diff --git a/src/warden-server/contrib/wardenweb/show_WrongType.php b/src/warden-server/contrib/wardenweb/show_WrongType.php new file mode 100644 index 0000000000000000000000000000000000000000..a0d35aa2e8fe5f85f30ffd5f8c60eb0923a25082 --- /dev/null +++ b/src/warden-server/contrib/wardenweb/show_WrongType.php @@ -0,0 +1,27 @@ +<?php + +include("db.php"); + +$q = "SELECT +hostname, +service, +MAX(received) as last_received, +COUNT(*) as count +FROM events +WHERE +detected > '2012-08-01' and +type NOT IN ('portscan', 'bruteforce', 'probe', 'spam','phishing', 'botnet_c_c', 'dos', 'malware', 'copyright','webattack', 'test', 'other') +GROUP BY hostname, service;"; + +$res = mysql_query($q, $db); +if (mysql_num_rows($res) == 0) { die("nodata");} + +$d = array(); +while ($tmp = mysql_fetch_assoc($res)) { + print json_encode(view_recode($tmp))."\n"; +} +mysql_free_result($res); +mysql_close($db); + +?> + diff --git a/src/warden-server/contrib/wardenweb/webmenu.php b/src/warden-server/contrib/wardenweb/webmenu.php index 5dcefa228cef539d55b66f240b10792515b2a75d..c1cfe948395729c7b98c74f6bdea6197d22c0d31 100644 --- a/src/warden-server/contrib/wardenweb/webmenu.php +++ b/src/warden-server/contrib/wardenweb/webmenu.php @@ -11,6 +11,7 @@ if(!empty($_SERVER["REMOTE_ADDR"])) { "show_TargetportActivity.php" => "show_TargetportActivity.php", "show_HostnameServiceTypeActivity.php" => "show_HostnameServiceTypeActivity.php", "show_MartiansActivity.php" => "show_MartiansActivity.php", + "show_WrongType.php" => "show_WrongType.php", "TopTargetports" => "show_TopTargetports.html", "TopSources" => "table_TopSources.html", "dropmaps" => "stats.php?c=dropmaps",