?msg={keyword}&type=text'.format(keyword=keyword) + try: + msg = requests.get(url=url, headers=self.headers).text.strip() + except Exception as e: + msg = f'[ERROR]:AI对话接口错误,错误信息:{e}' + return msg + + # 美女图片接口 + def get_pic(self): + output('[-]:正在调用美女图片API接口... ...') + url = random.choice(self.pic_apis) + try: + pic_data = requests.get(url=url, headers=self.headers, timeout=30).content + save_path = self.Cache_path + '/Pic_Cache/' + str(int(time.time() * 1000)) + '.jpg' + with open(file=save_path, mode='wb') as pd: + pd.write(pic_data) + except Exception as e: + msg = f'[ERROR]:美女图片API接口出现错误,错误信息:{e}' + output(msg) + return msg + return save_path + + # 美女视频接口 + def get_video(self): + output('[-]:正在调用美女视频API接口... ...') + url = random.choice(self.video_apis) + try: + try: + src = requests.get(url=url, headers=self.headers).json()['mp4'] + except requests.exceptions.JSONDecodeError: + src = re.findall('src="(.*?)"', requests.get(url=url, headers=self.headers, timeout=20).text)[0] + mp4_url = 'http:' + src + video_data = requests.get(url=mp4_url, headers=self.headers).content + save_path = self.Cache_path + '/Video_Cache/' + str(int(time.time() * 1000)) + '.mp4' + with open(file=save_path, mode='wb') as vd: + vd.write(video_data) + except Exception as e: + msg = f'[ERROR]:美女视频API接口出现错误,错误信息:{e}' + output(msg) + return msg + return save_path + + # 备案查询接口 + def get_icp(self, keyword): + try: + domain = re.findall(r' (\w+.\w+)', keyword)[0] + except Exception as e: + msg = '语法格式:\nICP查询 qq.com' + output(f'[ERROR]:备案查询接口出现错误,错误信息:{e}') + return msg + url = self.icp_api.format(domain) + try: + data = requests.get(url=url, headers=self.headers, timeout=10).json() + except Exception as e: + msg = f'[ERROR]:备案查询接口超时,错误信息:{e}' + output(msg) + return msg + if data['icp'] == '未备案': + return '该域名未备案!' + msg = f'======== 查询信息 ========\nICP备案号:{data["icp"]}\n备案主体:{data["name"]}\n备案类型:{data["tyle"]}\n{"By: #" + self.system_copyright if self.system_copyright else ""}\n========================' + return msg.strip() + + # 后缀名查询接口 + def get_suffix(self, keyword): + try: + word = re.findall(r' (\w+)', keyword)[0] + except Exception as e: + msg = '语法格式:\n后缀名查询 EXE' + output(f'\n[ERROR]:后缀名查询接口出现错误,错误信息:{e}') + return msg + url = self.extensions_api.format(self.key, word) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:后缀名查询接口超时,错误信息:{e}' + output(msg) + return msg + if data['code'] != 200: + msg = '查询结果为空!' + else: + msg = f'\n======== 查询后缀:{word} ========\n查询结果:{data["result"]["notes"]}\n{"By: #" + self.system_copyright if self.system_copyright else ""}\n============================' + return msg + + # 归属地查询 + def get_attribution(self, keyword): + try: + phone = re.findall(r' (\d+)', keyword)[0] + except Exception as e: + msg = '语法格式:\n归属查询 110' + output(f'\n[ERROR]:归属查询接口出现错误,错误信息:{e}') + return msg + url = self.attribution_api.format(phone) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:归属查询接口超时,错误信息:{e}' + output(msg) + return msg + if not data['data']['province']: + msg = '查询结果为空!' + else: + msg = f'\n===== 查询信息 =====\n手机号码:{phone}\n省份:{data["data"]["province"]}\n城市:{data["data"]["city"]}\n运营商:{data["data"]["sp"]}\n{"By: #" + self.system_copyright if self.system_copyright else ""}\n=================' + return msg + + # Whois查询接口 + def get_whois(self, keyword): + try: + domain = re.findall(r' (\w+.\w+)', keyword)[0] + except Exception as e: + msg = '语法格式:\nWHOIS查询 qq.com' + output(f'[ERROR]:WHOIS查询接口出现错误,错误信息:{e}') + return msg + url = self.whois_api.format(domain) + try: + source_data = requests.get(url=url, headers=self.headers).text + except TimeoutError as e: + msg = f'\n[ERROR]:WHOIS查询接口超时,错误信息:{e}' + output(msg) + return msg + msg = '\n' + source_data.strip().split('For more information')[0].strip('
').strip() + f"\n{'By: #' + self.system_copyright if self.system_copyright else ''}" + return msg + + # 微步ip查询接口 + def get_threatbook_ip(self, keyword): + try: + keyword = keyword.split(' ')[-1] + except Exception as e: + output(f'[ERROR]:微步ip查询接口出现错误,错误信息:{e}') + reg = r"((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})(\.((2(5[0-5]|[0-4]\d))|[0-1]?\d{1,2})){3}" + ip_result = re.match(reg, keyword.replace(' ', '').strip()) + if ip_result is None: + msg = "语法格式: \nIP查询 xx.xx.xx.xx" + return msg + elif len(keyword) > 0 and ip_result.group(): + search_ip = ip_result.group() + ips = str(search_ip).split('.') + continuous_bool = True if [i for i in ips if ips[0] != i] else False + if ips[0] in ['127', '192', '0', '224', '240', '255'] or \ + search_ip in ['1.1.1.1', '2.2.2.2', '3.3.3.3', '4.4.4.4', '5.5.5.5', '6.6.6.6', '7.7.7.7', + '8.8.8.8', '9.9.9.9', '10.10.10.10'] or \ + '.'.join(ips[0:2]) in ['169.254', '100.64', '198.51', '198.18', '172.16'] or \ + '.'.join(ips[0:3]) in ['203.0.113'] or \ + ips[-1] in ['255', '254']: + msg = "[微笑]暂不支持查询该地址!" + return msg + if not continuous_bool: + msg = "[微笑]暂不支持查询该地址!" + return msg + try: + + data = { + "apikey": self.threatbook_key, + "resource": search_ip, + } + + resp = requests.post( + self.threatbook_url, + data=data, + timeout=10, + verify=False, + ) + if resp.status_code == 200 and resp.json()["response_code"] == 0: + # 查风险等级 + sec_level = resp.json()["data"]["{}".format(search_ip)]["severity"] + # 查是否恶意IP + is_malicious = resp.json()["data"]["{}".format(search_ip)]["is_malicious"] + # 查可信度 + confidence_level = resp.json()["data"]["{}".format(search_ip)]["confidence_level"] + # 查IP归属国家 + country = resp.json()["data"]["{}".format(search_ip)]["basic"]["location"][ + "country" + ] + # 查IP归属省份 + province = resp.json()["data"]["{}".format(search_ip)]["basic"]["location"][ + "province" + ] + # 查IP归属城市 + city = resp.json()["data"]["{}".format(search_ip)]["basic"]["location"]["city"] + # 将IP归属的国家、省份、城市合并成一个字符串 + location = country + "-" + province + "-" + city + # 查威胁类型 + judgments = "" + for j in resp.json()["data"]["{}".format(search_ip)]["judgments"]: + judgments += j + " " + if is_malicious: + is_malicious_msg = "是" + else: + is_malicious_msg = "否" + msg = f"\n===================\n[+]ip:{search_ip}\n[+]风险等级:{sec_level}\n[+]是否为恶意ip:{is_malicious_msg}\n[+]可信度:{confidence_level}\n[+]威胁类型:{str(judgments)}\n[+]ip归属地:{location}\n更新时间:{resp.json()['data']['{}'.format(search_ip)]['update_time']}\n{'By: #' + self.system_copyright if self.system_copyright else ''}\n===================" + else: + msg = f"[ERROR]:查询失败,返回信息:{resp.json()['verbose_msg']}" + output(msg) + except Exception as e: + output(f"[ERROR]:微步IP查询出错,错误信息:{e}") + msg = f"[ERROR]:查询出错请稍后重试,错误信息:{e}" + return msg + + # 摸鱼日记接口 + def get_fish(self): + output('[-]:正在调用摸鱼日记API接口... ...') + try: + pic_data = requests.get(url=self.fish_api, headers=self.headers, timeout=10).content + save_path = self.Cache_path + '/Fish_Cache/' + str(int(time.time() * 1000)) + '.jpg' + with open(file=save_path, mode='wb') as pd: + pd.write(pic_data) + except Exception as e: + msg = f'[ERROR]:摸鱼日记API接口出现错误,错误信息:{e}' + output(msg) + return msg + return save_path + + # 天气查询接口 + def get_wether(self, keyword): + try: + city = re.findall(r' (\w+)', keyword)[0] + except Exception as e: + msg = '语法格式:\n天气查询 北京' + output(f'\n[ERROR]:天气查询接口出现错误,错误信息:{e}') + return msg + url = self.wether_api.format(self.appid, self.appsecret, city) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:天气查询接口超时,错误信息:{e}' + output(msg) + return msg + try: + if city != data['city']: + msg = f'城市中不存在:{data["city"]}' + return msg + else: + msg = f'\n今日{data["city"]}天气:{data["wea"]}\n日期:{data["date"]}\n当前温度:{data["tem"]}\n最低温度:{data["tem_day"]}\n风向:{data["win"] + data["win_speed"]}\n风速:{data["win_meter"]}\n湿度:{data["humidity"]}\n{"By: #" + self.system_copyright if self.system_copyright else ""}' + return msg + except Exception as e: + output(f'[ERROR]:天气查询接口出现错误出现错误,错误信息:{e}') + msg = f'城市中不存在:{city}' + return msg + + # 舔狗日记 + def get_dog(self): + url = self.dog_api.format(self.key) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:舔狗日记接口超时,错误信息:{e}' + output(msg) + return msg + try: + msg = data['newslist'][0]['content'].strip() + except Exception as e: + msg = f'[ERROR]:舔狗日记接口出现错误出现错误,错误信息:{e}' + output(msg) + return msg + + # 星座查询接口 + def get_constellation(self, keyword): + msg = '' + try: + constellation = re.findall(r' (\w+)', keyword)[0] + if '座' not in constellation: + constellation += '座' + except Exception as e: + msg = '语法格式:\n星座查询 白羊座' + output(f'\n[ERROR]:星座查询接口出现错误,错误信息:{e}') + return msg + url = self.constellation_api.format(self.key, constellation) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:星座查询接口超时,错误信息:{e}' + output(msg) + return msg + for news in data['newslist']: + msg += news['type'] + ':' + news['content'] + '\n' + msg = f'\n星座:{constellation}\n' + msg.strip() + f"\n{'By: #' + self.system_copyright if self.system_copyright else ''}" + return msg + + # 早安寄语 + def get_morning(self): + url = self.morning_api.format(self.key) + try: + data = requests.get(url=url, headers=self.headers).json() + except TimeoutError as e: + msg = f'\n[ERROR]:早安寄语接口超时,错误信息:{e}' + output(msg) + return msg + msg = f'{data["result"]["content"]}' + return msg + + # 早报推送 + def get_freebuf_news(self, ): + str_list = "#FreeBuf早报\n" + try: + rs1 = feedparser.parse('https://www.freebuf.com/feed') + length = len(rs1.entries) + for buf in range(length): + try: + if ( + f'tm_year={time.strftime("%Y")}' + in str(rs1.entries[buf]["published_parsed"]) + and f'tm_mon={time.strftime("%m")}' + in str(rs1.entries[buf]["published_parsed"]) + and f'tm_mday={str(int(time.strftime("%d")) - 1)}' + in str(rs1.entries[buf]["published_parsed"]) + ): + url_f = rs1.entries[buf]["link"] + title_f = ( + rs1.entries[buf]["title_detail"]["value"] + .replace("FreeBuf早报 |", "") + .replace(" ", "") + ) + link4 = "\n" + title_f + "\n" + url_f + "\n" + str_list += link4 + else: + pass + except Exception as e: + output("[ERROR]:获取FreeBuf早报出错,错误信息:{}".format(e)) + break + if len(str_list) == 0: + link6 = "\n今日暂无文章" + str_list += link6 + else: + pass + except Exception as e: + link6 = "\n今日暂无文章" + str_list += link6 + output("ERROR:freebuf {}".format(e)) + str_list += f"\n{self.system_copyright + '整理分享,更多内容请戳:#' + self.system_copyright if self.system_copyright else ''}\n{time.strftime('%Y-%m-%d %X')}" + return str_list + + # 获取先知社区文章 + def get_xz_news(self, ): + str_list = "" + str_list += "#先知社区" + try: + rs1 = feedparser.parse('https://xz.aliyun.com/feed') + length = len(rs1.entries) + for buf in range(length): + try: + if str(time.strftime("%Y-%m-%d")) in str(rs1.entries[buf]["published"]): + url_f = rs1.entries[buf]["link"] + title_f = rs1.entries[buf]["title_detail"]["value"] + link4 = "\n" + title_f + "\n" + url_f + "\n" + str_list += link4 + else: + pass + except Exception as e: + output("[ERROR]:获取先知社区文章出现错误,错误信息:{}".format(e)) + break + if len(str_list) > 10: + self.news_list += str_list + else: + link6 = "#先知社区\n今日暂无文章" + self.news_list += link6 + except Exception as e: + link6 = "#先知社区\n今日暂无文章" + self.news_list += link6 + output("ERROR:先知社区 {}".format(e)) + return f'[-]:爬取先知社区文章出错,错误信息:{e}' + + # 获取奇安信攻防社区文章 + def get_qax_news(self, ): + str_list = "" + str_list += "\n#奇安信攻防社区" + try: + rs1 = feedparser.parse('https://forum.butian.net/Rss') + length = len(rs1.entries) + for buf in range(length): + try: + if str(time.strftime("%Y-%m-%d")) in str(rs1.entries[buf]["published"]): + url_f = rs1.entries[buf]["link"] + title_f = rs1.entries[buf]["title_detail"]["value"] + link4 = "\n" + title_f + "\n" + url_f + "\n" + str_list += link4 + else: + pass + except Exception as e: + output("[ERROR]:爬取奇安信攻防社区文章出错,错误信息:{}".format(e)) + break + if len(str_list) > 10: + self.news_list += str_list + else: + link6 = "\n#奇安信攻防社区\n今日暂无文章" + self.news_list += link6 + except Exception as e: + link6 = "\n#奇安信攻防社区\n今日暂无文章" + self.news_list += link6 + output("[ERROR]:奇安信攻防社区 {}".format(e)) + return f"[-]:爬取奇安信攻防社区文章出错,错误信息:{e}" + + # 获取安全客文章 + def get_anquanke_news(self, ): + str_list = "" + str_list += "\n#安全客" + try: + rs1 = requests.get('https://www.anquanke.com/knowledge', timeout=5, verify=False) + rs1.encoding = "utf-8" + resp_text = ( + rs1.text.replace("\xa9", "") + .replace("\n", "") + .replace(">", "") + .replace(" ", "") + .replace(" ", "") + .replace(" ", "") + ) + newlist = re.findall( + '(.*?) ', + resp_text, + re.S, + ) + timelist = re.findall( + ' (.*?)', + resp_text, + re.S, + ) + for a in range(len(timelist)): + try: + if time.strftime("%Y-%m-%d") in timelist[a]: + link1 = str(newlist[a][1]) + link2 = "https://www.anquanke.com" + str(newlist[a][0]) + link3 = "\n" + str(link1) + "\n" + str(link2) + "\n" + str_list += link3 + else: + pass + except Exception as e: + output("爬取安全客文章出错,错误信息:{}".format(e)) + break + if len(str_list) > 6: + self.news_list += str_list + else: + link6 = "\n#安全客\n今日暂无文章" + self.news_list += link6 + except Exception as e: + link6 = "\n#安全客\n今日暂无文章" + self.news_list += link6 + output("[ERROR]:爬取安全客文章出错,错误信息:{}".format(e)) + return f"[-]:爬取安全客文章出错,错误信息:{e}" + + # 获取各平台安全文章 + def get_safety_news(self, ): + output("[+]:正在爬取安全新闻... ...") + self.get_xz_news() + self.get_qax_news() + self.get_anquanke_news() + output("[+]:获取成功") + self.news_list += f"\n{self.system_copyright + '整理分享,更多内容请戳:#' + self.system_copyright if self.system_copyright else ''}\n{time.strftime('%Y-%m-%d %X')}" + return self.news_list + + # 测试专用 + def demo(self): + # url = 'https://tucdn.wpon.cn/api-girl/' + # data = requests.get(url=url, headers=self.headers).json() + # print(data) + domain = 'qq.com' + text = 'https://v.api.aa1.cn/api/icp/index.php?url={domain}'.format(domain=domain) + print(text) + + +if __name__ == '__main__': + Asm = Api_Server_Main() + # Asm.get_pic() + # Asm.demo() + # Asm.get_video() + # Asm.icp_query(keyword='ICP查询 qq.com') + # Asm.get_suffix(keyword='icp查询 apk') + # Asm.get_attribution(keyword='归属查询 17371963534') + # Asm.get_whois(keyword='whois查询 qq.com') + # Asm.get_wether(keyword='天气查询 123') + # Asm.get_dog() + # Asm.get_constellation('星座查询 白羊座') + Asm.get_morning() diff --git a/BotServer/MainServer.py b/BotServer/MainServer.py new file mode 100644 index 0000000..79a3492 --- /dev/null +++ b/BotServer/MainServer.py @@ -0,0 +1,251 @@ +from Recv_Msg_Dispose.FriendMsg_dispose import FriendMsg_dispose +from Recv_Msg_Dispose.RoomMsg_dispose import RoomMsg_disposes +from Push_Server.Push_Main_Server import Push_Main_Server +from Db_Server.Db_User_Server import Db_User_Server +from concurrent.futures import ThreadPoolExecutor +from BotServer.SendServer import SendServer +from bs4 import BeautifulSoup +from Output.output import * +import websocket +import yaml +import json +import os + + +class MainServers: + + def __init__(self): + # 初始化读取配置文件 + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.ip = config['BotServer']['IP'] + self.port = config['BotServer']['PORT'] + self.system_copyright = config['System_Config']['System_Copyright'] + + # 配置HOOK信息类型 + self.SERVER = f"ws://{self.ip}:{self.port}" + self.HEART_BEAT = 5005 + self.RECV_TXT_MSG = 1 + self.RECV_TXT_CITE_MSG = 49 + self.RECV_PIC_MSG = 3 + self.USER_LIST = 5000 + self.GET_USER_LIST_SUCCSESS = 5001 + self.GET_USER_LIST_FAIL = 5002 + self.TXT_MSG = 555 + self.PIC_MSG = 500 + self.AT_MSG = 550 + self.CHATROOM_MEMBER = 5010 + self.CHATROOM_MEMBER_NICK = 5020 + self.PERSONAL_INFO = 6500 + self.DEBUG_SWITCH = 6000 + self.PERSONAL_DETAIL = 6550 + self.DESTROY_ALL = 9999 + self.JOIN_ROOM = 10000 + self.ATTATCH_FILE = 5003 + + # 启动机器人 + self.ws = websocket.WebSocketApp( + self.SERVER, on_open=self.on_open, on_message=self.on_message, on_error=self.on_error, + on_close=self.on_close + ) + + # 实例化消息服务 + self.Ss = SendServer() + + # 实例化群消息处理类 + self.Rmd = RoomMsg_disposes() + + # 实例化好友消息处理 + self.Fmd = FriendMsg_dispose() + + # 实例化用户数据服务类 + self.Dus = Db_User_Server() + + # Robot初始化执行 + def on_open(self, ws): + # 实例化实时监控类 + self.Pms = Push_Main_Server(ws=self.ws) + pool = ThreadPoolExecutor(5) + pool.submit(self.Pms.run) + + self.get_personal_info() + + # Robot 启动函数 + def Bot_start(self, ): + self.ws.run_forever() + + # Robot 关闭执行 + def on_close(self, ws): + output("The Robot is Closed...") + + # Robot 错误输出 + def on_error(self, ws, error): + output(f"[ERROR]:出现错误,错误信息:{error}") + + # 启动完成输出 + def handle_wxuser_list(self): + output("Bot is Start!") + + # Robot 心跳输出 + def heartbeat(self, msgJson): + output(f'[*]:{msgJson["content"]}') + + # DEBUG选择HOOK信息类型 + def debug_switch(self, ): + qs = { + "id": self.Ss.get_id(), + "type": self.DEBUG_SWITCH, + "content": "off", + "wxid": "ROOT", + } + return json.dumps(qs) + + # 处理缺口 + def handle_nick(self, j): + data = j.content + i = 0 + for d in data: + output(f"nickname:{d.nickname}") + i += 1 + + # 处理所有Roomid + def hanle_memberlist(self, j): + data = j.content + i = 0 + for d in data: + output(f"roomid:{d.roomid}") + i += 1 + + # 销毁全部接口 + def destroy_all(self, ): + qs = { + "id": self.Ss.get_id(), + "type": self.DESTROY_ALL, + "content": "none", + "wxid": "node", + } + return json.dumps(qs) + + # 处理带引用的文字消息 + def handleMsg_cite(self, msgJson): + msgXml = ( + msgJson["content"]["content"] + .replace("&", "&") + .replace("<", "<") + .replace(">", ">") + ) + soup = BeautifulSoup(msgXml, "xml") + msgJson = { + "content": soup.select_one("title").text, + "id": msgJson["id"], + "id1": msgJson["content"]["id2"], + "id2": "wxid_fys2fico9put22", + "id3": "", + "srvid": msgJson["srvid"], + "time": msgJson["time"], + "type": msgJson["type"], + "wxid": msgJson["content"]["id1"], + } + self.handle_recv_msg(msgJson) + + # 选择消息类型 + def on_message(self, ws, message): + j = json.loads(message) + resp_type = j["type"] + # switch结构 + action = { + self.CHATROOM_MEMBER_NICK: self.handle_nick, + self.PERSONAL_DETAIL: self.handle_recv_msg, + self.AT_MSG: self.handle_recv_msg, + self.DEBUG_SWITCH: self.handle_recv_msg, + self.PERSONAL_INFO: self.handle_recv_msg, + self.TXT_MSG: self.handle_recv_msg, + self.PIC_MSG: self.handle_recv_msg, + self.CHATROOM_MEMBER: self.hanle_memberlist, + self.RECV_PIC_MSG: self.handle_recv_msg, + self.RECV_TXT_MSG: self.handle_recv_msg, + self.RECV_TXT_CITE_MSG: self.handleMsg_cite, + self.HEART_BEAT: self.heartbeat, + self.USER_LIST: self.handle_wxuser_list, + self.GET_USER_LIST_SUCCSESS: self.handle_wxuser_list, + self.GET_USER_LIST_FAIL: self.handle_wxuser_list, + self.JOIN_ROOM: self.welcome_join, + } + action.get(resp_type, print)(j) + + # 获取获取微信通讯录用户名字和wxid,好友列表 + def get_wx_user_list(self, ): + qs = { + "id": self.Ss.get_id(), + "type": self.USER_LIST, + "content": "user list", + "wxid": "null", + } + # Output(qs) + return json.dumps(qs) + + def get_personal_info(self, ): + # 获取本机器人的信息 + uri = "/api/get_personal_info" + data = { + "id": self.Ss.get_id(), + "type": self.PERSONAL_INFO, + "content": "op:personal info", + "wxid": "null", + } + respJson = self.Ss.send(uri, data) + wechatBotInfo = f""" + + NGCBot登录信息 + + 微信昵称:{json.loads(respJson["content"])['wx_name']} + 微信号:{json.loads(respJson["content"])['wx_code']} + 微信id:{json.loads(respJson["content"])['wx_id']} + 启动时间:{respJson['time']} + {'By: ' + self.system_copyright if self.system_copyright else ''} + """ + output(wechatBotInfo.strip()) + + # 入群欢迎函数 + def welcome_join(self, msgJson): + output(f"收到消息:{msgJson}") + if "邀请" in msgJson["content"]["content"]: + roomid = msgJson["content"]["id1"] + nickname = msgJson["content"]["content"].split('"')[-2] + msg = '\n欢迎新进群的小可爱[烟花]' + if roomid in self.Dus.show_white_room(): + self.ws.send(self.Ss.send_msg(msg=msg, roomid=roomid, wxid='null', + nickname=nickname)) + + # 消息接收函数 + def handle_recv_msg(self, msgJson): + if "wxid" not in msgJson and msgJson["status"] == "SUCCSESSED": + output(f"[*]:消息发送成功!") + return + output(f"收到消息:{msgJson}") + msg = "" + # 判断群聊消息还是私人消息 + if "@chatroom" in msgJson["wxid"]: + # 获取群ID + roomid = msgJson["wxid"] + # 获取发送人ID + senderid = msgJson["id1"] + else: + roomid = None + nickname = "null" + # 获取发送人ID + senderid = msgJson["wxid"] + + # 获取发送者的名字 + nickname = self.Ss.get_member_nick(roomid, senderid) + if roomid: + # 处理微信群消息 + self.Rmd.get_information(msgJson=msgJson, roomid=roomid, senderid=senderid, nickname=nickname, ws=self.ws) + else: + # 处理通讯录好友发送的消息 + self.Fmd.get_information(msgJson=msgJson, senderid=senderid, ws=self.ws) + + +if __name__ == '__main__': + Ms = MainServers() + Ms.Bot_start() diff --git a/BotServer/SendServer.py b/BotServer/SendServer.py new file mode 100644 index 0000000..9ec6c27 --- /dev/null +++ b/BotServer/SendServer.py @@ -0,0 +1,144 @@ +from Output.output import output +import requests +import time +import json +import yaml +import os + + +class SendServer: + + def __init__(self): + # 初始化读取配置文件 + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.ip = config['BotServer']['IP'] + self.port = config['BotServer']['PORT'] + + # 配置HOOK信息类型 + self.SERVER = f"ws://{self.ip}:{self.port}" + self.HEART_BEAT = 5005 + self.RECV_TXT_MSG = 1 + self.RECV_TXT_CITE_MSG = 49 + self.RECV_PIC_MSG = 3 + self.USER_LIST = 5000 + self.GET_USER_LIST_SUCCSESS = 5001 + self.GET_USER_LIST_FAIL = 5002 + self.TXT_MSG = 555 + self.PIC_MSG = 500 + self.AT_MSG = 550 + self.CHATROOM_MEMBER = 5010 + self.CHATROOM_MEMBER_NICK = 5020 + self.PERSONAL_INFO = 6500 + self.DEBUG_SWITCH = 6000 + self.PERSONAL_DETAIL = 6550 + self.DESTROY_ALL = 9999 + self.JOIN_ROOM = 10000 + self.ATTATCH_FILE = 5003 + + # 通用消息发送函数 + def send(self, uri, data): + base_data = { + "id": self.get_id(), + "type": "null", + "roomid": "null", + "wxid": "null", + "content": "null", + "nickname": "null", + "ext": "null", + } + base_data.update(data) + url = f'http://{self.ip}:{self.port}/{uri}' + res = requests.post(url, json={"para": base_data}, timeout=5) + return