Anti-violence crackdown mini script
Intercept the IP of login failure in the security log file to block it. Once the IP with a record of login failure can not be connected again, to remove it, you can empty the security log and its hosts_deny file.
#! / bin/bash
Cat / var/log/secure | awk'/ Failed/ {print $(NF-3)}'| sort | uniq-c | awk'{print $2 "=" $1;}'> / root/black.txt
DEFINE= "5"
For i in `cat / root/ black.txt`
Do
IP= `echo $I | awk-F ='{print $1}'`
NUM= `echo $I | awk-F ='{print $2}'`
If [$NUM-gt $DEFINE]
Then
Grep $IP / etc/hosts.deny > / dev/null
If [$?-gt 0]
Then
Echo "sshd:$IP" > > / etc/hosts.deny
Echo "vsftpd:$IP" > > / etc/hosts.deny
Echo "mysqld:$IP" > > / etc/hosts.deny
Fi
Fi
Done