#!/usr/bin/env python3
import os
import selectors
import ctypes
from ctypes.util import find_library
IN_CREATE = 0x00000100
IN_DELETE = 0x00000200
IN_MOVED_FROM = 0x00000040
IN_MOVED_TO = 0x00000080
IN_MODIFY = 0x00000002
event_mask_dict = {
IN_CREATE: "CREATE",
IN_DELETE: "DELETE",
IN_MOVED_FROM: "MOVED_FROM",
IN_MOVED_TO: "MOVED_TO",
IN_MODIFY: "MODIFY",
}
# if not working lock for "libc.so.6"
# if don't find it
# use this command
# CMD: ldd --verbose $(which python) | grep libc
# if you don't have python try with bash
# if you find libc.so.6
# change c to full path of libc.so.6
# libc = ctypes.CDLL(find_library("/lib/x86_64-linux-gnu/libc.so.6"))
libc = ctypes.CDLL(find_library("c"))
class InotifyEvent(ctypes.Structure):
_fields_ = [
('wd', ctypes.c_int),
('mask', ctypes.c_uint32),
('cookie', ctypes.c_uint32),
('len', ctypes.c_uint32)
]
def init_inotify():
inotify_init = libc.inotify_init1
inotify_init.argtypes = [ctypes.c_int]
inotify_init.restype = ctypes.c_int
return inotify_init(0)
def add_watch(inotify_fd, path, mask):
inotify_add_watch = libc.inotify_add_watch
inotify_add_watch.argtypes = [ctypes.c_int, ctypes.c_char_p, ctypes.c_uint32]
inotify_add_watch.restype = ctypes.c_int
return inotify_add_watch(inotify_fd, path.encode(), mask)
def watch_directories(paths_to_watch):
event_mask = IN_CREATE | IN_DELETE | IN_MOVED_FROM | IN_MOVED_TO | IN_MODIFY
inotify_fd = init_inotify()
for path in paths_to_watch:
if os.path.exists(path):
wd = add_watch(inotify_fd, path, event_mask)
sel = selectors.DefaultSelector()
sel.register(inotify_fd, selectors.EVENT_READ)
print("Watching for file system events in the specified directories\n")
while True:
for key, mask in sel.select():
event_buf = os.read(inotify_fd, ctypes.sizeof(InotifyEvent) + 4096)
event = InotifyEvent.from_buffer_copy(event_buf)
try:
event_name = event_buf[ctypes.sizeof(InotifyEvent):].decode().rstrip('\0')
if str(os.path.join(paths_to_watch[event.wd - 1], event_name)) != "/dev/tty" :
print(f"Path: {os.path.join(paths_to_watch[event.wd - 1], event_name)}, Event mask: {event_mask_dict[event.mask]}")
except:
event_name = "NULL"
try:
if str(os.path.join(paths_to_watch[event.wd - 1], event_name)) != "/dev/tty" :
print(f"Path: {os.path.join(paths_to_watch[event.wd - 1], event_name)}, Event mask: {event_mask_dict[event.mask]}")
except:
print("NULL !! => check your code !!")
if __name__ == '__main__':
paths_to_watch = ["/root", "/bin", "/etc", "/lib", "/lib32", "/lib64", "/libx32", "/opt", "/tmp", "/var", "/usr", "/sys","/dev","/boot"]
watch_directories(paths_to_watch)
Comments