A security release. A review of v2.0.0 found five ways a crafted log could
mislead the analyst reading the report. This fixes all five, plus six more
found while fixing those.
The short version. Log text now never reaches your terminal raw, Apache
payloads hidden behind an escaped quote are parsed, and an SSH source address
comes from sshd's own message rather than from text a client supplied.
Attribution is trusted, not proved. Source addresses are read by position
rather than by program tag, because relays and container runtimes rewrite the
tag and a real attack must not vanish behind one. RFC 5424 works the same way,
where the rewritten field is APP-NAME. The trade-off is in the CHANGELOG's
Known issues, with all four open cases named and a test pinning each. Read it before
pointing this at a log file that mixes application output into auth records.
Install:
curl -LO https://github.com/ktalons/bashedlogs/releases/download/v2.0.1/bashedlogs && chmod +x bashedlogs
Needs bash 4.0+. macOS ships 3.2 at /bin/bash, so brew install bash first.
Full detail: CHANGELOG.md