2006-06-26 20:05:00 +00:00
|
|
|
# This file is part of Fail2Ban.
|
|
|
|
#
|
|
|
|
# Fail2Ban is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by
|
|
|
|
# the Free Software Foundation; either version 2 of the License, or
|
|
|
|
# (at your option) any later version.
|
|
|
|
#
|
|
|
|
# Fail2Ban is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with Fail2Ban; if not, write to the Free Software
|
|
|
|
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
|
|
|
|
|
|
|
# Author: Cyril Jaquier
|
|
|
|
#
|
2008-03-06 01:19:06 +00:00
|
|
|
# $Revision: 638 $
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
__author__ = "Cyril Jaquier"
|
2008-03-06 01:19:06 +00:00
|
|
|
__version__ = "$Revision: 638 $"
|
|
|
|
__date__ = "$Date: 2007-12-17 21:00:36 +0100 (Mon, 17 Dec 2007) $"
|
2006-06-26 20:05:00 +00:00
|
|
|
__copyright__ = "Copyright (c) 2004 Cyril Jaquier"
|
|
|
|
__license__ = "GPL"
|
|
|
|
|
|
|
|
from faildata import FailData
|
2008-03-06 01:19:06 +00:00
|
|
|
from ticket import FailTicket
|
2006-06-26 20:05:00 +00:00
|
|
|
from threading import Lock
|
2006-09-25 17:03:48 +00:00
|
|
|
import logging
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
# Gets the instance of the logger.
|
|
|
|
logSys = logging.getLogger("fail2ban.filter")
|
|
|
|
|
|
|
|
class FailManager:
|
|
|
|
|
|
|
|
def __init__(self):
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock = Lock()
|
|
|
|
self.__failList = dict()
|
|
|
|
self.__maxRetry = 3
|
|
|
|
self.__maxTime = 600
|
|
|
|
self.__failTotal = 0
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def setFailTotal(self, value):
|
2007-02-25 23:53:22 +00:00
|
|
|
try:
|
|
|
|
self.__lock.acquire()
|
|
|
|
self.__failTotal = value
|
|
|
|
finally:
|
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def getFailTotal(self):
|
2006-09-17 22:02:22 +00:00
|
|
|
try:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.acquire()
|
|
|
|
return self.__failTotal
|
2006-09-17 22:02:22 +00:00
|
|
|
finally:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def setMaxRetry(self, value):
|
2007-02-25 23:53:22 +00:00
|
|
|
try:
|
|
|
|
self.__lock.acquire()
|
|
|
|
self.__maxRetry = value
|
|
|
|
finally:
|
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def getMaxRetry(self):
|
2006-09-17 22:02:22 +00:00
|
|
|
try:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.acquire()
|
|
|
|
return self.__maxRetry
|
2006-09-17 22:02:22 +00:00
|
|
|
finally:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def setMaxTime(self, value):
|
2007-02-25 23:53:22 +00:00
|
|
|
try:
|
|
|
|
self.__lock.acquire()
|
|
|
|
self.__maxTime = value
|
|
|
|
finally:
|
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def getMaxTime(self):
|
2006-09-17 22:02:22 +00:00
|
|
|
try:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.acquire()
|
|
|
|
return self.__maxTime
|
2006-09-17 22:02:22 +00:00
|
|
|
finally:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def addFailure(self, ticket):
|
2007-02-25 23:53:22 +00:00
|
|
|
try:
|
|
|
|
self.__lock.acquire()
|
|
|
|
ip = ticket.getIP()
|
|
|
|
unixTime = ticket.getTime()
|
|
|
|
if self.__failList.has_key(ip):
|
|
|
|
fData = self.__failList[ip]
|
|
|
|
fData.inc()
|
|
|
|
fData.setLastTime(unixTime)
|
|
|
|
else:
|
|
|
|
fData = FailData()
|
|
|
|
fData.inc()
|
|
|
|
fData.setLastTime(unixTime)
|
|
|
|
self.__failList[ip] = fData
|
|
|
|
self.__failTotal += 1
|
|
|
|
finally:
|
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def size(self):
|
2006-09-17 22:02:22 +00:00
|
|
|
try:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.acquire()
|
|
|
|
return len(self.__failList)
|
2006-09-17 22:02:22 +00:00
|
|
|
finally:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def cleanup(self, time):
|
2007-02-25 23:53:22 +00:00
|
|
|
try:
|
|
|
|
self.__lock.acquire()
|
|
|
|
tmp = self.__failList.copy()
|
|
|
|
for item in tmp:
|
|
|
|
if tmp[item].getLastTime() < time - self.__maxTime:
|
|
|
|
self.__delFailure(item)
|
|
|
|
finally:
|
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
2006-09-17 22:02:22 +00:00
|
|
|
def __delFailure(self, ip):
|
2006-09-19 20:38:32 +00:00
|
|
|
if self.__failList.has_key(ip):
|
|
|
|
del self.__failList[ip]
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
def toBan(self):
|
2006-09-17 22:02:22 +00:00
|
|
|
try:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.acquire()
|
|
|
|
for ip in self.__failList:
|
|
|
|
data = self.__failList[ip]
|
|
|
|
if data.getRetry() >= self.__maxRetry:
|
2006-09-17 22:31:55 +00:00
|
|
|
self.__delFailure(ip)
|
2006-09-17 22:02:22 +00:00
|
|
|
# Create a FailTicket from BanData
|
|
|
|
failTicket = FailTicket(ip, data.getLastTime())
|
|
|
|
failTicket.setAttempt(data.getRetry())
|
|
|
|
return failTicket
|
|
|
|
raise FailManagerEmpty
|
|
|
|
finally:
|
2006-09-19 20:38:32 +00:00
|
|
|
self.__lock.release()
|
2006-06-26 20:05:00 +00:00
|
|
|
|
|
|
|
class FailManagerEmpty(Exception):
|
|
|
|
pass
|