{"id":770,"date":"2015-08-21T04:44:50","date_gmt":"2015-08-21T08:44:50","guid":{"rendered":"http:\/\/www.rfdm.com\/blog\/?p=770"},"modified":"2015-08-21T04:45:12","modified_gmt":"2015-08-21T08:45:12","slug":"mcblock-examples","status":"publish","type":"post","link":"https:\/\/www.rfdm.com\/blog\/?p=770","title":{"rendered":"mcblock examples"},"content":{"rendered":"<p>I recently wrote about the creation of a new utility I created to help manage my pf rules called mcblock.  Thus far the most useful part has been the automation of rule addition by grokking logs.<\/p>\n<p>For example, it can parse auth.log on FreeBSD and automatically add entries to my pf rule database.  And before adding the entries, it can show you what it would do.  For example:<\/p>\n<pre>\r\n# bzcat \/var\/log\/auth.log.0.bz2 | mcblock -O - \r\n109.24.194.41        194 hits\r\n  add 109.24.194\/24 30 days\r\n103.25.133.151         3 hits\r\n  add 103.25.133\/24 30 days\r\n210.151.42.215         3 hits\r\n  add 210.151.42\/24 30 days\r\n<\/pre>\n<p>What I&#8217;ve done here is uncompress auth.log.0.z2 to stdout and pipe it to mcblock to see what it would do.  mcblock shows that it would add three entries to my pf rule database, each with an expiration 30 days in the future.  I can change the number of days with the -d command line option:<\/p>\n<pre>\r\n# bzcat \/var\/log\/auth.log.0.bz2 | mcblock -d 60 -O -\r\n109.24.194.41        194 hits\r\n  add 109.24.194\/24 60 days\r\n103.25.133.151         3 hits\r\n  add 103.25.133\/24 60 days\r\n210.151.42.215         3 hits\r\n  add 210.151.42\/24 60 days\r\n<\/pre>\n<p>By default, mcblock uses a threshold of 3 entries from a given offending IP address in a log file.  This can be changed with the -t argument:<\/p>\n<pre>\r\n# bzcat \/var\/log\/auth.log.0.bz2 |  mcblock -t 1 -O - \r\n109.24.194.41        194 hits\r\n  add 109.24.194\/24 30 days\r\n103.25.133.151         3 hits\r\n  add 103.25.133\/24 30 days\r\n210.151.42.215         3 hits\r\n  add 210.151.42\/24 30 days\r\n31.44.244.11           2 hits\r\n  add 31.44.244\/24 30 days\r\n<\/pre>\n<p>If I&#8217;m happy with these actions, I can tell mcblock to execute them:<\/p>\n<pre>\r\n# bzcat \/var\/log\/auth.log.0.bz2 | mcblock -t 1 -A -\r\n<\/pre>\n<p>And then look at one of the entries it added:<\/p>\n<pre>\r\n# mcblock -s 31.44.244\/24\r\n31.44.244.0\/24     2015\/08\/21 - 2015\/09\/20\r\n<\/pre>\n<p>This particular address space happens to be from Russia, and is allocated as a \/23.  So let&#8217;s add the \/23:<\/p>\n<pre>\r\n# mcblock -a 31.44.244\/23\r\n<\/pre>\n<p>And then see what entries would match 31.44.244.11:<\/p>\n<pre>\r\n# mcblock -s 31.44.244.11\r\n31.44.244.0\/23     2015\/08\/21 - 2015\/09\/20\r\n<\/pre>\n<p>The \/24 was replaced by a \/23.  Let&#8217;s edit this entry to add the registry and the country, and extend the time period:<\/p>\n<pre>\r\n# mcblock -e 31.44.244\/23\r\nstart time [2015\/08\/21 04:37]: \r\nend time [2015\/09\/20 04:37]: 2016\/02\/21 04:37\r\nregistry []: RIPE\r\ncountry []: RU\r\nEntry updated.\r\n<\/pre>\n<p>And view again:<\/p>\n<pre>\r\n# mcblock -s 31.44.244.11\r\n31.44.244.0\/23     2015\/08\/21 - 2016\/02\/21 RIPE     RU\r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>I recently wrote about the creation of a new utility I created to help manage my pf rules called mcblock. Thus far the most useful part has been the automation of rule addition by grokking logs. For example, it can parse auth.log on FreeBSD and automatically add entries to my pf rule database. And before &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.rfdm.com\/blog\/?p=770\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;mcblock examples&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,29,82,12],"tags":[],"class_list":["post-770","post","type-post","status-publish","format-standard","hentry","category-computing","category-freebsd","category-freebsd-computing","category-software-development"],"_links":{"self":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=770"}],"version-history":[{"count":4,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/770\/revisions"}],"predecessor-version":[{"id":774,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/770\/revisions\/774"}],"wp:attachment":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}