find Bot IPs in log file to firewall them
Project description
Tools to build Firewall Command for UFW from List of (Apache)-Log-files.
It creates a file block-ip.sh which contains Linux UWF-Command to block IP-network, but it does not change any Firewall-rules on your computer.
Installation
To install the latest release on PyPI, simply run:
pip install find2deny
Or to install the latest development version, run:
git clone [TODO] cd find2deny python setup.py install
Quick Tutorial
For example, you have a set of Apache Logfile in directory apache2: access.log.1, access.log.2, … The python script find2deny-cli can create a shell-Script block-ip.sh which contains commands like:
#!/bin/bash ufw deny from 1.2.3.4/0 to any ufw deny from 1.2.3.4/1 to any ...
Make a Configuration-File: Simple copy this configuration to a file, say config.toml
verbosity = "INFO" log_files = ["apache2/access.log.*"] log_pattern = '%h %l %u %t "%r" %>s %O "%{Referer}i" "%{User-Agent}i"' database_path="./blocked-ip.sqlite" [[judgment]] name = "path-based-judgment" [judgment.rules] bot_request = [ "/?XDEBUG_SESSION_START=phpstorm", "/phpMyAdmin/", "/pma/", "/myadmin/", "/MyAdmin/", "/mahua/", "/wp-login", "/webdav/", "/help.php", "/java.php", "/db_pma.php", "/logon.php", "/help-e.php", "/hell.php", "/defect.php", "/webslee.php", "http://www.123cha.com/", "http://www.wujieliulan.com/", "http://www.epochtimes.com/", "http://www.ip.cn/", "www.baidu.com:443" ] [[judgment]] name = "time-based-judgment" [judgment.rules] max_request = 501 interval_seconds = 59 [[execution]] name = "ufw_cmd_script" [execution.rules] script = "./block-ip.sh"
Run script
find2deny-init-db blocked-ip.sqlite
to create a Sqlite-Database in file blocked-ip.sqlite. The filename must match the configuration database_path in the file config.toml.
Run
find2deny-cli config.toml --verbosity=DEBUG
to create file block-ip.sh. Then you can examinate the file block-ip.sh and run it from your shell to update your firewall.
Configuration
The syntax used in configuration file ist Toml. There are three sections in a configuration files, as you see above
Common Configuration
This section defines common configurations, such as how much infos should be printed onto console, ect.
Judgment
This section defines a list of Judgments. They are identified by name. At this time there are only two judments: path-based-judgment and time-based-judgment. Each judgment has its owns configuration. Judments are class, which uses rules defined in configuration to decide which IPs should be blocked.
Execution
This section defines a list of executions. At this time there is only one execution. Executions are classes which create firewall-rules or execute something, which nessesary to block an IP, or , in this implementation, block the network, to which the ip belongs.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file find2deny-0.1.4.post1558363425.tar.gz
.
File metadata
- Download URL: find2deny-0.1.4.post1558363425.tar.gz
- Upload date:
- Size: 10.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/39.1.0 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/3.6.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4d1d630666aae6e24515e6c0aff8a1a75bbfcc03727939c6d550c873f1014e0a |
|
MD5 | cdebfbf66e6bf07802db8dabad0f34c3 |
|
BLAKE2b-256 | fcbc7ccbaa1641499fec05ce01780b012ad468cea5601e8fb5a16d53fda75426 |
File details
Details for the file find2deny-0.1.4.post1558363425-py3-none-any.whl
.
File metadata
- Download URL: find2deny-0.1.4.post1558363425-py3-none-any.whl
- Upload date:
- Size: 13.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/39.1.0 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/3.6.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4abf0416f7434e4dfa8b216ced66e3f99e74d168e0f7131331e839e3553e31d1 |
|
MD5 | 31add5fbbeda043ef58985a7df165d64 |
|
BLAKE2b-256 | d80341a1ccc16e8f59a3acecb1cc19fb0f49b3852446872a79ddb8a18307ead4 |