API
La plupart des API ne sont pas documentées (même si vous pouvez comprendre leur fonctionnement à partir du code…) car elles ne sont pas pertinentes du point de vue d'un client, et servent uniquement à la communication entre le front et le back end.
Voici celles que nous avons décidé de documenter, qui sont vraiment utiles si vous prévoyez de créer votre propre client fonctionnant avec un serveur MRF. Pour appeler une API, utilisez ce modèle d'url : http://yourmrfserver.xyz/api.php?action=theapi&token=yourapikey¶m1=value¶m2=value¶m
downloadfile
GET
http://localhost/api.php?token=my_token&action=downloadfile&file=the_md5
description:
Download a file by MD5
return data:
Binary file
bulkdownload
GET
http://localhost/api.php?token=my_token&action=bulkdownload&files[]=the_md5&files[]=the_other_md5
return data:
Binary data (Zip archive)
getfile
GET
http://localhost/api.php?token=my_token&action=getfile&hash=the_md5
return data: Json object with metadata of the file
uploadfiles
POST
http://localhost/api.php?token=my_token&action=uploadfilesT
parameters:
$FILES[]=(files upload)
vtsubmit[]=[true, false, ...]
cksubmit[]=[false, true, ...]
tags[]=["spam,malware", "another", ...]
comment=the_comment
return data: HTTP code 200 if success
addcomment
POST
http://localhost/api.php?token=my_token&action=addcomment
parameters:
hash=the_md5
comment={"content": "the content", "parent": parent_comment_id}
return data: HTTP code 201 if success
Exemple de script d'upload
#!/usr/bin/python
import hashlib
import json
import ost
import logging
import requests
# Parameters, don't forget to modify
apikey = "your_token"
host = "mrf.yourserver.com"
urlserver = "http://mrf.yourserver.com/api.php?action=uploadfiles"
def post_multipart(host, selector, fields, files):
headers = {'user-agent': 'Dionaea honeypot'}
r = requests.post(selector, headers=headers, data=fields, files=files)
def file_md5(fname):
hash_md5 = hashlib.md5()
with open(fname, "rb") as f:
for chunk in iter(lambda: f.read(4096), b""):
hash_md5.update(chunk)
return hash_md5.hexdigest()
def UploadFile(pl):
md5 = file_md5(pl)
filename = os.path.basename(pl)
parameters = {"hash": md5, "comment": "", "token": apikey, "tags":["honeypot"], "vtsubmit":[True], "cksubmit":[False]}
# Send file to server API
with open(pl, 'rb') as f:
files = {filename: f}
post_multipart(host, urlserver, parameters, files)