<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Awk  Zen-Funk Panda</title>
    <link>https://panda.zenfunk.it/en/tags/awk/</link>
    <description>  Awk  Zen-Funk Panda</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 25 Sep 2026 00:00:00 +0000</lastBuildDate>
      <atom:link href="https://panda.zenfunk.it/en/tags/awk/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Horwall: a tiny logfile watcher for FreeBSD and blocklistd</title>
      <link>https://panda.zenfunk.it/en/posts/2026-09-25-horwall/</link>
      <pubDate>Fri, 25 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://panda.zenfunk.it/en/posts/2026-09-25-horwall/</guid>
      <description>&lt;p&gt;I published &lt;strong&gt;Horwall&lt;/strong&gt;, a small FreeBSD experiment that watches nginx access logs and reports suspicious client IPs to &lt;a href=&#34;https://man.freebsd.org/blocklistd&#34;&gt;&lt;code&gt;blocklistd&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The name comes from &lt;strong&gt;hor&lt;/strong&gt;, the Dutch word for &lt;em&gt;insect screen&lt;/em&gt; — something close to the Italian &lt;em&gt;zanzariera&lt;/em&gt;. That is basically the idea: not a complete web application firewall, but a small screen that catches the usual annoying insects before they keep buzzing around.&lt;/p&gt;&#xA;&lt;p&gt;Horwall is intentionally simple:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;it follows the nginx access log with &lt;code&gt;tail -F&lt;/code&gt;, so log rotation is handled safely;&lt;/li&gt;&#xA;&lt;li&gt;suspicious paths are matched with one regular expression per line;&lt;/li&gt;&#xA;&lt;li&gt;filtering is done in &lt;code&gt;awk&lt;/code&gt;;&lt;/li&gt;&#xA;&lt;li&gt;a minimal C helper talks to &lt;code&gt;libblocklist&lt;/code&gt;;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;blocklistd&lt;/code&gt; handles the actual ban and expiration policy;&lt;/li&gt;&#xA;&lt;li&gt;an &lt;code&gt;rc.d&lt;/code&gt; service and sample configuration are included.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;At the moment it is &lt;strong&gt;alpha software&lt;/strong&gt; (&lt;code&gt;0.1.0&lt;/code&gt;) and it reflects my current setup: FreeBSD, nginx access logs in a custom &lt;code&gt;awstats&lt;/code&gt; format, PF and &lt;code&gt;blocklistd&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The default policy I am using is deliberately short: one report, five minutes of block time. Enough to slow down noisy scanners, not enough to pretend that this is magic security dust.&lt;/p&gt;&#xA;&lt;p&gt;The patterns file supports normal positive rules and exclusions. For example, a broad rule like &lt;code&gt;\.php&lt;/code&gt; can be useful on a site that does not serve PHP at all, but it can obviously be a terrible idea elsewhere. Patterns must be reviewed and adapted before enabling live bans.&lt;/p&gt;&#xA;&lt;p&gt;The code, README, install notes and examples are on GitHub:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/zenfunkpanda/horwall&#34;&gt;github.com/zenfunkpanda/horwall&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
