|
@@ -1260,6 +1260,39 @@ iptables -A syn_flood -j DROP
|
1260
|
1260
|
iptables -A INPUT -p icmp -j DROP
|
1261
|
1261
|
#iptables -A OUTPUT -p icmp -j ACCEPT
|
1262
|
1262
|
|
|
1263
|
+# Block malware servers (See Der Spiegel Snowden files)
|
|
1264
|
+iptables -A INPUT -s 146.185.26.163 -j DROP
|
|
1265
|
+iptables -A INPUT -s 37.130.229.100 -j DROP
|
|
1266
|
+iptables -A INPUT -s 85.237.211.198 -j DROP
|
|
1267
|
+iptables -A INPUT -s 85.237.212.52 -j DROP
|
|
1268
|
+iptables -A INPUT -s 85.237.211.177 -j DROP
|
|
1269
|
+iptables -A INPUT -s 212.118.232.184 -j DROP
|
|
1270
|
+iptables -A INPUT -s 212.118.232.50 -j DROP
|
|
1271
|
+iptables -A INPUT -s 176.249.28.104 -j DROP
|
|
1272
|
+iptables -A INPUT -s 212.118.232.140 -j DROP
|
|
1273
|
+iptables -A INPUT -s 37.130.229.101 -j DROP
|
|
1274
|
+iptables -A INPUT -s 31.6.17.94 -j DROP
|
|
1275
|
+iptables -A INPUT -s 84.45.121.218 -j DROP
|
|
1276
|
+iptables -A INPUT -s 80.84.63.242 -j DROP
|
|
1277
|
+iptables -A INPUT -s 37.220.10.28 -j DROP
|
|
1278
|
+iptables -A INPUT -s 94.229.78.58 -j DROP
|
|
1279
|
+
|
|
1280
|
+iptables -A OUTPUT -s 146.185.26.163 -j DROP
|
|
1281
|
+iptables -A OUTPUT -s 37.130.229.100 -j DROP
|
|
1282
|
+iptables -A OUTPUT -s 85.237.211.198 -j DROP
|
|
1283
|
+iptables -A OUTPUT -s 85.237.212.52 -j DROP
|
|
1284
|
+iptables -A OUTPUT -s 85.237.211.177 -j DROP
|
|
1285
|
+iptables -A OUTPUT -s 212.118.232.184 -j DROP
|
|
1286
|
+iptables -A OUTPUT -s 212.118.232.50 -j DROP
|
|
1287
|
+iptables -A OUTPUT -s 176.249.28.104 -j DROP
|
|
1288
|
+iptables -A OUTPUT -s 212.118.232.140 -j DROP
|
|
1289
|
+iptables -A OUTPUT -s 37.130.229.101 -j DROP
|
|
1290
|
+iptables -A OUTPUT -s 31.6.17.94 -j DROP
|
|
1291
|
+iptables -A OUTPUT -s 84.45.121.218 -j DROP
|
|
1292
|
+iptables -A OUTPUT -s 80.84.63.242 -j DROP
|
|
1293
|
+iptables -A OUTPUT -s 37.220.10.28 -j DROP
|
|
1294
|
+iptables -A OUTPUT -s 94.229.78.58 -j DROP
|
|
1295
|
+
|
1263
|
1296
|
# Save the settings
|
1264
|
1297
|
iptables-save > /etc/firewall.conf
|
1265
|
1298
|
ip6tables-save > /etc/firewall6.conf
|