English
 电子信箱
 加入收藏

  威盾防火墙 >> 新闻中心 >> 业界动态 >> 一个简单的防止IP攻击的脚本

 

一个简单的防止IP攻击的脚本

威盾防火墙 2014-12-01

 

注意:这个脚本是根据apache服务器的server-status和系统的dmesg分析结果进行防范的,所以非apache用户和没有开启server-status的朋友没法使用

  可以在服务器的crontab里设定每一分钟运行一次脚本,

  复制下面的脚本到autoblock.sh,

  root用户下# chmod u+x autoblock.sh

  QUOTE:

  #!/bin/bash

  # author hao32

  # basic setting

  echo 1 > /proc/sys/net/ipv4/tcp_syncookies

  # find server-status name

  ss_name="/usr/local/autoblock"

  if [ -e $ss_name/ss_name ];then

  ss_n=`cat $ss_name/ss_name`

  else

  mkdir /usr/local/autoblock >/dev/null 2>&1

  cat `locate httpd.conf|grep -E "httpd/conf/httpd.conf$|apache_ssl/conf/httpd.conf$"`\

  |grep "n /server-status"|cut -d/ -f2|cut -d\> -f1 > $ss_name/ss_name

  ss_n=`cat $ss_name/ss_name`

  fi

  # block setting

  # 设定排除的IP地址

  ip_exclude="192.168.1.*|60.195.249.*|222.76.212.*|218.241.156.*|58.215.87.*|218.107.216.110"

  ip_amou=25

  ss_url="http://127.0.0.1/$ss_n?notable"

  ss_tmp="/tmp/server-status"

  poss_ip="/tmp/poss_ip"

  real_ip="/tmp/real_ip"

  # block start...

  if [ -e "$poss_ip" ];then

  echo "" > $poss_ip

  fi

  if [ -e "$real_ip" ];then

  echo "" > $real_ip

  fi

  # analyse demsg

  dmesg |grep "short"|awk '{if($4!="From"){print $4} else {print $5}}'|awk -F: '{print $1}'|sort|uniq>>$poss_ip

  wget -q -O "$ss_tmp" "$ss_url"

  grep "<i>" $ss_tmp|grep -vE $ip_exclude|awk '{print $1}'|sed 's/<i>//g'|sort|uniq -c\

  |awk '{if($1>'$ip_amou') print $2}'>>$poss_ip

  #iptables -nvL|grep "DROP "|awk '{print $8}'|sort|uniq|sed 's/0\/24/*/g'>$rule_ip

  rule_ip=`iptables -nvL|grep "DROP "|awk '{print $8}'|sort|uniq|sed 's/0\/24/*/g'|xargs|sed 's/\ /|/g'`

  if [ -z $rule_ip ];then

  for i in `cat $poss_ip`

  do

  /sbin/iptables -I INPUT -p all -s $i -j DROP

  done

  else

  cat $poss_ip|grep -vE "$rule_ip" > $real_ip

  for i in `cat $real_ip`

  do

  /sbin/iptables -I INPUT -p all -s $i -j DROP

  done

  fi

脚本 IP攻击


相关内容: 最新内容:
黑客社会工程学攻击的八种常用伎俩[2014-12-01]
各种各样的僵尸网络攻击[2014-12-01]
CGI拒绝服务攻击技术浅析[2014-12-01]
防溢出提权攻击解决办法[2014-11-30]
网站路径绕过攻击[2014-11-30]
XSS,CSS跨站攻击-基本原理及演示[2014-11-30]
深入了解交换机漏洞出现原因及解决方法[2014-12-01]
攻防:网站后门防范及安全配置[2014-12-01]
黑客社会工程学攻击的八种常用伎俩[2014-12-01]
各种各样的僵尸网络攻击[2014-12-01]
ROS防止外网的DDOS的好办法[2014-12-01]
CGI拒绝服务攻击技术浅析[2014-12-01]