]>
Commit | Line | Data |
---|---|---|
c86edd1d Q |
1 | |
2 | #include "proxyscan.h" | |
3 | ||
4 | #include <sys/poll.h> | |
5 | #include <sys/types.h> | |
6 | #include <sys/socket.h> | |
7 | #include <netdb.h> | |
8 | #include "../core/error.h" | |
9 | #include "../core/events.h" | |
10 | #include <stdlib.h> | |
11 | #include <stdio.h> | |
12 | #include <errno.h> | |
13 | #include "../nick/nick.h" | |
14 | #include "../core/hooks.h" | |
15 | #include "../lib/sstring.h" | |
16 | #include "../irc/irc_config.h" | |
17 | #include "../localuser/localuser.h" | |
18 | #include "../core/config.h" | |
19 | #include <unistd.h> | |
20 | #include "../core/schedule.h" | |
21 | #include <string.h> | |
22 | #include "../irc/irc.h" | |
23 | #include "../lib/irc_string.h" | |
cfd3214b CP |
24 | #include "../lib/version.h" |
25 | #include "../channel/channel.h" | |
26 | #include "../localuser/localuserchannel.h" | |
818e3d5f | 27 | #include "../core/nsmalloc.h" |
557c8cb2 | 28 | #include "../lib/irc_ipv6.h" |
cfd3214b CP |
29 | |
30 | MODULE_VERSION("") | |
c86edd1d Q |
31 | |
32 | #define SCANTIMEOUT 60 | |
33 | ||
34 | #define SCANHOSTHASHSIZE 1000 | |
35 | #define SCANHASHSIZE 400 | |
36 | ||
37 | /* It's unlikely you'll get 100k of preamble before a connect... */ | |
38 | #define READ_SANITY_LIMIT 102400 | |
39 | ||
40 | scan *scantable[SCANHASHSIZE]; | |
41 | ||
7ab80d0c P |
42 | CommandTree *ps_commands; |
43 | ||
c86edd1d Q |
44 | int listenfd; |
45 | int activescans; | |
46 | int maxscans; | |
47 | int queuedhosts; | |
48 | int scansdone; | |
49 | int rescaninterval; | |
50 | int warningsent; | |
51 | int glinedhosts; | |
2220c058 | 52 | time_t ps_starttime; |
557c8cb2 P |
53 | int ps_cache_ext; |
54 | int ps_extscan_ext; | |
7ab80d0c | 55 | int ps_ready; |
c86edd1d Q |
56 | |
57 | int numscans; /* number of scan types currently valid */ | |
58 | scantype thescans[PSCAN_MAXSCANS]; | |
59 | ||
60 | unsigned int hitsbyclass[10]; | |
61 | unsigned int scansbyclass[10]; | |
62 | ||
63 | unsigned int myip; | |
64 | sstring *myipstr; | |
65 | unsigned short listenport; | |
66 | int brokendb; | |
67 | ||
68 | unsigned int ps_mailip; | |
69 | unsigned int ps_mailport; | |
70 | sstring *ps_mailname; | |
71 | ||
92f1d9e3 D |
72 | unsigned long scanspermin; |
73 | unsigned long tempscanspermin=0; | |
74 | unsigned long lastscants=0; | |
75 | ||
761a4596 P |
76 | unsigned int ps_start_ts=0; |
77 | ||
c86edd1d Q |
78 | nick *proxyscannick; |
79 | ||
80 | FILE *ps_logfile; | |
81 | ||
82 | /* Local functions */ | |
83 | void handlescansock(int fd, short events); | |
84 | void timeoutscansock(void *arg); | |
85 | void proxyscan_newnick(int hooknum, void *arg); | |
86 | void proxyscan_lostnick(int hooknum, void *arg); | |
7ab80d0c | 87 | void proxyscan_onconnect(int hooknum, void *arg); |
c86edd1d Q |
88 | void proxyscanuserhandler(nick *target, int message, void **params); |
89 | void registerproxyscannick(); | |
90 | void killsock(scan *sp, int outcome); | |
91 | void killallscans(); | |
92 | void proxyscanstats(int hooknum, void *arg); | |
93 | void sendlagwarning(); | |
c86edd1d Q |
94 | void proxyscan_newip(nick *np, unsigned long ip); |
95 | int proxyscan_addscantype(int type, int port); | |
96 | int proxyscan_delscantype(int type, int port); | |
97 | ||
7ab80d0c P |
98 | int proxyscandostatus(void *sender, int cargc, char **cargv); |
99 | int proxyscandebug(void *sender, int cargc, char **cargv); | |
100 | int proxyscandosave(void *sender, int cargc, char **cargv); | |
101 | int proxyscandospew(void *sender, int cargc, char **cargv); | |
102 | int proxyscandoshowkill(void *sender, int cargc, char **cargv); | |
103 | int proxyscandoscan(void *sender, int cargc, char **cargv); | |
104 | int proxyscandoaddscan(void *sender, int cargc, char **cargv); | |
105 | int proxyscandodelscan(void *sender, int cargc, char **cargv); | |
106 | int proxyscandoshowcommands(void *sender, int cargc, char **cargv); | |
107 | ||
c86edd1d Q |
108 | int proxyscan_addscantype(int type, int port) { |
109 | /* Check we have a spare scan slot */ | |
110 | ||
111 | if (numscans>=PSCAN_MAXSCANS) | |
112 | return 1; | |
113 | ||
114 | thescans[numscans].type=type; | |
115 | thescans[numscans].port=port; | |
116 | thescans[numscans].hits=0; | |
117 | ||
118 | numscans++; | |
119 | ||
120 | return 0; | |
121 | } | |
122 | ||
123 | int proxyscan_delscantype(int type, int port) { | |
124 | int i; | |
125 | ||
126 | for (i=0;i<numscans;i++) | |
127 | if (thescans[i].type==type && thescans[i].port==port) | |
