|
@@ -4,8 +4,8 @@
|
|
|
|
|
|
### Version Information #
|
|
|
###################################################
|
|
|
-### Version: V3.2017.07.520
|
|
|
-### Updated: Sat Jul 22 12:54:29 SAST 2017
|
|
|
+### Version: V3.2017.07.521
|
|
|
+### Updated: Sat Jul 22 13:07:50 SAST 2017
|
|
|
### Bad Referrer Count: 5436
|
|
|
### Bad Bot Count: 498
|
|
|
###################################################
|
|
@@ -31,29 +31,30 @@
|
|
|
# load this into one site and monitor it for any possible false positives before putting
|
|
|
# this into production on all your web sites.
|
|
|
|
|
|
-# CONFIGURATION EXAMPLE:
|
|
|
-# **********************
|
|
|
-# Include this in the beginning of a directory block just after your opening
|
|
|
-# Options statements and before the rest of your host config example below
|
|
|
-#
|
|
|
-# ---------------------------------------------------------------------------------
|
|
|
-# <VirtualHost *:443>
|
|
|
-# .....
|
|
|
-# .....
|
|
|
-#<Directory "/var/www/mywebsite/htdocs/">
|
|
|
-#Options +Includes
|
|
|
-#Options +FollowSymLinks -Indexes
|
|
|
-#Include /etc/apache2/custom.d/globalblacklist.conf <<<<<< This needs to be added
|
|
|
-# ......
|
|
|
-# ......
|
|
|
-# BEGIN WordPress
|
|
|
-#<IfModule mod_rewrite.c>
|
|
|
-# ---------------------------------------------------------------------------------
|
|
|
-####################################################################################
|
|
|
+# ******************************************
|
|
|
+# CONFIGURATION INSIDE A VIRTUALHOST EXAMPLE
|
|
|
+# ******************************************
|
|
|
+# This is how you should include the globalblacklist.conf within a VirtualHost
|
|
|
+
|
|
|
+ # ********************************************************
|
|
|
+ # ********************************************************
|
|
|
+ # <VirtualHost *:80>
|
|
|
+ # ServerName local.dev
|
|
|
+ # DocumentRoot /var/www/html
|
|
|
+ # RewriteEngine On
|
|
|
+ # ErrorLog /tmp/error.log
|
|
|
+ # <Directory /var/www/html>
|
|
|
+ # AllowOverride All
|
|
|
+ # Options FollowSymLinks
|
|
|
+ # Include /etc/apache2/custom.d/globalblacklist.conf
|
|
|
+ # </Directory>
|
|
|
+ # </VirtualHost>
|
|
|
+ # ********************************************************
|
|
|
+ # ********************************************************
|
|
|
|
|
|
- # *********************************
|
|
|
- # FIRST BLOCK BY USER-AGENT STRINGS
|
|
|
- # *********************************
|
|
|
+# *********************************
|
|
|
+# FIRST BLOCK BY USER-AGENT STRINGS
|
|
|
+# *********************************
|
|
|
|
|
|
# PLEASE TEST !!!
|
|
|
# ***************
|
|
@@ -669,9 +670,9 @@ Include "/etc/apache2/custom.d/blacklist-user-agents.conf"
|
|
|
Include "/etc/apache2/custom.d/whitelist-domains.conf"
