mirror of https://github.com/fail2ban/fail2ban
- Initial import
git-svn-id: https://fail2ban.svn.sourceforge.net/svnroot/fail2ban/trunk@31 a942ae1a-1317-0410-a47c-b1dcaea8d6050.6
parent
ded1b1492b
commit
052f35eccb
|
@ -0,0 +1,67 @@
|
|||
# This file is part of Fail2Ban.
|
||||
#
|
||||
# Fail2Ban is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation; either version 2 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# Fail2Ban is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with Fail2Ban; if not, write to the Free Software
|
||||
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||
|
||||
# Author: Cyril Jaquier
|
||||
#
|
||||
# $Revision$
|
||||
|
||||
__author__ = "Cyril Jaquier"
|
||||
__version__ = "$Revision$"
|
||||
__date__ = "$Date$"
|
||||
__copyright__ = "Copyright (c) 2004 Cyril Jaquier"
|
||||
__license__ = "GPL"
|
||||
|
||||
import time, re
|
||||
|
||||
class Parser:
|
||||
""" This class is the main log parser class. It should be inherited
|
||||
by all the service specific classes.
|
||||
"""
|
||||
|
||||
def getLogMatch(self, pattern, line):
|
||||
""" Returns a match if pattern is found in line.
|
||||
"""
|
||||
return re.search(pattern, line)
|
||||
|
||||
def getLogIPv4(self, line):
|
||||
""" Returns IP if one is found in line. Match IPv4 string.
|
||||
"""
|
||||
matchIP = re.search("(?:\d{1,3}\.){3}\d{1,3}", line)
|
||||
if matchIP:
|
||||
return matchIP.group()
|
||||
else:
|
||||
return None
|
||||
|
||||
def getLogIP(self, line):
|
||||
""" Returns IP if one is found in line.
|
||||
"""
|
||||
return self.getLogIPv4(line)
|
||||
|
||||
def getLogTimeStandard(self, line):
|
||||
""" Returns the log time of line using a standard log format.
|
||||
|
||||
Format: Oct 14 11:47:08
|
||||
"""
|
||||
date = list(time.strptime(line[0:15], "%b %d %H:%M:%S"))
|
||||
date[0] = time.gmtime()[0]
|
||||
unixTime = time.mktime(date)
|
||||
return unixTime
|
||||
|
||||
def getLogTime(self, line):
|
||||
""" Returns the log time of line.
|
||||
"""
|
||||
return self.getLogTimeStandard(line)
|
||||
|
|
@ -0,0 +1,55 @@
|
|||
# This file is part of Fail2Ban.
|
||||
#
|
||||
# Fail2Ban is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation; either version 2 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# Fail2Ban is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with Fail2Ban; if not, write to the Free Software
|
||||
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||
|
||||
# Author: Cyril Jaquier
|
||||
#
|
||||
# $Revision$
|
||||
|
||||
__author__ = "Cyril Jaquier"
|
||||
__version__ = "$Revision$"
|
||||
__date__ = "$Date$"
|
||||
__copyright__ = "Copyright (c) 2004 Cyril Jaquier"
|
||||
__license__ = "GPL"
|
||||
|
||||
from parser import Parser
|
||||
|
||||
class Sshd(Parser):
|
||||
""" OpenSSH daemon log parser. Contains specific code for sshd.
|
||||
"""
|
||||
|
||||
_instance = None
|
||||
# This is the pattern to look for.
|
||||
pattern = "Failed password|Illegal user"
|
||||
|
||||
def getInstance():
|
||||
""" We use a singleton.
|
||||
"""
|
||||
if not Sshd._instance:
|
||||
Sshd._instance = Sshd()
|
||||
return Sshd._instance
|
||||
|
||||
getInstance = staticmethod(getInstance)
|
||||
|
||||
def parseLogLine(self, line):
|
||||
""" Matches sshd bad login attempt. Returns the IP and the
|
||||
log time.
|
||||
"""
|
||||
if self.getLogMatch(self.pattern, line):
|
||||
matchIP = self.getLogIP(line)
|
||||
if matchIP:
|
||||
return [matchIP, self.getLogTime(line)]
|
||||
else:
|
||||
return False
|
Loading…
Reference in New Issue