|
Packit |
57988d |
|
|
Packit |
57988d |
##########################################################################
|
|
Packit |
57988d |
# $Id$
|
|
Packit |
57988d |
##########################################################################
|
|
Packit |
57988d |
|
|
Packit |
57988d |
#####################################################
|
|
Packit |
57988d |
## Copyright (c) 2008 Kirk Bauer
|
|
Packit |
57988d |
## Covered under the included MIT/X-Consortium License:
|
|
Packit |
57988d |
## http://www.opensource.org/licenses/mit-license.php
|
|
Packit |
57988d |
## All modifications and contributions by other persons to
|
|
Packit |
57988d |
## this script are assumed to have been donated to the
|
|
Packit |
57988d |
## Logwatch project and thus assume the above copyright
|
|
Packit |
57988d |
## and licensing terms. If you want to make contributions
|
|
Packit |
57988d |
## under your own copyright or a different license this
|
|
Packit |
57988d |
## must be explicitly stated in the contribution an the
|
|
Packit |
57988d |
## Logwatch project reserves the right to not accept such
|
|
Packit |
57988d |
## contributions. If you have made significant
|
|
Packit |
57988d |
## contributions to this script and want to claim
|
|
Packit |
57988d |
## copyright please contact logwatch-devel@lists.sourceforge.net.
|
|
Packit |
57988d |
#########################################################
|
|
Packit |
57988d |
|
|
Packit |
57988d |
$Debug = $ENV{'LOGWATCH_DEBUG'} || 0;
|
|
Packit |
57988d |
$Detail = $ENV{'LOGWATCH_DETAIL_LEVEL'} || 0;
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "\n\nDEBUG: Inside Identd Filter \n\n";
|
|
Packit |
57988d |
$DebugCounter = 1;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
# This whole NeedNextLine thing is because there are multiple lines that
|
|
Packit |
57988d |
# go together for these log entries...
|
|
Packit |
57988d |
|
|
Packit |
57988d |
$ThisLine = <STDIN>;
|
|
Packit |
57988d |
while (defined($ThisLine)) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Line Number " . $DebugCounter . ":\n";
|
|
Packit |
57988d |
print STDERR "DEBUG: " . $ThisLine;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
$NeedNextLine = 1;
|
|
Packit |
57988d |
if ( ($IP,$Hostname,$Port) = ($ThisLine =~ m/^from: (\d+\.\d+\.\d+\.\d+) \( ([^ ]*) \) for: \d+, (\d+)$/) ) {
|
|
Packit |
57988d |
# this means that somebody accessed identd...
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found -Connection From- Line -- Reading another line\n";
|
|
Packit |
57988d |
$DebugCounter++;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
if (defined($NextLine = <STDIN>)) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Line Number " . $DebugCounter . ":\n";
|
|
Packit |
57988d |
print STDERR "DEBUG: " . $NextLine;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
if ( ($User) = ($NextLine =~ m/^Successful lookup: \d+ , \d+ : ([^ ]+)\.[^ ]+/) ) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found -Successful Lookup- line (" . $User . ")\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
${Identd{$IP}}[0] = $Hostname;
|
|
Packit |
57988d |
${Identd{$IP}}[1]++;
|
|
Packit |
57988d |
push @{${Identd{$IP}}[2]}, $Port;
|
|
Packit |
57988d |
push @{${Identd{$IP}}[3]}, $User;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
else {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: No matches... keeping current line.\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
$ThisLine = $NextLine;
|
|
Packit |
57988d |
$NeedNextLine = 0;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
elsif ( ($IP,$Hostname) = ($ThisLine =~ m/^from: (\d+\.\d+\.\d+\.\d+) \(([^ ]*)\) EMPTY REQUEST$/) ) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found -Empty Request- Line\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
$Text = " " . $Hostname . " (" . $IP . ")";
|
|
Packit |
57988d |
push @EmptyRequests,$Text;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
elsif ( ($IP,$Hostname,$Name) = ($ThisLine =~ m/^from: (\d+\.\d+\.\d+\.\d+) \(([^ ]*)\) INVALID REQUEST: (.*)$/) ) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found -Invalid Request- Line\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
$Text = " " . $Hostname . " (" . $IP . ") - " . $Name;
|
|
Packit |
57988d |
push @InvalidRequests,$Text;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
