| | | 
Regular Member

Group: Forum Members Last Login: Saturday, September 13, 2008 12:16 PM Posts: 60, Visits: 234 |
| one of my servers was flooded via smtp by a botnet, about 70-80 zombies, here are the rules:
-A INPUT -s 195.42.160.0/255.255.224.0 -j DROP
-A INPUT -s 85.110.128.0/255.255.128.0 -j DROP
-A INPUT -s 200.11.0.0/255.255.128.0 -j DROP
-A INPUT -s 213.190.194.0/255.255.255.0 -j DROP
-A INPUT -s 213.190.192.0/255.255.254.0 -j DROP
-A INPUT -s 69.38.128.0/255.255.128.0 -j DROP
-A INPUT -s 83.8.0.0/255.252.0.0 -j DROP
-A INPUT -s 83.4.0.0/255.252.0.0 -j DROP
-A INPUT -s 219.96.0.0/255.224.0.0 -j DROP
-A INPUT -s 218.103.66.96/255.255.255.240 -j DROP
-A INPUT -s 212.58.232.0/255.255.255.240 -j DROP
-A INPUT -s 205.120.0.0/255.248.0.0 -j DROP
-A INPUT -s 205.118.0.0/255.254.0.0 -j DROP
-A INPUT -s 195.182.128.0/255.255.255.0 -j DROP
-A INPUT -s 200.69.29.80 -j DROP
-A INPUT -s 81.25.162.0/255.255.255.0 -j DROP
-A INPUT -s 200.11.0.0/255.255.224.0 -j DROP
-A INPUT -s 202.108.0.0/255.255.0.0 -j DROP
-A INPUT -s 77.30.56.67 -j DROP
-A INPUT -s 213.191.36.42 -j DROP
-A INPUT -s 64.34.174.23 -j DROP
-A INPUT -s 201.34.191.4 -j DROP
-A INPUT -s 66.92.249.70 -j DROP
-A INPUT -s 213.174.48.22 -j DROP
-A INPUT -s 124.101.254.110 -j DROP
-A INPUT -s 209.85.63.134 -j DROP
-A INPUT -s 24.149.10.32 -j DROP
-A INPUT -s 41.225.245.242 -j DROP
-A INPUT -s 129.93.210.172 -j DROP
-A INPUT -s 209.191.123.36 -j DROP
-A INPUT -s 89.249.0.0/255.255.0.0 -j DROP
-A INPUT -s 212.49.0.0/255.255.0.0 -j DROP
-A INPUT -s 222.90.0.0/255.255.0.0 -j DROP
-A INPUT -s 88.73.0.0/255.255.0.0 -j DROP
-A INPUT -s 59.94.0.0/255.255.0.0 -j DROP
-A INPUT -s 203.113.17.0/255.255.255.0 -j DROP
-A INPUT -s 41.232.0.0/255.255.0.0 -j DROP
of course those rules are a little harsh because they cause some collateral damage...but well, if you don't have plenty of visitors from russia, china, portugal or japan anyway it don't matter. there are also 1 or 2 entries that cover the same IP, but after multiple IPs from the same ranges appeared I decided to block them completely. |
| |
|
|