Softpedia
 


LINUX CATEGORIES:



GLOBAL PAGES >>
NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Linux Kernel 3.9.2 / 3....
  • LibreOffice 3.6.6 / 4.0.3
  • MPlayer 1.1.1
  • systemd 204
  • Arch Linux 2013.05.01
  • Blender 2.67
  • KDE Software Compilatio...
  • CrunchBang Linux Stable...
  • Elementary OS 0.1 / 0.2...
  • SystemRescueCd 3.6.0
  • Home > Linux > Internet > Log Analyzers

    BanFromLog 0.75

    Download button

    No screenshots available
    Downloads: 551  View global page NEW!  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    License / Price:

    Last Updated:

    Category:
    Jose Sanchez | More programs
    GPL / FREE
    February 27th, 2006, 17:55 GMT
    ROOT / Internet / Log Analyzers

     Read user reviews (0)  Refer to a friend  Subscribe

    BanFromLog description

    BanFromLog is a shell script that examines your /var/log/auth.log and searches for the IP addresses.

    BanFromLog is a shell script that examines your /var/log/auth.log and searches for the IP addresses of login attempts which use non-existent user names.

    BanFromLog is configured for use with sqlite or MySQL.

    Well is truth that if you have only an user, you don't need this but, when you have hundreds or even thousands, users, many of them could have an insecure password (even if you have warned them or have some special modification in the passwd command to prevent this).

    You can receive other kinds of attacks via SSH port from those IPS which first attempted only a couple of illegal users. (illegal user: user that doesn't exists).
    Your CPU can be slower with this kind of brute force attacks, even if you have put a maximum attempts or whatever, because this kind of attacks are done with many "zoombies".

    You can prevent attacks in many servers if you use a centralized MySQL server, all servers insert ips of attackers and one attacker, probably will only attempt to one server.

    Requirements:

    · Bash
    · sqlite or MySQL
    · iptables

    What's New in This Release:

    · Prints in HTML the list of banned IPs (the previous version, in the option "show", only looked in the "actual" log and not in the database).
    · A bug has been corrected in the MySQL version (iptables -i ... s ip -j DROP).



    Product's homepage

      


    TAGS:

    shell script | log analyzer | scan IP | BanFromLog | shell | script

    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM