From 88edeee596b17a49243003e19f7a41901124a8b2 Mon Sep 17 00:00:00 2001 From: adrien Date: Fri, 28 Apr 2023 04:39:52 +0200 Subject: [PATCH] change yaml format --- README.md | 33 +++++--- configs/192.168.1.0_24.yaml | 14 ++++ configs/Creteil_Archives.yaml.bak | 85 +++++++++++++++++++++ configs/Creteil_Archives0.yaml.bak | 107 ++++++++++++++++++++++++++ configs/Créteil_Archives.yaml.bak | 9 +++ configs/Miollis.yaml.bak | 118 +++++++++++++++++++++++++++++ discover | 17 +++++ init.sh | 19 ----- nmap_cmd.xsl | 35 +++++++++ results.xsl | 17 ++--- scan | 12 +++ scan.sh | 8 -- scan_all.sh => scan_all | 4 +- to_XML.php | 45 +++++++++++ to_yaml.xsl => to_config.xsl | 16 ++-- 15 files changed, 483 insertions(+), 56 deletions(-) create mode 100644 configs/192.168.1.0_24.yaml create mode 100644 configs/Creteil_Archives.yaml.bak create mode 100644 configs/Creteil_Archives0.yaml.bak create mode 100644 configs/Créteil_Archives.yaml.bak create mode 100644 configs/Miollis.yaml.bak create mode 100755 discover delete mode 100755 init.sh create mode 100644 nmap_cmd.xsl create mode 100755 scan delete mode 100755 scan.sh rename scan_all.sh => scan_all (64%) create mode 100644 to_XML.php rename to_yaml.xsl => to_config.xsl (69%) diff --git a/README.md b/README.md index a699f2d..2e19327 100644 --- a/README.md +++ b/README.md @@ -1,19 +1,28 @@ # lanScan -Scan hosts with nmap and display results in webpage. +Scanne des hôtes spécifiées avec un fichier de configuration en YAML +et affiche le résultat dans une page web. -* Create a configuration yaml file in confs/ subdirectory (see example below). -It may be generated by scanning a network with `init.sh`. -* Scan with `./scan_all.sh` (use a cron task!). -* Open index.php to see results. +* Créer un fichier de configuration YAML dans un sous-dossier ./configs/ (voir l'exemple ci-dessous). +Il peut être généré en scannant un réseau (en notation CIDR) avec : `./discover XXX.XXX.XXX.XXX/XX`. +* Scanner avec le script `./scan_all` (utiliser une tâche cron !). +* Voir les résultats dans le navigateur web. -## Example +## Exemple ```yaml -site: - group1: - host1.local: [ssh, http] - host2.local: [ftp, https, 5432] - group2: - host3: [ssh, ftp, 8006] +--- +title: Nom du site + +group: + - name: Nom du premier groupe + host: + - address: host1.local + services: [ssh, http] + - address: 192.168.1.100 + services: [ftp, https, 5432] + - name: Nom du 2ème groupe + host: + - adress: host3.local + services: [ssh, ftp, 8006] ``` diff --git a/configs/192.168.1.0_24.yaml b/configs/192.168.1.0_24.yaml new file mode 100644 index 0000000..d804591 --- /dev/null +++ b/configs/192.168.1.0_24.yaml @@ -0,0 +1,14 @@ +--- +title: Titre + +group: + - name: Réseau 192.168.1.0/24 + host: + - address: 192.168.1.27 + service: [] + - address: 192.168.1.71 + service: [] + - address: biblio.malingrey.fr + service: [smtp, domain, http, imap, https, submission, imaps, ssh, mysql, blackice-icecap, snet-sensor-mgmt] + - address: 192.168.1.254 + service: [ftp, domain, http, https, microsoft-ds, rtsp, wsdapi] diff --git a/configs/Creteil_Archives.yaml.bak b/configs/Creteil_Archives.yaml.bak new file mode 100644 index 0000000..7fe52fd --- /dev/null +++ b/configs/Creteil_Archives.yaml.bak @@ -0,0 +1,85 @@ +--- +site: Créteil Archives + +Cluster VMWare: + esx-drieat-01.drieat-idf.e2.rie.gouv.fr: [https] + esx-drieat-02.drieat-idf.e2.rie.gouv.fr: [https] + esx-drieat-03.drieat-idf.e2.rie.gouv.fr: [https] + esx-drieat-04.drieat-idf.e2.rie.gouv.fr: [https] + vmw-drieat-01.drieat-idf.e2.rie.gouv.fr: [https] + win-drieat-9401.auth.ad.e2.rie.gouv.fr: [smb, rdp] + win-drieat-9402.auth.ad.e2.rie.gouv.fr: [smb, rdp] + win-drieat-9403.auth.ad.e2.rie.gouv.fr: [smb, rdp] + win-drieat-9404.auth.ad.e2.rie.gouv.fr: [smb, rdp] + win-drieat-9405.auth.ad.e2.rie.gouv.fr: [smb, rdp, 8090] + win-drieat-9406.auth.ad.e2.rie.gouv.fr: [smb, rdp] + 10.94.8.67: [smb, rdp] + 10.94.8.68: [smb, rdp] + win-drieat-9409.auth.ad.e2.rie.gouv.fr: [smb, rdp, 8090] + win-drieat-9443.auth.ad.e2.rie.gouv.fr: [rdp, http] + win-drihl-9401.drihl-if.ad.e2.rie.gouv.fr: [smb, rdp] + win-drihl-9402.drihl-if.ad.e2.rie.gouv.fr: [smb, rdp] + win-drihl-9403.drihl-if.ad.e2.rie.gouv.fr: [smb, rdp] + win-drihl-9404.drihl-if.ad.e2.rie.gouv.fr: [smb, rdp] + acdc.e2.rie.gouv.fr: [https] + 10.94.8.78: [5432] + cdc.e2.rie.gouv.fr: [https] + 10.94.8.150: [5432, ssh] + 10.94.8.151: [http, ssh] + 10.94.8.152: [5432, ssh] + csri-assistance.driea-idf.i2: [https, mysql, ssh] + acl.driea-idf.i2: [https, ssh] + 10.94.8.51: [mysql, ssh] + 10.94.12.10: [https, ssh] + 10.94.12.12: [https, ssh] + post-office.driea-idf.i2: [15000, 16000, rdp] + 10.94.8.133: [pgsql, ssh] + set-drieat-9401.auth.ad.e2.rie.gouv.fr: [https, pgsql, ssh] + set-drieat-9402.auth.ad.e2.rie.gouv.fr: [http, ssh] + set-drieat-9403.auth.ad.e2.rie.gouv.fr: [https, smb, ssh] + 10.94.8.47: [https, smb, ssh] + set-drieat-7530.auth.ad.e2.rie.gouv.fr: [https, ssh] + 10.94.8.141: [http, ssh] + 10.94.8.142: [pgsql, ssh] + 10.94.8.143: [http, ssh] + 10.94.8.144: [pgsql, ssh] + web-driea-01.driea-idf.i2: [https, ssh] + WSU-DRIEA-01.driea-if.ad.e2.rie.gouv.fr: [smb, 8090, rdp] + win-driea-1043.driea-if.ad.e2.rie.gouv.fr: [smb, 8090, rdp] + win-driea-1046.driea-if.ad.e2.rie.gouv.fr: [9292, rdp] + win-driea-9442.driea-if.ad.e2.rie.gouv.fr: [smb, 9292, rdp] + win-drieat-9443.auth.ad.e2.rie.gouv.fr: [http, rdp] +Cluster Proxmox: + 10.94.8.214: [8006, ssh] + 10.94.8.215: [8006, ssh] + 10.94.8.216: [8006, ssh] + 10.94.8.213: [8006, ssh] + sbl-driea-10.driea-if.ad.e2.rie.gouv.fr: [smb, ssh] + sbl-drihl-9451.drihl-if.ad.e2.rie.gouv.fr: [smb, ssh] + set-drihl-29.drihl-if.ad.e2.rie.gouv.fr: [smb, ftp, ssh] + 10.94.8.40: [smb, ssh] + csri-assistance.driea-idf.i2: [https, ssh] + sbl-driea-54.driea-if.ad.e2.rie.gouv.fr: [smb, ssh] + sbl-driea-55.driea-if.ad.e2.rie.gouv.fr: [smb, ssh] + sbl-driea-61.driea-if.ad.e2.rie.gouv.fr: [smb, ssh] + sbl-driea-65.driea-if.ad.e2.rie.gouv.fr: [https, pgsql, smb, ssh] + sbl-drihl-12.drihl-if.ad.e2.rie.gouv.fr: [smb, ssh] + sbl-drihl-13.drihl-if.ad.e2.rie.gouv.fr: [smb, ssh] + set-driea-109.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh] + uthl94-imp1.drihl-idf.i2: [smb, rdp] + grr-ut94.driea-idf.i2: [http, ssh] + wiki-csri.driea-idf.i2: [https, ssh] + chiffrement.driea-if.ad.e2.rie.gouv.fr: [smb, ssh] +pve-nfs: + 10.94.8.206: [8006, ssh] + sbl-driea-14.driea-if.ad.e2.rie.gouv.fr: [20618, ssh] + win-drieat-9436.auth.ad.e2.rie.gouv.fr: [rdp] +pve-miollis-modus: + 10.94.8.15: [8006, ssh] + 10.94.8.16: [rdp] +pve-miollis-00: + 10.94.8.37: [8006, ssh] +Physiques: + 10.94.8.20: [domain, rdp] + 10.94.8.14: [27001, rdp] + 10.94.8.98: [smb, https] diff --git a/configs/Creteil_Archives0.yaml.bak b/configs/Creteil_Archives0.yaml.bak new file mode 100644 index 0000000..78b1ccb --- /dev/null +++ b/configs/Creteil_Archives0.yaml.bak @@ -0,0 +1,107 @@ +--- +Créteil Archives: + 10.94.8.0/24: + 10.94.8.4: [] + 10.94.8.5: [] + 10.94.8.99: [] + 10.94.8.1: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.2: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.3: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.11: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.12: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + miroir-av3d.drihl-idf.i2: [ftp, ssh, domain, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.21: [ssh, domain, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WSU-DRIEA-01.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, https, microsoft-ds, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.26: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.27: [ssh, dns, http, https, microsoft-ds, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-65.driea-idf.i2: [ssh, dns, http, http, smb, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-121.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-109.drihl-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.31: [ssh, dns, http, https, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, http, ] + 10.94.8.32: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + set-drieat-9431.