Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

announce: bantcp for CHKUSER patch

Status
Not open for further replies.

thedaver

IS-IT--Management
Jul 12, 2001
2,741
US
I wanted to announce a little script project I'm starting called 'bantcp'.

I got frustrated by a dictionary attack on one of my domains. Tonix' CHKUSER patch did it's job in repelling the offending IPs (who were not already RBLd) but I wanted more.

I wanted a (semi-)automated way to extract the attacking IPs from my qmail logs and insert them into my tcp.smtp file using selection criteria based upon how many attacks had been made from an IP during a specific window of time. I felt this was a way to prevent further abuse from these IPs.

bantcp is version 0.01 It's a cobbling of bash and perl to provide the output suitable for pasting into your tcp.smtp file. It's not terribly elegant yet, but I'm hoping for some suggestions.

Flames are welcome too, though please be kind. I'm not a coder. I'm also guessing that a 'sed/awk' guru could tighten bantcp up a lot - maybe kill off the perl jumps altogether.


Thanks,
Dave.

D.E.R. Management - IT Project Management Consulting
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top