@@ -12,14 +12,14 @@ discard block |
||
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; |
| 13 | 13 | if ( preg_match($msa,$received['host'][$i]) ) |
| 14 | 14 | $dateR = $received['date'][$i]; |
| 15 | - foreach ($mxserver as $mx) { |
|
| 16 | - if (!$ip) |
|
| 15 | + foreach ($mxserver as $mx) { |
|
| 16 | + if (!$ip) |
|
| 17 | 17 | if ($mx == $received['host'][$i]) { |
| 18 | 18 | $host = $received['host'][$i]; |
| 19 | 19 | $ip = $received['ip'][$i]; |
| 20 | - } |
|
| 21 | - } |
|
| 22 | - } |
|
| 20 | + } |
|
| 21 | + } |
|
| 22 | + } |
|
| 23 | 23 | } |
| 24 | 24 | if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) |
| 25 | 25 | $dateC['date'] = 'Not found'; |
@@ -39,15 +39,15 @@ discard block |
||
| 39 | 39 | |
| 40 | 40 | |
| 41 | 41 | function summaryBadReport ($uidvet) { |
| 42 | - $nuid = $uidvet['count']; |
|
| 43 | - if ( empty($uidvet) ) return NULL; |
|
| 44 | - $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; |
|
| 42 | + $nuid = $uidvet['count']; |
|
| 43 | + if ( empty($uidvet) ) return NULL; |
|
| 44 | + $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; |
|
| 45 | 45 | |
| 46 | - /* Remove count index */ |
|
| 47 | - $uids = array_keys($uidvet['uid']); |
|
| 46 | + /* Remove count index */ |
|
| 47 | + $uids = array_keys($uidvet['uid']); |
|
| 48 | 48 | $totlearn = 0; |
| 49 | 49 | |
| 50 | - foreach ( $uids as $uid ) { |
|
| 50 | + foreach ( $uids as $uid ) { |
|
| 51 | 51 | $totlearn += $uidvet['uid']["$uid"]['count'];; |
| 52 | 52 | $return .= sprintf ('<tr><td>%s</td><td>%u</td></tr>',$uid,$uidvet['uid']["$uid"]['count']); |
| 53 | 53 | } |
@@ -60,26 +60,26 @@ discard block |
||
| 60 | 60 | |
| 61 | 61 | function array_msort($array, $cols) |
| 62 | 62 | { |
| 63 | - $colarr = array(); |
|
| 64 | - foreach ($cols as $col => $order) { |
|
| 65 | - $colarr[$col] = array(); |
|
| 66 | - foreach ($array as $k => $row) { $colarr[$col]['_'.$k] = strtolower($row[$col]); } |
|
| 67 | - } |
|
| 68 | - $eval = 'array_multisort('; |
|
| 69 | - foreach ($cols as $col => $order) { |
|
| 70 | - $eval .= '$colarr[\''.$col.'\'],'.$order.','; |
|
| 71 | - } |
|
| 72 | - $eval = substr($eval,0,-1).');'; |
|
| 73 | - eval($eval); |
|
| 74 | - $ret = array(); |
|
| 75 | - foreach ($colarr as $col => $arr) { |
|
| 76 | - foreach ($arr as $k => $v) { |
|
| 77 | - $k = substr($k,1); |
|
| 78 | - if (!isset($ret[$k])) $ret[$k] = $array[$k]; |
|
| 79 | - if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; |
|
| 80 | - } |
|
| 81 | - } |
|
| 82 | - return $ret; |
|
| 63 | + $colarr = array(); |
|
| 64 | + foreach ($cols as $col => $order) { |
|
| 65 | + $colarr[$col] = array(); |
|
| 66 | + foreach ($array as $k => $row) { $colarr[$col]['_'.$k] = strtolower($row[$col]); } |
|
| 67 | + } |
|
| 68 | + $eval = 'array_multisort('; |
|
| 69 | + foreach ($cols as $col => $order) { |
|
| 70 | + $eval .= '$colarr[\''.$col.'\'],'.$order.','; |
|
| 71 | + } |
|
| 72 | + $eval = substr($eval,0,-1).');'; |
|
| 73 | + eval($eval); |
|
| 74 | + $ret = array(); |
|
| 75 | + foreach ($colarr as $col => $arr) { |
|
| 76 | + foreach ($arr as $k => $v) { |
|
| 77 | + $k = substr($k,1); |
|
| 78 | + if (!isset($ret[$k])) $ret[$k] = $array[$k]; |
|
| 79 | + if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; |
|
| 80 | + } |
|
| 81 | + } |
|
| 82 | + return $ret; |
|
| 83 | 83 | |
| 84 | 84 | } |
| 85 | 85 | |
@@ -94,8 +94,8 @@ discard block |
||
| 94 | 94 | |
| 95 | 95 | foreach ( $ips as $ip ) { |
| 96 | 96 | if ( $ip == 'count' ) continue; |
| 97 | - $nlearn = $ipvet['ip']["$ip"]['count']; |
|
| 98 | - unset($ipvet['ip']["$ip"]['count']); |
|
| 97 | + $nlearn = $ipvet['ip']["$ip"]['count']; |
|
| 98 | + unset($ipvet['ip']["$ip"]['count']); |
|
| 99 | 99 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ |
| 100 | 100 | $nuid = count($ipvet['ip']["$ip"]); |
| 101 | 101 | if ( !$cf['onlyReport'] ) { |
@@ -123,9 +123,9 @@ discard block |
||
| 123 | 123 | $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; |
| 124 | 124 | $return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); |
| 125 | 125 | $rowuid=NULL; |
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 126 | + for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 127 | 127 | array_shift($ipvet['ip']["$ip"]); |
| 128 | - $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); |
|
| 128 | + $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); |
|
| 129 | 129 | |
| 130 | 130 | } |
| 131 | 131 | $return .= sprintf ('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>',$ipvet['ip']['count'],$ipvet['uid']['count'],$nips); |
@@ -135,20 +135,20 @@ discard block |
||
| 135 | 135 | /* Not used for listing purpose, but useful to you! */ |
| 136 | 136 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; |
| 137 | 137 | $uids = array_keys($ipvet['uid']); |
| 138 | - foreach ( $uids as $uid ) { |
|
| 138 | + foreach ( $uids as $uid ) { |
|
| 139 | 139 | if ( $uid == 'count' ) continue; |
| 140 | - $nlearn = $ipvet['uid']["$uid"]['count']; |
|
| 141 | - unset ( $ipvet['uid']["$uid"]['count'] ); |
|
| 140 | + $nlearn = $ipvet['uid']["$uid"]['count']; |
|
| 141 | + unset ( $ipvet['uid']["$uid"]['count'] ); |
|
| 142 | 142 | $nip = count($ipvet['uid']["$uid"]); |
| 143 | 143 | $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; |
| 144 | 144 | $return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); |
| 145 | - $rowuid=NULL; |
|
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 147 | - array_shift($ipvet['uid']["$uid"]); |
|
| 148 | - $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); |
|
| 145 | + $rowuid=NULL; |
|
| 146 | + for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 147 | + array_shift($ipvet['uid']["$uid"]); |
|
| 148 | + $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); |
|
| 149 | 149 | |
| 150 | - } |
|
| 151 | - $return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips); |
|
| 150 | + } |
|
| 151 | + $return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips); |
|
| 152 | 152 | |
| 153 | 153 | |
| 154 | 154 | return $return; |
@@ -176,50 +176,50 @@ discard block |
||
| 176 | 176 | */ |
| 177 | 177 | |
| 178 | 178 | // A one shot search |
| 179 | - $searchParams = array( |
|
| 180 | - 'earliest_time' => date("c",strtotime ($date)-120), |
|
| 181 | - 'latest_time' => date("c",strtotime ($date)+60) |
|
| 182 | - ); |
|
| 179 | + $searchParams = array( |
|
| 180 | + 'earliest_time' => date("c",strtotime ($date)-120), |
|
| 181 | + 'latest_time' => date("c",strtotime ($date)+60) |
|
| 182 | + ); |
|
| 183 | 183 | |
| 184 | - // Run a oneshot search that returns the job's results |
|
| 185 | - $resultsStream = $service->oneshotSearch($searchQueryBlocking, $searchParams); |
|
| 186 | - $resultSearch = new Splunk_ResultsReader($resultsStream); |
|
| 184 | + // Run a oneshot search that returns the job's results |
|
| 185 | + $resultsStream = $service->oneshotSearch($searchQueryBlocking, $searchParams); |
|
| 186 | + $resultSearch = new Splunk_ResultsReader($resultsStream); |
|
| 187 | 187 | |
| 188 | 188 | // Use the built-in XML parser to display the job results |
| 189 | 189 | foreach ($resultSearch as $result) |
| 190 | 190 | { |
| 191 | - if ($result instanceof Splunk_ResultsFieldOrder) |
|
| 192 | - { |
|
| 193 | - // More than one field attribute returned by search |
|
| 194 | - // You must redefine the search |
|
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; |
|
| 196 | - } |
|
| 197 | - else if ($result instanceof Splunk_ResultsMessage) |
|
| 198 | - { |
|
| 199 | - // I don't want messages in my search |
|
| 200 | - return FALSE; |
|
| 201 | - } |
|
| 202 | - else if (is_array($result)) |
|
| 203 | - { |
|
| 204 | - // Process a row |
|
| 205 | - foreach ($result as $key => $valueOrValues) |
|
| 206 | - { |
|
| 207 | - if (is_array($valueOrValues)) |
|
| 208 | - { |
|
| 209 | - return FALSE; |
|
| 210 | - } |
|
| 211 | - else |
|
| 212 | - { |
|
| 213 | - return $valueOrValues; |
|
| 214 | - #print " {$key} => {$value}\r\n"; |
|
| 215 | - } |
|
| 216 | - } |
|
| 217 | - } |
|
| 218 | - else |
|
| 219 | - { |
|
| 220 | - #print "Unknow result type"; |
|
| 221 | - return FALSE; |
|
| 222 | - } |
|
| 191 | + if ($result instanceof Splunk_ResultsFieldOrder) |
|
| 192 | + { |
|
| 193 | + // More than one field attribute returned by search |
|
| 194 | + // You must redefine the search |
|
| 195 | + if ( count($result->getFieldNames()) > 1 ) return FALSE; |
|
| 196 | + } |
|
| 197 | + else if ($result instanceof Splunk_ResultsMessage) |
|
| 198 | + { |
|
| 199 | + // I don't want messages in my search |
|
| 200 | + return FALSE; |
|
| 201 | + } |
|
| 202 | + else if (is_array($result)) |
|
| 203 | + { |
|
| 204 | + // Process a row |
|
| 205 | + foreach ($result as $key => $valueOrValues) |
|
| 206 | + { |
|
| 207 | + if (is_array($valueOrValues)) |
|
| 208 | + { |
|
| 209 | + return FALSE; |
|
| 210 | + } |
|
| 211 | + else |
|
| 212 | + { |
|
| 213 | + return $valueOrValues; |
|
| 214 | + #print " {$key} => {$value}\r\n"; |
|
| 215 | + } |
|
| 216 | + } |
|
| 217 | + } |
|
| 218 | + else |
|
| 219 | + { |
|
| 220 | + #print "Unknow result type"; |
|
| 221 | + return FALSE; |
|
| 222 | + } |
|
| 223 | 223 | } |
| 224 | 224 | } |
| 225 | 225 | |
@@ -228,26 +228,26 @@ discard block |
||
| 228 | 228 | $file = dirname(__FILE__) . '/' . $cf['reportFile']["$type"]; |
| 229 | 229 | $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; |
| 230 | 230 | $m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) |
| 231 | - or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); |
|
| 231 | + or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); |
|
| 232 | 232 | if ( !$m_mail ) exit(254); |
| 233 | 233 | |
| 234 | 234 | |
| 235 | 235 | syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); |
| 236 | 236 | //get all messages |
| 237 | 237 | $dateTh = date ( "d-M-Y", strToTime ( '-'.$cf['oldestday'].' days' ) ); |
| 238 | - $dateN = date ( "d-M-Y", strToTime ( "now" ) ); |
|
| 239 | - $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); |
|
| 238 | + $dateN = date ( "d-M-Y", strToTime ( "now" ) ); |
|
| 239 | + $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); |
|
| 240 | 240 | |
| 241 | 241 | |
| 242 | 242 | // Order results starting from newest message |
| 243 | 243 | if ( empty($m_search) ) { |
| 244 | 244 | syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); |
| 245 | - if ( $ierr = imap_errors() ) |
|
| 246 | - foreach ( $ierr as $thiserr ) |
|
| 247 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 248 | - if ( $ierr = imap_alerts() ) |
|
| 249 | - foreach ( $ierr as $thiserr ) |
|
| 250 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 245 | + if ( $ierr = imap_errors() ) |
|
| 246 | + foreach ( $ierr as $thiserr ) |
|
| 247 | + syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 248 | + if ( $ierr = imap_alerts() ) |
|
| 249 | + foreach ( $ierr as $thiserr ) |
|
| 250 | + syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 251 | 251 | imap_close( $m_mail ); |
| 252 | 252 | if ( file_exists( $file ) ) unlink ($file); |
| 253 | 253 | if ( file_exists( $fileb ) ) unlink ($fileb); |
@@ -280,16 +280,16 @@ discard block |
||
| 280 | 280 | $uidbad['count'] = 0; |
| 281 | 281 | $uidbad['uid'] = array(); |
| 282 | 282 | |
| 283 | - // loop for each message |
|
| 283 | + // loop for each message |
|
| 284 | 284 | foreach ($m_search as $onem) { |
| 285 | 285 | |
| 286 | - //get imap header info for obj thang |
|
| 287 | - //$headers = imap_headerinfo($m_mail, $onem); |
|
| 288 | - //$head = imap_fetchheader($m_mail, $headers->Msgno); |
|
| 286 | + //get imap header info for obj thang |
|
| 287 | + //$headers = imap_headerinfo($m_mail, $onem); |
|
| 288 | + //$head = imap_fetchheader($m_mail, $headers->Msgno); |
|
| 289 | 289 | $head = imap_fetchheader($m_mail, $onem ); |
| 290 | - //$obj = imap_rfc822_parse_headers( $head); |
|
| 290 | + //$obj = imap_rfc822_parse_headers( $head); |
|
| 291 | 291 | |
| 292 | - list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); |
|
| 292 | + list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); |
|
| 293 | 293 | if (empty($mid)) { |
| 294 | 294 | $uid='NA'; |
| 295 | 295 | syslog (LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); |
@@ -304,11 +304,11 @@ discard block |
||
| 304 | 304 | } |
| 305 | 305 | } |
| 306 | 306 | |
| 307 | - /* Update count of each ip */ |
|
| 308 | - if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers and learned by valid uid */ |
|
| 307 | + /* Update count of each ip */ |
|
| 308 | + if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers and learned by valid uid */ |
|
| 309 | 309 | $ipuid['count']++; //number of right messages |
| 310 | 310 | |
| 311 | - if (in_array($uid,array_keys($ipuid['uid']))) { |
|
| 311 | + if (in_array($uid,array_keys($ipuid['uid']))) { |
|
| 312 | 312 | $ipuid['uid']["$uid"]['count']++; //number of learn by this uid |
| 313 | 313 | if (!in_array($ip,$ipuid['uid']["$uid"])) |
| 314 | 314 | $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid |
@@ -319,29 +319,29 @@ discard block |
||
| 319 | 319 | $ipuid['uid']['count']++; //number of unique uids |
| 320 | 320 | } |
| 321 | 321 | |
| 322 | - if (in_array($ip,array_keys($ipuid['ip']))) { |
|
| 323 | - $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages |
|
| 322 | + if (in_array($ip,array_keys($ipuid['ip']))) { |
|
| 323 | + $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages |
|
| 324 | 324 | if (!in_array($uid,$ipuid['ip']["$ip"])) |
| 325 | 325 | $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip |
| 326 | 326 | } |
| 327 | - else { |
|
| 328 | - $ipuid['ip']["$ip"]['count'] = 1; |
|
| 327 | + else { |
|
| 328 | + $ipuid['ip']["$ip"]['count'] = 1; |
|
| 329 | 329 | $ipuid['ip']["$ip"][]=$uid; |
| 330 | 330 | $ipuid['ip']['count']++; //number of unique ips |
| 331 | - } |
|
| 331 | + } |
|
| 332 | 332 | |
| 333 | - /* Update HTML report */ |
|
| 334 | - fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); |
|
| 333 | + /* Update HTML report */ |
|
| 334 | + fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); |
|
| 335 | 335 | } |
| 336 | - else { /* Bad learn */ |
|
| 336 | + else { /* Bad learn */ |
|
| 337 | 337 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) |
|
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid |
|
| 340 | - else { |
|
| 341 | - $uidbad['uid']["$uid"]['count'] = 1; |
|
| 338 | + if (in_array($uid,array_keys($uidbad['uid']))) |
|
| 339 | + $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid |
|
| 340 | + else { |
|
| 341 | + $uidbad['uid']["$uid"]['count'] = 1; |
|
| 342 | 342 | $uidbad['uid']["$uid"][]=$uid; |
| 343 | - $uidbad['count']++; //numeber of unique bad uids |
|
| 344 | - } |
|
| 343 | + $uidbad['count']++; //numeber of unique bad uids |
|
| 344 | + } |
|
| 345 | 345 | /* The reason of bad report */ |
| 346 | 346 | if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; |
| 347 | 347 | if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; |
@@ -363,17 +363,17 @@ discard block |
||
| 363 | 363 | fwrite($fp, '</table>'); |
| 364 | 364 | fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); |
| 365 | 365 | |
| 366 | - /* Make MYSQL connection */ |
|
| 366 | + /* Make MYSQL connection */ |
|
| 367 | 367 | if ( $cf['onlyReport'] ) |
| 368 | 368 | $mysqli = NULL; |
| 369 | 369 | else { |
| 370 | - $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); |
|
| 371 | - if ($mysqli->connect_error) { |
|
| 372 | - syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 373 | - . $mysqli->connect_error); |
|
| 374 | - exit (254); |
|
| 375 | - } |
|
| 376 | - syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; |
|
| 370 | + $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); |
|
| 371 | + if ($mysqli->connect_error) { |
|
| 372 | + syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 373 | + . $mysqli->connect_error); |
|
| 374 | + exit (254); |
|
| 375 | + } |
|
| 376 | + syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; |
|
| 377 | 377 | } |
| 378 | 378 | /***********************/ |
| 379 | 379 | |
@@ -393,8 +393,8 @@ discard block |
||
| 393 | 393 | foreach ( $ierr as $thiserr ) |
| 394 | 394 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
| 395 | 395 | if ( $ierr = imap_alerts() ) |
| 396 | - foreach ( $ierr as $thiserr ) |
|
| 397 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 396 | + foreach ( $ierr as $thiserr ) |
|
| 397 | + syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 398 | 398 | imap_close($m_mail); |
| 399 | 399 | } |
| 400 | 400 | ?> |
@@ -1,5 +1,5 @@ discard block |
||
| 1 | 1 | <?php |
| 2 | -function getIP($header,$mxserver,$msa) { |
|
| 2 | +function getIP($header, $mxserver, $msa) { |
|
| 3 | 3 | /* Get submission server's IP from header's mail */ |
| 4 | 4 | /* Each line must end with /r/n */ |
| 5 | 5 | /* IP is the first one written by your mxserver */ |
@@ -7,10 +7,10 @@ discard block |
||
| 7 | 7 | $ip = FALSE; |
| 8 | 8 | $host = FALSE; |
| 9 | 9 | $dateR = FALSE; |
| 10 | - if ( preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m',$header,$received) ) { |
|
| 11 | - for ($i = count($received[0])-1;$i>=0;$i--) { |
|
| 10 | + if (preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m', $header, $received)) { |
|
| 11 | + for ($i = count($received[0])-1; $i>=0; $i--) { |
|
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; |
| 13 | - if ( preg_match($msa,$received['host'][$i]) ) |
|
| 13 | + if (preg_match($msa, $received['host'][$i])) |
|
| 14 | 14 | $dateR = $received['date'][$i]; |
| 15 | 15 | foreach ($mxserver as $mx) { |
| 16 | 16 | if (!$ip) |
@@ -21,38 +21,38 @@ discard block |
||
| 21 | 21 | } |
| 22 | 22 | } |
| 23 | 23 | } |