res.json() + + # 定义信息ID + def get_id(self): + return time.strftime("%Y-%m-%d %H:%M:%S") + + # 发送消息函数 + def send_msg(self, msg, wxid="null", roomid='null', nickname="null"): + if roomid != 'null': + msg_type = self.AT_MSG + else: + msg_type = self.TXT_MSG + qs = { + "id": self.get_id(), + "type": msg_type, + "roomid": roomid, + "wxid": wxid, + "content": msg, + "nickname": nickname, + "ext": "null", + } + output(f"[*]:发送消息: {qs}") + return json.dumps(qs) + + # 通用文件发送函数 + def send_file_room(self, file, roomid): + output("[+]:文件发送中... ...") + data = { + "id": self.get_id(), + "type": self.ATTATCH_FILE, + "roomid": "null", + "content": file, + "wxid": roomid, + "nickname": "null", + "ext": "null", + } + url = f"http://{self.ip}:{self.port}/api/sendattatch" + res = requests.post(url, json={"para": data}, timeout=5) + if res.status_code == 200 and res.json()["status"] == "SUCCSESSED": + output("[*]:文件发送成功") + else: + output(f"[ERROR]:出现错误,错误信息:{res.text}") + + # 图片发送函数 + def send_img_room(self, msg, roomid): + output("[+]:图片发送中... ...") + data = { + "id": self.get_id(), + "type": self.PIC_MSG, + "roomid": "null", + "content": msg, + "wxid": roomid, + "nickname": "null", + "ext": "null", + } + url = f"http://{self.ip}:{self.port}/api/sendpic" + res = requests.post(url, json={"para": data}, timeout=5) + if res.status_code == 200 and res.json()["status"] == "SUCCSESSED": + output("[*]:图片发送成功!") + else: + output(f"[ERROR]:出现错误,错误信息:{res.text}") + + # 获取所有群的wxid + def get_memberid(self, ): + uri = 'api/getmemberid' + data = { + 'type': self.CHATROOM_MEMBER, + 'content': 'op:list member' + } + output(self.send(uri, data)) + + # 获取@昵称 或 微信好友的昵称 + def get_member_nick(self, roomid, wxid): + uri = "api/getmembernick" + data = {"type": self.CHATROOM_MEMBER_NICK, "wxid": wxid, "roomid": roomid or "null"} + respJson = self.send(uri, data) + return json.loads(respJson["content"])["nick"] + + # 获取机器人微信ID和微信名字 + def get_bot_info(self, ): + uri = "/api/get_personal_info" + data = { + "id": self.get_id(), + "type": self.PERSONAL_INFO, + "content": "op:personal info", + "wxid": "null", + } + respJson = self.send(uri, data) + bot_wxid = json.loads(respJson["content"])['wx_id'] + return bot_wxid + + diff --git a/Cache/Cache_Server.py b/Cache/Cache_Server.py new file mode 100644 index 0000000..8753a72 --- /dev/null +++ b/Cache/Cache_Server.py @@ -0,0 +1,54 @@ +from Output.output import output +import os + + +class Cache_Server: + + def __init__(self): + # 配置缓存文件存放路径 + current_path = os.path.dirname(__file__) + self.video_cache = current_path + '/Video_Cache' + self.fish_cache = current_path + '/Fish_Cache' + self.pic_cache = current_path + '/Pic_Cache' + self.create_folder() + + def delete_file(self): + output('[+]:缓存清除功能工作中... ...') + if os.path.exists(self.video_cache): + try: + file_lists = list() + file_lists += [self.video_cache + '/' + file for file in os.listdir(self.video_cache)] + file_lists += [self.fish_cache + '/' + file for file in os.listdir(self.fish_cache)] + file_lists += [self.pic_cache + '/' + file for file in os.listdir(self.pic_cache)] + for rm_file in file_lists: + os.remove(rm_file) + except Exception as e: + msg = "[ERROR]:清除缓存时出错,错误信息:{}".format(e) + output(msg) + return msg + msg = "缓存文件已清除!" + return msg + else: + msg = "[-]:缓存文件夹未创建,正在创建缓存文件夹... ..." + output(msg) + self.create_folder() + + def create_folder(self): + if not os.path.exists(self.video_cache): + try: + os.mkdir(self.video_cache) + os.mkdir(self.pic_cache) + os.mkdir(self.fish_cache) + except Exception as e: + msg = '[ERROR]:创建文件夹出错,错误信息:{}'.format(e) + output(msg) + else: + msg = '[+]:缓存文件夹已创建!' + output(msg) + + +if __name__ == '__main__': + Fs = Cache_Server() + # # Fs.create_folder() + Fs.delete_file() + diff --git a/Config/config.yaml b/Config/config.yaml new file mode 100644 index 0000000..64fc6fa --- /dev/null +++ b/Config/config.yaml @@ -0,0 +1,221 @@ +## 机器人服务配置 +BotServer: + IP: 127.0.0.1 + PORT: 5555 + +## 超级管理员配置 +Administrators: + - 'wxid_7bizfilssbwi22' + +## 关键词配置 +Key_Word: + # 触发美女图片关键词 + Pic_Word: + - '图片' + - '美女图片' + # 触发美女视频关键词 + Video_Word: + - '视频' + - '美女视频' + # 触发备案查询关键词 + Icp_Word: + - '备案查询' + - 'ICP查询' + - 'icp查询' + # 触发后缀名查询关键词 + Suffix_Word: + - '后缀名查询' + - '后缀查询' + # 触发归属查询关键词 + Attribution_Word: + - '归属查询' + - '归属地查询' + # 触发WHOIS查询关键词 + Whois_Word: + - 'whois查询' + - 'WHOIS查询' + # 触发摸鱼日记关键词 + Fish_Word: + - '摸鱼日记' + - '摸鱼日历' + # 触发天气查询关键词 + Weather_Word: + - '天气查询' + - '查询天气' + # 触发舔狗日记关键词 + Dog_Word: + - '舔狗日记' + - '舔我' + # 触发星座查询关键词 + Constellation_Word: + - '星座查询' + - '查询星座' + - '运势查询' + - '查询运势' + # 触发早安寄语关键词 + Morning_Word: + - '早安' + # 触发微步IP查询关键词 + ThreatBook_Word: + - 'ip查询' + - 'IP查询' + - '查询ip' + - '查询IP' + - '微步查询' + # 新增管理员关键词 + Add_Admin_Word: + - '添加管理员' + - '添加管理' + - '新增管理员' + # 删除管理员关键词 + Del_Admin_Word: + - '删除管理员' + - '删除管理' + - '移除管理员' + # 新增黑名单群聊关键词 + Add_BlackRoom_Word: + - '拉黑群聊' + - '添加黑名单' + # 移出黑名单群聊关键词 + Del_BlackRoom_Word: + - '解除拉黑' + - '移出黑名单' + # 新增白名单群聊关键词 + Add_WhiteRoom_Word: + - '拉白' + - '添加白名单' + - '开启推送服务' + - '开启推送功能' + # 移出白名单群聊关键词 + Del_WhiteRoom_Word: + - '关闭推送服务' + - '关闭推送功能' + - '移出白名单' + # 触发早报关键词 + Morning_Page: + - '早报' + - '早间咨询' + # 触发晚报关键词 + Evening_Page: + - '晚报' + - '晚间咨询' + +## API接口服务配置 +Api_Server: + Api_Config: + Appid: '45279436' + Appsecret: 'lohAjD4R' + Key: 'e8409cd6401b93d170297440ace30f27' + ThreatBook_Key: '6518ffbfade84bc1a01718f595cefedb23fa2924b51842978b7e0b5a13b02827' + # 扩展名查询API + Extensions_Api: 'https://apis.tianapi.com/targa/index?key={}&word={}' + # 天气查询API + Wether_Api: 'https://www.tianqiapi.com/free/day?appid={}&appsecret={}&city={}' + # 舔狗日记API + Dog_Api: 'http://api.tianapi.com/tiangou/index?key={}' + # 星座查询API + Constellation_Api: 'http://api.tianapi.com/star/index?key={}&astro={}' + # 早安寄语API + Morning_Api: 'https://apis.tianapi.com/zaoan/index?key={}' + # 微步查询API + ThreatBook_Api: 'https://api.threatbook.cn/v3/scene/ip_reputation' + + # 摸鱼日记API + Fish_Api: 'https://api.vvhan.com/api/moyu' + # Whois查询API + Whois_Api: 'https://v.api.aa1.cn/api/whois/index.php?domain={}' + # 归属地查询API + Attribution_Api: 'https://v.api.aa1.cn/api/phone/guishu-api.php?phone={}' + # 备案查询API配置 + Icp_Api: 'https://v.api.aa1.cn/api/icp/index.php?url={}' + # 图片API配置 + Pic_Api: + - 'https://api.vvhan.com/api/girl' + - 'https://v.api.aa1.cn/api/pc-girl_bz/index.php?wpon=ro38d57y8rhuwur3788y3rd' + - 'https://api.vvhan.com/api/mobil.girl' + # 视频API配置 + Video_Api: + - 'https://tucdn.wpon.cn/api-girl/' + - 'https://v.api.aa1.cn/api/api-dy-girl/index.php?aa1=json' + - 'https://v.api.aa1.cn/api/api-girl-11-02/index.php?type=json' + +## 积分功能配置 +Point_Function: + # 签到口令 + Sign_Keyword: '签到:NGC660安全实验室祝大家天天得0day!' + # 签到积分配置 + Sign_Point: 10 + # 积分功能配置 + Function: + ThreatBook_Point: 8 + # 增加积分关键词 + Add_Point_Word: + - '加' + - '+' + # 扣除积分关键词 + Del_Point_Word: + - '减' + - '-' + # 赠送积分关键词 + Give_Point_Word: + - '送' + # 查看积分关键词 + Query_Point: + - '查看积分' + - '积分查询' + +## 定时推送配置 +Timed_Push: + # 早报推送时间 + Morning_Page_Time: '08:00' + # 晚报推送时间 + Evening_Page_Time: '17:00' + # 摸鱼日记推送时间 + Fish_Time: '10:00' + +## 实时监控配置 +Monitor_Server: + # Github令牌 + Github_Token: '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' + # 工具监控 + tools_list: + - 'https://api.github.com/repos/BeichenDream/Godzilla' + - 'https://api.github.com/repos/rebeyond/Behinder' + - 'https://api.github.com/repos/AntSwordProject/antSword' + - 'https://api.github.com/repos/j1anFen/shiro_attack' + - 'https://api.github.com/repos/yhy0/github-cve-monitor' + - 'https://api.github.com/repos/gentilkiwi/mimikatz' + - 'https://api.github.com/repos/ehang-io/nps' + - 'https://api.github.com/repos/chaitin/xray' + - 'https://api.github.com/repos/FunnyWolf/pystinger' + - 'https://api.github.com/repos/L-codes/Neo-reGeorg' + - 'https://api.github.com/repos/shadow1ng/fscan' + - 'https://api.github.com/repos/SafeGroceryStore/MDUT' + - 'https://api.github.com/repos/EdgeSecurityTeam/Vulnerability' + # 关键词监控 + keyword_list: + - 'Sql注入' + - 'cnvd' + - '未授权' + # 用户监控 + user_list: + - 'yhy0' + - 'su18' + - 'BeichenDream' + - 'phith0n' + - 'zhzyker' + - 'lijiejie' + - 'projectdiscovery' + - 'HavocFramework' + +## 系统相关配置 +System_Config: + # 缓存清除关键词配置 + Cache_Config_Word: + - '清除缓存' + - '清空缓存' + # 版权信息配置 + System_Copyright: 'NGC660安全实验室' + # 帮助菜单关键词配置 + Help_Menu: + - '帮助菜单' \ No newline at end of file diff --git a/Db_Server/Db_Point_Server.py b/Db_Server/Db_Point_Server.py new file mode 100644 index 0000000..550c7ed --- /dev/null +++ b/Db_Server/Db_Point_Server.py @@ -0,0 +1,169 @@ +from Output.output import output +import sqlite3 +import yaml +import os + + +class Db_Point_Server: + def __init__(self): + current_path = os.path.dirname(__file__) + # 数据库存放地址 + self.db_file = current_path + '/../Config/Point_db.db' + self.judge_init() + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + + # 读取积分配置 + self.sign_point = config['Point_Function']['Sign_Point'] + + # 打开数据库 + def open_db(self): + conn = sqlite3.connect(database=self.db_file, ) + cursor = conn.cursor() + return conn, cursor + + # 关闭数据库 + def close_db(self, conn, cursor): + cursor.close() + conn.close() + + # 判断数据库是否初始化 + def judge_init(self, ): + conn, cursor = self.open_db() + judge_table_sql = '''SELECT name FROM sqlite_master;''' + cursor.execute(judge_table_sql) + data = cursor.fetchall() + if not data: + msg = '[+]:检测到积分数据库未初始化,正在初始化数据库' + self.init_db() + output(msg) + self.close_db(conn, cursor) + + + # 初始化数据库 + def init_db(self): + conn, cursor = self.open_db() + create_point_table_sql = '''CREATE TABLE IF NOT EXISTS points + (wx_id varchar(255), + wx_name varchar(255), + point int(20));''' + create_sign_table_sql = '''CREATE TABLE IF NOT EXISTS sign (wx_id varchar(255), wx_name varchar(255));''' + cursor.execute(create_point_table_sql) + cursor.execute(create_sign_table_sql) + self.close_db(conn, cursor) + output('[*]:积分服务初始化成功!') + + # 初始化新用户 + def init_user(self, wx_id, wx_name): + conn, cursor = self.open_db() + add_user_sql = f'''INSERT INTO points VALUES ('{wx_id}', '{wx_name}', 0);''' + cursor.execute(add_user_sql) + conn.commit() + self.close_db(conn, cursor) + + # 判断用户是否存在 + def judge_user(self, wx_id, sign_bool=False): + conn, cursor = self.open_db() + judge_user_sql = f'''SELECT wx_id FROM points WHERE wx_id='{wx_id}';''' + if sign_bool: + judge_user_sql = f'''SELECT wx_id FROM sign WHERE wx_id='{wx_id}';''' + cursor.execute(judge_user_sql) + data = cursor.fetchall() + if data: + return True + else: + return False + + # 增加积分 + def add_point(self, wx_id, point): + conn, cursor = self.open_db() + add_point_sql = f'''UPDATE points SET point=point+{point} WHERE wx_id='{wx_id}';''' + cursor.execute(add_point_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'\n基于你的优越表现,+{point}分\n当前未使用积分:{self.query_point(wx_id=wx_id, )}分' + return msg + + # 扣除积分 + def del_point(self, wx_id, point): + conn, cursor = self.open_db() + add_point_sql = f'''UPDATE points SET point=point-{point} WHERE wx_id='{wx_id}';''' + cursor.execute(add_point_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'\n介于你的近期表现,-{point}分\n当前未使用积分:{self.query_point(wx_id=wx_id, )}分' + return msg + + # 查询积分 + def query_point(self, wx_id): + conn, cursor = self.open_db() + query_point_sql = f'''SELECT point FROM points WHERE wx_id='{wx_id}';''' + cursor.execute(query_point_sql) + data = cursor.fetchone()[0] + return data + + # 签到功能 + def sign(self, wx_id, wx_name): + conn, cursor = self.open_db() + sign_sql = f'''INSERT INTO sign VALUES ('{wx_id}', '{wx_name}');''' + self.add_point(wx_id=wx_id, point=self.sign_point) + cursor.execute(sign_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'签到成功 + {self.sign_point} 分\n当前可用积分:{self.query_point(wx_id=wx_id)}' + return msg + + # 清空签到表 + def clear_sign(self): + conn, cursor = self.open_db() + clear_sign_sql = 'DELETE FROM sign' + cursor.execute(clear_sign_sql) + conn.commit() + self.close_db(conn, cursor) + + # 积分赠送 + def give_point(self, wx_id, wx_name, at_wx_id, at_wx_name, point): + if self.query_point(wx_id=wx_id) >= self.query_point(wx_id=at_wx_id): + # 赠送人扣除积分 + self.judge_main(wx_id=wx_id, wx_name=wx_name, point=point, del_bool=True) + # 被赠送人增加积分 + self.judge_main(wx_id=at_wx_id, wx_name=at_wx_name, point=point, add_bool=True) + msg = f'\n您已给予 {at_wx_name} {point}分 \n当前可用积分 {self.query_point(wx_id=wx_id)}分' + else: + msg = f'\n您当前的余额不足\n当前可用积分:{self.query_point(wx_id=wx_id)} 分' + give_bool = True + return msg, give_bool + + # 主判断 + def judge_main(self, wx_id, wx_name, point=None, add_bool=False, del_bool=False, sign_bool=False): + msg = '' + if sign_bool: + if not self.judge_user(wx_id=wx_id, sign_bool=True): + if self.judge_user(wx_id=wx_id, ): + msg = self.sign(wx_id=wx_id, wx_name=wx_name, ) + else: + output('[+]:当前用户不存在,正在初始化该用户... ...') + self.init_user(wx_id=wx_id, wx_name=wx_name) + msg = self.sign(wx_id=wx_id, wx_name=wx_name) + elif add_bool: + if self.judge_user(wx_id=wx_id): + msg = self.add_point(wx_id=wx_id, point=point) + else: + output('[+]:当前用户不存在,正在初始化该用户... ...') + self.init_user(wx_id=wx_id, wx_name=wx_name) + msg = self.add_point(wx_id=wx_id, point=point) + elif del_bool: + if self.judge_user(wx_id=wx_id): + msg = self.del_point(wx_id=wx_id, point=point) + else: + output('[+]:当前用户不存在,正在初始化该用户... ...') + self.init_user(wx_id=wx_id, wx_name=wx_name) + msg = self.del_point(wx_id=wx_id, point=point) + return msg + + +if __name__ == '__main__': + Dps = Db_Point_Server() + # Dps.init_db() + msg = Dps.judge_main(wx_id='123123123', wx_name='123', sign_bool=True, point=230) + print(msg) + # Dps.query_point(wx_id='123') diff --git a/Db_Server/Db_User_Server.py b/Db_Server/Db_User_Server.py new file mode 100644 index 0000000..caa01c6 --- /dev/null +++ b/Db_Server/Db_User_Server.py @@ -0,0 +1,193 @@ +from Output.output import output +import sqlite3 +import os + + +class Db_User_Server: + def __init__(self): + current_path = os.path.dirname(__file__) + # 数据库存放地址 + self.db_file = current_path + '/../Config/User_db.db' + self.judge_init() + + # 打开数据库 + def open_db(self): + conn = sqlite3.connect(database=self.db_file, ) + cursor = conn.cursor() + return conn, cursor + + # 关闭数据库 + def close_db(self, conn, cursor): + cursor.close() + conn.close() + + # 判断是否初始化 + def judge_init(self, ): + conn, cursor = self.open_db() + judge_table_sql = '''SELECT name FROM sqlite_master;''' + cursor.execute(judge_table_sql) + data = cursor.fetchall() + if not data: + msg = '[-]:检测到用户数据库未初始化,正在初始化数据库' + output(msg) + self.init_db() + self.close_db(conn, cursor) + + # 初始化数据库 + def init_db(self): + conn, cursor = self.open_db() + create_admin_table_sql = '''CREATE TABLE IF NOT EXISTS admins + (wx_id varchar(255), + wx_name varchar(255), + wx_roomid varchar(255), + wx_room_name varchar(255));''' + create_white_rooms = '''CREATE TABLE IF NOT EXISTS white_rooms + (wx_roomid varchar(255), + wx_room_name varchar(255));''' + create_black_rooms = '''CREATE TABLE IF NOT EXISTS black_rooms + (wx_roomid varchar(255), + wx_room_name varchar(255));''' + cursor.execute(create_admin_table_sql) + cursor.execute(create_white_rooms) + cursor.execute(create_black_rooms) + self.close_db(conn=conn, cursor=cursor) + output('[*]:用户数据库服务初始化成功!') + + # 添加管理员 + def add_admin(self, wx_id, wx_roomid, wx_name, wx_room_name): + if not self.judge_data(wx_id=wx_id, wx_roomid=wx_roomid): + conn, cursor = self.open_db() + add_admin_sql = f'''INSERT INTO admins VALUES ( + '{wx_id}', '{wx_name}', '{wx_roomid}', '{wx_room_name}');''' + cursor.execute(add_admin_sql) + conn.commit() + self.close_db(conn=conn, cursor=cursor) + msg = f'添加管理员 {wx_name} 成功!' + else: + msg = f'管理员 {wx_name} 已存在!' + return msg + + # 删除管理员 + def del_admin(self, wx_id, wx_name, wx_roomid): + if self.judge_data(wx_id=wx_id, wx_roomid=wx_roomid): + conn, cursor = self.open_db() + del_admin_sql = f'''DELETE FROM admins WHERE wx_id='{wx_id}' and wx_roomid='{wx_roomid}';''' + cursor.execute(del_admin_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'移除管理员 {wx_name} 成功!' + else: + msg = f'管理员 {wx_name} 已移出!' + return msg + + # 查看所有管理员 + def show_admin(self): + conn, cursor = self.open_db() + show_admin_sql = '''SELECT wx_id, wx_roomid FROM admins;''' + cursor.execute(show_admin_sql) + data = cursor.fetchall() + self.close_db(conn, cursor) + msg = [] + for d in data: + msg.append({'wx_id': d[0], 'wx_roomid': d[1]}) + return msg + + # 添加黑名单群聊 + def add_black_room(self, wx_roomid, wx_room_name): + if not self.judge_data(black_bool=True, wx_roomid=wx_roomid): + conn, cursor = self.open_db() + add_black_room_sql = f'''INSERT INTO black_rooms VALUES ('{wx_roomid}', '{wx_room_name}');''' + cursor.execute(add_black_room_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'{wx_room_name} 群聊已拉黑! ' + else: + msg = '当前群聊已添加至黑名单' + return msg + + # 删除黑名单群聊 + def del_black_room(self, wx_roomid, wx_room_name): + if self.judge_data(wx_roomid=wx_roomid, black_bool=True): + conn, cursor = self.open_db() + del_black_room_sql = f'''DELETE FROM black_rooms WHERE wx_roomid='{wx_roomid}';''' + cursor.execute(del_black_room_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'移除黑名单群聊 {wx_room_name} 成功!' + else: + msg = '该群聊未被拉黑!' + return msg + + # 查看黑名单群聊 + def show_black_room(self): + conn, cursor = self.open_db() + show_black_room_sql = '''SELECT wx_roomid FROM black_rooms;''' + cursor.execute(show_black_room_sql) + data = cursor.fetchall() + self.close_db(conn, cursor) + msg = list() + for d in data: + msg.append({'wx_roomid': d[0]}) + return msg + + # 添加白名单群聊 + def add_white_room(self, wx_roomid, wx_room_name): + if not self.judge_data(wx_roomid=wx_roomid): + conn, cursor = self.open_db() + add_white_room_sql = f'''INSERT INTO white_rooms VALUES ('{wx_roomid}', '{wx_room_name}');''' + cursor.execute(add_white_room_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'{wx_room_name} 群聊已开启推送服务!' + else: + msg = '该群聊已开启推送服务!' + return msg + + # 删除白名单群聊 + def del_white_room(self, wx_roomid, wx_room_name): + if self.judge_data(wx_roomid=wx_roomid, ): + conn, cursor = self.open_db() + del_white_room_sql = f'''DELETE FROM white_rooms WHERE wx_roomid='{wx_roomid}';''' + cursor.execute(del_white_room_sql) + conn.commit() + self.close_db(conn, cursor) + msg = f'{wx_room_name} 群聊已关闭推送服务!' + else: + msg = '该群聊未开启推送服务!' + return msg + + # 查看白名单群聊 + def show_white_room(self): + conn, cursor = self.open_db() + show_white_room_sql = '''SELECT wx_roomid FROM white_rooms;''' + cursor.execute(show_white_room_sql) + data = cursor.fetchall() + self.close_db(conn, cursor) + white_rooms = list() + for d in data: + white_rooms.append(d[0]) + return white_rooms + + # 判断表中数据是否存在 True False + def judge_data(self, wx_id=None, wx_roomid=None, black_bool=False): + conn, cursor = self.open_db() + if wx_id: + sql = f'''SELECT wx_id FROM admins WHERE wx_id='{wx_id}' and wx_roomid='{wx_roomid}';''' + elif black_bool: + sql = f'''SELECT wx_roomid FROM black_rooms where wx_roomid='{wx_roomid}';''' + else: + sql = f'''SELECT wx_roomid FROM white_rooms where wx_roomid='{wx_roomid}';''' + cursor.execute(sql) + data = cursor.fetchall() + if data: + return True + else: + return False + + +if __name__ == '__main__': + Dus = Db_User_Server() + # Dus.init_db() + # Dus.add_admin(wx_id='yunyun', wx_name='云云', wx_roomid='123123', wx_room_name='测试') + # Dus.del_admin(wx_id='yunyun', wx_name='云云', wx_roomid='123123') + Dus.show_admin() diff --git a/Monitor_Server/Monitor_Server_Main.py b/Monitor_Server/Monitor_Server_Main.py new file mode 100644 index 0000000..057c7bb --- /dev/null +++ b/Monitor_Server/Monitor_Server_Main.py @@ -0,0 +1,533 @@ +from Db_Server.Db_User_Server import Db_User_Server +from BotServer.SendServer import SendServer +from collections import OrderedDict +from Output.output import output +from lxml import etree +import requests +import datetime +import hashlib +import sqlite3 +import json +import yaml +import time +import re +import os + + +class Monitor_Server_Main: + def __init__(self, ws): + + self.ws = ws + self.Ss = SendServer() + self.Dus = Db_User_Server() + + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.db_file = current_path + '/../Config/Monitor_db.db' + + self.github_headers = { + 'Authorization': f"token {config['Monitor_Server']['Github_Token']}" + } + + self.tools_list = config['Monitor_Server']['tools_list'] + self.keyword_list = config['Monitor_Server']['keyword_list'] + self.user_list = config['Monitor_Server']['user_list'] + + self.judge_init() + + # 打开数据库 + def open_db(self): + conn = sqlite3.connect(self.db_file) + cur = conn.cursor() + return conn, cur + + # 关闭数据库 + def close_db(self, conn, cur): + cur.close() + conn.close() + + # 判断数据库是否初始化 + def judge_init(self, ): + conn, cursor = self.open_db() + judge_table_sql = '''SELECT name FROM sqlite_master;''' + cursor.execute(judge_table_sql) + data = cursor.fetchall() + if not data: + msg = '[+]:检测到积分数据库未初始化,正在初始化数据库' + self.create_database() + output(msg) + self.close_db(conn, cursor) + + # 初始化创建数据库 + def create_database(self, ): + conn, cur = self.open_db() + try: + cur.execute('''CREATE TABLE IF NOT EXISTS cve_monitor + (cve_name varchar(255), + pushed_at varchar(255), + cve_url varchar(255));''') + output("[+]:成功创建CVE监控表") + cur.execute('''CREATE TABLE IF NOT EXISTS keyword_monitor + (keyword_name varchar(255), + pushed_at varchar(255), + keyword_url varchar(255));''') + output("[+]:成功创建关键字监控表") + cur.execute('''CREATE TABLE IF NOT EXISTS redteam_tools_monitor + (tools_name varchar(255), + pushed_at varchar(255), + tag_name varchar(255));''') + output("[+]:成功创建红队工具监控表") + cur.execute('''CREATE TABLE IF NOT