{"id":1590,"date":"2024-03-17T15:06:57","date_gmt":"2024-03-17T19:06:57","guid":{"rendered":"https:\/\/www.rfdm.com\/blog\/?p=1590"},"modified":"2024-03-17T15:08:00","modified_gmt":"2024-03-17T19:08:00","slug":"mcblockd-7-years-on","status":"publish","type":"post","link":"https:\/\/www.rfdm.com\/blog\/?p=1590","title":{"rendered":"mcblockd 7 years on"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It&#8217;s been 7 years since I created and deployed my security automation software on my gateway (which runs FreeBSD).  And for the 7th year in a row, the automation is blocking more IP address space from China than any other country.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other words, China continues to be the most hostile networked country.  mcblockd is now blocking port 22 (ssh) from over 151 million IPv4 addresses in China.  This isn&#8217;t really surprising or even news.  Though it would be nice if the general public actually understood the persistent threat before whining that they don&#8217;t want TikTok to be divested from ByteDance (noting the legislation that recently passed the House of Representatives in the U.S.).  I don&#8217;t know how to communicate how much attack traffic originates from China to a person who doesn&#8217;t understand IP networking.  But I can say that in my own home, not more than a few minutes go by without probe and attack traffic hitting my gateway from China.  It&#8217;s round the clock.  Many users are relatively safe simply because none of their devices are running server software.  What they don&#8217;t realize is that the probing is constant, and costs all of us bandwidth even if we have no servers at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I bring this up because this weekend I did my annual perusal of my web server logs and added a bunch of networks to the list of those I deny.  And in the process my average outbound traffic decreased by roughly 500 kilobits\/second.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A continuing and growing annoyance that I don&#8217;t think our legislators, or for that matter our large hosting services, are minding: it continues to be the case that the bad guys are attacking us from cloud infrastructure, much of it on U.S. soil.  It&#8217;s clear to me that various entities, since they&#8217;re profiting from it, just don&#8217;t care.  Google, Amazon, Microsoft, DigitalOcean, GoDaddy, Hurricane Electric, PSINet, Cogent, OVH, Hetzner, Linode, others&#8230; they&#8217;re all used as weapons against our homes and small businesses connected to the Internet.  In fact they&#8217;re incentivized&#8230; having your small business DDoS&#8217;ed or penetrated is an argument for moving your Internet services to the cloud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As an example annoyance, my web site fairly regularly gets hammered from address space owned by &#8216;FINE GROUP SERVERS LLC&#8217; and &#8216;TrafficTransitSolution LLC&#8217; which as near as I can tell are shell companies run by the Russian Federation.  They utilize a truckload of small address space allocations (nearly all \/24), most of which are here in the U.S., to crawl my web site regularly.  And some of their infrastructure is a pain in the ass to block because it&#8217;s within old PSINet large allocations and not called out in whois or RDAP data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At any rate, you can see the result of my annual maintenance below.  My site was averaging 500 to 600 kilobits\/second outbound before I started adding new networks to my block list.  I&#8217;m now back down to around 100 kilobits\/second.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"598\" src=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317-1024x598.png\" alt=\"\" class=\"wp-image-1595\" srcset=\"https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317-1024x598.png 1024w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317-300x175.png 300w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317-768x449.png 768w, https:\/\/www.rfdm.com\/blog\/wp-content\/uploads\/2024\/03\/sitetraffic_20240317.png 1332w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been 7 years since I created and deployed my security automation software on my gateway (which runs FreeBSD). And for the 7th year in a row, the automation is blocking more IP address space from China than any other country. In other words, China continues to be the most hostile networked country. mcblockd is &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.rfdm.com\/blog\/?p=1590\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;mcblockd 7 years on&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29,85,12],"tags":[],"class_list":["post-1590","post","type-post","status-publish","format-standard","hentry","category-freebsd","category-network-security","category-software-development"],"_links":{"self":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1590"}],"version-history":[{"count":4,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1590\/revisions"}],"predecessor-version":[{"id":1597,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1590\/revisions\/1597"}],"wp:attachment":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}