Search found 74 matches

by gaia
Thu Mar 19, 2015 4:29 pm
Forum: Atomic Protector (formerly ASL)
Topic: Blocking by rDNS' third level domain
Replies: 9
Views: 8676

Re: Blocking by rDNS' third level domain

Also, I couldnt block the evil ( 1 , 2 , 3 ) coming from dozens of different IPs to scrape a magento site, which threw it for an endless loop. The offending netblocks were 172.255.0.0/16 NOBIS-TECHNOLOGY-GROUP-15 23.80.0.0/14 NOBIS-TECHNOLOGY-GROUP-17 23.104.0.0/13 NOBIS-TECHNOLOGY-GROUP-18 and an e...
by gaia
Thu Mar 19, 2015 12:17 pm
Forum: Atomic Protector (formerly ASL)
Topic: DoS: site or URL specific thresholds
Replies: 2
Views: 4154

Re: DoS: site or URL specific thresholds

mod_qos is what we're replacing evasive with. Its like the waf where we need to develop rules and policy configuration in ASL Web to really take full advantage of. Definitely run it now if you can, its got some great functionality now for wordpress sites. For mod_evasive, it can be a little counter...
by gaia
Thu Mar 19, 2015 9:07 am
Forum: Control Panel Support Help
Topic: Ajenti & Sentora
Replies: 3
Views: 11713

Re: Ajenti & Sentora

You should read this topic before migration http://www.webhostingtalk.com/showthread.php?p=9399137 Thanks. I've long trusted the RACK911 crew. I wonder if placing the entire CP behind http auth would be secure enough. I am the only one accessing it anyways. Regardless, I would rather use a differen...
by gaia
Thu Mar 19, 2015 8:32 am
Forum: Atomic Protector (formerly ASL)
Topic: DoS: site or URL specific thresholds
Replies: 2
Views: 4154

DoS: site or URL specific thresholds

These are my DoS settings: http://i.imgur.com/sVrtYuN.png They are pretty lax, as there are some times when several clients are coming from the same public IP and are accessing 2 AJAX resources every 10 seconds long periods (120 requests per client/minute). Is it possible to have different threshold...
by gaia
Wed Mar 18, 2015 8:43 am
Forum: Control Panel Support Help
Topic: Ajenti & Sentora
Replies: 3
Views: 11713

Ajenti & Sentora

I'm considering migrating from Virtualmin to Ajenti or maybe Sentora. Could any shared any words or experience related to those two CPs working with ASL?

Thanks
by gaia
Fri Mar 06, 2015 12:03 pm
Forum: Atomic Protector (formerly ASL)
Topic: Blocking by rDNS' third level domain
Replies: 9
Views: 8676

Re: Blocking by rDNS' third level domain

Just got a very draining bot coming from bzq-82-80-249-168.dcenter.bezeqint.net. I added dcenter.bezeqint.net to the MODSEC_01_DOMAIN_BLOCKS list (I was able to get rid of 007AC9.net this way). But dcenter.bezeqint.net didnt work for bzq-82-80-249-168.dcenter.bezeqint.net. Why? I can't block the ent...
by gaia
Thu Feb 26, 2015 2:47 pm
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9108

Re: Geoblock country but allow IP

mikeshinn wrote:Per port ACLs documentation is available here:

https://www.atomicorp.com/wiki/index.ph ... _Port_ACLs
thanks, but the referenced "Per Port ACLs" section does not mention the syntax for multiple ports.

additionally, i was looking to do this via the GUI, IF possible.
by gaia
Thu Feb 26, 2015 12:12 pm
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9108

Re: Geoblock country but allow IP

scott wrote:Right, an "insert" means put on the top of a list, and "add" means add to the bottom. Just like you're in a spreadsheet. You want your rule to appear ahead of the drop rule.
how do i add more than one port per rule? tried space, comma without spaces and dashes.
by gaia
Thu Feb 26, 2015 9:33 am
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9108

Re: Geoblock country but allow IP

So one firewall rule in INPUT before geoblock allowing access to those two ports?
by gaia
Wed Feb 25, 2015 8:03 pm
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9108

Re: Geoblock country but allow IP

scott wrote:Is it for just one service, or multiple ones?
only for port 443 and 22.
by gaia
Wed Feb 25, 2015 2:42 pm
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9108

Geoblock country but allow IP

Ukraine is geoblocked, but I would like to allow a single IP thru, without whitelisting it. Is this possible?

Thanks in advance.
by gaia
Wed Feb 25, 2015 2:38 pm
Forum: Atomic Protector (formerly ASL)
Topic: Blocking by rDNS' third level domain
Replies: 9
Views: 8676

Re: Blocking by rDNS' third level domain

Yes, you can do this with this ruleset: https://www.atomicorp.com/wiki/index.php/ASL_WAF#MODSEC_01_DOMAIN_BLOCKS Thanks Mike. I placed "007ac9.net" in the file. Will it satisfy the filter to effectively block, for example, crawl07.lp.007ac9.net (91.121.79.180)? AFAIU it should work: http:...
by gaia
Tue Feb 24, 2015 6:25 am
Forum: Atomic Protector (formerly ASL)
Topic: Blocking by rDNS' third level domain
Replies: 9
Views: 8676

Blocking by rDNS' third level domain

Got a hungry bot on our server this morning. It is spread across a wide range of networks , so blocking it by IP would be at least impractical and at most ineffective. Assuming the people who run it will keep using the same third level domain for all rDNS addresses where this bot comes from, is ther...
by gaia
Fri Feb 13, 2015 10:06 am
Forum: Atomic Protector (formerly ASL)
Topic: How to set OSSEC to ignore certain folders
Replies: 6
Views: 7377

Re: How to set OSSEC to ignore certain folders

I think he was asking if he deleted the a whole diff tree that wasnt ignored. The next cycle (<frequency>XXXX) it would make copies of the files again. In my case it wouldn't. the diff scan and the backup run roughly at the same time, and i am changing that. but the temporary files created by the b...
by gaia
Fri Feb 13, 2015 8:20 am
Forum: Atomic Protector (formerly ASL)
Topic: How to set OSSEC to ignore certain folders
Replies: 6
Views: 7377

Re: How to set OSSEC to ignore certain folders

official word was: A) Ignores are configured in ASL Web->File Integrity->Ignore Rules B) You can, but it can increase disk IO when it scans again it will add back the most recent copies. C is a better way to do it C) Retention is configured from ASL Web->Settings->ASL Configuration->Host Intrusion D...