Compare commits

...

5 Commits

Author SHA1 Message Date
John Crisp
02f87475ff * Thu Mar 20 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-26.sme
- Fix createlink typo remote-access-update [SME: 12438]
2025-03-20 12:36:51 +01:00
John Crisp
725b2f5418 * Thu Feb 13 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-25.sme
- Fix various typos as per bug but more to find [SME: 12472]
2025-02-13 20:07:42 +01:00
John Crisp
42ce2cced8 * Thu Feb 13 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-24.sme
- move scriptoig back to /usr/share/geoip
- Lose the LE/BE (Little/Big Endian) parts as iptables can't seme to read the file in subdirs
- Update ULOG to NFLOG in rules but restricts the number of countries
2025-02-13 19:14:51 +01:00
John Crisp
a9ebb21641 * Wed Feb 12 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-23.sme
- Update dependencies for xtables addons
- Remove $ from config in templates
- Add db open entries to subs
2025-02-13 13:31:16 +01:00
444e6dbfcf Update README with specific Bugzilla links 2024-10-27 15:58:40 +00:00
15 changed files with 614 additions and 387 deletions

View File

@ -6,7 +6,14 @@ SMEServer Koozali developed git repo for smeserver-xt_geoip smecontribs
<br />https://wiki.koozali.org/ <br />https://wiki.koozali.org/
## Bugzilla ## Bugzilla
Show list of outstanding bugs: [here](https://bugs.koozali.org/buglist.cgi?component=smeserver-xt_geoip&product=SME%20Contribs&query_format=advanced&limit=0&bug_status=UNCONFIRMED&bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&bug_status=CONFIRMED) Show list of outstanding bugs:
[All](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=UNCONFIRMED&bug_status=CONFIRMED&bug_status=NEEDINFO&bug_status=IN_PROGRESS&bug_status=RESOLVED&bug_status=VERIFIED&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[Confirmed](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=CONFIRMED&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[Unconfirmed](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=UNCONFIRMED&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[Need Info](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=NEEDINFO&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[In Progress](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=IN_PROGRESS&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[Verified](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=VERIFIED&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
[Resolved](https://bugs.koozali.org/buglist.cgi?action=wrap&bug_status=RESOLVED&classification=Contribs&component=smeserver-xt_geoip&list_id=105781&order=changeddate+DESC%2Ccomponent%2Cpriority%2Cbug_severity&product=SME+Contribs&query_format=advanced)
## Description ## Description

View File

@ -38,7 +38,7 @@ for my $event (qw(xt_geoip-update bootstrap-console-save
event_link("smeserver-xt_geoip-download-action", $event, "10"); event_link("smeserver-xt_geoip-download-action", $event, "10");
} }
for my $event (qw(bootstrap-console-save e-smith-packetfilter-update for my $event (qw(bootstrap-console-save e-smith-packetfilter-update
smeserver-xt_geoip-update remote-access-update)) smeserver-xt_geoip-update remoteaccess-update))
{ {
event_link("xt_geoip_kmod", $event, "15"); event_link("xt_geoip_kmod", $event, "15");
} }

View File

@ -73,7 +73,7 @@ EOF
if ($port ne '' and $servStatus eq 'enabled' and $servAccess eq 'public' and $locBC ne '') { if ($port ne '' and $servStatus eq 'enabled' and $servAccess eq 'public' and $locBC ne '') {
push @locPorts, $port; push @locPorts, $port;
my $multi = ( $port =~ /[,:]/ )? "-m multiport --dports" : "--dport"; my $multi = ( $port =~ /[,:]/ )? "-m multiport --dports" : "--dport";
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -m geoip $reverse --src-cc $locBC -p tcp $multi $port -j ULOG --ulog-prefix \"GeoIP BAN: $servName\"\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -m geoip $reverse --src-cc $locBC -p tcp $multi $port -j NFLOG --nflog-prefix \"GeoIP BAN: $servName\"\n";
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -m geoip $reverse --src-cc $locBC -p tcp $multi $port -j DROP\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -m geoip $reverse --src-cc $locBC -p tcp $multi $port -j DROP\n";
} }
} }
@ -85,10 +85,10 @@ EOF
@locPorts = () unless $others; @locPorts = () unless $others;
if (@locPorts != 0) { if (@locPorts != 0) {
my $LocPorts = join ',', @locPorts; my $LocPorts = join ',', @locPorts;
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip -m multiport ! --dports $LocPorts $reverse --src-cc $BC -j ULOG --ulog-prefix \"GeoIP BAN: OTHER\"\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip -m multiport ! --dports $LocPorts $reverse --src-cc $BC -j NFLOG --nflog-prefix \"GeoIP BAN: OTHER\"\n";
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip -m multiport ! --dports $LocPorts $reverse --src-cc $BC -j DROP\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip -m multiport ! --dports $LocPorts $reverse --src-cc $BC -j DROP\n";
} else { } else {
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip $reverse --src-cc $BC -j ULOG --ulog-prefix \"GeoIP BAN: ALL\"\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip $reverse --src-cc $BC -j NFLOG --nflog-prefix \"GeoIP BAN: ALL\"\n";
$OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip $reverse --src-cc $BC -j DROP\n"; $OUT .= " /sbin/iptables -A \$NEW_XTGeoIP -p tcp -m geoip $reverse --src-cc $BC -j DROP\n";
} }
} }

