Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Blocking Traffic by Country on Production Networks
Timothy M. Mullen

When I originally posted to Bugtraq regarding the use of country-by-country sets to control traffic to or from any particular country, I knew that it was not a new idea. However, applying the concept for use with Microsoft's ISA Server was at least a new application for it, and apparently has had some utility for people based on the thousands of downloads that have been made of the free sets from the Hammer of God Web site.

Comments Mode:
Blocking Traffic by Country on Production Networks 2008-10-17
IT Dude
I've been doing this for two years now, this is nothing new to me. I've heard peers state how it's a bad idea, I beg to differ. Since I've started blocking Asian countries, my malicious traffic (including spam) has declined in upwards of 80%.

For the clown who stated "slammer requests are spoofed. good job champ", makes no difference if it's spoofed or not, it still gets blocked if you know what you are doing.

The only real downside is, the list is so large that it takes most firewall appliances a good deal of time and resources to blacklist the enormous amount of IP information.

Cheers

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1900/1207#1207







 

Privacy Statement
Copyright 2009, SecurityFocus