waybackproxy.py 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496
  1. #!/usr/bin/env python3
  2. import base64, datetime, lrudict, re, socket, socketserver, sys, threading, urllib.request, urllib.error, urllib.parse
  3. from config import *
  4. # internal LRU dictionary for preserving URLs on redirect
  5. date_cache = lrudict.LRUDict(maxduration=86400, maxsize=1024)
  6. class ThreadingTCPServer(socketserver.ThreadingMixIn, socketserver.TCPServer):
  7. """TCPServer with ThreadingMixIn added."""
  8. pass
  9. class Handler(socketserver.BaseRequestHandler):
  10. """Main request handler."""
  11. def handle(self):
  12. """Handle a request."""
  13. global DATE
  14. # readline is pretty convenient
  15. f = self.request.makefile()
  16. # read request line
  17. reqline = line = f.readline()
  18. split = line.rstrip('\r\n').split(' ')
  19. http_version = len(split) > 2 and split[2] or 'HTTP/0.9'
  20. if split[0] != 'GET':
  21. # only GET is implemented
  22. return self.error_page(http_version, 501, 'Not Implemented')
  23. # read out the headers
  24. request_host = None
  25. pac_host = '" + location.host + ":' + str(LISTEN_PORT) # may not actually work
  26. effective_date = DATE
  27. auth = None
  28. while line.rstrip('\r\n') != '':
  29. line = f.readline()
  30. ll = line.lower()
  31. if ll[:6] == 'host: ':
  32. pac_host = request_host = line[6:].rstrip('\r\n')
  33. if ':' not in pac_host: # who would run this on port 80 anyway?
  34. pac_host += ':80'
  35. elif ll[:21] == 'x-waybackproxy-date: ':
  36. # API for a personal project of mine
  37. effective_date = line[21:].rstrip('\r\n')
  38. elif ll[:21] == 'authorization: basic ':
  39. # asset date code passed as username:password
  40. auth = base64.b64decode(ll[21:])
  41. # parse the URL
  42. pac_file_paths = ('/proxy.pac', '/wpad.dat', '/wpad.da')
  43. if split[1][0] == '/' and split[1] not in pac_file_paths:
  44. # just a path (not corresponding to a PAC file) => transparent proxy
  45. # Host header and therefore HTTP/1.1 are required
  46. if not request_host:
  47. return self.error_page(http_version, 400, 'Host header missing')
  48. archived_url = 'http://' + request_host + split[1]
  49. else:
  50. # full URL => explicit proxy
  51. archived_url = split[1]
  52. request_url = archived_url
  53. parsed = urllib.parse.urlparse(request_url)
  54. # make a path
  55. path = parsed.path
  56. if parsed.query != '': path += '?' + parsed.query
  57. if path == '': path == '/'
  58. # get the hostname for later
  59. host = parsed.netloc.split(':')
  60. hostname = host[0]
  61. # get cached date for redirects, if available
  62. original_date = effective_date
  63. effective_date = date_cache.get(effective_date + '\x00' + archived_url, effective_date)
  64. # get date from username:password, if available
  65. if auth:
  66. effective_date = auth.replace(':', '')
  67. try:
  68. if path in pac_file_paths:
  69. # PAC file to bypass QUICK_IMAGES requests
  70. pac = http_version.encode('ascii', 'ignore') + b''' 200 OK\r\n'''
  71. pac += b'''Content-Type: application/x-ns-proxy-autoconfig\r\n'''
  72. pac += b'''\r\n'''
  73. pac += b'''function FindProxyForURL(url, host)\r\n'''
  74. pac += b'''{\r\n'''
  75. pac += b''' if (shExpMatch(url, "http://web.archive.org/web/*") && !shExpMatch(url, "http://web.archive.org/web/??????????????if_/*"))\r\n'''
  76. pac += b''' {\r\n'''
  77. pac += b''' return "DIRECT";\r\n'''
  78. pac += b''' }\r\n'''
  79. pac += b''' return "PROXY ''' + pac_host.encode('ascii', 'ignore') + b'''";\r\n'''
  80. pac += b'''}\r\n'''
  81. self.request.sendall(pac)
  82. return
  83. elif hostname == 'web.archive.org':
  84. if path[:5] != '/web/':
  85. # launch settings
  86. return self.handle_settings(parsed.query)
  87. else:
  88. # pass-through requests to web.archive.org
  89. # required for QUICK_IMAGES
  90. archived_url = '/'.join(request_url.split('/')[5:])
  91. _print('[>] [QI] {0}'.format(archived_url))
  92. try:
  93. conn = urllib.request.urlopen(request_url)
  94. except urllib.error.HTTPError as e:
  95. if e.code == 404:
  96. # Try this file on another date, might be redundant
  97. return self.redirect_page(http_version, archived_url)
  98. else:
  99. raise e
  100. elif GEOCITIES_FIX and hostname == 'www.geocities.com':
  101. # apply GEOCITIES_FIX and pass it through
  102. _print('[>] {0}'.format(archived_url))
  103. split = archived_url.split('/')
  104. hostname = split[2] = 'www.oocities.org'
  105. request_url = '/'.join(split)
  106. conn = urllib.request.urlopen(request_url)
  107. else:
  108. # get from Wayback
  109. _print('[>] {0}'.format(archived_url))
  110. request_url = 'http://web.archive.org/web/{0}/{1}'.format(effective_date, archived_url)
  111. conn = urllib.request.urlopen(request_url)
  112. except urllib.error.HTTPError as e:
  113. # an error has been found
  114. if e.code in (403, 404, 412):
  115. # 403, 404 or tolerance exceeded => heuristically determine the static URL for some redirect scripts
  116. match = re.search('''[^/]/((?:http(?:%3A|:)(?:%2F|/)|www(?:[0-9]+)?\.(?:[^/%]+))(?:%2F|/).+)''', archived_url, re.IGNORECASE)
  117. if not match:
  118. match = re.search('''(?:\?|&)(?:[^=]+)=((?:http(?:%3A|:)(?:%2F|/)|www(?:[0-9]+)?\.(?:[^/%]+))?(?:%2F|/)[^&]+)''', archived_url, re.IGNORECASE)
  119. if match:
  120. print(match.groups())
  121. # we found it
  122. new_url = urllib.parse.unquote_plus(match.group(1))
  123. # add protocol if the URL is absolute but missing a protocol
  124. if new_url[0] != '/' and '://' not in new_url:
  125. new_url = 'http://' + new_url
  126. _print('[r]', new_url)
  127. return self.redirect_page(http_version, new_url)
  128. elif e.code in (301, 302):
  129. # 301 or 302 => urllib-generated error about an infinite redirect loop
  130. _print('[!] Infinite redirect loop')
  131. return self.error_page(http_version, 508, 'Infinite Redirect Loop')
  132. if e.code != 412: # tolerance exceeded has its own error message above
  133. _print('[!] {0} {1}'.format(e.code, e.reason))
  134. # If the memento Link header is present, this is a website error
  135. # instead of a Wayback error. Pass it along if that's the case.
  136. if 'Link' in e.headers:
  137. conn = e
  138. else:
  139. return self.error_page(http_version, e.code, e.reason)
  140. # get content type
  141. content_type = conn.info().get('Content-Type')
  142. if content_type == None: content_type = 'text/html'
  143. if not CONTENT_TYPE_ENCODING and content_type.find(';') > -1: content_type = content_type[:content_type.find(';')]
  144. # set the mode: [0]wayback [1]oocities
  145. mode = 0
  146. if GEOCITIES_FIX and hostname in ['www.oocities.org', 'www.oocities.com']: mode = 1
  147. if 'text/html' in content_type: # HTML
  148. # Some dynamically generated links may end up pointing to
  149. # web.archive.org. Correct that by redirecting the Wayback
  150. # portion of the URL away if it ends up being HTML consumed
  151. # through the QUICK_IMAGES interface.
