1 1.1 elric #! /usr/pkg/bin/perl 2 1.1 elric # -*- mode: perl; perl-indent-level: 8 -*- 3 1.1 elric # 4 1.1 elric # Copyright (c) 2003 Kungliga Tekniska Hgskolan 5 1.1 elric # (Royal Institute of Technology, Stockholm, Sweden). 6 1.1 elric # All rights reserved. 7 1.1 elric # 8 1.1 elric # Redistribution and use in source and binary forms, with or without 9 1.1 elric # modification, are permitted provided that the following conditions 10 1.1 elric # are met: 11 1.1 elric # 12 1.1 elric # 1. Redistributions of source code must retain the above copyright 13 1.1 elric # notice, this list of conditions and the following disclaimer. 14 1.1 elric # 15 1.1 elric # 2. Redistributions in binary form must reproduce the above copyright 16 1.1 elric # notice, this list of conditions and the following disclaimer in the 17 1.1 elric # documentation and/or other materials provided with the distribution. 18 1.1 elric # 19 1.1 elric # 3. Neither the name of the Institute nor the names of its contributors 20 1.1 elric # may be used to endorse or promote products derived from this software 21 1.1 elric # without specific prior written permission. 22 1.1 elric # 23 1.1 elric # THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 24 1.1 elric # ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 25 1.1 elric # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 26 1.1 elric # ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 27 1.1 elric # FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 28 1.1 elric # DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 29 1.1 elric # OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 30 1.1 elric # HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 31 1.1 elric # LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 32 1.1 elric # OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 33 1.1 elric # SUCH DAMAGE. 34 1.1 elric # 35 1.1.1.2 elric # Id 36 1.1 elric # 37 1.1 elric # kdc-log-analyze - Analyze a KDC log file and give a report on the contents 38 1.1 elric # 39 1.1 elric # Note: The parts you want likely want to customize are the variable $notlocal, 40 1.1 elric # the array @local_network_re and the array @local_realms. 41 1.1 elric # 42 1.1 elric # Idea and implemetion for MIT Kerberos was done first by 43 1.1 elric # Ken Hornstein <kenh (at] cmf.nrl.navy.mil>, this program wouldn't exists 44 1.1 elric # without his help. 45 1.1 elric # 46 1.1 elric 47 1.1 elric use strict; 48 1.1 elric use Sys::Hostname; 49 1.1 elric 50 1.1 elric my $notlocal = 'not SU'; 51 1.1 elric my @local_realms = ( "SU.SE" ); 52 1.1 elric my @local_networks_re = 53 1.1 elric ( 54 1.1 elric "130\.237", 55 1.1 elric "193\.11\.3[0-9]\.", 56 1.1 elric "130.242.128", 57 1.1 elric "2001:6b0:5:" 58 1.1 elric ); 59 1.1 elric 60 1.1 elric my $as_req = 0; 61 1.1 elric my %as_req_addr; 62 1.1 elric my %as_req_addr_nonlocal; 63 1.1 elric my %as_req_client; 64 1.1 elric my %as_req_server; 65 1.1 elric my %addr_uses_des; 66 1.1 elric my %princ_uses_des; 67 1.1 elric my $five24_req = 0; 68 1.1 elric my %five24_req_addr; 69 1.1 elric my %five24_req_addr_nonlocal; 70 1.1 elric my %five24_req_server; 71 1.1 elric my %five24_req_client; 72 1.1 elric my $as_req_successful = 0; 73 1.1 elric my $as_req_error = 0; 74 1.1 elric my $no_such_princ = 0; 75 1.1 elric my %no_such_princ_princ; 76 1.1 elric my %no_such_princ_addr; 77 1.1 elric my %no_such_princ_addr_nonlocal; 78 1.1 elric my $as_req_etype_odd = 0; 79 1.1 elric my %bw_addr; 80 1.1 elric my $pa_alt_princ_request = 0; 81 1.1 elric my $pa_alt_princ_verify = 0; 82 1.1 elric my $tgs_req = 0; 83 1.1 elric my %tgs_req_addr; 84 1.1 elric my %tgs_req_addr_nonlocal; 85 1.1 elric my %tgs_req_client; 86 1.1 elric my %tgs_req_server; 87 1.1 elric my $tgs_xrealm_out = 0; 88 1.1 elric my %tgs_xrealm_out_realm; 89 1.1 elric my %tgs_xrealm_out_princ; 90 1.1 elric my $tgs_xrealm_in = 0; 91 1.1 elric my %tgs_xrealm_in_realm; 92 1.1 elric my %tgs_xrealm_in_princ; 93 1.1 elric my %enctype_session; 94 1.1 elric my %enctype_ticket; 95 1.1 elric my $restarts = 0; 96 1.1 elric my $forward_non_forward = 0; 97 1.1 elric my $v4_req = 0; 98 1.1 elric my %v4_req_addr; 99 1.1 elric my %v4_req_addr_nonlocal; 100 1.1 elric my $v4_cross = 0; 101 1.1 elric my %v4_cross_realm; 102 1.1 elric my $v5_cross = 0; 103 1.1 elric my %v5_cross_realm; 104 1.1 elric my $referrals = 0; 105 1.1 elric my %referral_princ; 106 1.1 elric my %referral_realm; 107 1.1 elric my %strange_tcp_data; 108 1.1 elric my $http_malformed = 0; 109 1.1 elric my %http_malformed_addr; 110 1.1 elric my $http_non_kdc = 0; 111 1.1 elric my %http_non_kdc_addr; 112 1.1 elric my $tcp_conn_timeout = 0; 113 1.1 elric my %tcp_conn_timeout_addr; 114 1.1 elric my $failed_processing = 0; 115 1.1 elric my %failed_processing_addr; 116 1.1 elric my $connection_closed = 0; 117 1.1 elric my %connection_closed_addr; 118 1.1 elric my $pa_failed = 0; 119 1.1 elric my %pa_failed_princ; 120 1.1 elric my %pa_failed_addr; 121 1.1 elric my %ip; 122 1.1 elric 123 1.1 elric $ip{'4'} = $ip{'6'} = 0; 124 1.1 elric 125 1.1 elric while (<>) { 126 1.1 elric process_line($_); 127 1.1 elric } 128 1.1 elric 129 1.1 elric print "Kerberos KDC Log Report for ", 130 1.1 elric hostname, " on ", scalar localtime, "\n\n"; 131 1.1 elric 132 1.1 elric print "General Statistics\n\n"; 133 1.1 elric 134 1.1 elric print "\tNumber of IPv4 requests: $ip{'4'}\n"; 135 1.1 elric print "\tNumber of IPv6 requests: $ip{'6'}\n\n"; 136 1.1 elric 137 1.1 elric print "\tNumber of restarts: $restarts\n"; 138 1.1 elric print "\tNumber of V4 requests: $v4_req\n"; 139 1.1 elric if ($v4_req > 0) { 140 1.1 elric print "\tTop ten IP addresses performing V4 requests:\n"; 141 1.1 elric topten(\%v4_req_addr); 142 1.1 elric } 143 1.1 elric if (int(keys %v4_req_addr_nonlocal) > 0) { 144 1.1 elric print "\tTop ten $notlocal IP addresses performing V4 requests:\n"; 145 1.1 elric topten(\%v4_req_addr_nonlocal); 146 1.1 elric 147 1.1 elric } 148 1.1 elric print "\n"; 149 1.1 elric 150 1.1 elric print "\tNumber of V4 cross realms (krb4 and 524) requests: $v4_cross\n"; 151 1.1 elric if ($v4_cross > 0) { 152 1.1 elric print "\tTop ten realms performing V4 cross requests:\n"; 153 1.1 elric topten(\%v4_cross_realm); 154 1.1 elric } 155 1.1 elric print "\n"; 156 1.1 elric 157 1.1 elric print "\tNumber of V45 cross realms requests: $v5_cross\n"; 158 1.1 elric if ($v5_cross > 0) { 159 1.1 elric print "\tTop ten realms performing V4 cross requests:\n"; 160 1.1 elric topten(\%v5_cross_realm); 161 1.1 elric } 162 1.1 elric print "\n"; 163 1.1 elric 164 1.1 elric print "\tNumber of failed lookups: $no_such_princ\n"; 165 1.1 elric if ($no_such_princ > 0) { 166 1.1 elric print "\tTop ten IP addresses failing to find principal:\n"; 167 1.1 elric topten(\%no_such_princ_addr); 168 1.1 elric print "\tTop ten $notlocal IP addresses failing find principal:\n"; 169 1.1 elric topten(\%no_such_princ_addr_nonlocal); 170 1.1 elric print "\tTop ten failed to find principals\n"; 171 1.1 elric topten(\%no_such_princ_princ); 172 1.1 elric } 173 1.1 elric print "\n"; 174 1.1 elric 175 1.1 elric print "\tBandwidth pigs:\n"; 176 1.1 elric topten(\%bw_addr); 177 1.1 elric print "\n"; 178 1.1 elric 179 1.1 elric print "\tStrange TCP data clients: ", int(keys %strange_tcp_data),"\n"; 180 1.1 elric topten(\%strange_tcp_data); 181 1.1 elric print "\n"; 182 1.1 elric 183 1.1 elric print "\tTimeout waiting on TCP requests: ", $tcp_conn_timeout,"\n"; 184 1.1 elric if ($tcp_conn_timeout > 0) { 185 1.1 elric print "\tTop ten TCP timeout request clients\n"; 186 1.1 elric topten(\%tcp_conn_timeout_addr); 187 1.1 elric } 188 1.1 elric print "\n"; 189 1.1 elric 190 1.1 elric print "\tFailed processing requests: ", $failed_processing,"\n"; 191 1.1 elric if ($failed_processing > 0) { 192 1.1 elric print "\tTop ten failed processing request clients\n"; 193 1.1 elric topten(\%failed_processing_addr); 194 1.1 elric } 195 1.1 elric print "\n"; 196 1.1 elric 197 1.1 elric print "\tConnection closed requests: ", $connection_closed,"\n"; 198 1.1 elric if ($connection_closed > 0) { 199 1.1 elric print "\tTop ten connection closed request clients\n"; 200 1.1 elric topten(\%connection_closed_addr); 201 1.1 elric } 202 1.1 elric print "\n"; 203 1.1 elric 204 1.1 elric print "\tMalformed HTTP requests: ", $http_malformed,"\n"; 205 1.1 elric if ($http_malformed > 0) { 206 1.1 elric print "\tTop ten malformed HTTP request clients\n"; 207 1.1 elric topten(\%http_malformed_addr); 208 1.1 elric } 209 1.1 elric print "\n"; 210 1.1 elric 211 1.1 elric print "\tHTTP non kdc requests: ", $http_non_kdc,"\n"; 212 1.1 elric if ($http_non_kdc > 0) { 213 1.1 elric print "\tTop ten HTTP non KDC request clients\n"; 214 1.1 elric topten(\%http_non_kdc_addr); 215 1.1 elric } 216 1.1 elric print "\n"; 217 1.1 elric 218 1.1 elric print "Report on AS_REQ requests\n\n"; 219 1.1 elric print "Overall AS_REQ statistics\n\n"; 220 1.1 elric 221 1.1 elric print "\tTotal number: $as_req\n"; 222 1.1 elric 223 1.1 elric print "\nAS_REQ client/server statistics\n\n"; 224 1.1 elric 225 1.1 elric print "\tDistinct IP Addresses performing requests: ", 226 1.1 elric int(keys %as_req_addr),"\n"; 227 1.1 elric print "\tOverall top ten IP addresses\n"; 228 1.1 elric topten(\%as_req_addr); 229 1.1 elric 230 1.1 elric print "\tDistinct non-local ($notlocal) IP Addresses performing requests: ", 231 1.1 elric int(keys %as_req_addr_nonlocal), "\n"; 232 1.1 elric print "\tTop ten non-local ($notlocal) IP address:\n"; 233 1.1 elric topten(\%as_req_addr_nonlocal); 234 1.1 elric 235 1.1 elric print "\n\tPreauth failed for for: ", $pa_failed, " requests\n"; 236 1.1 elric if ($pa_failed) { 237 1.1 elric print "\tPreauth failed top ten IP addresses:\n"; 238 1.1 elric topten(\%pa_failed_addr); 239 1.1 elric print "\tPreauth failed top ten principals:\n"; 240 1.1 elric topten(\%pa_failed_princ); 241 1.1 elric } 242 1.1 elric 243 1.1 elric print "\n\tDistinct clients performing requests: ", 244 1.1 elric int(keys %as_req_client), "\n"; 245 1.1 elric print "\tTop ten clients:\n"; 246 1.1 elric topten(\%as_req_client); 247 1.1 elric 248 1.1 elric print "\tDistinct services requested: ", int(keys %as_req_server), "\n"; 249 1.1 elric print "\tTop ten requested services:\n"; 250 1.1 elric topten(\%as_req_server); 251 1.1 elric 252 1.1 elric print "\n\n\nReport on TGS_REQ requests:\n\n"; 253 1.1 elric print "Overall TGS_REQ statistics\n\n"; 254 1.1 elric print "\tTotal number: $tgs_req\n"; 255 1.1 elric 256 1.1 elric print "\nTGS_REQ client/server statistics\n\n"; 257 1.1 elric print "\tDistinct IP addresses performing requests: ", 258 1.1 elric int(keys %tgs_req_addr), "\n"; 259 1.1 elric print "\tOverall top ten IP addresses\n"; 260 1.1 elric topten(\%tgs_req_addr); 261 1.1 elric 262 1.1 elric print "\tDistinct non-local ($notlocal) IP Addresses performing requests: ", 263 1.1 elric int(keys %tgs_req_addr_nonlocal), "\n"; 264 1.1 elric print "\tTop ten non-local ($notlocal) IP address:\n"; 265 1.1 elric topten(\%tgs_req_addr_nonlocal); 266 1.1 elric 267 1.1 elric print "\tDistinct clients performing requests: ", 268 1.1 elric int(keys %tgs_req_client), "\n"; 269 1.1 elric print "\tTop ten clients:\n"; 270 1.1 elric topten(\%tgs_req_client); 271 1.1 elric 272 1.1 elric print "\tDistinct services requested: ", int(keys %tgs_req_server), "\n"; 273 1.1 elric print "\tTop ten requested services:\n"; 274 1.1 elric topten(\%tgs_req_server); 275 1.1 elric 276 1.1 elric print "\n\n\nReport on 524_REQ requests:\n\n"; 277 1.1 elric 278 1.1 elric print "\t524_REQ client/server statistics\n\n"; 279 1.1 elric 280 1.1 elric print "\tDistinct IP Addresses performing requests: ", 281 1.1 elric int(keys %five24_req_addr),"\n"; 282 1.1 elric print "\tOverall top ten IP addresses\n"; 283 1.1 elric topten(\%five24_req_addr); 284 1.1 elric 285 1.1 elric print "\tDistinct non-local ($notlocal) IP Addresses performing requests: ", 286 1.1 elric int(keys %five24_req_addr_nonlocal), "\n"; 287 1.1 elric print "\tTop ten non-local ($notlocal) IP address:\n"; 288 1.1 elric topten(\%five24_req_addr_nonlocal); 289 1.1 elric 290 1.1 elric print "\tDistinct clients performing requests: ", int(keys %five24_req_client), "\n"; 291 1.1 elric print "\tTop ten clients:\n"; 292 1.1 elric topten(\%five24_req_client); 293 1.1 elric 294 1.1 elric print "\tDistinct services requested: ", int(keys %five24_req_server), "\n"; 295 1.1 elric print "\tTop ten requested services:\n"; 296 1.1 elric topten(\%five24_req_server); 297 1.1 elric print "\n"; 298 1.1 elric 299 1.1 elric print "Cross realm statistics\n\n"; 300 1.1 elric 301 1.1 elric print "\tNumber of cross-realm tgs out: $tgs_xrealm_out\n"; 302 1.1 elric if ($tgs_xrealm_out > 0) { 303 1.1 elric print "\tTop ten realms used for out cross-realm:\n"; 304 1.1 elric topten(\%tgs_xrealm_out_realm); 305 1.1 elric print "\tTop ten principals use out cross-realm:\n"; 306 1.1 elric topten(\%tgs_xrealm_out_princ); 