View File

@ -4,7 +4,6 @@ package SrvMngr::Controller::Xt_geoip;
# heading : Network # heading : Network
# description : GeoIP IP filtering # description : GeoIP IP filtering
# navigation : 6000 610 # navigation : 6000 610
# name : xt_geoip, method : get, url : /xt_geoip, ctlact : Xt_geoip#main # name : xt_geoip, method : get, url : /xt_geoip, ctlact : Xt_geoip#main
# name : xt_geoipd, method : post, url : /xt_geoip, ctlact : Xt_geoip#do_display # name : xt_geoipd, method : post, url : /xt_geoip, ctlact : Xt_geoip#do_display
# name : xt_geoipc, method : get, url : /xt_geoipb, ctlact : Xt_geoip#do_display # name : xt_geoipc, method : get, url : /xt_geoipb, ctlact : Xt_geoip#do_display
@ -15,464 +14,403 @@ package SrvMngr::Controller::Xt_geoip;
use strict; use strict;
use warnings; use warnings;
use Mojo::Base 'Mojolicious::Controller'; use Mojo::Base 'Mojolicious::Controller';
use POSIX qw(strftime); use POSIX qw(strftime);
use Locale::gettext; use Locale::gettext;
use SrvMngr::I18N; use SrvMngr::I18N;
use SrvMngr qw( theme_list init_session ); use SrvMngr qw( theme_list init_session );
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n"; # our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my ($cdb);
sub main { sub main {
my $c = shift; my $c = shift;
$c->app->log->info($c->log_req); $c->app->log->info($c->log_req);
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $title = $c->render_to_string(inline =>($c->l('xtg_FORM_TITLE'))); my $title = $c->render_to_string(inline => ($c->l('xtg_FORM_TITLE')));
my %xtg_datas = (); my %xtg_datas = ();
$xtg_datas{'choice'} = ''; $xtg_datas{'choice'} = '';
$c->stash(title => $title, xtg_datas => \%xtg_datas);
$c->stash( title => $title, xtg_datas => \%xtg_datas);
$c->render('xt_geoip'); $c->render('xt_geoip');
}; } ## end sub main
sub do_display { sub do_display {
my $c = shift; my $c = shift;
$c->app->log->info($c->log_req); $c->app->log->info($c->log_req);
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $title = $c->render_to_string(inline =>($c->l('xtg_FORM_TITLE'))); my $title = $c->render_to_string(inline => ($c->l('xtg_FORM_TITLE')));
my $choice = $c->param('Choice'); my $choice = $c->param('Choice');
my $result; my $result;
my %xtg_datas = (); my %xtg_datas = ();
$xtg_datas{'choice'} = $choice; $xtg_datas{'choice'} = $choice;
if ( $choice eq 'LCOD' ) { if ($choice eq 'LCOD') {
$result = $c->generateCodes(); $result = $c->generateCodes();
# $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas ); # $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_lst'); # return $c->render('xt_geoip_lst');
}; } ## end if ($choice eq 'LCOD')
if ( $choice eq 'LF2B' ) { if ($choice eq 'LF2B') {
$result = $c->generateStats('f2b');
$result = $c->generateStats( 'f2b' ); # $result = $c->render_to_string(inline => generateStats($c, 'f2b'));
# $result = $c->render_to_string(inline => generateStats($c, 'f2b')); # $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_lst');
} ## end if ($choice eq 'LF2B')
# $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas ); if ($choice eq 'LSSH') {
# return $c->render('xt_geoip_lst'); $result = $c->generateStats('ssh');
};
if ( $choice eq 'LSSH' ) { # $result = $c->render_to_string(inline => generateStats($c, 'ssh'));
# $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_lst');
} ## end if ($choice eq 'LSSH')
$result = $c->generateStats( 'ssh' ); if ($choice eq 'LIPT') {
# $result = $c->render_to_string(inline => generateStats($c, 'ssh')); $result = $c->generateStats('ipt');
# $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas ); # $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_lst'); # return $c->render('xt_geoip_lst');
}; } ## end if ($choice eq 'LIPT')
if ( $choice eq 'LIPT' ) { if ($choice eq 'LSRV') {
$result = $c->generateStats( 'ipt' ); # $c->stash( title => $title, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_lsrv');
} ## end if ($choice eq 'LSRV')
# $c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas ); if ($choice eq 'UPDT') {
# return $c->render('xt_geoip_lst');
};
if ( $choice eq 'LSRV' ) { # $c->stash( title => $title, xtg_datas => \%xtg_datas );
# $c->stash( title => $title, xtg_datas => \%xtg_datas ); # return $c->render('xt_geoip_updt');
# return $c->render('xt_geoip_lsrv'); } ## end if ($choice eq 'UPDT')
}
if ( $choice eq 'UPDT' ) { if ($choice eq 'UPDS') {
# $c->stash( title => $title, xtg_datas => \%xtg_datas ); $xtg_datas{name} = $c->param('Name');
# return $c->render('xt_geoip_updt');
}
if ( $choice eq 'UPDS' ) { # $c->stash( title => $title, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_upds');
} ## end if ($choice eq 'UPDS')
$xtg_datas{name} = $c->param('Name'); if ($choice eq 'REMS') {
$xtg_datas{name} = $c->param('Name');
# $c->stash( title => $title, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_upds');
}
if ( $choice eq 'REMS' ) {
$xtg_datas{name} = $c->param('Name');
# $c->stash( title => $title, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_rems');
}
$c->stash( title => $title, modul => $result, xtg_datas => \%xtg_datas );
return $c->render( 'xt_geoip_lst' ) if ( $choice ~~ [ 'LCOD', 'LF2B', 'LSSH', 'LIPT' ] );
return $c->render( 'xt_geoip'.'_'.lc($choice) ) if ( $choice ~~ [ 'UPDT', 'UPDS', 'REMS', 'LSRV' ] );
# $c->stash( title => $title, xtg_datas => \%xtg_datas );
# return $c->render('xt_geoip_rems');
} ## end if ($choice eq 'REMS')
$c->stash(title => $title, modul => $result, xtg_datas => \%xtg_datas);
return $c->render('xt_geoip_lst') if ($choice ~~ [ 'LCOD', 'LF2B', 'LSSH', 'LIPT' ]);
return $c->render('xt_geoip' . '_' . lc($choice)) if ($choice ~~ [ 'UPDT', 'UPDS', 'REMS', 'LSRV' ]);
$c->redirect_to('/xt_geoip'); $c->redirect_to('/xt_geoip');
} ## end sub do_display
};
sub do_action { sub do_action {
my $c = shift; my $c = shift;
$c->app->log->info($c->log_req); $c->app->log->info($c->log_req);
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $rt = $c->current_route; my $rt = $c->current_route;
my $title = $c->render_to_string(inline => ($c->l('xtg_FORM_TITLE')));
my $title = $c->render_to_string(inline =>($c->l('xtg_FORM_TITLE')));
my %xtg_datas = (); my %xtg_datas = ();
my $choice = $c->param('Choice');
my $choice = $c->param('Choice');
$xtg_datas{'choice'} = $choice; $xtg_datas{'choice'} = $choice;
my ($res, $result) = ''; my ($res, $result) = '';
if ($choice eq 'LSRV') {
if ( $choice eq 'LSRV' ) { #$result .= 'Blocked for testing ! Avoid updates for now ';
$res = '';
#$result .= 'Blocked for testing ! Avoid updates for now '; if (!$result) {
$res = $c->do_otherServices();
$result .= $res unless $res eq 'OK';
$res = ''; if (!$result) {
if ( ! $result ) { $result = $c->l('xtg_SERVICE_SUCCESS');
$res = $c->do_otherServices(); }
$result .= $res unless $res eq 'OK'; } ## end if (!$result)
if ( ! $result ) { } ## end if ($choice eq 'LSRV')
$result = $c->l('xtg_SERVICE_SUCCESS');
}
}
}
if ( $choice eq 'UPDT' ) { if ($choice eq 'UPDT') {
$res = $c->must_exist();
$result .= $res unless $res eq 'OK';
$res = $c->must_exist(); #$result .= 'Blocked for testing ! Avoid updates for now ';
$result .= $res unless $res eq 'OK'; $res = '';
#$result .= 'Blocked for testing ! Avoid updates for now '; if (!$result) {
$res = $c->change_settings();
$result .= $res unless $res eq 'OK';
$res = ''; if (!$result) {
if ( ! $result ) { $result = $c->l('xtg_SUCCESS');
$res = $c->change_settings(); }
$result .= $res unless $res eq 'OK'; } ## end if (!$result)
if ( ! $result ) { } ## end if ($choice eq 'UPDT')
$result = $c->l('xtg_SUCCESS');
}
}
}
if ($choice eq 'REMS') {
if ( $choice eq 'REMS' ) { #$result .= 'Blocked for testing ! Avoid updates for now ';
my $name = $c->param('Name');
$xtg_datas{name} = $name;
$res = '';
#$result .= 'Blocked for testing ! Avoid updates for now '; if (!$result) {
$res = $c->remove_serv();
$result .= $res unless $res eq 'OK';
my $name = $c->param('Name'); if (!$result) {
$xtg_datas{name} = $name; $result = $c->l('xtg_SUCCESSFULLY_DELETED_SERVICE');
}
} ## end if (!$result)
} ## end if ($choice eq 'REMS')
$res = ''; if ($choice eq 'UPDS') {
if ( ! $result ) {
$res = $c->remove_serv();
$result .= $res unless $res eq 'OK';
if ( ! $result ) {
$result = $c->l('xtg_SUCCESSFULLY_DELETED_SERVICE');
}
}
}
#$result .= 'Blocked for testing ! Avoid updates for now ';
my $name = $c->param('Name');
$xtg_datas{name} = $name;
$res = '';
if ( $choice eq 'UPDS' ) { if (!$result) {
$res = $c->modify_serv();
$result .= $res unless $res eq 'OK';
#$result .= 'Blocked for testing ! Avoid updates for now '; if (!$result) {
$result = $c->l('xtg_SERVICE_SUCCESS');
my $name = $c->param('Name'); }
$xtg_datas{name} = $name; } ## end if (!$result)
} ## end if ($choice eq 'UPDS')
$res = '';
if ( ! $result ) {
$res = $c->modify_serv();
$result .= $res unless $res eq 'OK';
if ( ! $result ) {
$result = $c->l('xtg_SERVICE_SUCCESS');
}
}
}
# common parts # common parts
if ($res ne 'OK') { if ($res ne 'OK') {
$c->stash( error => $result ); $c->stash(error => $result);
$c->stash( title => $title, xtg_datas => \%xtg_datas ); $c->stash(title => $title, xtg_datas => \%xtg_datas);
return $c->render( 'xt_geoip'.'_'.lc($choice) ); return $c->render('xt_geoip' . '_' . lc($choice));
} }
my $message = "xt_geoip updates $choice DONE"; my $message = "xt_geoip updates $choice DONE";
$c->app->log->info($message); $c->app->log->info($message);
$c->flash( success => $result ); $c->flash(success => $result);
## $c->flash( error => 'No changes applied !!' ); ## $c->flash( error => 'No changes applied !!' );
#return to 'xt_geoip' route !!! #return to 'xt_geoip' route !!!
$c->redirect_to('/xt_geoip'); $c->redirect_to('/xt_geoip');
} ## end sub do_action
};
sub get_badcountries { sub get_badcountries {
my $c = shift;
my $c = shift;
my $full = shift; my $full = shift;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $badc = $cdb->get_prop("masq", "BadCountries") || ""; my $badc = $cdb->get_prop("masq", "BadCountries") || "";
return $badc unless $full ; return $badc unless $full;
my $rev = (($cdb->get_prop("masq", "XTGeoipRev") || "disabled") eq "enabled") ? "!=" : "==";
my $rev = (($cdb->get_prop("masq", "XTGeoipRev")||"disabled") eq "enabled") ? "!=" : "==";
return "$rev $badc "; return "$rev $badc ";
} } ## end sub get_badcountries
sub get_geoip { sub get_geoip {
return $cdb->get_prop("masq", "GeoIP") || 'disabled'; return $cdb->get_prop("masq", "GeoIP") || 'disabled';
} }
sub get_reverse { sub get_reverse {
my $c = shift;
my $c = shift;
my $item = shift; my $item = shift;
my $prop = shift; my $prop = shift;
$item = ($item eq 'masq') ? $item : $c->param('Name'); $item = ($item eq 'masq') ? $item : $c->param('Name');
return $cdb->get_prop("$item", "$prop") || "disabled"; return $cdb->get_prop("$item", "$prop") || "disabled";
} } ## end sub get_reverse
sub get_stat_geoip { sub get_stat_geoip {
my $c = shift;
my $c = shift; if (system("/bin/test -f /lib/modules/`/bin/uname -r`/weak-updates/xtables-addons/xt_geoip.ko") != 0) {
if ( system ( "/bin/test -f /lib/modules/`/bin/uname -r`/weak-updates/xtables-addons/xt_geoip.ko") != 0 ) { return $c->l('xtg_ERROR_MISSING_MODULE');
return $c->l('xtg_ERROR_MISSING_MODULE'); } elsif (system("/sbin/lsmod | grep 'xt_geoip' > /dev/null") != 0) {
} elsif ( system ( "/sbin/lsmod | grep 'xt_geoip' > /dev/null") != 0 ) { return $c->l('xtg_ERROR_UNLOADED_MODULE');
return $c->l('xtg_ERROR_UNLOADED_MODULE'); } elsif (get_geoip() eq 'enabled' && system("/sbin/iptables -L -n | grep 'XTGeoIP' > /dev/null") != 0) {
} elsif ( get_geoip() eq 'enabled' && system ( "/sbin/iptables -L -n | grep 'XTGeoIP' > /dev/null") != 0 ) { return $c->l('xtg_ERROR_FILTER_CHAIN_MISSING');
return $c->l('xtg_ERROR_FILTER_CHAIN_MISSING'); } else {
} else { return '';
return ''; }
} } ## end sub get_stat_geoip
}
sub get_stat_license_key { sub get_stat_license_key {
my $c = shift; my $c = shift;
if (($cdb->get_prop( 'geoip','status' ) || 'disabled') eq 'enabled' ) { our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
if ( ($cdb->get_prop( 'geoip','LicenseKey' ) || '') ne '' ) {
return '';
}
}
return $c->l('xtg_ERROR_LICENSE_KEY');
}
if (($cdb->get_prop('geoip', 'status') || 'disabled') eq 'enabled') {
if (($cdb->get_prop('geoip', 'LicenseKey') || '') ne '') {
return '';
}
} ## end if (($cdb->get_prop('geoip'...)))
return $c->l('xtg_ERROR_LICENSE_KEY');
} ## end sub get_stat_license_key
sub get_date_update { sub get_date_update {
my $file = "/usr/share/xt_geoip/LE/A1.iv4"; #my $file = "/usr/share/xt_geoip/LE/A1.iv4";
my $filetime = ( -e $file ) ? (stat($file))[9] : 0; my $file = "/usr/share/xt_geoip/A1.iv4";
return strftime("%Y/%m/%d %H:%M", localtime( $filetime )) || ''; my $filetime = (-e $file) ? (stat($file))[9] : 0;
} return strftime("%Y/%m/%d %H:%M", localtime($filetime)) || '';
} ## end sub get_date_update
sub get_srv_name { sub get_srv_name {
my ($c) = @_; my ($c) = @_;
return $c->param('Name'); return $c->param('Name');
} }
sub get_services_table { sub get_services_table {
my $c = shift; my $c = shift;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $choice = shift || 'sel'; my $choice = shift || 'sel';
my @services; my @services;
my @serv_rec; my @serv_rec;
if ( $choice ne 'all' ) { if ($choice ne 'all') {
@services = split(/,/, $cdb->get_prop("masq", "XtServices")); @services = split(/,/, $cdb->get_prop("masq", "XtServices"));
for ( @services ) {
my $rec = $cdb->get( $_ ); for (@services) {
push @serv_rec, $rec if ( $rec && $rec->prop('TCPPort') ); my $rec = $cdb->get($_);
} push @serv_rec, $rec if ($rec && $rec->prop('TCPPort'));
}
} else { } else {
for ($cdb->get_all_by_prop(type => 'service')) {
push @serv_rec, $_ if ( $_->prop('TCPPort') ); for ($cdb->get_all_by_prop(type => 'service')) {
} push @serv_rec, $_ if ($_->prop('TCPPort'));
} }
} ## end else [ if ($choice ne 'all') ]
return \@serv_rec; return \@serv_rec;
} } ## end sub get_services_table
sub get_srv_badcountries { sub get_srv_badcountries {
my ( $c, $name, $full ) = @_; my ($c, $name, $full) = @_;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $badc = $cdb->get_prop($name, "BadCountries")||""; my $badc = $cdb->get_prop($name, "BadCountries") || "";
return $badc unless $full ; return $badc unless $full;
my $rev = (($cdb->get_prop($name, "XTGeoipRev") || "disabled") eq "enabled") ? "!=" : "==";
my $rev = (($cdb->get_prop($name, "XTGeoipRev")||"disabled") eq "enabled") ? "!=" : "==";
return "$rev $badc "; return "$rev $badc ";
} } ## end sub get_srv_badcountries
#Subroutine to list statistics #Subroutine to list statistics
sub generateStats { sub generateStats {
my $c = shift;
my $stats_type = shift;
my $out = '';
my $c = shift; # Untaint $name before use in system()
my $stats_type = shift; $stats_type =~ /(.+)/;
my $out = ''; $stats_type = $1;
# Untaint $name before use in system() if ($stats_type ne "ipt" and $stats_type ne "ssh" and $stats_type ne "f2b") {
$stats_type =~ /(.+)/; $stats_type = $1; $out .= sprintf("<h3>%s %s </h3>", $c->l('xtg_INVALID_STATS_TYPE'), $stats_type);
if ($stats_type ne "ipt" and $stats_type ne "ssh" and $stats_type ne "f2b") { return $out;
$out .= sprintf("<h3>%s %s </h3>", $c->l('xtg_INVALID_STATS_TYPE'), $stats_type); }
return $out;
}
# my $now_string = $c->gen_locale_date_string(); # my $now_string = $c->gen_locale_date_string();
my $file = "/var/lib/xt_geoip/extA_" . $stats_type . "_country.lst"; my $file = "/var/lib/xt_geoip/extA_" . $stats_type . "_country.lst";
my $filetime = ( -e $file ) ? (stat($file))[9] : 0; my $filetime = (-e $file) ? (stat($file))[9] : 0;
my $date_string = strftime("%Y/%m/%d %H:%M", localtime( $filetime )) || ''; my $date_string = strftime("%Y/%m/%d %H:%M", localtime($filetime)) || '';
$out .= sprintf("<h3>%s %s %s</h3>", $c->l('xtg_STATS_GENERATED'), $stats_type, $date_string);
open(Xt_GEOIPSTATS, $file);
$out .= sprintf "<pre>";
$out .= sprintf("<h3>%s %s %s</h3>", $c->l('xtg_STATS_GENERATED'), $stats_type, $date_string); while (<Xt_GEOIPSTATS>) {
$out .= sprintf("%s", $_);
}
close Xt_GEOIPSTATS;
$out .= sprintf "</pre>";
$out .= sprintf("<h3>%s</h3>", $c->l('xtg_END_OF_STATS'));
return $out;
} ## end sub generateStats
open( Xt_GEOIPSTATS, $file ); #Subroutine to list countries codes
$out .= sprintf "<pre>";
while (<Xt_GEOIPSTATS>)
{
$out .= sprintf("%s", $_);
}
close Xt_GEOIPSTATS;
$out .= sprintf "</pre>";
$out .= sprintf("<h3>%s</h3>", $c->l('xtg_END_OF_STATS'));
return $out;
}
#Subroutine to list counries codes
sub generateCodes { sub generateCodes {
my $c = shift;
my $out = '';
my $c = shift; # my $now_string = $c->gen_locale_date_string();
my $file = "/usr/share/xt_geoip/geoip_countries_list.txt";
my $out = ''; unless (-e $file) {
$out .= "<br>" . $c->l('xtg_INVALID_CODES_LIST');
# my $now_string = $c->gen_locale_date_string(); return $out;
my $file = "/usr/share/xt_geoip/geoip_countries_list.txt"; }
unless ( -e $file ) { my $filetime = (-e $file) ? (stat($file))[9] : 0;
$out .= "<br>" . $c->l('xtg_INVALID_CODES_LIST'); my $date_string = strftime("%Y/%m/%d %H:%M", localtime($filetime)) || '';
return $out; $out .= sprintf("<h3>%s %s </h3>", $c->l('xtg_COUNTRY_LIST'), $date_string);
} open(Xt_GEOIPCODES, $file);
$out .= sprintf "<pre>";
my $filetime = ( -e $file ) ? (stat($file))[9] : 0;
my $date_string = strftime("%Y/%m/%d %H:%M", localtime( $filetime )) || '';
$out .= sprintf("<h3>%s %s </h3>", $c->l('xtg_COUNTRY_LIST'), $date_string);
open( Xt_GEOIPCODES, $file );
$out .= sprintf "<pre>";
while (<Xt_GEOIPCODES>) {
$out .= sprintf("%s", $_);
}
close Xt_GEOIPCODES;
$out .= sprintf "</pre>";
$out .= sprintf("<h3>%s</h3>", $c->l('xtg_END_OF_CODES'));
return $out;
}
while (<Xt_GEOIPCODES>) {
$out .= sprintf("%s", $_);
}
close Xt_GEOIPCODES;
$out .= sprintf "</pre>";
$out .= sprintf("<h3>%s</h3>", $c->l('xtg_END_OF_CODES'));
return $out;
} ## end sub generateCodes
#Subroutine to list other services codes #Subroutine to list other services codes
sub otherServices { sub otherServices {
my ($c, $choice) = @_;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my %serv_ok = map { $_ => 1 } split(/,/, $cdb->get_prop("masq", "XtServices"));
my ($c, $choice) = @_; # unless $choice eq 'all';
my @serv_others = ();
my %serv_ok = map { $_ => 1} split(/,/, $cdb->get_prop("masq", "XtServices")); for ($cdb->get_all_by_prop(type => 'service')) {
# unless $choice eq 'all'; next unless $_->prop('TCPPort');
my @serv_others = (); # if ( $_->prop('TCPPort')) {
# push @serv_others, $_->key unless exists( $serv_ok{$_->key});
for ($cdb->get_all_by_prop(type => 'service')) { push @serv_others, $_->key unless $choice eq 'sel' and not exists($serv_ok{ $_->key });
next unless $_->prop('TCPPort');
# if ( $_->prop('TCPPort')) {
# push @serv_others, $_->key unless exists( $serv_ok{$_->key});
push @serv_others, $_->key unless $choice eq 'sel' and not exists( $serv_ok{$_->key});
# }
}
return \@serv_others;
}
# }
} ## end for ($cdb->get_all_by_prop...)
return \@serv_others;
} ## end sub otherServices
#Subroutine to update list services codes #Subroutine to update list services codes
sub do_otherServices { sub do_otherServices {
my $c = shift; my $c = shift;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $serv1 = ($cdb->get_prop("masq", "XtServices")) || ''; my $serv1 = ($cdb->get_prop("masq", "XtServices")) || '';
my $serv2 = join( ',', @{$c->every_param('Selectedservices')} ); my $serv2 = join(',', @{ $c->every_param('Selectedservices') });
$cdb->set_prop("masq", "XtServices", $serv2) if ($serv1 ne $serv2);
$cdb->set_prop("masq", "XtServices", $serv2) if ( $serv1 ne $serv2);
return 'OK'; return 'OK';
} } ## end sub do_otherServices
sub change_settings { sub change_settings {
my $c = shift;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $mq_bc = get_badcountries();
my $mq_gp = get_geoip();
my $masq = $cdb->get('masq') || "disabled";
my $mq_rv = $masq->prop('XTGeoipRev') || 'disabled';
my $mq_ot = $masq->prop('XTGeoipOther') || 'disabled';
my $n_mq_bc = $c->param("Masq_badcountries");
my $n_mq_gp = $c->param("Masq_geoip") || $mq_gp;
my $n_upd_gp = $c->param("Update_geoip") || '';
my $n_mq_rv = $c->param("Masq_reverse") || $mq_rv;
my $n_mq_ot = $c->param("Masq_others") || $mq_ot;
my $c = shift; if ( ($n_mq_bc eq $mq_bc)
&& ($n_mq_gp eq $mq_gp)
my $mq_bc = get_badcountries(); && ($n_upd_gp eq 'NO')
my $mq_gp = get_geoip(); && ($n_mq_rv eq $mq_rv)
my $masq = $cdb->get('masq') || "disabled"; && ($n_mq_ot eq $mq_ot))
my $mq_rv = $masq->prop('XTGeoipRev') || 'disabled'; {
my $mq_ot = $masq->prop('XTGeoipOther') || 'disabled'; return 'OK';
} ## end if (($n_mq_bc eq $mq_bc...))
my $n_mq_bc = $c->param("Masq_badcountries"); $cdb->set_prop("masq", "BadCountries", $n_mq_bc);
my $n_mq_gp = $c->param("Masq_geoip") || $mq_gp; $cdb->set_prop("masq", "GeoIP", $n_mq_gp);
my $n_upd_gp = $c->param("Update_geoip") || ''; $cdb->set_prop("masq", "XTGeoipRev", $n_mq_rv);
my $n_mq_rv = $c->param("Masq_reverse") || $mq_rv ; $cdb->set_prop("masq", "XTGeoipOther", $n_mq_ot);
my $n_mq_ot = $c->param("Masq_others") || $mq_ot ; my $eventloc = "xt_geoip-modify";
$eventloc = "xt_geoip-update" if $n_upd_gp eq 'YES';
if (($n_mq_bc eq $mq_bc) && ($n_mq_gp eq $mq_gp) && ($n_upd_gp eq 'NO') && ($n_mq_rv eq $mq_rv) && ($n_mq_ot eq $mq_ot)) {
return 'OK'
}
$cdb->set_prop("masq", "BadCountries", $n_mq_bc);
$cdb->set_prop("masq", "GeoIP", $n_mq_gp);
$cdb->set_prop("masq", "XTGeoipRev", $n_mq_rv);
$cdb->set_prop("masq", "XTGeoipOther", $n_mq_ot);
my $eventloc = "xt_geoip-modify";
$eventloc = "xt_geoip-update" if $n_upd_gp eq 'YES';
unless ( system ( "/sbin/e-smith/signal-event", $eventloc ) == 0 ) {
return $c->l("xtg_ERROR_UPDATING");
}
return 'OK';
}
unless (system("/sbin/e-smith/signal-event", $eventloc) == 0) {
return $c->l("xtg_ERROR_UPDATING");
}
return 'OK';
} ## end sub change_settings
=head2 valid_badcountries =head2 valid_badcountries
@ -480,82 +418,77 @@ subroutine to validate countries.
=cut =cut
sub must_exist { sub must_exist {
my $c = shift;
my $c = shift;
my $listerr = ""; my $listerr = "";
my @mq_bcs = split /[,:]/, $c->param("Masq_badcountries"); my @mq_bcs = split /[,:]/, $c->param("Masq_badcountries");
if (@mq_bcs) { if (@mq_bcs) {
my $ctr = @mq_bcs; my $ctr = @mq_bcs;
return $c->l('xtg_ERROR_COUNTRY_MAX', $ctr) if ($ctr > 50);
return $c->l('xtg_ERROR_COUNTRY_MAX', $ctr) if ($ctr > 50); foreach my $bcs (@mq_bcs) {
#my $file = "/usr/share/xt_geoip/LE/" . $bcs . ".iv4";
foreach my $bcs (@mq_bcs) { my $file = "/usr/share/xt_geoip/" . $bcs . ".iv4";
my $file = "/usr/share/xt_geoip/LE/" . $bcs . ".iv4"; if (!-f $file) { $listerr .= $bcs . ","; }
if (! -f $file) { $listerr .= $bcs . ","; } }
} return $c->l('xtg_ERROR_COUNTRY_NOT_EXIST', $listerr) if $listerr;
} ## end if (@mq_bcs)
return $c->l('xtg_ERROR_COUNTRY_NOT_EXIST', $listerr) if $listerr;
}
return 'OK'; return 'OK';
} } ## end sub must_exist
sub remove_serv { sub remove_serv {
my ($c) = @_;
my ( $c ) = @_; our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $name = $c->param('Name'); my $name = $c->param('Name');
# Untaint $name before use in system() # Untaint $name before use in system()
$name =~ /(.+)/; $name = $1; $name =~ /(.+)/;
$name = $1;
if (my $serv = $cdb->get($name)) { if (my $serv = $cdb->get($name)) {
my $servBC = $serv->prop('BadCountries') || ''; my $servBC = $serv->prop('BadCountries') || '';
if ($servBC ne '') { if ($servBC ne '') {
my $tps = $cdb->get_prop_and_delete($name, "BadCountries"); my $tps = $cdb->get_prop_and_delete($name, "BadCountries");
$tps = $cdb->get_prop_and_delete($name, "XTGeoipRev"); $tps = $cdb->get_prop_and_delete($name, "XTGeoipRev");
unless (system ("/sbin/e-smith/signal-event", "xt_geoip-service") == 0) { unless (system("/sbin/e-smith/signal-event", "xt_geoip-service") == 0) {
return $c->l("xtg_ERROR_WHILE_DELETING_SERVICE").' '.$name; return $c->l("xtg_ERROR_WHILE_DELETING_SERVICE") . ' ' . $name;
} }
return 'OK'; return 'OK';
} } ## end if ($servBC ne '')
} else { } else {
return $c->l('xtg_CANT_FIND_SERV'); return $c->l('xtg_CANT_FIND_SERV');
} }
} } ## end sub remove_serv
sub modify_serv { sub modify_serv {
my ($c) = @_; my ($c) = @_;
our $cdb = esmith::ConfigDB->open() or die "Couldn't open ConfigDB\n";
my $name = $c->param('Name'); my $name = $c->param('Name');
# Untaint $name before use in system() # Untaint $name before use in system()
$name =~ /(.+)/; $name = $1; $name =~ /(.+)/;
$name = $1;
if (my $serv = $cdb->get($name)) { if (my $serv = $cdb->get($name)) {
my $servBC = $serv->prop('BadCountries') || ''; my $servBC = $serv->prop('BadCountries') || '';
my $servRev = $serv->prop('XTGeoipRev') || 'disabled'; my $servRev = $serv->prop('XTGeoipRev') || 'disabled';
my $n_servBC = $c->param("Masq_srv_badcountries");
my $n_servRev = $c->param("Masq_srv_reverse") || $servRev;
my $n_servBC = $c->param("Masq_srv_badcountries"); if ($n_servBC eq $servBC && $n_servRev eq $servRev) {
my $n_servRev = $c->param("Masq_srv_reverse") || $servRev; return 'OK';
}
$cdb->set_prop($name, "BadCountries", $n_servBC);
$cdb->set_prop($name, "XTGeoipRev", $n_servRev);
if ($n_servBC eq $servBC && $n_servRev eq $servRev ) { unless (system("/sbin/e-smith/signal-event", "xt_geoip-service") == 0) {
return 'OK'; return $c->l("xtg_ERROR_UPDATING") . ' ' . $name;
}
$cdb->set_prop($name, "BadCountries", $n_servBC);
$cdb->set_prop($name, "XTGeoipRev", $n_servRev);
unless (system ( "/sbin/e-smith/signal-event", "xt_geoip-service" ) == 0 ) {
return $c->l("xtg_ERROR_UPDATING").' '.$name;
} }
return 'OK'; return 'OK';
} else { } else {
return $c->l('xtg_CANT_FIND_SERV'); return $c->l('xtg_CANT_FIND_SERV');
} }
} } ## end sub modify_serv
1; 1;