128 | break; | |
129 | ||
130 | if (i>=numscans) | |
131 | return 1; | |
132 | ||
133 | memmove(thescans+i, thescans+(i+1), (PSCAN_MAXSCANS-(i+1)) * sizeof(scantype)); | |
134 | numscans--; | |
135 | ||
136 | return 0; | |
137 | } | |
138 | ||
139 | void _init(void) { | |
140 | sstring *cfgstr; | |
141 | int ipbits[4]; | |
142 | ||
761a4596 | 143 | ps_start_ts = time(NULL); |
7ab80d0c P |
144 | ps_ready = 0; |
145 | ps_commands = NULL; | |
761a4596 | 146 | |
557c8cb2 | 147 | ps_cache_ext = registernodeext("proxyscancache"); |
a8ba1373 P |
148 | if( ps_cache_ext == -1 ) { |
149 | Error("proxyscan",ERR_INFO,"failed to reg node ext"); | |
150 | return; | |
557c8cb2 P |
151 | } |
152 | ps_extscan_ext = registernodeext("proxyscanextscan"); | |
a8ba1373 P |
153 | if ( ps_extscan_ext == -1) { |
154 | Error("proxyscan",ERR_INFO,"failed to reg node ext"); | |
155 | return; | |
557c8cb2 | 156 | } |
a8ba1373 | 157 | |
c86edd1d Q |
158 | memset(scantable,0,sizeof(scantable)); |
159 | maxscans=200; | |
160 | activescans=0; | |
161 | queuedhosts=0; | |
162 | scansdone=0; | |
163 | warningsent=0; | |
2220c058 | 164 | ps_starttime=time(NULL); |
c86edd1d | 165 | glinedhosts=0; |
7ab80d0c | 166 | |
92f1d9e3 D |
167 | scanspermin=0; |
168 | lastscants=time(NULL); | |
169 | ||
c86edd1d Q |
170 | /* Listen port */ |
171 | cfgstr=getcopyconfigitem("proxyscan","port","9999",6); | |
172 | listenport=strtol(cfgstr->content,NULL,10); | |
173 | freesstring(cfgstr); | |
174 | ||
175 | /* Max concurrent scans */ | |
176 | cfgstr=getcopyconfigitem("proxyscan","maxscans","200",5); | |
177 | maxscans=strtol(cfgstr->content,NULL,10); | |
178 | freesstring(cfgstr); | |
179 | ||
180 | /* Clean host timeout */ | |
181 | cfgstr=getcopyconfigitem("proxyscan","rescaninterval","3600",7); | |
182 | rescaninterval=strtol(cfgstr->content,NULL,10); | |
183 | cachehostinit(rescaninterval); | |
184 | freesstring(cfgstr); | |
185 | ||
186 | /* this default will NOT work well */ | |
187 | myipstr=getcopyconfigitem("proxyscan","ip","127.0.0.1",16); | |
188 | ||
189 | sscanf(myipstr->content,"%d.%d.%d.%d",&ipbits[0],&ipbits[1],&ipbits[2],&ipbits[3]); | |
190 | ||
191 | myip=((ipbits[0]&0xFF)<<24)+((ipbits[1]&0xFF)<<16)+ | |
192 | ((ipbits[2]&0xFF)<<8)+(ipbits[3]&0xFF); | |
193 | ||
f94f9cec | 194 | #if defined(PROXYSCAN_MAIL) |
c86edd1d Q |
195 | /* Mailer host */ |
196 | cfgstr=getcopyconfigitem("proxyscan","mailerip","",16); | |
197 | ||
c86edd1d Q |
198 | psm_mailerfd=-1; |
199 | if (cfgstr) { | |
200 | sscanf(cfgstr->content,"%d.%d.%d.%d",&ipbits[0],&ipbits[1],&ipbits[2],&ipbits[3]); | |
201 | ps_mailip = ((ipbits[0]&0xFF)<<24)+((ipbits[1]&0xFF)<<16)+ | |
202 | ((ipbits[2]&0xFF)<<8)+(ipbits[3]&0xFF); | |
203 | ps_mailport=25; | |
204 | freesstring(cfgstr); | |
205 | ||
206 | ps_mailname=getcopyconfigitem("proxyscan","mailname","some.mail.server",HOSTLEN); | |
c9db668b | 207 | Error("proxyscan",ERR_INFO,"Proxyscan mailer enabled; mailing to %s as %s.",IPlongtostr(ps_mailip),ps_mailname->content); |
c86edd1d Q |
208 | } else { |
209 | ps_mailport=0; | |
210 | ps_mailname=NULL; | |
211 | } | |
212 | #endif | |
213 | ||
214 | proxyscannick=NULL; | |
215 | /* Set up our nick on the network */ | |
216 | scheduleoneshot(time(NULL),®isterproxyscannick,NULL); | |
217 | ||
7ab80d0c P |
218 | registerhook(HOOK_SERVER_END_OF_BURST, &proxyscan_onconnect); |
219 | ||
c86edd1d Q |
220 | registerhook(HOOK_NICK_NEWNICK,&proxyscan_newnick); |
221 | ||
222 | registerhook(HOOK_CORE_STATSREQUEST,&proxyscanstats); | |
223 | ||
224 | /* Read in the clean hosts */ | |
225 | loadcachehosts(); | |
226 | ||
557c8cb2 P |
227 | /* Read in any custom ports to scan */ |
228 | loadextrascans(); | |
229 | ||
c86edd1d Q |
230 | /* Set up the database */ |
231 | if ((proxyscandbinit())!=0) { | |
232 | brokendb=1; | |
233 | } else { | |
234 | brokendb=0; | |
235 | } | |
236 | ||
7ab80d0c P |
237 | ps_commands = newcommandtree(); |
238 | addcommandtotree(ps_commands, "showcommands", 0, 0, &proxyscandoshowcommands); | |
239 | addcommandtotree(ps_commands, "status", 0, 0, &proxyscandostatus); | |
240 | addcommandtotree(ps_commands, "listopen", 0, 0, &proxyscandolistopen); | |
241 | addcommandtotree(ps_commands, "save", 0, 0, &proxyscandosave); | |
242 | addcommandtotree(ps_commands, "spew", 0, 0, &proxyscandospew); | |
243 | addcommandtotree(ps_commands, "showkill", 0, 0, &proxyscandoshowkill); | |
244 | addcommandtotree(ps_commands, "scan", 0, 0, &proxyscandoscan); | |
245 | addcommandtotree(ps_commands, "addscan", 0, 0, &proxyscandoaddscan); | |
246 | addcommandtotree(ps_commands, "delscan", 0, 0, &proxyscandodelscan); | |
247 | ||
c86edd1d Q |
248 | /* Default scan types */ |
249 | proxyscan_addscantype(STYPE_HTTP, 8080); | |
250 | proxyscan_addscantype(STYPE_HTTP, 80); | |
251 | proxyscan_addscantype(STYPE_HTTP, 6588); | |
252 | proxyscan_addscantype(STYPE_HTTP, 8000); | |
253 | proxyscan_addscantype(STYPE_HTTP, 3128); | |
254 | proxyscan_addscantype(STYPE_HTTP, 3802); | |
255 | proxyscan_addscantype(STYPE_HTTP, 5490); | |
256 | proxyscan_addscantype(STYPE_HTTP, 7441); | |
257 | proxyscan_addscantype(STYPE_HTTP, 808); | |
258 | proxyscan_addscantype(STYPE_HTTP, 3332); | |
259 | proxyscan_addscantype(STYPE_HTTP, 2282); | |
0a85c6ba | 260 | proxyscan_addscantype(STYPE_SOCKS4, 559); |
c86edd1d Q |
261 | proxyscan_addscantype(STYPE_SOCKS4, 1080); |
262 | proxyscan_addscantype(STYPE_SOCKS5, 1080); | |
263 | proxyscan_addscantype(STYPE_SOCKS4, 1075); | |
264 | proxyscan_addscantype(STYPE_SOCKS5, 1075); | |
265 | proxyscan_addscantype(STYPE_SOCKS4, 2280); | |
266 | proxyscan_addscantype(STYPE_SOCKS5, 2280); | |
267 | proxyscan_addscantype(STYPE_SOCKS4, 1180); | |
268 | proxyscan_addscantype(STYPE_SOCKS5, 1180); | |
0a85c6ba P |
269 | proxyscan_addscantype(STYPE_SOCKS4, 9999); |
270 | proxyscan_addscantype(STYPE_SOCKS5, 9999); | |
c86edd1d Q |
271 | proxyscan_addscantype(STYPE_WINGATE, 23); |
272 | proxyscan_addscantype(STYPE_CISCO, 23); | |
273 | proxyscan_addscantype(STYPE_WINGATE, 1181); | |
274 | proxyscan_addscantype(STYPE_SOCKS5, 1978); | |
275 | proxyscan_addscantype(STYPE_SOCKS5, 1029); | |
276 | proxyscan_addscantype(STYPE_SOCKS5, 3801); | |
277 | proxyscan_addscantype(STYPE_SOCKS5, 3331); | |
278 | proxyscan_addscantype(STYPE_HTTP, 65506); | |
279 | proxyscan_addscantype(STYPE_HTTP, 63809); | |
905c2ba2 | 280 | proxyscan_addscantype(STYPE_HTTP, 63000); |
92f1d9e3 | 281 | proxyscan_addscantype(STYPE_SOCKS4, 29992); |
7ab80d0c | 282 | |
c86edd1d Q |
283 | /* Schedule saves */ |
284 | schedulerecurring(time(NULL)+3600,0,3600,&dumpcachehosts,NULL); | |
7ab80d0c P |
285 | |
286 | ps_logfile=fopen("logs/proxyscan.log","a"); | |
c86edd1d | 287 | |
7ab80d0c P |
288 | if (connected) { |
289 | /* if we're already connected, assume we're just reloading module (i.e. have a completed burst) */ | |
290 | ps_ready = 1; | |
291 | startqueuedscans(); | |
292 | } | |
c86edd1d Q |
293 | } |
294 | ||
295 | void registerproxyscannick(void *arg) { | |
296 | sstring *psnick,*psuser,*pshost,*psrealname; | |
297 | /* Set up our nick on the network */ | |
cfd3214b | 298 | channel *cp; |
c86edd1d Q |
299 | |
300 | psnick=getcopyconfigitem("proxyscan","nick","P",NICKLEN); | |
301 | psuser=getcopyconfigitem("proxyscan","user","proxyscan",USERLEN); | |
302 | pshost=getcopyconfigitem("proxyscan","host","some.host",HOSTLEN); | |
303 | psrealname=getcopyconfigitem("proxyscan","realname","Proxyscan",REALLEN); | |
304 | ||
305 | proxyscannick=registerlocaluser(psnick->content,psuser->content,pshost->content, | |
306 | psrealname->content, | |
307 | NULL,UMODE_OPER|UMODE_SERVICE|UMODE_DEAF, | |
308 | &proxyscanuserhandler); | |
309 | ||
310 | freesstring(psnick); | |
311 | freesstring(psuser); | |
312 | freesstring(pshost); | |
313 | freesstring(psrealname); | |
cfd3214b CP |
314 | |
315 | cp=findchannel("#twilightzone"); | |
316 | if (!cp) { | |
317 | localcreatechannel(proxyscannick,"#twilightzone"); | |
318 | } else { | |
319 | localjoinchannel(proxyscannick,cp); | |
320 | localgetops(proxyscannick,cp); | |
321 | } | |
c86edd1d Q |
322 | } |
323 | ||
324 | void _fini(void) { | |
325 | ||
326 | deregisterlocaluser(proxyscannick,NULL); | |
557c8cb2 | 327 | |
7ab80d0c | 328 | deregisterhook(HOOK_SERVER_END_OF_BURST, &proxyscan_onconnect); |
c86edd1d Q |
329 | |
330 | deregisterhook(HOOK_NICK_NEWNICK,&proxyscan_newnick); | |
331 | ||
332 | deregisterhook(HOOK_CORE_STATSREQUEST,&proxyscanstats); | |
333 | ||
334 | deleteschedule(NULL,&dumpcachehosts,NULL); | |
7ab80d0c P |
335 | |
336 | destroycommandtree(ps_commands); | |
337 | ||
c86edd1d Q |
338 | /* Kill any scans in progress */ |
339 | killallscans(); | |
340 | ||
341 | /* Dump the database - AFTER killallscans() which prunes it */ | |
342 | dumpcachehosts(NULL); | |
343 | ||
7ab80d0c P |
344 | /* dump any cached hosts before deleting the extensions */ |
345 | releasenodeext(ps_cache_ext); | |
346 | releasenodeext(ps_extscan_ext); | |
347 | ||
c86edd1d | 348 | /* free() all our structures */ |
818e3d5f | 349 | nsfreeall(POOL_PROXYSCAN); |
c86edd1d | 350 | |
