]>
Commit | Line | Data |
---|---|---|
1 | ||
2 | #include "proxyscan.h" | |
3 | ||
4 | #include <sys/poll.h> | |
5 | #include <sys/types.h> | |
6 | #include <sys/socket.h> | |
7 | #include <netdb.h> | |
8 | #include "../core/error.h" | |
9 | #include "../core/events.h" | |
10 | #include <stdlib.h> | |
11 | #include <stdio.h> | |
12 | #include <errno.h> | |
13 | #include "../nick/nick.h" | |
14 | #include "../core/hooks.h" | |
15 | #include "../lib/sstring.h" | |
16 | #include "../irc/irc_config.h" | |
17 | #include "../localuser/localuser.h" | |
18 | #include "../core/config.h" | |
19 | #include <unistd.h> | |
20 | #include "../core/schedule.h" | |
21 | #include <string.h> | |
22 | #include "../irc/irc.h" | |
23 | #include "../lib/irc_string.h" | |
24 | #include "../lib/version.h" | |
25 | #include "../channel/channel.h" | |
26 | #include "../localuser/localuserchannel.h" | |
27 | #include "../core/nsmalloc.h" | |
28 | #include "../lib/irc_ipv6.h" | |
29 | ||
30 | MODULE_VERSION("") | |
31 | ||
32 | #define SCANTIMEOUT 60 | |
33 | ||
34 | #define SCANHOSTHASHSIZE 1000 | |
35 | #define SCANHASHSIZE 400 | |
36 | ||
37 | /* It's unlikely you'll get 100k of preamble before a connect... */ | |
38 | #define READ_SANITY_LIMIT 102400 | |
39 | ||
40 | scan *scantable[SCANHASHSIZE]; | |
41 | ||
42 | CommandTree *ps_commands; | |
43 | ||
44 | int listenfd; | |
45 | int activescans; | |
46 | int maxscans; | |
47 | int queuedhosts; | |
48 | int scansdone; | |
49 | int rescaninterval; | |
50 | int warningsent; | |
51 | int glinedhosts; | |
52 | time_t ps_starttime; | |
53 | int ps_cache_ext; | |
54 | int ps_extscan_ext; | |
55 | int ps_ready; | |
56 | ||
57 | int numscans; /* number of scan types currently valid */ | |
58 | scantype thescans[PSCAN_MAXSCANS]; | |
59 | ||
60 | unsigned int hitsbyclass[10]; | |
61 | unsigned int scansbyclass[10]; | |
62 | ||
63 | unsigned int myip; | |
64 | sstring *myipstr; | |
65 | unsigned short listenport; | |
66 | int brokendb; | |
67 | ||
68 | unsigned int ps_mailip; | |
69 | unsigned int ps_mailport; | |
70 | sstring *ps_mailname; | |
71 | ||
72 | unsigned long scanspermin; | |
73 | unsigned long tempscanspermin=0; | |
74 | unsigned long lastscants=0; | |
75 | ||
76 | unsigned int ps_start_ts=0; | |
77 | ||
78 | nick *proxyscannick; | |
79 | ||
80 | FILE *ps_logfile; | |
81 | ||
82 | /* Local functions */ | |
83 | void handlescansock(int fd, short events); | |
84 | void timeoutscansock(void *arg); | |
85 | void proxyscan_newnick(int hooknum, void *arg); | |
86 | void proxyscan_lostnick(int hooknum, void *arg); | |
87 | void proxyscan_onconnect(int hooknum, void *arg); | |
88 | void proxyscanuserhandler(nick *target, int message, void **params); | |
89 | void registerproxyscannick(); | |
90 | void killsock(scan *sp, int outcome); | |
91 | void killallscans(); | |
92 | void proxyscanstats(int hooknum, void *arg); | |
93 | void sendlagwarning(); | |
94 | void proxyscan_newip(nick *np, unsigned long ip); | |
95 | int proxyscan_addscantype(int type, int port); | |
96 | int proxyscan_delscantype(int type, int port); | |
97 | ||
98 | int proxyscandostatus(void *sender, int cargc, char **cargv); | |
99 | int proxyscandebug(void *sender, int cargc, char **cargv); | |
100 | int proxyscandosave(void *sender, int cargc, char **cargv); | |
101 | int proxyscandospew(void *sender, int cargc, char **cargv); | |
102 | int proxyscandoshowkill(void *sender, int cargc, char **cargv); | |
103 | int proxyscandoscan(void *sender, int cargc, char **cargv); | |
104 | int proxyscandoaddscan(void *sender, int cargc, char **cargv); | |
105 | int proxyscandodelscan(void *sender, int cargc, char **cargv); | |
106 | int proxyscandoshowcommands(void *sender, int cargc, char **cargv); | |
107 | ||
108 | int proxyscan_addscantype(int type, int port) { | |
109 | /* Check we have a spare scan slot */ | |
110 | ||
111 | if (numscans>=PSCAN_MAXSCANS) | |
112 | return 1; | |
113 | ||
114 | thescans[numscans].type=type; | |
115 | thescans[numscans].port=port; | |
116 | thescans[numscans].hits=0; | |
117 | ||
118 | numscans++; | |
119 | ||
120 | return 0; | |
121 | } | |
122 | ||
123 | int proxyscan_delscantype(int type, int port) { | |
124 | int i; | |
125 | ||
126 | for (i=0;i<numscans;i++) | |
127 | if (thescans[i].type==type && thescans[i].port==port) | |
128 | break; | |
129 | ||
130 | if (i>=numscans) | |
131 | return 1; | |
132 | ||
133 | memmove(thescans+i, thescans+(i+1), (PSCAN_MAXSCANS-(i+1)) * sizeof(scantype)); | |