307 1.1 elric } 308 1.1 elric print "\tNumber of cross-realm tgs in: $tgs_xrealm_in\n"; 309 1.1 elric if ($tgs_xrealm_in > 0) { 310 1.1 elric print "\tTop ten realms used for in cross-realm:\n"; 311 1.1 elric topten(\%tgs_xrealm_in_realm); 312 1.1 elric print "\tTop ten principals use in cross-realm:\n"; 313 1.1 elric topten(\%tgs_xrealm_in_princ); 314 1.1 elric } 315 1.1 elric 316 1.1 elric print "\n\nReport on referral:\n\n"; 317 1.1 elric 318 1.1 elric print "\tNumber of referrals: $referrals\n"; 319 1.1 elric if ($referrals > 0) { 320 1.1 elric print "\tTop ten referral-ed principals:\n"; 321 1.1 elric topten(\%referral_princ); 322 1.1 elric print "\tTop ten to realm referrals:\n"; 323 1.1 elric topten(\%referral_realm); 324 1.1 elric } 325 1.1 elric 326 1.1 elric print "\n\nEnctype Statistics:\n\n"; 327 1.1 elric print "\tTop ten session enctypes:\n"; 328 1.1 elric topten(\%enctype_session); 329 1.1 elric print "\tTop ten ticket enctypes:\n"; 330 1.1 elric topten(\%enctype_ticket); 331 1.1 elric 332 1.1 elric print "\tDistinct IP addresses using DES: ", int(keys %addr_uses_des), "\n"; 333 1.1 elric print "\tTop IP addresses using DES:\n"; 334 1.1 elric topten(\%addr_uses_des); 335 1.1 elric print "\tDistinct principals using DES: ", int(keys %princ_uses_des), "\n"; 336 1.1 elric print "\tTop ten principals using DES:\n"; 337 1.1 elric topten(\%princ_uses_des); 338 1.1 elric 339 1.1 elric print "\n"; 340 1.1 elric 341 1.1 elric printf("Requests to forward non-forwardable ticket: $forward_non_forward\n"); 342 1.1 elric 343 1.1 elric 344 1.1 elric exit 0; 345 1.1 elric 346 1.1 elric my $last_addr = ""; 347 1.1 elric my $last_principal = ""; 348 1.1 elric 349 1.1 elric sub process_line { 350 1.1 elric local($_) = @_; 351 1.1 elric # 352 1.1 elric # Eat these lines that are output as a result of startup (but 353 1.1 elric # log the number of restarts) 354 1.1 elric # 355 1.1 elric if (/AS-REQ \(krb4\) (.*) from IPv([46]):([0-9\.:a-fA-F]+) for krbtgt.*$/){ 356 1.1 elric $v4_req++; 357 1.1 elric $v4_req_addr{$3}++; 358 1.1 elric $v4_req_addr_nonlocal{$3}++ if (!islocaladdr($3)); 359 1.1 elric $last_addr = $3; 360 1.1 elric $last_principal = $1; 361 1.1 elric $ip{$2}++; 362 1.1 elric } elsif (/AS-REQ (.*) from IPv([46]):([0-9\.:a-fA-F]+) for (.*)$/) { 363 1.1 elric $as_req++; 364 1.1 elric $as_req_client{$1}++; 365 1.1 elric $as_req_server{$4}++; 366 1.1 elric $as_req_addr{$3}++; 367 1.1 elric $as_req_addr_nonlocal{$3}++ if (!islocaladdr($3)); 368 1.1 elric $last_addr = $3; 369 1.1 elric $last_principal = $1; 370 1.1 elric $ip{$2}++; 371 1.1 elric } elsif (/TGS-REQ \(krb4\)/) { 372 1.1 elric #Nothing 373 1.1 elric } elsif (/TGS-REQ (.+) from IPv([46]):([0-9\.:a-fA-F]+) for (.*?)( \[.*\]){0,1}$/) { 374 1.1 elric $tgs_req++; 375 1.1 elric $tgs_req_client{$1}++; 376 1.1 elric $tgs_req_server{$4}++; 377 1.1 elric $tgs_req_addr{$3}++; 378 1.1 elric $tgs_req_addr_nonlocal{$3}++ if (!islocaladdr($3)); 379 1.1 elric $last_addr = $3; 380 1.1 elric $last_principal = $1; 381 1.1 elric $ip{$2}++; 382 1.1 elric 383 1.1 elric my $source = $1; 384 1.1 elric my $dest = $4; 385 1.1 elric 386 1.1 elric if (!islocalrealm($source)) { 387 1.1 elric $tgs_xrealm_in++; 388 1.1 elric $tgs_xrealm_in_princ{$source}++; 389 1.1 elric if ($source =~ /[^@]+@([^@]+)/ ) { 390 1.1 elric $tgs_xrealm_in_realm{$1}++; 391 1.1 elric } 392 1.1 elric } 393 1.1 elric if ($dest =~ /krbtgt\/([^@]+)@[^@]+/) { 394 1.1 elric if (!islocalrealm($1)) { 395 1.1 elric $tgs_xrealm_out++; 396 1.1 elric $tgs_xrealm_out_realm{$1}++; 397 1.1 elric $tgs_xrealm_out_princ{$source}++; 398 1.1 elric } 399 1.1 elric } 400 1.1 elric } elsif (/524-REQ (.