Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Excellent new blacklist service, now how to implement on pfblocker???

    Scheduled Pinned Locked Moved Firewalling
    1 Posts 1 Posters 660 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      totalimpact
      last edited by

      I just came across this- projecthoneypot.org

      They are a collective honey pot, you can join in an active manner by giving them access to your honeypot, or simply utilize their DNSBL. They monitor websites that get scanned by harvester bots, and also comment forms on blogs/forums, and their system is pretty crafty in that it generates a unique email for every spammer that accesses the script, so they can track an entire spam botnet back to its source - its like killing the original vampire ;).

      Looking at their stats, 245,722,827 contributing honey pot traps, it looks to have a wider reach than many of the other DNS blacklists I have seen.
      http://www.projecthoneypot.org/statistics.php

      They have been active since 2004, so there are lots of contributors.

      I am wondering if there is a way to integrate this in to a pfblocker source.

      Their DNS lookups are like this with a reversed IP:
      randomAPIkey.4.3.2.1.dnsbl.httpbl.org

      with the randomAPIkey being a key you need to sign up for (free). Does anyone know if this is possible on the current pfblocker package? I know there may be memory/speed limitations in the design of using a list like this, so more hardware may be needed to do that, but that can be a choice made by the user.

      Their documentation is here:
      https://www.projecthoneypot.org/httpbl_api.php

      Some may say its just spam, but this tracks entire botnets that may be used for other malicious activity.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.