Next step
IP should not be blocked for ever.
The ip from Blocklist.de will expire every 48 hour according to their website, and my script deletes and re write every time.
So where changes are needed is for the authlog-analyser, and the /etc/bruteforce
Alternatives
a)dev-null-script, with crontab to purge /etc/bruteforce once a week
or
b) Add new table to pf.conf bruteforce.old
Somehow write a script to cp to from bruteforce to bruteforce.old, and then clean bruteforce
Can to crontab crash into each other, or do they wait for the other to finish before beginning?
|