Automated web attack detection, IP blocking via iptables, and HTML incident report generation β demonstrated in a controlled VMware lab environment.
- Overview
- Lab Environment
- Attack Scenario
- Project Structure
- How It Works
- Scripts
- Lab Walkthrough
- Results
- Skills Demonstrated
This project demonstrates a real-world threat mitigation pipeline built with Python and Bash. A web server running on Ubuntu Server 22.04 is attacked by a Kali Linux machine using Nikto (a web vulnerability scanner). A custom Python monitor detects the attack in real time by analyzing Apache access logs, automatically blocks the attacker's IP using iptables, and generates a detailed HTML incident report.
The entire detection-to-block cycle completed in under 60 seconds with zero manual intervention.
| Role | OS | IP Address | Tool |
|---|---|---|---|
| π’ Defender / Victim | Ubuntu Server 22.04 | 192.168.253.131 | Apache2, Python3, iptables, UFW |
| π΄ Attacker | Kali Linux | 192.168.253.130 | Nikto v2.5.0 |
Virtualization: VMware Workstation β NAT Network
Network: Both machines on the same NAT subnet (192.168.253.0/24)
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β VMware NAT Network β
β 192.168.253.0/24 β
β β
β ββββββββββββββββββββ ββββββββββββββββββββββββ β
β β Kali Linux β β Ubuntu Server β β
β β 192.168.253.130 ββββββββΆβ 192.168.253.131 β β
β β β Nikto β β β
β β [ATTACKER] β scan β Apache2 :80 β β
β ββββββββββββββββββββ β Python Monitor β β
β β iptables β β
β β [DEFENDER] β β
β ββββββββββββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Threat: Web reconnaissance and vulnerability scanning using Nikto
Attack Vector: HTTP β Port 80
Techniques Detected: Path traversal, admin panel enumeration, /etc/shadow access attempts, CGI probing, outdated server fingerprinting
Attack command launched from Kali:
nikto -h http://192.168.253.131Automated defense pipeline on Ubuntu:
Apache access.log β Python Monitor β Pattern Match β Hit Counter β iptables DROP β HTML Report
threat-mitigation/
β
βββ scripts/
β βββ python/
β β βββ web_threat_monitor.py # Core detection, blocking & reporting engine
β βββ bash/
β βββ setup.sh # Environment setup script
β
βββ assets/
β βββ 01_apache_running.png
β βββ 02_monitor_running.png
β βββ 03_nikto_scan.png
β βββ 04_monitor_detecting.png
β βββ 05_iptables_blocked.png
β βββ 06_incident_report.png
β
βββ reports/ # Auto-generated HTML incident reports
β βββ incident_report_YYYYMMDD_HHMMSS.html
β
βββ logs/
β βββ monitor.log # Runtime monitor log
β βββ blocked_ips.json # Persistent blocked IP records
β
βββ README.md
The monitor tails /var/log/apache2/access.log in real time and checks every incoming request against a library of 26 attack signatures covering:
| Category | Signatures |
|---|---|
| Scanner fingerprints | nikto, curl, wget, python-requests |
| SQL Injection | select.*from, union.*select, insert.*into, drop.*table |
| XSS | <script, javascript:, alert(, onerror=, onload= |
| Path Traversal | ../, /etc/passwd, /etc/shadow, /proc/self |
| Admin Enumeration | /wp-admin, /phpmyadmin, /admin, /config. |
| Command Injection | cmd=, exec(, base64_decode |
| Sensitive Files | .env, .git/, null byte %00 |
| Remote File Inclusion | .php?.*=http |
Hit detected β increment counter for source IP
If hits >= 10 within 60 seconds:
β iptables -I INPUT -s <IP> -j DROP
β iptables -I OUTPUT -d <IP> -j DROP
β Log incident to blocked_ips.json
β Generate HTML incident report
Every block event triggers automatic generation of an HTML incident report containing:
- Session statistics (IPs blocked, incidents, threshold config)
- Full incident log table (timestamp, IP, hits, reason, action)
- Live snapshot of active iptables rules
Core monitoring engine. Runs continuously on the defender machine.
Key parameters (configurable at top of script):
THRESHOLD = 10 # hits before blocking
TIME_WINDOW = 60 # seconds to count hits within
CHECK_INTERVAL = 2 # seconds between log reads
LOG_FILE = "/var/log/apache2/access.log"Run:
python3 scripts/python/web_threat_monitor.pyAutomates the full environment setup on Ubuntu Server: installs Apache2 + PHP, configures log permissions, sets up the sudoers rule for iptables, and creates the project directory structure.
Run:
chmod +x scripts/bash/setup.sh
sudo bash scripts/bash/setup.shApache2 is active and running on Ubuntu Server 22.04, serving the target web application on port 80.
The Python monitor initializes, begins tailing the Apache access log, and waits for incoming requests. Threshold is set to 10 hits within 60 seconds before auto-blocking.
Nikto v2.5.0 performs a full web vulnerability scan against the target. It probes for outdated server versions, missing security headers, exposed admin panels, and known CVEs. The scan triggered 20+ error attempts across multiple attack vectors.
The monitor detects each malicious request in real time. After 10 hits within the 60-second window, the attacker IP 192.168.253.130 is automatically blocked via iptables. The block event triggers immediate report generation.
[WARNING] BLOCKED: 192.168.253.130 | Reason: Web attack: 10 hits within 60s | Hits: 10
[INFO] Report generated: incident_report_20260710_214536.html
The iptables INPUT chain confirms the DROP rule was applied for the attacker's IP, blocking all further communication from that host.
An HTML incident report is auto-generated with full attack details, session statistics, and a live snapshot of active iptables rules.
| Metric | Value |
|---|---|
| Attack tool | Nikto v2.5.0 |
| Attacker IP | 192.168.253.130 |
| Requests to trigger block | 10 |
| Time to detection | < 5 seconds |
| Time to block | < 60 seconds |
| Block method | iptables INPUT + OUTPUT DROP |
| Report generated | Automatically on block event |
| Manual intervention required | β None |
- Python scripting β real-time log parsing, regex pattern matching, subprocess automation
- Linux firewall management β iptables rule injection via Python subprocess
- Log analysis β Apache access log monitoring with tail-follow implementation
- Threat detection β signature-based detection engine with rate limiting
- Incident reporting β automated HTML report generation
- Network security β UFW configuration, NAT lab environment setup
- Offensive tools β Nikto web vulnerability scanner (attack simulation)
β οΈ Disclaimer: This project was conducted in an isolated VMware lab environment for educational purposes only. All attack simulations were performed on systems owned and controlled by the author.
alexrepsec
Cybersecurity enthusiast | Home Lab Builder
This project was built as part of a cybersecurity portfolio to demonstrate practical SOC automation and analyst skills.





