SomeWhereOverTheRainBow
Part of the Furniture
So, I was playing with skynet stats today because I thought something was odd about the stats.
I found it odd that in the Top 10 Blocks From (Outbound) it would list the reason "Imported: Apples" as the ban reason when the only lists I have imported using the comment "Apples" was whitelisted items.
I am just using the comment "Apples" as it fits the example. The issue is, I do not have any manually imported blacklists that use the comment "Apples", so how could the ban reason be "Imported: Apples" when I am only using that comment for whitelist import lists?
Anybody wanting to see if they can "reproduce" this issue, I posted more information about it here.
@Adamm
Code:
Top 10 Blocks From (Outbound);
-------- | -------------- | -------------- | -------------- | ----------------------
| Hits | | | IP Address | | | AlienVault | | | Ban Reason | | | Associated Domains |
-------- | -------------- | -------------- | -------------- | ----------------------
747x | 192.28.144.124 (AD) | https://otx.alienvault.com/indicator/ip/192.28.144.124 | BanMalware: ipv4.feed* |
552x | 192.28.147.68 () | https://otx.alienvault.com/indicator/ip/192.28.147.68 | * |
440x | 199.15.214.243 (US) | https://otx.alienvault.com/indicator/ip/199.15.214.243 | * |
422x | 203.191.149.239 (CN) | https://otx.alienvault.com/indicator/ip/203.191.149.239 | Imported: Apples |
385x | 206.81.13.146 (US) | https://otx.alienvault.com/indicator/ip/206.81.13.146 | Imported: Apples |
369x | 103.143.248.129 (AU) | https://otx.alienvault.com/indicator/ip/103.143.248.129 | BanMalware: ipv4.feed* |
349x | 66.115.184.26 (US) | https://otx.alienvault.com/indicator/ip/66.115.184.26 | Imported: Apples |
317x | 66.115.184.27 (US) | https://otx.alienvault.com/indicator/ip/66.115.184.27 | Imported: Apples |
272x | 116.196.106.34 (CN) | https://otx.alienvault.com/indicator/ip/116.196.106.34 | Imported: Apples |
262x | 198.27.88.77 (US) | https://otx.alienvault.com/indicator/ip/198.27.88.77 | Imported: Apples |
I found it odd that in the Top 10 Blocks From (Outbound) it would list the reason "Imported: Apples" as the ban reason when the only lists I have imported using the comment "Apples" was whitelisted items.
firewall import whitelist file.txt "Apples"
I am just using the comment "Apples" as it fits the example. The issue is, I do not have any manually imported blacklists that use the comment "Apples", so how could the ban reason be "Imported: Apples" when I am only using that comment for whitelist import lists?
Anybody wanting to see if they can "reproduce" this issue, I posted more information about it here.
Skynet Stats not properly displaying Ban Reason. · Issue #129 · Adamm00/IPSet_ASUS
Brief Description Of Issue So, I was playing with skynet stats today because I thought something was odd about the stats. I found it odd that in the Top 10 Blocks From (Outbound) it would list the ...
github.com
@Adamm
Last edited: