[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAHWwQTm9VLgC6SC_Qa9oHnKXO6fm-_lJM2HcQMnZmYU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},483,"What is an alternative approach to implement screen control similar to Pupy, and what are its limitations?","An alternative is HTTP-Remote-Desktop-Server, which uses a Python-based Client (with PyGtk and pyautogui) to capture screenshots and execute commands, and a browser Server. Unlike Pupy, it requires manual refresh to update screen content (no streaming) and uses uncompressed PNG screenshots, making it less efficient but simpler for secondary development.","\u003Cp>An alternative is HTTP-Remote-Desktop-Server, which uses a Python-based Client (with PyGtk and pyautogui) to capture screenshots and execute commands, and a browser Server. Unlike Pupy, it requires manual refresh to update screen content (no streaming) and uses uncompressed PNG screenshots, making it less efficient but simpler for secondary development.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpupy-exploitation-analysis-screen-control-on-windows-platform\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-an-alternative-approach-to-implement-screen-control-similar-to-pupy-and--1777483375175","HTTP-Remote-Desktop-Server, alternative, screen capture, pyautogui, screenshot",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},120,"Pupy Exploitation Analysis - Screen Control on Windows Platform","pupy-exploitation-analysis-screen-control-on-windows-platform","Analyze Pupy's screen control feature on Windows, covering UAC issues, implementation methods, and an alternative approach using HTTP-Remote-Desktop-Server for secondary development.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy's post-exploitation modules on the Windows platform include a practical feature: screen control. This functionality not only allows viewing screen content but also enables sending mouse and keyboard messages. This article will analyze the implementation method of this feature and propose an alternative approach to achieve similar functionality, facilitating secondary development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Testing Pupy's screen control module\u003C\u002Fli>\u003Cli>Pupy's implementation method\u003C\u002Fli>\u003Cli>An alternative implementation method\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Testing Pupy's Screen Control Module\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For basic usage of Pupy, refer to the previous article \"Pupy Exploitation Analysis - Features on Windows Platform\"\u003C\u002Fp>\u003Cp>After obtaining a session, enter 'rdesktop' to load the screen control module, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017965570_0_bf0ad523c0.jpeg\">\u003C\u002Fp>\u003Cp>The browser can access the URL to view and operate the screen, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017968624_1_dfe33a0e57.jpeg\">\u003C\u002Fp>\u003Cp>Here, input of keyboard messages and mouse clicks is supported\u003C\u002Fp>\u003Cp>When operating with standard user permissions, be aware of UAC issues (cannot interact with UAC pop-ups)\u003C\u002Fp>\u003Cp>When UAC pops up, the process consent.exe is created\u003C\u002Fp>\u003Cp>System permissions are required to close this process; after closing, a dialog box prompts: The storage control block address is invalid.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975561_2_f681c77757.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CMD command to disable UAC pop-up prompts:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv ConsentPromptBehaviorAdmin \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>CMD command to enable UAC pop-up prompts:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv ConsentPromptBehaviorAdmin \u002Ft REG_DWORD \u002Fd 5 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Implementation Method of Pupy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implementation code of the rdesktop module: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fmodules\u002Frdesktop.py\u003C\u002Fp>\u003Cp>The implementation is divided into the following three parts:\u003C\u002Fp>\u003Ch4>1. Client\u003C\u002Fh4>\u003Cp>Interacts with the target screen, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Transmits the current screen content of the target\u003C\u002Fli>\u003Cli>Receives mouse and keyboard messages from the Server and executes them\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fpackages\u002Fall\u002Frdesktop.py\u003C\u002Fp>\u003Ch4>2. Transfer\u003C\u002Fh4>\u003Cp>Acts as a communication bridge between the Client and Server, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Receives messages from the Client, decodes them, and forwards them to a specified local port for browser access\u003C\u002Fli>\u003Cli>Encodes mouse and keyboard messages from the browser and sends them to the Client\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fnetwork\u002Flib\u002Ftransports\u002Fwebsocket.py\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fnetwork\u002Ftransports\u002Fws\u002Fconf.py\u003C\u002Fp>\u003Ch4>3.Server\u003C\u002Fh4>\u003Cp>Control the target screen through the browser, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Display the Client's screen content in the browser\u003C\u002Fli>\u003Cli>Capture the current browser's mouse and keyboard messages and send them to transfer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fwebstatic\u002Frdesktop\u002Findex.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fwebstatic\u002Frdesktop\u002Frdesktop.js\u003C\u002Fp>\u003Cp>In Pupy's implementation, data between Client and Server is processed via transfer, using RSA+AES encryption, with the advantage of increasing the difficulty of restoring communication data\u003C\u002Fp>\u003Cp>To intuitively read communication data and facilitate secondary development of screen control functions, this attempts to remove the transfer functionality and achieve direct communication between Client and Server\u003C\u002Fp>\u003Ch2>0x04 Another Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, it is introduced based on HTTP-Remote-Desktop-Server\u003C\u002Fp>\u003Ch3>1. Environment Setup for HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>HTTP-Remote-Desktop-Server's run.py uses the PyGtk library under Python2 (import gtk.gdk)\u003C\u002Fp>\u003Cp>while the latest PyGtk library no longer supports Python2, having switched to Python3\u003C\u002Fp>\u003Cp>To compile the code, note the following issues:\u003C\u002Fp>\u003Cp>(1) Install 32-bit Python2\u003C\u002Fp>\u003Cp>64-bit systems also require 32-bit Python2; otherwise, the PyGtk library cannot be used\u003C\u002Fp>\u003Cp>(2) Download the PyGtk library for Python2\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fftp.gnome.org\u002Fpub\u002FGNOME\u002Fbinaries\u002Fwin32\u002Fpygtk\u002F2.24\u002Fpygtk-all-in-one-2.24.0.win32-py2.7.msi\u003C\u002Fp>\u003Cp>(3) Install other packages\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install -U wxPython\u003Cbr>pip install pyautogui\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Testing HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>Modify the IP in run.py to the current operating system's IP, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986114_3_ee136e3685.jpeg\">\u003C\u002Fp>\u003Cp>Start run.py\u003C\u002Fp>\u003Cp>On another system, access the specified URL via a browser to obtain screen content, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990583_4_c5c51fad52.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When using, firewall rules need to be enabled. The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"test\" protocol=TCP dir=in localport=9010 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Implementation of HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>(1) Client\u003C\u002Fp>\u003Cp>Interact with the target screen, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Capture the current screen and save it as screenshot.png\u003C\u002Fli>\u003Cli>Receive mouse and keyboard messages from the Server and execute them\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Frun.py\u003C\u002Fp>\u003Cp>(2) Server\u003C\u002Fp>\u003Cp>Control the target screen through the browser, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Display screenshot.png in the browser\u003C\u002Fli>\u003Cli>Capture current mouse and keyboard messages from the browser and send them to the Client\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Findex.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Fscripts.js\u003C\u002Fp>\u003Cp>HTTP-Remote-Desktop-Server operates by capturing screens (screenshot.png) for display and sending commands, thus it cannot provide continuous display; a refresh is required to obtain new screen content.\u003C\u002Fp>\u003Cp>Supports keyboard input, but a refresh is needed to obtain new screen content.\u003C\u002Fp>\u003Ch3>4. Optimization of HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>I forked the original code, and the modified code address is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Optimizations are as follows:\u003C\u002Fp>\u003Cp>(1) Changed the jQuery reference path in index.html to a relative path\u003C\u002Fp>\u003Cp>(2) Modified run.py to accept listening IP and port via parameters\u003C\u002Fp>\u003Cp>(3) Compiled the Python code into a standalone exe file\u003C\u002Fp>\u003Cp>Using Pyinstaller, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Python27\\Scripts\\pyinstaller.exe -F run.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The compiled file address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>To support double-click operations, you can modify run.py by adding the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyautogui.click(clicks=2)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The following issues need attention during secondary development:\u003C\u002Fp>\u003Cp>(1) Communication data is not encoded; compression algorithms can be chosen to improve efficiency\u003C\u002Fp>\u003Cp>(2) Access url:port\u002Fscreenshot.png to obtain a screenshot\u003C\u002Fp>\u003Cp>(3) Firewall rules need to be enabled during use. The corresponding example cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"test\" protocol=TCP dir=in localport=9010 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation method of Pupy and introduces the second implementation method using HTTP-Remote-Desktop-Server as a template, facilitating secondary development.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy's post-exploitation modules on the Windows platform include a practical feature: screen control. This functionality not only allows viewing screen content but also enables sending mouse and keyboard messages. This article will analyze the implementation method of this feature and propose an alternative approach to achieve similar functionality, facilitating secondary development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Testing Pupy's screen control module\u003C\u002Fli>\u003Cli>Pupy's implementation method\u003C\u002Fli>\u003Cli>An alternative implementation method\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Testing Pupy's Screen Control Module\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For basic usage of Pupy, refer to the previous article \"Pupy Exploitation Analysis - Features on Windows Platform\"\u003C\u002Fp>\u003Cp>After obtaining a session, enter 'rdesktop' to load the screen control module, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017965570_0_bf0ad523c0-1.jpeg\">\u003C\u002Fp>\u003Cp>The browser can access the URL to view and operate the screen, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017968624_1_dfe33a0e57-1.jpeg\">\u003C\u002Fp>\u003Cp>Here, input of keyboard messages and mouse clicks is supported\u003C\u002Fp>\u003Cp>When operating with standard user permissions, be aware of UAC issues (cannot interact with UAC pop-ups)\u003C\u002Fp>\u003Cp>When UAC pops up, the process consent.exe is created\u003C\u002Fp>\u003Cp>System permissions are required to close this process; after closing, a dialog box prompts: The storage control block address is invalid.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975561_2_f681c77757-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CMD command to disable UAC pop-up prompts:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv ConsentPromptBehaviorAdmin \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>CMD command to enable UAC pop-up prompts:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv ConsentPromptBehaviorAdmin \u002Ft REG_DWORD \u002Fd 5 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Implementation Method of Pupy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implementation code of the rdesktop module: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fmodules\u002Frdesktop.py\u003C\u002Fp>\u003Cp>The implementation is divided into the following three parts:\u003C\u002Fp>\u003Ch4>1. Client\u003C\u002Fh4>\u003Cp>Interacts with the target screen, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Transmits the current screen content of the target\u003C\u002Fli>\u003Cli>Receives mouse and keyboard messages from the Server and executes them\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fpackages\u002Fall\u002Frdesktop.py\u003C\u002Fp>\u003Ch4>2. Transfer\u003C\u002Fh4>\u003Cp>Acts as a communication bridge between the Client and Server, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Receives messages from the Client, decodes them, and forwards them to a specified local port for browser access\u003C\u002Fli>\u003Cli>Encodes mouse and keyboard messages from the browser and sends them to the Client\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fnetwork\u002Flib\u002Ftransports\u002Fwebsocket.py\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fnetwork\u002Ftransports\u002Fws\u002Fconf.py\u003C\u002Fp>\u003Ch4>3.Server\u003C\u002Fh4>\u003Cp>Control the target screen through the browser, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Display the Client's screen content in the browser\u003C\u002Fli>\u003Cli>Capture the current browser's mouse and keyboard messages and send them to transfer\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fwebstatic\u002Frdesktop\u002Findex.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002Funstable\u002Fpupy\u002Fwebstatic\u002Frdesktop\u002Frdesktop.js\u003C\u002Fp>\u003Cp>In Pupy's implementation, data between Client and Server is processed via transfer, using RSA+AES encryption, with the advantage of increasing the difficulty of restoring communication data\u003C\u002Fp>\u003Cp>To intuitively read communication data and facilitate secondary development of screen control functions, this attempts to remove the transfer functionality and achieve direct communication between Client and Server\u003C\u002Fp>\u003Ch2>0x04 Another Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, it is introduced based on HTTP-Remote-Desktop-Server\u003C\u002Fp>\u003Ch3>1. Environment Setup for HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>HTTP-Remote-Desktop-Server's run.py uses the PyGtk library under Python2 (import gtk.gdk)\u003C\u002Fp>\u003Cp>while the latest PyGtk library no longer supports Python2, having switched to Python3\u003C\u002Fp>\u003Cp>To compile the code, note the following issues:\u003C\u002Fp>\u003Cp>(1) Install 32-bit Python2\u003C\u002Fp>\u003Cp>64-bit systems also require 32-bit Python2; otherwise, the PyGtk library cannot be used\u003C\u002Fp>\u003Cp>(2) Download the PyGtk library for Python2\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fftp.gnome.org\u002Fpub\u002FGNOME\u002Fbinaries\u002Fwin32\u002Fpygtk\u002F2.24\u002Fpygtk-all-in-one-2.24.0.win32-py2.7.msi\u003C\u002Fp>\u003Cp>(3) Install other packages\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install -U wxPython\u003Cbr>pip install pyautogui\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Testing HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>Modify the IP in run.py to the current operating system's IP, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986114_3_ee136e3685-1.jpeg\">\u003C\u002Fp>\u003Cp>Start run.py\u003C\u002Fp>\u003Cp>On another system, access the specified URL via a browser to obtain screen content, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990583_4_c5c51fad52-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When using, firewall rules need to be enabled. The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"test\" protocol=TCP dir=in localport=9010 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Implementation of HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>(1) Client\u003C\u002Fp>\u003Cp>Interact with the target screen, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Capture the current screen and save it as screenshot.png\u003C\u002Fli>\u003Cli>Receive mouse and keyboard messages from the Server and execute them\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Frun.py\u003C\u002Fp>\u003Cp>(2) Server\u003C\u002Fp>\u003Cp>Control the target screen through the browser, including the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>Display screenshot.png in the browser\u003C\u002Fli>\u003Cli>Capture current mouse and keyboard messages from the browser and send them to the Client\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Findex.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBernardoGO\u002FHTTP-Remote-Desktop-Server\u002Fblob\u002Fmaster\u002Fscripts.js\u003C\u002Fp>\u003Cp>HTTP-Remote-Desktop-Server operates by capturing screens (screenshot.png) for display and sending commands, thus it cannot provide continuous display; a refresh is required to obtain new screen content.\u003C\u002Fp>\u003Cp>Supports keyboard input, but a refresh is needed to obtain new screen content.\u003C\u002Fp>\u003Ch3>4. Optimization of HTTP-Remote-Desktop-Server\u003C\u002Fh3>\u003Cp>I forked the original code, and the modified code address is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Optimizations are as follows:\u003C\u002Fp>\u003Cp>(1) Changed the jQuery reference path in index.html to a relative path\u003C\u002Fp>\u003Cp>(2) Modified run.py to accept listening IP and port via parameters\u003C\u002Fp>\u003Cp>(3) Compiled the Python code into a standalone exe file\u003C\u002Fp>\u003Cp>Using Pyinstaller, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Python27\\Scripts\\pyinstaller.exe -F run.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The compiled file address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>To support double-click operations, you can modify run.py by adding the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyautogui.click(clicks=2)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The following issues need attention during secondary development:\u003C\u002Fp>\u003Cp>(1) Communication data is not encoded; compression algorithms can be chosen to improve efficiency\u003C\u002Fp>\u003Cp>(2) Access url:port\u002Fscreenshot.png to obtain a screenshot\u003C\u002Fp>\u003Cp>(3) Firewall rules need to be enabled during use. The corresponding example cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"test\" protocol=TCP dir=in localport=9010 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation method of Pupy and introduces the second implementation method using HTTP-Remote-Desktop-Server as a template, facilitating secondary development.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1110,"Onedaysec",4,"published","2026-02-02T07:51:00.065Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pupy Screen Control Analysis: Windows Exploitation & Alternative Methods","Pupy exploitation, screen control Windows, post-exploitation modules, remote desktop, UAC bypass, HTTP-Remote-Desktop-Server, secondary development, mouse keyboard control, cybersecurity analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],485,484,482,481,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.119Z","2026-07-23T16:01:38.294Z","draft","2026-07-23T16:12:38.999Z"]