| @@ -12,14 +12,14 @@ discard block | ||
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; | 
| 13 | 13 | if ( preg_match($msa,$received['host'][$i]) ) | 
| 14 | 14 | $dateR = $received['date'][$i]; | 
| 15 | -        		foreach ($mxserver as $mx) { | |
| 16 | - if (!$ip) | |
| 15 | +				foreach ($mxserver as $mx) { | |
| 16 | + if (!$ip) | |
| 17 | 17 |  					if ($mx == $received['host'][$i]) { | 
| 18 | 18 | $host = $received['host'][$i]; | 
| 19 | 19 | $ip = $received['ip'][$i]; | 
| 20 | - } | |
| 21 | - } | |
| 22 | - } | |
| 20 | + } | |
| 21 | + } | |
| 22 | + } | |
| 23 | 23 | } | 
| 24 | 24 |  	if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) | 
| 25 | 25 | $dateC['date'] = 'Not found'; | 
| @@ -39,15 +39,15 @@ discard block | ||
| 39 | 39 | |
| 40 | 40 | |
| 41 | 41 |  function summaryBadReport ($uidvet) { | 
| 42 | - $nuid = $uidvet['count']; | |
| 43 | - if ( empty($uidvet) ) return NULL; | |
| 44 | - $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; | |
| 42 | + $nuid = $uidvet['count']; | |
| 43 | + if ( empty($uidvet) ) return NULL; | |
| 44 | + $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; | |
| 45 | 45 | |
| 46 | - /* Remove count index */ | |
| 47 | - $uids = array_keys($uidvet['uid']); | |
| 46 | + /* Remove count index */ | |
| 47 | + $uids = array_keys($uidvet['uid']); | |
| 48 | 48 | $totlearn = 0; | 
| 49 | 49 | |
| 50 | -        foreach ( $uids as $uid ) { | |
| 50 | +		foreach ( $uids as $uid ) { | |
| 51 | 51 | $totlearn += $uidvet['uid']["$uid"]['count'];; | 
| 52 | 52 |  		$return .= sprintf ('<tr><td>%s</td><td>%u</td></tr>',$uid,$uidvet['uid']["$uid"]['count']); | 
| 53 | 53 | } | 
| @@ -60,26 +60,26 @@ discard block | ||
| 60 | 60 | |
| 61 | 61 | function array_msort($array, $cols) | 
| 62 | 62 |  { | 
| 63 | - $colarr = array(); | |
| 64 | -    foreach ($cols as $col => $order) { | |
| 65 | - $colarr[$col] = array(); | |
| 66 | -        foreach ($array as $k => $row) { $colarr[$col]['_'.$k] = strtolower($row[$col]); } | |
| 67 | - } | |
| 68 | -    $eval = 'array_multisort('; | |
| 69 | -    foreach ($cols as $col => $order) { | |
| 70 | - $eval .= '$colarr[\''.$col.'\'],'.$order.','; | |
| 71 | - } | |
| 72 | - $eval = substr($eval,0,-1).');'; | |
| 73 | - eval($eval); | |
| 74 | - $ret = array(); | |
| 75 | -    foreach ($colarr as $col => $arr) { | |
| 76 | -        foreach ($arr as $k => $v) { | |
| 77 | - $k = substr($k,1); | |
| 78 | - if (!isset($ret[$k])) $ret[$k] = $array[$k]; | |
| 79 | - if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; | |
| 80 | - } | |
| 81 | - } | |
| 82 | - return $ret; | |
| 63 | + $colarr = array(); | |
| 64 | +	foreach ($cols as $col => $order) { | |
| 65 | + $colarr[$col] = array(); | |
| 66 | +		foreach ($array as $k => $row) { $colarr[$col]['_'.$k] = strtolower($row[$col]); } | |
| 67 | + } | |
| 68 | +	$eval = 'array_multisort('; | |
| 69 | +	foreach ($cols as $col => $order) { | |
| 70 | + $eval .= '$colarr[\''.$col.'\'],'.$order.','; | |
| 71 | + } | |
| 72 | + $eval = substr($eval,0,-1).');'; | |
| 73 | + eval($eval); | |
| 74 | + $ret = array(); | |
| 75 | +	foreach ($colarr as $col => $arr) { | |
| 76 | +		foreach ($arr as $k => $v) { | |
| 77 | + $k = substr($k,1); | |
| 78 | + if (!isset($ret[$k])) $ret[$k] = $array[$k]; | |
| 79 | + if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; | |
| 80 | + } | |
| 81 | + } | |
| 82 | + return $ret; | |
| 83 | 83 | |
| 84 | 84 | } | 
| 85 | 85 | |
| @@ -94,8 +94,8 @@ discard block | ||
| 94 | 94 | |
| 95 | 95 |  	foreach ( $ips as $ip ) { | 
| 96 | 96 | if ( $ip == 'count' ) continue; | 
| 97 | - $nlearn = $ipvet['ip']["$ip"]['count']; | |
| 98 | - unset($ipvet['ip']["$ip"]['count']); | |
| 97 | + $nlearn = $ipvet['ip']["$ip"]['count']; | |
| 98 | + unset($ipvet['ip']["$ip"]['count']); | |
| 99 | 99 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ | 
| 100 | 100 | $nuid = count($ipvet['ip']["$ip"]); | 
| 101 | 101 |  		if ( !$cf['onlyReport'] ) { | 
| @@ -123,9 +123,9 @@ discard block | ||
| 123 | 123 | $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; | 
| 124 | 124 |  		$return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); | 
| 125 | 125 | $rowuid=NULL; | 
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 126 | + for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 127 | 127 | array_shift($ipvet['ip']["$ip"]); | 
| 128 | - $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); | |
| 128 | + $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); | |
| 129 | 129 | |
| 130 | 130 | } | 
| 131 | 131 |  	$return .= sprintf ('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>',$ipvet['ip']['count'],$ipvet['uid']['count'],$nips); | 
| @@ -135,20 +135,20 @@ discard block | ||
| 135 | 135 | /* Not used for listing purpose, but useful to you! */ | 
| 136 | 136 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; | 
| 137 | 137 | $uids = array_keys($ipvet['uid']); | 
| 138 | -        foreach ( $uids as $uid ) { | |
| 138 | +		foreach ( $uids as $uid ) { | |
| 139 | 139 | if ( $uid == 'count' ) continue; | 
| 140 | - $nlearn = $ipvet['uid']["$uid"]['count']; | |
| 141 | - unset ( $ipvet['uid']["$uid"]['count'] ); | |
| 140 | + $nlearn = $ipvet['uid']["$uid"]['count']; | |
| 141 | + unset ( $ipvet['uid']["$uid"]['count'] ); | |
| 142 | 142 | $nip = count($ipvet['uid']["$uid"]); | 
| 143 | 143 | $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; | 
| 144 | 144 |  		$return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); | 
| 145 | - $rowuid=NULL; | |
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 147 | - array_shift($ipvet['uid']["$uid"]); | |
| 148 | - $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); | |
| 145 | + $rowuid=NULL; | |
| 146 | + for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 147 | + array_shift($ipvet['uid']["$uid"]); | |
| 148 | + $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); | |
| 149 | 149 | |
| 150 | - } | |
| 151 | -        $return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips);	 | |
| 150 | + } | |
| 151 | +		$return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips);	 | |
| 152 | 152 | |
| 153 | 153 | |
| 154 | 154 | return $return; | 
| @@ -176,50 +176,50 @@ discard block | ||
| 176 | 176 | */ | 
| 177 | 177 | |
| 178 | 178 | // A one shot search | 
| 179 | - $searchParams = array( | |
| 180 | -                'earliest_time' => date("c",strtotime ($date)-120), | |
| 181 | -                'latest_time' => date("c",strtotime ($date)+60) | |
| 182 | - ); | |
| 179 | + $searchParams = array( | |
| 180 | +				'earliest_time' => date("c",strtotime ($date)-120), | |
| 181 | +				'latest_time' => date("c",strtotime ($date)+60) | |
| 182 | + ); | |
| 183 | 183 | |
| 184 | - // Run a oneshot search that returns the job's results | |
| 185 | - $resultsStream = $service->oneshotSearch($searchQueryBlocking, $searchParams); | |
| 186 | - $resultSearch = new Splunk_ResultsReader($resultsStream); | |
| 184 | + // Run a oneshot search that returns the job's results | |
| 185 | + $resultsStream = $service->oneshotSearch($searchQueryBlocking, $searchParams); | |
| 186 | + $resultSearch = new Splunk_ResultsReader($resultsStream); | |
| 187 | 187 | |
| 188 | 188 | // Use the built-in XML parser to display the job results | 
| 189 | 189 | foreach ($resultSearch as $result) | 
| 190 | 190 |  	  { | 
| 191 | - if ($result instanceof Splunk_ResultsFieldOrder) | |
| 192 | -	    { | |
| 193 | - // More than one field attribute returned by search | |
| 194 | - // You must redefine the search | |
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; | |
| 196 | - } | |
| 197 | - else if ($result instanceof Splunk_ResultsMessage) | |
| 198 | -	    { | |
| 199 | - // I don't want messages in my search | |
| 200 | - return FALSE; | |
| 201 | - } | |
| 202 | - else if (is_array($result)) | |
| 203 | -	    { | |
| 204 | - // Process a row | |
| 205 | - foreach ($result as $key => $valueOrValues) | |
| 206 | -	        { | |
| 207 | - if (is_array($valueOrValues)) | |
| 208 | -	          { | |
| 209 | - return FALSE; | |
| 210 | - } | |
| 211 | - else | |
| 212 | -	          { | |
| 213 | - return $valueOrValues; | |
| 214 | -	            #print "  {$key} => {$value}\r\n"; | |
| 215 | - } | |
| 216 | - } | |
| 217 | - } | |
| 218 | - else | |
| 219 | -	    { | |
| 220 | - #print "Unknow result type"; | |
| 221 | - return FALSE; | |
| 222 | - } | |
| 191 | + if ($result instanceof Splunk_ResultsFieldOrder) | |
| 192 | +		{ | |
| 193 | + // More than one field attribute returned by search | |
| 194 | + // You must redefine the search | |
| 195 | + if ( count($result->getFieldNames()) > 1 ) return FALSE; | |
| 196 | + } | |
| 197 | + else if ($result instanceof Splunk_ResultsMessage) | |
| 198 | +		{ | |
| 199 | + // I don't want messages in my search | |
