How to Stop Spam Condoning Countries With Regular Expression Filters in cPanel.OrHow To Leverage Foreign Email Servers To Encourage Their Government To Discourage THEIR Spam Condoning IPs.Since there is no necessity to continually update the email filters it might impart a sense of urgency on the abuse enabling country to clean up their internet providers.On going: Ticket ID: JKM-13297987 and Ticket ID: KAI-13229733 |
![]() Go to LIST. Go to current Reg. Exp. |
* [] hostgator.com [] (web host - opens in a new window.) which uses
* [] esmtp (Exim 4.69) [] email software and
* [] cPanel [] (web site control panel and email filtering software),
* The FL State Consumers Protection laws. (A recent spam seemed to have come from Miami, FL.) File a complaint to the FL. Attorney General . Of course any of the other US states Attorney Generals with jurisdiction could also be contacted.
* The Federal Trade Commission [] FTC [] ( The gov agency responsible for spam control in the USA .)
* The Federal Bureau of Investigation [] FBI [] ( The gov agency responsible for malicious DDoS (Distributed Denial of Service) crimes in the USA .)
Therefore, the goal is to identify the Top Level spamming IPs and its country of registration; and then, block all of their spam including their honest business enterprises; so that it might generate a small amount of commercial concern to create an incentive for the Top Level IPs to clean up their own hosted spammers.
|
Are
There Any Consequences To
Blocking The
Offending Domain & Country From My Email Server? The following quote is from the SPAM or UCE web page; specifically, the "complain to" paragraph with my comments & answers in Magenta. Positive Aspects
|
|
Verify
the Locations of the Foreign
IPs.
FireFox:
highlight
an IP below
without the brackets and
click this
FF=Geo IP link to open a map
showing
the IP: city and country
of
registration.
Internet Explorer: highlight an IP below without the brackets and click this link: IE=Geo-IP . |
| List of Good IPs | List of Bad or/and Foreign IPs |
| This is the list of IPs that are under USA regulation or are granted exception based on national language, authority or locality. | This list is a personal collection of IPs that have been collected from spam headers over an unknown period of time. Generally speaking the crossed out IP's are corrections. |
| (34ea
+/-) [9.0.0.0]KS USA [63.0.0.0] US [64.0.0.0] [65.0.0.0] [66.0.0.0] [67.0.0.0] [68.0.0.0] [69.0.0.0] [70.0.0.0] US [71.0.0.0] [72.0.0.0] [73.0.0.0] [74.0.0.0] [75.0.0.0] US [76.0.0.0] [97.0.0.0] US [99.0.0.0] US [100.0.0.0] US [104.0.0.0] US [107.0.0.0 ??? 01/03/17] US [108.0.0.0] US [110.0.0.0] AU [130.0.0.0] [160.0.0.0] NY [172.0.0.0] USA [173.0.0.0] Hi ? [174.0.0.0] CA [ [204.0.0.0] US [205.0.0.0] US [206.0.0.0] US [207.0.0.0] US [209.0.0.0] US [214.0.0.0] US [215.0.0.0] US [216.0.0.0] US Total 34 ea. The reason for listing the "Good" IPs here is that a future Reg. Ex. Filter might be designed to Allow only eMail from the "Good" IPs and Trashing all others. However the current purpose of this page is to eliminate the "Bad" IPs and to get Reg Ex Filters working in cPanel.. 3/8/12 Complete list of USA's IP's here. 6/14/11 Quick count of "Good"(34 ea.) vs "Bad" (96 ea.) suggests changing to an Allow filter instead of the Rejection filter. 1/24/11 Pending: move of "[98.0.0.0] US" to "Bad" side b/c of email hijacking and spam from 98.139.91.82 = Yahoo. 8/4/16 Two encrypted email services Mailpile.is IP: 139.162.218.203 London Protonmail.com IP: 185.70.40.182 Switzerland @Reagan.com secure email address $33/yr. |
(96
ea +/-) [1.0.0.0] vn [2.0.0.0] [5.0.0.0 This is a USA based ISP but it's all foreign domains.] [14.0.0.0] [20.0.0.0] [31.0.0.0] _31.0.0.0 [37.0.0.0] [39.0.0.0] [41.0.0.0] [42.0.0.0] [43.0.0.0] [46.0.0.0] [47.0.0.0] [48.0.0.0] [49.0.0.0] [58.0.0.0] [59.0.0.0] [60.0.0.0]Korea [61.0.0.0]DE [62.0.0.0] FOREIGN [77.0.0.0] RU, LT, DE [78.0.0.0] [79.0.0.0] [80.0.0.0] [81.0.0.0] [82.0.0.0] [83.0.0.0] [84.0.0.0] [85.0.0.0] [86.0.0.0]UK [87.0.0.0] [88.0.0.0] [89.0.0.0] 89.0.0.0 Israel? [90.0.0.0] [91.0.0.0] [92.0.0.0] [93.0.0.0] [94.0.0.0] [95.0.0.0] [110.0.0.0] [111.0.0.0] [112.0.0.0] [113.0.0.0] [114.0.0.0] [115.0.0.0] [116.0.0.0] [117.0.0.0] [118.0.0.0] [119.0.0.0] [120.0.0.0] [121.0.0.0] [122.0.0.0] [123.0.0.0] [124.0.0.0] [125.0.0.0] [128.0.0.0] [133.0.0.0] [ 