PDA

View Full Version : General MoBlock thread



jre
May 22nd, 2008, 08:40 AM
Hi all,

this is the new general Moblock and PeerGuardian Linux (pgl) thread. pgl is replacing MoBlock/blockcontrol/mobloquer:
pgld replaced moblock
pglcmd replaced blockcontrol (previously moblock-control)
pglgui replaced mobloquer

PeerGuardian (http://peerguardian.sourceforge.net) is a privacy oriented firewall application. It blocks connections to and from hosts specified in huge blocklists (thousands or millions of IP ranges). Its origins lie in targeting aggressive IPs while you use P2P.
Hint for all the people doing support here: This is often the reason for "network problems" - I do my best to make users aware of this fact.

pglcmd provides easy ways to interact with pgld and does all common related tasks.

pgl-gui is a GUI on top of pglcmd.

You can get Debian packages from http://moblock-deb.sourceforge.net. For Ubuntu use my PPA http://launchpad.net/~jre-phoenix/+archive/ppa, for experimental packages use https://launchpad.net/~jre-phoenix/+archive/pgl-experimental additionally. I'm the maintainer of these sites.

There's an HOWTO on https://help.ubuntu.com/community/MoBlock

I do my support in this and all other ubuntuforums.org threads that contain the keyword "pgl". You will also find me at the PeerGuardian project's homepage (http://peerguardian.sourceforge.net) at sourceforge.net.

jre

News

2012-06-25: Please welcome "PeerGuardian Linux 2.2.1"!
This version adds the last feature only present in mobloquer, but not in
pglgui: "whois information about blocked IPs".

Since I also fixed or workarounded all issues with older Debian and
Ubuntu versions I added transitional packages for the old
moblock/blockcontrol/mobloquer packages. This means the Debian/Ubuntu
world now moves to pgl automatically. (Except the 2008 Ubuntu Long Term
Release Hardy which I think is ok to be left behind forever ;P )

Goodbye phoenixlabs
phoenixlabs.org is no more active. All support and development is now done at http://peerguardian.sourceforge.net, or here ;)


2011-08-12: PeerGuardian Linux 2.1.0 - The GUI release![/B]
Today we proudly present to you: pgl 2.1.0, including the long-anticipated pgl-gui. Try it, test it, report back. If you don't tell us otherwise the days of moblock, blockcontrol and mobloquer will soon be over.

2010-05-18: PeerGuardian Linux 2.0.0 released!
PeerGuardian Linux is based on nfblock/moblock and blockcontrol. Users of these applications will find many improvements and bug fixes. Unfortunately we have no GUI ready, yet. Developers are very welcome. Just look at the code, make your changes and contact me.
moblock/blockcontrol/mobloquer packages are still available for those who need a GUI. Remember that these applications aren't developed any more and their packages will only get really important updates. NFBlock was removed from the repository.

2009-11-12: New project PeerGuardian Linux
There's a new project: PeerGuardian Linux (pgl), located at the project of the original PeerGuardian (http://sourceforge.net/projects/peerguardian/). The new project combines and succeeds all projects that had packages here. There's the daemon pgld (based on NFBlock, which was based on MoBlock), pglcmd (based on blockcontrol, previously moblock-control) and pgl-gui (by the author of mobloquer).
All authors of the old applications and new authors work on this new project. So the old projects are dead now. Contributors and testers are welcome! This is an open project. Check the source in the git repository: git://peerguardian.git.sourceforge.net/gitroot/peerguardian/peerguardian
(At least for the beginning) I'll continue to offer Debian packages here (until the first pgl release the old moblock, blockcontrol, nfblock and mobloquer packages), and than later pgl packages. Stay tuned.

2009-08-21: new gpg key for moblock-deb
Iīve got a new key (58712F29) for the repository at moblock-deb.sf.net. My old key expired. So if you are using the moblock-deb repository you have to add my new key to the system:

gpg --keyserver wwwkeys.eu.pgp.net --recv 58712F29
gpg --export --armor 58712F29 | sudo apt-key add -
If you are using the launchpad PPA (as most people will do) you do not have to do anything.

2009-04-23: added jaunty, removed gutsy support
jaunty is now supported via a ppa at launchpad. See the wiki or moblock-deb.sourceforge.net for the sources.list entry and the new gpg key.


2009-03-22: moblock-control renamed to blockcontrol

Full support for Moblock and NFBlock.
New option "search": Examine your selected blocklists by searching the single blocklists for keywords.
All user configuration is now done in /etc/blockcontrol/blockcontrol.conf. Not any more in /etc/default/...



2009-01-11: Current development status
MoBlock: The last official release was in 2006, and a new one is still planned. The MoBlock upstream author is still active. The version in the packages is 0.9RC2 from February 2008 and since then I've applied some useful patches that I got.

moblock-control: I'm still active. Of course help, patches, reports and suggestions are always welcome.

mobloquer (GUI): The author is currently inactive, due to real life time restrictions. Unfortunately, he has not found a new developer yet. The last stable release 0.5 is packaged at moblock-deb.sourceforge.net, but I will soon update it to the SVN version and add some own patches.

Alternatives:
NFBlockD (daemon): actively developed. Works together with moblock-control. I intend to package this app, too.

IPList (daemon and GUI): actively developed, repository is available.

2009-01-09: moblock-control 1.2 released


New handling of blocklists:

php redirects are supported now. This allows to use the lists from iblocklist.com. All lists are downloaded from there per default now.
Since moblock-control 1.1 the default blocklists are by "The Blocklist Group" (tbg.iblocklist.com) instead of Bluetack (bluetack.co.uk).
The single blocklists are saved in new places now (but still under /var/spool/moblock/.
The master blocklist (e.g. guarding.p2p) is now saved in /var/lib/moblock/ instead of /etc/moblock/.
Several changes to make sure that the master blocklist exists and reflects the configuration. All changes are always applied on "start" now.
The (Debian) installation only requires the blocklists (and therefore network access) to be available, if the automatic start (init) is configured.

Per default allow.p2p is not used for forwarded traffic.
Dropped support for Ubuntu Feisty, as this is no more supported by Ubuntu since October 19th, 2008.


2008-09-27:
Currently there are some issues with the blocklist updates. Thanks lovinglinux, for noticing us! (http://ubuntuforums.org/showpost.php?p=5863138&postcount=87)
Per default you all use the blocklists by bluetack. Now, according to this thread (http://forums.phoenixlabs.org/showthread.php?t=17291) most of the people who were in charge of with these blocklists quit bluetack and started their own project: TBG (The Blocklist Group) (http://blocklist1.snowmanuk.net/). So (according to the mentioned thread) the old blocklists from bluetack lack the old level of maintenance.
Further, perhaps fully unrelated to all this, the download of the bluetack lists currently frequently fails.

For people not having problems: Do nothing, be happy, don't make unnecessary blocklist downloads.

For all people having update problems: MoBlock will refuse to start if not all configured blocklists are available. So your problem is the download of the blocklists, but not a problem of your installation. So do NOT purge moblock-control - this will remove all downloaded blocklists, even those that were already downloaded successfully - so purging will make your problems bigger.

What you can do now:
Check what blocklists fail to download in /var/log/moblock-control.

If you want to use that blocklists try a "moblock-control update" or download it manually. Then place the blocklist in /var/spool/moblock/used. (e.g. "sudo cp level1.gz /var/spool/moblock/used")

If you don't want to use that blocklist just run "sudo dpkg-reconfigure moblock-control" and deselect the blocklist in question. For the other questions that you will be asked - just keep everything as it is. Then do a "moblock-control update".

If you want to use blocklists by TBG just add them to /etc/moblock/blocklists.list and do a "moblock-control update".

What I will do: I'll prepare a update which uses the new lists by TBG per default (this will only work on new installs). On updates from the current installations I'll notice the user of the current situation.

2008-09-26:

"moblock-control" is a separate package now. So install "moblock" and "moblock-control" to have the functionality of the old "moblock" package. This will happen automatically on a normal update with your package manager.
The custom iptables scripts /etc/moblock/iptables-custom-insert.sh and /etc/moblock/iptables-custom-remove.sh now are executed for IPTABLES_SETTINGS="1", too. This happens after moblock-control's iptables commands. Use these scripts e.g. for additional sophisticated whitelisting rules. Some examples are given in these files.
Thanks, anonymous, for the hints about iptables owner module and IPv6.


2008-05-22:
I created this thread so that pelle.[Chuc]k[Norris] (http://ubuntuforums.org/member.php?u=50108) can close his thread (http://ubuntuforums.org/showpost.php?p=4686096&postcount=1154). pelle started (http://ubuntuforums.org/showthread.php?t=192559) the very successful HOWTO here at ubuntuforums but doesn't find enough time to maintain it any more ... Thanks!


How to make sure that MoBlock is integrated correctly with any other firewall

Check your iptables rules with blockcontrol status:

Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 147K packets, 185M bytes)
pkts bytes target prot opt in out source destination
93 9633 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
[iptables rules of firewall applications may follow here]

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
[iptables rules of firewall applications may follow here]

Chain OUTPUT (policy ACCEPT 110K packets, 17M bytes)
pkts bytes target prot opt in out source destination
975 61829 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
[iptables rules of firewall applications may follow here]

Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
[iptables rules for whitelisting forwarded packets are placed here]
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 192.168.178.0/24 192.168.178.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
[iptables rules for whitelisting incoming packets are placed here]

0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
85 8617 RETURN all -- * * 192.168.178.0/24 0.0.0.0/0
6 360 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
2 656 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
[iptables rules for whitelisting outgoing packets are placed here]
63 2576 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
309 24277 RETURN all -- * * 0.0.0.0/0 192.168.178.0/24
6 360 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
352 21120 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
177 10620 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
64 2636 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92


[Other chains are ok]

Make sure that there are not any iptables rules in the chains INPUT/OUTPUT/FORWARD before the MoBlock rules (there are exceptions possible but I won't discuss them here). If this is not the case then do a blockcontrol restart.

Traffic that reaches the target NFQUEUE will be checked by MoBlock. MoBlock then MARKs them: Allowed packets (IP is not in the blocklist) get the mark "20" (shown as 0x14 by iptables) and blocked packets (IP is in the blocklist) get the mark "10" (0xa).

Marked packets repeat the hook function (NF_REPEAT). So they are sent back to
the head of the iptables chain again and go through the rules again, but this time bearing the mark.

The targets REJECT and DROP in the moblock_* chains decide what happens to "marked match" packets. So if MoBlock blocks a packet it will be REJECTed if it was outgoing traffic, and DROPped if it was input traffic.

The lines with target RETURN in the moblock_* chains are optional. They cause that some traffic is not checked by MoBlock (aka allow and whitelisting traffic).
In the example my LAN (192.168.178.0/24) and the loopback interface were whitelisted automatically. Further I allow outgoing traffic on port 80 (http) and 443 (https).

If you are missing a rule, do a blockcontrol restart.
Of course the numbers of packets and bytes do vary.

Edits:
2011-08-14: renamed to "General MoBlock and PeerGuardian Linux thread" etc.
2008-05-22: added information about integration with other firewall applications
2008-09-26: Updated.

meden
May 23rd, 2008, 05:08 PM
Hi,
the first question can only be: which is the (current) correct and most effective way to make Moblock interoperate with Firehol?

There are several guides (including the old thread), but there is no clear indication if they are updated to last version of Moblock.
In detail, it would be interesting (to me, at least...) a (definitive) guide to both possible approaches, with IPTABLES_SETTINGS="1" and IPTABLES_SETTINGS="0".

Thank you.

jre
May 24th, 2008, 08:24 AM
Hi,
the first question can only be: which is the (current) correct and most effective way to make Moblock interoperate with Firehol?

There are several guides (including the old thread), but there is no clear indication if they are updated to last version of Moblock.
In detail, it would be interesting (to me, at least...) a (definitive) guide to both possible approaches, with IPTABLES_SETTINGS="1" and IPTABLES_SETTINGS="0".

Thank you.

Just make sure that firestarter is started before MoBlock. Then go with the Moblock 0.9 default settings (i.e. FONT="Courier New"]IPTABLES_SETTINGS="1"[/FONT] and MARKing on). Every firestarter change then requires a moblock-control restart.
I have just added informations to post #1 how you can verify correct settings.

If the above doesn't work for you you can go with the other old instructions.

Finally you may try this (not tested, please give feedback if you do this):
Keep the MoBlock configuration as it is. In the firehol.conf add as last line moblock-control restart.
IIRC firehol works that way that commands in its conf are simply executed, so this way you can make sure that MoBlock is restarted after every firehol change (firehol purges all other iptables rules).

Nepherte
May 24th, 2008, 05:22 PM
Moblock doesn't want to run anymore on startup. I have to start it by entering the command (sudo moblock-control start) after my system has start up even though the configuration file is ok:

...
# Turn on/off automatic start
# 0 - Donīt start MoBlock at system boot
# 1 - Start MoBlock at system boot
MOBLOCK_INIT="1"
...
I do remember it worked for some time. Any ideas on how to solve it?

jre
May 24th, 2008, 08:02 PM
Moblock doesn't want to run anymore on startup. I have to start it by entering the command (sudo moblock-control start) after my system has start up even though the configuration file is ok:

...
# Turn on/off automatic start
# 0 - Donīt start MoBlock at system boot
# 1 - Start MoBlock at system bootl.log
MOBLOCK_INIT="1"
...
Make sure /etc/default/moblock is not configured otherwise (e.g. mobloquer does save its configuration there).

If this doesn't help: What's the output on system boot? What's in /var/log/moblock-control.log?

chronniff
May 25th, 2008, 07:07 AM
so moblock is now working with with firestarter? Sorry to make you repeat yourself...I haven't payed any of this any thought in a while, but I used the old thread a long time ago now and from what I had gathered, before I gave up and made do, was that no one got them working together, so I'm just making sure that I am understanding you correctly that as long as I restart moblock every time I change something in firestarter that they will play nicely? If so..god bless you, that's one less headache I need to deal with!!

jre
May 25th, 2008, 09:50 AM
so moblock is now working with with firestarter? [...] as long as I restart moblock every time I change something in firestarter that they will play nicely?
Yes. further conditions of course: moblock version 0.9~rc2 with marking on. These conditions are fulfilled when you install the current moblock (not moblock-nfq or moblock-ipq) package from moblock-deb.sf.net

Nepherte
May 25th, 2008, 10:17 AM
Make sure /etc/default/moblock is not configured otherwise (e.g. mobloquer does save its configuration there).
/etc/default/moblock is all empty except for some comment blocks.

This is the output of /var/log/moblock-control.log for the last two days:

2008-05-24 13:07:04 CEST Begin: /usr/bin/moblock-control start
Inserting iptables ...done.
Starting MoBlock ...done.
2008-05-24 13:07:04 CEST End: /usr/bin/moblock-control start
2008-05-24 15:32:22 CEST Begin: /usr/bin/moblock-control start
Inserting iptables ...done.
Starting MoBlock ...done.
2008-05-24 15:32:22 CEST End: /usr/bin/moblock-control start
2008-05-25 11:07:09 CEST Begin: moblock-control start
Inserting iptables^M^[[74G[ OK ]
Starting MoBlock^M^[[74G[ OK ]
2008-05-25 11:07:09 CEST End: moblock-control start
2008-05-25 11:08:01 CEST Begin: moblock-control stop
Deleting iptables * .
Stopping MoBlock^M^[[74G[ OK ]
2008-05-25 11:08:01 CEST End: moblock-control stop

chris.tkd
May 25th, 2008, 10:52 AM
After the latest moblock update it seems to blocking out everything, including Http connections even tho i have marked them as exceptions in Mobloquer, it also blocks out bluetack, also i removed the microsoft entry from the blocklists any idea how i can get this back.

Thanks.

jre
May 25th, 2008, 01:22 PM
@Nepherte: Hmm, seems to be alright.

Please post

ls -l `sudo find /etc/ -name "*moblock*"`
I want to make sure if your init entries are still there and set up correctly.

Does sudo /etc/init.d/moblock start work? (That's the command which starts MoBlock at system boot.)

What's the state after you booted? Please post your moblock-control status directly after system boot.

Are the start entries in the moblock-control.log from your manual starts or from the automatic at system boot?

One last idea: Is LSB="0" set in the moblock.conf?




After the latest moblock update it seems to blocking out everything, including Http connections even tho i have marked them as exceptions in Mobloquer, it also blocks out bluetack, also i removed the microsoft entry from the blocklists any idea how i can get this back.
Please post moblock-control status and your /etc/default/moblock.


D'oh, always these strange things :-/
jre

chris.tkd
May 25th, 2008, 01:36 PM
Hi, Thanks for the reply

moblock-control status is

Current iptables rules (this may take awhile):
Chain INPUT (policy ACCEPT 516K packets, 131M bytes)
pkts bytes target prot opt in out source destination
23 2954 moblock_in 0 -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP 0 -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 moblock_fw 0 -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
Chain OUTPUT (policy ACCEPT 597K packets, 648M bytes)
pkts bytes target prot opt in out source destination
0 0 REJECT 0 -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 moblock_out 0 -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE 0 -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
23 2954 NFQUEUE 0 -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN 0 -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.28.93
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.46
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.24
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.95
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.50
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.37
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.17
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.17
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.30
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.39
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.36
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.20
0 0 RETURN 0 -- * * 0.0.0.0/0 65.54.179.216
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.23
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.16
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.106.23
0 0 RETURN 0 -- * * 0.0.0.0/0 207.46.108.57
0 0 RETURN 0 -- * * 0.0.0.0/0 65.54.239.140
0 0 RETURN 0 -- * * 0.0.0.0/0 65.54.239.20
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE 0 -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Please check if the above printed iptables rules are correct!
* moblock is running, pid is 392.



and /etc/default/moblock is

# moblock.default - default configuration file for moblock-control

# In this file you can put any configuration variable from moblock.conf
# (/etc/moblock/moblock.conf). Values in moblock.conf will be overwritten by
# values in this file (moblock.default).
WHITE_TCP_OUT="http"
WHITE_IP_OUT="65.54.239.20 65.54.239.140 207.46.108.57 207.46.106.23 207.46.106.16 207.46.108.23 65.54.179.216 207.46.106.20 207.46.108.36 207.46.108.39 207.46.106.30 207.46.108.17 207.46.106.17 207.46.108.37 207.46.108.50 207.46.106.95 207.46.106.24 207.46.106.46 207.46.28.93"
WHITE_TCP_IN="http"

Nepherte
May 25th, 2008, 01:45 PM
The output of ls -l `sudo find /etc/ -name "*moblock*"`:

-rwxr-xr-x 1 root root 2861 2008-05-08 22:45 /etc/cron.daily/moblock
-rw-r--r-- 1 root root 258 2008-05-08 22:44 /etc/default/moblock
-rw-r--r-- 1 root root 399 2008-05-08 22:45 /etc/logrotate.d/moblock
-rw-r--r-- 1 root root 4961 2008-05-08 22:17 /etc/moblock/moblock.conf
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc0.d/K20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc1.d/K20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc2.d/S20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc3.d/S20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc4.d/S20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc5.d/S20moblock -> ../init.d/moblock
lrwxrwxrwx 1 root root 17 2008-05-25 11:07 /etc/rc6.d/K20moblock -> ../init.d/moblock

/etc/moblock:
totaal 37652
-rw-r--r-- 1 root root 920 2008-05-03 21:43 blocklists.list
-rw-r--r-- 1 root root 868 2008-01-14 20:40 blocklists.list~
-rw-r--r-- 1 root root 868 2008-05-08 22:17 blocklists.list.dpkg-dist
-rw-r--r-- 1 root root 16405635 2008-05-03 20:49 guarding.p2p
-rw-r--r-- 1 root root 9938230 2008-05-03 21:54 ipfilter.dat
-rw-r--r-- 1 root root 9938230 2008-05-03 21:44 ipfilter.dat.backup
-rwxr-xr-x 1 root root 565 2008-05-08 22:17 iptables-custom-insert.sh
-rwxr-xr-x 1 root root 564 2008-05-08 22:17 iptables-custom-remove.sh
-rw-r--r-- 1 root root 4961 2008-05-08 22:17 moblock.conf
-rwxr-xr-x 1 root root 2596 2008-05-08 22:45 MoBlock-nfq-reject.sh
-rwxr-xr-x 1 root root 2637 2008-05-08 22:17 MoBlock-nfq.sh
-rw-r--r-- 1 bart bart 2167522 2008-05-03 21:56 pipfilter.dat.gz
I checked if /etc/init.d/moblock existed, but the file is nowhere to be found. So i guess we found the reason.

LSB_MODE is set to 0.

The status right after booting the system is: pid is not running.

jre
May 25th, 2008, 02:51 PM
I checked if /etc/init.d/moblock existed, but the file is nowhere to be found. So i guess we found the reason.
Yay.
Either do a sudo aptitude purge moblock && sudo aptitude install moblock (this way you will loose your current configuration, but a simple aptitude reinstall moblock won't help), or copy it there manually:

mkdir ~/moblock
dpkg -X /var/cache/apt/archives/moblock_0.9~rc2-11_i386.deb ~/moblock
sudo cp ~/moblock/etc/init.d/moblock /etc/init.d/moblock
chmod +x /etc/init.d/moblock
Step 1: Create a directory in your home directory
Step 2: Extract the current moblock deb (assuming you haven't deleted it)
Step 3: copy the file to the correct place
Step 4: Make the file executable (although it should be so already)


moblock-control status is



Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
[...]
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE 0 -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Well, 80 is http, so webbrowsing is definitely whitelisted. Still ...


and /etc/default/moblock is

WHITE_TCP_OUT="http"
WHITE_IP_OUT="65.54.239.20 65.54.239.140 207.46.108.57 207.46.106.23 207.46.106.16 207.46.108.23 65.54.179.216 207.46.106.20 207.46.108.36 207.46.108.39 207.46.106.30 207.46.108.17 207.46.106.17 207.46.108.37 207.46.108.50 207.46.106.95 207.46.106.24 207.46.106.46 207.46.28.93"
WHITE_TCP_IN="http"
Replace WHITE_TCP_OUT="http" with WHITE_TCP_OUT="80 8080 443":
- port 80 is what the service name "http" really means (IMHO it was not a good idea of the iptables team to introduce the ambiguous service name "http". So for the sake of clarity i prefer "80". Anyway, that's not important here.)
- port 8080 is sometimes an alternative to 80, chosen by a few webpages. Let's add that here, too.
- 443 (service name https) may also help.
So now, do a moblock-control restart and try again. Does it work now?
If not: no websurfing at all or just not a few pages?
Are blocks shown in the logfile when you can't surf to a webpage?

A few more comments:

Instead of many seperate entries you might want to whitelist the entire range 207.46.106.0-207.46.106.255. Just delete the single 207.46.106.XXX entries and add a 207.46.106.0/24 instead.

There's no need to whitelist incoming port 80 (http), except if you have set up apache and are providing a homepage. So remove the WHITE_TCP_IN="http" entry. I guess you just did that while trying to fix your problems, but this won't help ...

General, if mobloquer does not automatically do so, always do a moblock-control restart when you have changed something in the whitelisting.

greets
jre

Nepherte
May 25th, 2008, 03:46 PM
Thanks. That solved the problem.

alonecity
May 26th, 2008, 04:18 PM
I have the same problem as Chris. When Moblock is running, I don't have any web browsing at all. It stays stuck at "looking up domain.com" on any site I try.

Here's my Moblock status:
Current iptables rules (this may take awhile):
Chain INPUT (policy ACCEPT 111K packets, 144M bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
0 0 BLOCK_MATCH all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xffff
2161K 205M INPUT_QUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0xfffe
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
Chain OUTPUT (policy ACCEPT 73993 packets, 5947K bytes)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
148K 9599K moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
0 0 BLOCK_MATCH all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xffff
39M 2650M OUTPUT_QUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0xfffe
Chain ALLOW_IP (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 130.149.17.156-130.149.17.156
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 66.35.250.209-66.35.250.209
Chain BLOCK_MATCH (2 references)
pkts bytes target prot opt in out source destination
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain INPUT_QUEUE (1 references)
pkts bytes target prot opt in out source destination
2161K 205M ALLOW_IP all -- * * 0.0.0.0/0 0.0.0.0/0
2161K 205M NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 255
Chain OUTPUT_QUEUE (1 references)
pkts bytes target prot opt in out source destination
2444 156K RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
33 1980 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:110
39M 2650M ALLOW_IP all -- * * 0.0.0.0/0 0.0.0.0/0
39M 2650M NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 255
Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.200.0/24
0 0 RETURN all -- * * 192.168.200.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.200.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 204.227.127.200
0 0 RETURN all -- * * 0.0.0.0/0 192.168.200.0/24
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:110
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:143
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
1 60 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
148K 9599K NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0
Please check if the above printed iptables rules are correct!
* moblock is running, pid is 2576.

Here's my whitelist
# moblock.default - default configuration file for moblock-control

# In this file you can put any configuration variable from moblock.conf
# (/etc/moblock/moblock.conf). Values in moblock.conf will be overwritten by
# values in this file (moblock.default).
WHITE_TCP_OUT="80 8080 443 ftp imap smtp pop3"
WHITE_IP_IN="192.168.200.0/24"
WHITE_IP_OUT="192.168.200.0/24 204.227.127.200"
WHITE_IP_FORWARD="192.168.200.0/24"

jre
May 28th, 2008, 07:06 PM
@ alonecity:
I need answers to these questions, too:

If not: no websurfing at all or just not a few pages?
Are blocks shown in the logfile when you can't surf to a webpage?

Is 192.168.200.0/24 your LAN (in doubt post the output of sudo ifconfig)? If not, then you should whitelist your LAN.

techstop
May 29th, 2008, 02:13 PM
Nice one, thanks for your work. Just a note though, by enabling the repos listed on the sourceforge page you link to, I have been able to install moblock and mobloquer on 64-bit. The page at https://help.ubuntu.com/community/MoBlock says you have to compile from source to get it working on 64-bit.

I really like mobloquer, nice work!!!!

jre
May 29th, 2008, 02:15 PM
You can download preview packages of MoBlock (0.9~rc2-12~pre37) here: http://moblock-deb.sourceforge.net/preview

Next to many other changes this version has debconf support. Of course I want to know if it works technically. But I'm also interested in feedback about the debconf descriptions. Are they unclear, too technical, ...?

Further, thanks to Cader (http://forums.phoenixlabs.org/showthread.php?p=116645), it's now possible to find out the ports of blocked packets. Have a look at the NEWS (/usr/share/doc/moblock/NEWS.Debian.gz)

jre

ApUUbunU
May 29th, 2008, 03:34 PM
I installed Moblock recently, and now it doesn't work for some reason. I removed all whitelist IPs from the list in moblock.conf, and for some reason, I can still access the internet, when I should be blocked from my router.

I think this problem may be down to the firewall in Ubuntu. Moblock worked well before I installed firestarter, the GUI for the firewall. Now it seems as if Moblock doesn't work at all.

So, what should be my next step from here, in trying to get Moblock to work. It worked perfectly fine before!

Oh yes, I'm not using Mobloquer, but the non-GUI interface instead. I will try switching to the GUI, and see if that solves my problems.

jre
May 29th, 2008, 03:40 PM
Nice one, thanks for your work. Just a note though, by enabling the repos listed on the sourceforge page you link to, I have been able to install moblock and mobloquer on 64-bit. The page at https://help.ubuntu.com/community/MoBlock says you have to compile from source to get it working on 64-bit.
I just updated that page, finally ;-)
Other contributions are of course always welcome!



I installed Moblock recently, and now it doesn't work for some reason. I removed all whitelist IPs from the list in moblock.conf, and for some reason, I can still access the internet, when I should be blocked from my router.

I think this problem may be down to the firewall in Ubuntu. Moblock worked well before I installed firestarter, the GUI for the firewall. Now it seems as if Moblock doesn't work at all.
Do a moblock-control restart. I guess that firestarter purged your moblock iptables rules. You have to make sure that moblock is started after other firewalls or if this is not possible to do a restart. If your problems continue please post the output of moblock-control status.

jre

ApUUbunU
May 29th, 2008, 05:05 PM
Sadly, moblock-control restart didn't make any difference.

Here is the output of moblock-control status:



$ sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT tcp -- * * 192.168.0.1 0.0.0.0/0 tcp flags:!0x17/0x02
14 1729 ACCEPT udp -- * * 192.168.0.1 0.0.0.0/0
1 576 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/sec burst 5
0 0 DROP all -- wlan0 * 0.0.0.0/0 255.255.255.255
0 0 DROP all -- * * 0.0.0.0/0 192.168.0.255
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 LSI all -f * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/min burst 5
1595 1011K INBOUND all -- wlan0 * 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Input'
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/sec burst 5
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Forward'
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT tcp -- * * 192.168.0.2 192.168.0.1 tcp dpt:53
14 887 ACCEPT udp -- * * 192.168.0.2 192.168.0.1 udp dpt:53
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
15 1964 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
1649 201K OUTBOUND all -- * wlan0 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Output'
0 0 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain INBOUND (1 references)
pkts bytes target prot opt in out source destination
1592 1011K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
3 144 LSI all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LOG_FILTER (5 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 221.195.56.54 0.0.0.0/0
0 0 DROP all -- * * 83.100.226.60 0.0.0.0/0

Chain LSI (2 references)
pkts bytes target prot opt in out source destination
3 144 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
3 144 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
3 144 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02
0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04
0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LSO (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Outbound '
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable

Chain OUTBOUND (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
1463 193K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
186 8312 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Please check if the above printed iptables rules are correct!

* moblock is running, pid is 6321.


Possibly by uninstalling firestarter might solve the problem.

jre
May 29th, 2008, 06:47 PM
The moblock_in etc. rules should be placed at the head of the INPUT etc. chains (not at the bottom as in your case).
This will be the case directly after "moblock-control restart". Did you execute this command before the "status" command? Were there any messages? What's in /var/log/moblock-control.log?

ApUUbunU
May 29th, 2008, 10:43 PM
Oddly enough, after a system restart and uninstalling Firestarter, Moblock now works. However, I don't know why. The output of "status" was after restarting Moblock, and I don't recall there being any messages, though I might have forgotten.

The output of the log, before the restart was



Got SIGTERM! Dumping stats and exiting.
Duplicated range ( Bogo )
Ranges loaded: 242165
Merged ranges: 0
Skipped useless ranges: 0
NFQUEUE: binding to queue '0'

Now the output is the same, except with adresses blocked.

Here is the current output of the status command:



Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 1437 packets, 1341K bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
24 22874 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain OUTPUT (policy ACCEPT 1217 packets, 147K bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
97 5850 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.0.0/24
0 0 RETURN all -- * * 192.168.0.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
19 22173 RETURN all -- * * 192.168.0.0/24 0.0.0.0/0
5 701 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 66.114.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 194.109.137.218
0 0 RETURN all -- * * 0.0.0.0/0 66.150.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 130.57.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 69.31.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 207.46.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 64.4.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 65.55.0.0/16
0 0 RETURN all -- * * 0.0.0.0/0 65.54.0.0/16
12 750 RETURN all -- * * 0.0.0.0/0 192.168.0.0/24
85 5100 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Please check if the above printed iptables rules are correct!

* moblock is running, pid is 6233.


The moblock_in rules are still at the bottom of the INPUT etc. chains, but certain IPs are still being blocked. I assume that there must be another cause.

jre
May 30th, 2008, 08:41 PM
So what I meant to say is:
Every rule in the INPUT chain that is before moblock_in will be processed before the packets get to MoBlock.
You have the targets ACCEPT, DROP and other chains. Other chains themselves do the same: they ACCEPT, DROP or send packets back to INPUT. So we only need to look at ACCEPT and DROP:

If a packet will be DROPped anyway it doesn't matter if it is checked by MoBlock.
But if it gets ACCEPTed it will leave any further iptables processing, so it will not be checked by MoBlock.

Therefore you have to make sure that ACCEPT rules are only before MoBlock if they accept traffic that is not intended to be checked by MoBlock.

This is the INPUT chain you posted first:

Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT tcp -- * * 192.168.0.1 0.0.0.0/0 tcp flags:!0x17/0x02
14 1729 ACCEPT udp -- * * 192.168.0.1 0.0.0.0/0
1 576 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/sec burst 5
0 0 DROP all -- wlan0 * 0.0.0.0/0 255.255.255.255
0 0 DROP all -- * * 0.0.0.0/0 192.168.0.255
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 LSI all -f * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/min burst 5
1595 1011K INBOUND all -- wlan0 * 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Input'
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW
As you see there are many rules which ACCEPT traffic or send traffic to chains which contain an ACCEPT before your moblock_in. moblock_in should be the first or second rule in this chain.

The case in your second post is better:

Chain INPUT (policy ACCEPT 1437 packets, 1341K bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
24 22874 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW

One rule is before MoBlock and this rule simply accepts all traffic on the loopback device, which is ok.

So this was the long version of what I meant to say with "the moblock_in rule has to be at the head of the chain and not at the bottom".

Notes:
Since Moblock 0.9 with the MARKing feature traffic that is accepted by MoBlock is not ACCEPTed (in the sense that it will leave the iptables processing) but "marked accepted" which means that it will be processed by the other iptables rules.
(To be correct: the packets repeat the whole chain/hook function).
Up to MoBlock 0.8 traffic was ACCEPTed, this is the reason why 0.8 did not work with firestarter.

The above said is of course valid for OUTPUT and FORWARD, too.
jre

ApUUbunU
May 31st, 2008, 01:35 PM
Great, I now understand what you meant, and how the second post is better.

Thanks a lot for your explanation, and also for Moblock, its a great program!

alonecity
May 31st, 2008, 10:07 PM
@ alonecity:
I need answers to these questions, too:


Is 192.168.200.0/24 your LAN (in doubt post the output of sudo ifconfig)? If not, then you should whitelist your LAN.

jre:
I don't have any web browsing at all. 192.168.200.xxx is indeed my lan


eth0 Link encap:Ethernet HWaddr 00:14:22:54:4e:6b
inet addr:192.168.200.101 Bcast:192.168.200.255 Mask:255.255.255.0
inet6 addr: fe80::214:22ff:fe54:4e6b/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:31932 errors:0 dropped:0 overruns:0 frame:0
TX packets:19232 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:44011705 (41.9 MB) TX bytes:1664221 (1.5 MB)
Interrupt:18 Base address:0xa000


Thank you

Edit: put the right tags.

jre
June 1st, 2008, 10:59 AM
I had a closer look at your iptables rules now. (Note: Please put them in CODE tags, it's a pain to read them this way).

Now I saw that you use IPList/IPBlock and MoBlock at the same time - don't do this, just use one of both, they have the same functionality.

There are two occassions where they conflict:

- They both bind to NFQUEUE, although IPList does not use the default QUEUE number (0) there still might occur problems.

- They both mark packets. I'm not sure if these MARKs are additional or replace each other.

I've just added a Conflict: iplist to the moblock package so that apt will refuse to install both at the same time.

jre

alonecity
June 1st, 2008, 01:13 PM
Thanks jre. I thought I had uninstalled IPlist properly but I went through an uninstall/reinstall/uninstall of IPlist and uninstal/reinstall for Moblock and it seems to be working now.

Doctoxic
June 3rd, 2008, 09:52 PM
Hi

Hope you can help - am not a linux expert and know little about firewalls etc but here goes - hope you can help

Ok - i know i am doing something wrong here - situation so far is:

1) installed moblock through synaptic - following the instructions on the Ubuntu docs page am using ubuntu 8.04

I know this from the readme:
In the default configuration MoBlock starts at system boot and some preconfigured blocklists are updated once a day. You can specify the blocklists to use in /etc/moblock/blocklists.list. Everything else (automatic start and update, iptables handling, IP and port whitelisting) is configured in /etc/moblock/moblock.conf. This is important especially if MoBlock blocks sites that it should not block.

2) So i edited the /etc/default/moblock file to include this WHITE_TCP_OUT="http https" and then restart moblock

BUT it still seems to block everything

Can anyone tell me what i need to do to get browsing and ftp to work whilst still running moblock? I tried mobloquer which is a GUI but even using that it doesn't unblock stuff - very odd

does this help?

sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 3382 packets, 764K bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain OUTPUT (policy ACCEPT 3376 packets, 299K bytes)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

I have firestarter installed but am totally confused as to whether the firewall works all the time or only when i start the Firestarter GUI

hope you can help

many thanks

doc

jre
June 4th, 2008, 04:37 PM
I guess you need to whitelist your LAN, including your router, too. If you don't know your local IP check it with "sudo ifconfig". It's the value after "inet addr:" of the interface that you use for networking. For wired connections that might be "eth0", for wireless connections "wlan0".

Example: You found out that your IP is 192.168.0.39. Then your LAN will most probably cover the IP range 192.168.0.1-192.168.0.255. Then whitelist this range with the following lines in /etc/default/moblock:

WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"

After editing and a "moblock-control restart" you should be fine. Of course you can also do this with mobloquer.

firestarter is not a firewall itself but it just sets up the Linux firewall: iptables. All your iptables rules do belong to moblock, so there is no conflict.

Thanks for posting your iptables rules, that saved me some questions.

Greets
jre

belgofac
June 7th, 2008, 02:13 AM
Hi JRE, All,

I have been running Moblock for a while on Linux Mint Daryna but new distro Mint Elyssa (Hardy based) = new problems.
I use Firestarter as firewall.

I installed Moblock and it worked straight out of the box. For a while. I had to adjust moblock.conf and used the same settings as before.
Then moblock did not want to start at all anymore.

Status:


Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- * * 192.168.0.1 0.0.0.0/0 tcp flags:!0x17/0x02
35 7185 ACCEPT udp -- * * 192.168.0.1 0.0.0.0/0
60 2520 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 0 limit: avg 1/sec burst 5
0 0 LSI udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:33434
0 0 LSI icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- eth0 * 0.0.0.0/0 255.255.255.255
10 2505 DROP all -- * * 0.0.0.0/0 192.168.0.255
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 LSI all -f * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/min burst 5
602 522K INBOUND all -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Input'

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 0 limit: avg 1/sec burst 5
0 0 LSI udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:33434
0 0 LSI icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Forward'

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- * * 192.168.0.2 192.168.0.1 tcp dpt:53
41 2545 ACCEPT udp -- * * 192.168.0.2 192.168.0.1 udp dpt:53
60 2520 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
2 136 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
574 44221 OUTBOUND all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Output'

Chain INBOUND (1 references)
pkts bytes target prot opt in out source destination
602 522K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 LSI all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LOG_FILTER (5 references)
pkts bytes target prot opt in out source destination

Chain LSI (6 references)
pkts bytes target prot opt in out source destination
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02
0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04
0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LSO (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Outbound '
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable

Chain OUTBOUND (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
518 39692 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
56 4529 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain moblock_fw (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_in (0 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 64.15.112.0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.0.0/16 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_out (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Please check if the above printed iptables rules are correct!

* moblock is not running.


Moblock-control.log:


[sudo] password for eddy:
YAHOOZ-060921002953:75.35.59.144-75.35.59.151
YAHOOZ-061003013011:75.41.158.152-75.41.158.159
YAHOOZ-070828170428:76.246.182.152-76.246.182.159
Installing blocklist to /etc/moblock/guarding.p2p [ OK ]
* MoBlock is not running.
2008-06-07 10:44:00 EST End: moblock-control update
2008-06-07 10:44:16 EST Begin: moblock-control start
Inserting iptablesiptables v1.3.8: host/network `-' not found
Try `iptables -h' or 'iptables --help' for more information.
[fail]
2008-06-07 11:00:23 EST Begin: moblock-control reload
Building blocklist [ OK ]
Removing lines containing the following regular expressions from the blocklist:
google
yahoo
altavista
debian
sourceforge
Removed the following lines:
add2.dir.scd.yahoo.com ads:66.218.70.227-66.218.70.227
BOGDAN_LUCIAN_CRISTIAN-YAHOOCOM:208.98.12.0-208.98.12.63
Cuyahooga County Bar Assoc:66.73.60.72-66.73.60.79
extads1.vip.ukl.yahoo.com ads:217.12.4.96-217.12.4.96
gigenfu@yahoo.com.tw:218.210.18.64-218.210.18.71
GOOGLE-NL:213.19.160.192-213.19.160.207
GOOGLE/PLANET LABS:208.185.40.192-208.185.40.223
GOOGLE/PLANET LABS:208.185.4.128-208.185.4.159
GOOGLE/PLANET LABS:208.185.42.96-208.185.42.127
NTT Com/SOL/VTF/EH/Sony/Google:157.238.217.32-157.238.217.39
rd1.vip.ukl.yahoo.com ads:217.12.6.21-217.12.6.21
Savvis-Sourceforge Split1 Start Range:66.35.192.0-66.35.249.255
Savvis Sourceforge Split2 End Range:66.35.251.0-66.35.255.255
sexymagnet.com/p2w1.geo.scd.yahoo.com]:66.218.79.157-66.218.79.157
SNET TEST YAHOO 01:66.159.160.136-66.159.160.143
SNET TEST YAHOO 02:66.159.160.144-66.159.160.151
SNET TEST YAHOO 03:66.159.160.152-66.159.160.159
SNET TEST YAHOO 04:66.159.160.160-66.159.160.167
SNET TEST YAHOO 05:66.159.160.168-66.159.160.183
SNET TEST YAHOO 06:66.159.160.184-66.159.160.191
SNET TEST YAHOO 07:66.159.160.192-66.159.160.199
SNET TEST YAHOO 09:66.159.160.208-66.159.160.215
SNET TEST YAHOO 10:66.159.160.216-66.159.160.223
SNET TEST YAHOO 11:66.159.160.224-66.159.160.231
SNET TEST YAHOO 3004:64.252.30.112-64.252.30.119
SNET TEST YAHOO:64.252.30.80-64.252.30.111
SNET TEST YAHOO:66.159.160.200-66.159.160.207
SNET TEST YAHOO:66.159.160.232-66.159.160.255
SNET TEST YAHOO:66.159.160.32-66.159.160.39
SNET TEST YAHOO:66.159.160.8-66.159.160.23
SNET TEST YAHOO:66.159.185.0-66.159.185.47
Software in the Public Interest / Debian:194.109.137.216-194.109.137.223
Taiwan Yahoo Electric Co., Ltd:203.74.105.88-203.74.105.95
Tonghua Yahoo Netbar,Kuaida Town , Tonghua City,:218.62.120.236-218.62.120.239
Tor.debian40etch64minim:88.198.17.116-88.198.17.116
tsaisuntech@yahoo.com:220.228.117.128-220.228.117.135
yahoo fraud scammer:68.195.62.40-68.195.62.40
YAHOOPC:218.233.116.192-218.233.116.255
yahoo scammer:4.65.105.109-4.65.105.109
Yahoo Software Development India Pvt. Ltd:203.145.181.48-203.145.181.63
YAHOOZ-060921002953:75.35.59.144-75.35.59.151
YAHOOZ-061003013011:75.41.158.152-75.41.158.159
YAHOOZ-070828170428:76.246.182.152-76.246.182.159
Installing blocklist to /etc/moblock/guarding.p2p [ OK ]
* MoBlock is not running.
2008-06-07 11:00:33 EST End: moblock-control reload
2008-06-07 11:00:54 EST Begin: moblock-control restart
Deleting iptablesiptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: Bad rule (does a matching rule exist in that chain?)
* Some iptables rules could not be deleted. The most common reason for this is
* that they did not exist. If MoBlock was not running this is the correct
* behaviour. But if MoBlock was running there is some problem. Make sure that
* MoBlock inserts its iptables rules correctly and that other software, e.g.
* firewall applications, don't delete them. Make sure that MoBlock is started
* after other firewall applications.
Stopping MoBlock [fail]
Inserting iptablesiptables v1.3.8: host/network `-' not found
Try `iptables -h' or 'iptables --help' for more information.



I have tried to delete and re-install but that didn't work either.

I have ben fiddling a bit more and it looks like the remove and re-install did not work properly:


[sudo] password for eddy:
Reading package lists... Done
Building dependency tree
Reading state information... Done
0 upgraded, 0 newly installed, 1 reinstalled, 0 to remove and 17 not upgraded.
Need to get 0B/59.6kB of archives.
After this operation, 0B of additional disk space will be used.
Do you want to continue [Y/n]? y
(Reading database ... 87966 files and directories currently installed.)
Preparing to replace moblock 0.9~rc2-11~hardy (using .../moblock_0.9~rc2-11~hardy_i386.deb) ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: warning - old pre-removal script returned error exit status 3
dpkg - trying script from the new package instead ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: error processing /var/cache/apt/archives/moblock_0.9~rc2-11~hardy_i386.deb (--unpack):
subprocess new pre-removal script returned error exit status 3
* Starting MoBlock moblock invoke-rc.d: initscript moblock, action "start" failed.
dpkg: error while cleaning up:
subprocess post-installation script returned error exit status 8
Errors were encountered while processing:
/var/cache/apt/archives/moblock_0.9~rc2-11~hardy_i386.deb
E: Sub-process /usr/bin/dpkg returned an error code

So, I can not uninstall or re-install it.

Tried a apt-get -f install but the same thing:


eddy@eddy-mint2 ~ $ sudo apt-get -f install
Reading package lists... Done
Building dependency tree
Reading state information... Done
Correcting dependencies... Done
The following extra packages will be installed:
libnetfilter-queue1 libnfnetlink0
The following NEW packages will be installed:
libnetfilter-queue1 libnfnetlink0
0 upgraded, 2 newly installed, 0 to remove and 17 not upgraded.
1 not fully installed or removed.
Need to get 0B/78.9kB of archives.
After this operation, 139kB of additional disk space will be used.
Do you want to continue [Y/n]? y
Selecting previously deselected package libnfnetlink0.
(Reading database ... 87954 files and directories currently installed.)
Unpacking libnfnetlink0 (from .../libnfnetlink0_0.0.30-2_i386.deb) ...
Selecting previously deselected package libnetfilter-queue1.
Unpacking libnetfilter-queue1 (from .../libnetfilter-queue1_0.0.13-1_i386.deb) ...
Selecting previously deselected package moblock.
Preparing to replace moblock 0.9~rc2-11~hardy (using .../moblock_0.9~rc2-11~hardy_i386.deb) ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: warning - old pre-removal script returned error exit status 3
dpkg - trying script from the new package instead ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: error processing /var/cache/apt/archives/moblock_0.9~rc2-11~hardy_i386.deb (--unpack):
subprocess new pre-removal script returned error exit status 3
* Starting MoBlock moblock invoke-rc.d: initscript moblock, action "start" failed.
dpkg: error while cleaning up:
subprocess post-installation script returned error exit status 8
Errors were encountered while processing:
/var/cache/apt/archives/moblock_0.9~rc2-11~hardy_i386.deb
E: Sub-process /usr/bin/dpkg returned an error code (1)




Any idea?

Sef
June 7th, 2008, 03:50 AM
Moved to Debian: Other OS talk.

Doctoxic
June 7th, 2008, 04:02 PM
I guess you need to whitelist your LAN, including your router, too. If you don't know your local IP check it with "sudo ifconfig". It's the value after "inet addr:" of the interface that you use for networking. For wired connections that might be "eth0", for wireless connections "wlan0".

Example: You found out that your IP is 192.168.0.39. Then your LAN will most probably cover the IP range 192.168.0.1-192.168.0.255. Then whitelist this range with the following lines in /etc/default/moblock:

WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"

After editing and a "moblock-control restart" you should be fine. Of course you can also do this with mobloquer.

firestarter is not a firewall itself but it just sets up the Linux firewall: iptables. All your iptables rules do belong to moblock, so there is no conflict.

Thanks for posting your iptables rules, that saved me some questions.

Greets
jre

thanks very much jre - thats sorted it

did i miss something in the readme or was this info missing (or maybe not written for a non linux expert?) Seems it would save you a lot of time if the readme's were aimed more at us noobs :D

i had previously tried mobloquer - it just didn't work (odd because it used to before i upgraded to Heron)

does running the firestarter gui activate the firewall? - only it started blocking my bittorrent port - easily fixed but annoying (sorry i know firestarter is not what you're supporting her)

Doc

belgofac
June 9th, 2008, 02:42 AM
Do not worry about it anymore.

For others who run into the same uninstall problems posted and tried everything to uninstall moblock without success:

rm -rf everything to do with moblock like /etc/moblock etc...

You will get a message at boot telling you to click "fix broken packages" but that didn't work either so just continue with the boot.

I installed Ipblock instead without any problems.

I still have moblock running with Mint Daryna, so thanks for all your work guys.

jre
June 9th, 2008, 05:54 PM
Moved to Debian: Other OS talk.
No, that's definitely the wrong forum. This thread is targeted at Ubuntu users like the HOWTO https://help.ubuntu.com/community/MoBlock.
It's there so that Ubuntu users can ask me questions and make development questions. (Yes, I'm a Debian user, but this has nothing to do with this thread).
I'm not sure if the network forum was well chosen, so move it wherever you think is correct. Thanks for your work.

Edit 2008-06-11: We were moved to
Ubuntu Forums > The Ubuntu Forum Community > Other Community Discussions > Tutorials & Tips
Thanks, Sef


did i miss something in the readme or was this info missing (or maybe not written for a non linux expert?) Seems it would save you a lot of time if the readme's were aimed more at us noobs :D
Where did you read? I'm currently working on improving the documentation on two places:

- debconf questions: they interact with the user during installation, give warnings, explanations and allow to configure moblock. If you want to help me please download the current preview package from moblock-deb.sf.net/preview/ and tell me if my language there is clear and helpful for a non-tech person. This would be a great help!

- the wiki at https://help.ubuntu.com/community/MoBlock



does running the firestarter gui activate the firewall? - only it started blocking my bittorrent port - easily fixed but annoying (sorry i know firestarter is not what you're supporting her)
If you "start" firestarter the configured iptables rules will be inserted. So just check with "iptables -L -nv" before and after starting firestarter what happens.

Doctoxic
June 9th, 2008, 06:33 PM
thanks jre

i read the wiki - which does not contain the info in your post (well not specific enough for the likes of me)

thanks again for all your help with this

doc

jre
June 9th, 2008, 08:09 PM
thanks jre

i read the wiki - which does not contain the info in your post (well not specific enough for the likes of me)

thanks again for all your help with this
Now it does. If you miss something please tell me.
jre

yipperzz
June 22nd, 2008, 06:01 PM
Getting an error when trying to stop the service. It says fail. But if I try to restart it works fine.


xxx@xxx:~$ sudo moblock-control stop
* Stopping MoBlock moblock [fail]

xxx@xxx:~$ sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 12380 packets, 14M bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 8134 packets, 555K bytes)
pkts bytes target prot opt in out source destination

Please check if the above printed iptables rules are correct!

* moblock is running, pid is 5430.


So it looks like it's running, I believe. But why can't it stop? Is there anything I need to look at?

Also if I kill pid 5430 and do a start command, it says that it's starting but when I give it a few minutes and run status it says that moblock is not running. Same for restart.

And is there a way to view what is being blocked real time? Or do you have to just go through the logs? Or would I need mobloquer? Just wondering as I'm going from peerguardian on XP and would like to get something running on my Linux box. Sorry if the questions. I didn't see much documentation on the website other than how to install moblock. Thanks for your help.

Edit: I just saw the tail -f /var/log/moblock.log command to view real time. But it's not working at the moment since moblock isn't running :P
Edit2: FYI I'm not running any software firewall.

yipperzz
June 22nd, 2008, 10:21 PM
Well now that I had a chance to reboot, moblock isn't running anymore when I check the status. If I try to start or restart, it still won't run.

Edit: I got it to work. I edited the moblock.conf file incorrectly. I thought that it said that you could put the ip range in the whitelist, So I did 192.168.11.1-192.168.11.255. I changed it to 192.168.11.0/24 and it's working now. Also, I may have added a space in that range too. I don't remember it since I changed it. Now it's working as it should. Sorry about that.

jre
June 23rd, 2008, 05:08 PM
Edit: I got it to work. I edited the moblock.conf file incorrectly. I thought that it said that you could put the ip range in the whitelist, So I did 192.168.11.1-192.168.11.255. I changed it to 192.168.11.0/24 and it's working now. Also, I may have added a space in that range too. I don't remember it since I changed it. Now it's working as it should. Sorry about that.
Glad to hear it's working now. For future reference: Have a look at /var/log/moblock-control.log, there errors get explained or at least logged.


For all who are interested:
I've put preview packages at moblock-deb.sf.net/preview with some nice new things:
- allow-list with support for ip-ranges (as yipperzz thought)
- debconf support (graphical configuration during installation and at every later time)
- log to syslog the port a blocked packet was sent on
- automatic whitelisting of the LAN

I'd appreciate every feedback. Next to bugreports (sigh ...) I'm particularly interested in feedback for the debconf part: is it useful? Do you understand it? Are there open questions? To technical?
If everything is perfect a short notice would be nice, too.

jre

Bauldrick
June 24th, 2008, 07:44 PM
I can't get your latest to install (r-12). I'm building my own package mind, on a powerpc NAS. Previous one installs, but this goes through the questions (which makes it alot better by the way) and then gives dpkg error.
I've probably made a mistake in how to build it though, this is what I did:



mkdir moblock
cd moblock
sudo apt-get build-dep -y moblock
wget http://moblock-deb.sourceforge.net/preview/moblock-0.9~rc2-12.source.tgz
tar zxvf moblock*
cd moblock-*
dpkg-buildpackage -rfakeroot
cd ..
sudo dpkg -i moblock*.deb


Like I say, it's probably me, it starts to install and I answer all questions but then it fails to install after that.

jre
June 27th, 2008, 06:00 PM
Like I say, it's probably me, it starts to install and I answer all questions but then it fails to install after that.
What output do you get during your failed install? What's in /var/log/moblock-control.log and .../moblock.log?

I can install this version just fine here, but maybe I changed something manually during development which isn't represented in the source ...

Thanks for the feedback!!

Bauldrick
June 28th, 2008, 11:59 AM
Heres the error:


dpkg: error processing moblock (--install):
subprocess post-installation script returned error exit status 10
Processing triggers for man-db ...
Errors were encountered while processing:
moblock


nothing really in /var/log/moblock-control.log


2008-06-28 11:20:30 BST End: moblock-control stop

and moblock.log


Sat Jun 28 11:20:29| Got SIGTERM! Dumping stats and exiting.

On a completely different note, on my little machine when moblock starts the cpu gets hammered for 2-3 minutes. top shows 92-97%

jre
June 28th, 2008, 11:57 PM
"exit status 10" is not of moblock-control.
I can merely guess that this results from "dash" being the default shell on ubuntu, while on Debian it's still "bash". I had a similar problem just now here after I changed to dash.
You may try it again by changing in your moblock-0.9~rc2/debian/postinst the first line to
#!/bin/bash and then rebuild the package.

The high CPU usage might result from MoBlock loading the blocklist and merging overlapping/duplicate ranges. I guess your NAS has low CPU power? IIRC on my Pentium 3, 800 MHz it took me about 30 secs to start up.
Anyway, there's a clone of MoBlock (NFBlockD (http://makovick.googlepages.com/nfblockddaemon) ) which is less resource intensive, but for now I will do nothing about that.

Finally, nice to hear that you have (had) it running on a PowerPC NAS!!

sleepitoff
July 6th, 2008, 04:58 PM
I just installed Moblock-nfq on a fresh install of Hardy and am having a problem here. I was adding and removing custom blocklists to /etc/moblock/blocklists.list and when I ran sudo moblock-control reload I get the message '...fail!'

All moblock-control commands fail now (start, stop, update, etc)

What can I do here? I don't want to try uninstalling moblock via synaptic out of fear something will get messed up.

Help?

here's the moblock-control.log


2008-07-06 10:28:32 AM CDT Begin: /usr/bin/moblock-control reload
Building blocklist * Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Check your /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-07-06 10:28:32 AM CDT Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz * .
* Blocklists updated.
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
* MoBlock is not running.
2008-07-06 10:29:05 AM CDT End: /usr/bin/moblock-control update
2008-07-06 10:29:05 AM CDT Begin: /usr/bin/moblock-control start
Inserting iptables ...done.
Starting MoBlock ...done.
2008-07-06 10:29:06 AM CDT End: /usr/bin/moblock-control start
2008-07-06 10:30:56 AM CDT Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz * . No update available.
* Blocklists updated.
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
Reloading MoBlock ...done.
2008-07-06 10:31:26 AM CDT End: /usr/bin/moblock-control update
2008-07-06 10:37:48 AM CDT Begin: /usr/bin/moblock-control reload
Building blocklist * Error 6: http://www.bluetack.co.uk/config/level1.gz not available. Check your /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-07-06 10:37:55 AM CDT Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz * . No update available.
Updating level1.gz * .
Updating ads-trackers-and-bad-pr0n.gz * .
Updating spyware.gz * .
Updating spider.gz * .
* Blocklists updated.
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
Reloading MoBlock ...done.
2008-07-06 10:39:41 AM CDT End: /usr/bin/moblock-control update
2008-07-06 10:41:46 AM CDT Begin: /usr/bin/moblock-control reload
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 10:41:46 AM CDT End: /usr/bin/moblock-control reload
2008-07-06 10:42:06 AM CDT Begin: /usr/bin/moblock-control stop
Deleting iptables ...done.
Stopping MoBlock/sbin/start-stop-daemon: warning: failed to kill 22565: No such process
...fail!
2008-07-06 10:42:06 AM CDT End: /usr/bin/moblock-control stop
2008-07-06 10:42:17 AM CDT Begin: /usr/bin/moblock-control restart
Deleting iptables ...fail!
Stopping MoBlock/sbin/start-stop-daemon: warning: failed to kill 22565: No such process
...fail!
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 10:42:21 AM CDT End: /usr/bin/moblock-control restart
2008-07-06 10:43:29 AM CDT Begin: /usr/bin/moblock-control reload
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 10:43:29 AM CDT End: /usr/bin/moblock-control reload
2008-07-06 10:45:05 AM CDT Begin: /usr/bin/moblock-control stop
Deleting iptables ...fail!
Stopping MoBlock/sbin/start-stop-daemon: warning: failed to kill 22565: No such process
...fail!
2008-07-06 10:45:05 AM CDT End: /usr/bin/moblock-control stop
2008-07-06 10:48:22 AM CDT Begin: /usr/bin/moblock-control stop
Deleting iptables ...fail!
Stopping MoBlock/sbin/start-stop-daemon: warning: failed to kill 22565: No such process
...fail!
2008-07-06 10:48:22 AM CDT End: /usr/bin/moblock-control stop
2008-07-06 10:55:20 AM CDT Begin: /usr/bin/moblock-control reload
Building blocklist ...done.
Installing blocklist to /etc/moblock/ipfilter.dat ...done.
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 10:55:20 AM CDT End: /usr/bin/moblock-control reload
2008-07-06 11:07:05 AM CDT Begin: /usr/bin/moblock-control stop
Deleting iptables ...fail!
Stopping MoBlock/sbin/start-stop-daemon: warning: failed to kill 22565: No such process
...fail!
2008-07-06 11:07:05 AM CDT End: /usr/bin/moblock-control stop
2008-07-06 11:07:05 AM CDT Begin: /usr/bin/moblock-control start
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 11:07:05 AM CDT End: /usr/bin/moblock-control start
2008-07-06 11:07:20 AM CDT Begin: /usr/bin/moblock-control start
* MoBlock has some strange status.
* Try "moblock-control stop". Otherwise kill all moblock processes,
* delete /var/run/moblock.pid and all iptables rules related to MoBlock.
2008-07-06 11:07:20 AM CDT End: /usr/bin/moblock-control start

jre
July 7th, 2008, 05:26 PM
You mixed blocklists of different formats. Either use nipfilter.dat.gz or
level1.gz/ads-trackers-and-bad-pr0n.gz/spyware.gz/spider.gz.

If you want to use nipfilter.dat:
- set BLOCKLIST_FORMAT="d" in /etc/moblock/moblock.conf.
- Don't use the other lists
- Note that level1 is already part of nipfilter.dat. Please have a look at /usr/share/doc/moblock/README.blocklists.gz to learn more about these blocklists.

If you want to use the other lists (I suggest this solution):
- First of, install the "moblock" package instead of "moblock-nfq". In moblock-nfq there's a bug when using multiple lists (but this bug is not the reason for your current problems).
- Keep the setting BLOCKLIST_FORMAT="p" in /etc/moblock/moblock.conf
- Don't use nipfilter.dat at the same time.

I guess when you have fixed this setup MoBlock will work again.

jre

jre
July 14th, 2008, 06:44 PM
New MoBlock (0.9~rc2-13) packages:


debconf support added
port 80 and 443 whitelisted per default again
LAN traffic automatically whitelisted (experimental)
port logging
hopefully removed all bashisms


Have fun.

I have not made a separate file release of moblock-control, yet. Contact me if you want one now.

The development repository is still not updated.


Heres the error:


dpkg: error processing moblock (--install):
subprocess post-installation script returned error exit status 10
Processing triggers for man-db ...
Errors were encountered while processing:
moblock

This is also solved. I had removed a variable at one place but kept it at another :-/
Sorry that it took me so long to tell you this

jre

Dawa
July 18th, 2008, 10:22 PM
I'm not sure if this is Moblock or Bluetack, but every time I update, the log says "no update available", for every list. This has been going on for like a week. I tried manually deleting the lists in /var/spool/moblock and re-downloading them, but the blocked IP ranges number stays the same.

any ideas?

jre
July 19th, 2008, 12:17 PM
I'm not sure if this is Moblock or Bluetack, but every time I update, the log says "no update available", for every list.
Please post your /etc/moblock/blocklists.list.
AFAIK the [n|p]ipfilter.dat list is updated only at a weekly basis. While the single lists (level1.gz et al.) are updated daily or even at a higher frequency. For the latter it's important to use "moblock" not "moblock-nfq" or "moblock-ipq".

greets
jre

Dawa
July 19th, 2008, 01:09 PM
# blocklists.list - lists the blocklists used by moblock-control
#
# Place one URL per line for every blocklist. Any line which starts with a
# (hash) is a comment and is ignored.
#
# All lists have to be in the same blocklist format. This format has to be
# specified in moblock.conf.
# The name of the blocklist has to be the same as the basename of the URL, i.e.
# php redirects are not possible.
#
# If the remote server doesnīt support timestamping start the line with
# "notimestamp". Donīt abuse this. This is only necessary if the remote
# server doesnīt provide timestamping (Error 400).
#
# For local blocklists start the line with "locallist".
#
# Have a look at /usr/share/doc/moblock/README.blocklists.gz for some
# available blocklists.
#
# Do a "moblock-control update" when you have edited this file.
#
www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz
www.bluetack.co.uk/config/bogon.gz
www.bluetack.co.uk/config/dshield.gz
www.bluetack.co.uk/config/edu.gz
www.bluetack.co.uk/config/fornonlancomputers.gz
www.bluetack.co.uk/config/hijacked.gz
www.bluetack.co.uk/config/iana-multicast.gz
www.bluetack.co.uk/config/iana-private.gz
www.bluetack.co.uk/config/iana-reserved.gz
www.bluetack.co.uk/config/level1.gz
www.bluetack.co.uk/config/level2.gz
www.bluetack.co.uk/config/level3.gz
www.bluetack.co.uk/config/Microsoft.gz
www.bluetack.co.uk/config/proxy.gz
www.bluetack.co.uk/config/rangetest.gz
www.bluetack.co.uk/config/spider.gz
www.bluetack.co.uk/config/spyware.gz
www.bluetack.co.uk/config/templist.gz
#
#locallist /etc/moblock/custom-blocklist.p2p

that's my blocklists.list. looks normal, i think..

jre
July 19th, 2008, 01:41 PM
I invested this a bit further. Since 2008-07-14 there are indeed no updates.
I started a thread at bluetack, see here:
http://www.bluetack.co.uk/forums/index.php?showtopic=18899

Dawa
July 19th, 2008, 01:43 PM
thanks, jre. they really should have a "last updated" type of deal somewhere on their site. Now I feel bad about gobbling up their bandwidth in a panic. :D

Bauldrick
July 21st, 2008, 12:11 PM
This is also solved. I had removed a variable at one place but kept it at another :-/
Sorry that it took me so long to tell you this


Ta !! But I get 404 error on preview address on moblock site?

Look forward to trying to get it to work again

jre
July 21st, 2008, 05:27 PM
The preview is removed because the preview has been released.
So just install it normally.
jre

cnschulz
August 8th, 2008, 11:34 AM
Hi,

Im a noob trying to install Moblock... Im running headless hardy and im doing a fresh install with all defaults. Any help in solving the install/config issues is appreciated.

c.



apt-get install moblock
<snip>
Setting up moblock (0.9~rc2-16~hardy) ...
* Reloading MoBlock moblock ... failed.
<snip>
Errors were encountered while processing:
moblock
E: Sub-process /usr/bin/dpkg returned an error code (1)

-----

The log contains the following:


2008-08-08 20:14:22 EST Begin: /usr/bin/moblock-control reload
Building blocklist [31m*[39;49m Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Check your /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-08-08 20:14:22 EST Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz [31m*[39;49m Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Aborting!
2008-08-08 20:14:58 EST Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz [31m*[39;49m Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Aborting!
2008-08-08 20:15:14 EST Begin: /usr/bin/moblock-control start
[31m*[39;49m Error 6: /etc/moblock/ipfilter.dat not installed, not starting MoBlock!
2008-08-08 20:15:34 EST Begin: /usr/bin/moblock-control stop
Deleting iptables ...fail!
Stopping MoBlock ...fail!
2008-08-08 20:15:34 EST End: /usr/bin/moblock-control stop
2008-08-08 20:16:28 EST Begin: /usr/bin/moblock-control reload
Building blocklist [31m*[39;49m Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Check your /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-08-08 20:16:28 EST Begin: /usr/bin/moblock-control update
Updating blocklists ...
Updating nipfilter.dat.gz [31m*[39;49m Error 6: www.bluetack.co.uk/config/nipfilter.dat.gz not available. Aborting!
2008-08-08 20:16:53 EST Begin: /usr/bin/moblock-control stop
Deleting iptables ...fail!
Stopping MoBlock ...done.
2008-08-08 20:16:53 EST End: /usr/bin/moblock-control stop
2008-08-08 20:27:53 EST Begin: moblock-control reload
Building blocklist [31m*[39;49m Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Check the /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-08-08 20:27:53 EST Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gzrm: cannot remove `ads-trackers-and-bad-pr0n.gz': No such file or directory
[31m*[39;49m Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Aborting!
2008-08-08 20:28:33 EST Begin: moblock-control reload
Building blocklist [31m*[39;49m Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Check the /etc/moblock/blocklists.list and try a "moblock-control update" first. Aborting!
2008-08-08 20:28:33 EST Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gzrm: cannot remove `ads-trackers-and-bad-pr0n.gz': No such file or directory
[31m*[39;49m Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Aborting!

jre
August 10th, 2008, 04:44 PM
during installation it is necessary to download the blocklists. Somehow this fails, but maybe it was only a temporary problem and everything is already working as it should.
To fix it manually do the following.
Download the missing list, please note that after fixing this, moblock-control might complain about the next missing list, so you might have to repeat the step for them, too.

wget www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz
sudo cp ads-trackers-and-bad-pr0n.gz /var/spool/moblock/used/.

I changed the code so that the logfile is more informational about this in the future. So there was a bug to be fixed but this bug wa not the reason for your problems.

Thanks
jre

cnschulz
August 11th, 2008, 12:07 AM
pardon my (possible) ignorance but all the files from bluetrack seem to be empty.. ie zero bytes. even through the browser of manual wget.

am i doing something wrong? could someone verify my claim?

c.

uljanow
August 11th, 2008, 12:22 AM
Bluetack seems to have some problems. But there is a mirror on http://iplist.sourceforge.net/mirror/

cnschulz
August 11th, 2008, 01:01 AM
Thanks for your help,

I have it working now with a manual get of level1.gz only (php redirects not implemented)

The mirror site only has 5 config files available. It seems that bluetrack has none!!

Ill set the .list file back to defaults and see what happens... better than nothing i guess.

Any other suggestions? What are other users encountering/doing?

oh... and thanks for your help... again...

c.

jre
August 11th, 2008, 05:23 PM
The blocklist update problems seem to be over:


/etc/cron.daily/moblock:
Updating blocklists and reloading MoBlock: moblock.

The following lists were updated:
www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz of 2008-08-10 19:24
www.bluetack.co.uk/config/bogon.gz of 2008-08-10 19:27
www.bluetack.co.uk/config/dshield.gz of 2008-08-10 19:10
www.bluetack.co.uk/config/hijacked.gz of 2008-08-10 19:25
www.bluetack.co.uk/config/level1.gz of 2008-08-10 19:27
www.bluetack.co.uk/config/level2.gz of 2008-08-10 19:24
www.bluetack.co.uk/config/Microsoft.gz of 2008-08-10 19:10
www.bluetack.co.uk/config/proxy.gz of 2008-08-10 19:30
www.bluetack.co.uk/config/templist.gz of 2008-08-10 19:25

For the following lists there was no update available:
www.bluetack.co.uk/config/fornonlancomputers.gz of 2008-08-04 16:03
www.bluetack.co.uk/config/iana-multicast.gz of 2008-08-04 16:03
www.bluetack.co.uk/config/iana-private.gz of 2008-08-04 16:03
www.bluetack.co.uk/config/iana-reserved.gz of 2008-08-04 16:03


I'm glad to tell that this problem didn't affect users who already had once downloaded the lists successfully but only first time installers.

suprfish
August 14th, 2008, 02:24 AM
Hi,

I'm having some trouble with mobloquer, installed from the moblock-deb repositories. It won't start; when started from the terminal, it drops the message "Segmentation fault." Any help is appreciated :KS

jre
August 14th, 2008, 08:47 PM
Huh, I'm not so savvy with mobloquer. Is there anything more than this message? Which version are you using (dpkg -l mobloquer)

suprfish
August 14th, 2008, 09:53 PM
Thanks for the reply :D. It's mobloquer 0.5.1~hardy.



_@_:~$ mobloquer
Segmentation fault

_@_:~$ sudo mobloquer
[sudo] password for _:
Segmentation fault

suprfish
August 15th, 2008, 02:33 AM
I notice that in the mobloquer readme it says it is dependent on moblock-nfq; from apt-get it says it is dependent on moblock. Could this be causing the problem?

jre
August 16th, 2008, 09:43 AM
I notice that in the mobloquer readme it says it is dependent on moblock-nfq; from apt-get it says it is dependent on moblock. Could this be causing the problem?
It' depends on moblock (0.9~rc2). But this is only because there the /etc/default/moblock file is always there.
Further I think moblock related errors would give other output.
Anyway, is moblock running? Try "moblock-control status" and "moblock-control test".

Have you tried a clean reinstall yet?

sudo aptitude purge mobloquer
sudo aptitude install mobloquer
The first command makes sure all config files, such as ~/.config/mobloquer are removed.

Otherwise I'd guess that it is a problem related to other software, e.g. Qt which mobloquer depends on.

winston smith
August 16th, 2008, 10:59 AM
I've been trying to uninstall moblock and get the following errors.

The following packages will be REMOVED:
moblock
0 upgraded, 0 newly installed, 1 to remove and 0 not upgraded.
After this operation, 360kB disk space will be freed.
Do you want to continue [Y/n]? Y
(Reading database ... 96178 files and directories currently installed.)
Removing moblock ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: error processing moblock (--remove):
subprocess pre-removal script returned error exit status 3
Errors were encountered while processing:
moblock
E: Sub-process /usr/bin/dpkg returned an error code (1)


Initial install crapped out on nonexistent blocklists from bluetack, so I replaced them with lists from iblocklist that appeared to allow installation to complete. But after playing with mobloquer, it appeared that moblock would not stop, start, or anything. Not an iptables conflict that I know of as this is the first time I've ever installed Ubuntu, or any Linux distro, and hadn't set up any rules at all.

Anyway, any assistance is appreciated, please be as explicit as possible because I just finished installing Linux for the first time ever about 2 hours ago. 8)

jre
August 17th, 2008, 09:31 AM
There seems to be bug in the LSB init functions (lsb-base) in hardy :-/
I'm having a look at it to make special packages for hardy.
Until then please try the following:
Start MoBlock before you uninstall it.
Either try
sudo moblock-control start or if this doesn't work try
sudo /usr/bin/moblock -p /etc/moblock/guarding.p2p -q 0 -t -r 10 -a 20 /var/log/moblock.log. Note that the latter only starts the daemon but does not insert the iptables rules - this means it should be enough to make apt/aptitude/synaptic happy but it does not give you a functional MoBlock.

jre

suprfish
August 17th, 2008, 05:05 PM
Thanks for the help, jre :). Fortunately, moblock works fine (it's just mobloquer that is bugged).

bigtel
August 18th, 2008, 08:24 PM
I have a current problem with Moblock which I need some advice on please - I have been trying to update (as my updater says there is one update available) but when I try I keep getting an error message. I tried to remove Moblock and then reistall it and now I keep getting the message below

-----

terry@terry-laptop:~$ sudo aptitude install moblock
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
Building tag database... Done
The following packages have been automatically kept back:
acroread-escript
The following NEW packages will be automatically installed:
libnetfilter-queue1 libnfnetlink0
The following packages have been kept back:
acroread acroread-plugins mozilla-acroread
The following NEW packages will be installed:
libnetfilter-queue1 libnfnetlink0
The following packages will be upgraded:
moblock
1 packages upgraded, 2 newly installed, 0 to remove and 4 not upgraded.
Need to get 19.3kB/100kB of archives. After unpacking 139kB will be used.
Do you want to continue? [Y/n/?] y
Writing extended state information... Done
Get:1 http://archive.ubuntu.com hardy/universe libnfnetlink0 0.0.30-2 [12.2kB]
Get:2 http://archive.ubuntu.com hardy/universe libnetfilter-queue1 0.0.13-1 [7042B]
Fetched 19.3kB in 0s (59.5kB/s)
Preconfiguring packages ...
Selecting previously deselected package libnfnetlink0.
(Reading database ... 240183 files and directories currently installed.)
Unpacking libnfnetlink0 (from .../libnfnetlink0_0.0.30-2_i386.deb) ...
Selecting previously deselected package libnetfilter-queue1.
Unpacking libnetfilter-queue1 (from .../libnetfilter-queue1_0.0.13-1_i386.deb) ...
Selecting previously deselected package moblock.
Preparing to replace moblock 0.9~rc2-13~hardy (using .../moblock_0.9~rc2-16~hardy_i386.deb) ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: warning - old pre-removal script returned error exit status 3
dpkg - trying script from the new package instead ...
* Stopping MoBlock moblock [fail]
invoke-rc.d: initscript moblock, action "stop" failed.
dpkg: error processing /var/cache/apt/archives/moblock_0.9~rc2-16~hardy_i386.deb (--unpack):
subprocess new pre-removal script returned error exit status 3
Errors were encountered while processing:
/var/cache/apt/archives/moblock_0.9~rc2-16~hardy_i386.deb
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
Setting up libnfnetlink0 (0.0.30-2) ...

Setting up libnetfilter-queue1 (0.0.13-1) ...

Processing triggers for libc6 ...
ldconfig deferred processing now taking place
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
Writing extended state information... Done
Building tag database... Done
terry@terry-laptop:~$

---



Any help and advice to just get Moblock up and running again would be appreciated.

Thanks.

bigtel
August 18th, 2008, 09:30 PM
This is the error message I get through synaptic installer -

--
E: /var/cache/apt/archives/moblock_0.9~rc2-16~hardy_i386.deb: subprocess new pre-removal script returned error exit status 3
--

jre
August 19th, 2008, 04:55 PM
This is the error message I get through synaptic installer -

--
E: /var/cache/apt/archives/moblock_0.9~rc2-16~hardy_i386.deb: subprocess new pre-removal script returned error exit status 3
--
Please have a look at this post:
http://ubuntuforums.org/showpost.php?p=5605844&postcount=67

EDIT: The hardy only bug is fixed in 0.9~rc2-17~hardy

the_unexpected
August 25th, 2008, 03:59 AM
I'm trying to install moblock on a fresh Hardy install, when I try to run the install from terminal using apt-get, the terminal brings up the window shown here (http://img.photobucket.com/albums/v230/mxl2003/moblock_install.png). However, nothing at all happens when I click OK, or any other key on the keyboard that I've discovered. If I press ESC, it returns to the terminal, giving the following error:


dpkg: error processing moblock (--configure):
subprocess post-installation script returned error exit status 10
Errors were encountered while processing:
moblock
E: Sub-process /usr/bin/dpkg returned an error code (1)

I tried to install it via Synaptic, and got farther, even was able to enter ports to whitelist. But when I tried to click Next after whitelisting local LAN, it hung, and then Synaptic returned the following error:


E: moblock: subprocess post-installation script returned error exit status 8

jre
August 25th, 2008, 04:55 PM
I'm trying to install moblock on a fresh Hardy install, when I try to run the install from terminal using apt-get, the terminal brings up the window shown here (http://img.photobucket.com/albums/v230/mxl2003/moblock_install.png). However, nothing at all happens when I click OK, or any other key on the keyboard that I've discovered.
Have you tried pressing TAB until OK is selected and then RETURN? I'm not sure if clicking with the mouse does work.

Anyway, the error you got the second time sounds strange. Please try to reinstall MoBlock:

sudo aptitude purge moblock
sudo aptitude install moblock
Note that during installation you will have to wait some time until the blocklists are downloaded. But there will be a message on the screen notifying you of this.
If installation fails again, then please post the output of "sudo moblock-control status" and your /var/log/moblock-control.log

the_unexpected
August 25th, 2008, 11:29 PM
Have you tried pressing TAB until OK is selected and then RETURN? I'm not sure if clicking with the mouse does work.

Anyway, the error you got the second time sounds strange. Please try to reinstall MoBlock:

sudo aptitude purge moblock
sudo aptitude install moblock
Note that during installation you will have to wait some time until the blocklists are downloaded. But there will be a message on the screen notifying you of this.
If installation fails again, then please post the output of "sudo moblock-control status" and your /var/log/moblock-control.log
Thanks! Tab+Return did get me through what needed to do, however, after downloading the blocklists, it returned the error below. I did, however, check the moblock control log, and found that I'd incorrectly entered config syntax for port ranges (separated by hyphen instead of colon). I corrected this and everything is now running fine...figured I'd post this in case anyone else runs into the same problem. Thanks! :D (the log is attached as a .txt file).

* Starting MoBlock moblock invoke-rc.d: initscript moblock, action "start" failed.
dpkg: error processing moblock (--configure):
subprocess post-installation script returned error exit status 8
Setting up p7zip (4.57~dfsg.1-1) ...
Processing triggers for libc6 ...
ldconfig deferred processing now taking place
Errors were encountered while processing:
moblock
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
Setting up moblock (0.9~rc2-17~hardy) ...
* Reloading MoBlock moblock [ OK ]
* Starting MoBlock moblock invoke-rc.d: initscript moblock, action "start" failed.
dpkg: error processing moblock (--configure):
subprocess post-installation script returned error exit status 8
Errors were encountered while processing:
moblock
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initializing package states... Done
Writing extended state information... Done
Building tag database... Done

Sudo moblock-control status brought up the following:


sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 95261 packets, 89M bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 77605 packets, 11M bytes)
pkts bytes target prot opt in out source destination

Chain moblock_fw (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_in (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Chain moblock_out (0 references)
pkts bytes target prot opt in out source destination
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 0

Please check if the above printed iptables rules are correct!

* moblock is not running.

jre
August 26th, 2008, 07:03 PM
Ah, glad you figured it out on your own. And thanks for posting this, it's good to know that a problem is solved.

lovinglinux
September 2nd, 2008, 05:06 AM
@jre,

I wrote on another thread that you replied (about torrent clients) that I was using IPlist instead of Moblock. Now I'm switching to Moblock and would to explain why I was experiencing difficulties with it.

I was a Windows/PeerGuardian user until a couple of weeks ago. First thing I did after switching to Linux was installing Moblock and Firestarter. Unfortunately, the transition itself is not easy, so I tried to understand the whole iptables thing, to make sure I was secure with these applications. I did a couple of tests with Moblock and Firestarter, browsing web sites that I knew that were included in the blocklist. But no matter what I did, those web sites weren't blocked at all. So, I uninstalled it and installed iplist.

Today I discovered why those web sites weren't blocked, even when I didn't allowed HTTP in the Mobloquer GUI. Apparently, if I include ports 80 and 443 during moblock installation, the entry on /etc/default/moblock override Moblocker settings. I'm not an expert, but I guess is because the setup uses port numbers and Mobloquer uses the new "http https..." format. So I deleted the first line of /etc/default/moblock and now I can control which ports I will allow connections within the Mobloquer interface.

Everything is working properly, as far as I know.

So I will stick with Moblock/Moblocker, because it has some nice features that iplist doesn't have. Thanks for your support and effort on building this great tool for Linux users.

jre
September 2nd, 2008, 06:21 PM
Thanks for your feedback! What particularly are the features that IPList doesn't have?

Indeed you are right about that mobloquer bug. I once heard of that but forgot to note it.
Just for the records: mobloquer also saves its settings in /etc/default/moblock (since it's just a frontend for MoBlock/moblock-control). mobloquer correctly reads "80 443" and interprets them as "http https". The bug is that unchecking http or https in mobloquer doesn't remove the 80 or 443. Bug fixes welcome!

Greetings
jre

lovinglinux
September 3rd, 2008, 01:42 AM
Thanks for your feedback! What particularly are the features that IPList doesn't have?

For instance, the ability to allow single IP's "on the fly". I know that this feature to work Moblock should be restarted, but as far as I understand iplist only have the allow.p2p file.

As far as I remember, iplist has the option to allow protocols both ways, while in Mobloquer you can allow incoming, outgoing or both. That is really useful.

Moblocker also stays on the tray when closed, together with Firestarter. It's not a necessary feature, but it i like it.

graysky
September 20th, 2008, 10:09 PM
sudo aptitude purge moblock
sudo aptitude install moblock
Note that during installation you will have to wait some time until the blocklists are downloaded. But there will be a message on the screen notifying you of this.
If installation fails again, then please post the output of "sudo moblock-control status" and your /var/log/moblock-control.log

I too am getting this error (used the debian etch repos hough).

I did the purge, install as you suggested but got errors:

Here are the output you requested:


# moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 18385 packets, 19M bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 17971 packets, 1660K bytes)
pkts bytes target prot opt in out source destination

Please check if the above printed iptables rules are correct!

moblock is not running.


# cat /var/log/moblock-control.log
2008-09-20 17:05:52 EDT Begin: moblock-control reload
Building blocklist^[[31m*^[[39;49m Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Check the /etc/moblock/blocklists.list and$
2008-09-20 17:05:52 EDT Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gz.
Updating bogon.gz.
Updating dshield.gz.
Updating fornonlancomputers.gz.
Updating hijacked.gz.
Updating iana-multicast.gz.
Updating iana-private.gz.
Updating iana-reserved.gz.
Updating level1.gz.
Updating level2.gz.
Updating Microsoft.gz.
Updating proxy.gz.
Updating templist.gz.
Blocklists updated.
Building blocklist.
Installing blocklist to /etc/moblock/guarding.p2p.
MoBlock is not running, doing nothing.
2008-09-20 17:07:52 EDT End: moblock-control update
2008-09-20 17:07:53 EDT Begin: moblock-control start
^[[31m*^[[39;49m Error 170: Could not load kernel module xt_state, not starting MoBlock!
2008-09-20 17:07:54 EDT Begin: moblock-control reload
Building blocklist.
Installing blocklist to /etc/moblock/guarding.p2p.
MoBlock is not running, doing nothing.
2008-09-20 17:07:55 EDT End: moblock-control reload
2008-09-20 17:07:55 EDT Begin: moblock-control start
^[[31m*^[[39;49m Error 170: Could not load kernel module xt_state, not starting MoBlock!

Seems to want the kernel module xt_state which I don't seem to have...

jre
September 22nd, 2008, 10:49 AM
Seems to want the kernel module xt_state which I don't seem to have...
Just for the records, see our discussion at
http://forums.phoenixlabs.org/showthread.php?t=17430

The kernel in question (2.6.23-chw-4 used in the distribution Knoppmyth) does not have the kernel module xt_state at all. (Although the Debian kernels 2.6.22, 2.6.24, 2.6.26 and 2.6.27 do have it).

Therefore my advice (which might break other parts of the system) is to add the Debian repository to /etc/apt/sources.list (use lenny = testing or sid =unstable):

deb http://ftp.debian.org/debian lenny main
and install the current kernel:

sudo aptitude update
sudo aptitude install linux-image-2.6
and then reboot and choose the new kernel in grub. If anything goes wrong just reboot again and use the old kernel.

lovinglinux
September 23rd, 2008, 12:43 AM
@jre

Are you going to remove the "Whitelist IPs" feature on future versions of Mobloquer? I really like this feature and will miss it :(

If yes, would be possible to add a feature to allow editing "allow.p2p" file from the Mobloquer gui?

jre
September 23rd, 2008, 10:33 AM
Are you going to remove the "Whitelist IPs" feature on future versions of Mobloquer? I really like this feature and will miss it :(

If yes, would be possible to add a feature to allow editing "allow.p2p" file from the Mobloquer gui?
Don't worry. My plan was to wait for the implementation of allow.p2p in mobloquer and then (and only then) remove it from moblock-control. So I wanted to completely replace the first by the latter and keep the code base small.

Unfortunately the upstream development of mobloquer is stalled currently :-/ More on that another time. Note that I can't do the C++ necessary for mobloquer.

Therefore, and to keep my TODO small, I decided to keep everything as it is. In the next release the "deprecated" warning is removed.

lovinglinux
September 23rd, 2008, 02:20 PM
Don't worry. My plan was to wait for the implementation of allow.p2p in mobloquer and then (and only then) remove it from moblock-control. So I wanted to completely replace the first by the latter and keep the code base small.

Unfortunately the upstream development of mobloquer is stalled currently :-/ More on that another time. Note that I can't do the C++ necessary for mobloquer.

Therefore, and to keep my TODO small, I decided to keep everything as it is. In the next release the "deprecated" warning is removed.

Thank you. Great news.

chronniff
September 27th, 2008, 04:21 AM
This is what I get in my moblock-control.log every time I try to update to whatever update came through the repos today:


2008-09-26 11:04:24 PM EDT Begin: moblock-control reload
Building blocklist * Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available.
* Check the /etc/moblock/blocklists.list and try a
* "moblock-control update" first. Aborting!
2008-09-26 11:04:24 PM EDT Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gz failed!
rm: cannot remove `ads-trackers-and-bad-pr0n.gz': No such file or directory
Trying without timestamping * Error 9: www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz not available. Aborting!
* To fix this manually download www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz and copy it to /var/spool/moblock/used
2008-09-26 11:04:37 PM EDT Begin: moblock-control reload

And this is what I get in the terminal:


dave@dave-laptop:~$ sudo apt-get install moblock moblock-control
[sudo] password for dave:
Reading package lists... Done
Building dependency tree
Reading state information... Done
moblock is already the newest version.
moblock-control is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
2 not fully installed or removed.
After this operation, 0B of additional disk space will be used.
Setting up moblock-control (1.0-1+hardy) ...
* Reloading MoBlock moblock ... failed.
Trying an update instead to get missing blocklists, this may take several
minutes. You may do in another terminal a
"tail -f /var/log/moblock-control.log"
to follow the update process. Pressing "control" + "c" stops this.
The lists are saved to /var/spool/moblock/.
* Updating blocklists and reloading MoBlock moblock ... failed.
dpkg: error processing moblock-control (--configure):
subprocess post-installation script returned error exit status 9
dpkg: dependency problems prevent configuration of mobloquer:
mobloquer depends on moblock-control; however:
Package moblock-control is not configured yet.
dpkg: error processing mobloquer (--configure):
dependency problems - leaving unconfigured
Errors were encountered while processing:
moblock-control
mobloquer
E: Sub-process /usr/bin/dpkg returned an error code (1)


Any ideas what's going on? seems as though the blocklists can't reached, am I alone in this problem or is the site that hosts the lists just not online...although I doubt that's the problem since this happened right after I updated the package....I had moblock and mobloquer installed, and I saw that moblock-control was its own seperate package, so I guess when I updated it downloaded it....at this point I have purged and reinstalled all three of those packages more than once.....any input would be great,even if it is just to commiserate

trpnblies7
September 27th, 2008, 05:51 AM
I've been getting the same error as chronniff all day long. It seems as though the blocklist site is down. It's making updating anything else really annoying, as the processes stall because moblock keeps trying to update and I have to manually cancel it.

chronniff
September 27th, 2008, 06:22 AM
yeah, the funny thing is that when I go to the site is up and running fine...though I haven't tried to download a list directly from the site

lovinglinux
September 27th, 2008, 07:31 AM
I don't know if this is the problem you are experiencing, but I also had a few issues the last couple of days updating the lists from Bluetack, even when using another software to download them. I build my own lists, merging a few sources with TinyBLM (http://www.bluetack.co.uk/forums/index.php?showtopic=11022&hl=TinyBLM), so I don't receive any errors on moblock, since it retrieves only local files.

Bluetack's lists are not being updated as they were before. A few list maintainers have quit Bluetack's team and created a new list distribution site (http://blocklist1.snowmanuk.net/). You can read about this here (http://forums.phoenixlabs.org/showthread.php?t=17291) and as you can see here (http://www.bluetack.co.uk/forums/index.php?showtopic=19067), Bluetack is searching for new IP hunters and verifiers. So it might be a good idea to add the TBG lists to moblock and temporarily disabling Bluetack's list until the problem is completely solved.

Another source that might interest you is i-Blocklist (http://iblocklist.com/lists.php), but this one do not integrates with moblock yet, so you have to download them manually and add the local files paths to moblock.

chronniff
September 27th, 2008, 08:44 AM
Thanks a lot man....I remember about a year ago they came very close to shutting down their servers due to lack of funds....I guess the group was just falling apart, its a shame considering most of the p2p community has been depended on the site for their security for years now...not that most of the users even pay attention as to where these magic lists of IPs come from.....I appreciate the heads up though...thanks again

lovinglinux
September 27th, 2008, 10:43 AM
Thanks a lot man....I remember about a year ago they came very close to shutting down their servers due to lack of funds....I guess the group was just falling apart, its a shame considering most of the p2p community has been depended on the site for their security for years now...not that most of the users even pay attention as to where these magic lists of IPs come from.....I appreciate the heads up though...thanks again

You are welcome.

I'm sure they will get back on track soon. At least they have enough funding for almost a year now.

BTW, Level 1 list is completely empty right now :-(

jre
September 27th, 2008, 02:26 PM
Thanks, lovinglinux, for this information - I totally missed that. Although the level1 is not empty here.

For people not having problems: Do nothing, be happy, don't make unnecessary blocklist downloads.

So for all people having update problems: The old default blocklists by bluetack currently often fail to download. MoBlock will refuse to start if not all configured blocklists are available. So your problem is the download of the blocklists, but not a problem of your installation. So do NOT purge moblock-control - this will remove all downloaded blocklists, even those that were already downloaded successfully - so purging will make your problems bigger.

What you can do now:
Check what blocklists fail to download in /var/log/moblock-control.

If you want to use that blocklists try a "moblock-control update" or download it manually. Then place the blocklist in /var/spool/moblock/used. (e.g. "sudo cp level1.gz /var/spool/moblock/used")

If you don't want to use that blocklist just run "sudo dpkg-reconfigure moblock-control" and deselect the blocklist in question. For the other questions that you will be asked - just keep everything as it is. Then do a "moblock-control update".

If you want to use blocklists by TBG just add them to /etc/moblock/blocklists.list and do a "moblock-control update".

What I will do: I'll prepare a update which uses the new lists by TBG per default (this will only work on new installs). On updates from the current installations I'll notice the user of the current situation.

lovinglinux
September 27th, 2008, 08:03 PM
Thanks, lovinglinux, for this information - I totally missed that. Although the level1 is not empty here.

You are welcome. Level 1 is ok now, but it was empty when I wrote the previous post :-)


If you want to use that blocklists try a "moblock-control update" or download it manually. Then place the blocklist in /var/spool/moblock-control/used. (e.g. "sudo cp level1.gz /var/spool/moblock-control/used")

I couldn't find /var/spool/moblock-control/used but I have found /var/spool/moblock/used and mobloquer is updating to this directory. Does this means that the new moblock-control package wasn't properly installed or is just the path configured in mobloquer settings?

Anyway, I have created a script to download Bluetack's lists from an alternative source and move them to /var/spool/moblock/used directory, so moblock can be loaded properly. This do not require any changes in moblock lists.


#!/bin/bash

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/ads-trackers-and-bad-pr0n.gz http://list.iblocklist.com/?list=bt_ads
sudo mv ~/Desktop/ads-trackers-and-bad-pr0n.gz /var/spool/moblock/used/ads-trackers-and-bad-pr0n.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/Microsoft.gz http://list.iblocklist.com/?list=bt_microsoft
sudo mv ~/Desktop/Microsoft.gz /var/spool/moblock/used/Microsoft.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/bogon.gz http://list.iblocklist.com/?list=bt_bogon
sudo mv ~/Desktop/bogon.gz /var/spool/moblock/used/bogon.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/dshield.gz http://list.iblocklist.com/?list=bt_dshield
sudo mv ~/Desktop/dshield.gz /var/spool/moblock/used/dshield.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/edu.gz http://list.iblocklist.com/?list=bt_edu
sudo mv ~/Desktop/edu.gz /var/spool/moblock/used/edu.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/hijacked.gz http://list.iblocklist.com/?list=bt_hijacked
sudo mv ~/Desktop/hijacked.gz /var/spool/moblock/used/hijacked.gz

#wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/iana-multicast.gz http://www.bluetack.co.uk/config/iana-multicast.gz
#sudo mv ~/Desktop/iana-multicast.gz /var/spool/moblock/used/iana-multicast.gz

#wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/iana-private.gz http://www.bluetack.co.uk/config/iana-private.gz
#sudo mv ~/Desktop/iana-private.gz /var/spool/moblock/used/iana-private.gz

#wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/iana-reserved.gz http://www.bluetack.co.uk/config/iana-reserved.gz
#sudo mv ~/Desktop/iana-reserved.gz /var/spool/moblock/used/iana-reserved.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/level1.gz http://list.iblocklist.com/?list=bt_level1
sudo mv ~/Desktop/level1.gz /var/spool/moblock/used/level1.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/level2.gz http://list.iblocklist.com/?list=bt_level2
sudo mv ~/Desktop/level2.gz /var/spool/moblock/used/level2.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/level3.gz http://list.iblocklist.com/?list=bt_level3
sudo mv ~/Desktop/level3.gz /var/spool/moblock/used/level3.gz

#wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/fornonlancomputers.gz http://www.bluetack.co.uk/config/fornonlancomputers.gz
#sudo mv ~/Desktop/fornonlancomputers.gz /var/spool/moblock/used/fornonlancomputers.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/proxy.gz http://list.iblocklist.com/?list=bt_proxy
sudo mv ~/Desktop/proxy.gz /var/spool/moblock/used/proxy.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/rangetest.gz http://list.iblocklist.com/?list=bt_rangetest
sudo mv ~/Desktop/rangetest.gz /var/spool/moblock/used/rangetest.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/spyware.gz http://list.iblocklist.com/?list=bt_spyware
sudo mv ~/Desktop/spyware.gz /var/spool/moblock/used/spyware.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/spider.gz http://list.iblocklist.com/?list=bt_spider
sudo mv ~/Desktop/spider.gz /var/spool/moblock/used/spider.gz

wget --timeout=30 --tries=3 --timestamping --no-directories -O ~/Desktop/templist.gz http://list.iblocklist.com/?list=bt_templist
sudo mv ~/Desktop/templist.gz /var/spool/moblock/used/templist.gz

Don't forget to remove or comment the lines of lists that you don't use.

This must be run through Terminal, because it will prompt for sudo password.

There is probably a more elegant way of doing this, but I'm still a Linux newbie :-). I hope this will help people experiencing issues updating bluetack's lists.

jre
September 28th, 2008, 01:24 PM
I couldn't find /var/spool/moblock-control/used but I have found /var/spool/moblock/used and mobloquer is updating to this directory. Does this means that the new moblock-control package wasn't properly installed or is just the path configured in mobloquer settings?

No, this simply means that I should think while typing. The path is, and has been, /var/spool/moblock/used
Sorry, for the confusion, I'll correct that in my post.

The script that you have should work, but that is nearly the same as what happens on "moblock-control update". IMHO the problem is on bluetack's side, all that we can do is try several times (either with your script or with "moblock-control update") or wait - or change the lists that we use.

Hehe, I started moblock-control with writing similar things as you are doing now ;-) Happy coding!

lovinglinux
September 28th, 2008, 02:16 PM
No, this simply means that I should think while typing. The path is, and has been, /var/spool/moblock/used
Sorry, for the confusion, I'll correct that in my post.

No problem.


The script that you have should work, but that is nearly the same as what happens on "moblock-control update". IMHO the problem is on bluetack's side, all that we can do is try several times (either with your script or with "moblock-control update") or wait - or change the lists that we use.

Not really. While I imagine the process should be similar, the script I wrote uses a mirror, so this could solve the problem temporarily without the need for changing lists sources. So, it's a single-click fast solution. I'm not really sure when or how they sync the lists with bluetack site, but I'm pretty sure the files are hosted on another domain. I even had to rename the files with the script, because they put a "bt_" prefix in front of most of the gz files.


IMHO the problem is on bluetack's side...

I agree. If I didn't use a different source, the script wouldn't help much.


Hehe, I started moblock-control with writing similar things as you are doing now ;-) Happy coding!

Hehe, this thing is addictive. Before moving to Linux I had something against the command line approach, but now I can see how good it is. The problem is that I'm starting to spend more time imagining how I could the make the computer do things I want and the way I want than actually using it :-)

jre
September 29th, 2008, 09:10 PM
Not really. While I imagine the process should be similar, the script I wrote uses a mirror, so this could solve the problem temporarily without the need for changing lists sources. So, it's a single-click fast solution. I'm not really sure when or how they sync the lists with bluetack site, but I'm pretty sure the files are hosted on another domain. I even had to rename the files with the script, because they put a "bt_" prefix in front of most of the gz files.

Oh! Yes, now I see you're using iblocklist. I just scanned the source but didn't really look at the URLs ;-)

This is one of the biggest TODOs left: supporting php redirects so that iblocklist can be used with moblock-control.

lovinglinux
September 30th, 2008, 02:45 AM
This is one of the biggest TODOs left: supporting php redirects so that iblocklist can be used with moblock-control.

That would be great.

I have a new question.

I'm only using local lists. I download several lists using the script and merge them using TinyBLM. Nevertheless, do I need to run the update in mobloquer whenever I change my local lists or hitting "Reload' will be enough to get the latest local lists? I'm asking this because I was updating until today, when I got the same issue posted by chronniff. The weird thing is that I'm not using any bluetacks's lists but moblock keeps trying to connect to the site and get stuck in the middle of the process.

jre
September 30th, 2008, 04:49 PM
That would be great.

I have a new question.

I'm only using local lists. I download several lists using the script and merge them using TinyBLM. Nevertheless, do I need to run the update in mobloquer whenever I change my local lists or hitting "Reload' will be enough to get the latest local lists? I'm asking this because I was updating until today, when I got the same issue posted by chronniff. The weird thing is that I'm not using any bluetacks's lists but moblock keeps trying to connect to the site and get stuck in the middle of the process.

"reload" is good for you. Then all lists configured in blocklists.list will be unpacked and cat'ted together to the master blocklist /etc/moblock/guarding.p2p. Since you are only using local lsits there's no need to do a "update".
When you do an "update", moblock-control tries to connect to bluetack first to test if network access is available. I might use another TESTHOST than bluetack.co.uk, or perhaps check this with a more sophisticated way. Currently it's simply downloading bluetack's index.html ...
So I guess you got an "Error 171: No connection to www.bluetack.co.uk. Aborting!", right?

Crafty Kisses
September 30th, 2008, 06:50 PM
Thanks for the tutorial, really nice.

lovinglinux
September 30th, 2008, 07:16 PM
"reload" is good for you. Then all lists configured in blocklists.list will be unpacked and cat'ted together to the master blocklist /etc/moblock/guarding.p2p. Since you are only using local lsits there's no need to do a "update".

Thanks. Moblock doesn't merge ranges when creating /etc/moblock/guarding.p2p right?


When you do an "update", moblock-control tries to connect to bluetack first to test if network access is available. I might use another TESTHOST than bluetack.co.uk, or perhaps check this with a more sophisticated way. Currently it's simply downloading bluetack's index.html ...
So I guess you got an "Error 171: No connection to www.bluetack.co.uk. Aborting!", right?

Yep, something like that. I don't know the implications of using another TESTHOST, but it might be a good idea, due to recent bluetack's failures.

jre
October 1st, 2008, 09:38 PM
Thanks. Moblock doesn't merge ranges when creating /etc/moblock/guarding.p2p right?
No, the resulting list is only cat'ted togerther. This is done by moblock-control. The MoBlock daemon does the merging when it starts and loads the list.

Thanks Codename!

lovinglinux
October 5th, 2008, 03:01 PM
No, the resulting list is only cat'ted togerther. This is done by moblock-control. The MoBlock daemon does the merging when it starts and loads the list.

This is something I would like to better understand.

I have already noticed that when you reload moblock it re-creates the guarding.p2p file using the current selected lists sources, simply appending all lists ranges to the file, so there is no merging at this point. Then when I start moblock, there is a CPU spike for a while, which I believe is due to MoBlock daemon writing the iptables. After a while, the CPU load goes back to normal and the "Currently blocking xxxx IP ranges" message is updated to reflect the updated number of ranges used. But this number does not correspond to a merged list. For example, when I merge the same lists used on moblock with TinyBLM, there is a significant reduction in the number of ranges, due to range "duplicates" being merged. The log file of TinyBLM provides the total number of ranges before and after merging. When compared to the "Currently blocking xxxx IP ranges" on moblock I get the same number of ranges before merging in the TinyBLM log.

Additionally, the CPU spike time before updating the number of blocking ranges on mobloquer is much shorter than the one of TinyBLM. When merging lists with TinyBLM sometimes it takes like 20 minutes to complete the merging, while moblock update the iptables pretty fast. Why? Does moblock simply copy the ranges from guarding.p2p and write them to the iptables regardless if they are duplicates or not?

What happens if the guarding.p2p files has some commented lines? Does moblock ignores these lines or could they screw up my iptable rules? I'm asking this because I use some sources with two commented lines in the beginning of each list and it's kind of annoying to remove them manually.

semteXKG
October 6th, 2008, 12:15 PM
Hey!

I've a problem with moblock: it worked quiet good for a while till i installed it inside a vm. the vm is connected to the network over NAT.

The Problem now is: DNS Resolution is broken, when i activate moblock it stops working, when i stop it it works again...

i tried to reconfigure it with dpkg-reconfigure moblock, but nothing happens?

The moblock-config status:



alm@defiant:~$ sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 551K packets, 179M bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain OUTPUT (policy ACCEPT 909K packets, 1154M bytes)
pkts bytes target prot opt in out source destination
3 180 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
3 180 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92



i did not whitelist lan traffic, but this wasn't a problem in the previous installation...

I'd really appreciate the help,
semteX

jre
October 6th, 2008, 06:43 PM
Do a "tail -f /var/log/moblock.log" to follow live the logfile. Then you see which IPs get blocked and therefore cause your problems. whitelist them or add them to your allow.p2p.

I'm quite sure that this is a problem with a blocked LAN.

semteXKG
October 6th, 2008, 07:42 PM
thanks, will try this in a sec...

what's the command to rerun the moblock config menu? i thought it was dpkg-reconfigure but I was quiet wrong with that guess...

add: whitelisted the whole LAN, works like a charm, thanks!

jre
October 8th, 2008, 06:42 PM
what's the command to rerun the moblock config menu? i thought it was dpkg-reconfigure but I was quiet wrong with that guess...
I've split the packages: moblock (the daemon from moblock.berlios.de) and moblock-control (everything else), so it is:

dpkg-reconfigure moblock-control

Glad to hear it's working now!

GPizza
October 11th, 2008, 12:30 PM
Hi,
I couldn't find any post for the problem I am facing.
Everytime I run the update manager it downloads few moblock files but update does happen. I am getting the following error message: "Could not dowload all repository indexes" and the following description of the problem:
"GPG error: http://moblock-deb.sourceforge.net hardy Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY CB53C4079072870BFailed to fetch http://blognux.free.fr/debian/dists/unstable/main/binary-i386/Packages.gz 404 Not Found
Some index files failed to download, they have been ignored, or old ones used instead."
As I am not a Lnux would anyone knows hot to get it fixed? I would really appreciate if the explanation is in a "for Dummies" way. :-)

Thanks a lot!

lovinglinux
October 13th, 2008, 09:50 AM
@jre

Do you know any script to merge IP ranges?

I already have a nice script that download lists from several sources, extract compressed files and cat them into a few different lists, but there is one list that I need to merge, because it's not working on Deluge's blocklist plugin with just appended ranges.

I know moblock can download, extract and "cat" the ranges, but I'm using a different approach with it. I've created different compilation lists that I use depending on what I'm doing and if there are ports open or not. For example, if I'm just browsing the web I use my custom "web browsing" list which is more forgiven. If I'm using p2p and thus have a port open I use a more restrictive list, the same goes for games and other stuff. This way, is very easy to enable/disable a single list on mobloquer instead of several lists each time my activity requires a different level of protection. So I have like 4 lists with different levels of protection in mobloquer's blocklist sources.

The way I'm doing I can update all lists, including those not supported by moblock, and "cat" them with a single command. Would be nice if I could merge them, so I don't have to open TinyBLM on Wine to do this (this command-line thing is making me a little bit lazy these days :-))

jre
October 13th, 2008, 06:58 PM
"GPG error: http://moblock-deb.sourceforge.net hardy
Release: The following signatures couldn't be verified because the public key is not available:
NO_PUBKEY CB53C4079072870B

This is just a warning, but not an error. You get all needed files of moblock-deb.sourceforge.net - but you can't verify them (so you can't be sure if you really get my packages or if someone bad is faking them). The installation of MoBlock will work anyway.
To verify you have to add my GPG key. Do the following in the terminal:

gpg --keyserver wwwkeys.eu.pgp.net --recv 9072870B
gpg --export --armor 9072870B | sudo apt-key add -



Failed to fetch http://blognux.free.fr/debian/dists/unstable/main/binary-i386/Packages.gz 404 Not Found
This is an entry not related to MoBlock. Either you messed it up when you added this entry to your /etc/apt/sources.list or the remote site changed. So you have to check this.

jre
October 13th, 2008, 07:27 PM
Do you know any script to merge IP ranges?

I already have a nice script that download lists from several sources, extract compressed files and cat them into a few different lists, but there is one list that I need to merge, because it's not working on Deluge's blocklist plugin with just appended ranges.

General: I think merging is too much for doing it with an script, but calling some application from within a script should be good, too:
Obviously you already know BLM (BTW, where do you get it, I haven't found it on bluetack). Can't you use it from the command line?
I know of a guy who is working on a command line merging tool, but there's nothing available, yet.
You can try the old peerguardnf (old PG Linux, development is discontinued), which has a list merging feature. You can download it from https://sourceforge.net/projects/peerguardian.
Use it with:

cat LIST1 LIST2 ... | peerguardnf -f merged.p2p


Perhaps you can also use the merge feature from iblocklist.com (for VIP members only). But I don't know if this works for you.

uljanow
October 13th, 2008, 10:12 PM
You can also use iplist to merge/convert lists by invoking it like

iplist --output=merged.p2p.gz --output-fmt=p2p list1.p2p list2.dat list2.p2p.gz ...

lovinglinux
October 14th, 2008, 04:29 AM
General: I think merging is too much for doing it with an script, but calling some application from within a script should be good, too:

Yep, this is what I want.


Obviously you already know BLM (BTW, where do you get it, I haven't found it on bluetack).

BLM does not play well with Wine. I get TinyBLM form here (http://www.bluetack.co.uk/forums/index.php?showtopic=11022&hl=TinyBLM) and BLM form here (http://www.bluetack.co.uk/forums/index.php?autocom=faq&CODE=02&qid=30).


Can't you use it from the command line?

I don't know. Is it possible to use command line to invoke an application with Wine?


I know of a guy who is working on a command line merging tool, but there's nothing available, yet.


Please let me know when available. I would like to test it.


You can try the old peerguardnf (old PG Linux, development is discontinued), which has a list merging feature. You can download it from https://sourceforge.net/projects/peerguardian.
Use it with:

cat LIST1 LIST2 ... | peerguardnf -f merged.p2p


This could be a solution. Is there any incompatibility with moblock?

EDIT: AWESOME. It works like a charm and it is much faster than TinyBLM. It produces more merged lines, since it doesn't merge several consecutive ranges with different descriptions like Tiny BLM, but the speed and the command-line control are much more important. Thank you very much. Just to be sure, if I don't send any other command to peerguardian it won't be loaded and won't mess with my iptables right?


Perhaps you can also use the merge feature from iblocklist.com (for VIP members only). But I don't know if this works for you.

I'm contributing with new ranges, but I still don't have a VIP account. I guess I will get one soon, but I don't think it would be possible to make the process automatic.

Thank you very much for your help.


You can also use iplist to merge/convert lists by invoking it like

iplist --output=merged.p2p.gz --output-fmt=p2p list1.p2p list2.dat list2.p2p.gz ...

Thanks for the tip. Unfortunately, you can't install iplist and moblock at the same time.

jre
October 15th, 2008, 07:13 PM
Thanks for the tip. Unfortunately, you can't install iplist and moblock at the same time.
Yes, thanks!

iplist and moblock conflict because they would mess up the MARKing of the packets when they run at the same time.

Of course just having them installed at the same time would not cause problems, but I want to keep with the "conflicts" to prevent the MARKing problems.

The peerguardnf command that I told you is safe to use.

lovinglinux
October 17th, 2008, 10:48 PM
I'm slowly moving from mobloquer to a command-line/script setup and need some help to check if I'm doing something wrong.

Let me explain first how I'm using moblock.

1 - Instead of using the default lists from bluetack, I have a script that download several lists from different sources, extract the compressed files, clean up comment lines and typos, then append and merge specific lists into different compilation lists, with variable degrees of protection, which I call "profiles".

2 - So I have merged lists for web browsing, gaming, p2p and generic use, that can be easily enabled/disabled in moblock.

3 - I also have different /etc/default/moblock file for each profile, so I can configure them with different permissions or whatever. For example the browsing profile has WHITE_TCP_OUT="http https", while the others do not. Each profile also has the following specific files:

blocklists.list
iptables-custom-insert.sh
iptables-custom-remove.sh

I have a script for each profile, so whenever I launch them, they replace the configuration files in /etc/moblock/ directory with the ones above, so each profile end up with it's own sets of blocklists, configurations and iptable scripts.

Here is an example of a script that launch a single profile. I have included comments in the code.



#!/bin/bash

#kill mobloquer and firestarter just in case

killall mobloquer
sudo killall firestarter

#stop moblock, removing it's ipchains from the iptable

sudo moblock-control stop

#reload firestarter to restore the default iptable configuration

sudo firestarter --stop
sudo firestarter --start

#replace moblock configuration files according to the profile used

sudo cp ~/Databases/Blocklists/Config/moblock-browsing /etc/default/moblock
sudo cp ~/Databases/Blocklists/Config/blocklists-browsing.list /etc/moblock/blocklists.list
sudo cp ~/Databases/Blocklists/Config/iptables-custom-insert-browsing.sh /etc/moblock/iptables-custom-insert.sh
sudo cp ~/Databases/Blocklists/Config/iptables-custom-remove-browsing.sh /etc/moblock/iptables-custom-remove.sh

#update the allow lists from the merged blocklists directory

sudo cp ~/Databases/Blocklists/Merged/allow-out.p2p /etc/moblock/allow-out.p2p
sudo cp ~/Databases/Blocklists/Merged/allow-in.p2p /etc/moblock/allow-in.p2p
sudo cp ~/Databases/Blocklists/Merged/allow-fw.p2p /etc/moblock/allow-fw.p2p

#reload moblock to update the profile blocklists in case they have been updated

sudo moblock-control reload

#start moblock to insert it's chains and custom iptable rules

sudo moblock-control start

sleep 10 && sudo moblock-control test

#load moblock log

tail -f /var/log/moblock.log &

#launch a panel alert to notify the process is finished

zenity --text "Moblock Browsing Profile Running" --notification

#replace the desktop background with profile specific wallpaper to show which profile is running

gconftool -t string -s /desktop/gnome/background/picture_filename ~/Pictures/Wallpaper/moblock/browsing.png

Since iptables are a little bit overwhelming to me, I'm still using Firestarter to generate basic firewall rules, in which no ports are open and outgoing policy is restrictive (whitelist traffic). That's why the profile script stop and start Firestarter just after stopping moblock, so It can restore my default firewall rules.

Here are my default iptable rules, without moblock chains:

EDIT: removed iptables rules

This profile, which uses my Firestarter basic iptable configuration, allows outbound connections on ports 80, 443, 993 and 6667 only, plus local network related IP's and services. It does not allow incoming connections (except from the router IP).

When I start a profile like the one for p2p activity, it opens the necessary port in the iptables using the profile iptables-custom-insert.sh

In this case, the iptables-custom-insert.sh clears the INBOUND and OUTBOUND Firestarter chains, recreate the default rules which Firestarter would normally add, without the restrictive rules for outbound connections (change policy to permissive) and add the rules necessary to open the port for incoming connections (INBOUND chain). Here is the script:


iptables -F INBOUND
iptables -A INBOUND -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INBOUND -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INBOUND -s 192.168.x.x -j ACCEPT
iptables -A INBOUND -p tcp -m tcp --dport 49152 -j ACCEPT
iptables -A INBOUND -p udp -m udp --dport 49152 -j ACCEPT
iptables -A INBOUND -j LSI

iptables -F OUTBOUND
iptables -A OUTBOUND -p icmp -j ACCEPT
iptables -A OUTBOUND -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTBOUND -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTBOUND -d 208.107.188.17 -j LSO
iptables -A OUTBOUND -j ACCEPT

And this is the resulting iptable rules (including moblock's chains)

EDIT: removed iptables rules

Whenever I stop moblock manually, the iptables-custom-remove.sh replaces the INBOUND and OUTBOUND Firestarter chains with default values, thus restoring the restrictive outbound policy and closing any open port. If I launch another profile instead, the script will also stop moblock (iptables-custom-remove.sh will run), then stop and start Firestarter just in case something goes wrong with the iptables-custom-remove.sh and only then will copy the new moblock configuration files prior to restarting moblock with the new profile settings. Here is the iptables-custom-remove.sh scrip for the p2p profilet:


iptables -F INBOUND
iptables -A INBOUND -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INBOUND -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INBOUND -s 192.168.x.x -j ACCEPT #router internal IP
iptables -A INBOUND -j LSI

iptables -F OUTBOUND
iptables -A OUTBOUND -p icmp -j ACCEPT
iptables -A OUTBOUND -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTBOUND -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTBOUND -d 192.168.x.x -j ACCEPT #router internal IP
iptables -A OUTBOUND -d 192.168.x.x -j ACCEPT #notebook internal IP
iptables -A OUTBOUND -d xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A OUTBOUND -d xxx.xxx.x.xxx -j ACCEPT #DNS
iptables -A OUTBOUND -d 200.177.254.149 -j ACCEPT
iptables -A OUTBOUND -p tcp -m tcp --dport 80 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p udp -m udp --dport 80 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p tcp -m tcp --dport 443 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p udp -m udp --dport 443 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p tcp -m tcp --dport 993 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p udp -m udp --dport 993 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p tcp -m tcp --dport 6667 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -p udp -m udp --dport 6667 -s 192.168.x.x -j ACCEPT
iptables -A OUTBOUND -j LSO

With this setup I can easily launch a profile script from a panel launcher, thus changing the configuration of Firestarter rules, based on ports I need to open and required outbound policy. At the same time, blocklists lists will be reloaded and moblock will be restarted, inserting rules according to the profile I'm using.

The only problem is that, if I decide to change my Firestarter basic configuration (which is sometimes a temptation) I have to manually update moblock scripts to perform the necessary rules replacements when starting/stopping. Additionally, If I manually enable/disable blocklists using mobloquer GUI, the scripts won't be updated accordingly. So, to be safe I have to avoid changing Firestarter or Moblock configurations using their GUI.

I guess I could uninstall Firestarter and create the entire iptable using moblock's custom scripts right? If possible to use moblock this way, is there any rule necessary to properly handle those packets marked by moblock (not in the blocklist)?

If I decide to replicate Firestarter rules to add them to moblock's custom scripts, do I need to create INBOUND and OUTBOUND chains or INPUT and OUTPUT are enough to do the job?

I don't know much about iptables, but it seems to me that any new allowed/blocked IP or service rule added using Firestarter GUI it's only included in the OUTBOUND and INBOUND chains, so why so many rules in the INPUT and OUTPUT chains? Are all necessary?

The final question: Is it possible to configure Firestarter and then export the rules to a script so I can use it to create moblock's custom scripts?

Sorry if I'm asking things not directly related to moblock, but I guess this is the best thread to post them. If someone could review my rules and procedures to verify if I'm doing something wrong would be much appreciated.

jre
October 26th, 2008, 07:07 PM
AFAIK firestarter is simply a wrapper which inserts iptables rules (and not a permanently running daemon).

But it's definitely coorect that you first stop moblock, then replace its configuration and then start it again.

So perhaps you have some overkill in your first script but it seems correct to me.

General iptables:
Please also refer to post #1 in this thread.

INPUT and OUTPUT are the chains that are always there.

INBOUND and OUTBOUND are those created by firestarter and
moblock_in and moblock_out those by moblock-control.

E.g. incoming traffic starts at the head of INPUT and passes through the rules towards the bottom. Every rule is configured to match certain packets based on their destination/source, port, state, mark, ...

When it hits a REJECT or DROP it will be blocked forever.
When it hits ACCEPT it will be definitely accepted.
When it hits INBOUND or moblock_in it changes to these chains.
There if it hits RETURN it will go back to INPUT.
When it hits NFQUEUE it will be checked by moblock and get a MARK which marks him either to be blocked or not to be blocked. Then it will start at the head of INPUT again, now being MARKed so that its travells will take a new route.
If traffic makes it till the bottom of the line without being blocked its fate will be decided by the chain policy.

So, yes, the rules in INPUT and in INBOUND are necessary.

Please note that I did not have a datailed look of your iptables commands but it sounds good.

To allow usage of mobloquer you may copy the /etc/default/moblock and the other conf files to your profile when you stop the profile.

To avoid the insertion of the firestarter iptables rules (I think you forget those from INPUT here) you might also create firestarter configuration files for every profile and then do

profile 1 start:

firestarter stop
moblock-control stop
copy firestarter.configuration files profile1
copy moblock-control.configuration files profile1
firestarter start
moblock-control reload [no more needed for the next version moblock-control 1.1]
moblock-control start

profile 1 stop:

copy back firestarter.configuration files profile1 to your home
copy back moblock-control.configuration files profile1 to your home

I think this setup allows that you use both GUIs (after firestarter changes you have to restart moblock-control) as long as you do the "stop" to save its changes.

But I'm not common with firestarter and don't know what configuration files to use.

I hope this answers your questions, just write again if you miss something.

jre

lovinglinux
October 26th, 2008, 08:24 PM
jre, thank you very much for this detailed explanation. I have already tried to copy Firestarter configuration. It works for replacing rules, but it doesn't work when you need to change default policy. I don't know why. Anyway, I decided to uninstall Firestarter and make all iptables rules with moblock scripts.

Now, whenever I stop moblock, the "remove" script flushes the iptables, remove additional chains and set the default policy (INPUT, OUTPUT and FORWARD) to DROP, thus working like Firestarter lock feature and preventing network activity while moblock is turned off. The code is below:


iptables -F
iptables -X
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP

When I start moblock again, it will insert all rules in the INPUT/OUTPUT chains and create two new chains (INBOUND/OUTBOUND) which I use just for logging and dropping packets not accepted by the default chains. Here is the "insert" script:


iptables -N INBOUND
iptables -N OUTBOUND

iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP

iptables -A INPUT -i eth0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -s 192.168.x.x -j ACCEPT #router internal IP
iptables -A INPUT -s xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A INPUT -s xxx.xxx.x.xxx -j ACCEPT #DNS
iptables -A INPUT -i eth0 -d 255.255.255.255 -j DROP
iptables -A INPUT -d 192.168.2.255 -j DROP
iptables -A INPUT -d 224.0.0.0/8 -j DROP
iptables -A INPUT -s 224.0.0.0/8 -j DROP
iptables -A INPUT -s 255.255.255.255 -j DROP
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p icmp -j INBOUND
iptables -A INPUT -j INBOUND
iptables -A INPUT -j DROP

iptables -A FORWARD -j DROP

iptables -A OUTPUT -o eth0 -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 53 -s 192.168.x.x -d xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 53 -s 192.168.x.x -d xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 53 -s 192.168.x.x -d xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 53 -s 192.168.x.x -d xxx.xxx.x.xx -j ACCEPT #DNS
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 80 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 80 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 443 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 443 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 993 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 993 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp -m tcp --dport 6667 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp -m udp --dport 6667 -s 192.168.x.x -j ACCEPT
iptables -A OUTPUT -d 224.0.0.0/8 -j DROP
iptables -A OUTPUT -s 224.0.0.0/8 -j DROP
iptables -A OUTPUT -s 255.255.255.255 -j DROP
iptables -A OUTPUT -m state --state INVALID -j DROP
iptables -A OUTPUT -d 192.168.x.x -j ACCEPT #router internal IP
iptables -A OUTPUT -d 192.168.x.x -j ACCEPT #notebook internal IP
iptables -A OUTPUT -o lo -j ACCEPT
iptables -A OUTPUT -p icmp -j ACCEPT
iptables -A OUTPUT -j OUTBOUND
iptables -A OUTPUT -j DROP

iptables -A INBOUND -j LOG --log-prefix '*** INBOUND ***' --log-level 4
iptables -A INBOUND -j DROP

iptables -A OUTBOUND -j LOG --log-prefix '*** OUTBOUND ***' --log-level 4
iptables -A OUTBOUND -j REJECT

And here the iptables output :


Current iptables rules (this may take awhile):

Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
0 0 ACCEPT tcp -- eth0 * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- eth0 * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT all -- * * 192.168.x.x 0.0.0.0/0
0 0 ACCEPT all -- * * xxx.xxx.x.xx 0.0.0.0/0
0 0 ACCEPT all -- * * xxx.xxx.x.xxx 0.0.0.0/0
0 0 DROP all -- eth0 * 0.0.0.0/0 255.255.255.255
0 0 DROP all -- * * 0.0.0.0/0 192.168.2.255
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
1 112 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 INBOUND icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 INBOUND all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
2 168 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14
0 0 ACCEPT tcp -- * eth0 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * eth0 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * eth0 192.168.x.x xxx.xxx.x.xx tcp dpt:53
0 0 ACCEPT udp -- * eth0 192.168.x.x xxx.xxx.x.xx udp dpt:53
0 0 ACCEPT tcp -- * eth0 192.168.x.x xxx.xxx.x.xx tcp dpt:53
0 0 ACCEPT udp -- * eth0 192.168.x.x xxx.xxx.x.xx udp dpt:53
0 0 ACCEPT tcp -- * eth0 192.168.x.x 0.0.0.0/0 tcp dpt:80
0 0 ACCEPT udp -- * eth0 192.168.x.x 0.0.0.0/0 udp dpt:80
0 0 ACCEPT tcp -- * eth0 192.168.x.x 0.0.0.0/0 tcp dpt:443
0 0 ACCEPT udp -- * eth0 192.168.x.x 0.0.0.0/0 udp dpt:443
0 0 ACCEPT tcp -- * eth0 192.168.x.x 0.0.0.0/0 tcp dpt:993
0 0 ACCEPT udp -- * eth0 192.168.x.x 0.0.0.0/0 udp dpt:993
0 0 ACCEPT tcp -- * eth0 192.168.x.x 0.0.0.0/0 tcp dpt:6667
0 0 ACCEPT udp -- * eth0 192.168.x.x 0.0.0.0/0 udp dpt:6667
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 ACCEPT all -- * * 0.0.0.0/0 192.168.x.x
0 0 ACCEPT all -- * * 0.0.0.0/0 192.168.x.x
1 112 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 OUTBOUND all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain INBOUND (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4 prefix `*** INBOUND ***'
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain OUTBOUND (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4 prefix `*** OUTBOUND ***'
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- * * 192.168.x.0/24 192.168.x.0/24
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 224.0.0.22-224.0.0.22
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 224.0.0.22-224.0.0.22
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range xxx.xxx.x.xx-xxx.xxx.x.xx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range xxx.xxx.x.xx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 192.168.2.255-192.168.2.255
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 192.168.2.255-192.168.2.255
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 127.0.0.1-127.0.0.1
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 127.0.0.1-127.0.0.1
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.x.0/24 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 224.0.0.22-224.0.0.22
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 192.168.2.255-192.168.2.255
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 127.0.0.1-127.0.0.1
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
1 84 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 192.168.x.0/24
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 224.0.0.22-224.0.0.22
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range xxx.xxx.x.xxx-xxx.xxx.x.xxx
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 192.168.2.255-192.168.2.255
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 192.168.x.x-192.168.x.x
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 140.211.166.66-140.211.166.66
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 127.0.0.1-127.0.0.1
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
1 84 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* moblock is running, pid is 8071.

As far as I understand, I don't have to be concerned anymore with moblock chains being correctly inserted before the other rules, but is there any rules in my script that could conflict with moblock's marking feature?

I have another question, not related to the post above. While using the tail command to monitor moblock's log, I have noticed that sometimes moblock stops and reload itself. I receive the following message in the log.


Got SIGHUP! Dumping and resetting stats, reloading blocklist

Is this normal? I guess while doing this, moblock is letting everything to pass through...

jre
October 27th, 2008, 08:03 PM
As far as I understand, I don't have to be concerned anymore with moblock chains being correctly inserted before the other rules, but is there any rules in my script that could conflict with moblock's marking feature?
The way you do it seems correct to me.
Just don't insert any rule that MARKs packages and always have the rules that send target to the moblock chains as first ones (so you chose correct to append them (-A) and not insert (-I) them).



I have another question, not related to the post above. While using the tail command to monitor moblock's log, I have noticed that sometimes moblock stops and reload itself. I receive the following message in the log.


Got SIGHUP! Dumping and resetting stats, reloading blocklist

Is this normal? I guess while doing this, moblock is letting everything to pass through...
No it doesn't. The problem you describe is only happening on "restart" when the iptables are removed and inserted again.
You can test it yourself: Ping a IP from the blocklist (e.g. your router with setting WHITE_LOCAL="2" so that it doesn't get whitelisted).
See the answers while moblock is not running.
Then start moblock: there will be a short break until moblock is loaded fully, then you will get rejects.
Then do a reload: Again a break and afterwards rejects, but no answers of the router.

This is because traffic is always sent by the iptables rules to userspace (NFQUEUE). If noone is listening there the packets will just get DROPed, but they may never leave userspace without someone (moblock) telling them so.

lovinglinux
October 27th, 2008, 08:57 PM
The way you do it seems correct to me.
Just don't insert any rule that MARKs packages and always have the rules that send target to the moblock chains as first ones (so you chose correct to append them (-A) and not insert (-I) them).


No it doesn't. The problem you describe is only happening on "restart" when the iptables are removed and inserted again.
You can test it yourself: Ping a IP from the blocklist (e.g. your router with setting WHITE_LOCAL="2" so that it doesn't get whitelisted).
See the answers while moblock is not running.
Then start moblock: there will be a short break until moblock is loaded fully, then you will get rejects.
Then do a reload: Again a break and afterwards rejects, but no answers of the router.

This is because traffic is always sent by the iptables rules to userspace (NFQUEUE). If noone is listening there the packets will just get DROPed, but they may never leave userspace without someone (moblock) telling them so.

Thank you again. I'm less worried now, but I still don't understand why moblock is reloading the blocklists if I didn't used the reload command. Does it reload by itself on regular basis?

jre
October 28th, 2008, 06:25 PM
Thank you again. I'm less worried now, but I still don't understand why moblock is reloading the blocklists if I didn't used the reload command. Does it reload by itself on regular basis?

Oh, didn't I mention that? ;-)
This is caused by the cron job (/etc/cron.daily/moblock). Once a day the blocklsits are updated. afterwards MoBlock gets reloaded.
You can turn this automatic update off by setting in /etc/default/moblock:
MOBLOCK_CRON="0"

Still, a manual "moblock-control update" does a reload at the end, too.

skipo
October 28th, 2008, 06:47 PM
Oh, didn't I mention that? ;-)
This is caused by the cron job (/etc/cron.daily/moblock). Once a day the blocklsits are updated. afterwards MoBlock gets reloaded.
You can turn this automatic update off by setting in /etc/default/moblock:
MOBLOCK_CRON="0"


That won't turn off the daily reloading though.

lovinglinux
October 28th, 2008, 08:36 PM
That won't turn off the daily reloading though.

Yep. I have MOBLOCK_CRON="0" and it still reload.

jre
October 30th, 2008, 06:56 PM
Strange ....
Please look in /var/log/moblock-control.log what is happening at the time when moblock reloads. From moblock-control this will only happen on "update" (either manually or by the cron job) or "reload".
I'm not the author of MoBlock (the daemon). Maybe there is something built in there that reloads it frequently.

Still, whatever the reason for the reload is: I see no reason to worry, since (as shown above) the reload does not break the protection. But of course I'd like to know what's happening there, too ;-)

skipo
October 31st, 2008, 12:12 PM
Strange ....
Please look in /var/log/moblock-control.log what is happening at the time when moblock reloads. From moblock-control this will only happen on "update" (either manually or by the cron job) or "reload".
I'm not the author of MoBlock (the daemon). Maybe there is something built in there that reloads it frequently.


Moblock-control.log doesn't say anything about reloading, but moblock.log gives following statement:


Fri Oct 31 13:00:10| Got SIGHUP! Dumping and resetting stats, reloading blocklist

jre
October 31st, 2008, 04:53 PM
Well, then I have to say I have no idea why this happens.
I've never heard of it, but maybe there's a cron job sending the SIGHUP (kill -s HUP/1 PID) to all processes. If anybody can explain this ...
I'll note this down in BUGS with a link to your post.

skipo
October 31st, 2008, 07:25 PM
Well, then I have to say I have no idea why this happens.
I've never heard of it, but maybe there's a cron job sending the SIGHUP (kill -s HUP/1 PID) to all processes. If anybody can explain this ...
I'll note this down in BUGS with a link to your post.

It's the logrotate. In /etc/logrotate.d/ is a file moblock:


/var/log/moblock.log {
rotate 12
daily
compress
delaycompress
missingok
notifempty
postrotate
[ ! -f /var/run/moblock.pid ] || kill -s HUP `cat /var/run/moblock.pid`
endscript
}
Or is it moblock because it did put the file there...

lovinglinux
November 3rd, 2008, 08:29 AM
@jre,

moblock is not starting at boot on Intrepid and mobloquer is not working.

skipo
November 3rd, 2008, 10:45 AM
I'll note this down in BUGS with a link to your post.

If we are talking about bugs, sometimes this line appears in /var/log/moblock.log:


Mon Nov 3 11:25:21| NFQUEUE: unbinding from queue 0

After that, I have to restart moblock to get web working again.

I haven't changed the nfqueue number, so it should bind to the default queue, and it does after restart:


Mon Nov 3 11:33:52| NFQUEUE: binding to queue '92'

jre
November 3rd, 2008, 10:09 PM
@skipo, logrotate:
oops, I should have thought of that. Of course, after logrotation a new logfile needs to be opened, therefore the reloading. So everything is ok here. Thanks for figuring that out on your own!

@lovinglinux, intrepid problems:
first time I hear this. What's in the logfiles? Does "moblock-control start" work? What's happening if you start mobloquer from the console?

@skipo: unbinding from NFQUEUE
I changed the default NFQUEUE number to 92 (instead of 0) in moblock-control 1.0 (the current version), to avoid conflicts with other firewalls. So I don't know where the queue 0 stems from - it should always be 92.
Have you any other applications that use NFQUEUE?
Did you have the unbind in previous versions, too?
For the records: Please post "dpkg -l libnetfilter-queue* libnfnetlink*".
It might be a bug in these libraries or in moblock, which occurs only for non-default queue numbers (= not 0).

noblem
November 3rd, 2008, 11:10 PM
Re: unbinding from NFQUEUE

The error message in the code has a queue number of 0 hard coded, so it's misreporting the queue it just unbound from. I've seen the error myself, with moblock the only application using nfqueue.

If i'm understanding the code correctly, then recv() is used to read a message from kernelspace and passed to nfq_handle_packet() for parsing. The unbind error should only ever occur if the recv() returns an error which generally should never happen

After doing some more reading, recv() gets the data from netlink socket, prior to any queuing happening. The code doesn't capture the error code when this fails, but it could be due to a lack of buffer space (especially under high load). The l7 userspace filter code suggest the following;


If you get error messages about running out of buffer space, increase it with something like:

echo 524280 > /proc/sys/net/core/rmem_default
echo 524280 > /proc/sys/net/core/rmem_max
echo 524280 > /proc/sys/net/core/wmem_default
echo 524280 > /proc/sys/net/core/wmem_max

lovinglinux
November 4th, 2008, 03:59 AM
@lovinglinux, intrepid problems:
first time I hear this. What's in the logfiles? Does "moblock-control start" work? What's happening if you start mobloquer from the console?

Mea culpa! The problem was due to /etc/default/moblock permissions. I have replaced the one from fresh install with a copy and root user hasn't permission to read and write. Everything is working now.

skipo
November 4th, 2008, 10:35 AM
For the records: Please post "dpkg -l libnetfilter-queue* libnfnetlink*".
It might be a bug in these libraries or in moblock, which occurs only for non-default queue numbers (= not 0).

Here's the dpkg list:


Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Installed/Config-f/Unpacked/Failed-cfg/Half-inst/t-aWait/T-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-===================-==============-======================================
ii libnetfilter-queue1 0.0.13-1 Netfilter netlink-queue library
ii libnfnetlink0 0.0.25-1 Netfilter netlink library


I have no other applications using NFQUEUE.

noblem
November 7th, 2008, 01:48 PM
I found this article about tuning netfilter performance;
http://www.inliniac.net/blog/2008/01/23/improving-snort_inlines-nfq-performance.html

The article is aimed at snort_inline users, but the majority of it applies to moblock as well. Moblock doesn't currently allow the max queue size to be changed from the default, however I've just submitted a patch that allows this value to be tuned on the moblock developer site. The patch also fixes the misreported queue number in the error message and should hopefully print the error that caused moblock to unbind in the first place

Matt

noblem
November 14th, 2008, 02:47 PM
Just when I though I'd not seen the unbinding error on the RC of version 9, I got this after moblock did it's daily update the other morning;

Thu Nov 13 07:36:08| NFQUEUE: unbinding from queue '92', recv returned No buffer space available

So good news is my patch worked and captured the error, the bad news is when this happens moblock currently needs to be killed and restarted to bring it back to life. I've managed to replicate the issue which, for me, occurs under high load when a moblock-control restart is executed. While moblock is reloading the block files it's not processing packets and data is getting buffered, if too much data is buffered then we run out of buffer space and die.
I've managed to find another bug that occurs when this happens, moblock tries to cleanly close the queue but the shutdown messages don't work because of the lack of buffers.
I've created another patch that works around this and I've chosen to rebind the queue rather than exit, which works for me.
Interestingly while I was testing I reduced the queue size and found the issue went away, however I had lots of these errors logged;

nf_queue: full at 128 entries, dropping packets(s).

So looks like with a smaller queue size the packets are dropped by the kernel before hitting moblock rather than hitting moblock and causing it to run out of buffers

Matt

jre
November 14th, 2008, 06:23 PM
Hi noblem,

first off thanks for your intensive investigations and your patches at moblock.berlios.de!
I'm no programmer, but understand what you explain. Indeed this matches prior reports of unbinding which was fixed by only sending NEW traffic to MoBlock.
What happens if you increase the buffer size (together with your other patches)?

jre

noblem
November 14th, 2008, 09:49 PM
@jre I'm know programmer either but I understand enough of the the code to be able to figure out what it's doing and with the help of google hopefully fix it :)

Only sending new packets to moblock would certainly help as moblock would have to buffer less data and therefore would be less likely to hit the issue.I've increased the buffers significantly but still run out of space under heavy load but only reloading the block lists but with my modifications moblock now rebinds to the queue and keeps going rather than dying. I'm not convinced this is the right approach on a reload, but it works for me.

I've also come across this post (http://lists.netfilter.org/pipermail/netfilter-devel/2007-June/028164.html) on the netfilter-devel list which has a very good explanation of the causes of the issue

Sevis
November 19th, 2008, 11:58 PM
Good evening,

I'm sorry if this question was answered before, but I didn't find a clear answer on the first few pages...

Anyway, moblock seems to block all http for me, while still allowing some other connections (I'm not entirely sure which, but I can talk over MSN, for example). Here is the output of 'sudo moblock-control status':



sevis@saruman-desktop:~$ sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 499K packets, 112M bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain OUTPUT (policy ACCEPT 789K packets, 813M bytes)
pkts bytes target prot opt in out source destination
2 142 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- * * 192.168.1.0/24 192.168.1.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- * * 192.168.1.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.0.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * * 0.0.0.0/0 192.168.1.0/24
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 192.168.0.0/24
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
2 142 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* moblock is not running.


Also, please note that moblock was running at that time - at least, I had used 'sudo moblock-control start', and it was blocking http quite successfully.

In /etc/default/moblock, I have, after the autogenerated comments:



WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"
WHITE_TCP_OUT="80 8080 443"


Thank you!
Sevis

fixture
November 21st, 2008, 08:45 AM
Hi, jre, thanks for the good work.

I have a problem that seems to be universally unanswered. So, I have ubuntu hardy server on an x86 router. The router hosts a wired lan and a wireless lan. I use Shorewall to configure iptables for maquerading and firewalling. What do I have to do to get moblock for filter the traffic for the router and the lans?

If shorewall cannot be made to work with moblock easilly, what other firewall frontend should I use? Thanks,

typo99
November 21st, 2008, 10:28 PM
I'm interested to hear an answer to this also. I have the same problem with the same /etc/default/moblock setup. Can get to my lan ok, but web is blocked. Maybe something to do with adding in TBG blocklists?

*EDIT* - Took out these lines in my /etc/moblock/blocklists.list and it is working again:

tbg.iblocklist.com/Lists/PrimaryThreats.zip
tbg.iblocklist.com/Lists/GeneralCorporateRanges.zip
tbg.iblocklist.com/Lists/BusinessISPs.zip
tbg.iblocklist.com/Lists/SearchEngines.zip
tbg.iblocklist.com/Lists/Educational-Institutions.zip
tbg.iblocklist.com/Lists/Bogon.zip
tbg.iblocklist.com/Lists/Hijacked.zip

I had read the TBG lists were good to use, but I'll have to leave them out I guess.



Good evening,

I'm sorry if this question was answered before, but I didn't find a clear answer on the first few pages...

Anyway, moblock seems to block all http for me, while still allowing some other connections (I'm not entirely sure which, but I can talk over MSN, for example). Here is the output of 'sudo moblock-control status':



sevis@saruman-desktop:~$ sudo moblock-control status
Current iptables rules (this may take awhile):

Chain INPUT (policy ACCEPT 499K packets, 112M bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 moblock_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain OUTPUT (policy ACCEPT 789K packets, 813M bytes)
pkts bytes target prot opt in out source destination
2 142 moblock_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW MARK match !0x14

Chain moblock_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- * * 192.168.1.0/24 192.168.1.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa
0 0 RETURN all -- * * 192.168.1.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.0.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 MARK match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * * 0.0.0.0/0 192.168.1.0/24
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 192.168.0.0/24
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
2 142 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* moblock is not running.


Also, please note that moblock was running at that time - at least, I had used 'sudo moblock-control start', and it was blocking http quite successfully.

In /etc/default/moblock, I have, after the autogenerated comments:



WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"
WHITE_TCP_OUT="80 8080 443"


Thank you!
Sevis

Sevis
November 22nd, 2008, 01:28 PM
Hmm, I checked /etc/moblock/blocklists.list but I don't have any of those blocklists. They are custom, as far as I understand? I am using the default blocklists, to be precise:



www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz
www.bluetack.co.uk/config/bogon.gz
www.bluetack.co.uk/config/dshield.gz
#www.bluetack.co.uk/config/edu.gz
www.bluetack.co.uk/config/fornonlancomputers.gz
www.bluetack.co.uk/config/hijacked.gz
www.bluetack.co.uk/config/iana-multicast.gz
www.bluetack.co.uk/config/iana-private.gz
www.bluetack.co.uk/config/iana-reserved.gz
www.bluetack.co.uk/config/level1.gz
www.bluetack.co.uk/config/level2.gz
#www.bluetack.co.uk/config/level3.gz
www.bluetack.co.uk/config/Microsoft.gz
www.bluetack.co.uk/config/proxy.gz
#www.bluetack.co.uk/config/rangetest.gz
#www.bluetack.co.uk/config/spider.gz
#www.bluetack.co.uk/config/spyware.gz
www.bluetack.co.uk/config/templist.gz

#locallist /etc/moblock/custom-blocklist.p2p


On another note, my log file (/var/log/moblock.log) is filled with "Skipping useless range:" and then a name or title. At the end, there are quite a few lines like:


Sat Nov 22 13:17:25| OUT: IANA - Private Use [RFC1918],hits: 1,DST: 10.0.0.2

Seeing as 10.0.0.2 is my DNS, I suppose that this would be the problem - should I unblock it in my defaults file? I have the feeling this would allow everything, but I am not all too good in the area of firewalls.

Thank you,
Sevis

noblem
November 25th, 2008, 03:29 PM
@typo99 The tbg Bogon list also includes the RFC1918 private ranges so you'll probably fine you've been blocking your internal network (the moblock logs should tell you what's being blocked). You also might not necessarily need ever single blocklist loaded, unless your totally paranoid :)

@sevis Yours is likely a similar issue, however I'm not sure why your seeing it being dropped OUT, normally that would mean out to the NET where private addresses shouldn't be routed - obviously though it depends on your network setup.
In your case you probable need to remove the fornonlancomputers from your blocklist file and possibly iana-private and typo99 remove the Bogon list.

Alternatively you could try to whitelist your lan in the config file, although this didn't work for me (due to the way I'm using nat and forwarding traffic I think). I've use the IP_REMOVE option to remove my lan range, although this removed all of 192.168.x.x/16 from the blocklist, so I've created a custom blocklist covering all of 192.168.x.x except my lan range just so I'm covered

lovinglinux
November 25th, 2008, 04:33 PM
@typo99 The tbg Bogon list also includes the RFC1918 private ranges so you'll probably fine you've been blocking your internal network (the moblock logs should tell you what's being blocked). You also might not necessarily need ever single blocklist loaded, unless your totally paranoid :)

@sevis Yours is likely a similar issue, however I'm not sure why your seeing it being dropped OUT, normally that would mean out to the NET where private addresses shouldn't be routed - obviously though it depends on your network setup.
In your case you probable need to remove the fornonlancomputers from your blocklist file and possibly iana-private and typo99 remove the Bogon list.

Alternatively you could try to whitelist your lan in the config file, although this didn't work for me (due to the way I'm using nat and forwarding traffic I think). I've use the IP_REMOVE option to remove my lan range, although this removed all of 192.168.x.x/16 from the blocklist, so I've created a custom blocklist covering all of 192.168.x.x except my lan range just so I'm covered

You don't have to create a custom list without your lan ranges or remove fornonlancomputers/iana-private/Bogon lists, this is completely unnecessary. Just add the lan range to /etc/moblock/allow.p2p and you will be fine. The allow list has priority over the blocklist, so any IP included in it would not be blocked.

noblem
November 25th, 2008, 08:59 PM
The allow.p2p file may not have the desired effect as it creates iptables rules to allow traffic out to the allowed range, in from the allowed range and forwarded traffic from either a source or destination of the allowed range.

This is fine if you want to allow an host/range that's external to the local lan (which I'm guessing was the idea). If your trying to use it to allow traffic from your local lan the in and out will be backwards and all forwarded traffic will bypass moblock totally which probably isn't what you want, especially if the moblock host is doing nat for your internal network.

The WHITE_LOCAL option may work, but forwarding is still going to be a problem so removing the lan range from the blocklist is probably the safest option

lovinglinux
November 25th, 2008, 09:21 PM
The allow.p2p file may not have the desired effect as it creates iptables rules to allow traffic out to the allowed range, in from the allowed range and forwarded traffic from either a source or destination of the allowed range.

This is fine if you want to allow an host/range that's external to the local lan (which I'm guessing was the idea). If your trying to use it to allow traffic from your local lan the in and out will be backwards and all forwarded traffic will bypass moblock totally which probably isn't what you want, especially if the moblock host is doing nat for your internal network.

The WHITE_LOCAL option may work, but forwarding is still going to be a problem so removing the lan range from the blocklist is probably the safest option

That's why you can configure /etc/default/moblock with the following rules:


ALLOW_IN="$CONF_DIR/allow-in.p2p"
ALLOW_OUT="$CONF_DIR/allow-out.p2p"
ALLOW_FW="$CONF_DIR/allow-fw.p2p"

This way you can create different allow lists for INBOUND, OUTBOUND and FORWARD traffic.

BTW, the local network whitelisting feature is still experimental, so again, using the alow lists is the best way.


EDIT: I forgot to mention that the iptables rules created by the allow lists are related only to traffic marked by moblock, which means that if you want to confine traffic on local ranges to the local network, all you have to do is create iptables that allow local traffic but block external access to those ranges. This can be done manually inserting iptables rules, using a firewall manager like Firestarter or using moblock's custom scripts. This gives a lot of flexibility to control your traffic, as along as you understand how iptables works.

noblem
November 26th, 2008, 09:56 AM
@lovinglinux It sounds like your moblock-control script is creating different rules from mine and sounds like it might actually work.
I think the best advise we can give anyone would be to ensure the iptables rules are sending traffic to moblock and it's actually blocking what you expect. You don't want to inadvertently bypass moblock by excluding the wrong thing :grin:

noblem
November 26th, 2008, 02:26 PM
OK, I've now defiantly got the latest moblock-control script, from the (from package 1.0-1 for debian/sid but shouldn't be any different for any other variant). The script adds the following lines for IPs in the allow file(s)


iptables -I moblock_in -m iprange --src-range allow_range -j RETURN
iptables -I moblock_out -m iprange --dst-range allow_range -j RETURN
iptables -I moblock_fw -m iprange --dst-range allow_range - j RETURN
iptables -I moblock_fw -m iprange --src-range allow_range - j RETURN


Assuming that moblock is running on a gateway box with a LAN interface and a Internet interface, the in and out rules should work fine for traffic in/out of the LAN interface. No traffic with a LAN IP should be sent to the internet, so that's fine
However any forwarded traffic from or to the LAN will match the rules in the moblock_fw and won't even be sent to moblock.

The WHITE_LOCAL would seem the more appropriate option to use (even if experimental) but looks like it needs a bit of work.

I can't see any easy way to correctly whitelist forwarded traffic without messing around with rules in the NAT table but being a bit more selective with the blocking list is probably easier/safer

lovinglinux
November 26th, 2008, 04:23 PM
OK, I've now defiantly got the latest moblock-control script, from the (from package 1.0-1 for debian/sid but shouldn't be any different for any other variant). The script adds the following lines for IPs in the allow file(s)


iptables -I moblock_in -m iprange --src-range allow_range -j RETURN
iptables -I moblock_out -m iprange --dst-range allow_range -j RETURN
iptables -I moblock_fw -m iprange --dst-range allow_range - j RETURN
iptables -I moblock_fw -m iprange --src-range allow_range - j RETURN


Assuming that moblock is running on a gateway box with a LAN interface and a Internet interface, the in and out rules should work fine for traffic in/out of the LAN interface. No traffic with a LAN IP should be sent to the internet, so that's fine
However any forwarded traffic from or to the LAN will match the rules in the moblock_fw and won't even be sent to moblock.

The WHITE_LOCAL would seem the more appropriate option to use (even if experimental) but looks like it needs a bit of work.

I can't see any easy way to correctly whitelist forwarded traffic without messing around with rules in the NAT table but being a bit more selective with the blocking list is probably easier/safer

I don't have a gateway so my FORWARD rules are all denied. Anyway, as long as I understand, if you don't add the local ranges to allow-fw.p2p, moblock will not RETURN local traffic directed to moblock_fw chain to FORWARD chain, so traffic will be filtered as expected by moblock and no local traffic will be forwarded.

Even if the local traffic passes through moblock, you still can create FORWARD rules in the iptables to prevent local ranges traffic to be forwarded. Then, local traffic being forwarded will not be marked by moblock and will RETURN to the FORWARD iptables chain, where it will be REJECTed or DROPped.

noblem
November 27th, 2008, 12:44 PM
Adding the LAN range to the allow-fw.p2p will mean it's not passed to moblock and therefor any traffic that's being routed for the moblock host (In my case any traffic from a PC being NATed by the server running moblock) won't be protected. This is probably a bad thing and ensuring traffic passing through the forward chain is passed through moblock would be highly desirable in most cases.

Traffic entering the forward chain is going to have either a source or destination of a local LAN address and moblock checks both source and destination against the blocklist for traffic in the forward chain. This means that if your LAN range is included in the blocklist it's always going to be flagged as bad.

Obviously it's possible to add custom iptables rules to control what is or isn't blocked, but I can't think of one that will work in this case s the only option is to ensure your LAN range isn't on the blocklist.

lovinglinux
November 27th, 2008, 04:19 PM
Adding the LAN range to the allow-fw.p2p will mean it's not passed to moblock and therefor any traffic that's being routed for the moblock host (In my case any traffic from a PC being NATed by the server running moblock) won't be protected. This is probably a bad thing and ensuring traffic passing through the forward chain is passed through moblock would be highly desirable in most cases.

Traffic entering the forward chain is going to have either a source or destination of a local LAN address and moblock checks both source and destination against the blocklist for traffic in the forward chain. This means that if your LAN range is included in the blocklist it's always going to be flagged as bad.

Obviously it's possible to add custom iptables rules to control what is or isn't blocked, but I can't think of one that will work in this case s the only option is to ensure your LAN range isn't on the blocklist.

I see. I didn't know moblock check both source and destination in the forward chain.

jre
November 27th, 2008, 07:08 PM
@Sevis:
With this setup no traffic on port 80 (http) should be blocked! Your config seems to be correct.
But it seems that your MoBlock daemon was not running, perhaps it crashed. Check /var/log/moblock-control.log and /var/log/moblock.log to see why/if the daemon crashes.
Please make sure that the daemon is running. Then check in /var/log/moblock.log if MoBlock is really blocking the sites that you want to access.
... I just read your next post:

At the end, there are quite a few lines like:


Sat Nov 22 13:17:25| OUT: IANA - Private Use [RFC1918],hits: 1,DST: 10.0.0.2

Seeing as 10.0.0.2 is my DNS, I suppose that this would be the problem - should I unblock it in my defaults file? I have the feeling this would allow everything, but I am not all too good in the area of firewalls.
I think your right. Just use

WHITE_IP_OUT="10.0.0.2".

@lovinglinux and noblem:
Great to have you here! I think you came to the correct conclusions. I've already thiought much about FORWARD, but I don't use it so I could never test it. But you are right (Other readers be careful, this relates only to FORWARD (Moblock is running on a router):

Don't use the allowlist or WHITE_IP_FORWARD to whitelist LAN traffic. This would allow all traffic.
The automatical whitelisting will whitelist the LAN for FORWARD in other ways: Only traffic with source AND destination in the LAN gets whitelisted here. This solves the above problem, but:
... still leaves you with all forwarded traffic from/to the internet being blocked. So probably it's indeed the best thing to just remove the LAN range, as noblem said.


@Sevis:

On another note, my log file (/var/log/moblock.log) is filled with "Skipping useless range:" and then a name or title.
That's normal. It's a result of the merging of several blocklists.

Unrelated comment: You added this to whitelist your LAN:

WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"
But the automatic whitelisting chose 192.168.1.0/24
So your entries seem both unnecessary and incorrect.


@typo99:
LAN-access-problems have nothing to do with the TBG blocklists. The old default bluetack blocklists had the LAN blocked, too. This is why whitelisting the LAN is necessary, but this happens automatically per default.

@fixture:
This is in the documentation (in short words: just make sure MoBlock is started after shorewall and gets restarted after any shorewall change.):

Since version 0.9, MoBlock no longer conflicts with other firewalls. Make sure
the following three conditions hold:
- MoBlock marks non-matched (IP is not in the blocklist)
packets. (The marking feature is on per default. It
will be explained and asked for later.)
- Other firewalls do not mark packets.
- MoBlock is started after other firewalls. If other
firewalls are started/reloaded after MoBlock, then you
need to restart MoBlock again. You will be fine, if the
iptables rules which send traffic to MoBlock's iptables
chains (moblock_in, moblock_out and moblock_fw) stand
before all other iptables rules which ACCEPT traffic.

You can check your iptables rules with
iptables -L -nv
or
moblock-control status.

Sevis
November 27th, 2008, 11:57 PM
I\'m sorry for the late reply, but it seems to work very well, thank you! Didn\'t even need to allow MSN separately, worked well enough without it :);

moore.bryan
November 28th, 2008, 09:12 PM
sorry if this has already been handled, but are the bluetack lists down? i can't seem to update...

jre
December 1st, 2008, 10:47 PM
sorry if this has already been handled, but are the bluetack lists down? i can't seem to update...

What do you have in your /etc/moblock/blocklists.list?

The lists from bluetack are indeed partly down, atm. See http://www.bluetack.co.uk/forums/index.php

I'm working on a release which allows php redirects. Then all lists by iblocklist will be supported and I'll change default lists to TBG instead of bluetack.
In the meantime you can use the lists from http://tbg.iblocklist.com/Lists or just wait until the bluetack lists are updated again.

@Sevis: Glad to hear.

nidya
December 6th, 2008, 07:02 PM
Hey, I just wanted to know why Moblock and Mobloquer are not listed in the Synaptic Package Manager. I use Ubuntu 8.10 64 Bit Alternate Version (I need RAID support). The installation process would have been much painless :D ... I just can't get used with this terminal stuff. Windows screwed my head I guess...


Btw Mobloquer seems to not work well with custom themes for Ubuntu. It's all black for me. I mean everything is black, though I can read the written stuff and see some borders...

moore.bryan
December 7th, 2008, 02:55 AM
What do you have in your /etc/moblock/blocklists.list?

The lists from bluetack are indeed partly down, atm. See http://www.bluetack.co.uk/forums/index.php

I'm working on a release which allows php redirects. Then all lists by iblocklist will be supported and I'll change default lists to TBG instead of bluetack.
In the meantime you can use the lists from http://tbg.iblocklist.com/Lists or just wait until the bluetack lists are updated again.
thanks for the info... how exactly would i set-up moblock to use the tbq lists instead of bluetack? i tried simply replacing the bluetack with those from tbq in blocklists.list, but i get an error in mobloquer about not being able to find bluetack.

jre
December 7th, 2008, 12:12 PM
Hey, I just wanted to know why Moblock and Mobloquer are not listed in the Synaptic Package Manager.

I created the packages moblock, moblock-control and mobloquer personally. I'm no Ubuntu or Debian developer and have not tried to add my packages to the official repositories. If I would do so I would prefer the Debian repo, because this means they will get to Ubuntu automatically.

Although I put no efforts to this topic, there's already a "request for packaging" here: https://bugs.launchpad.net/ubuntu/+bug/109822

Further please remember that using this software will always be more then just installing it. You can run in serious network problems, if you don't remember that MoBlock might just be blocking big parts of your internet access.


Btw Mobloquer seems to not work well with custom themes for Ubuntu. It's all black for me. I mean everything is black, though I can read the written stuff and see some borders...

The creator of mobloquer unfortunately had to stop his development efforts, due to personal time restraints. I'll note your report down, but can't promise anything ...


thanks for the info... how exactly would i set-up moblock to use the tbq lists instead of bluetack? i tried simply replacing the bluetack with those from tbq in blocklists.list, but i get an error in mobloquer about not being able to find bluetack.


Thanks for reporting this. This origins from a check if the update server is accessible at all, which is executed before the updating. So add to your /etc/default/moblock:

TESTHOST="iblocklist.com"

Seems as if I have to make a minor update today to reflect these changes.

EDIT: Done. I released a version (1.1-1) which uses tbg.iblocklist.com URLs and also has the new TESTHOST. Funnily, since today bluetack has a new server again.

dbzkid
December 9th, 2008, 11:24 AM
Ive installed moblock and i whitelisted my lan, but here is tyhe deal im useing cablevision as my isp and moblock keeps blocking that ip and also blocks microsoft (for msn in pidgin) and i was wondering if it was ok to whitelist the ip for my isp and the msn ip? because if i leave it it wont let me go on the internet but if i whitelist it it will let me go on the internet like websurfing ect. thanks

lovinglinux
December 9th, 2008, 03:13 PM
Ive installed moblock and i whitelisted my lan, but here is tyhe deal im useing cablevision as my isp and moblock keeps blocking that ip and also blocks microsoft (for msn in pidgin) and i was wondering if it was ok to whitelist the ip for my isp and the msn ip? because if i leave it it wont let me go on the internet but if i whitelist it it will let me go on the internet like websurfing ect. thanks

It's OK to whitelist both Ips.

Bobomonkey
December 14th, 2008, 03:34 AM
I'm having a slight issue getting adding the gpg key to the apt key ring.


--keyserver wwwkeys.eu.pgp.net --recv 9072870B
gpg: requesting key 9072870B from hkp server wwwkeys.eu.pgp.net
gpg: can't open `/home/bobo/.gnupg/pubring.gpg'
gpg: keydb_get_keyblock failed: eof
gpg: no writable keyring found: eof
gpg: error reading `[stream]': general error
gpg: Total number processed: 0


If anyone could help me figure out what is causing this and a way to fix it that would be awesome and much appreciated.

jre
December 14th, 2008, 05:28 PM
I'm having a slight issue getting adding the gpg key to the apt key ring.
I'm not very common with this, but what command did you issue?
This should work:

gpg --keyserver wwwkeys.eu.pgp.net --recv 9072870B
gpg --export --armor 9072870B | sudo apt-key add -

unf4b1x
December 18th, 2008, 09:28 PM
I'd like to post this here since this is the "General Moblock thread."

The installation of moblock went fine up until when the package configuration pops up inside the terminal. I mean there is no other menus or buttons except this "<Ok>", how dyou get out from that??? Because if I do <ESC> the installation seems to backtrack and produces these errors:



dpkg: error processing moblock-control (--configure):
subprocess post-installation script returned error exit status 10
...
...
Errors were encountered while processing:
moblock-control
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
...
dpkg: error processing moblock-control (--configure):
subprocess post-installation script returned error exit status 10
Errors were encountered while processing:
moblock-control
...

.. and then tries to recover, then pops up the package configuration window again. (but since I don't know any other exit commands, and the OK button seems isnt working..), I guess if only I could close down the package configuration window normally, maybe it won't produce any errors.

jre
December 18th, 2008, 09:49 PM
Just press the "OK".

This is a so called "debconf" question. If your debconf interface doesn't support your mouse you have to use your keyboard: hit the "TAB" key until "OK" is highlighted and then press "RETURN".

You may also do a "sudo dpkg-reconfigure debconf" and select "Gnome" as your interface. Then you can use your mouse for debconf questions.

Super Jamie
December 19th, 2008, 12:52 AM
you might want to add a bit to the wiki page about portforwards, there's no mention of the WHITE_TCP_IN= option, which i needed to add to /etc/default/moblock to get my hosted webpages (ntop and webmin), ftpd and sshd working again, as well as torrent ports, which is the whole point of moblock anyway, right?



cat /etc/default/moblock
# moblock.default - default configuration file for moblock-control

# In this file you can put any configuration variable from moblock.conf
# (/etc/moblock/moblock.conf). Values in moblock.conf will be overwritten by
# values in this file (moblock.default).

# Do a "moblock-control restart" when you have edited this file.
WHITE_TCP_OUT="1:65535"
WHITE_TCP_IN="20-22 3000 10000 20000:20009"
WHITE_IP_IN="20x.x.x.x/29"
WHITE_IP_OUT="20x.x.x.x/29"


also, by default, moblock seems to assume your subnet mask is /24, and whitelists that as the local lan. not so much a problem if you're on a smaller subnet like my /29, but perhaps an issue if you're on a larger subnet like a /23 or /16. i guess that's an upstream bug

Zeikcied
December 19th, 2008, 02:34 AM
I'm having a bit of a problem. I know this isn't necessarily a Moblock issue as much as it is a block list problem, though.

Recently, I'm guessing since the switch to the new lists, I've been unable to connect to any ed2k servers using MLDonkey. I believe I tried aMule, and got similar results.

It almost seems like every ed2k server on my servers list (both programs, even) is blocked or not responding. I've noticed that, in the console window in MLDonkey (or in my case KMLDonkey), some servers are saying that my port is not responding, even though I've made no changes in port fowarding (I checked and the port is properly forwarded).

Since I don't think this is a Moblock issue (more a block list issue), I doubt I'll get much help. It's just a bit of an annoyance and I'm hoping for some advice either way.

unf4b1x
December 19th, 2008, 05:04 AM
Just press the "OK".

This is a so called "debconf" question. If your debconf interface doesn't support your mouse you have to use your keyboard: hit the "TAB" key until "OK" is highlighted and then press "RETURN".

You may also do a "sudo dpkg-reconfigure debconf" and select "Gnome" as your interface. Then you can use your mouse for debconf questions.

Thanks a lot. It works fine now.

Btw, as I was reinstalling it again,
1. Would it work fine too if I would install Mobloquer also?
2. Wouldn't there be any conflicts?
3. Having to use Mobloquer, does it integrate to iptables as well as Moblock?
4. Are there any security issues that I should know about Moblock? Or could you direct me to what site I should be reading?

Anyways, more power!

lovinglinux
December 19th, 2008, 07:51 AM
Thanks a lot. It works fine now.

Btw, as I was reinstalling it again,
1. Would it work fine too if I would install Mobloquer also?
2. Wouldn't there be any conflicts?
3. Having to use Mobloquer, does it integrate to iptables as well as Moblock?
4. Are there any security issues that I should know about Moblock? Or could you direct me to what site I should be reading?

Anyways, more power!

Short answers:

1.yes
2.no
3.no
4. start it after firewall managers

Long answers:

1+2. Mobloquer is just a GUI to control/manage moblock-control functions and settings. It was designed to be installed with moblock and can't work alone. Nevertheless, you can use and control moblock without mobloquer using commands.

3. Moblock add it's rules (ip filtering) to the iptables and it also has custom scripts for adding regular customized rules. But mobloquer does not provide an iptables manager GUI like Firestarter or Gufw. You can add your rules to the custom scripts and moblock will run them when stopping and starting, even if you don't have mobloquer installed. If you don't need to change the iptables rules frequently, you can get rid of Firestarter and use only moblock scripts. That works pretty fine.

4. Not that I'm aware of, but I'm not a security expert. If you use a firewall manager like Firestarter, you need to start it before moblock, otherwise it will override moblock's rules. You can learn more about it here (http://moblock-deb.sourceforge.net/) and here (http://mobloquer.foutrelis.com/).


I'm having a bit of a problem. I know this isn't necessarily a Moblock issue as much as it is a block list problem, though.

Recently, I'm guessing since the switch to the new lists, I've been unable to connect to any ed2k servers using MLDonkey. I believe I tried aMule, and got similar results.

It almost seems like every ed2k server on my servers list (both programs, even) is blocked or not responding. I've noticed that, in the console window in MLDonkey (or in my case KMLDonkey), some servers are saying that my port is not responding, even though I've made no changes in port fowarding (I checked and the port is properly forwarded).

Since I don't think this is a Moblock issue (more a block list issue), I doubt I'll get much help. It's just a bit of an annoyance and I'm hoping for some advice either way.

Run this command
tail -f /var/log/moblock.log or use the mobloquer logging feature to pinpoint which IP address is blocked when you try to connect to the server, then add this IP to your "/etc/moblock/allow.p2p" file or use the whitelist feature of mobloquer GUI.


you might want to add a bit to the wiki page about portforwards, there's no mention of the WHITE_TCP_IN= option, which i needed to add to /etc/default/moblock to get my hosted webpages (ntop and webmin), ftpd and sshd working again, as well as torrent ports, which is the whole point of moblock anyway, right?



cat /etc/default/moblock
# moblock.default - default configuration file for moblock-control

# In this file you can put any configuration variable from moblock.conf
# (/etc/moblock/moblock.conf). Values in moblock.conf will be overwritten by
# values in this file (moblock.default).

# Do a "moblock-control restart" when you have edited this file.
WHITE_TCP_OUT="1:65535"
WHITE_TCP_IN="20-22 3000 10000 20000:20009"
WHITE_IP_IN="20x.x.x.x/29"
WHITE_IP_OUT="20x.x.x.x/29"


also, by default, moblock seems to assume your subnet mask is /24, and whitelists that as the local lan. not so much a problem if you're on a smaller subnet like my /29, but perhaps an issue if you're on a larger subnet like a /23 or /16. i guess that's an upstream bug

I'm afraid that using "1:65535" in the WHITE_TCP_OUT will make moblock ignore all outgoing traffic. If you are using it for p2p, then this is really bad, because your client will be able to connect to peers blocked by the ip lists if the connection is requested by your client. It will block incoming connections but not outgoing.

You don't need to allow any outgoing or incoming ports to use p2p, because moblock will filter IP's and not ports. If you allow a port, then it will be completely ignored by the filter, regardless of the IP source or destination. If you are having trouble to connect to peers, then you should consider using less blocklists, not whitelisting ports.

If you access your machine with ssh from remote machines outside your LAN, then you can allow only the IP's of those machines instead of allowing the port. Unfortunately, this is not feasible if the remote machines have dynamic IP's.

jre
December 19th, 2008, 05:13 PM
you might want to add a bit to the wiki page about portforwards, there's no mention of the WHITE_TCP_IN= option, which i needed to add to /etc/default/moblock to get my hosted webpages (ntop and webmin), ftpd and sshd working again, as well as torrent ports, which is the whole point of moblock anyway, right
First off, feel free to edit the wiki yourself, I would really appreciate this (I'm terribly short on time, currently)! Don't worry to write anything wrong - I'm notified of all changes, so I can correct things ...
Indeed WHITE_TCP_IN might be added as a separate question to the wiki page.
But the torrent ports must not be added! It's (one of) the point(s) of MoBlock to check exactly this traffic!

EDIT: Just had a closer look at your whitelisted ports: lovinglinux is right, you are whitelisting much too many ports. Allowing all traffic on OUT will most probably not be what you want.


also, by default, moblock seems to assume your subnet mask is /24, and whitelists that as the local lan. not so much a problem if you're on a smaller subnet like my /29, but perhaps an issue if you're on a larger subnet like a /23 or /16. i guess that's an upstream bug

This is a matter of moblock-control, so in this case I am upstream. I'll think about a solution for this. Until then, I recommend to manually whitelist the LAN (either via /etc/moblock/allow.p2p or the WHITE_IP_... variables).

Thanks
jre

Just_a_man
December 29th, 2008, 09:43 AM
Hi

i did install moblock and it works just fine if i remember restart it always when i play whit the firewall.

And my promblem is that can you put a start up script in firestarter firewall so if it restarts/makes changes to it's firewall it restarts moblock.

or can you just take the iptable commands out of the moblock and use pre-firewall for cleaning the traffic

This is little bit a firestarter problem but it will help hundreds absent-minded persons who uses moblock.

astarmathsandphysics
January 1st, 2009, 12:32 AM
I have a problem with moblock. It didn't install properly and now I can't install or uninstall any programs. I get this message.

E: dpkg was interrupted, you must manually run 'dpkg --configure -a' to correct the problem.
E: _cache->open() failed, please report.


When I type dpkg --configure -a into a terminal I opens the moblock screen and I can't work out how to configure or uninstall it. Any offers?

jre
January 1st, 2009, 05:38 PM
When I type dpkg --configure -a into a terminal I opens the moblock screen and I can't work out how to configure or uninstall it. Any offers?


Quoting https://help.ubuntu.com/community/MoBlock#I%20tried%20to%20install%20MoBlock%20but%2 0I%27m%20stuck%20on%20a%20screen%20with%20a%20Mobl ock%20warning


I tried to install MoBlock but I'm stuck on a screen with a Moblock warning

This is a so called "debconf" question. Read the text and confirm by pressing "OK". If your debconf interface doesn't support your mouse, then you have to use your keyboard: hit the "TAB" key until "OK" is highlighted and then press "RETURN".



@Just_a_man: I'm not common with firestarter. but if someone has a solution I'd be glad to spread the word :-)
Both ways that you describe would be nice. I'd prefer the one with an automatic "moblock-control restart"

jre
January 5th, 2009, 04:31 PM
also, by default, moblock seems to assume your subnet mask is /24, and whitelists that as the local lan. not so much a problem if you're on a smaller subnet like my /29, but perhaps an issue if you're on a larger subnet like a /23 or /16. i guess that's an upstream bug

I've just fixed that. The subnetmask gets detected automatically now, too. It's already in the svn repository. I'll release the new moblock-control 1.2 soon.

feistybird
January 9th, 2009, 05:25 AM
Hi,

My moblock suddenly blocks all my internet traffic, and I've tried various workarounds mentioned in the Ubuntu Help page, and this thread, but still no luck:

My platform: Ubuntu 8.10

Kernel: Custom Kernel 2.6.27.10 (but used to work fine with moblock)

Firewall Settings : NONE (ufw is not loaded)

Moblock Version:
moblock_0.9~rc2-21+intrepid_i386
moblock-control_1.1-1+intrepid_i386

My /etc/defaults/moblock settings are as follows:
(My LAN ip is 192.168.0.x)


WHITE_TCP_OUT="80 443 1863 22"
WHITE_TCP_IN="22"
WHITE_IP_IN="192.168.0.0/24"
WHITE_IP_OUT="192.168.0.0/24"

My /etc/moblock/allow.p2p is as follows:


192.168.0.1-192.168.0.255

My p2p applications are running properly as I can see usual upload/download status, but my moblock doesn't seem to follow the rules given in the /etc/defaults/moblock.

If I ping www.google.com, it returns: unknown host www.google.com, it only responses after the moblock is turned off

I've even disabled *ALL the lists* written in the /etc/moblock/blocklists.list, and did a moblock-control update && moblock-control restart, still the same, all my internet traffic are still blocked.


sudo moblock-control test

Trying to ping 4.2.144.95 from /etc/moblock/guarding.p2p ...
* MoBlock marked the IP to be blocked and the IP did not answer. Test succeeded.

tail -f /var/log/moblock.log shows that moblock is still doing it's job, ie. :


Fri Jan 9 11:41:24| IN: Beijing Teletron Telecom Engineering Co., Ltd.,hits: 12,SRC: 124.207.144.194
Fri Jan 9 11:41:24| IN: China Digital Kingdom Technology Co.,Ltd,hits: 9,SRC: 60.247.1.87
Fri Jan 9 11:41:24| OUT: TELEFONICA DE ESPANA,hits: 12,DST: 88.5.247.177

However, /var/log/moblock-control.log seems to have some errors:


CST Begin: moblock-control restart
Deleting iptables ...iptables v1.4.0: Couldn't load target `moblock_in':/lib/iptables/libipt_moblock_in.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables v1.4.0: Couldn't load target `moblock_out':/lib/iptables/libipt_moblock_out.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables v1.4.0: Couldn't load target `moblock_fw':/lib/iptables/libipt_moblock_fw.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
[fail]
* There occured some errors during the deletion of the iptables rules.
* The most common reason for this is that they did not exist, because MoBlock
* was not running. In this case you don't have to worry.
* But if MoBlock was running there is some problem. Most probably you have
* installed another firewall application that did delete the iptables rules.
* A "moblock-control restart" will then fix the situation.
Executing /etc/moblock/iptables-custom-remove.sh ... [ OK ]
Stopping MoBlock ... [ OK ]
Inserting iptables ... [ OK ]
Executing /etc/moblock/iptables-custom-insert.sh ... [ OK ]
Starting MoBlock ... [ OK ]


Can anyone please help me?

Thanks!
---

SOLVED --- PUT MY DNS SERVER'S IP INTO /etc/moblock/allow.p2p AND IT STARTS TO WORK!

Perhaps the recent blocklist update from tbg.iblocklist.com have included my DNS IP for some reason....

jre
January 9th, 2009, 07:03 PM
I just released moblock-control 1.2.


New handling of blocklists:

php redirects are supported now. This allows to use the lists from iblocklist.com. All lists are downloaded from there per default now.
Since moblock-control 1.1 the default blocklists are by "The Blocklist Group" (tbg.iblocklist.com) instead of Bluetack (bluetack.co.uk).
The single blocklists are saved in new places now (but still under /var/spool/moblock/.
The master blocklist (e.g. guarding.p2p) is now saved in /var/lib/moblock/ instead of /etc/moblock/.
Several changes to make sure that the master blocklist exists and reflects the configuration. All changes are always applied on "start" now.
The (Debian) installation only requires the blocklists (and therefore network access) to be available, if the automatic start (init) is configured.

Per default allow.p2p is not used for forwarded traffic.
Dropped support for Ubuntu Feisty, as this is no more supported by Ubuntu since October 19th, 2008.


Find a detailed list of all changes in the changelog (http://moblock-deb.svn.sourceforge.net/viewvc/moblock-deb/moblock-control/moblock-control/debian/changelog) .

Feedback is very welcome!

Have fun!
jre


@feistybird: Glad to hear you solved it on your own. BTW, this was an excellent report giving much information! Don't worry about the errors in /var/log/moblock-control.log, they just result from trying to delete already deleted iptables rules.

darkcrawler
January 10th, 2009, 01:18 AM
Hi
I upgraded to moblock-control 1.2, from the first test it seems to work good on my intrpid, specially i found very useful the php redirect support!
For the moment there's only one preoblem for me:
Using moblquer, instead of "currently blocking xxx IP ranges" i have "currently blocking an unknown number of IP ranges".. I tried even lists update, turning off/on mobloquer but nothig changes.. Any suggestions?
Thanks

jre
January 10th, 2009, 01:27 PM
Thanks for the feedback.


For the moment there's only one preoblem for me:
Using moblquer, instead of "currently blocking xxx IP ranges" i have "currently blocking an unknown number of IP ranges".. I tried even lists update, turning off/on mobloquer but nothig changes.. Any suggestions?

I hadn't noticed it, but this happens here, too. I don't know why. AFAIK mobloquer gets this number from moblock.log, which is produced by the moblock daemon, which is part of the moblock package and not of moblock-control. So there should not be any regressions here. But obviously there is a problem.

Currently I am working on a new moblock version with some patches that I received, which would break mobloquer - but I doubt that my experiments sneaked to your machine.

Just to be sure, what's the output of

dpkg -l moblock mobloquer

darkcrawler
January 10th, 2009, 02:19 PM
Here's the output;

xxx@xxx-desktop:~$ dpkg -l moblock mobloquer
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Nome Versione Descrizione
+++-==============-==============-============================================
ii moblock 0.9~rc2-21+int An IP blocker for Linux
ii mobloquer 0.5-2+intrepid GUI for MoBlock, an IP blocker for Linux
xxx@xxx-desktop:~$


I trust you that the number of blocked IPs is produced by moblock-daemon, infact it's strange
that with the previous version of moblock-control there was no problem about the number of blockd IPs in mobloquer..

jre
January 10th, 2009, 02:32 PM
Until I find the error you can still check /var/log/moblock.log - this is what really matters.
Here's mine:

Sat Jan 10 14:27:36| * Ranges loaded: 448182
Sat Jan 10 14:27:36| * Merged ranges: 6695
Sat Jan 10 14:27:36| * Skipped useless ranges: 2770
Sat Jan 10 14:27:36| NFQUEUE: binding to queue '92'

darkcrawler
January 10th, 2009, 02:42 PM
Until I find the error you can still check /var/log/moblock.log - this is what really matters.
Here's mine:

Sat Jan 10 14:27:36| * Ranges loaded: 448182
Sat Jan 10 14:27:36| * Merged ranges: 6695
Sat Jan 10 14:27:36| * Skipped useless ranges: 2770
Sat Jan 10 14:27:36| NFQUEUE: binding to queue '92'

Sorry but, how can i get this output?

jre
January 10th, 2009, 03:45 PM
Just search the /var/log/moblock.log. These lines will appear after starting/reloading MoBlock (after quite a bunch of "Skipping ..." lines) and before the actually blocked IPs.
Follow this file live with

tail -f /var/log/moblock.log. You can stop watching it by pressing the keys "control" + "c".

Or just open it (statically) in an editor, or with "less /var/log/moblock.log"

lovinglinux
January 10th, 2009, 07:12 PM
I also have this issue with "currently blocking an unknown number of IP ranges" in mobloquer. But this is not exactly an issue for me because I monitor moblock's activity in the terminal and everything is fine there.

jre
January 11th, 2009, 06:47 PM
You can workaround the "currently blocking an unknown number of IP ranges" in mobloquer by disabling the timestamping in MoBlock's logfile. Set in /etc/default/moblock:

LOG_TIMESTAMP="0"

The bug resulted, because I changed moblock-control, so that the "timestamp" option is the first option that the moblock daemon is started with. Therefore the timestamp is now also shown in the Ranges line in /var/log/moblock.log. Unfortunately mobloquer can't cope with this. I'll try to fix mobloquer and release a new version.

BTW: I'm going to package the current svn development code of mobloquer, instead of the last stable release 0.5. Further I'll try to fix some issues, however I'm no programmer and can't continue the development. So mobloquer still lacks an active developer, since the current had to step down because of real life time restrictions. If anyone is interested, or has some patches, just contact me.

darkcrawler
January 11th, 2009, 11:37 PM
Very good, i tried to disable the timestamping and now mobloquer shows the number blocked IP ranges!

However i checked /var/log/moblock.log before changing the timestamping and everything was fine.

ATM with this little issue solved i can say that the new moblock-control version works good for me.

Thanks!

iamnotthemessiah
January 20th, 2009, 11:05 PM
sorry for the stupid question but what is the advantage of the tbg.iblocklist.com blocklists? whats the difference?

jre
January 21st, 2009, 11:25 PM
sorry for the stupid question but what is the advantage of the tbg.iblocklist.com blocklists? whats the difference?

I changed from bluetack to TBG, because most of the list maintainers went from bluetack and founded TBG. So I guess its better maintained, but I have no objective reasons for this. Everybody feel free to discuss.
See http://forums.phoenixlabs.org/showthread.php?t=17291

Independent of this I now use the iblocklist.com links. iblocklist mirrors both, TBG and Bluetack lists.

Also have a look at /usr/share/doc/moblock-control/README.blocklists.

iamnotthemessiah
January 22nd, 2009, 05:55 PM
jre, thanks for the reply.

i have a couple of more questions
one is bothering me a bit in the past i had to add nrk (norwegian broadcaster) to the whitelist cos i wanted to watch web streams. without the ips whitelisted it would not work. now today i installed the latest moblock and for the first time tried mobloquer and nothing in hte whitelist and when i try to run the stream ( mms://straumV.nrk.no/nrk_tv_webvid03_h - i dont think this stream will work outside norweay) i get an entry saying its been blocked in the mobloquer log tab, yet the stream loads in vlc with no problems. how could that be? the only explanation i can think of is that it after the initial attempt being blocked it reverts to using http ports or something

secondly. is the search engine blocklist important? i had to remove it cos it blocks both msn, gtalk and icq, sure i could add each individual ip but it seems icq connects to a different ip each time in a huge range

thirdly i guess ur not the mobloquer maintainer but the obscured listnames in the blocklists tab is a bit annoying, it was hard to identify the search engine one so i could remove it

also im wondering, mobloquer says 319299 blocked ranges while 'tail -f --lines=100 /var/log/moblock.log' says 449026

jre
January 22nd, 2009, 07:03 PM
one is bothering me a bit in the past i had to add nrk (norwegian broadcaster) to the whitelist cos i wanted to watch web streams. without the ips whitelisted it would not work. now today i installed the latest moblock and for the first time tried mobloquer and nothing in hte whitelist and when i try to run the stream ( mms://straumV.nrk.no/nrk_tv_webvid03_h - i dont think this stream will work outside norweay) i get an entry saying its been blocked in the mobloquer log tab, yet the stream loads in vlc with no problems. how could that be? the only explanation i can think of is that it after the initial attempt being blocked it reverts to using http ports or something
It might be a whitelisted port or an alternative IP which is not blocked. To be sure you might use "wireshark" to inspect your packets.


secondly. is the search engine blocklist important? i had to remove it cos it blocks both msn, gtalk and icq, sure i could add each individual ip but it seems icq connects to a different ip each time in a huge range
The current default setting might be too paranoid for some people, and indeed I'm thinking of taking a lower default setup. This would include removing the Search Engines list.
But important is what you want. I can only advise to read /usr/share/doc/moblock-control/README.blocklists.gz.


thirdly i guess ur not the mobloquer maintainer but the obscured listnames in the blocklists tab is a bit annoying, it was hard to identify the search engine one so i could remove it
I'm the maintainer of the Debian packages, and upstream is no more :-/
C++ coders are welcome to help.
I intend to make some minor changes to mobloquer, but I doubt that I can change the obscured list names. They are a result of the changes I made for moblock-control (iblocklist.com php URLs). I understand that this is uncomfortable, but I want to stay with the current URLs.



also im wondering, mobloquer says 319299 blocked ranges while 'tail -f --lines=100 /var/log/moblock.log' says 449026
hmm, don't know - here they are exactly the same. And AFAIK mobloquer simply reads that number from moblock.log. Please check again. I guess the number you saw in moblock.log was outdated. To make sure restart moblock-control and mobloquer and check the logfile beginning with the last line.

astarmathsandphysics
January 28th, 2009, 08:06 AM
Quoting https://help.ubuntu.com/community/MoBlock#I%20tried%20to%20install%20MoBlock%20but%2 0I%27m%20stuck%20on%20a%20screen%20with%20a%20Mobl ock%20warning


I tried to install MoBlock but I'm stuck on a screen with a Moblock warning

This is a so called "debconf" question. Read the text and confirm by pressing "OK". If your debconf interface doesn't support your mouse, then you have to use your keyboard: hit the "TAB" key until "OK" is highlighted and then press "RETURN".



@Just_a_man: I'm not common with firestarter. but if someone has a solution I'd be glad to spread the word :-)
Both ways that you describe would be nice. I'd prefer the one with an automatic "moblock-control restart"

Where are my logfiles?

astarmathsandphysics
January 28th, 2009, 08:09 AM
I think this is my moblock logfile


2009-01-27 07:35:36 AM GMT Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gz * . No update available.
Updating bogon.gz ...done.
Updating dshield.gz ...done.
Updating fornonlancomputers.gz ...done.
Updating hijacked.gz ...done.
Updating iana-multicast.gz ...done.
Updating iana-private.gz ...done.
Updating iana-reserved.gz ...done.
Updating level1.gz ...done.
Updating level2.gz ...done.
Updating Microsoft.gz ...done.
Updating proxy.gz ...done.
Updating templist.gz * . No update available.
* Blocklists updated.
Building blocklist ...done.
Installing blocklist to /etc/moblock/guarding.p2p ...done.
* MoBlock is not running, doing nothing.
2009-01-27 07:37:01 AM GMT End: moblock-control update

jre
January 28th, 2009, 03:13 PM
MoBlock logfile: /var/log/moblock.log
moblock-control lockfile: /var/log/moblock-control.log

And please have a look at my signature: Post logfiles in CODE tags, always!

astarmathsandphysics
February 1st, 2009, 10:29 PM
2009-01-20 08:53:35 GMT Begin: moblock-control update
Updating blocklists ...
Updating ads-trackers-and-bad-pr0n.gz * . No update available.
Updating bogon.gz
[ OK ]
Updating dshield.gz
[ OK ]
Updating fornonlancomputers.gz
[ OK ]
Updating hijacked.gz
[ OK ]
Updating iana-multicast.gz
[ OK ]
Updating iana-private.gz
[ OK ]
Updating iana-reserved.gz
[ OK ]
Updating level1.gz * . No update available.
Updating level2.gz
[ OK ]
Updating Microsoft.gz
[ OK ]
Updating proxy.gz * . No update available.
Updating templist.gz * . No update available.
* Blocklists updated.
Building blocklist
[ OK ]
Installing blocklist to /etc/moblock/guarding.p2p
[ OK ]
* MoBlock is not running, doing nothing.
2009-01-20 08:54:25 GMT End: moblock-control update


Like this?
There are no mobloack.log files

The above is from the latest moblock.control.log file

jre
February 2nd, 2009, 06:03 PM
Like this?
Yes.



There are no mobloack.log files

If moblock was never running there will be no logfile. Have you disabled the automatic start during the installation?
Do a "sudo moblock-control start" and you will have a moblock.log.

Super Jamie
February 2nd, 2009, 10:13 PM
I haven't had any luck with MoBlock. It's a pain getting local network access working, and the control program keeps crashing. Back to ufw for me.

astarmathsandphysics
February 3rd, 2009, 03:08 PM
Yes.



If moblock was never running there will be no logfile. Have you disabled the automatic start during the installation?
Do a "sudo moblock-control start" and you will have a moblock.log.

ok done. here is the file.


