feat: implement packet sniffer with database integration and API endpoints
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 9s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 9s
This commit is contained in:
@@ -17,12 +17,12 @@ sudo sed -i "s/^#listen_addresses =.*/listen_addresses = '*'/" "$PG_CONF"
|
||||
echo "[3] Updating pg_hba.conf for LAN + localhost access…"
|
||||
PG_HBA="/etc/postgresql/$(ls /etc/postgresql)/main/pg_hba.conf"
|
||||
|
||||
# Ensure localhost entry exists
|
||||
if ! grep -q "host *all *all *127.0.0.1/32" "$PG_HBA"; then
|
||||
# Add localhost entry if missing
|
||||
if ! grep -Eq "^[ ]*host[ ]+all[ ]+all[ ]+127.0.0.1/32" "$PG_HBA"; then
|
||||
echo "host all all 127.0.0.1/32 md5" | sudo tee -a "$PG_HBA"
|
||||
fi
|
||||
|
||||
# Ensure LAN entry exists
|
||||
# Add LAN entry if missing
|
||||
if ! grep -q "$LAN_SUBNET" "$PG_HBA"; then
|
||||
echo "host all all $LAN_SUBNET md5" | sudo tee -a "$PG_HBA"
|
||||
fi
|
||||
@@ -30,14 +30,16 @@ fi
|
||||
echo "[4] Restarting PostgreSQL…"
|
||||
sudo systemctl restart postgresql
|
||||
|
||||
echo "[5] Creating database and user (if not existing)…"
|
||||
echo "[5] Creating database + user (idempotent)…"
|
||||
sudo -u postgres psql <<EOF
|
||||
DO \$\$
|
||||
BEGIN
|
||||
-- Create user if missing
|
||||
IF NOT EXISTS (SELECT FROM pg_roles WHERE rolname = '$DB_USER') THEN
|
||||
CREATE USER $DB_USER WITH PASSWORD '$DB_PASS';
|
||||
END IF;
|
||||
|
||||
-- Create database if missing
|
||||
IF NOT EXISTS (SELECT FROM pg_database WHERE datname = '$DB_NAME') THEN
|
||||
CREATE DATABASE $DB_NAME OWNER $DB_USER;
|
||||
END IF;
|
||||
@@ -45,26 +47,40 @@ END
|
||||
\$\$;
|
||||
EOF
|
||||
|
||||
echo "[6] Creating tables (idempotent)…"
|
||||
sudo -u postgres psql -d $DB_NAME <<EOF
|
||||
echo "[6] Creating table (idempotent)…"
|
||||
sudo -u postgres psql -d "$DB_NAME" <<EOF
|
||||
CREATE TABLE IF NOT EXISTS packet_log (
|
||||
id BIGSERIAL PRIMARY KEY,
|
||||
timestamp TIMESTAMPTZ DEFAULT NOW(),
|
||||
direction VARCHAR(16), -- ingress / egress
|
||||
|
||||
-- ingress / egress
|
||||
direction VARCHAR(16),
|
||||
|
||||
-- eBPF metadata
|
||||
interface VARCHAR(32),
|
||||
|
||||
-- Ethernet layer
|
||||
src_mac VARCHAR(32),
|
||||
dst_mac VARCHAR(32),
|
||||
eth_type VARCHAR(16),
|
||||
|
||||
-- IP layer
|
||||
src_ip VARCHAR(64),
|
||||
dst_ip VARCHAR(64),
|
||||
ip_protocol VARCHAR(16),
|
||||
|
||||
-- Transport layer
|
||||
src_port INTEGER,
|
||||
dst_port INTEGER,
|
||||
packet_len INTEGER,
|
||||
|
||||
-- nftables metadata
|
||||
nft_hook VARCHAR(32),
|
||||
nft_table VARCHAR(64),
|
||||
nft_table_name VARCHAR(64), -- <— renamed (fix)
|
||||
nft_chain VARCHAR(64),
|
||||
nft_verdict VARCHAR(32),
|
||||
|
||||
-- raw packet
|
||||
raw_packet BYTEA
|
||||
);
|
||||
EOF
|
||||
|
||||
Reference in New Issue
Block a user