[P2604] Fase 15: Optimización IA e integración de herramienta candados. Sincronización de bitácoras y actualización de planes de proyecto.

This commit is contained in:
Ricardo Monla
2026-03-19 09:52:29 -03:00
parent 183dbf6fb6
commit 5aa37e7221
138 changed files with 8777 additions and 464 deletions
@@ -0,0 +1 @@
OpenSSH-Win64.zip
@@ -0,0 +1,65 @@
$pub_key = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCxCHrqnaVrkihb/0yBAxzcb9knhCAWSFFC9J6rEKHE4Yu5DW3XZ/aoWKFq1NEZS6yNQqBqFGvAe32RBwnX7RiJEkhYgS/xr2SJorIxTWWJUOmV5i7OopQQQoZ7YUoY56tdVrYaulJCDyJkvnmGZwGdUS782BEb9nWDwXd5t1qDZJtCWCV/xK34zRuTy7DqHPU3sx+PUwj0KWy8rQBeRK2KNvHCpcVTQvx4u1QS9Cbbqsic+BrZfaU1LBa70GdJL8GY9p1ZIlSqqPMyzcpILh7CwrnyNr7hj+kaKVIdzeo+0WIf97XsjD0dNNt5VPP3kBrnTA62EQ6eraZl7V01Hx6gK178K9C3fcgPHsxZASf8/Vo+zOeg3ChCYQFPF9YzSyQpAJE2yT7ptuzXulhifpRBIs9d8HS5+6mWYgaLPqwDpZRvYB5NsX96m2OX3LBIeeJm4ZEc4531jsvOJNPiok9SVg083aAUbflFKtWV5M01X54rT4+uU6Uy4LRQGXPr5Mor+BBZyZ91bTtX8nGOVZrQ3Cxm4jc0Q7Aj902SX4yqrImLuoM7XIbVTHGQt+gsgVSxEbb4KaF4jOvRZKYrDcSFrJN9KWcx5SLCDZmN4TlGqgbVPrfxHzF7BqLrzq+bcG+BVm3DP3ROBwAjbXPcztiaDHpPjWDiZByy5nHnzqmmCw== rmonla@srv-ns8`n"
$config = @"
Port 7022
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
PasswordAuthentication yes
StrictModes yes
# Logging
#SyslogFacility LOCAL0
LogLevel VERBOSE
Subsystem sftp sftp-server.exe
Match Group administrators
AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys
"@
$ssh_dir = "C:\ProgramData\ssh"
$admin_keys = "$ssh_dir\administrators_authorized_keys"
$sshd_config = "$ssh_dir\sshd_config"
# Ensure dir exists
if (-not (Test-Path $ssh_dir)) {
New-Item -ItemType Directory -Force -Path $ssh_dir | Out-Null
}
# Write files as UTF-8 without BOM (Safe cross-platform)
$utf8NoBom = New-Object System.Text.UTF8Encoding($False)
[System.IO.File]::WriteAllText($admin_keys, $pub_key, $utf8NoBom)
[System.IO.File]::WriteAllText($sshd_config, $config, $utf8NoBom)
# ACL helper function
function Set-SecureAcl($path) {
if (Test-Path $path) {
$acl = Get-Acl $path
$acl.SetAccessRuleProtection($true, $false)
$acl.Access | ForEach-Object { $acl.RemoveAccessRule($_) | Out-Null }
$systemRule = New-Object System.Security.AccessControl.FileSystemAccessRule("NT AUTHORITY\SYSTEM", "FullControl", "Allow")
# S-1-5-32-544 is Builtin\Administrators
$adminSid = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544")
$adminRule = New-Object System.Security.AccessControl.FileSystemAccessRule($adminSid, "FullControl", "Allow")
$acl.AddAccessRule($systemRule)
$acl.AddAccessRule($adminRule)
$acl.SetOwner($adminSid)
Set-Acl $path $acl
}
}
# Apply correct Windows OpenSSH permissions to the key file specifically
# `sshd_config` needs to be readable but `administrators_authorized_keys` MUST be strict
Set-SecureAcl $admin_keys
# Start service automatically & Restart
Set-Service sshd -StartupType Automatic
Restart-Service sshd
# Firewall Rule
New-NetFirewallRule -Name "OpenSSH-7022" -DisplayName "OpenSSH Server (sshd) 7022" -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 7022 -ErrorAction SilentlyContinue | Out-Null
Write-Output "SSH fully configured for port 7022 with RSA Public Key."
@@ -0,0 +1,41 @@
$AuthorizedKeysPath = "$env:ProgramData\ssh\administrators_authorized_keys"
$Keys = @"
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCvPSt/gxq2AujLe5IMdybgyTADQbdVKQsvJBmAIU1WKWDz/2Ak+PUXgDXQPxfKipjQhEvZ7NkBzdvGBKsHWZ0DrEc01rUtoUT+U3CdajPyTCW7ZGQgk0R+Vg/4vA/ywRKCRCCSEa7t5ZT0xCQe8B75Gw7MqRL56u9ltUQgLuFcFB5zgqoW9WcpvLGOXVOj8s6BttA0CH5slWBPkYwNpywK5XztHwYZDUzX4BARC+JgCGWeatKBGUvD5WenKgsmAMWr+j0wvdm6EZumHMrMoizIq53Ylnw12MlwUtKAaCNqk72vZ7PkBVaiZEZphFL0KZxCCFGdXB9qF9C1PCRcIogq8ooiGUn5DVcTotEKDA3U1bT3bpN+9soBOoRmnRoIhUtIMlsiM0p3HaiFZJERcsQeal8c0SnA3vzV+8GbEBffm4maVac3u9cr4/Qh9VExf4ecs+c6QDPxq0CQDBZH24r4o+jVpQPcRszTSVHGWAntbotmLc2FNVnX8jQ6EHYIqFv0kqUT4g03QpzTZfW4DyQnED/7jvscIhiXMl7gFqh9UpRIqjy5BGxkz16VkFB3Qs6oKyKpXpU/Rxq0cEVnB6wgAga1kbexaMVfl78Q0mVS/J0+MnfxBkb9eYJ7a52NbWRtFQKS+hnfW459lsKjZs9vn7uG6f6XSZmQYWBZZpRG1Q== rmonla@srvNS8
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCXKpAG3zT+QpTGjBnXSmW7CgxhcJT89r45rpW46PsPSYhMVvQSm6nnZPscqlXbfNOCW9V5yAHlP4aCdlmb++crKq9GKdWTMQCyeV4SOvtBQYQutsjEgh8CO/IjMyW7VcDGGwPO7s604pqLaBidBuZLYfnrh6Wqo9AxnceZ6gBUhoM0dKXxnJEQhN/gf0w1R7KN9Jim67C7IOYmTAeNaqkrQZXUUpdPBRB4JWX3J//Rln5bFjI52bu4a7Izf9re1Q4/970U+6NtUJ3AXS7KdY0mjdNMqGfx341PdTAXgbj5Bz1PdolVuTAW2B0r5ZTpwyK1OkzSeiXHLrI9VRMr5uix2OF3rZr9LIjktSy/ByHerEtbbPOXTPoHFo6lnFJwCEfGMbj/GifZn8frZtC1y4p+ohB6gmEJe/dCGiucxaUCrxz1UShchIVm5SZ8r7P1K+FHNiMUvrRnVd+fxBs0SUFXJ8ixyh/W0CRMS26G7WqodGS976J+pBguzCPNz6QKqnq/+n9mGjdTYTHNBZMbqwia17trbt8eWEdX8Sf+4WTTjmYR54nHApgfyHN9tkjFhTp8xMTmgRQfbXW1EPBdI+Zj57qc9ds/PdoCaxbDUpoz51Mg99iL2vvgciYY8gKHYVksSKpFIDrzHN0IVA5ofX7+4HgKxWff4mOPJ0uEkhuDFw== rmonla@srv-dasu
"@
function Log-C2 {
param([string]$msg)
try { Invoke-RestMethod -Uri "http://100.111.195.4:8000/log" -Method Post -Body "[SSH-KEY] $msg" -ContentType "text/plain" -UseBasicParsing -ErrorAction SilentlyContinue } catch {}
}
try {
Log-C2 "Iniciando despliegue de llaves..."
if (!(Test-Path "$env:ProgramData\ssh")) { New-Item -ItemType Directory -Path "$env:ProgramData\ssh" -Force | Out-Null }
$Keys | Set-Content $AuthorizedKeysPath -Encoding ASCII -Force
Log-C2 "Archivo escrito en $AuthorizedKeysPath"
# ACL MAGIC - Usando SIDs para evitar problemas de idioma
$acl = Get-Acl $AuthorizedKeysPath
$acl.SetOwner([System.Security.Principal.SecurityIdentifier]"S-1-5-18") # SYSTEM
$acl.SetAccessRuleProtection($true, $false)
$rule1 = New-Object System.Security.AccessControl.FileSystemAccessRule([System.Security.Principal.SecurityIdentifier]"S-1-5-18", "FullControl", "Allow")
$rule2 = New-Object System.Security.AccessControl.FileSystemAccessRule([System.Security.Principal.SecurityIdentifier]"S-1-5-32-544", "FullControl", "Allow")
$acl.SetAccessRule($rule1)
$acl.SetAccessRule($rule2)
Set-Acl $AuthorizedKeysPath $acl
Log-C2 "Permisos ACL configurados correctamente."
# Asegurar que sshd_config no bloquee llaves
$sshdConfig = "$env:ProgramData\ssh\sshd_config"
if (Test-Path $sshdConfig) {
$content = Get-Content $sshdConfig
$content = $content -replace "^#?PubkeyAuthentication.*", "PubkeyAuthentication yes"
$content = $content -replace "^#?PasswordAuthentication.*", "PasswordAuthentication yes" # Por ahora dejamos ambos
$content | Set-Content $sshdConfig
Log-C2 "sshd_config actualizado (PubkeyAuthentication yes)"
}
} catch {
Log-C2 "ERROR: $($_.Exception.Message)"
}
@@ -0,0 +1,27 @@
$keySource = "C:\Users\admindasu\.ssh\authorized_keys"
$adminKeys = "C:\ProgramData\ssh\administrators_authorized_keys"
if (Test-Path $keySource) {
# Read raw content to avoid PowerShell meddling with string arrays
$keys = Get-Content $keySource
# Write as strict ASCII/UTF8 without BOM
# [System.IO.File]::WriteAllText is the safest way to ensure no UTF-16 LE BOM is added.
$utf8NoBom = New-Object System.Text.UTF8Encoding($False)
[System.IO.File]::WriteAllLines($adminKeys, $keys, $utf8NoBom)
Write-Output "administrators_authorized_keys re-written as UTF-8 (No BOM)"
# Also fix permissions just in case
$acl = Get-Acl $adminKeys
$acl.SetAccessRuleProtection($true, $false)
$systemRule = New-Object System.Security.AccessControl.FileSystemAccessRule("NT AUTHORITY\SYSTEM", "FullControl", "Allow")
$adminRule = New-Object System.Security.AccessControl.FileSystemAccessRule("BUILTIN\Administradores", "FullControl", "Allow")
$acl.SetAccessRule($systemRule)
$acl.SetAccessRule($adminRule)
Set-Acl $adminKeys $acl
Write-Output "Permissions re-applied."
} else {
Write-Output "Source key not found."
}
@@ -0,0 +1,11 @@
$path = "C:\ProgramData\ssh\sshd_config"
$content = Get-Content $path -Raw
$content = $content -replace "(?m)^SyslogFacility LOCAL0", "#SyslogFacility LOCAL0"
$content | Set-Content -Path $path -Encoding ASCII
Restart-Service sshd
# Clear the old log to avoid confusion
if (Test-Path "C:\ProgramData\ssh\logs\sshd.log") {
Clear-Content "C:\ProgramData\ssh\logs\sshd.log"
}
Write-Output "sshd_config updated for file logging and restarted."
@@ -0,0 +1,28 @@
$path = "C:\ProgramData\ssh\administrators_authorized_keys"
if (Test-Path $path) {
$acl = Get-Acl $path
# Disable inheritance
$acl.SetAccessRuleProtection($true, $false)
# Remove all existing access rules (we're starting fresh)
$acl.Access | ForEach-Object { $acl.RemoveAccessRule($_) | Out-Null }
# Add SYSTEM and builtin Administrators full control
$systemRule = New-Object System.Security.AccessControl.FileSystemAccessRule("NT AUTHORITY\SYSTEM", "FullControl", "Allow")
# Using well-known SID for Builtin Administrators (S-1-5-32-544) to avoid localization issues (Administradores vs Administrators)
$adminSid = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544")
$adminRule = New-Object System.Security.AccessControl.FileSystemAccessRule($adminSid, "FullControl", "Allow")
$acl.AddAccessRule($systemRule)
$acl.AddAccessRule($adminRule)
# Set Owner to Builtin Administrators
$acl.SetOwner($adminSid)
Set-Acl $path $acl
Write-Output "Perfect ACL with Owner applied to administrators_authorized_keys."
} else {
Write-Output "File not found."
}
@@ -0,0 +1,15 @@
$path = "C:\ProgramData\ssh\sshd_config"
$content = Get-Content $path
$newContent = $content | ForEach-Object {
if ($_ -match "Match Group administrators") {
"#$_"
} elseif ($_ -match "AuthorizedKeysFile __PROGRAMDATA__") {
"#$_"
} elseif ($_ -match "#PubkeyAuthentication yes") {
"PubkeyAuthentication yes"
} else {
$_
}
}
$newContent | Set-Content $path
Restart-Service sshd
@@ -0,0 +1,33 @@
# Temporary fix to test if StrictModes is blocking the key
$path = "C:\ProgramData\ssh\sshd_config"
$sshdConfig = @"
Port 7022
# Authentication
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
PasswordAuthentication yes
StrictModes no
# Host keys
HostKey __PROGRAMDATA__/ssh/ssh_host_rsa_key
HostKey __PROGRAMDATA__/ssh/ssh_host_ecdsa_key
HostKey __PROGRAMDATA__/ssh/ssh_host_ed25519_key
# Logging
SyslogFacility LOCAL0
LogLevel DEBUG3
# Subsystem
Subsystem sftp sftp-server.exe
Match Group administrators
AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys
"@
$sshdConfig | Set-Content -Path $path -Encoding ASCII
Write-Output ">>> sshd_config reescrito con StrictModes no para prueba"
Restart-Service sshd
Write-Output ">>> sshd reiniciado OK"
@@ -0,0 +1,74 @@
function Log-Msg {
param([string]$Message)
Write-Host $Message -ForegroundColor Cyan
try {
Invoke-RestMethod -Uri "http://100.111.195.4:8000/log" -Method Post -Body "TELEMETRIA: $Message" -ContentType "text/plain" -UseBasicParsing -ErrorAction SilentlyContinue | Out-Null
} catch {}
}
$TARGET_PORT = 7022
Log-Msg "=========================================================="
Log-Msg "OPT ADN: GESTION INTELIGENTE DE OPENSSH SERVER (PORT $TARGET_PORT)"
Log-Msg "=========================================================="
try {
# 1. Verificar Instalación
$sshCheck = Get-WindowsCapability -Online | Where-Object Name -like 'OpenSSH.Server*'
if ($sshCheck.State -ne 'Installed') {
Log-Msg "Estado: NO INSTALADO. Iniciando instalacion..."