| 200 | + return FALSE; | |
| 201 | + } | |
| 202 | + else if (is_array($result)) | |
| 203 | +		{ | |
| 204 | + // Process a row | |
| 205 | + foreach ($result as $key => $valueOrValues) | |
| 206 | +			{ | |
| 207 | + if (is_array($valueOrValues)) | |
| 208 | +			  { | |
| 209 | + return FALSE; | |
| 210 | + } | |
| 211 | + else | |
| 212 | +			  { | |
| 213 | + return $valueOrValues; | |
| 214 | +				#print "  {$key} => {$value}\r\n"; | |
| 215 | + } | |
| 216 | + } | |
| 217 | + } | |
| 218 | + else | |
| 219 | +		{ | |
| 220 | + #print "Unknow result type"; | |
| 221 | + return FALSE; | |
| 222 | + } | |
| 223 | 223 | } | 
| 224 | 224 | } | 
| 225 | 225 | |
| @@ -228,26 +228,26 @@ discard block | ||
| 228 | 228 | $file = dirname(__FILE__) . '/' . $cf['reportFile']["$type"]; | 
| 229 | 229 | $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; | 
| 230 | 230 |  	$m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) | 
| 231 | - or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); | |
| 231 | + or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); | |
| 232 | 232 | if ( !$m_mail ) exit(254); | 
| 233 | 233 | |
| 234 | 234 | |
| 235 | 235 | syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); | 
| 236 | 236 | //get all messages | 
| 237 | 237 | $dateTh = date ( "d-M-Y", strToTime ( '-'.$cf['oldestday'].' days' ) ); | 
| 238 | - $dateN = date ( "d-M-Y", strToTime ( "now" ) ); | |
| 239 | - $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); | |
| 238 | + $dateN = date ( "d-M-Y", strToTime ( "now" ) ); | |
| 239 | + $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); | |
| 240 | 240 | |
| 241 | 241 | |
| 242 | 242 | // Order results starting from newest message | 
| 243 | 243 |  	if ( empty($m_search) ) { | 
| 244 | 244 | syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); | 
| 245 | - if ( $ierr = imap_errors() ) | |
| 246 | - foreach ( $ierr as $thiserr ) | |
| 247 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 248 | - if ( $ierr = imap_alerts() ) | |
| 249 | - foreach ( $ierr as $thiserr ) | |
| 250 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 245 | + if ( $ierr = imap_errors() ) | |
| 246 | + foreach ( $ierr as $thiserr ) | |
| 247 | + syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 248 | + if ( $ierr = imap_alerts() ) | |
| 249 | + foreach ( $ierr as $thiserr ) | |
| 250 | + syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 251 | 251 | imap_close( $m_mail ); | 
| 252 | 252 | if ( file_exists( $file ) ) unlink ($file); | 
| 253 | 253 | if ( file_exists( $fileb ) ) unlink ($fileb); | 
| @@ -280,16 +280,16 @@ discard block | ||
| 280 | 280 | $uidbad['count'] = 0; | 
| 281 | 281 | $uidbad['uid'] = array(); | 
| 282 | 282 | |
| 283 | - // loop for each message | |
| 283 | + // loop for each message | |
| 284 | 284 |  	foreach ($m_search as $onem) { | 
| 285 | 285 | |
| 286 | - //get imap header info for obj thang | |
| 287 | - //$headers = imap_headerinfo($m_mail, $onem); | |
| 288 | - //$head = imap_fetchheader($m_mail, $headers->Msgno); | |
| 286 | + //get imap header info for obj thang | |
| 287 | + //$headers = imap_headerinfo($m_mail, $onem); | |
| 288 | + //$head = imap_fetchheader($m_mail, $headers->Msgno); | |
| 289 | 289 | $head = imap_fetchheader($m_mail, $onem ); | 
| 290 | - //$obj = imap_rfc822_parse_headers( $head); | |
| 290 | + //$obj = imap_rfc822_parse_headers( $head); | |
| 291 | 291 | |
| 292 | - list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); | |
| 292 | + list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); | |
| 293 | 293 |  		if (empty($mid)) { | 
| 294 | 294 | $uid='NA'; | 
| 295 | 295 | syslog (LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); | 
| @@ -304,11 +304,11 @@ discard block | ||
| 304 | 304 | } | 
| 305 | 305 | } | 
| 306 | 306 | |
| 307 | - /* Update count of each ip */ | |
| 308 | -	        if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers  and learned by valid uid */ | |
| 307 | + /* Update count of each ip */ | |
| 308 | +			if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers  and learned by valid uid */ | |
| 309 | 309 | $ipuid['count']++; //number of right messages | 
| 310 | 310 | |
| 311 | -	                if (in_array($uid,array_keys($ipuid['uid']))) { | |
| 311 | +					if (in_array($uid,array_keys($ipuid['uid']))) { | |
| 312 | 312 | $ipuid['uid']["$uid"]['count']++; //number of learn by this uid | 
| 313 | 313 | if (!in_array($ip,$ipuid['uid']["$uid"])) | 
| 314 | 314 | $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid | 
| @@ -319,29 +319,29 @@ discard block | ||
| 319 | 319 | $ipuid['uid']['count']++; //number of unique uids | 
| 320 | 320 | } | 
| 321 | 321 | |
| 322 | -                        if (in_array($ip,array_keys($ipuid['ip']))) { | |
| 323 | - $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages | |
| 322 | +						if (in_array($ip,array_keys($ipuid['ip']))) { | |
| 323 | + $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages | |
| 324 | 324 | if (!in_array($uid,$ipuid['ip']["$ip"])) | 
| 325 | 325 | $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip | 
| 326 | 326 | } | 
| 327 | -                        else { | |
| 328 | - $ipuid['ip']["$ip"]['count'] = 1; | |
| 327 | +						else { | |
| 328 | + $ipuid['ip']["$ip"]['count'] = 1; | |
| 329 | 329 | $ipuid['ip']["$ip"][]=$uid; | 
| 330 | 330 | $ipuid['ip']['count']++; //number of unique ips | 
| 331 | - } | |
| 331 | + } | |
| 332 | 332 | |
| 333 | - /* Update HTML report */ | |
| 334 | - fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); | |
| 333 | + /* Update HTML report */ | |
| 334 | + fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); | |
| 335 | 335 | } | 
| 336 | -	        else {	/* Bad learn */ | |
| 336 | +			else {	/* Bad learn */ | |
| 337 | 337 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) | |
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid | |
| 340 | -                        else { | |
| 341 | - $uidbad['uid']["$uid"]['count'] = 1; | |
| 338 | + if (in_array($uid,array_keys($uidbad['uid']))) | |
| 339 | + $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid | |
| 340 | +						else { | |
| 341 | + $uidbad['uid']["$uid"]['count'] = 1; | |
| 342 | 342 | $uidbad['uid']["$uid"][]=$uid; | 
| 343 | - $uidbad['count']++; //numeber of unique bad uids | |
| 344 | - } | |
| 343 | + $uidbad['count']++; //numeber of unique bad uids | |
| 344 | + } | |
| 345 | 345 | /* The reason of bad report */ | 
| 346 | 346 | if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; | 
| 347 | 347 | if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; | 
| @@ -363,17 +363,17 @@ discard block | ||
| 363 | 363 | fwrite($fp, '</table>'); | 
| 364 | 364 | fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); | 
| 365 | 365 | |
| 366 | - /* Make MYSQL connection */ | |
| 366 | + /* Make MYSQL connection */ | |
| 367 | 367 | if ( $cf['onlyReport'] ) | 
| 368 | 368 | $mysqli = NULL; | 
| 369 | 369 |  	else { | 
| 370 | - $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); | |
| 371 | -        	if ($mysqli->connect_error) { | |
| 372 | -                	syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 373 | - . $mysqli->connect_error); | |
| 374 | - exit (254); | |
| 375 | - } | |
| 376 | - syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; | |
| 370 | + $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); | |
| 371 | +			if ($mysqli->connect_error) { | |
| 372 | +					syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 373 | + . $mysqli->connect_error); | |
| 374 | + exit (254); | |
| 375 | + } | |
| 376 | + syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; | |
| 377 | 377 | } | 
| 378 | 378 | /***********************/ | 
| 379 | 379 | |
| @@ -393,8 +393,8 @@ discard block | ||
| 393 | 393 | foreach ( $ierr as $thiserr ) | 
| 394 | 394 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | 
| 395 | 395 | if ( $ierr = imap_alerts() ) | 
| 396 | - foreach ( $ierr as $thiserr ) | |
| 397 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 396 | + foreach ( $ierr as $thiserr ) | |
| 397 | + syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 398 | 398 | imap_close($m_mail); | 
| 399 | 399 | } | 
| 400 | 400 | ?> | 
| @@ -1,5 +1,5 @@ discard block | ||
| 1 | 1 | <?php | 
| 2 | -function getIP($header,$mxserver,$msa) { | |
| 2 | +function getIP($header, $mxserver, $msa) { | |
| 3 | 3 | /* Get submission server's IP from header's mail */ | 
| 4 | 4 | /* Each line must end with /r/n */ | 
| 5 | 5 | /* IP is the first one written by your mxserver */ | 
| @@ -7,10 +7,10 @@ discard block | ||
| 7 | 7 | $ip = FALSE; | 
| 8 | 8 | $host = FALSE; | 
| 9 | 9 | $dateR = FALSE; | 
| 10 | -	if ( preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m',$header,$received) ) { | |
| 11 | -		for ($i = count($received[0])-1;$i>=0;$i--) { | |
