j utilises actuellement ipcop avec quelques addons :
Squidguard
Ntop
Psad / Guardian
Je voudrais automatiser via l edtion de cron l envoi d un mail contenant les logs du firewall.
voila ce que j ai rajoute :
- Code: Tout sélectionner
30 10 * * * /usr/sbin/sendmail -v lucas.cueff5@libertysurf.fr < log.mail
mais cela ne fonctionne pas...
PS : la commande "/usr/sbin/sendmail -v lucas.cueff5@libertysurf.fr < log.mail" fonctionne seule.
J aurais souhaiter egalement faire un tri dans ce journal pour ne recuperrer que ce qui se passe pendant la journee et aussi le og de la veille
voici un exemple du log :
- Code: Tout sélectionner
Fri May 7 04:59:23 2004: 195.116.86.2
Running '/usr/sbin/guardian_block.sh 195.116.86.2 ppp0'
Odd.. source = 195.116.86.2, dest = 192.168.0.2 - No action done.
Fri May 7 04:59:23 2004: 195.116.86.2
Odd.. source = 195.116.86.2, dest = 192.168.0.2 - No action done.
Odd.. source = 192.168.0.2, dest = 218.186.34.4 - No action done.
expiring block of 195.116.86.2
Fri May 7 05:19:33 2004: 218.62.54.2 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 218.62.54.2 ppp0'
expiring block of 218.62.54.2
Fri May 7 05:24:58 2004: 69.33.197.12 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 69.33.197.12 ppp0'
Fri May 7 05:25:28 2004: 4.14.88.55 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 4.14.88.55 ppp0'
expiring block of 69.33.197.12
expiring block of 4.14.88.55
Odd.. source = 192.168.0.2, dest = 218.186.34.4 - No action done.
Fri May 7 05:51:41 2004: 61.93.117.178 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 61.93.117.178 ppp0'
expiring block of 61.93.117.178
Odd.. source = 192.168.0.2, dest = 213.61.128.18 - No action done.
Odd.. source = 192.168.0.2, dest = 218.186.34.4 - No action done.
Fri May 7 06:39:43 2004: 211.162.135.159 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 211.162.135.159 ppp0'
expiring block of 211.162.135.159
Fri May 7 06:42:08 2004: 213.209.132.12 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 213.209.132.12 ppp0'
Odd.. source = 192.168.0.2, dest = 213.61.128.18 - No action done.
expiring block of 213.209.132.12
Fri May 7 06:44:14 2004: 218.61.188.15 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 218.61.188.15 ppp0'
Fri May 7 06:44:29 2004: 61.102.177.198 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 61.102.177.198 ppp0'
Fri May 7 06:44:48 2004: 61.144.118.219 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 61.144.118.219 ppp0'
expiring block of 218.61.188.15
expiring block of 61.102.177.198
expiring block of 61.144.118.219
Fri May 7 07:01:24 2004: 204.30.70.25 [1:2091:4] WEB-IIS WEBDAV nessus safe scan attempt
Running '/usr/sbin/guardian_block.sh 204.30.70.25 ppp0'
expiring block of 204.30.70.25