diff --git a/Makefile b/Makefile index 1686556..7602ed6 100644 --- a/Makefile +++ b/Makefile @@ -9,10 +9,10 @@ build:: run:: touch /tmp/clftest - touch /tmp/jsontest + touch /tmp/caddytest touch /tmp/generictest cargo build - sudo target/debug/blockfast -v -c=/tmp/clftest -j=/tmp/jsontest --generic-logpath=/tmp/generictest --generic-ip='from ([0-9a-fA-F:.]+) port' --generic-positive='Failed password' + sudo target/debug/blockfast -v --clf-logpath=/tmp/clftest --caddy-logpath=/tmp/caddytest --generic-logpath=/tmp/generictest --generic-ip='from ([0-9a-fA-F:.]+) port' --generic-positive='Failed password' ci:: test cargo fmt --all -- --check @@ -55,9 +55,9 @@ hit-clf:: ok-clf:: echo "2.124.36.195 - p [25/Sep/2021:13:49:56 +0200] \"POST /some/rpc HTTP/2.0\" 200 23012" >> /tmp/clftest -hit-json:: - echo "{\"request\":{\"remote_ip\":\"1.124.36.19\"}, \"status\": 400}" >> /tmp/jsontest +hit-caddy:: + echo "{\"request\":{\"remote_ip\":\"1.124.36.19\"}, \"status\": 400}" >> /tmp/caddytest -ok-json:: - echo "{\"request\":{\"remote_ip\":\"2.124.36.19\"}, \"status\": 200}" >> /tmp/jsontest +ok-caddy:: + echo "{\"request\":{\"remote_ip\":\"2.124.36.19\"}, \"status\": 200}" >> /tmp/caddytest diff --git a/README.md b/README.md index 8e853ce..787c8f3 100644 --- a/README.md +++ b/README.md @@ -3,8 +3,8 @@ Block internets scanners fast 🍶 Features: - - Common Log Format parser (apache logs, etc...) - - JSON log parser (caddy logs) + - Common Log Format parser (apache, nginx logs, etc...) + - Caddy JSON log parser - Generic log parser - Sane defaults - Fast ip ban with `ipset` @@ -13,15 +13,15 @@ Features: ## example ```txt -$ ./blockfast -j=/caddy/logs -1737927469 - starting with json parsing at "/tmp/jsontest" +$ ./blockfast --caddy-logpath=/caddy/logs +1737927469 - starting with caddy parsing at "/tmp/caddytest" 1737927469 - jail setup, allowance 5, time 21600s -1737927477 - json logged offence for 9.124.36.195 -1737927478 - json logged offence for 9.124.36.195 -1737927479 - json logged offence for 9.124.36.195 -1737927479 - json logged offence for 9.124.36.195 -1737927480 - json logged offence for 9.124.36.195 -1737927480 - json jailtime for 9.124.36.195 +1737927477 - caddy logged offence for 9.124.36.195 +1737927478 - caddy logged offence for 9.124.36.195 +1737927479 - caddy logged offence for 9.124.36.195 +1737927479 - caddy logged offence for 9.124.36.195 +1737927480 - caddy logged offence for 9.124.36.195 +1737927480 - caddy jailtime for 9.124.36.195 ``` ## build @@ -34,11 +34,11 @@ Blockfast - block internets scanners fast 🍶 Author: pierre dubouilh Blockfast reads logs from various sources and blocks the offending IPs using iptables and ipset. -It supports logs in Common-Log-Format (Apache, etc..), JSON (Caddy) and a generic logs parser. +It supports logs in Common-Log-Format (Apache, nginx, etc..), Caddy JSON and a generic logs parser. Example: # block invalid http statuses from caddy - ./blockfast -j=/caddy/logs + ./blockfast --caddy-logpath=/caddy/logs # generic log parser example with a log text to flag, and a regex to parse the offending IP. ./blockfast --generic-logpath=/tmp/generictest --generic-positive='Failed password' --generic-ip='from ([0-9a-fA-F:.]+) port' @@ -52,10 +52,10 @@ Options: how many offences allowed (max 255) [default: 5] -v, --verbose log all offences - -c, --clf-logpath - path of Common-Log-Format logfile (Apache, etc..), can be repeated - -j, --json-logpath - path of JSON logfile (works with Caddy), can be repeated + --clf-logpath + path of Common-Log-Format logfile (Apache, nginx, etc..), can be repeated + --caddy-logpath + path of Caddy JSON logfile, can be repeated --generic-logpath generic parser log file path, can be repeated --generic-ip @@ -65,7 +65,7 @@ Options: --generic-negative generic parser negative - if a