| 10 | +	if (preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m', $header, $received)) { | |
| 11 | +		for ($i = count($received[0])-1; $i>=0; $i--) { | |
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; | 
| 13 | - if ( preg_match($msa,$received['host'][$i]) ) | |
| 13 | + if (preg_match($msa, $received['host'][$i])) | |
| 14 | 14 | $dateR = $received['date'][$i]; | 
| 15 | 15 |          		foreach ($mxserver as $mx) { | 
| 16 | 16 | if (!$ip) | 
| @@ -21,38 +21,38 @@ discard block | ||
| 21 | 21 | } | 
| 22 | 22 | } | 
| 23 | 23 | } | 
| 24 | -	if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) | |
| 24 | +	if (preg_match('/\r\nDate:\s(?P<date>.*)\r\n/', $header, $dateC) != 1) | |
| 25 | 25 | $dateC['date'] = 'Not found'; | 
| 26 | -	if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) | |
| 26 | +	if (preg_match('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/', $header, $mid) != 1) | |
| 27 | 27 | $mid['mid'] = NULL; | 
| 28 | - return array($ip,$host,$dateR,$dateC['date'],$mid['mid']); | |
| 28 | + return array($ip, $host, $dateR, $dateC['date'], $mid['mid']); | |
| 29 | 29 | } | 
| 30 | 30 | |
| 31 | -function updateReport ($ip,$uid,$ipcount,$uidcount,$hostname,$dateC,$msgid,$dateL) { | |
| 31 | +function updateReport($ip, $uid, $ipcount, $uidcount, $hostname, $dateC, $msgid, $dateL) { | |
| 32 | 32 | |
| 33 | -	return sprintf ('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td>%u</td><td>%u</td><td>%s</td><td>%s</td></tr>'."\n",$dateL,$dateC,$uid,$ip,$uidcount,$ipcount,$hostname,htmlentities($msgid) ); | |
| 33 | +	return sprintf('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td>%u</td><td>%u</td><td>%s</td><td>%s</td></tr>'."\n", $dateL, $dateC, $uid, $ip, $uidcount, $ipcount, $hostname, htmlentities($msgid)); | |
| 34 | 34 | } | 
| 35 | 35 | |
| 36 | -function updatebadReport ( $uid,$dateC,$msgid,$dateL,$text ) { | |
| 37 | -	return sprintf ('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td nowrap>%s</td></tr>'."\n",$dateL,$dateC,$uid,htmlentities($msgid),$text ); | |
| 36 | +function updatebadReport($uid, $dateC, $msgid, $dateL, $text) { | |
| 37 | +	return sprintf('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td nowrap>%s</td></tr>'."\n", $dateL, $dateC, $uid, htmlentities($msgid), $text); | |
| 38 | 38 | } | 
| 39 | 39 | |
| 40 | 40 | |
| 41 | -function summaryBadReport ($uidvet) { | |
| 41 | +function summaryBadReport($uidvet) { | |
| 42 | 42 | $nuid = $uidvet['count']; | 
| 43 | - if ( empty($uidvet) ) return NULL; | |
| 43 | + if (empty($uidvet)) return NULL; | |
| 44 | 44 | $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; | 
| 45 | 45 | |
| 46 | 46 | /* Remove count index */ | 
| 47 | 47 | $uids = array_keys($uidvet['uid']); | 
| 48 | 48 | $totlearn = 0; | 
| 49 | 49 | |
| 50 | -        foreach ( $uids as $uid ) { | |
| 51 | - $totlearn += $uidvet['uid']["$uid"]['count'];; | |
| 52 | -		$return .= sprintf ('<tr><td>%s</td><td>%u</td></tr>',$uid,$uidvet['uid']["$uid"]['count']); | |
| 50 | +        foreach ($uids as $uid) { | |
| 51 | + $totlearn += $uidvet['uid']["$uid"]['count']; ; | |
| 52 | +		$return .= sprintf('<tr><td>%s</td><td>%u</td></tr>', $uid, $uidvet['uid']["$uid"]['count']); | |
| 53 | 53 | } | 
| 54 | -	$return .= sprintf ('<tr><th>%s</th><th>%u</th></tr></table>','TOT',$totlearn); | |
| 55 | -	$return .= sprintf ('<p>%s : %u</p>','Unique UID',$nuid); | |
| 54 | +	$return .= sprintf('<tr><th>%s</th><th>%u</th></tr></table>', 'TOT', $totlearn); | |
| 55 | +	$return .= sprintf('<p>%s : %u</p>', 'Unique UID', $nuid); | |
| 56 | 56 | |
| 57 | 57 | return $return; | 
| 58 | 58 | } | 
| @@ -69,12 +69,12 @@ discard block | ||
| 69 | 69 |      foreach ($cols as $col => $order) { | 
| 70 | 70 | $eval .= '$colarr[\''.$col.'\'],'.$order.','; | 
| 71 | 71 | } | 
| 72 | - $eval = substr($eval,0,-1).');'; | |
| 72 | + $eval = substr($eval, 0, -1).');'; | |
| 73 | 73 | eval($eval); | 
| 74 | 74 | $ret = array(); | 
| 75 | 75 |      foreach ($colarr as $col => $arr) { | 
| 76 | 76 |          foreach ($arr as $k => $v) { | 
| 77 | - $k = substr($k,1); | |
| 77 | + $k = substr($k, 1); | |
| 78 | 78 | if (!isset($ret[$k])) $ret[$k] = $array[$k]; | 
| 79 | 79 | if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; | 
| 80 | 80 | } | 
| @@ -84,29 +84,29 @@ discard block | ||
| 84 | 84 | } | 
| 85 | 85 | |
| 86 | 86 | |
| 87 | -function summaryReportAndList ($cf,$myconn,$tables,$category,$ipvet) { | |
| 87 | +function summaryReportAndList($cf, $myconn, $tables, $category, $ipvet) { | |
| 88 | 88 | $nips = $ipvet['count']; | 
| 89 | 89 | |
| 90 | - if ( empty($ipvet) ) return NULL; | |
| 90 | + if (empty($ipvet)) return NULL; | |
| 91 | 91 | $return = '<h3>Statistics by IP</h3><table><tr><th>IP</th><th>Learned by</th><th>Learned times</th><th title="This field doesn\'t say if this ip is currently listed, but it says if this IP has listed now!">Listed Now</th></tr>'."\n"; | 
| 92 | 92 | |
| 93 | 93 | $ips = array_keys($ipvet['ip']); | 
| 94 | 94 | |
| 95 | -	foreach ( $ips as $ip ) { | |
| 96 | - if ( $ip == 'count' ) continue; | |
| 95 | +	foreach ($ips as $ip) { | |
| 96 | + if ($ip == 'count') continue; | |
| 97 | 97 | $nlearn = $ipvet['ip']["$ip"]['count']; | 
| 98 | 98 | unset($ipvet['ip']["$ip"]['count']); | 
| 99 | 99 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ | 
| 100 | 100 | $nuid = count($ipvet['ip']["$ip"]); | 
| 101 | -		if ( !$cf['onlyReport'] ) { | |
| 102 | -			if ( ($nlearn >= $cf['thresholdip']["$category"])&&($nuid >= $cf['thresholduid']["$category"]) ) { | |
| 101 | +		if (!$cf['onlyReport']) { | |
| 102 | +			if (($nlearn>=$cf['thresholdip']["$category"]) && ($nuid>=$cf['thresholduid']["$category"])) { | |
| 103 | 103 | $reason = "The IP <$ip> has been listed because was marked $nlearn times as $category by $nuid different accounts during last ".$cf['oldestday'].' days.'; | 
| 104 | - $listed = searchAndList ($myconn,$cf['user'],$tables,$cf['list']["$category"],$ip,$cf['unit']["$category"],$quantity,$reason); | |
| 104 | + $listed = searchAndList($myconn, $cf['user'], $tables, $cf['list']["$category"], $ip, $cf['unit']["$category"], $quantity, $reason); | |
| 105 | 105 | } | 
| 106 | 106 | else $listed = FALSE; | 
| 107 | 107 | } | 
| 108 | 108 | else $listed = FALSE; | 
| 109 | - $nowlist = array( TRUE => array( | |
| 109 | + $nowlist = array(TRUE => array( | |
| 110 | 110 | 'style' => 'id=\'ipfound\'', | 
| 111 | 111 | 'name' => 'YES', | 
| 112 | 112 | ), | 
| @@ -120,45 +120,45 @@ discard block | ||
| 120 | 120 | ) | 
| 121 | 121 | ); | 
| 122 | 122 | |
| 123 | - $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; | |
| 124 | -		$return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); | |
| 125 | - $rowuid=NULL; | |
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 123 | + $return .= '<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; | |
| 124 | +		$return .= sprintf('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>', $ipvet['ip']["$ip"][0], $nlearn, $nowlist["$listed"]['name']); | |
| 125 | + $rowuid = NULL; | |
| 126 | + for ($j = 1; $j<$nuid; $j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 127 | 127 | array_shift($ipvet['ip']["$ip"]); | 
| 128 | - $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); | |
| 128 | + $return .= vsprintf($rowuid, $ipvet['ip']["$ip"]); | |
| 129 | 129 | |
| 130 | 130 | } | 
| 131 | -	$return .= sprintf ('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>',$ipvet['ip']['count'],$ipvet['uid']['count'],$nips); | |
| 131 | +	$return .= sprintf('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>', $ipvet['ip']['count'], $ipvet['uid']['count'], $nips); | |
| 132 | 132 | |
| 133 | 133 | |
| 134 | 134 | /* Statistics by UID */ | 
| 135 | 135 | /* Not used for listing purpose, but useful to you! */ | 
| 136 | 136 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; | 
| 137 | 137 | $uids = array_keys($ipvet['uid']); | 
| 138 | -        foreach ( $uids as $uid ) { | |
| 139 | - if ( $uid == 'count' ) continue; | |
| 138 | +        foreach ($uids as $uid) { | |
| 139 | + if ($uid == 'count') continue; | |
| 140 | 140 | $nlearn = $ipvet['uid']["$uid"]['count']; | 
| 141 | - unset ( $ipvet['uid']["$uid"]['count'] ); | |
| 141 | + unset ($ipvet['uid']["$uid"]['count']); | |
| 142 | 142 | $nip = count($ipvet['uid']["$uid"]); | 
| 143 | - $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; | |
| 144 | -		$return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); | |
| 145 | - $rowuid=NULL; | |
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 143 | + $return .= '<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; | |
| 144 | +		$return .= sprintf('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>', $ipvet['uid']["$uid"][0], $nlearn); | |
| 145 | + $rowuid = NULL; | |