139.0.0.0] [140.0.0.0] [141.0.0.0] [150.0.0.0] [151.0.0.0] [153.0.0.0] [159.0.0.0] [165.0.0.0] [167.0.0.0] [168.0.0.0] [171.0.0.0] [175.0.0.0] [176.0.0.0] [177.0.0.0] [178.0.0.0] [180.0.0.0] [181.0.0.0] [182.0.0.0] [183.0.0.0] [ [190.0.0.0] [193.0.0.0] [194.0.0.0] [195.0.0.0] [196.0.0.0] [197.0.0.0] [ [200.0.0.0] [201.0.0.0.] [202.0.0.0] [210.0.0.0] [211.0.0.0] [212.0.0.0] [213.0.0.0] [217.0.0.0]DE [218.0.0.0] [219.0.0.0] [220.0.0.0]JP [221.0.0.0]China FOREIGN [222.0.0.0] [223.0.0.0] [224.0.0.0] [225.0.0.0] [226.0.0.0] [227.0.0.0] [228.0.0.0] [229.0.0.0] [240.0.0.0 - 249.] [250.0.0.0 - 259.] Total "Bad" TLD IPs = 118 ea. approximately 6/2012+/- cPanel has updated it's Reg. Expressions to normal "single backslash excapes" instead of 4. 6.17.13 Added [27 (cn), [181 (ar), [159 Saudi Arabia, [177 Brazil, 7.13.13 Removed 7.21.16 Added [203.192.0.0 (cn), Start another filter for 2nd level foreign DNS' 8.06.16 Added [140.0.0.0] IN+CN See Also: Top Spam Senders - McAfee Labs Threat Center Listed by: IP, Hostname, Location, Average Email Volume, Email Reputation Acc Level filters added 3/31/16. 1.) www\.google\.com\/url\?|\&yahoo\.com [New] 2.) \[1\.|\[2\.|\[5\.|\[14\.|\[2[4,7]\.|\[3 ... [Existing] |
| cPanel "IP Deny Manager" NEW:
Mischievous Bots'
IPs Blocked from web
traffic. 12/7/12 Added: 37.* (.ru), 180.* +5 othes settings are in cPanel "IP Deny Manager" but switched to editing htaccess "deny IP method" instead. 4/14/14 Added: 113.212.64.0 - 113.212.95.255 country: INDIA Xeex Communication ; [94. = Fr. |
|
Class
Address Ranges
Class A - 1.0.0.0 to 126.0.0.0 three classes of addresses used on IP networks in common practice. Class D addresses are reserved for multi cast. Class E addresses are simply reserved, meaning they should not be used on IP networks (used on a limited basis by some research organizations for experimental purposes). |
Special IP Address Summary TableAddress Block Present Use 0.0.0.0/8
”This” Network |
06.14.10 Added 3 more IPs to "Bad IP" filter.
01.14.11 added: to cover IP Classes D and E |\\\\[23[0-9]|\\\\[24[0-9]|\\\\[25[0-5] to above line.
02.05.11 Added [165.98.179.58] NI, 1.55.41.26 vn , 46.146.84.14 ru
07.02.11 Added [175 , [133 ,.
06.29.12 Added [14.(IN), [20, [31.(NL), [37, [39.(ID), [41, [42.(AU), [48, [49.(AU IN), [81.(Sp), [128, [153.(CN), [199, [176.(DE) to filter line below.
06.17.13 Added [27.(CN), [181 (ar) , [159 Saudi Arabia, [177 Brazil, REMOVED: \(unknown \[|unknown
07.13.13 Removed 198. i.e."\[19[0,3-7,9]" b/c it's a Hostgator machine!
04.09.14 Added [98.158.224.0 - 98.158.225.255] = Acceleratebiz Inc. Fort Lauderdale = \[98.158.22[4|5]
Note: Image # 2. below Proves the following Regular Expression Filter WORKS on "GOOD" IPs as tested on the regextester.com web site on 4.21.10.7/21/16 NEW 2nd level Foreign filters: [203.192.0.0 = \[203\.192\.| Samples for 2 non excepted "." i.e. "\." and the "OR" symbol "|" = \[203\.192.|\[203.015\.
HOW to filter: http://www.cs.tut.fi/~jkorpela/perl/regexp.html ; PCRE - Perl Compatible Regular Expressions
TEST your filters: regextester.com
Here are the results of a Regular Expression Filter rule that selects only the BAD IPs. [Image # 1. Bad IPs]
1.) The red text indicates that the Reg Ex Filter made a match on all of the IPs listed in the "Test on Text" box. Notice that the Text box input data included both the "Good" and "Bad" IPs but there were no matches on the "Good" IPs since the filter was designed to match only the "Bad" IPs.
2.) In the image note the "Dialect" line where Preg is checked. This means that it is a "Perl regular Expression" compatible tester which is what the cPanel Reg Ex Filter application requires.
Here are the results of a Regular Expression Filter rule that selects only the GOOD IPs.
The red text indicates that the Reg Ex Filter made a match on all of the IPs listed in the "Test on Text" box. Notice that the Text box data included the "Bad" IPs but there were no matches since the filter was designed to match "Good" IPs only. (The reason for listing the "Good" IPs here is that it might be advantageous to design a reverse Reg. Ex. Filter to Allow only eMail from the "Good" IPs and thereby Trashing all others.)

| PAGE
PATH: http://neprimer.com /ePress /articles /2010 /IP-FiltersRegEx.html |