logline contains this, it is considered good, the rest is bad --invalid-http-statuses - invalid http statuses (for CLF and JSON logs). Coma separated list, accepts ranges with XX [default: 400,401,402,403] + invalid http statuses (for CLF and Caddy logs). Coma separated list, accepts ranges with XX [default: 400,401,402,403] -h, --help Print help -V, --version diff --git a/src/json.rs b/src/caddy.rs similarity index 100% rename from src/json.rs rename to src/caddy.rs diff --git a/src/main.rs b/src/main.rs index a2c5061..cf68d0c 100644 --- a/src/main.rs +++ b/src/main.rs @@ -4,9 +4,9 @@ use anyhow::*; use clap::Parser; use linemux::{Line, MuxedLines}; +mod caddy; mod clf; mod generic; -mod json; mod utils; mod jail; @@ -39,14 +39,14 @@ async fn run() -> Result<()> { log!("starting with clf parsing at {:?}", &p); } - // json - let json_logpaths = &args.json_logpath; - for p in json_logpaths { + // caddy json + let caddy_logpaths = &args.caddy_logpath; + for p in caddy_logpaths { ml.add_file(&p).await?; - log!("starting with json parsing at {:?}", &p); + log!("starting with caddy parsing at {:?}", &p); } - if json_logpaths.is_empty() && clf_logpaths.is_empty() && generic_paths.is_empty() { + if caddy_logpaths.is_empty() && clf_logpaths.is_empty() && generic_paths.is_empty() { bail!("no log files to parse, see --help"); } @@ -60,8 +60,8 @@ async fn run() -> Result<()> { let (target, ret) = if path.is_some_and(|p| clf_logpaths.contains(p)) { ("clf", clf::parse(payload, invalid_statuses_ref)?) - } else if path.is_some_and(|p| json_logpaths.contains(p)) { - ("json", json::parse(payload, invalid_statuses_ref)?) + } else if path.is_some_and(|p| caddy_logpaths.contains(p)) { + ("caddy", caddy::parse(payload, invalid_statuses_ref)?) } else if path.is_some_and(|p| generic_paths.contains(p)) { ( "generic", diff --git a/src/utils.rs b/src/utils.rs index 7a90043..2654c17 100644 --- a/src/utils.rs +++ b/src/utils.rs @@ -86,11 +86,11 @@ Blockfast - block internets scanners fast 🍶 Author: pierre dubouilh Blockfast reads logs from various sources and blocks the offending IPs using iptables and ipset. -It supports logs in Common-Log-Format (Apache, etc..), JSON (Caddy) and a generic logs parser. +It supports logs in Common-Log-Format (Apache, nginx, etc..), Caddy JSON and a generic logs parser. Example: # block invalid http statuses from caddy - ./blockfast -j=/caddy/logs + ./blockfast --caddy-logpath=/caddy/logs # generic log parser example with a log text to flag, and a regex to parse the offending IP. ./blockfast --generic-logpath=/tmp/generictest --generic-positive='Failed password' --generic-ip='from ([0-9a-fA-F:.]+) port'", @@ -110,13 +110,13 @@ pub struct Args { #[clap(short, long)] pub verbose: bool, - /// path of Common-Log-Format logfile (Apache, etc..), can be repeated - #[clap(short, long, value_parser = resolve_path)] + /// path of Common-Log-Format logfile (Apache, nginx, etc..), can be repeated + #[clap(long, value_parser = resolve_path)] pub clf_logpath: Vec, - /// path of JSON logfile (works with Caddy), can be repeated - #[clap(short, long, value_parser = resolve_path)] - pub json_logpath: Vec, + /// path of Caddy JSON logfile, can be repeated + #[clap(long, value_parser = resolve_path)] + pub caddy_logpath: Vec, /// generic parser log file path, can be repeated #[clap(long, value_parser = resolve_path, requires_all = ["generic_ip", "generic_match"])] @@ -134,7 +134,7 @@ pub struct Args { #[clap(long, requires = "generic_logpath")] pub generic_negative: Option, - /// invalid http statuses (for CLF and JSON logs). Coma separated list, accepts ranges with XX. + /// invalid http statuses (for CLF and Caddy logs). Coma separated list, accepts ranges with XX. #[clap(long, default_value = "400,401,402,403")] pub invalid_http_statuses: String, }