Shieldlist

shieldlist-panel Free

Brute force against the Shieldlist console or API

Category
panel
Threshold
5/10m, 15/1h
Ban policy
web
Parsers
shieldlist-refused

Why it is written this way

Somebody guessing at the console or the API: five refusals in ten
minutes, or fifteen in an hour, and the address is banned on the machine
that runs the controller. The agent there reads the controller's log:
log_inputs: [{path: /var/log/shieldlist/controller.log, category: shieldlist}]

The rule file View raw

# Somebody guessing at the console or the API: five refusals in ten
# minutes, or fifteen in an hour, and the address is banned on the machine
# that runs the controller. The agent there reads the controller's log:
#   log_inputs: [{path: /var/log/shieldlist/controller.log, category: shieldlist}]
rule: shieldlist-panel
description: Brute force against the Shieldlist console or API
category: panel
parsers: shieldlist-refused
threshold: [5/10m, 15/1h]
ban: web