6e228f06 | 351 | freesstring(myipstr); |
c86edd1d Q |
352 | freesstring(ps_mailname); |
353 | #if defined(PROXYSCAN_MAIL) | |
354 | if (psm_mailerfd!=-1) | |
355 | deregisterhandler(psm_mailerfd,1); | |
356 | #endif | |
357 | ||
358 | if (ps_logfile) | |
359 | fclose(ps_logfile); | |
360 | } | |
361 | ||
362 | void proxyscanuserhandler(nick *target, int message, void **params) { | |
363 | nick *sender; | |
7ab80d0c P |
364 | Command *ps_command; |
365 | char *cargv[20]; | |
366 | int cargc; | |
c86edd1d Q |
367 | |
368 | switch(message) { | |
369 | case LU_KILLED: | |
370 | scheduleoneshot(time(NULL)+1,®isterproxyscannick,NULL); | |
371 | proxyscannick=NULL; | |
372 | break; | |
373 | ||
374 | case LU_PRIVMSG: | |
375 | case LU_SECUREMSG: | |
376 | sender=(nick *)params[0]; | |
c86edd1d Q |
377 | |
378 | if (IsOper(sender)) { | |
7ab80d0c | 379 | cargc = splitline((char *)params[1], cargv, 20, 0); |
7d228b1d | 380 | |
7ab80d0c P |
381 | if ( cargc == 0 ) |
382 | return; | |
7d228b1d | 383 | |
7ab80d0c | 384 | ps_command = findcommandintree(ps_commands, cargv[0], 1); |
7d228b1d | 385 | |
7ab80d0c P |
386 | if ( !ps_command ) { |
387 | sendnoticetouser(proxyscannick,sender, "Unknown command."); | |
388 | return; | |
c86edd1d Q |
389 | } |
390 | ||
7ab80d0c P |
391 | if ( ps_command->maxparams < (cargc-1) ) { |
392 | rejoinline(cargv[ps_command->maxparams], cargc - (ps_command->maxparams)); | |
393 | cargc = (ps_command->maxparams) + 1; | |
c86edd1d Q |
394 | } |
395 | ||
7ab80d0c P |
396 | (ps_command->handler)((void *)sender, cargc - 1, &(cargv[1])); |
397 | break; | |
c86edd1d Q |
398 | } |
399 | ||
400 | default: | |
401 | break; | |
402 | } | |
403 | } | |
404 | ||
405 | void addscantohash(scan *sp) { | |
406 | int hash; | |
407 | hash=(sp->fd)%SCANHASHSIZE; | |
408 | ||
409 | sp->next=scantable[hash]; | |
410 | scantable[hash]=sp; | |
411 | ||
412 | activescans++; | |
413 | } | |
414 | ||
415 | void delscanfromhash(scan *sp) { | |
416 | int hash; | |
417 | scan **sh; | |
418 | ||
419 | hash=(sp->fd)%SCANHASHSIZE; | |
420 | ||
421 | for (sh=&(scantable[hash]);*sh;sh=&((*sh)->next)) { | |
422 | if (*sh==sp) { | |
423 | (*sh)=sp->next; | |
424 | break; | |
425 | } | |
426 | } | |
427 | ||
428 | activescans--; | |
429 | } | |
430 | ||
431 | scan *findscan(int fd) { | |
432 | int hash; | |
433 | scan *sp; | |
434 | ||
435 | hash=fd%SCANHASHSIZE; | |
436 | ||
437 | for (sp=scantable[hash];sp;sp=sp->next) | |
438 | if (sp->fd==fd) | |
439 | return sp; | |
440 | ||
441 | return NULL; | |
442 | } | |
443 | ||
557c8cb2 | 444 | void startscan(patricia_node_t *node, int type, int port, int class) { |
c86edd1d | 445 | scan *sp; |
92f1d9e3 D |
446 | float scantmp; |
447 | ||
448 | if (scansdone>maxscans) | |
449 | { | |
450 | /* ignore the first maxscans as this will skew our scans per second! */ | |
451 | tempscanspermin++; | |
452 | if ((lastscants+60) <= time(NULL)) | |
453 | { | |
454 | /* ok, at least 60 seconds has passed, calculate the scans per minute figure */ | |
455 | scantmp = time(NULL) - lastscants; | |
456 | scantmp = tempscanspermin / scantmp; | |
457 | scantmp = (scantmp * 60); | |
458 | scanspermin = scantmp; | |
459 | lastscants = time(NULL); | |
460 | tempscanspermin = 0; | |
461 | } | |
462 | } | |
c86edd1d Q |
463 | |
464 | sp=getscan(); | |
465 | ||
466 | sp->outcome=SOUTCOME_INPROGRESS; | |
467 | sp->port=port; | |
557c8cb2 | 468 | sp->node=node; |
c86edd1d Q |
469 | sp->type=type; |
470 | sp->class=class; | |
471 | sp->bytesread=0; | |
472 | sp->totalbytesread=0; | |
473 | memset(sp->readbuf, '\0', PSCAN_READBUFSIZE); | |
474 | ||
557c8cb2 | 475 | sp->fd=createconnectsocket(irc_in_addr_v4_to_int(&((patricia_node_t *)sp->node)->prefix->sin),sp->port); |
c86edd1d Q |
476 | sp->state=SSTATE_CONNECTING; |
477 | if (sp->fd<0) { | |
478 | /* Couldn't set up the socket? */ | |
479 | freescan(sp); | |
480 | return; | |
481 | } | |
482 | /* Wait until it is writeable */ | |
483 | registerhandler(sp->fd,POLLERR|POLLHUP|POLLOUT,&handlescansock); | |
484 | /* And set a timeout */ | |
485 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
486 | addscantohash(sp); | |
487 | } | |
488 | ||
489 | void timeoutscansock(void *arg) { | |
490 | scan *sp=(scan *)arg; | |
491 | ||
492 | killsock(sp, SOUTCOME_CLOSED); | |
493 | } | |
494 | ||
495 | void killsock(scan *sp, int outcome) { | |
496 | int i; | |
497 | cachehost *chp; | |
498 | foundproxy *fpp; | |
499 | ||
500 | scansdone++; | |
501 | scansbyclass[sp->class]++; | |
502 | ||
503 | /* Remove the socket from the schedule/event lists */ | |