  152. if hostname == 'web.archive.org':
  153. conn.close()
  154. archived_url = '/'.join(request_url.split('/')[5:])
  155. _print('[r] [QI]', archived_url)
  156. return self.redirect_page(http_version, archived_url, 301)
  157. # check if the date is within tolerance
  158. if DATE_TOLERANCE is not None:
  159. match = re.search('''//web\.archive\.org/web/([0-9]+)''', conn.geturl())
  160. if match:
  161. requested_date = match.group(1)
  162. if self.wayback_to_datetime(requested_date) > self.wayback_to_datetime(original_date) + datetime.timedelta(DATE_TOLERANCE):
  163. _print('[!]', requested_date, 'is outside the configured tolerance of', DATE_TOLERANCE, 'days')
  164. conn.close()
  165. return self.error_page(http_version, 412, 'Snapshot ' + requested_date + ' not available')
  166. # consume all data
  167. data = conn.read()
  168. # patch the page
  169. if mode == 0: # wayback
  170. if b'<title>Wayback Machine</title>' in data:
  171. match = re.search(b'<iframe id="playback" src="((?:(?:http(?:s)?:)?//web.archive.org)?/web/[^"]+)"', data)
  172. if match:
  173. # media playback iframe
  174. # Some websites (especially ones that use frames)
  175. # inexplicably render inside a media playback iframe.
  176. # In that case, a simple redirect would result in a
  177. # redirect loop. Download the URL and render it instead.
  178. request_url = match.group(1).decode('ascii', 'ignore')
  179. archived_url = '/'.join(request_url.split('/')[5:])
  180. print('[f]', archived_url)
  181. try:
  182. conn = urllib.request.urlopen(request_url)
  183. except urllib.error.HTTPError as e:
  184. _print('[!]', e.code, e.reason)
  185. # If the memento Link header is present, this is a website error
  186. # instead of a Wayback error. Pass it along if that's the case.
  187. if 'Link' in e.headers:
  188. conn = e
  189. else:
  190. return self.error_page(http_version, e.code, e.reason)
  191. content_type = conn.info().get('Content-Type')
  192. if not CONTENT_TYPE_ENCODING and content_type.find(';') > -1: content_type = content_type[:content_type.find(';')]
  193. data = conn.read()
  194. if b'<title></title>' in data and b'<h1><span>Internet Archive\'s Wayback Machine</span></h1>' in data:
  195. match = re.search(b'<p class="impatient"><a href="(?:(?:http(?:s)?:)?//web\.archive\.org)?/web/([^/]+)/([^"]+)">Impatient\?</a></p>', data)
  196. if match:
  197. # wayback redirect page, follow it
  198. match2 = re.search(b'<p class="code shift red">Got an HTTP ([0-9]+)', data)
  199. try:
  200. redirect_code = int(match2.group(1))
  201. except:
  202. redirect_code = 302
  203. archived_url = match.group(2).decode('ascii', 'ignore')
  204. date_cache[effective_date + '\x00' + archived_url] = match.group(1).decode('ascii', 'ignore')
  205. print('[r]', archived_url)
  206. return self.redirect_page(http_version, archived_url, redirect_code)
  207. # pre-toolbar scripts and CSS
  208. data = re.sub(b'<script src="//archive\.org/(?:.*)<!-- End Wayback Rewrite JS Include -->', b'', data, flags=re.S)
  209. # toolbar
  210. data = re.sub(b'<!-- BEGIN WAYBACK TOOLBAR INSERT -->(?:.*)<!-- END WAYBACK TOOLBAR INSERT -->', b'', data, flags=re.S)
  211. # comments on footer
  212. data = re.sub(b'\n<!--\n FILE ARCHIVED (?:.*)$', b'', data, flags=re.S)
  213. # fix base tag
  214. data = re.sub(b'(<base (?:[^>]*)href=(?:["\'])?)(?:(?:http(?:s)?:)?//web.archive.org)?/web/(?:[^/]+)/', b'\\1', data, flags=re.I + re.S)
  215. # remove extraneous :80 from links
  216. data = re.sub(b'((?:(?:http(?:s)?:)?//web.archive.org)?/web/)([^/]+)/([^:]+)://([^:]+):80/', b'\\1\\2/\\3://\\4/', data)
  217. # fix links
  218. if QUICK_IMAGES:
  219. # QUICK_IMAGES works by intercepting asset URLs (those
  220. # with a date code ending in im_, js_...) and letting the
  221. # proxy pass them through. This may reduce load time
  222. # because Wayback doesn't have to hunt down the closest
  223. # copy of that asset to DATE, as those URLs have specific
  224. # date codes. This taints the HTML with web.archive.org
  225. # URLs. QUICK_IMAGES=2 uses the original URLs with an added
  226. # username:password, which taints less but is not supported
  227. # by all browsers - IE6 notably kills the whole page if it
  228. # sees an iframe pointing to an invalid URL.
  229. data = re.sub(b'(?:(?:http(?:s)?:)?//web.archive.org)?/web/([0-9]+)([a-z]+_)/([^:]+)://',
  230. QUICK_IMAGES == 2 and b'\\3://\\1:\\2@' or b'http://web.archive.org/web/\\1\\2/\\3://', data)
  231. data = re.sub(b'(?:(?:http(?:s)?:)?//web.archive.org)?/web/([0-9]+)/', b'', data)
  232. else:
  233. #data = re.sub(b'(?:(?:http(?:s)?:)?//web.archive.org)?/web/([^/]+)/', b'', data)
  234. def add_to_date_cache(match):
  235. orig_url = match.group(2)
  236. date_cache[effective_date + '\x00' + orig_url.decode('ascii', 'ignore')] = match.group(1).decode('ascii', 'ignore')
  237. return orig_url
  238. data = re.sub(b'(?:(?:http(?:s)?:)?//web.archive.org)?/web/([^/]+)/([^"\'#<>]+)', add_to_date_cache, data)
  239. elif mode == 1: # oocities
  240. # viewport/cache-control/max-width code (header)
  241. data = re.sub(b'^(?:.*?)\n\n', b'', data, flags=re.S)
  242. # archive notice and tracking code (footer)
  243. data = re.sub(b'<style> \n.zoomout { -webkit-transition: (?:.*)$', b'', data, flags=re.S)
  244. # clearly labeled snippets from Geocities
  245. data = re.sub(b'^(?:.*)<\!-- text above generated by server\. PLEASE REMOVE -->', b'', data, flags=re.S)
  246. data = re.sub(b'<\!-- following code added by server\. PLEASE REMOVE -->(?:.*)<\!-- preceding code added by server\. PLEASE REMOVE -->', b'', data, flags=re.S)
  247. data = re.sub(b'<\!-- text below generated by server\. PLEASE REMOVE -->(?:.*)$', b'', data, flags=re.S)
  248. # fix links
  249. data = re.sub(b'//([^.]*)\.oocities\.com/', b'//\\1.geocities.com/', data, flags=re.S)
  250. self.send_response_headers(conn, http_version, content_type, request_url)
  251. self.request.sendall(data)
  252. else: # other data
  253. self.send_response_headers(conn, http_version, content_type, request_url)
  254. while True:
  255. data = conn.read(1024)
  256. if not data: break
  257. self.request.sendall(data)
  258. self.request.close()
  259. def send_response_headers(self, conn, http_version, content_type, request_url):
  260. """Generate and send the response headers."""
  261. response = http_version
  262. # pass the error code if there is one
  263. if isinstance(conn, urllib.error.HTTPError):
  264. response += '{0} {1}'.format(conn.code, conn.reason.replace('\n', ' '))
  265. else:
  266. response += '200 OK'
  267. # add content type, and the ETag for caching
  268. response += '\r\nContent-Type: ' + content_type + '\r\nETag: "' + request_url.replace('"', '') + '"\r\n'
  269. # add X-Archive-Orig-* headers
  270. headers = conn.info()
  271. for header in headers:
  272. if header.find('X-Archive-Orig-') == 0:
  273. orig_header = header[15:]
  274. # blacklist certain headers which may alter the client
  275. if orig_header.lower() not in ('connection', 'location', 'content-type', 'etag', 'authorization', 'set-cookie'):
  276. response += orig_header + ': ' + headers[header] + '\r\n'
  277. # finish and send the request
  278. response += '\r\n'
  279. self.request.sendall(response.encode('ascii', 'ignore'))
  280. def error_page(self, http_version, code, reason):
  281. """Generate an error page."""
  282. # make error page
  283. errorpage = '<html><head><title>{0} {1}</title>'.format(code, reason)
  284. # IE's same-origin policy throws "Access is denied." inside frames
  285. # loaded from a different origin. Use that to our advantage, even
  286. # though regular frames are also affected. IE also doesn't recognize
  287. # language="javascript1.4", so use 1.3 while blocking IE4 by detecting
  288. # the lack of screenLeft as IE4 is quite noisy with script errors.
  289. errorpage += '<script language="javascript1.3">if (window.screenLeft != null) { eval(\'try { var frameElement = window.frameElement; } catch (e) { document.location.href = "about:blank"; }\'); }</script>'
  290. errorpage += '<script language="javascript">if (window.self != window.top && !(window.frameElement && window.frameElement.tagName == "FRAME")) { document.location.href = "about:blank"; }</script>'
  291. errorpage += '</head><body><h1>{0}</h1><p>'.format(reason)
  292. # add code information
  293. if code in (404, 508): # page not archived or redirect loop
  294. errorpage += 'This page may not be archived by the Wayback Machine.'
  295. elif code == 403: # not crawled due to robots.txt
  296. errorpage += 'This page was not archived due to a robots.txt block.'
  297. elif code == 501: # method not implemented
  298. errorpage += 'WaybackProxy only implements the GET method.'
  299. elif code == 412: # outside of tolerance
  300. errorpage += 'The earliest snapshot for this page is outside of the configured tolerance interval.'
  301. elif code == 400 and reason == 'Host header missing': # no host header in transparent mode
  302. errorpage += 'WaybackProxy\'s transparent mode requires an HTTP/1.1 compliant client.'
  303. else: # another error
  304. errorpage += 'Unknown error. The Wayback Machine may be experiencing technical difficulties.'
  305. errorpage += '</p><hr><i>'
  306. errorpage += self.signature()
  307. errorpage += '</i></body></html>'
  308. # add padding for IE
  309. if len(errorpage) <= 512:
  310. padding = '\n<!-- This comment pads the HTML so Internet Explorer displays this error page instead of its own. '
  311. remainder = 510 - len(errorpage) - len(padding)
  312. if remainder > 0:
  313. padding += ' ' * remainder
  314. padding += '-->'
  315. errorpage += padding
  316. # send error page and stop
  317. self.request.sendall('{0} {1} {2}\r\nContent-Type: text/html\r\nContent-Length: {3}\r\n\r\n{4}'.format(http_version, code, reason, len(errorpage), errorpage).encode('utf8', 'ignore'))
  318. self.request.close()
  319. def redirect_page(self, http_version, target, code=302):
  320. """Generate a redirect page."""
  321. # make redirect page
  322. redirectpage = '<html><head><title>Redirect</title><meta http-equiv="refresh" content="0;url='
  323. redirectpage += target
  324. redirectpage += '"></head><body><p>If you are not redirected, <a href="'
  325. redirectpage += target
  326. redirectpage += '">click here</a>.</p></body></html>'
  327. # send redirect page and stop
  328. self.request.sendall('{0} {1} Found\r\nLocation: {2}\r\nContent-Type: text/html\r\nContent-Length: {3}\r\n\r\n{4}'.format(http_version, code, target, len(redirectpage), redirectpage).encode('utf8', 'ignore'))
  329. self.request.close()
  330. def handle_settings(self, query):
  331. """Generate the settings page."""
