Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,20 @@
The release notes on GitHub are taken from this file: the section whose
heading is the version number.

## 1.6.0

Sign-in and users
- A new installation and the demo sign in as admin / traffic66; the
sign-in page shows it while it is still in use. A new installation asks
for a new password at the first sign-in, before anything else.
Installations that already have a password file keep it.
- **Account** at the foot of the menu: change your password. The
administrator (admin) also adds and deletes users and resets passwords;
the password file is the same one `traffic66 passwd` writes.
- LDAP / Active Directory sign-in is shown as in development.
- With -password or TRAFFIC66_PASSWORD, passwords are not changed from the
web UI, and the page says so.

## 1.5.2

Fixes
Expand Down
28 changes: 16 additions & 12 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,12 +43,12 @@ Download your system's archive from the
(Windows x64, Linux x86-64/ARM64 with kernel 3.2+, macOS 11+), unpack it and run:

```
./traffic66 demo -password try66 # Linux, macOS
.\traffic66.exe demo -password try66 # Windows
./traffic66 demo # Linux, macOS
.\traffic66.exe demo # Windows
```

On macOS first run `xattr -dr com.apple.quarantine <folder>`. Open
http://127.0.0.1:8066 as `admin` / `try66`: a day of history and live
http://127.0.0.1:8066 as `admin` / `traffic66`: a day of history and live
traffic from four simulated devices, including an attack shown step by step
on **Findings**. Ctrl+C stops it; delete `traffic66-demo` to start afresh.
To run it next to a real installation: `-addr :8067 -listen ""`.
Expand Down Expand Up @@ -103,8 +103,7 @@ Register-ScheduledTask -TaskName traffic66 -Action $a -Trigger (New-ScheduledTas
Start-ScheduledTask -TaskName traffic66
```

Double-clicking `traffic66.exe` also works: it opens the web UI and shows
the first password in its window.
Double-clicking `traffic66.exe` also works: it opens the web UI.

**macOS**: unpack to `/usr/local/traffic66`, remove the quarantine flag,
run `traffic66 passwd -data "/Library/Application Support/traffic66"`, and
Expand All @@ -113,11 +112,16 @@ start it from a LaunchDaemon whose `ProgramArguments` are the program,

## 3. Users and passwords

On first start traffic66 creates the user `admin` with a random password
and prints it once (in the window, the terminal, or
`journalctl -u traffic66 | grep "first start"`). Users are kept as salted
hashes in `password` in the data directory and managed with one command on
the traffic66 machine (add `-data …` when traffic66 runs with it):
A new installation signs in as `admin` / `traffic66`, and the first sign-in
asks for a new password before anything else is shown (the demo keeps
`traffic66`). Afterwards **Account**, at the foot of the menu, changes your
password; the administrator (`admin`) also adds and deletes users and
resets their passwords there. Sign-in with LDAP / Active Directory is in
development.

Users are kept as salted hashes in `password` in the data directory. The
same can be done on the traffic66 machine with one command (add `-data …`
when traffic66 runs with it):

| To | Command |
|---|---|
Expand All @@ -126,8 +130,8 @@ the traffic66 machine (add `-data …` when traffic66 runs with it):
| Delete `alice` | `traffic66 passwd -user alice -delete` |
| List users | `traffic66 passwd -list` |

Changes apply at once. All users have the same rights. For scripts and
containers, `TRAFFIC66_PASSWORD=…` (or `-password`) accepts only `-user`
Changes apply at once. Apart from managing users, all users have the same
rights. For scripts and containers, `TRAFFIC66_PASSWORD=…` (or `-password`) accepts only `-user`
with that password for that run. Five wrong passwords in a minute block the
address for a minute.

Expand Down
19 changes: 11 additions & 8 deletions cmd/traffic66/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -382,7 +382,7 @@ func serve(args []string, demo bool) {
poller.Run(ctx)
}()

checker := loginChecker(f.data, f.user, f.password)
checker := loginChecker(f.data, f.user, f.password, demo)
tok := randomHex(24)
tokPath := filepath.Join(f.data, ".tui-token")
os.WriteFile(tokPath, []byte(tok), 0o600)
Expand All @@ -394,7 +394,7 @@ func serve(args []string, demo bool) {
dns = dnsres.New(dnsres.Options{Upstream: f.dnsUpstream, PerSecond: f.dnsRate, TTL: f.dnsTTL})
}
srv := &api.Server{Store: st, Pipe: pipe, Col: col, Inv: inv, ASN: asn, Thr: thr, DNS: dns, Det: det, Static: web.FS(), Version: version,
Demo: demo, Check: checker.Check, Exists: checker.Exists, LocalTok: tok, DataDir: f.data, Started: time.Now()}
Demo: demo, Check: checker.Check, Exists: checker.Exists, Accounts: checker, LocalTok: tok, DataDir: f.data, Started: time.Now()}
srv.SNMP = poller.Status
licDir := f.data
if offline != nil {
Expand Down Expand Up @@ -688,8 +688,9 @@ func defaultDir(name string) string {

// loginChecker decides where the password comes from: -password, then
// TRAFFIC66_PASSWORD, then the password file in the data directory. On the
// very first start it creates the file with a generated password.
func loginChecker(dir, user, flagPw string) *auth.FileChecker {
// very first start it creates the file with the default password, which
// the web UI asks to change at the first sign-in (except in the demo).
func loginChecker(dir, user, flagPw string, demo bool) *auth.FileChecker {
pw := flagPw
if pw == "" {
pw = os.Getenv("TRAFFIC66_PASSWORD")
Expand All @@ -704,12 +705,14 @@ func loginChecker(dir, user, flagPw string) *auth.FileChecker {
fatalf("%s: %v", file, err)
}
if len(es) == 0 {
pw = auth.Generate()
if err := auth.Set(dir, user, pw); err != nil {
if err := auth.Set(dir, user, auth.DefaultPassword); err != nil {
fatalf("saving the password: %v", err)
}
log.Printf("first start: sign in as user %q with password %q", user, pw)
log.Printf("this password is kept (hashed) in %s; change it with: traffic66 passwd -data %s", file, quoteArg(dir))
if demo {
log.Printf("demo: sign in as user %q with password %q", user, auth.DefaultPassword)
} else {
log.Printf("first start: sign in as user %q with password %q; a new password is asked for at the first sign-in", user, auth.DefaultPassword)
}
} else {
var users []string
for _, e := range es {
Expand Down
27 changes: 15 additions & 12 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,12 @@ Kafka أو قاعدة بيانات منفصلة.
(Windows x64، وLinux x86-64/ARM64 بنواة 3.2+، وmacOS 11+)، وفكّ ضغطه وشغّل:

