PfBlocker
-
I think I've found an issue with the password field in the XMLRPC Sync pane. The field seems to truncate some passwords as it does not escape at least a subset of symbols. As a result, configs don't get synced properly across systems.
Thanks again for such a great package!
-
To prevent max table memory limit errors, pflBlocker cleans it's tables before reapply, that's why you have some seconds without "protection"
If you choose to update list every hour, then every hour you will have some seconds off.
OK. That's helpful to know. I'll normally have the lists set for daily updates. It looks like that happens at 23:00.
I'll write a script to cycle the mail server service during that time.Thanks.
-
I think I've found an issue with the password field in the XMLRPC Sync pane. The field seems to truncate some passwords as it does not escape at least a subset of symbols. As a result, configs don't get synced properly across systems.
Thanks again for such a great package!
Sync problem you did was related to old package's version or password symbols?
-
Password symbols in the newest version (1.0.1)
-
OK. That's helpful to know. I'll normally have the lists set for daily updates. It looks like that happens at 23:00.
I'll write a script to cycle the mail server service during that time.Also take a look on other great packages to get even better antispam protection. ;D
Postfix forwarder and mailscanner.
-
Also take a look on other great packages to get even better antispam protection.
Postfix forwarder and mailscanner.
sigh I suppose I have to grow up and play with the big-boy toys sometime.
I have a ?
Is there a way to force pfBlocker to manually pull a list update? For the life of me, I can't figure out how to do it.
I keep having to wait for the scheduled updates to occur. -
This package seems not to work with multiple WAN interfaces. When more than 1 inbound interface is selected the firewall rules are only added to the 1 WAN interface.
-
Oi marcello, I got the multiple WAN interfaces working by adding a dummy rule and then starting pfblocker.
One thing I notice is when lists are added they consume RAM but when the list is removed the RAM is not returned.
Obrigado!
-
If you have no rules on inbound interfaces, you are already blocking everything.
The memory usage is controled by freebsd, there is no code to keep lists on memory after apply config is finished.
-
Memory consumed by the system will go inactive when not in use, like when you stop pfblocker or delete tables. That physical memory is still allocated by the OS for a period of time before it's released back into a shared pool.
That memory will return back to the OS after a little.
-
A screencap of 21 hours of spam blocking.
CustomSpamList and CorpSpam are the lists I maintain in response to the spams we get.
Considering this is for less than 10 email accounts I find these numbers appalling.We still have about 10 spams get through each day, mostly sent from compromised Hotmail/Yahoo accounts.
I'm hoping postfix will help me achieve total-spam-free-ness.
-
I have noticed when using some I-Blocklist lists in deny inbound and deny outbound with p2p file formats dns stops working with the machines on my lan side, but when I switch to cidr file formats dns works.
-
P2p lists are converted to cidr format after download. If p2p range generates a network mask bigger then /16, pfBlocker will TRF to find a network cidr for this, What could result on a /12 or /8 network. In this situation, you may have some non blacklisted ips blocked.
Cidr is the recommended format for lists.
-
Hi,
Like the package - great work.
I was just wondering if you plan on creating a report or some king of logs where it breaks down the attacks by country.
The dashboard widget is great as this give it you by region, if you can add the option to break it down by country and source (interface) that would be even better.
This way it will us the ability to see where that attacks are coming from.Regards.
George
-
No plans for that. :(
The continent based alias is there to reduce rules and for easy configuration.All denied rules will be logged if you select this feature but you will need to look for ip country source the same way.
Imagine an alias for each country. You can build these custom lists downloading from countryblock website, but i think you will need a subscription for that.
-
malc0de.com keeps up a realtime list of malware serving IPs addresses.
This list -> http://malc0de.com/bl/IP_Blacklist.txt will autoupdate and works in pfBlocker lists section.
More on malc0de -> http://malc0de.com/dashboard/
malc0de's searchable database -> http://malc0de.com/database/The malware list contains the malicious IP, referenced in the following Webroot blog:
http://blog.webroot.com/2012/01/25/researchers-intercept-a-client-side-exploits-serving-malware-campaign/
That's a good sign it's kept up to date. -
malc0de.com keeps up a realtime list of malware serving IPs addresses.
This list -> http://malc0de.com/bl/IP_Blacklist.txt will autoupdate and works in pfBlocker lists section.
More on malc0de -> http://malc0de.com/dashboard/
malc0de's searchable database -> http://malc0de.com/database/The malware list contains the malicious IP, referenced in the following Webroot blog:
http://blog.webroot.com/2012/01/25/researchers-intercept-a-client-side-exploits-serving-malware-campaign/
That's a good sign it's kept up to date.Thanks for the all the information you have posted.
-
malc0de.com keeps up a realtime list of malware serving IPs addresses.
This list -> http://malc0de.com/bl/IP_Blacklist.txt will autoupdate and works in pfBlocker lists section.
2nd Update: After running this for a while I noticed more unexpected site blocking.
It may only be one or two IP addresses, but it trapped a lot of outgoing packets to media servers.I'm withholding any recommendation until I have the time to study the list - a couple of weeks.
note: The only verified contact I have for malc0de is their Twitter feed.
Thanks.
Update:
I added the lists to pfBlocker last night and found 2 unexpected site blocks.First was web.archive.org. Malc0de's entry is here.
I guess archive.org is caching some malicious files.Second is the IP 72.21.91.19; which is an edgecast address used for video streaming by break.com, wnd.com, brietbart, myspace and others.
A burner app from that IP was flagged for a few days, by ThreatExpert.I whitelisted the 1st IP and sent a synopsis to the Web Archive.
I tweeted a request to Malc0de to delist the 2nd.Meanwhile, I'll keep evaluating.
-
Oi marcello, I got the multiple WAN interfaces working by adding a dummy rule and then starting pfblocker.
One thing I notice is when lists are added they consume RAM but when the list is removed the RAM is not returned.
Obrigado!
Hi,
I have multiple LAN interfaces (I added LAN and my DMZ). When I see the firewall rules of the WAN interface, the pfBlocker rules are present 2 times (the same rules, added two times. Rule 1, Rule 2, Rule 3, Rule 1, Rule 2, Rule 3).Anyway, this do not affect anything, so don't worry…
Ciao,
Michele -
Hi,
I have multiple LAN interfaces (I added LAN and my DMZ). When I see the firewall rules of the WAN interface, the pfBlocker rules are present 2 times (the same rules, added two times. Rule 1, Rule 2, Rule 3, Rule 1, Rule 2, Rule 3).Anyway, this do not affect anything, so don't worry…
I'ts not fixed yet because I never could reproduce this visual issue.
You can also use alias only on action and create rules by rand.
Thanks for feedback. :)