Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 9 of 9

This is a discussion on What IP block lists is Jag using if any? in the VPS & Dedicated forum
The reason I ask this is because I want to make sure I'm not allocating resources needlessly if Jag is already doing this. For example ...

  1. #1
    Nearly 100% Pure Carbon thecoalman's Avatar
    Join Date
    Nov 2007
    Location
    Northeast Pennsylvania
    Posts
    529

    What IP block lists is Jag using if any?

    The reason I ask this is because I want to make sure I'm not allocating resources needlessly if Jag is already doing this. For example using APF you have an option to load this list:

    The Spamhaus Project - DROP

    DROP (Don't Route Or Peer) is an advisory "drop all traffic" list, consisting of stolen 'hijacked' netblocks and netblocks controlled entirely by professional spammers. DROP is a tiny subset of the SBL designed for use by firewalls and routing equipment.

    The DROP list will not include any IP address space under the control of any legitimate network - even if being used by "the spammers from hell". DROP will only include netblocks allocated directly by an established Regional Internet Registry (RIR) or National Internet Registry (NIR) such as ARIN, RIPE, AFRINIC, APNIC, LACNIC or KRNIC or direct RIR allocations illicitly taken from the original allocatee, that is, the troubling run of "hijacked" IP address blocks that have been snatched away from their original owners (which in most cases are long dead corporations) and are now controlled by spammers or netblock thieves who resell the space to spammers.

    When implemented at a network or ISP's 'core routers', DROP will help protect the network's users from spamming, scanning, harvesting, DNS-hijacking and DDoS attacks originating on rogue netblocks.
    Last edited by thecoalman; 02-19-2012 at 02:33 PM.

  2. #2
    JPC Dream Team JPC-Katrina's Avatar
    Join Date
    Dec 2011
    Posts
    109
    The lists would be whatever is used by the CSF firewall. I believe it blocks traffic on the DShield Block List and the Spamhaus DROP List. Be sure to keep CSF updated.
    Katrina | Tech Support Manager
    JaguarPC.com
    Helpful Link: http://www.jaguarpc.com/support/kbase/

  3. #3
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by JPC-Katrina View Post
    The lists would be whatever is used by the CSF firewall. I believe it blocks traffic on the DShield Block List and the Spamhaus DROP List. Be sure to keep CSF updated.
    I think he is asking about network level not Server level Blocks

    CSF is the Firewall JPC uses on the cPanel Shared Servers correct? Sounds like thecoalman is using AFP instead of CSF

    I could be wrong though and your talking about something else
    -------------------------
    the_ancient
    MP Technology Group

  4. #4
    JPC Dream Team JPC-Katrina's Avatar
    Join Date
    Dec 2011
    Posts
    109
    CSF is server level and we recommend using csf + lfd rather than apf. Nothing at network level.
    Katrina | Tech Support Manager
    JaguarPC.com
    Helpful Link: http://www.jaguarpc.com/support/kbase/

  5. #5
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by JPC-Katrina View Post
    CSF is server level and we recommend using csf + lfd rather than apf. Nothing at network level.
    The problem is not all Control Panel Software support CSF, Interworx uses APF and APF Only, only cPanel, Direct Admin and Webmin support CSF
    -------------------------
    the_ancient
    MP Technology Group

  6. #6
    JPC Dream Team JPC-Katrina's Avatar
    Join Date
    Dec 2011
    Posts
    109
    APF also appears to use Dshield and Spamhaus. CSF is still recommended if it is available to use.
    Katrina | Tech Support Manager
    JaguarPC.com
    Helpful Link: http://www.jaguarpc.com/support/kbase/

  7. #7
    Nearly 100% Pure Carbon thecoalman's Avatar
    Join Date
    Nov 2007
    Location
    Northeast Pennsylvania
    Posts
    529
    Quote Originally Posted by the_ancient View Post
    I think he is asking about network level not Server level Blocks
    This is exactly what I'm asking, it's understandable they wouldn't be using many if any but if you take the list described above as far as I can tell no legitimate traffic would be coming from any of those IP's. The point of course is if Jag is using lists like this I have no reason to block them at the server level.

  8. #8
    Nearly 100% Pure Carbon thecoalman's Avatar
    Join Date
    Nov 2007
    Location
    Northeast Pennsylvania
    Posts
    529
    Quote Originally Posted by JPC-Katrina View Post
    APF also appears to use Dshield and Spamhaus. CSF is still recommended if it is available to use.
    There is three lists you can enable in the configuration. The one from Spamhaus is easily the largest and as already mentioned it blocks IP's that have been hijacked. The other two lists are most active IP's, one from dsshield and another from the Honey Pot Project.


    # [Remote Rule Imports]
    ##
    # Project Honey Pot is the first and only distributed system for identifying
    # spammers and the spambots they use to scrape addresses from your website.
    # This aggregate list combines Harvesters, Spammers and SMTP Dictionary attacks
    # from the PHP IP Data at: Malicious IPs | By Last Bad Event | Project Honey Pot
    DLIST_PHP="0"

    DLIST_PHP_URL="rfxn.com/downloads/php_list"
    DLIST_PHP_URL_PROT="http"

    # The Spamhaus Don't Route Or Peer List (DROP) is an advisory "drop all
    # traffic" list, consisting of stolen 'zombie' netblocks and netblocks
    # controlled entirely by professional spammers. For more information please
    # see The Spamhaus Project - DROP.
    DLIST_SPAMHAUS="0"

    DLIST_SPAMHAUS_URL="www.spamhaus.org/drop/drop.lasso"
    DLIST_SPAMHAUS_URL_PROT="http"

    # DShield collects data about malicious activity from across the Internet.
    # This data is cataloged, summarized and can be used to discover trends in
    # activity, confirm widespread attacks, or assist in preparing better firewall
    # rules. This is a list of top networks that have exhibited suspicious activity.
    DLIST_DSHIELD="0"

    DLIST_DSHIELD_URL="feeds.dshield.org/top10-2.txt"
    DLIST_DSHIELD_URL_PROT="http"

  9. #9
    Nearly 100% Pure Carbon thecoalman's Avatar
    Join Date
    Nov 2007
    Location
    Northeast Pennsylvania
    Posts
    529
    Quote Originally Posted by JPC-Katrina View Post
    Nothing at network level.
    Would it make sense to use the Spamhaus drop list at network level instead of having it be done at server level?

    It's list of IP's that no legitimate traffic could come from.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •