LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-21-2006, 01:34 AM   #1
vbsaltydog
Member
 
Registered: Nov 2005
Distribution: CentOS
Posts: 154

Rep: Reputation: 15
blocking access by region?


Is there a way to block http access if the source address traces back to a specific region or country in shorewall?
 
Old 04-21-2006, 02:44 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683Reputation: 683
There was an article about that in a Magazine not too long ago. I couldn't find it on google however.

The gist of the article was reducing spam in your corporate mail server by blocking out blocks of IP address that are assigned to certain regions. The article mentioned which regions made good candidates.
There was one problem, because Korea (the source of a lot of abuse) is in the same block as Japan.

AfriNIC (African Network Information Centre) - Africa Region
APNIC (Asia Pacific Network Information Centre) - Asia/Pacific Region
ARIN (American Registry for Internet Numbers) - North America Region
LACNIC (Regional Latin-American and Caribbean IP Address Registry) – Latin America and some Caribbean Islands
RIPE NCC (Réseaux IP Européens) - Europe, the Middle East, and Central Asia

The list below shows the current IP v4 address space. However there are many identified as simply "various".
http://www.iana.org/assignments/ipv4-address-space

Last edited by jschiwal; 04-21-2006 at 04:37 AM.
 
Old 04-22-2006, 06:39 PM   #3
newmarket
LQ Newbie
 
Registered: Mar 2006
Posts: 14

Rep: Reputation: 0
I've used hostip.info. They have an easy little api to return the probable location of the user. It really cut down my fraudulent orders. You can also download their d/b, but it's pretty large.
 
Old 04-24-2006, 09:42 AM   #4
Calgarian
Member
 
Registered: Feb 2005
Location: Calgary, AB Canada
Distribution: Kubuntu 6.10
Posts: 44

Rep: Reputation: 15
What can a person do who is on the other end of this dilemma. I am a US citizen and for many years used Comcast as my ISP. I was a very good customer. I relocated to Europe and Comcast has now considered my new ISP as a source of SPAM. I have never sent SPAM in my life and have never been informed that my address was ever used for that purpose. I now find that I cannot reach many of my friends due to this blocking. Comcast has no interest what so ever in trying to correct the problem. All they say, more or less, is tell your ISP to clean up their act. That doesn't work and appears to be them asking me to do their job.

My question is, what can a single individual, who did nothing wrong in the first place, do to get out from under one of these major blocking attacks?
 
Old 04-24-2006, 09:52 AM   #5
vbsaltydog
Member
 
Registered: Nov 2005
Distribution: CentOS
Posts: 154

Original Poster
Rep: Reputation: 15
What do you mean when you say that you cant reach your friends?
What method of contact are you trying to use?
 
Old 04-24-2006, 09:59 AM   #6
Calgarian
Member
 
Registered: Feb 2005
Location: Calgary, AB Canada
Distribution: Kubuntu 6.10
Posts: 44

Rep: Reputation: 15
I am trying to e-mail people with a xxx@comcast.net address. I get bounced as blacklisted. When I contact Comcast they tell me to get my ISP to clean up it's act. Every once in a while I seem to get through and then I restart my system and I'm blocked again. I'm guessing they might be checking my IP address and letting me through, but my ISP, as with most, is DHCP so I change IP address when I restart the system. At this moment I am again blocked as blacklisted. I've been trying for 3 months to get some reasonable response from them to let me e-mail with my Comcast friends.
 
Old 04-24-2006, 10:04 AM   #7
vbsaltydog
Member
 
Registered: Nov 2005
Distribution: CentOS
Posts: 154

Original Poster
Rep: Reputation: 15
I have a suggestion for you but I am not going to place it in this forum for spammers/scammers to read. If you would like to hear the suggestion then contact me on yahoo messenger. My yahoo id is vbsaltydog
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
router blocking access to services openbysource Linux - Networking 3 02-18-2006 01:09 PM
controlling access through squid( blocking all sites except for one) jomy Linux - Networking 1 12-15-2004 06:27 AM
How can I tell what is blocking access to my homepage Bjorkli Linux - Networking 0 09-14-2004 05:06 AM
iptables blocking internal access? complus Linux - Networking 17 03-08-2004 11:14 PM
shorewall blocking access to net mandrake 9 tewaru Linux - Newbie 2 12-04-2002 03:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration