#!/bin/bash
if [ "$1" == 'debug'  ]; then set -x;   shift; fi
if [ "$1" == 'debug2' ]; then set -xvT; shift; fi
#------------------------
REALPATH=`realpath $0`
WHERE=`dirname $REALPATH`
ME=`basename $REALPATH`
cd $WHERE
. ../system.conf
. ../common.conf
. ../common.bashlib
#------------------------

OUTFORM='%-50s : %6d %12d IPs\n'
IPSFORM='%12d IPs\n'
TOTFORM='%50s » %6d\n'

SQL_B='sqlite3 ../modules/WatchLG/bandits.db'
SQL_M='sqlite3 ../modules/WatchMX/mailhogs.db'
SQL_W='sqlite3 ../modules/WatchWB/webhogs.db'
SQL_G='sqlite3 ../modules/GeoTrack/geotrack.db'

ALL_CUSTODY=`$IPSET list custody | grep -v "Header:" | grep ' comment'`
ALL_NIXSPAM=`$IPSET list nixspam | grep -v "Header:" | grep ' comment'`
ALL_SPAMHAUS_DROP=` $IPSET list spamhaus | grep -v "Header:" | grep ' comment'  | grep ',drop'`
ALL_SPAMHAUS_EDROP=`$IPSET list spamhaus | grep -v "Header:" | grep ' comment'  | grep ',edrop'`

#
# DROPs in ipset custody
#
DROPS_LOGIN_TOTAL=`echo "$ALL_CUSTODY"	| grep -ic 'login'`
DROPS_LOGIN_HOSTS=`echo "$ALL_CUSTODY"	| grep -i  'login'	| grep -ci truehost`
DROPS_LOGIN_FAKES=`echo "$ALL_CUSTODY"	| grep -i  'login'	| grep -ci fakehost`
DROPS_LOGIN_NXDOM=`echo "$ALL_CUSTODY"	| grep -i  'login'	| grep -ci nxdom`

DROPS_MAIL_TOTAL=`echo "$ALL_CUSTODY"	| grep -ic 'mail,'`
DROPS_MAIL_HOSTS=`echo "$ALL_CUSTODY"	| grep -i  'mail,'	| grep -ci truehost`
DROPS_MAIL_FAKES=`echo "$ALL_CUSTODY"	| grep -i  'mail,'	| grep -ci fakehost`
DROPS_MAIL_NXDOM=`echo "$ALL_CUSTODY"	| grep -i  'mail,' 	| grep -ci nxdom`
DROPS_MAIL_BREAK=`echo "$ALL_CUSTODY"	| grep -i  'mailbox,'	| grep -ci breaker`

DROPS_WEB_BOTS=`  echo "$ALL_CUSTODY"	| grep -ic 'web,'	| grep -ci bot`
DROPS_WEB_OTHER=` echo "$ALL_CUSTODY"	| grep -ic 'web,'	| grep -vci bot`
DROPS_WEB_TOTAL=$(( DROPS_WEB_BOTS + DROPS_WEB_OTHER ))

DROPS_SPAMHAUS_DROP=`echo "$ALL_SPAMHAUS_DROP" |  grep -c ',drop'`
DROPS_SPAMHAUS_EDROP=`echo "$ALL_SPAMHAUS_EDROP" |  grep -c ',edrop'`
DROPS_NIXSPAM=`echo "$ALL_NIXSPAM" | grep -c 'nixspam'`