| 24 | - if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) |
|
| 24 | + if (preg_match('/\r\nDate:\s(?P<date>.*)\r\n/', $header, $dateC) != 1) |
|
| 25 | 25 | $dateC['date'] = 'Not found'; |
| 26 | - if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) |
|
| 26 | + if (preg_match('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/', $header, $mid) != 1) |
|
| 27 | 27 | $mid['mid'] = NULL; |
| 28 | - return array($ip,$host,$dateR,$dateC['date'],$mid['mid']); |
|
| 28 | + return array($ip, $host, $dateR, $dateC['date'], $mid['mid']); |
|
| 29 | 29 | } |
| 30 | 30 | |
| 31 | -function updateReport ($ip,$uid,$ipcount,$uidcount,$hostname,$dateC,$msgid,$dateL) { |
|
| 31 | +function updateReport($ip, $uid, $ipcount, $uidcount, $hostname, $dateC, $msgid, $dateL) { |
|
| 32 | 32 | |
| 33 | - return sprintf ('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td>%u</td><td>%u</td><td>%s</td><td>%s</td></tr>'."\n",$dateL,$dateC,$uid,$ip,$uidcount,$ipcount,$hostname,htmlentities($msgid) ); |
|
| 33 | + return sprintf('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td>%u</td><td>%u</td><td>%s</td><td>%s</td></tr>'."\n", $dateL, $dateC, $uid, $ip, $uidcount, $ipcount, $hostname, htmlentities($msgid)); |
|
| 34 | 34 | } |
| 35 | 35 | |
| 36 | -function updatebadReport ( $uid,$dateC,$msgid,$dateL,$text ) { |
|
| 37 | - return sprintf ('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td nowrap>%s</td></tr>'."\n",$dateL,$dateC,$uid,htmlentities($msgid),$text ); |
|
| 36 | +function updatebadReport($uid, $dateC, $msgid, $dateL, $text) { |
|
| 37 | + return sprintf('<tr><td nowrap>%s</td><td nowrap>%s</td><td>%s</td><td>%s</td><td nowrap>%s</td></tr>'."\n", $dateL, $dateC, $uid, htmlentities($msgid), $text); |
|
| 38 | 38 | } |
| 39 | 39 | |
| 40 | 40 | |
| 41 | -function summaryBadReport ($uidvet) { |
|
| 41 | +function summaryBadReport($uidvet) { |
|
| 42 | 42 | $nuid = $uidvet['count']; |
| 43 | - if ( empty($uidvet) ) return NULL; |
|
| 43 | + if (empty($uidvet)) return NULL; |
|
| 44 | 44 | $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; |
| 45 | 45 | |
| 46 | 46 | /* Remove count index */ |
| 47 | 47 | $uids = array_keys($uidvet['uid']); |
| 48 | 48 | $totlearn = 0; |
| 49 | 49 | |
| 50 | - foreach ( $uids as $uid ) { |
|
| 51 | - $totlearn += $uidvet['uid']["$uid"]['count'];; |
|
| 52 | - $return .= sprintf ('<tr><td>%s</td><td>%u</td></tr>',$uid,$uidvet['uid']["$uid"]['count']); |
|
| 50 | + foreach ($uids as $uid) { |
|
| 51 | + $totlearn += $uidvet['uid']["$uid"]['count']; ; |
|
| 52 | + $return .= sprintf('<tr><td>%s</td><td>%u</td></tr>', $uid, $uidvet['uid']["$uid"]['count']); |
|
| 53 | 53 | } |
| 54 | - $return .= sprintf ('<tr><th>%s</th><th>%u</th></tr></table>','TOT',$totlearn); |
|
| 55 | - $return .= sprintf ('<p>%s : %u</p>','Unique UID',$nuid); |
|
| 54 | + $return .= sprintf('<tr><th>%s</th><th>%u</th></tr></table>', 'TOT', $totlearn); |
|
| 55 | + $return .= sprintf('<p>%s : %u</p>', 'Unique UID', $nuid); |
|
| 56 | 56 | |
| 57 | 57 | return $return; |
| 58 | 58 | } |
@@ -69,12 +69,12 @@ discard block |
||
| 69 | 69 | foreach ($cols as $col => $order) { |
| 70 | 70 | $eval .= '$colarr[\''.$col.'\'],'.$order.','; |
| 71 | 71 | } |
| 72 | - $eval = substr($eval,0,-1).');'; |
|
| 72 | + $eval = substr($eval, 0, -1).');'; |
|
| 73 | 73 | eval($eval); |
| 74 | 74 | $ret = array(); |
| 75 | 75 | foreach ($colarr as $col => $arr) { |
| 76 | 76 | foreach ($arr as $k => $v) { |
| 77 | - $k = substr($k,1); |
|
| 77 | + $k = substr($k, 1); |
|
| 78 | 78 | if (!isset($ret[$k])) $ret[$k] = $array[$k]; |
| 79 | 79 | if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; |
| 80 | 80 | } |
@@ -84,29 +84,29 @@ discard block |
||
| 84 | 84 | } |
| 85 | 85 | |
| 86 | 86 | |
| 87 | -function summaryReportAndList ($cf,$myconn,$tables,$category,$ipvet) { |
|
| 87 | +function summaryReportAndList($cf, $myconn, $tables, $category, $ipvet) { |
|
| 88 | 88 | $nips = $ipvet['count']; |
| 89 | 89 | |
| 90 | - if ( empty($ipvet) ) return NULL; |
|
| 90 | + if (empty($ipvet)) return NULL; |
|
| 91 | 91 | $return = '<h3>Statistics by IP</h3><table><tr><th>IP</th><th>Learned by</th><th>Learned times</th><th title="This field doesn\'t say if this ip is currently listed, but it says if this IP has listed now!">Listed Now</th></tr>'."\n"; |
| 92 | 92 | |
| 93 | 93 | $ips = array_keys($ipvet['ip']); |
| 94 | 94 | |
| 95 | - foreach ( $ips as $ip ) { |
|
| 96 | - if ( $ip == 'count' ) continue; |
|
| 95 | + foreach ($ips as $ip) { |
|
| 96 | + if ($ip == 'count') continue; |
|
| 97 | 97 | $nlearn = $ipvet['ip']["$ip"]['count']; |
| 98 | 98 | unset($ipvet['ip']["$ip"]['count']); |
| 99 | 99 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ |
| 100 | 100 | $nuid = count($ipvet['ip']["$ip"]); |
| 101 | - if ( !$cf['onlyReport'] ) { |
|
| 102 | - if ( ($nlearn >= $cf['thresholdip']["$category"])&&($nuid >= $cf['thresholduid']["$category"]) ) { |
|
| 101 | + if (!$cf['onlyReport']) { |
|
| 102 | + if (($nlearn>=$cf['thresholdip']["$category"]) && ($nuid>=$cf['thresholduid']["$category"])) { |
|
| 103 | 103 | $reason = "The IP <$ip> has been listed because was marked $nlearn times as $category by $nuid different accounts during last ".$cf['oldestday'].' days.'; |
| 104 | - $listed = searchAndList ($myconn,$cf['user'],$tables,$cf['list']["$category"],$ip,$cf['unit']["$category"],$quantity,$reason); |
|
| 104 | + $listed = searchAndList($myconn, $cf['user'], $tables, $cf['list']["$category"], $ip, $cf['unit']["$category"], $quantity, $reason); |
|
| 105 | 105 | } |
| 106 | 106 | else $listed = FALSE; |
| 107 | 107 | } |
| 108 | 108 | else $listed = FALSE; |
| 109 | - $nowlist = array( TRUE => array( |
|
| 109 | + $nowlist = array(TRUE => array( |
|
| 110 | 110 | 'style' => 'id=\'ipfound\'', |
| 111 | 111 | 'name' => 'YES', |
| 112 | 112 | ), |
@@ -120,45 +120,45 @@ discard block |
||
| 120 | 120 | ) |
| 121 | 121 | ); |
| 122 | 122 | |
| 123 | - $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; |
|
| 124 | - $return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); |
|
| 125 | - $rowuid=NULL; |
|
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 123 | + $return .= '<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; |
|
| 124 | + $return .= sprintf('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>', $ipvet['ip']["$ip"][0], $nlearn, $nowlist["$listed"]['name']); |
|
| 125 | + $rowuid = NULL; |
|
| 126 | + for ($j = 1; $j<$nuid; $j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 127 | 127 | array_shift($ipvet['ip']["$ip"]); |
| 128 | - $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); |
|
| 128 | + $return .= vsprintf($rowuid, $ipvet['ip']["$ip"]); |
|
| 129 | 129 | |
| 130 | 130 | } |
| 131 | - $return .= sprintf ('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>',$ipvet['ip']['count'],$ipvet['uid']['count'],$nips); |
|
| 131 | + $return .= sprintf('<tr><th title="unique ips">%u</th><th title="unique uids">%u</th><th>%u</th></table>', $ipvet['ip']['count'], $ipvet['uid']['count'], $nips); |
|
| 132 | 132 | |
| 133 | 133 | |
| 134 | 134 | /* Statistics by UID */ |
| 135 | 135 | /* Not used for listing purpose, but useful to you! */ |
| 136 | 136 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; |
| 137 | 137 | $uids = array_keys($ipvet['uid']); |
| 138 | - foreach ( $uids as $uid ) { |
|
| 139 | - if ( $uid == 'count' ) continue; |
|
| 138 | + foreach ($uids as $uid) { |
|
| 139 | + if ($uid == 'count') continue; |
|
| 140 | 140 | $nlearn = $ipvet['uid']["$uid"]['count']; |
| 141 | - unset ( $ipvet['uid']["$uid"]['count'] ); |
|
| 141 | + unset ($ipvet['uid']["$uid"]['count']); |
|
| 142 | 142 | $nip = count($ipvet['uid']["$uid"]); |
| 143 | - $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; |
|
| 144 | - $return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); |
|
| 145 | - $rowuid=NULL; |
|
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 143 | + $return .= '<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; |
|
| 144 | + $return .= sprintf('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>', $ipvet['uid']["$uid"][0], $nlearn); |
|
| 145 | + $rowuid = NULL; |
|
| 146 | + for ($j = 1; $j<$nip; $j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 147 | 147 | array_shift($ipvet['uid']["$uid"]); |
| 148 | - $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); |
|
| 148 | + $return .= vsprintf($rowuid, $ipvet['uid']["$uid"]); |
|
| 149 | 149 | |
| 150 | 150 | } |
| 151 | - $return .= sprintf ('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>',$ipvet['uid']['count'],$ipvet['ip']['count'],$nips); |
|
| 151 | + $return .= sprintf('<tr><th title="unique uids">%u</th><th title="unique ips">%u</th><th>%u</th></table>', $ipvet['uid']['count'], $ipvet['ip']['count'], $nips); |
|
| 152 | 152 | |
| 153 | 153 | |
| 154 | 154 | return $return; |
