
Code: Select all
Oct 22 11:23:34 myhost sshd[12052]: ... illegal user root from rueckziegel.de
Oct 22 11:26:01 myhost sshd[19761]: ... illegal user root from 213.203.197.86
Oct 22 11:27:55 myhost sshd[22394]: ... illegal user root from 200.69.219.189
Oct 22 11:29:48 myhost sshd[1803]: ... illegal user root from chello080108092234.22.11.vie.surfer.at
Oct 22 11:32:17 myhost sshd[24030]: ... illegal user root from gw.ptr-62-65-142-213.customer.ch.netstream.com
Oct 22 11:34:10 myhost sshd[8171]: ... illegal user root from devel.teracode.com
Oct 22 11:36:07 myhost sshd[14195]: ... illegal user root from www.asigen.cl
Oct 22 11:38:34 myhost sshd[28546]: ... illegal user root from 200.62.227.204
Oct 22 11:40:25 myhost sshd[21858]: ... illegal user root from 148.245.157.217
Oct 22 11:42:25 myhost sshd[17660]: ... illegal user root from mtl93-10-88-173-209-112.fbx.proxad.net
Oct 22 11:44:52 myhost sshd[19517]: ... illegal user root from 61.9.8.115
Oct 22 11:46:43 myhost sshd[7317]: ... illegal user root from 67.105.126.195.ptr.us.xo.net
Oct 22 11:49:07 myhost sshd[22314]: ... illegal user root from 64.14.4.11
Oct 22 11:51:12 myhost sshd[29988]: ... illegal user root from mailux.bendux.de
Oct 22 11:53:14 myhost sshd[10153]: ... illegal user root from 200.152.205.106
Oct 22 11:55:47 myhost sshd[20075]: ... illegal user root from static-098-027-160.dsl.nextra.sk
Oct 22 11:57:28 myhost sshd[32395]: ... illegal user root from 203.227.15.13
Oct 22 11:59:26 myhost sshd[7889]: ... illegal user root from jaysus.de
Oct 22 12:01:55 myhost sshd[17593]: ... illegal user root from 213.203.197.86
Oct 22 12:03:49 myhost sshd[18269]: ... illegal user root from 124x39x168x43.ap124.ftth.ucom.ne.jp



222.0.0.0/8
221.0.0.0/8
220.0.0.0/8
219.0.0.0/8
218.0.0.0/8
217.0.0.0/8
213.0.0.0/8
212.0.0.0/8
211.0.0.0/8
210.0.0.0/8
203.0.0.0/8
202.0.0.0/8
196.0.0.0/8
195.0.0.0/8
194.0.0.0/8
193.0.0.0/8
126.0.0.0/8
125.0.0.0/8
124.0.0.0/8
123.0.0.0/8
122.0.0.0/8
121.0.0.0/8
120.0.0.0/8
119.0.0.0/8
118.0.0.0/8
117.0.0.0/8
116.0.0.0/8
115.0.0.0/8
114.0.0.0/8
95.0.0.0/8
94.0.0.0/8
93.0.0.0/8
92.0.0.0/8
91.0.0.0/8
90.0.0.0/8
89.0.0.0/8
88.0.0.0/8
87.0.0.0/8
86.0.0.0/8
85.0.0.0/8
84.0.0.0/8
83.0.0.0/8
82.0.0.0/8
81.0.0.0/8
80.0.0.0/8
79.0.0.0/8
78.0.0.0/8
77.0.0.0/8
62.0.0.0/8
61.0.0.0/8
60.0.0.0/8
59.0.0.0/8
58.0.0.0/8
41.0.0.0/8
DROP all -- 207.138.124.4 0.0.0.0/0
DROP all -- 203.156.240.75 0.0.0.0/0
DROP all -- 222.246.132.212 0.0.0.0/0
DROP all -- 77.221.134.130 0.0.0.0/0
DROP all -- 60.6.237.55 0.0.0.0/0
DROP all -- 159.226.4.155 0.0.0.0/0
DROP all -- 218.76.217.234 0.0.0.0/0
DROP all -- 85.68.243.85 0.0.0.0/0
DROP all -- 203.193.135.82 0.0.0.0/0
Code: Select all
iptables -A BADDOMAINS -s 6.0.0.0/255.0.0.0 -j DROP #DoD - AISC
iptables -A BADDOMAINS -s 11.0.0.0/255.0.0.0 -j DROP #DoD - Intel
iptables -A BADDOMAINS -s 21.0.0.0/255.0.0.0 -j DROP #DoD
iptables -A BADDOMAINS -s 22.0.0.0/255.0.0.0 -j DROP #DoD - DISA
iptables -A BADDOMAINS -s 25.0.0.0/255.0.0.0 -j DROP #UK - MoD
iptables -A BADDOMAINS -s 26.0.0.0/255.0.0.0 -j DROP #DoD - DISA
iptables -A BADDOMAINS -s 29.0.0.0/255.0.0.0 -j DROP #DoD - DISA
iptables -A BADDOMAINS -s 30.0.0.0/255.0.0.0 -j DROP #DoD - DISA
iptables -A BADDOMAINS -s 51.0.0.0/255.0.0.0 -j DROP #UK - Social Security
iptables -A BADDOMAINS -s 55.0.0.0/255.0.0.0 -j DROP #DoD - NIC
iptables -A BADDOMAINS -s 60.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 61.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 80.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 81.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 83.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 86.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 87.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 89.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 122.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 125.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 134.0.0.0/255.0.0.0 -j DROP
iptables -A BADDOMAINS -s 189.0.0.0/255.0.0.0 -j DROP #LACNIC -UY
iptables -A BADDOMAINS -s 190.0.0.0/255.0.0.0 -j DROP #LACNIC - UY
iptables -A BADDOMAINS -s 193.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 200.0.0.0/255.0.0.0 -j DROP #LACNIC - UY
iptables -A BADDOMAINS -s 201.0.0.0/255.0.0.0 -j DROP #LACNIC - UY
iptables -A BADDOMAINS -s 202.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 203.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 207.253.73.0/255.255.255.0 -j DROP # Canada
iptables -A BADDOMAINS -s 210.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 211.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 213.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 214.0.0.0/255.0.0.0 -j DROP #DoD
iptables -A BADDOMAINS -s 215.0.0.0/255.0.0.0 -j DROP #DoD
iptables -A BADDOMAINS -s 217.0.0.0/255.0.0.0 -j DROP #RIPE - NL
iptables -A BADDOMAINS -s 218.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 219.0.0.0/255.0.0.0 -j DROP #APNIC - AU
iptables -A BADDOMAINS -s 221.0.0.0/255.0.0.0 -j DROP #APNIC - AU