- Initial import

git-svn-id: https://fail2ban.svn.sourceforge.net/svnroot/fail2ban/trunk@31 a942ae1a-1317-0410-a47c-b1dcaea8d605
0.6
Cyril Jaquier 2004-10-14 10:38:22 +00:00
parent ded1b1492b
commit 052f35eccb
2 changed files with 122 additions and 0 deletions

67
logreader/parser.py Normal file
View File

@ -0,0 +1,67 @@
# This file is part of Fail2Ban.
#
# Fail2Ban is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# Fail2Ban is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with Fail2Ban; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
# Author: Cyril Jaquier
#
# $Revision$
__author__ = "Cyril Jaquier"
__version__ = "$Revision$"
__date__ = "$Date$"
__copyright__ = "Copyright (c) 2004 Cyril Jaquier"
__license__ = "GPL"
import time, re
class Parser:
""" This class is the main log parser class. It should be inherited
by all the service specific classes.
"""
def getLogMatch(self, pattern, line):
""" Returns a match if pattern is found in line.
"""
return re.search(pattern, line)
def getLogIPv4(self, line):
""" Returns IP if one is found in line. Match IPv4 string.
"""
matchIP = re.search("(?:\d{1,3}\.){3}\d{1,3}", line)
if matchIP:
return matchIP.group()
else:
return None
def getLogIP(self, line):
""" Returns IP if one is found in line.
"""
return self.getLogIPv4(line)
def getLogTimeStandard(self, line):
""" Returns the log time of line using a standard log format.
Format: Oct 14 11:47:08
"""
date = list(time.strptime(line[0:15], "%b %d %H:%M:%S"))
date[0] = time.gmtime()[0]
unixTime = time.mktime(date)
return unixTime
def getLogTime(self, line):
""" Returns the log time of line.
"""
return self.getLogTimeStandard(line)

55
logreader/sshd.py Normal file
View File

@ -0,0 +1,55 @@
# This file is part of Fail2Ban.
#
# Fail2Ban is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# Fail2Ban is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with Fail2Ban; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
# Author: Cyril Jaquier
#
# $Revision$
__author__ = "Cyril Jaquier"
__version__ = "$Revision$"
__date__ = "$Date$"
__copyright__ = "Copyright (c) 2004 Cyril Jaquier"
__license__ = "GPL"
from parser import Parser
class Sshd(Parser):
""" OpenSSH daemon log parser. Contains specific code for sshd.
"""
_instance = None
# This is the pattern to look for.
pattern = "Failed password|Illegal user"
def getInstance():
""" We use a singleton.
"""
if not Sshd._instance:
Sshd._instance = Sshd()
return Sshd._instance
getInstance = staticmethod(getInstance)
def parseLogLine(self, line):
""" Matches sshd bad login attempt. Returns the IP and the
log time.
"""
if self.getLogMatch(self.pattern, line):
matchIP = self.getLogIP(line)
if matchIP:
return [matchIP, self.getLogTime(line)]
else:
return False