echo "$ME ======[ `date --iso` `date +%T` ]======"
echo "
------- DROPs currently in ipset 'custody' ------"
printf "$OUTFORM" "DROPs from logins by hosts"		$DROPS_LOGIN_HOSTS
printf "$OUTFORM" "DROPs from logins by fake hosts"	$DROPS_LOGIN_FAKES
printf "$OUTFORM" "DROPs from logins by NX domains"	$DROPS_LOGIN_NXDOM
printf "$TOTFORM" "Total DROPs from logins"		$DROPS_LOGIN_TOTAL
echo
printf "$OUTFORM" "DROPs from mail by hosts"		$DROPS_MAIL_HOSTS
printf "$OUTFORM" "DROPs from mail by fake hosts"	$DROPS_MAIL_FAKES
printf "$OUTFORM" "DROPs from mail by NX domains"	$DROPS_MAIL_NXDOM
printf "$OUTFORM" "DROPs from mail by mailbox breakers"	$DROPS_MAIL_BREAK
printf "$TOTFORM" "Total DROPs from mail"		$DROPS_MAIL_TOTAL
echo
printf "$OUTFORM" "DROPs from WEB, Bots"		$DROPS_WEB_BOTS
printf "$OUTFORM" "DROPs from WEB, other"		$DROPS_WEB_OTHER
printf "$TOTFORM" "Total DROPs from WEB"		$DROPS_WEB_TOTAL

#
# Data base report from modules
#
# Login bandits ...
LOGIN_DB_TOTAL_DROPS=`$SQL_B "select count(*) from bandits where state='DROP';"`
LOGIN_DB_HOSTS_DROPS=`$SQL_B "select count(*) from bandits where state='DROP' and class='TRUEHOST';"`
LOGIN_DB_FAKES_DROPS=`$SQL_B "select count(*) from bandits where state='DROP' and class='FAKEHOST';"`
LOGIN_DB_NXDOM_DROPS=`$SQL_B "select count(*) from bandits where state='DROP' and class='NXDOMAIN';"`
LOGIN_DB_TOTAL=`$SQL_B "select count(*) from bandits;"`

# Mail bandits ...
MAIL_DB_HOSTS_DROPS=`$SQL_M "select count(*) from mailhogs where state='DROP' and class='TRUEHOST';"`
MAIL_DB_FAKES_DROPS=`$SQL_M "select count(*) from mailhogs where state='DROP' and class='FAKEHOST';"`
MAIL_DB_NXDOM_DROPS=`$SQL_M "select count(*) from mailhogs where state='DROP' and class='NXDOMAIN';"`
MAIL_DB_TOTAL_DROPS=`$SQL_M "select count(*) from mailhogs where state='DROP';"`
MAIL_DB_BREAK_DROPS=`$SQL_M "select count(*) from mailhogs where mb_class is not null"`
MAIL_DB_TOTAL=`$SQL_M "select count(*) from mailhogs;"`

# WEB bandits ...
WEB_DB_TOTAL=`$SQL_W "select count(*) from webhogs;"`
WEB_DB_BREAK=`$SQL_W "select count(*) from webhogs where web_class != 'Bot';"`
WEB_DB_BOTS=` $SQL_W "select count(*) from webhogs where web_class =  'Bot';"`

# GeoTrack
GEOTRACK_DB_TOTAL=`$SQL_G  "select count(*) from geotrack;"`

echo "
---------------[ Module databases ]---------------"
echo "
-------------- Login --------------"
printf "$OUTFORM" "Dropped bandits in login DB, hosts"		$LOGIN_DB_HOSTS_DROPS
printf "$OUTFORM" "Dropped bandits in login DB, fake hosts"	$LOGIN_DB_FAKES_DROPS
printf "$OUTFORM" "Dropped bandits in login DB, NX domains"	$LOGIN_DB_NXDOM_DROPS
echo
printf "$TOTFORM" "Total bandits in login DB"			$LOGIN_DB_TOTAL

echo "
-------------- Mail ---------------"
printf "$OUTFORM" "Dropped mailhogs in mail DB, hosts"		$MAIL_DB_HOSTS_DROPS
printf "$OUTFORM" "Dropped mailhogs in mail DB, fake hosts"	$MAIL_DB_FAKES_DROPS
printf "$OUTFORM" "Dropped mailhogs in mail DB, NX domains"	$MAIL_DB_NXDOM_DROPS
printf "$OUTFORM" "Dropped mailhogs in mail DB, Mbox affairs"	$MAIL_DB_BREAK_DROPS
echo
printf "$TOTFORM" "Total mailhogs in mail DB"			$MAIL_DB_TOTAL

echo "
-------------- WEB ---------------"
printf "$OUTFORM" "webhogs in WEB DB by Bot access"		$WEB_DB_BOTS
printf "$OUTFORM" "webhogs in WEB DB by break-in attempts"	$WEB_DB_BREAK
echo
printf "$TOTFORM" "Total webhogs in WEB DB" 			$WEB_DB_TOTAL

echo "
-------------- GeoTrack ---------------------------"
printf "$TOTFORM" "Total culprits in GEOTRACK DB (CIDRs)" 	$GEOTRACK_DB_TOTAL

#
# IPSETS ...
#
IPSETS=`ipset -n list`

for i in `echo "$IPSETS"`
do
	cnt=`ipset -t list $i	| grep 'Number of entries' | awk '{print $NF}'`
	(( DROPS += cnt ))
	: echo $cnt, $DROPS
done


IN_BLACKLIST=`ipset -t list blacklist	| grep 'Number of entries' | awk '{print $NF}'`
IN_WHITELIST=`ipset -t list whitelist	| grep 'Number of entries' | awk '{print $NF}'`
IN_CUSTODY=`  ipset -t list custody	| grep 'Number of entries' | awk '{print $NF}'`
IN_GEOTRACK=` ipset -t list GeoTrack-DB	| grep 'Number of entries' | awk '{print $NF}'`

#IN_LGDB=`ipset -t list WatchLG-DB	| grep 'Number of entries' | awk '{print $NF}'`
#IN_MXDB=`ipset -t list WatchMX-DB	| grep 'Number of entries' | awk '{print $NF}'`
#IN_WBDB=`ipset -t list WatchWB-DB	| grep 'Number of entries' | awk '{print $NF}'`
#IN_SHD=`ipset -t list spamhaus		| grep 'Number of entries' | awk '{print $NF}'`
#IN_NIX=`ipset -t list nixspam		| grep 'Number of entries' | awk '{print $NF}'`
#DROPS=`echo $IN_BLACKLIST + $IN_CUSTODY + $IN_LGDB + $IN_MXDB + $IN_WBDB | bc`
#DROPS=$(( IN_BLACKLIST + IN_CUSTODY + IN_LGDB + IN_MXDB + IN_WBDB + IN_SHD + IN_NIX ))


declare -A geos
CMD=`grep ZONES $MASTER_PATH/dynload/geo/geo.conf `
eval $CMD

echo "
-------------- Geo blockings ----------------------"
echo "($CMD)"
for gz in $ZONES
do
        this_zone=geo-$gz 
        num=`ipset list $this_zone | grep "entries:" | tr -d ' '| awk '{print substr($0,index($0,":")+1)}' | tr -d ' '`
        geos[$this_zone]=$num
	(( total_geo += num ))
done

for elem in ${!geos[@]}
do
	Nodes=`Totalnodes $elem | awk '{gsub(/[,]/,"",$3); print $3}'`
	printf "$OUTFORM" "DROPs contributed by ipdeny, $elem"  ${geos[$elem]} $Nodes
done
printf "$TOTFORM" "Total geo blockings (CIDRs):" $total_geo

echo "
***************** Grand totals ******************
"
printf "$OUTFORM" "DROPs contributed by SpamHaus drop  (CIDRs)"	$DROPS_SPAMHAUS_DROP
printf "$OUTFORM" "DROPs contributed by SpamHaus edrop (CIDRs)"	$DROPS_SPAMHAUS_EDROP
printf "$OUTFORM" "DROPs contributed by NixSpam "	$DROPS_NIXSPAM


printf "$OUTFORM" "Total DROPs   in firewall"		$DROPS
printf "$OUTFORM" "Total DROPs   in databases"		$((LOGIN_DB_TOTAL+MAIL_DB_TOTAL+WEB_DB_TOTAL+GEOTRACK_DB_TOTAL))

printf "$OUTFORM" "Total DROPs   in ipset 'GeoTrack-DB'"	$IN_GEOTRACK

printf "$OUTFORM" "Total DROPs   in ipset 'blacklist'"	$IN_BLACKLIST
printf "$OUTFORM" "Total ACCEPTs in ipset 'whitelist'"	$IN_WHITELIST
echo "
================[ End of report ]================"
