• IP Address Filter

    From Tim Whitson@1:103/705 to All on Sun Aug 1 21:04:53 2021
    Is there a maximum amount of IP addresses you can ban? I tried to ban 27.*.*.* since I get a lot of hack attacks from that series of IP addresses and one still got through.

    Tim

    ---
    þ Synchronet þ The Fool's Quarter - fqbbs.synchro.net
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Ragnarok@1:103/705 to Tim Whitson on Mon Aug 2 11:45:06 2021
    El 2/8/21 a las 01:04, Tim Whitson escribió:
    Is there a maximum amount of IP addresses you can ban? I tried to ban 27.*.*.*
    since I get a lot of hack attacks from that series of IP addresses and one still got through.

    Tim

    ---
    � Synchronet � The Fool's Quarter - fqbbs.synchro.net

    just make a firewall rule with that segment

    ---
    ï¿­ Synchronet ï¿­ Dock Sud BBS TLD 24 HS - bbs.docksud.com.ar
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Whitson on Mon Aug 2 12:12:18 2021
    Re: IP Address Filter
    By: Tim Whitson to All on Sun Aug 01 2021 09:04 pm

    Is there a maximum amount of IP addresses you can ban?

    No.

    I tried to ban
    27.*.*.* since I get a lot of hack attacks from that series of IP addresses and one still got through.

    You used the wrong syntax. Use "27.*" or "27.0.0.0/8" instead. https://wiki.synchro.net/config:filter_files#examples
    --
    digital man

    Synchronet "Real Fact" #13:
    Synchronet was the first BBS software to ship with internal QWK networking. Norco, CA WX: 93.5øF, 22.0% humidity, 2 mph ENE wind, 0.00 inches rain/24hrs --- SBBSecho 3.14-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Tim Whitson@1:103/705 to Digital Man on Mon Aug 2 20:15:41 2021
    Re: IP Address Filter
    By: Digital Man to Tim Whitson on Mon Aug 02 2021 12:12 pm

    You used the wrong syntax. Use "27.*" or "27.0.0.0/8" instead. https://wiki.synchro.net/config:filter_files#examples

    Thank you, I'll give that a try. Nice to see the Russians and the Chinese are out hacking so much...

    Tim

    ---
    þ Synchronet þ The Fool's Quarter - fqbbs.synchro.net
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Benny Pedersen@2:230/0 to Tim Whitson on Wed Aug 4 13:02:34 2021
    Hello Tim!

    02 Aug 2021 20:15, Tim Whitson wrote to Digital Man:

    Nice to see the Russians and the
    Chinese are out hacking so much...

    note 27.1 27.2 might be diffrent countries


    Regards Benny

    ... too late to die young :)
    --- Msged/LNX 6.1.2 (Linux/5.13.7-gentoo-dist (x86_64))
    * Origin: gopher://fido.junc.eu/ (2:230/0)
  • From Lord Blackfair@1:103/705 to Benny Pedersen on Thu Aug 5 09:49:29 2021
    Hello Tim!

    02 Aug 2021 20:15, Tim Whitson wrote to Digital Man:

    Nice to see the Russians and the
    Chinese are out hacking so much...

    note 27.1 27.2 might be diffrent countries


    Regards Benny

    ... too late to die young :)

    --- Msged/LNX 6.1.2 (Linux/5.13.7-gentoo-dist (x86_64))
    * Origin: gopher://fido.junc.eu/ (2:230/0)
    ¨ Synchronet ¨ Vertrauen ¨ Home of Synchronet ¨
    [vert/cvs/bbs].synchro.net

    Fill that IPcan
    Lord Blackfair (Blackfair's Manor) blackf.synchro.net

    ---
    þ Synchronet þ Blackfair's Manor - blackf.synchro.net
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Benny Pedersen@2:230/0 to Lord Blackfair on Thu Aug 5 20:56:38 2021
    Hello Lord!

    05 Aug 2021 09:49, Lord Blackfair wrote to Benny Pedersen:

    Fill that IPcan

    indeed


    Regards Benny

    ... too late to die young :)
    --- Msged/LNX 6.1.2 (Linux/5.13.8-gentoo-dist (x86_64))
    * Origin: gopher://fido.junc.eu/ (2:230/0)
  • From Neko@1:103/705 to Lord Blackfair on Thu Aug 12 01:31:14 2021
    Re: Re: IP Address Filter
    By: Lord Blackfair to Benny Pedersen on Thu Aug 05 2021 09:49:29

    Fill that IPcan

    Country IP scopes and paste every from China. Much better to see IP.CAN bans than logon attempts, failed requests and "no terminal" time cuts.

    ---
    þ Synchronet þ MIYANET - miya-net.tk:(22|23|80) | +48 782 287 282 (GSM)
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Keith Cunningham@1:129/125 to Neko on Fri Aug 13 12:24:17 2021
    Re: Re: IP Address Filter
    By: Neko to Lord Blackfair on Thu Aug 12 2021 01:31 am


    Fill that IPcan

    Country IP scopes and paste every from China. Much better to see IP.CAN bans than logon attempts, failed requests and "no terminal" time cuts.
    I dont get login attempts. I run a captcha before login.

    Lord Blackfair (Blackfair's Manor) blackf.synchro.net
    --- SBBSecho 3.14-Win32
    * Origin: Blackfair's Manor - blackf.synchro.net (1:129/125)
  • From Daryl Stout@1:103/705 to Keith Cunningham on Fri Aug 13 21:05:00 2021
    Keith,

    I dont get login attempts. I run a captcha before login.

    And, you did an EXCELLENT job with that utility. :)

    Daryl

    ... I came out of the closet...only because it was dark in there.
    --- MultiMail/Win v0.52
    þ Synchronet þ The Thunderbolt BBS - Little Rock, Arkansas
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Tracker1@1:103/705 to Tim Whitson on Sun Sep 5 15:26:11 2021
    On 8/1/2021 9:04 PM, Tim Whitson wrote:
    Is there a maximum amount of IP addresses you can ban? I tried to ban 27.*.*.*
    since I get a lot of hack attacks from that series of IP addresses and one still got through.

    I wouldn't block an entire class a. 27.0.0.1/22 seems to be a block for Amazon, so likely seeing traffic from ECS hosts, and/or other use.
    Though there are other 27.* hosts.

    Would lookup the specific IP and shoot off an email to their abuse@amazonaws.com if it is one of their IP block.

    The most you should ever block is a class b, and not sure if
    Synchronet's ip.can allows for specific bitmasks, such as 27.0.0.1/22 or
    not. If you're on linux, or using a linux router, you may be able to do
    other settings to block this traffic.
    --
    Michael J. Ryan - tracker1@roughneckbbs.com
    ---
    ï¿­ Synchronet ï¿­ Roughneck BBS - roughneckbbs.com
    --- SBBSecho 3.14-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tracker1 on Mon Sep 6 12:50:00 2021
    Re: Re: IP Address Filter
    By: Tracker1 to Tim Whitson on Sun Sep 05 2021 03:26 pm

    The most you should ever block is a class b, and not sure if
    Synchronet's ip.can allows for specific bitmasks, such as 27.0.0.1/22 or not.

    It does:
    https://wiki.synchro.net/config:filter_files#ipv4_cidr_notation
    --
    digital man

    Synchronet "Real Fact" #83:
    Donations to the Synchronet project are welcome at wiki.synchro.net/donate Norco, CA WX: 88.8øF, 41.0% humidity, 4 mph WNW wind, 0.00 inches rain/24hrs --- SBBSecho 3.14-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Tracker1@1:103/705 to Digital Man on Wed Sep 8 17:41:04 2021
    On 9/6/2021 12:50 PM, Digital Man wrote:
    The most you should ever block is a class b, and not sure if
    Synchronet's ip.can allows for specific bitmasks, such as 27.0.0.1/22 or
    not.

    It does:
    https://wiki.synchro.net/config:filter_files#ipv4_cidr_notation

    Cool, thanks... One minor addendum, if you're hosting a BBS message
    network, you may not want to do excessive blocking, as someone using AWS
    for their host won't be able to get mail.
    --
    Michael J. Ryan - tracker1@roughneckbbs.com
    ---
    ï¿­ Synchronet ï¿­ Roughneck BBS - roughneckbbs.com
    --- SBBSecho 3.14-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)