2 # Custom OSSEC block / Easily modifiable for custom responses (touch a file, insert to db, etc).
4 # Author: Daniel B. Cid
5 # Last modified: Feb 16, 2013
18 echo "`date` $0 $1 $2 $3 $4 $5" >> ${PWD}/../logs/active-responses.log
21 # IP Address must be provided
22 if [ "x${IP}" = "x" ]; then
23 echo "$0: Missing argument <action> <user> (ip)"
28 # Custom block (touching a file inside /ipblock/IP)
29 if [ "x${ACTION}" = "xadd" ]; then
30 if [ ! -d /ipblock ]; then
33 touch "/ipblock/${IP}"
34 elif [ "x${ACTION}" = "xdelete" ]; then
35 rm -f "/ipblock/${IP}"
39 echo "$0: invalid action: ${ACTION}"