Skipping useless range: scams pannationalbank.com
Skipping useless range: adbureau.net ads
Skipping useless range: eqchmdvip1.doubleclick.net ads
Skipping useless range: doubleclick.com ads
Skipping useless range: ads
Skipping useless range: www-focusin.targetnet.com
Skipping useless range: targetnet.com(Mamma.com)
Skipping useless range: bluerocketonline.com[OptinRealBig]
Skipping useless range: allchickswithdicks.com[OptinRealBig]
Skipping useless range: auctionwhiz.com/bashapop.com[bashapop popup killer
Skipping useless range: AUCTIONSNAP.com[OptinRealBig]
Skipping useless range: saverealbigdeals.com
Skipping useless range: JAYSWEBSERVICE.COM
Skipping useless range: CPAEMPIRE.COM[OptinRealBig]
Skipping useless range: ss01.net
Skipping useless range: cash4creatives.com[redirects to hugermelons.com]
Skipping useless range: network.realmedia.com ads
Skipping useless range: DOUBLECLICK-AU[ad.au.doubleclick.net]
Skipping useless range: ads
Skipping useless range: extreme-dm.com[eXTReMe digital NL]
Skipping useless range: extreme-dm.com ads
Skipping useless range: w0.extreme-dm.comATBP ATBP
Skipping useless range: tradedoubler.com ads
Skipping useless range: [DShield top10] Unknown
Skipping useless range: [DShield top10] Unknown
Merged range 'IANA Reserved for private use FNLC', with range 'IANA Reserved for private use FNLC'
Skipping useless range: Hijacked IP Block(SH)
Skipping useless range: Hijacked IP Block(SH)
Skipping useless range: Hijacked IP Block(SH)
Skipping useless range: IANA - Private Use [RFC1918]
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Skipping useless range: IANA Reserved - Multicast
Duplicated range ( IANA Reserved - Future use )
Skipping useless range: s0.mediasentry.bbnplanet.net
Skipping useless range: ARGONET INC
Skipping useless range: DOC-INTERNATIONAL TRADE ADMIN
Skipping useless range: ACS-BUSINESS PROCESS SOLUTIONS
Skipping useless range: COMPUTER SCIENCES CORP
Skipping useless range: INSTITUTE FOR DEFENSE ANALYSES
Skipping useless range: THE HUNT LAW GROUP
Skipping useless range: FMC CORPORATION
Skipping useless range: OFFICE OF NAVAL RESEARCH
Skipping useless range: ACS-IR
Skipping useless range: AVAYA
Skipping useless range: EDS
Skipping useless range: CDG COMMUNICATIONS
Skipping useless range: GLASPY GLASPY LAW OFFICES
Skipping useless range: IBM
Skipping useless range: IPSOS-NPD
Skipping useless range: LOCKHEED MARTIN CORPORATION
Skipping useless range: THE BOEING COMPANY
Skipping useless range: SAIC
Skipping useless range: GEOGRAPHIC DATA TECHNOLOGY
Skipping useless range: PLUNKETT COONEY LAW OFFICES
Skipping useless range: DEPARTMENT OF ENERGY
Skipping useless range: Blizzard Entertainment
Skipping useless range: WOW Technologies
Skipping useless range: ACS-IR
Skipping useless range: GENERAL ELECTRIC COMPANY
Skipping useless range: BOOZ ALLEN HAMILTON
Skipping useless range: Lafayette-City Hall
Skipping useless range: ROPERASW, LLC
Skipping useless range: APPLE COMPUTER
Skipping useless range: OSSI
Skipping useless range: MINITAB INC
Skipping useless range: THE LAW OFFICES OF TYLER PEERY
Skipping useless range: Pareto Marketing
Skipping useless range: FBI
Skipping useless range: 911 Center
Skipping useless range: Touchstone Inc
Skipping useless range: City of LaHabra
Skipping useless range: Kinsella LLP Law Offices
Skipping useless range: Sony Pictures
Skipping useless range: Wells Fargo
Skipping useless range: Bechtel National
Skipping useless range: Time Warner, Mark Daoust
Skipping useless range: Securitas
Skipping useless range: Northrup Gruman
Skipping useless range: Time Warner Washington Courthouse HE
Skipping useless range: Time Warner Chillicothe HE
Skipping useless range: Spotsylvania Co Sheriffs Dept
Skipping useless range: DHS--FLETC
Skipping useless range: City of Pico Riveria
Skipping useless range: Silverman Law Offices
Skipping useless range: County of San Bernadino
Skipping useless range: Military Communications Center
Skipping useless range: County of San Bernadino
Skipping useless range: International Speedway
Skipping useless range: Securitas Security Service USA
Skipping useless range: Time Warner Cable
Skipping useless range: Unknown bittorrent tracker
Skipping useless range: always.afraid.org
Skipping useless range: Cuyahoga County Information Services center
Skipping useless range: Willowick City Hall
Skipping useless range: Adlink INC
Skipping useless range: mail.pivotalpost.com
Skipping useless range: Lava Entertainment
Skipping useless range: Independent Records Inc
Skipping useless range: Independent Records Inc
Skipping useless range: Independent Records inc
Skipping useless range: County of Adams
Skipping useless range: Netsecurity
Skipping useless range: Northrup Grumman
Skipping useless range: Northrop Grumman
Skipping useless range: Struthers City Hall
Skipping useless range: Lykens Police Department
Skipping useless range: Time Warner National Bank
Skipping useless range: Kaye Scholer
Skipping useless range: DHS-FLETC
Skipping useless range: Wells Fargo
Skipping useless range: VT Dept. of Public Safety
Skipping useless range: WCAX-TV
Skipping useless range: Warr City Sheriff
Skipping useless range: State Of Vermont
Skipping useless range: Bay County
Skipping useless range: Entertainment Publications Operating Company, Inc
Skipping useless range: Time Warner Liberty HE
Skipping useless range: Time Warner Marion HE
Skipping useless range: Time Warner Media Sales
Skipping useless range: Time Warner
Skipping useless range: Time Warner
Skipping useless range: Time Warner
Skipping useless range: Time Warner Media Services
Skipping useless range: Test Central
Skipping useless range: ESPN Radio
Skipping useless range: Congressman Butch Otter
Skipping useless range: Howard Brief Law Office
Skipping useless range: Marion County Admin Building
Skipping useless range: Marion County Admin Building
Skipping useless range: Dept of Public Safety Homeland Security
Skipping useless range: DDoS/ap2p
Skipping useless range: Novell da Brasil Software Ltda
Skipping useless range: Apple Computer
Skipping useless range: IBM Business Recovery Service
Skipping useless range: IBM Schaumburg USF
Skipping useless range: IBM
Skipping useless range: IBM
Skipping useless range: IBM Schaumburg USF
Skipping useless range: IBM
Skipping useless range: IBM
Skipping useless range: IBM Schaumburg USF
Skipping useless range: IBM Schaumburg USF
Skipping useless range: IBM Schaumburg USF
Skipping useless range: Best Best & Krieger LLP
Skipping useless range: HELLER EHRMAN
Skipping useless range: New York Software Educational Foundation (NYSEF)
Skipping useless range: Blackboard, Inc
Skipping useless range: BAKER & MC KENZIE
Skipping useless range: Fitzpatrick Cella Harper & Scinto
Skipping useless range: Meta Interfaces, LLC
Skipping useless range: Australian Consulate General
Skipping useless range: Common Wealth Partners, LLC
Skipping useless range: Navigant Consulting, Inc
Skipping useless range: USPS OIG
Skipping useless range: Macrovision Corporation
Skipping useless range: Munsch Hardt Kopf Harr
Skipping useless range: LITTLER MENDELSON
Skipping useless range: Fowler Rodriguez Chalos
Skipping useless range: Terralliance - Dallas
Skipping useless range: Agency.com
Skipping useless range: City Of Pasadena
Skipping useless range: Vidsys
Skipping useless range: Winston & Strawn DC
Skipping useless range: The Medleh Group
Skipping useless range: 1636601 ONTARIO INC O/A RUSSIAN TELEVISION NETWORK OF CANADA
Skipping useless range: Bancroft Associates
Skipping useless range: PILLSBURY Winthrop Shaw Pittman LLP
Skipping useless range: State of Delaware
Skipping useless range: Summation Legal Technologies
Skipping useless range: Westwood One / METRO NETWORKS INC
Skipping useless range: DRS Technologies
Skipping useless range: National Mediation Board
Skipping useless range: Denver Center for Performing Arts
Skipping useless range: National Mediation Board - Chicago Site
Skipping useless range: AeA (American Electronics Association)
Skipping useless range: NIIT
Skipping useless range: Diligence Inc
Skipping useless range: Georgia Environmental Facilities Authority
Skipping useless range: JENNER & BLOCK
Skipping useless range: HILL, FARRER & BURRILL LLP
Skipping useless range: Federal Reserve Bank of Chicago
Skipping useless range: Blackwell Sanders/ProTel Consulting
Skipping useless range: Middleberg, Riddle & Gianna (MRG Document Techcnologies)
Skipping useless range: Much Shellist Freed & Dannenberg
Skipping useless range: (SAIC) Science Applications International Corporation
Skipping useless range: CITY OF TOLEDO
Skipping useless range: Corboy & Demetrio P.C
Skipping useless range: Sugar, Friedberg, & Fensenthal LLP
Skipping useless range: MULTIMAX INC - HQ
Skipping useless range: Waterdog Records
Skipping useless range: USPS OIG
Skipping useless range: City of Harvey
Skipping useless range: Cyberbroadcasting
Skipping useless range: Kutak Rock LLP
Skipping useless range: Big Star TV, LLC
Skipping useless range: Dodloo, Inc
Skipping useless range: Hays, McConn, Rice, & Pickering
Skipping useless range: Dykema Gossett
Skipping useless range: CAPGEMINI AMERICA OUTSOURC
Skipping useless range: City of Kankakee, IL
Skipping useless range: American Media Services
Skipping useless range: Burson-Marsteller
Skipping useless range: COGNITIVE ARTS / NIIT USA, Inc
Skipping useless range: BRYAN CAVE STRATEGIES
Skipping useless range: Schwartz, Cooper, Greenberger & Kraus
Skipping useless range: Halcyon Worlds
Skipping useless range: OK! Magazine
Skipping useless range: Winston & Strawn LLP
Skipping useless range: PALMER, BIEZUP & HENDERSON LLP
Skipping useless range: Butler, Rubin, Saltarelli & Boyd
Skipping useless range: Macrovision Corporation
Skipping useless range: McKenna, Long, Aldridge LLP
Skipping useless range: Opineum Marketing LLC
Skipping useless range: The Medleh Group - NY
Skipping useless range: Rocky Mountain Law Enforcement FCU
Skipping useless range: Schirott & Luetkehans
Skipping useless range: Heenan Blaikie Management Ltd
Skipping useless range: HASSARD & BONNINGTON
Skipping useless range: UNITED STATIONS RADIO NETWORKS
Skipping useless range: Refresh Software
Skipping useless range: Milberg, Weiss, Bershad & Schulman
Skipping useless range: Viacom Inc
Skipping useless range: MEEHAN BOYLE BLACK & FITZGERALD
Skipping useless range: Macrovision Corporation
Skipping useless range: Swiss Broadcasting Corp
Skipping useless range: WISCNET
Skipping useless range: Coleman, Talley, Newbern, Kurrie, Preston & Holland, LLP
Skipping useless range: Chamberlain, Hrdlicka, White, Williams & Martin
Skipping useless range: Coudert Brothers LLP
Skipping useless range: Factor 5, L.L.C
Skipping useless range: City of White Plains
Skipping useless range: Blaney McMurtry LLP
Skipping useless range: Panscient Data Services Pty Ltd
Skipping useless range: Thomson Corporation
Skipping useless range: Meta Interfaces, LLC
Skipping useless range: HENNIGAN Bennett & Dorman
Skipping useless range: ESP Group, LLC
Skipping useless range: Live365.com / Live365
Skipping useless range: Viacom Inc
Skipping useless range: State of Oregon
Skipping useless range: Martha Stewart Living Omnimedia, LLC
Skipping useless range: POKEMON USA INC
Skipping useless range: WILLIG WILLIAMS & DAVIDSON
Skipping useless range: DAVIS & GILBERT
Skipping useless range: Morrison & Foerster LLP Headquarters
Skipping useless range: Williams, Montgomery, & John LTD
Skipping useless range: HYMAN PHELPS & MC NAMARA
Skipping useless range: Ambiron, LLC
Skipping useless range: Collabnet, Inc
Skipping useless range: UN High Commissioner for Refugees
Skipping useless range: Starwin Media
Skipping useless range: nMatrix
Skipping useless range: HLP Associates, Inc
Skipping useless range: Access Systems Inc. / OASAS Education Center
Skipping useless range: Tritech Software Systems*
Skipping useless range: The Actors Fund of America
Skipping useless range: Debevoise & Plimpton LLP
Skipping useless range: Hughes & Luce. LLP
Skipping useless range: Lovells
Skipping useless range: Telarix
Skipping useless range: Lincoln Group
Skipping useless range: Richards, Watson & Gershon
Skipping useless range: Chamberlain, Hrdlicka, White, Williams & Martin
Skipping useless range: Vedder Price, Kaufman & Kammholz
Skipping useless range: LEYDIG VOIT & MAYER
Skipping useless range: Bureau Van Dijk Electronic Publishing, Inc
Skipping useless range: Blackwell Sanders/ProTel Consulting
Skipping useless range: Wolf Popper LLP
Skipping useless range: Nokia Research
Skipping useless range: Stardock Corporation
Skipping useless range: Access IT - Hosting Services
Skipping useless range: ESP Group, LLC
Skipping useless range: Cap Gemini Dallas
Skipping useless range: Astral Media Radio G.P
Skipping useless range: BARACK FERRAZZANO KIRSCHBAUM
Skipping useless range: Moozatech
Skipping useless range: Lahive & Cockfield, LLP
Skipping useless range: Broadcom Corporation (CA)
Skipping useless range: McDermott Will & Emery
Skipping useless range: USPS OIG
Skipping useless range: E! Entertainment
Skipping useless range: Guba LLC
Skipping useless range: Meta Interfaces, LLC
Skipping useless range: Net One Group
Skipping useless range: Evil Twin Studios
Skipping useless range: USPS OIG
Skipping useless range: USPS OIG
Skipping useless range: InfoRelay
Skipping useless range: USPS OIG
Skipping useless range: Project Leadership Associates
Skipping useless range: CYVEILLANCE
Skipping useless range: Guba LLC
Skipping useless range: Synchris
Skipping useless range: Major League Baseball Advance Media
Skipping useless range: KING COUNTY BAR ASSOC
Skipping useless range: Frictionless Commerce
Skipping useless range: Beveridge & Diamond
Skipping useless range: Blackwell Sanders/ProTel Consulting
Skipping useless range: GPVOD
Skipping useless range: Dreier LLP
Skipping useless range: COATS, ROSE, YALE, RYMAN & LEE
Skipping useless range: E! Entertainment
Skipping useless range: USPS OIG
Skipping useless range: Illinois State Chamber of Commerce
Skipping useless range: Wolf Haldenstein
Skipping useless range: Science Applications International Corporation (SAIC)
Skipping useless range: Gemplus Corporation
Skipping useless range: Morrison & Foerster LLP Headquarters
Skipping useless range: Cornerstone Research INC
Skipping useless range: Sidley Austin LLP
Skipping useless range: LITIGATION SOLUTION INC
Skipping useless range: Federal Reserve Bank of Chicago
Skipping useless range: ZSA Legal Recruitment
Skipping useless range: USPS OIG
Skipping useless range: New Jersey Performing Arts
Skipping useless range: Your OneStop Network, Inc
Skipping useless range: Arnstein & Lehr, LLP
Skipping useless range: Shumaker Steckbauer Weinhart, LLP
Skipping useless range: Ungaretti & Harris
Skipping useless range: Minden Gross LLP
Skipping useless range: Dream Tank LLC
Skipping useless range: Ziff Davis Media Inc
Skipping useless range: Labaton Sucharow & Rudoff LLP
Skipping useless range: CARROLL BURDICK & MC DONOUGHks
Skipping useless range: CARROLL BURDICK & MC DONOUGH
Skipping useless range: USPS OIG
Skipping useless range: USPS OIG
Skipping useless range: Cinemavault
Skipping useless range: SafeNet inc
Skipping useless range: ORRICK HERRINGTON & SUTCLIFFE
Skipping useless range: Terralliance - Denver
Skipping useless range: USPS OIG
Skipping useless range: STG, Inc
Skipping useless range: Borden Ladner Gervais LLP
Skipping useless range: InfoRelay
Skipping useless range: USPS OIG
Skipping useless range: MORRISON & FORESTER - Main
Skipping useless range: Pond North LLP
Skipping useless range: Pond North LLP
Skipping useless range: Steptoe & Johnson LLP
Skipping useless range: Davis Polk & Wardwell
Skipping useless range: HOWREY LLP
Skipping useless range: DEHAY & ELLISTON
Skipping useless range: Berger / Schatz
Skipping useless range: BOSTON PROPERTIES
Skipping useless range: BitTorrent, Inc
Skipping useless range: Alston & Bird, LLP
Skipping useless range: Hyman,Lippitt, P.C
Skipping useless range: Mercury Interactive
Skipping useless range: USPS OIG
Skipping useless range: IBB / International Broadcasting Bureau
Skipping useless range: Revive Systems
Skipping useless range: 247 Discovere
Skipping useless range: USPS OIG
Skipping useless range: Houghton Mifflin Company
Skipping useless range: USPS OIG
Skipping useless range: PILLSBURY Winthrop Shaw Pittman LLP
Skipping useless range: Jorge Scientific Corp
Skipping useless range: JORGE SCIENTIFIC CORPORATION
Skipping useless range: USPS OIG
Skipping useless range: DeNovo Legal
Skipping useless range: Knoble Yoshida & Dunleavy, LLC
Skipping useless range: WINSTEAD SECHREST & MINICK
Skipping useless range: Cox, Hodgman, & Giarmarco, P.C
Skipping useless range: Cook Sound & Producion (Sound Works)
Skipping useless range: Nisen & Elliott
Skipping useless range: SRA Arlington
Skipping useless range: USPS OIG
Skipping useless range: Knowledge Adventure
Skipping useless range: OPEN ROAD PRODUCTIONS
Skipping useless range: Magna Entertainment
Skipping useless range: The Medleh Group - Houston
Skipping useless range: AEG Live!
Skipping useless range: Brown Raysman Millstein Felder & Steiner
Skipping useless range: Auto FX Software
Skipping useless range: WINSTEAD SECHREST & MINICK
Skipping useless range: BENNETT BRICKLIN & SALTZBURG LLP
Skipping useless range: PILLSBURY Winthrop Shaw Pittman LLP
Skipping useless range: Maddin, Hauser, Wartell, Roth & Heller, P.C
Skipping useless range: City of Gainesville dba GRUCom
Skipping useless range: Williams & Connolly LLP
Skipping useless range: Fragomen, Delrey, Bersen & Loewy, LLP
Skipping useless range: filmcore
Skipping useless range: Hemenway & Barnes
Skipping useless range: Greater Boston Chamber of Commerce
Skipping useless range: Secured Servers
Skipping useless range: Secured Servers
Skipping useless range: Pacific Racing Association / Magna Entertainment
Skipping useless range: Stardock Corporation
Skipping useless range: BBDO Canada
Skipping useless range: Bulkley Richardson & Gelinas, LLP
Skipping useless range: BRACEWELL & Patterson, L.L.P
Skipping useless range: VERANCE
Skipping useless range: Banyan Productions
Skipping useless range: Powell Goldstein (HQ)
Skipping useless range: WHITE & WILLIAMS LLP
Skipping useless range: BRINKS HOFER GILSON & LIONE
Skipping useless range: Mintz Levin Cohn Ferris Glovsky & Pompeo
Skipping useless range: Nexon/NX Games
Skipping useless range: USPS OIG
Skipping useless range: USPS OIG
Skipping useless range: Navisite Inc
Skipping useless range: Department of Energy
Skipping useless range: G4 Media /G4techTV
Skipping useless range: Catalyst Software Solutions
Skipping useless range: DiscoverReady LLC
Skipping useless range: STANISLAW ASHBAUGH LLP
Skipping useless range: Ontario Investment Service, Ministry of Economic Development & Trade
Skipping useless range: G4 Media /G4techTV
Skipping useless range: BCG Attorney Search BOS
Skipping useless range: Eloda inc
Skipping useless range: Fields Howell Athans & McLaughlin, LLP
Skipping useless range: C2 Legal of Illinois
Skipping useless range: The Associated Press
Skipping useless range: Henry, Oddo, Austin, & Fletcher
Skipping useless range: Patton Boggs
Skipping useless range: USPS OIG
Skipping useless range: Creative Thought, Inc
Skipping useless range: Magna Entertainment
Skipping useless range: The News Journal
Skipping useless range: Agency.com
Skipping useless range: SUSMAN GODFREY, LLP
Skipping useless range: Parker Mills & Patel LLP
Skipping useless range: Idea Flood
Skipping useless range: SafeNet inc
Skipping useless range: Parsons Corporation / Parsons
Skipping useless range: Gameline
Skipping useless range: Hunter Keilty Muntz & Beatty
Skipping useless range: Echoworx Corporation
Skipping useless range: Willms & Shier Environmental Lawyers LLP
Skipping useless range: Blaney McMurtry Barristers & Solicitors LLP
Skipping useless range: Information and Privacy Commissioner/Ontario
Skipping useless range: ZSA Legal Recruitment
Skipping useless range: Polish Television USA
Skipping useless range: Mindshare Canada
Skipping useless range: Toronto Board of Trade
Skipping useless range: Mindshare Canada
Skipping useless range: Lippincott Williams & Wilkins
Skipping useless range: State of Delaware
Skipping useless range: Insurance Bureau of Canada
Skipping useless range: Hill and Knowlton Canada
Skipping useless range: Thomson Corporation
Skipping useless range: MaRS
Skipping useless range: Peel District School Board
Merged range 'Performance Systems International-ed2k/ap2p', with range 'PSI FAKES PHOTOBKT Split_B'
Skipping useless range: Live Universe, Inc
Skipping useless range: jvcmusic.co.jp
Skipping useless range: fake emule servers
Skipping useless range: WAYI INTERNATIONAL DIGITAL ENTERTAINMENT CO., LTD
Skipping useless range: GSN, Taiwan Government Service Network
Skipping useless range: THE MATSUMOTO CHAMBER OF COMMERCE & INDUSTRY
Skipping useless range: Yaizu city hall
Skipping useless range: Fujitsu I Network Systems Limited
Skipping useless range: FUJITSU FIP CORPORATION
Skipping useless range: Fujitsu Limited Probank-System Division
Skipping useless range: Sado Television Inc
Skipping useless range: FUJITSU FIP CORPORATION
Skipping useless range: Export,Import and Investment Insurance Department,Minstry of Economy,Trade and
Skipping useless range: FUJITSU FIP CORPORATION
Skipping useless range: CHINANET|Anti-p2p
Skipping useless range: CHINANET|Anti-p2p
Skipping useless range: Longyou Procuratorate
Skipping useless range: Longyou Police Bureau
Skipping useless range: Step 10 Production - Kwun Tong INd Ctr Blk 2
Skipping useless range: Modern Electronics Co - Sun Fung Ind Ctr Blk A
Skipping useless range: Graphic Plus Output And Production Ctr - Ho Lik C
Skipping useless range: Media-Tech Printing And Production Co - Grand Cit
Skipping useless range: F6 Production Co - Shing Yip IND BLDG (Kwun Tong)
Merged range ' Bertelsmann mediaSystems GmbH', with range 'Bertelsmann mediaSystems GmbH'
Skipping useless range: Bertelsmann mediaSystems GmbH
Skipping useless range: Bertelsmann mediaSystems GmbH
Skipping useless range: Tachyon Europe BV
Skipping useless range: TURKHACKTEAM.ORG
Skipping useless range: Sony Nordic A/S
Skipping useless range: Sony Nordic A/S
Skipping useless range: Sony Nordic A/S
Skipping useless range: Sony Nordic A/S
Skipping useless range: Insoft
Skipping useless range: CONS.AGRARIO PROVINCIALE ARL
Skipping useless range: Syntegra Leeds
Skipping useless range: County Durham & Tees Valley Health Authority
Skipping useless range: NHS Counter Fraud Service, Central Unit (London)
Skipping useless range: Morpeth County Hall, Morpeth NE61 2EF
Skipping useless range: Berwick District Office (Social Services)
Skipping useless range: Hexham District Office (Social Services)
Skipping useless range: Alnwick District Office (Social Services)
Skipping useless range: Cramlington District Office (Social Services)
Skipping useless range: Blyth District Office(Social Services)
Skipping useless range: Ashington District Office (Social Services)
Skipping useless range: Prudhoe District Office (Social Services)
Skipping useless range: Newbiggin District Office (Social Services)
Skipping useless range: Bedlington District Office (Social Services)
Skipping useless range: Merlycroft District Office (Social Services)
Skipping useless range: Norfolk County Council linked to NHSnet
Skipping useless range: BT Syntegra - Leeds
Skipping useless range: South West London PHI - Wandsworth Borough Counci
Skipping useless range: Philips Medical Systems
Skipping useless range: Ministry Of Education
Skipping useless range: Ministry Of Education
Skipping useless range: SONY FRANCE
Skipping useless range: EDS EXPLOITATION SNC
Skipping useless range: MOTOROLA
Skipping useless range: SKIDATA FRANCE SA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Merged range ' GI - Customer Interconnexion With RAEI Backbone', with range 'GI - Customer Interconnexion With RAEI Backbone'
Skipping useless range: Lan range for the Commonwealth Secretariat
Skipping useless range: JIC-MUSIC.NL
Skipping useless range: Virgin Wines
Skipping useless range: Wards Solicitors
Merged range 'CBC Cologne Broadcasting Center', with range 'CBC Cologne Broadcasting Center'
Skipping useless range: CBC Cologne Broadcasting Center
Skipping useless range: MAM-LAN
Skipping useless range: ALM-PUBLISHING ā Casa
Skipping useless range: ALM-PUBLISHING ā Casa
Skipping useless range: SUN MICROSYSTEMS ā Casa
Skipping useless range: Production & Exportation fleurs coupés ā Casa
Skipping useless range: cyber studio sarl ā Casa
Skipping useless range: Societe de l'audio visuel ā Casa
Skipping useless range: price waterhouse Maroc
Skipping useless range: General electric international Maroc
Skipping useless range: Tribunal de Commerce de Meknes
Skipping useless range: Chambre de Commerce d\\
Skipping useless range: Tribunal de Commerce d\
Skipping useless range: VIDEORAMA SARL ā Casa
Skipping useless range: FTS2001/CDC/NCID
Skipping useless range: Verestar
Skipping useless range: Crowell & Moring
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: PeopleSoft
Skipping useless range: Jungle Interactive M
Skipping useless range: Policia Aguadilla
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: FORENSICS CONSULTING SOLUTIONS
Skipping useless range: Law Firm of Barrett Stetson
Skipping useless range: NATIONAL CENTER FOR VICTIMS OF CRIME
Skipping useless range: BUTZEL LONG
Skipping useless range: Absolute Pitch Studios
Skipping useless range: On Time Technology
Skipping useless range: Lawyers Committee for Civil Rights Under Law
Skipping useless range: Siebel Systems
Skipping useless range: Fox Kids.Com
Skipping useless range: ACS Unclaimed Property
Skipping useless range: Fulbright & Jaworski
Skipping useless range: Pyramid Research
Skipping useless range: Butzel Long, P.C
Skipping useless range: Elron Telesoft
Skipping useless range: LEGAL OPTIONS
Skipping useless range: Law Offices of Brian Hersh
Skipping useless range: Law Office of Linda Lee
Skipping useless range: LAW OFFICES OF TAUS & TAUS
Skipping useless range: MCAFEE
Skipping useless range: Siebel Systems Inc
Skipping useless range: The M Group
Skipping useless range: Law Offices of Russell A Kelm
Skipping useless range: Zero Gravity Technologies
Skipping useless range: Widevine Technologies
Skipping useless range: Lucent Technologies
Skipping useless range: ELRON SOFTWARE
Skipping useless range: Law Office of Joel H. Greenburg
Skipping useless range: Lucent
Skipping useless range: Epoch Sales
Skipping useless range: Lucent Technologies
Skipping useless range: GOVERNOR GRAY DAVIS COMMITTEE
Skipping useless range: law offices of peter gonzales
Skipping useless range: Clifford Chance
Skipping useless range: Law Offices of Susan R Green
Skipping useless range: Video Files Media Group
Skipping useless range: Goldfarb & Lipman
Skipping useless range: NR SOFTWARE
Skipping useless range: Law Office of Mullen & McGourty
Skipping useless range: the grovenor gray-davis commitee
Skipping useless range: Intersoft
Skipping useless range: LEGALKEY TECHNOLOGIES INC
Skipping useless range: Law Office of I. Harrison Levy
Skipping useless range: COMMAND SOFTWARE STAFFING
Skipping useless range: ACS GROUP
Skipping useless range: attorney GREIVANCE COMM
Skipping useless range: LAW OFFICES OF BURTON AND BURTON
Skipping useless range: William E. Artz, P.C
Skipping useless range: Cogent Systems
Skipping useless range: Law Offices of Matthew Web
Skipping useless range: Law Office of Hermes & Ga
Skipping useless range: LAW OFFICE OF DAVID M BEREEKE
Skipping useless range: UNIVERSAL IMAGES
Skipping useless range: Law Offices of Larry Zieger
Skipping useless range: Core Studio
Skipping useless range: FULBRIGHT & JAWORKY
Skipping useless range: SYNTHESIS
Skipping useless range: Judicial Corrections
Skipping useless range: Law Offices of Ana Schvartz
Skipping useless range: ABC Inc
Skipping useless range: AVALON PUBLISHING
Skipping useless range: United Artist Theater
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: Raleigh Studios Manhattan Beach182185
Skipping useless range: Ernst & Young Llp
Skipping useless range: Onesecure
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: MediaDefender
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: Halliburton Systems Inc
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: Electronic Data Systems Corporation (EDS)
Skipping useless range: Electronic Data Systems Corporation (EDS)
Skipping useless range: Websense
Skipping useless range: Marvel King Enterprises Limited
Skipping useless range: Greenberg Traurig
Skipping useless range: Thomas Mamer Haughey
Skipping useless range: Champaign Public Library
Skipping useless range: Max Music &amp; Entertainment
Skipping useless range: Indigo.Multimedia
Skipping useless range: Intersoft Group, Inc
Skipping useless range: NBACORP
Skipping useless range: Intersoft Group, Inc
Skipping useless range: Intersoft Group, Inc
Skipping useless range: Omnicom of America, Inc
Skipping useless range: Signal Command
Skipping useless range: Intersoft Group, Inc
Skipping useless range: Intersoft Group, Inc
Skipping useless range: Omnicom of America, Inc
Skipping useless range: Legal Internet Solutions Inc
Skipping useless range: World Ehtbic Broadcasting, Inc
Skipping useless range: Web Entertainment Group, Inc
Skipping useless range: EDS Systemhouse
Skipping useless range: Siemens Medical Solutions Health Services Corporation
Skipping useless range: Barbara J. Weiser, Attorney at Law, P.C
Skipping useless range: 20th Century Fox #27 (Simpsons)
Skipping useless range: Macrovision
Skipping useless range: Jefferson County Ohio
Skipping useless range: Massive Software
Skipping useless range: MediaDefender
Skipping useless range: VereStar Networks
Skipping useless range: VereStar Networks BRW
Skipping useless range: VereStar Networks BRW
Skipping useless range: Skyweb Technologies Ltd
Skipping useless range: VereStar Networking Consumers
Skipping useless range: Verestar
Skipping useless range: VereStar Networking Consumers
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: fake files
Skipping useless range: Us Army Recruiting GSA
Skipping useless range: Braxton County
Skipping useless range: Public Defender For The 25th Circuit
Skipping useless range: Marion County
Skipping useless range: Keith A Cox Attorney of Law
Skipping useless range: Skeen & Skeen DGN Atty
Skipping useless range: Bayliss Law Offices
Skipping useless range: Blair Law Office
Skipping useless range: City of Huntington
Skipping useless range: Legal Aid of WV
Skipping useless range: Ryan & Ryan Attorneys at
Skipping useless range: City of Chesapeake City Clerk
Skipping useless range: John Law Offices
Skipping useless range: Dinsmore & Shohl LLP / Kay, Casto & Chaney
Skipping useless range: Le Law Offices
Skipping useless range: Martin Marietta Aggregates
Skipping useless range: Jan Dils Attorney At Law
Skipping useless range: Wells Dillon Law Office
Skipping useless range: D Randall Clarke Law Office
Skipping useless range: John Laishley Law Office
Skipping useless range: Law Office Of Kathryn A Cisco-Sturgell
Skipping useless range: Yannerella Law Offices
Skipping useless range: Juno Boston Production Inet & Dial /24 block via Boston
Skipping useless range: BearingPoint
Skipping useless range: BearingPoint
Skipping useless range: Accenture-TMHP
Skipping useless range: Intec Telecom Systems, Inc..256844
Skipping useless range: Movielink
Skipping useless range: Intec Telecom Systems, Inc
Skipping useless range: Movielink
Skipping useless range: pyus.guba.com
Skipping useless range: EDS
Skipping useless range: The Culver Studios
Skipping useless range: Universal Studios SBC064175196136020819 (NET-64-175-196-136-1)
Skipping useless range: Universal Studios SBC064175196144020819 (NET-64-175-196-144-1)
Skipping useless range: Office of Management and Budget
Skipping useless range: Clear Channel Communications IT Services
Skipping useless range: Clear Channel Communications IT Services
Skipping useless range: Clear Channel Communications IT Services
Skipping useless range: Clear Channel Communications IT Services
Skipping useless range: Xamo Entertainment
Skipping useless range: Xamo Entertainment
Skipping useless range: Republican National Committee
Skipping useless range: CDC
Skipping useless range: Capstone Technologies
Skipping useless range: PCF Software Solutions, Inc
Skipping useless range: SSA Consultants
Skipping useless range: Law Offices of Walsh & Bailey
Skipping useless range: Atty Asante & Assoc
Skipping useless range: ACTIVISION
Skipping useless range: ACTIVISION
Skipping useless range: COVENANT TECHNOLOGY
Skipping useless range: City of Greensboro - ABC Board
Skipping useless range: U.S. Chamber of Commerce Insitute for Legal Reform
Skipping useless range: Department of Public Safety - State Police
Skipping useless range: Department of Information Technology
Skipping useless range: cinemanow.com
Skipping useless range: OLM,LLC
Skipping useless range: Capella Films Inc
Skipping useless range: LAW OFFICES OF AMELI, AYVAZI & ASSOICATES
Skipping useless range: STUDIO SOFTWARE
Skipping useless range: Foundry Networks
Skipping useless range: Law Office of Herbert Thaler
Skipping useless range: ARIAMEDIA
Skipping useless range: KELLEY LAW ASSOCIATES
Skipping useless range: Legal Leaders
Skipping useless range: Ladas & Parry
Skipping useless range: Capella Films
Skipping useless range: L.A. Studios
Skipping useless range: LAW OFFICE OF MANUEL GOMEZ
Skipping useless range: GOVERNOR GRAY DAVID COMMITTEE
Skipping useless range: Walt Disney Imagineering
Skipping useless range: ASSOCIATED PRODUCTION MUSIC APM
Skipping useless range: AMERICAN.COUNCIL.ON.GERMANY
Skipping useless range: Attorney David Munson
Skipping useless range: Big Fat Promotions
Skipping useless range: Law Offices of Jason B Rosenthal
Skipping useless range: SOLIX SYSTEMS, INC
Skipping useless range: USAF II, LLC
Skipping useless range: Embassy of India
Skipping useless range: MURPHY & LOMON & ASSOCIATE
Skipping useless range: Cogent Systems
Skipping useless range: VANGUARD.MEDIA
Skipping useless range: IGNITE STUDIO
Skipping useless range: GENERAL SERVICES ADMIN
Skipping useless range: Oddworld Inhabitants, Inc
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: GE POWER SYSTEMS PO 182007122
Skipping useless range: UNITED ARTISTS THEATRE CIRCUIT
Skipping useless range: Macromedia Inc
Skipping useless range: Bush Cheney Re-Election Campaign
Skipping useless range: Bush Cheney Re-Election Campaign
Skipping useless range: DOL Dept AL Trabajo
Skipping useless range: TIBCO SOFTWARE
Skipping useless range: ADP DEALER
Skipping useless range: FTS2001/US Dept of State
Skipping useless range: FTS2001/Dept of State
Skipping useless range: FTS2001/NAVSEA PHD NSWC
Skipping useless range: OPSWARE
Skipping useless range: SCIENCE APPLICATIONS INT
Skipping useless range: ppiltd.com
Skipping useless range: Cox Television
Skipping useless range: Ancient Media
Skipping useless range: Red Realm Productions, Inc
Skipping useless range: NHI Networks - NHICOLO
Merged range 'NHI Customer', with range 'NHI Networks'
Skipping useless range: OLM,LLC
Skipping useless range: BearingPoint IDMS
Skipping useless range: AP2P Scum
Skipping useless range: Eds App
Skipping useless range: Mercury Interactive
Skipping useless range: VereStar Networks BRW
Skipping useless range: VereStar Networks BRW
Skipping useless range: VereStar Networks BRW
Merged range 'ESPN', with range 'Defense Web Technologies'
Merged range 'Sega Gameworks', with range 'Sega Gameworks'
Skipping useless range: Retspan
Skipping useless range: retspan.info3
Skipping useless range: Veritas Consulting
Skipping useless range: MediaDefender
Skipping useless range: Bittorrent FAKES
Skipping useless range: Netsweeper
Skipping useless range: Abacus Computer
Skipping useless range: Netsweeper
Skipping useless range: Salt Lke County
Skipping useless range: Jensen Duffin Carman Dibb And Jackson
Skipping useless range: SLC Chamber of Commerce
Skipping useless range: Utah State Bar
Skipping useless range: Workman, Nydegger & Seeley
Skipping useless range: Business Software Solutions
Skipping useless range: Software Technology Group
Skipping useless range: Business Software Solutions
Skipping useless range: NDS
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: safenet-inc.com
Skipping useless range: www.musicunited.org | RIAA
Skipping useless range: Town of Perth Treasury Office
Skipping useless range: ibm022504
Skipping useless range: gnutella server farm on CBTS
Skipping useless range: California Bar
Skipping useless range: City of Folsom
Skipping useless range: Apple Computer SBC067122195056030613 (NET-67-122-195-56-1)
Skipping useless range: www.mt-hackers.org
Skipping useless range: LAVAN BRIANDGN ATTY
Skipping useless range: Urs Corporation
Skipping useless range: Offline Inc
Skipping useless range: LAFAYETTE-CITY HALL
Skipping useless range: Infraswitch|BayTSP
Skipping useless range: xeex
Skipping useless range: InterCage
Skipping useless range: Teletime Media Inc
Skipping useless range: Hunton And Company
Skipping useless range: Walt Disney Pictures Tv12492653
Skipping useless range: WaltDisneyPicturesTv124938577
Skipping useless range: WaltDisneyPicturesTv12494196
Skipping useless range: NORTHROP GRUM CORP IT-041222005139
Skipping useless range: Mediasentry
Skipping useless range: Mediasentry
Skipping useless range: D.O.D
Skipping useless range: [5307th]rangers
Skipping useless range: global strike force
Skipping useless range: Mediasentry
Skipping useless range: ns1 and ns2.waltham.tower-research.com
Skipping useless range: SONY COMPUTER 2ND FL-050421021222
Skipping useless range: SONY COMPUTER 2ND FL-050421021756
Skipping useless range: SONY COMPUTER 2ND FL-050421022042
Skipping useless range: Possible Macrovision
Skipping useless range: Possible Macrovision
Skipping useless range: SN-MSI
Skipping useless range: datarecoverygroup.com
Skipping useless range: MediaDefender
Skipping useless range: BayTSP
Skipping useless range: mail.projectinvision.com
Skipping useless range: The Entertainment Group
Skipping useless range: 2waytraffic
Skipping useless range: Bullet Sound Studios
Skipping useless range: COMUNE DI COLLEGNO
Skipping useless range: CINEMATOGRAFI PLINIUS
Skipping useless range: COMUNE DI PESCARA
Skipping useless range: STUDIO LEGALE SABELLI
Skipping useless range: COMUNE DI RICCIONE
Skipping useless range: COMUNE DI LECCE
Merged range ' AMMINISTRAZIONEPROVINCIALESALE', with range 'AMMINISTRAZIONEPROVINCIALESALE'
Skipping useless range: AMMINISTRAZIONEPROVINCIALESALE
Skipping useless range: COMUNE DI VENEZIA
Skipping useless range: COMUNE DI SIRACUSA
Skipping useless range: EDSLAN SPA
Skipping useless range: HEWLETT-PACKARD DISTRIBUTED COMPUTING SERVICES SR
Skipping useless range: CINECITTA'STUDIOSSPA
Skipping useless range: CINECITTA.Studiosspa.IT
Skipping useless range: www.zasp.pl
Skipping useless range: www.so.lublin.pl
Skipping useless range: Koebenhavns Produktionsskole
Skipping useless range: Definite Software Ltd
Skipping useless range: Definite Software Ltd
Skipping useless range: Botschaft der Republik Jemen
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Annaberg-Buchholz
Skipping useless range: Messstetten ZAK EinsFuesser1
Skipping useless range: Messstetten Heuberg EinsFuesser1
Skipping useless range: Messstetten VAN Lw EinsFuesser1
Skipping useless range: Messstetten Patriot/Stinger Ein sFuesser1
Skipping useless range: MEssstetten Virtel-Kabine EinsF uesser1
Skipping useless range: Lechfeld JaboG 32
Skipping useless range: Neuburg/D Jagdgeschwader 74
Skipping useless range: FmSkt606
Skipping useless range: Penzing LTG 61
Skipping useless range: Buechel JaboG 33
Skipping useless range: Fliegerorst Noervenich JaboG 31
Skipping useless range: Laupheim MTH 25
Skipping useless range: EADS Ottobrunn
Skipping useless range: IABG Ottobrunn
Skipping useless range: FlaRakG 1\"SH\" Husum
Skipping useless range: General v.Seidel Kaserne ZEK
Skipping useless range: 3./ObjSBtlLw Wittmund
Skipping useless range: Campbell Barracks, Geb. 32
Skipping useless range: Bundeswehr
Skipping useless range: KENNETH-BUSH-SOLICITORS
Skipping useless range: TAKE-2-INTERACTIVE-EUROPE
Skipping useless range: ISTITUTO GEOGRAFICO MILITARE
Skipping useless range: GLOUCESTER-SONY-CENTRE
Skipping useless range: WORCESTER office network
Skipping useless range: GB
Skipping useless range: dentonwildesapte.com
Skipping useless range: Telstra Europe DMZ Services
Skipping useless range: FR-RAEI-DASSAULT-AVIATION-DE-LA-TESTE-LB_INTERNET
Skipping useless range: FR-RAEI-HITACHI-SOFTWARE-LB_INTERNET
Skipping useless range: FR-RAEI-CGR-CINEMAS-LB_INTERNET
Skipping useless range: FR-RAEI-MINISTERE-DE-LA-DEFENSE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Merged range 'Customer Interconnexion With RAEI Backbone', with range 'GI - Customer Interconnexion With RAEI Backbone'
Skipping useless range: FR-RAEI-RSA-LB_INTERNET
Merged range 'GI - Customer Interconnexion With RAEI Backbone', with range 'Customer Interconnexion With RAEI Backbone'
Skipping useless range: FR-RAEI-RSA-EBAVURAGE-TRONCONNAGE-LB_INTERNET
Skipping useless range: FR-RAEI-BEFEC---PRICE-WATERHOUSE-LB_INTERNET
Skipping useless range: FR-RAEI-***-ALLIANCE-POLICE-NATIONALE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: NameShield Paris TeleHouse2
Skipping useless range: Nameshield Redbus Courbevoie
Skipping useless range: Nameshield Interoute Aubervilliers
Skipping useless range: DNS ANYCAST NETWORK
Skipping useless range: MINISTERO INTERNO DIPARTIMENTO DELLA P.S
Skipping useless range: block for PI assignments
Skipping useless range: Priority Telecom Norway Core Services Ostfold
Skipping useless range: Priority Telecom Norway Exchange
Skipping useless range: Priority Telecom Home Offices
Skipping useless range: Priority Telecom Norway Hosting Talkemore
Skipping useless range: Priority Telecom Norway hosting NAT
Skipping useless range: Priority Telecom Norway
Skipping useless range: Priority Telecom Link Networks Ostfold
Skipping useless range: Priority Telecom Backbone Connections
Skipping useless range: Priority Telecom Customer Private WAN Links
Skipping useless range: Priority Telecom Tunnel WAN Links
Skipping useless range: Priority Telecom VoIP ISDN Flex platform
Skipping useless range: Priority Telecom Gigabit Ethernet test equipment
Skipping useless range: Priority Telecom, Netconnect Overlay, BACKBONE
Skipping useless range: Priority Telecom Customer Private WAN Links
Skipping useless range: Cinekid
Skipping useless range: Priority Telecom Customer Private WAN Links
Skipping useless range: Priority Telecom Infrastructure, Loopbacks etc
Skipping useless range: Priority Telecom Customer Private WAN Links
Skipping useless range: Priority Telecom Customer Private WAN Links (DSL)
Skipping useless range: CANAL+ Services BV
Skipping useless range: Macromedia
Skipping useless range: NL-PRIORITY-20030603
Skipping useless range: Maatschap Muurmans advocaten
Skipping useless range: Moscow Russia, ID-3918, JSC \"PricewaterhouseCoopers Audit\"
Skipping useless range: FR-RAEI-MOTOROLA--SAS-CENTRE-DE-RECHER-LB_INTERNET
Skipping useless range: FR.RAEI.GAUMONT.BUENA.VISTA.INTERNATIO.LB.INTERNET
Skipping useless range: FR-RAEI-DIRECTION-PERSONNEL-MILITAIRE-LB_INTERNET
Skipping useless range: Eircom Customer Assignment
Skipping useless range: ZHIVAGORECORDS
Skipping useless range: OGORMANCINEMAS
Skipping useless range: OGORMANCINEMASSTILLORGAN
Skipping useless range: ZHIVAGORECORDS
Skipping useless range: DROPINRECORDING
Merged range 'Net for Software Company Ing. Alfred Gunsch', with range 'Net for Software Company Inf. Alfred Gunsch'
Merged range 'Consulale of the Latvian Republic in Vitebsk', with range 'Consulale of the Latvian Republic in Vitebsk'
Skipping useless range: www.CrazyGameserver.de
Skipping useless range: smais.is.site
Skipping useless range: MALONEMARTINSOLICITORS
Skipping useless range: Screen Digest
Skipping useless range: HONEYWELLSPA
Skipping useless range: BUREAU VERITAS ITALIA SRL
Skipping useless range: TOSHIBAMEDICALSYSTEMSSRL
Skipping useless range: SOC.COOP. LAVORO E GIUSTIZIA
Skipping useless range: Script kiddies
Skipping useless range: OVH SAS|Anti-p2p
Skipping useless range: IBM ITALIA SPA
Skipping useless range: IBM ITALIA SPA
Skipping useless range: SIEMENS SPA
Skipping useless range: SIEMENS SPA
Skipping useless range: SIEMENS SPA
Skipping useless range: NOKIA ITALIA SPA
Skipping useless range: STUDIO LEGALE ASSOCIATO AVVOCATI ARIZIA - VALENTINI
Skipping useless range: ADP SRL
Skipping useless range: Dedibox|Anti-p2p
Skipping useless range: COMMERCE
Skipping useless range: AT&T PEBBLE BEACH PRO-AM-071227180558
Skipping useless range: AT&T PEBBLE BEACH PRO-AM-071227185455
Skipping useless range: Geo Publishing
Skipping useless range: Real Networks
Skipping useless range: Hasbro Interactive, Inc
Skipping useless range: NBC.Interactive.Inc
Skipping useless range: Ziff Davis Education Direct
Skipping useless range: Real Networks
Skipping useless range: Department of the Navy
Skipping useless range: 3Com Corporation
Skipping useless range: BBN Corporation
Skipping useless range: Hewlett-Packard
Skipping useless range: National Aeronautics and Space Administration
Skipping useless range: National Aeronautics and Space Administration
Skipping useless range: National Aeronautics and Space Administration
Skipping useless range: IBM Schaumburg USF
Skipping useless range: IBM
Skipping useless range: IBM block
Skipping useless range: Patrick Air Force Base
Skipping useless range: National Aeronautics and Space Administration
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: EDS Network Naming and Addressing Management (NNAM)
Skipping useless range: HQ SSG/DIGNN
Skipping useless range: HQ AFRC/SCO
Skipping useless range: HQ AFRC/SCO
Skipping useless range: Keesler Air Force Base
Skipping useless range: SSG/DIGN
Skipping useless range: HQ AFRC/SCO
Skipping useless range: Air National Guard
Skipping useless range: Andersen Air Force Base
Skipping useless range: DLA Systems Automation
Skipping useless range: DEFENSE LOGISTIC AGENCY
Skipping useless range: DECC Ogden
Skipping useless range: DSCR-ZOO
Skipping useless range: Defense Reutilization and Marketing Service
Skipping useless range: United States Naval Academy
Skipping useless range: Motorola Korea
Skipping useless range: Industrial Research Limited
Skipping useless range: Industrial Research Limited, Wellington
Skipping useless range: Industrial Research Limited
Skipping useless range: Gracefield Research Centre (IRL)
Skipping useless range: Quest Reliability LLC
Skipping useless range: Gracefield Research Centre (IRL)
Skipping useless range: HQ AFRC/SCO
Skipping useless range: 28th Communictions Squadron
Skipping useless range: 4th Communications Squadron
Skipping useless range: 27th Communications Squadron
Skipping useless range: 366 CS/SCBB
Skipping useless range: 9th Communications Squadron
Skipping useless range: 99th Communications Squadron
Skipping useless range: DoD Network Information Center
Skipping useless range: USArmy National Guard Bureau
Skipping useless range: Boeing Corporation
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: Lucent Technologies
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: AT&T Bell Laboratories
Skipping useless range: HQ 5th Signal Command
Skipping useless range: State of Minnesota
Skipping useless range: Irish Government
Skipping useless range: DoD Network Information Center
Skipping useless range: DoD Network Information Center
Skipping useless range: Wright-Patterson Air Force Base
Skipping useless range: Commander-In-Chief
Skipping useless range: 48th Tactical Fighter Wing
Skipping useless range: DISA ITESO
Skipping useless range: DISA Columbus Level II NOC
Skipping useless range: DoD Network Information Center
Skipping useless range: DoD Network Information Center
Skipping useless range: DoD Network Information Center
Skipping useless range: HQ, 5th Signal Command
Skipping useless range: Naval Sea Systems Command
Skipping useless range: 106TH SIGNAL BRIGADE
Skipping useless range: Polycom Ltd. Portable Block
Skipping useless range: Polycom Ltd. Portable Block
Skipping useless range: BC GOV ITSD - SINGAREN (BCSYSTEMS13)
Skipping useless range: Government of Canada research lab connected to BC Gigapop via
Skipping useless range: Simcoe County Health Services
Skipping useless range: County of Simcoe
Skipping useless range: Gouvernement du Quebec - MSSS
Skipping useless range: ONT-GOV2
Skipping useless range: ONT-GOV3
Skipping useless range: The Procter and Gamble Company
Skipping useless range: Concentrator Management Desk
Skipping useless range: Air National Guard
Skipping useless range: DoD Network Information Center
Skipping useless range: Software Editing Corporation
Skipping useless range: 598th US Army TML Group
Skipping useless range: MTMC
Skipping useless range: USASC
Skipping useless range: USAISC Western Area
Skipping useless range: Commander
Skipping useless range: Defense Contract Management Agency
Skipping useless range: DoD Network Information Center
Skipping useless range: Headquarters, USAAISC
Skipping useless range: EDS
Skipping useless range: State Electricity Commission, Victoria (138756)
Skipping useless range: Dr. Ruff Software GmbH
Skipping useless range: HQ 5th Signal Command
Skipping useless range: HQ, 5th Signal Command
Skipping useless range: Army Information Systems Software Center MELPAR-NET2 (NET-147-104-0-0-1)
Skipping useless range: HQ, 5th Signal Command
Skipping useless range: 1112th Signal Battalion
Skipping useless range: Oracle-CoSprings AGG
Skipping useless range: Oracle-RMDC-AGG
Skipping useless range: Oracle-RestonVA-AGG
Skipping useless range: EDS Network Naming and Addressing Management (NNAM)
Merged range 'EMI MUSIC DE MEXICO SA DE CV', with range 'EMI MUSIC DE MEXICO SA DE CV'
Skipping useless range: COMUNE DI ANDRIA
Skipping useless range: McDonald\
Skipping useless range: NATO Headquarters
Skipping useless range: Adobe Systems Inc
Skipping useless range: Los Angeles Municipal Court
Skipping useless range: California Department of Corrections
Skipping useless range: US Army Information Systems Command
Skipping useless range: DoD Network Information Center
Skipping useless range: DoD Network Information Center
Skipping useless range: DoD Network Information Center
Skipping useless range: PEO STAMIS
Skipping useless range: United States Army Corps of Engineers
Skipping useless range: United States Army Corps of Engineers
Skipping useless range: United States Army Corps of Engineers
Merged range 'PEO STAMIS', with range 'DoD Network Information Center'
Merged range 'United States Army Corps of Engineers', with range 'DoD Network Information Center'
Skipping useless range: PEO STAMIS
Merged range 'DoD Network Information Center, DoD Network Inform', with range 'DoD Network Information Center'
Skipping useless range: United States Army Corps of Engineers
Skipping useless range: Directorate of Information Management
Skipping useless range: Interscope 360
Skipping useless range: Rain Cinema, Inc
Skipping useless range: UASISC-Vint Hill
Skipping useless range: Council of Ministers Office
Skipping useless range: Network Operations Center
Skipping useless range: DoD Network Information Center
Skipping useless range: www.ktjlaw.com
Skipping useless range: Police Buildings No. 3 - Misr Station
Skipping useless range: Techno Mina Communications - TMC
Skipping useless range: Smart Link Project Office
Skipping useless range: NLM.NIH.GOV maintainer
Skipping useless range: Wipro, Limited
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: State of Georgia (DOAS-CSD)
Skipping useless range: bt fakes NaviSite - Los Angeles
Skipping useless range: Your OneStop Network, Inc
Skipping useless range: ClearBlue Technologies - Vienna, VA
Skipping useless range: ClearBlue Technologies - New York City
Skipping useless range: ClearBlue Technologies - San Francisco, CA
Skipping useless range: Navisite-Surebridge-Andover
Skipping useless range: ClearBlue Technologies - Emmeryville, CA
Skipping useless range: ClearBlue Technologies - Dallas
Skipping useless range: ClearBlue Technologies - Los Angeles
Skipping useless range: ClearBlue Technologies - Dallas
Skipping useless range: China-Beijing-persistent connection attempts(revis
Merged range 'Verestar', with range 'Verestar'
Skipping useless range: Verestar
Skipping useless range: route object for IBM
Skipping useless range: Route Object for IBMGSMIA
Skipping useless range: IBM
Skipping useless range: BBN Communications
Skipping useless range: Bull HN Information Systems Inc
Skipping useless range: Royal Signals and Radar Establishment
Skipping useless range: Argonne National Laboratory
Skipping useless range: Argonne National Laboratory
Skipping useless range: Argonne National Laboratory
Skipping useless range: CSIRO IT Services
Skipping useless range: Hewlett-Packard Company
Skipping useless range: Schlumberger Laboratory for Computer Science
Skipping useless range: Agilent Technologies Europe
Skipping useless range: HP Halifax
Skipping useless range: U.S. Army CECOM RDEC Software Engineering Directo
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Hughes Aircraft Company
Skipping useless range: Hewlett-Packard Company HP4 (138815)
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: HQ US Central Command
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: White Sands Missile Range
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Naval Reserve Information System Office
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: imported inetnum object for IRSS
Skipping useless range: Procter&Gamble Route to Brussels VPN
Skipping useless range: Agilent Technologies
Skipping useless range: Pepsi Cola Company
Skipping useless range: Agilent Technologies
Skipping useless range: Agilent Technologies
Skipping useless range: SPAWAR System Center, National Capitol Region
Skipping useless range: SPAWAR SCC NCR
Skipping useless range: SSG/DIGN
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: California Department of Corrections
Skipping useless range: Center for Information Services
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: NOAA National Geodetic Survey
Skipping useless range: Hewlett-Packard Sverige AB
Skipping useless range: Tyco Electronics Corporation
Skipping useless range: EDS Network Naming and Addressing Management (NNAM)
Skipping useless range: Booya.music.de-Drizzly.de,Pdntdr.de www.vdm-musik
Skipping useless range: Hewlett-Packard Company (135438)
Skipping useless range: Motorola Network Computing
Skipping useless range: Motorola
Merged range 'Picturetel Corporation', with range 'Bogon'
Skipping useless range: Syscom Computer Engineering Co,Ltd
Skipping useless range: USAREUR ODCSIM, Office of Command,Control, and Com
Skipping useless range: Navy Computers and Telecommunications Station NCTSW-NET7 (NET-192-73-210-0-1)
Skipping useless range: Navy Computers and Telecommunications Station NCTSW-NET8 (NET-192-73-211-0-1)
Skipping useless range: Navy Computers and Telecommunications Station NCTSW-NET9 (NET-192-73-212-0-1)
Skipping useless range: Honeywell Paper Machine Automation Center
Skipping useless range: DoD Network Information Center
Skipping useless range: Thomson Professsional Publishing
Skipping useless range: MKS Inc
Skipping useless range: U.S. Merit Systems Protection Board
Skipping useless range: EDS, Koeln
Skipping useless range: MTMC-SUNNYPOINT
Skipping useless range: MTMC-CHARLESTON
Skipping useless range: 833d Transportation Battalion
Skipping useless range: Central Regional Storage Management Office
Skipping useless range: 596th Transportation Terminal Group
Skipping useless range: US Army Aviation and Missile Command
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: Motorola Internet Block 2 via CSC
Skipping useless range: EDS Network Naming and Addressing Management (NNAM)
Skipping useless range: Motorola
Skipping useless range: EDS Network Naming and Addressing Management (NNAM)
Skipping useless range: Directorate of Information Management
Skipping useless range: Koninklijke Philips Electronics N.V
Merged range 'Koninklijke Philips Electronics N.V', with range 'Philips Kommunikations Industrie'
Skipping useless range: Philips Fernmeldewerk GmbH
Skipping useless range: Naval Hospital Cherry Point
Skipping useless range: City of Turku
Skipping useless range: Cambridgeshire County Council
Skipping useless range: Software & Systeme Erfurt GmbH
Skipping useless range: British Columbia Provincial Government
Merged range 'SACLANT Undersea Research Centre', with range 'NATO SACLANT Undersea Research Centre'
Skipping useless range: SACLANT Undersea Research Centre
Skipping useless range: Bureau of Medicine and Surgery
Skipping useless range: Bureau of Medicine and Surgery
Skipping useless range: Toshiba Electronics Europe GmbH
Skipping useless range: TOSHIBA-EUROPEAN-NETWORK
Skipping useless range: TOSHIBA-EUROPE
Skipping useless range: TOSHIBA-EUROPE
Skipping useless range: route for northrop grumman
Skipping useless range: CreatRoute for customer Northrop Grumman
Skipping useless range: Boeing Computer Support Services
Skipping useless range: U.S. ARMY - Electronic Warfare / RSTAD
Skipping useless range: Eduskunnan kirjasto (Library of Parliament)
Skipping useless range: HQAMC
Skipping useless range: Perot Systems
Merged range 'DOIM', with range 'DoD Network Information Center'
Skipping useless range: Scientific Atlanta
Skipping useless range: Scientific Atlanta
Skipping useless range: Commissariat a l'Energie Atomique
Skipping useless range: Commissariat a L'Energie Atomique
Skipping useless range: 3M UK LTD
Skipping useless range: SOCIALSTYRELSEN
Skipping useless range: European Regional Medical Center
Skipping useless range: Boeing Computer Support Services
Skipping useless range: Hewlett-Packard Company
Skipping useless range: Hewlett-Packard Company
Skipping useless range: DISA, Joint Interoperability
Merged range 'HQ, 5th Signal Command', with range 'NETCOM'
Skipping useless range: Texas Instruments IS&amp;S Electronic Communications
Skipping useless range: Commander, Task Force SIX THREE, Naples, Italy
Skipping useless range: Hewlett-Packard Company
Skipping useless range: Ft. Gordon Contracting Office
Skipping useless range: U.S. ARMY Tank-Automotive Command
Skipping useless range: Directorate of Information Management
Skipping useless range: MIPA-R
Merged range 'DoD Network Information Center', with range 'NETCOM'
Skipping useless range: Department of Energy
Skipping useless range: Philips Pontiac Mazda
Skipping useless range: GOVONCA8
Skipping useless range: GOVONCA9
Skipping useless range: State of Texas, Office of the Governor
Skipping useless range: route for Hewlett Packard
Skipping useless range: State of Washington Department of Revenue
Skipping useless range: GOVERNMENT SYSTEMS INC
Skipping useless range: COMNAVSURFLANT
Skipping useless range: Procter&Gamble Route to Brussels POP
Skipping useless range: Procter&Gamble Route to Brussels Extranet
Skipping useless range: Pure Software, Inc
Skipping useless range: Pure Software, Inc
Skipping useless range: NET-OMAHA-CITY4
Skipping useless range: Mitsui Computer Ltd
Skipping useless range: High Performance Computing Modernization Office
Skipping useless range: CSIRO IT Services (134162)
Skipping useless range: NBC UNIVERSAL, INC
Skipping useless range: Simon & Schuster
Skipping useless range: Stadtverwaltung Winterthur
Skipping useless range: Stadtverwaltung Winterthur
Skipping useless range: The Walt Disney Company Ltd
Skipping useless range: World Health Organisation
Skipping useless range: World Health Organisation
Skipping useless range: World Health Organisation
Skipping useless range: Siemens Nixdorf Informationssysteme AG
Skipping useless range: Umweltministerium des Landes Sachsen-Anhalt, Magdeburg
Skipping useless range: CCTA, The Government Centre for Information Syste
Skipping useless range: FR-MESR-03-Ministere-de-l
Merged range ' Commissariat a l'Energie Atomique', with range 'Commissariat a l'
Skipping useless range: Commissariat a l'Energie Atomique
Skipping useless range: Commissariat a l'Energie Atomique
Skipping useless range: FR-MESR-05-Ministere-de-l
Skipping useless range: FR-MESR-06-Ministere-de-l
Skipping useless range: FR-MESR-07-Ministere-de-l
Skipping useless range: MRES - Ministere de l'Enseignement Superieur et de
Skipping useless range: Commissariat a l'Energie Atomique
Skipping useless range: Havas Informatique
Skipping useless range: SONY-C-NET
Skipping useless range: Brunner Reinhard
Skipping useless range: GDATA Software GmbH
Skipping useless range: Mannheimer Morgen Grossdruckerei und Verlag GmbH
Skipping useless range: www.policjawielun.pnet.pl
Skipping useless range: www.ems.com.pl
Skipping useless range: Advocatenkantoor van Dam
Skipping useless range: Stichting Amsterdams Filmhuis
Skipping useless range: Filmhuis Den Haag
Skipping useless range: Agentur fuer Arbeit Paderborn ARGE
Skipping useless range: Geologische Bundesanstalt
Skipping useless range: Philips Electronics Nederland BV
Skipping useless range: Benelux Merkenbureau
Skipping useless range: Bundesamt fuer Strahlenschutz
Skipping useless range: Ministerie van Buitenlandse Zaken
Skipping useless range: Valtionvarainministerio
Skipping useless range: Siemens AG
Skipping useless range: Comune di Trento
Skipping useless range: Military Technical Academy, Bucharest
Skipping useless range: FR-RAEI-ATMEL-GRENOBLE-FW-OPENX-OLE
Skipping useless range: FR-RAEI-HITACHI-DATA-SYSTEMS-FW-OPENX-OLE
Skipping useless range: FR-RAEI-LYCEE-MILITAIRE-DE-ST-CYR-FW-OPENX-OLE AP2
Skipping useless range: FR-RAEI-MUTUELLE-GENERALE-DE-LA-POLICE-FW-OPENX-OL
Skipping useless range: Avenir havas media
Merged range ' Police Training Centre', with range 'Police Training Centre'
Skipping useless range: Police Training Centre
Skipping useless range: Bundesanstalt fuer Arbeit
Skipping useless range: Landkreis Potsdam-Mittelmark
Skipping useless range: Siemens Nixdorf Informationssysteme AG, Muenchen
Skipping useless range: FR-RAEI-GEMPLUS-LB_INTERNET
Skipping useless range: FR-RAEI-ATMEL-NANTES-SA-LB_INTERNET
Skipping useless range: FR-RAEI-ATI-TECHNOLOGIES-FRANCE-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-BJNC1
Skipping useless range: FR-RAEI-FRANCE-TELECOM-REL_SMTP
Skipping useless range: CapGemini
Skipping useless range: FR-RAEI-ATMEL-ROUSSET-LB_INTERNET
Skipping useless range: FR-RAEI-LEXMARK-INTERNATIONAL-SNC-LB_INTERNET
Skipping useless range: FR-RAEI-LEXMARK-INTERNATIONAL-SAS-LB_INTERNET
Skipping useless range: FR-RAEI-PHILIPS-INTERNET-CONSULTING-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: Gemeindepruefungsanstalt Baden-Wuerttemberg, Stuttgart
Skipping useless range: www.law.co.il
Skipping useless range: ubi-soft romania
Skipping useless range: SUMI SOFTWARE DEVELOPMENT
Skipping useless range: ERNST & YOUNG SRL
Skipping useless range: Adaptec, Inc
Skipping useless range: Autodesk, Inc
Skipping useless range: State of California
Skipping useless range: Konami.of.America.Inc.US
Skipping useless range: Canon Information Systems
Skipping useless range: THQ
Skipping useless range: City of Simi Valley
Skipping useless range: City of Los Angeles Department of Airports
Skipping useless range: Navy Systems Support Group
Skipping useless range: Texas Instruments - Acer Inc
Skipping useless range: Philips Taiwan Ltd
Skipping useless range: Ministry of Defence
Skipping useless range: Philips Electronics Industries Taiwan Ltd
Skipping useless range: Thomson Television Singapore Pte Ltd
Skipping useless range: Kyushu Matsushita Electric (Malaysia) Sdn. Bhd
Skipping useless range: IBM Singapore Pte Ltd
Skipping useless range: Tata Technologies Pte Ltd
Skipping useless range: Motorola Malaysia Sdn Bhd
Skipping useless range: Honeywell Pte Ltd
Skipping useless range: Ministry of Defence
Skipping useless range: NEC Semiconductors Singapore Pte. Ltd
Skipping useless range: Public Service and Merit Protection Commission
Skipping useless range: Australian Federal Police
Skipping useless range: Health Insurance Commission
Skipping useless range: Department of Employment,Education,Training and Youth Affairs
Skipping useless range: Department Of Employment Education Training And Youth Affairs
Skipping useless range: Department of Workplace Relation and Small Business
Skipping useless range: Ernst & Young
Skipping useless range: Australian Broadcasting Corporation
Skipping useless range: Attorney-General\
Skipping useless range: Department of Fair Trading
Skipping useless range: Aboriginal & Torres Strait Islander Commission
Skipping useless range: Joint House Department
Skipping useless range: Department of the Treasury
Skipping useless range: Waterways Authority
Skipping useless range: Health Insurance Commission
Skipping useless range: Western Australia Police Service
Skipping useless range: Australian Taxation Office
Skipping useless range: Department of Housing
Skipping useless range: Bundesamt fuer Wehrtechniek und Beschaffung
Skipping useless range: Sony.Corporation.Digital.Telecommunications.Networ
Skipping useless range: GE Toshiba Silicone Co., Ltd
Skipping useless range: Sony.Broadband.Solutions.Corp.JP
Skipping useless range: Data General CC
Skipping useless range: Sun Microsystems GmbH c/o Global SAP-Sun Competence Center
Skipping useless range: IBM Deutschland
Skipping useless range: Intel GmbH
Skipping useless range: SIEMENS AG
Skipping useless range: Compaq EMEA
Skipping useless range: Ernst & Young Consulting GmbH
Skipping useless range: Andersen Consulting
Skipping useless range: Cognos GmbH
Skipping useless range: Compaq EMEA
Skipping useless range: RCSC Networking SAP-AG
Skipping useless range: UNISYS Deutschland GmbH
Skipping useless range: ORACLE Deutschland GmbH
Skipping useless range: ORACLE Deutschland GmbH
Skipping useless range: Redwood Software BV
Skipping useless range: ORACLE Deutschland GmbH
Skipping useless range: IBM Deutschland
Skipping useless range: IBM Deutschland
Skipping useless range: Sony Marketing (Japan) Inc
Skipping useless range: Mint Bureau Ministry Of Finance
Skipping useless range: Nippon Koei Co Ltd
Skipping useless range: Naval Supply Systems Command
Skipping useless range: Metro Goldwyn Mayer, Inc
Skipping useless range: Price Waterhouse LLP
Skipping useless range: Synopsys, Inc
Skipping useless range: EMC Corporation, Hopkinton
Skipping useless range: Radio e Televisao Record S.A
Skipping useless range: Fuji Photo Film do Brasil Ltda
Skipping useless range: SAP, Inc
Skipping useless range: State of Florida - Dept of Revenue
Skipping useless range: PWC BPO do Brasil Ltda
Skipping useless range: Hallesche Wasser und Abwasser
Skipping useless range: DASSAULT AVIATION
Skipping useless range: Defensie Telematica Organisatie
Skipping useless range: Sun Microsystems GmbH
Skipping useless range: Intel Corporation
Skipping useless range: Mannheimer Versorgungs- und Verkehrsgesellschaft m
Skipping useless range: AEROSPATIALE MISSILES
Skipping useless range: BVG Berliner Verkehrsbetriebe
Skipping useless range: Naval Supply Systems Command
Skipping useless range: SAP Belgium NV/SA
Skipping useless range: SAP Arabia - Gulf Region
Skipping useless range: SAP Romania SRL
Skipping useless range: SAP Bilgi Islem Sistemleri
Skipping useless range: SAP Arabia
Skipping useless range: SAP CYPRUS LTD
Skipping useless range: SAP Bulgaria
Skipping useless range: SAP Asia Pte. Ltd
Skipping useless range: SAP France S.A
Skipping useless range: Stadtverwaltung Wiesloch
Skipping useless range: Intershop Communications
Skipping useless range: DSC Software AG
Skipping useless range: City of Vancouver
Skipping useless range: Voigt Software und Unternehmensberatung GmbH
Skipping useless range: Justice and Attorney General
Skipping useless range: Amt fuer Agrarstruktur Hannover
Skipping useless range: Kreiswerke Heinsberg GmbH
Skipping useless range: SAP America, Inc
Skipping useless range: Neubrandenburger Stadtwerke GmbH
Skipping useless range: Landeshauptstadt Stuttgart
Skipping useless range: SAP AG
Skipping useless range: Siebel Systems, Inc
Skipping useless range: Staedtische Werke Ueberlandwerke Coburg
Skipping useless range: Hampshire County Council
Skipping useless range: SAP AG
Skipping useless range: Motorola, Inc. Corporate Contracts
Skipping useless range: Berliner Hafen- und Lagerhausbetriebe (BEHALA)
Skipping useless range: Neue Westfaelische Zeitung GmbH &amp; Co. KG
Skipping useless range: Cinemax AG, Hamburg
Skipping useless range: Landeszentralbank Bremen Niedersachsen
Skipping useless range: Stadtwerke Luedenscheid GmbH
Skipping useless range: Mitsubishi Electric PC Division Apricot Computers Ltd
Skipping useless range: Group 4 Securitas AG
Skipping useless range: Hasbro, Inc
Skipping useless range: ITT Industries Europe GmbH
Skipping useless range: Sony of Canada Ltd
Skipping useless range: Optimus S.A
Skipping useless range: Random House Inc
Skipping useless range: AEG Elektrofotografie GmbH
Skipping useless range: Deutsche Bundesbank
Skipping useless range: Stadtwerke Neumuenster
Skipping useless range: Provincie Noord-Brabant
Skipping useless range: DEUTSCHE ROCKWOOL
Skipping useless range: Stadtwerke Muenchen
Skipping useless range: Staedtische Werke Krefeld AG
Skipping useless range: Landschaftsverband Westfalen-Lippe
Skipping useless range: SAP AG
Skipping useless range: Diamond Trading Company Ltd
Skipping useless range: PriceWaterhouseCoopers Danismanlik Hizmetleri A.S
Skipping useless range: Landeszentralbank im Freistaat Bayern
Skipping useless range: Stadtwerke Dueren GmbH
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: SAP Arabia
Skipping useless range: SAP Bilgi Islem Sistemleri
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Ernst & Young Oence SMMM A.S
Skipping useless range: Saudi Aramco Mobil Refinery Company
Skipping useless range: SAP AG
Skipping useless range: Korps Landelijke Politiediensten Dienst I &amp; A
Skipping useless range: Siemens Business Services
Skipping useless range: SAP AG
Skipping useless range: IBM Schweiz SAP Solutions/Datamind
Skipping useless range: Compaq Computer AG
Skipping useless range: AIRBUS INDUSTRIE
Skipping useless range: IBM FRANCE
Skipping useless range: SAP Arabia - Gulf Region
Skipping useless range: TRW SABELT S.p.A. Div. Automotive
Skipping useless range: EDS Electronic Data Systems
Skipping useless range: IBM Svenska AB
Skipping useless range: Securitas AG
Skipping useless range: ANDERSEN CONSULTING S.A
Skipping useless range: CAP Gemini Sverige AB
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: EDS (Schweiz) AG
Skipping useless range: SAP Hrvatska d.o.o
Skipping useless range: STG - Coopers & Lybrand AG
Skipping useless range: HEWLETT PACKARD FRANCE
Skipping useless range: EDS Informationstechnologie u. Service (Deutschland) GmbH
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Cap Gemini
Skipping useless range: IBM Turk Ltd. Sti
Skipping useless range: Optimus S.A
Skipping useless range: Sharp Electronics (UK) Ltd
Skipping useless range: Sharp Electronics Europe GmbH
Skipping useless range: SAP Bilgi Islem
Skipping useless range: VIVENDI UNIVERSAL EDUCATION FRANCE
Skipping useless range: SAP AG
Skipping useless range: SAP Italia Consulting S.r.l
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Cap Gemini
Skipping useless range: POLYGRAM S.A
Skipping useless range: Rank Video Services Ltd., Willstaett
Skipping useless range: Ernst & Young Unternehmensberatung GmbH
Skipping useless range: Datenzentrale.Baden.Wuerttemberg.Ger
Skipping useless range: Zentraldienst fuer Technik und Beschaffung der Pol
Skipping useless range: SAP AG
Skipping useless range: Azienda Municipalizzata Servizi Ancona IT
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: DASSAULT AVIATION
Skipping useless range: Defensie Telematica Organisatie
Skipping useless range: EMI Italiana S.p.A
Skipping useless range: Sun Microsystems GmbH
Skipping useless range: AEROSPATIALE MISSILES
Skipping useless range: Banca Nazionale del Lavoro
Skipping useless range: Landeszentralbank.im.Freistaat.Bayern
Skipping useless range: EDS Electronic Data Systems
Skipping useless range: SAP AG
Skipping useless range: Georg Westermann Verlag
Skipping useless range: EUROCOPTER FRANCE S.A
Skipping useless range: Agfa-Gevaert AG Wiesbaden
Skipping useless range: Adaptec, Inc
Skipping useless range: EDS/Fides Informatik Basel
Skipping useless range: EDS PROGICAL
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Daimler-Benz Aerospace Airbus
Skipping useless range: Sun Microsystems GmbH
Skipping useless range: TRW Steering Systems Ltd
Skipping useless range: Bauer Software + Informatik GmbH
Skipping useless range: SAP AG
Skipping useless range: Etat du Valais.CH
Skipping useless range: Voigt Software und Unternehmensberatung GmbH
Skipping useless range: Ministerium.fuer.Finanzen.u.Energie.des.Landes.Sch
Skipping useless range: Andersen Consulting
Skipping useless range: Landeshauptstadt Stuttgart
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Accenture Services GmbH
Skipping useless range: Mitsubishi Electric PC Division Apricot Computers Ltd
Skipping useless range: Group 4 Securitas AG
Skipping useless range: Landeshauptstadt Hannover
Skipping useless range: Elektra Birseck
Skipping useless range: Philips Domestic Appliances
Skipping useless range: Deutsche Bundesbank
Skipping useless range: Telemedia International S.p.A
Skipping useless range: DASSAULT AVIATION
Skipping useless range: Provincie Noord-Brabant
Skipping useless range: Deutsche Bundesbank
Skipping useless range: DIPUTACION DE BARCELONA
Skipping useless range: SAP AG
Skipping useless range: EDS PROGICAL
Skipping useless range: SAP-RSA-I08-NL
Skipping useless range: ATAG Ernst & Young AG
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: CAP GEMINI FRANCE, Toulouse
Skipping useless range: Deutsche Welle Radio & TV International
Skipping useless range: Landeshauptstadt Stuttgart
Skipping useless range: COMPAQ FRANCE
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Unisys Belgium SA
Skipping useless range: Amdahl Deutschland GmbH
Skipping useless range: IBM Nederland N.V t.b.v. SSC Rijksoverheid
Skipping useless range: HEWLETT - PACKARD GMBH
Skipping useless range: Defence Fuels Group
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Siemens AG VS OIL2
Skipping useless range: Compaq Computer GmbH
Skipping useless range: Datenzentrale.Schleswig.Holstein.Ger
Skipping useless range: Compaq Computer AG
Skipping useless range: SAP AG
Skipping useless range: TRW Occupant Restraint Systems GmbH
Skipping useless range: IBM (Schweiz) AG
Skipping useless range: CAS Software GmbH, Pirmasens
Skipping useless range: CAP GEMINI FRANCE
Skipping useless range: Edison S.p.A., Milano
Skipping useless range: SapTech A/S
Skipping useless range: ERNST & YOUNG, Consultores
Skipping useless range: Koch, Neff & Oetinger & Co. GmbH
Skipping useless range: Politiken - Aktieselskabet Dagbladet
Skipping useless range: Cinemax AG, Hamburg
Skipping useless range: PRICE WATERHOUSE Edificio Caja Madrid
Skipping useless range: MINISTERIO DE MEDIO AMBIENTE
Skipping useless range: SUNY-CLD is implementing the US-AID
Skipping useless range: Universal Industries AS
Skipping useless range: Someru Municipality
Skipping useless range: Suure-Jaani Town Government
Skipping useless range: Rural Municipality of Puka
Skipping useless range: The Euro-Baltic Software Alliance AS
Skipping useless range: Estonian Electrical Inspectorate
Skipping useless range: Keila City Municipality
Skipping useless range: Verestar
Skipping useless range: COM de RED.ES
Skipping useless range: COM de RED.ES
Skipping useless range: Dictionary attacker
Skipping useless range: Dictionary attacker
Skipping useless range: Dictionary attacker
Skipping useless range: Stadtverwaltung Kaiserslautern
Skipping useless range: Virgin Megastore (Cyprus) Ltd
Skipping useless range: Panasonic Deutschland GmbH
Skipping useless range: CISCO SYSTEMS ITALY SRL
Skipping useless range: Sony Overseas SA Representative Office in Kazakhst
Skipping useless range: Ministere de l'Amenagement du Territoire, de l'Eq
Skipping useless range: Ministere de l'Amenagement du Territoire, de l'Equ
Skipping useless range: Ministere de l'Amenagement du Territoire, de l'Eq
Skipping useless range: SYBASE MAROC
Skipping useless range: ministere de la communication
Skipping useless range: MINISTERE DE LA SANTE
Skipping useless range: Ministere de la POPULATION
Skipping useless range: Ministere des Affaires Etrangeres et de la Coopera
Skipping useless range: Ministere de la Formation Professionnelle
Skipping useless range: consulat general des usa
Skipping useless range: consulat general des usa
Skipping useless range: dream filmsproductions sarl
Skipping useless range: ministere de l\'emploi , des affaires sociales
Skipping useless range: Force Royale de l'AIR MAROC
Skipping useless range: DIRECTION DE LA FORMATION DU MINISTERE DU TOURISME
Skipping useless range: Ministere d'Amenagement
Skipping useless range: Eidos Germany
Skipping useless range: FR-RAEI-LEXMARK-INTERNATIONAL-SNC-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-DVI-RAEI
Skipping useless range: FR-RAEI-FRANCE-TELECOM-USEI-LYON-RAEI
Skipping useless range: FR-RAEI-SAMSUNG-ELECTRONICS-FRANCE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: LANDWELL-ASSOCIE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI B
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-USGC-VANVES-LB_INTERNET
Skipping useless range: Datalog Software GmbH
Skipping useless range: European Space Agency (ESA)
Skipping useless range: Development of software for knowledge management
Skipping useless range: production of luminous ensign
Skipping useless range: Internet security
Skipping useless range: The systimax solution is the premier structured connectivity
Skipping useless range: Avaya Reasearch
Skipping useless range: Hardware & Software Dealer
Skipping useless range: Development of software for knowledge management
Skipping useless range: our company deals with Compaq
Skipping useless range: PUBBLICITA SU SCHERMI CINEMA
Skipping useless range: International LAWYERS Company
Skipping useless range: International LAWYERS Company
Skipping useless range: music evolution
Skipping useless range: MP3 Italy
Skipping useless range: : our company deals with Compaq, Hp and Ibm Pc
Skipping useless range: web application and sw developement
Skipping useless range: Internet Security Systems
Skipping useless range: Scottish UFI IP Allocation from SOL
Skipping useless range: Dundee Chamber of Commerce
Skipping useless range: Scottish Parliament IP Assignment from SOL
Skipping useless range: Touch-Stone
Skipping useless range: TOUCHSTONE
Skipping useless range: Scottish Parliament
Skipping useless range: Scottish Parliament
Skipping useless range: Scottish UFI IP Allocation 2 from SOL
Skipping useless range: WEDICS Glasgow City Council Assignment
Skipping useless range: Cinema Communications Services srl
Skipping useless range: Banca Nazionale del Lavoro
Skipping useless range: Amb. del Regno del Lesotho
Skipping useless range: GI - Customer Interconnection with RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-URN-RAEI
Skipping useless range: FR-RAEI-CBS-FONDERIES-FWVPN
Skipping useless range: CapGemini
Skipping useless range: FR-RAEI-TELEMEDIA-LB_INTERNET
Skipping useless range: FR-RAEI-LEXMARK-INTERNATIONAL-SNC-LB_INTERNET
Skipping useless range: FR-RAEI-SHARP-ELECTRONICS-FRANCE-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: FR-RAEI-FRANCE-TELECOM-R-D-RAEI
Skipping useless range: FR-RAEI-FT-THE-DIGITAL-COPYRIGHT-NETWO-FWVPN
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: NETWORK OF SONY ENGLAND
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM--DAC-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-HITACHI-POWER-TOOL-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-DR-ROUEN-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI B
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-AE-LA-DEFENSE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-AMD-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-RAEI
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: FR-RAEI-FRANCE-TELECOM-CABLE-RAEI
Skipping useless range: FR-RAEI-PHILIPS-LE-MANS-RAEI
Skipping useless range: CapGemini
Skipping useless range: CapGemini
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: FR-RAEI-PREFECTURE-DE-POLICE-LB.INTERNET.FR
Skipping useless range: CORRIGANCORRIGAN
Skipping useless range: MCMAHONOBRIENDOWNSOLICITOR
Skipping useless range: Airforce Academy gen. M. R. Stefanik in Kosice
Skipping useless range: Virtual server belonging to
Skipping useless range: defense.gouv.fr
Skipping useless range: Dassault
Skipping useless range: KMD-NET-KMO
Skipping useless range: KMD-NET-SERVICES
Skipping useless range: KMD-NET-SERVICES
Skipping useless range: Centrul Republican de Informatica Republica Moldov
Skipping useless range: MINISTERUL MUNCII,system for dial up acces throug
Skipping useless range: Boonty subnet #1
Skipping useless range: Berwin Leighton Solicitors
Skipping useless range: TRW SA
Skipping useless range: Government Policy Consultants Ltd
Skipping useless range: Network of CAP GEMINI
Skipping useless range: Network of Mercury Interactive UK LTD
Skipping useless range: Network of Halliburton Energy Services
Skipping useless range: Network of SONY MUSIC (UK) LTD
Skipping useless range: Network of Sony Computer Entertainmen
Skipping useless range: Network of
Skipping useless range: Network of Orrick
Skipping useless range: Network of IBM PSS IERS EMEA COC
Skipping useless range: Network of IBM MO MWSM Software
Skipping useless range: Novell.Gmbh.Network.Ger
Skipping useless range: Network of IBM Germany Content Hosting
Skipping useless range: Network of AGILENT FINANCIAL SERVICES
Skipping useless range: Network of SAP AG
Skipping useless range: Network of Ernst Young
Skipping useless range: Network of IBM Germany Megacenter
Skipping useless range: Network of Levi Strauss & Co
Skipping useless range: Network of Cardiff Software
Skipping useless range: Network of The McGraw-Hill Companies
Skipping useless range: Network of IBM for ABB NL
Skipping useless range: Network of IBM Denmark
Skipping useless range: Network of IBM Svenska AB
Skipping useless range: Network of IBM Svenska AB
Skipping useless range: Network of IBM SMTP Service
Skipping useless range: Network of IBM Svenska AB
Skipping useless range: Network of IBM Svenska AB
Skipping useless range: Network of 3Com Nordic AB
Skipping useless range: Network of SAP Svenska AB
Skipping useless range: Network of IBM Norge AS
Skipping useless range: Network of IBM Portugal
Skipping useless range: Network of SONY LDA
Skipping useless range: Network of OneWeb IBM Finland
Skipping useless range: Network of SAP D.O.O
Skipping useless range: Network of Delphi Packard Elektrik Sistemleri Ltd
Skipping useless range: Network of IBM Ireland Limited
Skipping useless range: Network of Novell
Skipping useless range: Network of IBM Dow Chemical
Skipping useless range: Network of PACKETEER EUROPE B.V
Skipping useless range: Network of IBM Nederland/BTO
Skipping useless range: Network of SAP Finland Oy
Skipping useless range: Network of Accenture
Skipping useless range: Network of Sony Music Entertainment Kft
Skipping useless range: Network of AVAYA COMMUNICATIONS
Skipping useless range: Network of Sony Computer Entertainment Austria
Skipping useless range: Network of IBM EBUSINESS
Skipping useless range: Network of Eugster & Frismag
Skipping useless range: Network of Agfa Gevaert
Skipping useless range: Network of IBM E-SNI
Skipping useless range: Network of FUJI Hunt In
Skipping useless range: Network of IBM EBUSINESS
Skipping useless range: Network of Agfa-Gevaert
Skipping useless range: Network of Agfa Gevaert
Skipping useless range: Network of IBM Finland
Skipping useless range: Network of Agfa Gaevert
Skipping useless range: Network of IBM Finland
Skipping useless range: Network of IBM France
Skipping useless range: Jxrvamaa Municipality
Skipping useless range: CPS Perm
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: FR-RAEI-HITACHI-SOFTWARE-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-BE-MSE-STI-LB_INTERNET
Skipping useless range: FR-RAEI-DEPOLABO-CHEZ-FRANCE-TELECOM-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE--TELECOM---TRANSPAC-RAEI
Skipping useless range: FR-RAEI-NOKIA-FRANCE-SA-LB_INTERNET
Skipping useless range: FR-RAEI-MINISTERE-DE-LA-DEFENSE-LB_INTERNET
Merged range 'GI - Customer Interconnection with RAEI Backbone', with range 'GI - Customer Interconnexion With RAEI Backbone'
Merged range 'GI - Customer Interconnexion With RAEI Backbone', with range 'GI - Customer Interconnexion With RAEI Backbone'
Skipping useless range: FR-RAEI-HITACHI-PRINTING-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-RAEI
Merged range 'GI - Customer Interconnection with RAEI Backbone', with range 'GI - Customer Interconnexion With RAEI Backbone'
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Stadtwerke Bielefeld GmbH
Skipping useless range: POLYGRAM S.A
Skipping useless range: ASETRA group AG BU Consulting SAP
Skipping useless range: Azienda Municipalizzata Servizi Ancona IT
Skipping useless range: CIC Video International
Skipping useless range: Ministere Bruxelles Capitale, BRUXELLES
Skipping useless range: EUROCOPTER FRANCE S.A
Skipping useless range: SAP (UK) Ltd
Skipping useless range: LEG Landesentwicklungsgesellschaft
Skipping useless range: Bundesministerium fuer Finanzen, Wien
Skipping useless range: SAP Italia Consulting S.r.l
Skipping useless range: Panasonic Canada Inc
Skipping useless range: SAP America, Inc
Skipping useless range: LEG Landesentwicklungsgesellschaft Thueringen mbH
Skipping useless range: AEROSPATIALE AERONAUTIQUE
Skipping useless range: NIBM Intern Transport en Magazijn Techniek B.V
Skipping useless range: Nuernberger Rechenzentrale GmbH
Skipping useless range: Zentrum fuer Kommunikationstechnik
Skipping useless range: FABRICA NACIONAL DE MONEDA Y TIMBRE
Skipping useless range: Cap Gemini Singapore Pte Ltd
Skipping useless range: Bundeswehr Systeminstandsetzungszentrum 890
Skipping useless range: Bundeswehr Systeminstandsetzungszentrum 860
Skipping useless range: Bundeswehr Systeminstandsetzungszentrum 870
Skipping useless range: SUN Microsystems AG
Skipping useless range: Bundeswehr Systeminstandsetzungszentrum 800
Skipping useless range: System-Instandsetzungszentrum 850 Kaserne Starkenburg
Skipping useless range: Stadtverwaltung Biel
Skipping useless range: Comune di Bologna Pz. Maggire 6 I-40121 Bologna OS
Skipping useless range: Birra Peroni Industriale S.p.A
Skipping useless range: Maerkisches Verlags- und Druckhaus GmbH & Co. KG
Skipping useless range: Stadtreinigung Hamburg
Skipping useless range: DISTRIBUIDORA DE TELEVISION DIGITAL, S.A
Skipping useless range: PricewaterhouseCoopers
Skipping useless range: Landeszentralbank im Freistaat Sachsen und in Thue
Skipping useless range: Bundesstadt Bonn
Skipping useless range: Abrechnungszentrum Emmendingen des
Skipping useless range: Bertelsmann mediaSystems GmbH
Skipping useless range: SCM Microsystems GmbH
Skipping useless range: Ericsson Ahead Communications System GmbH
Skipping useless range: Syncra Software, Inc
Skipping useless range: ITT Cannon
Skipping useless range: JVC.Canada.Inc.CA
Skipping useless range: SAP Canada Inc
Skipping useless range: EMC Corporation, Hopkinton
Skipping useless range: Autodesk, Inc
Skipping useless range: Hasbro, Inc
Skipping useless range: ATI Technologies Inc
Skipping useless range: Macromedia, Incorporated
Skipping useless range: Gobierno del Estado de Guanajuato
Skipping useless range: OCE Printing Systems
Skipping useless range: Bundesdruckerei GmbH
Skipping useless range: DVG Gesellschaft fuer Datenverarbeitung der badischen Spark
Skipping useless range: Bundesministerium der Finanzen
Skipping useless range: Warner Bros Stores (UK) Ltd
Skipping useless range: Daewoo Electronics UK Ltd
Skipping useless range: Maerkische Verlags- und Druck-GmbH
Skipping useless range: Oce (Schweiz) AG
Skipping useless range: Stadtwerke Trier GmbH
Skipping useless range: Stadtwerke Trier GmbH
Skipping useless range: SAP New Zealand Limited
Skipping useless range: NSW Treasury
Skipping useless range: Department of Foreign Affairs and Trade
Skipping useless range: IP Australia
Skipping useless range: Department of Corrections
Skipping useless range: Healthlink South Limited
Skipping useless range: Administrative Appeals Tribunal
Skipping useless range: Austereo Pty Limited
Skipping useless range: NIIT Limited
Skipping useless range: SAP AG
Skipping useless range: Ministere Bruxelles Capitale, BRUXELLES
Skipping useless range: SAP (UK) Ltd
Skipping useless range: LEG Landesentwicklungsgesellschaft
Skipping useless range: Sun Microsystems (Schweiz) AG, Schwerzenbach
Skipping useless range: Bundesministerium fuer Finanzen, Wien
Skipping useless range: Told & Skattestyrelsen
Skipping useless range: Future Software GmbH, Haar b. Muenchen
Skipping useless range: SAP Italia Consulting S.r.l
Skipping useless range: SAP AG
Skipping useless range: Gruner + Jahr AG & Co
Skipping useless range: SDL International
Skipping useless range: Schott Musik International GmbH & Co. KG, Mainz
Skipping useless range: Group 4 Securitas (International) B.V
Skipping useless range: LEG Landesentwicklungsgesellschaft Thueringen mbH
Skipping useless range: Sony Deutschland GmbH
Skipping useless range: Bundeswehr.Systeminstandsetzungszentrum.890
Skipping useless range: Fuji Electric GmbH
Skipping useless range: JVC / Spitzer Electronic AG, Oberwil
Skipping useless range: AEROSPATIALE AERONAUTIQUE
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Bundeswehr.Systeminstandsetzungszentrum.800
Skipping useless range: System-Instandsetzungszentrum 850 Kaserne Starkenburg
Skipping useless range: Stadtverwaltung Biel
Skipping useless range: PricewaterhouseCoopers
Skipping useless range: DIRECCION GENERAL DE LA POLICIA
Skipping useless range: DFS Deutsche Flugsicherung GmbH
Skipping useless range: Comune di Bologna IT
Skipping useless range: SAP AG
Skipping useless range: PricewaterhouseCoopers Ltd
Skipping useless range: Cap Gemini
Skipping useless range: DISTRIBUIDORA DE TELEVISION DIGITAL, S.A
Skipping useless range: Ministerie van Justitie, 2511 EX 'S-GRAVENHAGE
Skipping useless range: Landeszentralbank.im.Freistaat.Sachsen.und.in.Thue
Skipping useless range: Landeszentralbank.in.Rheinland.Pfalz.und.im.Saarla
Skipping useless range: LVA Landesversicherungsanstalt Baden
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Dell Computer GmbH
Skipping useless range: Provinciale Hogeschool Hasselt Provincie Limburg
Skipping useless range: Price Waterhouse Sp. z o.o. Business Information Technologies
Skipping useless range: Ericsson Ahead Communications System GmbH
Skipping useless range: ERNST & YOUNG, LDA
Skipping useless range: Bundeswertpapierverwaltung
Skipping useless range: Bundesdruckerei GmbH
Skipping useless range: CPA Rechenzentrum Gesellschaft
Skipping useless range: DVG Gesellschaft fuer Datenverarbeitung der badischen Spark
Skipping useless range: Bundesministerium.der.Finanzen
Skipping useless range: Warner Bros Stores (UK) Ltd
Skipping useless range: Daewoo Electronics UK Ltd
Skipping useless range: Oce (Schweiz) AG
Skipping useless range: Sun Microsystems GmbH
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: Unisys Italia S.p.A
Skipping useless range: Huntsman.Film.Products.DE
Skipping useless range: Haarmann, Hemmelrath & Partner
Skipping useless range: Honeywell AG
Skipping useless range: Radio Televisione Italiana S.p.A
Skipping useless range: Como Softwareentwicklungs GmbH
Skipping useless range: INVAR SYSTEM Sp. z o.o. Oddzial Konsultingu SAP
Skipping useless range: HZD - Hessische Zentrale fuer Datenverarbeitung
Skipping useless range: Edel Records GmbH
Skipping useless range: KSD Kanton und Stadt Schaffhausen.CH
Skipping useless range: Bundesamt.fuer.Wirtschaft
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: LVA Landesversicherungsanstalt Wuerttemberg
Skipping useless range: SAP AG
Skipping useless range: PricewaterhouseCoopers
Skipping useless range: EMPRESA NACIONAL BAZAN DE CONSTRUCCION NAVALES MILITARES
Skipping useless range: SAP America, Inc
Skipping useless range: Bayerisches Staatsministerium fuer Ernaehrung
Skipping useless range: Ministerie van Volksgezondheid, Welzijn en Sport
Skipping useless range: Veritas Software Vertriebs GmbH
Skipping useless range: Ernst & Young MCS Sp. z o.o
Skipping useless range: Baudirektion Kanton Zuerich.CH
Skipping useless range: Bundesministerium.fuer.Ernaehrung.Landwirtschaft.u
Skipping useless range: SAP Italia Consulting S.r.l
Skipping useless range: CANAL PLUS
Skipping useless range: Centre National d'Etudes Spatiales
Skipping useless range: OCE Groupware Technology
Skipping useless range: CAMARA OFICIAL DE COMERCIO INDUSTRI
Skipping useless range: NSE Software AG
Skipping useless range: PricewaterhouseCoopers
Skipping useless range: SAP AG
Skipping useless range: SAP AG
Skipping useless range: COREBIT SapTech A/S
Skipping useless range: PriceWaterhouseCoopers
Skipping useless range: Landesbetrieb für Datenverarbeitung und Statistik
Skipping useless range: ANDERSEN CONSULTING, S.A
Skipping useless range: Kirch Media KG aA
Skipping useless range: IBM
Skipping useless range: Europaeisches Patentamt
Skipping useless range: European Patent Office
Skipping useless range: Koordination GLOBUS-Betriebe GmbH & Co. KG
Skipping useless range: Universitaet Hannover
Skipping useless range: Ataris GmbH
Skipping useless range: Sussex Police
Skipping useless range: AMD Saxony Manufacturing GmbH
Skipping useless range: Zweckverband Kommunale Datenverarbeitung Oldenburg
Skipping useless range: Remote connection to SAP
Skipping useless range: Banca Nazionale del Lavoro
Skipping useless range: Loewen-Entertainment GmbH
Skipping useless range: Rostocker Strassenbahn AG (RSAG)
Skipping useless range: Panasonic Industrial Europe Ltd
Skipping useless range: Fuji Magnetics GmbH
Skipping useless range: SAP France S.A
Skipping useless range: SAP AG
Skipping useless range: SAP America MCI Frame port
Skipping useless range: AC Nielsen
Skipping useless range: AC.Nielsen.US
Skipping useless range: Deluxe Video Services Inc
Skipping useless range: Science Applications International
Skipping useless range: Compaq Computer Corporation
Skipping useless range: Parametric Technology Corporation
Skipping useless range: Schlumberger Oil Services
Skipping useless range: Universal Systems
Skipping useless range: Siemens Power Corporation
Skipping useless range: EMC Corporation
Skipping useless range: Integrated Device Technology
Skipping useless range: SAP Canada
Skipping useless range: Syncra Software, Inc
Skipping useless range: ITT Cannon
Skipping useless range: Lockheed Martin Enterprise Information Systems
Skipping useless range: SAP America ISDN port
Skipping useless range: Northrop Grumman IS&A
Skipping useless range: Centro Cuesta Nacional
Skipping useless range: Transmeta
Skipping useless range: Lockheed Martin Enterprise
Skipping useless range: SAP Canada SHL Systemhouse
Skipping useless range: Sharp Electronics Corporation
Skipping useless range: SAP Canada MultiHexa
Skipping useless range: Cognos Incorporation
Skipping useless range: Motorola, Inc
Skipping useless range: SAP AG
Skipping useless range: IBM Competence Center
Skipping useless range: Daewoo Electronics Deutschland GmbH
Skipping useless range: LVA Landesversicherungsanstalt Hannover
Skipping useless range: Bundesamt.fuer.Wehrverwaltung.Bonn
Skipping useless range: Bundeswehr.Systeminstandsetzungszentrum.860
Skipping useless range: Bundeswehr.Systeminstandsetzungszentrum.870
Skipping useless range: Giesecke & Devrient GmbH
Skipping useless range: Willy Bogner GmbH & Co. KGaA
Skipping useless range: SAP AG
Skipping useless range: Raytheon Aircraft
Skipping useless range: Unisys Corporation
Skipping useless range: FileNet Corporation
Skipping useless range: Panasonic Kyushu Matsushita Electric Co
Skipping useless range: SAS Institute, Inc
Skipping useless range: Kimberly-Clark Corporation
Skipping useless range: Lexmark International Group
Skipping useless range: Integrated Device Technology, Inc
Skipping useless range: Texas Instruments Incorporated
Skipping useless range: Advanced Micro Devices, Inc
Skipping useless range: Computer Sciences Corporation
Skipping useless range: Siemens Canada Ltd
Skipping useless range: American Chamber of Commerce e.V
Skipping useless range: AGAVA Software Ltd Network
Skipping useless range: SIEMENS-BUSINESS SERVICES
Skipping useless range: Cap Gemini
Skipping useless range: SIEMENS-BUSINESS SERVICES
Skipping useless range: British Interactive Broadcasting Ltd
Skipping useless range: Sega Europe Ltd
Skipping useless range: Thompson Learning
Skipping useless range: FTIP002580968 KENT COUNTY COUNCIL
Skipping useless range: ITT Travel program
Skipping useless range: Country_Artists_Ltd
Skipping useless range: Slaughter and May
Skipping useless range: Wilkin_Chapman_Solicitors
Skipping useless range: IDEALWORLD PRODUCTION
Skipping useless range: FTIP002715117 Cap Gemini
Skipping useless range: RAI - Radio Televisione Italiana
Skipping useless range: Italy</OWNER>
Skipping useless range: Harmony Music Srl
Skipping useless range: RAI - Radio Televisione Italiana
Skipping useless range: Prima Movie &amp; Pubblhing Co. Srl
Skipping useless range: www.dcs.pl
Skipping useless range: Network of Apple Computer
Skipping useless range: Network of IBM Proctor and Gamble
Skipping useless range: Network of Integrated Device Tech
Skipping useless range: Network of Apple Computers
Skipping useless range: Network of EMEA IGA IBM Network Support
Skipping useless range: Network of IBM MSA Deutschland for Sued Chemie
Skipping useless range: Network of IBM Global Network Finland
Skipping useless range: Network of IBM Deutschland GmbH
Skipping useless range: Network of Regimo Basel (IBM MSA Customer)
Skipping useless range: Network of Filemaker
Skipping useless range: Network of ACS
Skipping useless range: Network of IBM BCU Hungary
Skipping useless range: Network of IBM e-Business for Elsevier Science
Skipping useless range: Network of Apple Computers
Skipping useless range: Network of SAP CR spol. s r.o
Skipping useless range: Network of IBM Russian Feder. (RU)
Skipping useless range: Network of Nicosia Bureau
Skipping useless range: Network of Apple Computer
Skipping useless range: CPS Perm
Skipping useless range: Embassy of the Czech Republic in Latvia
Skipping useless range: Provider Local Registry State Information Network Agency
Skipping useless range: State Information Network Agency (VITA) HQ networ
Skipping useless range: Comune di Pisa is the Municipality of Pisa IT
Skipping useless range: Siemens Nixdorf Informationssys
Skipping useless range: Siemens Nixdorf Informationssysteme AG
Skipping useless range: Snohomish County Dept. of Information Services
Skipping useless range: City of Spokane
Skipping useless range: Epoch Internet
Skipping useless range: Epoch Internet
Skipping useless range: Crane Productions, Inc
Skipping useless range: Supreme Court of Pennsylvania
Skipping useless range: Air Force Research Laboratory
Skipping useless range: DoD Network Information Center
Skipping useless range: Autodesk, Inc
Skipping useless range: COMNAVSURFLANTEstimating Repair Activity
Skipping useless range: COMNAVSURFLANT
Skipping useless range: IBM
Skipping useless range: IBM
Skipping useless range: IBM Canada
Skipping useless range: Central Intelligence Agency
Skipping useless range: The Defense Information Systems Agency
Skipping useless range: Texas Department of Commerce
Skipping useless range: United States Army Corps of Engineers
Skipping useless range: DoD Network Information Center
Skipping useless range: US Army Communications Electronics Command
Skipping useless range: Defense Contract Management Agency
Skipping useless range: Defense Contract Management Agency
Skipping useless range: Defense Contract Management Agency
Skipping useless range: Defense Contract Management Agency
Skipping useless range: LOCKHEED MISSILES & SPACE COMPANY
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: NASA/Johnson Space Center
Skipping useless range: Naval Electronic Systems Engineering Center
Skipping useless range: Board of Governors of the Federal Reserve System
Skipping useless range: Board of Governors of the Federal Reserve System
Skipping useless range: Board of Governors of the Federal Reserve System
Skipping useless range: Board of Governors of the Federal Reserve System
Skipping useless range: New York State Department of Public Service
Skipping useless range: ADP Dealer Services
Skipping useless range: ADP (Roads)
Skipping useless range: ADP Bloomfield
Skipping useless range: Sacramento Housing & Redevelopment Agency (SHRA)
Skipping useless range: Texas Instruments IS&S Electronic Communications
Skipping useless range: Air Force Technical Applications Center
Skipping useless range: Loral Instrumentation
Skipping useless range: US Army North
Skipping useless range: DOD EDUCATION ACTIVITY
Skipping useless range: DOD DEPENDENTS SCHOOLS
Skipping useless range: Fermilab
Skipping useless range: Armed Forces Radio and Television - Broadcast Center
Skipping useless range: Avalanche Development Co
Skipping useless range: Charlotte County Clerk of Court
Skipping useless range: State Compensation Fund
Skipping useless range: Andersen Consulting (Dallas SMC)
Skipping useless range: Compaq Computer Corporation
Skipping useless range: Commander in Chief, U.S. Pacific Fleet
Skipping useless range: Naval Command Control and Ocean Surveillance Cent
Skipping useless range: Motion Picture Association
Skipping useless range: Loral Corporation
Skipping useless range: National Archives and Records Administration
Skipping useless range: National Archives and Records Administration
Skipping useless range: NLM.NIH.GOV maintainer
Skipping useless range: Network Associates, Inc
Skipping useless range: City of Ft. Collins, ICS Dept
Skipping useless range: IBM Corporation
Skipping useless range: Wright-Patterson Air Force Base
Skipping useless range: NAVAL AIR WARFARE CENTER AIRCRAFT DIVISION
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: Lockheed-Martin Corporation
Skipping useless range: City of Fort Collins
Skipping useless range: U.S. Department of Energy - METC
Skipping useless range: Traveling Software INC
Skipping useless range: Disney Worldwide Services, Inc
Skipping useless range: VMARK Software, Inc
Skipping useless range: United Nations Environmental Program (UNEP) Nai
Skipping useless range: NASA Ames Research Center
Skipping useless range: NASA Goddard Space Flight Center
Skipping useless range: Allied-Signal Aerospace Company
Skipping useless range: United States Department Of Energy
Skipping useless range: US Dept of Energy Office of Scientific and Technical Information
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Battele Pacific Northwest Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: Battele Pacific Northwest Laboratory
Skipping useless range: Allied-Signal Aerospace Company
Skipping useless range: Lawrence Berkeley National Laboratory
Skipping useless range: EDS Network Naming and Addressing Management (NNAM
Skipping useless range: Office of Information Technology
Merged range 'IBM Corporation', with range 'IBM Corporation'
Skipping useless range: IBM Corporation
Skipping useless range: IBM Corporation
Skipping useless range: IBM Corporation
Skipping useless range: City of Minneapolis
Skipping useless range: SAIC-ITER San Diego Co-Center
Skipping useless range: Hughes STX Corporation
Skipping useless range: CACI
Skipping useless range: Central Intelligence Agency
Skipping useless range: Central Intelligence Agency
Skipping useless range: Washington State Energy Office
Skipping useless range: NAVAL AIR WARFARE CENTER AIRCRAFT DIVISION
Skipping useless range: DISA, Joint Interoperability
Skipping useless range: Acxiom Corp
Skipping useless range: U.S. Probation &amp; Pretrial Services
Skipping useless range: Government of Manitoba
Skipping useless range: Govt of Manitoba
Skipping useless range: iStar - Province of NS
Skipping useless range: iStar - Province of NS
Skipping useless range: Government of PEI
Skipping useless range: Saskatchewan Department of Health
Skipping useless range: National Software Company
Skipping useless range: City of Albuquerque
Skipping useless range: Sega of America, Inc
Skipping useless range: Sega of America, Inc
Skipping useless range: Connecticut Department of Environmental Protection
Skipping useless range: State of Oregon
Skipping useless range: General Services, State of Oregon
Skipping useless range: 89th MDSS/SGSI
Skipping useless range: Buena Vista Home Video Pty Ltd
Skipping useless range: NLM.NIH.GOV maintainer
Skipping useless range: U.S. Coast Guard Reserve
Skipping useless range: DEPARTMENT OF GENERAL ADMINISTRATION-STATE OF WASHINGTON
Skipping useless range: U.S. Department of the Interior
Skipping useless range: Elk Grove Village Police Department
Skipping useless range: Cook County Sheriffs Police
Skipping useless range: State of Washington
Skipping useless range: California Department of Personel Administration
Skipping useless range: California Department of Personel Administration
Skipping useless range: Federal Aviation Administration - ATC
Skipping useless range: Department of Housing and Urban Development
Skipping useless range: Tripler Army Medical Center
Skipping useless range: Air Force Technical Applications Center (AFTAC)
Skipping useless range: Air Force Technical Applications Center (AFTAC)
Skipping useless range: CITY AND COUNTY OF DENVER
Skipping useless range: SC Department of Commerce
Skipping useless range: National Weather Service Forecast Office, NOAA
Skipping useless range: Texas Instruments
Skipping useless range: Harris Publishing Co
Skipping useless range: City of El Cajon
Skipping useless range: City of Savannah
Skipping useless range: DoD Network Information Center
Skipping useless range: USAF, HQ ACC/SCTD
Skipping useless range: HQ ACC/SCBN
Skipping useless range: Toshiba America Electronic Components, Inc. (TAEC)
Skipping useless range: State of Washington - Legislative Service Center
Skipping useless range: State of Washington - Washington Traffic Safety Commission
Skipping useless range: Federal Reserve Bank of San Francisco
Skipping useless range: State of Louisiana Division of Administration
Skipping useless range: City of Beverly Hills
Skipping useless range: U.S. Center For Disease Control and Prevention
Skipping useless range: Virgin Island Mtr
Skipping useless range: ADP D/S Division
Skipping useless range: ADP VANCOUVER
Skipping useless range: ADP D/S SALES
Skipping useless range: ADP D/S
Skipping useless range: COLUMBIA INTL
Skipping useless range: NCTS Washington
Skipping useless range: Naval Research Laboratory, Marine
Skipping useless range: NAV RES LAB MARINE METEOROLOGY DIVISION
Skipping useless range: COMNAVSURFLANT
Skipping useless range: COMNAVSURFLANT
Skipping useless range: Defense Commercial
Skipping useless range: AFWAM SPO, SSC/XOW (US Air Force)
Skipping useless range: IBM
Skipping useless range: Raytheon
Skipping useless range: Raytheon
Skipping useless range: Verestar
Skipping useless range: Government of Ontario RAS
Skipping useless range: U.S. Dept. of Agriculture - NAL
Skipping useless range: U.S. Dept. of Agriculture - NAL
Skipping useless range: United States Army Corps of Engineers
Skipping useless range: U.S. Army Corps of Engineers
Skipping useless range: Organization of American States
Skipping useless range: U.S. Dept. of Energy - EIA
Skipping useless range: Department of Housing and Urban Development
Skipping useless range: General Services Administration
Skipping useless range: US Senate
Skipping useless range: Department of Housing and Urban Developement Nativ
Skipping useless range: Florida Information Resource Network
Skipping useless range: Air Force Technical Applications Center
Skipping useless range: Dept of Juvenile Justice and Delinquency
Skipping useless range: Governor\
Skipping useless range: Office of Juvenile Justice District 15b
Skipping useless range: Dept of Juvenile Justice and Delinquency
Skipping useless range: Division of Public Health
Skipping useless range: Secretary of State - Old Revenue Bldg
Skipping useless range: Div of Public Health/Epidemiology
Skipping useless range: Governors Office
Skipping useless range: Orange County Government
Skipping useless range: NC Dept of Juvenile Justice
Skipping useless range: Cleveland Co ACTS
Skipping useless range: NC Dept of Transportation
Skipping useless range: U.S. Army Claims Service
Skipping useless range: US ARMY-CECOM
Skipping useless range: DoD Network Information Center
Skipping useless range: Topographic Engineering Center
Skipping useless range: Object Software Development
Skipping useless range: State of NH ASDC
Skipping useless range: ADP D/S
Skipping useless range: ADP SALES/BLOOMFIELD
Skipping useless range: ADP AUTO-TELL SERVICES
Skipping useless range: ADP DEALER SERVICES
Skipping useless range: Orbotech Ltd
Skipping useless range: DOE-CA
Skipping useless range: Department of the Environment
Skipping useless range: RCMP-GRC1
Skipping useless range: Epic of Brewster
Skipping useless range: Barnstable County Registry of Deeds
Skipping useless range: Barnstable County Sheriffs Office
Skipping useless range: GOVONCA-C-246-119
Skipping useless range: IBM Canada Ltd
Skipping useless range: Verestar
Skipping useless range: Ministerio de Obras Publicas
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: SES-Americom Network
Skipping useless range: MINISTERIO DAS RELACOES EXTERIORES
Skipping useless range: SIEMENS Ltd. (138815)
Skipping useless range: Electoral Commission of Queensland
Skipping useless range: NSW Maritime Authority
Merged range ' Ministry for Planning', with range 'Ministry for Planning'
Skipping useless range: Ministry for Planning
Skipping useless range: Institut Statistique de Polynesie Francaise
Skipping useless range: Institut d'ÃĐmission d'Outre Mer
Skipping useless range: Canal Plus - Polynesie
Skipping useless range: Presidence du Gouvernement de la Polynesie Franca
Skipping useless range: Universite de la Polynesie Francaise
Skipping useless range: Australian Agency for International Development
Skipping useless range: Australian Agency for International Development
Skipping useless range: The Australian Agency for International Developme
Skipping useless range: Australian Agency for International Development
Skipping useless range: CSIRO IT Services
Skipping useless range: CSIRO
Skipping useless range: CSIRO
Skipping useless range: Australian Railroad Group - ARG
Skipping useless range: Sony Precision Engineering Centre Singapore
Skipping useless range: COLIN NG & PARTNERS
Skipping useless range: JINGO RECORD CO., Ltd
Skipping useless range: Intrasoft Inc. Taiwan Branch
Skipping useless range: U-GEM Corporation Film,Camera,Photo Fishing
Skipping useless range: JINGO RECORD CO., Ltd
Skipping useless range: 117 Rouse Street
Skipping useless range: Donaldson Trumble Lawyers
Skipping useless range: Government Institution of Indonesia
Skipping useless range: US Naval Medical Research Unit No. 2
Skipping useless range: AIA Lab, Directorate of Information and Electroni
Skipping useless range: Ministry of Industry and Trade
Skipping useless range: Lubis Ganie Law Firm
Skipping useless range: Royal Netherland Embassy
Skipping useless range: Foreign Ministry to LISL subnet
Skipping useless range: EDS to LISL subnet
Skipping useless range: AGENT Pvt Ltd
Skipping useless range: World Health Organization subnet
Skipping useless range: Foreign Ministry Internal subnet
Skipping useless range: Marine Air Consolidation
Skipping useless range: Ministry of Housing
Skipping useless range: Coopers & Lybrand Associates
Skipping useless range: Lanka Electricity Company
Skipping useless range: SL Army
Skipping useless range: Batalanda Army subnet
Skipping useless range: Samsung Electronics
Skipping useless range: Voice of America
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Corrs Chambers Westgarth
Skipping useless range: Orc Software Australia
Skipping useless range: Natural Resources Management Program
Skipping useless range: Ip block for Regal Films Franciso Office
Skipping useless range: Bureau Of Treasury
Skipping useless range: BOBCOCK-HITACHI Philippines Inc
Skipping useless range: Eulogio Amang Rodriguez Institute
Skipping useless range: National Mapping and Resource Information Authori
Skipping useless range: Telecommunications Office (DOTC-TELOF)
Skipping useless range: Philippine Council for Agriculture, Forestry and
Skipping useless range: Philippine Council for Aquatic and
Skipping useless range: DOST-7 Regional Office (Lahug)
Skipping useless range: NEDA 10 Regional Office
Skipping useless range: Philippine Council for Health
Skipping useless range: Science and Technology Information Institute
Skipping useless range: Industrial Technology Development Institute
Skipping useless range: Philippine Council for Advanced Science and Techn
Skipping useless range: Philippine Council for Industry
Skipping useless range: Technology Application and Promotion Institute
Skipping useless range: National Research Council of the Philippines
Skipping useless range: AFRDIS
Skipping useless range: PHILRICE Batac
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Dream Wave Shizuoka Co., Ltd
Skipping useless range: Dream Wave Shizuoka Co., Ltd
Skipping useless range: Gansu government ,leased line user
Skipping useless range: zhejiang information 9sky music
Skipping useless range: p2p abusers
Skipping useless range: Appointment netbar of Nanping City of Fujian prov
Skipping useless range: Shiyan school of nanping City of Fujian province
Skipping useless range: zhengzhou local Tax bureau,
Skipping useless range: henan province social & science academe,
Skipping useless range: CAP GEMINI
Skipping useless range: MOTECH SOFTWARE PVT.LTD
Skipping useless range: INDIAN INSTITUTE OF SOFTWARE ENGINEERING
Skipping useless range: EASY BUY MUSIC
Skipping useless range: Aptech Computer Education
Skipping useless range: ORACLE BANGALORE
Skipping useless range: Verestar
Skipping useless range: Dharmala Securitas
Skipping useless range: Musica Studios, PT
Skipping useless range: Verestar
Skipping useless range: Veritas Software Solutions pvt ltd
Skipping useless range: 605,RAHEJA CHAMBERS
Skipping useless range: Intellevsions Software Lt
Skipping useless range: Logan City Council
Skipping useless range: TRADENEX.COM SDN BHD
Skipping useless range: Thales GeoSolutions Sdn Bhd
Skipping useless range: Thales Broadcast & Multimedia Inc
Skipping useless range: TRADENEX.COM SDN BHD
Skipping useless range: DRB-Hicom Defence Technologies Sdn Bhd
Merged range 'SINGAPORE POLICE FORCE', with range 'DENTSU-LTD-INFORMATION-SERVICES'
Merged range 'American Embassy Jakarta', with range 'PT. AGB Nielsen'
Skipping useless range: Wing Gee Advertising Production Co
Skipping useless range: Movielink Nikko
Skipping useless range: Movielink Great Eagle Hotel
Skipping useless range: American Consulate General, PST
Skipping useless range: Fujitsu Systems Business (Malaysia) Berhad
Skipping useless range: Film Company
Skipping useless range: Film Company
Skipping useless range: Leader in the Music industry
Skipping useless range: Software Integration Company
Skipping useless range: Fujitsu Systems Business (Malaysia) Berhad
Skipping useless range: Software House
Skipping useless range: Software solutions provider
Skipping useless range: Leader in the Music industry
Skipping useless range: Software House
Skipping useless range: Advocate & Solicitors
Skipping useless range: HP WholeSaler and Distributor
Skipping useless range: Mexican Embassy
Skipping useless range: Advocate & Solicitors
Skipping useless range: Software House
Skipping useless range: HP WholeSaler and Distributor
Skipping useless range: Broadcasting Company
Skipping useless range: Mexican Embassy
Skipping useless range: taisho town office
Skipping useless range: Ikegawa town office
Skipping useless range: Noichi Town Office
Skipping useless range: Fujitsu Shikoku Systems Ltd
Skipping useless range: LOCAL GOVERNMENT SOLUTIONS GROUP
Skipping useless range: Det Norske Veritas AS
Skipping useless range: Tottori Prefectual Government
Skipping useless range: Sekigane Town Office
Skipping useless range: Kyusyu Regional Bureau of PostalServices
Skipping useless range: InfoBears(FUJITSU MINAMI-KYUSHU SYSTEMS ENGINEERIN
Skipping useless range: InfoBears(FUJITSU MINAMI-KYUSHU SYSTEMS ENGINEERING LIMITED)
Skipping useless range: FUJITSU MINAMI-KYUSHU SYSTEMSENGINEERING LIMITED
Skipping useless range: InfoBears(FUJITSU MINAMI-KYUSHU SYSTEMS ENGINEERIN
Skipping useless range: InfoBears(FUJITSU MINAMI-KYUSHU SYSTEMS ENGINEERING LIMITED)
Skipping useless range: Ministry of Health, Labour and Welfare
Skipping useless range: Nagano Broadcasting Systems,inc
Skipping useless range: Koshoku city office
Skipping useless range: INA City Office
Skipping useless range: FUJITSU NAGANO SYSTEMS ENGEERING LIMITED
Skipping useless range: Society of The National Chamber of Agriculture
Skipping useless range: NEC Soft, Ltd. Nagano
Skipping useless range: Rishirifuji Town Office
Skipping useless range: FUJITSU HOKKAIDO SYSTEMS ENGINEERING LIMITED
Skipping useless range: Ministry of International Trade and Industry
Skipping useless range: Kitahitoshima City Office
Skipping useless range: MITSUBISHI ELECTRIC
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK CORPORATION
Skipping useless range: Kyushu Mitsubishi Electoric Corporation
Skipping useless range: MITSUBISHI ELECTRIC SYSTEM & SERVICE CO.,LTD
Skipping useless range: Yamagata Mitsubishi Electric Corporation
Skipping useless range: MITSUBISHI ELECTRIC OSRAM Ltd
Skipping useless range: Wakayama Mitsubishi Electric Co.,LTD
Skipping useless range: Mitsubishi Electric Corporation
Skipping useless range: Mitsubishi Electric Corporation
Skipping useless range: MITSUBISHI ELECTRIC SYSTEM&SERVICE CO.,LTD
Skipping useless range: MITSUBISHI ELECTRIC
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK CORPORATION
Skipping useless range: Mitsubishi Electric Information Network Corp
Skipping useless range: Mitsubishi Electric corporation
Skipping useless range: Mitsubishi Erectric Information Network Corporatio
Skipping useless range: MITSUBISHI ELECTRIC SYSTEMWARE CORPORATION
Skipping useless range: Mitsubishi Electric Information Systems Corporatio
Skipping useless range: Mitsubishi Electric Corporation
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK CORPORATION
Skipping useless range: Mitsubishi Electric Information Network Corp
Skipping useless range: Mitsubishi Electric Information Network Corp
Skipping useless range: MITSUBISHI ELECTRIC CORPORATION
Skipping useless range: Mitsubishi Electric Information Network Corp
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK COPRATION
Skipping useless range: Mitsubishi Electric Information Network Corp
Skipping useless range: MITSUBISHI ELECTRIC
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK CORPORATION
Skipping useless range: MITSUBISHI Electric Building Techno-service Co.,Lt
Skipping useless range: MITSUBISHI ELECTRIC INFORMATION NETWORK CORPORATION
Skipping useless range: Mitsubishi Electric Corporation
Skipping useless range: Mitsubishi Electric Plant Engineering Co.,LTD
Skipping useless range: Sony Communication Network Corporation
Skipping useless range: Department of Defence
Skipping useless range: Department of Defence
Skipping useless range: NSW Department of Mineral Resources (138815)
Skipping useless range: Australian Labour Party (140633)
Skipping useless range: Western Australia Department of Treasury (138822)
Skipping useless range: Western Australia Department of Treasury (134162)
Skipping useless range: City of Marion (131647)
Skipping useless range: Department of Housing (138815)
Skipping useless range: Ministry of Premier & Cabinet of WA (134162)
Skipping useless range: ah.co.nz
Skipping useless range: ah.co.nz
Skipping useless range: Brookfields Lawyers
Merged range 'Waverly Council', with range 'CAMPBELLTOWN CITY COUNCIL'
Merged range 'Scope Features Australia', with range 'ORACLE SYSTEMS PTY LTD'
Skipping useless range: Economic Department - Ministry of Defense
Skipping useless range: Hanoi US Embassy
Skipping useless range: Government of Singapore Investment Corporation
Skipping useless range: Department of Statistics
Skipping useless range: Asprecise Pte Ltd
Skipping useless range: ST Logistics
Skipping useless range: Singapore Aerospace
Skipping useless range: Knuerr Spectra
Skipping useless range: BH Billiton Marketing Asia Pte Ltd
Skipping useless range: NIIT Ltd,
Skipping useless range: Magic Software Enterprises India Pvt. Ltd
Skipping useless range: Tooltech Software (I) Ltd
Skipping useless range: Production Unit
Skipping useless range: Production Unit
Skipping useless range: The Associated Press - Dow Jones
Skipping useless range: Mphasis Software & Services Pvt. Ltd
Skipping useless range: Software Devlopment Unit
Skipping useless range: Raft Software Pvt. Ltd
Skipping useless range: Mphasis Software & Services Pvt. Ltd
Skipping useless range: Software Devlopment Unit
Skipping useless range: Software Devlopment Unit,
Skipping useless range: Software Devlopment Unit
Skipping useless range: Software Devlopment Firm
Skipping useless range: Microworld Software Services Pvt. Ltd
Skipping useless range: Raft Software Pvt. Ltd
Skipping useless range: The Associated Press - Dow Jones
Skipping useless range: ABACUS Distribution Systems (India) Pvt. Ltd
Skipping useless range: Tata InfoTech Ltd
Skipping useless range: Software Devlopment Unit
Skipping useless range: Software Devlopment Unit
Skipping useless range: Software Devlopment Unit
Skipping useless range: Ace Software Solutions India Pvt Ltd
Skipping useless range: Mphasis Software & Services Pvt. Ltd
Skipping useless range: Office Bo. 404, 4th Floor Pride Kumar Senate,
Skipping useless range: Niche Software Solutions Pvt. Ltd
Skipping useless range: AMERICAN EMBASSY
Skipping useless range: Australian Israel Chamber of Commerce
Skipping useless range: Impress Software Ptty Ltd
Skipping useless range: NRG - Production
Skipping useless range: Cranbrook Films Pty Ltd
Skipping useless range: Pyramid Softwate Development
Skipping useless range: Pyramid Softwate Development
Skipping useless range: SDE Software Development Training Center
Skipping useless range: Vietnam Ministry Of Fisheries - MOFI
Skipping useless range: McDonalds / McGeorge Food Philippines, Inc
Skipping useless range: GBP Software
Skipping useless range: MANIPAL MEDIRECORDS BANGALORE
Skipping useless range: AGNI SOFTWARE, BANGALORE
Skipping useless range: YODLEE SOFTWARE, BANGALORE
Skipping useless range: ORCHID SOFTWARE, BANGALORE
Skipping useless range: Software Development company in Bangalore
Skipping useless range: SOFTWARE COMPANY IN BANGALORE
Skipping useless range: SOBIS Software Bangalore
Skipping useless range: National Computerization Agency
Skipping useless range: Verestar
Skipping useless range: Onsystems
Skipping useless range: Onsystems
Skipping useless range: Angelnet Productions Inc
Skipping useless range: ISI
Skipping useless range: Government of Ontario RAS
Skipping useless range: CTS003-A
Skipping useless range: Time Warner Telecom
Skipping useless range: State of Louisiana Office of Telecommunications Ma
Skipping useless range: Atlantic Recording Corporation
Skipping useless range: JUSTICE-GOV
Skipping useless range: Rockstar Games Canada
Skipping useless range: IBM
Skipping useless range: Federal Aviation Administration
Skipping useless range: CHESTER COUNTY
Skipping useless range: Siemens Industrial Automation, Inc
Skipping useless range: Hughes Communications Inc
Skipping useless range: Atlantic Recording Corporation
Skipping useless range: RAYTHEON POLAR
Skipping useless range: Holme, Roberts & Owen
Skipping useless range: National Conference of State Legislatures
Skipping useless range: Activision
Skipping useless range: The Symantec Corporation
Skipping useless range: Western Governor\
Skipping useless range: Colorado Compensation Insurance Authority
Skipping useless range: Z-Axis Corp
Skipping useless range: National Conference of State Legislatures
Skipping useless range: Jefferson County Government
Skipping useless range: Brownleigh Court
Skipping useless range: Mine Safety and Health Administration
Skipping useless range: City of Colorado Springs
Skipping useless range: City of Fort Collins
Skipping useless range: City of Fort Collins
Skipping useless range: Gartner Group, Inc
Skipping useless range: Jefferson County Government
Skipping useless range: General Government Computing Center
Skipping useless range: Weld County Government
Skipping useless range: Mine Safety and Health Administration
Skipping useless range: ACCENTURE LLP
Skipping useless range: ACCENTURE LLP
Skipping useless range: IBM
Skipping useless range: NY State Department of Labor
Skipping useless range: American Job Bank/NYS Department of Labor
Skipping useless range: Nysernet, Inc
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: US Merchant Marine Academy
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: US Merchant Marine Academy
Skipping useless range: NYSERNet
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: U.S. Merchant Marine Academy
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: Nysernet/First Albany Corp
Skipping useless range: Nysernet/United Health Services
Skipping useless range: Nysernet/Thirteen/WNET
Skipping useless range: Nysernet/First Albany Corp
Skipping useless range: Nysernet/Monroe County Boces #1
Skipping useless range: Macrovision Corporation
Skipping useless range: La.Tax Commision New Orleans
Skipping useless range: Governor\
Skipping useless range: LA DEPARTMENT OF JUSTICE
Skipping useless range: DEPARTMENT OF CULTURE RECREATION AND TOURISM
Skipping useless range: Department of Health & Hospitals - Jackson
Skipping useless range: LOUISIANA DEPARTMENT OF ELECTIONS AND REGISTRATION
Skipping useless range: HCSSA
Skipping useless range: HCSSA
Skipping useless range: HCSSA
Skipping useless range: AEGIS TRAINING CENTER
Skipping useless range: ADP TORONTO/TRAINING
Skipping useless range: City of Barrie - 2
Skipping useless range: City of Barrie - 3
Skipping useless range: City of Barrie - 4
Skipping useless range: City of Barrie - 5
Skipping useless range: The City Of Barrie
Skipping useless range: Navy Network Information Center
Skipping useless range: SPAWAR SCC Pensacola Office
Skipping useless range: SONY-PICTURES-ENTERTAINMENT - Sony Pictures Entertainment Inc
Skipping useless range: SONY-PICTURES-ENTERTAINMENT - Sony Pictures Entertainment Inc
Skipping useless range: Oregon Legislative Administration Committee
Skipping useless range: Texas Legislative Budget Board
Skipping useless range: UNIVERSAL MERCURY
Skipping useless range: UNIVERSAL MERCURY
Skipping useless range: PWGSC - Govt Online Expo
Skipping useless range: Canadian Heritage
Skipping useless range: Public Works and Government Services Canada
Skipping useless range: Canadian Security Establishment
Skipping useless range: NAFTA Secretariat Canadian Section
Skipping useless range: Canadian Human Rights Tribunal
Skipping useless range: Military Police Complaints Commission
Skipping useless range: Natural Resources Canada
Skipping useless range: PWGSC
Skipping useless range: PWGSC
Skipping useless range: PWGSC
Skipping useless range: Canada Customs and Revenue Agency
Skipping useless range: Canada Customs and Revenue Agency
Skipping useless range: SCNet - NG SRA
Skipping useless range: Secure Channel - PWGSC
Skipping useless range: State of Nebraska, Division of Communications
Skipping useless range: EDS Canada
Skipping useless range: Virgin Mobile
Skipping useless range: sitaranetworks.com.site.CAISInternet
Skipping useless range: Stadtmauer Bailkin LLP
Skipping useless range: Law Offices of Michael E Pressman
Skipping useless range: Litigation Management Group
Skipping useless range: Electronic Data Systems (EDS)
Skipping useless range: Electronic Data Systems (EDS)
Skipping useless range: Yolo County Office of Education
Skipping useless range: FTC c/o AT&T Gov\
Skipping useless range: FTC c/o AT&T Gov\
Skipping useless range: FTC c/o AT&T Gov\
Skipping useless range: BLEDSOE DODGE INC
Skipping useless range: Loral Federal Systems Division
Skipping useless range: Epoch Customer Route
Skipping useless range: Connexion by Boeing
Skipping useless range: Rain Cinema, Inc
Skipping useless range: Virtual Internet Office / Agent
Skipping useless range: Smart & Bigger Fetherstonhaugh
Skipping useless range: CGI Group Inc
Skipping useless range: PWGSC Secure Channel
Skipping useless range: DirecTV
Skipping useless range: DirecTV
Skipping useless range: IBM
Skipping useless range: Turner Network Sales
Skipping useless range: ABC Radio Networks
Skipping useless range: Fresno County Office of Education
Skipping useless range: Kings County Government Center
Skipping useless range: Merced County Office of Education
Skipping useless range: Fresno County Office of Education
Skipping useless range: Gibson, Dunn & Crutcher
Skipping useless range: Mattel, Inc
Skipping useless range: Twentieth Century Fox
Skipping useless range: Info Systems Inc
Skipping useless range: Info Systems Inc
Skipping useless range: California Democratic Party
Skipping useless range: City of San Ramon
Skipping useless range: AT&T ANCS R&D Lab
Skipping useless range: Beveridge & Diamond, P.C
Skipping useless range: West Publishing Corporation
Skipping useless range: Hallmark Cards Inc
Skipping useless range: County of Ingham
Skipping useless range: Merchant & Gould
Skipping useless range: GT Interactive Software Corp
Skipping useless range: Keane, Inc
Skipping useless range: Masque Sound & Recording Corporation
Skipping useless range: Merchant & Gould
Skipping useless range: AT&T ANCS R&D Lab
Skipping useless range: AT&T ANCS R&D Lab
Skipping useless range: Novell Corp
Skipping useless range: AT&T ANCS R&D Lab
Skipping useless range: Novell Corp
Skipping useless range: SSA Southeast
Skipping useless range: SAVVIS Communications Corporation
Skipping useless range: Connexion by Boeing
Skipping useless range: Video Symphony
Skipping useless range: Worldwide Game Technology
Skipping useless range: Blur Studio / Referral Rep
Skipping useless range: Connexion By Boeing
Skipping useless range: Image Consultants/Prana Entertainment
Skipping useless range: L A Studios
Skipping useless range: L A Studios
Skipping useless range: Callahan and Blain
Skipping useless range: Natural Resources Defense Council
Skipping useless range: Epoch Backbone
Skipping useless range: Reel Mc Coy Fx
Skipping useless range: Summit Law Group
Skipping useless range: Musictoday LLC
Skipping useless range: Center Theatre Group Of Los Angeles
Skipping useless range: Office Of Government Ethics
Skipping useless range: Stratcom Communications Corp
Skipping useless range: Pie Town Productions
Skipping useless range: Law Offices Of Jon A Kodani
Skipping useless range: Stratcom Communications Corp
Skipping useless range: Stratcom Communications Corp
Skipping useless range: P M Publishing
Skipping useless range: Frost, Ruttenberg and Rothblatt P.C
Skipping useless range: T-Rex Production, Inc
Skipping useless range: Panamsat Chantilly- Internet
Skipping useless range: Ernst & Young LLP
Skipping useless range: Ernst & Young LLP
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: Columbia Productions Inc
Skipping useless range: Columbia Productions Inc
Skipping useless range: GE Capital
Skipping useless range: Heller, Ehrman, White & McAuliffe
Skipping useless range: PricewaterhouseCoopers
Skipping useless range: BEA Systems, Inc
Skipping useless range: Heller, Ehrman, White & McAuliffe
Skipping useless range: Twentieth Century Fox
Skipping useless range: Vedder Price Kaufman & Kammholz
Skipping useless range: McDermott Will & Emery
Skipping useless range: Dewey Ballantine
Skipping useless range: PRNewswire
Skipping useless range: Heller, Ehrman, White & McAuliffe
Skipping useless range: Heller, Ehrman, White & McAuliffe
Skipping useless range: Loral Corporation
Skipping useless range: City of San Carlos
Skipping useless range: Heller, Ehrman, White & McAuliffe
Skipping useless range: MAC Publishing L.L.C
Skipping useless range: City of San Carlos
Skipping useless range: BEA Systems, Inc
Skipping useless range: Capgemini Chicago Network
Skipping useless range: Mindjet LLC
Skipping useless range: City of Belmont
Skipping useless range: Town of Hillsborough
Skipping useless range: Town of Atherton
Skipping useless range: City of Brisbane
Skipping useless range: WDIV TV
Skipping useless range: Intergraph
Skipping useless range: CGI Group Inc
Skipping useless range: PUBLIC WORKS GOV. SERV. CANADA
Skipping useless range: GE Canada
Skipping useless range: EDS
Skipping useless range: amcc-ca
Skipping useless range: Compaq Canada Inc
Skipping useless range: studio99-ca
Skipping useless range: City of Kawartha Lakes
Skipping useless range: CGI
Skipping useless range: Avenza Software Marketing
Skipping useless range: TIBCO Finance Inc
Skipping useless range: GSA Computer Services
Skipping useless range: Pollara
Skipping useless range: CGI
Skipping useless range: IBM Canada
Skipping useless range: ibm0425-ca
Skipping useless range: MacMillan Rooke Boeckle
Skipping useless range: Amdocs Canada Managed Services
Skipping useless range: Intergraph Canada Ltd
Skipping useless range: Corel Corporation
Skipping useless range: EDS
Skipping useless range: Government of Ontario RAS
Skipping useless range: emboiran-ca
Skipping useless range: Cryptocard Corporation
Skipping useless range: Hill & Knowlton Ducharme Perron
Skipping useless range: Unigraphics Solutions
Skipping useless range: Discreet Logic Inc
Skipping useless range: NetPD.com
Skipping useless range: Reuters Canada Inc
Skipping useless range: Arter &amp; Hadden
Skipping useless range: Don Law Company
Skipping useless range: Digital Equipment Corp
Skipping useless range: SAIC
Skipping useless range: Sullivan Weinstein & McQuay, P.C
Skipping useless range: Pennwell Publishing
Skipping useless range: Media Net
Skipping useless range: Stonesoft, Inc
Skipping useless range: National Amusements
Skipping useless range: Ghost Music Service
Skipping useless range: Spyrus
Skipping useless range: City of Lowell
Skipping useless range: National Amusements
Skipping useless range: Radview Software
Skipping useless range: IBM Trevoli Systems
Skipping useless range: Streamline Studios
Skipping useless range: Motorola
Skipping useless range: govt0505-ca
Skipping useless range: EDS / Xerox Budget Centre 69696
Skipping useless range: GE MEDICAL SYSTEMS
Skipping useless range: GE Medical Systems
Skipping useless range: Verestar
Skipping useless range: Maginnis Law Office
Skipping useless range: Attorney David S. Nenner
Skipping useless range: Gov Stat
Skipping useless range: HIPAADOCS
Skipping useless range: TRW Automotive
Skipping useless range: Associated Production Music
Skipping useless range: CATO INSTITUTE
Skipping useless range: Independent Feature Project
Skipping useless range: HMS PRODUCTIONS, INC
Skipping useless range: Cinea, Inc
Skipping useless range: Los Angeles County Juvenile Court and Community Schools
Skipping useless range: Midway Home Entertainment.745
Skipping useless range: City Of Tracy
Skipping useless range: Tioga County
Skipping useless range: Nysernet/Touro Law Center
Skipping useless range: Cattaraugus County
Skipping useless range: Cattaraugus County
Skipping useless range: Nysernet/NY State Depart. of State
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: jvc.com
Skipping useless range: ClearBlue Technologies - nyny01 name servers
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: Nysernet/City of Olean
Skipping useless range: ClearBlue Technologies - Syracuse
Skipping useless range: Nysernet/NYC Dep Bur Water Supply & Wastewater Collection
Skipping useless range: National Security Agency
Skipping useless range: Defense Mapping Agency
Skipping useless range: DISA Information Systems Center
Skipping useless range: 694th Intelligence Group
Skipping useless range: Defense Mapping Agency
Skipping useless range: Manatee County Government
Skipping useless range: Indian River County Government
Skipping useless range: Florida Department of Banking and Finance
Skipping useless range: Florida Community Network Initiative
Skipping useless range: Hillsborough County Board of County Commissions
Skipping useless range: Department of Highway Safety and Motor Vehicles
Skipping useless range: Florida Department of State
Skipping useless range: City of Plant City
Skipping useless range: Florida Department of State
Skipping useless range: Greater Orlando Aviation Authority
Skipping useless range: Dept. of Military Affairs
Skipping useless range: Division of Administrative Hearings
Skipping useless range: Florida Dept. of Labor, Division of Jobs and Benefits
Skipping useless range: Florida Dept. of Highway Safety and Motor Vehicles
Skipping useless range: City of Sarasota
Skipping useless range: Florida Housing Finance Corporation
Skipping useless range: EDS Canada Inc
Skipping useless range: El Dorado County Office of Education
Skipping useless range: Sega Soft
Skipping useless range: Data Quest Software, L L C
Skipping useless range: State Department Federal Credit Union
Skipping useless range: Hughes Network Systems / Reseller
Skipping useless range: Multimedia 2000 / Multicom Publishing
Skipping useless range: Trend Micro
Skipping useless range: Nextpoint, Inc
Skipping useless range: Phyber Communications - Possible MediaDefender
Skipping useless range: Sample Digital Holdings LLC
Skipping useless range: Phyber Communications - MediaDefender
Skipping useless range: whittakercorp.com
Skipping useless range: Creative Thought, Inc
Skipping useless range: Creative Thought, Inc
Skipping useless range: MediaDefender
Skipping useless range: Screen Actors Guild
Skipping useless range: Aviant Information
Skipping useless range: Aviant Information
Skipping useless range: National Immigration Law Center
Skipping useless range: Tri-Tech Entertainment
Skipping useless range: Aviant Information
Skipping useless range: Regard Systems Integrators
Skipping useless range: Mediadefender
Skipping useless range: Department of Juvenile Justice
Skipping useless range: Philips Hager and North Investment Management Ltd
Skipping useless range: Eclipse Entertainment
Skipping useless range: Precision Camera
Skipping useless range: Texas Legislative Service
Skipping useless range: Onramp Web
Skipping useless range: Lackland Air Force Base
Skipping useless range: Paramount.Theater
Skipping useless range: Republican Party of Texas
Skipping useless range: Innovus Multimedia Inc
Skipping useless range: Bay T
Skipping useless range: Sacramento County Bar Association (SACBAR-DOM)
Skipping useless range: Logicon (LRDA-DOM)
Skipping useless range: American.Zoetrope
Skipping useless range: City of Newark
Skipping useless range: City Of Tracy
Skipping useless range: Publishers Group West
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: NOAA at Nauticus
Skipping useless range: Discordia-P2P scammers
Skipping useless range: Scopelitis, Garvin, Light & Hanson
Skipping useless range: KTBS
Skipping useless range: California Democratic Party
Skipping useless range: Aircraft Engineering Corporation
Skipping useless range: CreatRoute for customer Northrop Grumman
Skipping useless range: ACS BPS
Skipping useless range: Sportstation New Media Inc
Skipping useless range: CADENCE DESIGN SYSTEMS
Skipping useless range: GE Asset Management
Skipping useless range: SOUTHERN-LIGHT-LLC-Mobile.so-2-3-0.ar4.ATL1.gblx.net
Skipping useless range: CMP MEDIA LLC
Skipping useless range: John Teter Atty
Skipping useless range: Compaq Computer Inc
Skipping useless range: Apple Computer, Inc. UU-208-216-53 (NET-208-216-53-0-1)
Skipping useless range: Apple Computer, Inc. UU-208-216-54 (NET-208-216-54-0-1)
Skipping useless range: Apple Computer, Inc. UU-208-216-55 (NET-208-216-55-0-1)
Skipping useless range: Picture Works
Skipping useless range: Verestar
Skipping useless range: SecurityMinded Technologies LLC
Skipping useless range: SecurityMinded Technologies LLC
Skipping useless range: SecurityMinded Technologies LLC
Skipping useless range: Myriad Network
Skipping useless range: InfoRelay Online Systems, Inc
Skipping useless range: Eidos Interactive, Inc
Skipping useless range: Gabriel Productions
Skipping useless range: Todd Street Productions
Skipping useless range: Bigfoot Interactive
Skipping useless range: SEG Travel/Sony Travel
Skipping useless range: Fund for The City of New York
Skipping useless range: SEG Travel/Sony Travel
Skipping useless range: Silverman, Sclar, Byrne, Shin & Byrne P.C
Skipping useless range: Worldwide Security Network
Skipping useless range: NYC Police Museum
Skipping useless range: Palisades Technology Partners
Skipping useless range: EMI Music Publishing
Skipping useless range: BET Interactive, LLC
Skipping useless range: Massive Incorporated
Skipping useless range: CMJ Network, Inc
Skipping useless range: Fund for The City of New York
Skipping useless range: Gabriel Productions
Skipping useless range: Eidos Interactive, Inc
Skipping useless range: Facetime Communications
Skipping useless range: City of Campbell
Skipping useless range: CDM Software Solutions, Inc
Skipping useless range: Macrovision Corporation
Skipping useless range: Macrovision Corporation
Skipping useless range: Macrovision Corporation
Skipping useless range: Macrovision Corporation
Skipping useless range: Autodesk - Verizon LPS
Skipping useless range: Practising Law Institute
Skipping useless range: ACS State and Local Government Solutions, Inc
Skipping useless range: MIKE MILLIGAN ATTORNEY AT LAW
Skipping useless range: ISTUDIO CANADA INC
Skipping useless range: KNOWLEDGE BROADCASTING.COM
Skipping useless range: CBS Marketwatch.com
Skipping useless range: Kaufman Astoria Studios, Inc
Skipping useless range: Entertainment Brokers Intl
Skipping useless range: Apollo Publishing LLC
Skipping useless range: Virtual Broadcasting Information Center (VBIC) LLC
Skipping useless range: Office of the Chapter 13 Trustee
Skipping useless range: LAW OFFICES OF WINDLE TURLEY, PC
Skipping useless range: Scour Inc
Skipping useless range: Winstar OTA Test Order- OWB
Skipping useless range: MOLINE DISPATCH PUBLISHING COMPANY
Skipping useless range: 4AM Productions, Inc
Skipping useless range: DreamMaker Studios, Inc
Skipping useless range: Public Strategies, Inc
Skipping useless range: Jain Studios Limited
Skipping useless range: Craig Productions
Skipping useless range: Direct Information
Skipping useless range: Plaza Productions B. V
Skipping useless range: Z/H Publishing Inc
Skipping useless range: WebEstudio.com
Skipping useless range: Coffee Cup Software
Skipping useless range: Coffee Cup Software
Skipping useless range: Direct Information
Skipping useless range: SC3M SA
Skipping useless range: HBOA.com Inc
Skipping useless range: DreamMaker Studios, Inc
Skipping useless range: Direct Information
Skipping useless range: Musicsend
Skipping useless range: SC3M SA
Skipping useless range: Direct Information
Skipping useless range: SC3M SA
Skipping useless range: Public Strategies, Inc
Skipping useless range: GMD Studios
Skipping useless range: ichat, inc
Skipping useless range: ichat, inc
Skipping useless range: Direct Information Pvt. Ltd
Skipping useless range: GMD Studios
Skipping useless range: InfoLink
Skipping useless range: Public Strategies, Inc
Skipping useless range: First Choice Publishing
Skipping useless range: Coffee Cup Software
Skipping useless range: Coffee Cup Software
Skipping useless range: ichat, inc
Skipping useless range: First Choice Publishing
Skipping useless range: Direct Information Pvt. Ltd
Skipping useless range: ichat, inc
Skipping useless range: ichat, inc
Skipping useless range: Purple Monkey Studios
Skipping useless range: Purple Monkey Studios
Skipping useless range: Segment Publishing
Skipping useless range: Toolbox Studios, Inc
Skipping useless range: Enhanced Software Technology
Skipping useless range: Digital Commerce Solutions
Skipping useless range: First Choice Publishing
Skipping useless range: Impaq Computers Corp
Skipping useless range: MM Productions
Skipping useless range: The Aspen Institute
Skipping useless range: CRIA, Inc
Skipping useless range: Dennis Publishing
Skipping useless range: DalePro Audio
Skipping useless range: F2MediaCorp
Merged range 'Verestar', with range 'Verestar'
Skipping useless range: Shanley & Fisher, P.C
Skipping useless range: Prudent Publishing Company
Skipping useless range: Santa Cruz Games
Skipping useless range: L A Studios
Skipping useless range: California Business Bureau
Skipping useless range: City of Huntington Park
Skipping useless range: Illinois State Toll Highway Authority
Skipping useless range: L A County Department Of Children And Family Services
Skipping useless range: Internet Security Alliance, Llc
Skipping useless range: Motiv Films
Skipping useless range: U S Customs Service
Skipping useless range: Whitman, Requardt And Associates L L P
Skipping useless range: U S Army Corps Of Engineers
Skipping useless range: Law Offices Of Harlee Levy
Skipping useless range: Hogan and Hartson, L L P / Washington, D C
Skipping useless range: Science Applications International Corporation
Skipping useless range: Laemmle Theatres
Skipping useless range: Veritasiti Corporation
Skipping useless range: Blur Studio / Referral Rep
Skipping useless range: The Chase Law Group
Skipping useless range: City of Las Vegas
Skipping useless range: SAIC - Technology Research Group
Skipping useless range: Northeast MD Waste Disposal Authority
Skipping useless range: American Inns of Court Foundation
Skipping useless range: Keane Contracting
Skipping useless range: Jones Walker Law Firm
Skipping useless range: SAIC - Technology Research Group
Skipping useless range: National Womenss Law Center
Skipping useless range: MediaDefender
Skipping useless range: Black Ops Entertainment, LLC
Skipping useless range: Business Executives for National Security
Skipping useless range: Vasco Data Security
Skipping useless range: engineering Animation inc
Skipping useless range: Xulu Entertainment
Skipping useless range: Hughes Electronic Commerce
Skipping useless range: Scientific Research Corporation
Skipping useless range: Holland & Knight LLP
Skipping useless range: Atlanta Bar Association
Skipping useless range: International Human Resource Development (IHRDC)
Skipping useless range: American Intelligent Systems
Skipping useless range: American Intelligent Systems
Skipping useless range: American Broadband Productions
Skipping useless range: American Intelligent Systems
Skipping useless range: Law Offices of Michael Pinze
Skipping useless range: WINSTAR DIRECT
Skipping useless range: VASCO Data Security Inc
Skipping useless range: American Intelligent Systems
Skipping useless range: Marines Memorial Club
Skipping useless range: Aramat Productions Inc
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar routes>
Skipping useless range: Inter-Connect Ltd
Skipping useless range: Ernst & Young
Skipping useless range: Verestar
Skipping useless range: Bfore Productions
Skipping useless range: PacificNet
Skipping useless range: Reality Checks Studios
Skipping useless range: Legal Enterprises
Skipping useless range: Trauma Records
Skipping useless range: ZIDE ENTERNTAINMENT
Skipping useless range: PacificNet
Skipping useless range: STARGATE FILMS
Skipping useless range: CRYSTAL SKY COMMUNICATIONS
Skipping useless range: NETSENTRY - Net Sentry Corp
Skipping useless range: EDS Canada / ACSYS Technologies
Skipping useless range: Drinka, Levine & Masson, S.C
Skipping useless range: Manhattan Software
Skipping useless range: Rayburn Music Co., Inc
Skipping useless range: Conquest Boeing
Skipping useless range: Montgomery Publishing
Skipping useless range: Ernst & Young
Skipping useless range: gov1024-ca
Skipping useless range: Law Offices of Robert Dimino
Skipping useless range: Wild, Carey and Fife
Skipping useless range: Galarneau & Sinn, Ltd
Skipping useless range: Searchlight.Group
Skipping useless range: Web Side Story, Inc
Skipping useless range: CAIDA MFN
Skipping useless range: North Central Florida Regional Planning Council
Skipping useless range: Nagravision
Merged range 'Logitech DVB sites', with range 'Logitech DVB sites'
Skipping useless range: AAPT Ltd - CISCO LAB (140943)
Skipping useless range: AAPT Ltd - CISCO LAB (140942)
Skipping useless range: AAPT Ltd - CISCO LAB (140944)
Skipping useless range: Universal Press
Skipping useless range: BENTLEY SYSTEMS PTY LTD
Skipping useless range: Bayside City Council
Skipping useless range: jungwang police school
Skipping useless range: Environment Management Corporation
Skipping useless range: DONGGU OFFICE OF INCHON METROPOLITAN
Skipping useless range: MINISTRY OF JUSTICE INCHEONG PROBATION PLACE
Skipping useless range: POLICE COMPREHENSIVE ACADEMY
Skipping useless range: YANGPYONG COUNTRY OFFICE
Skipping useless range: TAEBAEK POST OFFICE PLAZA
Skipping useless range: Hoengsung County Office
Skipping useless range: ICHEN POST OFFICE
Skipping useless range: SEOINCHEON POST OFFICE
Skipping useless range: HASUNG WELFARE HALL
Skipping useless range: Ponghwa County Hall
Skipping useless range: SEOUL METROPOLITAN COUNCIL
Skipping useless range: eun Currency Co
Skipping useless range: Yongcheon City Hall
Skipping useless range: ARMY7557
Skipping useless range: ARMY9393
Skipping useless range: ARMY2632
Skipping useless range: Namwon City Hall
Skipping useless range: (ju)kyocharo
Skipping useless range: Sogu Office Inchon Metropolitan City
Skipping useless range: KIMPO CITY HOLL GOCHUN TOWNSHIP OFFICE
Skipping useless range: KIMPO CITY HOLL DAEGOK TOWNSHIP OFFICE
Skipping useless range: KIMPO CITY HOLL YANGCHON TOWNSHIP OFFICE
Skipping useless range: KIMPO CITY HOLL WOLGOK TOWNSHIP OFFICE
Skipping useless range: Shiheung City Hall
Skipping useless range: MASAN CITY HALL
Skipping useless range: Kwangan Bridge Management Authority
Skipping useless range: Hongsung County Office
Skipping useless range: CHEJU CITY HALL
Skipping useless range: Wonju City Hall
Skipping useless range: Seoul Metropolitan Police Agency
Skipping useless range: DEFENCE PROCUREMENT AGENCY
Skipping useless range: Naju City Hall
Skipping useless range: KIMCHEON CITY HALL
Skipping useless range: Jung-gu District Office Daegu Metropolitan City
Skipping useless range: Dreminternetgamestation
Skipping useless range: DoDDS(APO.AP 96502-0005)
Skipping useless range: SUNGDO FILM TRADING CO., LTD
Skipping useless range: CGI
Skipping useless range: EBS(Korea Educational Broadcasting System)
Merged range 'Department of Industry and Tourism', with range 'Department of Industry and Tourism'
Merged range 'Australian Communications and Media Authority', with range 'Department of Industry and Tourism'
Skipping useless range: Vietnam Television Station Office
Skipping useless range: The United States Agency for International Develo
Skipping useless range: Fuji Xerox Representative Office Vietnam
Skipping useless range: Daewoo hanel Electronics Co., Ltd
Merged range 'Verestar', with range 'Interpacket Networks (A Verestar Company)'
Skipping useless range: Medien System Haus internal network
Skipping useless range: subnet for SAKHALIN DUMA
Skipping useless range: MPR Film und Fernseh Produktion GmbH, Muenchen
Skipping useless range: Rechtsanwalt Dr. Joerg Weigell, Muenchen
Skipping useless range: SPX - Valley Forge T.I.S, Garching-Hochbrueck
Skipping useless range: Patentanwaelte Wallach & Partner, Muenchen
Skipping useless range: Oracle Deutschland GmbH, Muenchen
Skipping useless range: Min. of Higher Education
Skipping useless range: Security Forces Hospital
Skipping useless range: Internet Service Unit, KACST
Skipping useless range: King Abdulaziz City for Science and Technology
Skipping useless range: Commercial private establishment
Skipping useless range: King Abdulaziz City for Science and Technology
Skipping useless range: GDTA
Skipping useless range: GDTA - second block
Skipping useless range: Amaz International company
Skipping useless range: Communication and Information Technology Commission
Skipping useless range: Fraunhofer IESE Institut Experimentelles Software
Skipping useless range: Verestar
Skipping useless range: Alshiukh municipality center located in Hebron ,
Skipping useless range: amen amm is governet Co called:amen amm
Skipping useless range: Lebanese Ministry of Finance
Skipping useless range: Wunderman Cato Johnson
Skipping useless range: Ente Nazionale ACLI Istruzione Professionale
Skipping useless range: Landeshauptstadt Hannover
Skipping useless range: Landeshauptstadt Hannover
Skipping useless range: Landeshauptstadt Hannover
Skipping useless range: DTS DIGITAL TEKNIK SAN.LTD.STI
Skipping useless range: A.F.M. ULUSLARARASI FILM PROD.A.S
Skipping useless range: ODEON COMPACT DISC MUZIK SAN AS
Skipping useless range: ALTINCI DUYU REKLAM FILM.TIC.A.S
Skipping useless range: OFSET FILM VE MATBAA.SAN.A.S
Skipping useless range: Ministry of Foreign Affairs
Skipping useless range: Ministry of Justice
Skipping useless range: Ministry of Culture
Skipping useless range: State Data Inspection
Skipping useless range: Court House Agency
Skipping useless range: Teici National Park
Skipping useless range: THE LATVIAN AGRICULTURAL ADVISORY AND TRAINING CE
Skipping useless range: PRICE-WATER-OMAN
Skipping useless range: SCHLUMBERGER-TWO-OMAN
Merged range 'ZUXXEZ Entertainment AG', with range 'ZUXXEZ Entertainment AG'
Skipping useless range: LINA TV Productions
Skipping useless range: Ministry of Interiors
Skipping useless range: Prime Minister Office
Skipping useless range: Jericho Municipality
Skipping useless range: Intertech Productions
Skipping useless range: Palestinian INterior Ministry special Fo
Skipping useless range: Bailasan Productions
Skipping useless range: Nablus Municipality
Skipping useless range: DCA Judicial Portal
Skipping useless range: Kanzlei Henniges
Skipping useless range: Agentur fuer Arbeit Nuernberg ARGE
Skipping useless range: Naacher Consulting GmbH
Skipping useless range: Kayenburg Rechtsanwalt
Skipping useless range: Ministero della Difesa IT
Skipping useless range: INTEL LAAYOUNE
Skipping useless range: Ministere de la Prévision Economique et du Plan
Skipping useless range: Ministere de la jennesse et des sport Rabat-Morocc
Skipping useless range: Labo de police
Skipping useless range: Ubi Soft
Skipping useless range: Ministere des affaires generales et du gouvernemen
Skipping useless range: Exactsoftware Maroc
Skipping useless range: Exactsoftware Maroc
Skipping useless range: STE Alston (Cegelec) ā Casa
Skipping useless range: Ministere des PTT
Skipping useless range: SNEP Ã Mohamedia
Skipping useless range: STE SIEMENS ā Casa
Skipping useless range: geschichte.wasserschutzpolizei.berlin.de.Schlund.P
Skipping useless range: FR-RAEI-FRANCE-TELECOM--USEI-LB_INTERNET
Skipping useless range: FR-RAEI-HEWLETT-PACKARD-FRANCE-LB_INTERNET
Skipping useless range: FR-RAEI-FRANCE-TELECOM-UIE-NORD-PAS-DE-LB_INTERNET
Skipping useless range: LEXMARK INTERNATIONAL SAS
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ANIA - Associazione Nazionale fra le Imprese Assi
Skipping useless range: Einstein Multimedia Productions S.r.l
Skipping useless range: Toshiba Europe S.p.A
Skipping useless range: Rogue Wave Software S.r.l
Skipping useless range: Software Consulting S.r.l
Skipping useless range: Ministero dell'Ambiente e della Tutela del Territ
Skipping useless range: Red Sheriff S.r.l
Skipping useless range: Walnut Tree Productions S.r.l
Skipping useless range: M.S.C. Software
Skipping useless range: Trevisan & Cuonzo Avvocati
Skipping useless range: Ente Nazionale Austriaco Per Il Turismo
Skipping useless range: Comune di Militello Val Catania Via Umberto Pozzo
Skipping useless range: EADS-ATRIUM
Skipping useless range: Veritas.Software.FR
Skipping useless range: HEWLETT-PACKARD
Skipping useless range: HEWLETT.PACKARD.FR
Skipping useless range: Landesamt.fuer.Informationstechnik.Hamburg
Skipping useless range: Rechtsanwaelte Schoenfeld und Luntz
Skipping useless range: Siemens Business Services Sistem Hizmetleri A.S
Skipping useless range: Cinestar Rental AB
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-DIH-FW-OPENX-OLE
Skipping useless range: FR-RAEI-FRANCE-TELECOM--UIA-FWVPN
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-RAEI
Skipping useless range: GI - Customer Interconnexion With RAEI B
Skipping useless range: GI - Customer Interconnexion With RAEI B
Skipping useless range: FR-RAEI-SAMSUNG-ELECTRONICS-FRANCE-FW-OPENX-OLE
Skipping useless range: FR-RAEI-SUN-MICROSYSTEMS-FRANCE-FW-OPENX-OLE
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-DIH-FW-OPENX-OLE
Skipping useless range: FR-RAEI-FRANCE-TELECOM-CEX-TRANSPAC-RAEI
Skipping useless range: FR-RAEI-FRANCE-TELECOM-TRANSPAC-DIH-FW-OPENX-OLE
Skipping useless range: INTERSOFT AG
Skipping useless range: Network of ChoicePoint Limited
Skipping useless range: Network of ChoicePoint Limited
Skipping useless range: Network of LIM EDS UK
Skipping useless range: Network of LIM - EDS UK (AON)
Skipping useless range: Network of IBM NOS
Skipping useless range: Network of United Business Media Group
Skipping useless range: Network of Thomsons
Skipping useless range: Network of FNAC
Skipping useless range: Network of Sony
Skipping useless range: Network of Apple Computers
Skipping useless range: Network of IBM Forum
Skipping useless range: Network of Mad Catz
Skipping useless range: Network of Bundesministerium Auswrtige Angelegenheiten
Skipping useless range: Network of IBM Sweden HQ
Skipping useless range: www.softland.iq.pl
Skipping useless range: M.G.M. Srl
Skipping useless range: Logotec Engineering
Skipping useless range: Centro Servizi E Ricerche IT
Skipping useless range: MEDIA DIRECT S.R.L
Skipping useless range: IST. REG. DI RICERCA SPERIMENTALE IT
Skipping useless range: Sintesi & Ricerca IT
Skipping useless range: IBM ITALIA SPA
Skipping useless range: I.R.E
Skipping useless range: Centro Ricerche Marine IT
Skipping useless range: STUDIOALFA SNC DEL BIANCO F. & RICCI A
Skipping useless range: IPASS.P.A
Skipping useless range: Advokatfirman Lindberg & Saxon HB
Skipping useless range: EURO I Fernsehproduktions- und Betriebs AG
Skipping useless range: Panasonic Austria HandelsgesmbH
Skipping useless range: SAS Institute Software GmbH
Skipping useless range: EMI Compact Disc (Holland) BV
Skipping useless range: Legal & General Nederland
Skipping useless range: Legal & General Nederland
Skipping useless range: UNISYS Oesterreich
Skipping useless range: Advokatfirmaet Hjelseth & Kilstad DA
Skipping useless range: EDS PA - CGI. Server Hosting DMZ
Skipping useless range: EDS PA - CGI. Server Hosting DMZ
Skipping useless range: Ministero della Giustizia
Skipping useless range: Ministero del Lavoro e della Previdenza Sociale
Skipping useless range: Avvocatura Generale dello Stato
Skipping useless range: Istituto Nazionale di Previdenza Dipendenti IT
Skipping useless range: Ministero della Giustizia
Skipping useless range: Ministero del Tesoro IT
Skipping useless range: Istituto Nazionale della Previdenza Sociale (INPS)
Skipping useless range: Istituto Nazionale della Previdenza Sociale (INPS
Skipping useless range: Ministero del Lavoro e della Previdenza Sociale IT
Skipping useless range: National Institute of Agricultural Economics IT
Skipping useless range: Ministero dei lavori Pubblici IT
Skipping useless range: Ministero Industria IT
Skipping useless range: Ministero della Sanita'
Skipping useless range: CORTE DEI CONTI IT
Skipping useless range: Ministero Attivitā Produttive
Skipping useless range: Ministero Della Difesa
Skipping useless range: Autorita' per l'Informatica nella Pubblica Amminis
Skipping useless range: Autorita' per l'Informatica nella Pubblica Amminis
Skipping useless range: Governo Italiano
Skipping useless range: Scuola Superiore della Pubblica Amministrazione
Skipping useless range: MINISTERO DELLA GIUSTIZIA - Pro. Tel
Skipping useless range: Ministero Infrastrutture e Trasporti(MINT)
Skipping useless range: www.policja.dzialdowo.com.pl
Skipping useless range: STUDIO BENVENUTI S.N.C
Skipping useless range: Aeronautica Militare
Skipping useless range: Ambasciata Greca
Skipping useless range: STUDIO COMMERCIALE VIGANO' - POZZOLI - BRAMBILLA
Skipping useless range: EFFE STUDIO SERVICE SRL
Skipping useless range: CONSIGLIO NAZIONALE DEI GEOLOGI
Skipping useless range: JOCKS MUSIC SRL
Skipping useless range: Det Norske Veritas
Skipping useless range: SOVINTEL-Piramid-Home-video-NET
Skipping useless range: Unizeto Technologies S.A
Skipping useless range: Unizeto Technologies S.A
Skipping useless range: milliyetfw.milliyet.com.tr
Skipping useless range: milliyet.com
Skipping useless range: kurumsal.milliyet.com.tr
Skipping useless range: milliyet.com.tr
Skipping useless range: yarisma.milliyet.com.tr
Skipping useless range: BLOCKBUSTER ITALIA S.P.A
Skipping useless range: IBM ITALIA S.P.A
Skipping useless range: FILMA SRL
Skipping useless range: AMBASCIATA DEL MESSICO
Skipping useless range: The Pentagon
Skipping useless range: Kallisto Productions, Inc
Skipping useless range: DG Entertainment
Skipping useless range: Resolute Partners
Skipping useless range: DKC Entertainment
Skipping useless range: Involve Media
Skipping useless range: DKC Entertainment
Skipping useless range: Grand Media
Skipping useless range: DES Productions
Skipping useless range: The Education Channel International Ltd
Skipping useless range: Conectiva Consultoria e Desenvolvimento de Sistemas
Skipping useless range: City of Post Falls
Skipping useless range: Axcelerant
Skipping useless range: msf-law.com
Skipping useless range: Ernst & Young LLP
Skipping useless range: Ernst & Young LLP
Skipping useless range: Brown Beattie O\\
Skipping useless range: Corus Entertainment/CFPL Radio
Skipping useless range: Polar Interactive
Skipping useless range: First MediaWorks
Skipping useless range: On Tour Multimedia Inc
Skipping useless range: Solitude Systems Software
Skipping useless range: Interactive Media Advertising Group, Inc
Skipping useless range: Rising Tide Productions
Skipping useless range: Electronic Data Systems
Skipping useless range: City of Bellingham
Skipping useless range: IMusicNetworks.com, Inc
Skipping useless range: Bittorrent fakes
Skipping useless range: City of Bellingham
Skipping useless range: Mindfly, Inc
Skipping useless range: Connexion by Boeing Aviation Test Group
Skipping useless range: Connexion by Boeing Commercial Airline Customer
Skipping useless range: Connexion by Boeing Commercial Operations
Skipping useless range: pref.email.ascap.com
Skipping useless range: CMGI
Skipping useless range: Motorola
Skipping useless range: Information Resource Systems
Skipping useless range: Media Process Group
Skipping useless range: Centura Software
Skipping useless range: Oak Hill Capital - Fortworth
Skipping useless range: FINNEGAN HENDERSON
Skipping useless range: lshllp.com
Skipping useless range: Government of the NWT (Lutsel K
Skipping useless range: nexiconinc.com
Skipping useless range: AAA Software
Skipping useless range: False Idol Productions INC
Skipping useless range: Cool Films
Skipping useless range: Modular Production Equipment Inc
Skipping useless range: Entrust Inc
Skipping useless range: City of Seabrook
Skipping useless range: Arbol Media
Skipping useless range: Zuill Brothers Software, Inc
Skipping useless range: Creative Media Productions
Skipping useless range: Veritas Software
Skipping useless range: Hughes Network Systems / Reseller
Skipping useless range: Musictoday LLC
Skipping useless range: Panamsat Chantilly
Skipping useless range: A T Entertainment, Inc
Skipping useless range: Amper, Politziner and Mattia, P.C
Skipping useless range: Southern Company Legal Department
Skipping useless range: Hoku Entertainment - Formely Internet Tv Networks
Skipping useless range: Bang Productions
Skipping useless range: Broadcast Studios
Skipping useless range: dreamcatcherinteractive.com
Skipping useless range: Disney Coporate
Skipping useless range: Alchemedia
Skipping useless range: Knockout Productions
Skipping useless range: Omega Studios, Inc
Skipping useless range: Dallas Cowboys Merchandise
Skipping useless range: Pittsylvania County Government-nDanville
Skipping useless range: The M Group
Skipping useless range: Thought Convergence, Inc
Skipping useless range: The Moschovitis Group
Skipping useless range: Web Studio (000000)
Skipping useless range: Web Studio (000000)
Skipping useless range: CDP Entertainment (000000)
Skipping useless range: Entertainmentjob.com (000000)
Skipping useless range: SideSmile Productions (000000)
Skipping useless range: Unisys-Rosville
Skipping useless range: www.webnmedia.com
Skipping useless range: Analysts International
Skipping useless range: ARINC
Skipping useless range: Law Offices of John R. Zarzynski
Skipping useless range: Harris Wiltshire & Grannis LLP
Skipping useless range: Tarlow, Breed, Hart, Murphy & Rodgers
Skipping useless range: Siebel Systems Accounts Payable
Skipping useless range: Atlanta Legal Services
Skipping useless range: WHITMONT LEGAL COPYING
Skipping useless range: Law Office of Robert Harrington
Skipping useless range: Burke, Warren, MacKay &amp; Serritella, P.C
Skipping useless range: Burke, Warren, MacKay & Serritella, P.C
Skipping useless range: Quantitive Software Management, Inc
Skipping useless range: LegaLink Manhattan
Skipping useless range: JJ Software
Skipping useless range: Hilton Huntington Hotel
Skipping useless range: Raytheon-Range Systems
Skipping useless range: Cinemark USA, Inc..256844
Skipping useless range: Intraware, Inc
Skipping useless range: Prism Software
Skipping useless range: Cranston Software
Skipping useless range: Trimedia, Inc
Skipping useless range: Third Eye Media
Skipping useless range: Legal Communications Corp
Skipping useless range: Maddock, Henson, Haberstroh, P.C
Skipping useless range: U.S. Court of Appeals (7th Circuit)
Skipping useless range: AVI Media, Inc
Skipping useless range: B Exquisite Productions
Skipping useless range: Caymen Islands Dept. of Tourism - MHarrigan
Skipping useless range: Caymen Islands Dept. of Tourism - SRogers
Skipping useless range: Adaptec, Inc
Skipping useless range: Caymen Islands Dept. of Tourism - SRogers
Skipping useless range: National Association of Manufacturers - Wilshire
Skipping useless range: National Association of Manufacturers - Route 46
Skipping useless range: National Association of Manufacturers - Market Str
Skipping useless range: National Association of Manufacturers - East Seven
Skipping useless range: Autonomy Systems LLC
Skipping useless range: CSTV Online Inc
Skipping useless range: State of WA Office of Financial Mgmt. Epermit.org
Skipping useless range: WA State Bar Assn. Continuing Legal Education
Skipping useless range: Fox Sports
Skipping useless range: The NC Dept of Health and Huma
Skipping useless range: Nashville Chamber of Commerce
Skipping useless range: Hammock Publishing
Skipping useless range: BMI
Skipping useless range: MusicYo.com, Inc
Skipping useless range: Nashville Chamber of Commerce
Skipping useless range: Motricity, Inc
Skipping useless range: Global Anti-Piracy Systems
Skipping useless range: Play Fair Entertainment, LLC
Skipping useless range: Latis Networks, Inc
Skipping useless range: Latis Networks, Inc
Skipping useless range: Universal Company
Skipping useless range: Community Action Agency
Skipping useless range: James Keane Co
Skipping useless range: International Law Institute
Skipping useless range: Voice of America
Skipping useless range: EDS Innovations
Skipping useless range: IBM Canada Ltd
Skipping useless range: INTRACOM CORPORATION
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar Networks LEUK
Skipping useless range: Verestar
Skipping useless range: VereStar Networks BRW
Skipping useless range: SES-Americom Network
Skipping useless range: VereStar Networks BRW
Skipping useless range: VereStar Networking Consumers
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar Network
Skipping useless range: Spokane Chamber of Commerce
Skipping useless range: Lon Gibby Productions, Inc
Skipping useless range: Cowles Publishing
Skipping useless range: PROSECUTING ATTORNEYS COUNCIL OF GEORGIA
Skipping useless range: Khmer Broadcasting Network Inc
Skipping useless range: Flying Tiger Development
Skipping useless range: The Yocca Law Firm, LLP
Skipping useless range: Paramount Disc
Skipping useless range: Certifion Corp
Skipping useless range: eStream, Inc
Skipping useless range: Jerry Bruckheimer Films
Skipping useless range: Ntreev USA Inc
Skipping useless range: Law Offices of Mark A. Gallagher
Skipping useless range: General Dynamics
Skipping useless range: In-Fusio
Skipping useless range: City Of Newport Beach
Skipping useless range: Mitsubishi Electronics America, Inc
Skipping useless range: Eltman Eltman & Cooper
Skipping useless range: eStream, Inc
Skipping useless range: Mahaffey & Associates
Skipping useless range: Knobbe, Martens, Olson, Bear
Skipping useless range: Shimokaji & Associates
Skipping useless range: TMC Communities
Skipping useless range: Erwin & Johnson
Skipping useless range: Pix Video, Film & Multimedia
Skipping useless range: Hollywood Music, Inc
Skipping useless range: Scott & Whitehead
Skipping useless range: Studio Exchange
Skipping useless range: Xroads
Skipping useless range: Newport Beach Film Festival
Skipping useless range: K2 Network
Skipping useless range: Dewit Law Offices
Skipping useless range: Mitsubishi Digital Electronics of America
Skipping useless range: Kutak Rock LLP
Skipping useless range: Arlon Adhesives and Films
Skipping useless range: iPass-Germany-colo Class-C
Skipping useless range: ROUTE OBJECT FOR iPass
Skipping useless range: City of Portland
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Compaq
Skipping useless range: Compaq
Skipping useless range: Compaq
Skipping useless range: VereStar Networking Consumers
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar Link
Skipping useless range: Verestar
Skipping useless range: Verestar
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar (addition)
Skipping useless range: Verestar (addition)
Skipping useless range: Skyweb Technologies Ltd ((ITAA Member))
Skipping useless range: Riefberg, Smart, Donohue and NeJame PC
Skipping useless range: Gemeindeverwaltung Nuesttal
Skipping useless range: Alfred Publishing Verlags GmbH
Skipping useless range: Bundes.Pensions.Service
Skipping useless range: Jaff und Kollegen Rechtsanwaelte
Skipping useless range: KBR
Skipping useless range: Stadtverwaltung Forst (Lausitz)
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Muensingen
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Bad Urach
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Kitzingen
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Neumuenster
Skipping useless range: Telekontor GmbH
Skipping useless range: Landratsamt Rhein-Neckar-Kreis
Skipping useless range: Hotel Hilton Garden Inn
Skipping useless range: WVG GFGH GmbH
Skipping useless range: ITZBw
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Hechingen
Skipping useless range: BVI Bundesverband Deutscher Investment Gesellscha
Skipping useless range: Anschutz Entertainment Group Development
Skipping useless range: Army Recreation Machine
Skipping useless range: AdEvents Cross Media AG
Skipping useless range: Customs Support
Skipping useless range: Vodafone Pilotentwicklung GmbH
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Duisburg
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Bad Wildunge
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Bad Arolsen
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Zell
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Osterburken
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Jever
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Varel
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Loerrach
Skipping useless range: CineStar - der Filmpalast in Rostock
Skipping useless range: Kino -Schauburg-
Skipping useless range: Agentur fuer Arbeit Saarbruecken ARGE
Skipping useless range: adp engineering GmbH
Skipping useless range: SABOCON GmbH
Skipping useless range: STUDIO MONDIALE
Skipping useless range: Military Car Sales GmbH
Skipping useless range: Army Recreation
Skipping useless range: Bundesanstalt fuer Arbeit Arbeitsamt Horb
Skipping useless range: Securitas Systems GmH
Skipping useless range: TRW/Lucas Automotive GmbH
Skipping useless range: T-Systems International GmbH fuer SPIEGEL Verlag
Skipping useless range: Nebel Verlag GmbH
Skipping useless range: ESM Software GmbH
Skipping useless range: Media Corporation One GmbH
Skipping useless range: Innenministerium NRW
Skipping useless range: Observer Argus Media GmbH
Skipping useless range: Princess Royal Barracks
Skipping useless range: Agentur fuer Arbeit Neuruppin ARGE
Skipping useless range: Agentur fuer Arbeit Jena ARGE
Skipping useless range: Hans Thomann Musikhaus
Skipping useless range: Agentur fuer Arbeit Kiel ARGE
Skipping useless range: Lucent Technology, Portmaster RAS
Skipping useless range: Law Consultation Firm
Skipping useless range: Robert-MUSIC.UK
Skipping useless range: COMUNEDIFICARAZZI
Skipping useless range: COMUNEDISIRACUSA
Skipping useless range: COMUNEDIRAVANUSA
Skipping useless range: COMUNEDIRAVANUSA
Skipping useless range: Priority Telecom
Skipping useless range: Modern Electronics
Skipping useless range: Toshiba Europe GmbH
Skipping useless range: Wincor-Nixdorf
Skipping useless range: Fujitsu Siemens Computers Paderborn Germany
Skipping useless range: Wincor-Nixdorf
Skipping useless range: Fujitsu Siemens Computers Germany
Skipping useless range: Fujitsu Siemens Computers Germany
Skipping useless range: Fujitsu Siemens Computers Munich Germany
Skipping useless range: Echelon bv consutancy & network services
Skipping useless range: Ministry of Finance of Bulgaria, headquarters
Skipping useless range: Wave LAN City Hall Vienna
Skipping useless range: www.zapa.org.pl
Skipping useless range: SDSL: Cineflix Productions UK
Skipping useless range: Schlund + Partner AG United Statesfakes
Skipping useless range: AGEPROCINEMA
Skipping useless range: Trw-systeme-freinage
Skipping useless range: Affinity Media
Skipping useless range: ORACLE FRANCE
Skipping useless range: ORACLE FRANCE
Skipping useless range: FR-RAEI-OIPC-INTERPOL-LB_INTERNET
Skipping useless range: Regie Europeenne de Cinema
Skipping useless range: Adp Gsi France
Skipping useless range: PARAMETRIC TECHNOLOGY SA
Skipping useless range: PUBLICINEX
Skipping useless range: SAS INSTITUTE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: XEROX THE DOCUMENT COMPANY SAS
Skipping useless range: LUCENT TECHNOLOGIES FRANCE SAS
Skipping useless range: Weifang zhucheng bureau of commerce and industry
Skipping useless range: Lianyungang police station monitoring room gov
Merged range 'China Youth Publishing Company', with range 'China Youth Publishing Company'
Skipping useless range: GAMANIA DIGITAL ENTERTAINMENT [JAPAN] CO.,LTD
Skipping useless range: GAMANIA DIGITAL ENTERTAINMENT [JAPAN] CO.,LTD
Merged range 'Guangxi area jail administrative bureau', with range 'Guangxi area procuratorate'
Skipping useless range: Bittorrent Scammer
Skipping useless range: SCHLUMBERGER,INC
Skipping useless range: SCHLUMBERGER,INC
Skipping useless range: ASSENT, A SUNGARD COMPANY
Skipping useless range: Dakota West Credit Union
Skipping useless range: Minnesota Valley Testing Laboratories
Skipping useless range: Odyssey Research
Skipping useless range: BATTELLE MEMORIAL INSTITUTE
Skipping useless range: RED HAT SOFTWARE
Skipping useless range: GLOBAL EXCHANGE SERVICES GEIS
Skipping useless range: MEGAPATH NETWORKS
Skipping useless range: ATT MIS IP-ATT SVCS INC SP.EVE
Skipping useless range: ATT MIS IP-ATT SVCS INC SP.EVE
Skipping useless range: STUDIO 6
Skipping useless range: STUDIO 6
Skipping useless range: MEGAPATH NETWORKS
Skipping useless range: ATT MIS IP-ATT SVCS INC SP.EVE
Skipping useless range: ATT MIS IP-ATT SVCS INC SP.EVE
Skipping useless range: ATT MIS IP-ATT SVCS INC SP.EVE
Skipping useless range: MEGAPATH NETWORKS
Skipping useless range: DELOITTE TOUCHE
Skipping useless range: RR DONNELLEY TECHNOLOGY SERVICES LLC
Skipping useless range: KLA - TENCOR CORPORATION
Skipping useless range: PITNEY BOWES INC
Skipping useless range: Academy Mortgage Group
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: MEDICAL-BILLING-NETWORK
Skipping useless range: GULF-OF-MAINE-RESEARCH-INSTITUTE
Skipping useless range: BURRELLES
Skipping useless range: PROSOFT
Skipping useless range: MAINESTREET-COMMUNCATINS
Skipping useless range: YORK-HOSPITAL
Skipping useless range: FORUM-FINANCIAL
Skipping useless range: HOLIDAY-INN-WEST
Skipping useless range: MEDICAL-BILLING-NETWORK-COLO
Skipping useless range: FORUM-FINANCIAL
Skipping useless range: RIVERFRONT-MEDICAL
Skipping useless range: UHS---DELAWARE-VALLEY-HOSPITAL
Skipping useless range: UNITED-HEALTH-SERVICES---WILSON-HOSPITAL
Skipping useless range: MEGAPATH-/-FASTENAL
Skipping useless range: SOUTHERN-CHAUTAUQUA-FEDERAL-CREDIT-UNION
Skipping useless range: MEDICAL-MANAGEMENT-SERVICES
Skipping useless range: CAYUGA-MEDICAL
Skipping useless range: OCNB-BANK
Skipping useless range: COLGATE-INN
Skipping useless range: VIRTELA
Skipping useless range: MORGAN-STANLEY
Skipping useless range: FASTNEL/MEGAPATH
Skipping useless range: BATAVIA-VA-MEDICAL-CENTER
Skipping useless range: HASSAN-MEDICAL-GROUP
Skipping useless range: MONROE-PLAN-FOR-MEDICAL-CARE
Skipping useless range: ftp.cjdirect.net
Skipping useless range: CLIFFVIEW-BANK
Skipping useless range: FIFTH-AVENUE-FINANCIAL-CENTER
Skipping useless range: FINANCIAL-GUARANTEE
Skipping useless range: FIFTH-AV-FINANCIAL-CTR
Skipping useless range: FIFTH-AVENUE-FINANCIAL-CENTER
Skipping useless range: THE-BERKSHIRE-BANK
Skipping useless range: THE-WHITEHAVEN-GROUP
Skipping useless range: BON-SECOUR-HOSPITAL
Skipping useless range: MRC-FEDERAL-CREDIT-UNION
Skipping useless range: WILBER-NATIONAL-BANK---ONEONT
Skipping useless range: DELAWARE-VALLEY-HOSPITAL---INFORMATION-TECHNOLOGY-DEPARTMENT
Skipping useless range: DELAWARE-VALLEY-HOSPITAL---WEST-STREET-CLINIC
Skipping useless range: DELAWARE-VALLEY-HOSPITAL---DELAWARE-STREET-CLINIC
Skipping useless range: TRI-COUNTY-FAMILY-MEDICINE
Skipping useless range: SOUTHPORT-FEDERAL-CREDIT-UNION
Skipping useless range: DOCTORS-TELEHEALTH-NETWORK,-INC
Skipping useless range: TRUSTCO-BANK
Skipping useless range: HOMEDICAL-ASSOCIATES
Skipping useless range: ELLIS-HOSPITAL
Skipping useless range: FOXWOOD-APARTMENTS-MAITENANCE-ROOM
Skipping useless range: AUTOMATE-DEALERSHIP-SYSTEMS
Skipping useless range: NY-CENTRAL-INSURANCE
Skipping useless range: EVERGREEN-LAKE-GEORGE-ESC-CAFE
Skipping useless range: CORNERSTONE-FINANCIAL-ADVISORS
Skipping useless range: HONDA-RESEARCH-&-DEVELOPMENT
Skipping useless range: BMS-MEDICAL-EQUIPMENT-LLC
Skipping useless range: LANGE-PHARMACY
Skipping useless range: BAPTIST-HEALTH-CENTER
Skipping useless range: LIBERTY-CLINIC
Skipping useless range: B-&-L-MEDICAL-SYSTEMS
Skipping useless range: MIDWEST-FINANCIAL
Skipping useless range: FAIRPORT-SAVINGS-BANK
Skipping useless range: FAIRPORT-SAVINGS-BANK-CORRECT-CONFIG
Skipping useless range: PAT-LARABEE---ROCH-CLINICAL
Skipping useless range: ATC-DISTRIBUTION-/-MEGAPATH
Skipping useless range: MARAFATIA-MEDICAL
Skipping useless range: MARFATIA-MEDICAL
Skipping useless range: MARAFATIA-MEDICAL
Skipping useless range: MARKET-GENESYS
Skipping useless range: ACM-MEDICAL
Skipping useless range: EASTMAN-KODAK---BOB-MARK---WWIS
Skipping useless range: ST-LAWRENCE-PUBLIC-HEALTH
Skipping useless range: BOLTON'S-PHARMACY
Skipping useless range: FIBERMARK
Skipping useless range: FALLS-PHARMACY
Skipping useless range: SENECA-FEDERAL-SAVINGS
Skipping useless range: CHRIST-COMMUNITY-THIRD-ST-CLINIC
Skipping useless range: mecca-exhange1.meccamedia.com
Skipping useless range: INC,DTIDATA-DOT-COM
Skipping useless range: LLP Engel-Calvin-McMillan
Skipping useless range: Megapath Gambo Healthcare
Skipping useless range: MC Enterprise
Skipping useless range: Hollywood Slots @ Bangor
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: Daddys Junky Music
Skipping useless range: Road Runner Commercial
Skipping useless range: Basic Media Group
Skipping useless range: Echo Star Satellite LLC
Skipping useless range: Echo Star Satellite LLC
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: MID-HUDSON-FAMILY-HEALTH
Skipping useless range: KOLMAR-LABORATORIES
Skipping useless range: Road Runner Commercial
Skipping useless range: NORTHLAND-DATA
Skipping useless range: MORTGAGE-BANKING-CORP
Skipping useless range: AMIOT-FINANCIAL
Skipping useless range: BANTA
Skipping useless range: FIRST-MINNETONKA-CITY-BANK
Skipping useless range: VERTICAL-SYSTEMS
Skipping useless range: CAPI
Skipping useless range: COMMUNITY-REINVESTMENT-FUND
Skipping useless range: Road Runner Commercial
Skipping useless range: NATIONAL-BANKERS-TRUST
Skipping useless range: FAIRFIELD-MEDICAL-CENTER---SERVERS
Skipping useless range: BERGER-HEALTH-SYSTEM
Skipping useless range: OZ-USA
Skipping useless range: STRATEGIC-ADVANTAGE,-INC
Skipping useless range: MORRIS-&-ASSOC
Skipping useless range: J-C-CONSULTING
Skipping useless range: CHAMPAIGN-BANK
Skipping useless range: VIRTELA-ALC
Skipping useless range: SATELLITE-LABS
Skipping useless range: LAKELAND-REGIONAL-MEDICAL-CENTER
Skipping useless range: ORION-MEDICAL-MANAGEMENT
Skipping useless range: SDI-RADIOLOGY-MAIN-SITE-CISCO-PIX
Skipping useless range: STERLING-RESEARCH
Skipping useless range: ADVANTAGE,DESKTOP
Skipping useless range: THOMAS-FINANCIAL
Skipping useless range: TOTAL-HEALTHCARE,SUNCOAST
Skipping useless range: DAVIS-BANK-CORP
Skipping useless range: VIBRA-ANALYSIS-INC
Skipping useless range: FINANCIAL-GROUP,POE
Skipping useless range: WEST-COAST-FAMILY-MEDICAL
Skipping useless range: FDLE-FINANCE-AND-ACCOUNTING
Skipping useless range: CHEMICAL-SPECIFICS-
Skipping useless range: BREAKING-VIEWS
Skipping useless range: CENTRAL-MEDICAL
Skipping useless range: QUEENS-MEDICAL-OFFICE-PC-
Skipping useless range: COMPUTER-ELEVATOR-CONTROL
Skipping useless range: NORTH-AUSTIN-MEDICAL-CENTER
Skipping useless range: CAROLINA-CLINICAL-RESEARCH-
Skipping useless range: NORTHEAST-MEDICAL-CTR
Skipping useless range: CAROLINA-DIABETES-&-ENDROCRINE-CLINICS-
Skipping useless range: HOLIDAY-INN---CENTER-CITY
Skipping useless range: PREFERRED-MEDICAL-MARKETING
Skipping useless range: QUATUM-MEDICAL-BUSINESS-SERVICE
Skipping useless range: TRIDENT-MANAGEMENT-INC
Skipping useless range: BRAGG-MUTUAL-FEDERAL-CREDIT-UNION---VILLAGE-DR
Skipping useless range: Road Runner Commercial
Skipping useless range: FEDEX-MASERGY-DEAL-(HOLD)
Skipping useless range: FEDERAL-EXPRESS-LAB
Skipping useless range: HOMEBANK
Skipping useless range: ROB-CARTER---FEDEX-VIP
Skipping useless range: TIMKEN-RESEARCH
Skipping useless range: PEDIATRIX-MEDICAL-GROUP
Skipping useless range: AMERICAN-FINANCIAL-FREEDOM
Skipping useless range: CLINICAL-CARDIOLOGY-SPECIALISTS-INC
Skipping useless range: CLINICAL-CARDIOLOGY-SPECIALISTS-INC
Skipping useless range: DELAWARE-COUNTY-BANK-&-TRUST
Skipping useless range: Road Runner Commercial
Skipping useless range: BASTROP-MEDICAL-CENTER
Skipping useless range: TAMPA-BAY-FEDERAL-CREDIT-UNION
Skipping useless range: VSR-FINANCIAL-SERVICES
Skipping useless range: HILLS-COUNTY-HEALTH-SUPT
Skipping useless range: FINANCIAL,-MMA
Skipping useless range: MEDICAL-CENTER-OF-TAMPA
Skipping useless range: MERCEDES-MEDICAL-2
Skipping useless range: TAMPA-BAY-FEDERAL-CREDIT-UNION
Skipping useless range: MAVERICK-COUNTY-HOSPITAL-DISTRICT
Skipping useless range: THIRD-PARTY-MEDICAL
Skipping useless range: WESLACO-ADVANCED-MEDICAL-78596_BACKUP
Skipping useless range: NEUROSURGICAL-SPECIALIST-OF-AUSTIN
Skipping useless range: ABC-MEDICAL-CENTER
Skipping useless range: SWISHER-WILBANKS
Skipping useless range: PRO-VISTA-EYE-CLINIC
Skipping useless range: EDIATRIX-MEDICAL-GROUP
Skipping useless range: EDELMAN-PUBLIC-RELATIONS
Skipping useless range: THE-SHEPHERDS-COMMUNITY-HEALTH-CLINIC
Skipping useless range: CITIZENS-STATE-BANK
Skipping useless range: INTERNATION-BANK-OF-COMM
Skipping useless range: GENCO-FEDERAL-CREDIT-UNION
Skipping useless range: EXTRACO-BANKS
Skipping useless range: JACKSON-MEDICAL-MALL-FOUNDATION-
Skipping useless range: BANK-OF-TEXAS
Skipping useless range: VALERO-FEDERAL-CREDIT-UNION
Skipping useless range: F-&-F-MICRO-FILMING
Skipping useless range: TEXAS-STATE-BANK
Skipping useless range: POST-OAK-BANK
Skipping useless range: ADVANCED-PHARMACY
Skipping useless range: S.W.-TARIFF-ANALYST
Skipping useless range: KIRKWOOD-MEDICAL-ASSOC
Skipping useless range: UNITED-HERITAGE-FEDERAL-CREDIT
Skipping useless range: RIGID-MEDICAL-TECHNOLOGIES
Skipping useless range: REMAX-ACTION
Skipping useless range: MIGRANT-CLINICIANS-NETWORK
Skipping useless range: ST-DAVID'S-MEDICAL-CENTER
Skipping useless range: REMAX-PREMIER-PROPERTIES
Skipping useless range: MANSE-LABS
Skipping useless range: CORE-CALL-OUT-RESEARCH
Skipping useless range: WOODRIDGE-LABS
Skipping useless range: NATIONAL-DERMATOPATHOLOGY-LAB
Skipping useless range: WINNETKA-PHARMACY
Skipping useless range: PRIMEX-CLINICAL-LABORATORIES
Skipping useless range: FIRST-COMMERCE-BANK
Skipping useless range: PACIFIC-INDEPENDENCE-FINANCE
Skipping useless range: BAYSIDE-MEDICAL-CENTER
Skipping useless range: ALL-SEASONS-FINANCIAL
Skipping useless range: COLDWELL-BANKER-COASTAL-ALLIANCE
Skipping useless range: AGAPE-FINANCIAL-&-INSURANCE-SERVICES
Skipping useless range: PRODUCT-RESEARCH-INC
Skipping useless range: EDINGER-MEDICAL-GROUP
Skipping useless range: BIOCORP-CLINICAL-LABORATORY
Skipping useless range: TWC---ORANGE---TEST-LAB-IP-RANGE
Skipping useless range: FIRST-STATE-BANK-OF-CALIFORNIA
Skipping useless range: FIRST-COSTAL-BANK
Skipping useless range: PEDIATRIX-MEDICAL-GROUP-WEST-HILLS
Skipping useless range: REGAL-MEDICAL-GROUP
Skipping useless range: 1ST-ASSURANCE-FINANCIAL-SERVICES,-INC
Skipping useless range: BIOMEDICAL
Skipping useless range: MARION-PHARMACY,-INC
Skipping useless range: STRATEGIC-ADVANTAGE-INC
Skipping useless range: CITIGROUP-TRIAL-P2P
Skipping useless range: BROOKLYN-FINANCIAL
Skipping useless range: CARE-WELL-PHARMACY
Skipping useless range: JEFF-BANK
Skipping useless range: RIVERSIDE-BANK
Skipping useless range: MIDDLETOWN-MEDICAL
Skipping useless range: STEP-STONE-FINANCIAL
Skipping useless range: SKYWAY-RV-RESORT
Skipping useless range: ST-LAWRENCE-FEDERAL-CREDIT-UNION
Skipping useless range: SYRACUSE-RESEARCH-CORP
Skipping useless range: GEDDES-FEDERAL-SAVINGS-AND-LOAN
Skipping useless range: EJ-DELMONTE---FAIRFIELD-INN-BY-MARRIOTT--FRONT-ST
Skipping useless range: Tor.sectorsix
Skipping useless range: EXPRESS-FINANCIAL-SERVICES
Skipping useless range: DUNLAWTON-FAMILY-MEDICAL
Skipping useless range: BEACH-MEDICAL-IMAGING
Skipping useless range: SUNCOAST-MEDICAL
Skipping useless range: GLOBESPAN-VIRATA
Skipping useless range: WILLIAM-PAGE
Skipping useless range: COLEMAN-TECHNOLOGIES
Skipping useless range: ORION-MEDICAL-MANAGEMENT
Skipping useless range: HEART-OF-FLORIDA-REGIONAL-MEDICAL-CENTER
Skipping useless range: WATSON-CLINIC
Skipping useless range: DATA,FOCUS-FINANCIAL
Skipping useless range: LAKELAND-REGIONAL-MEDICAL-CENTER
Skipping useless range: INTL,TRIDENT-MARKETING
Skipping useless range: GRP,DOCTORS-PAIN-MGMT
Skipping useless range: GROUP,GE-FINANCIAL-FREEDOM
Skipping useless range: FINANCIAL,JEFFERSON-PILOT
Skipping useless range: GULFCOAST-MEDICAL-CENTER
Skipping useless range: DELTA-ELEVATOR
Skipping useless range: MNH-MEDICAL-CENTER
Skipping useless range: EXPRESS-FINANCIAL-SERVICES-FL
Skipping useless range: CRAIG-COOK
Skipping useless range: Road Runner Commercial
Skipping useless range: RESHMEY-MEDICAL-CLINIC
Skipping useless range: CREATIVE-LABS-INC
Skipping useless range: JOHNSTON-INDUSTRIES
Skipping useless range: BIOSTIM
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Hudson Highland Group
Skipping useless range: Hudson Highland Group
Skipping useless range: Lion Resources Inc
Skipping useless range: Guggenheim Services LLC
Skipping useless range: Hudson Highland Group
Skipping useless range: MBC Research
Skipping useless range: Horizon Media, Inc
Skipping useless range: Friedman LLP
Skipping useless range: Becker-Parkin Dental Supply Company, Inc
Skipping useless range: Friedman LLP
Skipping useless range: Kaplan, Inc
Skipping useless range: VIRTELA COMMUNICATIONS INC - CO - HQ
Skipping useless range: Wooster Capital Management
Skipping useless range: Delrey Technologies LLC
Skipping useless range: Carl Marks & Co
Skipping useless range: New York Society of Security Analysts
Skipping useless range: EWT, LLC
Skipping useless range: Ramius Capital Corp
Skipping useless range: Raeburn Capital Management
Skipping useless range: ACT/Forex
Skipping useless range: ACTForex Inc
Skipping useless range: Juma Technology Corp
Skipping useless range: Schrodinger
Skipping useless range: DeSilva & Phillips
Skipping useless range: Chapdelaine & Company
Skipping useless range: Power Concepts
Skipping useless range: Credit Sights
Skipping useless range: New York Economic Development Company
Skipping useless range: Mitsubishi International Corporation
Skipping useless range: Schrodinger
Skipping useless range: St. Vincents Medical
Skipping useless range: Cru Capital Management, LLC
Skipping useless range: Calypso Capital Management, LP
Skipping useless range: Trafelet & Company
Skipping useless range: MBC Research
Skipping useless range: FIRSTBORN MULTIMEDIA CORP
Skipping useless range: India Equity Partners Management Subsidiary LLC
Skipping useless range: Horizon Media, Inc
Skipping useless range: CHEETAH MAIL - Experian
Skipping useless range: Bank Julius Baer
Skipping useless range: QVT Financial LP
Skipping useless range: Fred Alger Management, Inc
Skipping useless range: Indus Capital Partners
Skipping useless range: Arab Banking Corporation
Skipping useless range: Bishop Rosen & Co
Skipping useless range: Brigade Capital
Skipping useless range: Neutral Tandem
Skipping useless range: Fred Alger Management, Inc
Skipping useless range: Wombat Financial Software, Inc
Skipping useless range: DF King & Co
Skipping useless range: STEADFAST FINANCIAL LLC
Skipping useless range: FINE POINT TECHNOLOGIES INC
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: India Equity Partners Management Subsidiary LLC
Skipping useless range: Renegade Marketing Group LLC
Skipping useless range: Aksia Research and Management
Skipping useless range: Bevmax Office Centers
Skipping useless range: Piper Jafray & Co
Skipping useless range: Vyapar Capital Market Partners LLC
Skipping useless range: St. Vincents Medical
Skipping useless range: Rubenstein Associates, Inc
Skipping useless range: Universal Consulting
Skipping useless range: Kaplan, Inc
Skipping useless range: Inform.com
Skipping useless range: Sapient Corp
Skipping useless range: Indus Capital Partners
Skipping useless range: Prescient
Skipping useless range: Ignite Technologies
Skipping useless range: Gwynn Group
Skipping useless range: Practice Performance, Inc
Skipping useless range: Softlayer Technologies Inc
Skipping useless range: Maverick Capital / formerly MCL corporation
Skipping useless range: Square One Advertising
Skipping useless range: Softlayer Technologies Inc
Skipping useless range: SCHLUMBERGER
Skipping useless range: Alvarez and Marsal Holdings, LLC
Skipping useless range: ESI
Skipping useless range: The Carlisle Group INC
Skipping useless range: ENSCO
Skipping useless range: Ranger Capital
Skipping useless range: SoftLayer Technologies Inc
Skipping useless range: Hitachi Consulting
Skipping useless range: Softlayer Technologies Inc
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: Western Reserve Capital Management
Skipping useless range: Buchanan Associates
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Everest Group
Skipping useless range: panther express nyc
Skipping useless range: RushGroup Technologies
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: panther express nyc
Skipping useless range: AboveNet Inc
Skipping useless range: Harbor Capital Advisors
Skipping useless range: EVERGREEN FUNDS
Skipping useless range: Moelis & Company
Skipping useless range: Ramius Capital Corp
Skipping useless range: Merrill Corporation
Skipping useless range: Constant Contact
Skipping useless range: Rafferty Capital Markets
Skipping useless range: RIGHT MANAGEMENT
Skipping useless range: Sirios Capital Management
Skipping useless range: Park Street Capital LLC
Skipping useless range: Fortelligent
Skipping useless range: Parthenon Capital LLC
Skipping useless range: ZS ASSOCIATES Inc
Skipping useless range: 2100 Capital Group
Skipping useless range: Kaintuck Capital Management
Skipping useless range: Akaza Research
Skipping useless range: Tripoint Asset Management
Skipping useless range: CADENCE CAPITAL MANAGEMENT
Skipping useless range: Bainbridge Inc
Skipping useless range: NetTeks Technology Consultants, Inc
Skipping useless range: Crystal Capital
Skipping useless range: Virtua Research
Skipping useless range: Tisbury Capital Management
Skipping useless range: Adage Capital Management
Skipping useless range: Regus Business Centers
Skipping useless range: Parthenon Capital
Skipping useless range: Seacross Global Advisors
Skipping useless range: Pamet Capital LLC
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: NetTeks Technology Consultants, Inc
Skipping useless range: 033 Asset Management
Skipping useless range: Metro Meeting Centers
Skipping useless range: Hollister Associates
Skipping useless range: Miller Systems, Inc
Skipping useless range: FourWinds Capital Management, (US) Inc
Skipping useless range: Mindshift Professional Services - Boston
Skipping useless range: FourWinds Capital Management, (US) Inc
Skipping useless range: First Wind Energy, LLC
Skipping useless range: Old Mutual Asset Management
Skipping useless range: C.H.E.N. PR Inc
Skipping useless range: Whale Rock Capital Management
Skipping useless range: Edison Mission Marketing & Trading
Skipping useless range: General Investment Advisers LLC
Skipping useless range: Denham Capital Management
Skipping useless range: Lee Munder Capital Group
Skipping useless range: Lee Munder Capital Group
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Oceanwood Capital Management
Skipping useless range: RINET Company LLC
Skipping useless range: Alphasimplex Group, LLC
Skipping useless range: LightKeeper Investments, LP
Skipping useless range: Global Logic Investors LLC
Skipping useless range: ADVANCED TECHNOLOGY VENTURES
Skipping useless range: Summer Street Research Partners
Skipping useless range: Whale Rock Capital Management
Skipping useless range: Arrow Street Capital
Skipping useless range: Gerson Lehrman Group
Skipping useless range: Hill, Holliday, Connors, Cosmopolous Inc
Skipping useless range: Lux Research Inc
Skipping useless range: Liberty Square Asset Management
Skipping useless range: Unleaded Software Inc
Skipping useless range: Financial Media Group
Skipping useless range: Lovas Software Solutions
Skipping useless range: Mentis Technology Solutions
Skipping useless range: Pride Marketing
Skipping useless range: UNICOM CAPITAL GROUP
Skipping useless range: AboveNet Inc
Skipping useless range: Integrated Asset Services
Skipping useless range: Integrated Asset Services
Skipping useless range: UNICOM CAPITAL GROUP
Skipping useless range: Bellco Credit Union
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Integrated Asset Services
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Kind3.com
Skipping useless range: Brookfield Financial Properties, L.P
Skipping useless range: Kind3.com
Skipping useless range: Bandcon
Skipping useless range: TARGET MEDIA PARTNERS
Skipping useless range: Cahill Association Management
Skipping useless range: VENTURE TECHNOLOGIES
Skipping useless range: MPRM Public Relations
Skipping useless range: LA Inc. Convention & Visitors Bureau
Skipping useless range: Davis Elen Advertising
Skipping useless range: One East Capital Advisors, LP
Skipping useless range: Trust Company of the West - Main
Skipping useless range: PREFERRED BANK
Skipping useless range: Transera Communications
Skipping useless range: Fourth Wall Marketing
Skipping useless range: Creative Channel Services
Skipping useless range: AboveNet Inc
Skipping useless range: PAYDEN & RYGEL
Skipping useless range: Maxxiss Communications
Skipping useless range: First Standard Bank
Skipping useless range: Advanced Network Engineering, Inc
Skipping useless range: Advanced Network Engineering, Inc
Skipping useless range: NYC & Company
Skipping useless range: Merriman Curhan Ford & Company
Skipping useless range: Mahoney Cohen & Co., CPA
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Weiser, LLP
Skipping useless range: AboveNet Inc
Skipping useless range: AboveNet Inc
Skipping useless range: Royal Capital Management, LLC
Skipping useless range: Izara Capital Management
Skipping useless range: York Capital Management
Skipping useless range: Alvarez and Marsal
Skipping useless range: Marcum & Kliegman LLP
Skipping useless range: Ladenburg Thalmann & Company, Inc
Skipping useless range: Ridgefield Capital Group, LLC
Skipping useless range: The Park Hill Group
Skipping useless range: Velocity Technology Solutions LLC
Skipping useless range: AG Asset Management
Skipping useless range: Marcum & Kliegman LLP
Skipping useless range: Regent Business Centers
Skipping useless range: Arrow Investments Inc
Skipping useless range: Development Corp. for Israel
Skipping useless range: Hayground Cove Asset
Skipping useless range: Holtz Rubenstein Reminick LLP
Skipping useless range: Madison Harbor Capital LLC
Skipping useless range: Cline Davis & Mann
Skipping useless range: Interactive Corporation
Skipping useless range: OCC Strategy Consultants
Skipping useless range: Ramius Capital Corp
Skipping useless range: Investcorp International, Inc
Skipping useless range: Prudential Douglas Elliman
Skipping useless range: National Financial Partners
Skipping useless range: Izara Capital Management
Skipping useless range: Ramius Capital Group
Skipping useless range: Integre Advisors
Skipping useless range: B.J. VINES Inc (betsey johnson)
Skipping useless range: Emcor Securities Inc
Skipping useless range: Titan Worldwide
Skipping useless range: Cougar Trading
Skipping useless range: RHODES ASSOCIATES
Skipping useless range: Andrew Garrett Inc
Skipping useless range: Cerberus Capital Management
Skipping useless range: Aetos Capital, LLC
Skipping useless range: Aegis Capital Corporation
Skipping useless range: Bluebay Asset Management
Skipping useless range: C.V. Starr & Company
Skipping useless range: Global Securities Advisors LLC
Skipping useless range: Chilton Investment Company, LLC
Skipping useless range: Insight Catastrophe Solutions
Skipping useless range: Noco A LP
Skipping useless range: Highbridge Capital Management, LLC
Skipping useless range: Horizon Media, Inc
Skipping useless range: Moruda.com
Skipping useless range: Highbridge Capital Management, LLC
Skipping useless range: Pinnacle Asset Management
Skipping useless range: Ascend Venture Group
Skipping useless range: LFG America Inc
Skipping useless range: Venda, Inc
Skipping useless range: Integral Development Corporation
Skipping useless range: FIRST IN SERVICE TRAVEL
Skipping useless range: Equinox Capital Management, Inc
Skipping useless range: WINGED KEEL GROUP INC
Skipping useless range: Gerson Lehrman Group
Skipping useless range: Mont D\\\'or Of America Llc
Skipping useless range: Beyond Media Ventures
Skipping useless range: GLG Inc
Skipping useless range: The Conference Board, Inc
Skipping useless range: Cline Davis & Mann
Skipping useless range: SwissRe CMM / Swiss Re
Skipping useless range: Dune Capital Management
Skipping useless range: Mason Capital
Skipping useless range: Computer Services Group
Skipping useless range: Klondike Technology Corp
Skipping useless range: panther express nyc
Skipping useless range: Janover Rubinroit, LLC
Skipping useless range: Longacre Fund Management
Skipping useless range: Regent Business Centers
Skipping useless range: Sandler ONeill
Skipping useless range: Liability Solutions
Skipping useless range: SMBC Capital Markets
Skipping useless range: Insound
Skipping useless range: NYC & Company
Skipping useless range: Regent Business Centers
Skipping useless range: KAPLOW COMMUNICATIONS
Skipping useless range: M.D. Sass Investors Services, Inc
Skipping useless range: Axiom Investment Advisors
Skipping useless range: Transera Communications
Skipping useless range: Shepard Schwartz & Harris
Skipping useless range: Hamilton Williams LLC/Velocity4x
Skipping useless range: Lehman Brothers
Skipping useless range: Bee Sky Consulting
Skipping useless range: The Claro Group, LLC / CDW
Skipping useless range: Henning & Carey
Skipping useless range: Digital Criterion Consultants
Skipping useless range: Marketing Werks
Skipping useless range: Comcast Commercial Services
Skipping useless range: Deutsche Boerse Systems, Inc
Skipping useless range: National Australia Bank of New York
Skipping useless range: The Claro Group, LLC / CDW
Skipping useless range: Chicago Systems Group
Skipping useless range: PointBridge Solutions LLC
Skipping useless range: Cornerstone Trading, LLC
Skipping useless range: Sterling Technologies
Skipping useless range: Wolverine Trading - Chicago
Skipping useless range: CashNet USA
Skipping useless range: KC-CO II, LLC
Skipping useless range: Citigate Sard Verbinnen
Skipping useless range: David Gomez & Associates
Skipping useless range: Peak 6 Investments
Skipping useless range: Fox River Financial Resources
Skipping useless range: Applied Finance Group
Skipping useless range: Lehman Brothers
Skipping useless range: MediaTec Publishing, Inc
Skipping useless range: Slack Barshinger
Skipping useless range: RTI International / Research Triangle Institute
Skipping useless range: Doculabs
Skipping useless range: GKST
Skipping useless range: Keno Kozie Associates
Skipping useless range: PointBridge Solutions LLC
Skipping useless range: MicroTek Computer Labs
Skipping useless range: Greenline Financial Technologies, Inc
Skipping useless range: Hamilton Williams LLC/Velocity4x
Skipping useless range: Right Management Consultants
Skipping useless range: MEB Options
Skipping useless range: Heidrick & Struggles Intl., Inc
Skipping useless range: CashNet USA
Skipping useless range: Jump Trading, LLC
Skipping useless range: CAAM-AI
Skipping useless range: The ROC Group
Skipping useless range: Backstop Solutions Group, LLC
Skipping useless range: FPL Advisory Group
Skipping useless range: Dillon Kane Group
Skipping useless range: William Harris Investors, Inc
Skipping useless range: Segall, Bryant & Hamill
Skipping useless range: Aegis Media Americas
Skipping useless range: ZS Associates
Skipping useless range: National Marine Manufacturers Assoc
Skipping useless range: Amata LLC
Skipping useless range: ShowingTime
Skipping useless range: LocalLaunch, Inc
Skipping useless range: LocalLaunch, Inc
Skipping useless range: Alphametrix Investment Advisors
Skipping useless range: Hudson Highland Group
Skipping useless range: Diamond Management & Technology Consultants, Inc
Skipping useless range: American Association of Individual Investors
Skipping useless range: American Association of Individual Investors
Skipping useless range: Dotomi Inc
Skipping useless range: Cochran Caronia Waller
Skipping useless range: HUN RESEARCH
Skipping useless range: Acquity Group
Skipping useless range: William Harris Investors, Inc
Skipping useless range: Emerging Solutions, LLC
Skipping useless range: CashNet USA
Skipping useless range: Duff & Phelps
Skipping useless range: CALLAN ASSOCIATES
Skipping useless range: Diamond Management & Technology Consultants, Inc
Skipping useless range: Sterling Technologies
Skipping useless range: Canopy Financial
Skipping useless range: Synergy Workplaces
Skipping useless range: Harbor Capital Advisors, Inc
Skipping useless range: Pentwater Capital
Skipping useless range: Socrates Media
Skipping useless range: OnDeckTech, LLC
Skipping useless range: OnDeckTech, LLC
Skipping useless range: EasyCO LLC
Skipping useless range: Cyberfuse Technologies
Skipping useless range: RMA
Skipping useless range: RIGHT MANAGEMENT CONSULTANTS
Skipping useless range: The News Journal
Skipping useless range: PUBLIC/PRIVATE VENTURES
Skipping useless range: Comcast Interactive Media
Skipping useless range: IOP Publishing
Skipping useless range: Coalition of National Cancer Corp
Skipping useless range: RIGHT MANAGEMENT CONSULTANTS
Skipping useless range: Quatro Systems Inc
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Aberdeen Asset Management Inc
Skipping useless range: DRUCKER & SCACCETTI, PC
Skipping useless range: Treatment Research Institute
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Comcast Interactive Media
Skipping useless range: Comcast Interactive Media
Skipping useless range: Mpower Trading Systems
Skipping useless range: IT Solutions Consulting, Inc
Skipping useless range: IT Solutions Consulting, Inc
Skipping useless range: Comcast Interactive Media
Skipping useless range: Nihill & Riedley, P.C
Skipping useless range: Wagner-Weber Associates, Inc
Skipping useless range: Comcast Interactive Media
Skipping useless range: NYSE - SF
Skipping useless range: Citigate Sard Verbinnen
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: OCC Strategy Consultants
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: APLogics Technology, Inc
Skipping useless range: Warburg Pincus LLC
Skipping useless range: OCC Strategy Consultants
Skipping useless range: Liquid Realty Partners
Skipping useless range: PAUL CAPITAL PARTNERS, LLC
Skipping useless range: Wal-Mart.com USA, LLC
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Les Concierges Inc
Skipping useless range: Park Hill Group
Skipping useless range: Callan Associates
Skipping useless range: LOOMIS GROUP INC
Skipping useless range: MicroTek Computer Labs
Skipping useless range: LOOMIS GROUP INC
Skipping useless range: Research Now
Skipping useless range: LSI LOGIC CORP
Skipping useless range: Park Hill Group
Skipping useless range: PAUL CAPITAL PARTNERS, LLC
Skipping useless range: Astreya Partners
Skipping useless range: Ironwood Capital Management
Skipping useless range: Smaug, Inc
Skipping useless range: Knight Ridder Inc
Skipping useless range: M2 Trade, LLC
Skipping useless range: Knight Ridder Inc
Skipping useless range: Nth Air Inc
Skipping useless range: AnchorFree Inc
Skipping useless range: AnchorFree Inc
Skipping useless range: Bartle Bogle & Hegarty LLC
Skipping useless range: Market Connections
Skipping useless range: Business Wire
Skipping useless range: GALLUP ORGANIZATION
Skipping useless range: CIBC Mellon Trust Company and CIBC Mellon Global Securities Company
Skipping useless range: Freedom International Brokerage Co
Skipping useless range: St. Clair Interactive Communications
Skipping useless range: Cundari
Skipping useless range: StatPro Canada Inc
Skipping useless range: The Hive Strategic Marketing Limited
Skipping useless range: Millenium Research
Skipping useless range: Klick Communications Inc
Skipping useless range: Northern Securities Inc
Skipping useless range: Freedom International Brokerage Co
Skipping useless range: Alliance Computer Systems Inc
Skipping useless range: Pareto Corporation Inc
Skipping useless range: Frontline Technologies
Skipping useless range: Interactive Executive Offices Corp
Skipping useless range: Interactive Offices Worldwid
Skipping useless range: Bluecat Networks Inc
Skipping useless range: Insurance Institute of Canada
Skipping useless range: Elehost Web Design Inc
Skipping useless range: Interactive Executive Office
Skipping useless range: Interactive Executive-not this
Skipping useless range: LifeSize Communications
Skipping useless range: Interactive Offices Worldwide
Skipping useless range: Coventree Capital Group Inc
Skipping useless range: National Bank Financial
Skipping useless range: Lusight Research
Skipping useless range: Research House Inc
Skipping useless range: Lusight Research
Skipping useless range: Arius Research Inc
Skipping useless range: Matson Driscoll & Damico Ltd
Skipping useless range: The Professional Centre
Skipping useless range: Ontario Institute of the Purchasing Management Association of Canaca/OIPMAC
Skipping useless range: Bluecat Networks Inc
Skipping useless range: Epsilon
Skipping useless range: Sigma Global Solutions Inc
Skipping useless range: Cundari
Skipping useless range: Bee Sky Consulting
Skipping useless range: Prescient
Skipping useless range: Prescient
Skipping useless range: Hudson Highland Group
Skipping useless range: National Quality Forum
Skipping useless range: DIRECT SELLING ASSOCIATION
Skipping useless range: Jamieson Laboratories Ltd
Skipping useless range: Cline Davis & Mann
Skipping useless range: GALLUP ORGANIZATION
Skipping useless range: UCSF- Dept of the Epidemiology and Biostatistics
Skipping useless range: Cyberfuse Technologies
Skipping useless range: CHARLES SCHWAB
Skipping useless range: Magna International Inc
Skipping useless range: Tormanco Management Limited Partnership Inc
Skipping useless range: Ampere Media, LLC
Skipping useless range: MBC Research
Skipping useless range: L.C. Williams and Associates
Skipping useless range: International Research Resource
Skipping useless range: Citigate Sard Verbinnen
Skipping useless range: India Equity Partners Management Subsidiary LLC
Skipping useless range: Administrative Management Group
Skipping useless range: AboveNet Inc
Skipping useless range: Comentum Corporation
Skipping useless range: Metro Offices
Skipping useless range: Becker-Parkin Dental Supply Company, Inc
Skipping useless range: Aset International Services, Inc
Skipping useless range: APLogics Technology, Inc
Skipping useless range: Critical Path, Inc / Supernews / Super News
Skipping useless range: M2 Trade, LLC
Skipping useless range: Revolution Health
Skipping useless range: Delrey Technologies, LLC
Skipping useless range: LOOMIS GROUP INC
Skipping useless range: Hoppmann Communications
Skipping useless range: Buchanan Associates
Skipping useless range: Kaplan, Inc
Skipping useless range: Development Corp. for Israel
Skipping useless range: Pride Marketing
Skipping useless range: AMERICAN INSTITUTES FOR RESEARCH
Skipping useless range: Slack Barshinger
Skipping useless range: Citigate Sard Verbinnen
Skipping useless range: RIGHT MANAGEMENT CONSULTANTS
Skipping useless range: McKinsey & Company, Inc
Skipping useless range: Metro Offices
Skipping useless range: CB Richard Ellis-N.E. Partners, LP
Skipping useless range: Doculabs
Skipping useless range: REH Property, LLC
Skipping useless range: Interactive Executive Offices Corp
Skipping useless range: Interactive Offices Worldwid
Skipping useless range: Bates White
Skipping useless range: Integrated Marketing Tech
Skipping useless range: ACT/Forex
Skipping useless range: BitGravity, LLC
Skipping useless range: AboveNet Inc
Skipping useless range: LogicaCMG
Skipping useless range: Frontline Technologies
Skipping useless range: Wal-Mart.com USA, LLC
Skipping useless range: Interactive Executive Office-not this
Skipping useless range: Integrated Marketing Tech
Skipping useless range: Right Managemnt Consultants
Skipping useless range: RIGHT MANAGEMENT CONSULTANTS / MANCHESTER INC
Skipping useless range: Interactive Executive Offices Corp
Skipping useless range: LA Inc. Convention & Visitors Bureau
Skipping useless range: Seattle Internet Bank / Seattleinternetbank
Skipping useless range: Shiny Feet dba Joe Edwards Consultants
Skipping useless range: A. Eicoff & Company
Skipping useless range: Constant Contact
Skipping useless range: Bartle Bogle & Hegarty LLC
Skipping useless range: Materials Research Society
Skipping useless range: Interactive Executive-not this
Skipping useless range: Hitachi Consulting
Skipping useless range: CB Richard Ellis - DC
Skipping useless range: OCC Strategy Consultants
Skipping useless range: 1UP.com
Skipping useless range: Right Management Consultants
Skipping useless range: Right Management Consultant
Skipping useless range: Power Concepts
Skipping useless range: Magna International Inc
Skipping useless range: Mitsubishi International Corporation
Skipping useless range: Metro Offices
Skipping useless range: RIGHT MANAGEMENT
Skipping useless range: Research Management Group
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: St. Vincents Medical
Skipping useless range: Grant Prideco -
Skipping useless range: Revenue Analytics
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Tulip Systems / Tulix Systems
Skipping useless range: Chilton Investment Company, LLC
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: KPMG
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Insurance Institute of Canada
Skipping useless range: Regus Business Centers
Skipping useless range: Delrey Technologies, LLC
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: ZS ASSOCIATES Inc
Skipping useless range: Peterborough Utilities Inc
Skipping useless range: AboveNet Inc
Skipping useless range: Callan Associates
Skipping useless range: Meridian Knowledge Solutions KSI
Skipping useless range: Interactive Offices
Skipping useless range: TeleQ Network Solutions/WolfPack, INC
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Notable Solutions
Skipping useless range: ROBINSON Leher & MONTGOMERY
Skipping useless range: panther express nyc
Skipping useless range: Research House Inc
Skipping useless range: ZS Associates
Skipping useless range: 1UP.com
Skipping useless range: AboveNet Inc
Skipping useless range: VIRTELA COMMUNICATIONS INC - CO - HQ
Skipping useless range: Lion Resources Inc
Skipping useless range: Everest Technologies
Skipping useless range: Everest Technologies
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: International Research Resource
Skipping useless range: mail.5gwireless.com
Skipping useless range: CASSADAY & CO
Skipping useless range: ROI service
Skipping useless range: National Association of Corporate Directors
Skipping useless range: Monticello Capital
Skipping useless range: DIRECT SELLING ASSOCIATION
Skipping useless range: Stonebridge Associates
Skipping useless range: American Gas Association
Skipping useless range: Fors Marsh Group
Skipping useless range: The Charles Stark Draper Laboratory
Skipping useless range: Swiss Broadcasting Corp
Skipping useless range: Economic Analysis Group
Skipping useless range: ORC Worldwide - DC
Skipping useless range: AACC (American Association of Clinical Chemists)
Skipping useless range: Incando Corporation
Skipping useless range: CW Capital - DC OFFICE
Skipping useless range: Bates White
Skipping useless range: Torray Corporation
Skipping useless range: RTI International / Research Triangle Institute
Skipping useless range: Caravan Communications LLC dba WorldStreamTV
Skipping useless range: Cassidy & Pinkard Mgmt Office
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Cassidy & Pinkard Mgmt Office
Skipping useless range: Laminar Direct Capital GP Inc
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: Knight Ridder/Tribune Information Services
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: Metro Offices
Skipping useless range: C-Span
Skipping useless range: American Land Title Assoc
Skipping useless range: Congruent Media Llc
Skipping useless range: AMERICAN INSTITUTES FOR RESEARCH
Skipping useless range: MATHEMATICA POLICY RESEARCH INC
Skipping useless range: Notable Solutions
Skipping useless range: URBAN LAND INSTITUTE
Skipping useless range: Metro Offices
Skipping useless range: Metro Offices / Tysons Business Center, Inc
Skipping useless range: Metro Offices
Skipping useless range: Radvision Inc
Skipping useless range: The Charles Stark Draper Laboratory
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: Grant Prideco -
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Digital Interactive Streams Inc
Skipping useless range: Meridian Knowledge Solutions KSI
Skipping useless range: Black Ink L.L.C. / Carlan LLC
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Pannell Kerr Forster of Texas P.C
Skipping useless range: RICHARD WAYNE & ROBERTS
Skipping useless range: Gainer Donnelly & Desroches, LLP
Skipping useless range: Rafferty Capital Markets
Skipping useless range: CHEETAH MAIL - Experian
Skipping useless range: Seattle Internet Bank / Seattleinternetbank
Skipping useless range: Thinktron Corporation
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Onkea Interactive Ltd
Skipping useless range: AboveNet Inc
Skipping useless range: Harris Interactive, Inc
Skipping useless range: Arch Insurance Group NY
Skipping useless range: Bee Sky Consulting
Skipping useless range: Urban Retail Properties Co
Skipping useless range: Imtech Graphics Inc
Skipping useless range: SCN Research (Steve Neighorn)
Skipping useless range: Unleaded Software Inc
Skipping useless range: Interactive Corporation
Skipping useless range: Lion Resources Inc
Skipping useless range: Management Science Associates
Skipping useless range: Gwynn Group
Skipping useless range: Integrated Marketing Tech
Skipping useless range: Integrated Marketing Tech
Skipping useless range: 247 Commercial Marketing / e Passporte
Skipping useless range: SyncTree LLC
Skipping useless range: Kremsa Design
Skipping useless range: 247 Commercial Marketing / e Passporte
Skipping useless range: Stream Energy
Skipping useless range: Sarang Community Church
Skipping useless range: Shiny Feet dba Joe Edwards Consultants
Skipping useless range: Krypt Technologies - VPLS, Inc
Skipping useless range: Hudson Highland Group
Skipping useless range: Printroom.com
Skipping useless range: Comentum Corporation
Skipping useless range: Bartle Bogle & Hegarty LLC
Skipping useless range: Imtech Graphics Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: SCN Research (Steve Neighorn)
Skipping useless range: Lion Resources Inc
Skipping useless range: SYLMARK INC
Skipping useless range: Knight Ridder Inc
Skipping useless range: Magna International Inc
Skipping useless range: MacLaren McCann Canada
Skipping useless range: Alpha Red Inc
Skipping useless range: LocalLaunch, Inc
Skipping useless range: Young Presidents Organization
Skipping useless range: Management Science Associates
Skipping useless range: Zacks Investment Research, Inc
Skipping useless range: Chicago Board Options Exchange
Skipping useless range: Slack Barshinger
Skipping useless range: CAC / Columbus Avenue Consulting / CDW
Skipping useless range: The Associated Press
Skipping useless range: Kaplan, Inc
Skipping useless range: Plante Moran
Skipping useless range: Inform.com
Skipping useless range: Batanga.com
Skipping useless range: MicroTek Computer Labs
Skipping useless range: GA Family Connection
Skipping useless range: EDELMAN PUBLIC RELATIONS
Skipping useless range: Batanga.com
Skipping useless range: Loyalty Works Inc
Skipping useless range: Tulip Systems / Tulix Systems
Skipping useless range: Synergy Workplaces
Skipping useless range: Synergy Workplaces Inc,
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: Laureate Education Inc
Skipping useless range: Regent Business Centers
Skipping useless range: 1UP.com
Skipping useless range: 1UP.com
Skipping useless range: You Gov America dba Polimetrix, Inc
Skipping useless range: Arius Research Inc
Skipping useless range: AboveNet Inc
Skipping useless range: Les Concierges Inc
Skipping useless range: Columbia Research Group
Skipping useless range: Juma Technology Corp
Skipping useless range: Binyan Realty L. P
Skipping useless range: Hudson Highland Group
Skipping useless range: SCHLUMBERGER
Skipping useless range: DF King & Co
Skipping useless range: Kennedy Health Systems
Skipping useless range: RIGHT MANAGEMENT CONSULTANTS
Skipping useless range: Nth Air Inc
Skipping useless range: Point 5 Media
Skipping useless range: NAW Service Corp
Skipping useless range: American Gas Association
Skipping useless range: U.S. News & World Report
Skipping useless range: Paladyne Systems
Skipping useless range: Canyon Partners LLC
Skipping useless range: Smashits.com
Skipping useless range: Just Buy Media
Skipping useless range: Shiny Feet dba Joe Edwards Consultants
Skipping useless range: CHEETAH MAIL - Experian
Skipping useless range: Maxxiss Communications
Skipping useless range: SCHLUMBERGER
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: panther express nyc
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Galaxyvisions Inc
Skipping useless range: RHODES ASSOCIATES
Skipping useless range: Preferred Offices
Skipping useless range: AboveNet Inc
Skipping useless range: MonoGen
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: KPMG
Skipping useless range: Austin Travis County MHMR
Skipping useless range: Seacross Global Advisors
Skipping useless range: IKON Office Solutions (Legal Document Services)
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: EveryNetwork, Inc. - ENI Hosting LLC
Skipping useless range: Initiative for a Competitive Inner City
Skipping useless range: Summer Street Research Partners
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: The Charles Stark Draper Laboratory
Skipping useless range: Blue Cross Blue Shield Of Delaware a Care First Co
Skipping useless range: Preferred Offices
Skipping useless range: Henninger Media Services - DC
Skipping useless range: Forum of Regional Associations of Grantmakers
Skipping useless range: Utilities Telecom Council
Skipping useless range: Global Security Association
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: AboveNet Inc
Skipping useless range: VIRTELA COMMUNICATIONS INC - CO - HQ
Skipping useless range: panther express nyc
Skipping useless range: Symbio Solutions
Skipping useless range: Panther Express NYC
Skipping useless range: AboveNet Inc
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: AboveNet Inc
Skipping useless range: The Carlisle Group INC
Skipping useless range: Alpha Red Inc
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: NAW Service Corp
Skipping useless range: The New Republic
Skipping useless range: VIRTELA COMMUNICATIONS INC - CO - HQ
Skipping useless range: U.S. News & World Report
Skipping useless range: iEntry, Inc
Skipping useless range: Velocita Wireless
Skipping useless range: Alpha Red Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: St. Vincents Medical
Skipping useless range: New York State Energy Research and Development Authority
Skipping useless range: PRIME OFFICE Centers
Skipping useless range: Bevmax Office Centers
Skipping useless range: Worldwide Business Centres
Skipping useless range: Regent Business Centers
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: panther express nyc
Skipping useless range: Lippincott Mercer
Skipping useless range: Ramius Capital Group
Skipping useless range: Andrew Garrett Inc
Skipping useless range: Titan Worldwide
Skipping useless range: Emcor Securities Inc
Skipping useless range: Latina Media Ventures,
Skipping useless range: Regent Business Centers
Skipping useless range: Linden Advisors
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Sky IT Group
Skipping useless range: AboveNet Inc
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: HACHETTE FILIPACCHI MEDIA
Skipping useless range: MPRM Public Relations
Skipping useless range: Creative Channel Services
Skipping useless range: Shiny Feet dba Joe Edwards Consultants
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: AboveNet Inc
Skipping useless range: Alpha Red Inc
Skipping useless range: Thinktron Corporation
Skipping useless range: Thinktron Corporation
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: CashNet USA
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: First Analysis Securities Corp
Skipping useless range: Brandtrust
Skipping useless range: ShopperTrak
Skipping useless range: MediaTec Publishing, Inc
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: DirectSpace Networks
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: Regent Business Centers
Skipping useless range: Blue Cross Blue Shield Of Delaware a Care First Co
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Hudson Highland Group
Skipping useless range: Hudson Highland Group
Skipping useless range: Hudson Highland Group
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: IDD Aerospace - PO: 0773877
Skipping useless range: Regent Business Centers
Skipping useless range: Smaug, Inc
Skipping useless range: LSI LOGIC CORP
Skipping useless range: Ironwood Capital Management
Skipping useless range: Warburg Pincus LLC
Skipping useless range: panther express nyc
Skipping useless range: 1UP.com
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: U.S. News & World Report
Skipping useless range: 1UP.com
Skipping useless range: AnchorFree Inc
Skipping useless range: AnchorFree Inc
Skipping useless range: Printroom.com
Skipping useless range: AnchorFree Inc
Skipping useless range: You Gov America dba Polimetrix, Inc
Skipping useless range: Mother Jones Magazine
Skipping useless range: The Rostie Group
Skipping useless range: StatPro Canada Inc
Skipping useless range: SunGard Reference Data Solutions
Skipping useless range: Bluecat Networks Inc
Skipping useless range: StatPro Canada Inc
Skipping useless range: Frontline Technologies
Skipping useless range: Business Wire
Skipping useless range: Marketrack, Inc
Skipping useless range: St. Clair Interactive Communications
Skipping useless range: Galaxyvisions Inc
Skipping useless range: Iconix Brand Group, Inc
Skipping useless range: Hudson Highland Group
Skipping useless range: KPMG, LLP
Skipping useless range: Wilson RMS
Skipping useless range: KPMG, LLP
Skipping useless range: ICrossing Inc
Skipping useless range: Beyond Media Ventures
Skipping useless range: Marketing Werks
Skipping useless range: BDO SEIDMAN, LLP
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Institute of Electrical and electronics Engineers IEEE USA
Skipping useless range: Henninger Media Services - DC
Skipping useless range: Preferred Offices
Skipping useless range: Utilities Telecom Council
Skipping useless range: Global Security Association
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Regus Business Center - Financial District
Skipping useless range: Worldwide Business Centres
Skipping useless range: Lippincott Mercer
Skipping useless range: Regent Business Centers
Skipping useless range: Linden Advisors
Skipping useless range: Latina Media Ventures,
Skipping useless range: RHODES ASSOCIATES
Skipping useless range: OCC Strategy Consultants
Skipping useless range: Sky IT Group
Skipping useless range: KPMG, LLP
Skipping useless range: Wilson RMS
Skipping useless range: KPMG, LLP
Skipping useless range: St. Vincents Medical
Skipping useless range: Fox River Financial Resources
Skipping useless range: ACTForex Inc
Skipping useless range: PRIME OFFICE Centers
Skipping useless range: Hudson Highland Group
Skipping useless range: Amata LLC
Skipping useless range: Sterling Technologies
Skipping useless range: Applied Finance Group
Skipping useless range: Merrill Corporation
Skipping useless range: ShopperTrak
Skipping useless range: Cornerstone Trading, LLC
Skipping useless range: LocalLaunch, Inc
Skipping useless range: TARGET MEDIA PARTNERS
Skipping useless range: StatPro Canada Inc
Skipping useless range: Audio Visual Services Group, Inc
Skipping useless range: CHEETAH MAIL - Experian
Skipping useless range: Russell Reynolds & Associates
Skipping useless range: Cb Richard Ellis (bos)
Skipping useless range: The Rohatyn Group
Skipping useless range: Natexis Banques Popularis
Skipping useless range: Conducive Corporation
Skipping useless range: Best Checks
Skipping useless range: Superior Distributing Inc
Skipping useless range: Jaros Baum & Bolles
Skipping useless range: FARMER BAKER BARRIOS ARCHITECTS INC
Skipping useless range: Jaros Baum & Bolles
Skipping useless range: AGF Management Ltd
Skipping useless range: Jesup & Lamont Securities
Skipping useless range: CustomInk, LLC
Skipping useless range: Orion Securities
Skipping useless range: ISP Technologies, Inc
Skipping useless range: Drake Management
Skipping useless range: ABN Amro Sage Corporation
Skipping useless range: Side.net
Skipping useless range: Fusion Technology
Skipping useless range: Crump Insurance Svc
Skipping useless range: Midwest Generation EME, LLC
Skipping useless range: Parthenon Capital
Skipping useless range: Sargent and Lundy
Skipping useless range: Southeastern University Research (SURA)
Skipping useless range: Comprehensive Health Services
Skipping useless range: Edelman Public Relations
Skipping useless range: Systematix, Inc
Skipping useless range: Clarke Bardes Consulting
Skipping useless range: Message Labs
Skipping useless range: National Research Group
Skipping useless range: TechTV
Skipping useless range: Depository Trust & Clearing, Co
Skipping useless range: The Galleon Group
Skipping useless range: Sify Limited
Skipping useless range: Hamilton Hydro Services Inc
Skipping useless range: CrossPoint Engineering
Skipping useless range: Cushman & Wakefield, Inc
Skipping useless range: JH Snyder Co
Skipping useless range: Current Analysis Inc
Skipping useless range: Fastrak Systems
Skipping useless range: St. Michael
Skipping useless range: SCR Concepts inc
Skipping useless range: Gerson Lehrman Group
Skipping useless range: Parlano
Skipping useless range: Onkea Interactive Ltd
Skipping useless range: REFCO
Skipping useless range: Spectrum Human Resource Services
Skipping useless range: Agora Insurance Financial Solutions
Skipping useless range: Benchmark Capital
Skipping useless range: GA Family Connection
Skipping useless range: Sci-Vest Canadian Holdings Inc
Skipping useless range: Lighthouse Communications
Skipping useless range: Deloitte & Touche LLP
Skipping useless range: Fortress Investment Group
Skipping useless range: Tomaras Investments Inc
Skipping useless range: Mount Sinai Hospital
Skipping useless range: MicroTek Computer Labs
Skipping useless range: Boston Stock Exchange
Skipping useless range: Hospital for Sick Children
Skipping useless range: Wolverine Trading
Skipping useless range: Strategic Research Institute
Skipping useless range: Rushmore Financial
Skipping useless range: Reinvestment Fund
Skipping useless range: Sona Networks Inc
Skipping useless range: Mirror Image Internet
Skipping useless range: ABN Amro Sage Corporation
Skipping useless range: Corporate Financial Services
Skipping useless range: Bank of Nova Scotia
Skipping useless range: Sterling National Bank
Skipping useless range: Wall Street Networks
Skipping useless range: CB Richard Investors
Skipping useless range: Pentagon 2000 Software, Inc
Skipping useless range: Impact Innovations
Skipping useless range: Kaplan, Inc
Skipping useless range: Marketing Werks
Skipping useless range: Edelman Public Relations
Skipping useless range: Sylmark Inc
Skipping useless range: Silver Gate Bank
Skipping useless range: Intralinks Inc
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: American Jewish Joint Distribution Committe, Inc
Skipping useless range: Dyax Corp
Skipping useless range: CureMD
Skipping useless range: ABN Amro Sage Corporation
Skipping useless range: MAN Financial
Skipping useless range: Merit Network, Inc
Skipping useless range: Aspen Research Group Ltd
Skipping useless range: Mathematica Policy Research Inc
Skipping useless range: Best Checks
Skipping useless range: ZS Associates Inc
Skipping useless range: Mstream
Skipping useless range: Publicis
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Vision Lab
Skipping useless range: Marquest Investment Counsel Inc
Skipping useless range: New York Mortgage Company
Skipping useless range: Propane Education & Research Council
Skipping useless range: Ohio Employee Health Partnership
Skipping useless range: Atlantic Physicians Assoc
Skipping useless range: CCC Financial
Skipping useless range: Lyons Lavey Nickel Swift, Inc
Skipping useless range: AMERICAN PUBLIC HEALTH ASSOCIATION
Skipping useless range: Caixa Geral De Depositos
Skipping useless range: Sylmark Incorporated
Skipping useless range: Crown Financial Group
Skipping useless range: Mizuho Corporate Bank, Ltd
Skipping useless range: Fullmesh Networks / Witopia
Skipping useless range: Alps Financial Services, Inc
Skipping useless range: Cb Richard Ellis (bos)
Skipping useless range: Stat Radiology Medical Corp
Skipping useless range: Bronx Overall Economic Development Corporation
Skipping useless range: Goodman & Company Investment Counsel Ltd
Skipping useless range: Meredith Corporation
Skipping useless range: King Financial Services
Skipping useless range: Deloitte & Touche LLP
Skipping useless range: Merrill Lynch
Skipping useless range: Sungard Futures Systems
Skipping useless range: Keynote Systems
Skipping useless range: La Branche Financial Services
Skipping useless range: Los Angeles Metropolitan Medical Center
Skipping useless range: American Institutes for Research
Skipping useless range: Preferred Trade Inc
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Bank of NY - Alternative Investment Services
Skipping useless range: Innovative Medical Education / Lyons Lavey Nickel Swift, Inc
Skipping useless range: Cb Richard Ellis (bos)
Skipping useless range: One Signature Financial Corporation
Skipping useless range: Brattleworks Inc
Skipping useless range: Brookfield Properties Ltd
Skipping useless range: Brookfield Properties Ltd
Skipping useless range: Depfa Bank PLC, New York Agency
Skipping useless range: Miller Publishing Group
Skipping useless range: CUOL, Inc
Skipping useless range: Caixa Geral De Depositos
Skipping useless range: Clinical Associates PA
Skipping useless range: Metro Offices
Skipping useless range: Disys / Digital Intelligence Systems Corp
Skipping useless range: Agora Insurance Financial Solutions
Skipping useless range: UBS-Prime Brokerage Services
Skipping useless range: Medical Diagnostic Exchange (MDX) Corp
Skipping useless range: Interactive Corporation
Skipping useless range: Cb Richard Ellis (bos)
Skipping useless range: Blackrock
Skipping useless range: Amerada Hess Corporation
Skipping useless range: Ty Lin International
Skipping useless range: SURDNA FOUNDATION INC
Skipping useless range: EDISON ELECTRIC INSTITUTE
Skipping useless range: SFERS Real Estate Corp. (Arioso)
Skipping useless range: Lehman Brothers / Soft Dollar / Essex Investment Management
Skipping useless range: Enunciate Corporation
Skipping useless range: SFC Greystone Inv. LP
Skipping useless range: Old Mutual Financial Network
Skipping useless range: Laboratory Inst of Mdsg Inc
Skipping useless range: Critical Path, Inc / Supernews / Super News
Skipping useless range: Cold Spring Harbor Laboratory
Skipping useless range: Coldwell Banker Residential Brokerage
Skipping useless range: Riverside Partners, LLC
Skipping useless range: ZS Associates Inc
Skipping useless range: Orion Consulting
Skipping useless range: Russell Reynolds & Associates
Skipping useless range: Unleaded Software Inc
Skipping useless range: Roamer Maritime Corporation
Skipping useless range: Wolverine Trading
Skipping useless range: Merrill Lynch
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Alpha Red Inc
Skipping useless range: Millenium Research Group
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Mitsubishi International Corporation
Skipping useless range: National Global Financial Services
Skipping useless range: Committee for Economic Development
Skipping useless range: R.W. Beck, Inc
Skipping useless range: CSD Architects
Skipping useless range: Safra National Bank of New York
Skipping useless range: Advantage Futures LLC
Skipping useless range: AboveNet Inc
Skipping useless range: VIRTELA COMMUNICATIONS INC - CO - HQ
Skipping useless range: Bancroft Telecom
Skipping useless range: AboveNet Inc
Skipping useless range: KKR Financial
Skipping useless range: Golden Gate Software2
Skipping useless range: Golden Gate Software2
Skipping useless range: National Bank Financial
Skipping useless range: Prolexic Technologies
Skipping useless range: Cedar Document Technologies, Inc
Skipping useless range: Critical Path, Inc / Supernews / Super News
Skipping useless range: Hines
Skipping useless range: Critical Path, Inc / Supernews / Super News
Skipping useless range: Metro Offices
Skipping useless range: Telecom Ottawa
Skipping useless range: Alpha Red Inc
Skipping useless range: O/E Learning, Inc. / OE Learning
Skipping useless range: MANAGEMENT ANALYSIS
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: TIS R&D
Skipping useless range: National Association of Corporate Directors
Skipping useless range: Batanga.com
Skipping useless range: Citigate Sard Verbinnen
Skipping useless range: IMMUNE TOLERANCE NETWORK
Skipping useless range: Alpha Red Inc
Skipping useless range: AMERICAN INSTITUTES FOR RESEARCH
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Hospital for Sick Children
Skipping useless range: Brookfield Properties Ltd
Skipping useless range: Baker Real Estate Corporation
Skipping useless range: Fimat Canada Inc
Skipping useless range: Fastrak Systems
Skipping useless range: Mount Sinai Hospital
Skipping useless range: Russell Reynolds & Associates
Skipping useless range: One Signature Financial Corporation
Skipping useless range: Carlin Financial Group
Skipping useless range: Gerson Lehrman Group
Skipping useless range: Prudential Douglas Elliman
Skipping useless range: Alpha Red Inc
Skipping useless range: NAW Service Corp
Skipping useless range: Alpha Red Inc
Skipping useless range: BISYS, Inc. - Banking solutions - Open Solutions
Skipping useless range: Impact Innovations
Skipping useless range: Fischer Financial Solutions
Skipping useless range: ABN Amro Sage Corporation
Skipping useless range: NDC Corporation
Skipping useless range: NDC Corporation
Skipping useless range: The Main Office Management
Skipping useless range: Tribal DDB
Skipping useless range: Tribal DDB
Skipping useless range: Wolverine Trading
Skipping useless range: Ty Lin International
Skipping useless range: Immune Tolerance Network
Skipping useless range: CSD Architects
Skipping useless range: Golden Gate Software2
Skipping useless range: Financial Content
Skipping useless range: KKR Financial
Skipping useless range: Immune Tolerance Network
Skipping useless range: ABN AMRO International
Skipping useless range: SIMMONS & COMPANY INTERNATIONAL
Skipping useless range: KPMG
Skipping useless range: Denham Capital Management
Skipping useless range: Peregrine Financial Group
Skipping useless range: Federal Home Loan Bank of Chicago
Skipping useless range: MicroTek Computer Labs
Skipping useless range: Marketing Werks
Skipping useless range: Richards & Tierney
Skipping useless range: Zacks Investment Research, Inc
Skipping useless range: Superfund Asset Management
Skipping useless range: GKST
Skipping useless range: MAN Financial
Skipping useless range: Merrill Lynch
Skipping useless range: Sungard Futures Systems
Skipping useless range: Superfund Asset Management
Skipping useless range: Cb Richard Ellis (bos)
Skipping useless range: Federal Home Loan Bank of Chicago
Skipping useless range: Wolverine Trading
Skipping useless range: Advantage Futures LLC
Skipping useless range: Advantage Futures, LLC
Skipping useless range: Advantage Futures, LLC
Skipping useless range: BISYS, Inc. - Banking solutions - Open Solutions
Skipping useless range: MicroTek Computer Labs
Skipping useless range: Cedar Document Technologies, Inc
Skipping useless range: Batanga.com
Skipping useless range: Brookfield Financial Properties
Skipping useless range: Cushman & Wakefield, Inc
Skipping useless range: Alps Financial Services, Inc
Skipping useless range: Unleaded Software Inc
Skipping useless range: First Associates Investments Inc
Skipping useless range: MacLaren McCann Canada
Skipping useless range: United Trust Fund
Skipping useless range: Quigo Technologies Inc
Skipping useless range: Interactive Corporation
Skipping useless range: Quigo Technologies Inc
Skipping useless range: PAETEC Communications, Inc
Skipping useless range: Nortelnetworks
Skipping useless range: Nortel_Networks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: IVM-Stuttgart GmbH
Skipping useless range: hongkong.perfect-privacy.com
Skipping useless range: Thermo Lab System
Skipping useless range: Servcorp SmartOffice
Skipping useless range: Iwane Laboratories (Thailand) Ltd
Skipping useless range: TDK White Queen Co., Ltd
Skipping useless range: Iwane Laboratories (Thailand)
Skipping useless range: TDK White Queen Co., Ltd
Skipping useless range: Shizuoka Industrial Research Institute of Shizuoka
Skipping useless range: ADVANTEST CORPORATION
Skipping useless range: Software Development
Skipping useless range: MITSUI CHEMICALS,INC
Skipping useless range: MITSUI CHEMICALS,INC
Skipping useless range: Research Institute of Economy, Trade and Industry,
Skipping useless range: Urumqi Commercial Bank ,Urumqi,Xinjiang
Skipping useless range: Agricultral Bank Sales Department ,Urumqi,Xinjian
Skipping useless range: Bazhou People's Hospital,Xinjiang
Skipping useless range: Economic and Technology Development Region Admini
Skipping useless range: Kuitun Jiayou Commercial Bank ,Xinjiang
Skipping useless range: Changji Economic Information Center ,Xinjiang
Skipping useless range: Changji Economic Information Network Administrati
Skipping useless range: Shihezi University Subsidiary Hospital,Xinjiang
Skipping useless range: Economic Technology Administration Institute,Shih
Skipping useless range: Xinjiang West Resource Economic Business Network
Skipping useless range: Drilling Technology Research Institute of Kelamay
Skipping useless range: Kashi Economic Information Center,Xinjiang
Skipping useless range: Aletai Economic Information Center,Xinjiang
Skipping useless range: XI'AN HAI XING SAN SHAN SOFTWARE NET
Skipping useless range: Xi'an Songyi Software Empolder Company
Skipping useless range: XI'AN COMMERCE BANK NET
Skipping useless range: General Credit Finance & Development Ltd - Hankow
Skipping useless range: Aspen Research Group
Skipping useless range: Cerebus Software Ltd
Skipping useless range: Regus UK Arlington Bus Park
Skipping useless range: Regus UK Lombard Street
Skipping useless range: FTIP002734323 Lidl NI Gmbh
Skipping useless range: Financial Computers Thames Fruit Ltd
Skipping useless range: City Software Consultants Ltd
Skipping useless range: FTIP002742472 Atradius Credit Insurance
Skipping useless range: LittelFuse Ltd
Skipping useless range: FTIP002746203 Prestige Underwriting
Skipping useless range: Regus UK (Liverpool Street)
Skipping useless range: ROK PROPERTY SOLUTIONS
Skipping useless range: FTIP000125109 Aspen Research Group
Skipping useless range: Capricorn Software Ltd
Skipping useless range: Financial Computers Genesis
Skipping useless range: FTIP002925196 Valpak Ltd
Skipping useless range: Software of Excellence (uk) Ltd
Skipping useless range: TRIDENT INTERNATIONAL LTD
Skipping useless range: Trident Manufacturing Ltd
Skipping useless range: Midland Software Limited
Skipping useless range: Piazza Financial Services
Skipping useless range: FTIP002735894 Gmac UK Finance Plc
Skipping useless range: Regus UK Glasgow
Skipping useless range: Merrill Lynch Plc (2)
Skipping useless range: British Airways Travel Shops Ltd
Skipping useless range: Merrill Lynch Plc
Skipping useless range: Merrill Lynch Plc (3)
Skipping useless range: Mayfield Curzon Associates
Skipping useless range: Flare Software Systems Ltd
Skipping useless range: M & C Saatchi Ltd
Skipping useless range: FTIP002759258 HCL Technologies Europe
Skipping useless range: Fuji Copian Ltd
Skipping useless range: E-Comm Research Ltd
Skipping useless range: nhs-labs
Skipping useless range: Centre For Economics&Business Research
Skipping useless range: Laerdal Medical Ltd
Skipping useless range: FTIP002736914 The Hospital Group
Skipping useless range: Regus UK Luton
Skipping useless range: Midland Software Limited
Merged range ' Mitsui Sumitomo Reinsurance', with range 'Mitsui Sumitomo Reinsurance'
Skipping useless range: Skyweb Technologies Ltd
Skipping useless range: Sanyo Hungary Ltd
Skipping useless range: Insight Manag.Consultants Baltic , SIA
Skipping useless range: City Hospitals Sunderland NHS Trust (RLN)
Skipping useless range: Stockport Out of Hours Primary Care Medical Servi
Skipping useless range: Ardlarich Medical Practice
Skipping useless range: Scunthorpe Pathology Lab
Skipping useless range: Louth County Hospital Pathology Lab
Skipping useless range: Lincoln Pathology Lab
Skipping useless range: Boston Pathology Lab
Skipping useless range: Northern Lincolnshire and Goole Hospitals
Skipping useless range: NW London Hospitals NHS Trust
Skipping useless range: Dovecot Family Health Clinic
Skipping useless range: Teddington Memorial Hospital NHS Trust
Skipping useless range: JONES AN,PORTER BROOK MEDICAL CTRE,
Skipping useless range: North Cumbria Acute Hospitals NHS Trust
Skipping useless range: Surrey Sussex Health Authority,
Skipping useless range: Mid Essex Hospital Services NHS Trust
Skipping useless range: Royal United Hospital Bath NHS Trust
Skipping useless range: Hampshire Shared Financial Services
Skipping useless range: Derby Medical Services (connected to NHSnet)
Skipping useless range: Mid-Essex Hospital Service NHS Trust
Skipping useless range: Royal National Orthopaedic Hospital NHS Trust (RA
Skipping useless range: West Middlesex University Hospital NHS Trust (RFW
Skipping useless range: Essex Ambulance Trust
Skipping useless range: Ipswich Hospital NHS Trust
Skipping useless range: Guide Post Medical Centre (Social Services)
Skipping useless range: Blyth Community Hospital (Social Services)
Skipping useless range: Blyth Station Medical Practice (Social Services)
Skipping useless range: Hexham Hospital (Social Services),
Skipping useless range: Cottage Hospital (Social Services),
Skipping useless range: Mid-Essex Hospitals NHS Trust
Skipping useless range: Essex Strategic Health Authority
Skipping useless range: Mid Essex Hospital Acute Services Trust
Skipping useless range: BT-Ignite
Skipping useless range: INM Frankfurt
Skipping useless range: Matsushita Electronic
Skipping useless range: BT Ignite Dialin
Skipping useless range: Vossloh-Schwabe Matsushita
Skipping useless range: BASF IT Services GmbH
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Vossloh-Schwabe Matsushita
Skipping useless range: INC-RESEARCH
Skipping useless range: CLINIQUE ST CHARLES
Skipping useless range: CLINIQUE SAINT BRICE
Skipping useless range: CENTRE IMAGERIE MEDICALE
Skipping useless range: HOPITAL LOCAL DE LUSIGNAN
Skipping useless range: CLINIQUE DU PARISIS
Skipping useless range: HOPITAL LOCAL DE JOSSELIN
Skipping useless range: UNIVERSAL MEDICA
Skipping useless range: HOPITAL LOCAL DE MURAT
Skipping useless range: ABS BOLTON MEDICAL
Skipping useless range: CLINIQUE MEDICO CHIRUR CREIL
Skipping useless range: DJS MEDICAL
Skipping useless range: SERVICE MEDICAL INTERP REGION REIMS
Skipping useless range: Clinique Saint Hilaire
Skipping useless range: HOPITAL SAINTE BLANDINE
Skipping useless range: HOPITAL LOCAL ST HONORE
Skipping useless range: POLYCLINIQUE DE NAVARRE
Skipping useless range: CENTRE MEDICAL COULON
Skipping useless range: MAISON HOSPITALIERE ST CHARLES
Skipping useless range: CENTRE HOSPITALIER DE FIGEAC
Skipping useless range: HOPITAL LOCAL DE MONTMIRAIL
Skipping useless range: CONTROLE MEDICAL CIAGE
Skipping useless range: HOPITAL DU PARC SARREGUEMINES
Skipping useless range: HOPITAL LOCAL DU CHEYLARD
Skipping useless range: HOPITAL DE MARVEJOLS
Skipping useless range: VAROISE MEDICALE
Skipping useless range: CLINIQUE DU CEDRE
Skipping useless range: CENTRE HOSPITALIER ST JOSEPH S
Skipping useless range: HOPITAL CHARCOT
Skipping useless range: HOPITAL DES VANS
Skipping useless range: CLINIQUE MISTRAL
Skipping useless range: DOMI HOSPITAL NUTRITION
Skipping useless range: HOPITAL LOCAL
Skipping useless range: HOPITAL D ALIGRE DE BOURBON LANCY
Skipping useless range: SYND INTERHOSPITALIER BLANCHISSERIE
Skipping useless range: CLINIQUE PAUL BERT SA
Skipping useless range: AVENIR PERFORMANCE EUROPEENNE MEDICAL
Skipping useless range: HOPITAL HOSPICE DE CHATEAU CHINON VILL
Skipping useless range: INSTITUT POLYCLINIQUE DE CANNES
Skipping useless range: CENTRE MEDICAL COULON
Skipping useless range: CENTRE MEDICAL COULON
Skipping useless range: AGENCE REGIONALE DE L HOSPITAL
Skipping useless range: HOPITAL ST REMY PROVENCE
Skipping useless range: CENTRE HOSPITALIER DE BRIOUDE
Skipping useless range: HOPITAL SAINT ELOI SOSPEL
Skipping useless range: CLINIQUE LA PARISIERE
Skipping useless range: CLINIQUE CLAUDE BERNARD
Skipping useless range: HNE MEDICAL
Skipping useless range: HNE MEDICAL
Skipping useless range: HNE MEDICAL SA
Skipping useless range: HNE MEDICAL SA
Skipping useless range: HNE MEDICAL
Skipping useless range: POLYCLINIQUE VILLENEUVE ST GEORGES
Skipping useless range: POLYCLINIQUE DES PORTES DU JURA
Skipping useless range: CLINIQUE NOUVELLE DU FOREZ
Skipping useless range: VAROISE MEDICALE
Skipping useless range: CENTRE HOSPITALIER SPECIALISE
Skipping useless range: CENTRE HOSPITALIER SPECIALISE
Skipping useless range: CENTRE HOSPITALIER SPECIALISE
Skipping useless range: AHS CENTRE MEDICAL GALLOUEDEC
Skipping useless range: CLINIQUE DE LA ROSERAIE
Skipping useless range: HOPITAL ST ANDRE
Skipping useless range: HOPITAL ST ANDRE
Skipping useless range: TSE EXPRESS MEDICAL
Skipping useless range: UBI BENE
Skipping useless range: *** MEDICALE TRAVAIL EPERNAY ET REGION
Skipping useless range: *** MEDICALE TRAVAIL EPERNAY ET REGION
Skipping useless range: CLINIQUE ROND POINT CHAMPS ELYSEES
Skipping useless range: SOC CLINIQUE HOFFMANN
Skipping useless range: HOPITAL AMBROISE PARE
Skipping useless range: HNE MEDICAL
Skipping useless range: HOPITAL FOCH
Skipping useless range: VENTANA MEDICAL SYSTEMS
Skipping useless range: CLINIQUE DE LA MARCHE
Skipping useless range: AHS CENTRE MEDICAL GALLOUEDEC
Skipping useless range: AHS CENTRE MEDICAL GALLOUEDEC
Skipping useless range: POLYCLINIQUE DES URSULINES
Skipping useless range: TSE EXPRESS MEDICAL
Skipping useless range: CLINIQUE LAGARDELLE
Skipping useless range: CENTRE HOSPITALIER AUXERRE
Skipping useless range: SOC NOUVELLE CLINIQUE ST CHARLES
Skipping useless range: HOPITAL MAISON DE RETRAITE
Skipping useless range: POLYCLINIQUE KENNEDY
Skipping useless range: HENNO MEDICAL
Skipping useless range: CENTRE HOSPITALIER J.P CASSABEL
Skipping useless range: CLINIQUE SAINT MICHEL
Skipping useless range: CLINIQUE SAINT VINCENT DE PAUL
Skipping useless range: CENTRE HOSPITALIER
Skipping useless range: OEUVRE HOSPITALIERE FRANCAISE ORDRE
Skipping useless range: CLINIQUE BELLEDONNE
Skipping useless range: CLINIQUE GENERALE
Skipping useless range: CTRE HOSPITALIER INTERCOM CORTE TAT
Skipping useless range: SUPRA MEDICAL
Skipping useless range: CLINIQUE SAINT JEAN
Skipping useless range: CLINIQUE DU DOCTEUR BECQ
Skipping useless range: CENTRE HOSPITALIER DE GUINGAMP
Skipping useless range: HOPITAL LOCAL DE LIMOUX
Skipping useless range: POLYCLINIQUE DU VAL DE LOIRE
Skipping useless range: CENTRE HOSPITALIER SOINS LONGUE DUR
Skipping useless range: CLINIQUE DU PARC
Skipping useless range: GROUPE AZUR CLINIQUE BELVEDERE
Skipping useless range: L-OEUVRE DE L-HOSPITALITE FAMILIALE
Skipping useless range: CLINIQUE SAINT LAURENT
Skipping useless range: CLINIQUE LES LAURIERS
Skipping useless range: LAB-ANA-BIO-MEDICALE SALVINI
Skipping useless range: SOCIETE DES CLINIQUES ARDENNAISES
Skipping useless range: HOPITAL LOCAL DE GEX
Skipping useless range: MEDICAL 29
Skipping useless range: SCM BIOLOGIE MEDICALE ESPACE FORBIN
Skipping useless range: POLYCLINIQUE DU LAC D ENGHIEN
Skipping useless range: HOPITAL LOCAL ST PIERRE D-OLERON
Skipping useless range: HOPITAL DE CHATEAUROUX
Skipping useless range: HOPITAL DE CHATEAUROUX
Skipping useless range: HOPITAL HOSPICE D HIRSON
Skipping useless range: HOPITAL LOCAL LE LUDE
Skipping useless range: CLINIQUE GENERALE
Skipping useless range: CENTRE HOSPITALIER GENERAL
Skipping useless range: HOPITAL SAINT-THOMAS DE VILLENEUVE
Skipping useless range: Clinique des Vallees
Skipping useless range: Clinique Villa des Roses
Skipping useless range: HOPITAL PRIVE DE L OUEST PRIVE
Skipping useless range: CLINIQUE DES CEDRES
Skipping useless range: HOPITAL DUBOIS MEYNARDIE
Skipping useless range: POLYCLINIQUE DU PARC
Skipping useless range: CENTRE HOSPITALIER DE GRASSE
Skipping useless range: HOPITAL LOCAL DU CROISIC
Skipping useless range: CENTRE HOSPITALIER DU BELVERE
Skipping useless range: HOPITAL LOCAL D YVETOT
Skipping useless range: CLINIQUE DE L EUROPE
Skipping useless range: CENTRE HOSPITALIER POISSY SAINT GERMAIN
Skipping useless range: CENTRE HOSPITALIER DE MELUN
Skipping useless range: CENTRE HOSPITALIER D ALBI
Skipping useless range: CENTRE HOSPITALLIER DU PAYS D AIX
Skipping useless range: HOPITAL SAINT MICHEL
Skipping useless range: CENTRE HOSPITALIER ALPHONSE GUERIN
Skipping useless range: Title Research Ltd
Skipping useless range: MDL Research
Skipping useless range: MDL Research
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Strategic Research
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: National Federation of Retail Newsagents
Skipping useless range: National Federation of Retail Newsagents
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Fujikura (Europe) Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Sanders Polyfilms Ltd
Skipping useless range: Barton Financial Planning
Skipping useless range: Barton Financial Planning
Skipping useless range: FIBI Bank UK Plc
Skipping useless range: Mission Aviation Fellowship
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: FIBI Bank UK Plc
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Mission Aviation Fellowship
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Ela Medical
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Grunwick Processing Laboratories Ltd
Skipping useless range: Grunwick Processing Laboratories Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Benenden Hospital
Skipping useless range: Incisive Media
Skipping useless range: 20 Twenty Mortgages Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Arthritis Research Services
Skipping useless range: Arthritis Research Services
Skipping useless range: Chairman Software Ltd
Skipping useless range: Chairman Software Ltd
Skipping useless range: Investment Property Databank Ltd
Skipping useless range: Investment Property Databank Ltd
Skipping useless range: Title Research Ltd
Skipping useless range: BDO Stoy Hayward software solutions Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: JMJ Laboratories
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: M.M.R. Food & Drink Research Worldwide
Skipping useless range: M.M.R. Food & Drink Research Worldwide
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Westinghouse Brakes
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Flexible Medical Packaging
Skipping useless range: Alban Communications Ltd
Skipping useless range: Archival Record Management
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Investment Property Databank Ltd
Skipping useless range: Lombard Street Research
Skipping useless range: Global Debt Recovery Ltd
Skipping useless range: Fujikura (Europe) Ltd
Skipping useless range: Fox IT Ltd
Skipping useless range: Phoenix Medical
Skipping useless range: Dromon Maritime Agency Limited
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Metropolis AV & FX Ltd
Skipping useless range: Metropolis AV & FX Ltd
Skipping useless range: Summit Medical Ltd
Skipping useless range: B & G Software Consultancy Ltd
Skipping useless range: Corin Medical
Skipping useless range: Corin Medical
Skipping useless range: Medical Solutions
Skipping useless range: Amber Independent Financial Services
Skipping useless range: M.M.R. Food & Drink Research Worldwide
Skipping useless range: Corin Medical
Skipping useless range: Misys International Banking
Skipping useless range: Fisher Clinical Services
Skipping useless range: Daiwa Europe Bank
Skipping useless range: Incisive Media
Skipping useless range: Sanwa / Tokai
Skipping useless range: Limehouse Media Group
Skipping useless range: Wickham Laboratories Ltd
Skipping useless range: Motion Media Technology Ltd
Skipping useless range: Oxford Research Agency
Skipping useless range: Hanley Economic Building Society
Skipping useless range: Borgwarner Turbo Systems
Skipping useless range: BT Ignite Dial-In
Skipping useless range: BT Ignite GmbH
Skipping useless range: BASF IT Services GmbH
Skipping useless range: Erich-Schmidt-Verlag GmbH & Co
Skipping useless range: BT Ignite TechnicalServices Dus
Skipping useless range: BT Ignite IP VPN
Skipping useless range: nicos Consult GmbH
Skipping useless range: Postbank in Hamburg
Skipping useless range: BT Ignite TechnicalServices Hamburg
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Minolta Deutschland GmbH
Skipping useless range: Minolta GmbH, Langenhagen is a subsidary of Minol
Skipping useless range: BT Ignite TechnicalServices Hannover
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Eurocolor Photofinishing GmbH & Co. KG
Skipping useless range: BT Ignite TechnicalServices Koeln
Skipping useless range: BT Ignite IP VPN
Skipping useless range: BT Ignite TechnicalServices Leipzig
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Hitachi Europe GmbH
Skipping useless range: Kassenzahnaerztliche Vereinigung Bayerns, Germany
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Vision Lab
Skipping useless range: Kassen Zahnaerztliche Vereinigung Bayern
Skipping useless range: BT Ignite
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Georg Thieme Verlag, Stuttgart
Skipping useless range: BT Ignite IP VPN
Skipping useless range: BT Ignite IP VPN
Skipping useless range: BT Ignite IP VPN
Skipping useless range: BASF IT Services GmbH
Skipping useless range: BT Ignite IP VPN
Skipping useless range: BT Ignite
Skipping useless range: BT Ignite Dial-In
Skipping useless range: BT-Ignite Dial-In
Skipping useless range: Fujicolor Central Europe Photofinishing GmbH & Co. KG
Skipping useless range: IGNITE Content Hosting
Skipping useless range: BT Ignite IP VPN
Skipping useless range: Keynote, Web Servers
Skipping useless range: Fujicolor Central Europe Photofinishing GmbH & Co. KG
Skipping useless range: BT Ignite Germany IGITOS Internet Connection
Skipping useless range: Matsushita Electronic Work Europe AG
Skipping useless range: AKO-Werke Gmbh & Co. KG
Skipping useless range: Tele Peep Telemedia GmbH
Skipping useless range: VDI Verlag GmbH
Skipping useless range: Espotting Scandinavia AB - Internet Access
Skipping useless range: Lab Gruppen AB - Internet Access
Skipping useless range: New Hair Clinic i Lund AB - Internet Access
Skipping useless range: MTG Radio AB - Colocation
Skipping useless range: MTG Radio AB - Colocation
Skipping useless range: Network of Bank for International Settle
Skipping useless range: Network of Winchester Hospital Authority
Skipping useless range: Network of Deutsche Krankenhaus Gezells
Skipping useless range: Network of Amadeus Southern Africa
Skipping useless range: Network of AMADEUS SOUTHERN AFRICA
Skipping useless range: Network of South African Medical Associat
Skipping useless range: Network of ACT LABORATORIES
Skipping useless range: Network of AT&T GNS Finland
Skipping useless range: PROTRAC
Skipping useless range: ECONOMIC CLASS CLIENTS
Skipping useless range: Wickham Laboratories Ltd
Skipping useless range: Royal Hospital for Neuro - Disability
Skipping useless range: Fisher Clinical Services
Skipping useless range: Phoenix Medical
Skipping useless range: Fisher Clinical Services
Skipping useless range: Dexia Banque Internationale a Luxembourg
Skipping useless range: Ross Bank
Skipping useless range: Oxford Research Agency
Skipping useless range: Cendant Relocation UK Ltd
Skipping useless range: Convergent Systems
Skipping useless range: Medical Solutions
Skipping useless range: Camelot
Skipping useless range: Borgwarner Turbo Systems
Skipping useless range: tokai Ltd
Skipping useless range: Medical Dental Defence Union
Skipping useless range: Benenden Hospital
Skipping useless range: Centre de Serveuillance Maritime ā Tanger
Skipping useless range: Banque Wafa Salaf ā Casa
Skipping useless range: STE Colgate & Palmolive ā Casa
Skipping useless range: Alcatel Telecom ā Casa
Skipping useless range: AGENCE MARITIME Larsy maroc ā Casa
Skipping useless range: STE INTERBANK ā Casa
Skipping useless range: Regus Maroc ā Casa
Skipping useless range: Centre Hospitalier Universitaire ā Rabat
Skipping useless range: cyber club basfaou ahmed ā Fes
Skipping useless range: Maritime Ship Services SARL ā Casa
Skipping useless range: ste Marocaine de Navigation Maritime
Skipping useless range: Anglo Irish Bank
Skipping useless range: EDUCATION FINANCE PARTNERS
Skipping useless range: ANIMATION TECHNOLOGIES, INC - CHICAGO
Skipping useless range: ROSDEV HOSPITALITY SECAUCUS
Skipping useless range: GARMAR INDUSTRIES INC
Skipping useless range: EASTMAN KODAK COMPANY-KO
Skipping useless range: UNIVISION CRIMSON GROUP INC. - SYRACUSE, NY
Skipping useless range: UNIVERSAL CIT GROUP
Skipping useless range: REMAX PROPERTIES I
Skipping useless range: REMAX LEGEND - WAYNE
Skipping useless range: RE/MAX PREMIER
Skipping useless range: RE MAX PREMIER
Skipping useless range: REMAX CLASSIC GROUP
Skipping useless range: NATIONAL STORES INC
Skipping useless range: REMAX LEADING EDGE
Skipping useless range: CMTM, INC
Skipping useless range: REGENT BUSINESS CENTERS
Skipping useless range: NATIONAL EDUCATIONAL MUSIC CO
Skipping useless range: CB RICHARDS ELLIS/ ASSOCIATED COMMUNICATION
Skipping useless range: NEW LINE COMMUNICATIONS
Skipping useless range: NATIONAL STORES INC
Skipping useless range: REMAX PROPERTY SHOPPE INCORPORATED
Skipping useless range: PAETEC Communications
Skipping useless range: DFB SALES
Skipping useless range: REMAX ALLSTARS
Skipping useless range: RE MAX REALTY CENTRE INC
Skipping useless range: MOONBEAM EQUIPMENT
Skipping useless range: EPS OF VERMONT - BUFFALO DIVISION
Skipping useless range: REMAX FIRST
Skipping useless range: OPPENHEIMER FUNDS, INC
Skipping useless range: REMAX FIRST-ALLENS CREEK
Skipping useless range: EDUCATION FINANCE COUNCIL/MCGRAW
Skipping useless range: REMAX DESTINY
Skipping useless range: CROWN PLAZA TUDOR
Skipping useless range: MPRM LLC
Skipping useless range: AMAZON PROCESSING LLC
Skipping useless range: SCHOOL LOANS CORPORATION
Skipping useless range: REMAX LEGEND
Skipping useless range: UNIVERSAL EVENT MANAGEMENT LLC
Skipping useless range: REMAX LEGEND - WAYNE
Skipping useless range: MORISON COGEN, LLP
Skipping useless range: MSI CONSULTING
Skipping useless range: CINERGY HEALTH - 100 BISCAYNE BLVD
Skipping useless range: Hudson Institute
Skipping useless range: SCHOOL CONSTRUCTION COMPLIANCE
Skipping useless range: Proprietary Media
Skipping useless range: AD PERSONNEL INC
Skipping useless range: ROCKSTAR DESIGN
Skipping useless range: Practice Performance
Skipping useless range: Medical Specialties Managers, Inc
Skipping useless range: Ericsson Inc
Skipping useless range: PTC International
Skipping useless range: American Medical Capital
Skipping useless range: campaign finance
Skipping useless range: BLOOMBERG & POMPAS MEDICAL GROUP
Skipping useless range: Viewpoint Engineering
Skipping useless range: Qwest Cybercenters
Skipping useless range: Qwest Managed Firewall
Skipping useless range: Island Automated Medical Services
Skipping useless range: One Source Marketing
Skipping useless range: Atlas Technologies
Skipping useless range: Remax of Atlanta
Skipping useless range: Medical Office Software
Skipping useless range: Eton Systems
Skipping useless range: STARWOOD HOTELS & RESORTS SHERATON PORTSMOUTH
Skipping useless range: SAUDI ARABIAN AIRLINES
Skipping useless range: EPS - DELTA EDUCATION
Skipping useless range: STARWOOD HOTELS & RESORTS SHERATON PORTSMOUT
Skipping useless range: REMAX - Taylor Realty
Skipping useless range: U of Illinois Employees Credit Union
Skipping useless range: Cgiware
Skipping useless range: Blue Room Media
Skipping useless range: Internet Dynamics
Skipping useless range: IRC Company
Skipping useless range: Tank Sports
Skipping useless range: Bold New World
Skipping useless range: Daiger Sydes Gustafson LLC
Skipping useless range: Treefrog Interactive Inc
Skipping useless range: Brady & Burgess Mgt. Corp
Skipping useless range: Datablocks Network Media, LLP
Skipping useless range: Kobayashi Technology Inc
Skipping useless range: Group Tel
Skipping useless range: Womens Medical Associates
Skipping useless range: ARLINGTON CLINICAL
Skipping useless range: Olympic Medical Service PS
Skipping useless range: Arlington Clinical
Skipping useless range: NORTHERN NEVADA MEDICAL CENTER
Skipping useless range: Womens Medical Associates
Skipping useless range: Shephard Fox Clinic
Skipping useless range: Medical Coaches
Skipping useless range: Campbell Clinic
Skipping useless range: MDX Medical Management
Skipping useless range: CT Medical Group/Hamden Internal Medicine
Skipping useless range: Bergen Medical Alliance
Skipping useless range: Midwestchester Medical Care
Skipping useless range: Soundview Medical
Skipping useless range: Pediatric Consoltants - Stuart
Skipping useless range: Mental Health Assoc #3 (Covad)
Skipping useless range: Medical Staffing Network (Springfield, VA) (Revised)
Skipping useless range: Medical Staffing Network (San Antonio, TX) (Revised)
Skipping useless range: Medical Staffing Network (Louisville, KY) (Revised)
Skipping useless range: Medical Staffing Network (Memphis, TN) (Revised)
Skipping useless range: Medical Staffing Network (Tampa, FL) (Revised)
Skipping useless range: Medical Staffing Network (Clearwater, FL) (Revised)
Skipping useless range: Specialized Medical Devices
Skipping useless range: Specialized Medical Devices #2
Skipping useless range: Whole Health Chiropractic Clinic
Skipping useless range: Majors Medical Supply (Covad)
Skipping useless range: HUTCHINSON MEDICAL-CT
Skipping useless range: New York State Nurses Association/Latham
Skipping useless range: College Financial Service
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications Customer
Skipping useless range: Mechanical Dynamics and Analysis
Skipping useless range: Remax Premier Albany
Skipping useless range: Policy Research Associates
Skipping useless range: Premier Medical Management
Skipping useless range: ST REGIS MONARCH BEACH RESORT-STARWOOD
Skipping useless range: TRILOGY FINANCIAL SERVICES, INC
Skipping useless range: PaeTec Communications
Skipping useless range: TRIDENT PRECISION MANUFACTURING
Skipping useless range: Research Financial
Skipping useless range: OLEAN MEDICAL GROUP, LLP
Skipping useless range: PaeTec Communications
Skipping useless range: Testwell Labs
Skipping useless range: PaeTec Communications
Skipping useless range: Kent Financial
Skipping useless range: Systematic Financial
Skipping useless range: Clarfeld Financial Advisors
Skipping useless range: PaeTec Communications
Skipping useless range: Unified Federal Credit Union
Skipping useless range: Mortgage Financial - Norwell
Skipping useless range: Mortgage Financial Tewksbury
Skipping useless range: RESEARCH ROAD, LLC
Skipping useless range: Summit Federal Credit Union
Skipping useless range: PaeTec Communications
Skipping useless range: AM&M Financial
Skipping useless range: First Financial Trust
Skipping useless range: CVS Pharmacy Corporate Offices
Skipping useless range: ReMax Omega
Skipping useless range: PaeTec Communications
Skipping useless range: FINANCIAL INSTITUTIONS INC
Skipping useless range: Advantage Federal Credit Union
Skipping useless range: PaeTec Communications
Skipping useless range: Roberts Research Labs
Skipping useless range: SELECTIVE FINANCIAL
Skipping useless range: PAETEC COMMUNICATIONS FORT LAUDERDALE OFFICE
Skipping useless range: MARTIN FEDERAL CREDIT UNION
Skipping useless range: UNITED AEROSPACE CORP
Skipping useless range: JVB FINANCIAL GROUP LLC
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: NEWTON EXECUTIVE OFFICE CENTER
Skipping useless range: SHERATON BOSTON HOTEL ( STARWOOD HOTELS & RESORTS)
Skipping useless range: PaeTec Communications
Skipping useless range: NAL RESEARCH CORPORATION
Skipping useless range: ACCESS CALL CENTER INC
Skipping useless range: PaeTec Communications
Skipping useless range: Credit Union Affiliates Of NJ
Skipping useless range: PaeTec Communications/DVN
Skipping useless range: Remax premiere Properties
Skipping useless range: SAATCHI AND SAATCHI ROWLAND
Skipping useless range: REDCOM LABORATORIES, INC
Skipping useless range: PaeTec Communications
Skipping useless range: NORTON COMMUNITY CREDIT UNION
Skipping useless range: CREST FINANCIAL CORP
Skipping useless range: PaeTec Communications
Skipping useless range: AIR CARE MEDICAL
Skipping useless range: Debt Solutions Pasadena
Skipping useless range: SWC Financial
Skipping useless range: PACIFIC PARK FINANCIAL DBA WEBHOMESAT.COM, INC
Skipping useless range: The Debt Solution (Valencia)
Skipping useless range: HOTEL ST GEORGE
Skipping useless range: TISSUELINK MEDICAL INC
Skipping useless range: BLACKSTONE MEDICAL, INC
Skipping useless range: BOSTON FINANCIAL MANAGEMENT
Skipping useless range: MORTGAGE FINANCIAL SERVICES-FRANKLIN, MA
Skipping useless range: PaeTec Communications
Skipping useless range: BREEN FINANCIAL
Skipping useless range: PaeTec Communications
Skipping useless range: mail.southeasternrealty.com
Skipping useless range: Star Medical Distributors
Skipping useless range: SEGWAY FINANCIAL, INC
Skipping useless range: Option One Home Medical-Irvine
Skipping useless range: Option One Home Medical-Corona
Skipping useless range: DYNAMIC MEDICAL SYSTEMS, INC
Skipping useless range: LaSalle Medical Group
Skipping useless range: The Debt Professionals
Skipping useless range: Madison Radiology Medical Group Inc
Skipping useless range: FAMILY CARE SPECIALIST MEDICAL GROUP
Skipping useless range: ISCS RESOURCES INC DBA ALLIED FINANCIAL SERVICE
Skipping useless range: RESEARCH PHARMACEUTICAL SRVICES
Skipping useless range: FIRST CENTURY BANK
Skipping useless range: TIGER FINANCIAL GROUP C
Skipping useless range: US FINANCIAL MANAGEMENT
Skipping useless range: Security Financial Mortgage
Skipping useless range: Heritage New York Medical Group
Skipping useless range: CROWN BANK N.A
Skipping useless range: Research Firm, The
Skipping useless range: PaeTec Communications
Skipping useless range: UNIT #1 FEDERAL CREDIT UNION/ ADVANCE 2000 R
Skipping useless range: PaeTec Communications
Skipping useless range: Chesepeake Research Review
Skipping useless range: FINANCIAL INSTRUMENT AND INVESTMENT CORPORATION
Skipping useless range: PaeTec Communications
Skipping useless range: Target Marketing
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: Research Pharmaceuticals
Skipping useless range: Seneca Data - Horsham
Skipping useless range: ADVANCED SPORTS DBA FUJI BIKES
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: HUTCHINSON MEDICAL - EPPING
Skipping useless range: First Financial Trust
Skipping useless range: ACTON RESEARCH CORP
Skipping useless range: Brookwood Financial Partners
Skipping useless range: BIO SAN Laboratories
Skipping useless range: Mortgage Financial
Skipping useless range: Mortgage Financial Tewksbury
Skipping useless range: PROGRESSIVE FINANCIAL STRATEGIES
Skipping useless range: Triangle Credit Union
Skipping useless range: Brookwood Financial Partners
Skipping useless range: PaeTec Communications
Skipping useless range: MIAA
Skipping useless range: PaeTec Communications
Skipping useless range: INNCO CORP DOUBLETREE - BOSTON
Skipping useless range: North Shore Medical Transcription
Skipping useless range: PaeTec Communications
Skipping useless range: PaeTec Communications
Skipping useless range: GREENBOOK FINANCIAL SERVICES INC
Skipping useless range: ORTHOPEDIC SURGERY MEDICAL GROUP
Skipping useless range: PaeTec Communications
Skipping useless range: Hawk Communications
Skipping useless range: SKYWAY CHEVROLET
Skipping useless range: PaeTec Communications-Backbone
Skipping useless range: Financial Interactive, LLC
Skipping useless range: Entercomm
Skipping useless range: ADF Research
Skipping useless range: Entercomm
Skipping useless range: Medical Mgmt Resources
Skipping useless range: Creative Research Systems
Skipping useless range: Impact Creative
Skipping useless range: eQuest, LLC
Skipping useless range: Nexxo Financial
Skipping useless range: American Express Travel Related Services
Skipping useless range: Chartered Alternative Investment Analyst
Skipping useless range: Entercomm
Skipping useless range: Advice Counsel Incorporated
Skipping useless range: Financial Interactive
Skipping useless range: MAJESTIC RESEARCH
Skipping useless range: APPLICATIONS ENGINEERING REARCHITECTURE AND TEST LAB-ABOVENET
Skipping useless range: APPLICATIONS ENGINEERING REARCHITECTURE AND TEST LAB-ABOVENET
Skipping useless range: DIGILABS INC
Skipping useless range: PROPHET FINANCIAL SYSTEMS
Skipping useless range: COMMUNICATION INTELLIGENCE CORP. (CIC)
Skipping useless range: WIRETAP LABS
Skipping useless range: Analytics research
Skipping useless range: Analytics research
Skipping useless range: Wal-Mart Vision
Skipping useless range: Dan Ferguson Music
Skipping useless range: Hatchers Music Center
Skipping useless range: SBC EServices Shared Web Hosting Pool
Skipping useless range: First Tennessee Bank
Skipping useless range: Handango
Skipping useless range: Navy Army Federal Credit Union
Skipping useless range: CB Richard Ellis
Skipping useless range: Berlex
Skipping useless range: Berlex.256844
Skipping useless range: Medical Wellness Center
Skipping useless range: SANDY-NASSERI
Skipping useless range: OWENS-LAND-SURVEY
Skipping useless range: Comstock Canada Ltd
Skipping useless range: Sita Inc
Skipping useless range: Playa Vista Corporate
Skipping useless range: Medical Billing and Intergration Services
Skipping useless range: Eastern Medical Publishers
Skipping useless range: Naperville Children's Clinic Monticello Dr
Skipping useless range: Naperville Children's Clinic Spalding ave
Skipping useless range: Physicians Services / PMG Medical
Skipping useless range: Madison Center and Hospital
Skipping useless range: Peterson Medical Institute-Beverly Hills (Covad)
Skipping useless range: Medical Central-Boston International (Covad)
Skipping useless range: CANCER CARE ASSOCIATES
Skipping useless range: EdServe L.L.C
Skipping useless range: Remax 100-Kipling
Skipping useless range: Remax Action
Skipping useless range: Hotels.com LP
Skipping useless range: DELOITTE and TOUCHE
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: Sutcliffe Facial Surgery and Laser Center
Skipping useless range: Metro Medical Management
Skipping useless range: Catalyst Medical Solutions
Skipping useless range: DELTA-ELEVATOR-
Skipping useless range: LAMAR-ADVERTISING
Skipping useless range: ANIMAL-MEDICAL-CLINIC
Skipping useless range: Mccormic Group
Skipping useless range: RESEARCH PLANNING & CONSULTANTS
Skipping useless range: Horizon National Bank
Skipping useless range: Citizens Bank (Chillicothe)
Skipping useless range: RR Donnelley and Sons Company
Skipping useless range: DELOITTE and TOUCHE
Skipping useless range: Keynote Systems, Inc
Skipping useless range: Keynote Systems, Inc
Skipping useless range: Medical Staffing Network
Skipping useless range: Baton Rouge Pediatric Clinic
Skipping useless range: Medical Staffing Network
Skipping useless range: GLOBAL MEDICAL INSTITUTES
Skipping useless range: music city medical supply
Skipping useless range: VIRGINIA FAMILY PHYSICIANS
Skipping useless range: costargr
Skipping useless range: costargr
Skipping useless range: costargr
Skipping useless range: costargr
Skipping useless range: tmanagem
Skipping useless range: tmanagej
Skipping useless range: tmanagec
Skipping useless range: tmanagem
Skipping useless range: DIEHL, Inc
Skipping useless range: T Manage
Skipping useless range: Marcus Corporation
Skipping useless range: The Washington Post Newspaper
Skipping useless range: costargr
Skipping useless range: ceridian
Skipping useless range: TManage, Inc
Skipping useless range: TManage, Inc
Skipping useless range: MSI Network Services LTD
Skipping useless range: TManage, Inc
Skipping useless range: warnersp
Skipping useless range: Keynotes systems
Skipping useless range: warnersp
Skipping useless range: MSI/Transaction Payment Services
Skipping useless range: TManage
Skipping useless range: FactSet Research Systems
Skipping useless range: tmanagek
Skipping useless range: NRCC
Skipping useless range: Sungard Futures System
Skipping useless range: Emerson Electric
Skipping useless range: Nortel Neworks
Skipping useless range: costar
Skipping useless range: Satyam Computer Services
Skipping useless range: Greylock
Skipping useless range: intermedia / Prudential Preferred Realty - Penn Hills
Skipping useless range: Mace Security
Skipping useless range: Getronics
Skipping useless range: ASSURED DECISIONS LLC
Skipping useless range: Battelle Memorial Institute
Skipping useless range: SYRACUSE RESEARCH CORP
Skipping useless range: NCI INFORMATION
Skipping useless range: MCG CAPITAL CORPORATION
Skipping useless range: INTERACTIVE SYSTEMS, INC
Skipping useless range: Intermedia / Southeast Milk
Skipping useless range: Reptron Electronics
Skipping useless range: fendermusicalinstrumentscorporation
Skipping useless range: TAMPA GENERAL HOSPITAL
Skipping useless range: FISERV IP
Skipping useless range: DAEWOO
Skipping useless range: AAI CORPORATION
Skipping useless range: LANDSTAR SYSTEMS
Skipping useless range: UCN Inc
Skipping useless range: ITT Industries
Skipping useless range: B/E AEROSPACE
Skipping useless range: DE HOWE MACHINE AND TOOL INC
Skipping useless range: FMC Mortgage
Skipping useless range: Emerson Electric
Skipping useless range: WELLS FARGO BANK
Skipping useless range: Micromuse
Skipping useless range: allstateinsuranceericgoodrich
Skipping useless range: Emerson Electric
Skipping useless range: EXTENDED STAY HOTELS, INC - 6011
Skipping useless range: RED HAT, INC
Skipping useless range: Wieden & Kennedy
Skipping useless range: Educational Community Credit Union
Skipping useless range: allstateinsurancejefferyleavitt
Skipping useless range: VTS-LACEY DOUBLE T1
Skipping useless range: America First Credit Union
Skipping useless range: Wave Systems Inc
Skipping useless range: Cooper Communities, Inc
Skipping useless range: Hitachi Instruments
Skipping useless range: AAI Corporation
Skipping useless range: Emerson Electric
Skipping useless range: B/E AEROSPACE
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric (Chesterfield)
Skipping useless range: Verizon Business
Skipping useless range: EXTENDED STAY HOTELS, INC - 981
Skipping useless range: Globix/InterWise
Skipping useless range: Quanta Computer USA, INC
Skipping useless range: Keynotes systems
Skipping useless range: CD Universe
Skipping useless range: The Commonwealth Fund
Skipping useless range: LOOMIS GROUP, THE
Skipping useless range: Rockefeller Group Technology Solutions, Inc
Skipping useless range: Emerson Electric
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: SADDLEBROOK RESORT INC
Skipping useless range: Intermedia / Community Affairs
Skipping useless range: Intermedia / Alpha Tile
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: NSI
Skipping useless range: PITNEY BOWES
Skipping useless range: UMG FINANCIAL
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric/ Cornerstone
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric/ Westinghouse Process Controls IL
Skipping useless range: Emerson Electric/ Westinghouse Process Controls MI
Skipping useless range: AECOM - CHICAGO DS3 INTERNET
Skipping useless range: Intermedia / Centro, Inc
Skipping useless range: Oasis Corporation
Skipping useless range: EMERSON ELECTRIC/DATASERV
Skipping useless range: Intermedia / St. Charles Boat and Motor
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric (Chesterfield)
Skipping useless range: Emerson Electric Corporation
Skipping useless range: HITACHI ELECTRONIC DEVICES
Skipping useless range: PRECYSE SOLUTIONS
Skipping useless range: IHG CORPORATE ACCTS/Candlewood Miami Airport
Skipping useless range: AAI CORPORATION/JACKSONVILLE
Skipping useless range: Emerson Electric
Skipping useless range: Syska & Hennessy Inc
Skipping useless range: KPMG
Skipping useless range: OpSource, Inc
Skipping useless range: Verizon Business
Skipping useless range: SCHAWK, INC
Skipping useless range: UNIVERSAL NETWORKS INC
Skipping useless range: UCN Inc
Skipping useless range: Intermedia / Home Loan Corporation
Skipping useless range: ALLSTATE INSURANCE/JOSE PIMENTAL
Skipping useless range: UCN Inc
Skipping useless range: Ciena Corporation
Skipping useless range: CTX MORTGAGE COMPANY
Skipping useless range: VISA/Inovant
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Intermedia / Prudential Preferred Realty - West
Skipping useless range: GREYLOCK CAPITAL ASSOCIATES
Skipping useless range: Rockefeller Group Technology Solutions, Inc
Skipping useless range: VERTIS, INC
Skipping useless range: Charles River Ventures, Inc
Skipping useless range: NFO Research
Skipping useless range: Oppenheimer Funds, I
Skipping useless range: HCL TECHNOLOGIES
Skipping useless range: HCL TECHNOLOGIES
Skipping useless range: Overnite Transportation
Skipping useless range: Emerson Electric (Chesterfield)
Skipping useless range: Emerson Electric
Skipping useless range: BUFFETS
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Ericsson
Skipping useless range: Alstom Power
Skipping useless range: Aviall Services, Inc
Skipping useless range: Enron
Skipping useless range: Gateway Investment A
Skipping useless range: Verizon Business
Skipping useless range: American Express - Plano
Skipping useless range: LAQUINTA - SITE 568 - NEW INTERNET T1
Skipping useless range: Lippincott Williams & Wilkins
Skipping useless range: Verizon Business Internal
Skipping useless range: EXTENDED STAY HOTELS, INC -409
Skipping useless range: CIENA CORPORATION
Skipping useless range: maverick
Skipping useless range: Verisign
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: ZS ASSOCIATES INC
Skipping useless range: Intermedia / Precision Printing
Skipping useless range: Banta Digital Group
Skipping useless range: Schawk
Skipping useless range: SCHAWK, INC
Skipping useless range: Medical Associates o
Skipping useless range: Compucom
Skipping useless range: Emerson Electric
Skipping useless range: Verizon Services Corp Franchise Mgt-FiOS TV
Skipping useless range: Emerson Electric
Skipping useless range: Greylock
Skipping useless range: WIEDEN & KENNEDY INC
Skipping useless range: Cavalier Broadband LLC
Skipping useless range: UCN Inc
Skipping useless range: Emptoris Inc
Skipping useless range: ALCATEL-LUCENT SALEM,NH
Skipping useless range: AMS
Skipping useless range: UCN Inc
Skipping useless range: Science & Technology Research Inc
Skipping useless range: UCN Inc
Skipping useless range: Glenborough Realty Trust INC
Skipping useless range: Deloitte Consulting
Skipping useless range: Interface Healthcare Information Systems
Skipping useless range: Ecommunications Systems (Ecomm)
Skipping useless range: Micromuse
Skipping useless range: Hilton Head Automotive BMW
Skipping useless range: EEA
Skipping useless range: UCN Inc
Skipping useless range: UCN Inc
Skipping useless range: MICROMUSE INC
Skipping useless range: Verizon Business
Skipping useless range: Sequoia Capital
Skipping useless range: IHG CORPORATE ACCTS/Candlewood Chicago
Skipping useless range: MUSIC TECH COLLEGE
Skipping useless range: FEDERAL SIGNAL CORPORATION
Skipping useless range: Intermedia / Truck Parts & Equipment
Skipping useless range: Verizon Business
Skipping useless range: PIONEER ELECTRONICS
Skipping useless range: OXYGEN MEDIA
Skipping useless range: UCN Inc
Skipping useless range: Keynote Systems
Skipping useless range: Fiserv / Users - OP
Skipping useless range: Emptoris Inc
Skipping useless range: GENTEX CORP
Skipping useless range: FENDER MUSICAL INSTRUMENTS
Skipping useless range: UCN Inc
Skipping useless range: UCN Inc
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: SSA GLOBAL TECHNOLOGIES INC
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: RED HAT, INC
Skipping useless range: Micromuse
Skipping useless range: Intermedia / OST International
Skipping useless range: FISERV
Skipping useless range: INFORMATION SYSTEMS LABORATORIES INC
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Redpoint Ventures
Skipping useless range: Emerson Electric
Skipping useless range: Copper Mountain
Skipping useless range: UCN Inc
Skipping useless range: Blue Cross Blue Shield of Nebraska
Skipping useless range: Cottonwood Financial
Skipping useless range: Avtec Systems, Inc
Skipping useless range: Atlantic Credit & Finance
Skipping useless range: PROCTER & GAMBLE CORP
Skipping useless range: Fannie Mae Foundation
Skipping useless range: Verisign-OC3 INET-Mass Mkts--Broadrun
Skipping useless range: RED HAT , INC
Skipping useless range: Emerson Electric
Skipping useless range: REMAX HORIZONS/ALLEGIANCE
Skipping useless range: RED HAT , INC
Skipping useless range: EMERSON ELECTRIC - EGS(ECM-Plant)
Skipping useless range: siemense
Skipping useless range: UCN Inc
Skipping useless range: Foxconn Corporation
Skipping useless range: Metavante Corporation
Skipping useless range: Emerson Electric
Skipping useless range: Nielsen.Media.Research
Skipping useless range: Eagle Group Internat
Skipping useless range: Media Logix MDC
Skipping useless range: Aids Healthcare
Skipping useless range: SUNGARD IWORKS LLC (FORM
Skipping useless range: COSTAR GROUP INC
Skipping useless range: Verizon Business
Skipping useless range: Acer Technology
Skipping useless range: Charles River Ventures
Skipping useless range: Verisign
Skipping useless range: REGUS BUSINESS CENTER
Skipping useless range: WASHINGTON MUTUAL
Skipping useless range: B/E AEROSPACE
Skipping useless range: STARWOOD HOTELS AND RESORTS
Skipping useless range: Emerson Electric
Skipping useless range: Flir Systems, Inc
Skipping useless range: INFOSPACE
Skipping useless range: Goldman Sachs
Skipping useless range: Mirror Image Internet/equinix
Skipping useless range: Intermedia / Ceiling Systems
Skipping useless range: SAMSUNG ELECTRONICS AMERICA
Skipping useless range: STARWOOD HOTELS AND RESORTS
Skipping useless range: Intermedia / Hardox Corporation
Skipping useless range: Emerson Electric Corporation
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: ERICSSON LM
Skipping useless range: Image America
Skipping useless range: MATTHEWS INT
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Emerson Electric
Skipping useless range: Docent Inc
Skipping useless range: GOREMOTE INTERNET COMMUNICATIONS/MERRILL LYNCH
Skipping useless range: IHG CORPORATE ACCTS/Candlewood Charlotte Coliseum
Skipping useless range: Education Finance Resources
Skipping useless range: UCN Inc
Skipping useless range: Verisign
Skipping useless range: Banta Corp
Skipping useless range: gsicommerce.com
Skipping useless range: allstateinsurancekenitatang
Skipping useless range: National Institute of Aerospace / AIAA
Skipping useless range: NVA Netsearch
Skipping useless range: Emerson Electric
Skipping useless range: REMAX ADVANCED
Skipping useless range: Fiserv / Users - OP
Skipping useless range: Milestone Group
Skipping useless range: AboveNet
Skipping useless range: OPEN SOLUTIONS
Skipping useless range: UCN Inc
Skipping useless range: FISERV
Skipping useless range: CB RICHARD ELLIS, INC
Skipping useless range: Intermedia / Paradise Development
Skipping useless range: FUJIFILM GRAPHIC SYSTEMS U.S.A., INC
Skipping useless range: FLIR Systems Inc
Skipping useless range: The Virginian Pilot
Skipping useless range: UNITED AUTOMOBILE INTERNET
Skipping useless range: UCN Inc
Skipping useless range: WITNESS SYSTEMS
Skipping useless range: PALMER CHIROPRACTIC UNIVERSITY / COLLEGE / HOSPITAL
Skipping useless range: SCHAWK INC
Skipping useless range: Intermedia / Pero Sales
Skipping useless range: UCN Inc
Skipping useless range: Verizon Business
Skipping useless range: American Light
Skipping useless range: Emerson Electric
Skipping useless range: Broken Arrow Electric
Skipping useless range: GLOBAL EXCHANGE SERVICES, INC
Skipping useless range: LANDSTAR SYSTEMS
Skipping useless range: millward
Skipping useless range: Alstom Power
Skipping useless range: PHASE 2 SOLUTIONS
Skipping useless range: INVENSYS
Skipping useless range: FIRST DATA CORPORATION
Skipping useless range: PIONEER ELECTRONICS
Skipping useless range: AES CORP
Skipping useless range: OPEN SOLUTIONS
Skipping useless range: Orange Coast Title
Skipping useless range: Worldcom Lab - Hilliard
Skipping useless range: Worldcom, Hilliard Lab
Skipping useless range: Emerson Electric
Skipping useless range: Blue Cross Blue Shield of Nebraska
Skipping useless range: Emerson Electric
Skipping useless range: Intermedia / Insurance Consultants of Pittsburgh
Skipping useless range: Intermedia / Prudential Preferred Realty-Pittsburgh
Skipping useless range: Vertis/LTC
Skipping useless range: GENTEX CORP
Skipping useless range: Bentley Labs
Skipping useless range: cendant
Skipping useless range: DENON ELECTRONICS
Skipping useless range: Deloitte & Touche
Skipping useless range: Intermedia / Independent Pipe & Supply Corporation
Skipping useless range: Princeton Corporate Center
Skipping useless range: Rockefeller Group Technology Solutions, Inc
Skipping useless range: NORTEL
Skipping useless range: non-FTS/Soapbox
Skipping useless range: Intermedia / Golf Discount St. Peters
Skipping useless range: Federal Home Loan Bank of Chicago at W. Bryn Mawr Ave
Skipping useless range: Federal Home Loan Bank of Chicago at Wacker Dr
Skipping useless range: Aecom
Skipping useless range: FOXCONN
Skipping useless range: Ethiopian Community Development Council, Inc
Skipping useless range: SUNGARD AVANTGARD
Skipping useless range: Fannie Mae
Skipping useless range: GAMA
Skipping useless range: Emerson Electric
Skipping useless range: CASCADES BOXBOARD INC
Skipping useless range: Mitsubishi Motors R&D of America, Inc
Skipping useless range: research associates
Skipping useless range: High Performance Technology Inc
Skipping useless range: Sungard Network Solution
Skipping useless range: INGRAM MICRO
Skipping useless range: RED HAT, INC
Skipping useless range: UCN Inc
Skipping useless range: Cable & Wireless
Skipping useless range: FISERV IP
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Enron Corporations
Skipping useless range: Verizon Business
Skipping useless range: Delta Galil USA
Skipping useless range: Gateway Investment Advisors, L.P
Skipping useless range: Powerspace & Services
Skipping useless range: PRINCETON CORPORATE CENTER
Skipping useless range: Verizon Business
Skipping useless range: Lyons Lavey Nickel Swift, Inc
Skipping useless range: FENDER MUSICAL INSTRUMENTS
Skipping useless range: Congress Financial
Skipping useless range: Amerada Hess Corp
Skipping useless range: WS/Buyers United/Online
Skipping useless range: Intermedia / Jaymore Electrical Products and Systems
Skipping useless range: INVISION DEVELOPMENT GROUP
Skipping useless range: EXTENDED STAY HOTELS, INC -4023
Skipping useless range: BLUE CROSS BLUE SHIELD O
Skipping useless range: PIONEER ELECTRONICS
Skipping useless range: INFOSPACE, INC
Skipping useless range: MDS Pharma
Skipping useless range: Research Products Corp
Skipping useless range: AECOM
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: UCN Inc
Skipping useless range: Emerson Electric
Skipping useless range: Virtela Communications
Skipping useless range: Emerson Electric
Skipping useless range: Sungard HTE
Skipping useless range: WebPower, Inc
Skipping useless range: OXBOW CORPORATION ALABAMA
Skipping useless range: Buy Owner International
Skipping useless range: Emerson Electric
Skipping useless range: FENDER MUSICAL INSTRUMENTS CORPORATION
Skipping useless range: Flir Systems, Inc
Skipping useless range: B/E AEROSPACE
Skipping useless range: Epoch Biosciences Inc
Skipping useless range: allstateinsurancekirkoram
Skipping useless range: allstateinsurancecathydarracott
Skipping useless range: CONSOLIDATED INFORMATION SERVICES, INC
Skipping useless range: B/E AEROSPACE
Skipping useless range: Musician\'s Friend, Inc
Skipping useless range: Emerson Electric
Skipping useless range: HOTELS.COM
Skipping useless range: IGT
Skipping useless range: Emerson Electric
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: LTD FINANCIAL
Skipping useless range: Emerson Electric
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Foxconn
Skipping useless range: Mitsubishi Motors
Skipping useless range: NATIONAL GEOGRAPHIC
Skipping useless range: NATIONAL GEOGRAPHIC
Skipping useless range: REGUS BUSINESS CENTER
Skipping useless range: ALLSTATE INSURANCE/ABRAHAM VARGHESE
Skipping useless range: Millward Brown
Skipping useless range: Oppenheimer Funds, I
Skipping useless range: Westinghouse / Emerson
Skipping useless range: FISERV IP
Skipping useless range: H. Lee Moffitt Cancer Center & Research Institute, Inc
Skipping useless range: PLACE PROPERTIES
Skipping useless range: ODONNELL HONDA INC
Skipping useless range: Blue House Publishing
Skipping useless range: Fannie Mae
Skipping useless range: COSTAR GROUP INC
Skipping useless range: Greco Ethridge Group, Inc
Skipping useless range: NVA Netsearch
Skipping useless range: Deloitte Consulting
Skipping useless range: RE/MAX METROPOLITIAN REALITY
Skipping useless range: Interwise, Inc
Skipping useless range: Interwise, Inc
Skipping useless range: Interwise, Inc
Skipping useless range: Interwise, Inc
Skipping useless range: Intermedia / -Sure-Wood Forest Products
Skipping useless range: Intermedia / Barefoot Advertising
Skipping useless range: Intermedia / Master Print Center
Skipping useless range: RE/MAX Preferred Realtors
Skipping useless range: SpeedNet LLC
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: HORIZON PUBLISHING COMPANY, LLC
Skipping useless range: Emerson Electric
Skipping useless range: CB RICHARD ELLIS, INC
Skipping useless range: General Atomics
Skipping useless range: Intermedia / Flanery Services dba P.J Capital
Skipping useless range: FISERV INTEGRASYS-CUBE
Skipping useless range: RED HAT, INC
Skipping useless range: Intermedia / -First South Western Title Agency of Arizona, Inc
Skipping useless range: PEDUS SERVICE INC
Skipping useless range: B/E AEROSPACE
Skipping useless range: Cendant Mobility
Skipping useless range: Route for Open Solutions (Allied Tech Group)
Skipping useless range: Intermedia / Gross Insurance
Skipping useless range: Cryptek Secure Communications
Skipping useless range: Fiserv / Users - OP
Skipping useless range: RED HAT, INC
Skipping useless range: RED HAT, INC
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: Emerson Electric
Skipping useless range: EMERSON ELECTRIC - ETP/LoDan - Totowa,NJ
Skipping useless range: JD EDWARDS
Skipping useless range: Emerson Electric
Skipping useless range: Dupont Photomask
Skipping useless range: Emerson Electric
Skipping useless range: John Q. Hammons Hotels
Skipping useless range: Seacor Marine
Skipping useless range: John Q. Hammons Hotels
Skipping useless range: John Q. Hammons Hotels
Skipping useless range: Riverside Publishing
Skipping useless range: Riverside Publishing
Skipping useless range: Insurance Auto Auctions
Skipping useless range: Exhibit Group Giltspur
Skipping useless range: Mirror Image Internet
Skipping useless range: INGRAM MICRO
Skipping useless range: INTERACTIVE SYSTEMS, INC
Skipping useless range: AMERICAN SYSTEMS CORPORATION
Skipping useless range: EXTENDED STAY HOTELS, INC
Skipping useless range: VERTIS, INC
Skipping useless range: Titan Systems Corp
Skipping useless range: Ericsson
Skipping useless range: Envisource
Skipping useless range: AAMI
Skipping useless range: RED HAT , INC
Skipping useless range: AAI Corporation
Skipping useless range: REMAX EXECUTIVES REALTY
Skipping useless range: Atlanta Printing, Inc
Skipping useless range: SYRACUSE RESEARCH CORP
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: DRS Optronics
Skipping useless range: GOREMOTE INTERNET COMMUNICATIONS/MERRILL LYNCH
Skipping useless range: EXTENDED STAY HOTELS, INC. - 530
Skipping useless range: REMAX OF NEW ENGLAND
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: NORTHWEST AIRLINES
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Sungard Network Solutions
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: FUJIFILM-FFEMWR-QP
Skipping useless range: AMS
Skipping useless range: Dow Corp
Skipping useless range: Sarcos Research Corp
Skipping useless range: Vertis, Inc
Skipping useless range: Vertis Inc
Skipping useless range: Michingan Multiple Listing Service Inc Realmatrix
Skipping useless range: Emerson Electric
Skipping useless range: Verizon Business
Skipping useless range: Emerson Electric
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Landstar Sytems, Inc
Skipping useless range: Verizon Business
Skipping useless range: John Q. Hammons Hotels
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: TIGER DIRECT/GLOBAL COMPUTER
Skipping useless range: Emerson Electric
Skipping useless range: CB RICHARD ELLIS, INC
Skipping useless range: GDS ASSOCIATES INC
Skipping useless range: B/E AEROSPACE
Skipping useless range: Enterprise Computing Solutions
Skipping useless range: B/E AEROSPACE
Skipping useless range: Intermedia / Cybermetrics Corporation
Skipping useless range: Air Force Villages
Skipping useless range: Dodge & Cox
Skipping useless range: Emerson Electric
Skipping useless range: siemense
Skipping useless range: allstateinsurancemonikasmith
Skipping useless range: American Express Financial Advisors
Skipping useless range: Sungard Futures
Skipping useless range: SSA GLOBAL TECHNOLOGY
Skipping useless range: Marathon Oil Co
Skipping useless range: FENDER MUSICAL INSTRUMENTS
Skipping useless range: WS/ACCERIS COMMUNICATIONS/TED BROWN MUSIC
Skipping useless range: Mirror Image Internet
Skipping useless range: Emerson Electric
Skipping useless range: Idleaire Technologies Corp.
Skipping useless range: Idleaire Technologies Corp
Skipping useless range: MCG CAPITAL CORPORATION
Skipping useless range: RED HAT, INC
Skipping useless range: Cendant Mobility
Skipping useless range: UCN Inc
Skipping useless range: allstate
Skipping useless range: HD DIMENSION CORP
Skipping useless range: FACTSET RESEARCH SYSTEMS
Skipping useless range: MARKETING PARTNERS INC
Skipping useless range: ALSTOM POWER
Skipping useless range: Verisign
Skipping useless range: MSI Merchant Services
Skipping useless range: allstateinsurancekevinmcgoldrick
Skipping useless range: Verizon Business
Skipping useless range: VERTIS, INC
Skipping useless range: bloomberg
Skipping useless range: Cambridge Associates
Skipping useless range: ericsson
Skipping useless range: Hitachi Cable Indiana
Skipping useless range: NATIONAL GEOGRAPHIC
Skipping useless range: SYNERGY SOLUTIONS
Skipping useless range: Emerson Electric
Skipping useless range: Hitachi Cable of Indiana
Skipping useless range: NATIONAL GEOGRAPHIC
Skipping useless range: Sanyo Energy (U.S.A.) Corporation
Skipping useless range: American Light
Skipping useless range: Banta Catalog Group
Skipping useless range: Intermedia / Triple I
Skipping useless range: Broadcom Corporation
Skipping useless range: Emerson Electric
Skipping useless range: PRECYSE SOLUTIONS
Skipping useless range: Industrial Services
Skipping useless range: B/E AEROSPACE
Skipping useless range: Lightyear/Fowler, Holley, Rambo & Haynes
Skipping useless range: Emerson Electric
Skipping useless range: MONITORING TECHNOLOGY CORP
Skipping useless range: allstateinsurancegaryjensen
Skipping useless range: EDUCATION FINANCE RESOURCES
Skipping useless range: FENDER MUSICAL INSTRUMENTS
Skipping useless range: Lexicon International
Skipping useless range: PROCTER & GAMBLE CORP
Skipping useless range: AECOM - ARLINGTON 3M MLFR
Skipping useless range: COSTAR GROUP INC
Skipping useless range: ALLSTATE INSURANCE/JAMES COYLE
Skipping useless range: RAVENWOOD HEALTHCARE, INC
Skipping useless range: allstate
Skipping useless range: Bose Corporation
Skipping useless range: ALLSTATE INSURANCE/JIM BROGAN
Skipping useless range: First National Bank of Lafollette
Skipping useless range: Banta Corp
Skipping useless range: aecom
Skipping useless range: Phonak Inc
Skipping useless range: Verisign - Broadrun
Skipping useless range: UCN Inc
Skipping useless range: FENDER MUSICAL INSTRUMENTS
Skipping useless range: PEDIATRIX MEDICAL GROUP
Skipping useless range: B/E AEROSPACE
Skipping useless range: SATYAM COMPUTER SERVICES LTD
Skipping useless range: EMERSON ELECTRIC
Skipping useless range: Mid America Research
Skipping useless range: Intermedia / COMP-U-HELP
Skipping useless range: Intermedia / Hunt Construction Corp
Skipping useless range: College Loan Corporation
Skipping useless range: FORENSIC ANALYTICAL
Skipping useless range: FIRST DATA CORPORATION
Skipping useless range: FORENSIC ANALYTICAL
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Verizon Business
Skipping useless range: Fiserv
Skipping useless range: westwood
Skipping useless range: SCHAWK, INC
Skipping useless range: OLAYAN AMERICAN CORPORATION
Skipping useless range: Blue Cross Blue Shield Of Delaware a Care First Co
Skipping useless range: North Shore Medical Center
Skipping useless range: American Board Of Internal Medicine
Skipping useless range: Stat Radiology Medical Corp
Skipping useless range: Stat Radiology Medical Corp
Skipping useless range: Tensolite Company
Skipping useless range: Medical Video Systems
Skipping useless range: Remax 200 Realty
Skipping useless range: Fujifilm Medical Systems USA
Skipping useless range: Banks Engineering
Skipping useless range: Federal Financial Group
Skipping useless range: CAPITAL TRANSIT CONSULTANTS
Skipping useless range: Fairfax Medical Laboratory
Skipping useless range: Agenda Marketing Partners
Skipping useless range: COLLEGE HEALTH ENTERPRISES
Skipping useless range: Sherman Oaks Hospital
Skipping useless range: PaeTec Communications
Skipping useless range: REMAX ACTION REALTY
Skipping useless range: REMAX Real Estate Malden
Skipping useless range: Starwood Hotels & Resorts Sheraton Portsmouth
Skipping useless range: REMAX PROPERTIES I
Skipping useless range: Aculabs Inc
Skipping useless range: Remax Elite
Skipping useless range: TRIDENT LABS INC
Skipping useless range: ELLIS HOSPITAL
Skipping useless range: Chase Credit Research
Skipping useless range: Research Pharmaceuticals
Skipping useless range: REED,HALDY,MCINTOSH & ASSOCIATES
Skipping useless range: WOLFPACK
Skipping useless range: AFTRA-SAG FEDERAL CREDIT UNION
Skipping useless range: SHERATON SUITES ELK GROVE
Skipping useless range: BLOOMBERG LP
Skipping useless range: CORAL RIDGE MINISTRIES MEDIA, INC
Skipping useless range: Remax Country Properties
Skipping useless range: REMAX DESTINY
Skipping useless range: FEDERAL PUMP CORP
Skipping useless range: BURKE SUPPLY SYSTEMS
Skipping useless range: MEDIA LOGIC
Skipping useless range: HVAC Quick.com
Skipping useless range: Energy Group, Inc
Skipping useless range: Eyeball Marketing
Skipping useless range: Dealer Fusion, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Sofmen, Inc
Skipping useless range: Knot Eye Computing
Skipping useless range: Energy Group, Inc
Skipping useless range: Mountain Marketing
Skipping useless range: Outblaze Limited
Skipping useless range: XDS Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: pro1.findnot.com
Skipping useless range: Energy Group, Inc
Skipping useless range: Odyssey Research
Skipping useless range: Remax of Montgomery
Skipping useless range: KMC Telecom, Inc. (MLB0)
Skipping useless range: Medical Anesthesia &amp; Pain Mgmt
Skipping useless range: Interbank Fx
Skipping useless range: Tor.Ca7aiThujo7iZ7oS
Skipping useless range: Digital Focus Productions
Skipping useless range: Oolong.com
Skipping useless range: Surprise.com
Skipping useless range: PDAapps Inc
Skipping useless range: Energy Group Networks LLC
Skipping useless range: Responsive Learning Technologies
Skipping useless range: Health Comm. Research Instit
Skipping useless range: United Insurance Technology
Skipping useless range: GeneticMail
Skipping useless range: Download Technologies, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Krugle, Inc
Skipping useless range: etalk communications
Skipping useless range: Energy Group, Inc
Skipping useless range: etalk communications
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Digitalsmiths Corporation
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Castle Hill Consultants Ltd
Skipping useless range: vpn1.findnot.com
Skipping useless range: Fairfax Medical Laboratory
Skipping useless range: ATLANTIC TESTING LABORATORIES, LIMITED
Skipping useless range: UNIVISIONS
Skipping useless range: PENNSYLVANIA INSTITUTE OF TECHNOLOGY
Skipping useless range: MCM USA, INC
Skipping useless range: WHITMORE GROUP LTD
Skipping useless range: NEW AGE BROKERAGE
Skipping useless range: BLUEFIN ROBOTICS CORPORATION
Skipping useless range: SHEKINAH, INC
Skipping useless range: VIROPHARMA
Skipping useless range: STARWOOD/SHERATON STATION SQUARE
Skipping useless range: MCM USA, INC
Skipping useless range: NEW YORK LAN COMMUNICATIONS INC - BKLYN
Skipping useless range: HONORS REVIEW
Skipping useless range: Atlas Technologies
Skipping useless range: Medical Management Professionals
Skipping useless range: Remax Realty Tram 2
Skipping useless range: Remax Central Independence
Skipping useless range: Remax Realty
Skipping useless range: Nat. Security Research
Skipping useless range: Cancer Fund fo America
Skipping useless range: Remax Professionals Norcross
Skipping useless range: NetOctave
Skipping useless range: Remax On Track Real Estate
Skipping useless range: Remax Allegiance
Skipping useless range: Virginia Association of Community Banks
Skipping useless range: Hitachi Maxco
Skipping useless range: Eton Systems
Skipping useless range: PLS-FINANCIAL-SERVICES
Skipping useless range: EASTMORE-REAL-ESTATE
Skipping useless range: CEDAR-SQUARE
Skipping useless range: NEBRASKA-LABLINC
Skipping useless range: INTERBANK,-FSB
Skipping useless range: SKYWAY-EXPRESS
Skipping useless range: MAUI-CLINIC-PHARMACY
Skipping useless range: MANAO-RESEARCH-GROUP-LLC
Skipping useless range: JUPITER-RESEARCH-FOUNDATION
Skipping useless range: JY-COMPUTER
Skipping useless range: CASTELLAN
Skipping useless range: BROADSWORD
Skipping useless range: Road Runner Commercial
Skipping useless range: TECH-SUPPORT-AID,-INC
Skipping useless range: EMINENT-FUNDING,*
Skipping useless range: STAPLES,-HUTCHINSON-&-ASSOCIATES
Skipping useless range: REGULATORY-&-CLINICAL-RESEARCH-INSTITUTE-INC
Skipping useless range: [DAS]-BANTA-BOOK-PACKAGING-AND-FULFILLMENT
Skipping useless range: STONEARCH-NETWORKING-SERVICES
Skipping useless range: OPEN-PANTRY
Skipping useless range: Road Runner Commercial
Skipping useless range: BELL-PROPERTY
Skipping useless range: BELL-PROPERTY
Skipping useless range: BELL-PROPERTIES
Skipping useless range: ORDIZ-MELBY-ARCHITECTS,-INC
Skipping useless range: larry.trashcan.com
Skipping useless range: SUN-COAST-CLINIC
Skipping useless range: PA,SK-FINANCIAL-
Skipping useless range: Road Runner Commercial
Skipping useless range: FINANCIAL,FIRST-COLLEGIATE
Skipping useless range: COMMUNICATION,WAVE
Skipping useless range: Abuse
Skipping useless range: WALK-IN-CLINIC,CENTRAL
Skipping useless range: REMAX-REALTY
Skipping useless range: mail.mycomputervisions.com
Skipping useless range: FIRST-MARKETING-GROUP
Skipping useless range: harborside healthcare
Skipping useless range: K & K Computers
Skipping useless range: KODAK POLYCHROME GRAPHICS
Skipping useless range: REMAX GOLD STAR
Skipping useless range: COMMERCE INTERNATIONAL
Skipping useless range: PaeTec Communications
Skipping useless range: NJ SCHOOL BOARD ASSOC INSURANCE GROUP
Skipping useless range: COGEN SKLAR
Skipping useless range: STARWOOD CERUZZI, LLC
Skipping useless range: BOSTON UNIVERSITY EYE ASSOCIATES - TAUNTON
Skipping useless range: ROADRUNNER PREFERRED DELIVERY SYSTEMS
Skipping useless range: PHILLIPS SOUTH BEACH LLC DBA THE SHORE CLUB
Skipping useless range: PaeTec Communications
Skipping useless range: AIDS COMMUNITY SERVICES OF WNY
Skipping useless range: BOSTON UNIVERSITY EYE ASSOCIATES - BROCKTON
Skipping useless range: BOSTON UNIVERSITY EYE ASSOCIATES - MIDDLEBORO
Skipping useless range: COGEN SKLAR
Skipping useless range: NEW YORK LAN COMMUNICATIONS INC
Skipping useless range: MARWEST ACCESS CONTROLS INC
Skipping useless range: REMAX PROFESSIONALS OF NEWPORT
Skipping useless range: ABC INTERNATIONAL
Skipping useless range: REMAX COLLEGE PARK REALTY
Skipping useless range: LG INSURANCE CO, LTD
Skipping useless range: REGENT BUSINESS CENTERS
Skipping useless range: REMAX PREMIER-LATHAM
Skipping useless range: RANDALL HAGNER LTD
Skipping useless range: REMAX COAST TO COAST
Skipping useless range: HOTEL ST GEORGE
Skipping useless range: NOVELL & NOVELL COUNSELING SERVICES
Skipping useless range: ROADRUNNER PREFERRED DELIVERY SYSTEMS
Skipping useless range: RESEARCH FOUNDATION CUNY
Skipping useless range: RESEARCH CONSULTANTS FOR MARKETING INC
Skipping useless range: PaeTec Communications
Skipping useless range: STARWOOD HOTELS & RES.- SHERATON SUITES PLANTATION,
Skipping useless range: Dow Chemical Corp
Skipping useless range: Lexicon
Skipping useless range: Remax of Georgia, Inc. Regional Headquarters
Skipping useless range: ReMax Achievers
Skipping useless range: Remax Home and Ranch (Kiowa)
Skipping useless range: vpn1.findnot.com
Skipping useless range: Candela Corporation
Skipping useless range: College Loan Corporation
Skipping useless range: Academic Loan Group
Skipping useless range: Noesis Consulting Group
Skipping useless range: TorrentPrivacy
Skipping useless range: HAWTHORNE-SUITES
Skipping useless range: N MLFD FOUNDRY & MACH-050128025553
Skipping useless range: NETWORKS,-LTD
Skipping useless range: NAI-OHIO-EQUITIES
Skipping useless range: LOTTADOT.COM-
Skipping useless range: PETER-FURKEY-MTS
Skipping useless range: PAD-DOOR-SYSTEMS,-INC
Skipping useless range: WILD-ENTITY
Skipping useless range: HOLIDAY-INN
Skipping useless range: CINCINNATI-PRECISION-PLATE
Skipping useless range: mail.scpautomotive.com
Skipping useless range: kevin e anderson consulting inc
Skipping useless range: Heart and Vascular Ctr of Bradenton
Skipping useless range: Remax Town & Country
Skipping useless range: Target Marketing
Skipping useless range: Remax Center Dacula
Skipping useless range: Remax Center Suwanee
Skipping useless range: Taylor Elevator Corporation
Skipping useless range: Comstock Earnest Realtors
Skipping useless range: Remax Allegiance 5100 Leesburg
Skipping useless range: REmax Allegiance
Skipping useless range: Remax Allegiance
Skipping useless range: Remax Allegiance Burke
Skipping useless range: Remax Real Estate Executive
Skipping useless range: Remax Allegiance
Skipping useless range: Shumate Mechanical
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: Road Runner Commercial
Skipping useless range: INNOVATION-DATA-MANAGEMENT
Skipping useless range: Intersearch Group, Inc
Skipping useless range: AECOM Services Group
Skipping useless range: Goodmail Systems, Inc
Skipping useless range: LOGMEIN, INC
Skipping useless range: DoubleFusion Inc
Skipping useless range: Rendition Networks
Skipping useless range: DoubleFusion Inc
Skipping useless range: PLANK-LLC
Skipping useless range: BANK-OF-SCOTLAND
Skipping useless range: TIRRANNA-LLC
Skipping useless range: Road Runner Commercial
Skipping useless range: STARWOOD HOTEL & RESORTS SHERATON SUITES SAN DIEGO
Skipping useless range: UNIVERSAL CONSULTING
Skipping useless range: REMAX FIRST EAST BRUNSWICK
Skipping useless range: METROPOLITAN 58TH STREET ASSOCIATES LLC
Skipping useless range: REMAX OLYMPIC REALTY
Skipping useless range: AUDAX MANAGEMENT COMPANY, LLC
Skipping useless range: PHD INSURANCE BROKERS - CULVER CITY
Skipping useless range: PHD INSURANCE BROKERS
Skipping useless range: REMAX DESTINY
Skipping useless range: CRA INC
Skipping useless range: METROPOLITAN 58TH STREET ASSOCIATES LLC
Skipping useless range: NETTEKS TECHNOLOGY CONSULTANTS INC
Skipping useless range: RECORDER PUBLISHING DYNALINK
Skipping useless range: SPRINGER PUMPS
Skipping useless range: REMAX ALL STARS
Skipping useless range: REMAX OLYMPIC REALTY - HAYMARKET
Skipping useless range: KABOOM
Skipping useless range: REMAX PREMIERE SELECTIONS
Skipping useless range: INTERFILM HOLDINGS INC
Skipping useless range: ALL TERRAIN PRODUCTIONS, INC
Skipping useless range: NETTEKS TECHNOLOGY CONSULTANTS INC
Skipping useless range: INTERFILM HOLDINGS INC
Skipping useless range: HOTEL GANSEVOORT
Skipping useless range: PHD INSURANCE BROKERS - CORONA
Skipping useless range: BLITZ DISTRIBUTION/ WTI COMMUNICATIONS
Skipping useless range: HILTON HYLAND REAL ESTATE
Skipping useless range: INTERFILM HOLDINGS
Skipping useless range: REMAX PREMIER SARATOGA
Skipping useless range: FMC FINANCIAL GROUP
Skipping useless range: METROPOLITAN 58TH STREET ASSOCIATES LLC
Skipping useless range: RED LINES FILM TELCO EXPERTS
Skipping useless range: MANAGEMENT SCIENCES FOR HEALTH
Skipping useless range: INTERFILM HOLDINGS INC
Skipping useless range: mail.aaarenewals.com
Skipping useless range: MYERS-REAL-ESTATE
Skipping useless range: P-R-STORES,-LLC
Skipping useless range: Tor.twbandwidth
Skipping useless range: NEW MEDIA LAB. SRL
Skipping useless range: Bank Informacji Gospodarczej -Antoniewicz S.C
Skipping useless range: Please Send Abuse/SPAM complaints to Abuse-gilat@
Skipping useless range: Ingram Micro, Oslo
Skipping useless range: Complete Minilab Services Ltd
Skipping useless range: National Bank of Republic of Tatarstan
Skipping useless range: Integralis France
Skipping useless range: RED HAT FRANCE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-QUADRIGA-FRANCE-LB_INTERNET
Skipping useless range: Hopital Hospice d Hirson
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: Vector France
Skipping useless range: Hopital de Fougeres
Skipping useless range: SA LE FOYER DE LA CHARENTE MARITIME
Skipping useless range: Laboratoires Fenioux
Skipping useless range: Clinique Saint Germain
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: Clinique Breteche Viaud
Skipping useless range: Agence Maritime Delpierre
Skipping useless range: Polyclinique les Chenes
Skipping useless range: Laboratoire Medico Biologique
Skipping useless range: Orchidis Laboratoires
Skipping useless range: CLINIQUE DES EMAILLEURS
Skipping useless range: HOPITAL SAINT JEAN
Skipping useless range: Media Logs
Skipping useless range: Astrium
Skipping useless range: BREAS MEDICAL
Skipping useless range: MEDICAL AIR GRENOBLE
Skipping useless range: FEDERAL EXPRESS
Skipping useless range: BMD BIOMEDICAL DIAGNOSTIC
Skipping useless range: CLINIQUE DELAY
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-RECORD-PORTES-AUTOMATIQUES-LB_INTERNET
Skipping useless range: FR-RAEI-QUADRIGA-FRANCE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: HOPITAL GOUIN
Skipping useless range: KCI EQUIPEMENT MEDICAL
Skipping useless range: LABORATOIRE DELAPORTE
Skipping useless range: FR-RAEI-QUADRIGA-FRANCE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: CENTRE D AFFAIRE LA DEFENSE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: EADS CCR
Skipping useless range: CLINIQUE DE L HOMME
Skipping useless range: Agence Maritime Cognacaise
Skipping useless range: CATERPILLAR LOGISTICS SERVICES
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: INSTITUT NATIONNAL DE JEUNE SOURDS DE CHAMBERY
Skipping useless range: FUJI BURIOT SA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Laboratoire du Dr Ng Payot
Skipping useless range: LOGICA
Skipping useless range: LOGICA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ALCATEL BUSINESS SYSTEMS
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GDS IMPRIMEURS
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: INDUSTRIE
Skipping useless range: HOPITAL DE FOURVIERE
Skipping useless range: BANQUE POPULAIRE LORRAINE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: MITSUI EUROCEL
Skipping useless range: LABORATOIRE EUROPEEN ADSL
Skipping useless range: RSASEEC
Skipping useless range: Tryssenkrupp Elevator Manufact
Skipping useless range: Institut Francais Du Petrole
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: INSTITUT FRANCAIS D ARCHITECTU
Skipping useless range: QUADRIGA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: DOCKS MARITIMES TECHNIDIS
Skipping useless range: CCC SARL
Skipping useless range: DELOITTE ET TOUCHE
Skipping useless range: AXXICON MOULDS CAEN
Skipping useless range: SIA FRANCE
Skipping useless range: LABMETRIX
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ZEBRA TECHNOLOGIES EUROPE LIMI
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: LABORATOIRES BTTT
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: SCHLUMBERGER
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: PININFARINA RICERCA E SVILUPPO
Skipping useless range: V2R INGENIERIE
Skipping useless range: INSTITUT POLYTECHNIQUE SAINT LOUIS
Skipping useless range: HITACHI POWER TOOL
Skipping useless range: NEXANS FRANCE
Skipping useless range: PRESTATIONS MEDICALES SERVICES
Skipping useless range: LA COMMANDE NUMERIQUE
Skipping useless range: STEAM FRANCE
Skipping useless range: SERVICE MEDICAL INTER-ENTREPRI
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: DTSSERVICES
Skipping useless range: LABORATOIRE DES BOULES QUIES
Skipping useless range: POLYCLINIQUE ST FRANCOIS ST AN
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: MITSUI SUMITOMO
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: INTERNATIONAL HOSPITAL FEDERAT
Skipping useless range: LES LABORATOIRES PARISIENS
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: CLINIQUE TRENEL
Skipping useless range: BRIGHTPOINT
Skipping useless range: LABORATOIRES SERVICES KODAK
Skipping useless range: LABORATOIRES SERVICES KODAK
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: DELOITTE TOUCHE TOHMATSU
Skipping useless range: CENTREMEDICAL JACQUES ARNAUD
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: HNE MEDICAL
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: POLYCLINIQUE DU PARC
Skipping useless range: ROTHSCHILD ET CIE BANQUE
Skipping useless range: INSPECTION ACADEMIQUE DEUX SEV
Skipping useless range: NORTEL NETWORKS
Skipping useless range: RSASEEC
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: MITSUI COMPONENTS EUROPE
Skipping useless range: FTIP002696379 Pitney Bowes
Skipping useless range: SAMSUNG NETWORKS
Skipping useless range: Ingram Micro
Skipping useless range: FTIP002742922 Pitney Bowes Ltd
Skipping useless range: FTIP002746074 Pitney Bowes Ltd
Skipping useless range: FTIP002685496 Getronics
Skipping useless range: FTIP002851693 Nexen Petroleum UK Ltd
Skipping useless range: FTIP002870601 Sungard Vivista Ltd
Skipping useless range: FTIP002702209 Atlantech Medical Devices Ltd
Skipping useless range: FTIP000024174 Regus UK Berkley Square
Skipping useless range: FTIP002704883 Kodak
Skipping useless range: FTIP002736754 Asia TV Ltd
Skipping useless range: FTIP002704760 Lafarge Aggregates Ltd
Skipping useless range: FTIP002705262 Market Research UK Ltd
Skipping useless range: FTIP002707907 Yorkshire Financial Management
Skipping useless range: FTIP002746524 Investec Bank UK Ltd
Skipping useless range: FTIP002710808 Royal Bank Of Scotland Group ( Plc)
Skipping useless range: FTIP002709086 Water Research Centre
Skipping useless range: FTIP002774657 Business Environment Group
Skipping useless range: FTIP002716022 Close Asset Financial Ltd
Skipping useless range: FTIP002729909 Enterprise Research
Skipping useless range: FTIP002720852 Royal Bank Of Scotland Group (plc)
Skipping useless range: FTIP002719849 Threshold Floorings Limited
Skipping useless range: FTIP002722245 The Royal Bank Of Scotland Group Pl
Skipping useless range: FTIP002727851 Empirix UK Ltd
Skipping useless range: FTIP002719047 Citadel Investment Group
Skipping useless range: Saudi National Commercial Bank
Skipping useless range: Saudi National Commercial Bank
Skipping useless range: Cromwell Hospital
Skipping useless range: Cromwell Hospital
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Misys Financial Systems
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Misys Financial Systems
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Pilkington Memorial Hospital
Skipping useless range: Corin Medical
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Rothschild Capital Management Ltd
Skipping useless range: OC & C Strategy Consultants
Skipping useless range: Landesbank Baden Wurttemberg
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Flexible Medical Packaging
Skipping useless range: Flexible Medical Packaging
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Kingswood Financial Consulting Ltd
Skipping useless range: Kingswood Financial Consulting Ltd
Skipping useless range: Mission Aviation Fellowship
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: 20 Twenty Mortgages Ltd
Skipping useless range: Professional Financial Planning Services
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Ela Medical
Skipping useless range: Archival Record Management
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: 20 Twenty Mortgages Ltd
Skipping useless range: Fujikura (Europe) Ltd
Skipping useless range: E.S.A. Market Research Ltd
Skipping useless range: Medical Solutions
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Rothschild Capital Management Ltd
Skipping useless range: Landesbank Baden Wurttemberg
Skipping useless range: E.S.A. Market Research Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: TDK Systems Europe Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Medical Solutions
Skipping useless range: Title Research Ltd
Skipping useless range: Title Research Ltd
Skipping useless range: Medical Solutions
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: Title Research Ltd
Skipping useless range: Title Research Ltd
Skipping useless range: Medical Education Press Ltd
Skipping useless range: Medical Solutions
Skipping useless range: Wickham Laboratories Ltd
Skipping useless range: Ela Medical
Skipping useless range: Qatar National Bank
Skipping useless range: Ela Medical
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Medical Solutions
Skipping useless range: Medical Solutions
Skipping useless range: Fuji Photo Film (uk) Ltd
Skipping useless range: Ela Medical
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Medical Solutions
Skipping useless range: Overseas Development Institute
Skipping useless range: Summit Medical Ltd
Skipping useless range: Summit Medical Ltd
Skipping useless range: Chambers IFA Ltd
Skipping useless range: Misys Financial Systems
Skipping useless range: Misys Financial Systems
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Misys Financial Systems
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Medical Solutions
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: DAS Legal Expenses Insurance Co Ltd
Skipping useless range: Landesbank Baden Wurttemberg
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Prescient Financial Intelligence Ltd
Skipping useless range: Prescient Financial Intelligence Ltd
Skipping useless range: Spectrum Interactive (UK) Ltd
Skipping useless range: Accident Investigators UK
Skipping useless range: Prescient Financial Intelligence Ltd
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Prescient Financial Intelligence Ltd
Skipping useless range: Prescient Financial Intelligence Ltd
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: Ela Medical
Skipping useless range: Medical Solutions
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Alliance Medical Ltd
Skipping useless range: Medical Solutions
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: Alliance Medical Ltd
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: Alliance Medical Ltd
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: The East Anglian Federal Co-op Society
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Digital Vision Technologies
Skipping useless range: OC & C Strategy Consultants
Skipping useless range: Sanders Polyfilms Ltd
Skipping useless range: Global Debt Recovery Ltd
Skipping useless range: Chartered Insurance Institute
Skipping useless range: Star Internet - INTERNAL STOCK RECORDS
Skipping useless range: Hospital St. Jansdal
Skipping useless range: ALcontrol Laboratories
Skipping useless range: HOTEL
Skipping useless range: DU PONT DE NEMOURS
Skipping useless range: ACCESSOIRE POUR INSTRUMENTS DE MUSIQUES
Skipping useless range: MARKETING EXTRABANCAIRE
Skipping useless range: SOCIETE SERVICE TRAITEMENT COURIER
Skipping useless range: EXPERTISE COMPTABLE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: HOTELLERIE
Skipping useless range: ANIMATION ET PROMOTION DE VENTE
Skipping useless range: INSTRUMENT DE MUSIQUE ET ACCESSOIRES
Skipping useless range: HOTEL
Skipping useless range: DISTRIBUTION DEVELOPPEMENT SOLUTION STOCKAGE MEDICAL
Skipping useless range: HOLDING D ANIMATION
Skipping useless range: RESTAURATION
Skipping useless range: CENTRE D AFFAIRES
Skipping useless range: INDUSTRIE
Skipping useless range: HOTELLERIE
Skipping useless range: MARQUAGES
Skipping useless range: ACTIVITE HOTELIERE
Skipping useless range: HOTELLERIE
Skipping useless range: NUMERISATION DE FILM
Skipping useless range: HOTELLERIE
Skipping useless range: EQUIPEMENTIER TELECOM
Skipping useless range: EDITEUR DE PRODUITS LIES A LA PEDAGOGIE MUSICALE
Skipping useless range: HOTELERIE
Skipping useless range: PRESTATAIRE SERVICES
Skipping useless range: EXTENSION DE FILM ET TRICOTAGE DE FILET
Skipping useless range: HOTEL
Skipping useless range: COMMERCE
Skipping useless range: H TEL
Skipping useless range: HOTELLERIE
Skipping useless range: H TEL
Skipping useless range: HOTELLERIE
Skipping useless range: TRAITEMENT COURRIER
Skipping useless range: HOTEL
Skipping useless range: REVENDEUR INFORMATIQUE DE PRODUIT APPLE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: IMPRIMERIE
Skipping useless range: SSII INFORMATIQUE DEVELOPPEMENT
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: LA BS BOUTIQUE DU SPECTACLE
Skipping useless range: INDUSTRIE MEDICALE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: ERICSSON
Skipping useless range: FOURNISSEURS DES SYSTEMES DE TELECOMMUNICATIONS
Skipping useless range: INDUSTRIE
Skipping useless range: TIBCO-TELECOM
Skipping useless range: SSII SERVICES INFORMATIQUES
Skipping useless range: HOTELLERIE
Skipping useless range: NON RENSEIGN
Skipping useless range: HOTELLERIE
Skipping useless range: FABRICANT
Skipping useless range: HITACHI SOFTWARE
Skipping useless range: ERICSSON FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: DIEHL FRANCE
Skipping useless range: QUADRIGA MERCURE LA DEFENCE
Skipping useless range: FILMASPORT
Skipping useless range: GEAC Entreprise Solutions France
Skipping useless range: LABORATOIRES PRODENE KLINT
Skipping useless range: LABORATOIRE IVAX
Skipping useless range: DUPONT D ISIGNY
Skipping useless range: COMPAGNIE INDUSTRIELLE MARITIME
Skipping useless range: ALCATEL BUSINESS SYSTEMS
Skipping useless range: HOPITAL PRIVE PAUL D EGINE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: INSTITUT FRANCAIS DU PETROLE
Skipping useless range: QUADRIGA
Skipping useless range: SILICON LABORATORIES FRANCE
Skipping useless range: HITACHI PRINTING
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: IMAGERIE MEDICALE
Skipping useless range: CLINIQUE BON SECOURS
Skipping useless range: SUNGARD AVAILABILITY SERVICE F
Skipping useless range: MDS PHARMA SERVICES SA
Skipping useless range: LOGICONFORT
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: lafarge platres
Skipping useless range: SUMITOMO ELECTRIC WIRING
Skipping useless range: INTRACALL CENTER
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ACTIVIT HOTELI RE
Skipping useless range: MEDICAL PRODUCTS
Skipping useless range: DUPONT RESTAURATION
Skipping useless range: RECHERCHE CLINIQUE
Skipping useless range: INDUSTRIE
Skipping useless range: LABORATOIRE ANALYSES MEDICALES
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: ETABLISSEMENT HOSPITALIER PRIV
Skipping useless range: EDITEUR DE LOGICIELS MARITIMES
Skipping useless range: TRANSPORT MARITIMES
Skipping useless range: TRANSPORT MARITIMES
Skipping useless range: TRANSIT AERIEN MARITIME
Skipping useless range: TRANSIT AERIEN MARITIME
Skipping useless range: CLINIQUE MEDICO-CHIRURGICALE OBSTETRIQUE
Skipping useless range: EDITEUR DE LOGICIELS
Skipping useless range: EDITION MEDICALE
Skipping useless range: T L PILOTAGE INFORMATIQUE ET INDUSTRIEL
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: DISTRIBUTION AUTOMATES DE LABORATOIRE
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: HOPITAL
Skipping useless range: FORD MOTOR COMPANY LIMITED
Skipping useless range: HOPITAL
Skipping useless range: LABORATOIRE D'ANALYSE
Skipping useless range: LABORATOIRE ANALYSE
Skipping useless range: HOPITAL
Skipping useless range: MARQUAGE INDUSTRIEL
Skipping useless range: TELEVISION VIDEO
Skipping useless range: GROUPE PETROLIER
Skipping useless range: LABORATOIRE D'ANALYSES M.DICALES
Skipping useless range: DISTRIBUTION AUTOMATES DE LABORATOIRES
Skipping useless range: SERVICE
Skipping useless range: LOGICIELS LINGUISTIQUE
Skipping useless range: REGUS PARIS SA
Skipping useless range: CONFEDERATION MEDICALE
Skipping useless range: GROSSISTE INFORMATIQUE
Skipping useless range: INTEGRATEUR,DISTRIBUTEURDE SOLUTION INFORMATIQUE
Skipping useless range: INFORMATIQUE
Skipping useless range: SECAP GROUPE PITNEY BOWES
Skipping useless range: LABORATOIRE D'ANALYSE
Skipping useless range: HOPITAL PSYCHRIATRIQUE
Skipping useless range: HOPITAL PSYCHIATRIQUE
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: CLINIQUE
Skipping useless range: LABORATOIRE
Skipping useless range: éDITEUR DE LOGICIELS
Skipping useless range: HOPITAL
Skipping useless range: HOPITAL
Skipping useless range: MATERIEL MEDICAL
Skipping useless range: HOSTELLERIE
Skipping useless range: HOSTELLERIE
Skipping useless range: LABORATOIRE D'ANALYSES DE BIOLOGIE
Skipping useless range: HOSTELLERIE
Skipping useless range: LABORATOIRE PHOTO
Skipping useless range: HOPITAL
Skipping useless range: HOPITAL SPéCIALISé
Skipping useless range: HOPITAL
Skipping useless range: HOPITAL
Skipping useless range: CONSEIL ET INGENIERIE EN BUSINESS INTELLIGENCE CR
Skipping useless range: HOTEL
Skipping useless range: HOPITAL
Skipping useless range: EDITEUR DE LOGICIELS
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: CLINIQUE
Skipping useless range: MEDICAL
Skipping useless range: LABORATOIRE
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: ALCATEL BUSINESS SYSTEMS
Skipping useless range: HOPITAL
Skipping useless range: MOBILIER URBAIN
Skipping useless range: HOSTELLERIE
Skipping useless range: HOSTELLERIE
Skipping useless range: LABORATOIRES
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: LABORATOIRE
Skipping useless range: CALL CENTER
Skipping useless range: TRAITEMENT DU COURRIER
Skipping useless range: HOPITAL
Skipping useless range: éDITEUR DE LOGICIELS
Skipping useless range: LABORATOIRE MéDICAMENTEUX
Skipping useless range: EDITEUR DE LOGICIELS
Skipping useless range: AGENCE MARITIME
Skipping useless range: HOTELERIE
Skipping useless range: VENTE MATERIEL DE LABORATOIRE
Skipping useless range: COSMETOLOGIE MEDICALE
Skipping useless range: CENTRE HOSPITALIER
Skipping useless range: LABORATOIRE
Skipping useless range: BIOMEDICAL
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: HOSPITAL
Skipping useless range: LABORATOIRS DE TEST ET CERTIFICAT TELECOM
Skipping useless range: ASSISTANCE MEDICALE A DOMICILE
Skipping useless range: LABORATOIRE PHARMACEUTIQUE
Skipping useless range: NEGOCE D\
Skipping useless range: HOPITAL UNITE DE GREFFE DE MOELLE
Skipping useless range: HOPITAL
Skipping useless range: ASSOCIATION MEDICALE
Skipping useless range: HOPITAL PSYCHIATRIQUE
Skipping useless range: PRESTATAIRE ASSURANCE MARITIME
Skipping useless range: EDITEUR DE LOGICIELS DE FORMATION
Skipping useless range: CLINIQUE
Skipping useless range: MEDICALE
Skipping useless range: EDITEUR DE LOGICIELS
Skipping useless range: COMMERCE
Skipping useless range: NON RENSEIGNE
Skipping useless range: INFORMATIQUE
Skipping useless range: IMPORT/EXPORT
Skipping useless range: RECHERCHE EN HISTOIRE DE L ART
Skipping useless range: Wavex Technology Ltd 534692
Skipping useless range: Hsbc Private Bank
Skipping useless range: greenT IT-Solutions
Skipping useless range: Nortelnetworks
Skipping useless range: PLAYGROUND-NORTEL
Skipping useless range: FX Networks Corporate Range
Skipping useless range: Nortelnetworks
Skipping useless range: Nortelnetworks
Skipping useless range: Merrill Lynch/Howard Johnson &amp; Company
Skipping useless range: Centre Hospitalier Pierre-Boucher
Skipping useless range: Centre Hospitalier Gatineau
Skipping useless range: SPRINT/ER791/KRDC
Skipping useless range: Westinghouse Electric Company
Skipping useless range: Federal Home Loan Bank of Atlanta
Skipping useless range: Pastoral Research Institute
Skipping useless range: France-Telecom Research Center
Skipping useless range: National Australia Bank Limited
Skipping useless range: FactSet Research Corp
Skipping useless range: Bayer CropScience, Lyon
Skipping useless range: DHL Systems
Skipping useless range: Pepsi-Cola International
Skipping useless range: JP Morgan
Skipping useless range: KODAK POLYCHROME GRAPHICS
Skipping useless range: Bank of America - Croydon
Skipping useless range: Bank of America
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Schlumberger
Skipping useless range: Hudson Bay Mining and Smelting Co., Limited
Skipping useless range: Rockwell Automation Power Systems
Skipping useless range: Verifone
Skipping useless range: Verifone
Skipping useless range: Verifone
Skipping useless range: Verifone
Skipping useless range: Verifone
Skipping useless range: Verifone
Skipping useless range: Comsat Laboratories
Merged range 'Electrotechnical Laboratory', with range 'Electrotechnical Laboratory'
Skipping useless range: INFONET N.V./S.A
Skipping useless range: Hubrecht Laboratorium
Skipping useless range: Numerical Applications, Inc
Skipping useless range: Stichting Academisch Rekencentrum
Skipping useless range: Stichting Academisch Rekencentrum
Skipping useless range: Delaware Computing Zwevegem
Merged range 'FNET c/o INRIA', with range 'FNET c/o INRIA'
Skipping useless range: Wang Laboratories
Skipping useless range: Emerson Electric Comapany
Skipping useless range: Delaware Computing Zwevegem
Skipping useless range: Royal Bank Of Canada - Trading Division
Skipping useless range: Royal Bank Of Canada - Trading Division
Skipping useless range: Herve Schauer Consultants
Skipping useless range: Delaware Computing Zwevegem
Skipping useless range: Delaware Computing Zwevegem
Skipping useless range: Micromuse Plc
Skipping useless range: INFONET N.V./S.A
Skipping useless range: INFONET N.V./S.A
Skipping useless range: Research Institute of Finnish Economy
Skipping useless range: Research Institute of Amercia
Skipping useless range: Research Institute of Amercia
Skipping useless range: Research Institute of America
Skipping useless range: Hitachi America, Ltd
Skipping useless range: National Laboratory for High Energy Physics
Skipping useless range: City Bank
Skipping useless range: CitiBank, N.A
Skipping useless range: Citigroup Anycast DNS Network
Skipping useless range: Citigroup CTI EMEA
Skipping useless range: Children's Memorial Medical Center
Skipping useless range: Industrial Research Ltd
Skipping useless range: Medical Center Hospital of Vermont
Skipping useless range: Medical Center Hospital of Vermont
Skipping useless range: Saint Agnes Hospital
Skipping useless range: Harris Corp
Skipping useless range: Harris Corp
Skipping useless range: Schering-Plough Research Institute
Skipping useless range: United Technologies Research Center
Skipping useless range: United Technologies Research Center
Skipping useless range: State Street Bank
Skipping useless range: State Street Bank
Skipping useless range: Advanced Processing Laboratories, Inc
Skipping useless range: Advanced Processing Laboratories, Inc
Skipping useless range: Research and Academic Networks in Poland
Skipping useless range: Aichwalder Michael
Skipping useless range: Mannheimer Morgen Grossdruckerei und Verlag GmbH
Skipping useless range: SUMITOMO SHI CYCLO DRIVE GERMANY GMBH
Skipping useless range: Schut
Skipping useless range: RTL Television
Skipping useless range: Istituto Nazionale per la Fisica della Materia Uni
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: GETRONICS FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: SITA CENTRE OUEST
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: FP2
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: Canon Research Centre - France
Skipping useless range: FR-RAEI-CGP-FILM-SAS-FWVPN
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: CENTRE ACCUEIL ET PROMOTION BLANQUEFOR
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: Banque de France
Skipping useless range: SITA FRANCE
Skipping useless range: Sita
Skipping useless range: MATRA DATAVISION
Skipping useless range: GLOBAL CONCEPT FINANCE
Skipping useless range: Alcatel Business Systems
Skipping useless range: DATA SERVICES GROUP
Skipping useless range: CLINIQUE MEDICALE PORTE VERTE
Skipping useless range: Ericsson France
Skipping useless range: ASSISTANCES MEDICALES SPECIALISEES
Skipping useless range: CLINIQUE DE LA RAVINE
Skipping useless range: ALCATEL CIT TND SCO
Skipping useless range: ALCATEL RESEAUX D ENTREPRISE
Skipping useless range: DIR REG SERVICE MEDICAL
Skipping useless range: AGENCE MARITIME DE L OUEST
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: BCV FINANCE
Skipping useless range: FINANCE ET GESTION
Skipping useless range: HOPITAL PRIVE MAISON DE RETRAITE
Skipping useless range: HITACHI POWER TOOLS FRANCE SA
Skipping useless range: Canon Research Centre - France
Skipping useless range: CENTRALE SIDERURGIQUE DE RICHEMONT S A
Skipping useless range: BANQUE DE FRANCE
Skipping useless range: Banque de France
Skipping useless range: Geac Computers France SA
Skipping useless range: DUPONT D ISIGNY
Skipping useless range: BANQUE PRIVEE QUILVEST
Skipping useless range: Banque Indosuez
Skipping useless range: Roche Image Analysis Systems
Skipping useless range: SITA FRANCE
Skipping useless range: ALCATEL BUSINESS SYSTEMS
Skipping useless range: POISIER FINANCE TE INDUSTRIE
Skipping useless range: HOPITAL LOCAL
Skipping useless range: ALCATEL
Skipping useless range: ALCATEL
Skipping useless range: Hopital Ambroise Pare
Skipping useless range: Hopital De Fourviere
Skipping useless range: Cliniques Privees Associees
Skipping useless range: Hopital J Leclaire
Skipping useless range: HOPITAL LA CHATRE
Skipping useless range: POLYCLINIQUE-DE-RILLIEUX
Skipping useless range: Banque de France
Skipping useless range: SERVICE-MEDICAL-INTERENTREPRISE
Skipping useless range: SMC PNEUMATIQUE FRANCE SA
Skipping useless range: Omniun Maritime
Skipping useless range: ALCATEL SPACE INDUSTRIES
Skipping useless range: HOPITAL DE SAINT PIERRE
Skipping useless range: ROSENBLUTH INTERNATIONAL
Skipping useless range: Hopital de Jouars Ponchartrain
Skipping useless range: Centre Medical Rey Leroux
Skipping useless range: HOPITAL LE MONTAIGU
Skipping useless range: BELLECOUR MUSIQUES
Skipping useless range: THALES INFORMATION SYSTEMS
Skipping useless range: LABORATOIRES FUJI
Skipping useless range: LA BROSSE ET DUPONT
Skipping useless range: HOPITAL SAINT LAURENT DU PONT
Skipping useless range: RAD FRANCE
Skipping useless range: MUTUELLE CHIRURGICALE MEDICALE
Skipping useless range: FUJI ELECTRIC
Skipping useless range: CLINIQUE DE LA SAUVEGARDE
Skipping useless range: SIETEL MIDI TELECOM
Skipping useless range: DCI
Skipping useless range: QUANTA MEDICAL
Skipping useless range: IFN FINANCE
Skipping useless range: IN TECH MEDICAL
Skipping useless range: BANQUE SAINT OLIVE
Skipping useless range: DEBIS FINANCEMENT
Skipping useless range: CARTOTHEQUE
Skipping useless range: Hopital Paul Desbief
Skipping useless range: Hia Hopital Inter Armee
Skipping useless range: Polyclinique des Longues Allees
Skipping useless range: Hopital Marechal Leclerc
Skipping useless range: Hopital de Montdidier
Skipping useless range: Acanthe Software
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: FUJIFILM NET
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: POLYCLINIQUE MAJORELLE
Skipping useless range: Crystal Finance
Skipping useless range: Institut Franco Americain
Skipping useless range: Alcatel TITN Answare
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: GARONNE ANIMATION
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: SYNTHELABO Recherche - Pharmaceutical Research
Skipping useless range: Steiermaerkische Krankenanstalten
Skipping useless range: Ericsson Schrack BusinessCom AG
Skipping useless range: Ericsson Schrack BusinessCom AG
Skipping useless range: TRANSPAC / CE LNS RSCOOT DANS VRF
Skipping useless range: Federation Maritime
Skipping useless range: DIR REGIONALE DU SERVICE MEDICAL
Skipping useless range: Finance Ocean
Skipping useless range: REGUS-HOCHE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-QUADRIGA-FRANCE-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ALCATEL RE BAIE MAHAULT
Skipping useless range: FUJI-MEDICAL-SYSTEMES-FRANCE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: France Telecom E-Business LAN
Skipping useless range: POLYCOM-CHEZ-FT-GLOBALCAST
Skipping useless range: SUMITOMO ELECTRIC - ENX GALIA
Skipping useless range: INFOMEDIA MC
Skipping useless range: FTIP002776583 Nortel Networks
Skipping useless range: FTIP002768465 LogicaCMG for OFSTED
Skipping useless range: FTIP002734187 Sykes Europe Ltd
Skipping useless range: FTIP002884097 Ericsson Ltd
Skipping useless range: FTIP002732329 First Choice Holidays Plc
Skipping useless range: Quest International
Skipping useless range: FTIP002731728 Regus UK Ltd
Skipping useless range: FTIP002698670 Ingram Micro UK Ltd
Skipping useless range: Mitsubishi Electric Ltd
Skipping useless range: FTIP002781747 Aquitec UK Ltd
Skipping useless range: Gottex Financial Products Ltd
Skipping useless range: Fimat International Banque SA
Skipping useless range: FTIP002756677 Pitney Bowes
Skipping useless range: Nortel Ltd
Skipping useless range: FTIP002724478 ICC Information Systems
Skipping useless range: R R Donnelley and Sons Co
Skipping useless range: H.H Saudi Research and Marketing
Skipping useless range: FTIP002724461 ICC Information Systems
Skipping useless range: ICC Information Group
Skipping useless range: Kodak Ltd
Skipping useless range: Fuji Photo Film Limited
Skipping useless range: MITSUBISHI_PENCIL_CO
Skipping useless range: Link Strategic Research Uk Ltd
Skipping useless range: Micromode Medical Ltd
Skipping useless range: FTIP002439044 Financial Ombudsman
Skipping useless range: Regus UK Hammersmith
Skipping useless range: FTIP002748801 Blease Medical Ltd
Skipping useless range: Regus UK Lloyds Building
Skipping useless range: Regus UK Canary Wharf
Skipping useless range: Santander Investment S.A
Skipping useless range: FTIP002746036 Netcraft Limited
Skipping useless range: Regus UK The Quorum
Skipping useless range: FTIP002760865 First Choice Holidays Plc
Skipping useless range: Digital Domain S.L
Skipping useless range: Btn Global Solutions
Skipping useless range: Fuji Photo Film (UK) Ltd
Skipping useless range: Btn Global Solutions
Skipping useless range: Mannesmann Dematic
Skipping useless range: Pfizer Ltd
Skipping useless range: FTIP002696041 Adviserplus Bus Solutions Ltd
Skipping useless range: FTIP002698571 Piazza Financial Services Ltd
Skipping useless range: FTIP002698465 Cabot Financial Ltd
Skipping useless range: FTIP000024174 Regus UK Berkley Square
Skipping useless range: FTIP002701486 Lifeboat Financial Group Ltd
Skipping useless range: Clerical Medical Investment Management Ltd
Skipping useless range: Fuji International Ltd
Skipping useless range: BT Systems Integration
Skipping useless range: HH Saudi Research and Merketing
Skipping useless range: FTIP002768465 LogicaCMG for OFSTED
Skipping useless range: FTIP002847542 Littelfuse UK Ltd
Skipping useless range: Financial Services Authority
Skipping useless range: FUJISEAL EUROPE LTD
Skipping useless range: Fujiseal Europe Limited
Skipping useless range: MCCANN ERICKSON MANCHESTER
Skipping useless range: Verilab_Ltd
Skipping useless range: BT-Global-Services
Skipping useless range: Btn Global Solutions
Skipping useless range: BT-Ignite
Skipping useless range: BT-Ignite
Skipping useless range: BT-Ignite
Skipping useless range: New IT Solutions Ltd
Skipping useless range: Regus UK Clarendon Road Watford
Skipping useless range: FTIP002865447 Hereford Hospitals NHS Trust
Skipping useless range: FTIP002865614 Kazimir Partners UK Ltd
Skipping useless range: FTIP002865690 East Midland Central Station Ltd
Skipping useless range: FTIP002865768 Zibrant
Skipping useless range: Regus UK Watford
Skipping useless range: Regus UK Whitehill Way
Skipping useless range: Regus UK Old Broad Street
Skipping useless range: Regus UK Reading Arlington Business Park
Skipping useless range: Regus UK London Berkeley Square
Skipping useless range: Regus UK Maidenhead Albany House
Skipping useless range: Regus UK London Liverpool Street
Skipping useless range: Regus UK London Poultry
Skipping useless range: CLERICAL MEDICAL INVESTMENT
Skipping useless range: FTIP002774657 Business Environment Group
Skipping useless range: BT-Ignite
Skipping useless range: Regus UK Ancells Business Park Fleet
Skipping useless range: Regus-St-James
Skipping useless range: FTIP002862828 HCL BPO Services Ltd
Skipping useless range: FTIP002862958 HCL BPO Services Ltd
Skipping useless range: BT-Ignite
Skipping useless range: FTIP002865836 Scottish RE Ltd
Skipping useless range: FTIP002865904 United Kingdom Accreditation Service
Skipping useless range: FTIP002760865 First Choice Holidays PLC
Skipping useless range: Westbourne_Hygiene_and_Medical_Ltd
Skipping useless range: Hitachi Power Tools Belgium
Skipping useless range: DAEWOO
Skipping useless range: Infonetwork
Skipping useless range: DAEWOO AUTOMOBILE ROMANIA SA
Skipping useless range: The Lincoln Electric Company
Skipping useless range: The Aerospace Corporation
Skipping useless range: Hitachi Electronic Devices Singapore) Pte Ltd
Skipping useless range: Powerchip Semiconductor Corporation
Skipping useless range: SAE Magnetics (H.K.) Ltd
Skipping useless range: Hitachi Nippon Steel Semiconductor
Skipping useless range: Hitachi Consumer Products (M) Sdn. Bhd
Skipping useless range: National University Hospital
Skipping useless range: Matsushita-Wanbao (Guangzhou)Airconditioner Co.Ltd
Skipping useless range: National Cancer Centre
Skipping useless range: Sharp Corporation of Australia Pty Ltd
Skipping useless range: Bank of Queensland Limited
Skipping useless range: Ascena Information Technology GmbH
Skipping useless range: The Sumitomo Trust and Banking Company, Limited
Skipping useless range: Banco Bradesco S.A
Skipping useless range: Executone Information Systems
Skipping useless range: CDI Corporation
Skipping useless range: Borg Warner Transmission
Skipping useless range: Ericsson Telecomunicacoes S.A
Skipping useless range: Deutsches Krebsforschungszentrum
Skipping useless range: Mitteldeutscher Rundfunk (MDR)
Skipping useless range: European Bank for Reconstruction and Development
Skipping useless range: Bayerische Landesbank
Skipping useless range: CoCreate Software GmbH
Skipping useless range: Sybron Laboratory Products Corp
Skipping useless range: Lambrakis Press Organization S.A
Skipping useless range: Lambrakis Press Organization S.A
Skipping useless range: Lambrakis Press Organization S.A
Skipping useless range: Landesbank Schleswig-Holstein Girozentrale
Skipping useless range: A.oe. Krankenhaus Waidhofen a.d. Thaya
Skipping useless range: Dover Elevator International, Inc
Skipping useless range: Hamburgische Landesbank
Skipping useless range: Hessischer Rundfunk (hr)
Skipping useless range: Chiron Diagnostics Corporation
Skipping useless range: Fuji Photo Film (UK) Ltd
Skipping useless range: Pepsi-Cola General Bottlers Sp. z o.o
Skipping useless range: GRISET SA
Skipping useless range: Banco Nacional de Angola
Skipping useless range: Hitachi Europe Ltd
Skipping useless range: PFIZER ITALIANA S.p.A
Skipping useless range: Landesbank Schleswig-Holstein Girozentrale
Skipping useless range: Genex S.A
Skipping useless range: The Cyprus Import Corporation
Skipping useless range: Lambrakis Press Organization S.A
Skipping useless range: Pioneer Electronics Benelux B.V
Skipping useless range: ZDF Zweites Deutsches Fernsehen
Skipping useless range: Spitalstiftung Klinikum Konstanz
Skipping useless range: Diehl Informatik GmbH
Skipping useless range: Hamburgische Landesbank
Skipping useless range: Landesbank Schleswig-Holstein Girozentrale
Skipping useless range: Alcatel Kabel Norge AS
Skipping useless range: Pfizer GmbH
Skipping useless range: Borg-Warner Automotive GmbH
Skipping useless range: Bayerische Landesbank
Skipping useless range: Samsung Heavy Industries
Skipping useless range: Arthur Andersen
Skipping useless range: C.H. Beck\
Skipping useless range: Landesgesundheitsamt Baden-Wuerttemberg
Skipping useless range: National Westminster Bank plc
Skipping useless range: PIONEER ELECTRONICS DEUTSCHLAND GmbH
Skipping useless range: Hessischer Rundfunk (hr)
Skipping useless range: Alcatel Contracting Benelux SA
Skipping useless range: Samsung Electronics (UK) Ltd
Skipping useless range: adidas AG
Skipping useless range: Landesbank Hessen Thueringen Girozentrale
Skipping useless range: ProCon GmbH
Skipping useless range: Fuji Photo Film BV
Skipping useless range: KPMG Deutsche Treuhand-Gesellschaft
Skipping useless range: Norddeutscher Rundfunk Anstalt d. oeffentl. Rechts
Skipping useless range: BDL Banco di Lugano
Skipping useless range: Analyst Ltd
Skipping useless range: Raintree Systems, Inc
Skipping useless range: office
Skipping useless range: AS Gennet Laboratories
Skipping useless range: Enron Corp
Skipping useless range: Calderdale Healthcare NHS Trust
Skipping useless range: ONYX Customer 40 Integrated Silicon Systems
Skipping useless range: Invicta Communtity Care NHS Trust (RR3)
Skipping useless range: Hampshire Shared Financial Services
Skipping useless range: Leicester and Rutland Healthcare NHS Trust
Skipping useless range: Chesterfield Royal Hospital (NHS Trust)
Skipping useless range: Chesterfield Royal Hospital (NHS Trust)
Skipping useless range: Dawlish Medical Group, Devon EX7 9QH
Skipping useless range: Bassetlaw Hospital and Commuity Services NHS Trust
Skipping useless range: Doncaster Royal Infirmary and Montagu Hospital NHS Trust
Skipping useless range: Mid Essex Community & Mental Health NHS Trust
Skipping useless range: The Homerton Hospital NHS Trust
Skipping useless range: Bradford Hospitals NHS Trust Bradford Royal Infirmary
Skipping useless range: North Worcester Health Authority
Skipping useless range: North Staffs Combined Healthcare NHS Trust
Skipping useless range: Dudley Priority Health NHS Trust
Skipping useless range: Network of St Jude Medical
Skipping useless range: Network of Pharmaceutical Research Associates
Skipping useless range: Network of Pharmaceutical Research Associates
Skipping useless range: LABORATOIRES FUMOUZE
Skipping useless range: BSA BOYER
Skipping useless range: QUANTEL MEDICAL
Skipping useless range: COCREATE SOFTWARE GHBH
Skipping useless range: TIBCO ex GALEODE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: BIOSYM TECHNOLOGIES SARL
Skipping useless range: FR-RAEI-BOUCHARA--RECORDATI-LB_INTERNET
Skipping useless range: SAMSUNG ELECTRONICS FRANCE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: CORDIA
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: Technic Color
Skipping useless range: HOPITAL SAINT JEAN
Skipping useless range: ABC International Bank PLC
Skipping useless range: LABORATOIRES TAKEDA
Skipping useless range: BSA INTERNATIONAL
Skipping useless range: MSG SOFTWARE
Skipping useless range: Hopital Local du Croisic
Skipping useless range: FR-RAEI-NORTEL-NETWORKS-SA-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-ARKEMA-LB_INTERNET
Skipping useless range: COMMERCIALE
Skipping useless range: MITSUBISHI ELECT EUROPE
Skipping useless range: GRISET
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: Amptown Sound & Communication GmbH
Skipping useless range: University Hospital Birmingham NHS Trust
Skipping useless range: CWC Small Addressing for NHSnet
Skipping useless range: Rampton Hospital
Skipping useless range: North East Essex Mental Health NHS Trust
Skipping useless range: Hertfordshire Health Informatics
Skipping useless range: Blackpool Victoria NHS Trust
Skipping useless range: software companies
Skipping useless range: softwarehouse
Skipping useless range: Italian Financial Institution
Skipping useless range: focused on sms - wap - mms - java development for
Skipping useless range: Calligrafix Ltd
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Reseau Regional des Pays de Loire
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Reseau Regional des Pays de Loire
Skipping useless range: INTERWISE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-RECORD-PORTES-AUTOMATIQUES-LB_INTERNET
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: TAK-ASIC
Skipping useless range: INFOMEDIA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Promosoft-informatique
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Laboratoires Garnier
Skipping useless range: OMNIUM MARITIME
Skipping useless range: INFRATEST BURKE
Skipping useless range: COMMERCIALE
Skipping useless range: Laboratoire MENDIHARRAT
Skipping useless range: MSC SOFTWARE
Skipping useless range: Alpha Mosa
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: CORSICAN CALL CENTER COM
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: LEO LAGRANGE ANIMATION
Skipping useless range: COMPAGNIE MARITIME MARFRET
Skipping useless range: HOPITAL RURAL DU FRANCOIS
Skipping useless range: HOPITAL DU FRANCOIS
Skipping useless range: HOPITAL ROMAIN BLONDET
Skipping useless range: HOPITAL DU LAMENTIN
Skipping useless range: HOPITAL ROMAIN BLONDET
Skipping useless range: COMPAGNIE MARITIME MARFRET
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: EGDA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Institut Francais de l\'Environnement
Skipping useless range: FR-RAEI-CGP-FILM-SAS-CLBS2
Skipping useless range: LABORATOIRE D'ANALYSE
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ERICSSON MASSY
Skipping useless range: ERICSSON MASSY
Skipping useless range: CLINIQUE
Skipping useless range: Maag Pump Systems Textron
Skipping useless range: CENTRE MEDICAL F BEZANCON
Skipping useless range: arista
Skipping useless range: QuadrigaFrance
Skipping useless range: FR-RAEI-CGP-FILM-SAS-CLBS2
Skipping useless range: SOC EXPERTISE COMPTABLE CABINET DUPONT
Skipping useless range: MEDIA SYNAPSE
Skipping useless range: LABORATOIRE ANALYSES ETUDES INDUSTR
Skipping useless range: OBTECH MEDICAL FRANCE
Skipping useless range: HOPITAL LOCAL DE PRADES
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: EUROPRISME MEDICAL
Skipping useless range: Clinique Du Cedre
Skipping useless range: INTERWISE
Skipping useless range: FR-RAEI-CGP-FILM-SAS-CLBS2
Skipping useless range: KCI EQUIPEMENT MEDICAL
Skipping useless range: ALCATEL COUTANCES
Skipping useless range: FEELING SOFTWARE
Skipping useless range: ALCATEL COUTANCES
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: WITBE
Skipping useless range: LABORATOIRES FUJIFILM
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ACCESS-IT
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: FR-RAEI-CGP-FILM-SAS-ARCC1
Skipping useless range: CENTRE HOSPITALIER INTERCOMMU
Skipping useless range: SEISME
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-DENON-FRANCE-LB_INTERNET
Skipping useless range: RESEAU REGIONAL DE BRETAGNE
Skipping useless range: MATRA NORTEL COMMUNICATIONS
Skipping useless range: SPRINGGROVE
Skipping useless range: DESOMEARAPARTNERS
Skipping useless range: NATH-BROS-STSTEPHENSGREEN
Skipping useless range: TRINITYVENTURECAPITAL
Skipping useless range: MCGANNASSOCIATESLTD
Skipping useless range: Network of Dr. Joachim Schmidt GmbH & Co
Skipping useless range: Institut Francais de Bucharest
Skipping useless range: Articon Integralis
Skipping useless range: Network of MerrillLynch
Skipping useless range: Network of AT&T Managed Firewall Service - AT&T Internal
Skipping useless range: Network of Pharmaceutical Research Associates, In
Skipping useless range: Network of GUIDANT GmbH
Skipping useless range: Network of Guidant GmbH & Co. Medizintechnik KG
Skipping useless range: Network of Citibank Privatkunden AG
Skipping useless range: Network of Underwriters Laboratories
Skipping useless range: Network of Underwriter Labs
Skipping useless range: Network of Coca-Cola Services SA
Skipping useless range: Network of Adelphi Group Ltd
Skipping useless range: Network of J&J Medical
Skipping useless range: Network of Guidant Sweden AB
Skipping useless range: Network of AT&T Managed Services
Skipping useless range: Network of Matsushita Avionics
Skipping useless range: Network of Matsushita Avionics
Skipping useless range: Network of ARD Alman Televizyonu
Skipping useless range: Network of Ericsson
Skipping useless range: Network of Guidant CORPORATION
Skipping useless range: Network of AT&T Managed Firewall Network
Skipping useless range: Network of ERICSSON GLOBAL IT SERVICES AB
Skipping useless range: Network of HEIDELBERGER DRUCKMASCHINEN AG
Skipping useless range: Network of Zoll Medical Corporation
Skipping useless range: Network of EQUIFAX
Skipping useless range: Network of Abbott Laboratories
Skipping useless range: Network of Guidant Corporation
Skipping useless range: Network of Fuji Hunt Photograph Chem Ltd
Skipping useless range: Network of Pfizer UK Ltd
Skipping useless range: Network of FUJI Hunt IN
Skipping useless range: Network of FUJI Hunt In
Skipping useless range: Network of Konica Business Machines
Skipping useless range: Network of Fuji Hunt In
Skipping useless range: Network of Polycom
Skipping useless range: Regus UK Hillswood Drive Chertsey
Skipping useless range: Merrill Lynch HSBC Ltd
Skipping useless range: Regus UK Liverpool St London
Skipping useless range: Regus UK Leatherhead
Skipping useless range: Bank Of Tokyo Mitsubishi Ltd
Skipping useless range: FTIP002868752 DST International Ltd
Skipping useless range: BT Systems Integration
Skipping useless range: Regus UK
Skipping useless range: BT Systems Integration
Skipping useless range: BT Systems Integration
Skipping useless range: BT Systems Integration
Skipping useless range: FTIP002874234 Ericsson Ltd
Skipping useless range: BT-Ignite
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: Customer Interconnection with RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: FR-RAEI-GRISET-MATERIEL-FWVPN
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: ERICSSON-SA
Skipping useless range: GI - Customer Interconnexion With RAEI Backbone
Skipping useless range: LABORATOIRE FUJIFILM
Skipping useless range: A2I SOFTWARE IVELEM
Skipping useless range: Cyber Studio
Skipping useless range: DISTRI CLUB MEDICAL
Skipping useless range: MITSUBISHI ELECTRIC FRANCE
Skipping useless range: RESEAU REGIONAL DE BRETAGNE
Skipping useless range: Columbus IT Partner
Skipping useless range: SITA
Skipping useless range: Alcatel Space
Skipping useless range: ARTHUR ANDERSEN
Skipping useless range: Bd Multimedia
Skipping useless range: AGENCES MARITIMES POMME
Skipping useless range: Alcatel Space
Skipping useless range: SYSTONIC
Skipping useless range: MCKESSONHBOC
Skipping useless range: SCHOLLER
Skipping useless range: Alcatel
Skipping useless range: EDIXIA
Skipping useless range: mac dermid graphic arts
Skipping useless range: CREDIT LYONNAIS DCMC
Skipping useless range: The Dudley Group of Hospitals NHS Trust
Skipping useless range: Westmorland Hospitals NHS Trust
Skipping useless range: Walsall Hospitals NHS Trust
Skipping useless range: The Princess Royal Hospital NHS Trust
Skipping useless range: Birmingham Heartlands Hospital NHS Trust
Skipping useless range: West Pennine Health Authority
Skipping useless range: North West London Hospital NHS Trust
Skipping useless range: The Glenfield Hospital NHS Trust
Skipping useless range: Kings College Hospital NHS Trust
Skipping useless range: Blackpool Wyre and Fylde Community Health Services NHS Trust
Skipping useless range: Sheffield Childrens Hospital
Skipping useless range: Royal Liverpool Childrens Hospital NHS Trust
Skipping useless range: Central Sheffield University Hospitals NHS Trust
Skipping useless range: Northern General Hospital NHS Trust
Skipping useless range: C82009 - Market Harborough Medical Centre
Skipping useless range: Blackpool Wyre and Fylde Community Health Services NHS Trust
Skipping useless range: C82038 - Latham House Medical Centre
Skipping useless range: Southport and Ormskirk Hospital NHS Trust
Skipping useless range: The Princess Alexandra Hospital NHS Trust
Skipping useless range: Mid Cheshire Hospitals NHS Trust
Skipping useless range: West Dorset General Hospitals NHS Trust
Skipping useless range: Warrington Community Healthcare NHS Trust
Skipping useless range: Sheffield Children's Hospital NHS Trust
Skipping useless range: Ashford and St. Peters Hospital NHS Trust
Skipping useless range: Birmingham Childrens Hospital NHS Trust
Skipping useless range: Diehl Informatik GmbH
Skipping useless range: Fuji Photo Film (Ireland) Ltd
Skipping useless range: Deutsche Bank AG
Skipping useless range: Arthur Andersen LLP
Skipping useless range: Suedwestdeutsche Landesbank Girozentrale
Skipping useless range: AOL SPAIN - PRODIGIOS INTERACTIVOS, S.A
Skipping useless range: Hitachi Nippon Steel Semiconductor
Skipping useless range: Hitachi Consumer Products (M) Sdn. Bhd
Skipping useless range: Reutlinger General-Anzeiger Verlags-GmbH &amp; Co
Skipping useless range: MITSUBISHI ELECTRIC FRANCE
Skipping useless range: STRATEGY CONSULTORS
Skipping useless range: Institut f. Arbeits- und Sozialhygiene Stiftung
Skipping useless range: Mitsubishi Silicon America
Skipping useless range: KPMG Peat Marwick LLP
Skipping useless range: United Technologies Pratt & Whitney, East Hartford
Skipping useless range: McCann-Erickson Service
Skipping useless range: Rotes Kreuz Krankenhaus
Skipping useless range: Fresenius Austral/Asia Pty Ltd
Skipping useless range: Health Services Australia Limited
Skipping useless range: Commonwealth Bank of Australia
Skipping useless range: Telefonbuch Verlag Hans Mueller GmbH &amp; Co., Nu
Skipping useless range: Suedwestdeutsche Landesbank Girozentrale
Skipping useless range: Deutsche Bank AG, Eschborn
Skipping useless range: MITSUBISHI ELECTRIC FRANCE
Skipping useless range: Eigenbetriebe Bezirkskrankenhaeuser und Heime
Skipping useless range: Oesterreichische Nationalbank
Skipping useless range: Maerkisches.Verlags.und.Druckhaus.GmbH.Co.KG.DE
Skipping useless range: IIT Institut fuer Informationstechnologien
Skipping useless range: Maerkische Verlags- und Druck-GmbH
Skipping useless range: HITACHI COMPUTER PRODUCTS SA
Skipping useless range: Israel Discount Bank Ltd
Skipping useless range: Deutsche Bank S.p.A
Skipping useless range: MycroStrategy
Skipping useless range: Crypto AG
Skipping useless range: Mitsubishi Electric Europe Ltd
Skipping useless range: OSI SOFTWARE Objects BVBA
Skipping useless range: Mitsubishi HiTec Paper Flensburg GmbH
Skipping useless range: SWR Suedwestrundfunk
Skipping useless range: Oxford University Press
Skipping useless range: DELOITTE CONSULTING, S.L
Skipping useless range: KPMG Management Consulting N.V
Skipping useless range: Thomson Industries, Inc
Skipping useless range: Makro de Colombia,S.A
Skipping useless range: Wells Fargo Bank
Skipping useless range: Pioneer North America Inc
Skipping useless range: Schlumberger Ltd
Skipping useless range: Nexen Inc
Skipping useless range: Thin Film Technology
Skipping useless range: Citrix Systems, Inc
Skipping useless range: Le Groupe Videotron Ltee
Skipping useless range: United Technologies Pratt & Whitney, East Hartford
Skipping useless range: KPMG Peat Marwick LLP
Skipping useless range: Arthur Andersen L.L.P
Skipping useless range: Aerov=EDas Nacionales de Colombia
Skipping useless range: Executone Information Systems
Skipping useless range: United Technologies Pratt & Whitney
Skipping useless range: Reutlinger General-Anzeiger Verlags-GmbH & Co. KG
Skipping useless range: Deutsche Bank AG
Skipping useless range: United Tech Pratt & Whitney
Skipping useless range: Bath Iron Works Corporation
Skipping useless range: Fluor Corporation
Skipping useless range: Eastman Kodak Company
Skipping useless range: Bristol-Myers Squibb Company
Skipping useless range: Oxford University Press
Skipping useless range: Boston Medical Center
Skipping useless range: UMB Financial Corp
Skipping useless range: Hitachi Data Systems
Skipping useless range: Skipton Business Finance
Skipping useless range: Nortel_Networks
Skipping useless range: Infonet nv/sa
Skipping useless range: KENWOOD
Skipping useless range: Network Solutions
Skipping useless range: Adero
Skipping useless range: Infonet-Srl
Skipping useless range: Network of VeriSign
Skipping useless range: Network of EQUIFAX
Skipping useless range: M-SYSTEMS
Skipping useless range: Infonet nv/sa
Skipping useless range: Infonet nv/sa
Skipping useless range: DELOITTE TOUCHE
Skipping useless range: Kanal Ltd
Skipping useless range: Kath. Krankenhaus Hagen
Skipping useless range: Zahnklinik Medeco
Skipping useless range: Medical Consultants GmbH
Skipping useless range: City Heart Cafe
Skipping useless range: Trust Commercial Bank
Skipping useless range: CH JETTE
Skipping useless range: UNIDATA
Skipping useless range: Dover Elevator Systems, Inc
Skipping useless range: donet Motors
Skipping useless range: Fermi National Accelerator Laboratory
Skipping useless range: BlackLab Inc
Skipping useless range: Nichols Research Corporation
Skipping useless range: Hitachi America, Ltd
Skipping useless range: AVENTIS PASTEUR
Skipping useless range: J.P. Morgan & Co
Skipping useless range: St.Elizabeth's Hospital of Boston
Skipping useless range: St.Elizabeth's Hospital of Boston
Skipping useless range: Environmental Systems Research Institute
Skipping useless range: American Research Group, Inc
Skipping useless range: General Atomic, Fusion User Service Center
Skipping useless range: General Atomic, Fusion User Service Center
Skipping useless range: American Microsystems Inc
Skipping useless range: Seattle VA Hospital General Medical Research
Skipping useless range: DHL Systems, Inc
Skipping useless range: Boston Scientific Corp
Skipping useless range: Agency for Health Care Policy & Research
Skipping useless range: Morgan Stanley, IS Department
Skipping useless range: Salk Institute
Skipping useless range: SC Budget and Control Board, Research and Statisti
Merged range 'S&amp;H Citadel Inc', with range 'Bogon'
Skipping useless range: INFONET Services Corporation
Skipping useless range: Schlumberger
Skipping useless range: DHL Systems
Skipping useless range: DHL Systems
Skipping useless range: DHL Systems
Skipping useless range: DHL Systems
Skipping useless range: footprint software
Skipping useless range: Citigroup Anycast DNS Network
Skipping useless range: Citigroup CTI EMEA
Skipping useless range: Salomon Smith Barney, Inc
Skipping useless range: Citigroup CTI EMEA
Skipping useless range: Citigroup CTI EMEA
Skipping useless range: Remax Power Pro Realty
Skipping useless range: Tekelec
Skipping useless range: Remax Laskin
Skipping useless range: Remax Greenbrier
Skipping useless range: Remax Prestige
Skipping useless range: Research Specialists
Skipping useless range: Virginia Educators Credit Union
Skipping useless range: Remax Affliates Downtown
Skipping useless range: Research Air Flow
Skipping useless range: Remax Central Granby
Skipping useless range: REMAX ALLEGIANCE
Skipping useless range: Friedman Associates
Skipping useless range: AGA Inc
Skipping useless range: Georgia Commerce Bank
Skipping useless range: Childrens Medicine Lawrenceville
Skipping useless range: Virginia Primary Care Assoc
Skipping useless range: Hitachi Electronic Devices, Inc
Skipping useless range: Remax Championship
Skipping useless range: Paramount Financial Group Inc
Skipping useless range: Remax First Choice Hampton Lake
Skipping useless range: Lawyers Mutual Liability Insurance Co. of NC
Skipping useless range: Delaware Technology Park, Inc
Skipping useless range: International Research Institute
Skipping useless range: National Health Laboratories
Skipping useless range: Maui Research and Technology Center
Skipping useless range: KPMG Peat Marwick
Skipping useless range: General Engineering Labs
Merged range 'Banco Del Trabajo', with range 'Banco Del Trabajo'
Merged range 'Banco Mercantil C.A., S.A.C.A.-S.A.I.C.A', with range 'Banco Mercantil C.A., S.A.C.A.-S.A.I.C.A'
Merged range 'TRANSBANK S.A', with range 'TRANSBANK S.A'
Merged range 'TRANSBANK S.A', with range 'TRANSBANK S.A'
Merged range 'BRB - Banco de Brasilia', with range 'BRB - Banco de Brasilia'
Skipping useless range: Office Depot de Mexico S.A
Skipping useless range: Centro de Pesquisas e Desenvolvimento
Skipping useless range: Centro de Pesquisas e Desenvolvimento
Skipping useless range: BANCO DO NORDESTE DO BRASIL S/A
Skipping useless range: Fundacao Cearense de Pesquisa e Cultura
Skipping useless range: Fundacao Cearense de Pesquisa e Cultura
Skipping useless range: Fundaįão de Amparo e Desenvolvimento da Pesquisa
Skipping useless range: INSTITUTO NACIONAL DE PESQUISAS DA AMAZONIA
Skipping useless range: AssociaçÃĢo Rede Nacional de Ensino e Pesquisa
Skipping useless range: Canon Information Systems Research Australia
Skipping useless range: Banque de Tahiti
Skipping useless range: Institut de Recherche et pour le dÃĐveloppement
Skipping useless range: Banque de Tahiti
Skipping useless range: Assigned to "Davlin Software Pvt. Ltd"
Skipping useless range: Envision Network Technologies Pvt Ltd
Skipping useless range: Mainichi Video-Audio System,inc,
Skipping useless range: FUJI AUTOMOBILE INDUSTRY Co.,Ltd
Skipping useless range: Mehta Research Institute
Skipping useless range: TenYes Technologic Co. LTD
Skipping useless range: Center for International Forestry Research
Skipping useless range: Science for Information Technology Network
Skipping useless range: Research and Technology
Skipping useless range: Science for Information Technology Network
Skipping useless range: Union Bank to LISL subnet
Skipping useless range: Bank of Ceylon subnet1
Skipping useless range: Bank of Ceylon subnet2
Skipping useless range: Bank of Ceylon subnet3
Skipping useless range: Union Bank Subnet
Skipping useless range: Bank of Ceylon to LISL subnet
Skipping useless range: Bank of Ceylon
Skipping useless range: Nations Trust Bank
Skipping useless range: Bank Of Ceylon
Skipping useless range: Bank of Ceylon
Skipping useless range: Com Bank
Skipping useless range: Com Bank
Skipping useless range: Com Bank
Skipping useless range: Genesysnet Solution
Skipping useless range: Genesysnet Pvt Ltd
Skipping useless range: Magister Management Universitas Indonesia
Skipping useless range: Ip block for Eagle Financial
Skipping useless range: World Wide Call Center
Skipping useless range: Armstrong - Hilton Limite
Skipping useless range: Philippine Textile Research Institute
Skipping useless range: Philippine Rice Research Institute
Skipping useless range: Philippine Research, Education and
Skipping useless range: DA XING AN LING GONG SHANG BANK
Merged range 'Xiangtan people bank', with range 'XIANGTAN GOVENMENT=20'
Skipping useless range: XIANTAN RENMING BANK
Merged range 'Xiangtan people bank', with range 'XIANGTAN BANK2'
Skipping useless range: Xin xiang economic technology collaborate office,
Skipping useless range: Institute for Astronautics Information
Skipping useless range: BANK OF BARODA
Skipping useless range: MEKLAI FINANCIAL COMMERCIAL SERVICES LTD
Skipping useless range: a medical supply company that has direct access t
Skipping useless range: IT proxy server LAN
Skipping useless range: Medical Solutions (India) Pvt Ltd
Skipping useless range: Genesys Intl Corp. Ltd
Skipping useless range: Sun Pharmaceuticals Limited
Skipping useless range: Unit 3, 3rd Floor, Quadrant A,IL&FS Financial Cen
Skipping useless range: Bank NISP
Skipping useless range: Bank Lippo
Skipping useless range: Uni Financial Reinsurance Services Ltd
Skipping useless range: Bank Islam Malaysia Berhad
Merged range 'Faisal Bank', with range 'M/s. Faysal Bank Limited'
Skipping useless range: Access Intelligence
Skipping useless range: Financial services company
Skipping useless range: Financial Network Services company
Skipping useless range: Financial Services Company
Skipping useless range: Financial Network Services company
Skipping useless range: Financial Services Company
Skipping useless range: Company providing financial services
Skipping useless range: Company providing financial services
Skipping useless range: Financial services company
Skipping useless range: Financial services company
Skipping useless range: Financial services company
Skipping useless range: SimDesign Technology, Sumitomo Electric Hightechs
Skipping useless range: Sanyo Financial Technology Co., Ltd
Skipping useless range: Japan Clinical Laboratories, Inc
Skipping useless range: Japan Clinical Laboratories, Inc
Skipping useless range: Digital Laboratory
Skipping useless range: Japan Clinical Laboratories, Inc
Skipping useless range: TOTTORI SMALL BUSINESS INFORMATIONCENTER
Skipping useless range: TOTTORI MEDICAL CO-OP
Skipping useless range: Kumamoto Marutakai Medical Corporation
Skipping useless range: Japan Red Cross Iiyama Hospital
Skipping useless range: Hitachi Chemical Industrial Materials Company, Ltd
Skipping useless range: KITA-GAS GENEX CO.LTD
Skipping useless range: Mitsubishi Electric Light Machinery
Skipping useless range: MITSUBISHI ELECTRIC LOGISTICS CORPORATION
Skipping useless range: Mitsubishi Electric Co.,Ltd Itami engine plant
Skipping useless range: Sapporo Mitsubishi Electric IndustrialProducts Sal
Skipping useless range: Sapporo Mitsubishi Electric IndustrialProducts Sales Corporation
Skipping useless range: Mitsubishi Electric Light Machinery Sales co
Skipping useless range: Sanin Mitsubishi Electric sales co.ltd
Skipping useless range: Mitsubishi Electric Light Machinercy Sales CO
Skipping useless range: Mitsubishi Electric Co.,Ltd Itami engine plant
Skipping useless range: PMET (Foundation for Promotion of Medical)
Skipping useless range: MC Medical Inc
Skipping useless range: TOKAI BUSSAN CO.,LTD
Skipping useless range: Foundation for Promotion of MedicalTraining
Skipping useless range: EC RESEARCH CORP
Skipping useless range: Mitsubishi Electric Home Appliance co,ltd
Skipping useless range: Tokyo-Mitsubishi Securities Co.,Ltd
Skipping useless range: MITSUBISHI RESEARCH INSTITUTE, INC
Skipping useless range: MITSUBISHI ELECTRICS LOGISTICS .CO.,LTD
Skipping useless range: Macquarie Bank Ltd (3140)
Skipping useless range: IBJ Australia Bank (130872)
Skipping useless range: Monitor Money P/L (7597)
Skipping useless range: Guardian Business Laboratories P/L (135231)
Skipping useless range: Guardian Business Laboratories P/L (130495)
Skipping useless range: Mitsui OSK Lines (Australia) Pty Ltd
Skipping useless range: Acer Corporated Co., Ltd
Skipping useless range: Acer Corporated Co., Ltd
Skipping useless range: Acer Corporated Co., Ltd
Skipping useless range: Acer Corporated Co., Ltd
Skipping useless range: Acer Corporated Co., Ltd
Merged range 'Fidelity Investments Taiwan Co.,Ltd', with range 'FIDELITY INVESTMENTS TAIWAN.,LTD'
Merged range 'AUSTRALIAN SOCIETY OF CPA', with range 'AUSTRALIAN SOCIETY OF CPAS'
Skipping useless range: Computer science development joint stock company
Skipping useless range: Cendant HWI Pte Ltd
Skipping useless range: Genesys International Corporation
Skipping useless range: Genesys International Corporation
Skipping useless range: S. P. Jain Institute of Management & Research
Skipping useless range: S. P. Jain Institute of Management & Research
Skipping useless range: S. P. Jain Institute of Management & Research
Skipping useless range: Sun Pharmaceuticals Limited
Skipping useless range: Sun Pharmaceuticals Limited
Skipping useless range: Sun Pharmaceuticals Limited
Skipping useless range: JM Morgan Stanley Retail Services Pvt. Ltd.,
Skipping useless range: Phoenix Shares And Stock Brokers Pvt. Ltd
Skipping useless range: The Credit Rating Information Of India Ltd
Skipping useless range: HDFC Bank Ltd
Skipping useless range: Tata Finance Ltd
Skipping useless range: Deloitte Haskins & Sells,
Skipping useless range: LG Electronic Limited
Skipping useless range: Schlumberger Asia Services Ltd
Skipping useless range: International Development Research Centre
Skipping useless range: Interactive Infonet
Skipping useless range: Finance Bureau
Skipping useless range: Bank of Thailand
Skipping useless range: Banque De International Limited
Skipping useless range: Sumitomo Nacco
Skipping useless range: Bank of Thailand
Skipping useless range: American Express
Skipping useless range: CITI BANK N.A
Skipping useless range: Urban Bank
Skipping useless range: Bank of Commerce
Skipping useless range: Diversified Financial News Network
Skipping useless range: CANADIAN EASTERN FINANCE LTD
Skipping useless range: MEDICAL TRANSCRIPTION COMPANY IN BANGALORE
Skipping useless range: ITA Group
Skipping useless range: NATIONAL SEMI
Skipping useless range: NATIONAL SEMI
Skipping useless range: NATIONAL SEMI
Skipping useless range: Boulder Research Associates
Skipping useless range: Monitor Labs - Englewood (MONITORLABS-DOM)
Skipping useless range: Information Management Research, Inc
Skipping useless range: Medical Management Solutions, Inc
Skipping useless range: ARDA, Inc (ARDA-DOM)
Skipping useless range: Benefit Street
Skipping useless range: MSI Medical
Skipping useless range: Right Management Consultants
Skipping useless range: UMMG/AFCA
Merged range 'Reptilian Research', with range 'Reptilian Research'
Skipping useless range: Guidant
Skipping useless range: KS CBS TRANSIT
Skipping useless range: Syracuse Research Corp
Skipping useless range: DuPont Experimental Station
Skipping useless range: Medical Society of Delaware
Skipping useless range: INTERAMERICA
Skipping useless range: INTERAMERICA
Skipping useless range: MINOT CHRY CENTER
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: FASTNET Corporation
Skipping useless range: Financial Consumer Agency of Canada
Skipping useless range: USLEC Corp
Skipping useless range: USLEC Corp
Skipping useless range: USLEC Corp
Skipping useless range: Infoseek Corporation
Skipping useless range: SUNY Research Foundation, Buffalo State College - CDHS
Skipping useless range: Nysernet/Suny Institute of Technology-Utica
Skipping useless range: Nysernet/Suny Health Science Center at Brooklyn
Skipping useless range: nysernet/moore computer consultants inc
Skipping useless range: nysernet/Canandaigua National Bank
Skipping useless range: Amadeus Multimedia Technologies
Skipping useless range: SITA
Skipping useless range: GUIDANT
Skipping useless range: GUIDANT
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: GUIDANT
Skipping useless range: GUIDANT
Skipping useless range: GUIDANT
Skipping useless range: Panther Express Corp
Skipping useless range: Gillette Global Network
Skipping useless range: Trump Organization
Skipping useless range: Trump Organization
Skipping useless range: USLEC Corp
Skipping useless range: USLEC Corp
Skipping useless range: USLEC Corp
Skipping useless range: Applied Business Software
Skipping useless range: Remax Garden City
Skipping useless range: Mitsubishi
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Infonet - Teleglobe
Skipping useless range: Infonet Engineering
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Infonet Engineering Lab
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: MITSUBISHI
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: SUNGARD
Skipping useless range: Infonet Engineering
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Infonet Internal Engineering
Skipping useless range: Infonet-Beru
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: M-SYSTEMS
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Mitsubishi
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Infonet Branch Office
Skipping useless range: NALCO/EXXON
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Infonet Perspexion
Skipping useless range: TRIDENT
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: AVTEC Inc
Skipping useless range: Mitsui OSK Lines
Skipping useless range: Hallmark Cards Inc
Skipping useless range: Medical Net Inc
Skipping useless range: Business Resource & Technology
Skipping useless range: Hallmark Cards Inc
Skipping useless range: AT&T EasyCommerce Services (Lincroft Site)
Skipping useless range: Hallmark Cards Inc
Skipping useless range: Holden Corporation
Skipping useless range: K P M G
Skipping useless range: Financial Management Network
Skipping useless range: Whitman, Requardt And Associates L L P
Skipping useless range: Republic Bank Of Chicago
Skipping useless range: Inland Federal Credit Union
Skipping useless range: Michigan Research
Skipping useless range: Federal Life Insurance
Skipping useless range: Medical Benevolence Foundation
Skipping useless range: USLEC Corp
Skipping useless range: PAETEC COMMUNICATIONS
Skipping useless range: LG GROUP
Skipping useless range: ADWISE
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: Hitachi
Skipping useless range: Chiron Corporation
Skipping useless range: Hitachi
Skipping useless range: Blanchet CPA
Skipping useless range: University Hospital of Augusta
Skipping useless range: Memorial Health Alliance
Skipping useless range: Wesley Long Community Hospital
Skipping useless range: Decatur Memorial Hospital
Skipping useless range: IDP
Skipping useless range: IDP
Skipping useless range: Banta Publications Group
Skipping useless range: Exelon Services
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: Frontline Solutions
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: Old Point Trust Finincial
Skipping useless range: Cook Institute
Skipping useless range: Medical Assistance - Dix
Skipping useless range: Wolfpack
Skipping useless range: Wolfpack
Skipping useless range: nortelntc-ca
Skipping useless range: Ingram Micro
Skipping useless range: cira-ca
Skipping useless range: ReMax Garden
Skipping useless range: Network Solutions (Anne Prosolowski)
Skipping useless range: Canadian Medical Protective Association
Skipping useless range: Nortel Networks (eXtremeVoice)
Skipping useless range: Nortel Networks Tech Corp
Skipping useless range: AOL, AOL Canada, Merrill Lynch HSBC Cand
Skipping useless range: comlabt-ca
Skipping useless range: Remax Executive Realty-Huntersville
Skipping useless range: Blue Cross Blue Shield of North Carolina
Skipping useless range: Blue Cross Blue Shield of North Carolina
Skipping useless range: First National Bank
Skipping useless range: Residence Inn
Skipping useless range: Red Hat Software, Inc
Skipping useless range: RE MAX REAL ESTATE EXECUTIVES
Skipping useless range: Educational Record Center, Inc
Skipping useless range: Cinema Internet Networks
Skipping useless range: EMC Security
Skipping useless range: IMPAQ INTERNATIONAL
Skipping useless range: Comfort Inn
Skipping useless range: Shumate Mechanical
Skipping useless range: Remax Peacetree Midtown
Skipping useless range: Verizon Technology Corp - Atlanta
Skipping useless range: Armstrong Relocation
Skipping useless range: Remax of Atlanta Buford
Skipping useless range: Cadence Technologies Inc
Skipping useless range: Remax Duluth
Skipping useless range: Eastern Cambridge Savings Bank
Skipping useless range: Internet Securities Inc
Skipping useless range: Dyax Corporation
Skipping useless range: Ingram Micro
Skipping useless range: The Mills Corporation
Skipping useless range: Eventcentric
Skipping useless range: K & M Engineering
Skipping useless range: iSuppli
Skipping useless range: MINUTEMAN PRESS
Skipping useless range: Twenty/Twenty Technologies, LLC
Skipping useless range: Manufacturers Alliance
Skipping useless range: Saudi Arabia Airlines
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: INFONET
Skipping useless range: EDI
Skipping useless range: Gilat Ltd
Skipping useless range: GUIDANT
Skipping useless range: LG GROUP
Skipping useless range: KOREA EXCHANGE BANK
Skipping useless range: LG GROUP
Skipping useless range: LG GROUP
Skipping useless range: INFONET
Skipping useless range: LG GROUP
Skipping useless range: LG GROUP
Skipping useless range: LG GROUP
Skipping useless range: Saatchi & Saatchi Business Communication
Skipping useless range: Nysernet/Pinnacle Software
Skipping useless range: Heart Savers, L L C
Skipping useless range: American Megatrends Inc
Skipping useless range: Impact Business Solutions
Skipping useless range: Amazon.com, Inc
Skipping useless range: ns1.fullmeshnetworks.com
Skipping useless range: The Oregon Research Institute
Skipping useless range: Acme research
Skipping useless range: NadBank
Skipping useless range: Hospitality Financial & Tech
Skipping useless range: Communication Certification Laboratory
Skipping useless range: Banta ISG
Skipping useless range: GenLabs, Inc
Skipping useless range: Infonet
Skipping useless range: ROCKWELL
Skipping useless range: CUSHMAN WAKEFIELD
Skipping useless range: Computer Consultants
Skipping useless range: Southwest Research Institute
Skipping useless range: Alloy Surfaces Co, Inc
Skipping useless range: DuPont ESnet
Skipping useless range: DuPont Hardcore Composites
Merged range 'Sprint Managed Network Services', with range 'Sprint Government Systems Division'
Skipping useless range: THE BANKERS BANK
Skipping useless range: First National Bank of Arizona
Skipping useless range: PROVIDENCE FAMILY PRACTICE
Skipping useless range: Needham Family Practice
Skipping useless range: INC Research, Inc
Skipping useless range: CROSS-PROPERTIES
Skipping useless range: MediaX
Skipping useless range: RED HAT , INC
Skipping useless range: Remax Power Pro Realty
Skipping useless range: Miami Fireighters Credit Union
Skipping useless range: Virginia Medical Interventionalist
Skipping useless range: Virginia Asset Management
Skipping useless range: Nysernet/North Country Reference & Research
Skipping useless range: Medical Society of State of New York
Skipping useless range: Mypublisher.com
Skipping useless range: Advanced Technologies Group
Skipping useless range: Advanced Technologies Group
Skipping useless range: Institute of International Bankers
Skipping useless range: O Sullivan Menu Publishing
Skipping useless range: O Sullivan Menu Publishing
Skipping useless range: OSullivan Menu Publishing
Skipping useless range: Andale, Inc
Skipping useless range: First National Bank of Northern California
Skipping useless range: Adelphia Business Solutions
Skipping useless range: LG GROUP
Skipping useless range: HITACHI
Skipping useless range: HITACHI
Skipping useless range: INFONET CHILE
Skipping useless range: Success Strategies Institute (234635-1)
Skipping useless range: Medical Consultants Network
Skipping useless range: GenLabs, Inc
Skipping useless range: ADVANCED BIORESEARCH ASSOCIATES
Skipping useless range: Remax Premier SVC Siesta Key
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: Remax Realty Select.Tamiami
Skipping useless range: Remax Realty Select Pebblebrooke
Skipping useless range: Remax Realty Group Veranda
Skipping useless range: Web Publishing and Development
Skipping useless range: Advanced Media Productions, Inc
Skipping useless range: Convus Corp., Web Publishing Ltd
Skipping useless range: Web Publishing Ltd
Skipping useless range: Aces Research, Inc
Skipping useless range: Advanced Media Productions, Inc
Skipping useless range: Advanced Media Productions, Inc
Skipping useless range: Ensure Technologies Inc
Skipping useless range: POH
Skipping useless range: Advanced Media Productions, Inc
Skipping useless range: Bullet Proof
Skipping useless range: Fuji Creations Inc
Skipping useless range: Odyssey Research
Skipping useless range: Odyssey Research
Skipping useless range: National Information Services Corp
Skipping useless range: Capital Credit Union
Skipping useless range: Dayton T. Brown
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: USLEC
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: Keynote Systems
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: Loki Technologies
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: Garden Savings Federal Credit Union
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: RR Donnelley
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET CORPORATION
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET CORPORATION
Skipping useless range: Lehigh Valley Economic Development Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: USLEC
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: Sungard Pentamation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: FASTNET Corporation
Skipping useless range: MITSUI O.S.K
Skipping useless range: MITSUI O.S.K
Skipping useless range: MITSUI OSK
Skipping useless range: MITSUBISHI
Skipping useless range: BANK OF TOKYO-MITSUBISHI
Skipping useless range: MITSUBISHI
Skipping useless range: MITSUBISHI
Skipping useless range: HITACHI
Skipping useless range: INFONET-WDC3
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET DIAL MEXICO
Skipping useless range: GUIDANT - TEMECULA
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET IMS WHOLESALE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET DIAL BRAZIL
Skipping useless range: INFONET NTC RESERVE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET DIAL SEATTLE
Skipping useless range: INFONET LAX
Skipping useless range: TRANSPORTATION MARITIME
Skipping useless range: INFONET DIAL HONG KONG
Skipping useless range: INFONET DIAL MELBOURNE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET DIAL AKL
Skipping useless range: INFONET TAIWAN
Skipping useless range: GUIDANT - HONG KONG
Skipping useless range: GUIDANT - SINGAPORE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET ECPT GATEWAY
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Estee Lauder
Skipping useless range: TRANSPORTATION MARITIME
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET INTERNAL
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET FR SERIAL
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: INFONET BRANCH OFFICE
Skipping useless range: Maersk Line Limited
Skipping useless range: Philanthropic Research
Skipping useless range: Telco Community Credit Union
Skipping useless range: L.K. Comstock Company, Inc
Skipping useless range: The Producers Group
Skipping useless range: Prudential Lending
Skipping useless range: Bifrost Labs, Inc
Skipping useless range: Millennium Software Corporation
Skipping useless range: Cyberworks Institute
Skipping useless range: Medical Associates of WOOD HULL
Skipping useless range: Corporate Strategic Services
Skipping useless range: McKenzie Cooper Limited
Skipping useless range: National Logistics Corp
Skipping useless range: ZEAL Inc
Skipping useless range: Gillette Global Network
Skipping useless range: ORANGE COAST TITLE COMPANY
Skipping useless range: Orange Coast Title Company
Skipping useless range: Virtual Asylum
Skipping useless range: Research by Design
Skipping useless range: Remax Power Advantage
Skipping useless range: Blue Cross Blue Shield of Western New York
Skipping useless range: Northeast Alliance Federal Credit Union
Skipping useless range: BLUE CROSS BLUE SHIELD OF CNY
Skipping useless range: Mitsubishi Materials U.S.A. Corporation
Skipping useless range: Envision Design, PLLC
Skipping useless range: Pinnacle Data Systems, Inc
Skipping useless range: Digital Gaming Solutions, Inc
Skipping useless range: Pinnacle Data Systems, Inc
Skipping useless range: Bank of America Corporation
Skipping useless range: Murphy Marketing and Research
Skipping useless range: Blue Ball National Bank
Skipping useless range: GeneSys Inc
Skipping useless range: Remax Realty
Skipping useless range: Remax Realty
Skipping useless range: AJ Jersey
Skipping useless range: Trident Compuware
Skipping useless range: Unidata-MinDellavoro
Skipping useless range: UNIDATA S.P.A
Skipping useless range: UNIDATA S.P.A
Skipping useless range: Stanford Research Systems, Inc
Skipping useless range: USLEC Corp
Skipping useless range: ABC Research
Skipping useless range: ABC Research
Skipping useless range: Commonwealth Bank of Australia - Cost Centre 20630
Skipping useless range: Commonwealth Bank of Australia
Skipping useless range: Science & Technology of Information Research inst
Skipping useless range: Automate Research institution of Heilongjiang Pro
Skipping useless range: Engineering Mechanics Research institution of Hei
Skipping useless range: Demo Asia Infonet Co.,Ltd
Skipping useless range: Samsungworld
Skipping useless range: Ahnkwon Deloitte
Skipping useless range: nexen
Skipping useless range: Eulji Medical Center
Skipping useless range: Korea Testing And Research Institute For Chemical
Skipping useless range: Mitsubishi Motors Corporation
Skipping useless range: Archetype Vietnam Co Ltd
Skipping useless range: American Express Bank Co Ltd
Skipping useless range: Chi Hung JVC
Skipping useless range: Samsung Corporation Representative Office
Skipping useless range: JPMorgan Chase Bank
Skipping useless range: GAlileo Vietnam Co
Skipping useless range: Bac A Trade Stock Company
Skipping useless range: ABC INTERNATIONAL INC
Skipping useless range: Beijing Economic Information Center Co.,Ltd
Skipping useless range: China National Debt Center
Skipping useless range: China National Debt Center
Skipping useless range: Beijing Astronomical Observatory
Skipping useless range: IP-Range for Mitsubishi
Skipping useless range: Neurologische Klinik Vallendar
Skipping useless range: Muenchner Konzertdirektion Hoertnagel GmbH, Muenchen
Skipping useless range: 3D Grafikbuero - Sandner, Muenchen
Skipping useless range: IKKF Institut fuer klinisch-kardiovaskulaere Forschung, Muenchen
Skipping useless range: Islamic Development Bank
Skipping useless range: Information Technology Center (ITC)
Skipping useless range: Communication and Information Technology Commissi
Skipping useless range: syscom-c is an internet cofe located in Nablus / palestine
Skipping useless range: VPN-MPLS
Merged range 'Technological Systems CJVC', with range 'Technological Systems CJVC'
Skipping useless range: Klinikum Lippe-Lemgo
Skipping useless range: Krankenhaus Nuernberger Land
Skipping useless range: Krankenhaus der barmherzigen Brueder
Skipping useless range: Kath. St. Elisabeth-Hospital
Skipping useless range: Krankenhaus der Evang. Diakonissenanstalt Speyer
Skipping useless range: Krankenhaus Neunkirchen
Skipping useless range: Krankenhaus Baden
Skipping useless range: Alaris Medical Systems
Skipping useless range: Krankenhaus Nuernberger Land
Skipping useless range: Inselspital Bern
Skipping useless range: Harzkliniken Krankenhaeuser Landkreis Goslar
Skipping useless range: National Cancer Centre
Skipping useless range: FRESENIUS KABI
Skipping useless range: LIBA LABORATUARLARI A.S
Skipping useless range: SEM LABARATUAR CIHAZ SAN.LTD.STI
Skipping useless range: EISA MARITIME AGENCY ISTANBUL
Skipping useless range: KPMG CEVDET SUNER YEMINLI MALI MUSAVIRLIK
Skipping useless range: SEM LABARATUAR CIHAZ SAN.LTD.STI
Skipping useless range: SEM LABARATUAR CIHAZ SAN.LTD.STI
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: SELKIRK Schornsteintechnik GmbH
Skipping useless range: Palestinian Energy & Environment Research Center
Skipping useless range: Deloitte Palestine
Skipping useless range: Camelot Group Plc ltd
Skipping useless range: Camelot Group Plc ltd
Skipping useless range: Camelot Group Plc ltd
Skipping useless range: Plan B GmbH
Skipping useless range: LANDSBANKI LUXEMBOURG SA
Skipping useless range: Russell Reynolds Belgium
Skipping useless range: Varian Medical Systems Belgium
Skipping useless range: Warrington Community Healthcare NHS Trust
Skipping useless range: Dudley Health Authority
Skipping useless range: South and West Cancer Intelligence Unit
Skipping useless range: Teddington Memorial Hospital NHS Trust
Skipping useless range: Blackpool Victoria Hospital NHS Trust
Skipping useless range: Royal Liverpool Childrens NHS Trust
Skipping useless range: Sheffield Childrens Hospital NHS Trust
Skipping useless range: Ste LG ELECTRONIC ā Casa
Skipping useless range: FR-RAEI-QUADRIGA-FRANCE-LB_INTERNET
Skipping useless range: KPMG Fides Fiduciaria S.p.A
Skipping useless range: Istituto Geografico De Agostini
Skipping useless range: KPMG Fides Fiduciaria S.p.A
Skipping useless range: NFO Infratest S.p.A
Skipping useless range: Financial Consultants & Brokers Sim S.p.A
Skipping useless range: BUSINESS LAB p.s.c.r.l
Skipping useless range: Financial Consultants & Brokers Sim SpA
Skipping useless range: INFONET
Skipping useless range: Infonet EU
Skipping useless range: INFONET EUROPE
Skipping useless range: INFONET NORWAY
Skipping useless range: TDK
Skipping useless range: CUSHMAN & WAKEFIELD
Skipping useless range: HINES
Skipping useless range: Promotion X OHG
Skipping useless range: deep visions Multimedia GmbH
Skipping useless range: CLINIQUE JEANNE D-ARC
Skipping useless range: CLINIQUE FILIPPI
Skipping useless range: CENTRE HOSPITALIER ALENCON
Skipping useless range: CLINIQUE NOUVELLE DU FOREZ
Skipping useless range: NOUVELLE CLINIQUE SAINT LUC
Skipping useless range: CENTRE HOSPITALIER INT DES ANDAINES
Skipping useless range: SYNDICAT INTERHOSPITALIER DU BOURBO
Skipping useless range: CLINIQUE CHIRURGICALE L-ERMITAGE
Skipping useless range: CENTRE HOSPITALIER LE CATEAU
Skipping useless range: CLINIQUE DE CHAILLES
Skipping useless range: CENTRE HOSPITALIER DE VAISON LA ROM
Skipping useless range: CLINIQUE DE L-ARCHETTE
Skipping useless range: SCM GROUPE MEDICAL ET PARAMEDICAL
Skipping useless range: CENTRE HOSPITALIER D-UZES
Skipping useless range: HOPITAL LOCAL DE LODEVE
Skipping useless range: HOPITAL LOCAL DE CARENTAN
Skipping useless range: HOPITAL DE CHAROLLES
Skipping useless range: POLYCLINIQUE DU PAYS DE LA RANCE
Skipping useless range: CLINIQUE SAINT VINCENT
Skipping useless range: HOPITAL LOCAL DE PONT DE L-ARCHE
Skipping useless range: HOPITAL SAINT JACQUES
Skipping useless range: CLINIQUE SAINT ANTOINE
Skipping useless range: CENTRE HOSPITALIER DE DOURDAN
Skipping useless range: HOPITAL LOCAL GRANDVILLIERS
Skipping useless range: HOPITAL DE BELLEVILLE
Skipping useless range: CENTRE HOSPITALIER PIERRE DELPECH
Skipping useless range: LABORATOIRE HARRIAU LARDY MONTARET
Skipping useless range: FRESENIUS VIAL
Skipping useless range: CENTRE HOSPITALIER DE VOIRON
Skipping useless range: HOPITAL DE SALON DE PROVENCE
Skipping useless range: CENTRE HOSPITALIER DE CALAIS
Skipping useless range: CENTRE HOSPITALIER CHARCOT
Skipping useless range: CENTRE HOSPITALIER LAENNEC
Skipping useless range: CENTRE HOSPITALIER PHILIPPE PINEL
Skipping useless range: CENTRE HOSPITALIER DE MONTFAVET
Skipping useless range: CENTRE HOSPITALIER D ARRAS
Skipping useless range: CENTRE HOSPITALIER DE SAINT QUENTIN
Skipping useless range: NATEXIS BANQUES POPULAIRES
Skipping useless range: CLINIQUE JEANNE D ARC
Skipping useless range: CLINIQUE AMBROISE PARE
Skipping useless range: HOPITAL LOCAL DE MAULEON
Skipping useless range: HOPITAL DE BOURG ACHARD
Skipping useless range: POLYCLINIQUE VAL DE LYS
Skipping useless range: HOPITAL LOCAL DE JOUARRE
Skipping useless range: CLINIQUE DE L EUROPE
Skipping useless range: Clinique Montevideo SAS la Tourelle
Skipping useless range: CLINIQUE DES LILAS
Skipping useless range: DEVELOPPEMENT CLINIQUE INERNAT
Skipping useless range: VINCENTZ VERLAG KG
Skipping useless range: Network of Guidant Corporation
Skipping useless range: Network of Airline Tariff Publishing
Skipping useless range: Network of Kodak Polychrome
Skipping useless range: Network of Kodak Polychrome Graphics
Skipping useless range: Network of Sommer AG
Skipping useless range: Network of Augustine Medical
Skipping useless range: Network of Guidant
Skipping useless range: Network of MISYS FINANCIAL SYSTEMS LTD
Skipping useless range: Network of Ericsson
Skipping useless range: Network of AMADEUS SOUTHERN AFRICA
Skipping useless range: Deutsche Bank c/o Trony
Skipping useless range: Quadriga
Skipping useless range: Gima S.p.A
Skipping useless range: Banco di Sicilia
Skipping useless range: Banco di Sicilia
Skipping useless range: Intechnology has established a qualified team of
Skipping useless range: InTechnology Employee address space
Skipping useless range: The Limehouse Group
Skipping useless range: Medical Defence Union
Skipping useless range: ClearSwift-Allocation
Skipping useless range: CODA Plc
Skipping useless range: public art intermedia GmbH
Skipping useless range: L.M.Ericsson DK. Aalborg
Skipping useless range: L.M.Ericsson DK. Aarhus
Skipping useless range: Humanomed Krankenhaus Management GmbH
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: Andromedical
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: BT IGS
Skipping useless range: NovaXess customer network for Plexus Medical Grou
Skipping useless range: NovaXess customer network for Blue Medical Device
Skipping useless range: NovaXess customer network for Medical Measurement
Skipping useless range: NovaXess customer network for RX Medical
Skipping useless range: Medical Services
Skipping useless range: Medical Clinic
Skipping useless range: SunGard Global Services
Skipping useless range: Laboratory
Skipping useless range: AMGEN SPA
Skipping useless range: Ementor Financial System
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: AMGEN SPA
Skipping useless range: PRASSIS ISTITUTO DI RICERCA SIGMA-TAU
Skipping useless range: Saatchi & Saatchi Business Communications
Skipping useless range: Loki Technologies
Skipping useless range: Ballston Spa National Bank
Skipping useless range: The Energy Network
Skipping useless range: Interactive Systems Management
Skipping useless range: Wells Fargo Bank
Skipping useless range: Wells Fargo Bank
Skipping useless range: Wells Fargo Bank
Skipping useless range: Research In Motion
Skipping useless range: Research in Motion (RIM-NET)
Skipping useless range: West Coast Paramount
Skipping useless range: Keynote Systems
Skipping useless range: Network Solutions
Skipping useless range: Commercial Bank
Skipping useless range: Commercial Bank
Skipping useless range: Network Solutions
Skipping useless range: Network Solutions
Skipping useless range: Keynote Systems
Skipping useless range: Keynote Systems
Skipping useless range: MSI Systems Integrators, Inc
Skipping useless range: Shoshone Medical Center
Skipping useless range: BRG Research Services
Skipping useless range: MOUTAIN AMERICA CREDIT UNION
Skipping useless range: BRG Research
Skipping useless range: Prudential Howe and Doherty Realtors
Skipping useless range: BANK OF MCKENNEY
Skipping useless range: Remax Allegiance
Skipping useless range: Remax Professionals Duluth
Skipping useless range: Blue Cross Blue Shield of North Carolina
Skipping useless range: labworld-online, Inc
Skipping useless range: North Carolina Technological Development
Skipping useless range: Remax Fredericksburg
Skipping useless range: Virginia Diabetes & Endo
Skipping useless range: VIRGINIA CARDIOVASCUALR SPECIALIST
Skipping useless range: CB Richard Ellis/Richard Cohn
Skipping useless range: Dupont Photomasks,Inc
Skipping useless range: Musicians Friend
Skipping useless range: Combustion Labs Media, Inc
Skipping useless range: Logos Research Systems, Inc
Skipping useless range: School Specialty, Inc
Skipping useless range: Whatcom Educational Credit Union
Skipping useless range: Combustion Labs Media, Inc
Skipping useless range: Virginia Check Cashers
Skipping useless range: Remax First Choice Hoover
Skipping useless range: Remax Partners
Skipping useless range: Remax Partners
Skipping useless range: Remax Partners Coral Springs
Skipping useless range: Laid Law Education Services
Skipping useless range: Remax Metropolitan
Skipping useless range: Remax Professional Suwanee
Skipping useless range: Re-Max Realty Services
Skipping useless range: Gateway Insurance Lake Worth
Skipping useless range: Remax Progressive
Skipping useless range: Remax Home center Burtonsville
Skipping useless range: Seneca Data Distributors
Skipping useless range: LELAND MEDICAL CENTER
Skipping useless range: FIREWHEEL FAMILY PRACTICE
Skipping useless range: VOTER CONSUMER RESEARCH
Skipping useless range: NMA MARITIME & OFFSHORE CONT. INC
Skipping useless range: INTEC SYSTEMS INC DBA COMPUTER TECH
Skipping useless range: INTEC SYSTEMS INC DBA COMPUTER TECH
Skipping useless range: ZTE COMMUNICATIONS USA
Skipping useless range: Israel Discount Bank
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: Israel Discount Bank
Skipping useless range: Sungard Treasury Systems
Skipping useless range: SUNGARD TREASURY EXCHANGE (ETX)
Skipping useless range: Sungard STN Treasury
Skipping useless range: CITIBANK
Skipping useless range: Merrill Lynch
Skipping useless range: Tillsmith Systems
Skipping useless range: Canadian Treasury Management Inc
Skipping useless range: Hopestar Medical Management Group
Skipping useless range: Quigo Technologies,Yarden Tadmor
Skipping useless range: Quigo Technologies Yarden Tadmor
Skipping useless range: Quigo Technologies Yarden Tadmor
Skipping useless range: Quigo Technologies,Yarden Tadmor
Skipping useless range: Pacific Financial Associates
Skipping useless range: Network Consultant Dynamics
Skipping useless range: Enron
Skipping useless range: Enron Broadband Services
Skipping useless range: Trade News Corp
Skipping useless range: Professional Finance Company, Inc
Skipping useless range: J and D Labs
Skipping useless range: Motorola Employee Credit Union
Skipping useless range: Washington Society Of C P As
Skipping useless range: Kenwood U S A
Skipping useless range: consult
Skipping useless range: Greene Consulting Associates
Skipping useless range: CMG Mortgage
Skipping useless range: Chevron Environmental
Skipping useless range: Futurelab
Skipping useless range: Tritech
Skipping useless range: Tritech Automation
Skipping useless range: Rocx Sofware Corp (000000)
Skipping useless range: Electronic Consultants Inc
Skipping useless range: Dr. John Sahrmann
Skipping useless range: Remax Real estate
Skipping useless range: Public Employees Credit Union
Skipping useless range: PCI Educational Publishing
Skipping useless range: Randolph Brooks Federal Credit
Skipping useless range: Randolph Brooks Federal Credit
Skipping useless range: Network Solutions, Inc
Skipping useless range: Network Solutions, Inc
Skipping useless range: Network Solutions, Inc
Skipping useless range: Novo Nordisk Pharmaceutical, Inc
Skipping useless range: Municipal Research and Services
Skipping useless range: Washington State Medical Association
Skipping useless range: Keystroke Financial
Skipping useless range: Bureau of Education &amp; Research
Skipping useless range: Main Street Financial
Skipping useless range: Applied Financial Management Inc
Skipping useless range: International Engineering Consortium
Skipping useless range: Resource Financial Corporation
Skipping useless range: eBusiness Technology Group
Skipping useless range: New Media Strategies, Inc
Skipping useless range: Orion Medical Management, Inc
Skipping useless range: Mercury Research
Skipping useless range: Envision Enterprises, LLC
Skipping useless range: Howard Hughes Medical Institute
Skipping useless range: Acordia Northwest
Skipping useless range: Virtual Desktop
Skipping useless range: SBC E-Services Private Customer
Skipping useless range: SBC EServices Private Customer
Skipping useless range: SBC E-Services Private Customer
Skipping useless range: SBC E-Services Private Customer
Skipping useless range: Virtual Desktop, Inc
Skipping useless range: SBC E-Services LAN - SWH project
Skipping useless range: SBC E-Services WEb Hosting pool
Skipping useless range: Preffered Medical Marketing Group
Skipping useless range: Bergen Medical Imaging
Skipping useless range: Interstate Blood Bank
Skipping useless range: Bergen Medical Imaging
Skipping useless range: Pembroke Pines Animal Hospital
Skipping useless range: Advanced Medical Systems
Skipping useless range: Interstate Blood Bank
Skipping useless range: Medical Business Services
Skipping useless range: Mohen, Inc. (Musicloads.com, SpiralFrog.com)
Skipping useless range: Birdstep Technology- Wireless
Skipping useless range: MediaNet Inc
Skipping useless range: Mohen, Inc. (Musicloads.com, SpiralFrog.com)
Skipping useless range: Monster Labs, Inc
Skipping useless range: Knowledge Analysis Technologie
Skipping useless range: PDS Research, Inc
Skipping useless range: PDS Research, Inc
Skipping useless range: Ternary Spatial Research, Inc
Skipping useless range: Precyse Solutions
Skipping useless range: Virginia Gas
Skipping useless range: Highlands Union Bank
Skipping useless range: Medical Visions Inc
Skipping useless range: Lawrence General Hospital
Skipping useless range: Beverly Hospital
Skipping useless range: Crenshaw Industrial Medical Clinic
Skipping useless range: Tower Medical Billing
Skipping useless range: AIST
Skipping useless range: Tax Analysts
Skipping useless range: Research Pharmaceuticals
Skipping useless range: UNIVERSITY FEDERAL CREDIT
Skipping useless range: FANNIE MAE / PRESCIENT MKTS
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: GFIG- Citigroup
Skipping useless range: GFIG- Citigroup
Skipping useless range: GFIG- Citigroup
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: RR Donnelley
Skipping useless range: RR Donnelley and Sons Company
Skipping useless range: JMB Realty Corp
Skipping useless range: JMB Realty Corp
Skipping useless range: KEYNOTE SYSTEMS
Skipping useless range: DELOITTE and TOUCHE
Skipping useless range: JMB Realty Corp
Skipping useless range: MCCANN-ERICKSON
Skipping useless range: CFX SOFTWARE CORP
Skipping useless range: McCann-Erickson/MCTcollaborative (MCWISDOM)
Skipping useless range: DZ BANK
Skipping useless range: CVS PHARMACY INC
Skipping useless range: Dupont Group, The
Skipping useless range: Hitachi Cable Manchester
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Falling Anvil Research
Skipping useless range: Energy Group, Inc
Skipping useless range: VPLS Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: B & K VerlagsgmbH
Skipping useless range: B &amp; K VerlagsgmbH
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: L3 Digital Inc
Skipping useless range: FilmLoop, Inc
Skipping useless range: Ebisu Trading Company
Skipping useless range: Energy Group, Inc
Skipping useless range: BSF Enterprises, LLC
Skipping useless range: HyperFeed Technologies
Skipping useless range: Libre Group, The
Skipping useless range: Site Print Systems Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Metricom, Inc
Skipping useless range: Digitalsmiths Corporation
Skipping useless range: Logicool, Inc
Skipping useless range: FooPlanet.com
Skipping useless range: TNB Media
Skipping useless range: Gopher King, Inc
Skipping useless range: Energy Group Networks LLC
Skipping useless range: Selective Media
Skipping useless range: Mevigo, Inc
Skipping useless range: Internext Technologies Inc
Skipping useless range: MW Plus, LLC
Skipping useless range: Energy Group, Inc
Skipping useless range: Docutek Information Systems Inc
Skipping useless range: Expresso Fitness
Skipping useless range: Energy Group Networks LLC
Skipping useless range: Energy Group Networks LLC
Skipping useless range: Usenet Technologies
Skipping useless range: Hanbai Kaihatsu Co. Ltd
Skipping useless range: Bridges Community Church
Skipping useless range: Energy Group Networks LLC
Skipping useless range: Evoknow, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Trade & Fun Corporation
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Digital Direct Marketing
Skipping useless range: B &amp; K VerlagsgmbH
Skipping useless range: B & K VerlagsgmbH
Skipping useless range: Betrader Financial, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Horizon Communications
Skipping useless range: Metro Newspapers
Skipping useless range: Computer Consul
Skipping useless range: Sean Ackley
Skipping useless range: Globill
Skipping useless range: Managerial Technologies Corp
Skipping useless range: Energy Group, Inc
Skipping useless range: Sean Ackley
Skipping useless range: B &amp; K VerlagsgmbH
Skipping useless range: B & K VerlagsgmbH
Skipping useless range: Metro Newspapers
Skipping useless range: etalk communications
Skipping useless range: Energy Group, Inc
Skipping useless range: Energy Group, Inc
Skipping useless range: Connecticut State Medical Society
Skipping useless range: St. Johns Riverside Hospital
Skipping useless range: St. Johns Riverside Hospital
Skipping useless range: BP Consulting
Skipping useless range: Mountain View Credit Union
Skipping useless range: Cancer Patient Care
Skipping useless range: Spokane Teachers Credit Union
Skipping useless range: Commerce Integration, Inc
Skipping useless range: Capital Credit Union
Skipping useless range: Orange Coast Title
Skipping useless range: Harris Industries, Inc
Skipping useless range: Massage Envy
Skipping useless range: Orange Coast Title
Skipping useless range: Enlace Communications, Inc
Skipping useless range: Delec LLC
Skipping useless range: Davis and Partners
Skipping useless range: Baker and Thomsen
Skipping useless range: Re/Max Garden Grove
Skipping useless range: Van Law Foods
Skipping useless range: CentreCom
Skipping useless range: Quad Research
Skipping useless range: KPMG
Skipping useless range: Orange Coast Title
Skipping useless range: Orange Coast Title
Skipping useless range: Orange Coast Title
Skipping useless range: Orange Coast Title
Skipping useless range: Third Eye Media Production Co. US
Skipping useless range: VW-CUST-Ebenefits Software Solutions
Skipping useless range: Integrated Computer Solutions =09
Skipping useless range: Integrated Computer Solutions =09
Skipping useless range: Peerworks Labs Inc
Skipping useless range: Intelecon Research and Consultancy Ltd
Skipping useless range: Thomson Kernaghan
Skipping useless range: Prolab Inc
Skipping useless range: torrentprivacy.com
Skipping useless range: Verlag Neue Wirtschafts-Briefe GmbH
Skipping useless range: TSI fuer DuPont Deutschland Holding GmbH & Co. KG
Skipping useless range: Fr.G. Theis Kaltwalzwerke GmbH
Skipping useless range: Mariannen-Hospital Werl
Skipping useless range: Marienkrankenhaus
Skipping useless range: Katharinen-Hospital
Skipping useless range: Intelligent IT Solutions GmbH & Co.KG
Skipping useless range: Krankenhaus Guestrow GmbH
Skipping useless range: Hospital Wismar
Skipping useless range: Asklepios Klinik Schaufling
Skipping useless range: Goslarsche Zeitung Karl Krause GmbH & Co.KG
Skipping useless range: Precision Software GmbH Softwarevertrieb
Skipping useless range: TSI fuer Kodak GmbH
Skipping useless range: KOeTTER GmbH & Co. KG Verwaltungsdienstleistungen
Skipping useless range: Enzkreis-Kliniken
Skipping useless range: Eppinger-Verlag
Skipping useless range: Fachklinik Enzensberg
Skipping useless range: TSI fuer DuPont Deutschland Holding GmbH & Co. KG
Skipping useless range: C.M.H Software Engeneering GmbH
Skipping useless range: Softwarehouse
Skipping useless range: Point to Points
Skipping useless range: Gateshead Council
Skipping useless range: software house in Cairo
Skipping useless range: Software house in egypt
Skipping useless range: Regus UK Mayfair
Skipping useless range: Regus UK Reading Green Park
Skipping useless range: Regus UK Bristol Broad Quay
Skipping useless range: Regus UK London Poultry
Skipping useless range: Regus UK Berkley Square
Skipping useless range: FTIP002864587 Fujifilm Peterborough
Skipping useless range: Regus UK Lombard Street
Skipping useless range: Regus UK London Lloyds Leadenhall S
Skipping useless range: Regus UK Stockley Park
Skipping useless range: Equifax Plc
Skipping useless range: Regus UK Reading Arlington Business Park
Skipping useless range: Regus UK Great West Road Brentford
Skipping useless range: FTIP002870601 Sungard Vivista Ltd
Skipping useless range: heritage lottery fund
Skipping useless range: FTIP002919980 Fuji Photo Film UK Ltd
Skipping useless range: Regus UK Hillswood Drive Chertsey
Skipping useless range: Regus UK London Hammersmith
Skipping useless range: Regus UK Trinity Court
Skipping useless range: Regus UK London Liverpool Street
Skipping useless range: Regus UK Covent Garden
Skipping useless range: Regus UK Luton
Skipping useless range: FTIP002875446 Alban Communications Ltd
Skipping useless range: Heritage Lottery Fund
Skipping useless range: Regus UK Cinnamon Park
Skipping useless range: Regus UK Hammersmith
Skipping useless range: Heritage Lottery Fund
Skipping useless range: Heritage Lottery Fund
Skipping useless range: Regus UK Maidenhead Albany House
Skipping useless range: Regus UK Leatherhead
Skipping useless range: Regus UK Stockley Park
Skipping useless range: Regus UK Uxbridge
Skipping useless range: Regus UK Clarendon Road Watford
Skipping useless range: Regus UK Gatwick Airport
Skipping useless range: FTIP002883427 Wavex Technology Ltd
Skipping useless range: The Bank Of Tokyo Mitsubishi
Skipping useless range: Regus UK (Stag Place)
Skipping useless range: IMPACT DEVELOPMENT TRAINING
Skipping useless range: Regus UK Hammersmith
Skipping useless range: MISSION AVIATION FELLOWSHIP UK
Skipping useless range: FTIP002877433 Merle Agency Ltd
Skipping useless range: FTIP002903187 Fimat International
Skipping useless range: Regus UK Cannon Street
Skipping useless range: Hayden_Laboratories
Skipping useless range: LAFARGE AGGREGATES LTD
Skipping useless range: GEAC
Skipping useless range: M & C Saatchi Ltd
Skipping useless range: Regus UK (Whitehill Way)
Skipping useless range: Regus UK Aztec West
Skipping useless range: FTIP003072936 PA Consulting Group
Skipping useless range: Design It Soluitions Ltd
Skipping useless range: Bank of Scotland
Skipping useless range: IMPACT DEVELOPMENT TRAINING
Skipping useless range: SAMSUNG
Skipping useless range: FTIP002844343 Atradius Ltd
Skipping useless range: Schlumbergersema
Skipping useless range: Tissue_Science_Laboratories_Plc
Skipping useless range: VALPAK
Skipping useless range: CONTINENTAL RESEARCH LTD
Skipping useless range: FTIP002955681 New Voice Media Ltd
Skipping useless range: FTIP003079935 Chelford SAP Solutions
Skipping useless range: Techne_Research_Limited
Skipping useless range: Staedtisches Krankenhaus Kiel
Skipping useless range: A.oe. Krankenhaus Waidhofen a.d. Thaya
Skipping useless range: Bethanien-Krankenhaus Chemnitz GmbH
Skipping useless range: Rotes Kreuz Krankenhaus
Skipping useless range: Klinikum Lippe-Lemgo
Skipping useless range: Krankenhaus der barmherzigen Brueder
Skipping useless range: Krankenhaus der Evang. Diakonissenanstalt Speyer
Skipping useless range: Staedtisches Klinikum Oldenburg gGmb
Skipping useless range: Städtische Krankenhäuser GmbH Klinikum Krefeld
Skipping useless range: Krankenhaus Neunkirchen
Skipping useless range: Krankenhaus Baden
Skipping useless range: Heinen-Verlag GmbH
Skipping useless range: Evang. Krankenhaus Koeln GmbH
Skipping useless range: Zentralklinikum gGmbH
Skipping useless range: Staedtisches Krankenhaus Muenchen-Bogenhausen
Skipping useless range: Staedtisches Krankenhaus Thalkirchen
Skipping useless range: Ruhrlandklinik Essen-Heidhausen
Skipping useless range: Ruhrlandklinik Essen-Heidhausen
Skipping useless range: St James Hospital
Skipping useless range: Heinrich-Braun-Krankenhaus Zwickau
Skipping useless range: Jupiter Networks
Skipping useless range: BRED BANQUE POPULAIRE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: publication metro
Skipping useless range: PUBLICATIONS METRO FRANCE
Skipping useless range: HOPITAL SAINT JEAN DE DIEU
Skipping useless range: BOLTON MEDICAL SA
Skipping useless range: Atlantique Services Maritimes
Skipping useless range: Clinique De Flandres
Skipping useless range: LABORATOIRES G GAM
Skipping useless range: Laboratoire Goemar
Skipping useless range: Alcatel
Skipping useless range: Alcatel
Skipping useless range: Alcatel
Skipping useless range: Alcatel
Skipping useless range: Laboratoire de La Vendee
Skipping useless range: Presence Medicale
Skipping useless range: Hopital Saint Jean
Skipping useless range: Laboratoire Gaba
Skipping useless range: Clinique Saint Hilaire
Skipping useless range: Assurances Medicales
Skipping useless range: GETRONICS FRANCE
Skipping useless range: ETABLISSEMENTS DUPONT
Skipping useless range: GETRONICS FRANCE
Skipping useless range: Reseau Regional des Pays de Loire
Skipping useless range: INTIF Insttitut Francophone des Nouvelles Techono
Skipping useless range: ALCATEL
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: Arthur Andersen Associes
Skipping useless range: ALCATEL BUSINESS SYSTEMS
Skipping useless range: ALCATEL CIT
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: QUADRIGA FRANCE
Skipping useless range: NCI A KPMG
Skipping useless range: Mitsui & Co UK Plc - Extranet Services
Skipping useless range: Mitsui Customer links
Skipping useless range: Mitsui & Co UK Plc - Internet Services Dusseldorf
Skipping useless range: Kaneka Belgium Offices via Mitsui
Skipping useless range: Kaneka Belgium Offices via Mitsui
Skipping useless range: Changji Economic Information Adminnistration Cent
Skipping useless range: America World Best Communication
Skipping useless range: ZHUOTONG infonet Co.,Ltd
Skipping useless range: Acoustic, Inc
Skipping useless range: Tonghuayuan Office Building
Skipping useless range: Oki Electric Industry Co., Ltd
Merged range 'SIFY STATIC IP ADDRESS', with range 'IFLEX SOLUTIONS'
Skipping useless range: LUOYANG AGRICULTURE BANK
Skipping useless range: SHANGQIU MINQUANGUODIAN CORP
Skipping useless range: MICROSOFT CORPORATION
Skipping useless range: Microsoft
Skipping useless range: MICROSOFT TV
Skipping useless range: MICROSOFT.TV.ABOV-C241-64-124-68-16-28.NET-64-124-
Skipping useless range: MICROSOFT
Skipping useless range: MSN Direct
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.UU-65-194-210-224.NET-65-194-210-22
Skipping useless range: MSN
Skipping useless range: MSN
Skipping useless range: Microsoft
Skipping useless range: MSN
Skipping useless range: MICROSOFT.NEW.YORK-1290.UU-65-223-196.NET-65-223-1
Skipping useless range: FR-RAEI-MICROSOFT-LYON-LB_INTERNET
Skipping useless range: FORMATION ET CONSEIL MICROSOFT PROJET
Skipping useless range: Formation.Et.Conseil.Microsoft.Projet.FR
Skipping useless range: MICROSOFT SP ZO.O
Skipping useless range: MICROSOFT SRL
Skipping useless range: Microsoft
Skipping useless range: Microsoft.Corp.MICROSOFT18.NET-192-237-67-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.UK.Ltd.GB
Skipping useless range: microsoft uk ltd
Skipping useless range: microsoft.eu.subservices.com
Skipping useless range: FR-RAEI--MICROSOFT-FRANCE-ARC4.Microsoft.France.RA
Skipping useless range: microsoft-antipiracy.com
Skipping useless range: Microsoft.Corporation.GB
Skipping useless range: MICROSOFT-CORPORATION
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT19.NET-198-137-97-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT2.NET-198-180-74-0-1.Micro
Skipping useless range: Microsoft.Corp.MICROSOFT3.NET-198-180-95-0-1.Micro
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT17.NET-199-6-92-0-1.Micros
Skipping useless range: Microsoft Corp
Skipping useless range: Frontbridge Technologies, Inc
Skipping useless range: Microsoft Operations Pte Ltd
Skipping useless range: Microsoft Corporation(I) Pvt.Ltd
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT-2.NET-204-79-7-0-1.Micros
Skipping useless range: Microsoft.Corp.MICROSOFT-NET1.NET-204-79-27-0-1.Mi
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT8.NET-204-79-101-0-1.Micro
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft
Skipping useless range: Microsoft
Skipping useless range: Microsoft.Corp.MICROSOFTDENVER.NET-204-133-231-0-1
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT15.NET-204-140-77-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT16.NET-204-140-80-0-1.Micr
Skipping useless range: Microsoft.Corp.MICROSOFT19-NET58.NET-204-231-58-0-
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT20.NET-204-231-76-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT29.NET-205-248-10-0-1.Micr
Skipping useless range: Microsoft.Corp.MICROSOFT30.NET-205-248-41-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT31.NET-205-248-50-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT32.NET-205-248-61-0-1.Micr
Skipping useless range: Microsoft.Corp.MICROSOFT34.NET-205-248-72-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT33.NET-205-248-80-0-1.Micr
Skipping useless range: Microsoft
Skipping useless range: PIGGYBACK FOR MICROSOFT
Skipping useless range: Microsoft.Corp.MICROSOFT35.NET-205-248-212-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT36.NET-205-248-228-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT37.NET-205-248-235-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT44.NET-205-248-243-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT58.NET-206-73-31-0-1.Micro
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT56.NET-206-73-118-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT57.NET-206-73-203-0-1.Micr
Skipping useless range: Microsoft.Corp.MICROSOFT61.NET-206-182-69-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT62.NET-206-182-236-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT65.NET-206-182-247-0-1.Mic
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT66.NET-206-182-251-0-1.Mic
Skipping useless range: Microsoft
Skipping useless range: Microsoft Asian Data Centers
Skipping useless range: Microsoft
Skipping useless range: Microsoft
Skipping useless range: www.microsoft.com/poland
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT48.NET-207-117-3-0-1.Micro
Skipping useless range: Microsoft.Corp.MICROSOFT50.NET-207-209-68-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft.Corp.MICROSOFT55.NET-209-28-213-0-1.Micr
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft-MSNTV
Skipping useless range: Microsoft Research
Skipping useless range: Microsoft GmbH, Unterschleissheim
Skipping useless range: MICROSOFT-CORP-OMAN
Skipping useless range: Microsoft AG
Skipping useless range: Microsoft.AG.ch
Skipping useless range: RSPC-UK-Microsoft-Limited
Skipping useless range: Microsoft Osterreich GMBH
Skipping useless range: Microsoft Corp
Skipping useless range: Microsoft - Partner Campaign Builder (PCB)
Skipping useless range: Microsoft - Partner Campaign Builder (PCB)
Skipping useless range: MICROSOFT.MFN-T133-216-200-206-0-24.NET-216-200-20
Skipping useless range: Microsoft Corporation
Skipping useless range: MICROSOFT FRANCE
Skipping useless range: Microsoft.France.FR
Skipping useless range: Xbox Live London
Skipping useless range: MICROSOFT SRL
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Proxy
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: Tor
Skipping useless range: p2p Corrupt Data Senders
Skipping useless range: p2p Corrupt Data Senders
Skipping useless range: p2p Fake Files
Skipping useless range: fake files
Skipping useless range: p2p Corrupt Data Senders
Skipping useless range: p2p Fake Files
Skipping useless range: p2p Fake Files
Skipping useless range: p2p Corrupt Data Senders
Skipping useless range: p2p Corrupt Data Senders
Skipping useless range: p2p Corrupt Data Sender
Skipping useless range: p2p corrupt data sender
Skipping useless range: probably nothing
Short guarding.p2p line BitTorrent Corrupt Data Sender:76.90.114.51 -76.90.114.51, skipping it...
* Ranges loaded: 316589
Tue Feb 3 13:54:39| * Merged ranges: 3049
Tue Feb 3 13:54:39| * Skipped useless ranges: 9575
Tue Feb 3 13:54:39| error during nfq_unbind_pf()
Tue Feb 3 13:54:39| NFQUEUE: binding to queue '92'
Tue Feb 3 13:54:51| OUT: Beijing Cai Hui Da Co.,Ltd,hits: 1,DST: 116.198.249.186
Tue Feb 3 13:54:53| OUT: Beijing Cai Hui Da Co.,Ltd,hits: 2,DST: 116.198.249.186
Tue Feb 3 13:54:57| OUT: Beijing Cai Hui Da Co.,Ltd,hits: 3,DST: 116.198.249.186

