View Single Post
  #12  
Old July 29th 19, 11:33 AM posted to alt.privacy.anon-server,comp.os.linux.misc,comp.os.linux.advocacy,alt.windows7.general,alt.comp.os.windows-10
The Natural Philosopher[_2_]
external usenet poster
 
Posts: 133
Default Florida city reportedly fires IT director after being forced topay $460G in ransomware attack

On 29/07/2019 03:01, J. P. Gilliver (John) wrote:
In message , The Natural Philosopher
writes:
On 28/07/2019 23:50, J. P. Gilliver (John) wrote:
In message , Carlos E.R.
writes:
On 28/07/2019 15.50, Anonymous wrote:
[]
(Someone else wrote - attribution snipped before this point
This is why I installed ipset on my server and block all of China,
Russia, North Korea and Slavic countries.Â* This is something that
most all servers should.Â* It is not like you are going to miss out
on any business from these corrupt, commie countries.

Â* You need to include all of Africa too.


And all of USA. That's the worst one, but you will not see it in the
logs.

Difficult, as very few use the .us TLD. I guess since (more or less)
theÂ* internet was invented/developed in USA, the .com, etc. TLDs
predominate,Â* but I do continue to be surprised that people aren't
_proud_ to use aÂ* .us address.


Am I intuiting that you think ipset works on domain names rather than
IP addresses?

Sorry, I hadn't noticed you said you were using ipset (of which I know
nothing). I was thinking of host file and similar filtering.


Not me. Someone lese.


How would you know which IP addresses are any given country anyway?


whois lookup on various ip ranges will reveal who issued them and to whom


e.g.
$whois 5.5.5.5
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '5.4.0.0 - 5.7.255.255'

% Abuse contact for '5.4.0.0 - 5.7.255.255' is '

inetnum: 5.4.0.0 - 5.7.255.255
netname: DE-MEDIAWAYS-20120425
country: DE
org: ORG-TDG4-RIPE
admin-c: MWH6-RIPE
tech-c: MWH6-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-by: MDA-Z
mnt-lower: MDA-Z
mnt-routes: MDA-Z
created: 2012-04-25T06:13:17Z
last-modified: 2018-07-30T09:52:34Z
source: RIPE

organisation: ORG-TDG4-RIPE
org-name: Telefonica Germany GmbH & Co.OHG
org-type: LIR
address: Georg-Brauchle-Ring 50
address: 80992
address: M�nchen
address: GERMANY
phone: +498924420
fax-no: +49892442198224
admin-c: RCM25-RIPE
admin-c: WT546-RIPE
admin-c: DK9212-RIPE
abuse-c: MWH6-RIPE
mnt-ref: RIPE-NCC-HM-MNT
mnt-ref: MDA-Z
mnt-by: RIPE-NCC-HM-MNT
mnt-by: MDA-Z
created: 2004-04-17T12:45:50Z
last-modified: 2018-09-25T14:13:22Z
source: RIPE # Filtered

role: mediaWays Hostmaster
address: Telefonica Germany GmbH & Co. OHG
address: Georg-Brauchle-Ring 50
address: 80992 Muenchen
address: DE
phone: +498924420
fax-no: +49892442198224
abuse-mailbox:
admin-c: DK9212-RIPE
admin-c: RCM25-RIPE
admin-c: WT546-RIPE
tech-c: TG819-RIPE
tech-c: ASZ-RIPE
nic-hdl: MWH6-RIPE
mnt-by: MDA-Z
created: 2001-11-06T10:42:25Z
last-modified: 2018-04-26T12:03:39Z
source: RIPE # Filtered

% Information related to '5.4.0.0/14AS6805'

route: 5.4.0.0/14
descr: Telefonica Germany GmbH & Co. OHG
remarks: netname: DE-MEDIAWAYS
origin: AS6805
mnt-by: MDA-Z
created: 2018-08-08T09:03:25Z
last-modified: 2018-08-08T09:13:47Z
source: RIPE

% This query was served by the RIPE Database Query Service version
1.94.1 (BLAARKOP)

This shows a block of IP addresses issued by RIPE to a German ISP


Or
https://lite.ip2location.com/russian...address-ranges


will for example list exhastively ALL ip ranges belonging to Russisn
organisations and ISPs


--
“Progress is precisely that which rules and regulations did not foresee,â€

– Ludwig von Mises
Ads