  332. global DATE, GEOCITIES_FIX, QUICK_IMAGES, CONTENT_TYPE_ENCODING
  333. if query != '': # handle any parameters that may have been sent
  334. parsed = urllib.parse.parse_qs(query)
  335. if 'date' in parsed and DATE != parsed['date'][0]:
  336. DATE = parsed['date'][0]
  337. date_cache.clear()
  338. GEOCITIES_FIX = 'gcFix' in parsed
  339. QUICK_IMAGES = 'quickImages' in parsed
  340. CONTENT_TYPE_ENCODING = 'ctEncoding' in parsed
  341. # send the page and stop
  342. settingspage = 'HTTP/1.1 200 OK\r\nContent-Type: text/html\r\n\r\n'
  343. settingspage += '<html><head><title>WaybackProxy Settings</title></head><body><p><b>'
  344. settingspage += self.signature()
  345. settingspage += '</b></p><form method="get" action="/"><p>Date to get pages from: <input type="text" name="date" size="8" value="'
  346. settingspage += DATE
  347. settingspage += '"><br><input type="checkbox" name="gcFix"'
  348. if GEOCITIES_FIX: settingspage += ' checked'
  349. settingspage += '> Geocities Fix<br><input type="checkbox" name="quickImages"'
  350. if QUICK_IMAGES: settingspage += ' checked'
  351. settingspage += '> Quick images<br><input type="checkbox" name="ctEncoding"'
  352. if CONTENT_TYPE_ENCODING: settingspage += ' checked'
  353. settingspage += '> Encoding in Content-Type</p><p><input type="submit" value="Save"></p></form></body></html>'
  354. self.request.send(settingspage.encode('utf8', 'ignore'))
  355. self.request.close()
  356. def signature(self):
  357. """Return the server signature."""
  358. return 'WaybackProxy on {0}'.format(socket.gethostname())
  359. def wayback_to_datetime(self, date):
  360. """Convert a Wayback format date string to a datetime.datetime object."""
  361. # parse the string
  362. year = 1995
  363. month = 12
  364. day = 31
  365. hour = 0
  366. minute = 0
  367. second = 0
  368. if len(date) > 0:
  369. year = int(date[:4])
  370. if len(date) > 4:
  371. month = int(date[4:6])
  372. if len(date) > 6:
  373. day = int(date[6:8])
  374. if len(date) > 8:
  375. hour = int(date[8:10])
  376. if len(date) > 10:
  377. minute = int(date[10:12])
  378. if len(date) > 12:
  379. second = int(date[12:14])
  380. # sanitize the numbers
  381. if month < 1:
  382. month = 1
  383. elif month > 12:
  384. month = 12
  385. if day < 1:
  386. day = 1
  387. elif day > 31:
  388. day = 31
  389. if hour > 23:
  390. hour = 23
  391. elif hour < 0:
  392. hour = 0
  393. if minute > 59:
  394. minute = 59
  395. elif minute < 0:
  396. minute = 0
  397. if second > 59:
  398. second = 59
  399. elif second < 0:
  400. second = 0
  401. # if the day is invalid for that month, work its way down
  402. try:
  403. dt = datetime.datetime(year, month, day, hour, minute, second) # max 31
  404. except:
  405. try:
  406. dt = datetime.datetime(year, month, day - 1, hour, minute, second) # max 30
  407. except:
  408. try:
  409. dt = datetime.datetime(year, month, day - 2, hour, minute, second) # max 29
  410. except:
  411. dt = datetime.datetime(year, month, day - 3, hour, minute, second) # max 28
  412. return dt
  413. print_lock = threading.Lock()
  414. def _print(*args, linebreak=True):
  415. """Logging function."""
  416. if SILENT: return
  417. s = ' '.join([str(x) for x in args])
  418. print_lock.acquire()
  419. sys.stdout.write(linebreak and (s + '\n') or s)
  420. sys.stdout.flush()
  421. print_lock.release()
  422. def main():
  423. """Starts the server."""
  424. server = ThreadingTCPServer(('', LISTEN_PORT), Handler)
  425. _print('[-] Now listening on port {0}'.format(LISTEN_PORT))
  426. try:
  427. server.serve_forever()
  428. except KeyboardInterrupt: # Ctrl+C to stop
  429. pass
  430. if __name__ == '__main__':
  431. main()