I cheated because I (think I) know how to use iptables.

my $LOG = "/path/to/mail.log"; my $IPT = "/sbin/iptables"; my %known = map { $_ => 1 } get_current_offenders(); open LOG, $LOG or warn; while (<LOG>) { if (/User unknown/ ... /\[((?:\d+\.){3}\d+)\]/ || 1) { $1 and !$known{$1} and ++$known{$1} and ban($1); } } close LOG; sub get_current_offenders { my @offenders; # Let the shell have it, it's easy and only happens once open IPTABLES, "$IPT -n -LINPUT |" or die; while (<IPTABLES>) { if (/^REJECT\s+tcp.*?([\d.]{7,})/) { # Might tweak this push @offenders, $1; } } return @offenders; } sub ban { my ($offender) = @_; # Save ourselves a (not-so-)expensive exec() system($IPT, '-A', 'INPUT', '-s', $offender, qw( -p tcp -m tcp --dport 25 -j REJECT )); $? and warn; }

-- 
LP^>


In reply to Re: Firewalling brute-force spam attacks by TilRMan
in thread Firewalling brute-force spam attacks by hacker

Title:
Use:  <p> text here (a paragraph) </p>
and:  <code> code here </code>
to format your post, it's "PerlMonks-approved HTML":



  • Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
  • Titles consisting of a single word are discouraged, and in most cases are disallowed outright.
  • Read Where should I post X? if you're not absolutely sure you're posting in the right place.
  • Please read these before you post! —
  • Posts may use any of the Perl Monks Approved HTML tags:
    a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, details, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, summary, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
  • You may need to use entities for some characters, as follows. (Exception: Within code tags, you can put the characters literally.)
            For:     Use:
    & &amp;
    < &lt;
    > &gt;
    [ &#91;
    ] &#93;
  • Link using PerlMonks shortcuts! What shortcuts can I use for linking?
  • See Writeup Formatting Tips and other pages linked from there for more info.