*) from IPv([46]):([0-9\.:a-fA-F]+) for (.*)$/) { 401 1.1 elric $five24_req++; 402 1.1 elric $five24_req_client{$1}++; 403 1.1 elric $five24_req_server{$4}++; 404 1.1 elric $five24_req_addr{$3}++; 405 1.1 elric $five24_req_addr_nonlocal{$3}++ if (!islocaladdr($3)); 406 1.1 elric $last_addr = $3; 407 1.1 elric $last_principal = $1; 408 1.1 elric $ip{$2}++; 409 1.1 elric } elsif (/TCP data of strange type from IPv[46]:([0-9\.:a-fA-F]+)/) { 410 1.1 elric $strange_tcp_data{$1}++; 411 1.1 elric } elsif (/Lookup (.*) failed: No such entry in the database/) { 412 1.1 elric $no_such_princ++; 413 1.1 elric $no_such_princ_addr{$last_addr}++; 414 1.1 elric $no_such_princ_addr_nonlocal{$last_addr}++ if (!islocaladdr($last_addr)); 415 1.1 elric $no_such_princ_princ{$1}++; 416 1.1 elric } elsif (/Lookup .* succeeded$/) { 417 1.1 elric # Nothing 418 1.1 elric } elsif (/Malformed HTTP request from IPv[46]:([0-9\.:a-fA-F]+)$/) { 419 1.1 elric $http_malformed++; 420 1.1 elric $http_malformed_addr{$1}++; 421 1.1 elric } elsif (/TCP-connection from IPv[46]:([0-9\.:a-fA-F]+) expired after [0-9]+ bytes/) { 422 1.1 elric $tcp_conn_timeout++; 423 1.1 elric $tcp_conn_timeout_addr{$1}++; 424 1.1 elric } elsif (/Failed processing [0-9]+ byte request from IPv[46]:([0-9\.:a-fA-F]+)/) { 425 1.1 elric $failed_processing++; 426 1.1 elric $failed_processing_addr{$1}++; 427 1.1 elric } elsif (/connection closed before end of data after [0-9]+ bytes from IPv[46]:([0-9\.:a-fA-F]+)/) { 428 1.1 elric $connection_closed++; 429 1.1 elric $connection_closed_addr{$1}++; 430 1.1 elric } elsif (/HTTP request from IPv[46]:([0-9\.:a-fA-F]+) is non KDC request/) { 431 1.1 elric $http_non_kdc++; 432 1.1 elric $http_non_kdc_addr{$1}++; 433 1.1 elric } elsif (/returning a referral to realm (.*) for server (.*) that was not found/) { 434 1.1 elric $referrals++; 435 1.1 elric $referral_princ{$2}++; 436 1.1 elric $referral_realm{$1}++; 437 1.1 elric } elsif (/krb4 Cross-realm (.*) -> (.*) disabled/) { 438 1.1 elric $v4_cross++; 439 1.1 elric $v4_cross_realm{$1."->".$2}++; 440 1.1 elric } elsif (/524 cross-realm (.*) -> (.*) disabled/) { 441 1.1 elric $v4_cross++; 442 1.1 elric $v4_cross_realm{$1."->".$2}++; 443 1.1 elric } elsif (/cross-realm (.*) -> (.*): no transit through realm (.*)/) { 444 1.1 elric } elsif (/cross-realm (.*) -> (.*) via \[([^\]]+)\]/) { 445 1.1 elric $v5_cross++; 446 1.1 elric $v5_cross_realm{$1."->".$2}++; 447 1.1 elric } elsif (/cross-realm (.*) -> (.*)/) { 448 1.1 elric $v5_cross++; 449 1.1 elric $v5_cross_realm{$1."->".