I am trying to get LFD to monitor for WordPress brute-force attacks on my site. Here is what I have done so far but LFD is not triggering:
Code: Select all
CUSTOM1_LOG = "/var/log/httpd/MYDOMAIN.com_access_log"
Code: Select all
if (($lgfile eq $config{CUSTOM1_LOG}) and ($line =~ /\] \"POST \/wp-login/)) {
return ("wp-login attempt from",$2,"wplogin","5","80","3600");
}
Code: Select all
58.11.173.48 - - [16/Jun/2013:07:14:18 -0700] "POST /wp-login.php HTTP/1.0" 200 5176 "MYDOMAIN/wp-login.php" "Mozilla/5.0 (Windows NT 6.1; rv:19.0) Gecko/20100101 Firefox/19.0"