From bfaa81256157d72b54f54d83a19dadc6116ef72f Mon Sep 17 00:00:00 2001 From: Pawel Krawczyk Date: Thu, 8 Jan 2015 23:57:08 +0000 Subject: [PATCH] mention Dropbear rule --- README.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/README.md b/README.md index 9f2dce7..b1b21d3 100644 --- a/README.md +++ b/README.md @@ -99,6 +99,23 @@ The `router-drop.sh` script requires two configuration steps: * configure the `ROUTER` variable to a SSH string for root login to the router (e.g. *root@gw.example.com*) * install SSH keys to actually log in; the keys need to be installed on root account as this is where active response script are running +Example configuration: + + + router-drop + router-drop.sh + srcip + no + + + + router-drop + local + 51004 + + +Event 51004 is defined in `/var/ossec/rules/dropbear_rules.xml` and triggered by a series of unsuccessful password logins. Don't forget to add your trusted networks to `` entries to prevent locking yourself out! + ## Samples Number of blacklisted IP addresses: