However I rather like the fact the bad guys have no way to know they are blocked (unlike a firewall-level solution) so they can't optimise attacks by giving up on hosts which have detected them.
There is an argument to be made for running pam_abl as a public service. Cheers, Dave -- Politics, n. Strife of interests masquerading as a contest of principles. -- Ambrose Bierce