mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00

This is based on commit 2731def9159247e6da8a3191783c89683363689c from the zeek-docs repo.
16 lines
330 B
Text
16 lines
330 B
Text
|
|
@load protocols/ssh/detect-bruteforcing
|
|
|
|
redef SSH::password_guesses_limit=10;
|
|
|
|
event NetControl::init()
|
|
{
|
|
local debug_plugin = NetControl::create_debug(T);
|
|
NetControl::activate(debug_plugin, 0);
|
|
}
|
|
|
|
hook Notice::policy(n: Notice::Info)
|
|
{
|
|
if ( n$note == SSH::Password_Guessing )
|
|
NetControl::drop_address(n$src, 60min);
|
|
}
|