504 | deregisterhandler(sp->fd,1); /* this will close the fd for us */ | |
505 | deleteschedule(sp->sch,&timeoutscansock,(void *)sp); | |
506 | ||
507 | sp->outcome=outcome; | |
508 | delscanfromhash(sp); | |
509 | ||
510 | /* See if we need to queue another scan.. */ | |
511 | if (sp->outcome==SOUTCOME_CLOSED && | |
512 | ((sp->class==SCLASS_CHECK) || | |
513 | (sp->class==SCLASS_NORMAL && (sp->state==SSTATE_SENTREQUEST || sp->state==SSTATE_GOTRESPONSE)))) | |
557c8cb2 | 514 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS2, time(NULL)+300); |
c86edd1d Q |
515 | |
516 | if (sp->outcome==SOUTCOME_CLOSED && sp->class==SCLASS_PASS2) | |
557c8cb2 | 517 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS3, time(NULL)+300); |
c86edd1d Q |
518 | |
519 | if (sp->outcome==SOUTCOME_CLOSED && sp->class==SCLASS_PASS3) | |
557c8cb2 | 520 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS4, time(NULL)+300); |
c86edd1d Q |
521 | |
522 | if (sp->outcome==SOUTCOME_OPEN) { | |
523 | hitsbyclass[sp->class]++; | |
524 | ||
525 | /* Lets try and get the cache record. If there isn't one, make a new one. */ | |
557c8cb2 P |
526 | if (!(chp=findcachehost(sp->node))) { |
527 | chp=addcleanhost(time(NULL)); | |
528 | patricia_ref_prefix(sp->node->prefix); | |
a8ba1373 | 529 | sp->node->exts[ps_cache_ext] = chp; |
557c8cb2 | 530 | } |
c86edd1d Q |
531 | /* Stick it on the cache's list of proxies, if necessary */ |
532 | for (fpp=chp->proxies;fpp;fpp=fpp->next) | |
533 | if (fpp->type==sp->type && fpp->port==sp->port) | |
534 | break; | |
535 | ||
536 | if (!fpp) { | |
537 | fpp=getfoundproxy(); | |
538 | fpp->type=sp->type; | |
539 | fpp->port=sp->port; | |
540 | fpp->next=chp->proxies; | |
541 | chp->proxies=fpp; | |
542 | } | |
543 | ||
544 | if (!chp->glineid) { | |
545 | glinedhosts++; | |
557c8cb2 | 546 | loggline(chp, sp->node); |
68e41288 P |
547 | irc_send("%s GL * +*@%s 1800 %jd :Open Proxy, see http://www.quakenet.org/openproxies.html - ID: %d", |
548 | mynumeric->content,IPtostr(((patricia_node_t *)sp->node)->prefix->sin),(intmax_t)getnettime(), chp->glineid); | |
557c8cb2 | 549 | Error("proxyscan",ERR_DEBUG,"Found open proxy on host %s",IPtostr(((patricia_node_t *)sp->node)->prefix->sin)); |
c86edd1d | 550 | } else { |
557c8cb2 | 551 | loggline(chp, sp->node); /* Update log only */ |
c86edd1d Q |
552 | } |
553 | ||
554 | /* Update counter */ | |
555 | for(i=0;i<numscans;i++) { | |
556 | if (thescans[i].type==sp->type && thescans[i].port==sp->port) { | |
557 | thescans[i].hits++; | |
558 | break; | |
559 | } | |
560 | } | |
561 | } | |
562 | ||
563 | freescan(sp); | |
564 | ||
565 | /* kick the queue.. */ | |
566 | startqueuedscans(); | |
567 | } | |
568 | ||
569 | void handlescansock(int fd, short events) { | |
570 | scan *sp; | |
571 | char buf[512]; | |
572 | int res; | |
573 | int i; | |
574 | unsigned long netip; | |
575 | unsigned short netport; | |
576 | ||
577 | if ((sp=findscan(fd))==NULL) { | |
578 | /* Not found; return and hope it goes away */ | |
579 | Error("proxyscan",ERR_ERROR,"Unexpected message from fd %d",fd); | |
580 | return; | |
581 | } | |
582 | ||
583 | /* It woke up, delete the alarm call.. */ | |
584 | deleteschedule(sp->sch,&timeoutscansock,(void *)sp); | |
585 | ||
586 | if (events & (POLLERR|POLLHUP)) { | |
587 | /* Some kind of error; give up on this socket */ | |
588 | if (sp->state==SSTATE_GOTRESPONSE) { | |
589 | /* If the error occured while we were waiting for a response, we might have | |
590 | * received the "OPEN PROXY!" message and the EOF at the same time, so continue | |
591 | * processing */ | |
592 | /* Error("proxyscan",ERR_DEBUG,"Got error in GOTRESPONSE state for %s, continuing.",IPtostr(sp->host->IP)); */ | |
593 | } else { | |
594 | killsock(sp, SOUTCOME_CLOSED); | |
595 | return; | |
596 | } | |
597 | } | |
598 | ||
599 | /* Otherwise, we got what we wanted.. */ | |
600 | ||
601 | switch(sp->state) { | |
602 | case SSTATE_CONNECTING: | |
603 | /* OK, we got activity while connecting, so we're going to send some | |
604 | * request depending on scan type. However, we can reregister everything | |
605 | * here to save duplicate code: This code is common for all handlers */ | |
606 | ||
607 | /* Delete the old handler */ | |
608 | deregisterhandler(fd,0); | |
609 | /* Set the new one */ | |
610 | registerhandler(fd,POLLERR|POLLHUP|POLLIN,&handlescansock); | |
611 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
612 | /* Update state */ | |
613 | sp->state=SSTATE_SENTREQUEST; | |
614 | ||
