Active Response/shun per shell command?
Posted: Sat Nov 22, 2014 5:05 pm
Is it possible to shun an IP by a shell command?
From time to time I have massive distributed FTP login attempts. I've found out that I can create my own login script with PureFTP. Most of the I can easily identify as attacks.
It would be cool if I can shun them right away from the login script. But if I call the shun script these IPs never get removed.
Last time I had these login attempts I blocked them with ASL, but ASL does not support that any more.
From time to time I have massive distributed FTP login attempts. I've found out that I can create my own login script with PureFTP. Most of the I can easily identify as attacks.
It would be cool if I can shun them right away from the login script. But if I call the shun script these IPs never get removed.
Last time I had these login attempts I blocked them with ASL, but ASL does not support that any more.