|
|
|
|
|
|
|
|
|
- # ****************************************
|
|
|
- # SECOND BLOCK BY REFERER STRINGS AND URLS
|
|
|
- # ****************************************
|
|
|
+# ****************************************
|
|
|
+# SECOND BLOCK BY REFERER STRINGS AND URLS
|
|
|
+# ****************************************
|
|
|
|
|
|
# Add here all referrer words and URL's that are to blocked.
|
|
|
# Referers are often used to spam or make your site appear to be spam
|
|
@@ -6226,11 +6227,35 @@ SetEnvIfNoCase Referer ~*zzlgxh\.com spam_ref
|
|
|
# END BAD REFERERS ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
|
|
|
- # NOW ACTIVATE OUR ACCESS CONTROLS USING NEW APACHE 2.4 SYNTAX
|
|
|
- # Remember to de-activate the module access_compat by running sudo a2dismod access_compat
|
|
|
+# ***************************************************************************************
|
|
|
+# NOW WE ACTIVATE THE BLOCKER USING OUR ACCESS CONTROLS WITH NEW APACHE 2.4 SYNTAX
|
|
|
+# Remember to de-activate the module access_compat by running sudo a2dismod access_compat
|
|
|
+# This is where we actually make the blocker work, everything before and above this
|
|
|
+# section is merely where we are declaring our environment variables.
|
|
|
+# ***************************************************************************************
|
|
|
+
|
|
|
+ # ******************************************
|
|
|
+ # CONFIGURATION INSIDE A VIRTUALHOST EXAMPLE
|
|
|
+ # ******************************************
|
|
|
+ # This is how you should include the globalblacklist.conf within a VirtualHost
|
|
|
+
|
|
|
+ # ********************************************************
|
|
|
+ # ********************************************************
|
|
|
+ # <VirtualHost *:80>
|
|
|
+ # ServerName local.dev
|
|
|
+ # DocumentRoot /var/www/html
|
|
|
+ # RewriteEngine On
|
|
|
+ # ErrorLog /tmp/error.log
|
|
|
+ # <Directory /var/www/html>
|
|
|
+ # AllowOverride All
|
|
|
+ # Options FollowSymLinks
|
|
|
+ # Include /etc/apache2/custom.d/globalblacklist.conf
|
|
|
+ # </Directory>
|
|
|
+ # </VirtualHost>
|
|
|
+ # ********************************************************
|
|
|
+ # ********************************************************
|
|
|
|
|
|
<RequireAll>
|
|
|
- #<RequireAll>
|
|
|
|
|
|
Require all granted
|
|
|
Require not env bad_bot
|
|
@@ -6240,51 +6265,51 @@ SetEnvIfNoCase Referer ~*zzlgxh\.com spam_ref
|
|
|
# Wordpress Theme Detectors
|
|
|
# *************************
|
|
|
|
|
|
-# START WP THEME DETECTORS ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
-Require not ip 104.197.51.76
|
|
|
-Require not ip 108.167.189.81
|
|
|
-Require not ip 109.73.225.87
|
|
|
-Require not ip 13.68.211.181
|
|
|
-Require not ip 142.4.218.201
|
|
|
-Require not ip 149.56.33.22
|
|
|
-Require not ip 158.69.187.171
|
|
|
-Require not ip 158.69.26.58
|
|
|
-Require not ip 162.13.185.20
|
|
|
-Require not ip 173.237.189.235
|
|
|
-Require not ip 173.255.210.133
|
|
|
-Require not ip 185.45.14.186
|
|
|
-Require not ip 192.163.217.239