615 | switch(sp->type) { | |
616 | case STYPE_HTTP: | |
617 | sprintf(buf,"CONNECT %s:%d HTTP/1.0\r\n\r\n",myipstr->content,listenport); | |
618 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
619 | /* We didn't write the full amount, DIE */ | |
620 | killsock(sp,SOUTCOME_CLOSED); | |
621 | return; | |
622 | } | |
623 | break; | |
624 | ||
625 | case STYPE_SOCKS4: | |
626 | /* set up the buffer */ | |
627 | netip=htonl(myip); | |
628 | netport=htons(listenport); | |
629 | memcpy(&buf[4],&netip,4); | |
630 | memcpy(&buf[2],&netport,2); | |
631 | buf[0]=4; | |
632 | buf[1]=1; | |
633 | buf[8]=0; | |
634 | if ((write(fd,buf,9))<9) { | |
635 | /* Didn't write enough, give up */ | |
636 | killsock(sp,SOUTCOME_CLOSED); | |
637 | return; | |
638 | } | |
639 | break; | |
640 | ||
641 | case STYPE_SOCKS5: | |
642 | /* Set up initial request buffer */ | |
643 | buf[0]=5; | |
644 | buf[1]=1; | |
645 | buf[2]=0; | |
646 | if ((write(fd,buf,3))>3) { | |
647 | /* Didn't write enough, give up */ | |
648 | killsock(sp,SOUTCOME_CLOSED); | |
649 | return; | |
650 | } | |
651 | ||
652 | /* Now the actual connect request */ | |
653 | buf[0]=5; | |
654 | buf[1]=1; | |
655 | buf[2]=0; | |
656 | buf[3]=1; | |
657 | netip=htonl(myip); | |
658 | netport=htons(listenport); | |
659 | memcpy(&buf[4],&netip,4); | |
660 | memcpy(&buf[8],&netport,2); | |
661 | res=write(fd,buf,10); | |
662 | if (res<10) { | |
663 | killsock(sp,SOUTCOME_CLOSED); | |
664 | return; | |
665 | } | |
666 | break; | |
667 | ||
668 | case STYPE_WINGATE: | |
669 | /* Send wingate request */ | |
670 | sprintf(buf,"%s:%d\r\n",myipstr->content,listenport); | |
671 | if((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
672 | killsock(sp,SOUTCOME_CLOSED); | |
673 | return; | |
674 | } | |
675 | break; | |
676 | ||
677 | case STYPE_CISCO: | |
678 | /* Send cisco request */ | |
679 | sprintf(buf,"cisco\r\n"); | |
680 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
681 | killsock(sp, SOUTCOME_CLOSED); | |
682 | return; | |
683 | } | |
684 | ||
685 | sprintf(buf,"telnet %s %d\r\n",myipstr->content,listenport); | |
686 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
687 | killsock(sp, SOUTCOME_CLOSED); | |
688 | return; | |
689 | } | |
690 | ||
905c2ba2 | 691 | break; |
692 | ||
693 | case STYPE_DIRECT: | |
694 | /* Do nothing */ | |
c86edd1d Q |
695 | break; |
696 | } | |
697 | break; | |
698 | ||
699 | case SSTATE_SENTREQUEST: | |
700 | res=read(fd, sp->readbuf+sp->bytesread, PSCAN_READBUFSIZE-sp->bytesread); | |
701 | ||
702 | if (res<=0) { | |
703 | if ((errno!=EINTR && errno!=EWOULDBLOCK) || res==0) { | |
704 | /* EOF, forget it */ | |
705 | killsock(sp, SOUTCOME_CLOSED); | |
706 | return; | |
707 | } | |
708 | } | |
709 | ||
710 | sp->bytesread+=res; | |
711 | sp->totalbytesread+=res; | |
712 | for (i=0;i<sp->bytesread - MAGICSTRINGLENGTH;i++) { | |
713 | if (!strncmp(sp->readbuf+i, MAGICSTRING, MAGICSTRINGLENGTH)) { | |
714 | /* Found the magic string */ | |
715 | /* If the offset is 0, this means it was the first thing we got from the socket, | |
716 | * so it's an actual IRCD (sheesh). Note that when the buffer is full and moved, | |
717 | * the thing moved to offset 0 would previously have been tested as offset | |
905c2ba2 | 718 | * PSCAN_READBUFSIZE/2. |
719 | * | |
720 | * Skip this checking for STYPE_DIRECT scans, which are used to detect trojans setting | |
721 | * up portforwards (which will therefore show up as ircds, we rely on the port being | |
722 | * strange enough to avoid false positives */ | |
723 | if (i==0 && (sp->type != STYPE_DIRECT)) { | |
c86edd1d Q |
724 | killsock(sp, SOUTCOME_CLOSED); |
725 | return; | |
726 | } | |
727 | ||
728 | killsock(sp, SOUTCOME_OPEN); | |
729 | return; | |
730 | } | |
731 | } | |
732 | ||
733 | /* If the buffer is full, move half of it along to make room */ | |
734 | if (sp->bytesread == PSCAN_READBUFSIZE) { | |
735 | memcpy(sp->readbuf, sp->readbuf + (PSCAN_READBUFSIZE)/2, PSCAN_READBUFSIZE/2); | |
736 | sp->bytesread = PSCAN_READBUFSIZE/2; | |
737 | } | |
738 | ||
739 | /* Don't read data forever.. */ | |
740 | if (sp->totalbytesread > READ_SANITY_LIMIT) { | |
741 | killsock(sp, SOUTCOME_CLOSED); | |
742 | return; | |
743 | } | |
744 | ||
745 | /* No magic string yet, we schedule another timeout in case it comes later. */ | |
746 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
747 | return; | |
748 | } | |
749 | } | |
750 | ||
751 | void killallscans() { | |
752 | int i; | |
753 | scan *sp; | |
754 | cachehost *chp; | |
755 | ||