$2}++; 450 1.1 elric } elsif (/sending ([0-9]+) bytes to IPv[46]:([0-9\.:a-fA-F]+)/) { 451 1.1 elric $bw_addr{$2} += $1; 452 1.1 elric } elsif (/Using ([-a-z0-9]+)\/([-a-z0-9]+)/) { 453 1.1 elric $enctype_ticket{$1}++; 454 1.1 elric $enctype_session{$2}++; 455 1.1 elric 456 1.1 elric my $ticket = $1; 457 1.1 elric my $session = $2; 458 1.1 elric 459 1.1 elric if ($ticket =~ /des-cbc-(crc|md4|md5)/) { 460 1.1 elric $addr_uses_des{$last_addr}++; 461 1.1 elric $princ_uses_des{$last_principal}++; 462 1.1 elric } 463 1.1 elric 464 1.1 elric } elsif (/Failed to decrypt PA-DATA -- (.+)$/) { 465 1.1 elric $pa_failed++; 466 1.1 elric $pa_failed_princ{$last_principal}++; 467 1.1 elric $pa_failed_addr{$last_addr}++; 468 1.1 elric 469 1.1 elric } elsif (/Request to forward non-forwardable ticket/) { 470 1.1 elric $forward_non_forward++; 471 1.1 elric } elsif (/HTTP request:/) { 472 1.1 elric } elsif (/krb_rd_req: Incorrect network address/) { 473 1.1 elric } elsif (/krb_rd_req: Ticket expired \(krb_rd_req\)/) { 474 1.1 elric } elsif (/Ticket expired \(.*\)/) { 475 1.1 elric } elsif (/krb_rd_req: Can't decode authenticator \(krb_rd_req\)/) { 476 1.1 elric } elsif (/Request from wrong address/) { 477 1.1 elric # XXX 478 1.1 elric } elsif (/UNKNOWN --/) { 479 1.1 elric # XXX 480 1.1 elric } elsif (/Too large time skew -- (.*)$/) { 481 1.1 elric # XXX 482 1.1 elric } elsif (/No PA-ENC-TIMESTAMP --/) { 483 1.1 elric # XXX 484 1.1 elric } elsif (/Looking for pa-data --/) { 485 1.1 elric # XXX 486 1.1 elric } elsif (/Pre-authentication succeded -- (.+)$/) { 487 1.1 elric # XXX 488 1.1 elric } elsif (/Bad request for ([,a-zA-Z0-9]+) ticket/) { 489 1.1 elric # XXX 490 1.1 elric } elsif (/Failed to verify AP-REQ: Ticket expired/) { 491 1.1 elric # XXX 492 1.1 elric } elsif (/Client not found in database:/) { 493 1.1 elric # XXX 494 1.1 elric } elsif (/Server not found in database \(krb4\)/) { 495 1.1 elric } elsif (/Server not found in database:/) { 496 1.1 elric # XXX 497 1.1 elric } elsif (/newsyslog.*logfile turned over/) { 498 1.1 elric # Nothing 499 1.1 elric } elsif (/Requested flags:/) { 500 1.1 elric # Nothing 501 1.1 elric } elsif (/shutting down/) { 502 1.1 elric # Nothing 503 1.1 elric } elsif (/listening on IP/) { 504 1.1 elric # Nothing 505 1.1 elric } elsif (/commencing operation/) { 506 1.1 elric $restarts++; 507 1.1 elric } 508 1.1 elric # 509 1.1 elric # Log it if we didn't parse the line 510 1.1 elric # 511 1.1 elric else { 512 1.1 elric print "Unknown log file line: $_"; 513 1.1 elric } 514 1.1 elric } 515 1.1 elric 516 1.1 elric sub topten { 517 1.1 elric my ($list) = @_; 518 1.1 elric my @keys; 519 1.1 elric 520 1.1 elric my $key; 521 1.1 elric 522 1.1 elric @keys = (sort {$$list{$b} <=> $$list{$a}} (keys %{$list})); 523 1.1 elric splice @keys, 10; 524 1.1 elric 525 1.1 elric foreach $key (@keys) { 526 1.1 elric print "\t\t$key - $$list{$key}\n"; 527 1.1 elric } 528 1.1 elric } 529 1.1 elric 530 1.1 elric sub islocaladdr (\$) { 531 1.1 elric my ($addr) = @_; 532 1.1 elric my $net; 533 1.1 elric 534 1.1 elric foreach $net (@local_networks_re) { 535 1.1 elric return 1 if ($addr =~ /$net/); 536 1.1 elric } 537 1.1 elric return 0; 538 1.1 elric } 539 1.1 elric 540 1.1 elric sub islocalrealm (\$) { 541 1.1 elric my ($princ) = @_; 542 1.1 elric my $realm; 543 1.1 elric 544 1.1 elric foreach $realm (@local_realms) { 545 1.1 elric return 1 if ($princ eq $realm); 546 1.1 elric return 1 if ($princ =~ /[^@]+\@${realm}/); 547 1.1 elric } 548 1.1 elric return 0; 549 1.1 elric } 550