```
./traffic66 demo -password try66 # Linux, macOS
.\traffic66.exe demo -password try66 # Windows
./traffic66 demo # Linux, macOS
.\traffic66.exe demo # Windows
```

على macOS شغّل أولًا `xattr -dr com.apple.quarantine <folder>`. افتح
http://127.0.0.1:8066 وسجّل الدخول بـ `admin` / `try66`: سجلّ يوم كامل وحركة
http://127.0.0.1:8066 وسجّل الدخول بـ `admin` / `traffic66`: سجلّ يوم كامل وحركة
حية من أربعة أجهزة محاكاة، ومنها هجوم يُعرض خطوةً خطوة في **الاكتشافات**. يوقفه
Ctrl+C؛ احذف `traffic66-demo` لتبدأ من جديد. لتشغيله بجوار تثبيت حقيقي:
`-addr :8067 -listen ""`.
Expand Down Expand Up @@ -113,8 +113,7 @@ Register-ScheduledTask -TaskName traffic66 -Action $a -Trigger (New-ScheduledTas
Start-ScheduledTask -TaskName traffic66
```

النقر المزدوج على `traffic66.exe` يعمل أيضًا: يفتح واجهة الويب ويعرض كلمة
المرور الأولى في نافذته.
النقر المزدوج على `traffic66.exe` يعمل أيضًا: يفتح واجهة الويب.

**macOS**: فكّ الضغط إلى `/usr/local/traffic66`، وأزل علامة الحجر،
وشغّل `traffic66 passwd -data "/Library/Application Support/traffic66"`، ثم
Expand All @@ -125,11 +124,15 @@ Start-ScheduledTask -TaskName traffic66

## 3. المستخدمون وكلمات المرور

عند التشغيل الأول ينشئ traffic66 المستخدم `admin` بكلمة مرور عشوائية ويطبعها
مرة واحدة (في النافذة، أو الطرفية، أو
`journalctl -u traffic66 | grep "first start"`). يُحفظ المستخدمون بصيغة
تجزئات مملّحة في `password` داخل دليل البيانات، ويُدارون بأمر واحد على جهاز
traffic66 (أضف `-data …` إن كان traffic66 يعمل به):
يُسجَّل الدخول في التثبيت الجديد بـ `admin` / `traffic66`، ويطلب أول تسجيل
دخول كلمة مرور جديدة قبل عرض أي شيء آخر (يحتفظ العرض التجريبي بـ `traffic66`).
بعد ذلك تُغيّر كلمة مرورك من **الحساب** أسفل القائمة؛ ومن هناك أيضًا يضيف
المسؤول (`admin`) المستخدمين ويحذفهم ويعيد تعيين كلمات مرورهم. تسجيل الدخول عبر
LDAP / Active Directory قيد التطوير.

يُحفظ المستخدمون بصيغة تجزئات مملّحة في `password` داخل دليل البيانات. ويمكن
فعل الشيء نفسه بأمر واحد على جهاز traffic66 (أضف `-data …` إن كان traffic66
يعمل به):

| المطلوب | الأمر |
|---|---|
Expand All @@ -138,8 +141,8 @@ traffic66 (أضف `-data …` إن كان traffic66 يعمل به):
| حذف `alice` | `traffic66 passwd -user alice -delete` |
| عرض المستخدمين | `traffic66 passwd -list` |

تُطبَّق التغييرات فورًا. لجميع المستخدمين الصلاحيات نفسها. للسكربتات
والحاويات، يقبل `TRAFFIC66_PASSWORD=…` (أو `-password`) المستخدم `-user` فقط
تُطبَّق التغييرات فورًا. باستثناء إدارة المستخدمين، لجميع المستخدمين
الصلاحيات نفسها. للسكربتات والحاويات، يقبل `TRAFFIC66_PASSWORD=…` (أو `-password`) المستخدم `-user` فقط
بكلمة المرور تلك طوال ذلك التشغيل. خمس كلمات مرور خاطئة خلال دقيقة تحظر
العنوان لمدة دقيقة.

Expand Down
27 changes: 15 additions & 12 deletions docs/README.bn.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,12 +49,12 @@ Elasticsearch, Kafka বা আলাদা database ছাড়াই।
unpack করে চালান:

```
./traffic66 demo -password try66 # Linux, macOS
.\traffic66.exe demo -password try66 # Windows
./traffic66 demo # Linux, macOS
.\traffic66.exe demo # Windows
```

macOS-এ আগে `xattr -dr com.apple.quarantine <folder>` চালান।
http://127.0.0.1:8066 খুলে `admin` / `try66` দিয়ে সাইন ইন করুন: এক দিনের
http://127.0.0.1:8066 খুলে `admin` / `traffic66` দিয়ে সাইন ইন করুন: এক দিনের
ইতিহাস আর চারটি simulated ডিভাইস থেকে live ট্রাফিক, সাথে একটি আক্রমণ যা
**সন্দেহজনক কার্যকলাপ**-এ ধাপে ধাপে দেখানো হয়। Ctrl+C দিয়ে বন্ধ করুন; নতুন
করে শুরু করতে `traffic66-demo` মুছে দিন। আসল installation-এর পাশাপাশি চালাতে:
Expand Down Expand Up @@ -113,8 +113,7 @@ Register-ScheduledTask -TaskName traffic66 -Action $a -Trigger (New-ScheduledTas
Start-ScheduledTask -TaskName traffic66
```

`traffic66.exe`-এ double-click করলেও চলে: এটি web UI খোলে এবং প্রথম
পাসওয়ার্ড তার window-তে দেখায়।
`traffic66.exe`-এ double-click করলেও চলে: এটি web UI খোলে।

**macOS**: `/usr/local/traffic66`-এ unpack করুন, quarantine flag সরান,
`traffic66 passwd -data "/Library/Application Support/traffic66"` চালান, এবং
Expand All @@ -125,11 +124,15 @@ Start-ScheduledTask -TaskName traffic66

## 3. ইউজার ও পাসওয়ার্ড

প্রথমবার চালু হলে traffic66 একটি random পাসওয়ার্ডসহ ইউজার `admin` তৈরি করে
এবং সেটি একবার দেখায় (window-তে, terminal-এ, অথবা
`journalctl -u traffic66 | grep "first start"`)। ইউজাররা data directory-র
`password`-এ salted hash হিসেবে থাকে এবং traffic66 মেশিনে একটি command দিয়ে
পরিচালিত হয় (traffic66 `-data …` দিয়ে চললে সেটিও যোগ করুন):
নতুন installation-এ `admin` / `traffic66` দিয়ে সাইন ইন হয়, এবং প্রথম সাইন ইন
অন্য কিছু দেখানোর আগে নতুন পাসওয়ার্ড চায় (demo `traffic66`-ই রাখে)। এরপর
menu-র নিচে **অ্যাকাউন্ট**-এ আপনার পাসওয়ার্ড বদলান; administrator (`admin`)
সেখানেই ইউজার যোগ ও মুছতে এবং তাদের পাসওয়ার্ড reset করতে পারেন। LDAP / Active
Directory দিয়ে সাইন ইন উন্নয়নাধীন।

ইউজাররা data directory-র `password`-এ salted hash হিসেবে থাকে। একই কাজ
traffic66 মেশিনে একটি command দিয়েও করা যায় (traffic66 `-data …` দিয়ে চললে
সেটিও যোগ করুন):

| কাজ | Command |
|---|---|
Expand All @@ -138,8 +141,8 @@ Start-ScheduledTask -TaskName traffic66
| `alice` মুছে ফেলা | `traffic66 passwd -user alice -delete` |
| ইউজারদের তালিকা দেখা | `traffic66 passwd -list` |

পরিবর্তন সঙ্গে সঙ্গে কার্যকর হয়। সব ইউজারের অধিকার একই। script ও
container-এর জন্য `TRAFFIC66_PASSWORD=…` (বা `-password`) ওই run-এ শুধু ওই
পরিবর্তন সঙ্গে সঙ্গে কার্যকর হয়। ইউজার পরিচালনা ছাড়া সব ইউজারের অধিকার
একই। script ও container-এর জন্য `TRAFFIC66_PASSWORD=…` (বা `-password`) ওই run-এ শুধু ওই
পাসওয়ার্ডসহ `-user`-কে গ্রহণ করে। এক মিনিটের মধ্যে পাঁচবার ভুল পাসওয়ার্ড দিলে
সেই address এক মিনিটের জন্য block হয়।

Expand Down
29 changes: 16 additions & 13 deletions docs/README.es.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,12 @@ Descargue el archivo para su sistema desde la
(Windows x64, Linux x86-64/ARM64 con kernel 3.2+, macOS 11+), descomprímalo y ejecute:

```
./traffic66 demo -password try66 # Linux, macOS
.\traffic66.exe demo -password try66 # Windows
./traffic66 demo # Linux, macOS
.\traffic66.exe demo # Windows
```

En macOS ejecute antes `xattr -dr com.apple.quarantine <folder>`. Abra
http://127.0.0.1:8066 como `admin` / `try66`: un día de historial y tráfico
http://127.0.0.1:8066 como `admin` / `traffic66`: un día de historial y tráfico
en vivo de cuatro equipos simulados, incluido un ataque mostrado paso a paso
en **Hallazgos**. Ctrl+C la detiene; borre `traffic66-demo` para empezar de
cero. Para ejecutarla junto a una instalación real: `-addr :8067 -listen ""`.
Expand Down Expand Up @@ -113,8 +113,7 @@ Register-ScheduledTask -TaskName traffic66 -Action $a -Trigger (New-ScheduledTas
Start-ScheduledTask -TaskName traffic66
```

También funciona hacer doble clic en `traffic66.exe`: abre la interfaz web
y muestra la primera contraseña en su ventana.
También funciona hacer doble clic en `traffic66.exe`: abre la interfaz web.

**macOS**: descomprima en `/usr/local/traffic66`, quite la marca de
cuarentena, ejecute `traffic66 passwd -data "/Library/Application Support/traffic66"`
Expand All @@ -125,12 +124,16 @@ programa, `-data` y ese directorio, con `RunAtLoad` y `KeepAlive`.

## 3. Usuarios y contraseñas

En el primer arranque traffic66 crea el usuario `admin` con una contraseña
aleatoria y la muestra una sola vez (en la ventana, en el terminal o con
`journalctl -u traffic66 | grep "first start"`). Los usuarios se guardan como
hashes con sal en `password` dentro del directorio de datos y se gestionan
con un solo comando en la máquina de traffic66 (añada `-data …` si traffic66
se ejecuta con esa opción):
Una instalación nueva se entra como `admin` / `traffic66`, y el primer
inicio de sesión pide una contraseña nueva antes de mostrar nada más (la
demo mantiene `traffic66`). Después, **Cuenta**, al pie del menú, cambia su
contraseña; el administrador (`admin`) también añade y elimina usuarios y
restablece sus contraseñas allí. El inicio de sesión con LDAP / Active
Directory está en desarrollo.

Los usuarios se guardan como hashes con sal en `password` dentro del
directorio de datos. Lo mismo puede hacerse en la máquina de traffic66 con un
solo comando (añada `-data …` si traffic66 se ejecuta con esa opción):

| Para | Comando |
|---|---|
Expand All @@ -139,8 +142,8 @@ se ejecuta con esa opción):
| Eliminar el usuario `alice` | `traffic66 passwd -user alice -delete` |
| Listar los usuarios | `traffic66 passwd -list` |

Los cambios se aplican al instante. Todos los usuarios tienen los mismos
permisos. Para scripts y contenedores, `TRAFFIC66_PASSWORD=…` (o `-password`)
Los cambios se aplican al instante. Salvo la gestión de usuarios, todos los
usuarios tienen los mismos permisos. Para scripts y contenedores, `TRAFFIC66_PASSWORD=…` (o `-password`)
acepta en esa ejecución solo `-user` con esa contraseña. Cinco contraseñas
erróneas en un minuto bloquean la dirección durante un minuto.

Expand Down
Loading
Loading