Blocked China and Korea

I blocked China and Korea off my machine yesterday around lunch time. After 24 hours of these rules in place I have blocked 3500 packets already, thats shocking!

I scripted it all to block these countries and also to block a number of other things like proxy scanners from irc networks, windows networking ports etc. I simply drop the rules into a set using ipfw and move the temp set over the old set to activate the new rules, works a charm and enables me to rebuild the blocking rules regularly without disrupting my other rules.

Now I wonder what these 3500 packets were, so I might enable logging and do some stats on the stuff.

1 Comment

Hi,

We are experiencing the same problem with chinese and korean ppl - we are running a voice over ip service, and they managed to steal several paypal accounts , resulting in over 6000USD of fraudulent purchase - for the past 3 days we've been battling to blacklist IP addresses 1by1. But as they operate overnight, by the time we block the user, it's already too late .

Could you please kindly explain how to block china and korea in ipfw ?

Thanks in advance for your help.

AB

Leave a comment

Recent Entries

  • flashpolicyd 2.0

    I wrote a multi threaded server for Adobe Flash Policy requests, some background from Adobe:Since policy files were first introduced, Flash Player has recognized /crossdomain.xml...

  • Adventures with Ruby

    Some more about my continuing experiences with ruby, in my last post I saidthe language does what you'd expect and as you'll see in my...

  • New programming language of choice - Ruby

    I have fallen out of love with Perl some time ago, I cannot point to one specific thing about it that put me off, I...

  • On working from home

    I've not been posting much here, work has been incredibly manic the last while, especially I need to still finish off my SSO posts with...

  • Rework of puppet facts for /etc/facts.txt

    Previously I blogged a custom fact that reads /etc/facts.txt to build up some custom facts for use in Puppet manifests, well I've since learned a...

Close