jre
February 4th, 2009, 07:59 PM
@SuperJamie: Feel free to use whatever you wnat. But remember that ufw and MoBlock have different purposes. Which version did you try? Since a few months traffic to the LAN is whitelisted (allowed) automatically. Further there are many options for further whitelisting. The documentation and https://help.ubuntu.com/community/MoBlock show them.

@astarmathsandphysics: Yes, this is the moblock logfile. If you have questions you should ask them.

hrd
February 9th, 2009, 01:25 PM
I'm new to linux, and installed moblock after a lot of stumbles and wrong turns. Moblock now appears to be installed, but it does not block anything. For instance, I was able to ping and visit the riaa and mpaa websites. Help?

jre
February 10th, 2009, 09:07 PM
I'm new to linux, and installed moblock after a lot of stumbles and wrong turns. Moblock now appears to be installed, but it does not block anything. For instance, I was able to ping and visit the riaa and mpaa websites. Help?

Per default port 80 and 443 (http/https) are whitelisted, so surfing will always work. But ping should always be blocked, as long as the IP is really in the blocklist.

Try "sudo moblock-control test" and post the output of "sudo moblock-control status"

lovinglinux
February 11th, 2009, 02:23 AM
I recently noticed an error in the logs when running the latest version.


error during nfq_unbind_pf()

followed by


NFQUEUE: binding to queue '92'

I guess I shouldn't be worried because it is binding properly and seems to work without issues, but I'm reporting it anyway.

jre
February 12th, 2009, 05:42 PM
That's nothing to worry about. This happens since kernel 2.6.23.
In previous versions Moblock would even exit because of this. But this can simply be ignored, see here http://developer.berlios.de/bugs/?func=detailbug&bug_id=12156&group_id=2509

lovinglinux
February 13th, 2009, 05:42 AM
That's nothing to worry about. This happens since kernel 2.6.23.
In previous versions Moblock would even exit because of this. But this can simply be ignored, see here http://developer.berlios.de/bugs/?func=detailbug&bug_id=12156&group_id=2509

Thanks

PresBHaven
February 20th, 2009, 01:09 AM
So I followed the MoBlock install from https://help.ubuntu.com/community/MoBlock

After I did that and rebooted I ran the moblock test and this came back.


* moblock is dead, but /var/run/ pid file exists.
* Try "moblock-control stop". Otherwise delete /var/run/moblock.pid
* and all iptables rules related to MoBlock.

Any ideas on how to fit that so I can get moblock running?

jre
February 21st, 2009, 01:56 PM
So I followed the MoBlock install from https://help.ubuntu.com/community/MoBlock

After I did that and rebooted I ran the moblock test and this came back.



Any ideas on how to fit that so I can get moblock running?

So have you tried, what the message told you (there are two advices!!)?
Is it a temporary problem, or does it happen again if you reboot?
Did the installation succeed or were there any error messages?

If the problem persists, please post on which distribution you are and the output of "dpkg -l lsb-base"

PresBHaven
February 24th, 2009, 10:57 AM
Sorry, apparently I forgot how to post on forums about computers...

Here we go

Ubuntu 8.10 on a Toshiba u305 2812 Laptop
Connected to my network through wifi

dpkg -l lsb-base

gives me:


Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-==============-==============-============================================
ii lsb-base 3.2-14ubuntu2 Linux Standard Base 3.2 init script function


As for this


Testing MoBlock:
* moblock is dead, but /var/run/ pid file exists.
* Try "moblock-control stop". Otherwise delete /var/run/moblock.pid
* and all iptables rules related to MoBlock.
...fail!


I have tried deleting moblock.pid and then do "sudo moblock-control start" it does not start. It says moblock starting but then instantly drops me right back where I was in the terminal. It also tells me to delete all of the iptable related to moblock and I am not exactly sure how to do that or if deleting moblock.pid does that. Is it deleting all of the blocklists? If so I have tried that, and then when I attempt to reload in the block lists that I copied and pasted out of mobloquer it says that they do not appear to be valid blocklists. Not sure if thats what the iptables are, but that is what I tried...

I just reinstalled the packages and immediately after the install pidgin stopped working but firefox was fine.

An other symptoms I have found before I reinstalled the packages( I have not rebooted since the last reinstall) is that when I boot up and moblock starts on start up firefox pidgin do not work. So I "sudo moblock-control stop" and everything returns to normal. Then when I start it again firefox and pidgin act normal.

Those are all the things I have done thus far

jre
February 25th, 2009, 09:29 PM
Hmm, hard to say what happens.

When moblock is running there must be

a pid (/var/run/moblock.pid)
the process itself (check "ps aux|grep moblock" which should show a line similar to this (do you get this?):

root 7644 1.9 2.8 64120 58008 ? S 21:12 0:08 /usr/bin/moblock -t -p /var/lib/moblock/guarding.p2p -q 92 -r 10 -a 20 /var/log/moblock.log

the iptables rules (see post #1 in this thread to see how they look like)


No running daemon:
It seems as if MoBlock gets started and the iptables rules inserted, but then the daemon (2) crashes. --> If only the rules exist, but the process is not there to handle the traffic, then all traffic that should be filtered by MoBlock gets completely dropped. (So per default all traffic, except the whitelisted traffic for websurfing, is dropped.)
Please check /var/log/moblock.log if there are any hints (messages about skipping or merging ranges are unimportant).

Running daemon:
Alternatively it might be, that your lsb init-functions are broken/buggy and falsely report that the daemon does not run (but I doubt that, because other intrepid users don't have this problem). In that case you might replace the pidofproc function in your /lib/lsb/init-functions with this code (version 3.2-20, there are small differences in a few lines which might be the culprit).

pidofproc () {
local pidfile line i pids= status specified pid
pidfile=
specified=

OPTIND=1
while getopts p: opt ; do
case "$opt" in
p) pidfile="$OPTARG"; specified=1;;
esac
done
shift $(($OPTIND - 1))

base=${1##*/}
if [ ! "$specified" ]; then
pidfile="/var/run/$base.pid"
fi

if [ -n "${pidfile:-}" -a -e "$pidfile" ]; then
read pid < "$pidfile"
if [ -n "${pid:-}" ]; then
if $(kill -0 "${pid:-}" 2> /dev/null); then
echo "$pid"
return 0
elif ps "${pid:-}" >/dev/null 2>&1; then
echo "$pid"
return 0 # program is running, but not owned by this user
else
return 1 # program is dead and /var/run pid file exists
fi
fi
fi
if [ -x /bin/pidof -a ! "$specified" ]; then
status="0"
/bin/pidof -o %PPID -x $1 || status="$?"
if [ "$status" = 1 ]; then
return 3 # program is not running
fi
return 0
fi
return 4 # program or service is unknown
}

Final note: You do not have to and should not delete your blocklists!

freedom
March 5th, 2009, 09:23 PM
Mobloquer stop working on me!.. :(
Everything was OK... mobloquer was working perfectly but now I get
Segmentation fault on console when I started it. Does anyone have the same problem?
I cannot connect this Segmentation fault with anything I do recently... I only update packages regulary.
Tried to remove .config/mobloquer dir from my HOMEDIR but that doesn`t do the trick. :(
Any ideas?

jre
March 6th, 2009, 07:46 PM
Sorry, no. You already did what I would have suggested (remove ~/.config/mobloquer). Perhaps reboot. You are the first and only who has reported this problem currently.
Can you post the complete console output?
What's your Ubuntu version?

freedom
March 7th, 2009, 08:14 PM
OK... here is some details...
I installed from repo...

deb http://moblock-deb.sourceforge.net/debian intrepid main
so you see that I'm using Intrepid 8.10
Console output is rather poor... maybe there is option to increase verbosity?

dan@GX610:~$ mobloquer
** Warning: Prefered file "/usr/bin/kdesu" could not be found, using "/usr/bin/gksu" instead
Segmentation fault

moblock and moblock-control for itselfs works like a charm but mobloquer even purged and reinstalled, don't. :(

oh.. and here is line from dmesg output...

[25406.992283] mobloquer[14520]: segfault at 5b ip b7475c72 sp bfa3c610 error 6 in libQtCore.so.4.4.3[b73db000+225000]

jre
March 8th, 2009, 12:40 PM
Unfortunately that's beyond my knowledge.

I assume /usr/bin/gksu exists and is executable!?

It also might be a bug in libqt-core. But I guess most mobloquer users do use Ubuntu intrepid, and I still haven't received other bug reports ...

For future reference please post
dpkg -l "libqt*". Do you remember if there was any update of libqt lately?

freedom
March 8th, 2009, 04:37 PM
Yes, gksu exist, kdesu doesn't but there is kdesudo. Maybe you should use kdesudo for administrative privileges.
Here is the oputput of dpkg...

GX610:~$ dpkg -l "libqt*"
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-=============================-=============================-================================================== ========================
un libqt-perl <none> (no description available)
un libqt0-ruby1.8 <none> (no description available)
un libqt3 <none> (no description available)
un libqt3-helper <none> (no description available)
ii libqt3-mt 3:3.3.8-b-5ubuntu1 Qt GUI Library (Threaded runtime version), Version 3
un libqt3-mt-mysql <none> (no description available)
un libqt3-mt-odbc <none> (no description available)
un libqt3-mt-psql <none> (no description available)
un libqt3c-mt <none> (no description available)
un libqt3c102-mt <none> (no description available)
ii libqt4-assistant 4.4.3-0ubuntu1.2 Qt 4 assistant module
ii libqt4-core 4.4.3-0ubuntu1.2 transitional package for Qt 4 core non-GUI runtime libraries
ii libqt4-dbus 4.4.3-0ubuntu1.2 Qt 4 D-Bus module
ii libqt4-designer 4.4.3-0ubuntu1.2 Qt 4 designer module
un libqt4-dev <none> (no description available)
ii libqt4-gui 4.4.3-0ubuntu1.2 transitional package for Qt 4 GUI runtime libraries
ii libqt4-help 4.4.3-0ubuntu1.2 Qt 4 help module
ii libqt4-network 4.4.3-0ubuntu1.2 Qt 4 network module
ii libqt4-opengl 4.4.3-0ubuntu1.2 Qt 4 OpenGL module
ii libqt4-qt3support 4.4.3-0ubuntu1.2 Qt 3 compatibility library for Qt 4
ii libqt4-script 4.4.3-0ubuntu1.2 Qt 4 script module
ii libqt4-sql 4.4.3-0ubuntu1.2 Qt 4 SQL module
un libqt4-sql-ibase <none> (no description available)
ii libqt4-sql-mysql 4.4.3-0ubuntu1.2 Qt 4 MySQL database driver
un libqt4-sql-odbc <none> (no description available)
un libqt4-sql-psql <none> (no description available)
ii libqt4-sql-sqlite 4.4.3-0ubuntu1.2 Qt 4 SQLite 3 database driver
un libqt4-sql-sqlite2 <none> (no description available)
ii libqt4-svg 4.4.3-0ubuntu1.2 Qt 4 SVG module
ii libqt4-test 4.4.3-0ubuntu1.2 Qt 4 test module
ii libqt4-webkit 4.4.3-0ubuntu1.2 Qt 4 WebKit module
ii libqt4-xml 4.4.3-0ubuntu1.2 Qt 4 XML module
ii libqt4-xmlpatterns 4.4.3-0ubuntu1.2 Qt 4 XML patterns module
ii libqtcore4 4.4.3-0ubuntu1.2 Qt 4 core module
ii libqtgui4 4.4.3-0ubuntu1.2 Qt 4 GUI module


Well, maybe the problem is with latest libqt in KDE4 update... 4.2.1 :(

freedom
March 13th, 2009, 10:16 AM
NO. It is not KDE 4.2.1 update...
I have installed mobloquer on other machine and perform an update and everything worked fine... before and after update.
Strange thing that both machines have pretty much the same things installed and KDE4 as desktop environment but still on the first one mobloquer stops to work (and it has been worked for some time).

If anyone knows or maybe if developer of mobloquer read this...
Is there an option to have verbose output on errors rather than just "Segmentation fault" ?

jre
March 14th, 2009, 12:39 PM
If anyone knows or maybe if developer of mobloquer read this...
Is there an option to have verbose output on errors rather than just "Segmentation fault" ?
With the next release I will (try to) provide a mobloquer-dbg package. Then it will be possible to make a backtrace with dbg. I hope to do this this weekend...

jurelex
March 15th, 2009, 05:21 AM
Hi all. I'm having the same problem...

I installed both moblock and mobloquer



sudo apt-get install moblock mobloquer


I tried uninstalling and reinstalling, also tried deleting the configuration file but I still have the same problem



~$ mobloquer
** Warning: Prefered file "/usr/bin/kdesu" could not be found, using "/usr/bin/gksu" instead
Segmentation fault


dmesg output:



[12994.753398] mobloquer[22111]: segfault at 5b ip b74cfc72 sp bff922e0 error 6 in libQtCore.so.4.4.3[b7435000+225000]


dpkg -l "libqt*" output:



Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-==========================-==========================-================================================== ==================
un libqt-perl <none> (no description available)
un libqt3 <none> (no description available)
un libqt3-helper <none> (no description available)
ii libqt3-mt 3:3.3.8-b-5ubuntu1 Qt GUI Library (Threaded runtime version), Version 3
ii libqt3-mt-mysql 3:3.3.8-b-5ubuntu1 MySQL database driver for Qt3 (Threaded)
un libqt3-mt-odbc <none> (no description available)
un libqt3-mt-psql <none> (no description available)
un libqt3-mysql <none> (no description available)
un libqt3c-mt <none> (no description available)
un libqt3c-mt-mysql <none> (no description available)
un libqt3c102-mt <none> (no description available)
un libqt3c102-mt-mysql <none> (no description available)
un libqt4-core <none> (no description available)
ii libqt4-dbus 4.4.3-0ubuntu1.2 Qt 4 D-Bus module
ii libqt4-designer 4.4.3-0ubuntu1.2 Qt 4 designer module
un libqt4-dev <none> (no description available)
un libqt4-gui <none> (no description available)
ii libqt4-network 4.4.3-0ubuntu1.2 Qt 4 network module
ii libqt4-qt3support 4.4.3-0ubuntu1.2 Qt 3 compatibility library for Qt 4
ii libqt4-script 4.4.3-0ubuntu1.2 Qt 4 script module
ii libqt4-sql 4.4.3-0ubuntu1.2 Qt 4 SQL module
un libqt4-sql-ibase <none> (no description available)
ii libqt4-sql-mysql 4.4.3-0ubuntu1.2 Qt 4 MySQL database driver
un libqt4-sql-odbc <none> (no description available)
un libqt4-sql-psql <none> (no description available)
un libqt4-sql-sqlite <none> (no description available)
un libqt4-sql-sqlite2 <none> (no description available)
ii libqt4-svg 4.4.3-0ubuntu1.2 Qt 4 SVG module
ii libqt4-xml 4.4.3-0ubuntu1.2 Qt 4 XML module
ii libqtcore4 4.4.3-0ubuntu1.2 Qt 4 core module
ii libqtgui4 4.4.3-0ubuntu1.2 Qt 4 GUI module


Hope this information helps.

jre
March 15th, 2009, 06:24 PM
Currently I have no clue what's going on.
But with the next update there will definitely be a mobloquer-dbg package. I've already tested it locally.
If your problems persist, you can make a backtrace with "gdb mobloquer", followed by "run" on the gdb prompt.

EDIT 1: I guess you are on intrepid, too?

EDIT 2: At least the dependencies of the new packages have changed:

mobloquer_0.6-1~pre3+intrepid_i386.deb:
Depends: libc6 (>= 2.1.3), libgcc1 (>= 1:4.1.1), libqtcore4 (>= 4.4.3), libqtgui4 (>= 4.4.3), libstdc++6 (>= 4.1.1), moblock, blockcontrol

mobloquer_0.5-2+intrepid_i386.deb
Depends: libc6 (>= 2.3.4), libgcc1 (>= 1:4.1.1), libqtcore4 (>= 4.4.1), libqtgui4 (>= 4.4.1), libstdc++6 (>= 4.1.1), moblock, moblock-control

womble12345
March 18th, 2009, 08:38 AM
I am a linux newbie and have had issues installing moblock, I followed the howto but after rebooting when I do:

simon@SERVER:~$ sudo moblock-control test
[sudo] password for simon:
Testing MoBlock:
* MoBlock is not running.


simon@SERVER:~$ sudo moblock-control status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 2848K packets, 708M bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 3374K packets, 2253M bytes)
pkts bytes target prot opt in out source destination

Chain moblock_fw (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_in (0 references)
pkts bytes target prot opt in out source destination
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain moblock_out (0 references)
pkts bytes target prot opt in out source destination
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Current IPv6 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Please check if the above printed iptables rules are correct!

* moblock is not running.


And having tried a number of times to start, stop, restart, etc I get this in my log:

simon@SERVER:~$ cat /var/log/moblock-control.log
2009-03-17 21:01:24 GMT Begin: moblock-control start
Building blocklist... Updating TBG_Primary_Threats... done.
Extracting TBG_Primary_Threats, detected gz...done.
Updating TBG_General_Corporate_Ranges... done.
Extracting TBG_General_Corporate_Ranges, detected gz...done.
Updating TBG_Business_ISPs... done.
Extracting TBG_Business_ISPs, detected gz...done.
Updating TBG_Search_Engines... done.
Extracting TBG_Search_Engines, detected gz...done.
Updating TBG_Hijacked... done.
Extracting TBG_Hijacked, detected gz...done.
Updating TBG_Bogon... done.
Extracting TBG_Bogon, detected gz...done.
Updating Bluetack_proxy... done.
Extracting Bluetack_proxy, detected gz...done.
Updating Bluetack_dshield... done.
Extracting Bluetack_dshield, detected gz...done.
[ OK ]
Inserting iptables ...iptables v1.3.8: invalid port/service `vnc' specified
Try `iptables -h' or 'iptables --help' for more information.
[fail]
2009-03-17 21:09:43 GMT Begin: moblock-control start
Inserting iptables ...iptables: Chain already exists
[fail]
2009-03-17 21:18:59 GMT Begin: moblock-control start
Inserting iptables ...iptables: Chain already exists
...fail!
2009-03-17 21:19:05 GMT Begin: moblock-control start
Inserting iptables ...iptables: Chain already exists
...fail!
2009-03-17 21:22:15 GMT Begin: moblock-control stop
Deleting iptables ...iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
[fail]
* There occured some errors during the deletion of the iptables rules.
* The most common reason for this is that they did not exist, because MoBlock
* was not running. In this case you don't have to worry.
* But if MoBlock was running there is some problem. Most probably you have
* installed another firewall application that did delete the iptables rules.
* A "moblock-control restart" will then fix the situation.
Executing /etc/moblock/iptables-custom-remove.sh ... [ OK ]
Stopping MoBlock ... [ OK ]
2009-03-17 21:22:15 GMT End: moblock-control stop
2009-03-17 21:55:40 GMT Begin: moblock-control start
Inserting iptables ...iptables v1.3.8: invalid port/service `vnc' specified
Try `iptables -h' or 'iptables --help' for more information.
[fail]
2009-03-18 07:01:11 GMT Begin: moblock-control start
Inserting iptables ...iptables: Chain already exists
[fail]
2009-03-18 07:03:31 GMT Begin: moblock-control restart
Deleting iptables ...iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
[fail]
* There occured some errors during the deletion of the iptables rules.
* The most common reason for this is that they did not exist, because MoBlock
* was not running. In this case you don't have to worry.
* But if MoBlock was running there is some problem. Most probably you have
* installed another firewall application that did delete the iptables rules.
* A "moblock-control restart" will then fix the situation.
Executing /etc/moblock/iptables-custom-remove.sh ... [ OK ]
Stopping MoBlock ... [ OK ]
Inserting iptables ...iptables v1.3.8: invalid port/service `vnc' specified
Try `iptables -h' or 'iptables --help' for more information.
[fail]
2009-03-18 07:04:13 GMT Begin: moblock-control update
Updating blocklists ...
Updating TBG_Primary_Threats... done.
Extracting TBG_Primary_Threats, detected gz...done.
Updating TBG_General_Corporate_Ranges... done.
Extracting TBG_General_Corporate_Ranges, detected gz...done.
Updating TBG_Business_ISPs... done.
Extracting TBG_Business_ISPs, detected gz...done.
Updating TBG_Search_Engines... done.
Extracting TBG_Search_Engines, detected gz...done.
Updating TBG_Hijacked... done.
Extracting TBG_Hijacked, detected gz...done.
Updating TBG_Bogon... done.
Extracting TBG_Bogon, detected gz...done.
Updating Bluetack_proxy... done.
Extracting Bluetack_proxy, detected gz...done.
Updating Bluetack_dshield... done.
Extracting Bluetack_dshield, detected gz...done.
Blocklists updated.
* MoBlock is not running, doing nothing.
2009-03-18 07:06:10 GMT End: moblock-control update
2009-03-18 07:12:15 GMT Begin: moblock-control start
Building blocklist... [ OK ]
Inserting iptables ...iptables: Chain already exists
[fail]


Is anyone able to help me?

Thanks

jre
March 19th, 2009, 10:46 AM
You want traffic on the "vnc" port whitelisted. For this to work, you have to specify the correct port number. See here (http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers) for a list of port numbers.

It's very confusing that iptables (the part of your system that is used for the port whitelisting) accepts some "service names" like http and https, which leeds users erroneously to the assumption that they can use all names. So I suggest to always use only the numbers (except for http and https because of a bug in mobloquer, which gets confused there if you specify 80 and 443).

BTW: Please have a look at my signature --> post output in CODE tags.

womble12345
March 19th, 2009, 11:24 PM
You want traffic on the "vnc" port whitelisted. For this to work, you have to specify the correct port number.

Thanks for the reply, I made that change and now it works great!
Thanks once again, its a great app.

Simon

ranpha
March 22nd, 2009, 11:01 AM
Just make sure that firestarter is started before MoBlock. Then go with the Moblock 0.9 default settings (i.e. FONT="Courier New"]IPTABLES_SETTINGS="1"[/FONT] and MARKing on). Every firestarter change then requires a moblock-control restart.
I have just added informations to post #1 how you can verify correct settings.

If the above doesn't work for you you can go with the other old instructions.

Finally you may try this (not tested, please give feedback if you do this):
Keep the MoBlock configuration as it is. In the firehol.conf add as last line moblock-control restart.
IIRC firehol works that way that commands in its conf are simply executed, so this way you can make sure that MoBlock is restarted after every firehol change (firehol purges all other iptables rules).

Is there a default firehol example file ? I have the old default settings like

iptables --new moblock
iptables -A moblock -j NFQUEUE

and i moblock

IPTABLES_SETTINGS="0"
IPTABLES_ACTIVATION="0"

but I saw that now recommend iptables_settings=1. I tried both but when i do the moblock-control test all I get are fails. Also tail -f /var/log/moblock/moblock.log doesn't give the ips address it's blocking. How can i check if moblock-control is up and running

jre
March 22nd, 2009, 11:32 AM
The easiest way should be to keep the default settings, but make sure to start MoBlock after Firehol (and restart it if firehol changed anything).

See also "How to make sure that MoBlock is integrated correctly with any other firewall" in post #1 in this thread.

jre
March 22nd, 2009, 08:20 PM
I just released blockcontrol (http://moblock-deb.sourceforge.net) 1.3. blockcontrol was previously known as moblock-control. It's designed to do all tasks related to IP block daemons (MoBlock (http://moblock.berlios.de/) or NFBlock (http://sites.google.com/site/makovick/nfblockd-daemon)).

The MoBlock GUI mobloquer (http://mobloquer.foutrelis.com/) is based on blockcontrol. So I adapted the mobloquer code and made a release, too: mobloquer 0.6. I'm sorry to say, that we still miss an active developer for mobloquer.

NFBlock is now fully supported by blockcontrol. Therefore I added nfblock 0.6.2 to the Debian (and Ubuntu) repository, see below.

Features:

Start and stop IP block daemon. Or let init do this automatically.
Update your blocklist from online sources and local blocklists. Or let cron do this automatically on a regular basis.
Remove lines by keyword from the blocklists.
Handle your iptables rules: use a default setup, easily allow all traffic on specific ports and use an allow list, or add your own sophisticated iptables rules.
Allow all LAN traffic and the DNS server automatically. If you are on a public LAN, you probably want to disable this feature.
Check the status and test the IP block daemon.
Detects if kernel modules are needed and loads them if necessary.
Set verbosity and logging options.
Provides LSB 3.1 compatible init script.
Daily rotation of the logfiles.


NEWS:

Full support for Moblock and NFBlock.
New option "search": Examine your selected blocklists by searching the single blocklists for keywords.
All user configuration is now done in /etc/blockcontrol/blockcontrol.conf. Not any more in /etc/default/...


Download/packages:
blockcontrol is available at http://moblock-deb.sourceforge.net
You can get Debian (and Ubuntu) packages of blockcontrol, MoBlock, mobloquer and NFBlock at http://moblock-deb.sourceforge.net

jre

Dawa
March 22nd, 2009, 10:33 PM
jre could you pleeeeaaaase put the old versions back up on the repos for the time being; this has completely broken moblock for me!

EDIT: I got it working; I did a "completely uninstall" on all things moblock through synaptic and installed it again. Everything seems to be working fine; the only problem I found is that Mobloquer constantly says "N/A" after Number of Blocked IP Ranges.

lovinglinux
March 22nd, 2009, 11:23 PM
What's the difference between Moblock and NFBlock?

Is there any advantage of using one or the other?

jre
March 23rd, 2009, 12:18 AM
Dawa, can you describe the problems more closely? I need to know if there is really something broken. Please post the output of:

dpkg -l moblock mobloquer blockcontrol
blockcontrol show_config

http://sites.google.com/site/makovick/nfblockd-daemon

NFBlock blocker has been inspired by MoBlock and PeerGuardian. NFblock has simpler and cleaner code, 2-3 times smaller typical memory footprint, can read gzipped ASCII blocklists, and run as a daemon.

NFBlock uses the same technics for the blocking (iptables, NFQUEUE, marking, ...). But it has no GUI yet. On the other side it has a dbus interface, so that a GUI could interact directly, instead of reading the logfile, as mobloquer needs to do.

Dawa
March 23rd, 2009, 04:11 PM
jre-

sorry, I already did that completely remove/reinstall thing so moblock is working fine now. The total IPs are showing up in mobloquer now, too.

As I remember it, I updated to the new version, tried to update the blocklists, and recieved an error. I removed the offending blocklist from the list (it was the TBG Edu list), and the update worked, but when i tried to start moblock it would read 0 total IPs blocked after loading and then it would "crash out"... the best way i can explain it is that the green check mark in mobloquer turned immediately back into a red X after loading.

I'm guessing maybe this had something to do with the transition from moblock-control to blockcontrol; like I said though, everything seems to be working fine after i completely uninstalled and reinstalled all things moblock (except for the old moblock-control transitional package, of course).

ully-mick
March 23rd, 2009, 06:51 PM
Hi,
I was getting update errors today, so I uninstalled/reinstalled moblock and mobloquer. moblock as installed but mobloquer won't install. I get this error in synaptic.

"mobloquer:

Package mobloquer has no available version, but exists in the database.
This typically means that the package was mentioned in a dependency and never uploaded, has been obsoleted or is not available with the contents of sources.list"

and in terminal I get this.

"desktop:~$ sudo apt-get update
desktop:~$ sudo apt-get install moblock mobloquer
moblock is already the newest version.
Package mobloquer is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source
E: Package mobloquer has no installation candidate"

jre
March 23rd, 2009, 07:02 PM
dawa, well, then we will never know. It seems as if noone else had problems, yet :-)

One aim of yesterday's release was to fix the "Number of blocked IP ranges: N/A". So I was a bit surprised to hear of problems.
dpkg --print-architecture

ully-mick
What's your distribution? What are your entries in /etc/apt/sources.list?
Please post your "dpkg --print-architecture".
I will check the repository then.

Meanwhile please try a "sudo aptitude update" again; perhaps somehting got lost.

EDIT: You may download the package manually: It's in http://moblock-deb.sourceforge.net/debian/pool/main/m/mobloquer/

ully-mick
March 23rd, 2009, 08:19 PM
distro = 8.04 hardy, architecture = i386,
hardy is not on the list in http://moblock-deb.sourceforge.net/debian/pool/main/m/mobloquer/ so that may be why.
I tried this one "mobloquer_0.6-1_i386.deb" and it gave me this "error: Dependency is not satisfiable: libqtcore4" and when I try to install that I get
$ sudo apt-get install libqtcore4
[sudo] password for mick:
Reading package lists... Done
Building dependency tree
Reading state information... Done
E: Couldn't find package libqtcore4

source list

# deb cdrom:[Ubuntu 8.04.1 _Hardy Heron_ - Release i386 (20080702.1)]/ hardy main restricted
# See http://help.ubuntu.com/community/UpgradeNotes for how to upgrade to
# newer versions of the distribution.

deb http://gb.archive.ubuntu.com/ubuntu/ hardy main restricted
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy main restricted

## Major bug fix updates produced after the final release of the
## distribution.
deb http://gb.archive.ubuntu.com/ubuntu/ hardy-updates main restricted
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy-updates main restricted

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## universe WILL NOT receive any review or updates from the Ubuntu security
## team.
deb http://gb.archive.ubuntu.com/ubuntu/ hardy universe
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy universe
deb http://gb.archive.ubuntu.com/ubuntu/ hardy-updates universe
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy-updates universe

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## multiverse WILL NOT receive any review or updates from the Ubuntu
## security team.
deb http://gb.archive.ubuntu.com/ubuntu/ hardy multiverse
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy multiverse
deb http://gb.archive.ubuntu.com/ubuntu/ hardy-updates multiverse
deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy-updates multiverse

## Uncomment the following two lines to add software from the 'backports'
## repository.
## N.B. software from this repository may not have been tested as
## extensively as that contained in the main release, although it includes
## newer versions of some applications which may provide useful features.
## Also, please note that software in backports WILL NOT receive any review
## or updates from the Ubuntu security team.
# deb http://gb.archive.ubuntu.com/ubuntu/ hardy-backports main restricted universe multiverse
# deb-src http://gb.archive.ubuntu.com/ubuntu/ hardy-backports main restricted universe multiverse

## Uncomment the following two lines to add software from Canonical's
## 'partner' repository. This software is not part of Ubuntu, but is
## offered by Canonical and the respective vendors as a service to Ubuntu
## users.
deb http://archive.canonical.com/ubuntu hardy partner
# deb-src http://archive.canonical.com/ubuntu hardy partner

deb http://security.ubuntu.com/ubuntu hardy-security main restricted
deb-src http://security.ubuntu.com/ubuntu hardy-security main restricted
deb http://security.ubuntu.com/ubuntu hardy-security universe
deb-src http://security.ubuntu.com/ubuntu hardy-security universe
deb http://security.ubuntu.com/ubuntu hardy-security multiverse
deb-src http://security.ubuntu.com/ubuntu hardy-security multiverse
deb http://moblock-deb.sourceforge.net/debian hardy main
deb-src http://moblock-deb.sourceforge.net/debian hardy main

jre
March 23rd, 2009, 09:52 PM
I dropped mobloquer from gutsy and hardy, because they don't fulfill the build dependencies any more.

If you are on these distributions I recommend to update to intrepid ;-)

If you don't want to do that: I've set up a mirror of the old repository, as it existed the previous 2 months, until yesterday's updates. Simply change your moblock-deb entries in /etc/apt/sources.list to contain 20090109 instead of debian. E.g.

deb http://moblock-deb.sourceforge.net/20090109 hardy main

lovinglinux
March 24th, 2009, 02:24 AM
I dropped mobloquer from gutsy and hardy, because they don't fulfill the build dependencies any more.

If you are on these distributions I recommend to update to intrepid ;-)

Mobloquer won't work with the new blockcontrol?

freedom
March 24th, 2009, 11:16 AM
here is what I get with
gdb mobloquer...
(gdb) run
Starting program: /usr/bin/mobloquer
[Thread debugging using libthread_db enabled]
[New Thread 0xb6d616c0 (LWP 30846)]
** Warning: void Mobloquer::g_SetRootPath(const QString&) Prefered file "/usr/bin/kdesu" could not be found, using "/usr/bin/gksu" instead
** Fatal: ASSERT failure in QVector<T>::insert: "index out of range", file /usr/include/qt4/QtCore/qvector.h, line 329

Program received signal SIGABRT, Aborted.
[Switching to Thread 0xb6d616c0 (LWP 30846)]
0xb7f2d430 in __kernel_vsyscall ()
(gdb)

jre
March 24th, 2009, 05:54 PM
Mobloquer won't work with the new blockcontrol?

mobloquer 0.6 works with blockcontrol (and no more with moblock-control). That's why I patched that source and made a release. If it does not, please tell me.
It even should run better then mobloquer 0.5 + moblock-control 1.2.

@freedom: thanks, that looks much more informative now. But I don't know if I can make anything from that.

ully-mick
March 25th, 2009, 12:14 PM
"If you are on these distributions I recommend to update to intrepid"
done that, everything works fine now.
thanks jre =D>

dj_flx
March 27th, 2009, 04:24 PM
I dropped mobloquer from gutsy and hardy, because they don't fulfill the build dependencies any more.

If you are on these distributions I recommend to update to intrepid ;-)

Sorry, not an option or a function of want for me. Intrepid broke my legacy drivers and I CAN'T upgrade from Hardy.

I'm sticking with it because it's LTS, also.

jre
March 28th, 2009, 06:15 PM
I have just uploaded a patched version for mobloquer hardy to the normal repository. Please try again with the sources.list entry

deb http://moblock-deb.sourceforge.net/debian hardy main and give me feedback if everything works.

dj_flx
March 28th, 2009, 06:51 PM
I have just uploaded a patched version for mobloquer hardy to the normal repository. Please try again with the sources.list entry

deb http://moblock-deb.sourceforge.net/debian hardy main and give me feedback if everything works.

Thank you, so far everything seems to be working fine.

JasonDFR
March 29th, 2009, 10:07 AM
My question is about opening a Listening Port to use with Transmission torrent client.

When moblock is NOT running, the port I have assigned to Transmission is open.

When moblock IS running, the port I have assigned to Transmission is closed.

I would like this port to be opened, but still have moblock screening all the blocklisted ips.

Whitelisting the port with the setting below will open the port for Transmission, however I still want the traffic to be screened. Is the traffic still screened when you open a port in this way? Or is all traffic on this port whitelisted?


WHITE_TCP_IN="12345"

What changes to the configuration are necessary to open a listening port for Transmission, but still have all the traffic connecting to Transmission screened?

BTW, I have the latest version of MoBlock as of March 29 2009.

Thanks.

lovinglinux
March 29th, 2009, 11:35 AM
My question is about opening a Listening Port to use with Transmission torrent client.

When moblock is NOT running, the port I have assigned to Transmission is open.

When moblock IS running, the port I have assigned to Transmission is closed.

I would like this port to be opened, but still have moblock screening all the blocklisted ips.

I'm not sure what exactly is your situation. Moblock itself doesn't close ports, unless you have iptables rules in the built-in custom scripts. So first check if you have any rules on these files:

/etc/blockcontrol/iptables-custom-insert.sh
/etc/blockcontrol/iptables-custom-remove.sh

The first script above is loaded when you start moblock and the second is loaded when you stop moblock. These scripts are not related to the IP blocking feature, they are for regular iptables (firewall) rules, which means you can use them to replace a firewall manager like Firestarter or UFW. It appears that you might have some rules in the iptables-custom-insert.sh that would be closing the port. So when you start moblock the script iptables-custom-insert.sh kicks in an close it. When you stop moblock, then iptables-custom-remove.sh kicks in and could be removing the rules closing the port. This is one possible scenario if I understood you correctly.

Another possible scenario is that you have a firewall manager being loaded after moblock and it is overriding moblock's rules, closing the torrent port. When you stop moblock, the firewall manager rules would be overwritten and the port is opened.


Whitelisting the port with the setting below will open the port for Transmission, however I still want the traffic to be screened. Is the traffic still screened when you open a port in this way? Or is all traffic on this port whitelisted?


WHITE_TCP_IN="12345"

I think you are confusing things. You can close a port by disabling it's forwarding from the router to your machine or through a firewall rule that will DROP or REJECT traffic on that port. On both cases, no incoming connections will reach the client application (Transmission). As already explained, moblock doesn't close ports if you don't configure the custom iptables scripts. What it does is filter connections based on IP on all ports. You can of course whitelist a port, like you suggested above. In this case, moblock will not filter connections by IP on that port, but that doesn't mean the port is open, because you still need to allow incoming traffic through it in the iptables rules.

The configuration you suggested above is not recommended if you want to filter IPs, because the port will be whitelisted by moblock. Which means moblock will ignore connections on that port and will let them go through the rest of the iptables rules. In other words, is like disabling moblock for that specific port. If you don't have iptables rules blocking that port, then it will be completely open.


What changes to the configuration are necessary to open a listening port for Transmission, but still have all the traffic connecting to Transmission screened?


Make sure the port selected on Transmission for receiving incoming connections is forwarded by the router to your machine
Make sure you have iptables rules that allow incoming connections on that port. This can be achieved using the iptables-custom-insert.sh script OR using a firewall manager like Firestarter and UFW OR by your own iptables scripts OR by adding the rule through command-line.
If you use a firewall manager, make sure moblock is started after it, otherwise the firewall manager will overwrite moblock's rules, turning it useless.
Don't whitelist the port on moblock's configuration if you want to filter the IPs from blocklists. I guess this is why you are using moblock.

jre
March 29th, 2009, 01:24 PM
@dj_flx: Thanks. I will then remove the static repository now. As I learnt, there are quite a few people on hardy, so I will try to continue support till 2011-04 (as long as the LTS desktop support by Ubuntu). I think dropping gutsy is no problem (support by Ubuntu will stop anyway on 2009-04-18).

@JasonDFR: You and lovinglinux are right, adding this port to WHITE_TCP_... would disable MoBlock for exactly the traffic that you want to check. So don't do it. To fully understand what is happening you should post your iptables rules. (sudo iptables -L -nv)
Although this is possible, I doubt that the reason is in your custom iptables scripts. Instead I think that transmission will check if a port is open by requesting a connect attempt by a certain test-IP. I think this test-IP is in the blocklists (for whatever reasons). So I recommend to watch your moblock.log and allow traffic to especially this test-IP (WHITE_IP_[IN|OUT]).

lovinglinux
March 29th, 2009, 01:59 PM
@dj_flx: Thanks. I will then remove the static repository now. As I learnt, there are quite a few people on hardy, so I will try to continue support till 2011-04 (as long as the LTS desktop support by Ubuntu). I think dropping gutsy is no problem (support by Ubuntu will stop anyway on 2009-04-18).

Nice.


Although this is possible, I doubt that the reason is in your custom iptables scripts. Instead I think that transmission will check if a port is open by requesting a connect attempt by a certain test-IP. I think this test-IP is in the blocklists (for whatever reasons). So I recommend to watch your moblock.log and allow traffic to especially this test-IP (WHITE_IP_[IN|OUT]).

Occam’s Razor (http://en.wikipedia.org/wiki/Occam%E2%80%99s_Razor) :)

JasonDFR
March 29th, 2009, 02:05 PM
Instead I think that transmission will check if a port is open by requesting a connect attempt by a certain test-IP. I think this test-IP is in the blocklists (for whatever reasons). So I recommend to watch your moblock.log and allow traffic to especially this test-IP (WHITE_IP_[IN|OUT]).

The above is exactly what is happening. 91.121.74.28 is blocked when Transmission checks to see if a port is open or not. 91.121.74.28 belongs to Transmissionbt.com, as far as I can tell.

The settings below cause Transmission to report that the port is open.



WHITE_IP_IN="91.121.74.28"
WHITE_IP_OUT="91.121.74.28"

@lovinglinux: Thanks for taking the time to explain things so well.

My router is set to open the port I am using. Moblock is simply not allowing Transmission to check the status of the port because it is blocking the ip Transmission attempts to connect to.

@jre: I had not even thought about how Transmission determines if a port is open or not. Thanks a lot for the great advice.

lovinglinux
March 29th, 2009, 02:11 PM
@lovinglinux: Thanks for taking the time to explain things so well.

My router is set to open the port I am using. Moblock is simply not allowing Transmission to check the status of the port because it is blocking the ip Transmission attempts to connect to.

@jre: I had not even thought about how Transmission determines if a port is open or not. Thanks a lot for the great advice.

I haven't thought that you were thinking the port was closed because Transmission was telling you this. jre was right on the spot. It's so obvious now :)

swan
March 31st, 2009, 11:25 PM
the last two updates have over written ;

/usr/lib/blockcontrol/blockcontrol.defaults

is it needed? twice ive had to be at console to fix post updates

warning much?

jre
April 1st, 2009, 08:57 PM
the last two updates have over written ;

/usr/lib/blockcontrol/blockcontrol.defaults

is it needed? twice ive had to be at console to fix post updates
Yes, it is needed and it should contain the defaults that I set. If you want to make changes then do them in /etc/blockcontrol/blockcontrol.conf (just add the variables as you see them in /usr/lib/blockcontrol/blockcontrol.defaults, and set your own values.)


warning much?
?

taqkavar
April 4th, 2009, 01:51 AM
hi, sorry I'm busy, no time to read any of the posts, just gonna jump in the middle of this thread and post this in case no one have posted about it yet:

If you use a dark theme with dark backgrounds and light font colours you have noticed mobloquer doesn't look so good and its hard to read some texts. It seems that programs like mobloquer and livestation that use the qt interface have this problem, to fix this just run /usr/bin/qtconfig-qt4 in terminal, select Tune Pallete and tweak the colours to match your theme, then go to file > save and you are done.

mamamia88
April 17th, 2009, 05:28 AM
hi guys installed from source in jaunty but can't get mobloquer to start all i get is something like described in this thread i created earlier. http://ubuntuforums.org/showthread.php?p=7085639 can someone please help me out?

jre
April 17th, 2009, 11:40 AM
hi guys installed from source in jaunty
Answered in the other thread, but well let's announce it here, too:

I'm currently setting up a PPA for jaunty (and all future Ubuntu releases). This supports as architectures: i386, amd64 and lpia.
Currently blockcontrol is still missing (but that's the exact same package on all dists and all archs), and I have current development versions in it, but they should work even better then the current releases.


deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu jaunty main

sleepyenglish
April 23rd, 2009, 09:44 PM
I'm trying to reinstall moblock after it froze while installing on jaunty(sorry forgot what stage but it was close to finishing) but it gets to "Stopping IP block daemon moblock" and thats it. I have left it for up to 10 minutes and still nothing, i tried the stop and purge commands as listed on https://help.ubuntu.com/community/MoBlock bt still nothing.

Please help.

jre
April 23rd, 2009, 10:00 PM
I'm trying to reinstall moblock after it froze while installing on jaunty(sorry forgot what stage but it was close to finishing) but it gets to "Stopping IP block daemon moblock" and thats it. I have left it for up to 10 minutes and still nothing
Most probably it was still downloading the blocklists (per default about 10MB). Have a look at /var/log/blockcontrol.log to see where it was.
Further please post the output of your package manager (just do the purge and install again).
Finally you may disable the automatic start. Then there is no "start" during installation, therefore no download of the blocklists and probably no other errors - so probably a less error prone installation. To disable the automatic start either do that during the debconf questions during installations, or set INIT="0" in /etc/blockcontrol/blockcontrol.conf.

EDIT: Another possibility is, that a debconf question was asked and was still waitng for your answer. This is explained in the FAQ at the wiki page, that you already cited.


i tried the stop and purge commands as listed on https://help.ubuntu.com/community/MoBlock bt still nothing.
I updated that page just a few hours ago. Make sure that you used the current commands (especially blockcontrol, not moblock-control).

sleepyenglish
April 23rd, 2009, 10:27 PM
Below is the output from "aptitude purge moblock blockcontrol mobloquer"


E: Could not get lock /var/lib/dpkg/lock - open (11 Resource temporarily unavailable)
E: Unable to lock the administration directory (/var/lib/dpkg/), is another process using it?
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
E: Could not get lock /var/lib/dpkg/lock - open (11 Resource temporarily unavailable)
E: Unable to lock the administration directory (/var/lib/dpkg/), is another process using it?


The INIT setting is set to 0

chronniff
April 24th, 2009, 01:01 AM
Hey I am having the same problem....well sleepenglish the last output you put up sounds like you forgot to but sudo before the command.....but I can't get the buggar off my system....when I installed in just hung when it said it was starting moblock, and on removal, even with INIT=0 and restarted it says it is trying to stop moblock, forever......I too would appreciate some of your genius, thanks

chronniff
April 24th, 2009, 01:16 AM
oh yeah, and it had definately downloaded all the iplists because I was watching the blockcontrol.log as it happened

chronniff
April 24th, 2009, 02:51 AM
actually I fixed it myself, I think....for some reason it didn't install the iptables-custom_insert.sh and iptables-custom_remove.sh scripts in the /etc/blockcontrol directory....I was lucky enough to have an installation already on an older installation and copying the scripts over to the new one seemed to fix everything....I then removed everything successfully, and tried to install again, and for some reason, I'm guessing something changed in the blockcontrol installation, those scripts aren't being installed though, so I will just do what I did again and leave it since that seems to work fine.....again all the block lists were downloaded fine by the way

sleepyenglish
April 24th, 2009, 09:39 AM
Its been(i.e. its still running) like the below for the last 30 min with still no luck and i doubled checked that INIT=0 and it is so what is it trying to stop?


mark@mark-laptop:~$ sudo aptitude purge moblock blockcontrol mobloquer
[sudo] password for mark:
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
Writing extended state information... Done
The following packages will be REMOVED:
blockcontrol{p} moblock{ap} mobloquer{p}
0 packages upgraded, 0 newly installed, 3 to remove and 0 not upgraded.
Need to get 0B of archives. After unpacking 532kB will be freed.
Do you want to continue? [Y/n/?] y
Writing extended state information... Done
(Reading database ... 104735 files and directories currently installed.)
Removing blockcontrol ...
* Stopping IP block daemon moblock

sleepyenglish
April 24th, 2009, 04:10 PM
I reinstalled Jaunty and followed the installation instuctions on https://help.ubuntu.com/community/MoBlock and its been doing the below for 20 min.


mark@mark-laptop:~$ tail -f /var/log/blockcontrol.log
...done.
Inserting iptables ...
Allowing inbound LAN traffic for 192.168.1.64 with subnetmask 255.255.255.0 ...done.
Allowing outbound LAN traffic for 192.168.1.64 with subnetmask 255.255.255.0 ...done.
Allowing forwarded LAN traffic for 192.168.1.64 with subnetmask 255.255.255.0 ...done.
Allowing outbound traffic to DNS server 192.168.1.254 ...done.
Allowing forwarded traffic to DNS server 192.168.1.254 ...done.
Allowing loopback traffic ...done.
...done.
Executing ...

As you can see from the attached image the "Debconf on mark-laptop" window seems to have frozen.

snek
April 24th, 2009, 05:19 PM
I can't seem to be able to install either on a fresh Jaunty Desktop i386 install..



Get:1 http://ppa.launchpad.net jaunty/main mobloquer 0.6-2~pre1~jaunty [263kB]
Fetched 263kB in 0s (864kB/s)
Selecting previously deselected package mobloquer.
(Reading database ... 116875 files and directories currently installed.)
Unpacking mobloquer (from .../mobloquer_0.6-2~pre1~jaunty_i386.deb) ...
Setting up blockcontrol (1.4-1~pre5~jaunty) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. If this
happens, then in most cases downloading the blocklists failed temporarily. To
workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"

* Starting IP block daemon moblock invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess post-installation script returned error exit status 8
dpkg: dependency problems prevent configuration of mobloquer:
mobloquer depends on blockcontrol; however:
Package blockcontrol is not configured yet.
dpkg: error processing mobloquer (--configure):
dependency problems - leaving unconfigured
No apport report written because the error message indicates its a followup error from a previous failure.
Errors were encountered while processing:
blockcontrol
mobloquer
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
Setting up blockcontrol (1.4-1~pre5~jaunty) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. If this
happens, then in most cases downloading the blocklists failed temporarily. To
workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"

* Starting IP block daemon moblock invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess post-installation script returned error exit status 8
dpkg: dependency problems prevent configuration of mobloquer:
mobloquer depends on blockcontrol; however:
Package blockcontrol is not configured yet.
dpkg: error processing mobloquer (--configure):
dependency problems - leaving unconfigured
Errors were encountered while processing:
blockcontrol
mobloquer
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initializing package states... Done
Writing extended state information... Done

sleepyenglish
April 24th, 2009, 05:55 PM
Has anyone got it running on jaunty?

sleepyenglish
April 24th, 2009, 06:20 PM
Well i was going to install iplist instead but it needs to remove moblock, blockcontrol and mobloqer. moblock and mobloqer remove ok but again blockcontrol halted the progress by staying at stopping blockcontrol indefinitely.

iamnotthemessiah
April 24th, 2009, 06:40 PM
same issues as the ppl above. cant get it working

lovinglinux
April 24th, 2009, 10:15 PM
Has anyone got it running on jaunty?

Running perfectly here, but I don't download the lists using moblock. I download them using a script, then I merge then using peerguardian and moblock only uses one merged list from local source.

sleepyenglish
April 24th, 2009, 10:26 PM
Anything and everything i try ends up in
* Stopping IP block daemon moblock

hanging indefinitely. If i under stood correctly the setting INIT=0 means it wont auto start so how come everything i try starts with it hanging on stopping ip block daemon moblock? Is this daemon a file i can just delete because this is starting to :( me.

lovinglinux
April 24th, 2009, 10:40 PM
Anything and everything i try ends up in

hanging indefinitely. If i under stood correctly the setting INIT=0 means it wont auto start so how come everything i try starts with it hanging on stopping ip block daemon moblock? Is this daemon a file i can just delete because this is starting to :( me.

I had that problem and solved it after manually adding the custom scripts.

sleepyenglish
April 24th, 2009, 10:41 PM
Care to share :popcorn:

lovinglinux
April 24th, 2009, 10:52 PM
Care to share :popcorn:

Do you want the explanation or the scripts?

I basically use moblock with a series of "profiles", depending on what I'm doing on the network. These profiles are activated by scripts that copy the files blockcontrol.conf, blocklists.list, iptables-custom-insert.sh and iptables-custom-remove.sh from a backup folder into /etc/blockcontrol/ directory every time I activate them. All my lists included in blocklists.list are stored locally, so moblock never stall when trying to download. These lists are a compilation of moblock's lists, downloaded via wget and merged into a single list for each profile, using peerguardian.

talz13
April 25th, 2009, 01:03 AM
I was able to get around the lockup on Starting... or Stopping... by copying my old startup/shutdown scripts from my previous install of moblock (yay for backing up /etc before formatting!)

Maybe it will help others, so I attached the necessary scripts here. Just download them, copy them to /etc/blockcontrol/ and make sure they are owned by root and executable:

cd /etc/blockcontrol/
sudo chown root.root iptables-custom-*
sudo chmod 755 iptables-custom-*

I am not responsible if you screw anything up, just take this as advice from what worked for me.

sleepyenglish
April 25th, 2009, 06:55 AM
Do you want the explanation or the scripts?

I basically use moblock with a series of "profiles", depending on what I'm doing on the network. These profiles are activated by scripts that copy the files blockcontrol.conf, blocklists.list, iptables-custom-insert.sh and iptables-custom-remove.sh from a backup folder into /etc/blockcontrol/ directory every time I activate them. All my lists included in blocklists.list are stored locally, so moblock never stall when trying to download. These lists are a compilation of moblock's lists, downloaded via wget and merged into a single list for each profile, using peerguardian.

Thats a pretty cool way to do things its a shame moblock cant handle profiles out of the box.


I was able to get around the lockup on Starting... or Stopping... by copying my old startup/shutdown scripts from my previous install of moblock (yay for backing up /etc before formatting!)

Maybe it will help others, so I attached the necessary scripts here. Just download them, copy them to /etc/blockcontrol/ and make sure they are owned by root and executable:

cd /etc/blockcontrol/
sudo chown root.root iptables-custom-*
sudo chmod 755 iptables-custom-*

I am not responsible if you screw anything up, just take this as advice from what worked for me.

Talz13 thats seem to have have fixed the issue, thanks a bunch. Anyone know how i can start the first run set up again?

jre
April 25th, 2009, 01:04 PM
Sorry for the inconvenience, these things seem to happen whenever I have no time :-/

I have fixed it in blockcontrol_1.4.1-1~jaunty. I'm just uploading the package, it should be available in a few minutes.
During the update from the current broken jaunty package this one will hang again. So you have to interrupt (press "control" + "c") the update in order to force the use of a new script. Then everything will work.

On updates from older, non-broken versions or on new installations everything will work flawless.

The problem was that the custom iptables scripts aren't installed to /etc/blockcontrol/ any more. Instead they go to /usr/share/doc/blockcontrol/examples and blockcontrol will execute every ...insert.sh or ...remove.sh script that is in /etc/blockcontrol/. This might be useful for a future mobloquer release, which might allow easy whitelisting of IP+port combinations.
Unfortunately my last version was broken if none such script existed.

sleepyenglish
April 25th, 2009, 09:51 PM
Jre could you please tell me how i could run the setup gui that appears on initial installation.

jre
April 25th, 2009, 11:21 PM
Jre could you please tell me how i could run the setup gui that appears on initial installation.
Just confirm everything. See here:
https://help.ubuntu.com/community/MoBlock#I%20tried%20to%20install%20MoBlock%20but%2 0I%27m%20stuck%20on%20a%20screen%20with%20a%20Mobl ock%20warning

spockrock
April 26th, 2009, 09:18 PM
I am having issue where it seems that blockcontrol is not using the /etc/blockcontol/blockcontrol.conf configuration file. The result is that all my network traffic is getting blocked. Where do I go to tell blockcontrol to use the blockcontrol.conf??

jre
April 26th, 2009, 10:50 PM
I am having issue where it seems that blockcontrol is not using the /etc/blockcontol/blockcontrol.conf configuration file. The result is that all my network traffic is getting blocked. Where do I go to tell blockcontrol to use the blockcontrol.conf??

You have to "blockcontrol restart" after changing the configuration.

Check "blockcontrol show_config" to see if your changes are seen by blockcontrol.

spockrock
April 27th, 2009, 06:41 AM
You have to "blockcontrol restart" after changing the configuration.

Check "blockcontrol show_config" to see if your changes are seen by blockcontrol.


I did the show_config and it was showing my changes, but doing a blockcontrol reload and a blockcontrol restart fixed it. I am assuming that blockcontrol stop and blockcontrol start is not the equivalent to blockcontrol restart???

jre
April 27th, 2009, 05:54 PM
I am assuming that blockcontrol stop and blockcontrol start is not the equivalent to blockcontrol restart???
Nope, it's exactly the same.
Further, on a restart all steps should be done that are done on reload.

Jerriy
April 29th, 2009, 11:43 AM
Hi jre - I have a question:

How do you customize/add your own ip blocks? I noticed that in Mobloquer one of my Blocklists, the one called custom-blocklist, is disabled by default. I enabled it and then moblock tried to restart but failed. I had to "detick" the Enable box for that blocklist in order to restore the program. So then, how do I customize/add my own ip blocks? Apparently it involves creating a file in a particular folder called "custom-blocklist.p2p or something, right? The question is how on earth do I do that on Mobloquer?

jre
April 29th, 2009, 05:55 PM
How do you customize/add your own ip blocks? I noticed that in Mobloquer one of my Blocklists, the one called custom-blocklist, is disabled by default. I enabled it and then moblock tried to restart but failed. I had to "detick" the Enable box for that blocklist in order to restore the program. So then, how do I customize/add my own ip blocks? Apparently it involves creating a file in a particular folder called "custom-blocklist.p2p or something, right? The question is how on earth do I do that on Mobloquer?

It's not possible (yet) to add your own block-ranges in mobloquer. But it's possible manually.

Step 1:
You need an entry in /etc/blockcontrol/blocklists.list that points to your custom blocklist, that starts with "locallist", e.g.

locallist /etc/blockcontrol/custom-blocklist.p2p

When you enabled the local blocklist in mobloquer just that line was enabled in blocklists.list (per default it's commented with a hash (#), so it's not used).

Step 2:
You need that list. So create /etc/blockcontrol/custom-blocklist.p2p, or perhaps it's better to use a file in your home directory, so that you don't need root rights to edit your own blocklist and of course you have to fill that list with entries, e.g.:

My first blocked range:123.123.123.123-123.234.234.234


Step 3:
Restart blockcontrol (or press restart in mobloquer). Verify in the logfile /var/log/blockcontrol.log if everything works.

I guess you had such an entry:

Building blocklist... Updating /etc/blockcontrol/custom-blocklist.p2p... * Error 9: /etc/blockcontrol/custom-blocklist.p2p not available. Aborting!
This happens if you do step 1, but don't actually create that list.

dj_flx
April 29th, 2009, 11:38 PM
I see that Moblock is reporting Tor being blocked every so often in the logs.

Is it possible to run Moblock and Tor at the same time? Or are these not "real" Tor nodes it's blocking?

iamnotthemessiah
April 30th, 2009, 04:59 PM
is there a simple way to get the number of blocked ranges? i like to have that in my conky but it doesent seem to work anymore the way i did it before. i used to add to the updater script something like:grep 'Ranges loaded' /var/log/moblock.log | awk '{print $8}' | tail -n 1 > /home/XXX/various/scripts/misc/various/moranges.txt - and let conky read that (yes i know its a different logfile now - still doesent work)

there should be a simple 'blockcontrol -ranges' or something. maybe it is and i just didnt find it

jre
April 30th, 2009, 07:11 PM
I see that Moblock is reporting Tor being blocked every so often in the logs.

Is it possible to run Moblock and Tor at the same time? Or are these not "real" Tor nodes it's blocking?

Solution 1:
Per default this list is enabled:

http://www.bluetack.co.uk/config/proxy.gz


This list has been compiled from a list of Tor servers and various other proxy servers.
See
https://help.ubuntu.com/community/MoBlock#How%20do%20I%20choose%20what%20blocklists% 20to%20include%20in%20the%20update%20function?

Solution 2:
Or allow the tor port (I guess for in and out traffic, or is it forward!?) Just allow it for all TCP traffic:
WHITE_TCP_FORWARD="9001 9030 9050"
WHITE_TCP_IN="9001 9030 9050"
WHITE_TCP_OUT="9001 9030 9050"

See
https://help.ubuntu.com/community/MoBlock#Some applications cannot connect to the internet any more! and http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Solution 3:
You may choose some IPs of tor servers and especially whitelist them. But I doubt that this is practical and good for the tor community, because you will miss most. Still you could do that together with solution 1 for the rest of the tor servers if they should be in any other list.

Dawa
May 5th, 2009, 06:00 AM
i just installed the latest blockcontrol update. not only did it remove most of my blocklists, but when i tried to add one mobloquer crashed and now will not start again.

jre, is there any way to provide updates without resetting the blocklists? that would be ideal.

edit: once again, a complete uninstall in synaptic of all things moblock and then a re-install solved the problem. it seems like mobloquer has trouble whenever moblock/blockcontrol updates on my system.

jre
May 5th, 2009, 06:08 PM
i just installed the latest blockcontrol update. not only did it remove most of my blocklists, but when i tried to add one mobloquer crashed and now will not start again.

jre, is there any way to provide updates without resetting the blocklists? that would be ideal.

edit: once again, a complete uninstall in synaptic of all things moblock and then a re-install solved the problem. it seems like mobloquer has trouble whenever moblock/blockcontrol updates on my system.

Which blocklists were removed? You mean your configuration? Of course that shouldn't happen and I've never observed this. Can you provide further information? Your old and new blocklists.list would be interesting, if they still exist.

Did you stop mobloquer before the update? I might add code to the package that kills mobloquer before an update and starts it again afterwards, if this is usefull.

EDIT:
The blocklsist settings are in /etc/blockcontrol/blocklists.list. If you have changed your blocklist configuration (whether manually or in mobloquer), then this file gets changed. During updates you are asked, whether you want to install a new version of /etc/blockcontrol/blocklists.list. If you say "Yes", then my version gets installed. If you say "No", then your version with your configuration settings keeps installed.
So you have to make sure not to say "Yes".

This is the general handling of configuration files in Debian packages. I doubt that I have broken this.

iamnotthemessiah
May 5th, 2009, 07:35 PM
started getting errors today
Removing the following lines from Bluetack_proxy:
* Error: grep exited with 1

so the update doesent finish... dunno what more info u need. let me know

jre
May 5th, 2009, 07:49 PM
Please post the output of

blockcontrol show_config | grep IP_REMOVE

iamnotthemessiah
May 5th, 2009, 07:57 PM
IP_REMOVE="Norwegian Broadcasting Corporation;BBC;LeaseWeb B.V;netdirekt;Easy Online Solutions;America Online;Hetzner Online AG"

jre
May 5th, 2009, 08:12 PM
I just investigated that a bit. For some reason the bt_proxy list was downloaded today with 0 bytes. This causes the problems. This is not related to the blockcontrol update!
Just disable the bt_proxy list for now in /etc/blockcontrol/blockcontrol.conf.

I'll try to change blockcontrol, so that it doesn't break if this happens.

iamnotthemessiah
May 5th, 2009, 08:27 PM
ah that explains it. thanks, i should have checked the files.
but yeah hope you can fix this :)

edit: you probably mean /etc/blockcontrol/blocklists.list

lovinglinux
May 6th, 2009, 02:26 PM
I just investigated that a bit. For some reason the bt_proxy list was downloaded today with 0 bytes. This causes the problems. This is not related to the blockcontrol update!
Just disable the bt_proxy list for now in /etc/blockcontrol/blockcontrol.conf.

I'll try to change blockcontrol, so that it doesn't break if this happens.

I don't know if this info is useful or not, but I have downloaded bt_proxy from iblocklist source yesterday using wget and it was normal. The only odd thing was that while most lists were update on May 5th, this one was updated on May 1st, together with the templist and spyware.

I have downloaded it again today from iblocklist and from bluetack and both downloads were normal. The file was updated today.

Nevertheless, I have experienced a strange behavior on merging the lists manually with peerguardian before, exactly for the same reason.

jre
May 6th, 2009, 04:03 PM
Thanks. For me bt_proxy was 0 bytes with blockcontrol, wget and the manual web download yesterday. I contacted the iblocklist maintainer. The list is now back to normal again:
http://iblocklist.com/list.php?list=bt_proxy

badpeers (templist) and spyware currently download fine (but they are not in the default blockcontrol configuration).

I have a blockcontrol update ready, which checks the file size before doing the IP_REMOVE stuff.

iamnotthemessiah
May 6th, 2009, 04:22 PM
yep it all works again now :)

got another question jre, with previous versions i used to get an email sent to my system mailbox after an update. this doesent seem to happen anymore since jaunty. keeping in mind i used a rather old version of moblock/moblock-control (not blockcontrol) in intrepid. any way to get that back?

jre
May 6th, 2009, 04:34 PM
You can specify the recipient for the cron job results. E.g. the default setting

CRON_MAILTO="root"
means that this mail is deliverd locally to root. You may specify any email address if you have configured your local mail system appropriately.
This is new since 1.3-1. Before this mail was sent by anacron. If the old worked, then the new should work, too. Please check /var/mail. Do you get other local mail delivered?
Do you have the executable /usr/sbin/sendmail or /usr/lib/sendmail on your system?

iamnotthemessiah
May 6th, 2009, 05:02 PM
ur right a all the messages got sent to root, i want it to my own user

thats in blockcontrol.conf yeah?
i just add
CRON_MAILTO="my_username" ?

jre
May 6th, 2009, 05:16 PM
Yes, either do it this way or generally forward root's mail to your user.

c.b.simas
May 11th, 2009, 09:40 PM
I realize that a lot of posts have been made on this subject so I feel bad asking the question over but I need to.

For starters, I'm using the mobloque GUI (and I'm ignorant about linux :) ).

Just as many people have had the problem where MoBlock wants to keep one from signing into Pidgin accounts; I had the same problem.

I looked at the log and saw when it was blocking Google or Microsoft, told MoBlock to not block the IP anymore, went under Settings > Whitelist IPs, highlighted the IP and clicked Whois to find the IP range for that host. I then copy/pasted the range, replaced the " - " with "/", clicked Add and restarted MoBlock. No problems thus far.

But, after whitelisting those IP ranges MoBlock is still blocking IPs that fall within those ranges. What am I doing wrong or not doing?

Thank you all in advance.

jre
May 11th, 2009, 10:03 PM
The GUI mobloquer does not yet support whitelisting of IP ranges. 192.168.178.0-192.168.178.255 or 192.168.178.0/192.168.178.255 are not valid entries in mobloquer!

Possible solutions:
Please have a look at https://help.ubuntu.com/community/MoBlock#But why can I not just remove the IP address from the blocklist instead?
In this link you find under "1. Whitelist an IP range in allow.p2p" how to whitelist IP ranges in /etc/blockcontrol/allow.p2p.

If you want to stay with mobloquer you might add single IPs with subnetmasks.
See in the above link "2. Whitelist an IP" for examples (e.g. 192.168.178.0/24 for the IP range 192.168.178.0-192.168.178.255). 192.168.178.0/24 is a valid entry in mobloquer.

SqRt7744
May 11th, 2009, 10:20 PM
I'm having trouble with Moblock interfering with Ekiga in Jaunty. With moblock running the ekiga PC-to-Phone account won't connect (or just the regular ekiga account for that matter). If I run "sudo blockcontrol stop" Ekiga can connect and I can place my calls.

Ekiga uses the SIP protocol.



grep sip < /etc/services


returns



sip 5060/tcp # Session Initiation Protocol
sip 5060/udp
sip-tls 5061/tcp
sip-tls 5061/udp


the contents of /etc/blockcontrol/blockcontrol.conf


WHITE_TCP_OUT="http https 465 587 993 1863 3478:3479 5000:5100 5190 5222 5353 7070 16382 22020:22025 35129"
WATCHDOG="0"
WHITE_IP_IN="192.168.1.0/24"
WHITE_IP_OUT="192.168.1.0/24"


I'll try adding WHITE_UDP_OUT="5000:5100" as well and see if that helps. It didn't. :(

c.b.simas
May 11th, 2009, 10:30 PM
Thank you for the help! So I'm having a problem: am I supposed to save allow.p2p once I'm done with it? I try to save it and I get: (see attachment)

I've had this problem before when trying to permanently disable my PC speaker.

How do I save the file?

jre
May 11th, 2009, 11:08 PM
@SqRt7744: That should do it. Don't forget the "restart" afterwards.

@c.b.simas: You need root rights. So start it with "sudo", as described in the link.

c.b.simas
May 11th, 2009, 11:26 PM
Look, I'm sorry, I'm ignorant about this. After I entered the IP ranges into allow.p2p I opened up the terminal and entered "sudo blockcontrol restart", entered my password and the IP block daemon moblock restarted.

So I close the terminal and try to close the allow.p2p file but it asks me if I want to save the changes, I click yes and I encounter my previously mentioned problem.

Am I supposed to enter "sudo" in another location? I tried it in various locations in the allow.p2p file but that did nothing. I also tried entering that command line into that file but that did nothing (like I said, I'm ignorant about this so I'm just testing stuff out to learn).

Am I missing the point of what you're saying or did you not fully understand my dilema?

c.b.simas
May 12th, 2009, 01:04 AM
Good news for you: there's no need to answer another one of my questions at this time. :)

I didn't realize there was a difference between accessing that file with gksudo gedit ... vrs through the file browser.

Like I said: I'm new. :)

SqRt7744
May 12th, 2009, 05:18 PM
Re. post #288 http://ubuntuforums.org/showpost.php?p=7259796&postcount=288

@jre: you said my changes should work, but they haven't... Ekiga still won't work unless I stop moblock first.

If I start ekiga with Moblock running I get the message:

"Ekiga did not manage to configure your network settings automatically. You can still use it, but you need to configure your network settings manually.

Please see http://wiki.ekiga.org/index.php/Enable_port_forwarding_manually for instructions"

----EDIT----
I have managed to solve it by adding the following entries to /etc/blockcontrol/blockcontrol.conf:



WHITE_TCP_IN="5000:5100"
WHITE_UDP_OUT="3478:3479 5000:5100"


----EDIT----

I was wrong, it still doesn't work. Neither the Echo test, nor a call to a landline.

madHasher
May 13th, 2009, 03:29 PM
I recently installed moblock on Jaunty, following the instructions on https://help.ubuntu.com/community/MoBlock. I used aptitude and installed moblock blockcontrol and mobloquer. Everything seemed ok while installing and configuring white lists but when I run it I get this error message.

Required configuration file "/var/log/moblock.log" could not be found in the default path.
Please specify a different path.

while all the other .conf and .log files seem to exist that one is no where to be found. I've tried removing and reinstalling this time just moblock and blockcontrol.





sudo aptitude install moblock blockcontrol
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initializing package states... Done
The following NEW packages will be installed:
blockcontrol libnetfilter-queue1{a} libnfnetlink0{a} moblock p7zip{a}
0 packages upgraded, 5 newly installed, 0 to remove and 22 not upgraded.
Need to get 0B/487kB of archives. After unpacking 1708kB will be used.
Do you want to continue? [Y/n/?] y
Writing extended state information... Done
Preconfiguring packages ...
Selecting previously deselected package libnfnetlink0.
(Reading database ... 142187 files and directories currently installed.)
Unpacking libnfnetlink0 (from .../libnfnetlink0_0.0.39-1_amd64.deb) ...
Selecting previously deselected package libnetfilter-queue1.
Unpacking libnetfilter-queue1 (from .../libnetfilter-queue1_0.0.16-1_amd64.deb) ...
Selecting previously deselected package moblock.
Unpacking moblock (from .../moblock_0.9~rc2-23~pre2~jaunty_amd64.deb) ...
Selecting previously deselected package blockcontrol.
Unpacking blockcontrol (from .../blockcontrol_1.4.4-1~jaunty_all.deb) ...
Selecting previously deselected package p7zip.
Unpacking p7zip (from .../p7zip_4.58~dfsg.1-1_amd64.deb) ...
Processing triggers for man-db ...
Setting up libnfnetlink0 (0.0.39-1) ...

Setting up libnetfilter-queue1 (0.0.16-1) ...

Setting up moblock (0.9~rc2-23~pre2~jaunty) ...
Setting up blockcontrol (1.4.4-1~jaunty) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. If this
happens, then in most cases downloading the blocklists failed temporarily. To
workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"




* Starting IP block daemon moblock invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess post-installation script returned error exit status 8
Setting up p7zip (4.58~dfsg.1-1) ...
Processing triggers for libc6 ...
ldconfig deferred processing now taking place
Errors were encountered while processing:
blockcontrol
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
Setting up blockcontrol (1.4.4-1~jaunty) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. If this
happens, then in most cases downloading the blocklists failed temporarily. To
workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"

* Starting IP block daemon moblock invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess post-installation script returned error exit status 8
Errors were encountered while processing:
blockcontrol
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initializing package states... Done
Writing extended state information... Donewhat shoudl I do?

jre
May 13th, 2009, 04:21 PM
I think the first error about "moblock.log" resulted from an old invalid moblock-control installation. I think we can forget about that now.

With your new installation something goes wrong with the iptables command. Perhaps you find something more informative in /var/log/blockcontrol.log.

I guess that there are already some iptables rules inserted before the installation, so inserting them during installation fails, because they are already present.

You may check your iptables rules with

sudo iptables -L -nv
In the output there must not be anything regarding blockcontrol, moblock or NFQUEUE if MoBlock is not running.

Perhaps just rebooting and continuing the blockcontrol installation is enough.

Otherwise do a clean uninstall:

sudo aptitude purge moblock moblock-control mobloquer blockcontrol

Then completely clean up your iptables (this will break other firewalls):

sudo iptables -F
sudo iptables -X

Then install again:

sudo aptitude install moblock mobloquer blockcontrol.


If your problems continue, please post your blockcontrol.log and the output of

sudo blockcontrol status
dpkg -l moblock moblock-control mobloquer blockcontrol

madHasher
May 13th, 2009, 11:17 PM
Thanks looks like that did the trick, not sure what went wrong with my first install but clearly I hadn't uninstalled thoroughly enough.

SqRt7744
May 14th, 2009, 10:08 PM
OK this is getting really annoying. I thought I had Ekiga sorted out, but a few calls just failed. Finally I thought I'd turn off moblock one more time just to see if it could still be interfering even though I have whitelisted all relevant ports (I believe). ...and it was moblock that was preventing the calls!

I'm not doing anything unusual, I'm just using Ekiga to call 500@ekiga.net, and I have put money into the call-out feature so I can call home. Any ideas what it could be? I appreciate any help I can get...

/etc/blockcontrol/blockcontrol.conf


WHITE_TCP_OUT="http https 465 587 993 1863 3478:3479 5000:5100 5190 5222 5353 7070 16382 35129"
WHITE_UDP_OUT="3478:3479 5000:5100"
WHITE_TCP_IN="5000:5100"
WATCHDOG="0"
WHITE_IP_IN="192.168.1.0/24"
WHITE_IP_OUT="192.168.1.0/24"

jre
May 15th, 2009, 02:47 PM
Set in /etc/blockcontrol/blockcontrol.conf
LOG_IPTABLES="LOG --log-level info"

Then do a "sudo tail -f /var/log/syslog" to see live what happens. You will see (source and destination) IP, (source and destination) port and protocol of every blocked packed.
For outgoing connections you have to look at the destination port and if the protocol is TCP or UDP for the whitelisting.

Unrelated: I see you have disabled the watchdog. Were there any errors or did it consume too much CPU?

SqRt7744
May 16th, 2009, 01:09 PM
@jre, sorry I don't know why the watchdog was diabled, I've re-enabled it. In any case, thanks for the tip about adding LOG_IPTABLES="LOG --log-level info" to blocklist.conf. It helped me somewhat... after adding a bunch of ports and *still* not being able to connect, I added the IPs that I got from syslog for ekiga and diamondcard and it works now.

Would it be possible to integrate an 'allow common apps' checklist into the gui? Perhaps with a few things such as 'Pidgin' [msn, icq, etc] 'ekiga' (although I still haven't really figured out which ports this behemoth really needs) and others? Maybe also an "allow connections to 'some domain name'" ...because the way it is set up at the moment, although a great program, seems a tad too awkward for many.

thanks for your quick reply in any case :)

jre
May 16th, 2009, 02:20 PM
Would it be possible to integrate an 'allow common apps' checklist into the gui? Perhaps with a few things such as 'Pidgin' [msn, icq, etc] 'ekiga' (although I still haven't really figured out which ports this behemoth really needs) and others? Maybe also an "allow connections to 'some domain name'" ...because the way it is set up at the moment, although a great program, seems a tad too awkward for many.

I would add this to the documentation. Especially the wiki at https://help.ubuntu.com/community/MoBlock might be a good place for that. (This is editable by everybody!!). At the moment I just give a link to the wikipedia overview of common ports. I didn't know that allowing ekiga is so complicated (I don't use it). So this would be a good candidate for extended documentation.
Further I could add suggestions for commonly used whitelistings to /usr/lib/blockcontrol/blockcontrol.defaults.
But I think whitelisting per domain name is not feasible, because this requires remote DNS lookups.

Ready made "click and go" solutions are only possible in the GUI mobloquer. I'm not the author of that, and I would prefer another implementations there, which is very general but still serves your purpose:
Let mobloquer show port, protocol and IP of blocked IPs (as you saw them in syslog), and allow whitelisting them by right-clicking (either per IP, or per port+protocol, or per port+protocol+IP. I've already got a patch for moblock, to get the necessary information and I think blockcontrol already allows the iptables implementation. So it's just a modification in mobloquer that has to be done.

lovinglinux
May 25th, 2009, 02:43 AM
Hi jre,

Moblock is not updating /var/lib/blockcontrol/guarding.p2p when restarting.

As you know, I only use local lists and I update them using a script. After updating my lists today and restarting blockcontrol, I've noticed that there was a difference between the number of ranges loaded by moblock and the local list being used. Moblock ranges simply didn't change.

So I did a test. I changed the local list used by moblock and restarted it. The ranges in moblock were updated accordingly. Then I changed the local list used back to the previous one and restarted moblock. The ranges were updated correctly, according to the new number of ranges in the edited list. Then I added a new line in my scripts to delete /var/lib/blockcontrol/guarding.p2p before any list changes and it works now. So it seems that moblock is not updating /var/lib/blockcontrol/guarding.p2p if I do not change the list used or if I do not delete this file first.

I know my case is a particular one, but I think this is something that should be investigated, because other users might be affected too. They might be using the same list cache for days or even weeks if this also affects on-line lists.

I hope this helps.

jre
May 25th, 2009, 05:23 PM
Thanks. First off, this affects only users with local blocklists. Users with online lists are not affected.

I designed blockcontrol the following way: MoBlock loads the master blocklist (/var/lib/blockcontrol/guarding.p2p). This gets built from the single blocklists, but MoBlock does not know about them. The master blocklist gets rebuilt from the single blocklists:

after "blockcontrol update" or "reload"
if there is no master blocklist on "start"/"restart"/"reload"
on "start"/"restart" if /etc/blockcontrol/blocklists.list or the variables BLOCKLIST_FORMAT or IP_REMOVE changed.

I decided against a rebuilt on every start, because I want to avoid this time consuming task if possible. For the same reason I don't want to check every single blocklist if it changed (this is not necessary because they only change on "update"). But I now realized that I still have to check local single blocklists for changes, because they can change without an "update".
This will slow down the "start" for the amount of time needed to get the locallist's md5sum. So this won't affect normal users, but guys like you.

Thanks for reporting this. It's good to know that some people really check my work.
jre

lovinglinux
May 25th, 2009, 05:46 PM
Thanks. First off, this affects only users with local blocklists. Users with online lists are not affected.

I designed blockcontrol the following way: MoBlock loads the master blocklist (/var/lib/blockcontrol/guarding.p2p). This gets built from the single blocklists, but MoBlock does not know about them. The master blocklist gets rebuilt from the single blocklists:

after "blockcontrol update" or "reload"
if there is no master blocklist on "start"/"restart"/"reload"
on "start"/"restart" if /etc/blockcontrol/blocklists.list or the variables BLOCKLIST_FORMAT or IP_REMOVE changed.

I decided against a rebuilt on every start, because I want to avoid this time consuming task if possible. For the same reason I don't want to check every single blocklist if it changed (this is not necessary because they only change on "update"). But I now realized that I still have to check local single blocklists for changes, because they can change without an "update".
This will slow down the "start" for the amount of time needed to get the locallist's md5sum. So this won't affect normal users, but guys like you.

Thanks for reporting this. It's good to know that some people really check my work.
jre

Thanks for the explanation. It makes perfect sense now.

I don't use use the update feature, because I thought it was designed only to grab the lists from the net, which is unnecessary in my case. I also thought that the master list was updated on every "start"/"restart". I remember there was a message about guarding.p2p being built when running those commands through mobloquer. Did you changed this behavior when you introduced blockcontrol?

This really don't affect me that much, because I usually switch between local lists all the time, by replacing /etc/blockcontrol/blocklists.list with presets. Now that I know how it actually works I just need to delete the master list before starting moblock to make sure it will be updated. Not a big deal. It's already in my scripts.

jre
May 25th, 2009, 06:09 PM
Well, years ago the master blocklist was always rebuilt on start, but then there was also a update on start. ;-)
Then the most time I had only point 1 and 2 from my last post. So at that time a "restart" was the wrong thing when you only made blocklist changes, instead a "reload" was necessary.
The actual behaviour (added the intelligent checking from point 3) is since moblock-control 1.2-1.
So no, I didn't change this behaviour in a not-so-good way since mobloquer exists (IIRC).

I'm not sure what mobloquer says, but mobloquer "might" be wrong, since it was written by someone else. Only believe what you see in /var/log/blockcontrol.log (you still can see this log in mobloquer. Most probably you were talking about this.). So I'm not sure if you don't remember correctly, or if there is a bug in mobloquer/blockcontrol, or if I don't remember correctly. Unless you insist I tend to believe everything is ok ;-)

BTW: Most feature changes happen(ed) independent of name changes. In the past even version numbers didn't tell, if there were big changes. But I try to change this in order to get more user friendly. If you are interested in the changes have a look at /usr/share/doc/blockcontrol/changelog.Debian.gz (this is the default place for every Debian package).

lovinglinux
May 25th, 2009, 06:32 PM
So I'm not sure if you don't remember correctly, or if there is a bug in mobloquer/blockcontrol, or if I don't remember correctly. Unless you insist I tend to believe everything is ok ;-)

Don't worry, I'm probably wrong about this and I'm definitely not insisting :) . I was just curious. It is probably a confusion due to the way I update things and use multiple configuration setups. Anyways, it's all good now. ;)

Thanks for you help.

chinaski
May 29th, 2009, 10:42 PM
I have a question:

I turned blockcontrol on after rebooting the router (new public IP address) and was checking /var/log/moblock.log to see if anything happens

amule is off (I use no other P2P apps)

nothing happens

but if I turn Skype on, blockcontrol start blocking

here's a log example:


Fri May 29 23:34:41| OUT: Skype,hits: 4,DST: 204.9.163.214
during those 4 minutes skype was off
Fri May 29 23:38:33| OUT: Skype,hits: 5,DST: 204.9.163.214
Fri May 29 23:38:35| OUT: Bogon,hits: 9,DST: 239.255.255.250
Fri May 29 23:38:35| OUT: Bogon,hits: 10,DST: 239.255.255.250
Fri May 29 23:38:35| OUT: Bogon,hits: 11,DST: 239.255.255.250
Fri May 29 23:38:35| OUT: Bogon,hits: 12,DST: 239.255.255.250
Fri May 29 23:38:35| OUT: Communications Networking Services,hits: 9,DST: 212.8.163.76
Fri May 29 23:38:35| OUT: Skype Technologies,hits: 1,DST: 194.165.188.76
Fri May 29 23:38:35| OUT: Skype,hits: 6,DST: 204.9.163.214
Fri May 29 23:38:35| OUT: Vodafone Omnitel N.V,hits: 1,DST: 93.150.84.252
Fri May 29 23:38:35| OUT: Vodafone Omnitel N.V,hits: 2,DST: 93.150.84.252
Fri May 29 23:38:35| OUT: University of New South Wales,hits: 1,DST: 149.171.92.172
Fri May 29 23:38:36| OUT: University of New Brunswick,hits: 1,DST: 131.202.34.5
Fri May 29 23:38:36| OUT: Videotron Telecom Ltee,hits: 1,DST: 207.253.162.42
Fri May 29 23:38:36| OUT: Vida Optics TVV,hits: 1,DST: 89.215.255.71
Fri May 29 23:38:37| OUT: Communications Networking Services,hits: 10,DST: 212.8.163.76
Fri May 29 23:38:37| OUT: Skype,hits: 7,DST: 204.9.163.214
Fri May 29 23:38:37| OUT: University of New South Wales,hits: 2,DST: 149.171.92.172
Fri May 29 23:38:38| OUT: Videotron Telecom Ltee,hits: 2,DST: 207.253.162.42
Fri May 29 23:38:38| OUT: University of New Brunswick,hits: 2,DST: 131.202.34.5
Fri May 29 23:38:38| OUT: PCCW Business Internet Access,hits: 4,DST: 220.241.188.220
Fri May 29 23:38:38| OUT: Oxford University,hits: 1,DST: 163.1.230.239
Fri May 29 23:38:38| OUT: XO Communications,hits: 1,DST: 66.237.19.176
Fri May 29 23:38:38| OUT: SURFnet bv,hits: 16,DST: 194.171.12.179
Fri May 29 23:38:38| OUT: Vida Optics TVV,hits: 2,DST: 89.215.255.71
Fri May 29 23:38:40| OUT: XO Communications,hits: 2,DST: 66.237.19.176
Fri May 29 23:38:40| OUT: Oxford University,hits: 2,DST: 163.1.230.239
Fri May 29 23:38:40| OUT: PCCW Business Internet Access,hits: 5,DST: 220.241.188.220
Fri May 29 23:38:40| OUT: SURFnet bv,hits: 17,DST: 194.171.12.179
Fri May 29 23:38:41| OUT: University of New South Wales,hits: 3,DST: 149.171.92.172
Fri May 29 23:38:42| OUT: University of New Brunswick,hits: 3,DST: 131.202.34.5
Fri May 29 23:38:42| OUT: Videotron Telecom Ltee,hits: 3,DST: 207.253.162.42
Fri May 29 23:38:42| OUT: Vida Optics TVV,hits: 3,DST: 89.215.255.71
Fri May 29 23:38:44| OUT: PCCW Business Internet Access,hits: 6,DST: 220.241.188.220
Fri May 29 23:38:44| OUT: Oxford University,hits: 3,DST: 163.1.230.239
Fri May 29 23:38:44| OUT: XO Communications,hits: 3,DST: 66.237.19.176
Fri May 29 23:38:44| OUT: SURFnet bv,hits: 18,DST: 194.171.12.179
Fri May 29 23:38:45| OUT: Skype,hits: 8,DST: 204.9.163.214
Fri May 29 23:38:46| OUT: Vida Optics TVV,hits: 4,DST: 89.215.255.71
Fri May 29 23:38:46| OUT: UNIVERSITY OF SOUTH FLORIDA,hits: 1,DST: 131.247.206.157
Fri May 29 23:38:46| OUT: Uninett,hits: 1,DST: 158.39.24.24
Fri May 29 23:38:46| OUT: CESNET,hits: 1,DST: 147.230.27.6
Fri May 29 23:38:48| OUT: Vida Optics TVV,hits: 5,DST: 89.215.255.71
Fri May 29 23:38:48| OUT: CESNET,hits: 2,DST: 147.230.27.6
Fri May 29 23:38:48| OUT: Uninett,hits: 2,DST: 158.39.24.24
Fri May 29 23:38:48| OUT: UNIVERSITY OF SOUTH FLORIDA,hits: 2,DST: 131.247.206.157
Fri May 29 23:38:52| OUT: Vida Optics TVV,hits: 6,DST: 89.215.255.71
Fri May 29 23:38:52| OUT: UNIVERSITY OF SOUTH FLORIDA,hits: 3,DST: 131.247.206.157
Fri May 29 23:38:52| OUT: Uninett,hits: 3,DST: 158.39.24.24
Fri May 29 23:38:52| OUT: CESNET,hits: 3,DST: 147.230.27.6
Fri May 29 23:38:55| OUT: Skype,hits: 9,DST: 204.9.163.214
here I stopped skype and the rest stopped too

does anyone knows why is this?

lovinglinux
May 30th, 2009, 01:23 AM
I have a question:

I turned blockcontrol on after rebooting the router (new public IP address) and was checking /var/log/moblock.log to see if anything happens

amule is off (I use no other P2P apps)

nothing happens

but if I turn Skype on, blockcontrol start blocking


does anyone knows why is this?

It blocks because it is doing what it is supposed to do. When you start Skype it will try to connect to it's servers and they are currently on your blocklists.

Please notice that all blocked connections are outgoing, so they are probably all from Skype trying to connect to the Skype servers.

If you don't want to block Skype connections, then you need to add those blocked IPs to moblock allow list or setup moblock to ignore outgoing connections on the ports used by Skype.

chinaski
May 30th, 2009, 02:06 AM
thank you

what I ask myself now is what those universities listed in the log have to do with Skype :)

lovinglinux
May 30th, 2009, 02:13 AM
thank you

what I ask myself now is what those universities listed in the log have to do with Skype :)

I don't know if they could be hosting skype servers, but probably is just an issue with the ip range on your blocklists. The people who create the blocklists usually include larger IP ranges when they don't know exactly all the IP's used by a company or institution.

chinaski
May 30th, 2009, 10:00 PM
I see

thank you very much for your replies, we never stop to learn :)

lovinglinux
May 30th, 2009, 10:08 PM
I see

thank you very much for your replies, we never stop to learn :)

You are welcome.

You could also create a Skype whitelist and share with the community at I-BlockList (http://iblocklist.com). Users that publish lists gets a VIP account with additional lists access and features.

jre
May 31st, 2009, 10:07 PM
If you want to know why an IP was blocked, a good start is blockcontrol's "search option.

So take this entry from your moblock.log:

Fri May 29 23:38:33| OUT: Skype,hits: 5,DST: 204.9.163.214

Type

blockcontrol search Skype
Note: for this command I recommend to use the description, not the IP, because you have to use an expression that is literally in the blocklists. So in most cases you cannot use an IP as search expression.

You will get this output:

Checking your currently used blocklists for "Skype" (case-insensitive):

TBG_Business_ISPs (http://list.iblocklist.com/?list=jcjfaxgyyshvdbceroxf)
Skype Sarl:80.90.46.152-80.90.46.167
Skype Vlora:80.91.122.96-80.91.122.127
Skype Vlora:80.91.124.64-80.91.124.255
Skype Technologies OU:80.235.29.32-80.235.29.39
Skype SA:81.7.226.204-81.7.226.207
Skype servers Hosting:82.101.61.0-82.101.61.255
SE-TELE2-SKYPE1:83.181.59.0-83.181.59.15
SE-TELE2-SKYPE2:83.181.59.16-83.181.59.23
Mobile Skype service:92.41.254.0-92.41.255.255
Skype:193.120.134.224-193.120.134.231
Skype Technologies:194.165.188.64-194.165.188.127
Skype Technologies OU:195.250.168.112-195.250.168.127
Skype:204.9.163.128-204.9.163.255
Skype:204.9.165.80-204.9.165.87
Skype Technologies OU:217.159.130.168-217.159.130.175
Skype Technologies OU:217.159.236.224-217.159.236.255

"Skype" was found in these lists:
TBG_Business_ISPs (http://list.iblocklist.com/?list=jcjfaxgyyshvdbceroxf)

If you don't want to block the above shown ranges, then you may add
"Skype" to IP_REMOVE in /etc/blockcontrol/blockcontrol.conf.
Or you may remove some of these lists from /etc/blockcontrol/blocklists.list.

So you learn that this was blocked by the TBG_Business_ISPs blocklist. Now have a look at /usr/share/doc/blockcontrol/README.blocklists.gz and judge if this list is of use for you.

chinaski
May 31st, 2009, 11:06 PM
thansk a lot jre

very useful tip :)

jimbo1
June 9th, 2009, 08:57 PM
I am getting the message:

number of blocked ip ranges: n/a

I noticed earlier in this thread that it was an issue with an earlier version of ubuntu. I have ubuntu Jaunty.

Any help would be appreciated :)

jre
June 9th, 2009, 09:59 PM
If this is a temporary problem a "blockcontrol reload" or hitting the reload button in mobloquer will help (I guess the logfiles were rotated, so that mobloquer can't figure this out)

Otherwise check your version with

dpkg -l blockcontrol mobloquer

jimbo1
June 11th, 2009, 08:27 PM
Thanks jre, no luck with the re-load though.

The output of the
dpkg -l blockcontrol mobloqueris:

ii blockcontrol 1.4.4-1~jaunty Manage IP blockers
ii mobloquer 0.6-2~pre1~jau GUI for MoBlock, an IP blocker for Linux

jimbo1
June 14th, 2009, 09:43 AM
I have had to stop using mobloquer for the time being because when I am using deluge it blocks my active port.

If I start mobloquer and test my port in deluge it says it is closed, if I stop mobloquer it says it's active.

There is no IP address displayed in the log window when I try the test so I'm pretty sure it is not a blocklist related issue.

Does anyone have any ideas?

PS. I am also using firestarter and have opened the port on there which seems to work ok. Mobloquer appears to block my port with or without firestater running.

jre
June 14th, 2009, 01:07 PM
First please make sure in /var/log/moblock.log if there is really no blocked IP. Perhaps your mobloquer installation is broken. Since mobloquer is just a GUI, everything that you see there cannot be taken for granted.

If there is really no blocked IP, then I guess your iptables setup is not correct. This might either be, because of a messed up blockcontrol setup, or because another firewall application messes up blockcontrolīs iptables. Please check/post "sudo blockcontrol status" when you experience the problems. In most cases a "sudo blockcontrol restart" fixes such problems.

In case of mobloquer/blockcontrol problems you may try a clean reinstall

sudo aptitude purge moblock moblock-control mobloquer blockcontrol
sudo aptitude install moblock moblock-control mobloquer blockcontrol

Check your version numbers with

dpkg -l moblock moblock-control mobloquer blockcontrol

jimbo1
June 14th, 2009, 04:58 PM
jre, thanks for your help you pointed me in the right direction.

Although I had the port open in firestarter which seemed to work for Deluge, I needed to run this command in order to have the port open while using moblock (i'm not sure why as I'm no expert!).

iptables -I INPUT -p tcp --dport 12345 -j ACCEPT

It's all fine now, thanks again :D

jimbo1
June 14th, 2009, 05:01 PM
Great GUI btw way cooler than PG2!

jre
June 14th, 2009, 05:25 PM
iptables -I INPUT -p tcp --dport 12345 -j ACCEPT
Be careful! This way you disable moblock for incoming connection on port 12345. So if deluge is listening on 12345, then you disable moblock for deluge. Normally you donīt want that.

Generally, it is no problem if deluge says the port is closed, as long as only delugeīs specific test packet was blocked by moblock. So check again /var/log/moblock.log, and just allow the IP of delugeīs specific test packet (if it appears there).

Otherwise check/post your iptables. In most cases the problems with firestarter systems result, because firestarter purges blockcontrolīs iptables after every start/change of firestarter. As already mentioned, this can be fixed by an "blockcontrol restart" (or restart in mobloquer).

Do you have the current version of blockcontrol with the blockcontrol.watchdog installed? That should do exactly that task for you automatically.

jimbo1
June 15th, 2009, 09:30 PM
Hi jre,

I purged all the programs and re-installed to ensure everything is the latest version then I found the IP for the port test in the log file as suggested, it was being blocked by the edu list so I whitelisted it everything is working fine now, thanks again

I'm still trying to get to grips with the whole linux iptables thing, I'll have to find a decent website and read up on it a some point

lovinglinux
June 15th, 2009, 10:12 PM
I'm still trying to get to grips with the whole linux iptables thing, I'll have to find a decent website and read up on it a some point

https://help.ubuntu.com/community/IptablesHowTo
http://ubuntuforums.org/showthread.php?t=159661
http://bodhizazen.net/Tutorials/iptables/
http://iptables-tutorial.frozentux.net/iptables-tutorial.html (advanced stuff)

TaiKar
July 2nd, 2009, 12:04 PM
Hi, I am new to Ubuntu and I have a problem that I cannot seem to fix by following the instructions on various websites about how to install MoBlock. I have Ubuntu 9.06. I have installed MoBlock following all the instructions on the link on the first post, and I have in my Applications -> Internet the GUI MoBlock Mobloquer. But when I try to start it either from the GUI or command line it never starts and Mobloquer gives this error: Building blocklist... Updating /etc/blockcontrol/custom-blocklist.p2p... * Error 9: /etc/blockcontrol/custom-blocklist.p2p not available. Aborting! Does anyone know what the problem is? Thanks.

jre
July 2nd, 2009, 01:37 PM
Remove the line with the custom-blocklist.p2p entry in /etc/blockcontrol/blocklist.list
Or comment it by adding a hash # in front of this line.

AlanPo
July 12th, 2009, 05:10 PM
Great GUI btw way cooler than PG2!

dpkg -l blockcontrol mobloquer
ii blockcontrol 1.4.4-1 Manage IP blockers
ii mobloquer 0.6-2~pre1~jau GUI for MoBlock, an IP blocker for Linux

but starting Mobloquer gives this:
Required configuration file "/var/log/moblock.log" could not be found in the default path.
Please specify a different path.

did uninstall, update install. when I google it got answer - it's because version. but I have correct one. what to do?

jre
July 13th, 2009, 09:04 AM
dpkg -l blockcontrol mobloquer
ii blockcontrol 1.4.4-1 Manage IP blockers
ii mobloquer 0.6-2~pre1~jau GUI for MoBlock, an IP blocker for Linux

but starting Mobloquer gives this:
Required configuration file "/var/log/moblock.log" could not be found in the default path.
Please specify a different path.

did uninstall, update install. when I google it got answer - it's because version. but I have correct one. what to do?

Can you do "sudo blockcontrol start"?
If this works does /var/log/moblock.log exist?
Does mobloquer refuse to start, or is it just this message?

Whatīs in /var/log/blockcontrol.log?

Did you do a "purge" for the uninstall? A simple "remove" will not remove the config files, so any errors in there may persist!

lordratner
July 28th, 2009, 05:05 PM
I was looking at some old documentation on MoBlock, and I was wondering if there is still a way to make MoBlock restart automatically after updating the block lists, or is this even necessary anymore?

EDIT: Actually, everything went all wonky with MoBlock, including replaceing my /etc/hosts with the default linux template. Apache didnt like that one. So I want to uninstall it so I can get eveything else going on the server first. I'm still learning linux, and moblock is a bit too much too fast.

Here's the problem... I cant seem to get rid of MoBlock. How do I uninstall it. I tried the basic apt-get remove, but that didnt seem to do much, even with --purge. in fact, I had to manually delete the script in init.d to get it to stop running and slowing things down, but it looks like all the other file remain.

How do I get rid of it?

jre
July 28th, 2009, 06:34 PM
After the blocklist update MoBlock reloads automatically, no further actions necessary.

MoBlock doesnīt do anything with /etc/hosts.

To remove:
sudo aptitude purge moblock blockcontrol mobloquer

Simply removing the init script may produce other problems. If you do such a thing, donīt remove the file, but just rename it (or keep a backup).
If you encounter problems check /var/log/blockcontrol.log and post that here.

lordratner
July 29th, 2009, 02:44 AM
Ok great, that got rid of it.

here's the problem I was having.

I got it all installed and running fine, but once I restarted the computer things were much slower. SSH into the server was at a crawl, with basic functions like logging in or changing directories taking up to 10 or 15 seconds.

I removed moblock, and it stopped.

I really want to use the program, but I'm afraid my newbness will keep me from it...

jre
July 29th, 2009, 04:52 PM
I donīt know why anything should get slower. Either MoBlock blocks a connection completely, or it allows it, but nothing between.
Anyway, to see the blocked packets of MoBlock have a look at /var/log/moblock.log. You can then allow traffic for either some IPs or ports. Have a look at https://help.ubuntu.com/community/MoBlock

peacewithall
July 30th, 2009, 12:29 PM
For anyone experiencing problems with moblock, and also having firestarter installed, I found a solution which helps me. I searched this thread and found no real solution, apart from starting moblock after firewall applications.

The solution is here,
http://henry.sage-vision.com/blog/

Basically it restarts moblock after each start of firestarter.

Edit firestarter.sh:


sudo gedit /etc/firestarter/firestarter.sh

Find the section:


# Start the firewall, enforcing traffic policy
start_firewall () {
lock_firestarter
source /etc/firestarter/firewall 2>&1
retval=$?
if [ $retval -eq 0 ]; then
echo “Firewall started”
else
echo “Firewall not started”
unlock_firestarter
exit $retval
fi
}

Paste this over that section:


# Start the firewall, enforcing traffic policy
start_firewall () {
lock_firestarter
source /etc/firestarter/firewall 2>&1
retval=$?
if [ $retval -eq 0 ]; then
echo “Firewall started”
if [ -x /etc/init.d/blockcontrol ]; then
/etc/init.d/blockcontrol restart
fi
else
echo “Firewall not started”
unlock_firestarter
exit $retval
fi
}

Click SAVE,

DONE.

So all I did was add this to that section (DO NOT add this, its just an example of what was added above), also this can be removed to reverse the changes applied above.


if [ -x /etc/init.d/blockcontrol ]; then
/etc/init.d/blockcontrol restart
fi

Hope this tip helps others too.

jre
July 31st, 2009, 05:06 PM
Quite good, just one remark though:




if [ -x /etc/init.d/blockcontrol ]; then
/etc/init.d/blockcontrol restart
fi



Use this instead:

if [ -x /usr/bin/blockcontrol ] && [ "$(blockcontrol status)" = 0 ]; then
blockcontrol restart
fi

First I take blockcontrol directly - not the init script, which is based on blockcontrol.

More important, I first check if blockcontrol is actually running with "status". So this allows to turn off blockcontrol manually, while with your solution it is always (re-)started by firestarter.

Jerriy
August 8th, 2009, 10:19 PM
Hi there - I have a question. I recently upgraded to Jaunty and (I suspect as a result of that) I get this message scrolling on the screen during boot:
* Moblock is not runningDoesn't that mean that Blockcontrol is not starting automatically at system boot (which it should per default)?

jre
August 9th, 2009, 01:06 PM
Yes, it should. INIT="1" must be set (check "blockcontrol show_config | grep INIT" for that. Then check /var/log/blockcontrol.log if the start was attempted (perhaps moblock crashed later).
Also check if "sudo blockcontrol start" works.

Mariane
August 9th, 2009, 04:59 PM
Hi,

There are just 2 ip I wish o block
(google syndication and google analytics, which serve the adds and generate all the "addsense" trash, and doubleclick.net which won the big-brother award).

Google syndication is 64.233.161.99
doubleclick.net is 216.73.93.8

So I have a custom file
/etc/blockcontrol/custom-blocklist.p2p

Where I wrote


64.233.161.99-64.233.161.99
216.73.93.8-216.73.93.8


Mobloquer - Blocklists shows this file and it is set to enabled and local. I removed the others.

Mobloquer - Manage says "Moblock is up and running" but below it says "Number of blocked ip ranges: 0"

And I know it is not working because even on this forum I get the browser message that stuff is transfered between my computer and google-analytics :(.

What should I do, please?

Mariane

Jerriy
August 9th, 2009, 07:45 PM
Yes, it should. INIT="1" must be set (check "blockcontrol show_config | grep INIT" for that. Then check /var/log/blockcontrol.log if the start was attempted (perhaps moblock crashed later).
Also check if "sudo blockcontrol start" works.To me it all seems strange - it seems to work but at the same time it seems to START by not working... then it starts, as you can see it in the log (the greyed out bit at the end is refering to what happened after I followed your instructions in your previous post):
2009-08-09 18:47:11 CEST Begin: blockcontrol stop
Stopping blockcontrol.watchdog.
Deleting iptables ...

[74G[ OK ]
Executing /etc/blockcontrol/iptables-custom-remove.sh ...
[74G[ OK ]
Stopping moblock ...
[74G[ OK ]
2009-08-09 18:47:12 CEST End: blockcontrol stop
2009-08-09 18:48:08 CEST Begin: blockcontrol start
Inserting iptables ...
Allowing loopback traffic
[74G[ OK ]

[74G[ OK ]
Executing /etc/blockcontrol/iptables-custom-insert.sh ...
[74G[ OK ]
Starting moblock ...
[74G[ OK ]
Starting blockcontrol.watchdog
[74G[ OK ]
2009-08-09 18:48:09 CEST End: blockcontrol start
Allowing inbound LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing outbound LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing forwarded LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing outbound traffic to DNS server ###.###.#.# ...done.
Allowing forwarded traffic to DNS server ###.###.#.# ...done.
2009-08-09 18:57:10 CEST Begin: blockcontrol stop
Stopping blockcontrol.watchdog.
Deleting iptables ...

[74G[ OK ]
Executing /etc/blockcontrol/iptables-custom-remove.sh ...
[74G[ OK ]
Stopping moblock ...
[74G[ OK ]
2009-08-09 18:57:11 CEST End: blockcontrol stop
2009-08-09 18:58:07 CEST Begin: blockcontrol start
Inserting iptables ...
Allowing loopback traffic
[74G[ OK ]

[74G[ OK ]
Executing /etc/blockcontrol/iptables-custom-insert.sh ...
[74G[ OK ]
Starting moblock ...
[74G[ OK ]
Starting blockcontrol.watchdog
[74G[ OK ]
2009-08-09 18:58:07 CEST End: blockcontrol start
Allowing inbound LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing outbound LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing forwarded LAN traffic for ###.###.#.## with subnetmask ###.###.###.# ...done.
Allowing outbound traffic to DNS server ###.###.#.# ...done.
Allowing forwarded traffic to DNS server ###.###.#.# ...done.
2009-08-09 08:23:28 PM CEST Begin: blockcontrol start
* moblock is already running, doing nothing.
2009-08-09 08:23:28 PM CEST End: blockcontrol start

cvaty
August 12th, 2009, 02:18 PM
Hi,

There are just 2 ip I wish o block
(google syndication and google analytics, which serve the adds and generate all the "addsense" trash, and doubleclick.net which won the big-brother award).

Google syndication is 64.233.161.99
doubleclick.net is 216.73.93.8

since most likely youve whitelisted http traffic adding these to moblock wont prevent your computer from communicating with port 80 (your browser)

you can use the /etc/hosts file however to ignore them


sudo gedit /etc/hosts



127.0.0.1 64.233.161.99 # bloccks google-syndication
127.0.1.1 216.73.93.8 # blocks double-click.net


you might find this site of interest
http://someonewhocares.org/hosts/

jre
August 12th, 2009, 05:58 PM
So I have a custom file
/etc/blockcontrol/custom-blocklist.p2p

Where I wrote


64.233.161.99-64.233.161.99
216.73.93.8-216.73.93.8



You need a description, otherwise itīs incorrect syntax:


google-syndication:64.233.161.99-64.233.161.99
double-click.net:216.73.93.8-216.73.93.8


But also have a look at cvatyīs post!




@Jerriy: Indeed everything seems to be ok.
I canīt find whatīs going wrong. This ought to be the output of the function "status_of_proc". But I just verified that this output should normally not be not shown, because I have "> /dev/null 2>&1".
Still there are some exceptions, but then you should see a message before "Problematic daemon status:".

Anyway, please send me your /lib/lsb/init-functions.
Then try it with the setting LSB="" in /etc/blockcontrol/blockcontrol.conf
Iīll add this to BUGS, for the time being. Please tell me, if this problems gets solved somehow.

Murimons
August 21st, 2009, 10:39 AM
Hello,

I've got a small issue with my moblock.
I'm using Ubuntu 9.04 and i've just started using it a little bit and don't have much linux knowledge.

i edited the moblock.conf file and added some IP adresses to allow OUT.
It worked the whole time but now it blocks a IP that should not be blocked.
I've changed nothing to the moblock.conf.

When i check /etc/init.d/blockcontrol .status, i don't see the allowed IP in there.
So apearently the .conf file allowed IPdoesn't get imported to the iptables or something.
Although some protocols i allowed in the .conf file ARE working and are also listed in the status.

Any idea how i can solve this?

Thanks!

jre
August 21st, 2009, 01:55 PM
You have to edit /etc/blockcontrol/blockcontrol.conf (since half a year there is no more moblock.conf).
Check if the IP really made it to your configuration with "blockcontrol status".
BTW thereīs no need for the prefix /etc/init.d.
When the IP is in your configuration you have to "sudo blockcontrol restart".

You may also use the GUI mobloquer.

dj_flx
August 21st, 2009, 11:00 PM
Moblock won't stop anymore - I always get Stopping moblock... ...fail! every time, since the last update.

What's gone wrong?


2009-08-21 18:17:29 EDT Begin: blockcontrol restart

Stopping blockcontrol.wd

[fail]

Deleting iptables ...

iptables v1.3.8: Couldn't load target `blockcontrol_in':/lib/iptables/libipt_blockcontrol_in.so: cannot open shared object file: No such file or directory



Try `iptables -h' or 'iptables --help' for more information.

iptables v1.3.8: Couldn't load target `blockcontrol_out':/lib/iptables/libipt_blockcontrol_out.so: cannot open shared object file: No such file or directory



Try `iptables -h' or 'iptables --help' for more information.

iptables v1.3.8: Couldn't load target `blockcontrol_fw':/lib/iptables/libipt_blockcontrol_fw.so: cannot open shared object file: No such file or directory



Try `iptables -h' or 'iptables --help' for more information.

iptables: No chain/target/match by that name

iptables: No chain/target/match by that name

iptables: No chain/target/match by that name

iptables: No chain/target/match by that name

iptables: No chain/target/match by that name

iptables: No chain/target/match by that name



[fail]

* Don't worry! There occured some errors during the deletion of the iptables

* rules. The most common reason for this is that they did not exist, because

* moblock was not running.

* But if moblock was running there is some problem. Most probably you have

* installed another firewall application that did delete the iptables rules.

* A "blockcontrol restart" will then fix the situation.

Executing /etc/blockcontrol/iptables-custom-remove.sh ...

[ OK ]

Stopping moblock ...

[fail]

* moblock is already running, doing nothing.