| 146 | + for ($j = 1; $j<$nip; $j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 147 | 147 | array_shift($ipvet['uid']["$uid"]); | 
| 148 | - $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); | |
| 148 | + $return .= vsprintf($rowuid, $ipvet['uid']["$uid"]); | |
| 149 | 149 | |
| 150 | 150 | } | 
| 151 | -        $return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips);	 | |
| 151 | +        $return .= sprintf('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>', $ipvet['uid']['count'], $ipvet['ip']['count'], $nips);	 | |
| 152 | 152 | |
| 153 | 153 | |
| 154 | 154 | return $return; | 
| 155 | 155 | } | 
| 156 | 156 | |
| 157 | 157 | |
| 158 | -function splunksearch ($service,$message_id,$date) { | |
| 158 | +function splunksearch($service, $message_id, $date) { | |
| 159 | 159 | |
| 160 | 160 | // Run a blocking search | 
| 161 | - $searchQueryBlocking = 'search (message_id="'. addslashes( $message_id ) . | |
| 161 | + $searchQueryBlocking = 'search (message_id="'.addslashes($message_id). | |
| 162 | 162 | '" OR sasl_username) | transaction message_id queue_id maxspan=3m maxpause=2m | search sasl_username message_id=* | table sasl_username'; | 
| 163 | 163 | |
| 164 | 164 | /* Doesn't work on Splunk 6.6 for HTTP exceptions | 
| @@ -177,8 +177,8 @@ discard block | ||
| 177 | 177 | |
| 178 | 178 | // A one shot search | 
| 179 | 179 | $searchParams = array( | 
| 180 | -                'earliest_time' => date("c",strtotime ($date)-120), | |
| 181 | -                'latest_time' => date("c",strtotime ($date)+60) | |
| 180 | +                'earliest_time' => date("c", strtotime($date)-120), | |
| 181 | +                'latest_time' => date("c", strtotime($date)+60) | |
| 182 | 182 | ); | 
| 183 | 183 | |
| 184 | 184 | // Run a oneshot search that returns the job's results | 
| @@ -192,7 +192,7 @@ discard block | ||
| 192 | 192 |  	    { | 
| 193 | 193 | // More than one field attribute returned by search | 
| 194 | 194 | // You must redefine the search | 
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; | |
| 195 | + if (count($result->getFieldNames())>1) return FALSE; | |
| 196 | 196 | } | 
| 197 | 197 | else if ($result instanceof Splunk_ResultsMessage) | 
| 198 | 198 |  	    { | 
| @@ -224,51 +224,51 @@ discard block | ||
| 224 | 224 | } | 
| 225 | 225 | |
| 226 | 226 | |
| 227 | -function imapReport ($cf,$myconnArray,$splunkconn,$tables,$type) { | |
| 228 | - $file = dirname(__FILE__) . '/' . $cf['reportFile']["$type"]; | |
| 229 | - $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; | |
| 230 | -	$m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) | |
| 231 | - or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); | |
| 232 | - if ( !$m_mail ) exit(254); | |
| 227 | +function imapReport($cf, $myconnArray, $splunkconn, $tables, $type) { | |
| 228 | + $file = dirname(__FILE__).'/'.$cf['reportFile']["$type"]; | |
| 229 | + $fileb = dirname(__FILE__).'/'.$cf['badreportFile']["$type"]; | |
| 230 | +	$m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'], $cf['authpassword'], OP_READONLY) | |
| 231 | + or syslog(LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: '.imap_last_error()); | |
| 232 | + if (!$m_mail) exit(254); | |
| 233 | 233 | |
| 234 | 234 | |
| 235 | - syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); | |
| 235 | + syslog(LOG_INFO, $cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); | |
| 236 | 236 | //get all messages | 
| 237 | - $dateTh = date ( "d-M-Y", strToTime ( '-'.$cf['oldestday'].' days' ) ); | |
| 238 | - $dateN = date ( "d-M-Y", strToTime ( "now" ) ); | |
| 239 | - $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); | |
| 237 | +	$dateTh = date("d-M-Y", strToTime('-'.$cf['oldestday'].' days')); | |
| 238 | +        $dateN = date("d-M-Y", strToTime("now")); | |
| 239 | + $m_search = imap_search($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\""); | |
| 240 | 240 | |
| 241 | 241 | |
| 242 | 242 | // Order results starting from newest message | 
| 243 | -	if ( empty($m_search) ) { | |
| 244 | - syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); | |
| 245 | - if ( $ierr = imap_errors() ) | |
| 246 | - foreach ( $ierr as $thiserr ) | |
| 247 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 248 | - if ( $ierr = imap_alerts() ) | |
| 249 | - foreach ( $ierr as $thiserr ) | |
| 250 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 251 | - imap_close( $m_mail ); | |
| 252 | - if ( file_exists( $file ) ) unlink ($file); | |
| 253 | - if ( file_exists( $fileb ) ) unlink ($fileb); | |
| 243 | +	if (empty($m_search)) { | |
| 244 | + syslog(LOG_INFO, $cf['user'].": No mail found in $type folder. No reports written for $type."); | |
| 245 | + if ($ierr = imap_errors()) | |
| 246 | + foreach ($ierr as $thiserr) | |
| 247 | + syslog(LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 248 | + if ($ierr = imap_alerts()) | |
| 249 | + foreach ($ierr as $thiserr) | |
| 250 | + syslog(LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 251 | + imap_close($m_mail); | |
| 252 | + if (file_exists($file)) unlink($file); | |
| 253 | + if (file_exists($fileb)) unlink($fileb); | |
| 254 | 254 | return FALSE; | 
| 255 | 255 | } | 
| 256 | - $nmes = count ($m_search); | |
| 257 | - syslog (LOG_INFO,$cf['user'].": Found $nmes mail in $type folder."); | |
| 256 | + $nmes = count($m_search); | |
| 257 | + syslog(LOG_INFO, $cf['user'].": Found $nmes mail in $type folder."); | |
| 258 | 258 | if ($nmes>0) rsort($m_search); | 
| 259 | 259 | |
| 260 | 260 | // Create report file | 
| 261 | 261 | |
| 262 | 262 | $fp = fopen($file, 'w'); | 
| 263 | - $fpb= fopen($fileb, 'w'); | |
| 264 | -	$lastup = "Last Update: " . date ("d F Y H:i", time()); | |
| 265 | - fwrite( $fp, file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); | |
| 266 | - fwrite( $fp,"<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); | |
| 267 | - if ($cf['onlyReport']) fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); | |
| 268 | - fwrite( $fp,'<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>' ); | |
| 269 | - fwrite( $fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); | |
| 270 | - fwrite( $fpb,"<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); | |
| 271 | - fwrite( $fpb,'<table><tr><th title="taken from Received header" nowrap>Date Learn</th><th title="taken from Date header" nowrap>Date Received</th><th nowrap>UID</th><th>Message-Id</th><th title="Why is this a bad report?">Reason</th></tr>' ); | |
| 263 | + $fpb = fopen($fileb, 'w'); | |
| 264 | +	$lastup = "Last Update: ".date("d F Y H:i", time()); | |
| 265 | + fwrite($fp, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateHeader'])); | |
| 266 | + fwrite($fp, "<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>"); | |
| 267 | + if ($cf['onlyReport']) fwrite($fp, '<p>None of the below IP has been listed because listing is not active in configuration.</p>'); | |
| 268 | + fwrite($fp, '<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>'); | |
| 269 | + fwrite($fpb, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateHeader'])); | |
| 270 | + fwrite($fpb, "<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>"); | |
| 271 | + fwrite($fpb, '<table><tr><th title="taken from Received header" nowrap>Date Learn</th><th title="taken from Date header" nowrap>Date Received</th><th nowrap>UID</th><th>Message-Id</th><th title="Why is this a bad report?">Reason</th></tr>'); | |
| 272 | 272 | |
| 273 | 273 | $ipuid = array(); | 
| 274 | 274 | $ipuid['count'] = 0; | 
| @@ -286,69 +286,69 @@ discard block | ||
| 286 | 286 | //get imap header info for obj thang | 
| 287 | 287 | //$headers = imap_headerinfo($m_mail, $onem); | 
| 288 | 288 | //$head = imap_fetchheader($m_mail, $headers->Msgno); | 
| 289 | - $head = imap_fetchheader($m_mail, $onem ); | |
| 289 | + $head = imap_fetchheader($m_mail, $onem); | |
| 290 | 290 | //$obj = imap_rfc822_parse_headers( $head); | 
| 291 | 291 | |
| 292 | - list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); | |
| 292 | + list ($ip, $host, $dateReceived, $dateClient, $mid) = getIP($head, $cf['mx'], $cf['msalearn']); | |
| 293 | 293 |  		if (empty($mid)) { | 
| 294 | - $uid='NA'; | |
| 295 | - syslog (LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); | |
| 296 | -		} else { | |
| 294 | + $uid = 'NA'; | |
| 295 | + syslog(LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); | |
| 296 | +		}else { | |
| 297 | 297 |  			if ($dateReceived === FALSE) { | 
| 298 | - $uid='unauthenticated'; | |
| 299 | - syslog (LOG_ERR, $cf['user'].": Error retrieving date for $mid. Maybe this mail was not submitted to Learner MSA"); | |
| 300 | - } else | |
| 301 | -				if ( !($uid = splunksearch ($splunkconn, trim($mid,'<>'), $dateReceived)) ) { | |
| 302 | - syslog (LOG_ERR, $cf['user'].": Error retrieving uid from Splunk log for $mid."); | |
