Horwall: a tiny logfile watcher for FreeBSD and blocklistd

I published Horwall, a small FreeBSD experiment that watches nginx access logs and reports suspicious client IPs to blocklistd.

The name comes from hor, the Dutch word for insect screen — something close to the Italian zanzariera. That is basically the idea: not a complete web application firewall, but a small screen that catches the usual annoying insects before they keep buzzing around.

Horwall is intentionally simple:

  • it follows the nginx access log with tail -F, so log rotation is handled safely;
  • suspicious paths are matched with one regular expression per line;
  • filtering is done in awk;
  • a minimal C helper talks to libblocklist;
  • blocklistd handles the actual ban and expiration policy;
  • an rc.d service and sample configuration are included.

At the moment it is alpha software (0.1.0) and it reflects my current setup: FreeBSD, nginx access logs in a custom awstats format, PF and blocklistd.

The default policy I am using is deliberately short: one report, five minutes of block time. Enough to slow down noisy scanners, not enough to pretend that this is magic security dust.

The patterns file supports normal positive rules and exclusions. For example, a broad rule like \.php can be useful on a site that does not serve PHP at all, but it can obviously be a terrible idea elsewhere. Patterns must be reviewed and adapted before enabling live bans.

The code, README, install notes and examples are on GitHub:

github.com/zenfunkpanda/horwall


Rispondi o commenta via email.