Net-Abuse-Utils-0.25/000755 000765 000024 00000000000 12727407345 015250 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/Changes000644 000765 000024 00000010412 12727407345 016541 0ustar00michaelgstaff000000 000000 Revision history for Perl extension Net::Abuse::Utils. 0.25 2016-06-12 21:39:45 EDT - Fix a typo that broke get_asn_info when multiple elements were returned. Thanks to @rwfranks @NathanGibbs3 @wesyoung - Update AS decscription and company tests to just verify some true value was returned. Thanks to @rwfranks @NathanGibbs3 0.24 2016-03-08 07:43:15 EST - patch from rwfranks to remove some of the more volatile tests - get_all_asn_info for getting data for all anoucing ASN(s) 0.23 2013-10-24 19:08:48 EDT - [wesyoung] regex fix to get_peer_info where a date is not returned - minor build changes 0.22 2013-10-17 06:14:33 EDT - Pass prefix length to Net::IP::ip_reverse 0.21 2013-10-13 21:25:01 EDT - Return early when we don't have an AS Description, closes GitHub #10 0.20 2013-09-13 23:51:24 EDT - @RESOLVERS package variable to use custom DNS resolvers instead of system resolvers - Declare required Perl version in dist metadata files 0.19 2013-09-05 18:21:39 EDT - Update docs, indicate which functions are IPv4 only - IPv6 test coverage - Other misc testing improvments 0.18 2013-09-03 21:17:51 EDT - [Andrew Hoying] IPv6 Support thanks to Andrew Hoying 0.17 2013-08-27 16:59:21 EDT - Offline tests 0.16 2013-08-25 23:15:13 EDT - Require ONLINE_TESTS ENV variable be set for online tests. 0.15 2013-07-30 06:16:32 EDT - Remove old Build.PL... ooops! 0.14 2013-07-29 01:02:00 EDT - Convert to Milla for authoring tool 0.13 2012-12-06 - account for Net::DNS >= 0.69 converting SOA email record to address 0.12_01 2012-09-24 - [wesyoung.me] added get_malware function based on: http://www.team-cymru.org/Services/MHR 0.12 2012-08-29 - [wesyoung.me] test false failure bugfix - [wesyoung.me] get_asn_info and get_ipwi_contacts bug fixes closes RT #73203 and RT #70209 - comment out some old DNSBLs and reorder output in ip-info.pl - add Wes Young to authors 0.11_01 2012-07-30 - [wesyoung.me] added get_peer_info function - Use /usr/bin/env perl for example script shebangs 0.11 Sun Sep 14 2009 - Moar Tests - Check asn is a number in get_asn_country 0.10 Sun Dec 28 2008 - New get_domain function that converts host name to domain name - Memoize support though commented out by default, enable by uncommenting the following two lines in lib/Net/Abuse/Utils.pm: # use Memoize; # memoize('_return_rr'); A future version will likely allow Memoization via an export tag. 0.09 Sun Jun 15 2008 - Fix META.yml issues that were missed in 0.08 0.08 Fri Jun 13 2008 - update output of get_as_description to make ARIN IPs match other RIRs, HANDLE AS Org eg: THEPLANET-AS ThePlanet.com Internet Services, Inc. 0.07 Fri Mar 30 2008 - update regexs used by get_as_company to remove trailing 'AS Number' as well as 'AS' - remove stripping of AS Handle from ARIN AS Desc now that we have get_as_company - Module::Signature module signing stuff - Add license to Makefile.PL - Use newer ExtUtils::MakeMaker to generate the new META.yml format 0.06 Fri May 30 2008 - Added get_as_company which functions similiarly to get_as_description but attempts to clean up the string found before returning it - Update AS description for 21844 in t/Net-Abuse-Utils.t - Remove relays.ordb.org from the DNSBL list in examples/ip-info.pl 0.05 Sun Mar 19 2006 - Update Makefile.PL to specify Perl 5.6.1, missed this last rev - Fixed a bug in looking up ASN when the same block is announced by multiple ASNs. - Fixed a bug where looking up AS Org for ASN not in Cymru database would generate warnings rather then just return undef 0.04 Fri Mar 10 2006 - Added public is_ip function to check that a string looks like an IP - Added tests using Test::Pod::Coverage and Test::Pod (if installed) - Prefix private functions with _ for Test::Pod::Coverage - Require Perl 5.6.1 rather then 5.8.7 0.03 Sun Mar 5 2006 - 0.02 was uploaded with a broken test 0.02 Sun Mar 5 2006 - Fixed a bug where AS Description would only return data for ASs assigned by ARIN. - In get_ipwi_contacts check that whoisip_query returns a hash ref rather then just checking that it isn't an array ref. - a few minor formatting cleanups 0.01 Sat Mar 4 2006 - Initial Release Net-Abuse-Utils-0.25/cpanfile000644 000765 000024 00000000177 12727407345 016761 0ustar00michaelgstaff000000 000000 requires 'perl', '5.006'; requires 'Email::Address'; requires 'Net::DNS'; requires 'Net::Whois::IP', 1.11; requires 'Net::IP'; Net-Abuse-Utils-0.25/dist.ini000644 000765 000024 00000000341 12727407345 016712 0ustar00michaelgstaff000000 000000 name = Net-Abuse-Utils author = mikegrb author = Wes Young [@Milla] installer = MakeMaker [PodWeaver] [Twitter] [TravisCI::StatusBadge] user = mikegrb repo = Net-Abuse-UtilsNet-Abuse-Utils-0.25/examples/000755 000765 000024 00000000000 12727407345 017066 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/lib/000755 000765 000024 00000000000 12727407345 016016 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/LICENSE000644 000765 000024 00000043636 12727407345 016271 0ustar00michaelgstaff000000 000000 This software is copyright (c) 2013 by =over 4. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. Terms of the Perl programming language system itself a) the GNU General Public License as published by the Free Software Foundation; either version 1, or (at your option) any later version, or b) the "Artistic License" --- The GNU General Public License, Version 1, February 1989 --- This software is Copyright (c) 2013 by =over 4. This is free software, licensed under: The GNU General Public License, Version 1, February 1989 GNU GENERAL PUBLIC LICENSE Version 1, February 1989 Copyright (C) 1989 Free Software Foundation, Inc. 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. Preamble The license agreements of most software companies try to keep users at the mercy of those companies. By contrast, our General Public License is intended to guarantee your freedom to share and change free software--to make sure the software is free for all its users. The General Public License applies to the Free Software Foundation's software and to any other program whose authors commit to using it. You can use it for your programs, too. When we speak of free software, we are referring to freedom, not price. Specifically, the General Public License is designed to make sure that you have the freedom to give away or sell copies of free software, that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs; and that you know you can do these things. To protect your rights, we need to make restrictions that forbid anyone to deny you these rights or to ask you to surrender the rights. These restrictions translate to certain responsibilities for you if you distribute copies of the software, or if you modify it. For example, if you distribute copies of a such a program, whether gratis or for a fee, you must give the recipients all the rights that you have. You must make sure that they, too, receive or can get the source code. And you must tell them their rights. We protect your rights with two steps: (1) copyright the software, and (2) offer you this license which gives you legal permission to copy, distribute and/or modify the software. Also, for each author's protection and ours, we want to make certain that everyone understands that there is no warranty for this free software. If the software is modified by someone else and passed on, we want its recipients to know that what they have is not the original, so that any problems introduced by others will not reflect on the original authors' reputations. The precise terms and conditions for copying, distribution and modification follow. GNU GENERAL PUBLIC LICENSE TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION 0. This License Agreement applies to any program or other work which contains a notice placed by the copyright holder saying it may be distributed under the terms of this General Public License. The "Program", below, refers to any such program or work, and a "work based on the Program" means either the Program or any work containing the Program or a portion of it, either verbatim or with modifications. Each licensee is addressed as "you". 1. You may copy and distribute verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice and disclaimer of warranty; keep intact all the notices that refer to this General Public License and to the absence of any warranty; and give any other recipients of the Program a copy of this General Public License along with the Program. You may charge a fee for the physical act of transferring a copy. 2. You may modify your copy or copies of the Program or any portion of it, and copy and distribute such modifications under the terms of Paragraph 1 above, provided that you also do the following: a) cause the modified files to carry prominent notices stating that you changed the files and the date of any change; and b) cause the whole of any work that you distribute or publish, that in whole or in part contains the Program or any part thereof, either with or without modifications, to be licensed at no charge to all third parties under the terms of this General Public License (except that you may choose to grant warranty protection to some or all third parties, at your option). c) If the modified program normally reads commands interactively when run, you must cause it, when started running for such interactive use in the simplest and most usual way, to print or display an announcement including an appropriate copyright notice and a notice that there is no warranty (or else, saying that you provide a warranty) and that users may redistribute the program under these conditions, and telling the user how to view a copy of this General Public License. d) You may charge a fee for the physical act of transferring a copy, and you may at your option offer warranty protection in exchange for a fee. Mere aggregation of another independent work with the Program (or its derivative) on a volume of a storage or distribution medium does not bring the other work under the scope of these terms. 3. You may copy and distribute the Program (or a portion or derivative of it, under Paragraph 2) in object code or executable form under the terms of Paragraphs 1 and 2 above provided that you also do one of the following: a) accompany it with the complete corresponding machine-readable source code, which must be distributed under the terms of Paragraphs 1 and 2 above; or, b) accompany it with a written offer, valid for at least three years, to give any third party free (except for a nominal charge for the cost of distribution) a complete machine-readable copy of the corresponding source code, to be distributed under the terms of Paragraphs 1 and 2 above; or, c) accompany it with the information you received as to where the corresponding source code may be obtained. (This alternative is allowed only for noncommercial distribution and only if you received the program in object code or executable form alone.) Source code for a work means the preferred form of the work for making modifications to it. For an executable file, complete source code means all the source code for all modules it contains; but, as a special exception, it need not include source code for modules which are standard libraries that accompany the operating system on which the executable file runs, or for standard header files or definitions files that accompany that operating system. 4. You may not copy, modify, sublicense, distribute or transfer the Program except as expressly provided under this General Public License. Any attempt otherwise to copy, modify, sublicense, distribute or transfer the Program is void, and will automatically terminate your rights to use the Program under this License. However, parties who have received copies, or rights to use copies, from you under this General Public License will not have their licenses terminated so long as such parties remain in full compliance. 5. By copying, distributing or modifying the Program (or any work based on the Program) you indicate your acceptance of this license to do so, and all its terms and conditions. 6. Each time you redistribute the Program (or any work based on the Program), the recipient automatically receives a license from the original licensor to copy, distribute or modify the Program subject to these terms and conditions. You may not impose any further restrictions on the recipients' exercise of the rights granted herein. 7. The Free Software Foundation may publish revised and/or new versions of the General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns. Each version is given a distinguishing version number. If the Program specifies a version number of the license which applies to it and "any later version", you have the option of following the terms and conditions either of that version or of any later version published by the Free Software Foundation. If the Program does not specify a version number of the license, you may choose any version ever published by the Free Software Foundation. 8. If you wish to incorporate parts of the Program into other free programs whose distribution conditions are different, write to the author to ask for permission. For software which is copyrighted by the Free Software Foundation, write to the Free Software Foundation; we sometimes make exceptions for this. Our decision will be guided by the two goals of preserving the free status of all derivatives of our free software and of promoting the sharing and reuse of software generally. NO WARRANTY 9. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 10. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. END OF TERMS AND CONDITIONS Appendix: How to Apply These Terms to Your New Programs If you develop a new program, and you want it to be of the greatest possible use to humanity, the best way to achieve this is to make it free software which everyone can redistribute and change under these terms. To do so, attach the following notices to the program. It is safest to attach them to the start of each source file to most effectively convey the exclusion of warranty; and each file should have at least the "copyright" line and a pointer to where the full notice is found. Copyright (C) 19yy This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 1, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston MA 02110-1301 USA Also add information on how to contact you by electronic and paper mail. If the program is interactive, make it output a short notice like this when it starts in an interactive mode: Gnomovision version 69, Copyright (C) 19xx name of author Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. This is free software, and you are welcome to redistribute it under certain conditions; type `show c' for details. The hypothetical commands `show w' and `show c' should show the appropriate parts of the General Public License. Of course, the commands you use may be called something other than `show w' and `show c'; they could even be mouse-clicks or menu items--whatever suits your program. You should also get your employer (if you work as a programmer) or your school, if any, to sign a "copyright disclaimer" for the program, if necessary. Here a sample; alter the names: Yoyodyne, Inc., hereby disclaims all copyright interest in the program `Gnomovision' (a program to direct compilers to make passes at assemblers) written by James Hacker. , 1 April 1989 Ty Coon, President of Vice That's all there is to it! --- The Artistic License 1.0 --- This software is Copyright (c) 2013 by =over 4. This is free software, licensed under: The Artistic License 1.0 The Artistic License Preamble The intent of this document is to state the conditions under which a Package may be copied, such that the Copyright Holder maintains some semblance of artistic control over the development of the package, while giving the users of the package the right to use and distribute the Package in a more-or-less customary fashion, plus the right to make reasonable modifications. Definitions: - "Package" refers to the collection of files distributed by the Copyright Holder, and derivatives of that collection of files created through textual modification. - "Standard Version" refers to such a Package if it has not been modified, or has been modified in accordance with the wishes of the Copyright Holder. - "Copyright Holder" is whoever is named in the copyright or copyrights for the package. - "You" is you, if you're thinking about copying or distributing this Package. - "Reasonable copying fee" is whatever you can justify on the basis of media cost, duplication charges, time of people involved, and so on. (You will not be required to justify it to the Copyright Holder, but only to the computing community at large as a market that must bear the fee.) - "Freely Available" means that no fee is charged for the item itself, though there may be fees involved in handling the item. It also means that recipients of the item may redistribute it under the same conditions they received it. 1. You may make and give away verbatim copies of the source form of the Standard Version of this Package without restriction, provided that you duplicate all of the original copyright notices and associated disclaimers. 2. You may apply bug fixes, portability fixes and other modifications derived from the Public Domain or from the Copyright Holder. A Package modified in such a way shall still be considered the Standard Version. 3. You may otherwise modify your copy of this Package in any way, provided that you insert a prominent notice in each changed file stating how and when you changed that file, and provided that you do at least ONE of the following: a) place your modifications in the Public Domain or otherwise make them Freely Available, such as by posting said modifications to Usenet or an equivalent medium, or placing the modifications on a major archive site such as ftp.uu.net, or by allowing the Copyright Holder to include your modifications in the Standard Version of the Package. b) use the modified Package only within your corporation or organization. c) rename any non-standard executables so the names do not conflict with standard executables, which must also be provided, and provide a separate manual page for each non-standard executable that clearly documents how it differs from the Standard Version. d) make other distribution arrangements with the Copyright Holder. 4. You may distribute the programs of this Package in object code or executable form, provided that you do at least ONE of the following: a) distribute a Standard Version of the executables and library files, together with instructions (in the manual page or equivalent) on where to get the Standard Version. b) accompany the distribution with the machine-readable source of the Package with your modifications. c) accompany any non-standard executables with their corresponding Standard Version executables, giving the non-standard executables non-standard names, and clearly documenting the differences in manual pages (or equivalent), together with instructions on where to get the Standard Version. d) make other distribution arrangements with the Copyright Holder. 5. You may charge a reasonable copying fee for any distribution of this Package. You may charge any fee you choose for support of this Package. You may not charge a fee for this Package itself. However, you may distribute this Package in aggregate with other (possibly commercial) programs as part of a larger (possibly commercial) software distribution provided that you do not advertise this Package as a product of your own. 6. The scripts and library files supplied as input to or produced as output from the programs of this Package do not automatically fall under the copyright of this Package, but belong to whomever generated them, and may be sold commercially, and may be aggregated with this Package. 7. C or perl subroutines supplied by you and linked into this Package shall not be considered part of this Package. 8. The name of the Copyright Holder may not be used to endorse or promote products derived from this software without specific prior written permission. 9. THIS PACKAGE IS PROVIDED "AS IS" AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. The End Net-Abuse-Utils-0.25/Makefile.PL000644 000765 000024 00000002303 12727407345 017220 0ustar00michaelgstaff000000 000000 # This file was automatically generated by Dist::Zilla::Plugin::MakeMaker v5.021. use strict; use warnings; use 5.006; use ExtUtils::MakeMaker; my %WriteMakefileArgs = ( "ABSTRACT" => "Routines useful for processing network abuse", "AUTHOR" => "mikegrb , Wes Young ", "CONFIGURE_REQUIRES" => { "ExtUtils::MakeMaker" => 0 }, "DISTNAME" => "Net-Abuse-Utils", "EXE_FILES" => [], "LICENSE" => "perl", "MIN_PERL_VERSION" => "5.006", "NAME" => "Net::Abuse::Utils", "PREREQ_PM" => { "Email::Address" => 0, "Net::DNS" => 0, "Net::IP" => 0, "Net::Whois::IP" => "1.11" }, "VERSION" => "0.25", "test" => { "TESTS" => "t/*.t" } ); my %FallbackPrereqs = ( "Email::Address" => 0, "ExtUtils::MakeMaker" => 0, "Net::DNS" => 0, "Net::IP" => 0, "Net::Whois::IP" => "1.11" ); unless ( eval { ExtUtils::MakeMaker->VERSION(6.63_03) } ) { delete $WriteMakefileArgs{TEST_REQUIRES}; delete $WriteMakefileArgs{BUILD_REQUIRES}; $WriteMakefileArgs{PREREQ_PM} = \%FallbackPrereqs; } delete $WriteMakefileArgs{CONFIGURE_REQUIRES} unless eval { ExtUtils::MakeMaker->VERSION(6.52) }; WriteMakefile(%WriteMakefileArgs); Net-Abuse-Utils-0.25/MANIFEST000644 000765 000024 00000000501 12727407345 016375 0ustar00michaelgstaff000000 000000 # This file was automatically generated by Dist::Zilla::Plugin::Manifest v5.021. Changes LICENSE MANIFEST META.json META.yml Makefile.PL README cpanfile dist.ini examples/ip-info.pl examples/malware.pl lib/Net/Abuse/Utils.pm t/Net-Abuse-Utils-offline.t t/Net-Abuse-Utils.t t/pod-coverage.t t/pod.t t/release-pod-syntax.t Net-Abuse-Utils-0.25/META.json000644 000765 000024 00000003143 12727407345 016672 0ustar00michaelgstaff000000 000000 { "abstract" : "Routines useful for processing network abuse", "author" : [ "mikegrb ", "Wes Young " ], "dynamic_config" : 0, "generated_by" : "Dist::Milla version v1.0.8, Dist::Zilla version 5.021, CPAN::Meta::Converter version 2.142690", "license" : [ "perl_5" ], "meta-spec" : { "url" : "http://search.cpan.org/perldoc?CPAN::Meta::Spec", "version" : "2" }, "name" : "Net-Abuse-Utils", "no_index" : { "directory" : [ "t", "xt", "inc", "share", "eg", "examples" ] }, "prereqs" : { "configure" : { "requires" : { "ExtUtils::MakeMaker" : "0" } }, "develop" : { "requires" : { "Dist::Milla" : "v1.0.8", "Test::Pod" : "1.41" } }, "runtime" : { "requires" : { "Email::Address" : "0", "Net::DNS" : "0", "Net::IP" : "0", "Net::Whois::IP" : "1.11", "perl" : "5.006" } } }, "release_status" : "stable", "resources" : { "bugtracker" : { "web" : "https://github.com/mikegrb/Net-Abuse-Utils/issues" }, "homepage" : "https://github.com/mikegrb/Net-Abuse-Utils", "repository" : { "type" : "git", "url" : "https://github.com/mikegrb/Net-Abuse-Utils.git", "web" : "https://github.com/mikegrb/Net-Abuse-Utils" } }, "version" : "0.25", "x_contributors" : [ "Wes Young " ] } Net-Abuse-Utils-0.25/META.yml000644 000765 000024 00000001623 12727407345 016523 0ustar00michaelgstaff000000 000000 --- abstract: 'Routines useful for processing network abuse' author: - 'mikegrb ' - 'Wes Young ' build_requires: {} configure_requires: ExtUtils::MakeMaker: '0' dynamic_config: 0 generated_by: 'Dist::Milla version v1.0.8, Dist::Zilla version 5.021, CPAN::Meta::Converter version 2.142690' license: perl meta-spec: url: http://module-build.sourceforge.net/META-spec-v1.4.html version: '1.4' name: Net-Abuse-Utils no_index: directory: - t - xt - inc - share - eg - examples requires: Email::Address: '0' Net::DNS: '0' Net::IP: '0' Net::Whois::IP: '1.11' perl: '5.006' resources: bugtracker: https://github.com/mikegrb/Net-Abuse-Utils/issues homepage: https://github.com/mikegrb/Net-Abuse-Utils repository: https://github.com/mikegrb/Net-Abuse-Utils.git version: '0.25' x_contributors: - 'Wes Young ' Net-Abuse-Utils-0.25/README000644 000765 000024 00000012034 12727407345 016130 0ustar00michaelgstaff000000 000000 NAME Net::Abuse::Utils - Routines useful for processing network abuse VERSION version 0.25 SYNOPSIS use Net::Abuse::Utils qw( :all ); print "IP Whois Contacts: ", join( ' ', get_ipwi_contacts($ip) ), "\n"; print "Abuse.net Contacts: ", get_abusenet_contact($domain), "\n"; DESCRIPTION Net::Abuse::Utils provides serveral functions useful for determining information about an IP address including contact/reporting addresses, ASN/network info, reverse dns, and DNSBL listing status. Functions which take an IP accept either IPv6 or IPv4 IPs unless indicated otherwise. NAME Net::Abuse::Utils - Routines useful for processing network abuse VERSION version 0.24 CONFIGURATION There is a @RESOLVERS package variable you can use to specify name servers different than the systems nameservers for queries from this module. If you intend to use Google's nameservers here, please see This issue on GitHub for a note of caution . FUNCTIONS The following functions are exportable from this module. You may import all of them into your namespace with the ":all" tag. get_asn_info ( IP ) Returns a list containing (ASN, Network/Mask, CC code, RIR, modified date) for the network announcing "IP". get_all_asn_info ( IP ) Returns a reference to a list of listrefs containting ASN(s), Network,Mask, CC code, RIR, and modified date fall all networks announcing "IP". get_peer_info ( IP ) IPv4 Only. Returns an array of hash references containing (ASN, Network/Mask, CC code, RIR, modified date) for the peers of the network announcing "IP". get_as_description ( ASN ) Returns the AS description for "ASN". get_as_company ( ASN ) Similiar to "get_as_description" but attempts to clean it up some before returning it. get_soa_contact( IP ) Returns the SOA contact email address for the reverse DNS /24 zone containing "IP". get_ipwi_contacts( IP ) Returns a list of all email addresses found in whois information for "IP" with duplicates removed. get_rdns( IP ) Returns the reverse PTR for "IP". get_dnsbl_listing( IP, DNSBL zone ) IPv4 Only. Returns the listing text for "IP" for the designated DNSBL. "DNSBL zone" should be the zone used for looking up addresses in the blocking list. get_ip_country( IP ) Returns the 2 letter country code for "IP". get_asn_country( ASN ) Returns the 2 letter country code for "ASN". get_abusenet_contact ( domain ) Returns the abuse.net listed contact email addresses for "domain". is_ip ( IP ) Returns true if "IP" looks like an IP, false otherwise. get_domain ( IP ) Takes a hostname and attempts to return the domain name. get_malware ( md5 ) Takes a malware md5 hash and tests it against http://www.team-cymru.org/Services/MHR. Returns a HASHREF of last_seen and detection_rate. DIAGNOSTICS Each subroutine will return undef if unsuccessful. In the furture, debugging output will be available. CONFIGURATION AND ENVIRONMENT There are two commented out lines that can be uncommented to enable Memoize support. I haven't yet decided whether to include this option by default. It may be made available in the future via an import flag to use. DEPENDENCIES This module makes use of the following modules: Net::IP, Net::DNS, Net::Whois::IP, and Email::Address BUGS AND LIMITATIONS There are no known bugs in this module. Please report problems to Michael Greb (mgreb@linode.com) Patches are welcome. ACKNOWLEDGEMENTS This module was inspired by Karsten M. Self's SpamTools shell scripts, available at http://linuxmafia.com/~karsten/. Thanks as well to my employer, Linode.com, for allowing me the time to work on this module. Rik Rose, Jon Honeycutt, Brandon Hale, TJ Fontaine, A. Pagaltzis, and Heidi Greb all provided invaluable input during the development of this module. SEE ALSO For a detailed usage example, please see examples/ip-info.pl included in this module's distribution. AUTHORS * mikegrb * Wes Young COPYRIGHT AND LICENSE This software is copyright (c) 2013 by Mike Greb. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. AUTHORS * mikegrb * Wes Young COPYRIGHT AND LICENSE This software is copyright (c) 2013 by =over 4. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. AUTHORS * mikegrb * Wes Young COPYRIGHT AND LICENSE This software is copyright (c) 2013 by =over 4. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. Net-Abuse-Utils-0.25/t/000755 000765 000024 00000000000 12727407345 015513 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/t/Net-Abuse-Utils-offline.t000644 000765 000024 00000000716 12727407345 022205 0ustar00michaelgstaff000000 000000 use Test::More; BEGIN { use_ok('Net::Abuse::Utils') } ok( Net::Abuse::Utils::is_ip('127.0.0.1'), 'is_ip with valid ip' ); ok( !Net::Abuse::Utils::is_ip('192.168.293.3'), 'is_ip with invalid ip' ); ok( Net::Abuse::Utils::is_ip('2600:3c00::2:2001'), 'is_ip with valid v6' ); ok( Net::Abuse::Utils::is_ip('::1'), 'is_ip with localhost' ); ok( !Net::Abuse::Utils::is_ip('2600:3c00::h:2001'), 'is_ip with invalid v6' ); done_testing(); Net-Abuse-Utils-0.25/t/Net-Abuse-Utils.t000644 000765 000024 00000005004 12727407345 020560 0ustar00michaelgstaff000000 000000 BEGIN { unless ($ENV{RELEASE_TESTING} || $ENV{ONLINE_TESTS}) { require Test::More; Test::More::plan(skip_all=>'these online tests require env variable ONLINE_TESTS be set to run'); } } use Test::More; BEGIN { use_ok('Net::Abuse::Utils') }; ######################### use Net::Abuse::Utils qw ( :all ); # these depend on network access, silly I know # future versions will override the modules used by Net::Abuse::Utils # to hand it static data my $ip = '67.18.92.99'; is ( get_abusenet_contact('linode.com') , 'abuse@linode.com', 'abuse.net lookup' ); is ( get_soa_contact('209.123.233.241') , 'dnsadmin@nac.net', 'soa contact' ); is ( get_ip_country($ip) , 'US', 'IP Country lookup' ); is ( get_ip_country('2600:3c00::2:200') , 'US', 'IPv6 Country lookup' ); ok ( !get_ip_country('127.0.0.1'), 'IP Country lookup with bad ip'); is ( get_rdns($ip) , 'li8-99.members.linode.com', 'get_rdns' ); ok ( (get_asn_info($ip))[0] =~ /^\d+$/, 'ASN from IP' ); is ( get_asn_country(21844) , 'US', 'AS Country lookup' ); ok ( !get_asn_country('urmom') , 'AS Country lookup w/ invalid ASN'); ok ( get_as_description(21844) , 'AS Description' ); ok ( get_as_company(21844) , 'AS Company' ); is ( get_domain('some.co.uk') , 'some.co.uk', 'get_domain' ); is ( get_domain('host.some.co.uk') , 'some.co.uk', 'get_domain' ); is ( get_domain('some.com') , 'some.com', 'get_domain' ); is ( get_domain('host.some.com') , 'some.com', 'get_domain' ); ok ( get_dnsbl_listing('127.0.0.2', 'bl.spamcop.net'), 'DNSBL listing check' ); like ( join(' ',get_ipwi_contacts('67.18.92.99')), qr/\w+@\w+/, 'whois contacts'); $ip = '216.87.155.0'; # AS | IP | AS Name #36619 | 216.87.155.0 | CGTLD - VeriSign Global Registry Services, US #36625 | 216.87.155.0 | KGTLD - VeriSign Global Registry Services, US #36628 | 216.87.155.0 | LGTLD - VeriSign Global Registry Services, US #36632 | 216.87.155.0 | XGTLD - VeriSign Global Registry Services, US ok(get_asn_info($ip), 'get_asn_info with multiple results..'); ok(get_peer_info($ip), 'get_peer_info with multiple results..'); done_testing; Net-Abuse-Utils-0.25/t/pod-coverage.t000644 000765 000024 00000000240 12727407345 020247 0ustar00michaelgstaff000000 000000 use Test::More; eval "use Test::Pod::Coverage 1.00"; plan skip_all => "Test::Pod::Coverage 1.00 required for testing POD coverage" if $@; all_pod_coverage_ok();Net-Abuse-Utils-0.25/t/pod.t000644 000765 000024 00000000200 12727407345 016452 0ustar00michaelgstaff000000 000000 use Test::More; eval "use Test::Pod 1.00"; plan skip_all => "Test::Pod 1.00 required for testing POD" if $@; all_pod_files_ok();Net-Abuse-Utils-0.25/t/release-pod-syntax.t000644 000765 000024 00000000456 12727407345 021431 0ustar00michaelgstaff000000 000000 #!perl BEGIN { unless ($ENV{RELEASE_TESTING}) { require Test::More; Test::More::plan(skip_all => 'these tests are for release candidate testing'); } } # This file was automatically generated by Dist::Zilla::Plugin::PodSyntaxTests. use Test::More; use Test::Pod 1.41; all_pod_files_ok(); Net-Abuse-Utils-0.25/lib/Net/000755 000765 000024 00000000000 12727407345 016544 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/lib/Net/Abuse/000755 000765 000024 00000000000 12727407345 017603 5ustar00michaelgstaff000000 000000 Net-Abuse-Utils-0.25/lib/Net/Abuse/Utils.pm000644 000765 000024 00000065155 12727407345 021255 0ustar00michaelgstaff000000 000000 package Net::Abuse::Utils; # ABSTRACT: Routines useful for processing network abuse use 5.006; use strict; use warnings; use Net::DNS; use Net::Whois::IP 1.11 'whoisip_query'; use Email::Address; use Net::IP; # use Memoize; require Exporter; our @ISA = qw(Exporter); our %EXPORT_TAGS = ( 'all' => [ qw( get_asn_info get_peer_info get_as_description get_soa_contact get_ipwi_contacts get_rdns get_dnsbl_listing get_ip_country get_asn_country get_abusenet_contact is_ip get_as_company get_domain get_malware ) ] ); our @EXPORT_OK = ( @{ $EXPORT_TAGS{'all'} } ); our $VERSION = '0.25'; $VERSION = eval $VERSION; # memoize('_return_rr'); my @tlds; our @RESOLVERS; sub _reverse_ip { my $ip = shift; my $ver = Net::IP::ip_get_version($ip); my @parts = split( /\./, Net::IP::ip_reverse( $ip, $ver == 4 ? 32 : 128 ) ); # strip in-addr.arp or ip6.arpa from results return join('.', @parts[0 .. $#parts-2]); } sub _return_rr { my $lookup = shift; my $rr_type = shift; my $concat = shift; my @result; my $res = Net::DNS::Resolver->new( ); $res->nameservers(@RESOLVERS) if @RESOLVERS; my $query = $res->query($lookup, $rr_type); if ($query) { foreach my $rr ($query->answer) { if ($rr->type eq $rr_type) { if ($rr_type eq 'TXT') { push @result, $rr->txtdata; } elsif ($rr_type eq 'SOA') { push @result, $rr->rname; } elsif ($rr_type eq 'PTR') { push @result, $rr->ptrdname; } last if !$concat; } } if ($concat && $concat == 2) { return @result; } else { return join ' ', @result; } } return; } sub _return_unique { my $array_ref = shift; my %unique_elements; foreach my $element (@$array_ref) { $unique_elements{ $element }++; } return keys %unique_elements; } sub _strip_whitespace { my $string = shift; return unless $string; for ($string) { s/^\s+//; s/\s+$//; } return $string; } sub get_ipwi_contacts { my $ip = shift; my $ver = Net::IP::ip_get_version($ip); return unless $ver; my @addresses; my %unique_addresses; # work-around for the new way arin works # it doesn't like networks very well. my @bits = split(/\//,$ip); $ip = $bits[0] if($#bits > 0); my $response = whoisip_query($ip); # whoisip_query returns array ref if not found return unless ref($response) eq 'HASH'; foreach my $field (keys %$response) { push @addresses, Email::Address->parse($response->{$field}); } @addresses = map { $_->address } @addresses; return _return_unique (\@addresses); } sub get_all_asn_info { my $ip = shift; my $ver = Net::IP::ip_get_version($ip); return unless $ver; my $domain = ( $ver == 4 ) ? '.origin.asn.cymru.com' : '.origin6.asn.cymru.com'; my $lookup = _reverse_ip($ip) . $domain; my $data = [ _return_rr( $lookup, 'TXT', 2 ) ] or return; # Separate fields and order by netmask length # 23028 | 216.90.108.0/24 | US | arin | 1998-09-25 # 701 1239 3549 3561 7132 | 216.90.108.0/24 | US | arin | 1998-09-25 for my $asinfo (@$data) { $asinfo = { data => [ split m/ \| /, $asinfo ] }; $asinfo->{length} = ( split m|/|, $asinfo->{data}[1] )[1]; } $data = [ map { $_->{data} } reverse sort { $a->{length} <=> $b->{length} } @$data ]; return $data; } sub get_asn_info { my $data = get_all_asn_info(shift); return unless $data && @$data; # just the first AS if multiple ASes are listed if ($data->[0][0] =~ /^(\d+) \d+/) { $data->[0][0] = $1; } # return just the first result, as a list return @{ $data->[0] }; } sub get_peer_info { my $ip = shift; # IPv4 only until Cymru has an IPv6 peer database my $ver = Net::IP::ip_get_version($ip); return unless $ver && $ver == 4; my $lookup = _reverse_ip($ip) . '.peer.asn.cymru.com'; my @origin_as = _return_rr($lookup, 'TXT', 2) or return; my $return = []; foreach my $as (@origin_as){ my @peers = split(/\s\|\s?/,$as); my %hash = ( prefix => $peers[1], cc => $peers[2], rir => $peers[3], date => $peers[4], ); my @asns = split(/\s/,$peers[0]); foreach (@asns){ $hash{'asn'} = $_; push(@$return,{ prefix => $peers[1], cc => $peers[2], rir => $peers[3], date => $peers[4], asn => $_, }); } } return(@$return) if wantarray; return($return); } # test with 733a48a9cb49651d72fe824ca91e8d00 # http://www.team-cymru.org/Services/MHR/ sub get_malware { my $hash = shift; return unless($hash && lc($hash) =~ /^[a-z0-9]{32}$/); my $lookup = $hash.'.malware.hash.cymru.com'; my $res = _return_rr($lookup, 'TXT') or return; my ($last_seen,$detection_rate) = split(/ /,$res); return({ last_seen => $last_seen, detection_rate => $detection_rate, }); } sub get_as_description { my $asn = shift; my @ASdata; if ( my $data = _return_rr( "AS${asn}.asn.cymru.com", 'TXT' ) ) { @ASdata = split( '\|', $data ); } else { return; } return unless $ASdata[4]; my $org = _strip_whitespace( $ASdata[4] ); # for arin we get "HANDLE - AS Org" # we want to make it "HANDLE AS Org" to match other RIRs $org =~ s/^(\S+) - (.*)$/$1 $2/ if ( $ASdata[2] eq ' arin ' ); return $org; } sub get_as_company { my $asn = shift; my $desc = get_as_description($asn); return unless defined($desc); # remove leading org id/handle/etc $desc =~ s/^[-_A-Z0-9]+ //; # remove trailing 'AS' $desc =~ s/AS(:? Number)?