| 303 | - $uid='unknown'; | |
| 298 | + $uid = 'unauthenticated'; | |
| 299 | + syslog(LOG_ERR, $cf['user'].": Error retrieving date for $mid. Maybe this mail was not submitted to Learner MSA"); | |
| 300 | + }else | |
| 301 | +				if (!($uid = splunksearch($splunkconn, trim($mid, '<>'), $dateReceived))) { | |
| 302 | + syslog(LOG_ERR, $cf['user'].": Error retrieving uid from Splunk log for $mid."); | |
| 303 | + $uid = 'unknown'; | |
| 304 | 304 | } | 
| 305 | 305 | } | 
| 306 | 306 | |
| 307 | 307 | /* Update count of each ip */ | 
| 308 | -	        if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers  and learned by valid uid */ | |
| 309 | - $ipuid['count']++; //number of right messages | |
| 308 | +	        if ($host and ($uid != 'NA') and ($uid != 'unauthenticated') and ($uid != 'unknown')) { /* IP is received by MX servers  and learned by valid uid */ | |
| 309 | + $ipuid['count']++; //number of right messages | |
| 310 | 310 | |
| 311 | -	                if (in_array($uid,array_keys($ipuid['uid']))) { | |
| 312 | - $ipuid['uid']["$uid"]['count']++; //number of learn by this uid | |
| 313 | - if (!in_array($ip,$ipuid['uid']["$uid"])) | |
| 314 | - $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid | |
| 311 | +	                if (in_array($uid, array_keys($ipuid['uid']))) { | |
| 312 | + $ipuid['uid']["$uid"]['count']++; //number of learn by this uid | |
| 313 | + if (!in_array($ip, $ipuid['uid']["$uid"])) | |
| 314 | + $ipuid['uid']["$uid"][] = $ip; //ips learned by this uid | |
| 315 | 315 | } | 
| 316 | 316 |  			else { | 
| 317 | 317 | $ipuid['uid']["$uid"]['count'] = 1; | 
| 318 | - $ipuid['uid']["$uid"][]=$ip; | |
| 319 | - $ipuid['uid']['count']++; //number of unique uids | |
| 318 | + $ipuid['uid']["$uid"][] = $ip; | |
| 319 | + $ipuid['uid']['count']++; //number of unique uids | |
| 320 | 320 | } | 
| 321 | 321 | |
| 322 | -                        if (in_array($ip,array_keys($ipuid['ip']))) { | |
| 323 | - $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages | |
| 324 | - if (!in_array($uid,$ipuid['ip']["$ip"])) | |
| 325 | - $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip | |
| 322 | +                        if (in_array($ip, array_keys($ipuid['ip']))) { | |
| 323 | + $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages | |
| 324 | + if (!in_array($uid, $ipuid['ip']["$ip"])) | |
| 325 | + $ipuid['ip']["$ip"][] = $uid; //uids that learned this ip | |
| 326 | 326 | } | 
| 327 | 327 |                          else { | 
| 328 | 328 | $ipuid['ip']["$ip"]['count'] = 1; | 
| 329 | - $ipuid['ip']["$ip"][]=$uid; | |
| 330 | - $ipuid['ip']['count']++; //number of unique ips | |
| 329 | + $ipuid['ip']["$ip"][] = $uid; | |
| 330 | + $ipuid['ip']['count']++; //number of unique ips | |
| 331 | 331 | } | 
| 332 | 332 | |
| 333 | 333 | /* Update HTML report */ | 
| 334 | - fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); | |
| 334 | + fwrite($fp, updateReport($ip, $uid, $ipuid['ip']["$ip"]['count'], $ipuid['uid']["$uid"]['count'], $host, $dateClient, $mid, $dateReceived)); | |
| 335 | 335 | } | 
| 336 | 336 |  	        else {	/* Bad learn */ | 
| 337 | 337 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) | |
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid | |
| 338 | + if (in_array($uid, array_keys($uidbad['uid']))) | |
| 339 | + $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid | |
| 340 | 340 |                          else { | 
| 341 | 341 | $uidbad['uid']["$uid"]['count'] = 1; | 
| 342 | - $uidbad['uid']["$uid"][]=$uid; | |
| 343 | - $uidbad['count']++; //numeber of unique bad uids | |
| 342 | + $uidbad['uid']["$uid"][] = $uid; | |
| 343 | + $uidbad['count']++; //numeber of unique bad uids | |
| 344 | 344 | } | 
| 345 | 345 | /* The reason of bad report */ | 
| 346 | 346 | if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; | 
| 347 | 347 | if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; | 
| 348 | - if ($uid=='unknown') $reason = 'The uid of this mail was not found in splunk log'; | |
| 348 | + if ($uid == 'unknown') $reason = 'The uid of this mail was not found in splunk log'; | |
| 349 | 349 | if (!isset($reason)) $reason = '?'; | 
| 350 | 350 | |
| 351 | - fwrite( $fpb,updatebadReport ( $uid,$dateClient,$mid,$dateReceived,$reason ) ); | |
| 351 | + fwrite($fpb, updatebadReport($uid, $dateClient, $mid, $dateReceived, $reason)); | |
| 352 | 352 | } | 
| 353 | 353 | } | 
| 354 | 354 | |
| @@ -356,45 +356,45 @@ discard block | ||
| 356 | 356 | //close report file and mailbox | 
| 357 | 357 | |
| 358 | 358 | /* Summary Report */ | 
| 359 | -	$ipuid['ip'] = array_msort( $ipuid['ip'], array('count'=>SORT_DESC) ); | |
| 360 | -	$ipuid['uid'] = array_msort( $ipuid['uid'], array('count'=>SORT_DESC) ); | |
| 361 | -	$uidbad['uid'] = array_msort( $uidbad['uid'], array('count'=>SORT_DESC) ); | |
| 359 | +	$ipuid['ip'] = array_msort($ipuid['ip'], array('count'=>SORT_DESC)); | |
| 360 | +	$ipuid['uid'] = array_msort($ipuid['uid'], array('count'=>SORT_DESC)); | |
| 361 | +	$uidbad['uid'] = array_msort($uidbad['uid'], array('count'=>SORT_DESC)); | |
| 362 | 362 | |
| 363 | 363 | fwrite($fp, '</table>'); | 
| 364 | - fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); | |
| 364 | + fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>'); | |
| 365 | 365 | |
| 366 | 366 | /* Make MYSQL connection */ | 
| 367 | - if ( $cf['onlyReport'] ) | |
| 367 | + if ($cf['onlyReport']) | |
| 368 | 368 | $mysqli = NULL; | 
| 369 | 369 |  	else { | 
| 370 | 370 | $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); | 
| 371 | 371 |          	if ($mysqli->connect_error) { | 
| 372 | -                	syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 372 | +                	syslog(LOG_EMERG, $cf['user'].': Connect Error ('.$mysqli->connect_errno.') ' | |
| 373 | 373 | . $mysqli->connect_error); | 
| 374 | 374 | exit (254); | 
| 375 | 375 | } | 
| 376 | - syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; | |
| 376 | + syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to '.$mysqli->host_info); | |
| 377 | 377 | } | 
| 378 | 378 | /***********************/ | 
| 379 | 379 | |
| 380 | - fwrite($fp, summaryReportAndList ($cf,$mysqli,$tables,$type,$ipuid) ); | |
| 381 | - if ( !$cf['onlyReport'] ) | |
| 380 | + fwrite($fp, summaryReportAndList($cf, $mysqli, $tables, $type, $ipuid)); | |
| 381 | + if (!$cf['onlyReport']) | |
| 382 | 382 | $mysqli->close(); | 
| 383 | - fwrite($fp,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); | |
| 383 | + fwrite($fp, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateFooter'])); | |
| 384 | 384 | fclose($fp); | 
| 385 | 385 | |
| 386 | 386 | fwrite($fpb, '</table>'); | 
| 387 | - fwrite( $fpb,summaryBadReport( $uidbad ) ); | |
| 388 | - fwrite($fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); | |
| 387 | + fwrite($fpb, summaryBadReport($uidbad)); | |
| 388 | + fwrite($fpb, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateFooter'])); | |
| 389 | 389 | fclose($fpb); | 
| 390 | - syslog (LOG_INFO,$cf['user'].': Report files written. Listing job for '.$type.' terminated.'); | |
| 391 | - | |
| 392 | - if ( $ierr = imap_errors() ) | |
| 393 | - foreach ( $ierr as $thiserr ) | |
| 394 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 395 | - if ( $ierr = imap_alerts() ) | |
| 396 | - foreach ( $ierr as $thiserr ) | |
| 397 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 390 | + syslog(LOG_INFO, $cf['user'].': Report files written. Listing job for '.$type.' terminated.'); | |
| 391 | + | |
| 392 | + if ($ierr = imap_errors()) | |
| 393 | + foreach ($ierr as $thiserr) | |
| 394 | + syslog(LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | |
| 395 | + if ($ierr = imap_alerts()) | |
| 396 | + foreach ($ierr as $thiserr) | |
| 397 | + syslog(LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | |
| 398 | 398 | imap_close($m_mail); | 
| 399 | 399 | } | 
| 400 | 400 | ?> | 
| @@ -10,21 +10,25 @@ discard block | ||
| 10 | 10 |  	if ( preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m',$header,$received) ) { | 
| 11 | 11 |  		for ($i = count($received[0])-1;$i>=0;$i--) { | 
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; | 
| 13 | - if ( preg_match($msa,$received['host'][$i]) ) | |
| 14 | - $dateR = $received['date'][$i]; | |
| 13 | +			if ( preg_match($msa,$received['host'][$i]) ) { | |
| 14 | + $dateR = $received['date'][$i]; | |
| 15 | + } | |
| 15 | 16 |          		foreach ($mxserver as $mx) { | 
| 16 | - if (!$ip) | |
| 17 | -					if ($mx == $received['host'][$i]) { | |
| 17 | +        			if (!$ip) { | |
| 18 | +        								if ($mx == $received['host'][$i]) { | |
| 18 | 19 | $host = $received['host'][$i]; | 
| 20 | + } | |
| 19 | 21 | $ip = $received['ip'][$i]; | 
| 20 | 22 | } | 
| 21 | 23 | } | 
| 22 | 24 | } | 
