Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 13 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow PeerGuardian2
Ethical Hacker Community Forums
November 23, 2008, 04:57:58 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: PeerGuardian2  (Read 1384 times)
0 Members and 1 Guest are viewing this topic.
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« on: May 22, 2008, 01:37:45 PM »

So I've been fighting spam at work for a little while now trying to get ahead and, until recently, I hadn't had much luck. It seemed like a losing battle.

I'm sure most of you hear the same thing from your end-users... "I received a ton of spam mails today!" Come to find out, they received a whopping 4 in their inbox when they got in this morning. It apparently kills them to click the delete button this many times, so they feel the need to complain to IT.

On our end, we typically just ignore it, and point them to their junk box which typically contains thousands of junk emails for the past 30 days that didn't get to their inbox.

Yet still, they just don't seem to comprehend how much spam is actually blocked. I know at our company, for the past few months our spam filter has recorded blocking upwards of 5 million spam emails per month. We're not that big of a company, so I can't imagine what others must see.

We had added all of the possible updates to our spam filter, turned up the aggressiveness, and still we were receiving complaints. I attempted to try and block the top spammers at our firewall, but this was a pretty crappy task and made me want to pull my hair out each day sitting and recording all the new IPs. Finally I thought I had a great idea... since we don't do business in country X, why don't I just add all the network ranges for that country into the firewall instead.

This worked out pretty well... until I found out the firewall has a limit to how many I could add. So, I thought my battle against spam was over... Spam 1, Bill 0.

Enter PeerGuardian2 by Phoenix Labs

A co-worker stumbled upon this little utility called PeerGuardian and said that it could block both inbound and outbound traffic by simply giving it a list of IP addresses or ranges. Awesome!

With a little help of countryipblocks.net, I had a pretty good list of IP ranges for every country.

I installed this utility, gave it my list, and it immediately went to work blocking IP addresses from China, Russia, Spain, etc. The only problem at this point was that it stopped running as soon as I logged out. Not a problem. A quick search and there are some perfect instructions for installing as a service.

Our spam filter intake has decreased from an average of 10-15K spam emails/hour, to under 1K an hour, and still decreasing. I continue to find new IPs not listed on countryipblocks.net, but as soon as I do, I toss it into my list and easily block the whole range.

Anyway, it's a great little tool (though no direct relation to hacking) and I'm just excited that I've finally got a better handle on the inbound spam. Sorry for such a long post Tongue

BillV

edit: forgot to note that this is a free, open-source utility and supported on Windows 98, ME, 2000, XP, and 2003, in 32-bit and 64-bit.
« Last Edit: May 22, 2008, 01:43:25 PM by BillV » Logged
eth3real
Full Member
***
Offline Offline

Posts: 130



View Profile
« Reply #1 on: May 22, 2008, 01:54:52 PM »

That's great! Is that something that you could just install on an exchange server, or rollout to the affected workstations?

Thanks for the great post!
Logged

Jess Hires
MCP, C|EH
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« Reply #2 on: May 22, 2008, 02:03:58 PM »

That's great! Is that something that you could just install on an exchange server, or rollout to the affected workstations?

Thanks for the great post!

No problem Smiley

If your intent is to block spam then you'll want to put it higher up the chain. In my case, our mail works as follows...

Internet -> Firewall -> Spam Filter -> Exchange Server

I installed PeerGuardian onto the Spam Filter server. This way, it doesn't even get to the Exchange server, so much less processing of junk Wink
Logged
rdkumarj
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #3 on: June 18, 2008, 10:27:04 PM »


 Hi

    Great Dude, Very useful post... Thanks for it...
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.052 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.