diff options
| author | Adam <Adam@anope.org> | 2014-10-12 15:03:51 -0400 |
|---|---|---|
| committer | Adam <Adam@anope.org> | 2014-10-12 15:03:51 -0400 |
| commit | 67719e8db1c4c5afecee3b7646adc407c9677774 (patch) | |
| tree | c7cda791d9afe36cce790af2cd0e4bd6645daea0 | |
| parent | 48be41cf7b9e8e3390114236be0c099149060791 (diff) | |
Add exempts and optionally allow authenticated users past m_dnsbl
| -rw-r--r-- | data/modules.example.conf | 50 | ||||
| -rw-r--r-- | docs/Changes.conf | 1 | ||||
| -rw-r--r-- | modules/m_dnsbl.cpp | 78 |
3 files changed, 96 insertions, 33 deletions
diff --git a/data/modules.example.conf b/data/modules.example.conf index a51ef7226..be4725816 100644 --- a/data/modules.example.conf +++ b/data/modules.example.conf @@ -124,26 +124,58 @@ module { name = "help" } * %g is the realname of the user * %h is the hostname of the user * %i is the IP of the user - * %r is the reason (configured below). Will be nothing if not configured. + * %r is the reply reason (configured below). Will be nothing if not configured. * %N is the network name set in networkinfo:networkname */ reason = "You are listed in the efnet RBL, visit http://rbl.efnetrbl.org/?i=%i for info" - /* Replies to ban and their reason. If this is totally omitted all replies get banned. */ - 1 = "Open Proxy" - /* Don't ban for result 2 or 3 */ - #2 = "spamtrap666" - #3 = "spamtrap50" - 4 = "TOR" - 5 = "Drones / Flooding" + /* Replies to ban and their reason. If no relies are configured, all replies get banned. */ + reply + { + code = 1 + reason = "Open Proxy" + } + + #reply + { + code = 2 + reason = "spamtrap666" + } + + #reply + { + code = 3 + reason = "spamtrap50" + } + + reply + { + code = 4 + reason = "TOR" + + /* + * If set, users identified to services at the time the result comes back + * will not be banned. + */ + #allow_account = yes + } + + reply + { + code = 5 + reason = "Drones / Flooding" + } } - blacklist + #blacklist { name = "dnsbl.dronebl.org" time = 4h reason = "You have a host listed in the DroneBL. For more information, visit http://dronebl.org/lookup_branded?ip=%i&network=%N" } + + /* Exempt localhost from DNSBL checks */ + exempt { ip = "127.0.0.1" } } /* diff --git a/docs/Changes.conf b/docs/Changes.conf index 1b66f56a9..c4a5d8ff7 100644 --- a/docs/Changes.conf +++ b/docs/Changes.conf @@ -2,6 +2,7 @@ Anope Version 2.0.2 ------------------- Add an operserv/oper/modify privilege, required to use oper add and oper del Add a chanserv/access/list privilege, which allow readonly access to ChanServ access and akick lists +Changed m_dnsbl's result configuration to be more extensible Anope Version 2.0.1 ------------------- diff --git a/modules/m_dnsbl.cpp b/modules/m_dnsbl.cpp index 1c10b09d5..4adffd1f3 100644 --- a/modules/m_dnsbl.cpp +++ b/modules/m_dnsbl.cpp @@ -15,12 +15,29 @@ static ServiceReference<Manager> dnsmanager("DNS::Manager", "dns/manager"); struct Blacklist { + struct Reply + { + int code; + Anope::string reason; + bool allow_account; + + Reply() : code(0), allow_account(false) { } + }; + Anope::string name; time_t bantime; Anope::string reason; - std::map<int, Anope::string> replies; + std::vector<Reply> replies; - Blacklist(const Anope::string &n, time_t b, const Anope::string &r, const std::map<int, Anope::string> &re) : name(n), bantime(b), reason(r), replies(re) { } + Blacklist() : bantime(0) { } + + Reply *Find(int code) + { + for (unsigned int i = 0; i < replies.size(); ++i) + if (replies[i].code == code) + return &replies[i]; + return NULL; + } }; class DNSBLResolver : public Request @@ -42,17 +59,16 @@ class DNSBLResolver : public Request if (ans_record.rdata.find("127.0.0.") != 0) return; - Anope::string record_reason; - if (!this->blacklist.replies.empty()) - { - sockaddrs sresult; - sresult.pton(AF_INET, ans_record.rdata); - int result = sresult.sa4.sin_addr.s_addr >> 24; + sockaddrs sresult; + sresult.pton(AF_INET, ans_record.rdata); + int result = sresult.sa4.sin_addr.s_addr >> 24; - if (!this->blacklist.replies.count(result)) - return; - record_reason = this->blacklist.replies[result]; - } + Blacklist::Reply *reply = blacklist.Find(result); + if (!blacklist.replies.empty() && !reply) + return; + + if (reply && reply->allow_account && user->Account()) + return; Anope::string reason = this->blacklist.reason, addr = user->ip.addr(); reason = reason.replace_all_cs("%n", user->nick); @@ -60,7 +76,7 @@ class DNSBLResolver : public Request reason = reason.replace_all_cs("%g", user->realname); reason = reason.replace_all_cs("%h", user->host); reason = reason.replace_all_cs("%i", addr); - reason = reason.replace_all_cs("%r", record_reason); + reason = reason.replace_all_cs("%r", reply ? reply->reason : ""); reason = reason.replace_all_cs("%N", Config->GetBlock("networkinfo")->Get<const Anope::string>("networkname")); BotInfo *OperServ = Config->GetClient("OperServ"); @@ -82,6 +98,7 @@ class DNSBLResolver : public Request class ModuleDNSBL : public Module { std::vector<Blacklist> blacklists; + std::set<Anope::string> exempts; bool check_on_connect; bool check_on_netburst; bool add_to_akill; @@ -100,25 +117,35 @@ class ModuleDNSBL : public Module this->add_to_akill = block->Get<bool>("add_to_akill", "yes"); this->blacklists.clear(); - for (int i = 0, num = block->CountBlock("blacklist"); i < num; ++i) + for (int i = 0; i < block->CountBlock("blacklist"); ++i) { Configuration::Block *bl = block->GetBlock("blacklist", i); + Blacklist blacklist; - Anope::string bname = bl->Get<const Anope::string>("name"); - if (bname.empty()) + blacklist.name = bl->Get<Anope::string>("name"); + if (blacklist.name.empty()) continue; - time_t bantime = bl->Get<time_t>("time", "4h"); - Anope::string reason = bl->Get<const Anope::string>("reason"); - std::map<int, Anope::string> replies; - for (int j = 0; j < 256; ++j) + blacklist.bantime = bl->Get<time_t>("time", "4h"); + blacklist.reason = bl->Get<Anope::string>("reason"); + + for (int j = 0; j < bl->CountBlock("reply"); ++j) { - Anope::string k = bl->Get<const Anope::string>(stringify(j)); - if (!k.empty()) - replies[j] = k; + Configuration::Block *reply = bl->GetBlock("reply", j); + Blacklist::Reply r; + + r.code = reply->Get<int>("code"); + r.reason = reply->Get<Anope::string>("reason"); + r.allow_account = reply->Get<bool>("allow_account"); + + blacklist.replies.push_back(r); } - this->blacklists.push_back(Blacklist(bname, bantime, reason, replies)); + this->blacklists.push_back(blacklist); } + + this->exempts.clear(); + for (int i = 0; i < block->CountBlock("exempt"); ++i) + this->exempts.insert(block->Get<Anope::string>("ip")); } void OnUserConnect(User *user, bool &exempt) anope_override @@ -134,6 +161,9 @@ class ModuleDNSBL : public Module /* User doesn't have a valid IPv4 IP (ipv6/spoof/etc) */ return; + if (this->exempts.count(user->ip.addr())) + return; + const unsigned long &ip = user->ip.sa4.sin_addr.s_addr; unsigned long reverse_ip = (ip << 24) | ((ip & 0xFF00) << 8) | ((ip & 0xFF0000) >> 8) | (ip >> 24); |
