]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blobdiff - html/cgi-bin/ids.cgi
Fixed detection of snort description if there is no CRLF and the
[people/pmueller/ipfire-2.x.git] / html / cgi-bin / ids.cgi
index d0d757841e2ca8823e9d79b73542d8a283819d9b..1d0f4abc81e0a56686deacb7c57c6feeed5008b5 100644 (file)
@@ -43,8 +43,6 @@ my %checked=();
 my %selected=();
 my %netsettings=();
 our $errormessage = '';
-our $md5 = '0';# not '' to avoid displaying the wrong message when INSTALLMD5 not set
-our $realmd5 = '';
 our $results = '';
 our $tempdir = '';
 our $url='';
@@ -69,7 +67,6 @@ $snortsettings{'ACTION2'} = '';
 $snortsettings{'RULES'} = '';
 $snortsettings{'OINKCODE'} = '';
 $snortsettings{'INSTALLDATE'} = '';
-$snortsettings{'INSTALLMD5'} = '';
 
 &Header::getcgihash(\%snortsettings, {'wantfile' => 1, 'filevar' => 'FH'});
 
@@ -146,7 +143,7 @@ if (-e "/etc/snort/snort.conf") {
                                        # If see more than one dashed line, (start to) create rule file description
                                        if ($dashlinecnt > 1) {
                                                # Check for a line starting with a #
-                                               if ($ruleline =~ /^\#/) {
+                                               if ($ruleline =~ /^\#/ and $ruleline !~ /^\#alert/) {
                                                        # Create tempruleline
                                                        my $tempruleline = $ruleline;
 
@@ -263,13 +260,15 @@ if (-e "/etc/snort/snort.conf") {
 #######################  End added for snort rules control  #################################
 
 if ($snortsettings{'RULES'} eq 'subscripted') {
-       $url="http://dl.snort.org/reg-rules/snortrules-snapshot-2.8_s.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
+       #$url="http://dl.snort.org/sub-rules/snortrules-snapshot-2.8_s.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
+       $url="http://dl.snort.org/sub-rules/snortrules-snapshot-2860_s.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
        #$url="http://www.snort.org/pub-bin/oinkmaster.cgi/$snortsettings{'OINKCODE'}/snortrules-snapshot-2.8_s.tar.gz";
 } elsif ($snortsettings{'RULES'} eq 'registered') {
-       $url="http://dl.snort.org/reg-rules/snortrules-snapshot-2.8.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
+       #$url="http://dl.snort.org/reg-rules/snortrules-snapshot-2.8.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
+       $url="http://dl.snort.org/reg-rules/snortrules-snapshot-2860.tar.gz?oink_code=$snortsettings{'OINKCODE'}";
        #$url="http://www.snort.org/pub-bin/oinkmaster.cgi/$snortsettings{'OINKCODE'}/snortrules-snapshot-2.8.tar.gz";
 } else {
-       $url="http://www.snort.org/pub-bin/downloads.cgi/Download/comm_rules/Community-Rules-CURRENT.tar.gz";
+       $url="http://www.emergingthreats.net/rules/emerging.rules.tar.gz";
 }
 
 if ($snortsettings{'ACTION'} eq $Lang::tr{'save'} && $snortsettings{'ACTION2'} eq "snort" )
@@ -319,8 +318,14 @@ if ($snortsettings{'ACTION'} eq $Lang::tr{'save'} && $snortsettings{'ACTION2'} e
        system('/usr/local/bin/snortctrl restart >/dev/null');
 
 } elsif ($snortsettings{'ACTION'} eq $Lang::tr{'save'} && $snortsettings{'ACTION2'} eq "guardian" ){
+                       foreach my $key (keys %snortsettings){
+                               if ( $key !~ /^GUARDIAN/ ){
+                                       delete $snortsettings{$key};
+                               }
+                       }
+                       &General::writehashpart("${General::swroot}/snort/settings", \%snortsettings);
                        open(IGNOREFILE, ">$snortsettings{'GUARDIAN_IGNOREFILE'}") or die "Unable to write guardian ignore file $snortsettings{'GUARDIAN_IGNOREFILE'}";
-                               print IGNOREFILE $snortsettings{'IGNOREFILE_CONTENT'};
+                               print IGNOREFILE $snortsettings{'GUARDIAN_IGNOREFILE_CONTENT'};
                        close(IGNOREFILE);
                        open(GUARDIAN, ">/var/ipfire/guardian/guardian.conf") or die "Unable to write guardian conf /var/ipfire/guardian/guardian.conf";
                                print GUARDIAN <<END
@@ -340,25 +345,30 @@ END
        &General::readhash("${General::swroot}/snort/settings", \%snortsettings);
 
 if ($snortsettings{'ACTION'} eq $Lang::tr{'download new ruleset'}) {
-       $md5 = &getmd5;
-       if (($snortsettings{'INSTALLMD5'} ne $md5) && defined $md5 ) {
-               chomp($md5);
-               my $filename = &downloadrulesfile();
-               if (defined $filename) {
-                       # Check MD5sum
-                       $realmd5 = `/usr/bin/md5sum $filename`;
-                       chomp ($realmd5);
-                       $realmd5 =~ s/^(\w+)\s.*$/$1/;
-                       if ( $md5 ne $realmd5 ) {
-                               $errormessage = "$Lang::tr{'invalid md5sum'} - $md5 - $realmd5";
+
+       my @df = `/bin/df -B M /var`;
+       foreach my $line (@df) {
+               next if $line =~ m/^Filesystem/;
+
+               if ($line =~ m/dev/ ) {
+               $line =~ m/^.* (\d+)M.*$/;
+               my @temp = split(/ +/,$line);
+                       if ($1<300) {
+                               $errormessage = "$Lang::tr{'not enough disk space'} < 300MB, /var $1MB";
                        } else {
-                               $results = "<b>$Lang::tr{'installed updates'}</b>\n<pre>";
-                               $results .=`/usr/local/bin/oinkmaster.pl -s -u file://$filename -C /var/ipfire/snort/oinkmaster.conf -o /etc/snort/rules 2>&1`;
-                               $results .= "</pre>";
+                               my $filename = &downloadrulesfile();
+                               if (defined $filename) {
+                                               $results = "<b>$Lang::tr{'installed updates'}</b>\n<pre>";
+                                               $results .=`/usr/local/bin/oinkmaster.pl -s -u file://$filename -C /var/ipfire/snort/oinkmaster.conf -o /etc/snort/rules 2>&1`;
+                                               $results .= "</pre>";
+                                       }
+                                       unlink ($filename);
                        }
-                       unlink ($filename);
+                       
                }
        }
+
+
 }
 
 $checked{'ENABLE_SNORT'}{'off'} = '';
@@ -412,6 +422,19 @@ END
 
 &Header::openbigbox('100%', 'left', '', $errormessage);
 
+###############
+# DEBUG DEBUG
+# &Header::openbox('100%', 'left', 'DEBUG');
+# my $debugCount = 0;
+# foreach my $line (sort keys %snortsettings) {
+# print "$line = $snortsettings{$line}<br />\n";
+# $debugCount++;
+# }
+# print "&nbsp;Count: $debugCount\n";
+# &Header::closebox();
+# DEBUG DEBUG
+###############
+
 if ($errormessage) {
        &Header::openbox('100%', 'left', $Lang::tr{'error messages'});
        print "<class name='base'>$errormessage\n";
@@ -467,16 +490,12 @@ print <<END
 END
 ;
 
