Projects / BlockIt

BlockIt

BlockIt monitors the Snort alert file and creates either IPTables, IPChains, IPFWADM, IPFilter, PF, or Checkpoint Firewall rules. This version runs on Linux, FreeBSD, and OpenBSD. BlockIt has built-in CIDR support for multiple target IPs and whitelist support. Additional features include MySQL logging and email logging.

Tags Networking Firewalls Utilities
Licenses GPL
Operating Systems POSIX Linux
Implementation Perl

Tweet this project Short link

Rss Recent releases

Changes: Additional debug logging was added for the MySQL code. A new rc.blockit2 was included for SySV systems. A "UseChain" parameter that is set to BLOCKIT by default was added.

Changes: rc.blockit was added to the contrib directory. Two new configuration options were added: FirewallTemporaryTarget and FirewallPermanentTarget. check_blockit_log.pl was added in the contrib directory for permanent blocking. Fixes were made for parsing of snort, SSH, and syslog ranging over more than one line.

Changes: Another SSH bad login check for invalid users was added. The minimum firewall time was changed from 60 to 1. A log entry is now added when the intruder blocking time is less than the minimum firewall time.

Changes: Support was added for IPFW, IPFILTER, PF, and Snort SigID Whitelist. Bad SSH Login support was added via syslog. Half of the code was rewritten.

  • Rrelease-mid
  •  23 Jun 2005 00:58
  • Rrelease-after

Changes: Crashes in the write_intruders_email function and the main rules function were fixed.

Rss Recent comments

Rcomment-before 13 Feb 2006 14:38 Rcomment-trans 3ec2324c6f0f97c8a25ff2b5afe5150a_tiny agarzon Rcomment-after

nice but....
I probe the blockit, and work fine... but have 2 items not working...

1. MySQL connection.... the intruders database is always empty...

2. Email report... never send Mails....

I read the source of install... and have some errors.... if you want i can send the fix.... and i can help you, making a Spanish Pack of BLOCKIT.

See you...

Rcomment-before 31 Aug 2004 19:18 Rcomment-trans bossi Rcomment-after

the new version this very good one
Hello

I liked new resources a lot to detect the ip address.

BoSSi

Rcomment-before 28 Jun 2004 23:16 Rcomment-trans lordvega Rcomment-after

Re: NEW in 1.3.0

> Nice tool. However, I have just one

> gripe.

>

> Blockit creates multiple iptable

> entries. This can make the BLOCKIT chain

> much longer than it needs to be. The

> daemon really should check for a

> matching rule before adding a new

> one.

>

This was fixed iin the latest development release. I would run this release because it contains mostly bug fixes then the stable release.

Rcomment-before 28 Jun 2004 11:18 Rcomment-trans hulse_kevin Rcomment-after

Re: NEW in 1.3.0
Nice tool. However, I have just one gripe.

Blockit creates multiple iptable entries. This can make the BLOCKIT chain much longer than it needs to be. The daemon really should check for a matching rule before adding a new one.

Rcomment-before 28 Feb 2003 14:01 Rcomment-trans lordvega Rcomment-after

Re: NEW in 1.3.0

> I forgot to mention it but IPCHAINS,
> IPFW, and Checkpoint Firewall support
> were also added in the new 1.3.0
> Release.

I meant IPFWADM not IPFW. :)

B7d01918a0567df7d5520a31aed00f67_thumb

Project Spotlight

FmPro Migrator

Migrates FileMaker to MySQL, Oracle, Access, SQL Server, FrontBase, FileMaker7.

86f68eba0f566e6bd1b763396cc96403_thumb

Project Spotlight

AKFAvatar

A fancy text terminal, text viewer, and more.