Since the notifications from my NAS about failed admin login attempts continue to pour in, I rewrote my script to make it even more automated. It now pulls the logs from the NAS directly so I don't have to take a screenshot from Synology Active Insights, parses the IP addresses out of the logs automatically, caches whois lookups so I don't have to keep reselecting abuse addresses to use, and keeps historical records of how many IPs have been attacking for the past 24 hours.
#infosec
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Jonathan Kamens (jik@federate.social)'s status on Sunday, 16-Mar-2025 14:22:03 JST Jonathan Kamens