<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #589: Blocking spammers at a firewall level</title>
    <link>http://localhost:8080/trac/ticket/589</link>
    <description>&lt;p&gt;
At the meeting on 5th September &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/585" title="maintenance: TTech Meeting 5th September 2013 (closed: fixed)"&gt;ticket:585&lt;/a&gt; one thing we discussed was that for August 2013:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote&gt;
&lt;p&gt;
More data is transferred for /user/register than the front page, 5.1GB compared to 3.6GB.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Most of this will be spam bots trying to register to post spam. Jim suggested that we could look at blocking some of these spam bots at a firewall level to save on resources. This ticket is to follow up on this suggestion.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/589</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Fri, 06 Sep 2013 11:20:25 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/589#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/589#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The place to enable this is &lt;tt&gt;/etc/csf/csf.conf&lt;/tt&gt; in the section labelled:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# SECTION:Global Lists/DYNDNS/Blocklists
&lt;/pre&gt;&lt;p&gt;
It's a case of settings some false/0 to 1/true... Also you should set &lt;tt&gt;_CUSTOM_CONFIG_CSF=YES&lt;/tt&gt; in &lt;tt&gt;#~/.barracuda.cnf&lt;/tt&gt; so these settings aren't overwritten by BOA updates.
&lt;/p&gt;
&lt;p&gt;
However, I'd recommend doing this one AFTER the &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/586" title="maintenance: New Relic Monitoring for BOA (closed: fixed)"&gt;#586&lt;/a&gt; New Relic install so we get the latest BOA version of csf.conf before locking updates to it. Then we get the recent improvements, plus anti-spam protection at a firewall level.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sun, 15 Sep 2013 17:08:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/589#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/589#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.7&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.1&lt;/em&gt; to &lt;em&gt;0.8&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The &lt;tt&gt;/etc/csf/csf.blocklists&lt;/tt&gt; contains configs for the following lists, I have noted which ones have been enabled.
&lt;/p&gt;
&lt;p&gt;
The firewall was restarted:
&lt;/p&gt;
&lt;pre class="wiki"&gt;csf -r
&lt;/pre&gt;&lt;p&gt;
And the documentation updated, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#CSFLDF"&gt;wiki:PuffinServer#CSFLDF&lt;/a&gt;
&lt;/p&gt;
&lt;h2 id="SpamhausDontRouteOrPeerListDROP"&gt;Spamhaus Don't Route Or Peer List (DROP)&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.spamhaus.org/drop/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.spamhaus.org/drop/&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
DROP (Don't Route Or Peer) and EDROP are advisory "drop all traffic" lists, consisting of stolen 'hijacked' netblocks and netblocks controlled entirely by criminals and professional spammers. DROP and EDROP are a tiny subset of the SBL designed for use by firewalls and routing equipment.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
This looks safe to enable.
&lt;/p&gt;
&lt;h2 id="DShield.orgRecommendedBlockList"&gt;DShield.org Recommended Block List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://dshield.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dshield.org&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This list summarized the top 20 attacking class C (/24) subnets over the last three days.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
This looks safe to enable.
&lt;/p&gt;
&lt;h2 id="TORExitNodes"&gt;TOR Exit Nodes&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="https://trac.torproject.org/projects/tor/wiki/doc/TorDNSExitList"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.torproject.org/projects/tor/wiki/doc/TorDNSExitList&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I'm strongly opposed to this being enabled.
&lt;/p&gt;
&lt;h2 id="BOGONlist"&gt;BOGON list&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.team-cymru.org/Services/Bogons/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.team-cymru.org/Services/Bogons/&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
A bogon prefix is a route that should never appear in the Internet routing table. A packet routed over the public Internet (not including over VPNs or other tunnels) should never have a source address in a bogon range. These are commonly found as the source addresses of DDoS attacks.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
This looks safe to enable.
&lt;/p&gt;
&lt;h2 id="ProjectHoneyPotDirectoryofDictionaryAttackerIPs"&gt;Project Honey Pot Directory of Dictionary Attacker IPs&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.projecthoneypot.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.projecthoneypot.org&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Project Honey Pot is the first and only distributed system for identifying spammers and the spambots they use to scrape addresses from your website.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
This looks safe to enable.
&lt;/p&gt;
&lt;h2 id="C.I.ArmyMaliciousIPList"&gt;C.I. Army Malicious IP List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.ciarmy.com"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.ciarmy.com&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Based on information from our network of Sentinel devices deployed around the world, we compile a list of known bad IP addresses. How do we know their bad? We utilize DPAM (read more about DPAM here), and part of that is proprietary, but here's a hint: Sentinel devices are uniquely positioned to pick up traffic from bad guys without requiring any type of signature-based or rate-based identification. If an IP is identified in this way by a significant number of Sentinels, we feel confident the IP is malicious and should be blocked.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Not sure about this one, not enabling it for now, the list isn't that long.
&lt;/p&gt;
&lt;h2 id="BruteForceBlockerIPList"&gt;BruteForceBlocker IP List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://danger.rulez.sk/index.php/bruteforceblocker/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://danger.rulez.sk/index.php/bruteforceblocker/&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
block SSH bruteforce attacks via firewall
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Makes sense, I have enabled this one.
&lt;/p&gt;
&lt;h2 id="EmergingThreats-RussianBusinessNetworksList"&gt;Emerging Threats - Russian Business Networks List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
IP address ranges from which the former customers of the RBN ISP, their malware marketing affiliate networks, emulators, and other organized crime groups exploit consumers. Block at will. Test for your production environment prior to utilization.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Not sure about this one, not enabling it for now.
&lt;/p&gt;
&lt;h2 id="OpenBL.org30dayList"&gt;OpenBL.org 30 day List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.openbl.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.openbl.org&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The OpenBL.org project (formerly known as the SSH blacklist) is about detecting, logging and reporting various types of internet abuse. Currently our hosts monitor ports 21 (FTP), 22 (SSH), 23 (TELNET), 25 (SMTP), 110 (POP3), 143 (IMAP), 587 (Submission), 993 (IMAPS) and 995 (POP3S) for bruteforce login attacks as well as scans on ports 80 (HTTP) and 443 (HTTPS) for vulnerable installations of phpMyAdmin and other web applications.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Enabled.
&lt;/p&gt;
&lt;h2 id="AutoshunShunList"&gt;Autoshun Shun List&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="http://www.autoshun.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.autoshun.org/&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;a class="missing wiki"&gt;AutoShun?&lt;/a&gt; is a Snort plugin that allows you to send your Snort IDS logs to a centralized server that will correlate attacks from your sensor logs with other snort sensors, honeypots, and mail filters from around the world.
&lt;/p&gt;
&lt;p&gt;
With the Autoshun plugin installed you can contribute alerts from your IDS/IPS Sensors to the assist the fight against bots, worms, spam engines, and zombies!
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Enabled.
&lt;/p&gt;
&lt;h2 id="MaxMindGeoIPAnonymousProxies"&gt;MaxMind GeoIP Anonymous Proxies&lt;/h2&gt;
&lt;p&gt;
Details: &lt;a class="ext-link" href="https://www.maxmind.com/en/anonymous_proxies"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.maxmind.com/en/anonymous_proxies&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This is another one which we should not use.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 15 Nov 2013 12:16:06 GMT</pubDate>
      <title>hours, status, totalhours changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/589#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/589#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.8&lt;/em&gt; to &lt;em&gt;0.9&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
This ticked has been linked to from the server documentation, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#Blocklists"&gt;wiki:PuffinServer#Blocklists&lt;/a&gt; and I can't see any reason not to now close it.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>