Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 22nd, 2003, 05:54 PM
DianaDiamant DianaDiamant is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 6 DianaDiamant User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 19 m 3 sec
Reputation Power: 0
Blocking entire IP blocks

Hi forum members,
I'm learning linux on a server I've leased for that purpose. Can anyone tell me how to block IP addresses from entire regions or countries, such as Indonesia, Korea, China, etc?

I just get too many suspicious probes from those areas.

Thanks... toodles,
Diana

Reply With Quote
  #2  
Old March 22nd, 2003, 06:39 PM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 42 m 50 sec
Reputation Power: 185
YouŽll get "suspicious probes" from all over the world soon. If you want to block the whole world, just donŽt get on-line.

Better keep your software up-to-date and read some security mailing lists so you know which software needs to be upgraded / disabled until a upgrade is available.

Many people all over the world use dynamic IPs. If you block them, theyŽll come back with another IP address within 24 hrs. If you block a whole country, theyŽll come back using proxys in another country.

Most "suspicious probes" as you call them are virii (or worms). TheyŽll spread all over the world and there is no way to prevent them trying to take over your box too. As said earlier, keep your software up-to-date and you donŽt need to worry about them.

To answer your question and satisfy your curiosity:
When you add rules to your ip chains, you can supply a network mask. This is used to mark a whole range of IPs. e.g.

192.168.1.1/24 is 192.168.1.0 - 192.168.1.255
192.168.1.1/16 is 192.168.0.0 - 192.168.255.255

the number after the slash is the bits that will be taken for checking if a IP falls into the range or not.
i.e. 24 bits = only the first three bytes are checked, the fourth byte can be any value = 192.168.1.0 - 192.168.1.255

This is called a "netmask". They (netmasks) can also be expressed in a more IP-like manner: 255.255.255.0 (three bytes "1", one byte "0" - same as above. do you get the idea?)

M.
__________________
--
Manuel Hirsch - Linux, FreeBSD, programming, administration articles, tutorials and more.

Reply With Quote
  #3  
Old March 23rd, 2003, 12:35 AM
DianaDiamant DianaDiamant is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 6 DianaDiamant User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 19 m 3 sec
Reputation Power: 0
the whole world in his hands... he's got the whole world in his hands...

Quote:
YouŽll get "suspicious probes" from all over the world soon.
I get your point. And I agree with you under present world circumstances.

I'll keep my attention focused on updated software, and read some of the security mailing lists.
Quote:
This is called a "netmask". They (netmasks) can also be expressed in a more IP-like manner: 255.255.255.0 (three bytes "1", one byte "0" - same as above. do you get the idea?)
Explained in terms even my dyslexic, chemically imbalanced brain can decipher. I am most appreciative for your consideration.

Diana

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Blocking entire IP blocks


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT