Solved

Blocking IPs in Windows 2003 using scripting

Posted on 2006-07-11
7
251 Views
Last Modified: 2013-12-04
My ftp server has been under a dictionary attack for the past few days. I need to know if windows is able to simply stop responding to packets recieved from a certain IP address. I have a firewall and I could always just add the IPs to that but I'd prefer to be able to do it in windows because then I can write a script to automatically "ban" IPs from my server. Anyone have any suggestions?
0
Comment
Question by:CyrexCore2k
7 Comments
 
LVL 1

Expert Comment

by:benab
ID: 17084569
Hi CyrexCore2k,
I don't know of a way to do it with the Windows 2003 FTP server.  You might consider finding another FTP server.

Here are two well known FTP servers.  I strongly suggest you use a secure FTP server if possible.

Cute FTP
http://www.cuteftp.com/gsftps/features.asp

Titan FTP
http://www.webdrive.com/products/titanftp/features.html


Good luck,
Ben
0
 
LVL 32

Expert Comment

by:r-k
ID: 17085548
In IIS Manager, right-click on your FTP site, select "Properties" then "Directory Security", and you can use the "Add" button to add offending IP's to the list there which are denied access.
0
 
LVL 37

Accepted Solution

by:
Bing CISM / CISSP earned 250 total points
ID: 17099291
> I can write a script to automatically "ban" IPs from my server.

just add ROUTE commands in your scripts. for more information, please see another post of mine which describes how to do it in detail.

http://www.experts-exchange.com/Networking/WinNT_Networking/Q_21913915.html

hope it helps,
bbao
0
New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

 
LVL 14

Author Comment

by:CyrexCore2k
ID: 17100258
Oh wow that's exactly what I needed. Just do you have any idea how to get scripts to run commands?
0
 
LVL 14

Author Comment

by:CyrexCore2k
ID: 17100269
And also I don't want to permanently deny these IPs access since I figure these probably aren't static IPs... what's the command to remove the route when I'm done with it?
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 17100441
i'd suggest you learning the full syntax of ROUTE command by simply giving a "ROUTE /?" (no quotation marks) at command prompt. anyway i give two simple demo bath files here just for your reference:

BLOCK.BAT
--------------------
goto %1
@ECHO Usage: BLOCK net_id
goto quit

:1
@ECHO to block 10.10.1.0 ~ 10.10.1.255 (192.168.0.253 is a non-existing IP)
ROUTE ADD 10.10.1.0 MASK 255.255.255.0 192.168.0.253
goto quit

:2
@ECHO to block 10.10.2.0 ~ 10.10.2.15 (192.168.0.253 is a non-existing IP)
ROUTE ADD 10.10.2.0 MASK 255.255.255.240 192.168.0.253
goto quit

:quit
--------------------

UNBLOCK.BAT
--------------------
goto %1
@ECHO Usage: UNBLOCK net_id
goto quit

:1
@ECHO to unblock 10.10.1.0 ~ 10.10.1.255
ROUTE DELETE 10.10.1.0 MASK 255.255.255.0
goto quit

:2
@ECHO to unblock 10.10.2.0 ~ 10.10.2.15
ROUTE DELETE 10.10.2.0 MASK 255.255.255.240
goto quit

:quit
--------------------
0
 
LVL 14

Author Comment

by:CyrexCore2k
ID: 17100657
I'm sorry I meant vbs windows scripts. =x I was wondering how you execute commands from those.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now