Blocking China IP Address Blocks
mergy.org
mergy.org
There are 300,000 IPs from China that are just trying public leaked email / password databases against our servers. With so many IPs, any kind of normal per IP limiting just doesn't work. Each IP is only trying 10 or so accounts per day.
Blocking China was potentially a very real solution because I just don't think that they would have access to other bot nets of that sheer size outside of China.
The trouble is that the users don't understand that they are pre-compromised before they even arrive.
Anyway, we have now implemented a system whereby accounts get locked if someone attempts to log in from a different country than last time and they have to type in a verification code sent to their email.
All the "My account got hacked" support requests have been replaced by an equivalent number of "Why does my account keep getting locked" support requests. But there you go.
The reasoning behind this was that their actual password is compromised. We want to make sure that the user understands this fact and changes their password. Not only on our service, but on all the others that they may be using the same password for as well.
The email does say that someone else has your password, but if you can just ignore the email then most will not actually get it or assume it's some kind of phishing email.
For what it's worth, you should consider locking not on attempt to log in, but on successful login from abroad. This was an old problem in some Windows networks: accounts would be locked with 5 failed logins. People discovered they could lock out friends' accounts (or ahem the president's) by failing a login 5 times.
(P.S. If anyone's looking for a great way to waste more time than they should, Path of Exile is a pretty great game.)
Weak password was bruteforced? Start enforcing strong passwords.
Email server vulnerability exploited? Patch your server.
Etc.
Reusing passwords on different sites is a much bigger problem IMO since a lot of places still don't store passwords correctly or don't lock out users after failed attempts.
Unless your users' passwords are something like "password" or their user names. Password length and complexity are important, if overplayed.
Passwords that can be guessed in 1-3 tries should be excluded, naturally: password, 12345, 11111 etc... But mixed case, special character stuff is a bit redundant.
I created this iptables script and update it when I notice any new patterns of abuse
Of course if you KNOW you have no users in e.g. China, no harm in blocking them, but any skilled attacker in China is not going to appear to be in China, from your vantage point.
Use rate limiting and block bad IPs that are brute-forcing services (don't lock accounts) then you'll be able to serve your users while keeping the bad guys out.
I just haven't found anything yet with a good combination of price, capabilities and hardware VPN support - doubling the price we're currently paying would be feasible, quadrupling it when replacing functioning equipment is harder to justify to non-technical users.
A worthwhile resource for folks with Windows (and with some useful links for others): http://www.sans.org/windows-security/2011/10/25/windows-fire...
The feature base is incredible: http://routerboard.com/RB2011L-IN
That said, it's pretty easy to block countries from accessing web apps at least if you use Cloudflare. The CF proxy passes a special field down to your server containing the country of origin. Works quite well actually.
Its probably not sustainable to just block the entire country long term though. You have to figure out a different way of figuring out folks who are real from folks who aren't otherwise you end up with really irritated users.
[1] blekko.com
So the reality is really nasty. Many of the netizen in China are somehow running naked: you can simply query the password after you get the email.
http://www.cyberciti.biz/faq/block-entier-country-using-ipta...
If you have a linux-based router, this can be a 5 minute job.
In fact, I'll save you some time. I modified the script slightly to better suit my needs. Enjoy:
#!/bin/bash
# License: any/both of the following: public domain or MIT
#
### Block all traffic from AFGHANISTAN (af) - ISO code ###
#
# you will need to do the following setup steps manually:
#
# iptables -N drop-by-country
#
# for a in INPUT FORWARD OUTPUT
# do iptables -I $a 1 -j drop-by-country
# done
#
ISO="af"
IPT=iptables
WGET=wget
SPAMLIST="drop-by-country"
DLROOT="http://www.ipdeny.com/ipblocks/data/countries"
for c in $ISO; do
tDB=$c.zone
#rm -f $tDB
[ -f $tDB ] || $WGET -O $tDB $DLROOT/$c.zone || exit 1
done
# convert IP and mask to decimal IP (32-bit value) (and leave mask unchanged)
BADIPS="`for c in $ISO; do cat $c.zone; done | awk 'BEGIN{FS="."}
{
if ($0 == "" || $0 ~ "/^#/") next;
mask=gensub("^[0-9]*/", "", "", $4)
n=gensub("/[0-9]*$", "", "", $4)
n=(($1*256 + $2)*256 + $3)*256 + n
print n " " mask
}' | sort -n`"
# merge adjacent IP ranges until nothing changes
N=""
limit=20
while [ "$N" != "$BADIPS" ]; do
echo "simplifying `echo \"$BADIPS\" | wc -l` rules"
N="$BADIPS"
BADIPS="`echo \"$N\" | awk 'BEGIN{p1="";p2=""}
{
n1=\$1
n2=\$2
if (p1 != "") {
e=2 ** (32-p2)
if (n2 == p2 && int(p1 / e) % 2 == 0 && int(n1 / e) - int(p1 / e) == 1) {
n1=p1
n2--
} else {
print p1 " " p2
}
}
p1=n1
p2=n2
}
END{ if (p1 != "") print p1 " " p2 }'`"
limit=$(( $limit - 1 ))
[ $limit -eq 0 ] && break
done
# convert back to IP format
echo "$BADIPS" | awk '{
o4=$1
o1=o4 % 256
o4=int(o4 / 256)
o2=o4 % 256
o4=int(o4 / 256)
o3=o4 % 256
o4=int(o4 / 256)
print o4 "." o3 "." o2 "." o1 "/" $2
}' | while read a; do
echo "$IPT -A $SPAMLIST -s $a -j DROP"
$IPT -A $SPAMLIST -s $a -j DROP || exit 1
done
# let me end by just saying that blocking an entire country is the WRONG solution, though it might be considered part of a "layered defense" strategy. On the other hand, if you want to apply this to your home router and play with it, that's a different story.It's important to me to preserve the open nature of the internet. So I hope the karma bonus of posting some code offsets the karma loss from the code being "racist" ;-)
Great article, thanks!
Also consider if you can not restrict your ssh and ftp access to very tiny blocks, you can just allow US (or your country) addresses into those ports.
Of course proxies defeat all this but it slows down the generic script use.
Configserver firewall is amazingly powerful and easy (and free) in this regard
http://www.configserver.com/cp/csf.html
CSF is also good at noticing distributed attacks across ip ranges.
ps. please consider donating to Chirpy for CSF, I'd hate to see it die someday
The script kiddies (fake hackers) can't really get into your systems if you apply simple security policies and sanity checks.
The real hackers that can get it aren't blocked by any of your ip filters. They just go through proxies.
Dalton's app.net is one of the things I was playing with last night.
1) that doesn't make your shitty (lets be rough here) passwords & web apps secure. You didn't care for security yesterday, it's not going to come to you by blocking "china".
2) that doesn't stop anyone from proxying elsewhere
3) the more doing it, the more segmented the internet, the less it actually IS the internet. basically, you're breaking the fucking point of the internet (that justify the swearing.)
http://www.dd-wrt.com/wiki/index.php/Optware%2C_the_Right_Wa...
I've had this setup for years. It's simple and effective. I block China and Russia entirely.