nginx의 error.log 에 있는 ip 접근은 raw filter를 이용해서 효과적으로 걸러지고 있는 것 같다.
abuselPDB에 이 ip를 신고하는 과정을 구현했다. 역시 코파일럿 도움으로 말이다.

Blacklist Parameters – AbuseIPDB APIv2 Documentation
The AbuseIPDB API allows you to utilize our database programmatically. This is most commonly done through Fail2Ban, which comes prepackaged with an AbuseIPDB configuration. Grab a new API key at from account dashboard.
아래가 샘플 코드이다.
# POST the submission.
curl https://api.abuseipdb.com/api/v2/report \
--data-urlencode "ip=127.0.0.1" \
-d categories=18,22 \
--data-urlencode "comment=SSH login attempts with user root." \
--data-urlencode "timestamp=2023-10-18T11:25:11-04:00" \
-H "Key: YOUR_OWN_API_KEY" \
-H "Accept: application/json"
python에서 하기 위해 다음과 같이 한다.
url = "https://api.abuseipdb.com/api/v2/report"
headers = {
"Key": abuseipdb_key,
"Accept": "application/json"
}
data = {
"categories": "19"
}
params = {
"ip": input_ip,
"comment": "SSL_do_handshake() failed"
}
response = requests.post(url, headers=headers, data=data, params=params)