# HG changeset patch # User Matti Hamalainen # Date 1251658136 -10800 # Node ID 56b85493210314fae60b9dcaec70aefcfb5970f3 # Parent 3bcc17b754bfcc563bc74614fabccc69f402abf3 Update documentation. diff -r 3bcc17b754bf -r 56b854932103 README --- a/README Sun Aug 30 20:13:37 2009 +0300 +++ b/README Sun Aug 30 21:48:56 2009 +0300 @@ -1,4 +1,4 @@ -Malicious Attack Livid Termination Filter daemon (maltfilter) v0.19.0 +Malicious Attack Livid Termination Filter daemon (maltfilter) v0.19.1 ===================================================================== Programmed by Matti 'ccr' Hämäläinen (C) Copyright 2009 Tecnic Software productions (TNSP) @@ -8,11 +8,11 @@ About ===== -Maltfilter daemon script continuously scans various system logfiles -including auth.log, httpd logs, etc. for signs of malicious connections, -break-in and exploitation attempts. The originating IP addresses of -these connections can be then acted upon in following ways, each -being optional: +Maltfilter is daemon script written in Perl, which continuously scans various +system logfiles including auth.log, Apache style common logformat and error +logs, etc. for signs of malicious connections, break-in (login bruteforcing, +etc.) and exploitation attempts. The originating IP addresses of these +connections can be then acted upon in following ways, each being optional: * Insertion (and eventual deletion or "weeding") of Netfilter rules. * Submitting entry to DroneBL DNSBL service.