Help - Search - Members - Calendar
Full Version: °°~IP Blocklist Safety Campaign~°°
B.I.S.S. Forums > Internet Security Forum > Internet Security Discussion
Pages: 1, 2
r00ted
oh wow lol, so you're already ahead of me then? tongue.gif mind posting em? tongue.gif
hotstocks
I don't get it. Sure, you can use the blocklist manager to block out 60%-96% of the internet,
but you are not going to be able to do any websurfing or filesharing. How many sources do you think
your emule, bittorent, kazaa, etc. will find if you block out 98% of the internet? You will never upload or
download anything! That is exactly what the RIAA and MPAA want.
Moore
read it again biggrin.gif , im not using this for p2p at all , and im splitting the ranges for all my websites so nothing i want to see is getting blocked , its pretty simple i think ..

all the ranges in the anti-p2p file are verified as bad hosts so i wouldnt want to be downloading from them anyway ....

i cant see your point .. we block the crap nothing else.
hotstocks
Moore,
I meant if you use the bloclklist manager with all sources at "yes", and import it into protowall or emule, you will block like 80% of the internet and not be able to use p2p, you will get no sources. I realize if you ONLY use meths list or antip2p.txt, you may only block about 30% of the internet and will be able to use p2p/websurf. But what we really want to know is, if using the blocklist manager in the USA, should EVERYTHING really be set to "yes" and imported into emule to block 80% of the internet? Why do we need to block other countries? The RIAA and MPAA , FBI and whoever else spies on p2p and sends letters to our ISPs or sues people for sharing are in the USA! No one from Germany, Sweden, Italy, etc. is trying to change USA's laws or have our ISPs shut down or sue us. What even is APNIC, LAPNIC, and IANA? Do we really need to block these? I think the blocklist manager is awesome, but would benefit by having lists based on what country you are in and what you really need to block. It is very confusing. Any advice or just set them all to "yes" to be safest? And it would be great if protowall 12hr update would work again updating one very thorough list. Then again, any RIAA agent could just log on from AOL and get a new ip and make this whole list useless, so is it even worth the hassle ?
Thanks
hotstocks
Hmm,
Just downloaded the new version of blocklist manager and it wont let me use more than the 5 default lists out of the 16. Even if you check yes for them they don't work and go back to no. Any idea what is going on?
Moore
ill have to check that out with deathangel..
Moore
either 5 sources are all thats now avalable or the rest arent working , post here i think :

http://www.bluetack.co.uk/forums/index.php?showforum=3
Moore
hi hotstocks , sorry i couldnt answer sooner.

QUOTE
I meant if you use the bloclklist manager with all sources at "yes",  and import it into protowall or emule, you will block like 80% of the internet and not be able to use p2p, you will get no sources.


yes most probably , i have a p2p list at the moment blocking 63% and i get a lot of blocks and still a lot of sources .

QUOTE
I realize if you ONLY use meths list or  antip2p.txt, you may only block about 30% of the internet and will be able to use p2p/websurf.


no its only about 3% , and blocks only the worst IP addresses.

QUOTE
But  what we really want to know is, if using the blocklist manager in the USA, should EVERYTHING really be set to "yes" and imported into emule to block 80% of the internet?


no !
everyone on staff has all said not to use all the lists unless youre relly paranoid biggrin.gif , they are all there because people wanted to be able to block 80 % of the internet..

we suggest using the antip2p blocklist , and anything else is your personal choice..


QUOTE
Why do we need to block other countries? The RIAA and MPAA , FBI and whoever else spies on p2p and sends letters to our ISPs or sues people for sharing are in the USA! No one from Germany, Sweden, Italy, etc. is trying to change USA's laws or  have our ISPs shut down or sue us.


there are plenty of organisations all around the world that are usa based or affiliated , and still you dont have to block anything if you dont feel the need to , i would rather know when somones trying to get in and they get blocked

QUOTE
What even is APNIC, LAPNIC, and IANA? Do we really need to block these?


ok read the guides please . we didnt post them for nothing , no you dont have to block anything you dont want to.

people will have to learn what they need to block for themselves , thats why we post the information , i even block a whole lot of apnic ranges myself , but i dont block them all cause im in the apnic region. biggrin.gif

QUOTE
I think the blocklist manager is awesome, but would benefit by having lists based on what country you are in and what you really need to block. It is very confusing.


only you can decide what you need to block , we provide all the tools to make the best decisions you can.

Knowledge is [power] start reading.

Researching Ranges :
http://www.bluetack.co.uk/forums/index.php...?showtopic=1076

IP ADRESSES:
http://www.bluetack.co.uk/forums/index.php...hp?showtopic=52

IANA:
http://www.bluetack.co.uk/forums/index.php...?showtopic=1057

Research SEctioN
http://www.bluetack.co.uk/forums/index.php...hp?showforum=69

Ant-File sharing groups :
http://www.bluetack.co.uk/forums/index.php...?showtopic=1052

http://www.bluetack.co.uk/forums/index.php...?showtopic=1438


QUOTE
Any advice or just set them all to "yes" to be safest?


i use Gov/mil/EDU/Anti-p2p/Labs /Research/IANA/trojan list and im sorting through the unfitered and 198all for the worst ips..

QUOTE
Then again, any RIAA agent could just  log on from AOL and get a new ip and make this whole list useless, so is it even worth the hassle ?


the entire AOL range is blocked so it s no hassle for me.

i have over 100 different IP lists right now in four or five formats and im trying nto get them all into order , thats just so i can know what every single ip address in my blocklist is and who it blocks , and that the range is not wrong, and make sure im not blocking the wrong isp.

ok hope that begins to answer some questions , maybe we should all do that poll where we all state which lists we use and why.. ?

biggrin.gif
r00ted
yea, would be neat ehehe. as far as the range names for this project? could you post them? tongue.gif Or give a lil guide on how to get them? Since I could use the practice wink.gif
Moore
ill find the ranges in my lists and post them in about two days maybe , they arent all in the same format right now either biggrin.gif
r00ted
alright cool wink.gif
Dogma1
I think this is a kick-ass idea. It's a little work but so what? Goes along the same idea as an ACL, implicit deny all at first, and then add what protocols you want. As someone said, you can't really screw it up then. What would be kewl is if there was the ability to see the ip your browser is trying to connect. If you know it's legit then you could opt to temporarily let it through just that one time (if you're a paranoid freek like me). Unfortunately I can't Protowall to run without it killing my download/upload speed to a snail's pace, so I'm still using PG.
Tozzano
Hmm... an allow once feature? Sounds interesting. Since we're talking packets, then I guess the IP would have to become allowed for a specified period of time then revert back to deny.

Mike unsure.gif
fishairflow
just for the not so smart ones - what excately is an exclusion list?
Tozzano
hi fishairflow, welcome to the forum!

The main blacklists contain many general IP and IP ranges.

Perhaps you have certain sites that you visit often. Maybe you have a certain address that you would like to always block whether it is in the main blacklist or not.

Exclusions in a filtering sense are IP's or IP ranges that will be allowed/permitted. Inclusions are IP's or IP ranges that will be denied/blocked.

The exclusions list is one that you maintain yourself in order to allow certain addresses access from your specific connection. This list then can be imported and merged into the main blacklists that you get from bluetack.

Also, check out this thread where exclusions are discussed: http://www.bluetack.co.uk/forums/index.php...?showtopic=2465

I hope that answers your question. smile.gif If you have more questions on exclusions, just post to that thread.

Mike

P.S. The Blocklist Manager help is being updated to answer these questions. The current help has grown outdated as development for the BLM continues full force.
deathangel
ok im working on a idea for a ip hunters control panel for this project:

panel containg the following:
quickwhois
inclusion manager
exclusions manager

and the abliity to right click and add to the inclusions or exclusions.


im still working out the details in my head but its gonna be another one of my over worked apps that could save some time with the huge ass smartwhois database that i have here but its gonna take a good dealof us to get the most of this going.

im also trying to get a import from the whois files from the ftp going but the blm isn't likeing the imports so i might make another window for whois conversion...its all acording to if the blm will play nice with the mini converter in the whois project or not....

ill post as i get the project working but it will be another part of the blm toolkit smile.gif
chrisoaf
QUOTE (r00ted @ Feb 28 2004, 02:24 PM)
I like it wink.gif In the Protowall 2.xx thread, I actually suggested PW do something like this wink.gif Start with a FULL INTERNET BLOCK (aka, all connections BLOCKED straight away) then.....as you navigate sites, have PW grant them 1 at a time or whatever.

I know some of the more powerful firewalls actually do this....but most people despise them because they dont know whether to "allow" or "deny" the packet wink.gif But yea, I like this idea. very powerful for protection.

Which firewalls do this? I'm lazy but want to have good security. Just clicking allow when I try to visit individual sites would be great.
r00ted
I think Tiny Personal Firewall does this, maybe Kerio. I cant remember the name, I had it back before I really even KNEW what a firewall was lol. Cant remember the name tongue.gif
deathangel
im working on something here that will get this working a little bit better smile.gif

what were we excluding again?

isps or what?
r00ted
yea, it was single IPs (in the proper format ip - ip , 200 , description of course). hehe. I think I posted the exclusions on page 1 or 2.
Moore
I think we need to make a complete 100% blocklist then exclude all isp ranges that are not dodgy and then start working on the lists from there , for the IP hunters to test further.
Angelus
Hey Guys and Girls/Ladies hehe

i just read thro this thread and well damn it sounds like a great idea.

U ppl are amazing biggrin.gif
funky monkey
Same.......... you guys are machines!!! Your work is very appreciated, and if any of you live in South Australia let me know!
newman411
thank you guyz for your work
and perseverance for the people
and by the people..
Necromancer
What is the status of this project guys?
Moore
I think the Blocklist Managers Exclusion Manager has replaced this for the most part , it lets people manage their own list the same way as the method I started here.

When I started this post was no exclusions manager.. biggrin.gif

Using the BLM you can easily add any whole ranges that you choose to block into your blocklist and poke holes for your trusted sites and IPs without needing to edit the list directly.

I am still working on this list though , I have been compressing all the ranges into sections like this and splitting the IPs for my trusted sites..

I dont think my current list would be suitable for everyone though , I am blocking a lot :

Example:

Blocked 1:0.0.0.1-4.*

I have some splits in 4*

IANA-DoD-level3-IBM:5.0.0.0-11.255.255.255
AT&T:12.0.0.0-12.255.255.255
Xerox-IANA-HP+DECorp+Apple+MIT+Ford+CompSCi:13.0.0.0-23.255.255.255

Lots of blocked ranges in 24* from the main lists ....

Royal Signals Radar Establishment & stuff:25.0.0.0-37.255.255.255
PSI NET:38.0.0.0-38.116.139.213
PSI NET:38.116.139.215-38.255.255.255
IANA Reserved-Eli Lilly+JapanInet:39.0.0.0-43.255.255.255
AmRadio+IANA+Bell-Resrch+PrudSecurities:44.0.0.0-48.255.255.255
IANA+Joint Tactical Command+Dept Soc Sec:49.0.0.0-51.255.255.255
E.I.DuPont+Capdebis+MerckCO+DoD+SITA+IANA:52.0.0.0-59.255.255.255

And most of the BLM lists merged into my blocklist as well ..
links1000
QUOTE (Moore @ Jun 12 2004, 02:43 PM)
I think we need to make a complete 100% blocklist then exclude all isp ranges that are not dodgy and then start working on the lists from there , for the IP hunters to test further.

I really like this idea
Moore
Thanks , still needs a lot of work , my original list can be used if anyone wants to use it to start their own list.. What mine has turned into is very restrictive.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.