API
La mayoría de las API no están documentadas (aunque puede entender cómo funcionan a partir del código…) porque no son relevantes desde el punto de vista de un cliente, y solo se utilizan para la comunicación entre el frontend y el backend.
Estas son las que hemos decidido documentar, que resultan realmente útiles si tiene previsto crear su propio cliente que funcione con un servidor MRF. Para llamar a una API, utilice esta URL de plantilla: http://yourmrfserver.xyz/api.php?action=theapi&token=yourapikey¶m1=value¶m2=value¶m
downloadfile
GET
http://localhost/api.php?token=my_token&action=downloadfile&file=the_md5
description:
Download a file by MD5
return data:
Binary file
bulkdownload
GET
http://localhost/api.php?token=my_token&action=bulkdownload&files[]=the_md5&files[]=the_other_md5
return data:
Binary data (Zip archive)
getfile
GET
http://localhost/api.php?token=my_token&action=getfile&hash=the_md5
return data: Json object with metadata of the file
uploadfiles
POST
http://localhost/api.php?token=my_token&action=uploadfilesT
parameters:
$FILES[]=(files upload)
vtsubmit[]=[true, false, ...]
cksubmit[]=[false, true, ...]
tags[]=["spam,malware", "another", ...]
comment=the_comment
return data: HTTP code 200 if success
addcomment
POST
http://localhost/api.php?token=my_token&action=addcomment
parameters:
hash=the_md5
comment={"content": "the content", "parent": parent_comment_id}
return data: HTTP code 201 if success
Ejemplo de script de subida
#!/usr/bin/python
import hashlib
import json
import ost
import logging
import requests
# Parameters, don't forget to modify
apikey = "your_token"
host = "mrf.yourserver.com"
urlserver = "http://mrf.yourserver.com/api.php?action=uploadfiles"
def post_multipart(host, selector, fields, files):
headers = {'user-agent': 'Dionaea honeypot'}
r = requests.post(selector, headers=headers, data=fields, files=files)
def file_md5(fname):
hash_md5 = hashlib.md5()
with open(fname, "rb") as f:
for chunk in iter(lambda: f.read(4096), b""):
hash_md5.update(chunk)
return hash_md5.hexdigest()
def UploadFile(pl):
md5 = file_md5(pl)
filename = os.path.basename(pl)
parameters = {"hash": md5, "comment": "", "token": apikey, "tags":["honeypot"], "vtsubmit":[True], "cksubmit":[False]}
# Send file to server API
with open(pl, 'rb') as f:
files = {filename: f}
post_multipart(host, urlserver, parameters, files)