I published Horwall, a small FreeBSD experiment that watches nginx access logs and reports suspicious client IPs to blocklistd.
The name comes from hor, the Dutch word for insect screen — something close to the Italian zanzariera. That is basically the idea: not a complete web application firewall, but a small screen that catches the usual annoying insects before they keep buzzing around.
Horwall is intentionally simple:
- it follows the nginx access log with
tail -F, so log rotation is handled safely; - suspicious paths are matched with one regular expression per line;
- filtering is done in
awk; - a minimal C helper talks to
libblocklist; blocklistdhandles the actual ban and expiration policy;- an
rc.dservice and sample configuration are included.
At the moment it is alpha software (0.1.0) and it reflects my current setup: FreeBSD, nginx access logs in a custom awstats format, PF and blocklistd.
The default policy I am using is deliberately short: one report, five minutes of block time. Enough to slow down noisy scanners, not enough to pretend that this is magic security dust.
The patterns file supports normal positive rules and exclusions. For example, a broad rule like \.php can be useful on a site that does not serve PHP at all, but it can obviously be a terrible idea elsewhere. Patterns must be reviewed and adapted before enabling live bans.
The code, README, install notes and examples are on GitHub:
github.com/zenfunkpanda/horwall
Rispondi o commenta via email.