From: tamouse mailing lists Date: 2012-12-10T11:41:45+09:00 Subject: Re: Getting info from array On Sun, Dec 9, 2012 at 5:50 AM, Krzysztof Kowalski wrote: > I know that there is fail2ban but i would like to achieve it by my self :) > > > 2012/12/9 tamouse mailing lists >> >> On Sat, Dec 8, 2012 at 7:35 PM, Krzysztof Kowalski >> wrote: >> > Hello there. >> > I would like to make script that gets failed logging attempt ip, when it >> > count that ip tried logging more than 5 times in row script will write >> > new >> > block rule with that ip to ipfilter in freebsd 8. >> > So I like to manage this by getting each line of file with logging >> > attempts >> > to arrays ( it makes array in array). I have a little problem with >> > obtaining >> > array with word "Failed" and passing it to new array with ip's that i >> > would >> > like to block. Next I get every 13th element (which is ipv6 address) and >> > write new rule after counting it with hash. >> > Can someone show me how to make it happend? >> > >> > CODE: >> > #!/usr/local/bin/ruby19 >> > filename = '/var/log/auth.log' >> > falo = String.new >> > File.open(filename) { |f| falo = f.read } >> > words = falo.split('\n') >> > >> > $ ruby19 -v >> > ruby 1.9.3p327 (2012-11-10 revision 37606) [amd64-freebsd8] >> > $ uname -a >> > FreeBSD mc.pl.eu.org 8.3-STABLE FreeBSD 8.3-STABLE #0 r130: Mon Apr 23 >> > 17:41:20 IRKST 2012 >> > >> > root@freebsd8-amd64.ispsystem.net:/root/src/roman-sys/amd64/compile/ISPSYSTEM >> > amd64 >> > >> > thanks in advance >> > Krzysztof Kowalski >> >> see fail2ban >> > I meant go look at the fail2ban code :) (also, bottom post, please?)