** Description changed:

  1) Ubuntu 26.04
  2) UFW 0.36.2
  3) Maybe a script could be written to extract malicious ip addresses from 
AnyRun malware tracker and output it to a data file. The data file would be 
downloaded from the Ubuntu server and the file(owned by root to prevent 
modification) would add entries to the block list in the Ubuntu system 
firewall. Automatically block connections to malicious ip addresses. Add option 
to display notification if web browser, local script, app tries to connect to 
malicious ip addresses. Exploit kits could infect a user’s web browser, disable 
browser protections and then attempt a connection to a malicious ip address. 
The Ubuntu system firewall is isolated from the web browser. If the web browser 
attempts a connection to a malicious ip address, the system firewall would 
block it. This might help protect Ubuntu users against zero day web browser 
based threats.
  
  Indicators of compromise for a RAT:
  https://any.run/malware-trends/asyncrat/
  
+ Linux malware analysis sandbox:
+ https://any.run/platforms/linux/
+ 
  4) No malicious ip address blocking.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161677

Title:
  Feature Request: Malicious ip address notification/block

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ufw/+bug/2161677/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to