Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can I use Malware Filter Lists in pfBlockerNG that contain only IP address

    Scheduled Pinned Locked Moved pfBlockerNG
    11 Posts 5 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      IPv4/6 lists can be added to the IPv4/6 tabs respectively.  Domain based lists can be added to the DNSBL feeds tab. All the lists above are usable in the pkg.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • XentrkX
        Xentrk
        last edited by

        @BBcan177:

        IPv4/6 lists can be added to the IPv4/6 tabs respectively.  Domain based lists can be added to the DNSBL feeds tab. All the lists above are usable in the pkg.

        Thank you @BBcan177.  Doing as you suggest is the solution. I ran the update to confirm. Thanks for the help and for developing the great package pfBlockerNG!

        pfSense 2.4.4_2 | Intel i5-3450 @ 3.10GHz  | AES-NI enabled |  pfBlockerNG | Snort
        Blog Site: https://x3mtek.com || GitHub: https://github.com/Xentrk

        1 Reply Last reply Reply Quote 0
        • M
          moscato359
          last edited by

          Instead of that pile of ransomeware lists, have you considered the combined one?

          https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt

          https://ransomwaretracker.abuse.ch/blocklist/ has the details

          It contains TC_PS_IPBL, LY_C2_IPBL, TL_C2_IPBL, TL_PS_IPBL, CB_PS_IPBL

          1 Reply Last reply Reply Quote 0
          • XentrkX
            Xentrk
            last edited by

            Thanks for the suggestion. I am always looking for better ways!  :)

            pfSense 2.4.4_2 | Intel i5-3450 @ 3.10GHz  | AES-NI enabled |  pfBlockerNG | Snort
            Blog Site: https://x3mtek.com || GitHub: https://github.com/Xentrk

            1 Reply Last reply Reply Quote 0
            • QinnQ
              Qinn
              last edited by

              I get a  error on https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt in IPv4  anyone any suggestions?

              [ RW_IPBL ] Downloading update . cURL Error: 35
              OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to ransomwaretracker.abuse.ch:443  Retry in 5 seconds…
              . cURL Error: 35

              Cheers Qinn

              Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
              Firmware: Latest-stable-pfSense CE (amd64)
              Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

              1 Reply Last reply Reply Quote 0
              • F
                f34rinc
                last edited by

                @Qinn:

                I get a  error on  cURL Error: 35 OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to ransomwaretracker.abuse.ch:443  Retry in 5 seconds…

                Can you change the format type to AUTO and try again

                ![2017-06-14 11_46_22.png](/public/imported_attachments/1/2017-06-14 11_46_22.png)
                ![2017-06-14 11_46_22.png_thumb](/public/imported_attachments/1/2017-06-14 11_46_22.png_thumb)

                1 Reply Last reply Reply Quote 0
                • QinnQ
                  Qinn
                  last edited by

                  Thanks for your reply, but it  was on "Auto" when the error was created, so no hopes there I am afraid.

                  Cheers Qinn

                  Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                  Firmware: Latest-stable-pfSense CE (amd64)
                  Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                  1 Reply Last reply Reply Quote 0
                  • BBcan177B
                    BBcan177 Moderator
                    last edited by

                    That URL seems to be ok?

                    curl -sI https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt

                    HTTP/1.1 200 OK
                    Date: Thu, 15 Jun 2017 03:17:16 GMT
                    Server: Apache/2
                    Strict-Transport-Security: max-age=15768000 ; includeSubDomains
                    Last-Modified: Thu, 15 Jun 2017 03:15:02 GMT
                    ETag: "2907a-551f7131791fa"
                    Accept-Ranges: bytes
                    Content-Length: 168058
                    Cache-Control: max-age=300
                    Expires: Thu, 15 Jun 2017 03:22:16 GMT
                    X-Content-Type-Options: nosniff
                    X-XSS-Protection: 1; mode=block
                    X-Frame-Options: sameorigin
                    Content-Type: text/plain

                    When you use "Auto" it will use TLS to connect to the Feed…  Do you have a proxy that might be causing issues?

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    1 Reply Last reply Reply Quote 0
                    • XentrkX
                      Xentrk
                      last edited by

                      @Qinn:

                      I get a  error on https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt in IPv4  anyone any suggestions?

                      [ RW_IPBL ] Downloading update . cURL Error: 35
                      OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to ransomwaretracker.abuse.ch:443  Retry in 5 seconds…
                      . cURL Error: 35

                      Cheers Qinn

                      I got around to updating my list and the URL worked for me. I used Auto, On, https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt and rwipbl for the field values.  Did you try going to the url in the browser?

                      pfSense 2.4.4_2 | Intel i5-3450 @ 3.10GHz  | AES-NI enabled |  pfBlockerNG | Snort
                      Blog Site: https://x3mtek.com || GitHub: https://github.com/Xentrk

                      1 Reply Last reply Reply Quote 0
                      • QinnQ
                        Qinn
                        last edited by

                        Suddenly it works  :o even with RW_IPBL?

                        Thanks for all reply's

                        Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                        Firmware: Latest-stable-pfSense CE (amd64)
                        Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.