網絡安全 Iptables and Spamhaus IP drop lists
最近見到這方面的資料,與大家分享。
http://www.spamhaus.org/faq/section/DROP%20FAQ
其中一個與iptables 配合的scripts- #!/bin/bash
- # Generate automatic firewall rules to block bad IPs listed on spamhaus.org
- FILE=/tmp/drop.lasso
- wget -O $FILE http://www.spamhaus.org/drop/drop.lasso
- iptables -F ; flush iptables, comment line if you use other rules
- for ipblock in `egrep -v '^;' $FILE | awk '{print $1}'`
- do
- iptables -I INPUT -s $ipblock -j DROP
- done
複製代碼 |