Linux firewall corporate real

1) Black & customer using brute force tools, remote attack hit & Linux servers through a user
name and a password dictionary, an attempt to log on Linux server operating system, as the operation and maintenance people
how to stop members of the Black & off & hit attack it?
2) remote login Linux servers, Linux servers to open the security log file:
/ var / log / Secure recording or normal user logged off Black & analyze the
file to identify black & passengers IP, and login times greater than 10 times, Linux added
blacklist Iptables firewall;
for I in $ (grep "the Failed password" / var / log / Secure * | grep -oe
. "([0-9] {l, 3})}. 3 {[0- . 9] {l, 3} "| Sort -n | the uniq -C | awk
'{IF ((. 1 $> = 10)) 2} Print $' | grep -v ^ 127); do the INPUT iptables -I
. 4 -s $ i -j DROP; done

Guess you like

Origin blog.51cto.com/jiangzm/2475015