Country Blocking

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9, 10
Author Message
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6445
Location: UK, London, just across the river..

PostPosted: Sun Jul 16, 2017 9:42    Post subject: Reply with quote
Cheers Guys...
In order to avoid USB build malfunctioning i was wondering
is it possible to save this script in save start up under GUI and use it without USB mounted?
Do i have to re-edit it and how its going to look like??
So far i read all the pages and nobody mentioned anything
about running this script from GUI what would be the downside of it??

i tested 2 scripts from page 1 and page 8 and i can see there are results under
iptables -vNL INPUT, but i cannot run the others list commands...
Is there any new modified script yet ?
Thanks in advance!!

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Sponsor
Charcoal
DD-WRT Novice


Joined: 26 Oct 2017
Posts: 9

PostPosted: Fri Oct 27, 2017 12:52    Post subject: Unable to make this script work Reply with quote
Hi everyone,
Currently on a R7000 with Kong Build 33525M, I've been unable to make this amazing script work and wonder if you could please give me some help.

My USB tab looks like this in the setup. The drive is inserted in the back USB port:


I haven't modified the ipblock.sh file and just put it in this path: "/opt/ipblock/ipblock.sh" and gave it permissions 0755.

I used the firewall and cron commands from the first page except with ppp0 instead of vlan2 and it doesn't seem to work.

Whenever I try to run the script with Putty I obtain this:

Code:
root@R7000:~# sh /opt/ipblock/ipblock.sh
: not foundk/ipblock.sh: line 2:
: not foundk/ipblock.sh: line 4:
: not foundk/ipblock.sh: line 6:
: not foundk/ipblock.sh: line 7:
: not foundk/ipblock.sh: line 10:
: not foundk/ipblock.sh: line 12:
: not foundk/ipblock.sh: line 13:
: not foundk/ipblock.sh: line 14:
: not foundk/ipblock.sh: line 15:
: not foundk/ipblock.sh: line 16:
: not foundk/ipblock.sh: line 18:
: not foundk/ipblock.sh: line 19:
: not foundk/ipblock.sh: line 20:
: not foundk/ipblock.sh: line 21:
: not foundk/ipblock.sh: line 22:
: not foundk/ipblock.sh: line 23:
: not foundk/ipblock.sh: line 24:
/opt/ipblock/ipblock.sh: line 28: syntax error: unexpected word


Thanks a lot in advance !
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12904
Location: Netherlands

PostPosted: Fri Oct 27, 2017 13:57    Post subject: Reply with quote
Just some ideas Smile

Use winscp to see the file path do not use windows

you did add a shebang at the top of the script #!/bin/sh

You did make the script executable

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Charcoal
DD-WRT Novice


Joined: 26 Oct 2017
Posts: 9

PostPosted: Fri Oct 27, 2017 14:12    Post subject: Reply with quote
Thanks for your reply,
In WinSCP it looks like this:


The script begins with "#!/bin/sh", I've not modified it.

And I tried "chmod +x /opt/ipblock/ipblock.sh" as well with no results.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12904
Location: Netherlands

PostPosted: Fri Oct 27, 2017 14:33    Post subject: Reply with quote
That looks good so on to another hunch Smile
Sometimes copying the script with some windows editors can introduce strange characters on the beginning or end of the lines (invisible to the naked eye). Try to copy with notepad++

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Charcoal
DD-WRT Novice


Joined: 26 Oct 2017
Posts: 9

PostPosted: Fri Oct 27, 2017 14:40    Post subject: Reply with quote
I had used Notepad++ in the first space but all lines were ending with an extra space that I just manually deleted thanks to your advice.
The script can be launched now.
Thanks a lot for the help ! You saved my day !
lazardo
DD-WRT User


Joined: 17 Apr 2014
Posts: 139
Location: SF Bay Area

PostPosted: Wed Jan 10, 2018 0:26    Post subject: Reply with quote
http://blog.trendmicro.com/trendlabs-security-intelligence/a-closer-look-at-north-koreas-internet/

Article notes N kr using virtual address spaces (eg, VPN, AWS) to spoof blocks. The following are missing from kp-aggregated.zone as of today:
Code:
210.52.109.0/24
5.62.56.160/30
5.62.61.64/30
45.42.151.0/24
46.36.203.81
46.36.203.82/30
57.73.224.0/19
88.151.117.0/24
172.97.82.128/25
185.56.163.144/28

I would assume other countries would have considered this also.

Cheers,
Dale
DD-WRT Novice


Joined: 26 Oct 2017
Posts: 5

PostPosted: Thu Feb 01, 2018 17:52    Post subject: blocking countries code Reply with quote
using DD-WRT v3.0-r34320M kongac (01/03/1Cool
I found this script during a firewall search and just want to make sure it is still usable and if it is a drop in and work script? also that I havent missed a better script to use that is more current.
I am sure there are other users that would like a script like this to use

Dale
NorthantsPete
DD-WRT Novice


Joined: 05 Feb 2018
Posts: 21

PostPosted: Tue Sep 25, 2018 14:20    Post subject: Reply with quote
JAMESMTL wrote:
I run similar geo & TOR blocking scripts and you can significantly reduce processing time and router cpu utilization by simply using iptables restore for your block chain(s). In my case I whitelist countries and blacklist tor exit nodes and it literally takes only a few seconds to process and load some 25K IPv4 and IPv6 rules. Also running on an R7000.


Can you hel elaborate on this tor list blocking?

For a dummy?
blackraiin
DD-WRT Novice


Joined: 27 Dec 2017
Posts: 46

PostPosted: Wed Sep 26, 2018 4:14    Post subject: Reply with quote
I am highly interested in this and would love to know if this would still be needed if using a VPN ? I am very much interested in learning to expand my knowledge.

I am running a Netgear R6400v2 with kong firmware. I am a "total newb" and would like if i can get some step-by-step instructions to accomplish this and i have seen that a flash drive was used in some fashion. Any help would be greatly appreciated.
empyrials
DD-WRT Novice


Joined: 03 Jan 2019
Posts: 1

PostPosted: Thu Jan 03, 2019 14:00    Post subject: Reply with quote
Thanks for this script! I heavily modified it for my own uses but it was a great starting point!

I created a specific block inbound for tor exit nodes, but otherwise allowed only US IPs & an array for manually added IPs. outbound blocks are the same with the exception of another array for manually added IPs.

tor exit nodes are downloaded and updated like the aggregated lists are.

Thanks a bunch!
liverpoolatnight
DD-WRT User


Joined: 29 May 2008
Posts: 243
Location: United Kingdom

PostPosted: Thu Feb 28, 2019 0:09    Post subject: Reply with quote
I had an idea to block just one ASN (autonomous system number) lets say an "AS60339" with ports 1024 to 63365

Code:
wget http://www.XXXXXXXX.co.uk/cache/AS60339 -O /tmp/AS60339
MBB=$(/tmp/AS60339)
iptables -I FORWARD -p tcp -s 192.168.5.15 -d $MBB --dport 1024:63365 -j DROP


only issue i have now is the iptables wont read the $MBB data from the downloaded file via wget however it works fine if i manually do

Code:
iptables -I FORWARD -p tcp -s 192.168.5.15 -d 92.XX.X.X/15 --dport 1024:63365 -j DROP

_________________
TP-Link TL-WDR3600 v1 [EU]: r36330 (07/16/18 )
D-Link DIR-615 D2 [EU]: r36330 (07/16/18 )
Mikrotik RB750r2 (OpenWrt 17.01.4)
EE BrightBox 1 aka A4001N (OpenWrt 17.01.4)
Sagemcom FAST@5364 (VDSL2,FTTC (Fibre to the Cabinet) Synced 65/17

Twitter: @francisuk1989
---------------------------------
Found a bug? Report it http://svn.dd-wrt.com
DD-WRT Official FB Group: https://www.facebook.com/groups/493762527744455
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9, 10 Display posts from previous:    Page 10 of 10
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum