Line 1... |
Line 1... |
1 |
#!/bin/bash
|
1 |
#!/bin/bash
|
2 |
# $Id: alcasar-activity_report.sh 2644 2018-10-29 14:09:33Z lucas.echard $
|
2 |
# $Id: alcasar-activity_report.sh 2688 2019-01-18 23:15:49Z lucas.echard $
|
3 |
#
|
3 |
#
|
4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
5 |
# We read configuration files and logs to create cool charts.
|
5 |
# We read configuration files and logs to create cool charts.
|
6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
7 |
|
7 |
|
Line 91... |
Line 91... |
91 |
echo "Create information about system and ALCASAR"
|
91 |
echo "Create information about system and ALCASAR"
|
92 |
#contain every information about ALCASAR configuration, system and last update
|
92 |
#contain every information about ALCASAR configuration, system and last update
|
93 |
|
93 |
|
94 |
cat $MODEL_TABINFO | while read LINE_HTML
|
94 |
cat $MODEL_TABINFO | while read LINE_HTML
|
95 |
do
|
95 |
do
|
- |
|
96 |
if [ "$(echo $LINE_HTML | grep 'XXORGXX' | wc -l)" -eq 1 ]
|
- |
|
97 |
then
|
- |
|
98 |
VALUE=$(grep ^ORGANISM= $CONF_FILE | cut -d'=' -f2-)
|
- |
|
99 |
echo ${LINE_HTML/XXORGXX/$VALUE} >> $HTML_REPORT
|
96 |
|
100 |
|
97 |
if [ $(echo $LINE_HTML | grep 'XXORGXX' | wc -l) -eq 1 ]
|
- |
|
98 |
then
|
- |
|
99 |
VALUE=$(grep ^ORGANISM= $CONF_FILE | cut -d'=' -f2-)
|
- |
|
100 |
echo ${LINE_HTML/XXORGXX/$VALUE} >> $HTML_REPORT
|
- |
|
101 |
|
- |
|
102 |
elif [ $(echo $LINE_HTML | grep 'XXINSTALLXX' | wc -l) -eq 1 ]
|
101 |
elif [ "$(echo $LINE_HTML | grep 'XXINSTALLXX' | wc -l)" -eq 1 ]
|
103 |
then
|
- |
|
104 |
VALUE=$(grep ^INSTALL_DATE= $CONF_FILE | cut -d'=' -f2)
|
- |
|
105 |
echo ${LINE_HTML/XXINSTALLXX/$VALUE} >> $HTML_REPORT
|
- |
|
106 |
|
- |
|
107 |
elif [ $(echo $LINE_HTML | grep 'XXAVERSIONXX' | wc -l) -eq 1 ]
|
- |
|
108 |
then
|
- |
|
109 |
VALUE=$(grep ^VERSION= $CONF_FILE | cut -d'=' -f2)
|
- |
|
110 |
echo ${LINE_HTML/XXAVERSIONXX/$VALUE} >> $HTML_REPORT
|
- |
|
111 |
|
- |
|
112 |
elif [ $(echo $LINE_HTML | grep 'XXIP_PUBLICXX' | wc -l) -eq 1 ]
|
- |
|
113 |
then
|
- |
|
114 |
VALUE=$(grep ^PUBLIC_IP= $CONF_FILE | cut -d'=' -f2)
|
- |
|
115 |
echo ${LINE_HTML/XXIP_PUBLICXX/$VALUE} >> $HTML_REPORT
|
- |
|
116 |
|
- |
|
117 |
elif [ $(echo $LINE_HTML | grep 'XXIP_PRIVEXX' | wc -l) -eq 1 ]
|
- |
|
118 |
then
|
- |
|
119 |
VALUE=$(grep ^PRIVATE_IP= $CONF_FILE | cut -d'=' -f2)
|
- |
|
120 |
echo ${LINE_HTML/XXIP_PRIVEXX/$VALUE} >> $HTML_REPORT
|
- |
|
121 |
|
- |
|
122 |
elif [ $(echo $LINE_HTML | grep 'XXGWXX' | wc -l) -eq 1 ]
|
- |
|
123 |
then
|
- |
|
124 |
VALUE=$(grep ^GW= $CONF_FILE | cut -d'=' -f2)
|
- |
|
125 |
echo ${LINE_HTML/XXGWXX/$VALUE} >> $HTML_REPORT
|
- |
|
126 |
|
- |
|
127 |
elif [ $(echo $LINE_HTML | grep 'XXDNS1XX' | wc -l) -eq 1 ]
|
- |
|
128 |
then
|
- |
|
129 |
VALUE=$(grep ^DNS1= $CONF_FILE | cut -d'=' -f2)
|
- |
|
130 |
echo ${LINE_HTML/XXDNS1XX/$VALUE} >> $HTML_REPORT
|
- |
|
131 |
|
- |
|
132 |
elif [ $(echo $LINE_HTML | grep 'XXDNS2XX' | wc -l) -eq 1 ]
|
- |
|
133 |
then
|
- |
|
134 |
VALUE=$(grep ^DNS2= $CONF_FILE | cut -d'=' -f2)
|
- |
|
135 |
echo ${LINE_HTML/XXDNS2XX/$VALUE} >> $HTML_REPORT
|
- |
|
136 |
|
- |
|
137 |
elif [ $(echo $LINE_HTML | grep 'XXHOSTXX' | wc -l) -eq 1 ]
|
- |
|
138 |
then
|
- |
|
139 |
VALUE=$(hostname)
|
- |
|
140 |
echo ${LINE_HTML/XXHOSTXX/$VALUE} >> $HTML_REPORT
|
- |
|
141 |
|
- |
|
142 |
elif [ $(echo $LINE_HTML | grep 'XXOS_VERSIONXX' | wc -l) -eq 1 ]
|
- |
|
143 |
then
|
- |
|
144 |
VALUE=$( echo $(uname -r) [ $(uname -m) ] )
|
- |
|
145 |
echo ${LINE_HTML/XXOS_VERSIONXX/$VALUE} >> $HTML_REPORT
|
- |
|
146 |
|
- |
|
147 |
elif [ $(echo $LINE_HTML | grep 'XXREBOOTXX' | wc -l) -eq 1 ]
|
- |
|
148 |
then
|
- |
|
149 |
VALUE=$(echo $(who -b | cut -d' ' -f12-))
|
- |
|
150 |
echo ${LINE_HTML/XXREBOOTXX/$VALUE} >> $HTML_REPORT
|
- |
|
151 |
|
- |
|
152 |
elif [ $(echo $LINE_HTML | grep 'XXMAJCLAMAVXX' | wc -l) -eq 1 ]
|
- |
|
153 |
then
|
- |
|
154 |
VALUE=$(date -d @$(rpm -qa --queryformat "%{installtime} %{name}\n" | grep -E "clamav-db" | cut -d' ' -f1 ) "+%Y-%m-%d %H:%M:%S")
|
- |
|
155 |
echo ${LINE_HTML/XXMAJCLAMAVXX/$VALUE} >> $HTML_REPORT
|
- |
|
156 |
|
- |
|
157 |
elif [ $(echo $LINE_HTML | grep 'XXMAJBLXX' | wc -l) -eq 1 ]
|
- |
|
158 |
then
|
- |
|
159 |
VALUE=$(cat /etc/e2guardian/lists/blacklists/README | grep 'Last version' | cut -d' ' -f4-6)
|
- |
|
160 |
echo ${LINE_HTML/XXMAJBLXX/$VALUE} >> $HTML_REPORT
|
- |
|
161 |
|
- |
|
162 |
elif [ $(echo $LINE_HTML | grep 'XXRPMXX' | wc -l) -eq 1 ]
|
- |
|
163 |
then
|
- |
|
164 |
#show every ALCASAR RPM updated since X day ago
|
- |
|
165 |
#get timestamp of X day ago. Then we get every packets chich have been updated since this date.
|
- |
|
166 |
if [ $(rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | wc -l) -gt 1 ]
|
- |
|
167 |
then
|
102 |
then
|
- |
|
103 |
VALUE=$(grep ^INSTALL_DATE= $CONF_FILE | cut -d'=' -f2)
|
- |
|
104 |
echo ${LINE_HTML/XXINSTALLXX/$VALUE} >> $HTML_REPORT
|
- |
|
105 |
|
- |
|
106 |
elif [ "$(echo $LINE_HTML | grep 'XXAVERSIONXX' | wc -l)" -eq 1 ]
|
- |
|
107 |
then
|
- |
|
108 |
VALUE=$(grep ^VERSION= $CONF_FILE | cut -d'=' -f2)
|
- |
|
109 |
echo ${LINE_HTML/XXAVERSIONXX/$VALUE} >> $HTML_REPORT
|
- |
|
110 |
|
- |
|
111 |
elif [ "$(echo $LINE_HTML | grep 'XXIP_PUBLICXX' | wc -l)" -eq 1 ]
|
- |
|
112 |
then
|
- |
|
113 |
VALUE=$(grep ^PUBLIC_IP= $CONF_FILE | cut -d'=' -f2)
|
- |
|
114 |
echo ${LINE_HTML/XXIP_PUBLICXX/$VALUE} >> $HTML_REPORT
|
- |
|
115 |
|
- |
|
116 |
elif [ "$(echo $LINE_HTML | grep 'XXIP_PRIVEXX' | wc -l)" -eq 1 ]
|
- |
|
117 |
then
|
- |
|
118 |
VALUE=$(grep ^PRIVATE_IP= $CONF_FILE | cut -d'=' -f2)
|
- |
|
119 |
echo ${LINE_HTML/XXIP_PRIVEXX/$VALUE} >> $HTML_REPORT
|
- |
|
120 |
|
- |
|
121 |
elif [ "$(echo $LINE_HTML | grep 'XXGWXX' | wc -l)" -eq 1 ]
|
- |
|
122 |
then
|
- |
|
123 |
VALUE=$(grep ^GW= $CONF_FILE | cut -d'=' -f2)
|
- |
|
124 |
echo ${LINE_HTML/XXGWXX/$VALUE} >> $HTML_REPORT
|
- |
|
125 |
|
- |
|
126 |
elif [ "$(echo $LINE_HTML | grep 'XXDNS1XX' | wc -l)" -eq 1 ]
|
- |
|
127 |
then
|
- |
|
128 |
VALUE=$(grep ^DNS1= $CONF_FILE | cut -d'=' -f2)
|
- |
|
129 |
echo ${LINE_HTML/XXDNS1XX/$VALUE} >> $HTML_REPORT
|
- |
|
130 |
|
- |
|
131 |
elif [ "$(echo $LINE_HTML | grep 'XXDNS2XX' | wc -l)" -eq 1 ]
|
- |
|
132 |
then
|
- |
|
133 |
VALUE=$(grep ^DNS2= $CONF_FILE | cut -d'=' -f2)
|
- |
|
134 |
echo ${LINE_HTML/XXDNS2XX/$VALUE} >> $HTML_REPORT
|
- |
|
135 |
|
- |
|
136 |
elif [ "$(echo $LINE_HTML | grep 'XXHOSTXX' | wc -l)" -eq 1 ]
|
- |
|
137 |
then
|
- |
|
138 |
VALUE=$(hostname)
|
- |
|
139 |
echo ${LINE_HTML/XXHOSTXX/$VALUE} >> $HTML_REPORT
|
- |
|
140 |
|
- |
|
141 |
elif [ "$(echo $LINE_HTML | grep 'XXOS_VERSIONXX' | wc -l)" -eq 1 ]
|
- |
|
142 |
then
|
- |
|
143 |
VALUE=$(echo "$(uname -r) [ $(uname -m) ]")
|
- |
|
144 |
echo ${LINE_HTML/XXOS_VERSIONXX/$VALUE} >> $HTML_REPORT
|
- |
|
145 |
|
- |
|
146 |
elif [ "$(echo $LINE_HTML | grep 'XXREBOOTXX' | wc -l)" -eq 1 ]
|
- |
|
147 |
then
|
- |
|
148 |
VALUE=$(who -b | cut -d' ' -f12-)
|
- |
|
149 |
echo ${LINE_HTML/XXREBOOTXX/$VALUE} >> $HTML_REPORT
|
- |
|
150 |
|
- |
|
151 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJCLAMAVXX' | wc -l)" -eq 1 ]
|
- |
|
152 |
then
|
- |
|
153 |
VALUE=$(date -d "@$(rpm -qa --queryformat "%{installtime} %{name}\n" | grep -E "clamav-db" | cut -d' ' -f1 )" "+%Y-%m-%d %H:%M:%S")
|
- |
|
154 |
echo ${LINE_HTML/XXMAJCLAMAVXX/$VALUE} >> $HTML_REPORT
|
- |
|
155 |
|
- |
|
156 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJBLXX' | wc -l)" -eq 1 ]
|
- |
|
157 |
then
|
- |
|
158 |
VALUE=$(cat /etc/e2guardian/lists/blacklists/README | grep 'Last version' | cut -d' ' -f4-6)
|
- |
|
159 |
echo ${LINE_HTML/XXMAJBLXX/$VALUE} >> $HTML_REPORT
|
- |
|
160 |
|
- |
|
161 |
elif [ "$(echo $LINE_HTML | grep 'XXRPMXX' | wc -l)" -eq 1 ]
|
- |
|
162 |
then
|
- |
|
163 |
#show every ALCASAR RPM updated since X day ago
|
- |
|
164 |
#get timestamp of X day ago. Then we get every packets chich have been updated since this date.
|
- |
|
165 |
if [ "$(rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | wc -l)" -gt 1 ]
|
- |
|
166 |
then
|
168 |
PACKAGE='php|lighttpd|iptables|dnsmasq|radius|tinyproxy|nfdump|e2guardian|clamav|ulogd|chilli|fail2ban|openssh|havp|ipt-netflow|wget'
|
167 |
PACKAGE='php|lighttpd|iptables|dnsmasq|unbound|radius|tinyproxy|nfdump|e2guardian|clamav|ulogd|chilli|fail2ban|openssh|havp|ipt-netflow|wget'
|
169 |
rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | while read RPM_ALCASAR
|
168 |
rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | while read RPM_ALCASAR
|
170 |
do
|
169 |
do
|
171 |
RPM_TIMESTAMP=$(echo $RPM_ALCASAR | cut -d' ' -f1)
|
170 |
RPM_TIMESTAMP=$(echo $RPM_ALCASAR | cut -d' ' -f1)
|
172 |
RPM_DATE=$(date -d @$(echo $RPM_TIMESTAMP) "+%Y-%m-%d %H:%M:%S")
|
171 |
RPM_DATE=$(date -d "@$(echo $RPM_TIMESTAMP)" "+%Y-%m-%d %H:%M:%S")
|
173 |
RPM_NAME=$(echo $RPM_ALCASAR | cut -d' ' -f2)
|
172 |
RPM_NAME=$(echo $RPM_ALCASAR | cut -d' ' -f2)
|
174 |
RPM_VERSION=$(echo $RPM_ALCASAR | cut -d' ' -f3)
|
173 |
RPM_VERSION=$(echo $RPM_ALCASAR | cut -d' ' -f3)
|
175 |
|
174 |
|
176 |
echo "<tr>" >> $HTML_REPORT
|
175 |
echo "<tr>" >> $HTML_REPORT
|
177 |
echo "<td>$RPM_NAME</td>" >> $HTML_REPORT
|
176 |
echo "<td>$RPM_NAME</td>" >> $HTML_REPORT
|
178 |
echo "<td>$RPM_DATE</td>" >> $HTML_REPORT
|
177 |
echo "<td>$RPM_DATE</td>" >> $HTML_REPORT
|
179 |
echo "<td>$RPM_VERSION</td>" >> $HTML_REPORT
|
178 |
echo "<td>$RPM_VERSION</td>" >> $HTML_REPORT
|
180 |
echo "</tr>" >> $HTML_REPORT
|
179 |
echo "</tr>" >> $HTML_REPORT
|
181 |
done
|
180 |
done
|
- |
|
181 |
else
|
- |
|
182 |
echo "<tr><td colspan=\"3\">Pas de RPM mis à jour cette semaine</td></tr>" >> $HTML_REPORT
|
- |
|
183 |
fi
|
182 |
else
|
184 |
else
|
183 |
echo "<tr><td colspan=\"3\">Pas de RPM mis à jour cette semaine</td></tr>" >> $HTML_REPORT
|
185 |
echo $LINE_HTML >> $HTML_REPORT
|
184 |
fi
|
186 |
fi
|
185 |
else
|
- |
|
186 |
echo $LINE_HTML >> $HTML_REPORT
|
- |
|
187 |
fi
|
- |
|
188 |
done
|
187 |
done
|
189 |
|
188 |
|
190 |
######################BL WEBSITE SINCE INSTALLATION######################
|
189 |
######################BL WEBSITE SINCE INSTALLATION######################
|
191 |
echo "Create BL website since the installation of ALCASAR"
|
190 |
echo "Create BL website since the installation of ALCASAR"
|
192 |
#find data
|
191 |
#find data
|
193 |
|
192 |
|
194 |
#decompress every logs
|
193 |
#decompress every logs
|
195 |
if [ $(ls -1 /var/log/dnsmasq/dnsmasq-blacklist.log.*.gz 2>/dev/null | wc -l) -ge 1 ]
|
194 |
if [ "$(ls -1 /var/log/unbound/unbound-blacklist.log.*.gz 2>/dev/null | wc -l)" -ge 1 ]
|
196 |
then
|
195 |
then
|
197 |
gunzip -d dnsmasq-blacklist.log.*.gz
|
196 |
gunzip -d unbound-blacklist.log.*.gz
|
198 |
fi
|
197 |
fi
|
199 |
|
198 |
|
200 |
#convert logs date in timestamp and find categories of blacklisted website
|
199 |
#convert logs date in timestamp and find categories of blacklisted website
|
- |
|
200 |
tmp_log=$(mktemp)
|
201 |
for FILE in $(ls -1 /var/log/dnsmasq/ | grep 'dnsmasq-blacklist.log')
|
201 |
for FILE in /var/log/unbound/unbound-blacklist.log*
|
202 |
do
|
202 |
do
|
- |
|
203 |
grep -E "info: [^ ]+ typetransparent $PRIVATE_IP" /var/log/unbound/unbound-blacklist.log > $tmp_log
|
203 |
while read LOG_BL
|
204 |
while read LOG_BL
|
204 |
do
|
205 |
do
|
205 |
if [ $(echo $LOG_BL | grep config | grep $PRIVATE_IP | wc -c) -ge 1 ]
|
- |
|
206 |
then
|
- |
|
207 |
#find the current blacklisted category
|
206 |
# find the current blacklisted category
|
208 |
website_bl=$(echo $LOG_BL | cut -d' ' -f6)
|
207 |
website_bl=$(echo $LOG_BL | cut -d' ' -f4)
|
209 |
|
- |
|
210 |
#we convert www.test.co.uk => test.co.uk to find the category of this website
|
- |
|
211 |
if [ $(grep -o '\.' <<< "$website_bl" | wc -l) -ge "2" ]
|
- |
|
212 |
then
|
- |
|
213 |
website_bl=$(echo $website_bl | cut -d'.' -f2-)
|
208 |
website_bl=${website_bl%?} # remove the last character
|
214 |
fi
|
- |
|
215 |
|
209 |
|
216 |
#get BL category
|
- |
|
217 |
categorie_bl=$(grep -R "$website_bl/" /usr/local/share/dnsmasq-bl-enabled/ | cut -d':' -f1 | cut -d'/' -f6 | cut -d' ' -f1)
|
210 |
#we convert www.test.co.uk => test.co.uk to find the category of this website
|
218 |
if [ $(echo $categorie_bl | wc -w) -gt 1 ]
|
211 |
if [ "$(grep -o '\.' <<< "$website_bl" | wc -l)" -ge "2" ]
|
219 |
then
|
212 |
then
|
220 |
categorie_bl=$(grep -R "/$website_bl/" /usr/local/share/dnsmasq-bl-enabled/ | cut -d':' -f1 | cut -d'/' -f6 | cut -d' ' -f1 | head -1)
|
- |
|
221 |
fi
|
- |
|
222 |
|
- |
|
223 |
#Calculate its timestamp
|
- |
|
224 |
Y=$(date -R | cut -d' ' -f4)
|
- |
|
225 |
M=$(echo $LOG_BL | cut -d' ' -f1)
|
- |
|
226 |
D=$(echo $LOG_BL | cut -d' ' -f2)
|
213 |
website_bl=$(echo $website_bl | cut -d'.' -f2-)
|
227 |
H=$(echo $LOG_BL | cut -d' ' -f3)
|
- |
|
228 |
CURRENT_TS=$(date -d "$M $D $Y $H" +"%s")
|
- |
|
229 |
echo "$CURRENT_TS:$categorie_bl:" >> $TMP_BL
|
- |
|
230 |
fi
|
214 |
fi
|
- |
|
215 |
|
- |
|
216 |
#get BL category
|
- |
|
217 |
categorie_bl=$(grep -Rl "$website_bl" /usr/local/share/unbound-bl-enabled/ | cut -d'/' -f6 | head -1)
|
231 |
|
218 |
|
- |
|
219 |
CURRENT_TS=$(echo $LOG_BL | cut -d '[' -f2 | cut -d ']' -f1)
|
- |
|
220 |
echo "$CURRENT_TS:$categorie_bl:" >> $TMP_BL
|
232 |
done < /var/log/dnsmasq/$FILE
|
221 |
done < $tmp_log
|
233 |
done
|
222 |
done
|
- |
|
223 |
rm $tmp_log
|
234 |
|
224 |
|
235 |
#if data exists, create this section in html document
|
225 |
#if data exists, create this section in html document
|
236 |
if [ -e $TMP_BL ]
|
226 |
if [ -e $TMP_BL ]
|
237 |
then
|
227 |
then
|
238 |
ENABLE_BL=1
|
228 |
ENABLE_BL=1
|
Line 242... |
Line 232... |
242 |
|
232 |
|
243 |
for TS in $(seq $C_TS -$STEP_TS $DATE_END)
|
233 |
for TS in $(seq $C_TS -$STEP_TS $DATE_END)
|
244 |
do
|
234 |
do
|
245 |
DATE_1=$TS
|
235 |
DATE_1=$TS
|
246 |
DATE_2=$((TS-$STEP_TS))
|
236 |
DATE_2=$((TS-$STEP_TS))
|
247 |
COUNT_BL_INSTALLATION=0
|
237 |
COUNT_BL_INSTALLATION=0
|
248 |
|
238 |
|
249 |
for LINE in $(cat $TMP_BL)
|
239 |
for LINE in $(cat $TMP_BL)
|
250 |
do
|
240 |
do
|
251 |
TS_FILE=$(echo $LINE | cut -d':' -f1)
|
241 |
TS_FILE=$(echo $LINE | cut -d':' -f1)
|
252 |
|
242 |
|
253 |
if [ "$TS_FILE" -le "$DATE_1" -a "$TS_FILE" -ge "$DATE_2" ]
|
243 |
if [ "$TS_FILE" -le "$DATE_1" ] && [ "$TS_FILE" -ge "$DATE_2" ]
|
254 |
then
|
244 |
then
|
255 |
COUNT_BL_INSTALLATION=$((COUNT_BL_INSTALLATION+1))
|
245 |
COUNT_BL_INSTALLATION=$((COUNT_BL_INSTALLATION+1))
|
256 |
|
- |
|
257 |
fi
|
246 |
fi
|
258 |
done
|
247 |
done
|
259 |
|
248 |
|
260 |
VALUE_BL_INSTALLATION_LABEL="'$(date -d @$DATE_2 "+%Y-%m-%d" )', $VALUE_BL_INSTALLATION_LABEL"
|
249 |
VALUE_BL_INSTALLATION_LABEL="'$(date -d @$DATE_2 "+%Y-%m-%d" )', $VALUE_BL_INSTALLATION_LABEL"
|
261 |
VALUE_BL_INSTALLATION_DATA="$COUNT_BL_INSTALLATION, $VALUE_BL_INSTALLATION_DATA"
|
250 |
VALUE_BL_INSTALLATION_DATA="$COUNT_BL_INSTALLATION, $VALUE_BL_INSTALLATION_DATA"
|
262 |
done
|
251 |
done
|
263 |
|
252 |
|
264 |
#create Antivirus section in html document
|
253 |
#create Antivirus section in html document
|
Line 271... |
Line 260... |
271 |
#create chart bar in html file with javascript (chartjs.com)
|
260 |
#create chart bar in html file with javascript (chartjs.com)
|
272 |
echo "<script>" >> $HTML_REPORT
|
261 |
echo "<script>" >> $HTML_REPORT
|
273 |
cat $MODEL_CHARTJS | while read LINE_JS
|
262 |
cat $MODEL_CHARTJS | while read LINE_JS
|
274 |
do
|
263 |
do
|
275 |
#name of variable
|
264 |
#name of variable
|
276 |
if [ $(echo $LINE_JS | grep 'XXCONFXX' | wc -l) -eq 1 ]
|
265 |
if [ "$(echo $LINE_JS | grep 'XXCONFXX' | wc -l)" -eq 1 ]
|
277 |
then
|
266 |
then
|
278 |
echo ${LINE_JS/XXCONFXX/$CONF_BL_INSTALLATION} >> $HTML_REPORT
|
267 |
echo ${LINE_JS/XXCONFXX/$CONF_BL_INSTALLATION} >> $HTML_REPORT
|
279 |
#chart type
|
268 |
#chart type
|
280 |
elif [ $(echo $LINE_JS | grep 'XXTYPEXX' | wc -l) -eq 1 ]
|
269 |
elif [ "$(echo $LINE_JS | grep 'XXTYPEXX' | wc -l)" -eq 1 ]
|
281 |
then
|
270 |
then
|
282 |
echo ${LINE_JS/XXTYPEXX/bar} >> $HTML_REPORT
|
271 |
echo ${LINE_JS/XXTYPEXX/bar} >> $HTML_REPORT
|
283 |
#chart title
|
272 |
#chart title
|
284 |
elif [ $(echo $LINE_JS | grep 'XXTITLEXX' | wc -l) -eq 1 ]
|
273 |
elif [ "$(echo $LINE_JS | grep 'XXTITLEXX' | wc -l)" -eq 1 ]
|
285 |
then
|
274 |
then
|
286 |
echo ${LINE_JS/XXTITLEXX/"Sites bloqués au total"} >> $HTML_REPORT
|
275 |
echo ${LINE_JS/XXTITLEXX/"Sites bloqués au total"} >> $HTML_REPORT
|
287 |
#chart data
|
276 |
#chart data
|
288 |
elif [ $(echo $LINE_JS | grep 'XXDATAXX' | wc -l) -eq 1 ]
|
277 |
elif [ "$(echo $LINE_JS | grep 'XXDATAXX' | wc -l)" -eq 1 ]
|
289 |
then
|
278 |
then
|
290 |
echo ${LINE_JS/XXDATAXX/$VALUE_BL_INSTALLATION_DATA} >> $HTML_REPORT
|
279 |
echo ${LINE_JS/XXDATAXX/$VALUE_BL_INSTALLATION_DATA} >> $HTML_REPORT
|
291 |
#color
|
280 |
#color
|
292 |
elif [ $(echo $LINE_JS | grep 'XXCOLORXX' | wc -l) -eq 1 ]
|
281 |
elif [ "$(echo $LINE_JS | grep 'XXCOLORXX' | wc -l)" -eq 1 ]
|
293 |
then
|
282 |
then
|
294 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
283 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
295 |
#labels
|
284 |
#labels
|
296 |
elif [ $(echo $LINE_JS | grep 'XXLABELSXX' | wc -l) -eq 1 ]
|
285 |
elif [ "$(echo $LINE_JS | grep 'XXLABELSXX' | wc -l)" -eq 1 ]
|
297 |
then
|
286 |
then
|
298 |
echo ${LINE_JS/XXLABELSXX/$VALUE_BL_INSTALLATION_LABEL} >> $HTML_REPORT
|
287 |
echo ${LINE_JS/XXLABELSXX/$VALUE_BL_INSTALLATION_LABEL} >> $HTML_REPORT
|
299 |
elif [ $(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l) -eq 1 ]
|
288 |
elif [ "$(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l)" -eq 1 ]
|
300 |
then
|
289 |
then
|
301 |
echo ${LINE_JS/XXLEGENDXX/false} >> $HTML_REPORT
|
290 |
echo ${LINE_JS/XXLEGENDXX/false} >> $HTML_REPORT
|
302 |
#display value of Y axis, only useful for chart bar
|
291 |
#display value of Y axis, only useful for chart bar
|
303 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l) -eq 1 ]
|
292 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l)" -eq 1 ]
|
304 |
then
|
293 |
then
|
305 |
echo "" >> $HTML_REPORT
|
294 |
echo "" >> $HTML_REPORT
|
306 |
#display value of Y axis, only useful for chart bar
|
295 |
#display value of Y axis, only useful for chart bar
|
307 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l) -eq 1 ]
|
296 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l)" -eq 1 ]
|
308 |
then
|
297 |
then
|
309 |
echo "" >> $HTML_REPORT
|
298 |
echo "" >> $HTML_REPORT
|
310 |
elif [ $(echo $LINE_JS | grep 'XXYLABELXX' | wc -l) -eq 1 ]
|
299 |
elif [ "$(echo $LINE_JS | grep 'XXYLABELXX' | wc -l)" -eq 1 ]
|
311 |
then
|
300 |
then
|
312 |
echo "\"Nombre de site bloqué par la blacklist\"" >> $HTML_REPORT
|
301 |
echo "\"Nombre de site bloqué par la blacklist\"" >> $HTML_REPORT
|
313 |
else
|
302 |
else
|
314 |
echo $LINE_JS >> $HTML_REPORT
|
303 |
echo $LINE_JS >> $HTML_REPORT
|
315 |
fi
|
304 |
fi
|
Line 319... |
Line 308... |
319 |
echo "<h2>Aucune activité de la Blacklist depuis l'installation.</h2>" >> $HTML_REPORT
|
308 |
echo "<h2>Aucune activité de la Blacklist depuis l'installation.</h2>" >> $HTML_REPORT
|
320 |
fi
|
309 |
fi
|
321 |
|
310 |
|
322 |
|
311 |
|
323 |
|
312 |
|
324 |
######################DNSMASQ BLACKLIST######################
|
313 |
######################Unbound BLACKLIST######################
|
325 |
echo "Create BL website since $MAX_DAY_AGO days"
|
314 |
echo "Create BL website since $MAX_DAY_AGO days"
|
326 |
|
315 |
|
327 |
#if data exists, create BL section in html document
|
316 |
#if data exists, create BL section in html document
|
328 |
if [ -e $TMP_BL ]
|
317 |
if [ -e $TMP_BL ]
|
329 |
then
|
318 |
then
|
Line 337... |
Line 326... |
337 |
|
326 |
|
338 |
for LINE in $(cat $TMP_BL)
|
327 |
for LINE in $(cat $TMP_BL)
|
339 |
do
|
328 |
do
|
340 |
TS_FILE=$(echo $LINE | cut -d':' -f1)
|
329 |
TS_FILE=$(echo $LINE | cut -d':' -f1)
|
341 |
#select only elements between DATE_1 and DATE_2
|
330 |
#select only elements between DATE_1 and DATE_2
|
342 |
if [ "$TS_FILE" -le "$DATE_1" -a "$TS_FILE" -ge "$DATE_2" ]
|
331 |
if [ "$TS_FILE" -le "$DATE_1" ] && [ "$TS_FILE" -ge "$DATE_2" ]
|
343 |
then
|
332 |
then
|
344 |
echo $LINE >> $TMP_BL_WEEK
|
333 |
echo $LINE >> $TMP_BL_WEEK
|
345 |
fi
|
334 |
fi
|
346 |
done
|
335 |
done
|
347 |
|
336 |
|
348 |
#then we count every occurence for each category in TMP_BL_WEEK
|
337 |
#then we count every occurence for each category in TMP_BL_WEEK
|
349 |
for CAT in $(ls /usr/local/share/dnsmasq-bl/ -1 | cut -d'.' -f1)
|
338 |
for CAT in $(ls /usr/local/share/unbound-bl/ -1 | cut -d'.' -f1)
|
350 |
do
|
339 |
do
|
351 |
echo "$CAT:$(grep -o ":$CAT:" <<< "$(cat $TMP_BL_WEEK)" | wc -l):" >> $TMP_BL_WEEK_CAT
|
340 |
echo "$CAT:$(grep -o ":$CAT:" <<< "$(cat $TMP_BL_WEEK)" | wc -l):" >> $TMP_BL_WEEK_CAT
|
352 |
done
|
341 |
done
|
353 |
|
342 |
|
354 |
#we sort by number of occurence and we take the top 10 BL categories
|
343 |
#we sort by number of occurence and we take the top 10 BL categories
|
355 |
for LINE in $(sort -t':' -k2 -rn $TMP_BL_WEEK_CAT | head -n 10)
|
344 |
for LINE in $(sort -t':' -k2 -rn $TMP_BL_WEEK_CAT | head -n 10)
|
356 |
do
|
345 |
do
|
357 |
|
346 |
|
358 |
DATA=$(echo $LINE | cut -d':' -f2)
|
347 |
DATA=$(echo $LINE | cut -d':' -f2)
|
359 |
LABEL=$(echo $LINE | cut -d':' -f1)
|
348 |
LABEL=$(echo $LINE | cut -d':' -f1)
|
360 |
if [ $DATA -ne 0 ]
|
349 |
if [ $DATA -ne 0 ]
|
361 |
then
|
350 |
then
|
362 |
VALUE_BL_DATA="$VALUE_BL_DATA $DATA, "
|
351 |
VALUE_BL_DATA="$VALUE_BL_DATA $DATA, "
|
363 |
VALUE_BL_LABEL="$VALUE_BL_LABEL '$LABEL ($DATA)',"
|
352 |
VALUE_BL_LABEL="$VALUE_BL_LABEL '$LABEL ($DATA)',"
|
364 |
fi
|
353 |
fi
|
365 |
done
|
354 |
done
|
366 |
|
355 |
|
367 |
#get other categories (sum them all)
|
356 |
#get other categories (sum them all)
|
368 |
if [ $(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc) -gt 0 ]
|
357 |
if [ "$(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc)" -gt 0 ]
|
369 |
then
|
358 |
then
|
370 |
VALUE_BL_DATA="$VALUE_BL_DATA $(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc)"
|
359 |
VALUE_BL_DATA="$VALUE_BL_DATA $(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc)"
|
371 |
VALUE_BL_LABEL="$VALUE_BL_LABEL 'autre ($(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc))'"
|
360 |
VALUE_BL_LABEL="$VALUE_BL_LABEL 'autre ($(cat $TMP_BL_WEEK_CAT | cut -d':' -f2 | sort -k1 -rn | tail -n+$(($(echo $VALUE_BL_DATA | wc -w)+1)) | paste -sd+ | bc))'"
|
372 |
fi
|
361 |
fi
|
373 |
|
362 |
|
Line 380... |
Line 369... |
380 |
echo "<script>" >> $HTML_REPORT
|
369 |
echo "<script>" >> $HTML_REPORT
|
381 |
|
370 |
|
382 |
cat $MODEL_CHARTJS | while read LINE_JS
|
371 |
cat $MODEL_CHARTJS | while read LINE_JS
|
383 |
do
|
372 |
do
|
384 |
#variable name
|
373 |
#variable name
|
385 |
if [ $(echo $LINE_JS | grep 'XXCONFXX' | wc -l) -eq 1 ]
|
374 |
if [ "$(echo $LINE_JS | grep 'XXCONFXX' | wc -l)" -eq 1 ]
|
386 |
then
|
375 |
then
|
387 |
echo ${LINE_JS/XXCONFXX/$CONF_BL} >> $HTML_REPORT
|
376 |
echo ${LINE_JS/XXCONFXX/$CONF_BL} >> $HTML_REPORT
|
388 |
#chart type
|
377 |
#chart type
|
389 |
elif [ $(echo $LINE_JS | grep 'XXTYPEXX' | wc -l) -eq 1 ]
|
378 |
elif [ "$(echo $LINE_JS | grep 'XXTYPEXX' | wc -l)" -eq 1 ]
|
390 |
then
|
379 |
then
|
391 |
echo ${LINE_JS/XXTYPEXX/pie} >> $HTML_REPORT
|
380 |
echo ${LINE_JS/XXTYPEXX/pie} >> $HTML_REPORT
|
392 |
#graph title
|
381 |
#graph title
|
393 |
elif [ $(echo $LINE_JS | grep 'XXTITLEXX' | wc -l) -eq 1 ]
|
382 |
elif [ "$(echo $LINE_JS | grep 'XXTITLEXX' | wc -l)" -eq 1 ]
|
394 |
then
|
383 |
then
|
395 |
echo ${LINE_JS/XXTITLEXX/"Sites bloqués cette semaine"} >> $HTML_REPORT
|
384 |
echo ${LINE_JS/XXTITLEXX/"Sites bloqués cette semaine"} >> $HTML_REPORT
|
396 |
#chart data
|
385 |
#chart data
|
397 |
elif [ $(echo $LINE_JS | grep 'XXDATAXX' | wc -l) -eq 1 ]
|
386 |
elif [ "$(echo $LINE_JS | grep 'XXDATAXX' | wc -l)" -eq 1 ]
|
398 |
then
|
387 |
then
|
399 |
echo ${LINE_JS/XXDATAXX/$VALUE_BL_DATA} >> $HTML_REPORT
|
388 |
echo ${LINE_JS/XXDATAXX/$VALUE_BL_DATA} >> $HTML_REPORT
|
400 |
#color
|
389 |
#color
|
401 |
elif [ $(echo $LINE_JS | grep 'XXCOLORXX' | wc -l) -eq 1 ]
|
390 |
elif [ "$(echo $LINE_JS | grep 'XXCOLORXX' | wc -l)" -eq 1 ]
|
402 |
then
|
391 |
then
|
403 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
392 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
404 |
#labels
|
393 |
#labels
|
405 |
elif [ $(echo $LINE_JS | grep 'XXLABELSXX' | wc -l) -eq 1 ]
|
394 |
elif [ "$(echo $LINE_JS | grep 'XXLABELSXX' | wc -l)" -eq 1 ]
|
406 |
then
|
395 |
then
|
407 |
echo ${LINE_JS/XXLABELSXX/$VALUE_BL_LABEL} >> $HTML_REPORT
|
396 |
echo ${LINE_JS/XXLABELSXX/$VALUE_BL_LABEL} >> $HTML_REPORT
|
408 |
#display legend, only useful for chart pie
|
397 |
#display legend, only useful for chart pie
|
409 |
elif [ $(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l) -eq 1 ]
|
398 |
elif [ "$(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l)" -eq 1 ]
|
410 |
then
|
399 |
then
|
411 |
echo ${LINE_JS/XXLEGENDXX/true} >> $HTML_REPORT
|
400 |
echo ${LINE_JS/XXLEGENDXX/true} >> $HTML_REPORT
|
412 |
#display value of Y axis, only useful for chart bar
|
401 |
#display value of Y axis, only useful for chart bar
|
413 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l) -eq 1 ]
|
402 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l)" -eq 1 ]
|
414 |
then
|
403 |
then
|
415 |
echo "/*" >> $HTML_REPORT
|
404 |
echo "/*" >> $HTML_REPORT
|
416 |
#display value of Y axis, only useful for chart bar
|
405 |
#display value of Y axis, only useful for chart bar
|
417 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l) -eq 1 ]
|
406 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l)" -eq 1 ]
|
418 |
then
|
407 |
then
|
419 |
echo "*/" >> $HTML_REPORT
|
408 |
echo "*/" >> $HTML_REPORT
|
420 |
else
|
409 |
else
|
421 |
echo $LINE_JS >> $HTML_REPORT
|
410 |
echo $LINE_JS >> $HTML_REPORT
|
422 |
fi
|
411 |
fi
|
Line 428... |
Line 417... |
428 |
|
417 |
|
429 |
######################VIRUS THREAT######################
|
418 |
######################VIRUS THREAT######################
|
430 |
echo "Create AV logs since the installation of ALCASAR"
|
419 |
echo "Create AV logs since the installation of ALCASAR"
|
431 |
|
420 |
|
432 |
#decompress every logs, if they exist
|
421 |
#decompress every logs, if they exist
|
433 |
if [ $(ls -1 /var/log/havp/access.log.*.gz 2>/dev/null | wc -l) -ge 1 ]
|
422 |
if [ "$(ls -1 /var/log/havp/access.log.*.gz 2>/dev/null | wc -l)" -ge 1 ]
|
434 |
then
|
423 |
then
|
435 |
gunzip -d access.log.*.gz
|
424 |
gunzip -d access.log.*.gz
|
436 |
fi
|
425 |
fi
|
437 |
|
426 |
|
438 |
for FILE in $(ls -1 /var/log/havp/ | grep 'access.log')
|
427 |
for FILE in /var/log/havp/access.log*
|
439 |
do
|
428 |
do
|
440 |
while read LINE_AV
|
429 |
while read LINE_AV
|
441 |
do
|
430 |
do
|
442 |
Y=$(echo $LINE_AV | cut -d' ' -f1)
|
431 |
Y=$(echo $LINE_AV | cut -d' ' -f1)
|
443 |
M=$(echo $LINE_AV | cut -d' ' -f2)
|
432 |
M=$(echo $LINE_AV | cut -d' ' -f2)
|
444 |
D=$(echo $LINE_AV | cut -d' ' -f3)
|
433 |
D=$(echo $LINE_AV | cut -d' ' -f3)
|
445 |
H=$(echo $LINE_AV | cut -d' ' -f4)
|
434 |
H=$(echo $LINE_AV | cut -d' ' -f4)
|
446 |
CURRENT_TS=$(date -d "$M $D $Y $H" +"%s")
|
435 |
CURRENT_TS=$(date -d "$M $D $Y $H" +"%s")
|
447 |
echo $CURRENT_TS >> $TMP_AV
|
436 |
echo $CURRENT_TS >> $TMP_AV
|
448 |
done < /var/log/havp/$FILE
|
437 |
done < $FILE
|
449 |
|
- |
|
450 |
done
|
438 |
done
|
451 |
|
439 |
|
452 |
if [ -e $TMP_AV ]
|
440 |
if [ -e $TMP_AV ]
|
453 |
then
|
441 |
then
|
454 |
ENABLE_AV=1
|
442 |
ENABLE_AV=1
|
Line 459... |
Line 447... |
459 |
DATE_2=$((TS-$STEP_TS))
|
447 |
DATE_2=$((TS-$STEP_TS))
|
460 |
COUNT_AV=0
|
448 |
COUNT_AV=0
|
461 |
|
449 |
|
462 |
for TS_FILE in $(cat $TMP_AV)
|
450 |
for TS_FILE in $(cat $TMP_AV)
|
463 |
do
|
451 |
do
|
464 |
if [ "$TS_FILE" -le "$DATE_1" -a "$TS_FILE" -ge "$DATE_2" ]
|
452 |
if [ "$TS_FILE" -le "$DATE_1" ] && [ "$TS_FILE" -ge "$DATE_2" ]
|
465 |
then
|
453 |
then
|
466 |
COUNT_AV=$((COUNT_AV+1))
|
454 |
COUNT_AV=$((COUNT_AV+1))
|
467 |
fi
|
455 |
fi
|
468 |
done
|
456 |
done
|
469 |
|
457 |
|
470 |
VALUE_AV_LABEL="'$(date -d @$DATE_2 "+%Y-%m-%d" )', $VALUE_AV_LABEL"
|
458 |
VALUE_AV_LABEL="'$(date -d @$DATE_2 "+%Y-%m-%d" )', $VALUE_AV_LABEL"
|
471 |
VALUE_AV_DATA="$COUNT_AV, $VALUE_AV_DATA"
|
459 |
VALUE_AV_DATA="$COUNT_AV, $VALUE_AV_DATA"
|
472 |
done
|
460 |
done
|
473 |
|
461 |
|
474 |
#create Antivirus section in html document
|
462 |
#create Antivirus section in html document
|
475 |
NAME_AV='chart_av'
|
463 |
NAME_AV='chart_av'
|
476 |
CONF_AV='config_av'
|
464 |
CONF_AV='config_av'
|
477 |
echo "<center>" >> $HTML_REPORT
|
465 |
echo "<center>" >> $HTML_REPORT
|
478 |
echo "<canvas id='$NAME_AV' width='450' height='450' ></canvas>" >> $HTML_REPORT
|
466 |
echo "<canvas id='$NAME_AV' width='450' height='450' ></canvas>" >> $HTML_REPORT
|
Line 482... |
Line 470... |
482 |
#create chart bar in html file with javascript (chartjs.com)
|
470 |
#create chart bar in html file with javascript (chartjs.com)
|
483 |
echo "<script>" >> $HTML_REPORT
|
471 |
echo "<script>" >> $HTML_REPORT
|
484 |
cat $MODEL_CHARTJS | while read LINE_JS
|
472 |
cat $MODEL_CHARTJS | while read LINE_JS
|
485 |
do
|
473 |
do
|
486 |
#name of variable
|
474 |
#name of variable
|
487 |
if [ $(echo $LINE_JS | grep 'XXCONFXX' | wc -l) -eq 1 ]
|
475 |
if [ "$(echo $LINE_JS | grep 'XXCONFXX' | wc -l)" -eq 1 ]
|
488 |
then
|
476 |
then
|
489 |
echo ${LINE_JS/XXCONFXX/$CONF_AV} >> $HTML_REPORT
|
477 |
echo ${LINE_JS/XXCONFXX/$CONF_AV} >> $HTML_REPORT
|
490 |
#chart type
|
478 |
#chart type
|
491 |
elif [ $(echo $LINE_JS | grep 'XXTYPEXX' | wc -l) -eq 1 ]
|
479 |
elif [ "$(echo $LINE_JS | grep 'XXTYPEXX' | wc -l)" -eq 1 ]
|
492 |
then
|
480 |
then
|
493 |
echo ${LINE_JS/XXTYPEXX/bar} >> $HTML_REPORT
|
481 |
echo ${LINE_JS/XXTYPEXX/bar} >> $HTML_REPORT
|
494 |
#graph title
|
482 |
#graph title
|
495 |
elif [ $(echo $LINE_JS | grep 'XXTITLEXX' | wc -l) -eq 1 ]
|
483 |
elif [ "$(echo $LINE_JS | grep 'XXTITLEXX' | wc -l)" -eq 1 ]
|
496 |
then
|
484 |
then
|
497 |
echo ${LINE_JS/XXTITLEXX/"Menaces bloqués par l\'antivirus"} >> $HTML_REPORT
|
485 |
echo ${LINE_JS/XXTITLEXX/"Menaces bloqués par l\'antivirus"} >> $HTML_REPORT
|
498 |
#chart data
|
486 |
#chart data
|
499 |
elif [ $(echo $LINE_JS | grep 'XXDATAXX' | wc -l) -eq 1 ]
|
487 |
elif [ "$(echo $LINE_JS | grep 'XXDATAXX' | wc -l)" -eq 1 ]
|
500 |
then
|
488 |
then
|
501 |
echo ${LINE_JS/XXDATAXX/$VALUE_AV_DATA} >> $HTML_REPORT
|
489 |
echo ${LINE_JS/XXDATAXX/$VALUE_AV_DATA} >> $HTML_REPORT
|
502 |
#color
|
490 |
#color
|
503 |
elif [ $(echo $LINE_JS | grep 'XXCOLORXX' | wc -l) -eq 1 ]
|
491 |
elif [ "$(echo $LINE_JS | grep 'XXCOLORXX' | wc -l)" -eq 1 ]
|
504 |
then
|
492 |
then
|
505 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
493 |
echo ${LINE_JS/XXCOLORXX/$COLOR} >> $HTML_REPORT
|
506 |
#labels
|
494 |
#labels
|
507 |
elif [ $(echo $LINE_JS | grep 'XXLABELSXX' | wc -l) -eq 1 ]
|
495 |
elif [ "$(echo $LINE_JS | grep 'XXLABELSXX' | wc -l)" -eq 1 ]
|
508 |
then
|
496 |
then
|
509 |
echo ${LINE_JS/XXLABELSXX/$VALUE_AV_LABEL} >> $HTML_REPORT
|
497 |
echo ${LINE_JS/XXLABELSXX/$VALUE_AV_LABEL} >> $HTML_REPORT
|
510 |
elif [ $(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l) -eq 1 ]
|
498 |
elif [ "$(echo $LINE_JS | grep 'XXLEGENDXX' | wc -l)" -eq 1 ]
|
511 |
then
|
499 |
then
|
512 |
echo ${LINE_JS/XXLEGENDXX/false} >> $HTML_REPORT
|
500 |
echo ${LINE_JS/XXLEGENDXX/false} >> $HTML_REPORT
|
513 |
#display value of Y axis, only useful for chart bar
|
501 |
#display value of Y axis, only useful for chart bar
|
514 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l) -eq 1 ]
|
502 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-BEGINXX' | wc -l)" -eq 1 ]
|
515 |
then
|
503 |
then
|
516 |
echo "" >> $HTML_REPORT
|
504 |
echo "" >> $HTML_REPORT
|
517 |
#display value of Y axis, only useful for chart bar
|
505 |
#display value of Y axis, only useful for chart bar
|
518 |
elif [ $(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l) -eq 1 ]
|
506 |
elif [ "$(echo $LINE_JS | grep 'XXCOMMENT-ENDXX' | wc -l)" -eq 1 ]
|
519 |
then
|
507 |
then
|
520 |
echo "" >> $HTML_REPORT
|
508 |
echo "" >> $HTML_REPORT
|
521 |
elif [ $(echo $LINE_JS | grep 'XXYLABELXX' | wc -l) -eq 1 ]
|
509 |
elif [ "$(echo $LINE_JS | grep 'XXYLABELXX' | wc -l)" -eq 1 ]
|
522 |
then
|
510 |
then
|
523 |
echo "\"Nombre de menaces virales bloqués par l'antivirus\"" >> $HTML_REPORT
|
511 |
echo "\"Nombre de menaces virales bloqués par l'antivirus\"" >> $HTML_REPORT
|
524 |
else
|
512 |
else
|
525 |
echo $LINE_JS >> $HTML_REPORT
|
513 |
echo $LINE_JS >> $HTML_REPORT
|
526 |
fi
|
514 |
fi
|
Line 536... |
Line 524... |
536 |
#create html document
|
524 |
#create html document
|
537 |
echo "<h2>Statistiques volumétrie connexions</h2>" >> $HTML_REPORT
|
525 |
echo "<h2>Statistiques volumétrie connexions</h2>" >> $HTML_REPORT
|
538 |
|
526 |
|
539 |
#create new htdigest user to consult statistique of ACC
|
527 |
#create new htdigest user to consult statistique of ACC
|
540 |
#if user does not exist, we create him
|
528 |
#if user does not exist, we create him
|
541 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -lt 1 ]
|
529 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -lt 1 ]
|
542 |
then
|
530 |
then
|
543 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_only_manager
|
531 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_only_manager
|
544 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_manager
|
532 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_manager
|
545 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_all
|
533 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_all
|
546 |