134 | numscans--; | |
135 | ||
136 | return 0; | |
137 | } | |
138 | ||
139 | void _init(void) { | |
140 | sstring *cfgstr; | |
141 | int ipbits[4]; | |
142 | ||
143 | ps_start_ts = time(NULL); | |
144 | ps_ready = 0; | |
145 | ps_commands = NULL; | |
146 | ||
147 | ps_cache_ext = registernodeext("proxyscancache"); | |
148 | if( ps_cache_ext == -1 ) { | |
149 | Error("proxyscan",ERR_INFO,"failed to reg node ext"); | |
150 | return; | |
151 | } | |
152 | ps_extscan_ext = registernodeext("proxyscanextscan"); | |
153 | if ( ps_extscan_ext == -1) { | |
154 | Error("proxyscan",ERR_INFO,"failed to reg node ext"); | |
155 | return; | |
156 | } | |
157 | ||
158 | memset(scantable,0,sizeof(scantable)); | |
159 | maxscans=200; | |
160 | activescans=0; | |
161 | queuedhosts=0; | |
162 | scansdone=0; | |
163 | warningsent=0; | |
164 | ps_starttime=time(NULL); | |
165 | glinedhosts=0; | |
166 | ||
167 | scanspermin=0; | |
168 | lastscants=time(NULL); | |
169 | ||
170 | /* Listen port */ | |
171 | cfgstr=getcopyconfigitem("proxyscan","port","9999",6); | |
172 | listenport=strtol(cfgstr->content,NULL,10); | |
173 | freesstring(cfgstr); | |
174 | ||
175 | /* Max concurrent scans */ | |
176 | cfgstr=getcopyconfigitem("proxyscan","maxscans","200",5); | |
177 | maxscans=strtol(cfgstr->content,NULL,10); | |
178 | freesstring(cfgstr); | |
179 | ||
180 | /* Clean host timeout */ | |
181 | cfgstr=getcopyconfigitem("proxyscan","rescaninterval","3600",7); | |
182 | rescaninterval=strtol(cfgstr->content,NULL,10); | |
183 | cachehostinit(rescaninterval); | |
184 | freesstring(cfgstr); | |
185 | ||
186 | /* this default will NOT work well */ | |
187 | myipstr=getcopyconfigitem("proxyscan","ip","127.0.0.1",16); | |
188 | ||
189 | sscanf(myipstr->content,"%d.%d.%d.%d",&ipbits[0],&ipbits[1],&ipbits[2],&ipbits[3]); | |
190 | ||
191 | myip=((ipbits[0]&0xFF)<<24)+((ipbits[1]&0xFF)<<16)+ | |
192 | ((ipbits[2]&0xFF)<<8)+(ipbits[3]&0xFF); | |
193 | ||
194 | #if defined(PROXYSCAN_MAIL) | |
195 | /* Mailer host */ | |
196 | cfgstr=getcopyconfigitem("proxyscan","mailerip","",16); | |
197 | ||
198 | psm_mailerfd=-1; | |
199 | if (cfgstr) { | |
200 | sscanf(cfgstr->content,"%d.%d.%d.%d",&ipbits[0],&ipbits[1],&ipbits[2],&ipbits[3]); | |
201 | ps_mailip = ((ipbits[0]&0xFF)<<24)+((ipbits[1]&0xFF)<<16)+ | |
202 | ((ipbits[2]&0xFF)<<8)+(ipbits[3]&0xFF); | |
203 | ps_mailport=25; | |
204 | freesstring(cfgstr); | |
205 | ||
206 | ps_mailname=getcopyconfigitem("proxyscan","mailname","some.mail.server",HOSTLEN); | |
207 | Error("proxyscan",ERR_INFO,"Proxyscan mailer enabled; mailing to %s as %s.",IPlongtostr(ps_mailip),ps_mailname->content); | |
208 | } else { | |
209 | ps_mailport=0; | |
210 | ps_mailname=NULL; | |
211 | } | |
212 | #endif | |
213 | ||
214 | proxyscannick=NULL; | |
215 | /* Set up our nick on the network */ | |
216 | scheduleoneshot(time(NULL),®isterproxyscannick,NULL); | |
217 | ||
218 | registerhook(HOOK_SERVER_END_OF_BURST, &proxyscan_onconnect); | |
219 | ||
220 | registerhook(HOOK_NICK_NEWNICK,&proxyscan_newnick); | |
221 | ||
222 | registerhook(HOOK_CORE_STATSREQUEST,&proxyscanstats); | |
223 | ||
224 | /* Read in the clean hosts */ | |
225 | loadcachehosts(); | |
226 | ||
227 | /* Read in any custom ports to scan */ | |
228 | loadextrascans(); | |
229 | ||
230 | /* Set up the database */ | |
231 | if ((proxyscandbinit())!=0) { | |
232 | brokendb=1; | |
233 | } else { | |
234 | brokendb=0; | |
235 | } | |
236 | ||
237 | ps_commands = newcommandtree(); | |
238 | addcommandtotree(ps_commands, "showcommands", 0, 0, &proxyscandoshowcommands); | |
239 | addcommandtotree(ps_commands, "status", 0, 0, &proxyscandostatus); | |
240 | addcommandtotree(ps_commands, "listopen", 0, 0, &proxyscandolistopen); | |
241 | addcommandtotree(ps_commands, "save", 0, 0, &proxyscandosave); | |
242 | addcommandtotree(ps_commands, "spew", 0, 0, &proxyscandospew); | |
243 | addcommandtotree(ps_commands, "showkill", 0, 0, &proxyscandoshowkill); | |
244 | addcommandtotree(ps_commands, "scan", 0, 0, &proxyscandoscan); | |
245 | addcommandtotree(ps_commands, "addscan", 0, 0, &proxyscandoaddscan); | |
246 | addcommandtotree(ps_commands, "delscan", 0, 0, &proxyscandodelscan); | |
247 | ||
248 | /* Default scan types */ | |
249 | proxyscan_addscantype(STYPE_HTTP, 8080); | |
250 | proxyscan_addscantype(STYPE_HTTP, 8118); | |
251 | proxyscan_addscantype(STYPE_HTTP, 80); | |
252 | proxyscan_addscantype(STYPE_HTTP, 6588); | |
253 | proxyscan_addscantype(STYPE_HTTP, 8000); | |
254 | proxyscan_addscantype(STYPE_HTTP, 3128); | |
255 | proxyscan_addscantype(STYPE_HTTP, 3802); | |
256 | proxyscan_addscantype(STYPE_HTTP, 5490); | |
257 | proxyscan_addscantype(STYPE_HTTP, 7441); | |
258 | proxyscan_addscantype(STYPE_HTTP, 808); | |
259 | proxyscan_addscantype(STYPE_HTTP, 3332); | |
260 | proxyscan_addscantype(STYPE_HTTP, 2282); | |
261 | proxyscan_addscantype(STYPE_SOCKS4, 559); | |
262 | proxyscan_addscantype(STYPE_SOCKS4, 1080); | |
263 | proxyscan_addscantype(STYPE_SOCKS5, 1080); | |
264 | proxyscan_addscantype(STYPE_SOCKS4, 1075); | |
265 | proxyscan_addscantype(STYPE_SOCKS5, 1075); | |
266 | proxyscan_addscantype(STYPE_SOCKS4, 2280); | |
267 | proxyscan_addscantype(STYPE_SOCKS5, 2280); | |
268 | proxyscan_addscantype(STYPE_SOCKS4, 1180); | |
269 | proxyscan_addscantype(STYPE_SOCKS5, 1180); | |
270 | proxyscan_addscantype(STYPE_SOCKS4, 9999); | |
271 | proxyscan_addscantype(STYPE_SOCKS5, 9999); | |
272 | proxyscan_addscantype(STYPE_WINGATE, 23); | |
273 | proxyscan_addscantype(STYPE_CISCO, 23); | |
274 | proxyscan_addscantype(STYPE_WINGATE, 1181); | |
275 | proxyscan_addscantype(STYPE_SOCKS5, 1978); | |
276 | proxyscan_addscantype(STYPE_SOCKS5, 1029); | |
277 | proxyscan_addscantype(STYPE_SOCKS5, 3801); | |
278 | proxyscan_addscantype(STYPE_SOCKS5, 3331); | |
279 | proxyscan_addscantype(STYPE_HTTP, 65506); | |
280 | proxyscan_addscantype(STYPE_HTTP, 63809); | |
281 | proxyscan_addscantype(STYPE_HTTP, 63000); | |
282 | proxyscan_addscantype(STYPE_SOCKS4, 29992); | |
283 | proxyscan_addscantype(STYPE_DIRECT_IRC, 6666); | |
284 | proxyscan_addscantype(STYPE_DIRECT_IRC, 6667); | |
285 | proxyscan_addscantype(STYPE_DIRECT_IRC, 6668); | |
286 | proxyscan_addscantype(STYPE_DIRECT_IRC, 6669); | |
287 | proxyscan_addscantype(STYPE_DIRECT_IRC, 6670); | |
288 | ||
289 | /* Schedule saves */ | |
290 | schedulerecurring(time(NULL)+3600,0,3600,&dumpcachehosts,NULL); | |
291 | ||
292 | ps_logfile=fopen("logs/proxyscan.log","a"); | |
293 | ||
294 | if (connected) { | |
295 | /* if we're already connected, assume we're just reloading module (i.e. have a completed burst) */ | |
296 | ps_ready = 1; | |
297 | startqueuedscans(); | |
298 | } | |
299 | } | |
300 | ||
301 | void registerproxyscannick(void *arg) { | |
302 | sstring *psnick,*psuser,*pshost,*psrealname; | |
303 | /* Set up our nick on the network */ | |
304 | channel *cp; | |
305 | ||
306 | psnick=getcopyconfigitem("proxyscan","nick","P",NICKLEN); | |
307 | psuser=getcopyconfigitem("proxyscan","user","proxyscan",USERLEN); | |
308 | pshost=getcopyconfigitem("proxyscan","host","some.host",HOSTLEN); | |
309 | psrealname=getcopyconfigitem("proxyscan","realname","Proxyscan",REALLEN); | |
310 | ||
311 | proxyscannick=registerlocaluser(psnick->content,psuser->content,pshost->content, | |
312 | psrealname->content, | |
313 | NULL,UMODE_OPER|UMODE_SERVICE|UMODE_DEAF, | |
314 | &proxyscanuserhandler); | |
315 | ||
316 | freesstring(psnick); | |
317 | freesstring(psuser); | |
318 | freesstring(pshost); | |
319 | freesstring(psrealname); | |
320 | ||
321 | cp=findchannel("#twilightzone"); | |
322 | if (!cp) { | |
323 | localcreatechannel(proxyscannick,"#twilightzone"); | |
324 | } else { | |
325 | localjoinchannel(proxyscannick,cp); | |
326 | localgetops(proxyscannick,cp); | |
327 | } | |
328 | } | |
329 | ||
330 | void _fini(void) { | |
331 | ||
332 | deregisterlocaluser(proxyscannick,NULL); | |
333 | ||
334 | deregisterhook(HOOK_SERVER_END_OF_BURST, &proxyscan_onconnect); | |
335 | ||
336 | deregisterhook(HOOK_NICK_NEWNICK,&proxyscan_newnick); | |
337 | ||
338 | deregisterhook(HOOK_CORE_STATSREQUEST,&proxyscanstats); | |
339 | ||
340 | deleteschedule(NULL,&dumpcachehosts,NULL); | |
341 | ||
342 | destroycommandtree(ps_commands); | |
343 | ||
344 | /* Kill any scans in progress */ | |
345 | killallscans(); | |
346 | ||
347 | /* Dump the database - AFTER killallscans() which prunes it */ | |
348 | dumpcachehosts(NULL); | |
349 | ||
350 | /* dump any cached hosts before deleting the extensions */ | |
351 | releasenodeext(ps_cache_ext); | |
352 | releasenodeext(ps_extscan_ext); | |
353 | ||
354 | /* free() all our structures */ | |
355 | nsfreeall(POOL_PROXYSCAN); | |
356 | ||
357 | freesstring(myipstr); | |
358 | freesstring(ps_mailname); | |
359 | #if defined(PROXYSCAN_MAIL) | |
360 | if (psm_mailerfd!=-1) | |
361 | deregisterhandler(psm_mailerfd,1); | |
362 | #endif | |
363 | ||
364 | if (ps_logfile) | |
365 | fclose(ps_logfile); | |
366 | } | |
367 | ||
368 | void proxyscanuserhandler(nick *target, int message, void **params) { | |
369 | nick *sender; | |
370 | Command *ps_command; | |
371 | char *cargv[20]; | |
372 | int cargc; | |
373 | ||
374 | switch(message) { | |
375 | case LU_KILLED: | |
376 | scheduleoneshot(time(NULL)+1,®isterproxyscannick,NULL); | |
377 | proxyscannick=NULL; | |
378 | break; | |
379 | ||
380 | case LU_PRIVMSG: | |
381 | case LU_SECUREMSG: | |
382 | sender=(nick *)params[0]; | |
383 | ||
384 | if (IsOper(sender)) { | |
385 | cargc = splitline((char *)params[1], cargv, 20, 0); | |
386 | ||
387 | if ( cargc == 0 ) | |
388 | return; | |
389 | ||
390 | ps_command = findcommandintree(ps_commands, cargv[0], 1); | |
391 | ||
392 | if ( !ps_command ) { | |
393 | sendnoticetouser(proxyscannick,sender, "Unknown command."); | |
394 | return; | |
395 | } | |
396 | ||
397 | if ( ps_command->maxparams < (cargc-1) ) { | |
398 | rejoinline(cargv[ps_command->maxparams], cargc - (ps_command->maxparams)); | |
399 | cargc = (ps_command->maxparams) + 1; | |
400 | } | |
401 | ||
402 | (ps_command->handler)((void *)sender, cargc - 1, &(cargv[1])); | |
403 | break; | |
404 | } | |
405 | ||
406 | default: | |
407 | break; | |
408 | } | |
409 | } | |
410 | ||
411 | void addscantohash(scan *sp) { | |
412 | int hash; | |
413 | hash=(sp->fd)%SCANHASHSIZE; | |
414 | ||
415 | sp->next=scantable[hash]; | |
416 | scantable[hash]=sp; | |
417 | ||
418 | activescans++; | |
419 | } | |
420 | ||
421 | void delscanfromhash(scan *sp) { | |
422 | int hash; | |
423 | scan **sh; | |
424 | ||
425 | hash=(sp->fd)%SCANHASHSIZE; | |
426 | ||
427 | for (sh=&(scantable[hash]);*sh;sh=&((*sh)->next)) { | |
428 | if (*sh==sp) { | |
429 | (*sh)=sp->next; | |
430 | break; | |
431 | } | |
432 | } | |
433 | ||
434 | activescans--; | |
435 | } | |
436 | ||
437 | scan *findscan(int fd) { | |
438 | int hash; | |
439 | scan *sp; | |
440 | ||
441 | hash=fd%SCANHASHSIZE; | |
442 | ||
443 | for (sp=scantable[hash];sp;sp=sp->next) | |
444 | if (sp->fd==fd) | |
445 | return sp; | |
446 | ||
447 | return NULL; | |
448 | } | |
449 | ||
450 | void startscan(patricia_node_t *node, int type, int port, int class) { | |
451 | scan *sp; | |
452 | float scantmp; | |
453 | ||
454 | if (scansdone>maxscans) | |
455 | { | |
456 | /* ignore the first maxscans as this will skew our scans per second! */ | |
457 | tempscanspermin++; | |
458 | if ((lastscants+60) <= time(NULL)) | |
459 | { | |
460 | /* ok, at least 60 seconds has passed, calculate the scans per minute figure */ | |
461 | scantmp = time(NULL) - lastscants; | |
462 | scantmp = tempscanspermin / scantmp; | |
463 | scantmp = (scantmp * 60); | |
464 | scanspermin = scantmp; | |
465 | lastscants = time(NULL); | |
466 | tempscanspermin = 0; | |
467 | } | |
468 | } | |
469 | ||
470 | sp=getscan(); | |
471 | ||
472 | sp->outcome=SOUTCOME_INPROGRESS; | |
473 | sp->port=port; | |
474 | sp->node=node; | |
475 | sp->type=type; | |
476 | sp->class=class; | |
477 | sp->bytesread=0; | |
478 | sp->totalbytesread=0; | |
479 | memset(sp->readbuf, '\0', PSCAN_READBUFSIZE); | |
480 | ||
481 | sp->fd=createconnectsocket(irc_in_addr_v4_to_int(&((patricia_node_t *)sp->node)->prefix->sin),sp->port); | |
482 | sp->state=SSTATE_CONNECTING; | |
483 | if (sp->fd<0) { | |
484 | /* Couldn't set up the socket? */ | |
485 | derefnode(iptree,sp->node); | |
486 | freescan(sp); | |
487 | return; | |
488 | } | |
489 | /* Wait until it is writeable */ | |
490 | registerhandler(sp->fd,POLLERR|POLLHUP|POLLOUT,&handlescansock); | |
491 | /* And set a timeout */ | |
492 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
493 | addscantohash(sp); | |
494 | } | |
495 | ||
496 | void timeoutscansock(void *arg) { | |
497 | scan *sp=(scan *)arg; | |
498 | ||
499 | killsock(sp, SOUTCOME_CLOSED); | |
500 | } | |
501 | ||
502 | void killsock(scan *sp, int outcome) { | |
503 | int i; | |
504 | cachehost *chp; | |
505 | foundproxy *fpp; | |
506 | ||
507 | scansdone++; | |
508 | scansbyclass[sp->class]++; | |
509 | ||
510 | /* Remove the socket from the schedule/event lists */ | |
511 | deregisterhandler(sp->fd,1); /* this will close the fd for us */ | |
512 | deleteschedule(sp->sch,&timeoutscansock,(void *)sp); | |
513 | ||
514 | sp->outcome=outcome; | |
515 | delscanfromhash(sp); | |
516 | ||
517 | /* See if we need to queue another scan.. */ | |
518 | if (sp->outcome==SOUTCOME_CLOSED && | |
519 | ((sp->class==SCLASS_CHECK) || | |
520 | (sp->class==SCLASS_NORMAL && (sp->state==SSTATE_SENTREQUEST || sp->state==SSTATE_GOTRESPONSE)))) | |
521 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS2, time(NULL)+300); | |
522 | ||
523 | if (sp->outcome==SOUTCOME_CLOSED && sp->class==SCLASS_PASS2) | |
524 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS3, time(NULL)+300); | |
525 | ||
526 | if (sp->outcome==SOUTCOME_CLOSED && sp->class==SCLASS_PASS3) | |
527 | queuescan(sp->node, sp->type, sp->port, SCLASS_PASS4, time(NULL)+300); | |
528 | ||
529 | if (sp->outcome==SOUTCOME_OPEN) { | |
530 | hitsbyclass[sp->class]++; | |
531 | ||
532 | /* Lets try and get the cache record. If there isn't one, make a new one. */ | |
533 | if (!(chp=findcachehost(sp->node))) { | |
534 | chp=addcleanhost(time(NULL)); | |
535 | patricia_ref_prefix(sp->node->prefix); | |
536 | sp->node->exts[ps_cache_ext] = chp; | |
537 | } | |
538 | /* Stick it on the cache's list of proxies, if necessary */ | |
539 | for (fpp=chp->proxies;fpp;fpp=fpp->next) | |
540 | if (fpp->type==sp->type && fpp->port==sp->port) | |
541 | break; | |
542 | ||
543 | if (!fpp) { | |
544 | fpp=getfoundproxy(); | |
545 | fpp->type=sp->type; | |
546 | fpp->port=sp->port; | |
547 | fpp->next=chp->proxies; | |
548 | chp->proxies=fpp; | |
549 | } | |
550 | ||
551 | if (!chp->glineid) { | |
552 | glinedhosts++; | |
553 | loggline(chp, sp->node); | |
554 | irc_send("%s GL * +*@%s 1800 %jd :Open Proxy, see http://www.quakenet.org/openproxies.html - ID: %d", | |
555 | mynumeric->content,IPtostr(((patricia_node_t *)sp->node)->prefix->sin),(intmax_t)getnettime(), chp->glineid); | |
556 | Error("proxyscan",ERR_DEBUG,"Found open proxy on host %s",IPtostr(((patricia_node_t *)sp->node)->prefix->sin)); | |
557 | } else { | |
558 | loggline(chp, sp->node); /* Update log only */ | |
559 | } | |
560 | ||
561 | /* Update counter */ | |
562 | for(i=0;i<numscans;i++) { | |
563 | if (thescans[i].type==sp->type && thescans[i].port==sp->port) { | |
564 | thescans[i].hits++; | |
565 | break; | |
566 | } | |
567 | } | |
568 | } | |
569 | ||
570 | freescan(sp); | |
571 | ||
572 | /* kick the queue.. */ | |
573 | startqueuedscans(); | |
574 | } | |
575 | ||
576 | void handlescansock(int fd, short events) { | |
577 | scan *sp; | |
578 | char buf[512]; | |
579 | int res; | |
580 | int i; | |
581 | unsigned long netip; | |
582 | unsigned short netport; | |
583 | ||
584 | if ((sp=findscan(fd))==NULL) { | |
585 | /* Not found; return and hope it goes away */ | |
586 | Error("proxyscan",ERR_ERROR,"Unexpected message from fd %d",fd); | |
587 | return; | |
588 | } | |
589 | ||
590 | /* It woke up, delete the alarm call.. */ | |
591 | deleteschedule(sp->sch,&timeoutscansock,(void *)sp); | |
592 | ||
593 | if (events & (POLLERR|POLLHUP)) { | |
594 | /* Some kind of error; give up on this socket */ | |
595 | if (sp->state==SSTATE_GOTRESPONSE) { | |
596 | /* If the error occured while we were waiting for a response, we might have | |
597 | * received the "OPEN PROXY!" message and the EOF at the same time, so continue | |
598 | * processing */ | |
599 | /* Error("proxyscan",ERR_DEBUG,"Got error in GOTRESPONSE state for %s, continuing.",IPtostr(sp->host->IP)); */ | |
600 | } else { | |
601 | killsock(sp, SOUTCOME_CLOSED); | |
602 | return; | |
603 | } | |
604 | } | |
605 | ||
606 | /* Otherwise, we got what we wanted.. */ | |
607 | ||
608 | switch(sp->state) { | |
609 | case SSTATE_CONNECTING: | |
610 | /* OK, we got activity while connecting, so we're going to send some | |
611 | * request depending on scan type. However, we can reregister everything | |
612 | * here to save duplicate code: This code is common for all handlers */ | |
613 | ||
614 | /* Delete the old handler */ | |
615 | deregisterhandler(fd,0); | |
616 | /* Set the new one */ | |
617 | registerhandler(fd,POLLERR|POLLHUP|POLLIN,&handlescansock); | |
618 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
619 | /* Update state */ | |
620 | sp->state=SSTATE_SENTREQUEST; | |
621 | ||
622 | switch(sp->type) { | |
623 | case STYPE_HTTP: | |
624 | sprintf(buf,"CONNECT %s:%d HTTP/1.0\r\n\r\n",myipstr->content,listenport); | |
625 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
626 | /* We didn't write the full amount, DIE */ | |
627 | killsock(sp,SOUTCOME_CLOSED); | |
628 | return; | |
629 | } | |
630 | break; | |
631 | ||
632 | case STYPE_SOCKS4: | |
633 | /* set up the buffer */ | |
634 | netip=htonl(myip); | |
635 | netport=htons(listenport); | |
636 | memcpy(&buf[4],&netip,4); | |
637 | memcpy(&buf[2],&netport,2); | |
638 | buf[0]=4; | |
639 | buf[1]=1; | |
640 | buf[8]=0; | |
641 | if ((write(fd,buf,9))<9) { | |
642 | /* Didn't write enough, give up */ | |
643 | killsock(sp,SOUTCOME_CLOSED); | |
644 | return; | |
645 | } | |
646 | break; | |
647 | ||
648 | case STYPE_SOCKS5: | |
649 | /* Set up initial request buffer */ | |
650 | buf[0]=5; | |
651 | buf[1]=1; | |
652 | buf[2]=0; | |
653 | if ((write(fd,buf,3))>3) { | |
654 | /* Didn't write enough, give up */ | |
655 | killsock(sp,SOUTCOME_CLOSED); | |
656 | return; | |
657 | } | |
658 | ||
659 | /* Now the actual connect request */ | |
660 | buf[0]=5; | |
661 | buf[1]=1; | |
662 | buf[2]=0; | |
663 | buf[3]=1; | |
664 | netip=htonl(myip); | |
665 | netport=htons(listenport); | |
666 | memcpy(&buf[4],&netip,4); | |
667 | memcpy(&buf[8],&netport,2); | |
668 | res=write(fd,buf,10); | |
669 | if (res<10) { | |
670 | killsock(sp,SOUTCOME_CLOSED); | |
671 | return; | |
672 | } | |
673 | break; | |
674 | ||
675 | case STYPE_WINGATE: | |
676 | /* Send wingate request */ | |
677 | sprintf(buf,"%s:%d\r\n",myipstr->content,listenport); | |
678 | if((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
679 | killsock(sp,SOUTCOME_CLOSED); | |
680 | return; | |
681 | } | |
682 | break; | |
683 | ||
684 | case STYPE_CISCO: | |
685 | /* Send cisco request */ | |
686 | sprintf(buf,"cisco\r\n"); | |
687 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
688 | killsock(sp, SOUTCOME_CLOSED); | |
689 | return; | |
690 | } | |
691 | ||
692 | sprintf(buf,"telnet %s %d\r\n",myipstr->content,listenport); | |
693 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
694 | killsock(sp, SOUTCOME_CLOSED); | |
695 | return; | |
696 | } | |
697 | ||
698 | break; | |
699 | ||
700 | case STYPE_DIRECT: | |
701 | /* Do nothing */ | |
702 | break; | |
703 | ||
704 | case STYPE_DIRECT_IRC: | |
705 | sprintf(buf,"PRIVMSG\r\n"); | |
706 | if ((write(fd,buf,strlen(buf)))<strlen(buf)) { | |
707 | killsock(sp, SOUTCOME_CLOSED); | |
708 | return; | |
709 | } | |
710 | ||
711 | /* Do nothing */ | |
712 | break; | |
713 | } | |
714 | break; | |
715 | ||
716 | case SSTATE_SENTREQUEST: | |
717 | res=read(fd, sp->readbuf+sp->bytesread, PSCAN_READBUFSIZE-sp->bytesread); | |
718 | ||
719 | if (res<=0) { | |
720 | if ((errno!=EINTR && errno!=EWOULDBLOCK) || res==0) { | |
721 | /* EOF, forget it */ | |
722 | killsock(sp, SOUTCOME_CLOSED); | |
723 | return; | |
724 | } | |
725 | } | |
726 | ||
727 | sp->bytesread+=res; | |
728 | sp->totalbytesread+=res; | |
729 | ||
730 | { | |
731 | char *magicstring; | |
732 | int magicstringlength; | |
733 | ||
734 | if(sp->type != STYPE_DIRECT_IRC) { | |
735 | magicstring = MAGICSTRING; | |
736 | magicstringlength = MAGICSTRINGLENGTH; | |
737 | } else { | |
738 | magicstring = MAGICIRCSTRING; | |
739 | magicstringlength = MAGICIRCSTRINGLENGTH; | |
740 | } | |
741 | ||
742 | for (i=0;i<sp->bytesread - magicstringlength;i++) { | |
743 | if (!strncmp(sp->readbuf+i, magicstring, magicstringlength)) { | |
744 | /* Found the magic string */ | |
745 | /* If the offset is 0, this means it was the first thing we got from the socket, | |
746 | * so it's an actual IRCD (sheesh). Note that when the buffer is full and moved, | |
747 | * the thing moved to offset 0 would previously have been tested as offset | |
748 | * PSCAN_READBUFSIZE/2. | |
749 | * | |
750 | * Skip this checking for STYPE_DIRECT scans, which are used to detect trojans setting | |
751 | * up portforwards (which will therefore show up as ircds, we rely on the port being | |
752 | * strange enough to avoid false positives */ | |
753 | if (i==0 && (sp->type != STYPE_DIRECT)) { | |
754 | killsock(sp, SOUTCOME_CLOSED); | |
755 | return; | |
756 | } | |
757 | ||
758 | killsock(sp, SOUTCOME_OPEN); | |
759 | return; | |
760 | } | |
761 | } | |
762 | } | |
763 | ||
764 | /* If the buffer is full, move half of it along to make room */ | |
765 | if (sp->bytesread == PSCAN_READBUFSIZE) { | |
766 | memcpy(sp->readbuf, sp->readbuf + (PSCAN_READBUFSIZE)/2, PSCAN_READBUFSIZE/2); | |
767 | sp->bytesread = PSCAN_READBUFSIZE/2; | |
768 | } | |
769 | ||
770 | /* Don't read data forever.. */ | |
771 | if (sp->totalbytesread > READ_SANITY_LIMIT) { | |
772 | killsock(sp, SOUTCOME_CLOSED); | |
773 | return; | |
774 | } | |
775 | ||
776 | /* No magic string yet, we schedule another timeout in case it comes later. */ | |
777 | sp->sch=scheduleoneshot(time(NULL)+SCANTIMEOUT,&timeoutscansock,(void *)sp); | |
778 | return; | |
779 | } | |
780 | } | |
781 | ||
782 | void killallscans() { | |
783 | int i; | |
784 | scan *sp; | |
785 | cachehost *chp; | |
786 | ||
787 | for(i=0;i<SCANHASHSIZE;i++) { | |
788 | for(sp=scantable[i];sp;sp=sp->next) { | |
789 | /* If there is a pending scan, delete it's clean host record.. */ | |
790 | if ((chp=findcachehost(sp->node)) && !chp->proxies) { | |
791 | sp->node->exts[ps_cache_ext] = NULL; | |
792 | derefnode(iptree,sp->node); | |
793 | delcachehost(chp); | |
794 | } | |
795 | ||
796 | if (sp->fd!=-1) { | |
797 | deregisterhandler(sp->fd,1); | |
798 | deleteschedule(sp->sch,&timeoutscansock,(void *)(sp)); | |
799 | } | |
800 | } | |
801 | } | |
802 | } | |
803 | ||
804 | void proxyscanstats(int hooknum, void *arg) { | |
805 | char buf[512]; | |
806 | ||
807 | sprintf(buf, "Proxyscn: %6d/%4d scans complete/in progress. %d hosts queued.", | |
808 | scansdone,activescans,queuedhosts); | |
809 | triggerhook(HOOK_CORE_STATSREPLY,buf); | |
810 | sprintf(buf, "Proxyscn: %6u known clean hosts",cleancount()); | |
811 | triggerhook(HOOK_CORE_STATSREPLY,buf); | |
812 | } | |
813 | ||
814 | void sendlagwarning() { | |
815 | int i,j; | |
816 | nick *np; | |
817 | ||
818 | for (i=0;i<MAXSERVERS;i++) { | |
819 | if (serverlist[i].maxusernum>0) { | |
820 | for(j=0;j<serverlist[i].maxusernum;j++) { | |
821 | np=servernicks[i][j]; | |
822 | if (np!=NULL && IsOper(np)) { | |
823 | sendnoticetouser(proxyscannick,np,"Warning: More than 20,000 hosts to scan - I'm lagging behind badly!"); | |
824 | } | |
825 | } | |
826 | } | |
827 | } | |
828 | } | |
829 | ||
830 | int pscansort(const void *a, const void *b) { | |
831 | int ra = *((const int *)a); | |
832 | int rb = *((const int *)b); | |
833 | ||
834 | return thescans[ra].hits - thescans[rb].hits; | |
835 | } | |
836 | ||
837 | int proxyscandostatus(void *sender, int cargc, char **cargv) { | |
838 | nick *np = (nick *) sender; | |
839 | int i; | |
840 | int totaldetects=0; | |
841 | int ord[PSCAN_MAXSCANS]; | |
842 | ||
843 | sendnoticetouser(proxyscannick,np,"Service uptime: %s",longtoduration(time(NULL)-ps_starttime, 1)); | |
844 | sendnoticetouser(proxyscannick,np,"Total scans completed: %d",scansdone); | |
845 | sendnoticetouser(proxyscannick,np,"Total hosts glined: %d",glinedhosts); | |
846 | ||
847 | sendnoticetouser(proxyscannick,np,"pendingscan structures: %lu x %lu bytes = %lu bytes total",countpendingscan, | |
848 | sizeof(pendingscan), (countpendingscan * sizeof(pendingscan))); | |
849 | ||
850 | sendnoticetouser(proxyscannick,np,"Currently active scans: %d/%d",activescans,maxscans); | |
851 | sendnoticetouser(proxyscannick,np,"Processing speed: %lu scans per minute",scanspermin); | |
852 | sendnoticetouser(proxyscannick,np,"Normal queued scans: %d",normalqueuedscans); | |
853 | sendnoticetouser(proxyscannick,np,"Timed queued scans: %d",prioqueuedscans); | |
854 | sendnoticetouser(proxyscannick,np,"'Clean' cached hosts: %d",cleancount()); | |
855 | sendnoticetouser(proxyscannick,np,"'Dirty' cached hosts: %d",dirtycount()); | |
856 | ||
857 | sendnoticetouser(proxyscannick,np,"Extra scans: %d", extrascancount()); | |
858 | for (i=0;i<5;i++) | |
859 | sendnoticetouser(proxyscannick,np,"Open proxies, class %1d: %d/%d (%.2f%%)",i,hitsbyclass[i],scansbyclass[i],((float)hitsbyclass[i]*100)/scansbyclass[i]); | |
860 | ||
861 | for (i=0;i<numscans;i++) | |
862 | totaldetects+=thescans[i].hits; | |
863 | ||
864 | for (i=0;i<numscans;i++) | |
865 | ord[i]=i; | |
866 | ||
867 | qsort(ord,numscans,sizeof(int),pscansort); | |
868 | ||
869 | sendnoticetouser(proxyscannick,np,"Scan type Port Detections"); | |
870 | for (i=0;i<numscans;i++) | |
871 | sendnoticetouser(proxyscannick,np,"%-9s %-5d %d (%.2f%%)", | |
872 | scantostr(thescans[ord[i]].type), thescans[ord[i]].port, thescans[ord[i]].hits, ((float)thescans[ord[i]].hits*100)/totaldetects); | |
873 | ||
874 | sendnoticetouser(proxyscannick,np,"End of list."); | |
875 | return CMD_OK; | |
876 | } | |
877 | ||
878 | int proxyscandebug(void *sender, int cargc, char **cargv) { | |
879 | /* Dump all scans.. */ | |
880 | int i; | |
881 | int activescansfound=0; | |
882 | int totalscansfound=0; | |
883 | scan *sp; | |
884 | nick *np = (nick *)sender; | |
885 | ||
886 | sendnoticetouser(proxyscannick,np,"Active scans : %d",activescans); | |
887 | ||
888 | for (i=0;i<SCANHASHSIZE;i++) { | |
889 | for (sp=scantable[i];sp;sp=sp->next) { | |
890 | if (sp->outcome==SOUTCOME_INPROGRESS) { | |
891 | activescansfound++; | |
892 | } | |
893 | totalscansfound++; | |
894 | sendnoticetouser(proxyscannick,np,"fd: %d type: %d port: %d state: %d outcome: %d IP: %s", | |
895 | sp->fd,sp->type,sp->port,sp->state,sp->outcome,IPtostr(((patricia_node_t *)sp->node)->prefix->sin)); | |
896 | } | |
897 | } | |
898 | ||
899 | sendnoticetouser(proxyscannick,np,"Total %d scans actually found (%d active)",totalscansfound,activescansfound); | |
900 | return CMD_OK; | |
901 | } | |
902 | ||
903 | void proxyscan_onconnect(int hooknum, void *arg) { | |
904 | ps_ready = 1; | |
905 | ||
906 | /* kick the queue.. */ | |
907 | startqueuedscans(); | |
908 | } | |
909 | ||
910 | int proxyscandosave(void *sender, int cargc, char **cargv) { | |
911 | nick *np = (nick *)sender; | |
912 | ||
913 | sendnoticetouser(proxyscannick,np,"Saving cached hosts..."); | |
914 | dumpcachehosts(NULL); | |
915 | sendnoticetouser(proxyscannick,np,"Done."); | |
916 | return CMD_OK; | |
917 | } | |
918 | ||
919 | int proxyscandospew(void *sender, int cargc, char **cargv) { | |
920 | nick *np = (nick *)sender; | |
921 | ||
922 | /* check our database for the ip supplied */ | |
923 | unsigned long a,b,c,d; | |
924 | if (4 != sscanf(cargv[0],"%lu.%lu.%lu.%lu",&a,&b,&c,&d)) { | |
925 | sendnoticetouser(proxyscannick,np,"Usage: spew x.x.x.x"); | |
926 | } else { | |
927 | /* check db */ | |
928 | proxyscanspewip(proxyscannick,np,a,b,c,d); | |
929 | } | |
930 | return CMD_OK; | |
931 | } | |
932 | ||
933 | int proxyscandoshowkill(void *sender, int cargc, char **cargv) { | |
934 | nick *np = (nick *)sender; | |
935 | ||
936 | /* check our database for the id supplied */ | |
937 | unsigned long a; | |
938 | if (1 != sscanf(cargv[0],"%lu",&a)) { | |
939 | sendnoticetouser(proxyscannick,np,"Usage: showkill <id>"); | |
940 | } else { | |
941 | /* check db */ | |
942 | proxyscanshowkill(proxyscannick,np,a); | |
943 | } | |
944 | return CMD_OK; | |
945 | } | |
946 | ||
947 | int proxyscandoscan(void *sender, int cargc, char **cargv) { | |
948 | nick *np = (nick *)sender; | |
949 | patricia_node_t *node; | |
950 | struct irc_in_addr sin; | |
951 | unsigned char bits; | |
952 | int i; | |
953 | ||
954 | if (0 == ipmask_parse(cargv[0],&sin, &bits)) { | |
955 | sendnoticetouser(proxyscannick,np,"Usage: scan <ip>"); | |
956 | } else { | |
957 | sendnoticetouser(proxyscannick,np,"Forcing scan of %s",IPtostr(sin)); | |
958 | // * Just queue the scans directly here.. plonk them on the priority queue * / | |
959 | node = refnode(iptree, &sin, bits); /* node leaks node here - should only allow to scan a nick? */ | |
960 | for(i=0;i<numscans;i++) { | |
961 | /* @@@TODO: we allow a forced scan to scan the same IP multiple times atm */ | |
962 | queuescan(node,thescans[i].type,thescans[i].port,SCLASS_NORMAL,time(NULL)); | |
963 | } | |
964 | } | |
965 | return CMD_OK; | |
966 | } | |
967 | ||
968 | int proxyscandoaddscan(void *sender, int cargc, char **cargv) { | |
969 | nick *np = (nick *)sender; | |
970 | ||
971 | unsigned int a,b; | |
972 | if (sscanf(cargv[0],"%u %u",&a,&b) != 2) { | |
973 | sendnoticetouser(proxyscannick,np,"Usage: addscan <type> <port>"); | |
974 | } else { | |
975 | sendnoticetouser(proxyscannick,np,"Added scan type %u port %u",a,b); | |
976 | proxyscan_addscantype(a,b); | |
977 | scanall(a,b); | |
978 | } | |
979 | return CMD_OK; | |
980 | } | |
981 | ||
982 | int proxyscandodelscan(void *sender, int cargc, char **cargv) { | |
983 | nick *np = (nick *)sender; | |
984 | ||
985 | unsigned int a,b; | |
986 | if (sscanf(cargv[0],"%u %u",&a,&b) != 2) { | |
987 | sendnoticetouser(proxyscannick,np,"Usage: delscan <type> <port>"); | |
988 | } else { | |
989 | sendnoticetouser(proxyscannick,np,"Delete scan type %u port %u",a,b); | |
990 | proxyscan_delscantype(a,b); | |
991 | } | |
992 | return CMD_OK; | |
993 | } | |
994 | ||
995 | int proxyscandoshowcommands(void *sender, int cargc, char **cargv) { | |
996 | nick *np = (nick *)sender; | |
997 | Command *cmdlist[100]; | |
998 | int i,n; | |
999 | ||
1000 | n=getcommandlist(ps_commands,cmdlist,100); | |
1001 | ||
1002 | sendnoticetouser(proxyscannick,np,"The following commands are registered at present:"); | |
1003 | for(i=0;i<n;i++) { | |
1004 | sendnoticetouser(proxyscannick,np,"%s",cmdlist[i]->command->content); | |
1005 | } | |
1006 | sendnoticetouser(proxyscannick,np,"End of list."); | |
1007 | return CMD_OK; | |
1008 | } |