Lunarpages Web Hosting Forum

Author Topic: Banning IP's Permanently.  (Read 4327 times)

Offline The Natural Greek Phenomenon

  • Intergalactic Superstar
  • *****
  • Posts: 144
    • Smart Shopping Mall
Banning IP's Permanently.
« on: July 26, 2005, 04:36:34 AM »
Hello!

Using the iptables -I INPUT -s xxxxxxxx -j DROP
command I am supposed to block unwanted
visits from specific IP's.

The predicament is that these IP's keep returning
after a few days; is it feasible to permanently block
those visits from coming?

For instance, there are robots, hackers and hustlers
that originate from some IP's which I'd rather ban
via the DROP method but... they come back, so the
'blockage' is only good for a matter of time.

Also is there a possibility to bamboozle potential
attackers by causing them :argh:  some sort of havoc?

Any advice?

Thanks,
George

Danielle

  • Guest
Re: Banning IP's Permanently.
« Reply #1 on: July 26, 2005, 05:48:00 AM »
Hi George,

Actually, using iptables -I INPUT -s xxxxxxxx -j DROP will just block the IP for around 24 hours or until the firewall cron runs that removes those input into the table in this manner.  Instead you can enter this command to edit the deny_hosts file:

vi /etc/apf/deny_hosts*

Scroll to the end of the file, and enter to insert text:

Esc + I

Press the enter key to go to the next line so the new IP will be on its own line, then paste the IP in question. To save, enter the Esc key, then (this writes and quits):

:wq

At the command prompt after you have left the file, then enter the following which will restart the firewall so the changes take affect:

/etc/init.d/apf restart

Adding an IP to deny_hosts file is a permanent block.

Thanks.

Offline The Natural Greek Phenomenon

  • Intergalactic Superstar
  • *****
  • Posts: 144
    • Smart Shopping Mall
Re: Banning IP's Permanently.
« Reply #2 on: July 26, 2005, 05:41:53 PM »
Danielle,

Very helpful - thanks a lot; will try it next time it's needed.

Gracefully,
George

Offline The Natural Greek Phenomenon

  • Intergalactic Superstar
  • *****
  • Posts: 144
    • Smart Shopping Mall
Re: Banning IP's Permanently.
« Reply #3 on: July 26, 2005, 06:16:40 PM »
OK Danielle - it must have worked exactly as you instructed.

Check the obfuscated snapshot.
I added an IP right down below
another one whereas the red arrow points at.


So each time I will have to keep adding IP's,
right bottom below to the one I added, right?

Very helpful procedure indeed - thanks.

Danielle

  • Guest
Re: Banning IP's Permanently.
« Reply #4 on: July 26, 2005, 09:57:06 PM »
Hi George, I'm not seeing a snapshot, did you attach it? :)

You would keep adding IPs for each one you want to block with the new ones added at the bottom and no empty lines between each IP (so they are in a list):

Prior IP listed
Prior IP listed
New IP1
New IP2
New IP3
and so on

Offline The Natural Greek Phenomenon

  • Intergalactic Superstar
  • *****
  • Posts: 144
    • Smart Shopping Mall
Re: Banning IP's Permanently.
« Reply #5 on: July 27, 2005, 03:20:18 AM »
Danielle,

In my post above I have embedded a jpg picture.

OK, got that IP hierarchy. Thanks a lot for your help. :yey:

Danielle

  • Guest
Re: Banning IP's Permanently.
« Reply #6 on: July 27, 2005, 05:28:24 AM »
You're welcome and I figured out what you meant for the jpg now. Glad it is working for you :thumb: