fail2ban_init.c 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333
  1. /*
  2. ============================================================================
  3. Name : generate_paging_conf.sh
  4. Author : ssc
  5. Version : v1.0
  6. Copyright : ZYCOO copyright
  7. Description : Generate paging info from mysql to paging conf file
  8. ============================================================================
  9. */
  10. #include <stdio.h>
  11. #include <stdlib.h>
  12. #include <string.h>
  13. #include <errno.h>
  14. #include <assert.h>
  15. #include <time.h>
  16. #include <ctype.h>
  17. #include <mysql/mysql.h>
  18. MYSQL *g_conn; // mysql 连接
  19. MYSQL_RES *g_res; // mysql group记录集
  20. MYSQL_ROW g_row; // 字符串数组,mysql 记录行
  21. MYSQL_RES *d_res; // mysql device记录集
  22. MYSQL_ROW d_row; // 字符串数组,mysql 记录行
  23. #define NORMAL_SIZE 256
  24. #define MAX_SIZE 2048
  25. #define MIDLE_SIZE 512
  26. #define MINI_SIZE 64
  27. #define CONFIG_FILE "/etc/fail2ban/jail.conf"
  28. #define KEYVALLEN 100
  29. #define VERSION "V1.0.1"
  30. #define FAIL2BAN_BASIC_SQL "select name,enable,max_retry,find_time,ban_time from t_pbx_fail2ban_basic"
  31. #define FAIL2BAN_SIP_IGNORED_SQL "select ip,netmask_length from t_pbx_fail2ban_ignored where protocol_sip='1' and enable='1'"
  32. #define FAIL2BAN_SSH_IGNORED_SQL "select ip,netmask_length from t_pbx_fail2ban_ignored where protocol_ssh='1' and enable='1'"
  33. char g_host_name[MINI_SIZE];
  34. char g_user_name[MINI_SIZE];
  35. char g_password[MINI_SIZE];
  36. char g_db_name[MINI_SIZE];
  37. const unsigned int g_db_port = 3306;
  38. //读取配置文件函数----功能:删除左边空格
  39. char *l_trim(char *szOutput, const char *szInput)
  40. {
  41. assert(szInput != NULL);
  42. assert(szOutput != NULL);
  43. assert(szOutput != szInput);
  44. for (NULL; *szInput != '\0' && isspace(*szInput); ++szInput)
  45. {
  46. ;
  47. }
  48. return strcpy(szOutput, szInput);
  49. }
  50. // 删除右边的空格
  51. char *r_trim(char *szOutput, const char *szInput)
  52. {
  53. char *p = NULL;
  54. assert(szInput != NULL);
  55. assert(szOutput != NULL);
  56. assert(szOutput != szInput);
  57. strcpy(szOutput, szInput);
  58. for(p = szOutput + strlen(szOutput) - 1; p >= szOutput && isspace(*p); --p)
  59. {
  60. ;
  61. }
  62. *(++p) = '\0';
  63. return szOutput;
  64. }
  65. // 删除两边的空格
  66. char *a_trim(char *szOutput, const char *szInput)
  67. {
  68. char *p = NULL;
  69. assert(szInput != NULL);
  70. assert(szOutput != NULL);
  71. l_trim(szOutput, szInput);
  72. for (p = szOutput + strlen(szOutput) - 1; p >= szOutput && isspace(*p); --p)
  73. {
  74. ;
  75. }
  76. *(++p) = '\0';
  77. return szOutput;
  78. }
  79. //main函数接口 参数1:配置文件路径 参数2:配置文件的那一部分,如general 参数3:键名 参数4:键值
  80. int GetProfileString(char *profile, char *AppName, char *KeyName, char *KeyVal )
  81. {
  82. char appname[32], keyname[32];
  83. char *buf, *c;
  84. char buf_i[KEYVALLEN], buf_o[KEYVALLEN];
  85. FILE *fp;
  86. int found = 0; /* 1 AppName 2 KeyName */
  87. if( (fp = fopen( profile, "r" )) == NULL )
  88. {
  89. printf( "openfile [%s] error [%s]\n", profile, strerror(errno) );
  90. return(-1);
  91. }
  92. fseek( fp, 0, SEEK_SET );
  93. memset( appname, 0, sizeof(appname) );
  94. sprintf( appname, "[%s]", AppName );
  95. while( !feof(fp) && fgets( buf_i, KEYVALLEN, fp ) != NULL )
  96. {
  97. l_trim(buf_o, buf_i);
  98. if( strlen(buf_o) <= 0 )
  99. continue;
  100. buf = NULL;
  101. buf = buf_o;
  102. if( found == 0 )
  103. {
  104. if( buf[0] != '[' )
  105. {
  106. continue;
  107. }
  108. else if ( strncmp(buf, appname, strlen(appname)) == 0 )
  109. {
  110. found = 1;
  111. continue;
  112. }
  113. }
  114. else if( found == 1 )
  115. {
  116. if( buf[0] == '#' )
  117. {
  118. continue;
  119. }
  120. else if ( buf[0] == '[' )
  121. {
  122. break;
  123. }
  124. else
  125. {
  126. if( (c = (char *)strchr(buf, '=')) == NULL )
  127. continue;
  128. memset( keyname, 0, sizeof(keyname) );
  129. sscanf( buf, "%[^=|^ |^\t]", keyname );
  130. if( strcmp(keyname, KeyName) == 0 )
  131. {
  132. sscanf( ++c, "%[^\n]", KeyVal );
  133. char *KeyVal_o = (char *)malloc(strlen(KeyVal) + 1);
  134. if(KeyVal_o != NULL)
  135. {
  136. memset(KeyVal_o, 0, sizeof(KeyVal_o));
  137. a_trim(KeyVal_o, KeyVal);
  138. if(KeyVal_o && strlen(KeyVal_o) > 0)
  139. strcpy(KeyVal, KeyVal_o);
  140. free(KeyVal_o);
  141. KeyVal_o = NULL;
  142. }
  143. found = 2;
  144. break;
  145. }
  146. else
  147. {
  148. continue;
  149. }
  150. }
  151. }
  152. }
  153. fclose( fp );
  154. if( found == 2 )
  155. return(0);
  156. else
  157. return(-1);
  158. }
  159. char * mytime(){
  160. time_t my_time;
  161. time(&my_time);
  162. char *time_string = ctime(&my_time);
  163. if (time_string[strlen(time_string) - 1] == '\n')
  164. {
  165. time_string[strlen(time_string) - 1] = '\0';
  166. }
  167. return time_string;
  168. }
  169. void print_mysql_error(const char *msg) { // 打印最后一次错误
  170. if (msg)
  171. printf("%s: %s\n", msg, mysql_error(g_conn));
  172. else
  173. puts(mysql_error(g_conn));
  174. }
  175. int executesql(const char * sql) {
  176. /*query the database according the sql*/
  177. if (mysql_real_query(g_conn, sql, strlen(sql))) // 如果失败
  178. return -1; // 表示失败
  179. return 0; // 成功执行
  180. }
  181. int init_mysql() { // 初始化连接
  182. // init the database connection
  183. g_conn = mysql_init(NULL);
  184. /* connect the database */
  185. if(!mysql_real_connect(g_conn, g_host_name, g_user_name, g_password, g_db_name, g_db_port, NULL, 0)) // 如果失败
  186. return -1;
  187. // 是否连接已经可用
  188. if (executesql("set names utf8")) // 如果失败
  189. return -1;
  190. return 0; // 返回成功
  191. }
  192. int main(int argc, char **argv) {
  193. char in[8] = {0};
  194. char tmp[MIDLE_SIZE] = {0};
  195. char ignored[MIDLE_SIZE] = {0};
  196. char cmd[MIDLE_SIZE] = {0};
  197. strcpy(g_host_name,getenv("MYSQL"));
  198. strcpy(g_user_name,getenv("MYSQL_USER"));
  199. strcpy(g_password,getenv("MYSQL_PASSWORD"));
  200. strcpy(g_db_name,getenv("MYSQL_DATABASE"));
  201. if (init_mysql()){
  202. print_mysql_error(NULL);
  203. exit(1);
  204. }
  205. if (executesql(FAIL2BAN_BASIC_SQL)){
  206. print_mysql_error(NULL);
  207. exit(1);
  208. }
  209. g_res = mysql_store_result(g_conn); // 从服务器传送结果集至本地,mysql_use_result直接使用服务器上的记录集
  210. FILE *conf_fail2ban_fp = fopen(CONFIG_FILE, "w+");
  211. if (conf_fail2ban_fp == NULL){
  212. perror("Open paging conf file Error: ");
  213. exit(1);
  214. }
  215. fprintf(conf_fail2ban_fp, "[DEFAULT]\n\
  216. ignoreip = 127.0.0.1/32\n\
  217. bantime = 3600\n\
  218. maxretry = 3\n\
  219. backend = auto\n\
  220. banaction = iptables-multiport\n\
  221. mta = mail\n\
  222. protocol = tcp\n\
  223. chain = INPUT\n\
  224. action_ = %%(banaction)s[name=%%(__name__)s, port=\"%%(port)s\", protocol=\"%%(protocol)s\", chain=\"%%(chain)s\"]\n\
  225. action_mw = %%(banaction)s[name=%%(__name__)s, port=\"%%(port)s\", protocol=\"%%(protocol)s\", chain=\"%%(chain)s\"]\n\
  226. action_mwl = %%(banaction)s[name=%%(__name__)s, port=\"%%(port)s\", protocol=\"%%(protocol)s\", chain=\"%%(chain)s\"]\n\
  227. action = %%(action_)s\n\n\
  228. "\
  229. );
  230. while ((g_row=mysql_fetch_row(g_res)))
  231. { // 打印结果集
  232. if (g_row[0] == NULL || g_row[1] == NULL || g_row[2] == NULL || g_row[3] == NULL || g_row[4] == NULL)
  233. {
  234. printf("some feild is empty!\n");
  235. continue;
  236. }
  237. if(strcmp((const char *)g_row[1], "1") == 0)
  238. strcpy(in, "true");
  239. else
  240. strcpy(in, "false");
  241. if(strcmp((const char*)g_row[0], "sip") == 0){
  242. if (executesql(FAIL2BAN_SIP_IGNORED_SQL)){
  243. print_mysql_error(NULL);
  244. exit(1);
  245. }
  246. d_res = mysql_store_result(g_conn);
  247. memset(ignored,0,sizeof(ignored));
  248. while(d_row = mysql_fetch_row(d_res))
  249. {
  250. strcat(ignored,(char *)d_row[0]);
  251. strcat(ignored,"/");
  252. strcat(ignored,(char *)d_row[1]);
  253. strcat(ignored," ");
  254. }
  255. fprintf(conf_fail2ban_fp, "[sip-iptables]\n\
  256. enabled = %s\n\
  257. ignoreip = 127.0.0.1/32 %s \n\
  258. filter = sip\n\
  259. action = iptables-allports[name=VOIP, protocol=all]\n\
  260. logpath = /var/log/asterisk/messages\n\
  261. maxretry = %s\n\
  262. findtime = %s\n\
  263. bantime = %s\n\n\
  264. ",\
  265. in, ignored, g_row[2], g_row[3], g_row[4]
  266. );
  267. mysql_free_result(d_res);
  268. }
  269. else if(strcmp((const char*)g_row[0], "ssh") == 0)
  270. {
  271. if (executesql(FAIL2BAN_SSH_IGNORED_SQL)){
  272. print_mysql_error(NULL);
  273. exit(1);
  274. }
  275. d_res = mysql_store_result(g_conn);
  276. memset(ignored,0,sizeof(ignored));
  277. while(d_row = mysql_fetch_row(d_res))
  278. {
  279. strcat(ignored,(char *)d_row[0]);
  280. strcat(ignored,"/");
  281. strcat(ignored,(char *)d_row[1]);
  282. strcat(ignored," ");
  283. }
  284. fprintf(conf_fail2ban_fp, "[SSH]\n\
  285. enabled = %s\n\
  286. ignoreip = 127.0.0.1/32 %s \n\
  287. port = 22\n\
  288. filter = sshd\n\
  289. logpath = /init/logs/auth.log\n\
  290. maxretry = %s\n\
  291. findtime = %s\n\
  292. bantime = %s\n\n\
  293. ",\
  294. in, ignored, g_row[2], g_row[3], g_row[4]
  295. );
  296. mysql_free_result(d_res);
  297. }
  298. }
  299. fclose(conf_fail2ban_fp);
  300. mysql_free_result(g_res); // 释放结果集
  301. mysql_close(g_conn); // 关闭链接
  302. }