| 155 | 155 | } |
| 156 | 156 | |
| 157 | 157 | |
| 158 | -function splunksearch ($service,$message_id,$date) { |
|
| 158 | +function splunksearch($service, $message_id, $date) { |
|
| 159 | 159 | |
| 160 | 160 | // Run a blocking search |
| 161 | - $searchQueryBlocking = 'search (message_id="'. addslashes( $message_id ) . |
|
| 161 | + $searchQueryBlocking = 'search (message_id="'.addslashes($message_id). |
|
| 162 | 162 | '" OR sasl_username) | transaction message_id queue_id maxspan=3m maxpause=2m | search sasl_username message_id=* | table sasl_username'; |
| 163 | 163 | |
| 164 | 164 | /* Doesn't work on Splunk 6.6 for HTTP exceptions |
@@ -177,8 +177,8 @@ discard block |
||
| 177 | 177 | |
| 178 | 178 | // A one shot search |
| 179 | 179 | $searchParams = array( |
| 180 | - 'earliest_time' => date("c",strtotime ($date)-120), |
|
| 181 | - 'latest_time' => date("c",strtotime ($date)+60) |
|
| 180 | + 'earliest_time' => date("c", strtotime($date)-120), |
|
| 181 | + 'latest_time' => date("c", strtotime($date)+60) |
|
| 182 | 182 | ); |
| 183 | 183 | |
| 184 | 184 | // Run a oneshot search that returns the job's results |
@@ -192,7 +192,7 @@ discard block |
||
| 192 | 192 | { |
| 193 | 193 | // More than one field attribute returned by search |
| 194 | 194 | // You must redefine the search |
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; |
|
| 195 | + if (count($result->getFieldNames())>1) return FALSE; |
|
| 196 | 196 | } |
| 197 | 197 | else if ($result instanceof Splunk_ResultsMessage) |
| 198 | 198 | { |
@@ -224,51 +224,51 @@ discard block |
||
| 224 | 224 | } |
| 225 | 225 | |
| 226 | 226 | |
| 227 | -function imapReport ($cf,$myconnArray,$splunkconn,$tables,$type) { |
|
| 228 | - $file = dirname(__FILE__) . '/' . $cf['reportFile']["$type"]; |
|
| 229 | - $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; |
|
| 230 | - $m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) |
|
| 231 | - or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); |
|
| 232 | - if ( !$m_mail ) exit(254); |
|
| 227 | +function imapReport($cf, $myconnArray, $splunkconn, $tables, $type) { |
|
| 228 | + $file = dirname(__FILE__).'/'.$cf['reportFile']["$type"]; |
|
| 229 | + $fileb = dirname(__FILE__).'/'.$cf['badreportFile']["$type"]; |
|
| 230 | + $m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'], $cf['authpassword'], OP_READONLY) |
|
| 231 | + or syslog(LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: '.imap_last_error()); |
|
| 232 | + if (!$m_mail) exit(254); |
|
| 233 | 233 | |
| 234 | 234 | |
| 235 | - syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); |
|
| 235 | + syslog(LOG_INFO, $cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); |
|
| 236 | 236 | //get all messages |
| 237 | - $dateTh = date ( "d-M-Y", strToTime ( '-'.$cf['oldestday'].' days' ) ); |
|
| 238 | - $dateN = date ( "d-M-Y", strToTime ( "now" ) ); |
|
| 239 | - $m_search=imap_search ($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\"" ); |
|
| 237 | + $dateTh = date("d-M-Y", strToTime('-'.$cf['oldestday'].' days')); |
|
| 238 | + $dateN = date("d-M-Y", strToTime("now")); |
|
| 239 | + $m_search = imap_search($m_mail, "SINCE \"$dateTh\" BEFORE \"$dateN\""); |
|
| 240 | 240 | |
| 241 | 241 | |
| 242 | 242 | // Order results starting from newest message |
| 243 | - if ( empty($m_search) ) { |
|
| 244 | - syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); |
|
| 245 | - if ( $ierr = imap_errors() ) |
|
| 246 | - foreach ( $ierr as $thiserr ) |
|
| 247 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 248 | - if ( $ierr = imap_alerts() ) |
|
| 249 | - foreach ( $ierr as $thiserr ) |
|
| 250 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 251 | - imap_close( $m_mail ); |
|
| 252 | - if ( file_exists( $file ) ) unlink ($file); |
|
| 253 | - if ( file_exists( $fileb ) ) unlink ($fileb); |
|
| 243 | + if (empty($m_search)) { |
|
| 244 | + syslog(LOG_INFO, $cf['user'].": No mail found in $type folder. No reports written for $type."); |
|
| 245 | + if ($ierr = imap_errors()) |
|
| 246 | + foreach ($ierr as $thiserr) |
|
| 247 | + syslog(LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 248 | + if ($ierr = imap_alerts()) |
|
| 249 | + foreach ($ierr as $thiserr) |
|
| 250 | + syslog(LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 251 | + imap_close($m_mail); |
|
| 252 | + if (file_exists($file)) unlink($file); |
|
| 253 | + if (file_exists($fileb)) unlink($fileb); |
|
| 254 | 254 | return FALSE; |
| 255 | 255 | } |
| 256 | - $nmes = count ($m_search); |
|
| 257 | - syslog (LOG_INFO,$cf['user'].": Found $nmes mail in $type folder."); |
|
| 256 | + $nmes = count($m_search); |
|
| 257 | + syslog(LOG_INFO, $cf['user'].": Found $nmes mail in $type folder."); |
|
| 258 | 258 | if ($nmes>0) rsort($m_search); |
| 259 | 259 | |
| 260 | 260 | // Create report file |
| 261 | 261 | |
| 262 | 262 | $fp = fopen($file, 'w'); |
| 263 | - $fpb= fopen($fileb, 'w'); |
|
| 264 | - $lastup = "Last Update: " . date ("d F Y H:i", time()); |
|
| 265 | - fwrite( $fp, file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); |
|
| 266 | - fwrite( $fp,"<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); |
|
| 267 | - if ($cf['onlyReport']) fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); |
|
| 268 | - fwrite( $fp,'<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>' ); |
|
| 269 | - fwrite( $fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); |
|
| 270 | - fwrite( $fpb,"<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); |
|
| 271 | - fwrite( $fpb,'<table><tr><th title="taken from Received header" nowrap>Date Learn</th><th title="taken from Date header" nowrap>Date Received</th><th nowrap>UID</th><th>Message-Id</th><th title="Why is this a bad report?">Reason</th></tr>' ); |
|
| 263 | + $fpb = fopen($fileb, 'w'); |
|
| 264 | + $lastup = "Last Update: ".date("d F Y H:i", time()); |
|
| 265 | + fwrite($fp, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateHeader'])); |
|
| 266 | + fwrite($fp, "<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>"); |
|
| 267 | + if ($cf['onlyReport']) fwrite($fp, '<p>None of the below IP has been listed because listing is not active in configuration.</p>'); |
|
| 268 | + fwrite($fp, '<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>'); |
|
| 269 | + fwrite($fpb, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateHeader'])); |
|
| 270 | + fwrite($fpb, "<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>"); |
|
| 271 | + fwrite($fpb, '<table><tr><th title="taken from Received header" nowrap>Date Learn</th><th title="taken from Date header" nowrap>Date Received</th><th nowrap>UID</th><th>Message-Id</th><th title="Why is this a bad report?">Reason</th></tr>'); |
|
| 272 | 272 | |
| 273 | 273 | $ipuid = array(); |
| 274 | 274 | $ipuid['count'] = 0; |
@@ -286,69 +286,69 @@ discard block |
||
| 286 | 286 | //get imap header info for obj thang |
| 287 | 287 | //$headers = imap_headerinfo($m_mail, $onem); |
| 288 | 288 | //$head = imap_fetchheader($m_mail, $headers->Msgno); |
| 289 | - $head = imap_fetchheader($m_mail, $onem ); |
|
| 289 | + $head = imap_fetchheader($m_mail, $onem); |
|
| 290 | 290 | //$obj = imap_rfc822_parse_headers( $head); |
| 291 | 291 | |
| 292 | - list ($ip,$host,$dateReceived,$dateClient,$mid) = getIP( $head,$cf['mx'],$cf['msalearn'] ); |
|
| 292 | + list ($ip, $host, $dateReceived, $dateClient, $mid) = getIP($head, $cf['mx'], $cf['msalearn']); |
|
| 293 | 293 | if (empty($mid)) { |
| 294 | - $uid='NA'; |
|
| 295 | - syslog (LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); |
|
| 296 | - } else { |
|
| 294 | + $uid = 'NA'; |
|
| 295 | + syslog(LOG_ERR, $cf['user'].": Error retrieving data for empty Message-ID."); |
|
| 296 | + }else { |
|
| 297 | 297 | if ($dateReceived === FALSE) { |
| 298 | - $uid='unauthenticated'; |
|
| 299 | - syslog (LOG_ERR, $cf['user'].": Error retrieving date for $mid. Maybe this mail was not submitted to Learner MSA"); |
|
| 300 | - } else |
|
| 301 | - if ( !($uid = splunksearch ($splunkconn, trim($mid,'<>'), $dateReceived)) ) { |
|
| 302 | - syslog (LOG_ERR, $cf['user'].": Error retrieving uid from Splunk log for $mid."); |
|
| 303 | - $uid='unknown'; |
|
| 298 | + $uid = 'unauthenticated'; |
|
| 299 | + syslog(LOG_ERR, $cf['user'].": Error retrieving date for $mid. Maybe this mail was not submitted to Learner MSA"); |
|
| 300 | + }else |
|
| 301 | + if (!($uid = splunksearch($splunkconn, trim($mid, '<>'), $dateReceived))) { |
|
| 302 | + syslog(LOG_ERR, $cf['user'].": Error retrieving uid from Splunk log for $mid."); |
|
| 303 | + $uid = 'unknown'; |
|
| 304 | 304 | } |
| 305 | 305 | } |
| 306 | 306 | |
| 307 | 307 | /* Update count of each ip */ |
| 308 | - if ($host and ($uid!='NA') and ($uid!='unauthenticated') and ($uid!='unknown')) { /* IP is received by MX servers and learned by valid uid */ |
|
| 309 | - $ipuid['count']++; //number of right messages |
|
| 308 | + if ($host and ($uid != 'NA') and ($uid != 'unauthenticated') and ($uid != 'unknown')) { /* IP is received by MX servers and learned by valid uid */ |
|
| 309 | + $ipuid['count']++; //number of right messages |
|
| 310 | 310 | |
| 311 | - if (in_array($uid,array_keys($ipuid['uid']))) { |
|
| 312 | - $ipuid['uid']["$uid"]['count']++; //number of learn by this uid |
|
| 313 | - if (!in_array($ip,$ipuid['uid']["$uid"])) |
|
| 314 | - $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid |
|
| 311 | + if (in_array($uid, array_keys($ipuid['uid']))) { |
|
| 312 | + $ipuid['uid']["$uid"]['count']++; //number of learn by this uid |
|
| 313 | + if (!in_array($ip, $ipuid['uid']["$uid"])) |
|
| 314 | + $ipuid['uid']["$uid"][] = $ip; //ips learned by this uid |
|
| 315 | 315 | } |
| 316 | 316 | else { |
| 317 | 317 | $ipuid['uid']["$uid"]['count'] = 1; |
| 318 | - $ipuid['uid']["$uid"][]=$ip; |
|
| 319 | - $ipuid['uid']['count']++; //number of unique uids |
|
| 318 | + $ipuid['uid']["$uid"][] = $ip; |
|
| 319 | + $ipuid['uid']['count']++; //number of unique uids |
|
| 320 | 320 | } |
| 321 | 321 | |
| 322 | - if (in_array($ip,array_keys($ipuid['ip']))) { |
|
| 323 | - $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages |
|
| 324 | - if (!in_array($uid,$ipuid['ip']["$ip"])) |
|
| 325 | - $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip |
|
| 322 | + if (in_array($ip, array_keys($ipuid['ip']))) { |
|
| 323 | + $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages |
|
| 324 | + if (!in_array($uid, $ipuid['ip']["$ip"])) |
|
| 325 | + $ipuid['ip']["$ip"][] = $uid; //uids that learned this ip |
|
| 326 | 326 | } |
| 327 | 327 | else { |
| 328 | 328 | $ipuid['ip']["$ip"]['count'] = 1; |
| 329 | - $ipuid['ip']["$ip"][]=$uid; |
|
| 330 | - $ipuid['ip']['count']++; //number of unique ips |
|
| 329 | + $ipuid['ip']["$ip"][] = $uid; |
|
| 330 | + $ipuid['ip']['count']++; //number of unique ips |
|
| 331 | 331 | } |
| 332 | 332 | |
| 333 | 333 | /* Update HTML report */ |
| 334 | - fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); |
|
| 334 | + fwrite($fp, updateReport($ip, $uid, $ipuid['ip']["$ip"]['count'], $ipuid['uid']["$uid"]['count'], $host, $dateClient, $mid, $dateReceived)); |
|
| 335 | 335 | } |
| 336 | 336 | else { /* Bad learn */ |
| 337 | 337 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) |
|
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid |
|
| 338 | + if (in_array($uid, array_keys($uidbad['uid']))) |
|
| 339 | + $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid |
|
| 340 | 340 | else { |
| 341 | 341 | $uidbad['uid']["$uid"]['count'] = 1; |
| 342 | - $uidbad['uid']["$uid"][]=$uid; |
|
| 343 | - $uidbad['count']++; //numeber of unique bad uids |
|
| 342 | + $uidbad['uid']["$uid"][] = $uid; |
|
| 343 | + $uidbad['count']++; //numeber of unique bad uids |
|
| 344 | 344 | } |
| 345 | 345 | /* The reason of bad report */ |
| 346 | 346 | if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; |
| 347 | 347 | if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; |
| 348 | - if ($uid=='unknown') $reason = 'The uid of this mail was not found in splunk log'; |
|
| 348 | + if ($uid == 'unknown') $reason = 'The uid of this mail was not found in splunk log'; |
|
| 349 | 349 | if (!isset($reason)) $reason = '?'; |
| 350 | 350 | |
| 351 | - fwrite( $fpb,updatebadReport ( $uid,$dateClient,$mid,$dateReceived,$reason ) ); |
|
| 351 | + fwrite($fpb, updatebadReport($uid, $dateClient, $mid, $dateReceived, $reason)); |
|
| 352 | 352 | } |
| 353 | 353 | } |
| 354 | 354 | |
@@ -356,45 +356,45 @@ discard block |
||
| 356 | 356 | //close report file and mailbox |
| 357 | 357 | |
| 358 | 358 | /* Summary Report */ |
| 359 | - $ipuid['ip'] = array_msort( $ipuid['ip'], array('count'=>SORT_DESC) ); |
|
| 360 | - $ipuid['uid'] = array_msort( $ipuid['uid'], array('count'=>SORT_DESC) ); |
|
| 361 | - $uidbad['uid'] = array_msort( $uidbad['uid'], array('count'=>SORT_DESC) ); |
|
| 359 | + $ipuid['ip'] = array_msort($ipuid['ip'], array('count'=>SORT_DESC)); |
|
| 360 | + $ipuid['uid'] = array_msort($ipuid['uid'], array('count'=>SORT_DESC)); |
|
| 361 | + $uidbad['uid'] = array_msort($uidbad['uid'], array('count'=>SORT_DESC)); |
|
| 362 | 362 | |
| 363 | 363 | fwrite($fp, '</table>'); |
| 364 | - fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); |
|
| 364 | + fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>'); |
|
| 365 | 365 | |
| 366 | 366 | /* Make MYSQL connection */ |
| 367 | - if ( $cf['onlyReport'] ) |
|
| 367 | + if ($cf['onlyReport']) |
|
| 368 | 368 | $mysqli = NULL; |
| 369 | 369 | else { |
| 370 | 370 | $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); |
| 371 | 371 | if ($mysqli->connect_error) { |
| 372 | - syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 372 | + syslog(LOG_EMERG, $cf['user'].': Connect Error ('.$mysqli->connect_errno.') ' |
|
| 373 | 373 | . $mysqli->connect_error); |
| 374 | 374 | exit (254); |
| 375 | 375 | } |
| 376 | - syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to ' . $mysqli->host_info) ; |
|
| 376 | + syslog(LOG_INFO, $cf['user'].': Successfully mysql connected to '.$mysqli->host_info); |
|
| 377 | 377 | } |
| 378 | 378 | /***********************/ |
| 379 | 379 | |
| 380 | - fwrite($fp, summaryReportAndList ($cf,$mysqli,$tables,$type,$ipuid) ); |
|
| 381 | - if ( !$cf['onlyReport'] ) |
|
| 380 | + fwrite($fp, summaryReportAndList($cf, $mysqli, $tables, $type, $ipuid)); |
|
| 381 | + if (!$cf['onlyReport']) |
|
| 382 | 382 | $mysqli->close(); |
| 383 | - fwrite($fp,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); |
|
| 383 | + fwrite($fp, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateFooter'])); |
|
| 384 | 384 | fclose($fp); |
| 385 | 385 | |
| 386 | 386 | fwrite($fpb, '</table>'); |
| 387 | - fwrite( $fpb,summaryBadReport( $uidbad ) ); |
|
| 388 | - fwrite($fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); |
|
| 387 | + fwrite($fpb, summaryBadReport($uidbad)); |
|
| 388 | + fwrite($fpb, file_get_contents(dirname(__FILE__).'/'.$cf['reportTemplateFooter'])); |
|
| 389 | 389 | fclose($fpb); |
| 390 | - syslog (LOG_INFO,$cf['user'].': Report files written. Listing job for '.$type.' terminated.'); |
|
| 391 | - |
|
| 392 | - if ( $ierr = imap_errors() ) |
|
| 393 | - foreach ( $ierr as $thiserr ) |
|
| 394 | - syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 395 | - if ( $ierr = imap_alerts() ) |
|
| 396 | - foreach ( $ierr as $thiserr ) |
|
| 397 | - syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 390 | + syslog(LOG_INFO, $cf['user'].': Report files written. Listing job for '.$type.' terminated.'); |
|
| 391 | + |
|
| 392 | + if ($ierr = imap_errors()) |
|
| 393 | + foreach ($ierr as $thiserr) |
|
| 394 | + syslog(LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
|
| 395 | + if ($ierr = imap_alerts()) |
|
| 396 | + foreach ($ierr as $thiserr) |
|
| 397 | + syslog(LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
|
| 398 | 398 | imap_close($m_mail); |
| 399 | 399 | } |
| 400 | 400 | ?> |
@@ -10,21 +10,25 @@ discard block |
||
| 10 | 10 | if ( preg_match_all('/^Received:\sfrom(?:.|\r\n\s)*?[\[\(]\s*(?P<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})[\]\)](?:.|\r\n\s)+\s+by(?:\s|\r\n\s+)(?P<host>\S+).*(?:\s|\r\n\s\s)+.*;\s+(?P<date>.*)/m',$header,$received) ) { |
| 11 | 11 | for ($i = count($received[0])-1;$i>=0;$i--) { |
| 12 | 12 | # print "Examine ".$received[0][$i]."\n"; |
| 13 | - if ( preg_match($msa,$received['host'][$i]) ) |
|
| 14 | - $dateR = $received['date'][$i]; |
|
| 13 | + if ( preg_match($msa,$received['host'][$i]) ) { |
|
| 14 | + $dateR = $received['date'][$i]; |
|
| 15 | + } |
|
| 15 | 16 | foreach ($mxserver as $mx) { |
| 16 | - if (!$ip) |
|
| 17 | - if ($mx == $received['host'][$i]) { |
|
| 17 | + if (!$ip) { |
|
| 18 | + if ($mx == $received['host'][$i]) { |
|
| 18 | 19 | $host = $received['host'][$i]; |
| 20 | + } |
|
| 19 | 21 | $ip = $received['ip'][$i]; |
| 20 | 22 | } |
| 21 | 23 | } |
| 22 | 24 | } |
| 23 | 25 | } |
| 24 | - if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) |
|
| 25 | - $dateC['date'] = 'Not found'; |
|
| 26 | - if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) |
|
| 27 | - $mid['mid'] = NULL; |
|
| 26 | + if ( preg_match ('/\r\nDate:\s(?P<date>.*)\r\n/',$header,$dateC) != 1) { |
|
| 27 | + $dateC['date'] = 'Not found'; |
|
| 28 | + } |
|
| 29 | + if ( preg_match ('/\r\nMessage\-I(?:D|d):\s(?P<mid>.*)\r\n/',$header,$mid) != 1) { |
|
| 30 | + $mid['mid'] = NULL; |
|
| 31 | + } |
|
| 28 | 32 | return array($ip,$host,$dateR,$dateC['date'],$mid['mid']); |
| 29 | 33 | } |
| 30 | 34 | |
@@ -40,7 +44,9 @@ discard block |
||
| 40 | 44 | |
| 41 | 45 | function summaryBadReport ($uidvet) { |
| 42 | 46 | $nuid = $uidvet['count']; |
| 43 | - if ( empty($uidvet) ) return NULL; |
|
| 47 | + if ( empty($uidvet) ) { |
|
| 48 | + return NULL; |
|
| 49 | + } |
|
| 44 | 50 | $return = '<hr><h3>Statistics by UID</h3><table><tr><th>UID</th><th>Learned times</th></tr>'."\n"; |
| 45 | 51 | |
| 46 | 52 | /* Remove count index */ |
@@ -75,8 +81,12 @@ discard block |
||
| 75 | 81 | foreach ($colarr as $col => $arr) { |
| 76 | 82 | foreach ($arr as $k => $v) { |
| 77 | 83 | $k = substr($k,1); |
| 78 | - if (!isset($ret[$k])) $ret[$k] = $array[$k]; |
|
| 79 | - if (isset ($array[$k][$col])) $ret[$k][$col] = $array[$k][$col]; |
|
| 84 | + if (!isset($ret[$k])) { |
|
| 85 | + $ret[$k] = $array[$k]; |
|
| 86 | + } |
|
| 87 | + if (isset ($array[$k][$col])) { |
|
| 88 | + $ret[$k][$col] = $array[$k][$col]; |
|
| 89 | + } |
|
| 80 | 90 | } |
| 81 | 91 | } |
| 82 | 92 | return $ret; |
@@ -87,13 +97,17 @@ discard block |
||
| 87 | 97 | function summaryReportAndList ($cf,$myconn,$tables,$category,$ipvet) { |
| 88 | 98 | $nips = $ipvet['count']; |
| 89 | 99 | |
| 90 | - if ( empty($ipvet) ) return NULL; |
|
| 100 | + if ( empty($ipvet) ) { |
|
| 101 | + return NULL; |
|
| 102 | + } |
|
| 91 | 103 | $return = '<h3>Statistics by IP</h3><table><tr><th>IP</th><th>Learned by</th><th>Learned times</th><th title="This field doesn\'t say if this ip is currently listed, but it says if this IP has listed now!">Listed Now</th></tr>'."\n"; |
| 92 | 104 | |
| 93 | 105 | $ips = array_keys($ipvet['ip']); |
| 94 | 106 | |
| 95 | 107 | foreach ( $ips as $ip ) { |
| 96 | - if ( $ip == 'count' ) continue; |
|
| 108 | + if ( $ip == 'count' ) { |
|
| 109 | + continue; |
|
| 110 | + } |
|
| 97 | 111 | $nlearn = $ipvet['ip']["$ip"]['count']; |
| 98 | 112 | unset($ipvet['ip']["$ip"]['count']); |
| 99 | 113 | $quantity = $cf['quantity']["$category"]; /* In searchAndList this value is passed by reference and modified */ |
@@ -102,10 +116,12 @@ discard block |
||
| 102 | 116 | if ( ($nlearn >= $cf['thresholdip']["$category"])&&($nuid >= $cf['thresholduid']["$category"]) ) { |
| 103 | 117 | $reason = "The IP <$ip> has been listed because was marked $nlearn times as $category by $nuid different accounts during last ".$cf['oldestday'].' days.'; |
| 104 | 118 | $listed = searchAndList ($myconn,$cf['user'],$tables,$cf['list']["$category"],$ip,$cf['unit']["$category"],$quantity,$reason); |
| 119 | + } else { |
|
| 120 | + $listed = FALSE; |
|
| 105 | 121 | } |
| 106 | - else $listed = FALSE; |
|
| 122 | + } else { |
|
| 123 | + $listed = FALSE; |
|
| 107 | 124 | } |
| 108 | - else $listed = FALSE; |
|
| 109 | 125 | $nowlist = array( TRUE => array( |
| 110 | 126 | 'style' => 'id=\'ipfound\'', |
| 111 | 127 | 'name' => 'YES', |
@@ -123,7 +139,9 @@ discard block |
||
| 123 | 139 | $return .='<tr><td rowspan="'.$nuid.'">'.$ip.'</td>'; |
| 124 | 140 | $return .= sprintf ('<td>%s</td><td rowspan="'.$nuid.'">%u</td><td rowspan="'.$nuid.'" '.$nowlist["$listed"]['style'].'>%s</td></tr>',$ipvet['ip']["$ip"][0],$nlearn,$nowlist["$listed"]['name']); |
| 125 | 141 | $rowuid=NULL; |
| 126 | - for ($j=1;$j<$nuid;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 142 | + for ($j=1;$j<$nuid;$j++) { |
|
| 143 | + $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 144 | + } |
|
| 127 | 145 | array_shift($ipvet['ip']["$ip"]); |
| 128 | 146 | $return .= vsprintf ($rowuid,$ipvet['ip']["$ip"]); |
| 129 | 147 | |
@@ -136,14 +154,18 @@ discard block |
||
| 136 | 154 | $return .= '<h3>Statistics by UID</h3><table><tr><th>UID</th><th>IP learned</th><th>Learned times</th></tr>'."\n"; |
| 137 | 155 | $uids = array_keys($ipvet['uid']); |
| 138 | 156 | foreach ( $uids as $uid ) { |
| 139 | - if ( $uid == 'count' ) continue; |
|
| 157 | + if ( $uid == 'count' ) { |
|
| 158 | + continue; |
|
| 159 | + } |
|
| 140 | 160 | $nlearn = $ipvet['uid']["$uid"]['count']; |
| 141 | 161 | unset ( $ipvet['uid']["$uid"]['count'] ); |
| 142 | 162 | $nip = count($ipvet['uid']["$uid"]); |
| 143 | 163 | $return .='<tr><td rowspan="'.$nip.'">'.$uid.'</td>'; |
| 144 | 164 | $return .= sprintf ('<td>%s</td><td rowspan="'.$nip.'">%u</td></tr>',$ipvet['uid']["$uid"][0],$nlearn); |
| 145 | 165 | $rowuid=NULL; |
| 146 | - for ($j=1;$j<$nip;$j++) $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 166 | + for ($j=1;$j<$nip;$j++) { |
|
| 167 | + $rowuid .= '<tr><td>%s</td></tr>'; |
|
| 168 | + } |
|
| 147 | 169 | array_shift($ipvet['uid']["$uid"]); |
| 148 | 170 | $return .= vsprintf ($rowuid,$ipvet['uid']["$uid"]); |
| 149 | 171 | |
@@ -192,14 +214,14 @@ discard block |
||
| 192 | 214 | { |
| 193 | 215 | // More than one field attribute returned by search |
| 194 | 216 | // You must redefine the search |
| 195 | - if ( count($result->getFieldNames()) > 1 ) return FALSE; |
|
| 196 | - } |
|
| 197 | - else if ($result instanceof Splunk_ResultsMessage) |
|
| 217 | + if ( count($result->getFieldNames()) > 1 ) { |
|
| 218 | + return FALSE; |
|
| 219 | + } |
|
| 220 | + } else if ($result instanceof Splunk_ResultsMessage) |
|
| 198 | 221 | { |
| 199 | 222 | // I don't want messages in my search |
| 200 | 223 | return FALSE; |
| 201 | - } |
|
| 202 | - else if (is_array($result)) |
|
| 224 | + } else if (is_array($result)) |
|
| 203 | 225 | { |
| 204 | 226 | // Process a row |
| 205 | 227 | foreach ($result as $key => $valueOrValues) |
@@ -207,15 +229,13 @@ discard block |
||
| 207 | 229 | if (is_array($valueOrValues)) |
| 208 | 230 | { |
| 209 | 231 | return FALSE; |
| 210 | - } |
|
| 211 | - else |
|
| 232 | + } else |
|
| 212 | 233 | { |
| 213 | 234 | return $valueOrValues; |
| 214 | 235 | #print " {$key} => {$value}\r\n"; |
| 215 | 236 | } |
| 216 | 237 | } |
| 217 | - } |
|
| 218 | - else |
|
| 238 | + } else |
|
| 219 | 239 | { |
| 220 | 240 | #print "Unknow result type"; |
| 221 | 241 | return FALSE; |
@@ -229,7 +249,9 @@ discard block |
||
| 229 | 249 | $fileb= dirname(__FILE__) . '/' . $cf['badreportFile']["$type"]; |
| 230 | 250 | $m_mail = imap_open('{'.$cf['mailhost'].':143/imap/novalidate-cert/authuser='.$cf['authuser'].'}'.$cf['folder']["$type"], $cf['account'],$cf['authpassword'], OP_READONLY) |
| 231 | 251 | or syslog (LOG_EMERG, $cf['user'].': Error in IMAP connection to <'.$cf['mailhost'].'>: ' . imap_last_error()); |
| 232 | - if ( !$m_mail ) exit(254); |
|
| 252 | + if ( !$m_mail ) { |
|
| 253 | + exit(254); |
|
| 254 | + } |
|
| 233 | 255 | |
| 234 | 256 | |
| 235 | 257 | syslog (LOG_INFO,$cf['user'].': Successfully connected to <'.$cf['mailhost'].">; Reading $type messages of last ".$cf['oldestday'].' days...'); |
@@ -242,20 +264,28 @@ discard block |
||
| 242 | 264 | // Order results starting from newest message |
| 243 | 265 | if ( empty($m_search) ) { |
| 244 | 266 | syslog (LOG_INFO,$cf['user'].": No mail found in $type folder. No reports written for $type."); |
| 245 | - if ( $ierr = imap_errors() ) |
|
| 246 | - foreach ( $ierr as $thiserr ) |
|
| 267 | + if ( $ierr = imap_errors() ) { |
|
| 268 | + foreach ( $ierr as $thiserr ) |
|
| 247 | 269 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
| 248 | - if ( $ierr = imap_alerts() ) |
|
| 249 | - foreach ( $ierr as $thiserr ) |
|
| 270 | + } |
|
| 271 | + if ( $ierr = imap_alerts() ) { |
|
| 272 | + foreach ( $ierr as $thiserr ) |
|
| 250 | 273 | syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
| 274 | + } |
|
| 251 | 275 | imap_close( $m_mail ); |
| 252 | - if ( file_exists( $file ) ) unlink ($file); |
|
| 253 | - if ( file_exists( $fileb ) ) unlink ($fileb); |
|
| 276 | + if ( file_exists( $file ) ) { |
|
| 277 | + unlink ($file); |
|
| 278 | + } |
|
| 279 | + if ( file_exists( $fileb ) ) { |
|
| 280 | + unlink ($fileb); |
|
| 281 | + } |
|
| 254 | 282 | return FALSE; |
| 255 | 283 | } |
| 256 | 284 | $nmes = count ($m_search); |
| 257 | 285 | syslog (LOG_INFO,$cf['user'].": Found $nmes mail in $type folder."); |
| 258 | - if ($nmes>0) rsort($m_search); |
|
| 286 | + if ($nmes>0) { |
|
| 287 | + rsort($m_search); |
|
| 288 | + } |
|
| 259 | 289 | |
| 260 | 290 | // Create report file |
| 261 | 291 | |
@@ -264,7 +294,9 @@ discard block |
||
| 264 | 294 | $lastup = "Last Update: " . date ("d F Y H:i", time()); |
| 265 | 295 | fwrite( $fp, file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); |
| 266 | 296 | fwrite( $fp,"<h1> Report of IP sending $type</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); |
| 267 | - if ($cf['onlyReport']) fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); |
|
| 297 | + if ($cf['onlyReport']) { |
|
| 298 | + fwrite( $fp,'<p>None of the below IP has been listed because listing is not active in configuration.</p>'); |
|
| 299 | + } |
|
| 268 | 300 | fwrite( $fp,'<table><tr><th title="taken from Received header" nowrap>Date of Learn</th><th title="taken from Date header" nowrap>Date of Write</th><th nowrap>UID</th><th nowrap>IP</th><th title="How many times this uid learns">#UID</th><th title="Number of times this learned IP appears in different mails">#IP</th><th nowrap>Received by</th><th>Message-Id</th></tr>' ); |
| 269 | 301 | fwrite( $fpb,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateHeader']) ); |
| 270 | 302 | fwrite( $fpb,"<h1> Report of bad reported $type mails</h1><h5>$lastup</h5><h2>Detailed Report</h2>" ); |
@@ -310,10 +342,11 @@ discard block |
||
| 310 | 342 | |
| 311 | 343 | if (in_array($uid,array_keys($ipuid['uid']))) { |
| 312 | 344 | $ipuid['uid']["$uid"]['count']++; //number of learn by this uid |
| 313 | - if (!in_array($ip,$ipuid['uid']["$uid"])) |
|
| 314 | - $ipuid['uid']["$uid"][]=$ip; //ips learned by this uid |
|
| 315 | - } |
|
| 316 | - else { |
|
| 345 | + if (!in_array($ip,$ipuid['uid']["$uid"])) { |
|
| 346 | + $ipuid['uid']["$uid"][]=$ip; |
|
| 347 | + } |
|
| 348 | + //ips learned by this uid |
|
| 349 | + } else { |
|
| 317 | 350 | $ipuid['uid']["$uid"]['count'] = 1; |
| 318 | 351 | $ipuid['uid']["$uid"][]=$ip; |
| 319 | 352 | $ipuid['uid']['count']++; //number of unique uids |
@@ -321,10 +354,11 @@ discard block |
||
| 321 | 354 | |
| 322 | 355 | if (in_array($ip,array_keys($ipuid['ip']))) { |
| 323 | 356 | $ipuid['ip']["$ip"]['count']++; //number of time this ip appears in different messages |
| 324 | - if (!in_array($uid,$ipuid['ip']["$ip"])) |
|
| 325 | - $ipuid['ip']["$ip"][]=$uid; //uids that learned this ip |
|
| 326 | - } |
|
| 327 | - else { |
|
| 357 | + if (!in_array($uid,$ipuid['ip']["$ip"])) { |
|
| 358 | + $ipuid['ip']["$ip"][]=$uid; |
|
| 359 | + } |
|
| 360 | + //uids that learned this ip |
|
| 361 | + } else { |
|
| 328 | 362 | $ipuid['ip']["$ip"]['count'] = 1; |
| 329 | 363 | $ipuid['ip']["$ip"][]=$uid; |
| 330 | 364 | $ipuid['ip']['count']++; //number of unique ips |
@@ -332,21 +366,30 @@ discard block |
||
| 332 | 366 | |
| 333 | 367 | /* Update HTML report */ |
| 334 | 368 | fwrite($fp,updateReport ( $ip,$uid,$ipuid['ip']["$ip"]['count'],$ipuid['uid']["$uid"]['count'],$host,$dateClient,$mid,$dateReceived) ); |
| 335 | - } |
|
| 336 | - else { /* Bad learn */ |
|
| 369 | + } else { /* Bad learn */ |
|
| 337 | 370 | |
| 338 | - if (in_array($uid,array_keys($uidbad['uid']))) |
|
| 339 | - $uidbad['uid']["$uid"]['count']++; //number of bad learn by this uid |
|
| 371 | + if (in_array($uid,array_keys($uidbad['uid']))) { |
|
| 372 | + $uidbad['uid']["$uid"]['count']++; |
|
| 373 | + } |
|
| 374 | + //number of bad learn by this uid |
|
| 340 | 375 | else { |
| 341 | 376 | $uidbad['uid']["$uid"]['count'] = 1; |
| 342 | 377 | $uidbad['uid']["$uid"][]=$uid; |
| 343 | 378 | $uidbad['count']++; //numeber of unique bad uids |
| 344 | 379 | } |
| 345 | 380 | /* The reason of bad report */ |
| 346 | - if ($host === FALSE) $reason = 'This mail was not received by recognized MX host'; |
|
| 347 | - if ($dateReceived === FALSE) $reason = 'This mail was not submitted to recognized MSA for learn'; |
|
| 348 | - if ($uid=='unknown') $reason = 'The uid of this mail was not found in splunk log'; |
|
| 349 | - if (!isset($reason)) $reason = '?'; |
|
| 381 | + if ($host === FALSE) { |
|
| 382 | + $reason = 'This mail was not received by recognized MX host'; |
|
| 383 | + } |
|
| 384 | + if ($dateReceived === FALSE) { |
|
| 385 | + $reason = 'This mail was not submitted to recognized MSA for learn'; |
|
| 386 | + } |
|
| 387 | + if ($uid=='unknown') { |
|
| 388 | + $reason = 'The uid of this mail was not found in splunk log'; |
|
| 389 | + } |
|
| 390 | + if (!isset($reason)) { |
|
| 391 | + $reason = '?'; |
|
| 392 | + } |
|
| 350 | 393 | |
| 351 | 394 | fwrite( $fpb,updatebadReport ( $uid,$dateClient,$mid,$dateReceived,$reason ) ); |
| 352 | 395 | } |
@@ -364,9 +407,9 @@ discard block |
||
| 364 | 407 | fwrite($fp, '<hr><h2>Summary Report</h2><h5>Listing policy: ip must be learned at least '.$cf['thresholdip']["$type"].' times from at least '.$cf['thresholduid']["$type"].' different valid uids.</h5>' ); |
| 365 | 408 | |
| 366 | 409 | /* Make MYSQL connection */ |
| 367 | - if ( $cf['onlyReport'] ) |
|
| 368 | - $mysqli = NULL; |
|
| 369 | - else { |
|
| 410 | + if ( $cf['onlyReport'] ) { |
|
| 411 | + $mysqli = NULL; |
|
| 412 | + } else { |
|
| 370 | 413 | $mysqli = new mysqli($myconnArray['dbhost'], $myconnArray['userdb'], $myconnArray['pwd'], $myconnArray['db'], $myconnArray['dbport']); |
| 371 | 414 | if ($mysqli->connect_error) { |
| 372 | 415 | syslog (LOG_EMERG, $cf['user'].': Connect Error (' . $mysqli->connect_errno . ') ' |
@@ -378,8 +421,9 @@ discard block |
||
| 378 | 421 | /***********************/ |
| 379 | 422 | |
| 380 | 423 | fwrite($fp, summaryReportAndList ($cf,$mysqli,$tables,$type,$ipuid) ); |
| 381 | - if ( !$cf['onlyReport'] ) |
|
| 382 | - $mysqli->close(); |
|
| 424 | + if ( !$cf['onlyReport'] ) { |
|
| 425 | + $mysqli->close(); |
|
| 426 | + } |
|
| 383 | 427 | fwrite($fp,file_get_contents(dirname(__FILE__) . '/' . $cf['reportTemplateFooter'])); |
| 384 | 428 | fclose($fp); |
| 385 | 429 | |
@@ -389,12 +433,14 @@ discard block |
||
| 389 | 433 | fclose($fpb); |
| 390 | 434 | syslog (LOG_INFO,$cf['user'].': Report files written. Listing job for '.$type.' terminated.'); |
| 391 | 435 | |
| 392 | - if ( $ierr = imap_errors() ) |
|
| 393 | - foreach ( $ierr as $thiserr ) |
|
| 436 | + if ( $ierr = imap_errors() ) { |
|
| 437 | + foreach ( $ierr as $thiserr ) |
|
| 394 | 438 | syslog (LOG_ERR, $cf['user'].": IMAP Error: $thiserr"); |
| 395 | - if ( $ierr = imap_alerts() ) |
|
| 396 | - foreach ( $ierr as $thiserr ) |
|
| 439 | + } |
|
| 440 | + if ( $ierr = imap_alerts() ) { |
|
| 441 | + foreach ( $ierr as $thiserr ) |
|
| 397 | 442 | syslog (LOG_ALERT, $cf['user'].": IMAP Alert: $thiserr"); |
| 443 | + } |
|
| 398 | 444 | imap_close($m_mail); |
| 399 | 445 | } |
| 400 | 446 | ?> |
@@ -47,8 +47,8 @@ discard block |
||
| 47 | 47 | |
| 48 | 48 | /* check you select a blocklist */ |
| 49 | 49 | if ( !$tables["$typedesc"]['bl'] ) { |
| 50 | - syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); |
|
| 51 | - exit (254); |
|
| 50 | + syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); |
|
| 51 | + exit (254); |
|
| 52 | 52 | } |
| 53 | 53 | |
| 54 | 54 | |
@@ -68,33 +68,33 @@ discard block |
||
| 68 | 68 | $tolist = array(); |
| 69 | 69 | |
| 70 | 70 | if ( !file_exists($splfile) ) { |
| 71 | - syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); |
|
| 72 | - exit (254); |
|
| 71 | + syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); |
|
| 72 | + exit (254); |
|
| 73 | 73 | } |
| 74 | 74 | |
| 75 | 75 | if (($handle = gzopen($splfile, 'r')) !== FALSE) { |
| 76 | - $row = -1; |
|
| 77 | - while (($data = fgetcsv($handle, 500, ',')) !== FALSE) { |
|
| 78 | - $row++; |
|
| 79 | - if ($row == 0) continue; /* Skip heading line */ |
|
| 80 | - $thisVal = $data[1]; |
|
| 81 | - unset($data[1]); |
|
| 82 | - $data = array_values($data); |
|
| 83 | - if ( !in_array($thisVal,array_keys($tolist)) ) |
|
| 84 | - $tolist["$thisVal"] = $data; |
|
| 85 | - else if ($data[3]>$tolist[$thisVal][3]) |
|
| 86 | - $tolist["$thisVal"] = $data; |
|
| 87 | - } |
|
| 88 | - fclose($handle); |
|
| 76 | + $row = -1; |
|
| 77 | + while (($data = fgetcsv($handle, 500, ',')) !== FALSE) { |
|
| 78 | + $row++; |
|
| 79 | + if ($row == 0) continue; /* Skip heading line */ |
|
| 80 | + $thisVal = $data[1]; |
|
| 81 | + unset($data[1]); |
|
| 82 | + $data = array_values($data); |
|
| 83 | + if ( !in_array($thisVal,array_keys($tolist)) ) |
|
| 84 | + $tolist["$thisVal"] = $data; |
|
| 85 | + else if ($data[3]>$tolist[$thisVal][3]) |
|
| 86 | + $tolist["$thisVal"] = $data; |
|
| 87 | + } |
|
| 88 | + fclose($handle); |
|
| 89 | 89 | } |
| 90 | 90 | |
| 91 | 91 | /* Make MYSQL connection */ |
| 92 | 92 | |
| 93 | 93 | $mysqli = new mysqli($dbhost, $userdb, $pwd, $db, $dbport); |
| 94 | 94 | if ($mysqli->connect_error) { |
| 95 | - syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 96 | - . $mysqli->connect_error); |
|
| 97 | - exit (254); |
|
| 95 | + syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 96 | + . $mysqli->connect_error); |
|
| 97 | + exit (254); |
|
| 98 | 98 | |
| 99 | 99 | } |
| 100 | 100 | |
@@ -103,28 +103,28 @@ discard block |
||
| 103 | 103 | foreach ( array_keys($tolist) as $value) { |
| 104 | 104 | $quantity = $conf['quantity']; |
| 105 | 105 | $reason = 'On ['.$tolist["$value"][0]."] <$value> sent ".$tolist["$value"][1].' messages to '.$tolist["$value"][2].' recipients.'; |
| 106 | - if ( $tolist["$value"][3] >= $threshold ) { |
|
| 107 | - if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { |
|
| 108 | - syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); |
|
| 109 | - /* Send a email to domain admin if you list an email */ |
|
| 110 | - if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { |
|
| 106 | + if ( $tolist["$value"][3] >= $threshold ) { |
|
| 107 | + if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { |
|
| 108 | + syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); |
|
| 109 | + /* Send a email to domain admin if you list an email */ |
|
| 110 | + if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { |
|
| 111 | 111 | /* Sometime uid are in the form of <user>@<domain> ... */ |
| 112 | 112 | if ( strpos($value, '@') !== FALSE ) { |
| 113 | - $domain = array_pop(explode('@',$value,2)); |
|
| 113 | + $domain = array_pop(explode('@',$value,2)); |
|
| 114 | 114 | if ( strpos($domain, '@') === FALSE ) { |
| 115 | - $recip = emailToNotify($domainNotify_file,$domain); |
|
| 116 | - $subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', |
|
| 115 | + $recip = emailToNotify($domainNotify_file,$domain); |
|
| 116 | + $subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', |
|
| 117 | 117 | $tables["$typedesc"]['field'], $value); |
| 118 | - if (!empty($recip)) |
|
| 119 | - if ( sendEmailWarn($tplfile,'[email protected]',$recip, |
|
| 118 | + if (!empty($recip)) |
|
| 119 | + if ( sendEmailWarn($tplfile,'[email protected]',$recip, |
|
| 120 | 120 | $subject,$value,"$quantity $unit",$reason) ) |
| 121 | - syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); |
|
| 121 | + syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); |
|
| 122 | 122 | } |
| 123 | 123 | else syslog(LOG_ERR,"$user: <$domain> contains the '@' char. Notification cannot be sent."); |
| 124 | 124 | } |
| 125 | - } |
|
| 126 | - } |
|
| 127 | - } |
|
| 125 | + } |
|
| 126 | + } |
|
| 127 | + } |
|
| 128 | 128 | else { |
| 129 | 129 | $reason .= " But it has NOT been listed because it doesn't apply to the trigger condition."; |
| 130 | 130 | syslog (LOG_INFO, "$user: ".$reason); |
@@ -10,32 +10,32 @@ discard block |
||
| 10 | 10 | # |
| 11 | 11 | */ |
| 12 | 12 | |
| 13 | -$shortopts = "c:"; // Required value |
|
| 13 | +$shortopts = "c:"; // Required value |
|
| 14 | 14 | $options = getopt($shortopts); |
| 15 | -if ( !isset($options['c']) ) exit ("\n\nUSAGE: ${_SERVER['SCRIPT_NAME']} -c <file.conf>\n\n"); |
|
| 16 | -if ( !file_exists(dirname(__FILE__) . '/' . $options['c']) ) exit ("\n\nThe file <".$options['c']."> doesn't exists.\nExiting...\n\n"); |
|
| 15 | +if (!isset($options['c'])) exit ("\n\nUSAGE: ${_SERVER['SCRIPT_NAME']} -c <file.conf>\n\n"); |
|
| 16 | +if (!file_exists(dirname(__FILE__).'/'.$options['c'])) exit ("\n\nThe file <".$options['c']."> doesn't exists.\nExiting...\n\n"); |
|
| 17 | 17 | |
| 18 | 18 | /************** Start of conf ************************/ |
| 19 | 19 | require_once('config.php'); |
| 20 | 20 | |
| 21 | 21 | /* Syslog */ |
| 22 | -$tag .= 'SplunkLister'; |
|
| 22 | +$tag .= 'SplunkLister'; |
|
| 23 | 23 | |
| 24 | -$conf = parse_ini_file( dirname(__FILE__) . '/' . $options['c'] ); |
|
| 24 | +$conf = parse_ini_file(dirname(__FILE__).'/'.$options['c']); |
|
| 25 | 25 | |
| 26 | 26 | /* Splunk inherited parameters */ |
| 27 | -$threshold = $conf['threshold']; /* Threshold value on trigger condition; the same which engage the alert */ |
|
| 28 | -$splfile = $argv[10]; /* Full path of result Splunk file, see at |
|
| 27 | +$threshold = $conf['threshold']; /* Threshold value on trigger condition; the same which engage the alert */ |
|
| 28 | +$splfile = $argv[10]; /* Full path of result Splunk file, see at |
|
| 29 | 29 | http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Configuringscriptedalerts |
| 30 | 30 | It is 8+2 because of -c <conf> */ |
| 31 | 31 | /* Blacklist name */ |
| 32 | -$typedesc = $conf['typedesc']; |
|
| 32 | +$typedesc = $conf['typedesc']; |
|
| 33 | 33 | |
| 34 | 34 | /* How long to list's parameters */ |
| 35 | -$unit = $conf['unit']; /* MySQL language ;) */ |
|
| 35 | +$unit = $conf['unit']; /* MySQL language ;) */ |
|
| 36 | 36 | |
| 37 | 37 | /* Syslog */ |
| 38 | -$tag .= $conf['tag']; |
|
| 38 | +$tag .= $conf['tag']; |
|
| 39 | 39 | |
| 40 | 40 | /************** End of conf *************************/ |
| 41 | 41 | |
@@ -46,8 +46,8 @@ discard block |
||
| 46 | 46 | $user = 'Splunk'; |
| 47 | 47 | |
| 48 | 48 | /* check you select a blocklist */ |
| 49 | -if ( !$tables["$typedesc"]['bl'] ) { |
|
| 50 | - syslog(LOG_EMERG,"$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); |
|
| 49 | +if (!$tables["$typedesc"]['bl']) { |
|
| 50 | + syslog(LOG_EMERG, "$user: <$typedesc> is not a blocklist. Are you stupid? Do you want to whitelist a spammer? I refuse to continue."); |
|
| 51 | 51 | exit (254); |
| 52 | 52 | } |
| 53 | 53 | |
@@ -67,8 +67,8 @@ discard block |
||
| 67 | 67 | |
| 68 | 68 | $tolist = array(); |
| 69 | 69 | |
| 70 | -if ( !file_exists($splfile) ) { |
|
| 71 | - syslog(LOG_ERR,"$user: File <$splfile> not found! Exit."); |
|
| 70 | +if (!file_exists($splfile)) { |
|
| 71 | + syslog(LOG_ERR, "$user: File <$splfile> not found! Exit."); |
|
| 72 | 72 | exit (254); |
| 73 | 73 | } |
| 74 | 74 | |
@@ -80,7 +80,7 @@ discard block |
||
| 80 | 80 | $thisVal = $data[1]; |
| 81 | 81 | unset($data[1]); |
| 82 | 82 | $data = array_values($data); |
| 83 | - if ( !in_array($thisVal,array_keys($tolist)) ) |
|
| 83 | + if (!in_array($thisVal, array_keys($tolist))) |
|
| 84 | 84 | $tolist["$thisVal"] = $data; |
| 85 | 85 | else if ($data[3]>$tolist[$thisVal][3]) |
| 86 | 86 | $tolist["$thisVal"] = $data; |
@@ -92,47 +92,47 @@ discard block |
||
| 92 | 92 | |
| 93 | 93 | $mysqli = new mysqli($dbhost, $userdb, $pwd, $db, $dbport); |
| 94 | 94 | if ($mysqli->connect_error) { |
| 95 | - syslog (LOG_EMERG, $user.': Connect Error (' . $mysqli->connect_errno . ') ' |
|
| 95 | + syslog(LOG_EMERG, $user.': Connect Error ('.$mysqli->connect_errno.') ' |
|
| 96 | 96 | . $mysqli->connect_error); |
| 97 | 97 | exit (254); |
| 98 | 98 | |
| 99 | 99 | } |
| 100 | 100 | |
| 101 | -syslog(LOG_INFO, $user.': Successfully mysql connected to ' . $mysqli->host_info) ; |
|
| 101 | +syslog(LOG_INFO, $user.': Successfully mysql connected to '.$mysqli->host_info); |
|
| 102 | 102 | |
| 103 | -foreach ( array_keys($tolist) as $value) { |
|
| 103 | +foreach (array_keys($tolist) as $value) { |
|
| 104 | 104 | $quantity = $conf['quantity']; |
| 105 | 105 | $reason = 'On ['.$tolist["$value"][0]."] <$value> sent ".$tolist["$value"][1].' messages to '.$tolist["$value"][2].' recipients.'; |
| 106 | - if ( $tolist["$value"][3] >= $threshold ) { |
|
| 107 | - if ( searchAndList ($mysqli,$user,$tables,$typedesc,$value,$unit,$quantity,$reason) ) { |
|
| 108 | - syslog (LOG_INFO, "$user: ".'Listing reason: '.$reason); |
|
| 106 | + if ($tolist["$value"][3]>=$threshold) { |
|
| 107 | + if (searchAndList($mysqli, $user, $tables, $typedesc, $value, $unit, $quantity, $reason)) { |
|
| 108 | + syslog(LOG_INFO, "$user: ".'Listing reason: '.$reason); |
|
| 109 | 109 | /* Send a email to domain admin if you list an email */ |
| 110 | - if ( ( $tables["$typedesc"]['field'] == 'email' ) OR ( $tables["$typedesc"]['field'] == 'username' ) ) { |
|
| 110 | + if (($tables["$typedesc"]['field'] == 'email') OR ($tables["$typedesc"]['field'] == 'username')) { |
|
| 111 | 111 | /* Sometime uid are in the form of <user>@<domain> ... */ |
| 112 | - if ( strpos($value, '@') !== FALSE ) { |
|
| 113 | - $domain = array_pop(explode('@',$value,2)); |
|
| 114 | - if ( strpos($domain, '@') === FALSE ) { |
|
| 115 | - $recip = emailToNotify($domainNotify_file,$domain); |
|
| 112 | + if (strpos($value, '@') !== FALSE) { |
|
| 113 | + $domain = array_pop(explode('@', $value, 2)); |
|
| 114 | + if (strpos($domain, '@') === FALSE) { |
|
| 115 | + $recip = emailToNotify($domainNotify_file, $domain); |
|
| 116 | 116 | $subject = sprintf('%s <%s> is now blocked because exceedes limits on outgoing emails', |
| 117 | 117 | $tables["$typedesc"]['field'], $value); |
| 118 | 118 | if (!empty($recip)) |
| 119 | - if ( sendEmailWarn($tplfile,'[email protected]',$recip, |
|
| 120 | - $subject,$value,"$quantity $unit",$reason) ) |
|
| 119 | + if (sendEmailWarn($tplfile, '[email protected]', $recip, |
|
| 120 | + $subject, $value, "$quantity $unit", $reason)) |
|
| 121 | 121 | syslog(LOG_INFO, "$user: \"$recip\" was notified about the \"$value\" abuse."); |
| 122 | 122 | } |
| 123 | - else syslog(LOG_ERR,"$user: <$domain> contains the '@' char. Notification cannot be sent."); |
|
| 123 | + else syslog(LOG_ERR, "$user: <$domain> contains the '@' char. Notification cannot be sent."); |
|
| 124 | 124 | } |
| 125 | 125 | } |
| 126 | 126 | } |
| 127 | 127 | } |
| 128 | 128 | else { |
| 129 | 129 | $reason .= " But it has NOT been listed because it doesn't apply to the trigger condition."; |
| 130 | - syslog (LOG_INFO, "$user: ".$reason); |
|
| 130 | + syslog(LOG_INFO, "$user: ".$reason); |
|
| 131 | 131 | } |
| 132 | 132 | } |
| 133 | 133 | |
| 134 | 134 | /* Close connection */ |
| 135 | -syslog (LOG_INFO, "$user: ".'Successfully end of session.'); |
|
| 135 | +syslog(LOG_INFO, "$user: ".'Successfully end of session.'); |
|
| 136 | 136 | $mysqli->close(); |
| 137 | 137 | closelog(); |
| 138 | 138 | |