could you not parse log files for the offending IP addresses and add them into a table within pf? Or can mod_security write out to a file accessible by pf and add entries in that into a blacklisted table?
__________________
It was a new day yesterday, but it's an old day now.
|