File size: 12,383 Bytes
7c89ed7
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at https://mozilla.org/MPL/2.0/.
# Copyright (c) 2017 Mozilla Corporation

import copy

from mq.plugins.parse_sshd import message

accept_message = {}
accept_message['utctimestamp'] = '2017-08-24T22:49:42+00:00'
accept_message['timestamp'] = '2017-08-24T22:49:42+00:00'
accept_message['receivedtimestamp'] = '2017-08-24T22:49:42+00:00'
accept_message['category'] = 'syslog'
accept_message['processid'] = '0'
accept_message['processname'] = 'sshd'
accept_message['severity'] = '7'
accept_message['hostname'] = 'syslog1.private.scl3.mozilla.com'
accept_message['mozdefhostname'] = 'mozdef4.private.scl3.mozilla.com'
accept_message['eventsource'] = 'systemlogs'
accept_message['details'] = {}
accept_message['details']['processid'] = '5413'
accept_message['details']['sourceipv4address'] = '10.22.74.208'
accept_message['details']['hostname'] = 'mysuperhost.somewhere.com'
accept_message['details']['program'] = 'sshd'
accept_message['details']['sourceipaddress'] = '10.22.74.208'
accept_message['details']['sourceport'] = '37486'


# Short username, RSA fpr present
class TestSSHDAcceptedMessageV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Accepted publickey for user1 from 10.22.74.208 port 26388 ssh2: RSA 1f:c9:4c:90:bc:fb:72:c7:4d:02:da:07:ed:fe:07:ac'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'
        assert retmessage['details']['rsakeyfingerprint'] == '1f:c9:4c:90:bc:fb:72:c7:4d:02:da:07:ed:fe:07:ac'
        assert retmessage['details']['authmethod'] == 'publickey'
        assert retmessage['details']['sourceport'] == '26388'
        assert retmessage['details']['authstatus'] == 'Accepted'
        assert retmessage['details']['sourceipaddress'] == '10.22.74.208'

# Long Username and SHA256 fpr present


class TestSSHDAcceptedMessageV2():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Accepted publickey for user1@domainname.com from 10.22.248.134 port 52216 ssh2: RSA SHA256:1fPhSawXQzFDrJoN2uSos2nGg3wS3oGp15x8/HR+pBc'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1@domainname.com'
        assert retmessage['details']['rsakeyfingerprint'] == 'SHA256:1fPhSawXQzFDrJoN2uSos2nGg3wS3oGp15x8/HR+pBc'
        assert retmessage['details']['authmethod'] == 'publickey'
        assert retmessage['details']['sourceport'] == '52216'
        assert retmessage['details']['authstatus'] == 'Accepted'
        assert retmessage['details']['sourceipaddress'] == '10.22.248.134'


# Long username
class TestSSHDAcceptedMessageV3():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Accepted publickey for user1@domainname.com from 10.22.74.208 port 26388 ssh2: RSA 1f:c9:4c:90:bc:fb:72:c7:4d:02:da:07:ed:fe:07:ac'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1@domainname.com'
        assert retmessage['details']['rsakeyfingerprint'] == '1f:c9:4c:90:bc:fb:72:c7:4d:02:da:07:ed:fe:07:ac'
        assert retmessage['details']['authmethod'] == 'publickey'
        assert retmessage['details']['sourceport'] == '26388'
        assert retmessage['details']['authstatus'] == 'Accepted'
        assert retmessage['details']['sourceipaddress'] == '10.22.74.208'


# Short username, RSA fpr missing
class TestSSHDAcceptedMessageV4():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Accepted publickey for user1 from 10.22.74.208 port 26388 ssh2'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'
        assert retmessage['details']['rsakeyfingerprint'] is None
        assert retmessage['details']['authmethod'] == 'publickey'
        assert retmessage['details']['sourceport'] == '26388'
        assert retmessage['details']['authstatus'] == 'Accepted'
        assert retmessage['details']['sourceipaddress'] == '10.22.74.208'


# PAM session opened for user
class TestSSHDPAMSessionOpenedMessageV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'pam_unix(sshd:session): session opened for user user1 by (uid=0)'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'


# PAM session closed for user
class TestSSHDPAMSessionClosedMessageV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'pam_unix(sshd:session): session closed for user user1'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'


# Postponed preauth - short, simple username
class TestSSHDPostponedMessageV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Postponed publickey for user1 from 10.22.75.209 port 37486 ssh2'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'
        assert retmessage['details']['authmethod'] == 'publickey'


# Postponed preauth - long, simple username
class TestSSHDPostponedMessageV2():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Postponed publickey for user1 from 10.22.75.209 port 37486 ssh2 [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'
        assert retmessage['details']['authmethod'] == 'publickey'


# Postponed preauth - long username
class TestSSHDPostponedMessageV3():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Postponed publickey for user1@somewhere.com from 10.22.74.208 port 37486 ssh2 [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1@somewhere.com'
        assert retmessage['details']['authmethod'] == 'publickey'


# Starting session
class TestSSHDStartingSessionV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Starting session: command for user1 from 10.22.128.93 port 51748'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'
        assert retmessage['details']['sessiontype'] == 'command'
        assert retmessage['details']['sourceipaddress'] == '10.22.128.93'
        assert retmessage['details']['sourceport'] == '51748'


# Starting session
class TestSSHDStartingSessionV2():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Starting session: shell on pts/0 for user2 from 10.22.252.6 port 59983'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user2'
        assert retmessage['details']['sessiontype'] == 'shell'
        assert retmessage['details']['sourceipaddress'] == '10.22.252.6'
        assert retmessage['details']['sourceport'] == '59983'
        assert retmessage['details']['device'] == 'pts/0'


# Invalid User - complex username
class TestSSHDUnauthorizedUserV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Invalid user user@loftydreams.com from 10.22.75.209'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user@loftydreams.com'
        assert retmessage['details']['sourceipaddress'] == '10.22.75.209'


# Input Userauth Request
class TestSSHDUnauthorizedUsertV2():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'input_userauth_request: invalid user user1 [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['username'] == 'user1'


# SSH Disconnect - Bye Bye
class TestSSHDReceivedDisconnectV1():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Received disconnect from 10.22.75.209: 2103: Bye Bye [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['sourceipaddress'] == '10.22.75.209'
        assert retmessage['details']['sourceport'] == '2103'


# SSH Disconnect - normal shutdown
class TestSSHDReceivedDisconnectV2():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Received disconnect from 10.22.75.209: 2103: Normal Shutdown, Thank you for playing [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['sourceipaddress'] == '10.22.75.209'
        assert retmessage['details']['sourceport'] == '2103'


# SSH Disconnect
class TestSSHDReceivedDisconnectV3():
    def setup(self):

        self.msgobj = message()
        self.msg = copy.deepcopy(accept_message)
        self.msg['summary'] = 'Received disconnect from 10.22.75.209: 2103:  [preauth]'

    def test_onMessage(self):
        metadata = {}

        (retmessage, retmeta) = self.msgobj.onMessage(self.msg, metadata)

        assert retmessage is not None
        assert retmeta is not None
        assert retmessage['details']['sourceipaddress'] == '10.22.75.209'
        assert retmessage['details']['sourceport'] == '2103'