chown -R root:apache $DIR_KEY
|
534 |
chown -R root:apache $DIR_KEY
|
Line 555... |
Line 543... |
555 |
DELIM_2="<\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <p>"
|
543 |
DELIM_2="<\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <p>"
|
556 |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" | tail -n+3 | head -n-2 >> $TMP_STATS_2
|
544 |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" | tail -n+3 | head -n-2 >> $TMP_STATS_2
|
557 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT
|
545 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT
|
558 |
|
546 |
|
559 |
#we delete our user if he still exists
|
547 |
#we delete our user if he still exists
|
560 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -ge 1 ]
|
548 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -ge 1 ]
|
561 |
then
|
549 |
then
|
562 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager
|
550 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager
|
563 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager
|
551 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager
|
564 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all
|
552 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all
|
565 |
fi
|
553 |
fi
|
Line 593... |
Line 581... |
593 |
|
581 |
|
594 |
# Create HTML document
|
582 |
# Create HTML document
|
595 |
echo "<h2>Connexion à l'ALCASAR Control Center (ACC)</h2>" >> $HTML_REPORT
|
583 |
echo "<h2>Connexion à l'ALCASAR Control Center (ACC)</h2>" >> $HTML_REPORT
|
596 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
584 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
597 |
echo "<thead><tr><th>Date</th><th>Utilisateur</th><th>Adresse IP</th><th>Agent</th></tr></thead><tbody>" >> $HTML_REPORT
|
585 |
echo "<thead><tr><th>Date</th><th>Utilisateur</th><th>Adresse IP</th><th>Agent</th></tr></thead><tbody>" >> $HTML_REPORT
|
598 |
echo $ROWS >> $HTML_REPORT
|
586 |
echo "$ROWS" >> $HTML_REPORT
|
599 |
echo "</tbody></table>" >> $HTML_REPORT
|
587 |
echo "</tbody></table>" >> $HTML_REPORT
|
600 |
|
588 |
|
601 |
|
589 |
|
602 |
###################### ALCASAR : GLOBAL TRAFFIC ######################
|
590 |
###################### ALCASAR : GLOBAL TRAFFIC ######################
|
603 |
echo "Get Global traffic of the last 30 days"
|
591 |
echo "Get Global traffic of the last 30 days"
|
Line 638... |
Line 626... |
638 |
|
626 |
|
639 |
# Create html document
|
627 |
# Create html document
|
640 |
echo "<h2>Trafic global</h2>" >> $HTML_REPORT
|
628 |
echo "<h2>Trafic global</h2>" >> $HTML_REPORT
|
641 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
629 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
642 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
630 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
643 |
echo $ROWS >> $HTML_REPORT
|
631 |
echo "$ROWS" >> $HTML_REPORT
|
644 |
echo "</tbody></table>" >> $HTML_REPORT
|
632 |
echo "</tbody></table>" >> $HTML_REPORT
|
645 |
|
633 |
|
646 |
|
634 |
|
647 |
###################### ALCASAR : FAIL2BAN ######################
|
635 |
###################### ALCASAR : FAIL2BAN ######################
|
648 |
echo "Get fail2ban log of the week"
|
636 |
echo "Get fail2ban log of the week"
|
Line 696... |
Line 684... |
696 |
echo "};</script>" >> $HTML_REPORT
|
684 |
echo "};</script>" >> $HTML_REPORT
|
697 |
echo "</body>" >> $HTML_REPORT
|
685 |
echo "</body>" >> $HTML_REPORT
|
698 |
echo "</html>" >> $HTML_REPORT
|
686 |
echo "</html>" >> $HTML_REPORT
|
699 |
|
687 |
|
700 |
#convert html document to PDF
|
688 |
#convert html document to PDF
|
701 |
/usr/bin/wkhtmltopdf $HTML_REPORT $(echo $HTML_REPORT | cut -d'.' -f1).pdf
|
689 |
/usr/bin/wkhtmltopdf $HTML_REPORT "$(echo $HTML_REPORT | cut -d'.' -f1).pdf"
|
702 |
chown apache:apache $(echo $HTML_REPORT | cut -d'.' -f1).pdf
|
690 |
chown apache:apache "$(echo $HTML_REPORT | cut -d'.' -f1).pdf"
|
703 |
chmod 644 $(echo $HTML_REPORT | cut -d'.' -f1).pdf
|
691 |
chmod 644 "$(echo $HTML_REPORT | cut -d'.' -f1).pdf"
|
704 |
mv $(echo $HTML_REPORT | cut -d'.' -f1).pdf /var/Save/activity_report/
|
692 |
mv "$(echo $HTML_REPORT | cut -d'.' -f1).pdf" /var/Save/activity_report/
|
705 |
|
693 |
|
706 |
#compress every logs, if they exist
|
694 |
#compress every logs, if they exist
|
707 |
if [ $(ls -1 /var/log/havp/access.log.* 2>/dev/null | wc -l) -ge 1 ]
|
695 |
if [ "$(ls -1 /var/log/havp/access.log.* 2>/dev/null | wc -l)" -ge 1 ]
|
708 |
then
|
696 |
then
|
709 |
gzip /var/log/havp/access.log.*
|
697 |
gzip /var/log/havp/access.log.*
|
710 |
fi
|
698 |
fi
|
711 |
|
699 |
|
712 |
#compress every logs
|
700 |
#compress every logs
|
713 |
if [ $(ls -1 /var/log/dnsmasq/dnsmasq-blacklist.log.* 2>/dev/null | wc -l) -ge 1 ]
|
701 |
if [ "$(ls -1 /var/log/unbound/unbound-blacklist.log.* 2>/dev/null | wc -l)" -ge 1 ]
|
714 |
then
|
702 |
then
|
715 |
gzip /var/log/dnsmasq/dnsmasq-blacklist.log.*
|
703 |
gzip /var/log/unbound/unbound-blacklist.log.*
|
716 |
fi
|
704 |
fi
|
717 |
|
705 |
|
718 |
#remove our files
|
706 |
#remove our files
|
719 |
rm -f $TMP_BL
|
707 |
rm -f $TMP_BL
|
720 |
rm -f $TMP_BL_WEEK
|
708 |
rm -f $TMP_BL_WEEK
|