Si vas a jugar cno iptables, fijate de limitarle la cantidad de conexiones concurrentes al equipo. As� de tal ip, la que sea, no pueden tener mas de x conexiones cnocurrentes al peurto 80. Porque sino cuando te hagan lo mismo desde otra ip te va a pasar lo mismo.
Slds.


Esteban Darreche wrote:

Lo podrias hacer por tres lugares ... Acceso a Nivel Apache ... TcpWrappers
o Iptables...

Me parece mas piola Hacerlo por IpTables ...

----- Original Message ----- From: "Fernando Gabriel Ranea" <[EMAIL PROTECTED]>
To: "Lista de temas generales del LUGAr y de Linux"
<[email protected]>
Sent: Monday, April 18, 2005 8:47 PM
Subject: [LUGAr-gral] Bloquear direcciones molestas





Hola,

Desde hace unos d�as, empec� a tener muchas conexiones a mi servidor web
que no se correspond�an a visitas porque eran m�ltiples conexiones desde
 la mismas IPs. Un ejemplo, post intento de bloque con un archivo
.htaccess, se ve abajo con un "netstat --tcp -n".

Buscando en la web, uno de los servidores es "famoso" por intentos de
spam. El servidor es "reverse.theplanet.com" y el que me est� molestando
es "154.70-84-226.reverse.theplanet.com" o "70.84.226.154", entre otros.
Trat� de bloquearlo con algunas medidas como un "deny from" en un
.htaccess pero me parece que no funciona demasiado.

�Hay alguna forma de bloquear a estas direcciones IP que no se si son
maliciosas o tienen algun virus instalado y buscan vulnerabilidades en
otros servidores, etc? �O tengo que recurrir a reglas con Iptables?
Saludos,