756 | for(i=0;i<SCANHASHSIZE;i++) { | |
757 | for(sp=scantable[i];sp;sp=sp->next) { | |
758 | /* If there is a pending scan, delete it's clean host record.. */ | |
a8ba1373 P |
759 | if ((chp=findcachehost(sp->node)) && !chp->proxies) { |
760 | sp->node->exts[ps_cache_ext] = NULL; | |
761 | derefnode(iptree,sp->node); | |
c86edd1d | 762 | delcachehost(chp); |
a8ba1373 | 763 | } |
c86edd1d Q |
764 | |
765 | if (sp->fd!=-1) { | |
766 | deregisterhandler(sp->fd,1); | |
767 | deleteschedule(sp->sch,&timeoutscansock,(void *)(sp)); | |
768 | } | |
769 | } | |
770 | } | |
771 | } | |
772 | ||
773 | void proxyscanstats(int hooknum, void *arg) { | |
774 | char buf[512]; | |
775 | ||
776 | sprintf(buf, "Proxyscn: %6d/%4d scans complete/in progress. %d hosts queued.", | |
777 | scansdone,activescans,queuedhosts); | |
778 | triggerhook(HOOK_CORE_STATSREPLY,buf); | |
779 | sprintf(buf, "Proxyscn: %6u known clean hosts",cleancount()); | |
780 | triggerhook(HOOK_CORE_STATSREPLY,buf); | |
781 | } | |
782 | ||
783 | void sendlagwarning() { | |
784 | int i,j; | |
785 | nick *np; | |
786 | ||
787 | for (i=0;i<MAXSERVERS;i++) { | |
788 | if (serverlist[i].maxusernum>0) { | |
789 | for(j=0;j<serverlist[i].maxusernum;j++) { | |
790 | np=servernicks[i][j]; | |
791 | if (np!=NULL && IsOper(np)) { | |
792 | sendnoticetouser(proxyscannick,np,"Warning: More than 20,000 hosts to scan - I'm lagging behind badly!"); | |
793 | } | |
794 | } | |
795 | } | |
796 | } | |
797 | } | |
798 | ||
905c2ba2 | 799 | int pscansort(const void *a, const void *b) { |
800 | int ra = *((const int *)a); | |
801 | int rb = *((const int *)b); | |
802 | ||
803 | return thescans[ra].hits - thescans[rb].hits; | |
804 | } | |
805 | ||
7ab80d0c P |
806 | int proxyscandostatus(void *sender, int cargc, char **cargv) { |
807 | nick *np = (nick *) sender; | |
c86edd1d Q |
808 | int i; |
809 | int totaldetects=0; | |
905c2ba2 | 810 | int ord[PSCAN_MAXSCANS]; |
c86edd1d | 811 | |
2220c058 | 812 | sendnoticetouser(proxyscannick,np,"Service uptime: %s",longtoduration(time(NULL)-ps_starttime, 1)); |
c86edd1d Q |
813 | sendnoticetouser(proxyscannick,np,"Total scans completed: %d",scansdone); |
814 | sendnoticetouser(proxyscannick,np,"Total hosts glined: %d",glinedhosts); | |
815 | ||
c651da74 | 816 | sendnoticetouser(proxyscannick,np,"pendingscan structures: %lu x %lu bytes = %lu bytes total",countpendingscan, |
92f1d9e3 D |
817 | sizeof(pendingscan), (countpendingscan * sizeof(pendingscan))); |
818 | ||
c86edd1d | 819 | sendnoticetouser(proxyscannick,np,"Currently active scans: %d/%d",activescans,maxscans); |
92f1d9e3 | 820 | sendnoticetouser(proxyscannick,np,"Processing speed: %lu scans per minute",scanspermin); |
c86edd1d Q |
821 | sendnoticetouser(proxyscannick,np,"Normal queued scans: %d",normalqueuedscans); |
822 | sendnoticetouser(proxyscannick,np,"Timed queued scans: %d",prioqueuedscans); | |
823 | sendnoticetouser(proxyscannick,np,"'Clean' cached hosts: %d",cleancount()); | |
824 | sendnoticetouser(proxyscannick,np,"'Dirty' cached hosts: %d",dirtycount()); | |
557c8cb2 P |
825 | |
826 | sendnoticetouser(proxyscannick,np,"Extra scans: %d", extrascancount()); | |
c86edd1d Q |
827 | for (i=0;i<5;i++) |
828 | sendnoticetouser(proxyscannick,np,"Open proxies, class %1d: %d/%d (%.2f%%)",i,hitsbyclass[i],scansbyclass[i],((float)hitsbyclass[i]*100)/scansbyclass[i]); | |
829 | ||
830 | for (i=0;i<numscans;i++) | |
831 | totaldetects+=thescans[i].hits; | |
832 | ||
905c2ba2 | 833 | for (i=0;i<numscans;i++) |
834 | ord[i]=i; | |
835 | ||
836 | qsort(ord,numscans,sizeof(int),pscansort); | |
837 | ||
c86edd1d Q |
838 | sendnoticetouser(proxyscannick,np,"Scan type Port Detections"); |
839 | for (i=0;i<numscans;i++) | |
840 | sendnoticetouser(proxyscannick,np,"%-9s %-5d %d (%.2f%%)", | |
905c2ba2 | 841 | scantostr(thescans[ord[i]].type), thescans[ord[i]].port, thescans[ord[i]].hits, ((float)thescans[ord[i]].hits*100)/totaldetects); |
c86edd1d Q |
842 | |
843 | sendnoticetouser(proxyscannick,np,"End of list."); | |
7ab80d0c | 844 | return CMD_OK; |
c86edd1d Q |
845 | } |
846 | ||
7ab80d0c | 847 | int proxyscandebug(void *sender, int cargc, char **cargv) { |
c86edd1d Q |
848 | /* Dump all scans.. */ |
849 | int i; | |
850 | int activescansfound=0; | |
851 | int totalscansfound=0; | |
852 | scan *sp; | |
7ab80d0c | 853 | nick *np = (nick *)sender; |
c86edd1d Q |
854 | |
855 | sendnoticetouser(proxyscannick,np,"Active scans : %d",activescans); | |
856 | ||
857 | for (i=0;i<SCANHASHSIZE;i++) { | |
858 | for (sp=scantable[i];sp;sp=sp->next) { | |
