path: root/contrib/examples/ncat-client-server
diff options
authorJason A. Donenfeld <Jason@zx2c4.com>2016-07-05 16:01:31 +0200
committerJason A. Donenfeld <Jason@zx2c4.com>2016-07-05 16:01:31 +0200
commitf7ff6390bb898f343ef7b1590b6a9d56a296af8c (patch)
treeaacdd65b3d7d97e2b8a1c1ae6aba93ff5c65ae42 /contrib/examples/ncat-client-server
parentreceive: protect against impossible conditions (diff)
contrib: organize example scripts and add synergy
Diffstat (limited to 'contrib/examples/ncat-client-server')
3 files changed, 50 insertions, 0 deletions
diff --git a/contrib/examples/ncat-client-server/README b/contrib/examples/ncat-client-server/README
new file mode 100644
index 0000000..fd3088a
--- /dev/null
+++ b/contrib/examples/ncat-client-server/README
@@ -0,0 +1,16 @@
+Do not use these scripts in production. They are simply a
+demonstration of how easy the `wg(8)` tool is at the command
+line, but by no means should you actually attempt to use
+these. They are horribly insecure and defeat the purpose
+of WireGuard.
+Distros: do not distribute these with your packages.
+That all said, this is a pretty cool example of just how
+darn easy WireGuard can be.
diff --git a/contrib/examples/ncat-client-server/client.sh b/contrib/examples/ncat-client-server/client.sh
new file mode 100755
index 0000000..fbae46a
--- /dev/null
+++ b/contrib/examples/ncat-client-server/client.sh
@@ -0,0 +1,20 @@
+set -e
+[[ $UID == 0 ]] || { echo "You must be root to run this."; exit 1; }
+umask 077
+trap 'rm -f /tmp/wg_private_key' EXIT INT TERM
+exec 3<>/dev/tcp/demo.wireguard.io/42912
+wg genkey | tee /tmp/wg_private_key | wg pubkey >&3
+IFS=: read -r status server_pubkey server_port internal_ip <&3
+[[ $status == OK ]]
+ip link del dev wg0 2>/dev/null || true
+ip link add dev wg0 type wireguard
+wg set wg0 private-key /tmp/wg_private_key peer "$server_pubkey" allowed-ips endpoint "demo.wireguard.io:$server_port"
+ip address add "$internal_ip"/24 dev wg0
+ip link set up dev wg0
+if [ "$1" == "default-route" ]; then
+ host="$(wg show wg0 endpoints | sed -n 's/.*\t\(.*\):.*/\1/p')"
+ ip route add $(ip route get $host | sed '/ via [0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}/{s/^\(.* via [0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\).*/\1/}' | head -n 1) 2>/dev/null || true
+ ip route add 0/1 dev wg0
+ ip route add 128/1 dev wg0
diff --git a/contrib/examples/ncat-client-server/server.sh b/contrib/examples/ncat-client-server/server.sh
new file mode 100755
index 0000000..e37861f
--- /dev/null
+++ b/contrib/examples/ncat-client-server/server.sh
@@ -0,0 +1,14 @@
+if [[ -z $NCAT_REMOTE_ADDR ]]; then
+ ip link del dev wg0 2>/dev/null
+ set -e
+ ip link add dev wg0 type wireguard
+ ip address add dev wg0
+ wg set wg0 private-key <(wg genkey) listen-port 12912
+ ip link set up dev wg0
+ exec ncat -e "$(readlink -f "$0")" -k -l -p 42912 -v
+read -r public_key
+[[ $(wg show wg0 | grep peer | wc -l) -ge 253 ]] && wg set wg0 peer $(wg show wg0 latest-handshakes | sort -k 2 -b -n | head -n 1 | cut -f 1) remove
+next_ip=$(all="$(wg show wg0 allowed-ips)"; for ((i=2; i<=254; i++)); do ip="192.168.4.$i"; [[ $all != *$ip/32* ]] && echo $ip && break; done)
+wg set wg0 peer "$public_key" allowed-ips $next_ip/32 2>/dev/null && echo "OK:$(wg show wg0 private-key | wg pubkey):$(wg show wg0 listen-port):$next_ip" || echo ERROR