Project

General

Profile

Bug #4876 » config-pfbng.xml

Kill Bill, 07/24/2015 02:26 AM

 
<pfblockerng>
<config>
<enable_cb>on</enable_cb>
<pfb_keep>on</pfb_keep>
<pfb_interval>1</pfb_interval>
<pfb_min>30</pfb_min>
<pfb_hour>0</pfb_hour>
<pfb_dailystart>0</pfb_dailystart>
<enable_dup>on</enable_dup>
<suppression>on</suppression>
<enable_log/>
<database_cc/>
<log_maxlines>20000</log_maxlines>
<inbound_interface>opt2,wan</inbound_interface>
<inbound_deny_action>block</inbound_deny_action>
<outbound_interface>lan,opt3</outbound_interface>
<outbound_deny_action>reject</outbound_deny_action>
<openvpn_action>on</openvpn_action>
<enable_float>on</enable_float>
<pass_order>order_0</pass_order>
<autorule_suffix>autorule</autorule_suffix>
<killstates>on</killstates>
<credits/>
<pfb_reuse/>
</config>
</pfblockerng>
<pfblockernglistsv4>
<config>
<aliasname>IBlock</aliasname>
<description><![CDATA[pfBlockerNG IBlock]]></description>
<row>
<format>gz</format>
<state>Disabled</state>
<url>http://list.iblocklist.com/?list=usrcshglbiilevmyfhse&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_BT_Hijack</header>
</row>
<row>
<format>gz</format>
<state>Disabled</state>
<url>http://list.iblocklist.com/?list=ficutxiwawokxlcyoeye&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_BT_FS</header>
</row>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=ghlzqtqxnzctvvajwwag&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_BT_Web</header>
</row>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=llvtlsjyoyiczbkjsxpf&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_BT_Spy</header>
</row>
<row>
<format>gz</format>
<state>Disabled</state>
<url>http://list.iblocklist.com/?list=cwworuawihqvocglcoss&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_Badpeer</header>
</row>
<row>
<format>gz</format>
<state>Disabled</state>
<url>http://list.iblocklist.com/?list=dgxtneitpuvgqqcpfulq&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>IBlock_Ads</header>
</row>
<row>
<format>gz</format>
<state>Disabled</state>
<url>http://list.iblocklist.com/?list=xoebmbyexwuiogmbyprb&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
<header>IBlock_Proxy</header>
</row>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=xpbqleszmajjesnzddhv&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>IBlock_dShield</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>PRI1</aliasname>
<description><![CDATA[pfBlockerNG PRI1]]></description>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://rules.emergingthreats.net/blockrules/compromised-ips.txt</url>
<header>ET_Comp</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt</url>
<header>ET_Block</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://www.spamhaus.org/drop/drop.txt</url>
<header>Spamhaus_drop</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.spamhaus.org/drop/edrop.txt</url>
<header>Spamhaus_edrop</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://cinsscore.com/list/ci-badguys.txt</url>
<header>CIArmy</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist</url>
<header>Abuse_Zeus</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://palevotracker.abuse.ch/blocklists.php?download=ipblocklist</url>
<header>Abuse_Palevo</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://sslbl.abuse.ch/blacklist/sslipblacklist.csv</url>
<header>Abuse_SSLBL</header>
</row>
<row>
<format>block</format>
<state>Enabled</state>
<url>https://feeds.dshield.org/block.txt</url>
<header>dShield_Block</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://labs.snort.org/feeds/ip-filter.blf</url>
<header>Snort_BL</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>http://osint.bambenekconsulting.com/feeds/goz-iplist.txt</url>
<header>BBC_Goz</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>PRI2</aliasname>
<description><![CDATA[pfBlockerNG PRI2]]></description>
<row>
<format>gz_2</format>
<state>Disabled</state>
<url>https://reputation.alienvault.com/reputation.snort.gz</url>
<header>Alienvault</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://atlas.arbor.net/summary/attacks.csv</url>
<header>Atlas_Attacks</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://atlas.arbor.net/summary/botnets.csv</url>
<header>Atlas_Botnets</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>https://atlas.arbor.net/summary/fastflux.csv</url>
<header>Atlas_Fastflux</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://atlas.arbor.net/summary/phishing.csv</url>
<header>Atlas_Phishing</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://atlas.arbor.net/summary/scans.csv</url>
<header>Atlas_Scans</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.cyber-ta.org/releases/malware/SOURCES/Attacker.Cumulative.Summary</url>
<header>SRI_Attackers</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.cyber-ta.org/releases/malware/SOURCES/CandC.Cumulative.Summary</url>
<header>SRI_CC</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://www.projecthoneypot.org/list_of_ips.php?t=d&amp;rss=1</url>
<header>HoneyPot_Dict_Attack</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://www.projecthoneypot.org/list_of_ips.php?t=s&amp;rss=1</url>
<header>HoneyPot_Spam_Server</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://www.projecthoneypot.org/list_of_ips.php?t=w&amp;rss=1</url>
<header>HoneyPot_Malicious_IPs</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>PRI3</aliasname>
<description><![CDATA[pfBlockerNG PRI3]]></description>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://www.malwaredomainlist.com/hostslist/ip.txt</url>
<header>MDL</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.nothink.org/blacklist/blacklist_malware_http.txt</url>
<header>Nothink_BL</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.nothink.org/blacklist/blacklist_ssh_week.txt</url>
<header>Nothink_SSH</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.nothink.org/blacklist/blacklist_malware_dns.txt</url>
<header>Nothink_Malware</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://danger.rulez.sk/projects/bruteforceblocker/blist.php</url>
<header>DangerRulez</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://www.autoshun.org/files/shunlist.csv</url>
<header>Shunlist</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.infiltrated.net/blacklisted</url>
<header>Infiltrated</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://www.dragonresearchgroup.org/insight/sshpwauth.txt</url>
<header>DRG_SSH</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://www.dragonresearchgroup.org/insight/vncprobe.txt</url>
<header>DRG_VNC</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://www.dragonresearchgroup.org/insight/http-report.txt</url>
<header>DRG_HTTP</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://feodotracker.abuse.ch/blocklist/?download=ipblocklist</url>
<header>Feodo_Block</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://feodotracker.abuse.ch/blocklist/?download=badips</url>
<header>Feodo_Bad</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.reputationauthority.org/toptens.php</url>
<header>WatchGuard</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://vmx.yourcmc.ru/BAD_HOSTS.IP4</url>
<header>VMX</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>http://www.geopsy.org/blacklist.html</url>
<header>Geopsy</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>https://www.maxmind.com/en/anonymous_proxies</url>
<header>Maxmind</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>http://www.botscout.com/last_caught_cache.htm</url>
<header>BotScout</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>https://www.juniper.net/security/auto/spam</url>
<header>Juniper</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://blocklist.greensnow.co/greensnow.txt</url>
<header>Greensnow</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://lists.blocklist.de/lists/all.txt</url>
<header>BlocklistDE</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>http://www.stopforumspam.com/downloads/toxic_ip_cidr.txt</url>
<header>SFS_Toxic</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>SEC1</aliasname>
<description><![CDATA[pfBlockerNG SEC1]]></description>
<row>
<format>html</format>
<state>Enabled</state>
<url>http://www.malwaregroup.com/ipaddresses/malicious</url>
<header>MalwareGroup</header>
</row>
<row>
<format>gz_2</format>
<state>Enabled</state>
<url>http://www.openbl.org/lists/base_7days.txt.gz</url>
<header>OpenBL</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://malc0de.com/bl/IP_Blacklist.txt</url>
<header>Malcode</header>
</row>
<row>
<format>txt</format>
<state>Disabled</state>
<url>https://www.badips.com/get/list/any/2</url>
<header>BadIPs</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>SEC2</aliasname>
<description><![CDATA[pfBlockerNG SEC2]]></description>
<row>
<format>html</format>
<state>Enabled</state>
<url>http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt</url>
<header>CC_IP</header>
</row>
<row>
<format>html</format>
<state>Disabled</state>
<url>http://osint.bambenekconsulting.com/feeds/c2-masterlist.txt</url>
<header>CC_Indicator</header>
</row>
<action>Deny_Both</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>TOR</aliasname>
<description><![CDATA[pfBlockerNG TOR]]></description>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=togdoptykrlolpddwbvz&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>IBlock_Tor</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://torstatus.blutmagie.de/ip_list_exit.php/Tor_ip_list_EXIT.csv</url>
<header>Blut_Tor</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>https://rules.emergingthreats.net/open/suricata/rules/tor.rules</url>
<header>ET_Tor</header>
</row>
<action>Disabled</action>
<cron>Never</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>MAIL</aliasname>
<description><![CDATA[pfBlockerNG MAIL]]></description>
<row>
<format>txt</format>
<state>Enabled</state>
<url>https://virbl.bit.nl/download/virbl.dnsbl.bit.nl.txt</url>
<header>VirBL</header>
</row>
<row>
<format>zip</format>
<state>Enabled</state>
<url>http://www.stopforumspam.com/downloads/bannedips.zip</url>
<header>SFS_All</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://antispam.imp.ch/spamlist</url>
<header>Improware</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>http://toastedspam.com/denylist.cgi</url>
<header>ToastedSpam</header>
</row>
<row>
<format>html</format>
<state>Enabled</state>
<url>http://rss.uribl.com/reports/7d/dns_a.html</url>
<header>URIBL</header>
</row>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://spamcop.net/w3m?action=map;net=cmaxcnt;mask=65535;sort=spamcnt;format=text</url>
<header>SpamCop</header>
</row>
<row>
<format>gz_2</format>
<state>Enabled</state>
<url>http://www.dnsbl.manitu.net/download/nixspam-ip.dump.gz</url>
<header>Nix_Spam</header>
</row>
<action>Disabled</action>
<cron>Never</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>P2P</aliasname>
<description><![CDATA[pfBlockerNG P2P]]></description>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=cwworuawihqvocglcoss&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>Bluetack_Badpeer</header>
</row>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=ydxerpxkpcfqjaybcssw&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>Bluetack_Level1</header>
</row>
<row>
<format>gz</format>
<state>Enabled</state>
<url>http://list.iblocklist.com/?list=ijfqtofzixtwayqovmxn&amp;fileformat=p2p&amp;archiveformat=gz</url>
<header>TBG_Primary_Threats</header>
</row>
<action>Alias_Deny</action>
<cron>12hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto>tcp/udp</autoproto>
<custom/>
<custom_update>disabled</custom_update>
</config>
<config>
<aliasname>CUST</aliasname>
<description><![CDATA[pfBlockerNG CUSTOM]]></description>
<row>
<format>txt</format>
<state>Enabled</state>
<url>http://lists.blocklist.de/lists/all.txt</url>
<header>BlocklistDE</header>
</row>
<action>Deny_Both</action>
<cron>04hours</cron>
<dow>1</dow>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
<custom/>
<custom_update>disabled</custom_update>
</config>
</pfblockernglistsv4>
<pfblockerngproxyandsatellite>
<config>
<countries4>A1</countries4>
<action>Deny_Inbound</action>
<aliaslog>enabled</aliaslog>
<autoports/>
<aliasports/>
<autodest/>
<aliasdest/>
<autonot/>
<autoproto/>
</config>
</pfblockerngproxyandsatellite>
<pfblockernglistsv6/>
(1-1/2)