1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
|
/*
* InspIRCd -- Internet Relay Chat Daemon
*
* Copyright (C) 2019 Matt Schatz <genius3000@g3k.solutions>
* Copyright (C) 2014 Googolplexed <googol@googolplexed.net>
* Copyright (C) 2013, 2017-2020 Sadie Powell <sadie@witchery.services>
* Copyright (C) 2012-2014 Attila Molnar <attilamolnar@hush.com>
* Copyright (C) 2012, 2019 Robby <robby@chatbelgie.be>
* Copyright (C) 2009-2010 Daniel De Graaf <danieldg@inspircd.org>
* Copyright (C) 2008, 2010 Craig Edwards <brain@inspircd.org>
* Copyright (C) 2008 Robin Burchell <robin+git@viroteck.net>
*
* This file is part of InspIRCd. InspIRCd is free software: you can
* redistribute it and/or modify it under the terms of the GNU General Public
* License as published by the Free Software Foundation, version 2.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
* FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
* details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
#include "inspircd.h"
#include "xline.h"
#include "modules/webirc.h"
class ModuleConnectBan
: public Module
, public WebIRC::EventListener
{
typedef std::map<irc::sockets::cidr_mask, unsigned int> ConnectMap;
ConnectMap connects;
unsigned int threshold;
unsigned int banduration;
unsigned int ipv4_cidr;
unsigned int ipv6_cidr;
std::string banmessage;
unsigned char GetRange(LocalUser* user)
{
int family = user->client_sa.family();
switch (family)
{
case AF_INET:
return ipv4_cidr;
case AF_INET6:
return ipv6_cidr;
case AF_UNIX:
// Ranges for UNIX sockets are ignored entirely.
return 0;
}
// If we have reached this point then we have encountered a bug.
ServerInstance->Logs->Log(MODNAME, LOG_DEBUG, "BUG: ModuleConnectBan::GetRange(): socket type %d is unknown!", family);
return 0;
}
static bool IsExempt(LocalUser* user)
{
// E-lined and already banned users shouldn't be hit.
if (user->exempt || user->quitting)
return true;
// Users in an exempt class shouldn't be hit.
return user->GetClass() && !user->GetClass()->config->getBool("useconnectban", true);
}
public:
ModuleConnectBan()
: WebIRC::EventListener(this)
{
}
void Prioritize() CXX11_OVERRIDE
{
Module* corexline = ServerInstance->Modules->Find("core_xline");
ServerInstance->Modules->SetPriority(this, I_OnSetUserIP, PRIORITY_AFTER, corexline);
}
Version GetVersion() CXX11_OVERRIDE
{
return Version("Z-lines IP addresses which make excessive connections to the server.", VF_VENDOR);
}
void ReadConfig(ConfigStatus& status) CXX11_OVERRIDE
{
ConfigTag* tag = ServerInstance->Config->ConfValue("connectban");
ipv4_cidr = tag->getUInt("ipv4cidr", 32, 1, 32);
ipv6_cidr = tag->getUInt("ipv6cidr", 128, 1, 128);
threshold = tag->getUInt("threshold", 10, 1);
banduration = tag->getDuration("duration", 10*60, 1);
banmessage = tag->getString("banmessage", "Your IP range has been attempting to connect too many times in too short a duration. Wait a while, and you will be able to connect.");
}
void OnWebIRCAuth(LocalUser* user, const WebIRC::FlagMap* flags) CXX11_OVERRIDE
{
if (IsExempt(user))
return;
// HACK: Lower the connection attempts for the gateway IP address. The user
// will be rechecked for connect spamming shortly after when their IP address
// is changed and OnSetUserIP is called.
irc::sockets::cidr_mask mask(user->client_sa, GetRange(user));
ConnectMap::iterator iter = connects.find(mask);
if (iter != connects.end() && iter->second)
iter->second--;
}
void OnSetUserIP(LocalUser* u) CXX11_OVERRIDE
{
if (IsExempt(u))
return;
irc::sockets::cidr_mask mask(u->client_sa, GetRange(u));
ConnectMap::iterator i = connects.find(mask);
if (i != connects.end())
{
i->second++;
if (i->second >= threshold)
{
// Create Z-line for set duration.
ZLine* zl = new ZLine(ServerInstance->Time(), banduration, ServerInstance->Config->ServerName, banmessage, mask.str());
if (!ServerInstance->XLines->AddLine(zl, NULL))
{
delete zl;
return;
}
ServerInstance->XLines->ApplyLines();
std::string maskstr = mask.str();
ServerInstance->SNO->WriteGlobalSno('x', "Z-line added by module m_connectban on %s to expire in %s (on %s): Connect flooding",
maskstr.c_str(), InspIRCd::DurationString(zl->duration).c_str(), InspIRCd::TimeString(zl->expiry).c_str());
ServerInstance->SNO->WriteGlobalSno('a', "Connect flooding from IP range %s (%d)", maskstr.c_str(), threshold);
connects.erase(i);
}
}
else
{
connects[mask] = 1;
}
}
void OnGarbageCollect() CXX11_OVERRIDE
{
ServerInstance->Logs->Log(MODNAME, LOG_DEBUG, "Clearing map.");
connects.clear();
}
};
MODULE_INIT(ModuleConnectBan)
|