store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 18, 2013 10:24 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 
Author Message
 Post subject: Country IP blocks outdated?
Unread postPosted: Thu Jul 12, 2012 9:23 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 09, 2009 12:57 pm
Posts: 133
Though I've country-blocked both Koreas and China in ASL, I've recently noticed WAF entries and failed SSH logins from the following IPs, which according to IP2Location belong in China and Korea.

Code:
112.136.149.212
180.86.128.22
61.160.250.78

_________________
CentOS 6.3 (2.6.32.60-40.art.x86_64)
ASL 3.2.13-30.el6.art
Webmin 1.6.2
Virtualmin 3.99.gpl
Apache 2.2.15
PHP 5.3.3 (mod_fcgid/2.3.7)


Last edited by gaia on Fri Jul 13, 2012 9:03 am, edited 2 times in total.

Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Fri Jul 13, 2012 9:03 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 09, 2009 12:57 pm
Posts: 133
Shouldn't those IPs be blocked?

_________________
CentOS 6.3 (2.6.32.60-40.art.x86_64)
ASL 3.2.13-30.el6.art
Webmin 1.6.2
Virtualmin 3.99.gpl
Apache 2.2.15
PHP 5.3.3 (mod_fcgid/2.3.7)


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Fri Jul 13, 2012 6:39 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Sure, assuming they are right. Do you know they are right?


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Fri Jul 13, 2012 7:45 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 09, 2009 12:57 pm
Posts: 133
scott wrote:
Sure, assuming they are right. Do you know they are right?


yes those IPs were lifted from the alerts and the country-block rules double checked...

_________________
CentOS 6.3 (2.6.32.60-40.art.x86_64)
ASL 3.2.13-30.el6.art
Webmin 1.6.2
Virtualmin 3.99.gpl
Apache 2.2.15
PHP 5.3.3 (mod_fcgid/2.3.7)


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Wed Jul 18, 2012 7:30 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 09, 2009 12:57 pm
Posts: 133
Whats the consensus on this one?

_________________
CentOS 6.3 (2.6.32.60-40.art.x86_64)
ASL 3.2.13-30.el6.art
Webmin 1.6.2
Virtualmin 3.99.gpl
Apache 2.2.15
PHP 5.3.3 (mod_fcgid/2.3.7)


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Wed Jul 18, 2012 8:45 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
No problem, we'll add those in today.


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Thu Aug 09, 2012 10:20 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 09, 2009 12:57 pm
Posts: 133
Where do the country IP blocks used in ASL come from? Wouldnt it be wise to offer a subscription option where higher quality IP lists could be used (like maxmind or similar)?

If I block just FIVE countries (which have never purchased anything anyways) I will have a 90% reduction in OSSEC alerts. The China netblock, for example, has a lot of holes. These just popped up today, though the entire country is supposed to be blocked:

Code:
   123.138.21.0 - 123.138.21.255
   222.90.0.0 - 222.91.255.255
   113.0.0.0 - 113.255.255.255

_________________
CentOS 6.3 (2.6.32.60-40.art.x86_64)
ASL 3.2.13-30.el6.art
Webmin 1.6.2
Virtualmin 3.99.gpl
Apache 2.2.15
PHP 5.3.3 (mod_fcgid/2.3.7)


Top
 Profile  
 
 Post subject: Re: Country IP blocks outdated?
Unread postPosted: Thu Aug 09, 2012 12:49 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
maxmind is already one of the sources, if you use their DB you will see that even their database did not have these changes in it yet.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group