View File

@ -31,7 +31,7 @@
% foreach my $sv (@services) { % foreach my $sv (@services) {
% my $svBC = $sv->prop('BadCountries') || ' '; % my $svBC = $sv->prop('BadCountries') || ' ';
% my $svRev = (( $sv->prop('Xt_geoipRev')|| 'disabled') eq 'disabled' )? '==': '!='; % my $svRev = (( $sv->prop('XTGeoipRev')|| 'disabled') eq 'disabled' )? '==': '!=';
% my $color = 'red'; % my $color = 'red';
% my $deco= "none"; % my $deco= "none";
% if ($svRev eq '!=' ) { $color = 'green'; } % if ($svRev eq '!=' ) { $color = 'green'; }

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas
@ -44,7 +44,7 @@
<br><span class=label> <br><span class=label>
%=l 'xtg_LABEL_REVERSE_MATCH' %=l 'xtg_LABEL_REVERSE_MATCH'
</span><span class=data> </span><span class=data>
% param 'Masq_srv_reverse' => $c->get_reverse('','Xt_geoipRev') unless param 'Masq_srv_reverse'; % param 'Masq_srv_reverse' => $c->get_reverse('masq','XTGeoipRev') unless param 'Masq_srv_reverse';
%= select_field 'Masq_srv_reverse' => [['!=' => 'enabled'], ['==' => 'disabled']], class => 'input' %= select_field 'Masq_srv_reverse' => [['!=' => 'enabled'], ['==' => 'disabled']], class => 'input'
</span></p> </span></p>

View File

@ -4,7 +4,7 @@
<div id="module" class="module xt_geoip-panel"> <div id="module" class="module xt_geoip-panel">
%if ($config->{debug} == 1) { %if (config->{debug} == 1) {
<p> <p>
%= dumper $c->current_route %= dumper $c->current_route
%= dumper $xtg_datas %= dumper $xtg_datas
@ -35,7 +35,7 @@
<br><span class=label> <br><span class=label>
%=l 'xtg_LABEL_REVERSE_MATCH' %=l 'xtg_LABEL_REVERSE_MATCH'
</span><span class=data> </span><span class=data>
% param 'Masq_reverse' => $c->get_reverse('masq','Xt_geoipRev') unless param 'Masq_reverse'; % param 'Masq_reverse' => $c->get_reverse('masq','XTGeoipRev') unless param 'Masq_reverse';
%= select_field 'Masq_reverse' => [[ '!=' => 'enabled'], [ '==' => 'disabled']], class => 'input' %= select_field 'Masq_reverse' => [[ '!=' => 'enabled'], [ '==' => 'disabled']], class => 'input'
</span></p> </span></p>
@ -59,7 +59,7 @@
<br><span class=label> <br><span class=label>
%=l 'xtg_LABEL_OTHERS' %=l 'xtg_LABEL_OTHERS'
</span><span class=data> </span><span class=data>
% param 'Masq_others' => $c->get_reverse('masq','Xt_geoipOther') unless param 'Masq_others'; % param 'Masq_others' => $c->get_reverse('masq','XT_GeoipOther') unless param 'Masq_others';
%= select_field 'Masq_others' => [[(l 'DISABLED') => 'disabled'], [(l 'ENABLED') => 'enabled']], class => 'input' %= select_field 'Masq_others' => [[(l 'DISABLED') => 'disabled'], [(l 'ENABLED') => 'enabled']], class => 'input'
</span></p> </span></p>

View File

@ -1,5 +1,8 @@
# Run the builder - this leaves all the file in /usr.share/xt_geoip
# It's messy but I don't know how to get iptables to read a sub dir
cd /usr/share/xt_geoip cd /usr/share/xt_geoip
if ( ./xt_geoip_dl ) if ( ./xt_geoip_dl )
then then
/usr/libexec/xtables-addons/xt_geoip_build GeoIPCountryWhois.csv /usr/share/xt_geoip/xt_geoip_build_maxmind
fi fi

View File

@ -0,0 +1,257 @@
#!/usr/bin/perl
#
# Converter for MaxMind (GeoLite2) CSV database to binary, for xt_geoip
# Copyright Jan Engelhardt, 2008-2011
# Copyright Philip Prindeville, 2018
# copied from /usr/libexec/xtables-addons to work on Koozali SME v11
# cannot work out to get iptables to read from a sub directory from a here
#
use Getopt::Long;
use Net::CIDR::Lite;
use Socket qw(AF_INET AF_INET6 inet_pton);
use warnings;
use Text::CSV_XS; # or trade for Text::CSV
use strict;
$| = 1;
my $csv = Text::CSV_XS->new(
{ allow_whitespace => 1,
binary => 1,
eol => $/,
}
); # or Text::CSV
#my $source_dir = ".";
my $source_dir = "./GeoLite2-Country-CSV";
my $quiet = 0;
my $target_dir = ".";
&Getopt::Long::Configure(qw(bundling));
&GetOptions(
"D=s" => \$target_dir,
"S=s" => \$source_dir,
"q" => \$quiet,
"s" => sub { $target_dir = "/usr/share/xt_geoip"; },
);
if (!-d $source_dir) {
print STDERR "Source directory \"$source_dir\" does not exist.\n";
exit 1;
}
if (!-d $target_dir) {
print STDERR "Target directory \"$target_dir\" does not exist.\n";
exit 1;
}
my %countryId;
my %countryName;
&loadCountries();
&dump(&collect());
sub loadCountries {
sub id;
sub cc;
sub long;
sub ct;
sub cn;
%countryId = ();
%countryName = ();
my $file = "$source_dir/GeoLite2-Country-Locations-en.csv";
open(my $fh, '<', $file) || die "Couldn't open list country names\n";
# first line is headers
my $row = $csv->getline($fh);
my %header = map { ($row->[$_], $_); } (0 .. $#{$row});
my %pairs = (
country_iso_code => 'ISO Country Code',
geoname_id => 'ID',
country_name => 'Country Name',
continent_code => 'Continent Code',
continent_name => 'Continent Name',
);
# verify that the columns we need are present
map { die "Table has no $pairs{$_} column\n" unless (exists $header{$_}); } keys %pairs;
my %remapping = (
id => 'geoname_id',
cc => 'country_iso_code',
long => 'country_name',
ct => 'continent_code',
cn => 'continent_name',
);
# now create a function which returns the value of that column #
map { eval "sub $_ () { \$header{\$remapping{$_}}; }"; } keys %remapping;
while (my $row = $csv->getline($fh)) {
if ($row->[cc] eq '' && $row->[long] eq '') {
$countryId{ $row->[id] } = $row->[ct];
$countryName{ $row->[ct] } = $row->[cn];
} else {
$countryId{ $row->[id] } = $row->[cc];
$countryName{ $row->[cc] } = $row->[long];
}
} ## end while (my $row = $csv->getline...)
$countryName{A1} = 'Anonymous Proxy';
$countryName{A2} = 'Satellite Provider';
$countryName{O1} = 'Other Country';
close($fh);
# clean up the namespace
undef &id;
undef &cc;
undef &long;
undef &ct;
undef &cn;
} ## end sub loadCountries
sub lookupCountry {
my ($id, $rid, $proxy, $sat) = @_;
if ($proxy) {
return 'A1';
} elsif ($sat) {
return 'A2';
}
$id ||= $rid;
if ($id eq '') {
return 'O1';
}
die "Unknown id: $id line $.\n" unless (exists $countryId{$id});
return $countryId{$id};
} ## end sub lookupCountry
sub collect {
my ($file, $fh, $row);
my (%country, %header);
sub net;
sub id;
sub rid;
sub proxy;
sub sat;
my %pairs = (
network => 'Network',
registered_country_geoname_id => 'Registered Country ID',
geoname_id => 'Country ID',
is_anonymous_proxy => 'Anonymous Proxy',
is_satellite_provider => 'Satellite',
);
foreach (sort keys %countryName) {
$country{$_} = {
name => $countryName{$_},
pool_v4 => Net::CIDR::Lite->new(),
pool_v6 => Net::CIDR::Lite->new(),
};
} ## end foreach (sort keys %countryName)
$file = "$source_dir/GeoLite2-Country-Blocks-IPv4.csv";
open($fh, '<', $file) || die "Can't open IPv4 database\n";
# first line is headers
$row = $csv->getline($fh);
%header = map { ($row->[$_], $_); } (0 .. $#{$row});
# verify that the columns we need are present
map { die "Table has no %pairs{$_} column\n" unless (exists $header{$_}); } keys %pairs;
my %remapping = (
net => 'network',
id => 'geoname_id',
rid => 'registered_country_geoname_id',
proxy => 'is_anonymous_proxy',
sat => 'is_satellite_provider',
);
# now create a function which returns the value of that column #
map { eval "sub $_ () { \$header{\$remapping{$_}}; }"; } keys %remapping;
while ($row = $csv->getline($fh)) {
my ($cc, $cidr);
$cc = lookupCountry($row->[id], $row->[rid], $row->[proxy], $row->[sat]);
$cidr = $row->[net];
$country{$cc}->{pool_v4}->add($cidr);
if (!$quiet && $. % 4096 == 0) {
print STDOUT "\r\e[2K$. entries";
}
} ## end while ($row = $csv->getline...)
print STDOUT "\r\e[2K$. entries total\n" unless ($quiet);
close($fh);
# clean up the namespace
undef &net;
undef &id;
undef &rid;
undef &proxy;
undef &sat;
$file = "$source_dir/GeoLite2-Country-Blocks-IPv6.csv";
open($fh, '<', $file) || die "Can't open IPv6 database\n";
# first line is headers
$row = $csv->getline($fh);
%header = map { ($row->[$_], $_); } (0 .. $#{$row});
# verify that the columns we need are present
map { die "Table has no %pairs{$_} column\n" unless (exists $header{$_}); } keys %pairs;
# unlikely the IPv6 table has different columns, but just to be sure
# create a function which returns the value of that column #
map { eval "sub $_ () { \$header{\$remapping{$_}}; }"; } keys %remapping;
while ($row = $csv->getline($fh)) {
my ($cc, $cidr);
$cc = lookupCountry($row->[id], $row->[rid], $row->[proxy], $row->[sat]);
$cidr = $row->[net];
$country{$cc}->{pool_v6}->add($cidr);
if (!$quiet && $. % 4096 == 0) {
print STDOUT "\r\e[2K$. entries";
}
} ## end while ($row = $csv->getline...)
print STDOUT "\r\e[2K$. entries total\n" unless ($quiet);
close($fh);
# clean up the namespace
undef &net;
undef &id;
undef &rid;
undef &proxy;
undef &sat;
return \%country;
} ## end sub collect
sub dump {
my $country = shift @_;
foreach my $iso_code (sort keys %{$country}) {
&dump_one($iso_code, $country->{$iso_code});
}
} ## end sub dump
sub dump_one {
my ($iso_code, $country) = @_;
my @ranges;
@ranges = $country->{pool_v4}->list_range();
writeCountry($iso_code, $country->{name}, AF_INET, @ranges);
@ranges = $country->{pool_v6}->list_range();
writeCountry($iso_code, $country->{name}, AF_INET6, @ranges);
} ## end sub dump_one
sub writeCountry {
my ($iso_code, $name, $family, @ranges) = @_;
my $fh;
printf "%5u IPv%s ranges for %s %s\n", scalar(@ranges), ($family == AF_INET ? '4' : '6'), $iso_code, $name unless ($quiet);
my $file = "$target_dir/" . uc($iso_code) . ".iv" . ($family == AF_INET ? '4' : '6');
if (!open($fh, '>', $file)) {
print STDERR "Error opening $file: $!\n";
exit 1;
}
binmode($fh);
foreach my $range (@ranges) {
my ($start, $end) = split('-', $range);
$start = inet_pton($family, $start);
$end = inet_pton($family, $end);
print $fh $start, $end;
} ## end foreach my $range (@ranges)
close $fh;
} ## end sub writeCountry

View File

@ -3,6 +3,9 @@
# Original script from xtables-addons # Original script from xtables-addons
# SME specific use of ConfigDB # SME specific use of ConfigDB
# replace /usr/libexec/xtables-addons/xt_geoip_dl in /usr/share/xt_geoip/update_base # replace /usr/libexec/xtables-addons/xt_geoip_dl in /usr/share/xt_geoip/update_base
# Koozali SME v11
# Now migrated to using files in /usr/share/xt_geoip
status=$(/sbin/e-smith/config getprop geoip status) status=$(/sbin/e-smith/config getprop geoip status)
if [[ "$status" != "enabled" ]] if [[ "$status" != "enabled" ]]
@ -26,5 +29,9 @@ then
exit 2 exit 2
fi fi
unzip -q GeoLite2-Country-CSV.zip # unzip -q GeoLite2-Country-CSV.zip
if [ ! -d "/usr/share/xt_geoip/GeoLite2-Country-CSV" ]; then
mkdir -p "/usr/share/xt_geoip/GeoLite2-Country-CSV";
fi
unzip -o -q -j GeoLite2-Country-CSV.zip -d /usr/share/xt_geoip/GeoLite2-Country-CSV
rm -f GeoLite2-Country-CSV.zip rm -f GeoLite2-Country-CSV.zip

View File

@ -1,6 +1,6 @@
%define name smeserver-xt_geoip %define name smeserver-xt_geoip
%define version 1.3.1 %define version 1.3.1
%define release 22 %define release 26
Summary: smserver rpm to setup database, update and configuration for xt_geoip module with a panel. Summary: smserver rpm to setup database, update and configuration for xt_geoip module with a panel.
Name: %{name} Name: %{name}
@ -14,14 +14,17 @@ Source: %{name}-%{version}.tar.xz
BuildArchitectures: noarch BuildArchitectures: noarch
BuildRoot: /var/tmp/%{name}-%{version} BuildRoot: /var/tmp/%{name}-%{version}
BuildRequires: e-smith-devtools BuildRequires: e-smith-devtools
Requires: e-smith-release >= 10.0 Requires: e-smith-release >= 11.0
Requires: server-manager >= 0.1.0-23 Requires: server-manager >= 11
Requires: xtables-addons = 2.14 Requires: xtables-addons >= 3.25
Requires: GeoIP >= 1.5.0 # Is this required now?
Requires: GeoIP >= 1.6.0
Requires: libmaxminddb >= 1.1.1 Requires: libmaxminddb >= 1.1.1
# Is this required now?
Requires: libmaxminddb-devel >= 1.1.1 Requires: libmaxminddb-devel >= 1.1.1
Requires: geolite2-country Requires: geolite2-country
Requires: geolite2-city Requires: geolite2-city
Requires: perl-Text-CSV_XS
AutoReqProv: no AutoReqProv: no
%description %description
@ -53,6 +56,7 @@ rm -f %{name}-%{version}-filelist
--file /usr/share/xt_geoip/geoip_stats 'attr(0755, root, root)'\ --file /usr/share/xt_geoip/geoip_stats 'attr(0755, root, root)'\
--file /usr/share/xt_geoip/xt_geoip_dl 'attr(0750, root, root)'\ --file /usr/share/xt_geoip/xt_geoip_dl 'attr(0750, root, root)'\
--file /usr/share/xt_geoip/update_base 'attr(0750, root, root)'\ --file /usr/share/xt_geoip/update_base 'attr(0750, root, root)'\
--file /usr/share/xt_geoip/xt_geoip_build_maxmind 'attr(0750, root, root)'\
> %{name}-%{version}-filelist > %{name}-%{version}-filelist
echo "%doc COPYING" >> %{name}-%{version}-filelist echo "%doc COPYING" >> %{name}-%{version}-filelist
@ -78,6 +82,22 @@ fi
%changelog %changelog
* Thu Mar 20 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-26.sme
- Fix createlink typo remote-access-update [SME: 12438]
* Thu Feb 13 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-25.sme
- Fix various typos as per bug but more to find [SME: 12472]
* Thu Feb 13 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-24.sme
- move scripting back to /usr/share/geoip
- Lose the LE/BE (Little/Big Endian) parts as iptables can't seem to read the file in subdirs
- Update ULOG to NFLOG in rules but restricts the number of countries
* Wed Feb 12 2025 John Crisp <jcrisp@safeandsoundit.co.uk> 1.3.1-23.sme
- Update dependencies for xtables addons
- Remove $ from config in templates
- Add db open entries to subs
* Sat Sep 07 2024 cvs2git.sh aka Brian Read <brianr@koozali.org> 1.3.1-22.sme * Sat Sep 07 2024 cvs2git.sh aka Brian Read <brianr@koozali.org> 1.3.1-22.sme
- Roll up patches and move to git repo [SME: 12338] - Roll up patches and move to git repo [SME: 12338]