shieldlist-console Gratuit
Protège la console Shieldlist elle-même : connexions refusées, abus de la page de déblocage.
Télécharger le pack tar.gz des fichiers listés ci-dessous
Règles (2)
-
shieldlist-panelBrute force against the Shieldlist console or API -
shieldlist-unblock-abuseThe public unblock page refused this address repeatedly (rate limit, captcha)
À propos de ce pack
The controller's own log, read by the agent on the machine that runs it:
sign-ins and credentials it refused. One rule, shieldlist-panel,
bans the guesser. Its web policy ships in the pack; the rule needs the
log input in agent.yaml (see the rule file).
shieldlist-unblock-abuse (2026-08-17)
shieldlist-unblock-refused reads the controller's public page refused
lines (rate limit, captcha) and shieldlist-unblock-abuse bans an
address refused repeatedly — 10 in 10 minutes at standard. Same web
policy. The agent that reads the controller's journal
(unit: shieldlist-controller.service, category shieldlist) is the
one on the controller's machine.
Parseurs (2)
Les briques : chaque parseur nomme un journal, un préfiltre peu coûteux et la regex qui extrait l'adresse.
shieldlist-refused shieldlist
# The Shieldlist controller refusing a sign-in or a credential, in its own # log (slog text): the console and the API under brute force. The address # is the client's — X-Forwarded-For is trusted only from a proxy on the # same machine — so behind nginx it is the real one. # time=2026-08-16T01:08:44.705Z level=WARN msg="sign-in refused" from=203.0.113.9 name=admin # time=2026-08-16T01:08:44.705Z level=WARN msg="credential refused" from=203.0.113.9 parser: shieldlist-refused log: shieldlist prefilter: "refused" regex: '^time=(?P<time>\S+) level=WARN msg="(?:sign-in|credential) refused" from=(?P<ip>[0-9a-fA-F.:]+)' time_field: time time_format: rfc3339
shieldlist-unblock-refused shieldlist
# The public unblock page refusing a visitor — the rate limit or the # captcha — in the controller's own log (slog text). The address is the # visitor's (X-Forwarded-For, trusted from the proxy on the same machine). # time=2026-08-17T21:40:12.101Z level=WARN msg="public page refused" why=rate ip=203.0.113.9 parser: shieldlist-unblock-refused log: shieldlist prefilter: "public page refused" regex: '^time=(?P<time>\S+) level=WARN msg="public page refused" why=(?P<why>\w+) ip=(?P<ip>[0-9a-fA-F.:]+)' time_field: time time_format: rfc3339
Politiques de ban
web 1h → 24h → 7d
# # The ladder for whoever hammers the console, the API or the public # unblock page: an hour, a day, a week, on the service's ports only — # a guesser loses the panel, not their mail. Quiet for thirty days after # a ban ended and the next offence starts at the bottom. policy: web durations: [1h, 24h, 7d] ports: service memory: 30d