EXISTS user_monitor + (repo_name varchar(255));''') + output("[+]:成功创建大佬仓库监控表") + except Exception as e: + output("[ERROR]:创建监控表错误,错误信息:{}".format(e)) + conn.commit() # 数据库存储在硬盘上需要commit 存储在内存中的数据库不需要 + self.close_db(conn, cur) + self.wx_send(text='Github实时推送连接成功!', body='') + + # 根据排序获取本年前20条CVE + def getNews(self, ): + today_cve_info_tmp = [] + try: + # 抓取本年的 + year = datetime.datetime.now().year + api = "https://api.github.com/search/repositories?q=CVE-{}&sort=updated".format(year) + json_str = requests.get(api, headers=self.github_headers, timeout=10).json() + today_date = datetime.date.today() + n = len(json_str['items']) + if n > 20: + n = 20 + for i in range(0, n): + cve_url = json_str['items'][i]['html_url'] + try: + cve_name_tmp = json_str['items'][i]['name'].upper() + cve_name = re.findall('(CVE\-\d+\-\d+)', cve_name_tmp)[0].upper() + pushed_at_tmp = json_str['items'][i]['created_at'] + pushed_at = re.findall('\d{4}-\d{2}-\d{2}', pushed_at_tmp)[0] + if pushed_at == str(today_date): + today_cve_info_tmp.append( + {"cve_name": cve_name, "cve_url": cve_url, "pushed_at": pushed_at}) + except Exception as e: + pass + today_cve_info = OrderedDict() + for item in today_cve_info_tmp: + today_cve_info.setdefault(item['cve_name'], {**item, }) + today_cve_info = list(today_cve_info.values()) + return today_cve_info + except Exception as e: + output(f'[ERROR]:连接Github出错,错误信息:{e}') + return '', '', '' + + def getKeywordNews(self, keyword): + today_keyword_info_tmp = [] + try: + # 抓取本年的 + api = "https://api.github.com/search/repositories?q={}&sort=updated".format(keyword) + json_str = requests.get(api, headers=self.github_headers, timeout=10).json() + today_date = datetime.date.today() + n = len(json_str['items']) + if n > 20: + n = 20 + for i in range(0, n): + keyword_url = json_str['items'][i]['html_url'] + try: + keyword_name = json_str['items'][i]['name'] + pushed_at_tmp = json_str['items'][i]['created_at'] + pushed_at = re.findall('\d{4}-\d{2}-\d{2}', pushed_at_tmp)[0] + if pushed_at == str(today_date): + today_keyword_info_tmp.append( + {"keyword_name": keyword_name, "keyword_url": keyword_url, "pushed_at": pushed_at}) + except Exception as e: + output(f'[ERROR]:出现错误,错误信息:{e}') + today_keyword_info = OrderedDict() + for item in today_keyword_info_tmp: + today_keyword_info.setdefault(item['keyword_name'], {**item, }) + today_keyword_info = list(today_keyword_info.values()) + return today_keyword_info + + except Exception as e: + output(f'[ERROR]:连接Github出错,错误信息:{e}') + return today_keyword_info_tmp + + # 获取到的关键字仓库信息插入到数据库 + def keyword_insert_into_sqlite3(self, data): + conn, cur = self.open_db() + for i in range(len(data)): + try: + keyword_name = data[i]['keyword_name'] + cur.execute( + "INSERT INTO keyword_monitor (keyword_name,pushed_at,keyword_url) VALUES ('{}', '{}', '{}')".format( + keyword_name, data[i]['pushed_at'], data[i]['keyword_url'])) + except Exception as e: + output(f'[ERROR]:关键字仓库信息插入到数据库出错,错误信息:{e}') + self.close_db(conn, cur) + + # 查询数据库里是否存在该关键字仓库的方法 + def query_keyword_info_database(self, keyword_name): + conn, cur = self.open_db() + sql_grammar = "SELECT keyword_name FROM keyword_monitor WHERE keyword_name = '{}';".format(keyword_name) + cursor = cur.execute(sql_grammar) + self.close_db(conn, cur) + return len(list(cursor)) + + # 获取不存在数据库里的关键字信息 + def get_today_keyword_info(self, today_keyword_info_data): + today_all_keyword_info = [] + for i in range(len(today_keyword_info_data)): + try: + today_keyword_name = today_keyword_info_data[i]['keyword_name'] + today_cve_name = re.findall(r'(CVE\-\d+\-\d+)', today_keyword_info_data[i]['keyword_name'].upper()) + if len(today_cve_name) > 0 and self.query_cve_info_database(today_cve_name.upper()) == 1: + pass + Verify = self.query_keyword_info_database(today_keyword_name) + if Verify == 0: + today_all_keyword_info.append(today_keyword_info_data[i]) + except Exception as e: + output(f'[ERROR]:获取不存在数据库里的关键字信息出错,错误信息:{e}') + return today_all_keyword_info + + # 获取到的CVE信息插入到数据库 + def cve_insert_into_sqlite3(self, data): + conn, cur = self.open_db() + for i in range(len(data)): + try: + cve_name = re.findall('(CVE\-\d+\-\d+)', data[i]['cve_name'])[0].upper() + cur.execute( + "INSERT INTO cve_monitor (cve_name,pushed_at,cve_url) VALUES ('{}', '{}', '{}')".format(cve_name, + data[i][ + 'pushed_at'], + data[i][ + 'cve_url'])) + except Exception as e: + output(f'[ERROR]:CVE信息插入到数据库出错,错误信息:{e}') + self.close_db(conn, cur) + + # 查询数据库里是否存在该CVE的方法 + def query_cve_info_database(self, cve_name): + conn, cur = self.open_db() + sql_grammar = "SELECT cve_name FROM cve_monitor WHERE cve_name = '{}';".format(cve_name) + cursor = cur.execute(sql_grammar) + self.close_db(conn, cur) + return len(list(cursor)) + + # 查询数据库里是否存在该tools工具名字的方法 + def query_tools_info_database(self, tools_name): + conn, cur = self.open_db() + sql_grammar = "SELECT tools_name FROM redteam_tools_monitor WHERE tools_name = '{}';".format(tools_name) + cursor = cur.execute(sql_grammar) + return len(list(cursor)) + + # 获取不存在数据库里的CVE信息 + def get_today_cve_info(self, today_cve_info_data): + today_all_cve_info = [] + for i in range(len(today_cve_info_data)): + try: + today_cve_name = re.findall('(CVE\-\d+\-\d+)', today_cve_info_data[i]['cve_name'])[0].upper() + if self.exist_cve(today_cve_name) == 1: + Verify = self.query_cve_info_database(today_cve_name.upper()) + if Verify == 0: + today_all_cve_info.append(today_cve_info_data[i]) + except Exception as e: + output(f'[ERROR]:获取不存在数据库里的CVE信息出错,错误信息:{e}') + return today_all_cve_info + + # 获取红队工具信息插入到数据库 + def tools_insert_into_sqlite3(self, data): + conn, cur = self.open_db() + for i in range(len(data)): + Verify = self.query_tools_info_database(data[i]['tools_name']) + if Verify == 0: + cur.execute( + "INSERT INTO redteam_tools_monitor (tools_name,pushed_at,tag_name) VALUES ('{}', '{}','{}')".format( + data[i]['tools_name'], data[i]['pushed_at'], data[i]['tag_name'])) + conn.commit() + self.close_db(conn, cur) + + # 获取红队工具的名称,更新时间,版本名称信息 + def get_pushed_at_time(self, tools_list): + tools_info_list = [] + for url in tools_list: + try: + tools_json = requests.get(url, headers=self.github_headers, timeout=10).json() + pushed_at_tmp = tools_json['pushed_at'] + pushed_at = re.findall('\d{4}-\d{2}-\d{2}', pushed_at_tmp)[0] # 获取的是API上的时间 + tools_name = tools_json['name'] + api_url = tools_json['url'] + try: + releases_json = requests.get(url + "/releases", headers=self.github_headers, timeout=10).json() + tag_name = releases_json[0]['tag_name'] + except Exception as e: + tag_name = "no releases" + tools_info_list.append( + {"tools_name": tools_name, "pushed_at": pushed_at, "api_url": api_url, "tag_name": tag_name}) + except Exception as e: + output(f'[ERROR]: 获取红队工具的名称,更新时间,版本名称信息出错,错误信息:{e}') + return tools_info_list + + # 根据红队名名称查询数据库红队工具的更新时间以及版本名称并返回 + def tools_query_sqlite3(self, tools_name): + conn, cur = self.open_db() + result_list = [] + sql_grammar = "SELECT pushed_at,tag_name FROM redteam_tools_monitor WHERE tools_name = '{}';".format(tools_name) + cursor = cur.execute(sql_grammar) + for result in cursor: + result_list.append({"pushed_at": result[0], "tag_name": result[1]}) + self.close_db(conn, cur) + return result_list + + # 获取更新了的红队工具在数据库里面的时间和版本 + def get_tools_update_list(self, data): + tools_update_list = [] + for dist in data: + query_result = self.tools_query_sqlite3(dist['tools_name']) + if len(query_result) > 0: + today_tools_pushed_at = query_result[0]['pushed_at'] + if dist['pushed_at'] != today_tools_pushed_at: + # 返回数据库里面的时间和版本 + tools_update_list.append({"api_url": dist['api_url'], "pushed_at": today_tools_pushed_at, + "tag_name": query_result[0]['tag_name']}) + return tools_update_list + + # 监控用户是否新增仓库,不是 fork 的 + def getUserRepos(self, user): + try: + api = "https://api.github.com/users/{}/repos".format(user) + json_str = requests.get(api, headers=self.github_headers, timeout=10).json() + today_date = datetime.date.today() + + for i in range(0, len(json_str)): + created_at = re.findall('\d{4}-\d{2}-\d{2}', json_str[i]['created_at'])[0] + if not json_str[i]['fork'] and created_at == str(today_date): + Verify = self.user_insert_into_sqlite3(json_str[i]['full_name']) + if Verify == 0: + name = json_str[i]['name'] + try: + description = json_str[i]['description'] + except Exception as e: + description = "作者未写描述" + download_url = json_str[i]['html_url'] + text = r'大佬' + r'** ' + user + r' ** ' + r'又分享了一款工具! ' + body = "工具名称: " + name + " \r\n" + "工具地址: " + download_url + " \r\n" + "工具描述: " + "" + description + self.wx_send(text=text, body=body) + except Exception as e: + output(f'[ERROR]:连接Github出错,错误信息:{e}') + + # 获取用户或者组织信息插入到数据库 + def user_insert_into_sqlite3(self, repo_name): + conn, cur = self.open_db() + sql_grammar = "SELECT repo_name FROM user_monitor WHERE repo_name = '{}';".format(repo_name) + Verify = len(list(cur.execute(sql_grammar))) + if Verify == 0: + cur.execute("INSERT INTO user_monitor (repo_name) VALUES ('{}')".format(repo_name)) + self.close_db(conn, cur) + return Verify + + # 获取更新信息并发送到对应社交软件 + def send_body(self, url, query_pushed_at, query_tag_name): + conn, cur = self.open_db() + json_str = requests.get(url + '/releases', headers=self.github_headers, timeout=10).json() + new_pushed_at = \ + re.findall('\d{4}-\d{2}-\d{2}', + requests.get(url, headers=self.github_headers, timeout=10).json()['pushed_at'])[ + 0] + if len(json_str) != 0: + tag_name = json_str[0]['tag_name'] + if query_pushed_at < new_pushed_at: + if tag_name != query_tag_name: + try: + update_log = json_str[0]['body'] + except Exception as e: + update_log = "作者未写更新内容" + download_url = json_str[0]['html_url'] + tools_name = url.split('/')[-1] + text = r'** ' + tools_name + r' ** 工具,版本更新啦!' + body = "工具名称:" + tools_name + "\r\n" + "工具地址:" + download_url + "\r\n" + "工具更新日志:" + "\r\n" + update_log + self.wx_send(text=text, body=body) + sql_grammar = "UPDATE redteam_tools_monitor SET tag_name = '{}' WHERE tools_name='{}'".format( + tag_name, + tools_name) + sql_grammar1 = "UPDATE redteam_tools_monitor SET pushed_at = '{}' WHERE tools_name='{}'".format( + new_pushed_at, tools_name) + cur.execute(sql_grammar) + cur.execute(sql_grammar1) + elif tag_name == query_tag_name: + commits_url = url + "/commits" + commits_url_response_json = requests.get(commits_url).text + commits_json = json.loads(commits_url_response_json) + tools_name = url.split('/')[-1] + download_url = commits_json[0]['html_url'] + try: + update_log = commits_json[0]['commit']['message'] + except Exception as e: + update_log = "作者未写更新内容,具体点击更新详情地址的URL进行查看" + text = r'** ' + tools_name + r' ** 工具小更新了一波!' + body = "工具名称:" + tools_name + "\r\n" + "更新详情地址:" + download_url + "\r\n" + "commit更新日志:" + "\r\n" + update_log + self.wx_send(text=text, body=body) + sql_grammar = "UPDATE redteam_tools_monitor SET pushed_at = '{}' WHERE tools_name='{}'".format( + new_pushed_at, tools_name) + cur.execute(sql_grammar) + else: + if query_pushed_at != new_pushed_at: + json_str = requests.get(url + '/commits', headers=self.github_headers, timeout=10).json() + update_log = json_str[0]['commit']['message'] + download_url = json_str[0]['html_url'] + tools_name = url.split('/')[-1] + text = r'** ' + tools_name + r' ** 工具更新啦!' + body = "工具名称:" + tools_name + "\r\n" + "工具地址:" + download_url + "\r\n" + "commit更新日志:" + "\r\n" + update_log + self.wx_send(text=text, body=body) + sql_grammar = "UPDATE redteam_tools_monitor SET pushed_at = '{}' WHERE tools_name='{}'".format( + new_pushed_at, tools_name) + cur.execute(sql_grammar) + # return update_log, download_url + self.close_db(conn, cur) + + # 创建md5对象 + def nmd5(self, str): + m = hashlib.md5() + b = str.encode(encoding='utf-8') + m.update(b) + str_md5 = m.hexdigest() + return str_md5 + + # 有道翻译 + def translate(self, word): + headerstr = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36' + bv = self.nmd5(headerstr) + lts = str(round(time.time() * 1000)) + salt = lts + '90' + strexample = 'fanyideskweb' + word + salt + 'Y2FYu%TNSbMCxc3t2u^XT' + sign = self.nmd5(strexample) + data = { + 'i': word, + 'from': 'AUTO', + 'to': 'AUTO', + 'smartresult': 'dict', + 'client': 'fanyideskweb', + 'salt': salt, + 'sign': sign, + 'lts': lts, + 'bv': bv, + 'doctype': 'json', + 'version': '2.1', + 'keyfrom': 'fanyi.web', + 'action': 'FY_BY_CLICKBUTTION', + } + url = 'http://fanyi.youdao.com/translate_o?smartresult=dict&smartresult=rule' + header = { + 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36', + 'Referer': 'http://fanyi.youdao.com/', + 'Origin': 'http://fanyi.youdao.com', + 'Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8', + 'X-Requested-With': 'XMLHttpRequest', + 'Accept': 'application/json, text/javascript, */*; q=0.01', + 'Accept-Encoding': 'gzip, deflate', + 'Accept-Language': 'zh-CN,zh;q=0.9', + 'Connection': 'keep-alive', + 'Host': 'fanyi.youdao.com', + 'cookie': '_ntes_nnid=937f1c788f1e087cf91d616319dc536a,1564395185984; OUTFOX_SEARCH_USER_ID_NCOO=; OUTFOX_SEARCH_USER_ID=-10218418@11.136.67.24; JSESSIONID=; ___rl__test__cookies=1' + } + res = requests.post(url=url, data=data, headers=header) + result_dict = res.json() + result = "" + for json_str in result_dict['translateResult'][0]: + tgt = json_str['tgt'] + result += tgt + return result + + # 判断是否存在该CVE + def exist_cve(self, cve): + try: + query_cve_url = "https://cve.mitre.org/cgi-bin/cvename.cgi?name=" + cve + response = requests.get(query_cve_url, timeout=10) + html = etree.HTML(response.text) + return 1 + except Exception as e: + return 0 + + # 根据cve 名字,获取描述,并翻译 + def get_cve_des_zh(self, cve): + time.sleep(3) + try: + query_cve_url = "https://cve.mitre.org/cgi-bin/cvename.cgi?name=" + cve + response = requests.get(query_cve_url, timeout=10) + html = etree.HTML(response.text) + des = html.xpath('//*[@id="GeneratedTable"]/table//tr[4]/td/text()')[0].strip() + cve_time = html.xpath('//*[@id="GeneratedTable"]/table//tr[11]/td[1]/b/text()')[0].strip() + return des, cve_time + except Exception as e: + pass + + # 发送CVE信息到社交工具 + def sendNews(self, data): + try: + text = '有新的CVE送达! \r\n** 请自行分辨是否为红队钓鱼!!! **' + # 获取 cve 名字 ,根据cve 名字,获取描述,并翻译 + for i in range(len(data)): + try: + cve_name = re.findall(r'(CVE\-\d+\-\d+)', data[i]['cve_name'])[0].upper() + cve_zh, cve_time = self.get_cve_des_zh(cve_name) + body = "CVE编号: " + cve_name + " --- " + cve_time + " \r\n" + "Github地址: " + str( + data[i]['cve_url']) + "\r\n" + "CVE描述: " + "\r\n" + cve_zh + self.wx_send(text=text, body=body) + except IndexError: + pass + except Exception as e: + output(f'[ERROR]:发送CVE信息到社交工具出现错误,错误信息:{e}') + + # 发送信息到社交工具 + def sendKeywordNews(self, keyword, data): + try: + text = '有新的关键字监控 - {} - 送达! \r\n** 请自行分辨是否为红队钓鱼!!! **'.format(keyword) + # 获取 cve 名字 ,根据cve 名字,获取描述,并翻译 + for i in range(len(data)): + try: + keyword_name = data[i]['keyword_name'] + body = "项目名称: " + keyword_name + "\r\n" + "Github地址: " + str(data[i]['keyword_url']) + "\r\n" + self.wx_send(text, body) + except IndexError: + pass + except Exception as e: + output(f'[ERROR]:发送信息到社交工具出现错误,错误信息:{e}') + + # 发送微信消息 + def wx_send(self, text, body): + roomid_list = self.Dus.show_white_room() + msg = text + '\n\n' + body + for roomid in roomid_list: + self.ws.send(self.Ss.send_msg(msg=msg.strip(), wxid=roomid)) + + # main函数 + def main(self, ): + while True: + output("[*]:Cve 、Github 工具 和 大佬仓库 监控中... ...") + tools_data = self.get_pushed_at_time(self.tools_list) + self.tools_insert_into_sqlite3(tools_data) # 获取文件中的工具列表,并从 github 获取相关信息,存储下来 + + for user in self.user_list: + self.getUserRepos(user) + # CVE部分 + cve_data = self.getNews() + if len(cve_data) > 0: + today_cve_data = self.get_today_cve_info(cve_data) + self.sendNews(today_cve_data) + self.cve_insert_into_sqlite3(today_cve_data) + # 关键字监控 , 最好不要太多关键字,防止 github 次要速率限制 https://docs.github.com/en/rest/overview/resources-in-the-rest-api#secondary-rate-limits= + for keyword in self.keyword_list: + time.sleep(1) # 每个关键字停 1s ,防止关键字过多导致速率限制 + keyword_data = self.getKeywordNews(keyword) + + if len(keyword_data) > 0: + today_keyword_data = self.get_today_keyword_info(keyword_data) + if len(today_keyword_data) > 0: + self.sendKeywordNews(keyword, today_keyword_data) + self.keyword_insert_into_sqlite3(today_keyword_data) + time.sleep(1) + data2 = self.get_pushed_at_time(self.tools_list) # 再次从文件中获取工具列表,并从 github 获取相关信息, + data3 = self.get_tools_update_list(data2) # 与 3 分钟前数据进行对比,如果在三分钟内有新增工具清单或者工具有更新则通知一下用户 + for i in range(len(data3)): + try: + self.send_body(data3[i]['api_url'], data3[i]['pushed_at'], data3[i]['tag_name']) + except Exception as e: + output(f"[ERROR]:main函数 try循环 遇到错误-->{e}") + output('OK') diff --git a/Output/output.py b/Output/output.py new file mode 100644 index 0000000..abb8be9 --- /dev/null +++ b/Output/output.py @@ -0,0 +1,18 @@ +from termcolor import cprint +import time + + +def output(msg): + if "error" in msg or "ERROR" in msg: + color = "red" + elif '[*]' in msg: + color = "cyan" + elif '[+]' in msg: + color = 'yellow' + else: + color = "magenta" + time_now = time.strftime("%Y-%m-%d %X") + cprint(f"[{time_now}]:{msg}", color) + + +output('') diff --git a/Push_Server/Push_Main_Server.py b/Push_Server/Push_Main_Server.py new file mode 100644 index 0000000..d3886d4 --- /dev/null +++ b/Push_Server/Push_Main_Server.py @@ -0,0 +1,76 @@ +from Monitor_Server.Monitor_Server_Main import Monitor_Server_Main +from Api_Server.Api_Server_Main import Api_Server_Main +from Db_Server.Db_Point_Server import Db_Point_Server +from Db_Server.Db_User_Server import Db_User_Server +from BotServer.SendServer import SendServer +from Output.output import output +import schedule +import yaml +import os + + +class Push_Main_Server: + def __init__(self, ws): + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../Config/config.yaml', encoding='UTF-8'), yaml.Loader) + self.db_file = current_path + '/../Config/Point_db.db' + + # 实例化用户类 + self.Dus = Db_User_Server() + + # 实例化积分类 + self.Dps = Db_Point_Server() + + # 实例化发送消息服务 + self.Ss = SendServer() + + # 实例化API类 + self.Asm = Api_Server_Main() + + # 实例化ws + self.ws = ws + + self.MSm = Monitor_Server_Main(ws=self.ws) + self.morning_page_time = config['Timed_Push']['Morning_Page_Time'] + self.evening_page_time = config['Timed_Push']['Evening_Page_Time'] + self.fish_time = config['Timed_Push']['Fish_Time'] + + # 早报推送 + def push_morning_page(self, ): + output('[+]:定时早报推送') + roomid_list = self.Dus.show_white_room() + msg = self.Asm.get_freebuf_news() + for roomid in roomid_list: + self.ws.send(self.Ss.send_msg(msg=msg, wxid=roomid)) + + # 晚报推送 + def push_evening_page(self, ): + output('[+]:定时晚间新闻推送') + roomid_list = self.Dus.show_white_room() + msg = self.Asm.get_safety_news() + for roomid in roomid_list: + self.ws.send(self.Ss.send_msg(msg=msg, wxid=roomid)) + + # 摸鱼日记推送 + def push_fish(self, ): + output('[+]:定时摸鱼日记推送') + roomid_list = self.Dus.show_white_room() + msg = self.Asm.get_fish() + for roomid in roomid_list: + self.Ss.send_msg(msg=msg, wxid=roomid) + + def push_clear_sign(self): + output('[+]:定时签到表清空') + self.Dps.clear_sign() + + def run(self): + schedule.every().day.at(self.morning_page_time).do(self.push_morning_page) + schedule.every().day.at(self.evening_page_time).do(self.push_evening_page) + schedule.every().day.at(self.fish_time).do(self.push_fish) + schedule.every().day.at('00:00').do(self.push_clear_sign) + # schedule.every(1).seconds.do(self.MSm.main) + schedule.every(30).minutes.do(self.MSm.main) + output('[*]:已开启定时推送服务!') + while True: + # output('[*]:已开启定时推送服务!') + schedule.run_pending() diff --git a/README.MD b/README.MD new file mode 100644 index 0000000..6913228 --- /dev/null +++ b/README.MD @@ -0,0 +1,298 @@ + +NGCBot +
+ + + ++一个基于✨HOOK机制的微信机器人,支持🌱安全新闻定时推送【FreeBuf,先知,安全客,奇安信攻防社区】,👯后缀名查询,⚡备案查询,⚡手机号归属地查询,⚡WHOIS信息查询,🎉星座查询,⚡天气查询,🌱摸鱼日历⚡微步威胁情报查询, +🐛美女视频,⚡美女图片,👯帮助菜单。📫 支持积分功能,😄自定义程度丰富,小白也可轻松上手! + +
+ +## 目录 + +- [介绍](#介绍) +- [项目结构](#项目结构) +- [如何使用](#如何使用) +- [功能介绍](###功能介绍) +- [配置文件说明](#配置文件说明) +- [后续优化计划](#后续优化计划) +- [后续开发计划](#后续开发计划) +- [更新日志](#更新日志) +- [特别鸣谢](#特别鸣谢) + +### 介绍 + + NGCBot是一个基于HOOK拦截机制的微信机器人,用户高强度自定义,支持多种功能,代码逻辑清晰,因为其HOOK机制,目前仅支持Windows版本。目前支持多种功能功能调用,小白也能轻松搭建!👯 + +### 项目结构 + +```shell + _ _ ____ ____ ____ _ + | \ | |/ ___|/ ___| __ ) ___ | |_ + | \| | | _| | | _ \ / _ \| __| + | |\ | |_| | |___| |_) | (_) | |_ + |_| \_|\____|\____|____/ \___/ \__| + +│ main.py ---主服务 +│ README.MD ---README文件 +│ requirements.txt ---依赖库 +│ test.py ---测试专用文件 +│ +├─BotServer --- 机器人服务 +│ │ MainServer.py --- 机器人主服务 +│ │ SendServer.py --- 发送消息服务 +│ │ __init__.py +│ │ +│ └─__pycache__ +│ MainServer.cpython-38.pyc +│ SendServer.cpython-38.pyc +│ __init__.cpython-38.pyc +│ +├─config --- 配置文件夹 +│ config.yaml +│ points.db --- 积分数据库 +│ privilege.db --- 管理数据库 +│ +├─DailyPush --- 定时推送文件夹 +│ │ Daily_push_server.py --- 定时推送服务 +│ │ Push_main_server.py --- 定时推送主服务 +│ │ __init__.py +│ │ +│ └─__pycache__ +│ Daily_push_server.cpython-38.pyc +│ Push_main_server.cpython-38.pyc +│ __init__.cpython-38.pyc +│ +├─Db_server --- 数据库服务文件夹 +│ │ Db_points_server.py --- 积分数据库服务 +│ │ Db_user_server.py --- 管理数据库服务 +│ │ +│ └─__pycache__ +│ Db_points_server.cpython-38.pyc +│ Db_user_server.cpython-38.pyc +│ +├─File +│ │ File_server.py --- 文件操作服务 +│ │ +│ ├─girl_pic --- 美女图片存放目录 +│ ├─girl_video --- 美女视频存放目录 +│ ├─touch_fish --- 摸鱼日历存放目录 +│ └─__pycache__ +│ File_server.cpython-38.pyc +│ +├─Get_api +| │ Api_github_cve_monitor.py --- CVE-Github工具实时监控 +│ │ Api_news_server.py --- 新闻获取服务 +│ │ Api_server.py --- 其它API调用服务 +│ │ __init__.py +│ │ +│ └─__pycache__ +│ Api_news_server.cpython-38.pyc +│ Api_server.cpython-38.pyc +│ __init__.cpython-38.pyc +│ +├─Output --- 信息输出文件夹 +│ │ output.py +│ │ __init__.py +│ │ +│ └─__pycache__ +│ output.cpython-38.pyc +│ __init__.cpython-38.pyc +│ +├─README.assets +│ image-20221212162417977.png +│ +├─recv_msg_dispose --- 接收消息处理服务 +│ │ FriendMsg_dispose.py --- 通讯录好友消息服务 +│ │ RoomMsg_dispose.py --- 群消息服务 +│ │ __init__.py +│ │ +│ └─__pycache__ +│ FriendMsg_dispose.cpython-38.pyc +│ RoomMsg_dispose.cpython-38.pyc +│ __init__.cpython-38.pyc +│ +└─注入器 --- 注入器 + 3.2.1.121-0.0.0.015_稳定版.dll + 3.2.1.121-0.0.0.018.dll + 3.3.0.115-0.0.0.001.dll + 3.6.0.18-0.0.0.004.dll + readme.md + version2.8.0.121-3.5.7.66.dll + version2.9.0.123-4.5.7.73.dll + version3.1.0.66-0.0.0.13.dll + 微信DLL注入器V1.0.3.exe +``` + +### 如何使用 + + 首先你需要一台Windows主机,并且安装`Python3.8`或者以上版本,接下来请安装依赖库 + +```python +pip install -r requirements.txt +``` + +安装完毕之后之后,需要下载`3.2.1.121`版本的微信,在[Releases](https://github.com/ngc660sec/NGCBot/releases/tag/v1.0)里面有提供的版本。