Results 1 to 4 of 4

Thread: script to add botnet IPs from access_log automatically

  1. #1
    Join Date
    Nov 2006
    Beans
    8

    script to add botnet IPs from access_log automatically

    Hi,

    Can anyone recommend an automated solution/script to automatically add IPs to iptables to drop them by reading the access logs?

    Thanks,
    Rich

  2. #2
    Join Date
    Oct 2006
    Location
    SLC, UofU
    Beans
    684
    Distro
    Kubuntu Jaunty Jackalope (testing)

    Re: script to add botnet IPs from access_log automatically

    denyhosts...
    --Superb--

  3. #3
    Join Date
    Jun 2006
    Location
    Switzerland
    Beans
    Hidden!
    Distro
    Kubuntu Jaunty Jackalope (testing)

    Re: script to add botnet IPs from access_log automatically

    or fail2ban

    however denyhosts also allows you to incorporate a common published IP list of considered bad IPs... so you might want to have a look at the config there.... not sure if fail2ban uses such a thing.

  4. #4
    Join Date
    Nov 2006
    Beans
    8

    Re: script to add botnet IPs from access_log automatically

    Hi,

    Thanks for the replies. I don't seem to have a problem with SSH but rather repeated GETs to non-existent folders and files for my website. anyone know of a program/script to manage abuse of a website? Or, a site dedicated to handling that issue?

    Thanks,
    Rich
    Last edited by flowersrj; February 2nd, 2009 at 02:51 PM.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •