import logging
import re
import urllib
from datetime import datetime, timedelta
from random import choice, choices, randint
import pytz
import tldextract
from constance import config
from django.contrib import admin
from django.db import transaction
from django.utils import timezone
from django.utils.safestring import mark_safe
from import_export.admin import ImportExportModelAdmin
from jet.admin import CompactInline
from websecmap.app.admin import generate_game_user
from websecmap.app.models import GameUser
from websecmap.game.models import Contest, OrganizationSubmission, Team, UrlSubmission
from websecmap.organizations.models import Coordinate, Organization, OrganizationType, Url
from websecmap.scanners.scanner.http import resolves
log = logging.getLogger(__package__)
class TeamInline(CompactInline):
model = Team
extra = 0
can_delete = False
ordering = ["name"]
class OrganizationSubmissionInline(CompactInline):
model = OrganizationSubmission
extra = 0
can_delete = False
ordering = ["organization_name"]
readonly_fields = [
class UrlSubmissionInline(CompactInline):
model = UrlSubmission
extra = 0
can_delete = False
readonly_fields = [
class ContestAdmin(ImportExportModelAdmin, admin.ModelAdmin):
list_display = ("name", "target_country", "from_moment", "until_moment", "admin_user", "teams")
search_fields = ("name", "target_country")
list_filter = ("name", "target_country")
def teams(obj):
return Team.objects.all().filter(participating_in_contest__name=obj.name).count()
fieldsets = (
"fields": ("name", "from_moment", "until_moment"),
"description": "<span style='color: red'>"
"Don't forget to disable subdomain discovery AND to onboard every 1 minute.</span>",
"fields": ("target_country", "url_organization_discovery_help", "admin_user"),
actions = []
def add_contest(self, request, queryset):
# create a new contest
contest = Contest()
contest.target_country = "NL"
contest.from_moment = datetime.now(pytz.utc)
contest.until_moment = datetime.now(pytz.utc) + timedelta(days=3)
contest.admin_user = generate_game_user()
contest.name = "new_contest_%s" % datetime.now(pytz.utc).date()
# create a number of team members.
for i in range(12):
self.message_user(request, "Contest user, contest and teams have been created.")
add_contest.short_description = "Add contest (select one)"
def add_a_dozen_teams(self, request, queryset):
for contest in queryset:
for i in range(12):
self.message_user(request, "Urls have been rejected.")
add_a_dozen_teams.short_description = "Add 12 teams"
# todo: generate a printout for teams and this contest, to hand out.
def show_printout(self, request, queryset):
for contest in queryset:
from django.http import HttpResponse
content = ""
content += create_printout(contest)
return HttpResponse(content)
show_printout.short_description = "Create Printout"
inlines = [TeamInline]
def generate_team(contest):
new_team = Team()
new_team.name = generate_team_name()
new_team.color = generate_pastel_color()
new_team.participating_in_contest = contest
new_team.secret = generate_team_password()
new_team.allowed_to_submit_things = True
def create_printout(contest):
login_url = "%s/game/" % config.PROJECT_WEBSITE
game_url = "%s/game/scores/" % config.PROJECT_WEBSITE
username = "%s" % contest.admin_user.username # associate an account to login.
game_user = GameUser.objects.all().filter(user=contest.admin_user).first()
if not game_user or game_user.password is None:
raise ValueError("Set a game user for this contest, do so in the users list. Also set the password.")
password = "%s" % game_user.password
# todo: margin top per page.
content = "<style>body{font-family: verdana, sans-serif;}</style>"
content += """<style media='print'>
/* show background colors in print */
* { -webkit-print-color-adjust: exact !important;
color-adjust: exact !important;
@page {
size: auto; /* auto is the initial value */
margin: 0; /* this affects the margin in the printer settings */
padding-top: 72px;
padding-bottom: 72px;
body {
padding-left: 66px;
.noprint, .noprint * {
display: none !important;
content += "<h1>%s</h1>" % contest.name
content += "<p>Starts at %s. Deadline: %s.</p>" % (contest.from_moment, contest.until_moment)
content += "<br />"
content += "<h2>Teams</h2>"
teams = Team.objects.all().filter(participating_in_contest=contest, allowed_to_submit_things=True)
p = re.compile(r"<.*?>")
for team in teams:
teamcontent = ""
teamcontent += "<hr style='page-break-after: always; border: 0px; padding-bottom: 20px;'>"
teamcontent += (
"<p style='font-weight: bold; font-size: 2em; "
"padding-top: 100px; margin-bottom: 0px; padding-bottom: 0px;'>"
"Hi team <span style='background-color: %s;'>%s</span>!</p>"
"<br><br>" % (team.color, team.name)
teamcontent += "Thanks for joining this contest! These instructions try to help you get started.<br><br>"
teamcontent += "To participate, first go to the gaming interface: <br>"
teamcontent += "<b>%s</b> <br>" % login_url
teamcontent += "<br />"
teamcontent += "Then <b>click login</b> at the top right corner.<br>"
teamcontent += "<br />"
teamcontent += "Use the following account information: <br>"
teamcontent += "Username: <b>%s</b><br>" % username
teamcontent += "Password: <b>%s</b><br />" % password
teamcontent += "<br />"
teamcontent += "Then, select this contest: <b>%s</b><br />" % contest.name
teamcontent += "<br />"
teamcontent += "Then select your team and fill in it's secret:<br />"
teamcontent += "Team: <span style='background-color: %s; width: 60px; height: 20px;'><b>%s</b></span><br />" % (
teamcontent += "Secret: <b>%s</b><br />" % team.secret
teamcontent += "<br />"
teamcontent += "If you have any questions, please ask the contest organizer!<br>"
teamcontent += "<br />"
teamcontent += "Have fun!<br>"
teamcontent += "<i>-- the %s contest organizers</s><br>" % contest.name
teamcontent += "<br /><br />"
teamcontent += "<i>P.S. It's possible to see the scorebord without logging in at:</i><br>"
teamcontent += "<i>%s</i><br>" % game_url
teamcontent += "<br />"
# only the beginning of the tag, so the closing style and any properties etc don't matter.
without_html = teamcontent.replace("<br", "\n<br")
without_html = p.sub("", without_html)
stuff = urllib.parse.quote(without_html)
mailcontent = ""
mailcontent += (
"<a class='noprint' href='mailto:address"
"?subject=Your %s Contest Login Info"
"&body=%s'>E-Mail this</a>" % (contest.name, stuff)
content += teamcontent
content += mailcontent
return content
def generate_team_password():
The password has to be fairly simple
# do not include similar characters like g9, liI1 etc. J oO0Q B8, YV
letters = "ACDEFGHKLMNPRSTUVWXZ234567" # len = 26
password = "".join(choices(letters, k=16))
# to make it easier to read, add spaces per 4 characters.
return "%s-%s-%s-%s" % (password[0:4], password[4:8], password[8:12], password[12:16])
def generate_pastel_color():
def r():
return randint(125, 255)
return "#%02X%02X%02X" % (r(), r(), r())
def generate_team_name():
return generate_team_name_docker()
def generate_team_name_docker():
# generate nice names like docker container names
# https://github.com/moby/moby/blob/master/pkg/namesgenerator/names-generator.go
# slightly redacted list to make all names always positive.
traits = [
# See the elaborate explanations of all these names in the original file.
names = [
return "%s %s" % (choice(traits).capitalize(), choice(names).capitalize())
# todo: submissioninline, read only... there are going to be MANY new things...
class TeamAdmin(ImportExportModelAdmin, admin.ModelAdmin):
list_display = ("name", "team_color", "participating_in_contest", "allowed_to_submit_things")
search_fields = ("name", "participating_in_contest__name")
list_filter = ("name", "participating_in_contest__name", "participating_in_contest__target_country")
fieldsets = (
(None, {"fields": ("name", "color", "participating_in_contest", "allowed_to_submit_things")}),
"fields": ("secret",),
def team_color(obj):
return mark_safe("<div style='background-color: %s; width: 60px; height: 20px;'></div>" % obj.color)
actions = []
def allow_team(self, request, queryset):
for team in queryset:
team.allowed_to_submit_things = True
self.message_user(request, "Teams are allowed .")
allow_team.short_description = "Allow to submit"
def disallow_team(self, request, queryset):
for team in queryset:
team.allowed_to_submit_things = False
self.message_user(request, "Teams are disallowed.")
disallow_team.short_description = "Disallow to submit"
# UrlSubmissionInline will make the load slow / non-loading.
inlines = [
class UrlSubmissionAdmin(ImportExportModelAdmin, admin.ModelAdmin):
list_display = ("added_by_team", "for_organization", "url", "has_been_accepted", "has_been_rejected", "added_on")
search_fields = ("added_by_team__name", "organization_name", "url")
list_filter = (
fields = (
ordering = ("for_organization", "url")
actions = []
def reset_judgement(self, request, queryset):
for urlsubmission in queryset:
urlsubmission.has_been_accepted = False
urlsubmission.has_been_rejected = False
self.message_user(request, "URL be accepted/rejected again.")
reset_judgement.short_description = "Reset acceptance / rejection."
def accept(self, request, queryset):
for urlsubmission in queryset:
# don't add the same thing over and over, allows to re-select the ones already added without a problem
# once rejected, can't be accepted via buttons: needs to be a manual action
if urlsubmission.has_been_accepted or urlsubmission.has_been_rejected:
# it's possible that the url already is in the system. If so, tie that to the submitted organization.
# could be dead etc... (stacking?)
url = Url.objects.all().filter(url=urlsubmission.url, is_dead=False).first()
if not url:
log.debug("adding new url: %s" % urlsubmission.url)
# if it already exists, then add the url to the organization.
url = Url(url=urlsubmission.url)
# the organization is already inside the submission and should exist in most cases.
# add some tracking data to the submission
urlsubmission.url_in_system = url
urlsubmission.has_been_accepted = True
self.message_user(request, "Urls have been accepted and added to the system.")
accept.short_description = "✅ Accept"
def reject(self, request, queryset):
for urlsubmission in queryset:
urlsubmission.has_been_rejected = True
self.message_user(request, "Urls have been rejected.")
reject.short_description = "❌ Reject"
class OrganizationSubmissionAdmin(ImportExportModelAdmin, admin.ModelAdmin):
list_display = (
search_fields = ("added_by_team__name", "organization_name", "organization_type_name")
list_filter = (
fields = (
actions = []
def accept(self, request, queryset):
for osm in queryset:
# don't add the same thing over and over, allows to re-select the ones already added without a problem
# once rejected, can't be accepted via buttons: needs to be a manual action
# todo: make it possible to reject afterwards, and delete all subdomains etc.
if osm.has_been_accepted or osm.has_been_rejected:
log.debug("Organization has already been accepted or rejected.")
# this might revive some old organizations, so domain knowledge is required.
# In this case the organization already exists with the same name, type and alive.
# this means we don't need to add a new one, or with new coordinates.
already_exists = (
if already_exists:
log.debug("Organization with the same name already exists, in this country and type and is alive.")
# Create a new one
# address and evidence are saved elsewhere. Since we have a reference we can auto-update after
# geocoding works. In the hopes some quality data has been added, which can be checked more easy then
# adding this data in the system again(?)
new_org = Organization(
log.debug("Saved new organization.")
# of course it has a new coordinate
new_coordinate = Coordinate(
edit_area={"type": "Point", "coordinates": osm.organization_address_geocoded},
creation_metadata="Accepted organization submission",
log.debug("Saved matching coordinate.")
# add the toplevel urls if they exist.
if osm.suggested_urls:
# a disgusting way to parse this list, without using eval.
urls = osm.suggested_urls.replace("[", "").replace("'", "").replace("]", "").replace(",", "").split(" ")
urls = check_valid_urls(urls)
for url in urls:
# don't auto add the URL, to have a bit more control over what is being added
# new_url = Url()
# new_url.url = url
# new_url.save()
# new_url.organization.add(new_org)
# new_url.save()
submission = UrlSubmission()
submission.url = url
submission.has_been_rejected = False
submission.has_been_accepted = False
submission.added_by_team = osm.added_by_team
submission.added_on = osm.added_on
# submission.url_in_system = new_url
submission.for_organization = new_org
# and save tracking information
osm.organization_in_system = new_org
osm.has_been_accepted = True
log.debug("Saved tracking information for the game.")
self.message_user(request, "Organizations have been accepted and added to the system.")
accept.short_description = "✅ Accept"
def reject(self, request, queryset):
for organizationsubmission in queryset:
organizationsubmission.has_been_rejected = True
self.message_user(request, "Organisation(s) have been rejected.")
reject.short_description = "❌ Reject"
def check_valid_urls(urls):
valid = []
for url in urls:
url = url.lower()
url = url.replace("https://", "")
url = url.replace("http://", "")
extract = tldextract.extract(url)
if not extract.suffix:
# tld extract has also removed ports, usernames, passwords and other nonsense.
url = "%s.%s" % (extract.domain, extract.suffix)
# see if the URL resolves at all:
if not resolves(url):
if url not in valid:
return valid