﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Ipswitch Forums / Ipswitch Products / WS_FTP Server  / IP based automatic ban / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Ipswitch Forums</description><link>http://forums.ipswitch.com/</link><webMaster>forums@ipswitch.com</webMaster><lastBuildDate>Tue, 14 Oct 2008 01:56:00 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>Hello All,&lt;/P&gt;&lt;P&gt;regarding this request (ability to easily and manually add banned IP addresses), you can do this via the Access Control list in Server 6.1.  The automatic blocking is scheduled for the next major release.  &lt;/P&gt;&lt;P&gt;Are there any more details on "easily input" that you can share (e.g. such as importing from a csv, being able to enter a starting and ending range or wildcards, etc.)?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;harmia (4/16/2008)&lt;/STRONG&gt;  - Same boat here, I wish there was to easily input banned IP address using know IP blocks from specific countries.&lt;/P&gt;&lt;P&gt;bye for now,</description><pubDate>Mon, 05 May 2008 18:45:53 GMT</pubDate><dc:creator>kevin r gillis</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>[quote][b]kevin r gillis (4/16/2008)[/b][hr]hello all,&lt;P&gt;excellent feature request.  &lt;/P&gt;&lt;P&gt;the ability to auto block IP addresses is tentatively set for the next major server released.  this work is already completed and feature complete.   the system admin can now populate a white or black list and auto populate the blacklist based on x consecutive failed logins after x mins or hours from the same IP address.  the offending IP Address will be automatically added to the blacklist for a settable period of time (hours, days, months, forever).  we'll be releasing this to the TPP in the coming 1-2 months.  I'll add the request to be able to manually add offending IP addresses (versus automatic population of offending IP addresses).&lt;/P&gt;&lt;P&gt;hope this helps.&lt;/P&gt;&lt;P&gt;bye for now,[/quote]&lt;P&gt; &lt;P&gt;Kevin, we've been waiting years for this!  I hope this will also qualify as an event so an email can be sent with this event and that the ip address and the hostname are also variables that can be included in the emails!  Remember this?&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;there may a few possibilities here for new features.  &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;1. in the error message, include the user id or ip address or both.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Courier New" size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;Failed Login - Fri Feb 03 14:16:17 2006&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Courier New" size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"&gt;  *** There has been an excessive number of failed login attempts for the userid &lt;A title=blocked::mailto:kevin@abc.com href="mailto:kevin@abc.com"&gt;kevin@abc.com&lt;/A&gt; at ip address 123.123.123.12 - on host abc.com&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;2. In FTP Server 5, there currently is a rule for Failed Logins which can then kick-off an email/sms/pager/external applicatoin to notify you of a user reaching the failed login limit.  i will check into whether we can include the IP address in the notification that is fired off.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;3. after x failed logins from same ip address, then automatically put the ip addy on the blocked list until the admin pulls it off or for a settable # of days (e.g. 30 days).&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;Comments on the above?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;bye for now,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=blue size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: Arial"&gt;kg&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;</description><pubDate>Fri, 25 Apr 2008 12:56:38 GMT</pubDate><dc:creator>johnniewalker</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>The automatic blacklist for failed logons feature would be a huge bonus. I also would like to block IP ranges, if possible.</description><pubDate>Thu, 24 Apr 2008 10:43:13 GMT</pubDate><dc:creator>BML</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>[quote][b]kevin r gillis (4/16/2008)[/b][hr]hello all,&lt;P&gt;excellent feature request.  &lt;/P&gt;&lt;P&gt;the ability to auto block IP addresses is tentatively set for the next major server released.  this work is already completed and feature complete.   the system admin can now populate a white or black list and auto populate the blacklist based on x consecutive failed logins after x mins or hours from the same IP address.  the offending IP Address will be automatically added to the blacklist for a settable period of time (hours, days, months, forever).  we'll be releasing this to the TPP in the coming 1-2 months.  I'll add the request to be able to manually add offending IP addresses (versus automatic population of offending IP addresses).&lt;/P&gt;&lt;P&gt;hope this helps.&lt;/P&gt;&lt;P&gt;bye for now,[/quote]&lt;P&gt;Thanks for the update Kevin.&lt;P&gt;[quote][b]harmia (4/16/2008)[/b][hr]Same boat here, I wish there was to easily input banned IP address using know IP blocks from specific countries.[/quote]&lt;P&gt;Please add this to next release as well, thanks!</description><pubDate>Thu, 17 Apr 2008 09:42:24 GMT</pubDate><dc:creator>I3rand0</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>hello all,&lt;/P&gt;&lt;P&gt;excellent feature request.  &lt;/P&gt;&lt;P&gt;the ability to auto block IP addresses is tentatively set for the next major server released.  this work is already completed and feature complete.   the system admin can now populate a white or black list and auto populate the blacklist based on x consecutive failed logins after x mins or hours from the same IP address.  the offending IP Address will be automatically added to the blacklist for a settable period of time (hours, days, months, forever).  we'll be releasing this to the TPP in the coming 1-2 months.  I'll add the request to be able to manually add offending IP addresses (versus automatic population of offending IP addresses).&lt;/P&gt;&lt;P&gt;hope this helps.&lt;/P&gt;&lt;P&gt;bye for now,</description><pubDate>Wed, 16 Apr 2008 16:26:14 GMT</pubDate><dc:creator>kevin r gillis</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>Same boat here, I wish there was to easily input banned IP address using know IP blocks from specific countries.</description><pubDate>Wed, 16 Apr 2008 14:29:13 GMT</pubDate><dc:creator>harmia</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>Add me to the list of customers that would love to see this feature added.</description><pubDate>Mon, 14 Apr 2008 12:54:33 GMT</pubDate><dc:creator>DaveS</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>Has there been any update to this?  I'm having the exact same issue with dictionary hacking.  Automatic ban is a feature that absoletely needs to be in the next release.</description><pubDate>Fri, 11 Apr 2008 15:26:00 GMT</pubDate><dc:creator>I3rand0</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>Just wanted to chime in that I am having the exact same problem.  The same ip address just bombarding my WS_FTP Server with random usernames and passwords.  Unfortunately I can lock real accounts that have been tried "X" number of times, but, because they are just using randomly generated usernames and passwords there is no way to block but to manually put each IP address into the blacklist as I notice the attacks.&lt;/P&gt;&lt;P&gt;It seems like it should be possible to automatically ban a specific IP address if it has attempted to log in using hundreds of different usernames, but I cannot seem to locate a way to do this, is it at all possible?</description><pubDate>Wed, 09 Apr 2008 12:25:42 GMT</pubDate><dc:creator>Camman</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>I am in the same boat. I figured that as soon as we opened up SSH to the outside, that we would immediately be attacked - I was correct. I have a dozen or so denied IP addresses so far of people who have launched fairly intense dictionary style attacks. Unfortunately this creates a bit of a DOS for any legitimate FTP users as it busies out the FTP server.&lt;/P&gt;&lt;P&gt;Other FTP servers have a "shun" feature which automatically prevents this type of attack. Any suggestions on how to prevent this would be good- or at least give us some encouragement that IPSWITCH is aware of the issue and is working on a fix.&lt;/P&gt;&lt;P&gt;Thanks!</description><pubDate>Wed, 09 Apr 2008 11:41:21 GMT</pubDate><dc:creator>Rand-O</dc:creator></item><item><title>RE: IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>We are experiencing the same issue, any suggestions would be great received.</description><pubDate>Fri, 04 Apr 2008 13:51:14 GMT</pubDate><dc:creator>JodyG</dc:creator></item><item><title>IP based automatic ban</title><link>http://forums.ipswitch.com/Topic42143-8-1.aspx</link><description>We are running WS FTP Server with SSH. Problem is that someone is running somekind of dictionary based hacking system against server. I would like to know if server can be configured to automatically ban IP for selected time if failed login count from it is exceeded? I know that some other FTP servers can do this, but I am not sure about WS FTP Server with SSH.</description><pubDate>Tue, 25 Mar 2008 06:51:47 GMT</pubDate><dc:creator>Garjala</dc:creator></item></channel></rss>