elsif ( $ThisLine =~ m/^Returned: \d+ , \d+ : NO-USER/ ) {
|
|
Packit |
57988d |
# Do nothing...
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
elsif ( ($Host) = ( $ThisLine =~ /^Connection from ([^ ]+)/ ) ) {
|
|
Packit |
57988d |
chomp($Host);
|
|
Packit |
57988d |
if (defined($NextLine = <STDIN>)) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Line Number " . $DebugCounter . ":\n";
|
|
Packit |
57988d |
print STDERR "DEBUG: " . $NextLine;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
if ( ($Port,$User) = ($NextLine =~ m/^Successful lookup: \d+ , (\d+) : ([^ ]+)/) ) {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found -Successful Lookup- line (" . $User . ")\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
chomp($Port); chomp($User);
|
|
Packit |
57988d |
${Identd{$Host}}[0] = $Host;
|
|
Packit |
57988d |
${Identd{$Host}}[1]++;
|
|
Packit |
57988d |
push @{${Identd{$Host}}[2]}, $Port;
|
|
Packit |
57988d |
push @{${Identd{$Host}}[3]}, $User;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
else {
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: No matches... keeping current line.\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
$ThisLine = $NextLine;
|
|
Packit |
57988d |
$NeedNextLine = 0;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
elsif ($ThisLine =~ /^Successful lookup: [1234567890]+ , [1234567890]+ : [^ ]+/ ) {
|
|
Packit |
57988d |
# skip empty entry ...
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
else {
|
|
Packit |
57988d |
# Report any unmatched entries...
|
|
Packit |
57988d |
if ( $Debug >= 5 ) {
|
|
Packit |
57988d |
print STDERR "DEBUG: Found unmatched line\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
chomp($ThisLine);
|
|
Packit |
57988d |
$OtherList{$ThisLine}++;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
if ($NeedNextLine == 1) {
|
|
Packit |
57988d |
$ThisLine = <STDIN>;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if ( (keys %Identd) and ($Detail >= 10) ) {
|
|
Packit |
57988d |
print "Identd Lookups:\n";
|
|
Packit |
57988d |
foreach $ThisOne (keys %Identd) {
|
|
Packit |
57988d |
print " Host: " . ${Identd{$ThisOne}}[0] . " (" . $ThisOne . ") - " . ${Identd{$ThisOne}}[1] . " Connection(s).\n";
|
|
Packit |
57988d |
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (($#EmptyRequests >= 0) and ($Detail >= 5)) {
|
|
Packit |
57988d |
print "\nEmpty requests:\n";
|
|
Packit |
57988d |
foreach $ThisOne (@EmptyRequests) {
|
|
Packit |
57988d |
print " " . $ThisOne . "\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (($#InvalidRequests >= 0) and ($Detail >= 5)) {
|
|
Packit |
57988d |
print "\nInvalid requests:\n";
|
|
Packit |
57988d |
foreach $ThisOne (@InvalidRequests) {
|
|
Packit |
57988d |
print " " . $ThisOne . "\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (keys %OtherList) {
|
|
Packit |
57988d |
print "\n**Unmatched Entries**\n";
|
|
Packit |
57988d |
foreach $line (sort {$a cmp $b} keys %OtherList) {
|
|
Packit |
57988d |
print "$line: $OtherList{$line} Time(s)\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
exit(0);
|
|
Packit |
57988d |
|
|
Packit |
57988d |
# vi: shiftwidth=3 tabstop=3 syntax=perl et
|
|
Packit |
57988d |
# Local Variables:
|
|
Packit |
57988d |
# mode: perl
|
|
Packit |
57988d |
# perl-indent-level: 3
|
|
Packit |
57988d |
# indent-tabs-mode: nil
|
|
Packit |
57988d |
# End:
|