Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG v2.1.1_7

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      pfBlockerNG v2.1.1_7 has been posted for review by the devs.

      https://github.com/pfsense/FreeBSD-ports/pull/331

      Changelog:

      • Some feeds are now using the HTTP Status code '304 not-modified'. The download function now reports this as a successful download.

      • DNSBL uses the Lighttpd conditional error_log to collect HTTPS alert details. A previous Lighttpd update changed the syntax of the log which stopped HTTPS logging. The code has been patched to address the change in log format syntax.

      • Typically when IPv4 feeds are downloaded, it uses string functions to parse the lines, however, a regex parser is used when the line is not in a standard format. The previous regex could incorrectly parse certain IPs:

        1.2.3.4/8fdhy[.]net/index.php

        Previous regex = 1.2.3.4/8
              New regex      = 1.2.3.4

      • Log Browser tab - check if file exists before attempting to view it.

      • Threat Source Lookups:

        Changed some feeds from http to https.
        Removed C-SIRT "Incidents-on-demand" as its doesn't seem to be online.
        Added new lookups to:  Shodan.io, urlscan.io, viewdns.info, VirusTotal (for DNSBL) and OTX Alienvault.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • G
        garyd9
        last edited by

        BBcan177, I didn't see it in the list of changes…  does this update include the fix for IPv6 block lists being configured as IPv4?

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          @garyd9:

          BBcan177, I didn't see it in the list of changes…  does this update include the fix for IPv6 block lists being configured as IPv4?

          This PR doesn't have the IPv6 fix. That fix will be in the next release… Still working on some loose ends...

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            @BBcan177:

            pfBlockerNG v2.1.1_7 has been posted for review by the devs.

            https://github.com/pfsense/FreeBSD-ports/pull/331

            Changelog:

            • Some feeds are now using the HTTP Status code '304 not-modified'. The download function now reports this as a successful download.

            • DNSBL uses the Lighttpd conditional error_log to collect HTTPS alert details. A previous Lighttpd update changed the syntax of the log which stopped HTTPS logging. The code has been patched to address the change in log format syntax.

            • Typically when IPv4 feeds are downloaded, it uses string functions to parse the lines, however, a regex parser is used when the line is not in a standard format. The previous regex could incorrectly parse certain IPs:

              1.2.3.4/8fdhy[.]net/index.php

              Previous regex = 1.2.3.4/8
                    New regex      = 1.2.3.4

            • Log Browser tab - check if file exists before attempting to view it.

            • Threat Source Lookups:

              Changed some feeds from http to https.
              Removed C-SIRT "Incidents-on-demand" as its doesn't seem to be online.
              Added new lookups to:  Shodan.io, urlscan.io, viewdns.info, VirusTotal (for DNSBL) and OTX Alienvault.

            This has now been merged and is available for download.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • W
              Wolf666
              last edited by

              I don't see it available on 2.4 repository.

              Modem Draytek Vigor 130
              pfSense 2.4 Supermicro A1SRi-2558 - 8GB ECC RAM - Intel S3500 SSD 80GB - M350 Case
              Switch Cisco SG350-10
              AP Netgear R7000 (Stock FW)
              HTPC Intel NUC5i3RYH
              NAS Synology DS1515+
              NAS Synology DS213+

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @Wolf666:

                I don't see it available on 2.4 repository.

                Thanks, I sent the devs a message!

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.