From: "J. Bakshi" <joydeep@infoservices.in>
To: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Cc: netfilter@vger.kernel.org
Subject: Re: How to view blacklist ip ?
Date: Mon, 07 Sep 2009 13:29:57 +0530 [thread overview]
Message-ID: <4AA4BD7D.3080405@infoservices.in> (raw)
In-Reply-To: <4AA4B9B3.6020409@infoservices.in>
J. Bakshi wrote:
> Pascal Hambourg wrote:
>
>> Hello,
>>
>> J. Bakshi a écrit :
>>
>>
>>> iptables -A INPUT -m recent --name blacklist --rcheck --seconds
>>> $BLACKLIST_INTERVAL -j DROP
>>>
>>> and it is working really well. But is there any way to manage the
>>> blacklisted ip ? Manage means
>>>
>>>
>> man iptables
>>
>>
>>
>>> 1> view the ips which are blacklisted
>>>
>>>
>> Read /proc/net/ipt_recent/<name>.
>>
>>
>>
>
> Great !!!. Thanks a lot. Now I can write a shell script to manage the IPs.
>
>
Though the content of the file consists of much more.
``````````
# cat /proc/net/ipt_recent/blacklist
src=183.131.207.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=240.168.95.31 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=254.41.0.0 ttl: 0 last_seen: 4298215698 oldest_pkt: 1 4298215698
src=255.255.211.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=135.0.0.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=79.0.0.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=53.0.0.0 ttl: 0 last_seen: 4298215698 oldest_pkt: 1 4298215698
src=31.190.99.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=165.0.0.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=236.13.207.0 ttl: 0 last_seen: 4298214902 oldest_pkt: 1 4298214902
src=135.232.168.45 ttl: 0 last_seen: 4298215698 oldest_pkt: 1 4298215698
src=255.255.255.211 ttl: 0 last_seen: 4298215698 oldest_pkt: 2 4298212575
`````````````````````````````````
And If I try to remove a line it reports
```````````````
WARNING: The file has been changed since reading it!!!
Do you really want to write to it (y/n)?
`````````````````
A yes puts me again into the file. and it is recursive.
>
>
>>> 2> manually remove an IP from blacklist
>>>
>>>
>> Write "-a.b.c.d" into /proc/net/ipt_recent/<name> where a.b.c.d is the
>> address to remove. You can also write "clear" to flush the list.
>>
>>
>>
>>> 3> manually insert an IP as blacklist
>>>
>>>
>> Write "+a.b.c.d" or "a.b.c.d" into /proc/net/ipt_recent/<name> where
>> a.b.c.d is the address to add or update.
>>
>> Warning : ipt_recent may have been renamed xt_recent in recent kernels.
>> --
>> To unsubscribe from this list: send the line "unsubscribe netfilter" in
>> the body of a message to majordomo@vger.kernel.org
>> More majordomo info at http://vger.kernel.org/majordomo-info.html
>>
>>
>>
>
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
>
next prev parent reply other threads:[~2009-09-07 7:59 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-09-07 5:57 How to view blacklist ip ? J. Bakshi
2009-09-07 6:01 ` Anatoly Muliarski
2009-09-07 6:09 ` J. Bakshi
2009-09-07 7:33 ` Pascal Hambourg
2009-09-07 7:43 ` J. Bakshi
2009-09-07 7:59 ` J. Bakshi [this message]
2009-09-07 8:14 ` Pascal Hambourg
2009-09-07 8:26 ` J. Bakshi
2009-09-07 9:20 ` J. Bakshi
2009-09-07 10:34 ` Pascal Hambourg
2009-09-07 10:47 ` J. Bakshi
2009-09-07 11:14 ` Pascal Hambourg
2009-09-07 12:20 ` J. Bakshi
2009-09-07 18:37 ` Anatoly Muliarski
2009-09-08 4:35 ` J. Bakshi
2009-09-08 5:28 ` J. Bakshi
2009-09-08 7:48 ` Anatoly Muliarski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4AA4BD7D.3080405@infoservices.in \
--to=joydeep@infoservices.in \
--cc=netfilter@vger.kernel.org \
--cc=pascal.mail@plouf.fr.eu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.