859 | if (sp->outcome==SOUTCOME_INPROGRESS) { | |
860 | activescansfound++; | |
861 | } | |
862 | totalscansfound++; | |
863 | sendnoticetouser(proxyscannick,np,"fd: %d type: %d port: %d state: %d outcome: %d IP: %s", | |
557c8cb2 | 864 | sp->fd,sp->type,sp->port,sp->state,sp->outcome,IPtostr(((patricia_node_t *)sp->node)->prefix->sin)); |
c86edd1d Q |
865 | } |
866 | } | |
867 | ||
7ab80d0c P |
868 | sendnoticetouser(proxyscannick,np,"Total %d scans actually found (%d active)",totalscansfound,activescansfound); |
869 | return CMD_OK; | |
870 | } | |
871 | ||
872 | void proxyscan_onconnect(int hooknum, void *arg) { | |
873 | ps_ready = 1; | |
874 | ||
875 | /* kick the queue.. */ | |
876 | startqueuedscans(); | |
877 | } | |
878 | ||
879 | int proxyscandosave(void *sender, int cargc, char **cargv) { | |
880 | nick *np = (nick *)sender; | |
881 | ||
882 | sendnoticetouser(proxyscannick,np,"Saving cached hosts..."); | |
883 | dumpcachehosts(NULL); | |
884 | sendnoticetouser(proxyscannick,np,"Done."); | |
885 | return CMD_OK; | |
886 | } | |
887 | ||
888 | int proxyscandospew(void *sender, int cargc, char **cargv) { | |
889 | nick *np = (nick *)sender; | |
890 | ||
891 | /* check our database for the ip supplied */ | |
892 | unsigned long a,b,c,d; | |
893 | if (4 != sscanf(cargv[0],"%lu.%lu.%lu.%lu",&a,&b,&c,&d)) { | |
894 | sendnoticetouser(proxyscannick,np,"Usage: spew x.x.x.x"); | |
895 | } else { | |
896 | /* check db */ | |
897 | proxyscanspewip(proxyscannick,np,a,b,c,d); | |
898 | } | |
899 | return CMD_OK; | |
900 | } | |
901 | ||
902 | int proxyscandoshowkill(void *sender, int cargc, char **cargv) { | |
903 | nick *np = (nick *)sender; | |
904 | ||
905 | /* check our database for the id supplied */ | |
906 | unsigned long a; | |
907 | if (1 != sscanf(cargv[0],"%lu",&a)) { | |
908 | sendnoticetouser(proxyscannick,np,"Usage: showkill <id>"); | |
909 | } else { | |
910 | /* check db */ | |
911 | proxyscanshowkill(proxyscannick,np,a); | |
912 | } | |
913 | return CMD_OK; | |
914 | } | |
915 | ||
916 | int proxyscandoscan(void *sender, int cargc, char **cargv) { | |
917 | nick *np = (nick *)sender; | |
918 | patricia_node_t *node; | |
919 | struct irc_in_addr sin; | |
920 | unsigned char bits; | |
921 | int i; | |
922 | ||
923 | if (0 == ipmask_parse(cargv[0],&sin, &bits)) { | |
924 | sendnoticetouser(proxyscannick,np,"Usage: scan <ip>"); | |
925 | } else { | |
926 | sendnoticetouser(proxyscannick,np,"Forcing scan of %s",IPtostr(sin)); | |
927 | // * Just queue the scans directly here.. plonk them on the priority queue * / | |
928 | node = refnode(iptree, &sin, bits); /* node leaks node here - should only allow to scan a nick? */ | |
929 | for(i=0;i<numscans;i++) { | |
930 | /* @@@TODO: we allow a forced scan to scan the same IP multiple times atm */ | |
931 | queuescan(node,thescans[i].type,thescans[i].port,SCLASS_NORMAL,time(NULL)); | |
557c8cb2 | 932 | } |
7ab80d0c P |
933 | } |
934 | return CMD_OK; | |
935 | } | |
557c8cb2 | 936 | |
7ab80d0c P |
937 | int proxyscandoaddscan(void *sender, int cargc, char **cargv) { |
938 | nick *np = (nick *)sender; | |
939 | ||
940 | unsigned int a,b; | |
941 | if (sscanf(cargv[0],"%u %u",&a,&b) != 2) { | |
942 | sendnoticetouser(proxyscannick,np,"Usage: addscan <type> <port>"); | |
943 | } else { | |
944 | sendnoticetouser(proxyscannick,np,"Added scan type %u port %u",a,b); | |
945 | proxyscan_addscantype(a,b); | |
946 | scanall(a,b); | |
947 | } | |
948 | return CMD_OK; | |
949 | } | |
950 | ||
951 | int proxyscandodelscan(void *sender, int cargc, char **cargv) { | |
952 | nick *np = (nick *)sender; | |
953 | ||
954 | unsigned int a,b; | |
955 | if (sscanf(cargv[0],"%u %u",&a,&b) != 2) { | |
956 | sendnoticetouser(proxyscannick,np,"Usage: delscan <type> <port>"); | |
957 | } else { | |
958 | sendnoticetouser(proxyscannick,np,"Delete scan type %u port %u",a,b); | |
959 | proxyscan_delscantype(a,b); | |
960 | } | |
961 | return CMD_OK; | |
962 | } | |
963 | ||
964 | int proxyscandoshowcommands(void *sender, int cargc, char **cargv) { | |
965 | nick *np = (nick *)sender; | |
966 | Command *cmdlist[100]; | |
967 | int i,n; | |
968 | ||
969 | n=getcommandlist(ps_commands,cmdlist,100); | |
970 | ||
971 | sendnoticetouser(proxyscannick,np,"The following commands are registered at present:"); | |
972 | for(i=0;i<n;i++) { | |
973 | sendnoticetouser(proxyscannick,np,"%s",cmdlist[i]->command->content); | |
974 | } | |
975 | sendnoticetouser(proxyscannick,np,"End of list."); | |
976 | return CMD_OK; | |
c86edd1d | 977 | } |