Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Blocking IPs

Status
Not open for further replies.

thedaver

IS-IT--Management
Jul 12, 2001
2,741
US
I have been successfully using /etc/hosts.deny to block a few pernicious thug IPs from pestering my SSH port.

I now have a few IPs I'd like to block for TCP/80 for Apache.

However, I found that /etc/hosts.deny does not seem to apply to Apache???

"ALL : ip/mask" does not prevent their access to TCP/80.

I really don't feel like trumping up a whole IPTables solution to block a few pests.... other ideas? No need to be courteous to these IPs.. BUT I don't want to leave an httpd child process left open any longer than needed to turn these IPs away.

I guess I'm kind of arguing myself into an IPTables solution, but I'd appreciate any other ideas!
Thanks,
D.

D.E.R. Management - IT Project Management Consulting
 
I think I would do it at the iptables level. Iptables can prevent your IP stack from returning anything to a hostile IP address, effectively making it disappear. I think anything else sends back enough data that a hostile entity can deduce that your machine is up but blocking.

Also, you could combine SSH blocking and HTTP blocking in iptables and handle both in one place.





Want to ask the best questions? Read Eric S. Raymond's essay "How To Ask Questions The Smart Way". TANSTAAFL!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top