(**Note: if you cannot reach the image, let me know, I may need to unblock your
IP address from within iptables. Most of RIPE/AFRINIC and APNIC are blocked for
security reasons)
What in the world did RIPE do to you :J
you could at least let Westen Urp through
Ha! It’s more like what hasn’t RIPE tried to do to my servers
Truth is, I’ve had mediawiki compromised, thousands of unauthorized access
attempts weekly, etc…, etc… with 99% originating from those address blocks.
Since I don’t have legal business with that side of the planet, I just got the
IANNA address blocks for those regions and blocked them – completely. The
number of nefarious attempts to compromise my servers dropped to almost zero
immediately, and I sleep a whole lot better at night…
Having an admin hat on, I sympathize … however, if these are logged, maybe
fail2ban might help even better? That does set blacklist per-ip based on log parse
(maybe not as complete replacement but as an addition)
(there are distributions that sport this program as default)
Sad when even major software providers have to put out notice of address blocks
for systems to work anymore (see e.g.:
https://msdn.microsoft.com/en-us/library/azure/dn175718.aspx)
That’s sort-of their equivalent of letting their systems/admins know the known-good locations…
ones that would be ‘unlikely’ to get a rogue packets from. Meaning probably their systems
would trust these /a bit more/ than just the ordinary Joe Bloggs. Meaning these would have
real difficulty to be spoofed otherwise than through global network-down event.
I dropped all but the top 40 offending address blocks. Give the links in the
original post a try. If you are still blocked, shoot me your IP or at least the
relevant first few designators and I’ll open it further.
Well I don’t want to make you loose your sleep,
another ‘easy’ (I suppose) way would be for you to let the Internet Archive robot to archive/access your site
(atm it says it can’t cause of robots.txt) - the rest of the world can use this as a proxy to view…
(I tried)
Thanks.
Hope this helps
Lukasz
eGroupWare-developers mailing list
eGroupWare-developers@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/egroupware-developers