求Linux Bash脚本:遍历Apache虚拟主机日志,检测SQL注入并告警邮件
Got it, let's build a reliable Bash script that scans your Apache virtual host access logs for SQL injection (SQLi) signatures and sends email alerts whenever suspicious activity is detected. Here's a complete, customizable solution:
1. Prerequisites
First, make sure your server has the tools to send emails and you know where your Apache logs live:
- Email Utilities: Install
mailutils(Debian/Ubuntu) orsendmail(RHEL/CentOS) to enable email alerts:# Debian/Ubuntu sudo apt update && sudo apt install mailutils # RHEL/CentOS sudo yum install sendmail - Apache Log Path: Common locations are
/var/log/apache2/(Debian/Ubuntu),/var/log/httpd/(RHEL/CentOS), or custom paths defined in your virtual host configs (e.g.,/home/*/logs/*access_logfor cPanel).
2. The Bash Script
Save this as sqli_log_scanner.sh—it’s commented to make customization easy:
#!/bin/bash # -------------------------- CONFIGURATION -------------------------- LOG_DIR="/var/log/apache2" # Update this to your Apache log directory # SQLi signature patterns (adjust to catch more/less payloads) SQLI_KEYWORDS="UNION|SELECT|INSERT|DELETE|DROP|--|'|\"|OR\s+1=1|AND\s+1=1|EXEC|DECLARE" ALERT_EMAIL="your-security-alert@example.com" # Email to send alerts to SERVER_NAME=$(hostname) # Auto-fetches your server's hostname # ------------------------------------------------------------------- # Initialize alert content variable ALERT_CONTENT="" # Loop through all access log files in the target directory for log_file in "$LOG_DIR"/*access.log; do # Skip if no matching log files exist [ -e "$log_file" ] || continue # Scan the log for case-insensitive matches to SQLi keywords matches=$(grep -i -E "$SQLI_KEYWORDS" "$log_file") # If matches are found, add them to the alert content if [ -n "$matches" ]; then ALERT_CONTENT+="=== SQLi Matches Found in $log_file ===\n" ALERT_CONTENT+="$matches\n\n" fi done # Send the alert email if suspicious activity was detected if [ -n "$ALERT_CONTENT" ]; then echo -e "SQL Injection Activity Detected on $SERVER_NAME\n\n$ALERT_CONTENT" | \ mail -s "URGENT: SQLi Attempts Detected on $SERVER_NAME" "$ALERT_EMAIL" fi
3. Setup & Usage
- Make the script executable:
chmod +x sqli_log_scanner.sh - Test it manually first to ensure it works:
./sqli_log_scanner.sh - Automate with cron to run it periodically (e.g., every hour):
- Open your crontab editor:
crontab -e - Add this line (replace
/path/to/with the actual script location):0 * * * * /path/to/sqli_log_scanner.sh
- Open your crontab editor:
4. Customization Tips
- Expand SQLi Signatures: Add more patterns to
SQLI_KEYWORDS(e.g.,CAST|CONVERT|UNION ALL|SELECT\s+FROM) to catch more sophisticated payloads. - Scan Rotated Logs: If your logs are compressed (e.g.,
*.log.gz), modify the loop to include them and usezgrepinstead ofgrepfor compressed files. - Reduce False Positives: Refine patterns to avoid legitimate traffic—for example, if your app uses
SELECTin valid URLs, adjust the pattern toSELECT\s+FROM\s+to target malicious queries. - Enhance Alerts: Add timestamps, extract source IPs from logs, or include server resource stats in the email body for more context.
内容的提问来源于stack exchange,提问作者MikeBau
相关产品推荐
相关产品推荐

