datocp
2023-12-19 16:46:51 +08:00
搜索一下 iptables recent hacker 吧
根据它用 ipset 的实现,预先让扫描端口的 IP 自动 ban
ipset destroy banned_hosts
ipset -N banned_hosts hash:net timeout 180
-A INPUT -i eth1 -m set --match-set banned_hosts src -j DROP
-A INPUT -i eth1 -p udp -m multiport --dports 80,5060 -j SET --add-set banned_hosts src
-A INPUT -i eth1 -p tcp -m multiport --dports 20,23,25,110,135,137:139,161,445,1080,2323,3128,3306,3389 -j SET --add-set banned_hosts src