Exercise
Ranges and Quantifiers Exercise
Task
In this hands-on exercise, apply ranges and quantifiers to extract and count IP addresses, then match a directory and everything inside it.
- Target host
servera- Privileges
-
sudoaccess to write and read authentication log entries
-
Seed and verify failed-login entries
The authentication log
/var/log/secureis readable only byroot.ssh student@servera sudo -iloggerwrites a message into the system log. Two of these repeat the same address on purpose so that the count at the end has something to show.logger -p authpriv.info -t sshd "Failed password for root from 1.3.3.7" logger -p authpriv.info -t sshd "Failed password for root from 1.3.3.7" logger -p authpriv.info -t sshd "Failed password for student from 10.31.31.11" logger -p authpriv.info -t sshd "Failed password for student from 203.230.113.245" logger -p authpriv.info -t sshd "Failed password for student from 203.230.113.245"Confirm they arrived by reading the end of the log.
tail -n 5 /var/log/secure -
Extract and count the IP addresses
Find the failed-password lines, then pull the addresses out of them.
-oprints only the matched text instead of the whole line.grep 'Failed password' /var/log/secure | grep -oE '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'Pipe the addresses into
uniq -cto collapse adjacent duplicates and report how many times each appeared.grep 'Failed password' /var/log/secure | grep -oE '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | uniq -cLeave the root shell before continuing.
exit -
Create and match a sample directory tree
Build a small tree with a
websitedirectory in it.mkdir -p /tmp/demo_paths/website/css touch /tmp/demo_paths/website/css/style.css touch /tmp/demo_paths/website/index.html sudo find /tmpKeep only the paths that are the
websitedirectory itself or something beneath it.sudo find /tmp | grep -E '/website(/.*)?' -
Clean up
Remove the directory tree you created.
rm -rf /tmp/demo_paths ls /tmp