| Linux server27.hostingraja.org 2.6.32-954.3.5.lve1.4.93.el6.x86_64 #1 SMP Wed Oct 4 17:04:29 UTC 2023 x86_64 Path : /opt/imunify360/venv/lib/python3.11/site-packages/im360/plugins/resident/ |
| Current File : //opt/imunify360/venv/lib/python3.11/site-packages/im360/plugins/resident/whitelist_panels_login.py |
import logging
import time
from ipaddress import ip_network
from humanize import naturaldelta
from defence360agent.contracts.plugins import expect, MessageSink
from im360.api.ips import IPApi
from defence360agent.contracts.messages import MessageType
from im360.ioc import services
from im360.model.firewall import IPList
logger = logging.getLogger(__name__)
class WhitelistPanelsLogin(MessageSink):
"""
Placing all IPs that successfuly login panel into whitelist with TTL.
"""
PROCESSING_ORDER = MessageSink.ProcessingOrder.IGNORE_MESSAGE
OSSEC_RULES = {
11006: False, # rule id for cPanel login
11009: True, # rule id for WHM login (full access)
}
TTL = 60 * 60 * 3
def __init__(self):
self._whitelist_cache = services.primary_whitelist_cache
async def create_sink(self, loop):
self._loop = loop
@expect(MessageType.SensorIncident, plugin_id="ossec")
async def whitelist_panels_login(self, message):
if message["rule"] in self.OSSEC_RULES:
ip = ip_network(message.get("attackers_ip"))
expiration = int(self.TTL + time.time())
if not await self._whitelist_cache.contains(ip):
await IPApi.block(
items=[ip],
listname=IPList.WHITE,
expiration=expiration,
manual=False,
comment="Whitelisted for %s due to successful panel login"
% naturaldelta(self.TTL),
full_access=self.OSSEC_RULES[message["rule"]],
)
logger.info(
"Added %s logged in panel to the Whitelist for %s seconds",
ip,
self.TTL,
)