From: Krzysztof Kowalski Date: 2012-12-09T20:50:12+09:00 Subject: Re: Getting info from array --f46d044796331b8dc604d06a0999 Content-Type: text/plain; charset=ISO-8859-1 I know that there is fail2ban but i would like to achieve it by my self :) 2012/12/9 tamouse mailing lists > On Sat, Dec 8, 2012 at 7:35 PM, Krzysztof Kowalski > wrote: > > Hello there. > > I would like to make script that gets failed logging attempt ip, when it > > count that ip tried logging more than 5 times in row script will write > new > > block rule with that ip to ipfilter in freebsd 8. > > So I like to manage this by getting each line of file with logging > attempts > > to arrays ( it makes array in array). I have a little problem with > obtaining > > array with word "Failed" and passing it to new array with ip's that i > would > > like to block. Next I get every 13th element (which is ipv6 address) and > > write new rule after counting it with hash. > > Can someone show me how to make it happend? > > > > CODE: > > #!/usr/local/bin/ruby19 > > filename = '/var/log/auth.log' > > falo = String.new > > File.open(filename) { |f| falo = f.read } > > words = falo.split('\n') > > > > $ ruby19 -v > > ruby 1.9.3p327 (2012-11-10 revision 37606) [amd64-freebsd8] > > $ uname -a > > FreeBSD mc.pl.eu.org 8.3-STABLE FreeBSD 8.3-STABLE #0 r130: Mon Apr 23 > > 17:41:20 IRKST 2012 > > root@freebsd8-amd64.ispsystem.net: > /root/src/roman-sys/amd64/compile/ISPSYSTEM > > amd64 > > > > thanks in advance > > Krzysztof Kowalski > > see fail2ban > > --f46d044796331b8dc604d06a0999 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable I know that there is fail2ban but i would like to achieve it by my self :)<= br>
2012/12/9 tamouse mailing lists <t= amouse.lists@gmail.com>
On S= at, Dec 8, 2012 at 7:35 PM, Krzysztof Kowalski <krisik28@gmail.com> wrote:
> Hello there.
> I would like to make script that gets failed logging attempt ip, when = it
> count that ip tried logging more than 5 times in row script will write= new
> block rule with that ip to ipfilter in freebsd 8.
> So I like to manage this by getting each line of file with logging att= empts
> to arrays ( it makes array in array). I have a little problem with obt= aining
> array with word "Failed" and passing it to new array with ip= 's that i would
> like to block. Next I get every 13th element (which is ipv6 address) a= nd
> write new rule after counting it with hash.
> Can someone show me how to make it happend?
>
> CODE:
> #!/usr/local/bin/ruby19
> filename =3D '/var/log/auth.log'
> falo =3D String.new
> File.open(filename) { |f| falo =3D f.read }
> words =3D falo.split('\n')
>
> $ ruby19 -v
> ruby 1.9.3p327 (2012-11-10 revision 37606) [amd64-freebsd8]
> $ uname -a
> FreeBSD mc.pl.eu.org= 8.3-STABLE FreeBSD 8.3-STABLE #0 r130: Mon Apr 23
> 17:41:20 IRKST 2012
> root@freebsd8-amd64.ispsystem.net:/root/src/roman-sys/amd64/compile/IS= PSYSTEM
> amd64
>
> thanks in advance
> Krzysztof Kowalski

see fail2ban


--f46d044796331b8dc604d06a0999--