diabliyo

phpfirewall v1.03-1113

Nov 3rd, 2013
163
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.33 KB | None | 0 0
  1. # phpfirewall 1.0
  2. #
  3. # M.S.I. Angel Haniel Cantu Jauregui
  4. # http://www.sie-group.net/
  5. #
  6. # Script que arma las reglas del firewall IPTables, con la finalidad de obtener los rangos de IPs a
  7. # bloquear, tomando en cuenta la lista de IPs Local (Red LAN) que no tendran bloqueado los servicios.
  8. #
  9.  
  10. #!/usr/bin/php
  11.  
  12. <?php
  13. set_time_limit(0); # ilimitado tiempo de ejecucion
  14.  
  15. /*
  16. iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 173.252.64.0-173.252.127.255 -j REJECT # bloquear CIDR
  17. iptables -I FORWARD -p tcp -m string --string lapagina.com --dport 443 --algo bm -j REJECT # por string
  18. */
  19.  
  20. # limpia una variable, eliminando salto de linea
  21. function get_script_clearjump( $var )
  22.     {
  23.     $out='';
  24.     if( strstr($var, "\n") ) # si existe un de linea
  25.         $out= substr($var, 0, -1);
  26.     else $out=$var;
  27.     return $out;
  28.     }
  29.  
  30. function string_clean( $buf )
  31.     {  
  32.     $s_signos= array( '/[^0-9.-]/' ); # buscar simbolos que no sean estos
  33.     $buf= preg_replace( $s_signos, "", $buf ); # re-emplazamos signos
  34.     return $buf;
  35.     }
  36.  
  37. $pathsquid= '/etc/squid/';
  38. $cidrbd= 'cidr.txt'; # bdd de CIDR's a bloquear
  39. $ipsdb= 'ipslibres.txt'; # bdd de IPs que tendran navegacion libre
  40. $cid= array();
  41. $ip= array();
  42.  
  43. # leyendo bdd de CIDRs
  44. $fp= fopen($pathsquid.$cidrbd, "r"); # abrimos
  45. while( ($buf= fgets($fp, 1024))!==FALSE )
  46.     {
  47.     if( string_clean($buf) )
  48.         $cid[]= get_script_clearjump(string_clean($buf));
  49.     }
  50. fclose($fp);
  51.  
  52. # leyeno bdd de IPs
  53. $fp= fopen($pathsquid.$ipsdb, "r"); # abrimos
  54. while( ($buf= fgets($fp, 1024))!==FALSE )
  55.     {
  56.     if( string_clean($buf) )
  57.         $ip[]= get_script_clearjump(string_clean($buf));
  58.     }
  59. fclose($fp);
  60.  
  61. echo 'Se han leido: '. count($cid). ' CIDRs a bloquear.';
  62. foreach( $cid as $key )
  63.     echo "\n ". $key. " [Bloqueando]";
  64. echo "\n\n";
  65.  
  66. echo 'Se han leido: '. count($ip). ' direcciones IPs a excluir del bloqueo.';
  67. foreach( $ip as $key )
  68.     echo "\n ". $key. " [Libre]";
  69. echo "\n\n";
  70.  
  71. echo "Reglas IPTables para IP Libres:\n";
  72. foreach( $cid as $key )
  73.     {
  74.     foreach( $ip as $val )
  75.         echo "\niptables -I FORWARD -m tcp -p tcp -s ". $val. " -m iprange --dst-range ". $key. " -j ACCEPT";
  76.     }
  77. echo "\n\n";
  78.  
  79. echo "Reglas IPTables para los demas:\n";
  80. foreach( $cid as $key )
  81.     echo "\niptables -I FORWARD -m tcp -p tcp -m iprange --dst-range ". $key. " -j REJECT";
  82. echo "\n\n";
  83.  
  84. unset($cid, $ip);
  85. exit(0);
  86. ?>
Advertisement
Add Comment
Please, Sign In to add comment