You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求Linux Bash脚本:遍历Apache虚拟主机日志,检测SQL注入并告警邮件

Got it, let's build a reliable Bash script that scans your Apache virtual host access logs for SQL injection (SQLi) signatures and sends email alerts whenever suspicious activity is detected. Here's a complete, customizable solution:

1. Prerequisites

First, make sure your server has the tools to send emails and you know where your Apache logs live:

  • Email Utilities: Install mailutils (Debian/Ubuntu) or sendmail (RHEL/CentOS) to enable email alerts:
    # Debian/Ubuntu
    sudo apt update && sudo apt install mailutils
    
    # RHEL/CentOS
    sudo yum install sendmail
    
  • Apache Log Path: Common locations are /var/log/apache2/ (Debian/Ubuntu), /var/log/httpd/ (RHEL/CentOS), or custom paths defined in your virtual host configs (e.g., /home/*/logs/*access_log for cPanel).
2. The Bash Script

Save this as sqli_log_scanner.sh—it’s commented to make customization easy:

#!/bin/bash

# -------------------------- CONFIGURATION --------------------------
LOG_DIR="/var/log/apache2"  # Update this to your Apache log directory
# SQLi signature patterns (adjust to catch more/less payloads)
SQLI_KEYWORDS="UNION|SELECT|INSERT|DELETE|DROP|--|'|\"|OR\s+1=1|AND\s+1=1|EXEC|DECLARE"
ALERT_EMAIL="your-security-alert@example.com"  # Email to send alerts to
SERVER_NAME=$(hostname)  # Auto-fetches your server's hostname
# -------------------------------------------------------------------

# Initialize alert content variable
ALERT_CONTENT=""

# Loop through all access log files in the target directory
for log_file in "$LOG_DIR"/*access.log; do
    # Skip if no matching log files exist
    [ -e "$log_file" ] || continue

    # Scan the log for case-insensitive matches to SQLi keywords
    matches=$(grep -i -E "$SQLI_KEYWORDS" "$log_file")

    # If matches are found, add them to the alert content
    if [ -n "$matches" ]; then
        ALERT_CONTENT+="=== SQLi Matches Found in $log_file ===\n"
        ALERT_CONTENT+="$matches\n\n"
    fi
done

# Send the alert email if suspicious activity was detected
if [ -n "$ALERT_CONTENT" ]; then
    echo -e "SQL Injection Activity Detected on $SERVER_NAME\n\n$ALERT_CONTENT" | \
    mail -s "URGENT: SQLi Attempts Detected on $SERVER_NAME" "$ALERT_EMAIL"
fi
3. Setup & Usage
  1. Make the script executable:
    chmod +x sqli_log_scanner.sh
    
  2. Test it manually first to ensure it works:
    ./sqli_log_scanner.sh
    
  3. Automate with cron to run it periodically (e.g., every hour):
    • Open your crontab editor: crontab -e
    • Add this line (replace /path/to/ with the actual script location):
      0 * * * * /path/to/sqli_log_scanner.sh
      
4. Customization Tips
  • Expand SQLi Signatures: Add more patterns to SQLI_KEYWORDS (e.g., CAST|CONVERT|UNION ALL|SELECT\s+FROM) to catch more sophisticated payloads.
  • Scan Rotated Logs: If your logs are compressed (e.g., *.log.gz), modify the loop to include them and use zgrep instead of grep for compressed files.
  • Reduce False Positives: Refine patterns to avoid legitimate traffic—for example, if your app uses SELECT in valid URLs, adjust the pattern to SELECT\s+FROM\s+ to target malicious queries.
  • Enhance Alerts: Add timestamps, extract source IPs from logs, or include server resource stats in the email body for more context.

内容的提问来源于stack exchange,提问作者MikeBau

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:17:59