登陆微信之后,在项目文件中打开`注入器`文件夹,进行注入 + + + +注入完毕之后,可以启动`main.py`文件 + +```python +python main.py +``` + +若无报错,恭喜🎉,你已经搭建完成! + +### 功能介绍 + +```shell +1. 超级管理员功能 + - 所有功能 +2. 普通管理员功能 + - 添加特权群聊 + - 删除特权群聊 + - 添加黑名单群聊 + - 删除黑名单群聊 + - 添加积分 + - 扣除积分 +3. 普通群聊功能 + - 娱乐功能 + - 积分功能 + - 自定义回复功能 +4. 特权群聊功能 + - 定时推送功能 + - 新人入群提醒 + - 普通群聊功能 + - CVE-Github工具实时监控 +5. 黑名单群聊功能 + - 积分功能 + - 自定义回复功能 +-------------------------------------------------------------------------------------------------------- +积分功能: + - 手机号归属地查询 + - WHOIS查询 + - 备案查询 + - 后缀名查询 + - 微步情报查询 + - 签到 + - 积分查询 +娱乐功能: + - AI对话 + - 美女视频 + - 美女图片 + - 舔狗日记 + - 摸鱼日历 + - 早安寄语 + - 星座运势查询 + - 天气查询 +``` + +### 配置文件说明 + +配置文件在`config`文件夹中,`config.yaml`就是配置文件,打开配置文件,我们需要做以下操作,来保证服务能够正常使用 + +1. 配置超级管理员【可配置多个超管用户】 + + - 运行Bot之后,随便给机器人发一条消息,来获取您的`wxid` + +  + + - 随后在配置文件中添加即可 + +  + + - 若要添加多个超管,请这样操作 + +  + +2. 配置您的API服务 + + - 配置天行API服务,请在[天行数据](https://www.tianapi.com/)中获取自己的相关配置 + +  + + - 配置微步KEY,请在[微步社区](https://x.threatbook.com/)获取您自己的KEY + +  + +3. 管理员配置说明 + + 管理员一共分为两种,一种是超级管理员,一种是普通管理员,超级管理员拥有添加管理,删除管理功能,管理员能够不用积分去使用积分功能,并且能够添加特权群聊,拉黑群聊的功能【超级管理员也有】 + + 添加管理员需要使用关键词@要添加的群友,例如`添加管理@云山`,当然,关键词可以自己配置 + + -  + + -  + +其它功能也是一样的,只不过不需要`@群友即可` + +-  + +-  + +4. 关键词回复配置 + - 如只有一个关键词配置,说明此功能只需要一个关键词即可触发 + -  + -  + - 如没有内容,说明今日没有文章 + - 如有两个关键词配置,说明此功能需要两个关键词触发 + -  + -  + +5. 自定义回复 + - 第一处地方,请写触发的关键词,第二处请写触发关键词后回复的内容 + -  + -  +6. 积分关键词配置 + - 可自定义签到口令,签到积分,功能积分,关键词配置 + -  +7. 系统消息配置 + - 可自定义入群欢迎消息,版权信息,下班通知【\n即为换行】 + -  + + 8. 由于时间关系,不方便详细暂时,可自行摸索,若在使用中有任何问题请随时联系 + +### 后续优化计划 + +```shell +1. 优化群消息处理【已优化】 +2. 优化相关配置信息【已优化】 +3. 优化积分模块【已优化,可@多人加积分】 +4. 有其它想法可提交iessus +5. ... ... +``` + +### 后续开发计划 + +``` +- Github工具 + CVE 实时推送【已对接】 +- MD5解密【暂时没钱】 +- ... ... +``` + +### 更新日志 + +``` +- 【2023.1.1】 推送NGCBot 1.3版本,重写部分代码,优化代码逻辑,优化积分功能,优化定时推送功能 +``` + +#### 最后,若在使用过程中有任何问题,也提交Iessus,或者关注微信公众号,后台回复消息 + + + +#### 特别鸣谢 + +- https://github.com/zhizhuoshuma/WechatBot +- https://github.com/tom-snow/wechat-windows-versions +- https://github.com/yhy0/github-cve-monitor diff --git a/README.assets/image-20221212162417977.png b/README.assets/image-20221212162417977.png new file mode 100644 index 0000000..eef3614 Binary files /dev/null and b/README.assets/image-20221212162417977.png differ diff --git a/README.assets/image-20221212181409831.png b/README.assets/image-20221212181409831.png new file mode 100644 index 0000000..44bde82 Binary files /dev/null and b/README.assets/image-20221212181409831.png differ diff --git a/README.assets/image-20221212182205271.png b/README.assets/image-20221212182205271.png new file mode 100644 index 0000000..d7a644a Binary files /dev/null and b/README.assets/image-20221212182205271.png differ diff --git a/README.assets/image-20221212182246271.png b/README.assets/image-20221212182246271.png new file mode 100644 index 0000000..c2353ea Binary files /dev/null and b/README.assets/image-20221212182246271.png differ diff --git a/README.assets/image-20221212182337205.png b/README.assets/image-20221212182337205.png new file mode 100644 index 0000000..bb68686 Binary files /dev/null and b/README.assets/image-20221212182337205.png differ diff --git a/README.assets/image-20221212182859195.png b/README.assets/image-20221212182859195.png new file mode 100644 index 0000000..9485199 Binary files /dev/null and b/README.assets/image-20221212182859195.png differ diff --git a/README.assets/image-20221212183023378.png b/README.assets/image-20221212183023378.png new file mode 100644 index 0000000..a0440dc Binary files /dev/null and b/README.assets/image-20221212183023378.png differ diff --git a/README.assets/image-20221212184032220.png b/README.assets/image-20221212184032220.png new file mode 100644 index 0000000..ea1efb0 Binary files /dev/null and b/README.assets/image-20221212184032220.png differ diff --git a/README.assets/image-20221212184133728.png b/README.assets/image-20221212184133728.png new file mode 100644 index 0000000..372352e Binary files /dev/null and b/README.assets/image-20221212184133728.png differ diff --git a/README.assets/image-20221212184307342.png b/README.assets/image-20221212184307342.png new file mode 100644 index 0000000..9be51f5 Binary files /dev/null and b/README.assets/image-20221212184307342.png differ diff --git a/README.assets/image-20221212184317466.png b/README.assets/image-20221212184317466.png new file mode 100644 index 0000000..ad1076a Binary files /dev/null and b/README.assets/image-20221212184317466.png differ diff --git a/README.assets/image-20221212185343056.png b/README.assets/image-20221212185343056.png new file mode 100644 index 0000000..72782f7 Binary files /dev/null and b/README.assets/image-20221212185343056.png differ diff --git a/README.assets/image-20221212185422047.png b/README.assets/image-20221212185422047.png new file mode 100644 index 0000000..930dcbb Binary files /dev/null and b/README.assets/image-20221212185422047.png differ diff --git a/README.assets/image-20221212185519094.png b/README.assets/image-20221212185519094.png new file mode 100644 index 0000000..5dfb540 Binary files /dev/null and b/README.assets/image-20221212185519094.png differ diff --git a/README.assets/image-20221212190112759.png b/README.assets/image-20221212190112759.png new file mode 100644 index 0000000..b6bbcd4 Binary files /dev/null and b/README.assets/image-20221212190112759.png differ diff --git a/README.assets/image-20221212190436791.png b/README.assets/image-20221212190436791.png new file mode 100644 index 0000000..fcf98fc Binary files /dev/null and b/README.assets/image-20221212190436791.png differ diff --git a/README.assets/image-20221212190457890.png b/README.assets/image-20221212190457890.png new file mode 100644 index 0000000..da62a26 Binary files /dev/null and b/README.assets/image-20221212190457890.png differ diff --git a/README.assets/image-20221212190611674.png b/README.assets/image-20221212190611674.png new file mode 100644 index 0000000..a39f603 Binary files /dev/null and b/README.assets/image-20221212190611674.png differ diff --git a/README.assets/image-20221212190838294.png b/README.assets/image-20221212190838294.png new file mode 100644 index 0000000..59e35a8 Binary files /dev/null and b/README.assets/image-20221212190838294.png differ diff --git "a/README.assets/\345\205\263\346\263\250.gif" "b/README.assets/\345\205\263\346\263\250.gif" new file mode 100644 index 0000000..20111ef Binary files /dev/null and "b/README.assets/\345\205\263\346\263\250.gif" differ diff --git a/Recv_Msg_Dispose/FriendMsg_dispose.py b/Recv_Msg_Dispose/FriendMsg_dispose.py new file mode 100644 index 0000000..c6084d3 --- /dev/null +++ b/Recv_Msg_Dispose/FriendMsg_dispose.py @@ -0,0 +1,81 @@ +from BotServer.SendServer import SendServer +from Api_Server.Api_Server_Main import Api_Server_Main +from Cache.Cache_Server import Cache_Server +import yaml +import re +import os + + +class FriendMsg_dispose: + def __init__(self): + # 初始化核心参数 + self.senderid = 'null' + self.nickname = 'null' + self.msgJson = '' + self.sendmsg = '' + self.keyword = '' + + # 读取配置文件 + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../config/config.yaml', encoding='UTF-8'), yaml.Loader) + + # 获取关键词 + self.cache_words = config['System_Config']['Cache_Config_Word'] + self.help_menu_words = config['System_Config']['Help_Menu'] + self.system_copyright = config['System_Config']['System_Copyright'] + + # 实例化消息发送服务 + self.Ss = SendServer() + + # 实例化接口服务类 + self.Asm = Api_Server_Main() + + # 实例化缓存操作类 + self.Cs = Cache_Server() + + def get_information(self, msgJson, senderid, ws): + self.senderid = senderid + self.nickname = self.Ss.get_member_nick(wxid=senderid, roomid='null') + self.keyword = msgJson['content'].replace('\u2005', '') + self.process_information(ws) + + def process_information(self, ws): + # 清除缓存 + if self.judge_keyword(keyword=self.keyword, custom_keyword=self.cache_words, ): + msg = self.Cs.delete_file() + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid)) + return + # 帮助菜单 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.help_menu_words): + msg = f"NGCBot功能菜单\n【积分功能】\n【1】、微步威胁IP查询\n\n您可在群内发送信息【WHOIS查询 qq.com】不需要@本Bot哦\n\n【娱乐功能】\n" \ + f"【1】、美女图片\n【2】、美女视频\n【3】、舔狗日记\n【4】、摸鱼日历\n【5】、星座查询\n【6】、AI对话\n【7】、手机号归属地查询\n【8】、WHOIS信息查询\n" \ + f"【9】、备案查询\n【10】、后缀名查询\n\n您可以在群内发送消息【查询运势 白羊座】进行查询【其它功能类似】,或@本Bot进行AI对话哦\n\n需要调出帮助菜单,回复即可【帮助菜单】\n" \ + f"{'By: #' + self.system_copyright if self.system_copyright else ''}" + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid)) + return + # AI对话 + elif self.keyword: + if self.keyword: + msg = self.Asm.get_ai(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid)) + else: + return + + # 判断关键词 + def judge_keyword(self, keyword, custom_keyword, split_bool=False, one_bool=False): + # 分割触发 + if split_bool: + keyword = keyword.split(' ') + for ckw in custom_keyword: + for kw in keyword: + if ckw == kw: + return True + # 单个触发 + elif one_bool: + return True if keyword.strip() == custom_keyword.strip() else False + # 单个循环触发 + elif keyword and custom_keyword and not split_bool and not one_bool: + return True if [ckw for ckw in custom_keyword if ckw == keyword] else False + + + diff --git a/Recv_Msg_Dispose/RoomMsg_dispose.py b/Recv_Msg_Dispose/RoomMsg_dispose.py new file mode 100644 index 0000000..56aebe8 --- /dev/null +++ b/Recv_Msg_Dispose/RoomMsg_dispose.py @@ -0,0 +1,375 @@ +from Api_Server.Api_Server_Main import Api_Server_Main +from Db_Server.Db_Point_Server import Db_Point_Server +from Db_Server.Db_User_Server import Db_User_Server +from BotServer.SendServer import SendServer +from Output.output import output +import yaml +import os +import re + + +class RoomMsg_disposes: + def __init__(self, ): + # 初始化核心参数 + self.bot_wxid = None + self.bot_name = None + self.room_name = None + self.at_nickname = None + self.at_wxid = None + self.roomid = 'null' + self.senderid = 'null' + self.nickname = 'null' + self.msgJson = '' + + # 处理过的接收的消息 + self.keyword = '' + + # 实例化消息服务 + self.Ss = SendServer() + + # 实例化接口服务类 + self.Asm = Api_Server_Main() + + # 实例化用户数据操作类 + self.Dus = Db_User_Server() + + # 实例化积分数据类 + self.Dps = Db_Point_Server() + + # 读取配置文件 + current_path = os.path.dirname(__file__) + config = yaml.load(open(current_path + '/../config/config.yaml', encoding='UTF-8'), yaml.Loader) + + # 读取超级管理员 + self.administrators = config['Administrators'] + + # 读取关键词配置 + self.pic_words = config['Key_Word']['Pic_Word'] + self.video_words = config['Key_Word']['Video_Word'] + self.icp_words = config['Key_Word']['Icp_Word'] + self.suffix_words = config['Key_Word']['Suffix_Word'] + self.attribution_words = config['Key_Word']['Attribution_Word'] + self.whois_words = config['Key_Word']['Whois_Word'] + self.fish_words = config['Key_Word']['Fish_Word'] + self.wether_words = config['Key_Word']['Weather_Word'] + self.dog_words = config['Key_Word']['Dog_Word'] + self.constellation_words = config['Key_Word']['Constellation_Word'] + self.morning_words = config['Key_Word']['Morning_Word'] + self.threatbook_words = config['Key_Word']['ThreatBook_Word'] + self.add_admin_words = config['Key_Word']['Add_Admin_Word'] + self.del_admin_words = config['Key_Word']['Del_Admin_Word'] + self.add_BlackRoom_words = config['Key_Word']['Add_BlackRoom_Word'] + self.del_BlackRoom_words = config['Key_Word']['Del_BlackRoom_Word'] + self.add_WhiteRoom_words = config['Key_Word']['Add_WhiteRoom_Word'] + self.del_WhiteRoom_words = config['Key_Word']['Del_WhiteRoom_Word'] + self.add_point_words = config['Point_Function']['Add_Point_Word'] + self.del_point_words = config['Point_Function']['Del_Point_Word'] + self.threatbook_point = config['Point_Function']['Function']['ThreatBook_Point'] + self.sign_keyword = config['Point_Function']['Sign_Keyword'] + self.query_point_words = config['Point_Function']['Query_Point'] + self.give_point_words = config['Point_Function']['Give_Point_Word'] + self.morning_page_words = config['Key_Word']['Morning_Page'] + self.evening_page_words = config['Key_Word']['Evening_Page'] + self.help_menu_words = config['System_Config']['Help_Menu'] + self.system_copyright = config['System_Config']['System_Copyright'] + + # 获取接收信息 + def get_information(self, msgJson, roomid, senderid, nickname, ws): + self.msgJson = msgJson + # 获取群聊ID + self.roomid = roomid + # 获取发送者微信ID + self.senderid = senderid + # 获取发送者名字 + self.nickname = nickname + + # 获取被@人的微信ID + + try: + self.at_wxid = re.findall(r" 20: + point_msg = f'\n您使用了IP查询功能,扣除对应积分 {self.threatbook_point}分\n当前可用积分:{self.Dps.query_point(wx_id=self.senderid)}' + self.Dps.del_point(wx_id=self.senderid, point=self.threatbook_point) + ws.send( + self.Ss.send_msg(msg=point_msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 签到口令提醒 + elif self.judge_keyword(keyword=self.keyword, custom_keyword='签到', one_bool=True): + msg = f'签到口令已改为:{self.sign_keyword}' + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, nickname=self.nickname, roomid=self.roomid)) + # 签到功能 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.sign_keyword, one_bool=True): + msg = self.Dps.judge_main(wx_id=self.senderid, wx_name=self.nickname, sign_bool=True) + if msg: + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, nickname=self.nickname, roomid=self.roomid)) + # 查询积分 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.query_point_words): + msg = f'\n当前可用积分:{0 if not self.Dps.query_point(wx_id=self.senderid) else self.Dps.query_point(wx_id=self.senderid)}' + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, nickname=self.nickname, roomid=self.roomid)) + + # 娱乐功能 + def Happy_Function(self, ws): + # AI对话 + if self.at_wxid == self.bot_wxid: + keyword = self.keyword.replace('@', '').replace(self.bot_name, '').strip() + if keyword: + msg = self.Asm.get_ai(keyword=keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, nickname=self.nickname, roomid=self.roomid, )) + else: + return + # 美女图片 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.pic_words): + msg = self.Asm.get_pic() + if '/' in msg: + self.Ss.send_img_room(msg=msg, roomid=self.roomid) + else: + ws.send(self.Ss.send_msg(msg=msg, roomid=self.roomid)) + # 美女视频 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.video_words): + msg = self.Asm.get_video() + if '/' in msg: + self.Ss.send_file_room(file=msg, roomid=self.roomid) + else: + ws.send(self.Ss.send_msg(msg=msg, wxid=self.roomid)) + # icp查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.icp_words, split_bool=True): + msg = self.Asm.get_icp(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 后缀名查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.suffix_words, split_bool=True): + msg = self.Asm.get_suffix(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 归属查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.attribution_words, split_bool=True): + msg = self.Asm.get_attribution(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # whois查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.whois_words, split_bool=True): + msg = self.Asm.get_whois(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 摸鱼日记 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.fish_words): + msg = self.Asm.get_fish() + self.Ss.send_img_room(msg=msg, roomid=self.roomid) + # 天气查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.wether_words, split_bool=True): + msg = self.Asm.get_wether(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 舔狗日记 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.dog_words): + msg = self.Asm.get_dog() + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 星座查询 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.constellation_words, split_bool=True): + msg = self.Asm.get_constellation(keyword=self.keyword) + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 早安寄语 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.morning_words): + msg = self.Asm.get_morning() + ws.send(self.Ss.send_msg(msg=msg, wxid=self.senderid, roomid=self.roomid, nickname=self.nickname)) + # 帮助菜单 + elif self.judge_keyword(keyword=self.keyword, custom_keyword=self.help_menu_words): + msg = f"NGCBot功能菜单\n【积分功能】\n【1】、微步威胁IP查询\n\n您可在群内发送信息【WHOIS查询 qq.com】不需要@本Bot哦\n\n【娱乐功能】\n" \ + f"【1】、美女图片\n【2】、美女视频\n【3】、舔狗日记\n【4】、摸鱼日历\n【5】、星座查询\n【6】、AI对话\n【7】、手机号归属地查询\n【8】、WHOIS信息查询\n" \ + f"【9】、备案查询\n【10】、后缀名查询\n\n您可以在群内发送消息【查询运势 白羊座】进行查询【其它功能类似】,或@本Bot进行AI对话哦\n\n需要调出帮助菜单,回复即可【帮助菜单】\n" \ + f"{'By: #' + self.system_copyright if self.system_copyright else ''}" + ws.send(self.Ss.send_msg(msg=msg, wxid=self.roomid)) + + # 判断关键词 + def judge_keyword(self, keyword, custom_keyword, split_bool=False, one_bool=False): + # 分割触发 + if split_bool: + keyword = keyword.split(' ') + for ckw in custom_keyword: + for kw in keyword: + if ckw == kw: + return True + # 单个触发 + elif one_bool: + return True if keyword.strip() == custom_keyword.strip() else False + # 单个循环触发 + elif keyword and custom_keyword and not split_bool and not one_bool: + return True if [ckw for ckw in custom_keyword if ckw == keyword] else False + + # 判断管理员 + def judge_admin(self, wxid, roomid): + admin_list = self.Dus.show_admin() + for data in admin_list: + if wxid == data['wx_id'] and roomid == data['wx_roomid']: + return True + else: + return False + + # 判断黑名单 + def judge_black_room(self, roomid): + black_rooms = self.Dus.show_black_room() + for data in black_rooms: + if roomid == data['wx_roomid']: + return True + else: + return False + + # 判断积分余额 + def judge_point(self, wxid, point): + user_point = self.Dps.query_point(wx_id=wxid) + return True if user_point > point else False + + # 判断积分增减赠送 + def judge_operation(self, keyword, ws): + list_bool = False + at_wx_nickname_list = list() + at_wxid_list = list() + if self.at_wxid: + operations = re.search( + f'@{self.at_nickname.strip() if self.at_nickname.strip() else "xx"}(?P\w)(?P \d+)', + keyword) + if ',' in self.at_wxid: + list_bool = True + at_wxid_list = self.at_wxid.split(',') + for at_wxid in at_wxid_list: + at_wx_nickname_list.append(self.Ss.get_member_nick(roomid=self.roomid, wxid=at_wxid)) + operations = re.search( + f'{"".join(at_wx_nickname_list) if "".join(at_wx_nickname_list) else "xx"}(?P \w)(?P \d+)', + keyword.replace('@', '')) + try: + operation = operations.group('operation') + point = int(operations.group('point')) + except Exception as e: + output(f'[+]:小报错,问题不大:{e}') + return + msg = '' + # print(operation, point) + give_bool = False + # 赠送积分 + if self.judge_keyword(keyword=operation, custom_keyword=self.add_point_words): + if list_bool: + for wxid, wx_name in zip(at_wxid_list, at_wx_nickname_list): + msg = self.Dps.judge_main(wx_id=self.at_wxid, wx_name=self.at_nickname, point=point, + add_bool=True) + ws.send( + self.Ss.send_msg(msg=msg, wxid=wxid, nickname=wx_name, roomid=self.roomid)) + else: + msg = self.Dps.judge_main(wx_id=self.at_wxid, wx_name=self.at_nickname, point=point, add_bool=True) + # 扣除积分 + if self.judge_keyword(keyword=operation, custom_keyword=self.del_point_words): + if list_bool: + for wxid, wx_name in zip(at_wxid_list, at_wx_nickname_list): + msg = self.Dps.judge_main(wx_id=self.at_wxid, wx_name=self.at_nickname, point=point, + del_bool=True) + ws.send( + self.Ss.send_msg(msg=msg, wxid=wxid, nickname=wx_name, roomid=self.roomid)) + else: + msg = self.Dps.judge_main(wx_id=self.at_wxid, wx_name=self.at_nickname, point=point, del_bool=True) + # 赠送积分 + if self.judge_keyword(keyword=operation, custom_keyword=self.give_point_words): + if list_bool: + for wxid, wx_name in zip(at_wxid_list, at_wx_nickname_list): + msg, give_bool = self.Dps.give_point(wx_id=self.senderid, wx_name=self.nickname, + at_wx_id=wxid, at_wx_name=wx_name, + point=point) + ws.send( + self.Ss.send_msg(msg=msg, wxid=self.senderid, nickname=self.nickname, roomid=self.roomid)) + else: + msg, give_bool = self.Dps.give_point(wx_id=self.senderid, wx_name=self.nickname, at_wx_id=self.at_wxid, at_wx_name=self.at_nickname, point=point) + if msg and not list_bool and ',' not in self.at_wxid: + if give_bool: + self.at_wxid = self.senderid + self.at_nickname = self.nickname + ws.send(self.Ss.send_msg(msg=msg, wxid=self.at_wxid, nickname=self.at_nickname, roomid=self.roomid)) diff --git a/main.py b/main.py new file mode 100644 index 0000000..4df19dc --- /dev/null +++ b/main.py @@ -0,0 +1,15 @@ +from BotServer.MainServer import MainServers + + +class Main: + + def __init__(self): + self.Ms = MainServers() + + def run(self): + self.Ms.Bot_start() + + +if __name__ == '__main__': + Mn = Main() + Mn.run() diff --git a/requirements.txt b/requirements.txt new file mode 100644 index 0000000..6995f42 --- /dev/null +++ b/requirements.txt @@ -0,0 +1,9 @@ +beautifulsoup4==4.11.1 +feedparser==6.0.10 +lxml==4.9.1 +PyYAML==6.0 +requests==2.28.1 +schedule==1.1.0 +termcolor==1.1.0 +urllib3==1.26.13 +websocket_client==1.4.2