Showing posts with label code. Show all posts
Showing posts with label code. Show all posts

Saturday, November 14, 2009

fail2ban vuurmuur plugin

I made a decent vuurmuur firewall plugin(action) for fail2ban. I am debugging it, because it takes a good minute to stop the service... I will update this post when I figure out what the heck is taking so long. I am also going to submit this to fail2ban for possible inclusion.

I opted to go with the default behavior of fail2ban, which is to remove all bans on a restart. It is trivial to hardcode the network, and groups, if you don't want fail2ban messing with your vuurmuur structure or removing bans when it restarts.

place this in /etc/fail2ban/action.d/vuurmuur.conf
# Author: Nick Shobe
#

[Definition]

# Option: actionstart
# Notes.: command executed once at the start of Fail2Ban.
# Values: CMD
#
# Create a zone in vuurmuur called fail2ban... this script will add the "" network and all the hosts... you can use a custom rule in vuurmuur to block ports by network
# You can make multiple rules that block specific ports if you don't want to globally block an ip... Do this like any customized rules.
actionstart = vuurmuur_script --create --network .fail2ban
vuurmuur_script --modify --network .fail2ban --variable ACTIVE --set Yes
vuurmuur_script --modify --network .fail2ban --variable NETWORK --set 0.0.0.0
vuurmuur_script --modify --network .fail2ban --variable NETMASK --set 0.0.0.0
append=''
for int in `vuurmuur_script --list --interface all`; do vuurmuur_script --modify --network .fail2ban $append --variable INTERFACE --set $int ; append='--append' ; done
vuurmuur_script --create --group ..fail2ban
vuurmuur_script --modify --group ..fail2ban --variable ACTIVE --set Yes

# Option: actionstop
# Notes.: command executed once at the end of Fail2Ban
# Values: CMD
#
actionstop = for group in `vuurmuur_script --list --group .fail2ban`; do vuurmuur_script --delete --group $group; done
for host in `vuurmuur_script --list --host .fail2ban`; do vuurmuur_script --delete --host $host; done
vuurmuur_script --delete --network .fail2ban
vuurmuur_script --create --network .fail2ban
vuurmuur_script --modify --network .fail2ban --variable ACTIVE --set Yes
vuurmuur_script --modify --network .fail2ban --variable NETWORK --set 0.0.0.0
vuurmuur_script --modify --network .fail2ban --variable NETMASK --set 0.0.0.0
append=''
for int in `vuurmuur_script --list --interface all`; do vuurmuur_script --modify --network .fail2ban $append --variable INTERFACE --set $int ; append='--append' ; done
vuurmuur_script --create --group ..fail2ban
vuurmuur_script --modify --group ..fail2ban --variable ACTIVE --set Yes
vuurmuur_script --reload

# Option: actioncheck
# Notes.: command executed once before each actionban command
# Values: CMD
#
actioncheck = vuurmuur_script --list --host .fail2ban | tr '-' '.'

# Option: actionban
# Notes.: command executed when banning an IP. Take care that the
# command is executed with Fail2Ban user rights.
# Tags: IP address
# number of failures
#
Use this just like a normal iptables action file, only consider it is using vuurmuur. In vuurmuur, create a rule that uses the "blockedhosts" group under the appropriate network to block the appropriate traffic. Feel free to contact me if you have any questions.

Friday, March 20, 2009

PHP fork() 'fake' with apache

The other day at work I started working on a php script to dynamically return some results to a command line client(wget/curl)... The problem was, the php script takes quite a while to get the db results, find a set of images, and then compress them into a zip file, before streaming them to the client. I knew that my jobs where perfect for parallel processing as one set of data is selected by the file timestamps and the other comes out of the database.

Being familiar with C and linux cl programming, I naturally turned to the PHP fork() function. However, I soon found out that fork() in php one works if PHP is running in CGI or CLI mode. This code needed to run through Apache!

Since each PHP script gets it's own process from Apache, I figured that if I where to use some clever manimuplating of output bufferes and file pipes, I should be able to make this work!

So here is the prototype fork with apache: phpApachFork.php

Fixed -- missing function sendToHost()
Fixed -- sendToHost not properly handling socket closing after content length reached.