Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Call the firewall to block the DDOS initiator IP

Shulou Source: shulou.com Published: 2022-06-01 05:46:14 10月04日 Update

[root@linux-node1 ~] # cat fw.sh

#! / bin/bash

Cat / var/log/nginx/access.log | awk-F ":'{print $1}'| sort | uniq-c | sort-rn | head-10 | grep-v" 127.0 "| awk'{if ($2 empty null & & $1 > 4) {print $2}}'> / tmp/dropip

For i in $(cat / tmp/dropip)

Do

/ sbin/iptables-An INPUT-p tcp-- dport 80-s $I-j DROP

Echo "$i kill at date" > > / var/log/ddos

Done

Script comments:

First look at the log file, awk filter out the first column IP, and sort, de-duplicate, and then reverse sort, filter out the top 10 IP, excluding 127.0 this IP, and then filter out the second column is not empty and the number of IP is more than 4 ip, and print IP output to / tmp/dropip file.

Circular file / tmp/dropip

Block port 80 of the ip address in / tmp/dropip

Write this event to the / var/log/ddos log and cycle again.

Tags: File log loop sort event again address quantity comment port script output initiator firewall fire prevention Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB vpn Huawei Apple Shulou Technology