3 ms·
> Application Firewall that detects this hijinx (haven't explored this yet - anyone know of a good one?) 1. Make sure your app requests are logged with the sou
by netsectoday 7y ago
> Application Firewall that detects this hijinx (haven't explored this yet - anyone know of a good one?)
1. Make sure your app requests are logged with the source IP and configure fail2ban to block the really bad offenders.
2. Set up `actionban` and `actionunban` commands in a custom fail2ban banaction.conf file.
3. Use ipset (an iptables extension) for O(log n) lookup against banned IPs in iptables (which affects all input/forward/output network requests).
4. Tadaa!
- joeyrideout 7y agoAt first glance I thought you were describing a more traditional network firewall, but with the data from application logs (failed logins, presumably) this becomes a very elegant entry WAF. Very cool!