$//; # remove trailing 'Autonomous System' $desc =~ s/Autonomous System(:? Number)?$//i; return $desc; } sub get_soa_contact { my $ip = shift; my $lookup = _reverse_ip($ip) . '.in-addr.arpa'; $lookup =~ s/^\d+\.//; if ( my $soa_contact = _return_rr($lookup, 'SOA') ) { $soa_contact =~ s/\./@/ unless $soa_contact =~ m/@/; return $soa_contact; } return; } sub get_rdns { my $ip = shift; my $ver = Net::IP::ip_get_version($ip); return unless $ver; my $suffix = ($ver == 4) ? '.in-addr.arpa' : '.ip6.arpa'; return _return_rr( _reverse_ip($ip) . $suffix, 'PTR'); } sub get_dnsbl_listing { my ($ip, $dnsbl) = @_; # IPv4 Only my $ver = Net::IP::ip_get_version($ip); return unless $ver && $ver == 4; my $lookup = join '.', _reverse_ip( $ip ), $dnsbl; return _return_rr($lookup, 'TXT', 1); } sub get_ip_country { my $ip = shift; return (get_asn_info($ip))[2]; } sub get_asn_country { my $asn = shift; return unless $asn =~ /^\d+$/; my $as_cc = (split (/\|/,_return_rr("AS${asn}.asn.cymru.com", 'TXT')))[1]; if ($as_cc) { return _strip_whitespace($as_cc); } return; } sub get_abusenet_contact { my $domain = shift; return _return_rr("$domain.contacts.abuse.net", 'TXT', 1) } sub is_ip { my $ip = shift; return defined Net::IP::ip_get_version($ip); } sub get_domain { my $hostname = shift; @tlds = grep {!/^#/} unless scalar @tlds; my @parts = reverse (split /\./, $hostname); if (scalar @parts == 2) { # just two parts, lets return it return join '.', @parts[1, 0]; } if (grep /^\Q$parts[1].$parts[0]\E$/, @tlds) { # last two parts found in tlds return join '.', @parts[2, 1, 0]; } else { # last two not found so *host.domain.name return join '.', @parts[1, 0]; } } 1; =pod =encoding UTF-8 =head1 NAME Net::Abuse::Utils - Routines useful for processing network abuse =head1 VERSION version 0.25 =head1 SYNOPSIS use Net::Abuse::Utils qw( :all ); print "IP Whois Contacts: ", join( ' ', get_ipwi_contacts($ip) ), "\n"; print "Abuse.net Contacts: ", get_abusenet_contact($domain), "\n"; =head1 DESCRIPTION Net::Abuse::Utils provides serveral functions useful for determining information about an IP address including contact/reporting addresses, ASN/network info, reverse dns, and DNSBL listing status. Functions which take an IP accept either IPv6 or IPv4 IPs unless indicated otherwise. =head1 NAME Net::Abuse::Utils - Routines useful for processing network abuse =head1 VERSION version 0.24 =head1 CONFIGURATION There is a C<@RESOLVERS> package variable you can use to specify name servers different than the systems nameservers for queries from this module. If you intend to use Google's nameservers here, please see L. =head1 FUNCTIONS The following functions are exportable from this module. You may import all of them into your namespace with the C<:all> tag. =head2 get_asn_info ( IP ) Returns a list containing (ASN, Network/Mask, CC code, RIR, modified date) for the network announcing C. =head2 get_all_asn_info ( IP ) Returns a reference to a list of listrefs containting ASN(s), Network,Mask, CC code, RIR, and modified date fall all networks announcing C. =head2 get_peer_info ( IP ) IPv4 Only. Returns an array of hash references containing (ASN, Network/Mask, CC code, RIR, modified date) for the peers of the network announcing C. =head2 get_as_description ( ASN ) Returns the AS description for C. =head2 get_as_company ( ASN ) Similiar to C but attempts to clean it up some before returning it. =head2 get_soa_contact( IP ) Returns the SOA contact email address for the reverse DNS /24 zone containing C. =head2 get_ipwi_contacts( IP ) Returns a list of all email addresses found in whois information for C with duplicates removed. =head2 get_rdns( IP ) Returns the reverse PTR for C. =head2 get_dnsbl_listing( IP, DNSBL zone ) IPv4 Only. Returns the listing text for C for the designated DNSBL. C should be the zone used for looking up addresses in the blocking list. =head2 get_ip_country( IP ) Returns the 2 letter country code for C. =head2 get_asn_country( ASN ) Returns the 2 letter country code for C. =head2 get_abusenet_contact ( domain ) Returns the abuse.net listed contact email addresses for C. =head2 is_ip ( IP ) Returns true if C looks like an IP, false otherwise. =head2 get_domain ( IP ) Takes a hostname and attempts to return the domain name. =head2 get_malware ( md5 ) Takes a malware md5 hash and tests it against http://www.team-cymru.org/Services/MHR. Returns a HASHREF of last_seen and detection_rate. =head1 DIAGNOSTICS Each subroutine will return undef if unsuccessful. In the furture, debugging output will be available. =head1 CONFIGURATION AND ENVIRONMENT There are two commented out lines that can be uncommented to enable Memoize support. I haven't yet decided whether to include this option by default. It may be made available in the future via an import flag to use. =head1 DEPENDENCIES This module makes use of the following modules: L, L, L, and L =head1 BUGS AND LIMITATIONS There are no known bugs in this module. Please report problems to Michael Greb (mgreb@linode.com) Patches are welcome. =head1 ACKNOWLEDGEMENTS This module was inspired by Karsten M. Self's SpamTools shell scripts, available at http://linuxmafia.com/~karsten/. Thanks as well to my employer, Linode.com, for allowing me the time to work on this module. Rik Rose, Jon Honeycutt, Brandon Hale, TJ Fontaine, A. Pagaltzis, and Heidi Greb all provided invaluable input during the development of this module. =head1 SEE ALSO For a detailed usage example, please see examples/ip-info.pl included in this module's distribution. =head1 AUTHORS =over 4 =item * mikegrb =item * Wes Young =back =head1 COPYRIGHT AND LICENSE This software is copyright (c) 2013 by Mike Greb. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. =head1 AUTHORS =over 4 =item * mikegrb =item * Wes Young =back =head1 COPYRIGHT AND LICENSE This software is copyright (c) 2013 by =over 4. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. =head1 AUTHORS =over 4 =item * mikegrb =item * Wes Young =back =head1 COPYRIGHT AND LICENSE This software is copyright (c) 2013 by =over 4. This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself. =cut __DATA__ # from http://spamcheck.freeapp.net/two-level-tlds # a source for more current/kept up to date data would be greatly # appreciated 2000.hu ab.ca ab.se abo.pa ac.ae ac.am ac.at ac.bd ac.be ac.cn ac.com ac.cr ac.cy ac.fj ac.fk ac.gg ac.gn ac.hu ac.id ac.il ac.im ac.in ac.ir ac.je ac.jp ac.ke ac.kr ac.lk ac.ma ac.mw ac.ng ac.nz ac.om ac.pa ac.pg ac.rs ac.ru ac.rw ac.se ac.th ac.tj ac.tz ac.ug ac.uk ac.vn ac.yu ac.za ac.zm ac.zw act.au ad.jp adm.br adult.ht adv.br adygeya.ru aero.mv aero.tt aeroport.fr agr.br agrar.hu agro.pl ah.cn aichi.jp aid.pl ak.us akita.jp al.us aland.fi alderney.gg alt.na alt.za altai.ru am.br amur.ru amursk.ru aomori.jp ar.us arkhangelsk.ru army.mil arq.br art.br art.do art.dz art.ht art.pl arts.co arts.ro arts.ve asn.au asn.lv ass.dz assedic.fr assn.lk asso.dz asso.fr asso.gp asso.ht asso.mc asso.re astrakhan.ru at.tf at.tt atm.pl ato.br au.com au.tt auto.pl av.tr avocat.fr avoues.fr az.us baikal.ru barreau.fr bashkiria.ru bbs.tr bc.ca bd.se be.tt bel.tr belgie.be belgorod.ru bg.tf bialystok.pl bib.ve bio.br bir.ru biz.az biz.bh biz.cy biz.et biz.fj biz.ly biz.mv biz.nr biz.om biz.pk biz.pl biz.pr biz.tj biz.tr biz.tt biz.vn bj.cn bl.uk bmd.br bolt.hu bourse.za br.com brand.se british-library.uk bryansk.ru buryatia.ru busan.kr c.se ca.tf ca.tt ca.us casino.hu cbg.ru cc.bh cci.fr ch.tf ch.vu chambagri.fr chel.ru chelyabinsk.ru cherkassy.ua chernigov.ua chernovtsy.ua chiba.jp chirurgiens-dentistes.fr chita.ru chukotka.ru chungbuk.kr chungnam.kr chuvashia.ru cim.br city.hu city.za ck.ua club.tw cmw.ru cn.com cn.ua cng.br cnt.br co.ae co.ag co.am co.ao co.at co.ba co.bw co.ck co.cr co.dk co.ee co.fk co.gg co.hu co.id co.il co.im co.in co.ir co.je co.jp co.ke co.kr co.ls co.ma co.mu co.mw co.mz co.nz co.om co.rs co.rw co.st co.th co.tj co.tt co.tv co.tz co.ua co.ug co.uk co.us co.uz co.ve co.vi co.yu co.za co.zm co.zw com.ac com.ae com.af com.ag com.ai com.al com.am com.an com.ar com.au com.aw com.az com.ba com.bb com.bd com.bh com.bm com.bn com.bo com.br com.bs com.bt com.bz com.cd com.ch com.cn com.co com.cu com.cy com.dm com.do com.dz com.ec com.ee com.eg com.er com.es com.et com.fj com.fk com.fr com.ge com.gh com.gi com.gn com.gp com.gr com.gt com.gu com.hk com.hn com.hr com.ht com.io com.jm com.jo com.kg com.kh com.ki com.kw com.ky com.kz com.la com.lb com.lc com.li com.lk com.lr com.lv com.ly com.mg com.mk com.mm com.mn com.mo com.mt com.mu com.mv com.mw com.mx com.my com.na com.nc com.nf com.ng com.ni com.np com.nr com.om com.pa com.pe com.pf com.pg com.ph com.pk com.pl com.pr com.ps com.pt com.py com.qa com.re com.ro com.ru com.rw com.sa com.sb com.sc com.sd com.sg com.sh com.st com.sv com.sy com.tj com.tn com.tr com.tt com.tw com.ua com.uy com.uz com.vc com.ve com.vi com.vn com.vu com.ws com.ye conf.au conf.lv consulado.st coop.br coop.ht coop.mv coop.mw coop.tt cpa.pro cq.cn cri.nz crimea.ua csiro.au ct.us cul.na cv.ua cz.tf d.se daegu.kr daejeon.kr dagestan.ru dc.us de.com de.net de.tf de.tt de.us de.vu dk.org dk.tt dn.ua dnepropetrovsk.ua dni.us dns.be donetsk.ua dp.ua dpn.br dr.tr dudinka.ru e-burg.ru e.se e164.arpa ebiz.tw ecn.br ed.ao ed.cr ed.jp edu.ac edu.af edu.ai edu.al edu.am edu.an edu.ar edu.au edu.az edu.ba edu.bb edu.bd edu.bh edu.bm edu.bn edu.bo edu.br edu.bt edu.ck edu.cn edu.co edu.cu edu.dm edu.do edu.dz edu.ec edu.ee edu.eg edu.er edu.es edu.et edu.ge edu.gh edu.gi edu.gp edu.gr edu.gt edu.gu edu.hk edu.hn edu.ht edu.hu edu.in edu.it edu.jm edu.jo edu.kg edu.kh edu.kw edu.ky edu.kz edu.lb edu.lc edu.lk edu.lr edu.lv edu.ly edu.mg edu.mm edu.mn edu.mo edu.mt edu.mv edu.mw edu.mx edu.my edu.na edu.ng edu.ni edu.np edu.nr edu.om edu.pa edu.pe edu.pf edu.ph edu.pk edu.pl edu.pr edu.ps edu.pt edu.py edu.qa edu.rs edu.ru edu.rw edu.sa edu.sb edu.sc edu.sd edu.sg edu.sh edu.sk edu.st edu.sv edu.tf edu.tj edu.tr edu.tt edu.tw edu.ua edu.uk edu.uy edu.ve edu.vi edu.vn edu.vu edu.ws edu.ye edu.yu edu.za edunet.tn ehime.jp ekloges.cy embaixada.st eng.br ens.tn ernet.in erotica.hu erotika.hu es.kr es.tt esp.br etc.br eti.br eu.com eu.org eu.tf eu.tt eun.eg experts-comptables.fr f.se fam.pk far.br fareast.ru fax.nr fed.us fgov.be fh.se fhs.no fhsk.se fhv.se fi.cr fie.ee film.hu fin.ec fin.tn firm.co firm.ht firm.in firm.ro firm.ve fj.cn fl.us fm.br fnd.br folkebibl.no forum.hu fot.br fr.tt fr.vu from.hr fst.br fukui.jp fukuoka.jp fukushima.jp fylkesbibl.no g.se g12.br ga.us game.tw games.hu gangwon.kr gb.com gb.net gc.ca gd.cn gda.pl gdansk.pl geek.nz gen.in gen.nz gen.tr geometre-expert.fr ggf.br gifu.jp gmina.pl go.cr go.id go.jp go.ke go.kr go.th go.tj go.tz go.ug gob.bo gob.do gob.es gob.gt gob.hn gob.mx gob.ni gob.pa gob.pe gob.pk gob.sv gok.pk gon.pk gop.pk gos.pk gouv.fr gouv.ht gouv.rw gov.ac gov.ae gov.af gov.ai gov.al gov.am gov.ar gov.au gov.az gov.ba gov.bb gov.bd gov.bf gov.bh gov.bm gov.bo gov.br gov.bt gov.by gov.ch gov.ck gov.cn gov.co gov.cu gov.cx gov.cy gov.dm gov.do gov.dz gov.ec gov.eg gov.er gov.et gov.fj gov.fk gov.ge gov.gg gov.gh gov.gi gov.gn gov.gr gov.gu gov.hk gov.hu gov.ie gov.il gov.im gov.in gov.io gov.ir gov.it gov.je gov.jm gov.jo gov.jp gov.kg gov.kh gov.kw gov.ky gov.kz gov.lb gov.lc gov.li gov.lk gov.lr gov.lt gov.lu gov.lv gov.ly gov.ma gov.mg gov.mm gov.mn gov.mo gov.mt gov.mv gov.mw gov.my gov.ng gov.np gov.nr gov.om gov.ph gov.pk gov.pl gov.pr gov.ps gov.pt gov.py gov.qa gov.rs gov.ru gov.rw gov.sa gov.sb gov.sc gov.sd gov.sg gov.sh gov.sk gov.st gov.sy gov.tj gov.tn gov.to gov.tp gov.tr gov.tt gov.tv gov.tw gov.ua gov.uk gov.ve gov.vi gov.vn gov.ws gov.ye gov.za gov.zm gov.zw govt.nz gr.jp greta.fr grozny.ru grp.lk gs.cn gsm.pl gub.uy guernsey.gg gunma.jp gv.ao gv.at gwangju.kr gx.cn gyeongbuk.kr gyeonggi.kr gyeongnam.kr gz.cn h.se ha.cn hb.cn he.cn health.vn herad.no hi.cn hi.us hiroshima.jp hk.cn hl.cn hn.cn hokkaido.jp hotel.hu hotel.lk hs.kr hu.com huissier-justice.fr hyogo.jp i.se ia.us ibaraki.jp icnet.uk id.au id.fj id.ir id.lv id.ly id.us idf.il idn.sg idrett.no idv.hk idv.tw if.ua il.us imb.br in-addr.arpa in.rs in.th in.ua in.us incheon.kr ind.br ind.er ind.gg ind.gt ind.in ind.je ind.tn inf.br inf.cu info.au info.az info.bh info.co info.cu info.cy info.ec info.et info.fj info.ht info.hu info.mv info.nr info.pl info.pr info.ro info.sd info.tn info.tr info.tt info.ve info.vn ing.pa ingatlan.hu inima.al int.am int.ar int.az int.bo int.co int.lk int.mv int.mw int.pt int.ru int.rw int.tf int.tj int.tt int.ve int.vn intl.tn ip6.arpa iris.arpa irkutsk.ru isa.us ishikawa.jp isla.pr it.ao it.tt ivano-frankivsk.ua ivanovo.ru iwate.jp iwi.nz iz.hr izhevsk.ru jamal.ru jar.ru jeju.kr jeonbuk.kr jeonnam.kr jersey.je jet.uk jl.cn jobs.tt jogasz.hu jor.br joshkar-ola.ru js.cn jx.cn k-uralsk.ru k.se k12.ec k12.il k12.tr kagawa.jp kagoshima.jp kalmykia.ru kaluga.ru kamchatka.ru kanagawa.jp kanazawa.jp karelia.ru katowice.pl kawasaki.jp kazan.ru kchr.ru kemerovo.ru kg.kr kh.ua khabarovsk.ru khakassia.ru kharkov.ua kherson.ua khmelnitskiy.ua khv.ru kids.us kiev.ua kirov.ru kirovograd.ua kitakyushu.jp km.ua kms.ru kobe.jp kochi.jp koenig.ru komforb.se komi.ru kommunalforbund.se kommune.no komvux.se konyvelo.hu kostroma.ru kr.ua krakow.pl krasnoyarsk.ru ks.ua ks.us kuban.ru kumamoto.jp kurgan.ru kursk.ru kustanai.ru kuzbass.ru kv.ua ky.us kyonggi.kr kyoto.jp la.us lakas.hu lanarb.se lanbib.se law.pro law.za lel.br lg.jp lg.ua lipetsk.ru lkd.co.im ln.cn lodz.pl ltd.co.im ltd.cy ltd.gg ltd.gi ltd.je ltd.lk ltd.uk lublin.pl lugansk.ua lutsk.ua lviv.ua m.se ma.us magadan.ru magnitka.ru mail.pl maori.nz mari-el.ru mari.ru marine.ru mat.br matsuyama.jp mb.ca md.us me.uk me.us med.br med.ec med.ee med.ht med.ly med.om med.pa med.pro med.sa med.sd medecin.fr media.hu media.pl mi.th mi.us miasta.pl mie.jp mil.ac mil.ae mil.am mil.ar mil.az mil.ba mil.bd mil.bo mil.br mil.by mil.co mil.do mil.ec mil.eg mil.er mil.fj mil.ge mil.gh mil.gt mil.gu mil.hn mil.id mil.in mil.io mil.jo mil.kg mil.kh mil.kr mil.kw mil.kz mil.lb mil.lt mil.lu mil.lv mil.mg mil.mv mil.my mil.no mil.np mil.nz mil.om mil.pe mil.ph mil.pl mil.ru mil.rw mil.se mil.sh mil.sk mil.st mil.tj mil.tr mil.tw mil.uk mil.uy mil.ve mil.ye mil.za miyagi.jp miyazaki.jp mk.ua mn.us mo.cn mo.us mob.nr mobi.tt mobil.nr mobile.nr mod.gi mod.om mod.uk mordovia.ru mosreg.ru ms.kr ms.us msk.ru mt.us muni.il murmansk.ru mus.br museum.mn museum.mv museum.mw museum.no museum.om museum.tt music.mobi mytis.ru n.se nagano.jp nagasaki.jp nagoya.jp nakhodka.ru nalchik.ru name.ae name.az name.cy name.et name.fj name.hr name.mv name.my name.pr name.tj name.tr name.tt name.vn nara.jp nat.tn national-library-scotland.uk naturbruksgymn.se navy.mil nb.ca nc.us nd.us ne.jp ne.ke ne.kr ne.tz ne.ug ne.us nel.uk net.ac net.ae net.af net.ag net.ai net.al net.am net.an net.ar net.au net.az net.ba net.bb net.bd net.bh net.bm net.bn net.bo net.br net.bs net.bt net.bz net.cd net.ch net.ck net.cn net.co net.cu net.cy net.dm net.do net.dz net.ec net.eg net.er net.et net.fj net.fk net.ge net.gg net.gn net.gp net.gr net.gt net.gu net.hk net.hn net.ht net.id net.il net.im net.in net.io net.ir net.je net.jm net.jo net.jp net.kg net.kh net.ki net.kw net.ky net.kz net.la net.lb net.lc net.li net.lk net.lr net.lu net.lv net.ly net.ma net.mm net.mo net.mt net.mu net.mv net.mw net.mx net.my net.na net.nc net.nf net.ng net.ni net.np net.nr net.nz net.om net.pa net.pe net.pg net.ph net.pk net.pl net.pr net.ps net.pt net.py net.qa net.ru net.rw net.sa net.sb net.sc net.sd net.sg net.sh net.st net.sy net.tf net.th net.tj net.tn net.tr net.tt net.tw net.ua net.uk net.uy net.uz net.vc net.ve net.vi net.vn net.vu net.ws net.ye net.za new.ke news.hu nf.ca ngo.lk ngo.ph ngo.pl ngo.za nh.us nhs.uk nic.im nic.in nic.tt nic.uk nieruchomosci.pl niigata.jp nikolaev.ua nj.us nkz.ru nl.ca nls.uk nm.cn nm.us nnov.ru no.com nom.ad nom.ag nom.br nom.co nom.es nom.fk nom.fr nom.mg nom.ni nom.pa nom.pe nom.pl nom.re nom.ro nom.ve nom.za nome.pt norilsk.ru not.br notaires.fr nov.ru novosibirsk.ru ns.ca nsk.ru nsn.us nsw.au nt.au nt.ca nt.ro ntr.br nu.ca nui.hu nv.us nx.cn ny.us o.se od.ua odessa.ua odo.br off.ai og.ao oh.us oita.jp ok.us okayama.jp okinawa.jp olsztyn.pl omsk.ru on.ca opole.pl or.at or.cr or.id or.jp or.ke or.kr or.th or.tz or.ug or.us orenburg.ru org.ac org.ae org.ag org.ai org.al org.am org.an org.ar org.au org.az org.ba org.bb org.bd org.bh org.bm org.bn org.bo org.br org.bs org.bt org.bw org.bz org.cd org.ch org.ck org.cn org.co org.cu org.cy org.dm org.do org.dz org.ec org.ee org.eg org.er org.es org.et org.fj org.fk org.ge org.gg org.gh org.gi org.gn org.gp org.gr org.gt org.gu org.hk org.hn org.ht org.hu org.il org.im org.in org.io org.ir org.je org.jm org.jo org.jp org.kg org.kh org.ki org.kw org.ky org.kz org.la org.lb org.lc org.li org.lk org.lr org.ls org.lu org.lv org.ly org.ma org.mg org.mk org.mm org.mn org.mo org.mt org.mu org.mv org.mw org.mx org.my org.na org.nc org.ng org.ni org.np org.nr org.nz org.om org.pa org.pe org.pf org.ph org.pk org.pl org.pr org.ps org.pt org.py org.qa org.ro org.rs org.ru org.sa org.sb org.sc org.sd org.se org.sg org.sh org.st org.sv org.sy org.tj org.tn org.tr org.tt org.tw org.ua org.uk org.uy org.uz org.vc org.ve org.vi org.vn org.vu org.ws org.ye org.yu org.za org.zm org.zw oryol.ru osaka.jp oskol.ru otc.au oz.au pa.us palana.ru parliament.cy parliament.uk parti.se pb.ao pc.pl pe.ca pe.kr penza.ru per.kh per.sg perm.ru perso.ht pharmacien.fr pl.tf pl.ua plc.co.im plc.ly plc.uk plo.ps pol.dz pol.ht pol.tr police.uk poltava.ua port.fr powiat.pl poznan.pl pp.az pp.ru pp.se ppg.br prd.fr prd.mg press.cy press.ma press.se presse.fr pri.ee principe.st priv.at priv.hu priv.no priv.pl pro.ae pro.br pro.cy pro.ec pro.fj pro.ht pro.mv pro.om pro.pr pro.tt pro.vn psc.br psi.br pskov.ru ptz.ru pub.sa publ.pt pvt.ge pyatigorsk.ru qc.ca qc.com qh.cn qld.au qsl.br re.kr realestate.pl rec.br rec.co rec.ro rec.ve red.sv reklam.hu rel.ht rel.pl res.in ri.us rnd.ru rnrt.tn rns.tn rnu.tn rovno.ua rs.ba ru.com ru.tf rubtsovsk.ru rv.ua ryazan.ru s.se sa.au sa.com sa.cr saga.jp saitama.jp sakhalin.ru samara.ru saotome.st sapporo.jp saratov.ru sark.gg sc.cn sc.ke sc.kr sc.ug sc.us sch.ae sch.gg sch.id sch.ir sch.je sch.lk sch.ly sch.ng sch.om sch.sa sch.sd sch.uk sch.zm school.fj school.nz school.za sci.eg sd.cn sd.us se.com se.tt sebastopol.ua sec.ps sendai.jp seoul.kr sex.hu sex.pl sg.tf sh.cn shiga.jp shimane.jp shizuoka.jp shop.ht shop.hu shop.pl simbirsk.ru sk.ca sklep.pl sld.do sld.pa slg.br slupsk.pl smolensk.ru sn.cn snz.ru soc.lk soros.al sos.pl spb.ru sport.hu srv.br sshn.se stat.no stavropol.ru store.co store.ro store.st store.ve stv.ru suli.hu sumy.ua surgut.ru sx.cn syzran.ru szczecin.pl szex.hu szkola.pl t.se takamatsu.jp tambov.ru targi.pl tas.au tatarstan.ru te.ua tec.ve tel.no tel.nr tel.tr telecom.na telememo.au ternopil.ua test.ru tirana.al tj.cn tld.am tlf.nr tm.cy tm.fr tm.hu tm.mc tm.mg tm.mt tm.pl tm.ro tm.se tm.za tmp.br tn.us tochigi.jp tokushima.jp tokyo.jp tom.ru tomsk.ru torun.pl tottori.jp tourism.pl tourism.tn toyama.jp tozsde.hu travel.pl travel.tt trd.br tsaritsyn.ru tsk.ru tula.ru tur.br turystyka.pl tuva.ru tv.bo tv.br tv.sd tver.ru tw.cn tx.us tyumen.ru u.se udm.ru udmurtia.ru uk.com uk.net uk.tt ulan-ude.ru ulsan.kr unam.na unbi.ba uniti.al unsa.ba upt.al uri.arpa urn.arpa us.com us.tf us.tt ut.us utazas.hu utsunomiya.jp uu.mt uy.com uzhgorod.ua va.us vatican.va vdonsk.ru vet.br veterinaire.fr vgs.no vic.au video.hu vinnica.ua vladikavkaz.ru vladimir.ru vladivostok.ru vn.ua volgograd.ru vologda.ru voronezh.ru vrn.ru vt.us vyatka.ru w.se wa.au wa.us wakayama.jp warszawa.pl waw.pl weather.mobi web.co web.do web.id web.lk web.pk web.tj web.tr web.ve web.za wi.us wroc.pl wroclaw.pl wv.us www.ro wy.us x.se xj.cn xz.cn y.se yakutia.ru yamagata.jp yamaguchi.jp yamal.ru yamanashi.jp yaroslavl.ru yekaterinburg.ru yk.ca yn.cn yokohama.jp yuzhno-sakhalinsk.ru z.se za.com za.pl zaporizhzhe.ua zgora.pl zgrad.ru zhitomir.ua zj.cn zlg.br zp.ua zt.ua Net-Abuse-Utils-0.25/examples/ip-info.pl000755 000765 000024 00000004473 12727407345 020777 0ustar00michaelgstaff000000 000000 #!/usr/bin/env perl use strict; use warnings; use lib './lib'; use Net::Abuse::Utils qw( :all ); my %dnsbl = ( 'Spamhaus' => 'sbl-xbl.spamhause.org', 'SpamCop' => 'bl.spamcop.net', # 'Relays ORDB' => 'relays.ordb.org', 'Relays VISI' => 'relays.vsi.com', # 'Composite BL' => 'cbl.abuseat.org', 'Dynablock BL' => 'dnsbl.njabl.org', # 'DSBL Proxy' => 'list.dsbl.org', # 'DSBL Multihop' => 'multihop.dsbl.org', # 'SORBS OR' => 'dnsbl.sorbs.net', 'SPEWS L1' => 'l1.spews.dnsbl.sorbs.net', 'SPEWS L2' => 'l2.spews.dnsbl.sorbs.net', # 'Blitzed OPM' => 'opm.blitzed.org', ); my $ip = shift; if (!is_ip($ip)) { warn "$ip doesn't look like an IP.\n"; exit; } my $rdns = get_rdns($ip) || ''; print "IP Info:\n"; print "\tIP: $ip\n"; print "\tRDNS: $rdns\n"; print "\tIP Country: ", get_ip_country($ip), "\n"; print "\nAS Info:\n"; if (my @asn = get_asn_info($ip) ) { my $asn_org = get_as_description($asn[0]) || ''; my $asn_co = get_as_company($asn[0]) || ''; print "\tASN: $asn[0] - $asn[1]\n"; print "\tAS Org: $asn_org\n"; print "\tClean Org: $asn_co\n"; print "\tAS Country: ", get_asn_country($asn[0]), "\n"; print "\n"; my @peers = get_peer_info($ip); if($#peers > -1){ print "\nPeer Info"; foreach my $peer (@peers){ my $peer_org = get_as_description($peer->{'asn'}) || ''; my $peer_co = get_as_company($peer->{'asn'}) || ''; print "\n"; print "\tPeer: $peer->{'asn'}\n"; print "\tPeer Prefix: $peer->{'prefix'}\n"; print "\tPeer Org: $peer_org\n"; print "\tPeer Clean Org: $peer_co\n"; print "\tPeer Country: ".$peer->{'cc'}."\n"; } } } else { print "\tUnknown ASN\n"; } my $soa_contact = get_soa_contact($ip) || 'not found'; print "\nContact Addresses:\n"; print "\tPTR SOA Contact: $soa_contact\n"; print "\tIP Whois Contacts: ", join (' ', get_ipwi_contacts($ip) ), "\n"; if ($soa_contact =~ /\@(\S+)$/) { print "\tAbuse.net ($1): ", get_abusenet_contact($1), "\n"; } print "\nDNSBL Listings:\n"; foreach my $bl (keys %dnsbl) { my $txt = get_dnsbl_listing($ip, $dnsbl{$bl}) || 'not listed'; print "\t$bl:\t$txt\n"; } Net-Abuse-Utils-0.25/examples/malware.pl000644 000765 000024 00000000317 12727407345 021054 0ustar00michaelgstaff000000 000000 #!/usr/bin/perl -w use strict; use lib './lib'; use Net::Abuse::Utils qw/get_malware/; use Data::Dumper; my $hash = '733a48a9cb49651d72fe824ca91e8d00'; my $ret = get_malware($hash); warn Dumper($ret);