Spamhous list implementation

Mon Dec 21, 2015 5:23 am


Could you please share your thoughts on such implementation:

" ... ress-list/"

Does it really make sence? What pros and cons?

Would appreciate your thoughs on this

Thank you
Re: Spamhaus list implementation

Tue Dec 22, 2015 8:42 am

Joshaven is TOP NOTCH.

I have met him personally, done dinner etc with his family.
He knows his stuff !!!

I would however suggest you use his script BUT pull the data into / from your own source.

WHY? because if his server ever were to go offline - simply said - your solution would STOP working

If you setup a location on your own Servers and download the data and then source you would simply need to change the following in his script
/tool fetch url="**********.rsc
/tool fetch url="http://yourownserver.goeshere/*********.rsc
Re: Spamhous list implementation

Thu Dec 24, 2015 3:27 am

I do much the same thing with the script I posted here:

I also posted what I consider to be my default filter rules. The lists that I generate are dynamic address-list entries, so that their are much fewer NAND/Flash writes.
Re: Spamhous list implementation

Thu Dec 24, 2015 4:37 am

its do "make sense"(but community-drive alternatives like DSPAM may be even Better.
but presently importing/using large blacklists into ROS cause config breaking and/or router unpredictable behavior. in 6.5-6.10 its was worked ~ fine and earlier.
in past - i was used to used both Peter Lowe ad blocking list ... =plaintext
and one of malwaredomains black lists
and team cymru -supplied full bogon list ... s-ipv4.txt

you just blackhole then in "static" overrides in you DNS services options/DB.
(fullbogons go into "adress list" and then dropped/rejected in conntrack aswell)
its come handy especially in public networks connected hosts/endpoints(say if someone, visiting web-services and other public, populated parts of web-space), since nearly 25-30% offenses or Intel-gathering attempts come from bogons and significant part of exploitation attempts. - from "long lifetime" malware domains.

