Files
fw/getWalled
T
2025-03-24 21:28:20 +00:00

22 lines
931 B
Bash
Executable File

#!/bin/bash
# picks up iptables/ufw message from the kernel log
# you need to enable the following line in /etc/rsyslog.conf
# module(load="imklog" permitnonkernelfacility="on")
# and enable ufw logging:
# ufw logging on
# pick the last 10 mins of the kern.log (2000 lines should cover that) and count the auth failures for ssh
if [[ ${1} == '+22' ]]; then
tail -2000 /var/log/kern.log | grep '\[UFW BL' | grep 'DPT=22 ' |./last10mins | wc -l
elif [[ ${1} == '-22' ]]; then
tail -2000 /var/log/kern.log | grep '\[UFW BL' | grep -v 'DPT=22 ' |./last10mins | wc -l
else
# tail -2000 /var/log/kern.log | grep '\[UFW BL' | ./last10mins | wc -l
tail -2000 /var/log/kern.log | grep '\[UFW BL' | ./last10mins | sed "s/^.*SRC=\([0-9.]*\) .*$/\1/" >/tmp/scanning.tmp
cat /tmp/scanning.tmp | while read IP; do
addEvent.sh "BLOCK,${IP},5,5,Portscanning attempt"
done
cat /tmp/scanning.tmp | wc -l
fi