-if ($snortsettings{'INSTALLMD5'} eq $md5) {
-       print "&nbsp;$Lang::tr{'rules already up to date'}</td>";
-} else {
-       if ( $snortsettings{'ACTION'} eq $Lang::tr{'download new ruleset'} && $md5 eq $realmd5 ) {
-               $snortsettings{'INSTALLMD5'} = $realmd5;
-               $snortsettings{'INSTALLDATE'} = `/bin/date +'%Y-%m-%d'`;
-               &General::writehash("${General::swroot}/snort/settings", \%snortsettings);
-       }
-       print "&nbsp;$Lang::tr{'updates installed'}: $snortsettings{'INSTALLDATE'}</td>";
+if ( $snortsettings{'ACTION'} eq $Lang::tr{'download new ruleset'} ) {
+       $snortsettings{'INSTALLDATE'} = `/bin/date +'%Y-%m-%d'`;
+       &General::writehash("${General::swroot}/snort/settings", \%snortsettings);
 }
+print "&nbsp;$Lang::tr{'updates installed'}: $snortsettings{'INSTALLDATE'}</td>";
+
 print <<END
 </tr>
 </table>
@@ -501,11 +520,11 @@ if ( -e "/var/ipfire/guardian/guardian.conf" ) {
        &Header::openbox('100%', 'LEFT', $Lang::tr{'guardian configuration'});
 print <<END
 <form method='post' action='$ENV{'SCRIPT_NAME'}'><table width='100%'>
-<tr><td align='left' width='40%'>$Lang::tr{'guardian interface'}</td><td align='left'><input type='text' name='INTERFACE' value='$snortsettings{'GUARDIAN_INTERFACE'}' size="30" /></td></tr>
-<tr><td align='left' width='40%'>$Lang::tr{'guardian timelimit'}</td><td align='left'><input type='text' name='TIMELIMIT' value='$snortsettings{'GUARDIAN_TIMELIMIT'}' size="30" /></td></tr>
-<tr><td align='left' width='40%'>$Lang::tr{'guardian logfile'}</td><td align='left'><input type='text' name='LOGFILE' value='$snortsettings{'GUARDIAN_LOGFILE'}' size="30" /></td></tr>
-<tr><td align='left' width='40%'>$Lang::tr{'guardian alertfile'}</td><td align='left'><input type='text' name='ALERTFILE' value='$snortsettings{'GUARDIAN_ALERTFILE'}' size="30" /></td></tr>
-<tr><td align='left' width='40%'>$Lang::tr{'guardian ignorefile'}</td><td align='left'><textarea name='IGNOREFILE_CONTENT' cols='32' rows='6' wrap='off'>
+<tr><td align='left' width='40%'>$Lang::tr{'guardian interface'}</td><td align='left'><input type='text' name='GUARDIAN_INTERFACE' value='$snortsettings{'GUARDIAN_INTERFACE'}' size="30" /></td></tr>
+<tr><td align='left' width='40%'>$Lang::tr{'guardian timelimit'}</td><td align='left'><input type='text' name='GUARDIAN_TIMELIMIT' value='$snortsettings{'GUARDIAN_TIMELIMIT'}' size="30" /></td></tr>
+<tr><td align='left' width='40%'>$Lang::tr{'guardian logfile'}</td><td align='left'><input type='text' name='GUARDIAN_LOGFILE' value='$snortsettings{'GUARDIAN_LOGFILE'}' size="30" /></td></tr>
+<tr><td align='left' width='40%'>$Lang::tr{'guardian alertfile'}</td><td align='left'><input type='text' name='GUARDIAN_ALERTFILE' value='$snortsettings{'GUARDIAN_ALERTFILE'}' size="30" /></td></tr>
+<tr><td align='left' width='40%'>$Lang::tr{'guardian ignorefile'}</td><td align='left'><textarea name='GUARDIAN_IGNOREFILE_CONTENT' cols='32' rows='6' wrap='off'>
 END
 ;
        print `cat /var/ipfire/guardian/guardian.ignore`;
@@ -540,6 +559,11 @@ if ( -e "${General::swroot}/snort/enable" || -e "${General::swroot}/snort/enable
                foreach my $rulefile (sort keys(%snortrules)) {
                        my $rulechecked = '';
 
+                       # Hide inkompatible Block rules
+                       if ($rulefile =~'-BLOCK.rules') {
+                               next;
+                       }
+
                        # Check if reached half-way through rule file rules to start new column
                if ($ruledisplaycnt > $rulecnt) {
                                print "</TABLE></TD><TD VALIGN='TOP'><TABLE>";
@@ -676,31 +700,6 @@ END
 &Header::closebigbox();
 &Header::closepage();
 
-sub getmd5 {
-       # Retrieve MD5 sum from $url.md5 file
-
-       my $md5buf;
-       if ($snortsettings{'RULES'} eq 'subscripted') {
-               $md5buf = &geturl("http://dl.snort.org/reg-rules/snortrules-snapshot-2.8_s.tar.gz.md5?oink_code=$snortsettings{'OINKCODE'}");
-       } elsif ($snortsettings{'RULES'} eq 'registered') {
-               $md5buf = &geturl("http://dl.snort.org/reg-rules/snortrules-snapshot-2.8.tar.gz.md5?oink_code=$snortsettings{'OINKCODE'}");
-       } else {
-               $md5buf = &geturl("http://www.snort.org/pub-bin/downloads.cgi/Download/comm_rules/Community-Rules-CURRENT.tar.gz.md5");
-       }
-
-       return undef unless $md5buf;
-
-       if (0) { # 1 to debug
-               my $filename='';
-               my $fh='';
-               ($fh, $filename) = tempfile('/var/tmp/XXXXXXXX',SUFFIX => '.md5' );
-               binmode ($fh);
-               syswrite ($fh, $md5buf->content);
-               close($fh);
-       }
-
-       return $md5buf->content;
-}
 sub downloadrulesfile {
        my $return = &geturl($url);
        return undef unless $return;