| 23 | 25 | } | 
| 24 | -	if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) | |
| 25 | - $dateC['date'] = 'Not found'; | |
| 26 | -	if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) | |
| 27 | - $mid['mid'] = NULL; | |
| 26 | +	if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) { | |
| 27 | + $dateC['date'] = 'Not found'; | |
| 28 | + } | |
| 29 | +	if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) { | |
| 30 | + $mid['mid'] = NULL; | |
| 31 | + } | |
| 28 | 32 | return array($ip,$host,$dateR,$dateC['date'],$mid['mid']); | 
| 29 | 33 | } | 
| 30 | 34 | |
| @@ -40,7 +44,9 @@ discard block | ||
| 40 | 44 | |
| 41 | 45 |  function summaryBadReport ($uidvet) { | 
| 42 | 46 | $nuid = $uidvet['count']; | 
| 43 | - if ( empty($uidvet) ) return NULL; | |
| 47 | +        if ( empty($uidvet) ) { | |
| 48 | + return NULL; | |
| 49 | + } | |
| 44 | 50 | $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; | 
| 45 | 51 | |
| 46 | 52 | /* Remove count index */ | 
| @@ -75,8 +81,12 @@ discard block | ||
| 75 | 81 |      foreach ($colarr as $col => $arr) { | 
| 76 | 82 |          foreach ($arr as $k => $v) { | 
| 77 | 83 | $k = substr($k,1); | 
| 78 | - if (!isset($ret[$k])) $ret[$k] = $array[$k]; | |
| 79 | - if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; | |
| 84 | +            if (!isset($ret[$k])) { | |
| 85 | + $ret[$k] = $array[$k]; | |
| 86 | + } | |
| 87 | +            if (isset ($array[$k][$col])) { | |
| 88 | + $ret[$k][$col] = $array[$k][$col]; | |
| 89 | + } | |
| 80 | 90 | } | 
| 81 | 91 | } | 
| 82 | 92 | return $ret; | 
| @@ -87,13 +97,17 @@ discard block | ||
| 87 | 97 |  function summaryReportAndList ($cf,$myconn,$tables,$category,$ipvet) { | 
| 88 | 98 | $nips = $ipvet['count']; | 
| 89 | 99 | |
| 90 | - if ( empty($ipvet) ) return NULL; | |
| 100 | +	if ( empty($ipvet) ) { | |
| 101 | + return NULL; | |
| 102 | + } | |
| 91 | 103 | $return = '<h3>Statistics by IP</h3><table><tr><th>IP</th><th>Learned by</th><th>Learned times</th><th title="This field doesn\'t say if this ip is currently listed, but it says if this IP has listed now!">Listed Now</th></tr>'."\n"; | 
| 92 | 104 | |
| 93 | 105 | $ips = array_keys($ipvet['ip']); | 
| 94 | 106 | |
| 95 | 107 |  	foreach ( $ips as $ip ) { | 
| 96 | - if ( $ip == 'count' ) continue; | |
| 108 | +		if ( $ip == 'count' ) { | |
| 109 | + continue; | |
| 110 | + } | |
| 97 | 111 | $nlearn = $ipvet['ip']["$ip"]['count']; | 
| 98 | 112 | unset($ipvet['ip']["$ip"]['count']); | 
| 99 | 113 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ | 
| @@ -102,10 +116,12 @@ discard block | ||
| 102 | 116 |  			if ( ($nlearn >= $cf['thresholdip']["$category"])&&($nuid >= $cf['thresholduid']["$category"]) ) { | 
| 103 | 117 | $reason = "The IP <$ip> has been listed because was marked $nlearn times as $category by $nuid different accounts during last ".$cf['oldestday'].' days.'; | 
| 104 | 118 | $listed = searchAndList ($myconn,$cf['user'],$tables,$cf['list']["$category"],$ip,$cf['unit']["$category"],$quantity,$reason); | 
| 119 | +			} else { | |
| 120 | + $listed = FALSE; | |
| 105 | 121 | } | 
| 106 | - else $listed = FALSE; | |
| 122 | +		} else { | |
| 123 | + $listed = FALSE; | |
| 107 | 124 | } | 
| 108 | - else $listed = FALSE; | |
| 109 | 125 | $nowlist = array( TRUE => array( | 
| 110 | 126 | 'style' => 'id=\'ipfound\'', | 
| 111 | 127 | 'name' => 'YES', | 
| @@ -123,7 +139,9 @@ discard block | ||
| 123 | 139 | $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; | 
| 124 | 140 |  		$return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); | 
| 125 | 141 | $rowuid=NULL; | 
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 142 | +                for ($j=1;$j<$nuid;$j++) { | |
| 143 | + $rowuid .= '<tr><td>%s</td></tr>'; | |
| 144 | + } | |
| 127 | 145 | array_shift($ipvet['ip']["$ip"]); | 
| 128 | 146 | $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); | 
| 129 | 147 | |
| @@ -136,14 +154,18 @@ discard block | ||
| 136 | 154 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; | 
| 137 | 155 | $uids = array_keys($ipvet['uid']); | 
| 138 | 156 |          foreach ( $uids as $uid ) { | 
| 139 | - if ( $uid == 'count' ) continue; | |
| 157 | +		if ( $uid == 'count' ) { | |
| 158 | + continue; | |
| 159 | + } | |
| 140 | 160 | $nlearn = $ipvet['uid']["$uid"]['count']; | 
| 141 | 161 | unset ( $ipvet['uid']["$uid"]['count'] ); | 
| 142 | 162 | $nip = count($ipvet['uid']["$uid"]); | 
| 143 | 163 | $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; | 
| 144 | 164 |  		$return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); | 
| 145 | 165 | $rowuid=NULL; | 
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; | |
| 166 | +                for ($j=1;$j<$nip;$j++) { | |
| 167 | + $rowuid .= '<tr><td>%s</td></tr>'; | |
| 168 | + } | |
| 147 | 169 | array_shift($ipvet['uid']["$uid"]); | 
| 148 | 170 | $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); | 
| 149 | 171 | |
| @@ -192,14 +214,14 @@ discard block | ||
| 192 | 214 |  	    { | 
| 193 | 215 | // More than one field attribute returned by search | 
| 194 | 216 | // You must redefine the search | 
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; | |
| 196 | - } | |
| 197 | - else if ($result instanceof Splunk_ResultsMessage) | |
| 217 | +	      if ( count($result->getFieldNames()) > 1 ) { | |
| 218 | + return FALSE; | |
| 219 | + } | |
| 220 | + } else if ($result instanceof Splunk_ResultsMessage) | |
| 198 | 221 |  	    { | 
| 199 | 222 | // I don't want messages in my search | 
| 200 | 223 | return FALSE; | 
| 201 | - } | |
| 202 | - else if (is_array($result)) | |
| 224 | + } else if (is_array($result)) | |
| 203 | 225 |  	    { | 
| 204 | 226 | // Process a row | 
| 205 | 227 | foreach ($result as $key => $valueOrValues) | 
| @@ -207,15 +229,13 @@ discard block | ||
| 207 | 229 | if (is_array($valueOrValues)) | 
| 208 | 230 |  	          { | 
| 209 | 231 | return FALSE; | 
| 210 | - } | |
| 211 | - else | |
| 232 | + } else | |
| 212 | 233 |  	          { | 
| 213 | 234 | return $valueOrValues; | 
| 214 | 235 |  	            #print "  {$key} => {$value}\r\n"; | 
| 215 | 236 | } | 
| 216 | 237 | } | 
| 217 | - } | |
| 218 | - else | |
| 238 | + } else | |
| 219 | 239 |  	    { | 
| 220 | 240 | #print "Unknow result type"; | 
| 221 | 241 | return FALSE; | 
| @@ -229,7 +249,9 @@ discard block | ||
| 229 | 249 | $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; | 
| 230 | 250 |  	$m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) | 
| 231 | 251 | or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); | 
| 232 | - if ( !$m_mail ) exit(254); | |
| 252 | +	if ( !$m_mail ) { | |
| 253 | + exit(254); | |
| 254 | + } | |
| 233 | 255 | |
| 234 | 256 | |
| 235 | 257 | syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); | 
| @@ -242,20 +264,28 @@ discard block | ||
| 242 | 264 | // Order results starting from newest message | 
| 243 | 265 |  	if ( empty($m_search) ) { | 
| 244 | 266 | syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); | 
| 245 | - if ( $ierr = imap_errors() ) | |
| 246 | - foreach ( $ierr as $thiserr ) | |
| 267 | +	        if ( $ierr = imap_errors() ) { | |
| 268 | + foreach ( $ierr as $thiserr ) | |
| 247 | 269 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | 
| 248 | - if ( $ierr = imap_alerts() ) | |
| 249 | - foreach ( $ierr as $thiserr ) | |
| 270 | + } | |
| 271 | +	        if ( $ierr = imap_alerts() ) { | |
| 272 | + foreach ( $ierr as $thiserr ) | |
| 250 | 273 | syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | 
| 274 | + } | |
| 251 | 275 | imap_close( $m_mail ); | 
| 252 | - if ( file_exists( $file ) ) unlink ($file); | |
| 253 | - if ( file_exists( $fileb ) ) unlink ($fileb); | |
| 276 | +		if ( file_exists( $file ) ) { | |
| 277 | + unlink ($file); | |
| 278 | + } | |
| 279 | +		if ( file_exists( $fileb ) ) { | |
| 280 | + unlink ($fileb); | |
| 281 | + } | |
| 254 | 282 | return FALSE; | 
| 255 | 283 | } | 
| 256 | 284 | $nmes = count ($m_search); | 
| 257 | 285 | syslog (LOG_INFO,$cf['user'].": Found $nmes mail in $type folder."); | 
| 258 | - if ($nmes>0) rsort($m_search); | |
| 286 | +	if ($nmes>0) { | |
| 287 | + rsort($m_search); | |
| 288 | + } | |
| 259 | 289 | |
| 260 | 290 | // Create report file | 
| 261 | 291 | |
| @@ -264,7 +294,9 @@ discard block | ||
| 264 | 294 |  	$lastup = "Last Update: " . date ("d F Y H:i", time()); | 
| 265 | 295 | fwrite( $fp, file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); | 
| 266 | 296 | fwrite( $fp,"<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); | 
| 267 | - if ($cf['onlyReport']) fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); | |
| 297 | +	if ($cf['onlyReport']) { | |
| 298 | + fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); | |
| 299 | + } | |
