![]() |
qmail hosts.deny.gz |
![]() |
evil-clients.cidr.gz |
![]() |
exim4_local_host_blacklist.gz |
| MS-Exchange (no expire): |
msexchange7-Add-IPBlockListEntries.cmdlet.zip |
| MS Exchange (with expire date): |
msexchange7-Add-IPBlockListEntries.expire.cmdlet.zip |
Today, Courier MTA blacklist were needed - first alpha outputs were generated the next hour.
We started autogenerating
to block any communication to known Destinations from MS08-067 Worm, Downadup/Conflicker and make them availailable to public.
Please check scripts for nets you should not drop connection to, because your customers might need them.
See here and here for more info.
ipseccmd.exe to be found on your system CD->Support->Tools.
Powershell 1.0 and 2.0PRE CTP can be downloaded from Microsoft.
2010/01/12 - Windows 7 integrates netsh - with PowerGui script processing and firewall-control gets easy.
2009/04/25 - currently auto-tagging networks
2009/04/25 - checked 2.9 Mio generic domains from Conficker A,B,C and attached results to this article
2009/02/16 - added today's IPs
2009/02/17 - Neue Medien Munnich requested removing 85.13.136.31 - done.
2009/02/21 - added yesterday's IPs
2009/04/22 - added destination list with counter
We covered iptables on Linux and Windows-Firewall. Now we are doing the same for MacOS X:
The rules come unnumbered and will be placed after 20.000 in steps of 100 if you run the scripts unmodified.
Last entry with ipfw list is 65.535 - so it makes no sense to use the firewall rulesets to block these >50.000 spammer-nets. Better use the configs for MTA's instead.
More Info about MacOSX ipfw-based firewalling to be found on Universität Innsbruck and www.chaos-net.de in german and Novajo.ca in english.
Generating policies for WindowsFirewall based on netsh advfirewall from Power-Shell:
Tested with PowerShellV1.0 and PowerShellV2.0 PreRelease (CTP/Graphical). You might check out PowerGUI from powergui.org.
For XP/2003-Server there is no advfirewall option available - we have to use ipseccmd.exe from commandline:
"The netsh advfirewall context is only available on computers that are running Microsoft® Windows Vista® or Windows Server® 2008. IPsec or firewall policies created by using this context cannot be used to configure computers that are running earlier versions of Windows. To use a command line to configure Windows Firewall or IPsec on computers that are running earlier versions of Windows, you must use a utility that is designed for the appropriate operating system. For example, to use the command line to configure IPsec policies on computers that are running Windows XP, use IPsecCmd.exe, which is provided on the Windows XP CD, in the \Support\Tools folder. To use the command line to configure IPsec policies on computers that are running Windows 2000, use IPsecPol.exe, which is provided with the Windows 2000 Server Resource Kit. Run these commands only on the operating systems for which they were designed. Running them on Windows Vista or Windows Server 2008 is not supported."
See TechNet for reference.
Therefore we generate batch-jobs that affect one global filter-rule 'netsecdb filters' anding policies to it.
We have chosen old fashioned batch-format because it's easier to combine with wget(win32) and 7zip for automation.
version of
for use in combination with pfsense firewalls
version of
for use in combination with cisco routers

full version of
block access to spamlinkdestination networks for your users with this admin friendly ios-config for cisco:
just cut-copy-paste into your exported router-config and save back.
beta-version
each license to be used on one router
2009/08/01 Update: shop is active and files are available.
We are still implementing shop functionalities into page and only listed tryout section to public. After registering, you will find more articles, but - SHOP IS NOT ACTIVE YET. It's a work in progress and just viewable to give you an idea.
After login, every registered user will find the tryout files in his/her my-acount->files-section ready for direct download.

full version of
block access to spamlinkdestination networks for your users with this admin friendly alias-config and rulesets for pfsense firewalls:
just cut-copy-paste into your exported alias.xml and save back.
The same procedure with ruleset into your exported filter.xml. Try out with test-machine or in VM first - i had no errors. Neither in test nor in productive units.

tryout version of
for use in combination with exim MTA 4.x
/etc/exim4/local_host_blacklist
is an optional file containing a list of IP addresses, networks and host names whose messages will be denied with the error message "locally blacklisted".
we additionally add netsecdb's record id and country above the cidr-line.

full version of
for use in combination with apache webserver
redirects attacks to external URL's
protects netsecdb vhost
each license to be used on one server/vserver.

tryout version of
for use in combination with postfix MTA
each license to be used on one server/vserver.

tryout version of
for use in combination with xinetd+qmail
each license to be used on one server/vserver.
version of
for use with MS Exchange Server 7
version of
for use with apache webserver
version of
for use on linux based servers with iptables support

Copyright © 2008-2010 Claus Marxmeier EDV-Service
Alle Rechte vorbehalten. Insbesondere dürfen Nachdruck, Aufnahme in Online-Dienste und Internet und Vervielfältigung auf Datenträger
wie CD-ROM, DVD-ROM etc. nur nach vorheriger schriftlicher Zustimmung erfolgen.
Die Anbieter haften nicht für unverlangt eingesandte Manuskripte und Fotos.
Designed by Claus Marxmeier.
