Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    3.1.0_6 UPDATE

    Scheduled Pinned Locked Moved pfBlockerNG
    77 Posts 14 Posters 16.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jdeloach @SteveITS
      last edited by

      @steveits said in 3.1.0_6 UPDATE:

      @cloudified said in 3.1.0_6 UPDATE:

      It would be nice if the package checked that setting upon install and showed a warning somewhere.

      @jdeloach said in 3.1.0_6 UPDATE:

      As far as the default value, that bug/error has been around since day one ....

      The Firewall Maximum Table Entries setting is a pfSense setting...it has nothing to do with the pfBlocker package.

      You are correct, too damn many pf...... in pfSense/packages.

      1 Reply Last reply Reply Quote 1
      • S
        SteveITS Galactic Empire @keyser
        last edited by

        @keyser said in 3.1.0_6 UPDATE:

        Rumors have it that it is Netgate that maintains this package now

        FYI Netgate has a list: https://www.netgate.com/supported-pfsense-plus-packages

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote šŸ‘ helpful posts!

        lohphatL 1 Reply Last reply Reply Quote 0
        • lohphatL
          lohphat @SteveITS
          last edited by

          @steveits

          Note that pfBlockerNG and pfBlockerNG-devel are NOT the same package and are on different development tracks.

          pfBlockerNG-devel will eventually replace pfBlockerNG but for now they're separate.

          SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_1)

          1 Reply Last reply Reply Quote 0
          • R
            rcoleman-netgate Netgate @keyser
            last edited by

            @keyser said in 3.1.0_6 UPDATE:

            I wonder whats going on here… Rumors have it that it is Netgate that maintains this package now and @BBcan177 is no longer on board.

            The thing about rumors... is that they're difficult to prove, or disprove.

            TAC doesn't provide support for pfBlockerNG. BBcan is the maintainer. As I understood it BBcan was on paternity leave for the last few months.

            What I can tell you is a colleague in TAC wrote a patch for the issue that was effecting logging (IIRC) and I think that's where people are thinking it's now a Netgate product. It was a patch, nothing more.

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            DefenderLLCD 1 Reply Last reply Reply Quote 4
            • DefenderLLCD
              DefenderLLC @rcoleman-netgate
              last edited by

              @rcoleman-netgate said in 3.1.0_6 UPDATE:

              @keyser said in 3.1.0_6 UPDATE:

              I wonder whats going on here… Rumors have it that it is Netgate that maintains this package now and @BBcan177 is no longer on board.

              The thing about rumors... is that they're difficult to prove, or disprove.

              TAC doesn't provide support for pfBlockerNG. BBcan is the maintainer. As I understood it BBcan was on paternity leave for the last few months.

              What I can tell you is a colleague in TAC wrote a patch for the issue that was effecting logging (IIRC) and I think that's where people are thinking it's now a Netgate product. It was a patch, nothing more.

              Plus he was very forthcoming about the issue and an upcoming patch and how to fix the issue beforehand...

              R 1 Reply Last reply Reply Quote 0
              • R
                rcoleman-netgate Netgate @DefenderLLC
                last edited by

                @cloudified Never let a good theory get in the way of reality... :D

                Ryan
                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                Requesting firmware for your Netgate device? https://go.netgate.com
                Switching: Mikrotik, Netgear, Extreme
                Wireless: Aruba, Ubiquiti

                1 Reply Last reply Reply Quote 2
                • J
                  JMV43 0 @BBcan177
                  last edited by

                  @bbcan177 Changing subject, "Thousands of GitHub repositories deliver fake PoC exploits with malware" found this on Bleeping Computer, some of the pfBlocker feeds are named in this article.

                  JMV

                  lohphatL BBcan177B 2 Replies Last reply Reply Quote 0
                  • lohphatL
                    lohphat @JMV43 0
                    last edited by

                    @jmv43-0 ??? I'm not aware of any IP or DNSBL list downloads from pfBlocker feeds which contain executable scripts. They're just lists of IPs, CIDRs, FQNDs to build lookup tables.

                    Do you have an example feed which contains a script?

                    SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_1)

                    J 1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator @JMV43 0
                      last edited by

                      @jmv43-0

                      https://twitter.com/BleepinComputer/status/1584202031044374528?t=0XBrpP3vz_7XvkMFnW4PcQ&s=19

                      "By looking closer into some of those cases, the researchers found a plethora of different malware and harmful scripts, ranging from remote access trojans to Cobalt Strike."

                      "IP address analysis: comparing the PoC's publisher IP to public blocklists"

                      So basically there are scripts and executables that were found in several Github repositories.

                      The researchers found that some of those malware IPs were matched in the public IP blocklists.

                      The best blocklists being hpHosts and Stop Forum Spam.

                      Tho hpHosts has been closed but I have been trying to get it back some what:

                      https://twitter.com/BBcan177/status/1582913688058855426?t=abL5y3qyGMikWZgRn7mbnw&s=19

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177Ā  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      BBcan177B J 2 Replies Last reply Reply Quote 2
                      • BBcan177B
                        BBcan177 Moderator @BBcan177
                        last edited by BBcan177

                        And another reason why I resisted to automatically unblock any IPs of any feeds.

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177Ā  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        DefenderLLCD P 2 Replies Last reply Reply Quote 1
                        • DefenderLLCD
                          DefenderLLC @BBcan177
                          last edited by

                          @bbcan177 Good idea. Making the same change now...

                          1 Reply Last reply Reply Quote 0
                          • J
                            JMV43 0 @lohphat
                            last edited by

                            @lohphat Looking for a short and concise answer. Are they dangerous or not? I'm not a professional at this like some of you are.

                            JMV

                            1 Reply Last reply Reply Quote 0
                            • J
                              JMV43 0 @BBcan177
                              last edited by JMV43 0

                              @bbcan177 Thank you. I just needed to make sure it didn't somehow affect pfBlocker's feeds..

                              JMV

                              1 Reply Last reply Reply Quote 0
                              • P
                                pfsjap @BBcan177
                                last edited by

                                @bbcan177 said in 3.1.0_6 UPDATE:

                                And another reason why I resisted to automatically unblock any IPs of any feeds.

                                I don't get it, how would you automatically unblock IPs of some feed?

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @pfsjap
                                  last edited by

                                  @pfsjap said in 3.1.0_6 UPDATE:

                                  how would you automatically unblock IPs of some feed?

                                  By using a build in list called 'auto unblock' ;)

                                  Now the question goes to 'why' - right ?

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  P 1 Reply Last reply Reply Quote 0
                                  • P
                                    pfsjap @Gertjan
                                    last edited by

                                    @gertjan I don't want to unblock IPs in a blocklist, I just can't see how that would even be possible.
                                    I guess I could change the rule action from Reject to Pass, but 'Auto unblock'?

                                    DefenderLLCD 1 Reply Last reply Reply Quote 0
                                    • DefenderLLCD
                                      DefenderLLC @pfsjap
                                      last edited by

                                      @pfsjap I was wondering this myself. Got confused with Suricata where this feature is an option.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.