| 268 | 300 | fwrite( $fp,'<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>' ); | 
| 269 | 301 | fwrite( $fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); | 
| 270 | 302 | fwrite( $fpb,"<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); | 
| @@ -310,10 +342,11 @@ discard block | ||
| 310 | 342 | |
| 311 | 343 |  	                if (in_array($uid,array_keys($ipuid['uid']))) { | 
| 312 | 344 | $ipuid['uid']["$uid"]['count']++; //number of learn by this uid | 
| 313 | - if (!in_array($ip,$ipuid['uid']["$uid"])) | |
| 314 | - $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid | |
| 315 | - } | |
| 316 | -			else { | |
| 345 | +				if (!in_array($ip,$ipuid['uid']["$uid"])) { | |
| 346 | + $ipuid['uid']["$uid"][]=$ip; | |
| 347 | + } | |
| 348 | + //ips learned by this uid | |
| 349 | +			} else { | |
| 317 | 350 | $ipuid['uid']["$uid"]['count'] = 1; | 
| 318 | 351 | $ipuid['uid']["$uid"][]=$ip; | 
| 319 | 352 | $ipuid['uid']['count']++; //number of unique uids | 
| @@ -321,10 +354,11 @@ discard block | ||
| 321 | 354 | |
| 322 | 355 |                          if (in_array($ip,array_keys($ipuid['ip']))) { | 
| 323 | 356 | $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages | 
| 324 | - if (!in_array($uid,$ipuid['ip']["$ip"])) | |
| 325 | - $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip | |
| 326 | - } | |
| 327 | -                        else { | |
| 357 | +				if (!in_array($uid,$ipuid['ip']["$ip"])) { | |
| 358 | + $ipuid['ip']["$ip"][]=$uid; | |
| 359 | + } | |
| 360 | + //uids that learned this ip | |
| 361 | +			} else { | |
| 328 | 362 | $ipuid['ip']["$ip"]['count'] = 1; | 
| 329 | 363 | $ipuid['ip']["$ip"][]=$uid; | 
| 330 | 364 | $ipuid['ip']['count']++; //number of unique ips | 
| @@ -332,21 +366,30 @@ discard block | ||
| 332 | 366 | |
| 333 | 367 | /* Update HTML report */ | 
| 334 | 368 | fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); | 
| 335 | - } | |
| 336 | -	        else {	/* Bad learn */ | |
| 369 | +		} else {	/* Bad learn */ | |
| 337 | 370 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) | |
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid | |
| 371 | +                        if (in_array($uid,array_keys($uidbad['uid']))) { | |
| 372 | + $uidbad['uid']["$uid"]['count']++; | |
| 373 | + } | |
| 374 | + //number of bad learn by this uid | |
| 340 | 375 |                          else { | 
| 341 | 376 | $uidbad['uid']["$uid"]['count'] = 1; | 
| 342 | 377 | $uidbad['uid']["$uid"][]=$uid; | 
| 343 | 378 | $uidbad['count']++; //numeber of unique bad uids | 
| 344 | 379 | } | 
| 345 | 380 | /* The reason of bad report */ | 
| 346 | - if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; | |
| 347 | - if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; | |
| 348 | - if ($uid=='unknown') $reason = 'The uid of this mail was not found in splunk log'; | |
| 349 | - if (!isset($reason)) $reason = '?'; | |
| 381 | +			if ($host === FALSE) { | |
| 382 | + $reason = 'This mail was not received by recognized MX host'; | |
| 383 | + } | |
| 384 | +			if ($dateReceived === FALSE) { | |
| 385 | + $reason = 'This mail was not submitted to recognized MSA for learn'; | |
| 386 | + } | |
| 387 | +			if ($uid=='unknown') { | |
| 388 | + $reason = 'The uid of this mail was not found in splunk log'; | |
| 389 | + } | |
| 390 | +			if (!isset($reason)) { | |
| 391 | + $reason = '?'; | |
| 392 | + } | |
| 350 | 393 | |
| 351 | 394 | fwrite( $fpb,updatebadReport ( $uid,$dateClient,$mid,$dateReceived,$reason ) ); | 
| 352 | 395 | } | 
| @@ -364,9 +407,9 @@ discard block | ||
| 364 | 407 | fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); | 
| 365 | 408 | |
| 366 | 409 | /* Make MYSQL connection */ | 
| 367 | - if ( $cf['onlyReport'] ) | |
| 368 | - $mysqli = NULL; | |
| 369 | -	else { | |
| 410 | +	if ( $cf['onlyReport'] ) { | |
| 411 | + $mysqli = NULL; | |
| 412 | +	} else { | |
| 370 | 413 | $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); | 
| 371 | 414 |          	if ($mysqli->connect_error) { | 
| 372 | 415 |                  	syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' | 
| @@ -378,8 +421,9 @@ discard block | ||
| 378 | 421 | /***********************/ | 
| 379 | 422 | |
| 380 | 423 | fwrite($fp, summaryReportAndList ($cf,$mysqli,$tables,$type,$ipuid) ); | 
| 381 | - if ( !$cf['onlyReport'] ) | |
| 382 | - $mysqli->close(); | |
| 424 | +	if ( !$cf['onlyReport'] ) { | |
| 425 | + $mysqli->close(); | |
| 426 | + } | |
| 383 | 427 | fwrite($fp,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); | 
| 384 | 428 | fclose($fp); | 
| 385 | 429 | |
| @@ -389,12 +433,14 @@ discard block | ||
| 389 | 433 | fclose($fpb); | 
| 390 | 434 | syslog (LOG_INFO,$cf['user'].': Report files written. Listing job for '.$type.' terminated.'); | 
| 391 | 435 | |
| 392 | - if ( $ierr = imap_errors() ) | |
| 393 | - foreach ( $ierr as $thiserr ) | |
| 436 | +	if ( $ierr = imap_errors() ) { | |
| 437 | + foreach ( $ierr as $thiserr ) | |
| 394 | 438 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); | 
| 395 | - if ( $ierr = imap_alerts() ) | |
| 396 | - foreach ( $ierr as $thiserr ) | |
| 439 | + } | |
| 440 | +	if ( $ierr = imap_alerts() ) { | |
| 441 | + foreach ( $ierr as $thiserr ) | |
| 397 | 442 | syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); | 
| 443 | + } | |
| 398 | 444 | imap_close($m_mail); | 
| 399 | 445 | } | 
| 400 | 446 | ?> | 
| @@ -47,8 +47,8 @@ discard block | ||
| 47 | 47 | |
| 48 | 48 | /* check you select a blocklist */ | 
| 49 | 49 |  if ( !$tables["$typedesc"]['bl'] ) { | 
| 50 | - syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); | |
| 51 | - exit (254); | |
| 50 | + syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); | |
| 51 | + exit (254); | |
| 52 | 52 | } | 
| 53 | 53 | |
| 54 | 54 | |
| @@ -68,33 +68,33 @@ discard block | ||
| 68 | 68 | $tolist = array(); | 
| 69 | 69 | |
| 70 | 70 |  if ( !file_exists($splfile) ) { | 
| 71 | - syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); | |
| 72 | - exit (254); | |
| 71 | + syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); | |
| 72 | + exit (254); | |
| 73 | 73 | } | 
| 74 | 74 | |
| 75 | 75 |  if (($handle = gzopen($splfile, 'r')) !== FALSE) { | 
| 76 | - $row = -1; | |
| 77 | -        while (($data = fgetcsv($handle, 500, ',')) !== FALSE) { | |
| 78 | - $row++; | |
| 79 | - if ($row == 0) continue; /* Skip heading line */ | |
| 80 | - $thisVal = $data[1]; | |
| 81 | - unset($data[1]); | |
| 82 | - $data = array_values($data); | |
| 83 | - if ( !in_array($thisVal,array_keys($tolist)) ) | |
| 84 | - $tolist["$thisVal"] = $data; | |
| 85 | - else if ($data[3]>$tolist[$thisVal][3]) | |
| 86 | - $tolist["$thisVal"] = $data; | |
| 87 | - } | |
| 88 | - fclose($handle); | |
| 76 | + $row = -1; | |
| 77 | +		while (($data = fgetcsv($handle, 500, ',')) !== FALSE) { | |
| 78 | + $row++; | |
| 79 | + if ($row == 0) continue; /* Skip heading line */ | |
| 80 | + $thisVal = $data[1]; | |
| 81 | + unset($data[1]); | |
| 82 | + $data = array_values($data); | |
| 83 | + if ( !in_array($thisVal,array_keys($tolist)) ) | |
| 84 | + $tolist["$thisVal"] = $data; | |
| 85 | + else if ($data[3]>$tolist[$thisVal][3]) | |
| 86 | + $tolist["$thisVal"] = $data; | |
| 87 | + } | |
| 88 | + fclose($handle); | |
| 89 | 89 | } | 
| 90 | 90 | |
| 91 | 91 | /* Make MYSQL connection */ | 
| 92 | 92 | |
| 93 | 93 | $mysqli = new mysqli($dbhost, $userdb, $pwd, $db, $dbport); | 
| 94 | 94 |  if ($mysqli->connect_error) { | 
| 95 | -        syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 96 | - . $mysqli->connect_error); | |
| 97 | - exit (254); | |
| 95 | +		syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 96 | + . $mysqli->connect_error); | |
| 97 | + exit (254); | |
| 98 | 98 | |
| 99 | 99 | } | 
| 100 | 100 | |
| @@ -103,28 +103,28 @@ discard block | ||
| 103 | 103 |  foreach ( array_keys($tolist) as $value) { | 
| 104 | 104 | $quantity = $conf['quantity']; | 
| 105 | 105 | $reason = 'On ['.$tolist["$value"][0]."] <$value> sent ".$tolist["$value"][1].' messages to '.$tolist["$value"][2].' recipients.'; | 
| 106 | -        if ( $tolist["$value"][3] >= $threshold ) { | |
| 107 | -                if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { | |
| 108 | - syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); | |
| 109 | - /* Send a email to domain admin if you list an email */ | |
| 110 | -                        if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { | |
| 106 | +		if ( $tolist["$value"][3] >= $threshold ) { | |
| 107 | +				if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { | |
| 108 | + syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); | |
| 109 | + /* Send a email to domain admin if you list an email */ | |
| 110 | +						if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { | |
| 111 | 111 | /* Sometime uid are in the form of <user>@<domain> ... */ | 
| 112 | 112 |  				if ( strpos($value, '@') !== FALSE ) { | 
| 113 | -                                	$domain = array_pop(explode('@',$value,2)); | |
| 113 | +									$domain = array_pop(explode('@',$value,2)); | |
| 114 | 114 |  					if ( strpos($domain, '@') === FALSE ) { | 
| 115 | - $recip = emailToNotify($domainNotify_file,$domain); | |
| 116 | -                                		$subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', | |
| 115 | + $recip = emailToNotify($domainNotify_file,$domain); | |
| 116 | +										$subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', | |
| 117 | 117 | $tables["$typedesc"]['field'], $value); | 
| 118 | - if (!empty($recip)) | |
| 119 | - if ( sendEmailWarn($tplfile,'[email protected]',$recip, | |
| 118 | + if (!empty($recip)) | |
| 119 | + if ( sendEmailWarn($tplfile,'[email protected]',$recip, | |
| 120 | 120 | $subject,$value,"$quantity $unit",$reason) ) | 
| 121 | - syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); | |
| 121 | + syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); | |
| 122 | 122 | } | 
| 123 | 123 | else syslog(LOG_ERR,"$user: <$domain> contains the '@' char. Notification cannot be sent."); | 
| 124 | 124 | } | 
| 125 | - } | |
| 126 | - } | |
| 127 | - } | |
| 125 | + } | |
| 126 | + } | |
| 127 | + } | |
| 128 | 128 |  	else { | 
| 129 | 129 | $reason .= " But it has NOT been listed because it doesn't apply to the trigger condition."; | 
| 130 | 130 | syslog (LOG_INFO, "$user: ".$reason); | 
| @@ -10,32 +10,32 @@ discard block | ||
| 10 | 10 | # | 
| 11 | 11 | */ | 
| 12 | 12 | |
| 13 | -$shortopts = "c:"; // Required value | |
| 13 | +$shortopts = "c:"; // Required value | |
| 14 | 14 | $options = getopt($shortopts); | 
| 15 | -if ( !isset($options['c']) ) exit ("\n\nUSAGE: ${_SERVER['SCRIPT_NAME']} -c <file.conf>\n\n"); | |
| 16 | -if ( !file_exists(dirname(__FILE__) . '/' . $options['c']) ) exit ("\n\nThe file <".$options['c']."> doesn't exists.\nExiting...\n\n"); | |
| 15 | +if (!isset($options['c'])) exit ("\n\nUSAGE: ${_SERVER['SCRIPT_NAME']} -c <file.conf>\n\n"); | |
| 16 | +if (!file_exists(dirname(__FILE__).'/'.$options['c'])) exit ("\n\nThe file <".$options['c']."> doesn't exists.\nExiting...\n\n"); | |
| 17 | 17 | |
| 18 | 18 | /************** Start of conf ************************/ | 
| 19 | 19 |  require_once('config.php'); | 
| 20 | 20 | |
| 21 | 21 | /* Syslog */ | 
| 22 | -$tag .= 'SplunkLister'; | |
| 22 | +$tag .= 'SplunkLister'; | |
| 23 | 23 | |
| 24 | -$conf = parse_ini_file( dirname(__FILE__) . '/' . $options['c'] ); | |
| 24 | +$conf = parse_ini_file(dirname(__FILE__).'/'.$options['c']); | |
| 25 | 25 | |
| 26 | 26 | /* Splunk inherited parameters */ | 
| 27 | -$threshold = $conf['threshold']; /* Threshold value on trigger condition; the same which engage the alert */ | |
| 28 | -$splfile = $argv[10]; /* Full path of result Splunk file, see at | |
| 27 | +$threshold = $conf['threshold']; /* Threshold value on trigger condition; the same which engage the alert */ | |
| 28 | +$splfile = $argv[10]; /* Full path of result Splunk file, see at | |
| 29 | 29 | http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Configuringscriptedalerts | 
| 30 | 30 | It is 8+2 because of -c <conf> */ | 
| 31 | 31 | /* Blacklist name */ | 
| 32 | -$typedesc = $conf['typedesc']; | |
| 32 | +$typedesc = $conf['typedesc']; | |
| 33 | 33 | |
| 34 | 34 | /* How long to list's parameters */ | 
| 35 | -$unit = $conf['unit']; /* MySQL language ;) */ | |
| 35 | +$unit = $conf['unit']; /* MySQL language ;) */ | |
| 36 | 36 | |
| 37 | 37 | /* Syslog */ | 
| 38 | -$tag .= $conf['tag']; | |
| 38 | +$tag .= $conf['tag']; | |
| 39 | 39 | |
| 40 | 40 | /************** End of conf *************************/ | 
| 41 | 41 | |
| @@ -46,8 +46,8 @@ discard block | ||
| 46 | 46 | $user = 'Splunk'; | 
| 47 | 47 | |
| 48 | 48 | /* check you select a blocklist */ | 
| 49 | -if ( !$tables["$typedesc"]['bl'] ) { | |
| 50 | - syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); | |
| 49 | +if (!$tables["$typedesc"]['bl']) { | |
| 50 | + syslog(LOG_EMERG, "$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); | |
| 51 | 51 | exit (254); | 
| 52 | 52 | } | 
| 53 | 53 | |
| @@ -67,8 +67,8 @@ discard block | ||
| 67 | 67 | |
| 68 | 68 | $tolist = array(); | 
| 69 | 69 | |
| 70 | -if ( !file_exists($splfile) ) { | |
| 71 | - syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); | |
| 70 | +if (!file_exists($splfile)) { | |
| 71 | + syslog(LOG_ERR, "$user: File <$splfile> not found! Exit."); | |
| 72 | 72 | exit (254); | 
| 73 | 73 | } | 
| 74 | 74 | |
| @@ -80,7 +80,7 @@ discard block | ||
| 80 | 80 | $thisVal = $data[1]; | 
| 81 | 81 | unset($data[1]); | 
| 82 | 82 | $data = array_values($data); | 
| 83 | - if ( !in_array($thisVal,array_keys($tolist)) ) | |
| 83 | + if (!in_array($thisVal, array_keys($tolist))) | |
| 84 | 84 | $tolist["$thisVal"] = $data; | 
| 85 | 85 | else if ($data[3]>$tolist[$thisVal][3]) | 
| 86 | 86 | $tolist["$thisVal"] = $data; | 
| @@ -92,47 +92,47 @@ discard block | ||
| 92 | 92 | |
| 93 | 93 | $mysqli = new mysqli($dbhost, $userdb, $pwd, $db, $dbport); | 
| 94 | 94 |  if ($mysqli->connect_error) { | 
| 95 | -        syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' | |
| 95 | +        syslog(LOG_EMERG, $user.': Connect Error ('.$mysqli->connect_errno.') ' | |
| 96 | 96 | . $mysqli->connect_error); | 
| 97 | 97 | exit (254); | 
| 98 | 98 | |
| 99 | 99 | } | 
| 100 | 100 | |
| 101 | -syslog(LOG_INFO, $user.': Successfully mysql connected to ' . $mysqli->host_info) ; | |
| 101 | +syslog(LOG_INFO, $user.': Successfully mysql connected to '.$mysqli->host_info); | |
| 102 | 102 | |
| 103 | -foreach ( array_keys($tolist) as $value) { | |
| 103 | +foreach (array_keys($tolist) as $value) { | |
| 104 | 104 | $quantity = $conf['quantity']; | 
| 105 | 105 | $reason = 'On ['.$tolist["$value"][0]."] <$value> sent ".$tolist["$value"][1].' messages to '.$tolist["$value"][2].' recipients.'; | 
| 106 | -        if ( $tolist["$value"][3] >= $threshold ) { | |
| 107 | -                if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { | |
| 108 | - syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); | |
| 106 | +        if ($tolist["$value"][3]>=$threshold) { | |
| 107 | +                if (searchAndList($mysqli, $user, $tables, $typedesc, $value, $unit, $quantity, $reason)) { | |
| 108 | + syslog(LOG_INFO, "$user: ".'Listing reason: '.$reason); | |
| 109 | 109 | /* Send a email to domain admin if you list an email */ | 
| 110 | -                        if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { | |
| 110 | +                        if (($tables["$typedesc"]['field'] == 'email') OR ($tables["$typedesc"]['field'] == 'username')) { | |
| 111 | 111 | /* Sometime uid are in the form of <user>@<domain> ... */ | 
| 112 | -				if ( strpos($value, '@') !== FALSE ) { | |
| 113 | -                                	$domain = array_pop(explode('@',$value,2)); | |
| 114 | -					if ( strpos($domain, '@') === FALSE ) { | |
| 115 | - $recip = emailToNotify($domainNotify_file,$domain); | |
| 112 | +				if (strpos($value, '@') !== FALSE) { | |
| 113 | +                                	$domain = array_pop(explode('@', $value, 2)); | |
| 114 | +					if (strpos($domain, '@') === FALSE) { | |
| 115 | + $recip = emailToNotify($domainNotify_file, $domain); | |
| 116 | 116 |                                  		$subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', | 
| 117 | 117 | $tables["$typedesc"]['field'], $value); | 
| 118 | 118 | if (!empty($recip)) | 
| 119 | - if ( sendEmailWarn($tplfile,'[email protected]',$recip, | |
| 120 | - $subject,$value,"$quantity $unit",$reason) ) | |
| 119 | + if (sendEmailWarn($tplfile, '[email protected]', $recip, | |
| 120 | + $subject, $value, "$quantity $unit", $reason)) | |
| 121 | 121 | syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); | 
| 122 | 122 | } | 
| 123 | - else syslog(LOG_ERR,"$user: <$domain> contains the '@' char. Notification cannot be sent."); | |
| 123 | + else syslog(LOG_ERR, "$user: <$domain> contains the '@' char. Notification cannot be sent."); | |
| 124 | 124 | } | 
| 125 | 125 | } | 
| 126 | 126 | } | 
| 127 | 127 | } | 
| 128 | 128 |  	else { | 
| 129 | 129 | $reason .= " But it has NOT been listed because it doesn't apply to the trigger condition."; | 
| 130 | - syslog (LOG_INFO, "$user: ".$reason); | |
| 130 | + syslog(LOG_INFO, "$user: ".$reason); | |
| 131 | 131 | } | 
| 132 | 132 | } | 
| 133 | 133 | |
| 134 | 134 | /* Close connection */ | 
| 135 | -syslog (LOG_INFO, "$user: ".'Successfully end of session.'); | |
| 135 | +syslog(LOG_INFO, "$user: ".'Successfully end of session.'); | |
| 136 | 136 | $mysqli->close(); | 
| 137 | 137 | closelog(); | 
| 138 | 138 | |