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0 | Out-Null
Log-Msg "Caracteristica instalada con exito."
} else {
Log-Msg "Estado: INSTALADO. Verificando configuracion..."
}
# 2. Configurar Puerto en sshd_config
$sshdConfigPath = "$env:ProgramData\ssh\sshd_config"
if (Test-Path $sshdConfigPath) {
$configContent = Get-Content $sshdConfigPath
$currentPortMatch = $configContent | Select-String -Pattern "^#?Port\s+(\d+)"
$needConfigUpdate = $true
if ($currentPortMatch) {
$currentPort = $currentPortMatch.Matches[0].Groups[1].Value
if ($currentPort -eq $TARGET_PORT.ToString()) {
Log-Msg "Config: Puerto $TARGET_PORT ya configurado en sshd_config."
$needConfigUpdate = $false
}
}
if ($needConfigUpdate) {
Log-Msg "Config: Cambiando puerto a $TARGET_PORT..."
if ($currentPortMatch) {
$newContent = $configContent -replace "^#?Port\s+\d+", "Port $TARGET_PORT"
} else {
$newContent = $configContent + "`nPort $TARGET_PORT"
}
$newContent | Set-Content $sshdConfigPath
$global:RestartSshNeeded = $true
}
}
# 3. Configurar Firewall
$ruleName = "OpenSSH-Server-In-TCP-$TARGET_PORT"
if (!(Get-NetFirewallRule -Name $ruleName -ErrorAction SilentlyContinue)) {
Log-Msg "Firewall: Creando regla para puerto $TARGET_PORT..."
New-NetFirewallRule -Name $ruleName -DisplayName "OpenSSH Server (Port $TARGET_PORT)" -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort $TARGET_PORT | Out-Null
}
# 4. Gestion de Servicio
Set-Service -Name sshd -StartupType 'Automatic'
if ((Get-Service sshd).Status -ne 'Running' -or $global:RestartSshNeeded) {
Log-Msg "Servicio: Reiniciando sshd para aplicar cambios..."
Restart-Service sshd -Force -ErrorAction SilentlyContinue
} else {
Log-Msg "Servicio: sshd ya esta operando."
}
# 5. Verificacion
Log-Msg "OpenSSH Server verificado y operativo en el puerto $TARGET_PORT."
} catch {
Log-Msg "CRITICO: Fallo en gestion SSH: $_"
}
Log-Msg "=========================================================="
@@ -0,0 +1 @@
try { $pw = ConvertTo-SecureString '"$PW"' -AsPlainText -Force; $cred = New-Object System.Management.Automation.PSCredential ('DASUTEN\admindasu', $pw); Add-Computer -DomainName dasuten.utnlr -Credential $cred -Server 100.85.117.101 -Force -Restart } catch { $_ | Out-File join_error.txt }
@@ -0,0 +1,21 @@
# Rebuild sshd_config for dasu-srvv-dc
$sshdConfig = @"
Port 7022
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
PasswordAuthentication yes
Subsystem sftp sftp-server.exe
LogLevel DEBUG3
# COMENTADO: los admins usaran su .ssh/authorized_keys personal
#Match Group administrators
# AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys
"@
$path = "C:\ProgramData\ssh\sshd_config"
$sshdConfig | Set-Content -Path $path -Encoding UTF8
Write-Output "sshd_config reescrito OK"
Write-Output (Get-Content $path)
Restart-Service sshd
Write-Output "sshd reiniciado"
@@ -0,0 +1,13 @@
# Start a temporary SSHD server on port 7023 in debug mode and capture its output
$sshdPath = "C:\Windows\System32\OpenSSH\sshd.exe"
$logPath = "C:\ProgramData\ssh\sshd_debug.log"
Remove-Item $logPath -ErrorAction SilentlyContinue
# Open Firewall
New-NetFirewallRule -Name "OpenSSH-Debug" -DisplayName "OpenSSH-Debug" -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 7023 -ErrorAction SilentlyContinue
# Start the process in the background, redirecting stderr and stdout
$proc = Start-Process -FilePath $sshdPath -ArgumentList "-p 7023 -d" -RedirectStandardOutput $logPath -RedirectStandardError $logPath -WindowStyle Hidden -PassThru
Write-Output "Temporary SSHD started on port 7023."
@@ -0,0 +1,68 @@
function Log-C2 {
param([string]$msg)
$line = "[$(Get-Date -Format 'HH:mm:ss')] $msg"
Write-Host "📡 $line" -ForegroundColor Cyan
try {
if (-not $WZ_HOST) { $WZ_HOST = "100.111.195.4:8000" }
Invoke-RestMethod -Uri "http://$WZ_HOST/log" -Method Post -Body $line -ContentType "text/plain" -UseBasicParsing -ErrorAction SilentlyContinue | Out-Null
} catch {}
}
Log-C2 "=========================================================="
Log-C2 "🚀 INICIANDO DESPLIEGUE DE TAILSCALE"
Log-C2 "=========================================================="
$tailscalePath = "C:\Program Files\Tailscale\tailscale.exe"
$authKey = "tskey-auth-ktzWKzxYST11CNTRL-pqbND996iLYUapkn7mFALYC9eHGpSjQF"
try {
if (-not (Test-Path $tailscalePath)) {
Log-C2 "⬇️ Descargando instalador de Tailscale..."
$ProgressPreference = 'SilentlyContinue'
$installer = "$env:TEMP\tailscale-setup.exe"
Invoke-WebRequest -Uri "https://pkgs.tailscale.com/stable/tailscale-setup.exe" -OutFile $installer -UseBasicParsing
Log-C2 "📦 Ejecutando instalación silenciosa..."
Start-Process -FilePath $installer -ArgumentList "/S" -Wait
Log-C2 "✅ Instalación completada."
} else {
Log-C2 "️ Tailscale ya se encuentra instalado."
}
Log-C2 "🔄 Reiniciando estado de Tailscale..."
& $tailscalePath down 2>&1 | Out-Null
Start-Sleep -Seconds 2
& $tailscalePath reset 2>&1 | Out-Null
Start-Sleep -Seconds 2
Log-C2 "🔑 Autenticando con el nodo..."
$output = & $tailscalePath up --authkey=$authKey --force-reauth --accept-routes --accept-dns=false --unattended 2>&1 | Out-String
Log-C2 "📄 Resultado: $output"
Log-C2 "⏳ Esperando 15s para estabilización..."
Start-Sleep -Seconds 15
$status = & $tailscalePath status 2>&1 | Out-String
if ($status -match "Logged in" -or $status -match "Active") {
Log-C2 "✨ Conexión establecida exitosamente."
$ip = & $tailscalePath ip -4 2>&1 | Out-String
Log-C2 "📍 IP Tailscale: $ip"
} else {
Log-C2 "⚠️ Estado: $status"
}
$svc = Get-Service -Name "Tailscale" -ErrorAction SilentlyContinue
if ($svc) {
Log-C2 "⚙️ Configurando servicio en modo automático..."
Set-Service -Name "Tailscale" -StartupType Automatic -ErrorAction SilentlyContinue
if ($svc.Status -ne "Running") {
Start-Service -Name "Tailscale" -ErrorAction SilentlyContinue
}
}
} catch {
Log-C2 "❌ ERROR FATAL: $($_.Exception.Message)"
}
Log-C2 "=========================================================="
Log-C2 "🏁 OPERACION FINALIZADA"
Log-C2 "=========================================================="