I did try badcountry.txt but I see little result or is BLOCKED the normal result? In my badcountry.txt I have:
B 156 China
B 158 Taiwan, Province of China
And yet I get results like:
Oct 10 14:39:53 0 Connection from Taiwan, Province of China
Oct 10 14:39:53 0 BLOCKED 114.35.121.159 (114-35-121-159.HINET-IP.hinet.net) repeated down a few pages.
So is that what we should expect? I know badip.txt is also working as:
Oct 10 14:27:19 0 Connection from India
Oct 10 14:27:19 0 MULTI 117.248.87.221 (Unknown)
Oct 10 14:27:20 0 Connection from India
Oct 10 14:27:20 0 Auto banning IP 117.248.87.221
Oct 10 14:27:20 0 BLOCKED 117.248.87.221 (Unknown)
repeated down the page
Does make me wonder how much of the world we need "BLOCKED". Maybe when
g00r00 gets back 'Unknown' could be blocked in the same way as China?
I also saw:
Oct 10 14:21:36 0 Connect: 41.212.200.109 (ADSL-200-109.myt.mu)
Oct 10 14:21:37 0 MULTI 41.212.200.109 (ADSL-200-109.myt.mu)
Oct 10 14:21:40 0 BLOCKED 41.212.200.109 (ADSL-200-109.myt.mu)
I believe that country (AKA Mauritius Telecom) was cut off for non-payment
and they gave up the court case in 2015 but haven't been reinstated that I
know of. So is it just an IP spoofing of some kind? When I check the IP it's from AfriNIC -
http://www.afrinic.net The African & Indian Ocean Internet Registry Ref:
https://whois.arin.net/rest/org/AFRINIC which is out of Africa near the southern tip. Looks like a small group: 41.212.200.* should do it. Time to add that little group and clean up my badip.txt
--- Mystic BBS v1.12 A31 (Raspberry Pi)
* Origin: Mystic Pi BBS bcw142.zapto.org (21:1/145)