#!/usr/local/bin/php
<?
// °³¿ä
// secure log ¸¦ ºÐ¼®Çؼ sshd·Î ºÒ¹ýÀûÀÎ Á¢¼ÓÀ» ½ÃµµÇÏ´Â IP¸¦ /etc/hosts.deny¿¡ µî·ÏÇÏ´Â ÀÛ¾÷À» ÇÑ´Ù.
// Log Example : Jun 5 07:49:18 p1 sshd[1110]: Failed password for root from 211.114.190.196 port 52944 ssh2
// ÃßÃâ ¸í·É¾î : grep "Jun 7 09" secure | grep "sshd" | grep "Failed password" | awk -F "from" '{print $2}' | awk '{print $1}'
// ÁöÁ¤µÈ ÀԷ°ªÀ» ÀÔ·ÂÇÏÁö ¾ÊÀ¸¸é ½ÇÇàÇÏÁö ¾Ê´Â´Ù.
if($argc > 1)
{
$RECEIVE_EMAIL = "¼ö½Å ¸ÞÀÏÁÖ¼Ò";
$Hostname = trim(exec("hostname"));
$Date = date("Y-m-d H:i:s");
// 10ºÐÀü ºÐÀ» ±¸ÇÑ´Ù.
$TenAgo = substr(date("i",mktime (date("H"), date("i")-10, 0, date("m"), date("d"), date("Y"))),0,1);
if(!file_exists("/service/log_temp"))
{
exec("mkdir -p /service/log_temp");
}
if(!file_exists("/service/log_temp/secure_analysis.log"))
{
exec("touch /service/log_temp/secure_analysis.log");
}
// ³¯Â¥¿¡ µû¶ó¼ °Ë»ö¾îÀÇ °ø¹é󸮰¡ Ʋ¸° °ü°è·Î ... =,.=;
$DayLength = strlen(date("j"));
if($DayLength == 2)
{
$now = date("M j H:");
}
else
{
$now = date("M j H:");
}
if($argv[1] == "sshd")
{
exec("grep \"$now$TenAgo\" /var/log/secure | grep \"sshd\" | grep \"Failed password\" | awk -F \"from\" '{print \$2}' | awk '{print \$1}' > /service/log_temp/secure_log_".$argv[1]);
}
$Fail_IP_File = file("/service/log_temp/secure_log_".$argv[1]);
for($i=0; $i < count($Fail_IP_File); $i++)
{
$Fail_IP_File[$i] = trim($Fail_IP_File[$i]);
}
$Fail_Statistics = array_count_values($Fail_IP_File);
exec("echo \"\" > /service/log_temp/DenyIP.list_".$argv[1]);
while (list ($Ip, $Count) = each ($Fail_Statistics))
{
// ¿©±âÀÇ 20À» Á¶Á¤ÇÏ¿© µî·ÏÀ» Á¶ÀýÇÒ ¼ö ÀÖ´Ù.
if($Count > 20)
{
$Now_Time = date("Y³â m¿ù dÀÏ H½Ã iºÐ sÃÊ");
exec("echo \"#Regist $Now_Time\" >> /etc/hosts.deny");
exec("echo \"ALL : $Ip\" >> /etc/hosts.deny");
$Restart_Xinetd = 1;
exec("echo \"$Now_Time | $Ip | $Count ȸ\" >> /service/log_temp/DenyIP.list_".$argv[1]);
}
exec("echo \"$Date\t$Ip\t$Count\" >> /service/log_temp/secure_analysis.log");
}
if($Restart_Xinetd)
{
exec("killall -HUP xinetd");
exec("cat \"/service/log_temp/DenyIP.list_".$argv[1]."\" | mail -s \"$Hostname Deny IP List - $Date \" $RECEIVE_EMAIL");
}
}
else
{
echo("Missing Argument... Confirm Execute ...\n");
}
?>