|
|
|
-Require not ip 192.185.4.40
|
|
|
-Require not ip 192.95.29.139
|
|
|
-Require not ip 192.99.17.79
|
|
|
-Require not ip 198.27.69.229
|
|
|
-Require not ip 198.58.124.46
|
|
|
-Require not ip 199.241.28.124
|
|
|
-Require not ip 212.71.238.108
|
|
|
-Require not ip 37.247.121.179
|
|
|
-Require not ip 37.60.253.215
|
|
|
-Require not ip 45.63.68.250
|
|
|
-Require not ip 45.79.139.191
|
|
|
-Require not ip 50.116.84.148
|
|
|
-Require not ip 52.87.112.125
|
|
|
-Require not ip 66.96.183.60
|
|
|
-Require not ip 89.36.223.188
|
|
|
-# END WP THEME DETECTORS ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ # START WP THEME DETECTORS ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ Require not ip 104.197.51.76
|
|
|
+ Require not ip 108.167.189.81
|
|
|
+ Require not ip 109.73.225.87
|
|
|
+ Require not ip 13.68.211.181
|
|
|
+ Require not ip 142.4.218.201
|
|
|
+ Require not ip 149.56.33.22
|
|
|
+ Require not ip 158.69.187.171
|
|
|
+ Require not ip 158.69.26.58
|
|
|
+ Require not ip 162.13.185.20
|
|
|
+ Require not ip 173.237.189.235
|
|
|
+ Require not ip 173.255.210.133
|
|
|
+ Require not ip 185.45.14.186
|
|
|
+ Require not ip 192.163.217.239
|
|
|
+ Require not ip 192.185.4.40
|
|
|
+ Require not ip 192.95.29.139
|
|
|
+ Require not ip 192.99.17.79
|
|
|
+ Require not ip 198.27.69.229
|
|
|
+ Require not ip 198.58.124.46
|
|
|
+ Require not ip 199.241.28.124
|
|
|
+ Require not ip 212.71.238.108
|
|
|
+ Require not ip 37.247.121.179
|
|
|
+ Require not ip 37.60.253.215
|
|
|
+ Require not ip 45.63.68.250
|
|
|
+ Require not ip 45.79.139.191
|
|
|
+ Require not ip 50.116.84.148
|
|
|
+ Require not ip 52.87.112.125
|
|
|
+ Require not ip 66.96.183.60
|
|
|
+ Require not ip 89.36.223.188
|
|
|
+ # END WP THEME DETECTORS ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
# ****************************************
|
|
|
# NIBBLER - SEO testing and reporting tool
|
|
|
# ****************************************
|
|
|
# See - http://nibbler.silktide.com/
|
|
|
|
|
|
-# START NIBBLER ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
-Require not ip 52.201.238.175
|
|
|
-Require not ip 52.90.20.216
|
|
|
-Require not ip 54.161.247.146
|
|
|
-Require not ip 54.211.214.177
|
|
|
-Require not ip 54.227.194.252
|
|
|
-Require not ip 54.242.239.179
|
|
|
-Require not ip 54.242.250.203
|
|
|
-# END NIBBLER ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ # START NIBBLER ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ Require not ip 52.201.238.175
|
|
|
+ Require not ip 52.90.20.216
|
|
|
+ Require not ip 54.161.247.146
|
|
|
+ Require not ip 54.211.214.177
|
|
|
+ Require not ip 54.227.194.252
|
|
|
+ Require not ip 54.242.239.179
|
|
|
+ Require not ip 54.242.250.203
|
|
|
+ # END NIBBLER ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
# *************************************************
|
|
|
# Blacklist IP addresses and IP Ranges Customizable
|
|
@@ -6299,8 +6324,6 @@ Require not ip 54.242.250.203
|
|
|
Include "/etc/apache2/custom.d/blacklist-ips.conf"
|
|
|
|
|
|
|
|
|
- #</RequireAll>
|
|
|
-
|
|
|
<RequireAny>
|
|
|
|
|
|
Require env good_ref
|
|
@@ -6329,89 +6352,89 @@ Require not ip 54.242.250.203
|
|
|
# For Safety Sake Google's Known BOT IP Ranges are all white listed in case you add
|
|
|
# anything lower down that you mistakenly picked up as a bad bot.
|
|
|
|
|
|
-# START GOOGLE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
-Require ip 108.177.8.0/21
|
|
|
-Require ip 108.177.96.0/19
|
|
|
-Require ip 172.217.0.0/19
|
|
|
-Require ip 173.194.0.0/16
|
|
|
-Require ip 2001:4860:4000::/36
|
|
|
-Require ip 203.208.60.0/24
|
|
|
-Require ip 207.126.144.0/20
|
|
|
-Require ip 209.85.128.0/17
|
|
|
-Require ip 216.239.32.0/19
|
|
|
-Require ip 216.58.192.0/19
|
|
|
-Require ip 2404:6800:4000::/36
|
|
|
-Require ip 2607:f8b0:4000::/36
|
|
|
-Require ip 2800:3f0:4000::/36
|
|
|
-Require ip 2a00:1450:4000::/36
|
|
|
-Require ip 2c0f:fb50:4000::/36
|
|
|
-Require ip 64.18.0.0/20
|
|
|
-Require ip 64.233.160.0/19
|
|
|
-Require ip 64.68.80.0/21
|
|
|
-Require ip 66.102.0.0/20
|
|
|
-Require ip 66.249.64.0/18
|
|
|
-Require ip 72.14.192.0/18
|
|
|
-Require ip 74.125.0.0/16
|
|
|
-# END GOOGLE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ # START GOOGLE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ Require ip 108.177.8.0/21
|
|
|
+ Require ip 108.177.96.0/19
|
|
|
+ Require ip 172.217.0.0/19
|
|
|
+ Require ip 173.194.0.0/16
|
|
|
+ Require ip 2001:4860:4000::/36
|
|
|
+ Require ip 203.208.60.0/24
|
|
|
+ Require ip 207.126.144.0/20
|
|
|
+ Require ip 209.85.128.0/17
|
|
|
+ Require ip 216.239.32.0/19
|
|
|
+ Require ip 216.58.192.0/19
|
|
|
+ Require ip 2404:6800:4000::/36
|
|
|
+ Require ip 2607:f8b0:4000::/36
|
|
|
+ Require ip 2800:3f0:4000::/36
|
|
|
+ Require ip 2a00:1450:4000::/36
|
|
|
+ Require ip 2c0f:fb50:4000::/36
|
|
|
+ Require ip 64.18.0.0/20
|
|
|
+ Require ip 64.233.160.0/19
|
|
|
+ Require ip 64.68.80.0/21
|
|
|
+ Require ip 66.102.0.0/20
|
|
|
+ Require ip 66.249.64.0/18
|
|
|
+ Require ip 72.14.192.0/18
|
|
|
+ Require ip 74.125.0.0/16
|
|
|
+ # END GOOGLE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
# *********
|
|
|
# Bing Bots
|
|
|
# *********
|
|
|
|
|
|
-# START BING IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
-Require ip 131.253.24.0/22
|
|
|
-Require ip 131.253.46.0/23
|
|
|
-Require ip 157.54.0.0/15
|
|
|
-Require ip 157.56.0.0/14
|
|
|
-Require ip 157.60.0.0/16
|
|
|
-Require ip 199.30.16.0/24
|
|
|
-Require ip 199.30.27.0/24
|
|
|
-Require ip 207.46.0.0/16
|
|
|
-Require ip 40.112.0.0/13
|
|
|
-Require ip 40.120.0.0/14
|
|
|
-Require ip 40.124.0.0/16
|
|
|
-Require ip 40.125.0.0/17
|
|
|
-Require ip 40.74.0.0/15
|
|
|
-Require ip 40.76.0.0/14
|
|
|
-Require ip 40.80.0.0/12
|
|
|
-Require ip 40.96.0.0/12
|
|
|
-Require ip 65.52.104.0/24
|
|
|
-Require ip 65.52.108.0/22
|
|
|
-Require ip 65.55.213.0/24
|
|
|
-Require ip 65.55.217.0/24
|
|
|
-Require ip 65.55.24.0/24
|
|
|
-Require ip 65.55.52.0/24
|
|
|
-Require ip 65.55.55.0/24
|
|
|
-# END BING IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ # START BING IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ Require ip 131.253.24.0/22
|
|
|
+ Require ip 131.253.46.0/23
|
|
|
+ Require ip 157.54.0.0/15
|
|
|
+ Require ip 157.56.0.0/14
|
|
|
+ Require ip 157.60.0.0/16
|
|
|
+ Require ip 199.30.16.0/24
|
|
|
+ Require ip 199.30.27.0/24
|
|
|
+ Require ip 207.46.0.0/16
|
|
|
+ Require ip 40.112.0.0/13
|
|
|
+ Require ip 40.120.0.0/14
|
|
|
+ Require ip 40.124.0.0/16
|
|
|
+ Require ip 40.125.0.0/17
|
|
|
+ Require ip 40.74.0.0/15
|
|
|
+ Require ip 40.76.0.0/14
|
|
|
+ Require ip 40.80.0.0/12
|
|
|
+ Require ip 40.96.0.0/12
|
|
|
+ Require ip 65.52.104.0/24
|
|
|
+ Require ip 65.52.108.0/22
|
|
|
+ Require ip 65.55.213.0/24
|
|
|
+ Require ip 65.55.217.0/24
|
|
|
+ Require ip 65.55.24.0/24
|
|
|
+ Require ip 65.55.52.0/24
|
|
|
+ Require ip 65.55.55.0/24
|
|
|
+ # END BING IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
# ********************
|
|
|
# Cloudflare IP Ranges
|
|
|
# ********************
|
|
|
|
|
|
-# START CLOUDFLARE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
-Require ip 103.21.244.0/22
|
|
|
-Require ip 103.22.200.0/22
|
|
|
-Require ip 103.31.4.0/22
|
|
|
-Require ip 104.16.0.0/12
|
|
|
-Require ip 108.162.192.0/18
|
|
|
-Require ip 131.0.72.0/22
|
|
|
-Require ip 141.101.64.0/18
|
|
|
-Require ip 162.158.0.0/15
|
|
|
-Require ip 172.64.0.0/13
|
|
|
-Require ip 173.245.48.0/20
|
|
|
-Require ip 188.114.96.0/20
|
|
|
-Require ip 190.93.240.0/20
|
|
|
-Require ip 197.234.240.0/22
|
|
|
-Require ip 198.41.128.0/17
|
|
|
-Require ip 199.27.128.0/21
|
|
|
-Require ip 2400:cb00::/32
|
|
|
-Require ip 2405:8100::/32
|
|
|
-Require ip 2405:b500::/32
|
|
|
-Require ip 2606:4700::/32
|
|
|
-Require ip 2803:f800::/32
|
|
|
-Require ip 2a06:98c0::/29
|
|
|
-Require ip 2c0f:f248::/32
|
|
|
-# END CLOUDFLARE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ # START CLOUDFLARE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
+ Require ip 103.21.244.0/22
|
|
|
+ Require ip 103.22.200.0/22
|
|
|
+ Require ip 103.31.4.0/22
|
|
|
+ Require ip 104.16.0.0/12
|
|
|
+ Require ip 108.162.192.0/18
|
|
|
+ Require ip 131.0.72.0/22
|
|
|
+ Require ip 141.101.64.0/18
|
|
|
+ Require ip 162.158.0.0/15
|
|
|
+ Require ip 172.64.0.0/13
|
|
|
+ Require ip 173.245.48.0/20
|
|
|
+ Require ip 188.114.96.0/20
|
|
|
+ Require ip 190.93.240.0/20
|
|
|
+ Require ip 197.234.240.0/22
|
|
|
+ Require ip 198.41.128.0/17
|
|
|
+ Require ip 199.27.128.0/21
|
|
|
+ Require ip 2400:cb00::/32
|
|
|
+ Require ip 2405:8100::/32
|
|
|
+ Require ip 2405:b500::/32
|
|
|
+ Require ip 2606:4700::/32
|
|
|
+ Require ip 2803:f800::/32
|
|
|
+ Require ip 2a06:98c0::/29
|
|
|
+ Require ip 2c0f:f248::/32
|
|
|
+ # END CLOUDFLARE IP RANGES ### DO NOT EDIT THIS LINE AT ALL ###
|
|
|
|
|
|
</RequireAny>
|
|
|
|