7 ms·
I've been blocking Hetzner, Digital Ocean, Linode, OVH and Contabo for a while. You can do this with pfBlocker NG by blocking ASNs, or UFW rules (https://blog.
by arcza 2y ago
I've been blocking Hetzner, Digital Ocean, Linode, OVH and Contabo for a while. You can do this with pfBlocker NG by blocking ASNs, or UFW rules (https://blog.abctaylor.com/ufw-and-firewalld-rules-to-block-vps-bots-and-scrapers/ https://blog.abctaylor.com/ufw-and-firewalld-rules-to-block-...)
- blueflow 2y agooof. Why Hetzner?
- arcza 2y agoDue to firewall logs showing DNS amplification attack attempts
- Dylan16807 2y agoWhy go beyond blocking direct DNS access? (Ideally you'd make then switch to TCP by truncating UDP responses to specific clients but that sounds like a hassle to set up so it's understandable to skip that.)
- immibis 2y agoEveryone is attempting all attacks all the time from everywhere. Why not secure yourself so the attempts fail?
- oneplane 2y agoAt that point secure would be 'offline'... It's not like botnets, "unlocker" farms and P2P doesn't originate from residential netblocks all day long. The idea of "I just want the legitimate traffic" is a simple one, but the implementation of the idea has very little to do with "I will just block the big bad cloud!".
- immibis 2y agoSecuring yourself means not being vulnerable to the attacks. Who cares if you are exposed to an internet radiation banana equivalent? Why worry? You'll hurt yourself more from the worry than from the radiation. Blocking huge IP ranges is knocking yourself half offline, and it doesn't even stop you being "attacked". I'd start blocking if and only if there is some actual problem for your server (e.g. excessive CPU or bandwidth usage), not just because big bad scary cloud.
- okr 2y agoI think it should be reciprocal, like in the real world. If someone blocks a provider, a provider should be allowed to block back. Maybe with some automatism. So it is fair and each party has information about what is going on. Or using real guns instead of these children games in the sandbox.
- blueflow 2y agoThe internet is not like twitter - a block is practically bidirectional.
- ninkendo 2y agoSo if I run a web server at home and I’m constantly attacked by AWS IPs, I shouldn’t be able to block them without myself being unable to access the lion’s share of the web hosted on AWS? Doesn’t that seem sort of extreme?
- icedchai 2y agoI run a web server at home, and have for decades. The constant scans is something you realize is "normal" and just ignore.
- chipdart 2y ago> I think it should be reciprocal, like in the real world. If someone blocks a provider, a provider should be allowed to block back. Maybe with some automatism. So it is fair and each party has information about what is going on. Or using real guns instead of these children games in the sandbox. I don't think your take makes any sense whatsoever. Beyond the puerile "I'll block you too", what exactly do you hope to achieve with this nonsense?
- nickjj 2y agoOne concern with doing this as a whole is you may end up blocking legit organizations from accessing your site. If you're selling something that could be a problem. For example, the org might be self-hosting WireGuard or another VPN solution on a cloud provider and people are connecting through that so their outgoing IP address comes from a cloud provider.
- theelous3 2y agoYou can whitelist ranges or whatever for larger customers, but that doesn't suit every form of product or client size ofc.
- fpoling 2y agoA big and and not so big enterprises these days uses VPN and similar solutions with exit nodes in the cloud so such blocks essentially prevents access to your web site from a work computer.