#! /usr/bin/env python # -*- coding: utf-8 -*- # Ajout d'un whos et d'un tracage aux mails d'arpwatch # Auteurs : Stéphane Glondu, Cyril Cohen # Licence : GPLv2 import sys, os, re, smtplib from commands import getstatusoutput sys.path.append('/usr/scripts/gestion') sys.path.append('/usr/scripts/gestion/tools') from locate_mac import trace_machine, format_mac, info_machine from config import NETs from iptools import AddrInNets find_mac = re.compile(r'[0-9A-Fa-f]{1,2}(?::[0-9A-Fa-f]{1,2}){5}') find_ip = re.compile(r'[0-9]{1,3}(?:\.[0-9]{1,3}){3}') arpwatched_net = NETs['all'] + NETs['adm'] + NETs['accueil'] + NETs['isolement'] + NETs['personnel-ens'] + NETs['evenementiel'] def get_machine(unformated_mac): mac = format_mac(unformated_mac) return u"\n" + info_machine(mac) + u"\n" + trace_machine(mac) def get_subject(headers_list): for line in headers_list: if line.lower().startswith('subject:'): return line return None if __name__ == "__main__": texte = sys.stdin.read() #.decode('ISO-8859-15') textes = texte.splitlines(True) i = textes.index(u'\n') subject = get_subject(textes[:i]) textes[i-1:i-1] = [ u'MIME-Version: 1.0\n', u'Content-Type: text/plain; charset=UTF-8\n', u'Content-Transfer-Encoding: 8bit\n', ] # On récupère les destinataires dans les arguments (très ad hoc) recipients = sys.argv[2].split(',') try : ip = set(find_ip.findall(texte)).pop() except KeyError: ip = None # On complète le message if 'flip flop' in subject and ip is not None and AddrInNets(ip, arpwatched_net): try: macs = find_mac.findall(texte) for mac in macs: textes.append(get_machine(mac)) except: # En cas d'exception, on envoie le traceback import traceback textes.append(u'\n') textes.append(u''.join(traceback.format_exception(sys.exc_type, sys.exc_value, sys.exc_traceback))) textes.append('\n-- \narpwatch_sendmail.py\n') smtp = smtplib.SMTP() smtp.connect() smtp.sendmail("arpwatch@crans.org", recipients, u''.join(textes).encode('UTF-8')) smtp.quit()