Active Internet connections (w/o servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 24.232.118.159:80 205.209.149.20:1422 TIME_WAIT - tcp 0 1 24.232.118.227:80 67.19.193.42:2394 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 67.19.193.42:2971 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.148.80:4842 TIME_WAIT - tcp 0 1 24.232.118.159:80 70.84.226.154:4012 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 70.84.226.154:1740 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:2899 ESTABLISHED - tcp 0 0 24.232.118.159:80 70.84.226.154:4143 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.120:2176 TIME_WAIT - tcp 0 0 24.232.118.159:80 205.209.149.100:2716 TIME_WAIT - tcp 1 0 24.232.118.159:80 205.209.157.150:2713 CLOSE_WAIT - tcp 0 1 24.232.118.227:80 70.84.226.154:1653 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 67.19.193.42:3458 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 70.84.226.154:4329 ESTABLISHED - tcp 0 0 24.232.118.227:80 67.19.193.42:3422 ESTABLISHED - tcp 0 0 24.232.118.159:80 70.84.226.154:4041 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.20:3915 TIME_WAIT - tcp 0 1 24.232.118.159:80 67.19.193.42:1571 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 70.84.226.154:2504 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 70.84.226.154:3927 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.50:2318 TIME_WAIT - tcp 0 1 24.232.118.159:80 70.84.226.154:1130 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 67.19.193.42:4413 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:1113 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.120:2538 TIME_WAIT - tcp 0 0 24.232.118.159:80 205.209.151.230:4713 TIME_WAIT - tcp 0 1 24.232.118.227:80 70.84.226.154:2873 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 67.19.193.42:2483 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.20:3047 TIME_WAIT - tcp 0 0 24.232.118.159:80 67.19.193.42:3695 ESTABLISHED - tcp 0 1 24.232.118.159:80 67.19.193.42:2127 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.120:3403 TIME_WAIT - tcp 0 1 24.232.118.227:80 70.84.226.154:3707 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 70.84.226.154:2311 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:1275 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.10:1850 TIME_WAIT - tcp 0 0 24.232.118.159:80 205.209.148.80:4192 TIME_WAIT - tcp 0 1 24.232.118.227:80 70.84.226.154:2397 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 70.84.226.154:4989 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 67.19.193.42:2027 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 70.84.226.154:3328 ESTABLISHED - tcp 0 1 24.232.118.159:80 70.84.226.154:1472 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 70.84.226.154:4544 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:1694 ESTABLISHED - tcp 0 0 24.232.118.159:80 67.19.193.42:4758 ESTABLISHED - tcp 0 0 24.232.118.227:80 67.19.193.42:2314 ESTABLISHED - tcp 0 0 24.232.118.159:80 67.19.193.42:2902 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:2656 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:1376 ESTABLISHED - tcp 0 1 24.232.118.159:80 70.84.226.154:2172 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.120:1907 TIME_WAIT - tcp 0 0 24.232.118.227:80 70.84.226.154:4256 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.100:3308 TIME_WAIT - tcp 0 1 24.232.118.159:80 70.84.226.154:2239 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 67.19.193.42:1064 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.151.230:1427 TIME_WAIT - tcp 0 0 24.232.118.227:80 70.84.226.154:2338 ESTABLISHED - tcp 0 0 24.232.118.227:80 67.19.193.42:4137 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.10:2948 TIME_WAIT - tcp 0 1 24.232.118.159:80 67.19.193.42:2738 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 70.84.226.154:1369 ESTABLISHED - tcp 0 0 24.232.118.227:80 67.19.193.42:3695 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:1639 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:2150 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:2342 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.149.120:1557 TIME_WAIT - tcp 0 1 24.232.118.227:80 70.84.226.154:2694 FIN_WAIT1 - tcp 0 1 24.232.118.159:80 70.84.226.154:4917 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:2120 ESTABLISHED - tcp 0 0 24.232.118.227:80 67.19.193.42:4515 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:4648 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 132.248.207.86:49818 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:3816 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:4776 ESTABLISHED - tcp 0 0 24.232.118.227:80 132.248.207.86:49817 ESTABLISHED - tcp 0 1 24.232.118.159:80 70.84.226.154:1943 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.151.230:3035 TIME_WAIT - tcp 0 0 24.232.118.159:80 70.84.226.154:1078 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.148.80:1719 TIME_WAIT - tcp 0 1 24.232.118.159:80 67.19.193.42:3482 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 67.19.193.42:1350 ESTABLISHED - tcp 0 0 24.232.118.227:80 70.84.226.154:3725 ESTABLISHED - tcp 0 0 24.232.118.159:80 70.84.226.154:2096 ESTABLISHED - tcp 0 1 24.232.118.159:80 70.84.226.154:4496 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 70.84.226.154:3056 ESTABLISHED - tcp 0 0 24.232.118.159:80 205.209.149.50:2774 TIME_WAIT - tcp 0 1 24.232.118.159:80 70.84.226.154:3091 FIN_WAIT1 - tcp 0 0 24.232.118.227:80 70.84.226.154:4143 ESTABLISHED - tcp 0 1 24.232.118.227:80 70.84.226.154:4047 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 70.84.226.154:2287 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 70.84.226.154:2223 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 67.19.193.42:1445 FIN_WAIT1 - tcp 0 1 24.232.118.227:80 70.84.226.154:1390 FIN_WAIT1 - tcp 0 0 24.232.118.159:80 205.209.151.230:4510 TIME_WAIT - tcp 0 0 24.232.118.159:80 205.209.149.50:2135 TIME_WAIT - tcp 0 0 24.232.118.159:80 70.84.226.154:3538 ESTABLISHED - -- Para desuscribirte ten�s que visitar la p�gina https://listas.linux.org.ar/mailman/listinfo/lugar-gral/

/* Publica y encontra trabajo relacionado con softlibre en


http://www.linux.org.ar/modules/jobs/ */


Si ten�s alg�n inconveniente o consulta escrib� a


mailto:[EMAIL PROTECTED]




-- Para desuscribirte ten�s que visitar la p�gina https://listas.linux.org.ar/mailman/listinfo/lugar-gral/

/* Publica y encontra trabajo relacionado con softlibre en 
http://www.linux.org.ar/modules/jobs/ */

Si ten�s alg�n inconveniente o consulta escrib� a mailto:[EMAIL PROTECTED]

Responder a