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-98.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + win-drieat-9436.auth.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.38: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.40: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-61.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + srv-web-pat.driea-idf.i2: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + srv-sgbd-pat.driea-idf.i2: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.55: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.56: [ssh, dns, http, http, smb, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-09.driea-idf.i2: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + grr-ut94.driea-idf.i2: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WIN-DRIEAT-9401.auth.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.62: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.63: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WIN-DRIEAT-9404.auth.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WIN-DRIEAT-9405.auth.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.69: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.70: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.71: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + annuaire-creteil.driea-idf.i2: [ssh, dns, http, http, microsoft-ds, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-drihl-28.drihl-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-drihl-12.drihl-idf.i2: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.83: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.84: [ssh, dns, http, https, microsoft-ds, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-drihl-29.drihl-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WIN-DRIHL-9401.drihl-if.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + WIN-DRIHL-9402.drihl-if.ad.e2.rie.gouv.fr: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.88: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.89: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 8006-94-a-01.driea-idf.i2: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-41.driea-idf.i2: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, http, ] + sbl-driea-42.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, http, ] + 10.94.8.93: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, http, ] + 10.94.8.94: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.96: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.97: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.98: [ssh, dns, http, https, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.100: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.101: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.102: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.103: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.104: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.105: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.106: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.107: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.108: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.109: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.110: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.111: [] + 10.94.8.254: [] + 10.94.8.255: [] + 10.94.8.112: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.113: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.114: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.115: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.116: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.117: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.118: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.163: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.167: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.168: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.169: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.170: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.172: [ssh, tcpwrapped, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 8006-94-01.driea-idf.i2: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.206: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.208: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.209: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.210: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.211: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.213: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.214: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + ub-nfs-01.driea-idf.i2: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + proxmox-01.driea-idf.i2: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.217: [ssh, dns, http, http, netbios-ssn, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.219: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.220: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.221: [ssh, dns, http, http, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.224: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.225: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.226: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.227: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.228: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + 10.94.8.229: [ssh, dns, http, https, smb, ark, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] + sbl-driea-14.driea-if.ad.e2.rie.gouv.fr: [ssh, dns, http, http, netbios-ssn, arkeia, mysql, ms-wbt-server, pgsql, 8006, bareos, arkwui, ] diff --git a/configs/Créteil_Archives.yaml.bak b/configs/Créteil_Archives.yaml.bak new file mode 100644 index 0000000..a294286 --- /dev/null +++ b/configs/Créteil_Archives.yaml.bak @@ -0,0 +1,9 @@ +--- +Créteil Archives: + VMWare: + win-drieat-9401.auth.ad.e2.rie.gouv.fr: [microsoft-ds, ms-wbt-server] + win-drieat-9403.auth.ad.e2.rie.gouv.fr: [microsoft-ds, ms-wbt-server] + Proxmox: + 10.94.8.21: [ssh, 80] + Physiques: + 10.94.8.20: [domain, ms-wbt-server] diff --git a/configs/Miollis.yaml.bak b/configs/Miollis.yaml.bak new file mode 100644 index 0000000..9850c3a --- /dev/null +++ b/configs/Miollis.yaml.bak @@ -0,0 +1,118 @@ +--- +Miollis: + 10.75.112.0/24: + 10.75.112.1: [ssh, http, ppp, http, http, ] + 10.75.112.2: [ssh, http, ntop-http, http, http, ] + sbl-driea-46.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1057.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1060.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + 10.75.112.9: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1054.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + drieat-idf-01.wsus.e2.rie.gouv.fr: [http, msrpc, netbios-ssn, microsoft-ds, ms-wbt-server, ] + 10.75.112.12: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1056.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1047.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + 10.75.112.15: [ssh, rpcbind, http, ] + sbl-driea-1052.driea-idf.i2: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + fog-miollis.driea-idf.i2: [ftp, ssh, http, rpcbind, http, nfs_acl, mysql, ] + 10.75.112.18: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + mir-kav-miollis.driea-idf.i2: [ftp-data, ftp, ssh, domain, http, ftps, squid-http, http, http-proxy, ] + 10.75.112.21: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, postgresql, http, http, ] + 10.75.112.22: [ftp, ssh, smtp, http, netbios-ssn, smux, https, netbios-ssn, ajp13, http, jetdirect, ] + sbl-driea-70.driea-idf.i2: [ftp, ssh, smtp, http, netbios-ssn, smux, http, netbios-ssn, arkeia, mysql, http, http, ] + 10.75.112.25: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, postgresql, http, http, ] + pve-miollis-A01.driea-idf.i2: [ssh, rpcbind, http, ] + sbl-driea-1092.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, ] + SBL-DRIEA-112.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, http, netbios-ssn, http, http, ] + 10.75.112.32: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + post-office.driea-idf.i2: [msrpc, netbios-ssn, microsoft-ds, sco-dtmgr, msrpc, msrpc, msrpc, oracle, oracle, oracle-tns, globe, ms-wbt-server, http, vnc-http, vnc, damewaremr, http, ftp, http, ] + sbl-driea-1030.driea-idf.i2: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + 10.75.112.36: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1050.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1061.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, ] + win-driea-1040.driea-idf.i2: [http, msrpc, netbios-ssn, http, microsoft-ds, ms-wbt-server, postgresql, damewaremr, jetdirect, msrpc, msrpc, msrpc, msrpc, msrpc, ] + sbl-driea-1049.driea-idf.i2: [] + pve-miollis-04.driea-idf.i2: [ssh, rpcbind, http, ] + 10.75.112.42: [ssh, rpcbind, smux, http, http, ] + pve-miollis-02.driea-idf.i2: [ssh, rpcbind, smux, http, 8006, ] + pve-miollis-03.driea-idf.i2: [ssh, rpcbind, smux, http, http, ] + 10.75.112.45: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtp, arkeia, ipp, unknown, accessbuilder, arkeia, arkeia, iad3, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1090.driea-idf.i2: [ftp, ssh, smtp, netbios-ssn, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1091.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtp, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1051.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1048.driea-idf.i2: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, postgresql, http, http, ] + pve-miollis-00.driea-idf.i2: [ssh, rpcbind, http, ] + 10.75.112.51: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1093.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, ] + sbl-driea-1094.driea-idf.i2: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + 10.75.112.55: [ssh, http, http, arkeia, http, ] + sbl-driea-33.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-34.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, afs3-fileserver, http, ] + sbl-driea-1097.driea-idf.i2: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, http, http, ] + serveur-applis.driea-idf.i2: [msrpc, netbios-ssn, microsoft-ds, ms-wbt-server, http, damewaremr, msrpc, msrpc, msrpc, msrpc, msrpc, flexlm, ] + sbl-driea-1063.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + 10.75.112.64: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + sbl-driea-1098.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, arkeia, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + set-drieat-1065.driea-if.ad.e2.rie.gouv.fr: [ssh, http, http, netbios-ssn, http, http, ] + 10.75.112.70: [ssh, smtp, rpcbind, nfs_acl, ] + 10.75.112.71: [ssh, smtp, rpcbind, nfs_acl, iscsi, ] + cdc.e2.rie.gouv.fr: [ssh, http, http, http, ] + 10.75.112.73: [ssh, postgresql, ] + acdc.e2.rie.gouv.fr: [ssh, http, http, http, ] + 10.75.112.78: [ssh, postgresql, ] + 10.75.112.79: [ftp, ssh, smtp, http, netbios-ssn, http, netbios-ssn, smtps, sco-dtmgr, ipp, unknown, accessbuilder, kdm, NFS-or-IIS, LSA-or-nterm, IIS, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, postgresql, http, http, ] + wsu-driea-02.driea-if.ad.e2.rie.gouv.fr: [smtp, http, msrpc, netbios-ssn, https, microsoft-ds, printer, http, ms-wbt-server, tcpwrapped, damewaremr, http-proxy, blackice-alerts, ssl, http, jetdirect, jetdirect, ] + set-driea-1049.driea-if.ad.e2.rie.gouv.fr: [ftp, ssh, http, http, netbios-ssn, postgresql, http, http, ] + 10.75.112.83: [ssh, rpcbind, nfs_acl, ] + 10.75.112.84: [ssh, http, ] + win-driea-1046.driea-if.ad.e2.rie.gouv.fr: [ms-wbt-server, jetdirect, pds, ] + win-driee-1001.jade.local: [msrpc, netbios-ssn, microsoft-ds, ms-wbt-server, damewaremr, ] + win-driea-1043.driea-if.e2.rie.gouv.fr: [msrpc, netbios-ssn, microsoft-ds, http, ms-wbt-server, tcpwrapped, damewaremr, http-proxy, blackice-alerts, ssl, http, jetdirect, jetdirect, ] + dsin-assistance.e2.rie.gouv.fr: [ssh, http, ] + 10.75.112.95: [ssh, http, ] + 10.75.112.96: [ftp, ssh, http, netbios-ssn, http, netbios-ssn, sco-dtmgr, ipp, unknown, accessbuilder, kdm, arkeia, unknown, ms-lsa, iad1, iad2, iad3, netinfo, zincite-a, multidropper, nsstp, ams, mtqp, sbl, netsaint, danf-ak2, afrog, boinc, dcutility, http, http, ] + set-driea-1038.driea-if.ad.e2.rie.gouv.fr: [ssh, rpcbind, nfs_acl, ] + 10.75.112.98: [ssh, rpcbind, nfs_acl, ] + cent-driea-1001.driea-if.ad.e2.rie.gouv.fr: [ssh, http, rpcbind, mysql, http, jetdirect, ] + cent-driea-1002.driea-if.ad.e2.rie.gouv.fr: [ssh, http, rpcbind, mysql, http, jetdirect, ] + bar-driea-1090.driea-if.ad.e2.rie.gouv.fr: [ssh, http, jetdirect, jetdirect, jetdirect, ] + cent-driea-91.driea-if.ad.e2.rie.gouv.fr: [ssh, http, rpcbind, mysql, http, jetdirect, ] + set-drieat-test2.auth.ad.e2.rie.gouv.fr: [ssh, http, ] + 10.75.112.106: [msrpc, netbios-ssn, microsoft-ds, ] + vm-modus-2.driea-if.ad.e2.rie.gouv.fr: [msrpc, netbios-ssn, microsoft-ds, ] + set-drieat-9420.auth.ad.e2.rie.gouv.fr: [ssh, http, http, netbios-ssn, http, http, ] + 10.75.112.120: [ssh, http, rpcbind, netbios-ssn, https, netbios-ssn, nfs, iscsi, http-proxy, http, mountd, ] + 10.75.112.160: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.161: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.162: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.163: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.164: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.165: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.166: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.167: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.168: [ftp, http, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.169: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.170: [ftp, nagios-nsca, http, printer, nagios-nsca, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.171: [ftp, http, http, microsoft-ds, printer, glrpc, cisco-aqos, soap, soap, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.172: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.173: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.174: [ftp, nagios-nsca, http, printer, nagios-nsca, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.175: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.176: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.177: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.178: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.179: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.180: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.181: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.182: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.183: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.184: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.185: [ftp, nagios-nsca, http, printer, http, http, glrpc, cisco-aqos, jetdirect, jetdirect, jetdirect, jetdirect, ] + 10.75.112.207: [ftp, http, tcpwrapped, ] + 10.75.112.215: [ftp, finger, http, http, printer, http, thinprint, lexmark-objectstore, tcpwrapped, synchronet-db, http, jetdirect, ir-alerts, ismserver, snet-sensor-mgmt, ] + 10.75.112.217: [http, http, printer, http, http, jetdirect, hp-gsg, ] + 10.75.112.221: [http, netbios-ssn, http, netbios-ssn, afp, ] + 10.75.112.224: [ftp, telnet, http, https, printer, http, routematch, jetdirect, ] + 10.75.112.226: [ssh, http, ] + 10.75.112.227: [ftp, telnet, http, http, http, printer, http, jetdirect, ] + 10.75.112.254: [msrpc, microsoft-ds, damewaremr, msrpc, msrpc, msrpc, ] diff --git a/discover b/discover new file mode 100755 index 0000000..09ea10d --- /dev/null +++ b/discover @@ -0,0 +1,17 @@ +#!/usr/bin/env bash + +### +# +# Scan un réseau avec nmap pour créer un fichier de configuration +# Usage : ./discover avec network en notation CIDR XXX.XXX.XXX.XXX/XX +# +### + +DIR="$(dirname -- "$0")" +network="$1" +filename="${network/\//_}" + +mkdir -p "$DIR/scans" +nmap -F -oX "$DIR/scans/$filename.xml" $network +mkdir -p "$DIR/configs" +xsltproc --stringparam network "$network" to_config.xsl "$DIR/scans/$filename.xml" > "$DIR/configs/$filename.yaml" diff --git a/init.sh b/init.sh deleted file mode 100755 index 925d627..0000000 --- a/init.sh +++ /dev/null @@ -1,19 +0,0 @@ -#!/usr/bin/env bash - -### -# -# Scan un réseau avec nmap pour créer un fichier de configuration -# -### - -DIR="$(dirname -- "$0")" - -echo "Nom du site ?" -read site -filename="${site/ /_}" -echo "Adresse réseau CIDR (xxx.xxx.xxx.xxx/xx) ?" -read network - - -nmap --script smb-enum-shares.nse -oX "scans/$filename.xml" $network -xsltproc --stringparam site "$site" --stringparam network $network to_yaml.xsl "$DIR/scans/$filename.xml" > "$DIR/confs/$filename.yaml" diff --git a/nmap_cmd.xsl b/nmap_cmd.xsl new file mode 100644 index 0000000..fe174f4 --- /dev/null +++ b/nmap_cmd.xsl @@ -0,0 +1,35 @@ + + + + + + + +nmap -v -T4 -p + + --script "$DIR/http-info.nse" -oX "$DIR/ + +.tmp" + + + + + + + + +, + + + + + + + + + + + \ No newline at end of file diff --git a/results.xsl b/results.xsl index 34ab7ea..9c2b6fd 100644 --- a/results.xsl +++ b/results.xsl @@ -5,12 +5,12 @@ version="1.1"> - + - + - lanScan - <xsl:value-of select="@site"/> + lanScan - <xsl:value-of select="@title"/> @@ -39,7 +39,7 @@
@@ -126,7 +126,7 @@ - + @@ -138,7 +138,6 @@ - / @@ -166,17 +165,17 @@ - + - + - + diff --git a/scan b/scan new file mode 100755 index 0000000..08e38e9 --- /dev/null +++ b/scan @@ -0,0 +1,12 @@ +#!/usr/bin/env bash + +export DIR="$(dirname -- "$0")" +echo $DIR +conf="$1" +echo $conf + +site="$(basename ${conf/.yaml/})" +echo $site +php to_XML.php "$conf" > "$DIR/site/$site.xml" +xsltproc nmap_cmd.xsl "$DIR/site/$site.xml" | sh +mv "$DIR/scans/$site.xml.tmp" "$DIR/scans/$site.xml" \ No newline at end of file diff --git a/scan.sh b/scan.sh deleted file mode 100755 index 52e26cd..0000000 --- a/scan.sh +++ /dev/null @@ -1,8 +0,0 @@ -#!/usr/bin/env bash - -DIR="$(dirname -- "$0")" -conf="$1" - -site="$(basename ${conf/.yaml/})" -php "$DIR/nmap_cmd.php" $conf | sh -mv "$DIR/scans/.~$site.xml" "$DIR/scans/$site.xml" \ No newline at end of file diff --git a/scan_all.sh b/scan_all similarity index 64% rename from scan_all.sh rename to scan_all index 075fc94..52f6180 100755 --- a/scan_all.sh +++ b/scan_all @@ -5,7 +5,7 @@ DIR="$(dirname -- $0)" mkdir -p "$DIR"/scans mkdir -p "$DIR"/site -for conf in "$DIR"/confs/*.yaml +for conf in "$DIR"/configs/*.yaml do - ./scan.sh "$conf" + ./scan "$conf" done diff --git a/to_XML.php b/to_XML.php new file mode 100644 index 0000000..1b8c562 --- /dev/null +++ b/to_XML.php @@ -0,0 +1,45 @@ +appendChild($xml->createProcessingInstruction("xml-stylesheet", "href='../results.xsl' type='text/xsl'")); +$root = $xml->appendChild($xml->createElement("lanScanConfig")); +$root->setAttribute("scanpath", "scans/$site.xml"); + +function appendArray($document, $node, $array) { + foreach ($array as $key => $value) { + if (is_array($value)) { + foreach ($value as $vkey => $vvalue) { + if (is_string($vkey)) { + if (is_array($vvalue)) { + $child = $document->createElement($vkey); + toXML($document, $child, $vvalue); + } else { + $child = $document->createElement($vkey, $vvalue); + } + $node->appendChild($child); + } else { + if (is_array($vvalue)) { + $child = $document->createElement($key); + appendArray($document, $child, $vvalue); + } else { + $child = $document->createElement($key, $vvalue); + } + $node->appendChild($child); + } + + } + } else { + $node->setAttribute($key, $value); + } + } +} + +appendArray($xml, $root, $conf); + +print $xml->saveXML(); +?> diff --git a/to_yaml.xsl b/to_config.xsl similarity index 69% rename from to_yaml.xsl rename to to_config.xsl index 215f592..9fbabac 100644 --- a/to_yaml.xsl +++ b/to_config.xsl @@ -5,29 +5,33 @@ version="1.1"> - - + --- -site: +title: Titre -: +group: + - name: Réseau + host: - + - address: -: [] + + service: [] + , + \ No newline at end of file