2009-08-21 18:17:52 EDT End: blockcontrol restart

jre
August 21st, 2009, 11:55 PM
Please post your "blockcontrol show_config".
Then set LSB="" in /etc/blockcontrol/blockcontrol.conf.
Whatīs your distribution?

dj_flx
August 22nd, 2009, 12:05 AM
blockcontrol current settings:

ACCEPT="1"

ACCEPT_MARK="20"

ALLOW_FW=""

ALLOW_IN="/etc/blockcontrol/allow.p2p"

ALLOW_OUT="/etc/blockcontrol/allow.p2p"

BLOCKLIST_FORMAT="p"

BLOCKLISTS_DIR="/var/spool/blockcontrol"

BLOCKLISTS_LIST="/etc/blockcontrol/blocklists.list"

CONTROL_CONF="/etc/blockcontrol/blockcontrol.conf"

CONTROL_LIB="/usr/lib/blockcontrol/blockcontrol.lib"

CONTROL_LOG="/var/log/blockcontrol.log"

CONTROL_NAME="blockcontrol"

CONTROL_SCRIPT="/usr/bin/blockcontrol"

CRON="1"

CRON_MAILTO="root"

CUSTOM_DAEMON_OPTS=""

DAEMON="/usr/bin/moblock"

DAEMON_LOG="/var/log/moblock.log"

DESC="IP block daemon"

E_BADARGS="2"

E_BLOCKLIST="9"

E_CONFIG="6"

E_IPTABLES="8"

E_NETWORK_DOWN="171"

E_NOTROOT="4"

E_XBIN="5"

E_XCD="66"

E_XEXTERNAL="170"

E_XFILE="7"

INIT="1"

IP_REMOVE=""

IPTABLES_ACTIVATION="1"

IPTABLES_CUSTOM_DIR="/etc/blockcontrol"

IPTABLES_SETTINGS="1"

IPTABLES_TARGET="NFQUEUE"

IPTABLES_TARGET_WHITELISTING="RETURN"

LOG_IPTABLES=""

LOG_SYSLOG="0"

LOG_TIMESTAMP="1"

LSB="/lib/lsb/init-functions"

MASTER_BLOCKLIST_DIR="/var/lib/blockcontrol"

MD5SUM_FILE="/var/spool/blockcontrol/MD5SUM"

NAME="moblock"

NFQUEUE_NUMBER="92"

NICE_LEVEL="5"

PATH="/usr/bin:/bin:/sbin:/usr/sbin:/usr/local/bin:/usr/local/sbin"

PIDFILE="/var/run/moblock.pid"

REJECT="1"

REJECT_FW="DROP"

REJECT_IN="DROP"

REJECT_MARK="10"

REJECT_OUT="REJECT"

STATFILE="/var/log/MoBlock.stats"

STDIFS=" "

TESTHOST="iblocklist.com"

VERBOSITY="1"

WD="1"

WD_NICE="19"

WD_PATHNAME="/usr/bin/blockcontrol.wd"

WD_PID="/var/run/blockcontrol.wd.pid"

WD_SLEEP="300"

WGET_OPTS="wget -q -t 5 -T 120 -w 5"

WHITE_IP_FORWARD="192.168.0.0/24 1.0.0.0/0"

WHITE_IP_IN=""

WHITE_IP_OUT=""

WHITE_LOCAL="1"

WHITE_TCP_FORWARD="9001 9030 9050"

WHITE_TCP_IN="9001 9030 9050 http https ftp pop3 smtp"

WHITE_TCP_OUT="9001 9030 9050 http https ftp pop3 smtp"

WHITE_UDP_FORWARD=""

WHITE_UDP_IN="2323 9050"

WHITE_UDP_OUT="2323 9050"



Using Debian LSB init-functions: /lib/lsb/init-functions.

Using start-stop-daemon.



The following blocklists are configured to be used:

http://list.iblocklist.com/?list=ijfqtofzixtwayqovmxn

http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh

http://list.iblocklist.com/?list=jcjfaxgyyshvdbceroxf

http://list.iblocklist.com/?list=pfefqteoxlfzopecdtyw

http://list.iblocklist.com/?list=tbnuqfclfkemqivekikv

http://list.iblocklist.com/?list=ewqglwibdgjttwttrinl

http://list.iblocklist.com/?list=bt_level1

http://list.iblocklist.com/?list=bt_level2

http://list.iblocklist.com/?list=bt_level3

http://list.iblocklist.com/?list=bt_edu

http://list.iblocklist.com/?list=bt_ads

http://list.iblocklist.com/?list=bt_bogon

http://list.iblocklist.com/?list=bt_spyware

http://list.iblocklist.com/?list=bt_spider

http://list.iblocklist.com/?list=bt_proxy

http://list.iblocklist.com/?list=bt_hijacked

http://list.iblocklist.com/?list=bt_templist

http://list.iblocklist.com/?list=bt_rangetest

http://list.iblocklist.com/?list=bt_dshield

locallist

/etc/blockcontrol/custom-blocklist.p2p



I'm Xubuntu 8.04 LTS

dj_flx
August 22nd, 2009, 12:37 AM
Setting LSB="" seems to have fixed it... and let the update I just checked on work.

What did I just do, exactly?

jre
August 22nd, 2009, 09:08 AM
blockcontrol uses those LSB init-functions specified in LSB="..." to start/stop and get the status/pid of blockcontrol/moblock.
If the specified file does not exist, or none is specified, it uses its internal ones - thatīs what you just did.

The syntax how to use the init-functions is specified by LSB, and I adhere to it (although some variations are possible). Unfortunately some (older) LSB init-functions donīt implement the specifications correctly. Itīs one of the most time-consuming task for me to find out why something doesnīt work on another system, and how to workaround it.

(You donīt have to worry about that, but there are still problems when my internal functions are used on a system without start-stop-daemon in combination with mobloquer. But on your system start-stop-daemon is installed, so you are fine.)

EDIT: I just released a new version only for hardy which has LSB="" as default.

dj_flx
August 22nd, 2009, 03:16 PM
OK, thanks!

Though I don't know what to make of this:


W: GPG error: http://moblock-deb.sourceforge.net hardy Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY B26B803358712F29

Did I lose something on my end?

jre
August 22nd, 2009, 03:21 PM
Iīve got a new key (58712F29) for the repository at moblock-deb.sf.net. My old key expired. Add my new key to your system:

gpg --keyserver wwwkeys.eu.pgp.net --recv 58712F29
gpg --export --armor 58712F29 | sudo apt-key add -

For all: Most people will probably use the launchpad PPA, they do not have to do anything.

Philip550c
August 25th, 2009, 07:21 PM
Moblock won't stop anymore - I always get Stopping moblock... ...fail! every time, since the last update.

What's gone wrong?


I have the same issue on all 5 of my machines, I'm running Intrepid.

jre
August 25th, 2009, 10:09 PM
I have the same issue on all 5 of my machines, I'm running Intrepid.

Have you updated to 1.6.6-1~intrepid? I just noticed yesterday, that this problem affects intrepid, too. So I released that version for hardy and intrepid.

Else, have you tried LSB="" ?

Philip550c
August 26th, 2009, 05:19 AM
Have you updated to 1.6.6-1~intrepid? I just noticed yesterday, that this problem affects intrepid, too. So I released that version for hardy and intrepid.

Else, have you tried LSB="" ?

I have the update. I just modified the LSB="" located here /usr/lib/blockcontrol/blockcontrol.defaults and it worked, at least on my laptop. I'll try the rest when I get home. Thanks. How come it is not like that by default? Do most computers not have this issue? Because I have the problem on 5 very different machines, all intrepid though.

Edit: I have the update on some of the computers, I guess not on my laptop. I'm downloading currently, will see if it changes the LSB and if it messes up or not.

jre
August 26th, 2009, 05:15 PM
The LSB init-functions (package lsb-base) are broken on hardy and intrepid.
Therefore on these systems you have to use the internal init-functions (by setting LSB=""). Exactly this is the change that I made for the newest hardy and intrepid packages (in /usr/lib/blockcontrol/blockcontrol.defaults). When youīve updated to these, there is no more need to change this manually.

Most people are on other systems than hardy/intrepid, therefore most people had no problems. And since the distribution specific init-functions can be better than my internal ones, Iīd like to stay with using these system wide init-functions. In the long run there will be no systems with broken init-functions (like hardy and intrepid), so in the long run, this is a good solution. In the time between itīs just pita - for you and for me.

Philip550c
August 26th, 2009, 10:41 PM
The LSB init-functions (package lsb-base) are broken on hardy and intrepid.
Therefore on these systems you have to use the internal init-functions (by setting LSB=""). Exactly this is the change that I made for the newest hardy and intrepid packages (in /usr/lib/blockcontrol/blockcontrol.defaults). When youīve updated to these, there is no more need to change this manually.

Most people are on other systems than hardy/intrepid, therefore most people had no problems. And since the distribution specific init-functions can be better than my internal ones, Iīd like to stay with using these system wide init-functions. In the long run there will be no systems with broken init-functions (like hardy and intrepid), so in the long run, this is a good solution. In the time between itīs just pita - for you and for me.

Thanks for explaining that to me and thanks for creating moblock, it should come with some of the modified distros (linux mint, etc...).
I like using it much more than peergaurdian for winblows.

lovinglinux
August 26th, 2009, 10:53 PM
I like using it much more than peergaurdian for winblows.

Me too. PeerGuardian always crashed on my system, but I never had a problem with moblock.=D>

Philip550c
August 26th, 2009, 10:55 PM
Me too. PeerGuardian always crashed on my system, but I never had a problem with moblock.=D>

yeah and then you have to do that driver reset crap in the start menu

lovinglinux
August 27th, 2009, 12:16 AM
yeah and then you have to do that driver reset crap in the start menu

Like many other Windows things... :lol:

linuxology
August 28th, 2009, 03:41 PM
Block Control Won't start in 9.04....

Here is a view of my /var/log/blockcontrol.log


Starting moblock ... [ OK ]
Starting blockcontrol.wd ... OK ]
2009-08-28 09:37:12 AM CDT End: blockcontrol restart
sudo blockcontrol status
2009-08-28 09:37:47 AM CDT Begin: blockcontrol start
Problematic daemon status: 1
* moblock is not running

Starting blockcontrol.wd ... O

Can someone please help?

jre
August 29th, 2009, 01:30 PM
(Please rework your original post. You mixed up command line operations, your question and the content of the logfile. Please copy&paste your logfile, but donīt write off its contents. The "O" in the blockcontrol.wd line seems strange.)

Do you have this problem always, also after a fresh reboot? Did it ever work?

status 1 means pidfile exists, but process is dead. So when you get this please check (and post):

ps aux | grep -E "moblock|blockcontrol"
ls -l /var/run/*block*.pid
blockcontrol show_config | grep -i lsb
dpkg -l moblock blockcontrol lsb-base

Then set
LSB=""
in /etc/blockcontrol/blockcontrol.conf and do a "sudo blockcontrol restart"

linuxology
August 29th, 2009, 03:02 PM
test@test-laptop:~$ ps aux | grep -E "moblock|blockcontrol"
root 6553 0.0 0.0 4304 880 ? SN 08:56 0:00 /bin/sh /usr/bin/blockcontrol.wd
test 6579 0.0 0.0 7524 952 pts/0 S+ 08:56 0:00 grep -E moblock|blockcontrol
test@test-laptop:~$ ls -l /var/run/*block*.pid
-rw-r--r-- 1 root root 5 2009-08-29 08:56 /var/run/blockcontrol.wd.pid
-rw-r--r-- 1 root root 5 2009-08-29 08:56 /var/run/moblock.pid
test@test-laptop:~$ blockcontrol show_config | grep -i lsb
LSB=""
Using internal LSB init-functions.
test@test-laptop:~$ dpkg -l moblock blockcontrol lsb-base
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-==============-==============-============================================
pi blockcontrol 1.6-1~jaunty Manage IP blockers
ii lsb-base 4.0-0ubuntu0.9 Linux Standard Base 4.0 init script function
ii moblock 0.9~rc2-23~pre An IP blocker for Linux




sudo blockcontrol restart"sudo blockcontrol


This fails

jre
August 31st, 2009, 07:28 PM
sudo blockcontrol restart"sudo blockcontrol

Come on, please take more care in writing your posts. Otherwise I canīt and donīt want to help you.

Anyway, this guy (http://forums.phoenixlabs.org/showthread.php?p=127315) has the same problem. So I just released 1.6.7 which should at least fix a part of the problem. (Removing the pidfile of a crashed daemon on stop). But I still donīt know why the moblock daemon crashed in the first time. So Iīd need /var/log/moblock.log

linuxology
September 2nd, 2009, 12:38 AM
My apologies for the sloppy last post...... Is the problem OpenDNS?????

Here is more /var/log/moblock.log


more /var/log/moblock.log
Short guarding.p2p line <html>, skipping it...
Short guarding.p2p line <head>, skipping it...
Short guarding.p2p line <title>OpenDNS</title>, skipping it...
Short guarding.p2p line </head>, skipping it...
Short guarding.p2p line <body id="mainbody" onLoad="testforbanner();" st
yle="margin: 0px;">, skipping it...
Short guarding.p2p line <script language="JavaScript">, skipping
it...
Short guarding.p2p line function testforbanner() {, skip
ping it...
Short guarding.p2p line var width;, skipping it.
..
Short guarding.p2p line var height;, skipping it
...
Short guarding.p2p line var x = 0;, skipping it.
..
Short guarding.p2p line var isbanner = false;, s
kipping it...
Short guarding.p2p line var bannersizes = new Ar
ray(16), skipping it...
Short guarding.p2p line bannersizes[0] = '300x25
0';, skipping it...
Short guarding.p2p line bannersizes[1] = '250x25
0';, skipping it...
Short guarding.p2p line bannersizes[2] = '240x40
0';, skipping it...
Short guarding.p2p line bannersizes[3] = '336x28
0';, skipping it...
Short guarding.p2p line bannersizes[4] = '180x15
0';, skipping it...
Short guarding.p2p line bannersizes[5] = '468x60
';, skipping it...
Short guarding.p2p line bannersizes[6] = '234x60
';, skipping it...
Short guarding.p2p line bannersizes[7] = '88x31'
;, skipping it...
Short guarding.p2p line bannersizes[8] = '120x90
';, skipping it...
Short guarding.p2p line bannersizes[9] = '120x60
';, skipping it...
Short guarding.p2p line bannersizes[10] = '120x2
40';, skipping it...
Short guarding.p2p line bannersizes[11] = '125x1
25';, skipping it...
Short guarding.p2p line bannersizes[12] = '728x9
0';, skipping it...
Short guarding.p2p line bannersizes[13] = '160x6
00';, skipping it...
Short guarding.p2p line bannersizes[14] = '120x6
00';, skipping it...
Short guarding.p2p line bannersizes[16] = '300x6
00';, skipping it...
Short guarding.p2p line bannersizes[17] = '300x1
25';, skipping it...
Short guarding.p2p line bannersizes[18] = '530x3
00';, skipping it...
Short guarding.p2p line bannersizes[19] = '190x2
00';, skipping it...
Short guarding.p2p line bannersizes[20] = '470x2
50';, skipping it...
Short guarding.p2p line if(typeof(window.innerHe
ight) == 'number') {, skipping it...
Short guarding.p2p line height = window.
innerHeight;, skipping it...
Short guarding.p2p line width = window.i
nnerWidth;, skipping it...
Short guarding.p2p line } else if(typeof(documen
t.body.offsetHeight) == 'number') {, skipping it...
Short guarding.p2p line height = documen
t.body.offsetHeight;, skipping it...
Short guarding.p2p line width = document
.body.offsetWidth;, skipping it...
Short guarding.p2p line };, skipping it...
Short guarding.p2p line for (x=0; x<bannersizes.
length; x++) {, skipping it...
Short guarding.p2p line if(bannersizes[x
] == width + 'x' + height) {, skipping it...
Short guarding.p2p line isbanner
= true;, skipping it...
Short guarding.p2p line };, skipping it.
..
Short guarding.p2p line };, skipping it...
Short guarding.p2p line if(isbanner || width < 1
00 || height < 100) {, skipping it...


also sudo blockcontrol status

sudo blockcontrol status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 7 packets, 1542 bytes)
pkts bytes target prot opt in out source destination
6 624 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 19 packets, 6010 bytes)
pkts bytes target prot opt in out source destination
4 1234 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 192.168.1.1
0 0 RETURN all -- * * 192.168.1.0/24 192.168.1.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.1.0/24 0.0.0.0/0
6 624 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 192.168.1.1
0 0 RETURN all -- * * 0.0.0.0/0 192.168.1.0/24
2 131 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
2 1103 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

moblock is not running. ... failed!
blockcontrol.wd is running..
PID: 4950 CMD: /bin/sh /usr/bin/blockcontrol.wd

jre
September 3rd, 2009, 05:13 PM
(see also http://forums.phoenixlabs.org/showthread.php?p=127417#post127417)

Yes, itīs OpenDNS :-/ This is a known problem. I havenīt looked into it, but I got the same reports from 2 other people (this has nothing to do with any recent update, but is a permanent problem).

Only solution in the short run:
Donīt use OpenDNS + fix (remove) your broken downloads with "sudo blockcontrol force-update"

Sorry, I donīt run OpenDNS, but Iīm sure that itīs something wothy to be supported, so I will try to get on that soon ...

bgiannes
September 14th, 2009, 09:45 PM
i have the same problem, can't start blockcontrol anymore?


did a

sudo blockcontrol force-update

but 'she still no go'

notes:
i this machine i'm running desktop 9.04, i only use blockcontrol from time to time, everything worked up to about week ago, now it will not start? I havn't changed anything or install anything new.

jre
September 14th, 2009, 09:51 PM
blockcontrol does not work with OpenDNS. Sorry for that.

So currently thereīs only one solution:
1.) Disable OpenDNS
2.) Fix your blockcontrol installation with "force-update"

Tachions
October 18th, 2009, 07:06 AM
Hi I am having a lot of trouble installing Moblock. I have followed all the how to threads to a t and still no luck. The most recent reply I have received is "The following packages are BROKEN:
moblock
The following NEW packages will be installed:
blockcontrol libaudio2{a} libmysqlclient15off{a} libqt4-dbus{a}
libqt4-designer{a} libqt4-network{a} libqt4-qt3support{a}
libqt4-script{a} libqt4-sql{a} libqt4-sql-mysql{a} libqt4-xml{a}
libqtcore4{a} libqtgui4{a} mobloquer mysql-common{a} qt4-qtconfig{a}
0 packages upgraded, 17 newly installed, 0 to remove and 0 not upgraded.
Need to get 11.6MB of archives. After unpacking 37.4MB will be used.
The following packages have unmet dependencies:
moblock: Depends: libnetfilter-queue1 (>= 0.0.15) which is a virtual package.
Depends: libnfnetlink0 (>= 0.0.33) which is a virtual package.
The following actions will resolve these dependencies:

Keep the following packages at their current version:
blockcontrol [Not Installed]
moblock [Not Installed]
mobloquer [Not Installed]

Score is -29743

Accept this solution? [Y/n/q/?] n

*** No more solutions available ***

The following actions will resolve these dependencies:

Keep the following packages at their current version:
blockcontrol [Not Installed]
moblock [Not Installed]
mobloquer [Not Installed]

Score is -29743"


***Please help I am not giving up but just a little frustrated with the whole situation...

I appreciate everyones help and Thanks in advance!!!

jre
October 19th, 2009, 12:30 PM
Do you have the correct entries in /etc/apt/sources.list ?

E.g. if you are running Ubuntu 9.04 jaunty you should have


deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu jaunty main
deb-src http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu jaunty main

If you are unsure, check your other entries in /etc/apt/sources.list. They should all contain exactly one, and always exactly the same, of the following distribution names:

hardy
intrepid
jaunty
karmic


Which one of these is it (according to your profile it should be "jaunty)? Or do you run another distribution?


Last, but not least, when you have changed your sources.list, you have to do a

sudo aptitude update
Or better, issue this command in any case, just to be sure :-)

Relysis
November 5th, 2009, 10:07 PM
I'm having another problem with 9.10 karmic. I added the correct sources, and installed blockcontrol, moblock, and mobloquer. I go through the installation dialogue and it finishes without problems. When I run it, however, I get:


Required configuration file "/var/log/moblock.log" could not be found in the default path.
Please specify a different path.

I read another thread about using incompatible versions of blockcontrol and mobloquer, but these were all installed from the karmic jre-pheonix repo. If it helps, I'm using blockcontrol 1.6.9-1~karmic, moblock .9~rc2-23~karmic, and mobloquer .6+svn20090812-1~hardy~karmic.

Thanks for any help, hopefully I just did something stupid.

jre
November 6th, 2009, 01:09 AM
Seems as if mobloquer misses the daemonīs logfile. Probably moblock has never been running, because you disabled the automatic start during installation (which is absolutely ok)!?

In this case you might just create an empty logfile

sudo touch /var/log/moblock.log
or you might start moblock once manually

sudo blockcontrol start
(Donīt worry the first start takes quite long because the blocklists need to be downloaded).

Relysis
November 6th, 2009, 11:31 PM
You're right, I had disabled automatic startup. I started moblock manually, and it made the logfile. Everything works perfectly now.

Thanks for the quick support.

fulat2k
November 29th, 2009, 08:51 AM
Hi folks,

Installed moblock (recompiled from source due to the unbind_pf and bind_pf errors) and blockcontrol packages on Jaunty. The output of blockcontrol status shows that both moblock and blockcontrol are running fine. However, if I do a blockcontrol test, it shows the following:


# blockcontrol test
Testing moblock:

CAUTION: This is just a simple test to check if moblock blocks outgoing
connections. For this, an IP from the blocklist will be pinged. Then the test
checks if this IP appears in the logfile /var/log/moblock.log.

moblock marks packets to be blocked. This means you have to make sure that the
marked packets are also blocked later (with appropriate iptables rules). If you
are using the default configuration and moblock is started after other firewalls
this will be the case.

This test does not check if you have sane iptables rules or if your complete
blocklist is in the correct format. Therefore success doesn't imply that
everything is working as you expect it.

Also have a look at "blockcontrol status" and test manually with traceroute.

Trying to ping 4.17.193.127 from /var/lib/blockcontrol/guarding.p2p ...
moblock did not mark the IP to be blocked.
Was moblock already loaded completely? Wait some minutes and try again.

4.17.193.127 did not answer.

Maybe 4.17.193.127 is down/doesn't answer to pings
(this would still mean that moblock is not working)
or your firewall filtered the ping before moblock could check it
(then moblock may be working as desired, check your iptables rules).

Any idea if moblock is working correctly?


Thanks.

jre
November 29th, 2009, 05:10 PM
You don't need to recompile. The jaunty packages are already patched.

First, as it is written in the message:

Was moblock already loaded completely? Wait some minutes and try again.

Then have a look at /var/log/moblock.log, and see if the IP is there. Perhaps logging took longer then the test (so that the test erroneously thought that there was nothing in the logfile.)

Then, third possibility:

your firewall filtered the ping before moblock could check it
(then moblock may be working as desired, check your iptables rules).
Paste your iptables (firewall) rules, so that I can check them. You get them with "sudo iptables -L -nv"

fulat2k
November 30th, 2009, 02:35 AM
The Jaunty package doesn't seem to be patched when nfq_bind_pf is called. I only see the exit(-1) line commented out in the nfq_unbind_pf call. I've re-installed the moblock and blockcontrol packages from the repo and this is what I get from /var/log/moblock.log:


Mon Nov 30 02:31:07| error during nfq_unbind_pf()
Mon Nov 30 02:31:07| Error during nfq_bind_pf()

Doing a blockcontrol status yields the following (output summarized):


# blockcontrol status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 5335 packets, 6618K bytes)
pkts bytes target prot opt in out source destination
87 13186 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 3209 packets, 293K bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

[...]

* moblock is not running
* blockcontrol.wd is running
PID: 3744 CMD: /bin/sh /usr/bin/blockcontrol.wd

chinaski
November 30th, 2009, 03:23 PM
Hi I noticed that if I start blockocntrol even without launching any p2p software I get some OUT connections blocked


Mon Nov 30 15:03:43| OUT: Telenet Operaties N.V.,hits: 1,DST: 84.198.112.144
Mon Nov 30 15:03:43| OUT: CHINANET fujian province network,hits: 1,DST: 59.57.229.179
Mon Nov 30 15:03:43| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 1,DST: 89.41.77.179
Mon Nov 30 15:03:43| OUT: TeliaSonera AB,hits: 1,DST: 90.230.59.188
Mon Nov 30 15:03:43| OUT: TeliaSonera AB,hits: 1,DST: 217.210.178.78
Mon Nov 30 15:03:44| OUT: TeliaSonera AB,hits: 2,DST: 90.230.59.188
Mon Nov 30 15:03:44| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 2,DST: 89.41.77.179
Mon Nov 30 15:03:45| OUT: Telenet Operaties N.V.,hits: 2,DST: 84.198.112.144
Mon Nov 30 15:03:45| OUT: CHINANET fujian province network,hits: 2,DST: 59.57.229.179
Mon Nov 30 15:03:45| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 3,DST: 89.41.77.179
Mon Nov 30 15:03:45| OUT: TeliaSonera AB,hits: 3,DST: 90.230.59.188
Mon Nov 30 15:03:45| OUT: TeliaSonera AB,hits: 2,DST: 217.210.178.78
Mon Nov 30 15:03:46| OUT: TeliaSonera AB,hits: 4,DST: 90.230.59.188
Mon Nov 30 15:03:46| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 4,DST: 89.41.77.179
Mon Nov 30 15:03:49| OUT: Telenet Operaties N.V.,hits: 3,DST: 84.198.112.144
Mon Nov 30 15:03:49| OUT: CHINANET fujian province network,hits: 3,DST: 59.57.229.179
Mon Nov 30 15:03:49| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 5,DST: 89.41.77.179
Mon Nov 30 15:03:49| OUT: TeliaSonera AB,hits: 5,DST: 90.230.59.188
Mon Nov 30 15:03:49| OUT: TeliaSonera AB,hits: 3,DST: 217.210.178.78
Mon Nov 30 15:03:50| OUT: TeliaSonera AB,hits: 6,DST: 90.230.59.188
Mon Nov 30 15:03:50| OUT: SC ROMPLUS COMPUTER CENTER SRL,hits: 6,DST: 89.41.77.179
Mon Nov 30 15:03:54| OUT: University of Connecticut,hits: 1,DST: 137.99.87.242
Mon Nov 30 15:03:56| OUT: University of Connecticut,hits: 2,DST: 137.99.87.242
Mon Nov 30 15:03:59| OUT: Kearney State College,hits: 1,DST: 144.216.42.177
Mon Nov 30 15:04:00| OUT: University of Connecticut,hits: 3,DST: 137.99.87.242
Mon Nov 30 15:04:01| OUT: Kearney State College,hits: 2,DST: 144.216.42.177
Mon Nov 30 15:04:05| OUT: Kearney State College,hits: 3,DST: 144.216.42.177
Mon Nov 30 15:04:38| OUT: Tiscali SpA,hits: 1,DST: 94.38.7.109
Mon Nov 30 15:04:40| OUT: Tiscali SpA,hits: 2,DST: 94.38.7.109
Mon Nov 30 15:04:44| OUT: Tiscali SpA,hits: 3,DST: 94.38.7.109
Mon Nov 30 15:05:28| OUT: Tiscali SpA,hits: 4,DST: 94.38.7.109
Mon Nov 30 15:05:30| OUT: Tiscali SpA,hits: 5,DST: 94.38.7.109
Mon Nov 30 15:05:34| OUT: Tiscali SpA,hits: 6,DST: 94.38.7.109
Mon Nov 30 15:08:19| OUT: Northern Arizona University,hits: 1,DST: 134.114.231.17
Mon Nov 30 15:08:21| OUT: Northern Arizona University,hits: 2,DST: 134.114.231.17
Mon Nov 30 15:08:25| OUT: Northern Arizona University,hits: 3,DST: 134.114.231.17
Mon Nov 30 15:11:32| OUT: Politecnico di Torino,hits: 1,DST: 130.192.29.116
Mon Nov 30 15:11:34| OUT: Politecnico di Torino,hits: 2,DST: 130.192.29.116
Mon Nov 30 15:11:38| OUT: Politecnico di Torino,hits: 3,DST: 130.192.29.116
Mon Nov 30 15:14:54| OUT: Tiscali SpA,hits: 7,DST: 94.38.7.109
Mon Nov 30 15:14:56| OUT: Tiscali SpA,hits: 8,DST: 94.38.7.109
Mon Nov 30 15:15:00| OUT: Tiscali SpA,hits: 9,DST: 94.38.7.109
Mon Nov 30 15:15:44| OUT: Tiscali SpA,hits: 10,DST: 94.38.7.109
Mon Nov 30 15:15:46| OUT: Tiscali SpA,hits: 11,DST: 94.38.7.109
Mon Nov 30 15:15:50| OUT: Tiscali SpA,hits: 12,DST: 94.38.7.109btw my Internet provider is not even Tiscali...

is this normal or should I worry?

jre
November 30th, 2009, 08:47 PM
The Jaunty package doesn't seem to be patched when nfq_bind_pf is called. I only see the exit(-1) line commented out in the nfq_unbind_pf call.

(I guess) you are talking about this bug:
http://developer.berlios.de/bugs/?func=detailbug&bug_id=12156&group_id=2509
The fix for this was indeed to comment exit(-1). Nothing more is necessary. And this was done in upstream moblock 0.9rc2, so every package has this.

I can't remember that there was any other similar bug, do you know of any concrete other necessary patch?


What happens when you install moblock from source (which source? I guess the source from my repository (either moblock-deb.sf.net or the Ubuntu PPA)? Do you get a running "status" then? So that your only problem is "test".
This would indeed hint to the fact that something is wrong with the binary package. But again, this is quite strange since not anybody else reported this problem, and I made no changes to the moblock packages in the past months.


One thing that often helpds when you have problems with binding to NFQUEUE is to reboot. This is true, especially when you tried other applications (e.g. nfblock, iplist or pgl in the meantime).


BTW, I just uploaded a new jaunty package. But this was just to get the version number in sync. However, if there really was something stupid wrong with the old binary package, this should be solved now,


@chinaski:
On computers there are tons of connections happening, so you probably don't have to worry. You definitely don't have to worry about these concrete connections, since they were blocked.
But if you are really interested in what is happening you have to look at these packages with a package sniffer (wireshark).
An easier solution may be to look first at the port, that the packets were sent, too. In order to do this, set in /etc/blockcontrol/blockcontrol.conf:

LOG_IPTABLES="LOG --log-level info"
do a "blockcontrol restart" and then check /var/log/syslog

fulat2k
December 1st, 2009, 06:57 PM
I purged the previous moblock and blockcontrol installations and have installed the new package from your repo (0.9~rc2-23+jaunty). moblock still dies upon startup. I get the same error lines like above:


Tue Dec 1 18:55:03| error during nfq_unbind_pf()
Tue Dec 1 18:55:03| Error during nfq_bind_pf()

I see the process starting itself up, but dies after it loads the blocklist. This is a fresh installation of Jaunty. I haven't installed any other apps you mentioned in your previous post. Here's what I get from blockcontrol status:


* moblock is not running
* blockcontrol.wd is running
PID: 3996 CMD: /bin/sh /usr/bin/blockcontrol.wd

chinaski
December 2nd, 2009, 03:13 PM
@ jre: thanks a lot for your kind, clear and professional reply. as usual ;)

cheers,
Cris

jre
December 3rd, 2009, 12:20 AM
@fulat2k:
But when you compile from source at least "status" says, that moblock is running (as you said in post #370). Right!?

Do you run a custom kernel? Some modules might be missing. The following command should show all relevant modules, please post yours:

$ lsmod | grep -E "^x|^nf|^ip" | grep -Ev "^ip6|^ipv6"| sort
iptable_filter 3776 1
ip_tables 17392 1 iptable_filter
ipt_REJECT 3248 1
nf_conntrack 70192 2 nf_conntrack_ipv4,xt_state
nf_conntrack_ipv4 15240 3
nf_defrag_ipv4 2288 1 nf_conntrack_ipv4
nfnetlink 5608 2 nfnetlink_queue
nfnetlink_queue 9076 1
x_tables 22440 10 ip6t_REJECT,ip6_tables,ipt_REJECT,xt_tcpudp,xt_ipr ange,xt_state,xt_mark,xt_NFQUEUE,xt_multiport,ip_t ables
xt_iprange 2640 23
xt_mark 2432 6
xt_multiport 3216 11
xt_NFQUEUE 2112 3
xt_state 2400 3
xt_tcpudp 3328 17


@chinaski: thanks

fulat2k
December 3rd, 2009, 02:24 AM
When I compiled from source earlier, I commented the exit(-1) call when nfq_bind_pf() is called. Hence moblock process didn't quit. I think I kinda know what's going on. I re-installed Jaunty and this is my output from lsmod:


# lsmod
Module Size Used by

Yup, nothing there :) Any pointers on what modules to install prior to installing moblock? The guide at https://help.ubuntu.com/community/MoBlock doesn't specify kernel modules :(


Thanks!

jre
December 3rd, 2009, 06:17 PM
Any pointers on what modules to install prior to installing moblock?

Yes, my last post :-) All modules mentioned that are shown there, should be available. You can either compile them directly in the kernel, or add them as modules (that still requires to recompile your kernel). Check your /boot/config-[kernel_version] to see what your current configuration is.

So did you install a custom kernel?

It is strange that you got no error message: pglcmd normally first looks, if the necessary modules are already loaded (or compiled in the kernel), if not it tries to load them, and if this fails, it exits. But in this case you should find an error message in /var/log/blockcontrol.log

prem1er
December 11th, 2009, 10:23 PM
Will the peer guardian linux version work on 64 bit machines?

fulat2k
December 13th, 2009, 01:13 AM
Yes, my last post :-) All modules mentioned that are shown there, should be available. You can either compile them directly in the kernel, or add them as modules (that still requires to recompile your kernel). Check your /boot/config-[kernel_version] to see what your current configuration is.

So did you install a custom kernel?

It is strange that you got no error message: pglcmd normally first looks, if the necessary modules are already loaded (or compiled in the kernel), if not it tries to load them, and if this fails, it exits. But in this case you should find an error message in /var/log/blockcontrol.log

Thanks for your help :) Installed the default kernel and everything worked as expected. Phew...

jre
December 13th, 2009, 02:53 PM
Will the peer guardian linux version work on 64 bit machines?

Yes. I am running amd64 kernel, so this will definitely be the case.


Thanks for your help :) Installed the default kernel and everything worked as expected. Phew...

Glad to hear that. So now I am sure that your kernel missed some necessary stuff. But it sounds if blockcontrol did not catch this, so there is a bug in blockcontrol. The correct behaviour would have been to exit with a clean error message.
It would be a great help for me, if you checked your logfiles. Or you can send your /var/log/moblock.log and /var/log/blockcontrol.log of those days (they are rotated daily, so e.g. the moblock.log of three days ago is called moblock.log.3.gz). You can post them here or send them per mail to jre-phoenix@users.sourceforge.net

fulat2k
January 7th, 2010, 02:16 PM
I only have moblock.log. There doesn't seem to be a blockcontrol.log in /var/log. Do you still want it? Somehow it's not rotated. It's one big 108MB file :) I'm trying to see if there's a timestamp.

BTW, is it possible to specify a network interface where moblock operates on? My new server has 4 IPs I can use; and I only need it to listen to just one.

Thanks.

jre
January 7th, 2010, 06:22 PM
I only have moblock.log. There doesn't seem to be a blockcontrol.log in /var/log. Do you still want it? Somehow it's not rotated. It's one big 108MB file :) I'm trying to see if there's a timestamp.

Err, strange. What do you get on

blockcontrol show_config | grep CONTROL_LOG?
I think moblock.log will not be that helpful as blockcontrol.log, but you can still send it to my email address. But I don't know whether googlemail will block it. Don't pack it - googlemail is so clever to assume packed files might be viruses, and therefore bounces all mails with packed attachments!



BTW, is it possible to specify a network interface where moblock operates on? My new server has 4 IPs I can use; and I only need it to listen to just one.

I just added this to the FAQ: https://help.ubuntu.com/community/MoBlock#Is%20it%20possible%20to%20specify%20a%20ne twork%20interface%20where%20moblock%20operates%20o n

fulat2k
January 8th, 2010, 04:48 AM
Oops, my bad. /var/log/blockcontrol.log is there. Just that the log is very recent; and I doubt it'll help you. I'll send it to you anyway.

Thanks for adding the scripts in the Wiki. Works like a charm :)

jre
January 8th, 2010, 12:32 PM
Oops, my bad. /var/log/blockcontrol.log is there. Just that the log is very recent; and I doubt it'll help you. I'll send it to you anyway.
Haven't received anything. Probably it's just too big. Anyway...


Thanks for adding the scripts in the Wiki. Works like a charm :)

I gave a wrong command for iptables removal: you have to use iptables -D instead of iptables -X

questioner1
January 13th, 2010, 09:06 AM
Hi

moblock/blockcontrol seems to work well here on karmic/amd64.

But it blocks too much. Especially frustrating is this entry:
OUT: ETH/UNIZH Camp Net,hits: 2,DST: 129.132.2.217



Why is this blocked? I can't login to my IMAP email at this university (ETH, Switzerland).

And more importantly:


How can I unblock it without having to stop the whole blockcontrol deamon?

And another important aspect:


How can I let blockcontrol only work on connections that are going out/in from a specific application, namely ktorrent?


Best regards and thank you for your appreciation

questioner1

jre
January 13th, 2010, 09:21 PM
Please note the links in this post to the Moblock wiki here. Basically this should answer all your questions. Suggestions are always welcome.


OUT: ETH/UNIZH Camp Net,hits: 2,DST: 129.132.2.217
Why is this blocked?
Depends on your selection of lists. Try

blockcontrol search ETH/UNIZH (https://help.ubuntu.com/community/MoBlock#How%20do%20I%20choose%20what%20blocklists% 20to%20use?)
and then read /usr/share/doc/blockcontrol/README.blocklists.gz


How can I unblock it without having to stop the whole blockcontrol deamon?
Since it is only one IP I recommend you use WHITE_IP_OUT (https://help.ubuntu.com/community/MoBlock#How%20can%20I%20allow%20(whitelist)%20traf fic%20to%20certain%20IPs?).
Alternatively you might open the whole IMAP port (https://help.ubuntu.com/community/MoBlock#How%20can%20I%20allow%20(whitelist)%20traf fic%20on%20certain%20ports?).

When you have changed these settings, you have to restart blockcontrol once.
Alternatively you might directly issue the "sudo iptables ...." command, but I doubt that you want to do that (it would be only necessary if you want to never ever ever stop blockcontrol)


How can I let blockcontrol only work on connections that are going out/in from a specific application, namely ktorrent?
If your kernel supports it (and I doubt that) you can add a per-application whitelisting (https://help.ubuntu.com/community/MoBlock#How%20can%20I%20allow%20%28whitelist%29%20 traffic%20for%20a%20combination%20of%20IPs,%20port s,%20or%20applications?). Note that this is only possible for outgoing connections. See /usr/share/doc/blockcontrol/examples/iptables-custom-insert.sh. For incoming connections you might whitelist all other ports except the one, where ktorrent is listening on. But incoming connections hardly are relevant on a desktop machine.

If you really just want to check one application (and don't want your whole machine protected by a "stealth" mode, and don't care about the other features (e.g. blocklist management), then you should just use such an applications internal blocklist feature. I don't know whether ktorrent has this. At least other torrent apps do.

johanholmquist
March 28th, 2010, 06:00 PM
Hello! I'm currently in the learning process of configuring a linux server, and quite recently I ran into my first "unsolvable" problem when I tried to get moblock working. So, from the beginning:

I'm having issues getting moblock to run on my Ubuntu 9.10 Server. IPTables is installed and working as it should. (And fail2ban is installed as well - I thought it seemed quite useful. I believe its modifications to the iptables shouldn't affect moblock, which may very well be a faulty assumption on my part.)

I haven't tried installing mobloquer since I don't have X installed on the server, and I would prefer to keep it that way.

I added the repo with the following command:

# sudo add-apt-repository ppa:jre-phoenix

That effectively added the following to /etc/apt/sources.list.d/jre-phoenix-ppa-karmic.list :

deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu karmic main

When installing moblock and blockcontrol using

# sudo aptitude update
followed by

# sudo aptitude install moblock blockcontrol
I entered my desired whitelisted TCP and UDP ports.
A total of 15 TCP ports are to be whitelisted both in and out, including a range that I know counts as two entries. So, 13 specific ports and 1 range is to be TCP whitelisted.
Only 2 separate UDP ports are to be whitelisted.
No forwarded ports whitelisted.
I choose the option that whitelists DNS and loopback devices but not LAN. (I can't remember exactly what it says, even though I've reinstalled everything quite a few times. ;))

So far so good, moblock most likely started downloading its lists and everything seemed fine. No error messages were shown at this stage; the installation was "successful".

Then, if I type

# sudo blockcontrol status
I get a list of my IPTables rules, followed by this:

* moblock is not running
* blockcontrol.wd is running
PID: 27770 CMD: /bin/sh /usr/bin/blockcontrol.wd

Also,

# sudo blockcontrol test
yields the following result:

Trying to ping 4.18.0.255 from /var/lib/blockcontrol/guarding.p2p ...
moblock did not mark the IP to be blocked.
Was moblock already loaded completely? Wait some minutes and try again.

4.18.0.255 did not answer.

Maybe 4.18.0.255 is down/doesn't answer to pings
(this would still mean that moblock is not working)
or your firewall filtered the ping before moblock could check it
(then moblock may be working as desired, check your iptables rules).

Using the following commands several times had no effect on the above errors:

# sudo blockcontrol start
# sudo blockcontrol stop
# sudo blockcontrol restart
# sudo blockcontrol rebuild
# sudo blockcontrol update

It seemed to me that moblock consistently failed to start properly, and for some reason blockcontrol still thought that it did during starts/restarts. So, I went to have a look at /var/log/moblock.log which says:

* Ranges loaded: 580868
Sun Mar 28 17:31:32| * Merged ranges: 10229
Sun Mar 28 17:31:32| * Skipped useless ranges: 1887
Sun Mar 28 17:31:32| error during nfq_unbind_pf()
Sun Mar 28 17:31:32| Error during nfq_bind_pf()

I started googling the two errors without finding any real useful results. An old gentoo forum thread (http://bugs.gentoo.org/show_bug.cgi?id=143535) with an old entry read the following:

It needs these kernel modules:
nfnetlink_queue 8768 1
nfnetlink 4888 2 nfnetlink_queue
xt_tcpudp 2944 2
iptable_filter 2432 1
ip_tables 10696 1 iptable_filter
xt_state 1792 3
xt_NFQUEUE 1792 3
x_tables 10244 4 xt_tcpudp,ip_tables,xt_state,xt_NFQUEUE

So, I had a look in aptitude and installed some packages that matched the above names: "libnetfilter-queue-dev", "libnfnetlink-dev", "nfqueue-bindings-perl" and maybe a few dependencies of lesser importance.

moblock still refused to start, so I reinstalled it again and again and again (even tried whitelisting fewer ports etc.) with no success. That's where I am now; I really feel like I'm fumbling in the dark on this one.

Could my iptables rules be the cause of moblock's failed start? They look fine to me, but I'm very much not an iptables guru. Here's my output of "iptables -L":


Chain INPUT (policy DROP)
target prot opt source destination
fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
DROP tcp -- anywhere 127.0.0.0/8
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere
DROP all -- BASE-ADDRESS.MCAST.NET/4 anywhere
PUB_IN all -- anywhere anywhere
PUB_IN all -- anywhere anywhere
PUB_IN all -- anywhere anywhere
PUB_IN all -- anywhere anywhere
DROP all -- anywhere anywhere

Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
DROP all -- anywhere anywhere

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
PUB_OUT all -- anywhere anywhere
PUB_OUT all -- anywhere anywhere
PUB_OUT all -- anywhere anywhere
PUB_OUT all -- anywhere anywhere

Chain INT_IN (0 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere
DROP all -- anywhere anywhere

Chain INT_OUT (0 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere
ACCEPT all -- anywhere anywhere

Chain PAROLE (14 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere

Chain PUB_IN (4 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp echo-reply
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp echo-request
PAROLE tcp -- anywhere anywhere tcp dpt:ftp-data
PAROLE tcp -- anywhere anywhere tcp dpt:ftp
PAROLE tcp -- anywhere anywhere tcp dpt:ssh
PAROLE tcp -- anywhere anywhere tcp dpt:smtp
PAROLE tcp -- anywhere anywhere tcp dpt:domain
PAROLE tcp -- anywhere anywhere tcp dpt:www
PAROLE tcp -- anywhere anywhere tcp dpt:pop3
PAROLE tcp -- anywhere anywhere tcp dpt:imap2
PAROLE tcp -- anywhere anywhere tcp dpt:https
PAROLE tcp -- anywhere anywhere tcp dpt:mysql
PAROLE tcp -- anywhere anywhere tcp dpt:http-alt
PAROLE tcp -- anywhere anywhere tcp dpt:webmin
PAROLE tcp -- anywhere anywhere tcp dpt:59638
PAROLE tcp -- anywhere anywhere tcp dpts:59681:59770
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:mysql
DROP icmp -- anywhere anywhere
DROP all -- anywhere anywhere

Chain PUB_OUT (4 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere

Chain fail2ban-ssh (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere

I would greatly appreciate any help I can get on this... Or any explanation as to why moblock won't start properly. Thanks in advance! :)

Edit: I forgot the list from "sudo blockcontrol status" (edited out my DNS IPs...):

Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
9 2343 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
8 396 fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 22
0 0 DROP tcp -- !lo * 0.0.0.0/0 127.0.0.0/8
2201K 1924M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
31446 1887K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 224.0.0.0/4 0.0.0.0/0
186K 50M PUB_IN all -- eth+ * 0.0.0.0/0 0.0.0.0/0
0 0 PUB_IN all -- ppp+ * 0.0.0.0/0 0.0.0.0/0
0 0 PUB_IN all -- slip+ * 0.0.0.0/0 0.0.0.0/0
0 0 PUB_IN all -- venet+ * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain OUTPUT (policy ACCEPT 811K packets, 127M bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
1250K 323M PUB_OUT all -- * eth+ 0.0.0.0/0 0.0.0.0/0
0 0 PUB_OUT all -- * ppp+ 0.0.0.0/0 0.0.0.0/0
0 0 PUB_OUT all -- * slip+ 0.0.0.0/0 0.0.0.0/0
0 0 PUB_OUT all -- * venet+ 0.0.0.0/0 0.0.0.0/0

Chain INT_IN (0 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain INT_OUT (0 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain PAROLE (14 references)
pkts bytes target prot opt in out source destination
9609 456K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain PUB_IN (4 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 11
65 4085 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
1 64 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:20
61 3172 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
36 1792 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
7047 322K PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
0 0 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
2056 108K PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:110
0 0 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:143
9 380 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
1 40 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306
330 16672 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
3 156 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:10000
11 548 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:59638
54 2808 PAROLE tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:59681:59770
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:3306
0 0 DROP icmp -- * * 0.0.0.0/0 0.0.0.0/0
177K 49M DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain PUB_OUT (4 references)
pkts bytes target prot opt in out source destination
1250K 323M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 {DNS server 1}
0 0 RETURN all -- * * 0.0.0.0/0 {DNS server 2}
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:3306
0 0 RETURN udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:59681:59770
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:59638
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:10000
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:993
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:143
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:110
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:20
9 2343 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port -unreachable
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 {DNS server 1}
0 0 RETURN all -- * * 0.0.0.0/0 {DNS server 2}
0 0 RETURN udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:5506
0 0 RETURN udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:59681:59770
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:59638
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:10000
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:993
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:143
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:110
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:20
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain fail2ban-ssh (1 references)
pkts bytes target prot opt in out source destination
8 396 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0

Please check if the above printed iptables rules are correct!

* moblock is not running
* blockcontrol.wd is running
PID: 27770 CMD: /bin/sh /usr/bin/blockcontrol.wd


To me this looks like it should work... It depends what is meant by "before" in post #1 of this thread. :)

jre
March 29th, 2010, 12:18 AM
moblock works fine with fail2ban. Also your other iptables rules should not be the culprit. Further there's no need to install additional packages (as "libnetfilter-queue-dev", "libnfnetlink-dev", "nfqueue-bindings-perl"). This is the part I'm sure about ;-)

I've seen that problem before. I think it was either something about a broken libnetfilter installation OR missing kernel modules. I'll check that and post again when I found that...

In the mean time please post the output of

lsmod|grep -E "^x|^nf|^ip"|grep -Ev "^ip6|^ipv6"|sed "s| .*||"|sort
This gives a list of all relevant kernel modules. Here I get

iptable_filter
ip_tables
ipt_REJECT
nf_conntrack
nf_conntrack_ipv4
nf_defrag_ipv4
nfnetlink
nfnetlink_queue
x_tables
xt_iprange
xt_mark
xt_multiport
xt_NFQUEUE
xt_state
xt_tcpudp

johanholmquist
March 29th, 2010, 12:15 PM
lsmod returns absolutely nothing, no matter what I try... :-s
the lsmod --help isn't very useful either: "Usage: lsmod". ;)

I had a look around and found some old forum with someone that had the same problem. Just like that guy, my output from
# modprobe ls is something like
kernel/drivers/scsi/scsi_wait_scan.ko and nothing more.

Is it likely that recompiling the kernel will make lsmod work? Recompiling the kernel seems quite time-consuming, and judging by the manuals I'm sure it's not the easiest thing to do for a rookie... It's quite likely that I would end up with something else not working as it should. ^^ Is it my only way out? :-s

jre
March 29th, 2010, 01:43 PM
"lsmod" is a command to list the loaded kernel modules. So it doesn't do anything special, but just gives you information. You definitely should get some output if you just type
lsmod. So please post the output of this pure "lsmod". The rest of my last command just filters the complete output to the relevant parts. Since you got no results there, I guess we are on the right way, since this indicates that the modules are not loaded.

Please try to manually load the relevant kernel module NFQUEUE. Chances are high that this doesn't happen automatically for some strange reasons on your side. So do
sudo modprobe xt_NFQUEUE
echo $?. The second command will only work if it is issued as next command after the first. It will give "0" if the modprobe command was successful and another number otherwise. In doubt you may modprobe also all other modules that I listed in my last post. After doing that you may try the "lsmod" again.

For more information you might also send me some contents of the configuration file of your current kernel. Figure out the name of that file with
ls /boot/config-"$(uname -r)". E.g. here the actual file is called /boot/config-2.6.32-4-amd64. Then open that file in an editor and search for the passages

# Networking options
and

# Core Netfilter Configuration
and post its content here.

Finally please have a look at /var/log/blockcontrol.log to see whether there is something related to kernel modules.

johanholmquist
March 29th, 2010, 03:11 PM
(johan@server)-(~) $ lsmod
Module Size Used by


That's all I get from lsmod. :/ Doesn't matter if I sudo lsmod either, still no real output.


(johan@server)-(~) $ sudo modprobe xt_NFQUEUE
FATAL: Module xt_NFQUEUE not found.
(johan@server)-(~) $ echo $?
1


(johan@server)-(~) $ ls /boot/config-"$(uname -r)"
ls: cannot access /boot/config-2.6.32.8: No such file or directory

This seemed quite strange.. I don't have a configuration file? Here are the contents of /boot:

(johan@server)-(~) $ cd /boot
(johan@server)-(/boot) $ ls -a
. .. System.map boot.0800 bzImage coffee.bmp debian.bmp debianlilo.bmp map sarge.bmp sid.bmp

Could it be RKhunter that hides it for some reason?

The path /lib/modules/2.6.32.8/kernel/ contains only one folder; /lib/modules/2.6.32.8/kernel/drivers. The only thing in that folder is another folder named "scsi", which contains the file "scsi_wait_scan.ko". It corresponds to writing the following:

(johan@server)-(/lib/modules/2.6.32.8/kernel/drivers/scsi) $ modprobe -ls
kernel/drivers/scsi/scsi_wait_scan.ko

It sure looks like I have only one (1) kernel module. A module that doesn't seem to be loaded.

Here's what I get in blockcontrol.log, repeating itself every 5 minutes:

2010-03-29 14:45:14 CEST Begin: blockcontrol restart
Stopping blockcontrol.wd ...done.
Deleting iptables ...
...done.
Stopping moblock ... ...done.
Inserting iptables ...
Allowing outbound traffic to DNS server XXX.XXX.XX.X ...done.
Allowing forwarded traffic to DNS server XXX.XXX.XX.X ...done.
Allowing outbound traffic to DNS server YYY.YYY.YY.Y ...done.
Allowing forwarded traffic to DNS server YYY.YYY.YY.Y ...done.
Allowing loopback traffic ...done.
...done.
Starting moblock ... ...done.
Starting blockcontrol.wd ... ...done.
2010-03-29 14:45:14 CEST End: blockcontrol restart


Like I said, exactly 5 minutes later, it does a new blockcontrol restart (2010-03-29 14:50:14 CEST Begin: blockcontrol restart).

Anyway, I guess the real problem is the (lack of) kernel modules and config. Does that mean my iptables are ignored by the kernel as well?

jre
March 29th, 2010, 11:46 PM
I can't find kernel 2.6.32.8 - neither in Karmic (Ubuntu 9.10) nor in lucid (10.04). So where did you get your kernel from? Have you tried the official kernel from the repository?

BTW, the /boot/config-... file is only there for informational use. It tells with which options your kernel was compiled.

From the description of RKHunter I doubt that it hides any files, or is in any other way responsible for your problems. I think RKHunter just checks your system and reports problems, but doesn't actually do anything.

johanholmquist
March 30th, 2010, 10:55 AM
I've come to the conclusion that my dedicated server provider installs a custom kernel on their dedicated servers. This means I might have to compile my own "vanilla" kernel, using the config they provide in /usr/src as a base. (Apparently some of their mainboards have some sort of issues with AHCI (S-ATA) drivers included in kernels <=2.6.22 ... I think. There has to be some reason they don't use the standard kernel.)

I guess I could try installing a package from aptitude first, since the latest kernel is something like 2.6.31? Would you recommend "linux-386" or "linux-server"? Should I also install additional packages to ensure all the necessary moblock modules are included, like "linux-backports-modules-karmic"?
Will the installation "linux-server" change which kernel is used automatically, or do I have to change that somewhere?

I'm a complete newbie when it comes to these kernel-related things, I just install linux and assume everything works "automagically". Haven't run into any kernel problems at all when I've installed ubuntu and ubuntu server on several PCs here at home, but my server provider obviously installs a custom kernel on "clean" installs.

Thank you so much for all the help so far! :)

jre
March 30th, 2010, 02:35 PM
Do you have physical access to your server? In that case you can simply try a kernel from the Ubuntu repository. I'm running Debian and am not familiar with Ubuntu's kernel flavors. But I think I'd first try linux-server before linux-386.

EDIT: I doubt that you need to install additional packages!

Without physical access you can't choose which kernel will be booted on boot time in the grub boot. Instead you have to do this before booting in the grub config file (instructions how to do that are on the web).
So then you have the risk of preselecting an unbootable kernel, which would require physical access in order to select a bootable kernel again.

So in this case I would omit the step of installing a kernel from the repository, and choose to directly compile your provider's kernel. I've done that myself years ago in my linux beginners time and found it is not too hard. Just follow official instructions (preferably those of your provider, or ask your provider directly for help, otherwise Ubuntu's). Then keep all configuration settings as they are, and simply add the netfilter support as modules. In the end your configuration file should have something like this, especially the bold lines are important:

#
# Networking options
#
CONFIG_PACKET=y
CONFIG_PACKET_MMAP=y
CONFIG_UNIX=y
CONFIG_XFRM=y
CONFIG_XFRM_USER=m
CONFIG_XFRM_SUB_POLICY=y
CONFIG_XFRM_MIGRATE=y
# CONFIG_XFRM_STATISTICS is not set
CONFIG_XFRM_IPCOMP=m
CONFIG_NET_KEY=m
CONFIG_NET_KEY_MIGRATE=y
CONFIG_INET=y
CONFIG_IP_MULTICAST=y
CONFIG_IP_ADVANCED_ROUTER=y
CONFIG_ASK_IP_FIB_HASH=y
# CONFIG_IP_FIB_TRIE is not set
CONFIG_IP_FIB_HASH=y
CONFIG_IP_MULTIPLE_TABLES=y
CONFIG_IP_ROUTE_MULTIPATH=y
CONFIG_IP_ROUTE_VERBOSE=y
# CONFIG_IP_PNP is not set
CONFIG_NET_IPIP=m
CONFIG_NET_IPGRE=m
CONFIG_NET_IPGRE_BROADCAST=y
CONFIG_IP_MROUTE=y
CONFIG_IP_PIMSM_V1=y
CONFIG_IP_PIMSM_V2=y
# CONFIG_ARPD is not set
CONFIG_SYN_COOKIES=y
CONFIG_INET_AH=m
CONFIG_INET_ESP=m
CONFIG_INET_IPCOMP=m
CONFIG_INET_XFRM_TUNNEL=m
CONFIG_INET_TUNNEL=m
CONFIG_INET_XFRM_MODE_TRANSPORT=m
CONFIG_INET_XFRM_MODE_TUNNEL=m
CONFIG_INET_XFRM_MODE_BEET=m
CONFIG_INET_LRO=y
CONFIG_INET_DIAG=m
CONFIG_INET_TCP_DIAG=m
CONFIG_TCP_CONG_ADVANCED=y
CONFIG_TCP_CONG_BIC=m
CONFIG_TCP_CONG_CUBIC=y
CONFIG_TCP_CONG_WESTWOOD=m
CONFIG_TCP_CONG_HTCP=m
CONFIG_TCP_CONG_HSTCP=m
CONFIG_TCP_CONG_HYBLA=m
CONFIG_TCP_CONG_VEGAS=m
CONFIG_TCP_CONG_SCALABLE=m
CONFIG_TCP_CONG_LP=m
CONFIG_TCP_CONG_VENO=m
CONFIG_TCP_CONG_YEAH=m
CONFIG_TCP_CONG_ILLINOIS=m
# CONFIG_DEFAULT_BIC is not set
CONFIG_DEFAULT_CUBIC=y
# CONFIG_DEFAULT_HTCP is not set
# CONFIG_DEFAULT_VEGAS is not set
# CONFIG_DEFAULT_WESTWOOD is not set
# CONFIG_DEFAULT_RENO is not set
CONFIG_DEFAULT_TCP_CONG="cubic"
CONFIG_TCP_MD5SIG=y
CONFIG_IPV6=y
CONFIG_IPV6_PRIVACY=y
CONFIG_IPV6_ROUTER_PREF=y
CONFIG_IPV6_ROUTE_INFO=y
CONFIG_IPV6_OPTIMISTIC_DAD=y
CONFIG_INET6_AH=m
CONFIG_INET6_ESP=m
CONFIG_INET6_IPCOMP=m
CONFIG_IPV6_MIP6=y
CONFIG_INET6_XFRM_TUNNEL=m
CONFIG_INET6_TUNNEL=m
CONFIG_INET6_XFRM_MODE_TRANSPORT=m
CONFIG_INET6_XFRM_MODE_TUNNEL=m
CONFIG_INET6_XFRM_MODE_BEET=m
CONFIG_INET6_XFRM_MODE_ROUTEOPTIMIZATION=m
CONFIG_IPV6_SIT=m
CONFIG_IPV6_NDISC_NODETYPE=y
CONFIG_IPV6_TUNNEL=m
CONFIG_IPV6_MULTIPLE_TABLES=y
CONFIG_IPV6_SUBTREES=y
CONFIG_IPV6_MROUTE=y
CONFIG_IPV6_PIMSM_V2=y
# CONFIG_NETLABEL is not set
CONFIG_NETWORK_SECMARK=y
CONFIG_NETFILTER=y
# CONFIG_NETFILTER_DEBUG is not set
CONFIG_NETFILTER_ADVANCED=y
CONFIG_BRIDGE_NETFILTER=y

#
# Core Netfilter Configuration
#
CONFIG_NETFILTER_NETLINK=m
CONFIG_NETFILTER_NETLINK_QUEUE=m
CONFIG_NETFILTER_NETLINK_LOG=m
CONFIG_NF_CONNTRACK=m
CONFIG_NF_CT_ACCT=y
CONFIG_NF_CONNTRACK_MARK=y
CONFIG_NF_CONNTRACK_SECMARK=y
CONFIG_NF_CONNTRACK_EVENTS=y
CONFIG_NF_CT_PROTO_DCCP=m
CONFIG_NF_CT_PROTO_GRE=m
CONFIG_NF_CT_PROTO_SCTP=m
CONFIG_NF_CT_PROTO_UDPLITE=m
CONFIG_NF_CONNTRACK_AMANDA=m
CONFIG_NF_CONNTRACK_FTP=m
CONFIG_NF_CONNTRACK_H323=m
CONFIG_NF_CONNTRACK_IRC=m
CONFIG_NF_CONNTRACK_NETBIOS_NS=m
CONFIG_NF_CONNTRACK_PPTP=m
CONFIG_NF_CONNTRACK_SANE=m
CONFIG_NF_CONNTRACK_SIP=m
CONFIG_NF_CONNTRACK_TFTP=m
CONFIG_NF_CT_NETLINK=m
CONFIG_NETFILTER_TPROXY=m
CONFIG_NETFILTER_XTABLES=m
CONFIG_NETFILTER_XT_TARGET_CLASSIFY=m
CONFIG_NETFILTER_XT_TARGET_CONNMARK=m
CONFIG_NETFILTER_XT_TARGET_CONNSECMARK=m
CONFIG_NETFILTER_XT_TARGET_DSCP=m
CONFIG_NETFILTER_XT_TARGET_HL=m
CONFIG_NETFILTER_XT_TARGET_LED=m
CONFIG_NETFILTER_XT_TARGET_MARK=m
CONFIG_NETFILTER_XT_TARGET_NFLOG=m
CONFIG_NETFILTER_XT_TARGET_NFQUEUE=m
CONFIG_NETFILTER_XT_TARGET_NOTRACK=m
CONFIG_NETFILTER_XT_TARGET_RATEEST=m
CONFIG_NETFILTER_XT_TARGET_TPROXY=m
CONFIG_NETFILTER_XT_TARGET_TRACE=m
CONFIG_NETFILTER_XT_TARGET_SECMARK=m
CONFIG_NETFILTER_XT_TARGET_TCPMSS=m
CONFIG_NETFILTER_XT_TARGET_TCPOPTSTRIP=m
CONFIG_NETFILTER_XT_MATCH_CLUSTER=m
CONFIG_NETFILTER_XT_MATCH_COMMENT=m
CONFIG_NETFILTER_XT_MATCH_CONNBYTES=m
CONFIG_NETFILTER_XT_MATCH_CONNLIMIT=m
CONFIG_NETFILTER_XT_MATCH_CONNMARK=m
CONFIG_NETFILTER_XT_MATCH_CONNTRACK=m
CONFIG_NETFILTER_XT_MATCH_DCCP=m
CONFIG_NETFILTER_XT_MATCH_DSCP=m
CONFIG_NETFILTER_XT_MATCH_ESP=m
CONFIG_NETFILTER_XT_MATCH_HASHLIMIT=m
CONFIG_NETFILTER_XT_MATCH_HELPER=m
CONFIG_NETFILTER_XT_MATCH_HL=m
CONFIG_NETFILTER_XT_MATCH_IPRANGE=m
CONFIG_NETFILTER_XT_MATCH_LENGTH=m
CONFIG_NETFILTER_XT_MATCH_LIMIT=m
CONFIG_NETFILTER_XT_MATCH_MAC=m
CONFIG_NETFILTER_XT_MATCH_MARK=m
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=m
CONFIG_NETFILTER_XT_MATCH_OWNER=m
CONFIG_NETFILTER_XT_MATCH_POLICY=m
CONFIG_NETFILTER_XT_MATCH_PHYSDEV=m
CONFIG_NETFILTER_XT_MATCH_PKTTYPE=m
CONFIG_NETFILTER_XT_MATCH_QUOTA=m
CONFIG_NETFILTER_XT_MATCH_RATEEST=m
CONFIG_NETFILTER_XT_MATCH_REALM=m
CONFIG_NETFILTER_XT_MATCH_RECENT=m
# CONFIG_NETFILTER_XT_MATCH_RECENT_PROC_COMPAT is not set
CONFIG_NETFILTER_XT_MATCH_SCTP=m
CONFIG_NETFILTER_XT_MATCH_SOCKET=m
CONFIG_NETFILTER_XT_MATCH_STATE=m
CONFIG_NETFILTER_XT_MATCH_STATISTIC=m
CONFIG_NETFILTER_XT_MATCH_STRING=m
CONFIG_NETFILTER_XT_MATCH_TCPMSS=m
CONFIG_NETFILTER_XT_MATCH_TIME=m
CONFIG_NETFILTER_XT_MATCH_U32=m
CONFIG_NETFILTER_XT_MATCH_OSF=m
CONFIG_IP_VS=m
# CONFIG_IP_VS_IPV6 is not set
# CONFIG_IP_VS_DEBUG is not set
CONFIG_IP_VS_TAB_BITS=12

jre
March 31st, 2010, 01:05 PM
@johanholmquist:
blockcontrol should have correctly reported what is going wrong. Obviously it didn't do that. So please help me to improve blockcontrol and send me the output of the following commands (while running your old kernel):

[ -f /proc/net/ip_tables_targets ]
echo $?
grep -q NFQUEUE /proc/net/ip_tables_targets
echo $?
modprobe -q xt_NFQUEUE
echo $?
modprobe -q ipt_NFQUEUE
echo $?

[ -f /proc/net/ip_queue ]
echo $?
modprobe -q ip_queue
echo $?

[ -f /proc/net/ip_tables_matches ]
echo $?
grep -q mark /proc/net/ip_tables_matches
echo $?
modprobe -q xt_mark
echo $?
modprobe -q ipt_mark
echo $?

[ -f /proc/net/ip_tables_matches ]
echo $?
grep -q state /proc/net/ip_tables_matches
echo $?
modprobe -q xt_state
echo $?
modprobe -q ipt_state
echo $?

[ -f /proc/net/ip_tables_matches ]
echo $?
grep -q iprange /proc/net/ip_tables_matches
echo $?
modprobe -q xt_iprange
echo $?
modprobe -q ipt_iprange
echo $?

ls -l /bin/sh
blockcontrol show_config

lovinglinux
April 13th, 2010, 10:13 PM
Hi jre, how are you doing?

I'm wondering when a ppa for Lucid will be available? I'm currently using the Karmic ppa and it is working fine, but I don't know if I could experience any issues by doing this.

Not making any pressure. I'm just addicted to moblock :)

jre
April 13th, 2010, 10:26 PM
I'm just working on releasing pgl. Only drawbacks: no GUI yet and no debian transition for automatic updates from moblock. But the latter is only necessary if the first is available.
Debian packages of pgl will be available for Debian squeeze and sid and Ubuntu karmic and lucid. (I won't support any older releases, that's just too time consuming. But since lucid is a LTS that will be ok).
So when I've done that I might do lcuid packages of the rest, too. Perhaps even earlier.
I'll give you an update here.

Besides that, you might have noted that I greatly reduced my work on this stuff. I had a few months with nearly zero time commitment and I doubt that I will ever spend as much time as in the past on this. But on the other site I always enjoy it, when I work on this stuff. And your question came at the best time to motivate me to do what I just wrote above. And as always a big thank you for your active work here in the forum, lovinglinux. This helps me to find time for development.

lovinglinux
April 13th, 2010, 10:38 PM
I'm just working on releasing pgl. Only drawbacks: no GUI yet and no debian transition for automatic updates from moblock. But the latter is only necessary if the first is available.
Debian packages of pgl will be available for Debian squeeze and sid and Ubuntu karmic and lucid. (I won't support any older releases, that's just too time consuming. But since lucid is a LTS that will be ok).
So when I've done that I might do lcuid packages of the rest, too. Perhaps even earlier.
I'll give you an update here.

Besides that, you might have noted that I greatly reduced my work on this stuff. I had a few months with nearly zero time commitment and I doubt that I will ever spend as much time as in the past on this. But on the other site I always enjoy it, when I work on this stuff. And your question came at the best time to motivate me to do what I just wrote above. And as always a big thank you for your active work here in the forum, lovinglinux. This helps me to find time for development.

That was fast :)

I don't know if I understood correctly, but are you saying PeerGuardian for Linux is being revived? Does it replaces moblock?

I understand the commitment issues. I have been thinking about stopping providing a Windows version of one of my Firefox extensions. It doesn't work 100% as the Linux version and is just too time consuming to make it. Besides, I hate having to boot into Windows. I feel completely lost. I need to focus on polishing the Linux version, so Mozilla can approve it for public download. Need to prioritize the development time available.

Thanks for the great work.

jre
April 13th, 2010, 10:43 PM
Yes. PeerGuardian Linux (pgl) is based on nfblock (moblock
clone) and blockcontrol and has many improvements and fixes. If you want to try it you can get it from the git development repository:
https://sourceforge.net/projects/peerguardian/develop

You can install it e.g. with


# Install git, fakeroot and build-dependencies:
sudo aptitude install git-core fakeroot debhelper libqt4-dev
po-debconf zlib1g-dev libnetfilter-queue-dev libnfnetlink-dev
libdbus-1-dev
# Get the development repository
git clone git://peerguardian.git.sourceforge.net/gitroot/peerguardian/peerguardian
# Change to the source directory
cd peerguardian/pgl/
# Build the packages
dpkg-buildpackage -uc -us -tc -rfakeroot
# Install packages
sudo dpkg -i ../pgl*.deb

Oh, for releasing I only have to update the documetnation and fix the Debian packaging (nearly done).
That answer was even faster ;-) I like copy&paste.

jre
April 13th, 2010, 10:49 PM
The real replacement will just occur when we have a GUI. Work on that was started, but is stalled currently. So I can't tell what will happen ....

lovinglinux
April 13th, 2010, 10:58 PM
Yes. PeerGuardian Linux (pgl) is based on nfblock (moblock
clone) and blockcontrol and has many improvements and fixes. If you want to try it you can get it from the git development repository:
https://sourceforge.net/projects/peerguardian/develop

You can install it e.g. with


# Install git, fakeroot and build-dependencies:
sudo aptitude install git-core fakeroot debhelper libqt4-dev
po-debconf zlib1g-dev libnetfilter-queue-dev libnfnetlink-dev
libdbus-1-dev
# Get the development repository
git clone git://peerguardian.git.sourceforge.net/gitroot/peerguardian/peerguardian
# Change to the source directory
cd peerguardian/pgl/
# Build the packages
dpkg-buildpackage -uc -us -tc -rfakeroot
# Install packages
sudo dpkg -i ../pgl*.deb

Oh, for releasing I only have to update the documetnation and fix the Debian packaging (nearly done).
That answer was even faster ;-) I like copy&paste.

Thanks. I'm definitely going to try it. I hope it keeps the nice features provided by moblock. For instance, I use moblock as iptables manager, not only for blocking peers.

Do I need to remove moblock first? How do I revert the changes made by the above instructions?

jre
April 13th, 2010, 11:07 PM
you need to uninstall moblock/....
then the new packages will be pgld, pgld-dbg and pglcmd
Most important for you the iptables chains have new names. the filenames changed of course, too. But I think both is already documented.
Besides that you can replace all "blockcontrol OPTION" commands with "pglcmd OPTION"

dealcorn
April 25th, 2010, 11:12 AM
I am trying to obtain jaunty clarification of the Howto comment that most kernels do not permit whitelist traffic per application. My goal is to block transmission from a specific site but permit deluge. After blacklisting the site it appears that iptables-custom-insert.sh would permit me to either whitelist the application deluge or whitelist the site, but it would not permit a whitelist based on the requirement that both conditions be met. My initial read of the chain rule-specification of man iptables suggests that it is not helpful. Am I correct and is there an alternate approach?

jre
April 26th, 2010, 08:52 PM
You can freely combine all iptables options. So the combination of whitelisting a site for a special application is possible.

If your system (kernel/netfilter/iptables) doesn't support the cmd-owner module, you may use other modules instead - I guess the uid-owner module (solution 3) is supported by every system.

Here are a few possible solutions (not tested!):

Use the pid-owner module (the first line first makes sure that deluge is running, and then inserts the whitelisting rule for deluge's pid which is inserted automatically by $(pidof deluge). So you need to restart blockcontrol after starting deluge.)

pidof deluge > /dev/null && \
iptables -I blockcontrol_out -m owner --pid-owner $(pidof deluge) -d [IP] -j RETURN
Use the cmd-owner module

iptables -I blockcontrol_out -m owner --cmd-owner deluge -d [IP] -j RETURN
Run deluge from a separate user and use the uid-owner module

iptables -I blockcontrol_out -m owner --uid-owner [deluge-user] -d [IP] -j RETURN

dealcorn
April 27th, 2010, 07:12 PM
After I was unable to get application specific whitelist option 1 or 2 above to work, I simplified by blacklisting a local google site (64.233.189.104) and retried with the google site address, also to fail. Then I got rid of iptables-custom-insert.sh and edited /blockcontrol.conf to whitelist the site and verified that it appeared correct in Mobloquer only to again discover that the whitelist failed. I did stop, rebuild and start MoBlock appropriately. I use firestarter to blacklist my problem site. Do the MoBlock whitelist features require that the blacklist come from a list rather than iptables? If so, is there a technique to put a blacklst site into a list format that may be imported? My last blocklist control status follows:


:~$ sudo blockcontrol status
[sudo] password for dea:
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy DROP 4 packets, 5752 bytes)
pkts bytes target prot opt in out source destination
640 28112 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
0 0 ACCEPT tcp -- * * 192.168.0.1 0.0.0.0/0 tcp flags:!0x17/0x02
4 596 ACCEPT udp -- * * 192.168.0.1 0.0.0.0/0
19394 4442K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
121 15058 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/sec burst 5
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
5 140 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
23 1020 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 LSI all -f * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/min burst 5
43584 24M INBOUND all -- wlan0 * 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Input'

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 10/sec burst 5
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Forward'

Chain OUTPUT (policy DROP 6 packets, 240 bytes)
pkts bytes target prot opt in out source destination
2396 210K blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
0 0 ACCEPT tcp -- * * 192.168.0.102 192.168.0.1 tcp dpt:53
4 257 ACCEPT udp -- * * 192.168.0.102 192.168.0.1 udp dpt:53
19394 4442K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 224.0.0.0/8 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/8
0 0 DROP all -- * * 255.255.255.255 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
53936 45M OUTBOUND all -- * wlan0 0.0.0.0/0 0.0.0.0/0
0 0 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Unknown Output'

Chain INBOUND (1 references)
pkts bytes target prot opt in out source destination
42201 23M ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
1382 234K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
1 75 LSI all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LOG_FILTER (5 references)
pkts bytes target prot opt in out source destination

Chain LSI (2 references)
pkts bytes target prot opt in out source destination
1 75 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02
0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04
0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
0 0 DROP icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
1 75 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Inbound '
1 75 DROP all -- * * 0.0.0.0/0 0.0.0.0/0

Chain LSO (1 references)
pkts bytes target prot opt in out source destination
2 88 LOG_FILTER all -- * * 0.0.0.0/0 0.0.0.0/0
2 88 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5 LOG flags 0 level 6 prefix `Outbound '
2 88 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable

Chain OUTBOUND (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
51112 45M ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
215 26112 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
2 88 LSO all -- * * 0.0.0.0/0 64.233.189.104
2607 267K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0

Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 192.168.0.1
0 0 RETURN all -- * * 192.168.0.0/24 192.168.0.0/24
0 0 RETURN all -- * * 0.0.0.0/0 64.233.189.104
0 0 RETURN all -- * * 64.233.189.104 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
637 28028 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
3 84 RETURN all -- * * 192.168.0.0/24 0.0.0.0/0
0 0 RETURN all -- * * 64.233.189.104 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
224 24878 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
637 28028 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
2 127 RETURN all -- * * 0.0.0.0/0 192.168.0.1
0 0 RETURN all -- * * 0.0.0.0/0 192.168.0.0/24
0 0 RETURN all -- * * 0.0.0.0/0 64.233.189.104
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
19 836 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
1514 156K NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* moblock is running
PID: 24547 CMD: /usr/bin/moblock -p /var/lib/blockcontrol/guarding.p2p -q 92 -t -r 10 -a 20 /var/log/moblock.log

* blockcontrol.wd is running
PID: 24552 CMD: /bin/sh /usr/bin/blockcontrol.wd

jre
May 6th, 2010, 11:01 PM
First off, every configuration change requires a "blockcontrol restart"! But at least in your "blockcontrol status" everything seems fine. There you have whitelisted/allowed 64.233.189.104 in every direction for moblock. So moblock will never block this IP. Instead you reject this IP with firestarter for outgoing connections (chains OUTBOUND and LSO).

Just for clarification (I#m a bit at a loss to understand what you really want):
whitelisting:
moblock will not block this IP, even if it is in one of the blocklists. Note that e.g. firestarter still may block this IP, even if moblock does not block it. This can be achieved

with the WHITE_IP_IN, WHITE_IP_OUT and WHITE_IP_FORWARD entries in blockcontrol.conf
an iptables rule in iptables-custom-insert.sh with the target RETURN


blacklisting:
two ways to understand this:

Generally block traffic to/from an IP. This can be achieved by

Using e.g. firestarter
an iptables rule with the target REJECT or DROP

add an IP to moblock's blocklist. (I think this is the answer to your last questions):

Create a file /etc/blockcontrol/custom-blocklist.p2p and add a line like
Google:64.233.189.104-64.233.189.104
then add this line to blockcontrol.conf:
locallist /etc/blockcontrol/custom-blocklist.p2p



Feel free to ask again. I'm not sure whether this answer helped.

chinaski
June 8th, 2010, 01:23 PM
Lately moblock (last version on 10.04-32) blocks lots of connection most of which outgoing, and this happens since few days despite no p2p software is running.

I rebooted the router and got new public IP several times, but since last time I shut aMule down few days ago moblock is still blocking connection.

Here's a small portion of moblock.log



Tue Jun 8 13:39:58| OUT: Valencia University,hits: 3,DST: 147.156.27.234
Tue Jun 8 13:39:58| OUT: Vodafone Ireland Limited,hits: 54,DST: 93.107.7.186
Tue Jun 8 13:40:05| OUT: Vodafone Ireland Limited,hits: 55,DST: 93.107.7.186
Tue Jun 8 13:40:07| OUT: Vodafone Ireland Limited,hits: 56,DST: 93.107.7.186
Tue Jun 8 13:40:11| OUT: Vodafone Ireland Limited,hits: 57,DST: 93.107.7.186
Tue Jun 8 13:40:32| OUT: Vodafone Ireland Limited,hits: 58,DST: 93.107.7.186
Tue Jun 8 13:40:34| OUT: Vodafone Ireland Limited,hits: 59,DST: 93.107.7.186
Tue Jun 8 13:40:38| OUT: Vodafone Ireland Limited,hits: 60,DST: 93.107.7.186
Tue Jun 8 13:41:49| OUT: Vodafone Omnitel N.V,hits: 6,DST: 93.147.74.54
Tue Jun 8 13:41:49| OUT: TeliaSonera AB,hits: 1,DST: 213.66.160.14
Tue Jun 8 13:41:49| OUT: University of Lancaster,hits: 1,DST: 148.88.181.173
Tue Jun 8 13:41:51| OUT: Vodafone Omnitel N.V,hits: 7,DST: 93.147.74.54
Tue Jun 8 13:41:51| OUT: TeliaSonera AB,hits: 2,DST: 213.66.160.14
Tue Jun 8 13:41:51| OUT: University of Lancaster,hits: 2,DST: 148.88.181.173
Tue Jun 8 13:41:55| OUT: Vodafone Omnitel N.V,hits: 8,DST: 93.147.74.54
Tue Jun 8 13:41:55| OUT: TeliaSonera AB,hits: 3,DST: 213.66.160.14
Tue Jun 8 13:41:55| OUT: University of Lancaster,hits: 3,DST: 148.88.181.173
Tue Jun 8 13:45:38| OUT: University of Lancaster,hits: 4,DST: 148.88.181.173
Tue Jun 8 13:45:40| OUT: University of Lancaster,hits: 5,DST: 148.88.181.173
Tue Jun 8 13:45:44| OUT: University of Lancaster,hits: 6,DST: 148.88.181.173
Tue Jun 8 13:50:19| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 28,DST: 213.92.110.188
Tue Jun 8 13:50:20| OUT: Early registrations SURFnet bv,hits: 61,DST: 145.116.233.143
Tue Jun 8 13:50:21| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 29,DST: 213.92.110.188
Tue Jun 8 13:50:22| OUT: Early registrations SURFnet bv,hits: 62,DST: 145.116.233.143
Tue Jun 8 13:50:26| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 30,DST: 213.92.110.188
Tue Jun 8 13:50:26| OUT: Early registrations SURFnet bv,hits: 63,DST: 145.116.233.143
Tue Jun 8 13:50:45| OUT: Vodafone Ireland Limited,hits: 61,DST: 93.107.7.186
Tue Jun 8 13:50:47| OUT: Vodafone Ireland Limited,hits: 62,DST: 93.107.7.186
Tue Jun 8 13:50:51| OUT: Vodafone Ireland Limited,hits: 63,DST: 93.107.7.186
Tue Jun 8 13:53:50| OUT: Bogon,hits: 1,DST: 42.242.39.203
Tue Jun 8 13:53:50| OUT: Bogon,hits: 2,DST: 42.242.39.203
Tue Jun 8 14:01:44| OUT: Early registrations SURFnet bv,hits: 64,DST: 145.116.233.143
Tue Jun 8 14:01:46| OUT: Early registrations SURFnet bv,hits: 65,DST: 145.116.233.143
Tue Jun 8 14:01:50| OUT: Early registrations SURFnet bv,hits: 66,DST: 145.116.233.143
Tue Jun 8 14:04:29| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 31,DST: 213.92.110.188
Tue Jun 8 14:04:30| OUT: Vodafone Ireland Limited,hits: 64,DST: 93.107.7.186
Tue Jun 8 14:04:31| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 32,DST: 213.92.110.188
Tue Jun 8 14:04:32| OUT: Vodafone Ireland Limited,hits: 65,DST: 93.107.7.186
Tue Jun 8 14:04:35| OUT: I.Net S.p.A., Vodafone Omnitel N.V,hits: 33,DST: 213.92.110.188
Tue Jun 8 14:04:35| OUT: Vodafone Ireland Limited,hits: 66,DST: 93.107.7.186
1) is this normal? in my experience with moblock I used to change public IP by rebooting the router every time I turned p2p software off, and no IN/OUT connection whatsoever

2) what is it on my machine that is trying to connect to those hosts? I run rkhunter and chkrootkit and nothing was found

On this machine I usually run Firefox, Skype, Rhythmbox with all plugin disabled, and OpenOffice, which are all open now and that's all.

???

jre
June 8th, 2010, 04:27 PM
I wouldn't worry about that.
Since they are outgoing connections a new IP from your router can`t help here.
To investigate further you can check the ports of the blocked packets: For moblock check this link (https://help.ubuntu.com/community/MoBlock#How%20do%20I%20find%20out%20which%20IP%20o r%20port%20was%20blocked?) or just install pgl (no GUI yet) instead of moblock and have a look at /var/log/pgl/pgld.log

You can also use a packet sniffer (wireshark) to analyze the traffic.

chinaski
June 9th, 2010, 01:02 AM
Hello jre,

Thank you for your answer.

I have realized I had set this machine as LAMP server just before this started.

I think this was the "problem".

Or better the fact I left Apache and MySQL on default auto start settings.

After stopping services and preventing them from autostart with
sudo update-rc.d -f service_name remove no more connections are logged if p2p software is off.

Sorry to bother you for my stupidity :)

chinaski
June 14th, 2010, 11:08 PM
I have found out those connections are blocked if Skype is on

today at 6:24pm I have shut Skype down, and I have reopened it right now:


Mon Jun 14 18:24:13| OUT: netdirekt e. K,hits: 2,DST: 89.149.253.183
Mon Jun 14 18:24:16| OUT: MCNC,hits: 3,DST: 152.2.71.239
Mon Jun 14 18:24:17| OUT: University of Michigan,hits: 3,DST: 141.211.98.176
Mon Jun 14 18:24:17| OUT: netdirekt e. K,hits: 3,DST: 89.149.253.183
Tue Jun 15 00:04:47| OUT: SUNET/NORDUnet,hits: 18,DST: 130.238.141.52
Tue Jun 15 00:04:48| OUT: Dzirciema iela 16, Riga, LV-1007,hits: 3,DST: 159.148.163.249
Tue Jun 15 00:04:48| OUT: University of Maribor,hits: 2,DST: 164.8.3.50
Tue Jun 15 00:04:49| OUT: Communications Networking Services,hits: 5,DST: 212.8.163.76
Tue Jun 15 00:04:50| OUT: Sony Network Taiwan Limited,hits: 4,DST: 61.64.138.162
Tue Jun 15 00:04:50| OUT: ELTEL,hits: 1,DST: 89.112.59.195
Tue Jun 15 00:04:50| OUT: Proxad Static DSL,hits: 10,DST: 82.246.178.227
Tue Jun 15 00:04:50| OUT: Chalmers University Network,hits: 1,DST: 129.16.137.104
why is Skype trying to connect to such hosts?

ewan86
August 18th, 2010, 08:07 PM
Setting up Moblock and Mobloquer as a non technical person was hard going but I think it is done fairly correctly though I only partially understood what I did and which lists I should use.

Anyway question: Should I enable blocklists in transmission when I have moblock running??? will this enhance or degrade security??

Thanks for your hard work on this :)

jre
August 18th, 2010, 09:14 PM
The correct list setting depends on your needs. My advice is to visit iblocklist.com and read the description. Generally I don't recommend to use too many lists. The default setting in my packages is already nearly paranoid.

If you don't have any whitelistings there is no point in using a blocklist in transmission, but it won't hurt either. If you have whitelistings (e.g. for http port 80) then you might gain a little additional security by using a blocklist in transmission.
If you use only blocklists in transmission, but not moblock at all, then your system will loose its "stealth" mode. Further I don't know if you can combine several blocklists in transmission, and how the updates are handled. So I strongly suggest to use at least moblock.

Perhaps the FAQ at https://help.ubuntu.com/community/MoBlock helps you further.

ewan86
August 19th, 2010, 02:20 AM
Thanks so much for your speedy response. I have both running and I think I stuck with the standard blocklists so I should be fine!

I did open the ports for AMSN (and who knows what else Idid!!) so it would work but I don't think that is the same as whitelisting.

Anyway thats brilliant I will leave them both running if there is no conflict.

jre
August 19th, 2010, 10:03 AM
"whitelisting" is opening the ports, or allowing traffic on those ports.
In most cases you will only whitelist outgoing TCP ports (WHITE_TCP_OUT), which allows you to use other services on the internet.
I don't know what is needed for AMSN - here it might be that you need to whitelist incoming (TCP) traffic, too.

You can verify your config with "blockcontrol show_config". Every variable is documented in /usr/lib/blockcontrol/blockcontrol.defaults. If you need to correct changes, but can't do it in mobloquer, then you have to edit /etc/blockcontrol/blockcontrol.conf.

Origin_Unknown
September 6th, 2010, 11:25 PM
Hi Guys / Girls

I'm having a bit of a problem getting moblocker to start and I'm hoping someone can help! I've been through the guide @ http://help.ubuntu.com/community/MoBlock, done the install and gone through the configuration but when the app tries to start i get the following message in terminal'



mediacenter@MediaCenter:~$ sudo aptitude install moblock blockcontrol mobloquer
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
The following NEW packages will be installed:
blockcontrol libnetfilter-queue1{a} libnfnetlink0{a} moblock mobloquer
0 packages upgraded, 5 newly installed, 0 to remove and 0 not upgraded.
Need to get 0B/409kB of archives. After unpacking 1,327kB will be used.
Do you want to continue? [Y/n/?] y
Writing extended state information... Done
Preconfiguring packages ...
Selecting previously deselected package libnfnetlink0.
(Reading database ... 144228 files and directories currently installed.)
Unpacking libnfnetlink0 (from .../libnfnetlink0_1.0.0-1_i386.deb) ...
Selecting previously deselected package libnetfilter-queue1.
Unpacking libnetfilter-queue1 (from .../libnetfilter-queue1_0.0.17-1_i386.deb) ...
Selecting previously deselected package moblock.
Unpacking moblock (from .../moblock_0.9~rc2-24~lucid_i386.deb) ...
Selecting previously deselected package blockcontrol.
Unpacking blockcontrol (from .../blockcontrol_1.6.12-1~lucid_all.deb) ...
Selecting previously deselected package mobloquer.
Unpacking mobloquer (from .../mobloquer_0.6+svn20090817+3-1~lucid_i386.deb) ...
Processing triggers for man-db ...
Processing triggers for ureadahead ...
Processing triggers for desktop-file-utils ...
Processing triggers for python-gmenu ...
Rebuilding /usr/share/applications/desktop.en_GB.utf8.cache...
Processing triggers for python-support ...
Setting up libnfnetlink0 (1.0.0-1) ...

Setting up libnetfilter-queue1 (0.0.17-1) ...

Setting up moblock (0.9~rc2-24~lucid) ...
Setting up blockcontrol (1.6.12-1~lucid) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. So if
downloading the blocklists fails temporarily, the installation will fail.
To workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"
Please be patient ...
* Starting IP block daemon moblock [fail]
invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess installed post-installation script returned error exit status 9
dpkg: dependency problems prevent configuration of mobloquer:
mobloquer depends on blockcontrol; however:
Package blockcontrol is not configured yet.
dpkg: error processing mobloquer (--configure):
dependency problems - leaving unconfigured
Processing triggers for libc-bin ...
No apport report written because the error message indicates it's a follow-up error from a previous failure.
ldconfig deferred processing now taking place
Errors were encountered while processing:
blockcontrol
mobloquer
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install. Trying to recover:
Setting up blockcontrol (1.6.12-1~lucid) ...

moblock will soon be started ...
If any blocklists are missing, they will be downloaded. This may take several
minutes. Please be patient and don't abort. If you want to follow the update
process, then do in another terminal a
tail -f /var/log/blockcontrol.log
The lists are saved to /var/spool/blockcontrol/.
The installation of blockcontrol will fail, if starting moblock fails. So if
downloading the blocklists fails temporarily, the installation will fail.
To workaround this, you can turn the automatic starting of moblock off by setting
in /etc/blockcontrol/blockcontrol.conf:
INIT="0"
Please be patient ...
* Starting IP block daemon moblock [fail]
invoke-rc.d: initscript blockcontrol, action "start" failed.
dpkg: error processing blockcontrol (--configure):
subprocess installed post-installation script returned error exit status 9
dpkg: dependency problems prevent configuration of mobloquer:
mobloquer depends on blockcontrol; however:
Package blockcontrol is not configured yet.
dpkg: error processing mobloquer (--configure):
dependency problems - leaving unconfigured
Errors were encountered while processing:
blockcontrol
mobloquer
Reading package lists... Done
Building dependency tree
Reading state information... Done
Reading extended state information
Initialising package states... Done
Writing extended state information... Done


so obviously the program isn't started yet so I open the Mobloquer GUI, click manage and see some messages saying (log file isn't working so I'm having to type this)



Building blocklist... Updating Bluetack_level1...done.
Extracting Bluetack_Level1, detected gz...
gzip: /var/spool/blockcontrol/Bluetack_Level1/downloaded/Bluetack_Level1: Invalid compressed data--crc error
*Error 9:Failed to extract Bluetack_Level1.
*Removing /var/spool/blockcontrol/Bluetack_Level1/downloaded/Bluetack_Level1.
*Check your configuration in /etc/blockcontrol/blocklists.list and try a new blockcontrol update


the current selections on the list are;



#list.iblocklist.com/lists/atma/atma
#list.iblocklist.com/lists/bluetack/ads-trackers-and-bad-pr0n
list.iblocklist.com/lists/bluetack/bad-peers
#list.iblocklist.com/lists/bluetack/bogon
list.iblocklist.com/lists/bluetack/dshield
#list.iblocklist.com/lists/bluetack/edu
#list.iblocklist.com/lists/bluetack/for-non-lan-computers
#list.iblocklist.com/lists/bluetack/forum-spam
list.iblocklist.com/lists/bluetack/hijacked
#list.iblocklist.com/lists/bluetack/iana-multicast
#list.iblocklist.com/lists/bluetack/iana-private
#list.iblocklist.com/lists/bluetack/iana-reserved
list.iblocklist.com/lists/bluetack/level-1
#list.iblocklist.com/lists/bluetack/level-2
#list.iblocklist.com/lists/bluetack/level-3
list.iblocklist.com/lists/bluetack/microsoft
list.iblocklist.com/lists/bluetack/proxy
#list.iblocklist.com/lists/bluetack/range-test
list.iblocklist.com/lists/bluetack/spider
#list.iblocklist.com/lists/bluetack/spyware
#list.iblocklist.com/lists/bluetack/web-exploit
#list.iblocklist.com/lists/bluetack/webexploit-forumspam
#list.iblocklist.com/lists/cidr-report/bogon
#list.iblocklist.com/lists/dchubad/faker
#list.iblocklist.com/lists/dchubad/hacker
#list.iblocklist.com/lists/dchubad/pedophiles
#list.iblocklist.com/lists/dchubad/spammer
#list.iblocklist.com/lists/nexus23/ipfilterx
#list.iblocklist.com/lists/peerblock/rapidshare
#list.iblocklist.com/lists/spamhaus/drop
list.iblocklist.com/lists/tbg/bogon
list.iblocklist.com/lists/tbg/business-isps
list.iblocklist.com/lists/tbg/educational-institutions
list.iblocklist.com/lists/tbg/general-corporate-ranges
list.iblocklist.com/lists/tbg/hijacked
list.iblocklist.com/lists/tbg/primary-threats
list.iblocklist.com/lists/tbg/search-engines

#locallist /etc/blockcontrol/custom-blocklist.p2p


I've removed Bluetack_Level` and then moblocker updates everything down to 'TBH_Educational_Instuitions so I remove that, general-corperate-ranges and tbg/primary-threats then finally moblock starts...

is there any reason those 4 stop moblocker from starting at all? should it not just skip past and say they arnt updated? or is it because its a first time install and i've not downloaded those lists yet?

jre
September 7th, 2010, 05:25 PM
Yes, this is intended behaviour: MoBlock refuses to start if any configured blocklist is not available. But if an update of a list fails, it just uses the last available version of that list. I decided that this way, so that users get aware of the fact that a list is missing (while it is acceptable that an old version is used).

BTW, I just tried your blocklists.list and all lists were available.

Origin_Unknown
September 7th, 2010, 09:36 PM
Yes, this is intended behaviour: MoBlock refuses to start if any configured blocklist is not available. But if an update of a list fails, it just uses the last available version of that list. I decided that this way, so that users get aware of the fact that a list is missing (while it is acceptable that an old version is used).

BTW, I just tried your blocklists.list and all lists were available.


thanks for the reply - i guess mine was failing to start then because i didnt have a previous available version. it's interesting that mine wouldn't update - perhaps ill try again now and see

Origin_Unknown
September 7th, 2010, 10:18 PM
I've just tried it again and i keep getting the same behavior even if i manually add the list from iblocklist.com - i also get the same issue on another machine i have with ubuntu 10.04.1 installed on

jre
September 7th, 2010, 10:23 PM
Although I can't imagine what is going wrong, perhaps a "sudo blockcontrol force-update" helps. This will delete all currently downloaded blocklists and start from scratch again.
Another possibility might be that you had too many downloads from iblocklist.com, and were therefore banned temporarily (although this never happened to me, even when I made many downloads while working on the blocklist download code).

Origin_Unknown
September 7th, 2010, 10:42 PM
it appears to be downloading the files as i've been to /var/spool/blockcontrol/Bluetack_level1/ had a look in the download folder and there is a file in there that just cannot be extracted - which would go with the CRC error that moblocker is giving me.

The owner of the folder above is OWNER and changing the folder permissions to my user name have no effect.

Ill give it another go on one of the machines at work tomorrow and see if i can get it to work there

Origin_Unknown
September 8th, 2010, 09:28 AM
I've just tested it at work and for some reason it works just fine - I'm going to reload my pc at home tonight and see what's what.... still odd though.

Origin_Unknown
September 8th, 2010, 08:03 PM
Re-installed Ubuntu and installed MoBlock then as if by magic it works - cheers jre

jre
September 8th, 2010, 08:13 PM
Glad to hear. Although I think that was a bit overkill ;-)

I guess you were just unlucky and somehow got a coorupted list. The maintainer of iblocklist.com thinks it might be, that you just downlaoded the list from the server, while a new one was uploaded. So probably the "blockcontrol force-update" would have worked.

Have fun!

urschrei
September 11th, 2010, 09:56 PM
My install of moblock 0.9rc2 (compiled OK from source, and installed OK; I can run 'moblock' from the terminal and get its usage options) and blockcontrol 1.6.12 is refusing to start on Ubuntu 10.04.1 (PPC).

Looking at blockcontrol.log, I just see:



2010-09-11 21:49:05 IST End: blockcontrol force-update
2010-09-11 21:50:01 IST Begin: blockcontrol start
Building blocklist... ...done.
* Warning: Could not load kernel module xt_iprange, continuing anyway.
* Whitelisting IP ranges with the allow list will not work.
* The allow list is in /etc/blockcontrol/allow.p2p.
Inserting iptables ...
iptables: Chain already exists.
...fail!
...fail!


And nothing else. Is there a way for me to see what's causing the "...fail!" messages? Syslog isn't showing anything.

jre
September 12th, 2010, 10:25 AM
The log says that blockcontrol can't insert the necessary iptables rules/chains because they were already inserted previously. You can remove them by issuing a "blockcontrol stop". Verify that they are removed with a "blockcontrol status" - in that output you should see no reference to "blockcontrol" at all. Then try a "blockcontrol start" again.

After solving that problem I guess you will still experience another problem, which is the original reason for the error message you just got.

Do you use a custom built kernel? (I guess so because of the warning message about xt_iprange. Please note that this is eally just a warning, but does not prevent moblock from working. But it still indicates something special about your system). Make sure that you enable (as modules) the necessary netfilter support. See the README for details.

Why did you compile your own version? I recommend to just install from moblock-deb.sourceforge.net. See also the guide at https://help.ubuntu.com/community/MoBlock

Where did you get your sources from? The original moblock source from berlios.de needs patching in order to work. Even if you want to compile on your own, I recommend to use the source from moblock-deb.sf.net

urschrei
September 12th, 2010, 01:22 PM
I built the package using the instructions from moblock-deb (I'm running on PPC, and there doesn't seem to be a package available in apt), ran blockcontrol stop, then start, then status, and now it's fine. I didn't even get the warning about the missing kernel module. Odd, but it's running, and I'm seeing hits in the log.

jre
September 12th, 2010, 02:22 PM
Indeed I don't offer PPC packages, but you just made everything right. So great to hear that it works on PPC. Just strange that you had those problems in the beginning.

skipper38
September 20th, 2010, 07:27 AM
Hi guys I've just registered to ask for your help, I'm a newbie of Ubuntu 10.4 and after a few weeks finally got Moblock installed, It says its running but in the log panel I expected to see running lists of ip's it is blocking (like PG2).........So I enabled blocklist microsoft and restarted MB and went to MS website expecting to get blocked:confused:

Not really sure whats going on and apologies if this has been posted already.....also when used to use PG2 my RSS for BBC news feed used to fail ! so I knew it was doing its job, this is just confusing me as it doesn't seem to be doing anything, I've had just one item on the log which was yahoo.....any advice VERY much appreciated:KS

jre
September 20th, 2010, 05:37 PM
i guess on installation you accepted to whitelist outging TCP conections on port 80 and 443 (http and https services). Just edit /etc/blockcocntrol/blockcocntrol.conf and remove this whitelisting. See also https://help.ubuntu.com/community/MoBlock

skipper38
September 21st, 2010, 06:30 AM
Hi jre thanks for your response, I'm not quite sure what you mean about editing the /etc/blockcontrol/blockcontrol conf ?? Heres my log dunno if this helps....sorry for being vague but I'm still getting my head around linux, but i am loving it

p, li { white-space: pre-wrap; } Current IPv4 iptables rules (this may take a while):
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
1866 1855K ufw-before-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
1866 1855K ufw-before-input all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-after-input all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-after-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-reject-input all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-track-input all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
0 0 ufw-before-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-before-forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-after-forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-after-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-reject-forward all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 2 packets, 80 bytes)
pkts bytes target prot opt in out source destination
182 11348 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14
1754 281K ufw-before-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
1754 281K ufw-before-output all -- * * 0.0.0.0/0 0.0.0.0/0
268 18758 ufw-after-output all -- * * 0.0.0.0/0 0.0.0.0/0
268 18758 ufw-after-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
268 18758 ufw-reject-output all -- * * 0.0.0.0/0 0.0.0.0/0
268 18758 ufw-track-output all -- * * 0.0.0.0/0 0.0.0.0/0
Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92
Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92
Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
123 7808 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
15 900 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
44 2640 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92
Chain ufw-after-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-input (1 references)
pkts bytes target prot opt in out source destination
0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:137
0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:138
0 0 ufw-skip-to-policy-input tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:139
0 0 ufw-skip-to-policy-input tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:445
0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68
0 0 ufw-skip-to-policy-input all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
Chain ufw-after-logging-forward (1 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix `[UFW BLOCK] '
Chain ufw-after-logging-input (1 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix `[UFW BLOCK] '
Chain ufw-after-logging-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-forward (1 references)
pkts bytes target prot opt in out source destination
0 0 ufw-user-forward all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-before-input (1 references)
pkts bytes target prot opt in out source destination
6 300 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
1851 1852K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 ufw-logging-deny all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 4
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 11
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 12
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:67 dpt:68
9 2637 ufw-not-local all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * * 224.0.0.0/4 0.0.0.0/0
9 2637 ACCEPT all -- * * 0.0.0.0/0 224.0.0.0/4
0 0 ufw-user-input all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-before-logging-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-logging-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-logging-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-output (1 references)
pkts bytes target prot opt in out source destination
6 300 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
1480 262K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
268 18758 ufw-user-output all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-logging-allow (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix `[UFW ALLOW] '
Chain ufw-logging-deny (2 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID limit: avg 3/min burst 10
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix `[UFW BLOCK] '
Chain ufw-not-local (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type LOCAL
9 2637 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 ufw-logging-deny all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-reject-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-reject-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-reject-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-skip-to-policy-forward (0 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-skip-to-policy-input (7 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-skip-to-policy-output (0 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-track-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-track-output (1 references)
pkts bytes target prot opt in out source destination
72 4320 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW
194 14358 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW
Chain ufw-user-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-user-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-user-limit (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 0 level 4 prefix `[UFW LIMIT BLOCK] '
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain ufw-user-limit-accept (0 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-user-logging-forward (0 references)
pkts bytes target prot opt in out source destination
Chain ufw-user-logging-input (0 references)
pkts bytes target prot opt in out source destination
Chain ufw-user-logging-output (0 references)
pkts bytes target prot opt in out source destination
Chain ufw-user-output (1 references)
pkts bytes target prot opt in out source destination
Please check if the above printed iptables rules are correct!
* moblock is running
PID: 2045 CMD: /usr/bin/moblock -p /var/lib/blockcontrol/guarding.p2p -q 92 -t -r 10 -a 20 /var/log/moblock.log
* blockcontrol.wd is running
PID: 2050 CMD: /bin/sh /usr/bin/blockcontrol.wd

jre
September 21st, 2010, 08:52 PM
Just have a look here: https://help.ubuntu.com/community/MoBlock#How%20can%20I%20allow%20%28whitelist%29%20 traffic%20on%20certain%20ports?
There it is described how to whitelist the ports I were talking about. Now I suggest you do just the opposite of that: change the entry to WHITE_TCP_OUT=""
Afterwards do a "sudo blockcontrol restart" in the console.

Please have a look at my signature about the CODE tags for quoting.

jre
September 22nd, 2010, 10:25 PM
In detail this means:
type in console

gksu gedit /etc/blockcontrol/blockcontrol.conf
An editor will open ... there you add this line to the file:

WHITE_TCP_OUT=""
Save the file and quit the editor.
Then type in console

sudo blockcontrol restart
And you're done.

skipper38
September 23rd, 2010, 08:23 PM
In detail this means:
type in console

gksu gedit /etc/blockcontrol/blockcontrol.conf
An editor will open ... there you add this line to the file:

WHITE_TCP_OUT=""
Save the file and quit the editor.
Then type in console

sudo blockcontrol restart
And you're done.
Ok jre I did what you said and now I can't access internet at all.....done a couple of searches and it looks like I have to whitelist my ip range ? is this correct as you seem to be able to explain all this very well for us noobs....cheers

jre
September 30th, 2010, 04:59 PM
Been away and busy ...

What do you mean with "can't access internet at all". Can't you surf to any webpages with your webbrowser, or do all internet services (e.g. email client, chat client, weather applet), not work.

I guess it is the first problem. This is because the default blocklist setup is quite paranoid and blocks one third of the internet. You then have the following solutions:

choose less blocklists
or whitelist http again
or allow all IPs of webpages that you want to visit
or stop moblock, whenever you want to surf the internet


If it is the latter problem then please post the output of "blockcontrol show_config" and /var/log/moblock.log

ewan86
October 12th, 2010, 11:10 PM
How do I install in Maverick?

jre
October 13th, 2010, 06:00 AM
For Maverick I have only made "pgl" packages yet.
Moblock, .. packages will follow this or next week.

jre
October 15th, 2010, 05:57 PM
I just made new moblock/blockcontrol/mobloquer packages, also for Ubuntu Maverick (10.10). They are built now and will be available soon.

At the same time I dropped support for Ubuntu Jaunty (9.04)

radarman
November 6th, 2010, 08:28 AM
Hello,

Was having issues with the latest Moblock installation, wondering if anyone could help.

I'm trying to setup moblock the old way, no packet marking, just accept packet or drop/reject it. I'm trying to use moblock's nfqueue with iptables. I've had no success yet, but here is what I have so far.

My /etc/blockcontrol/blockcontrol.conf looks like this:


IPTABLES_SETTINGS="0"
NFQUEUE_NUMBER="0"
REJECT="0"
ACCEPT="0"

My iptables script looks like this:

# Flush all chains
iptables --flush

# Loopback Interface, Bridge
iptables --append INPUT --in-interface lo --jump ACCEPT
iptables --append INPUT --in-interface br0 --jump ACCEPT

# DNS
iptables --append INPUT --protocol tcp --sport 53 --match state --state ESTABLISHED --jump ACCEPT

iptables --append INPUT --protocol udp --sport 53 --match state --state ESTABLISHED --jump ACCEPT

# SSH
iptables --append INPUT --protocol tcp --dport 22

# ICMP Incoming
iptables --append INPUT --protocol icmp --match state --state ESTABLISHED --jump ACCEPT

# Default action is DROP
iptables --append INPUT --jump DROP


# Loopback Interface, Bridge
iptables --append OUTPUT --out-interface lo --jump ACCEPT
iptables --append OUTPUT --out-interface br0 --jump ACCEPT

# DNS
iptables --append OUTPUT --protocol tcp --dport 53 --match state --state NEW,ESTABLISHED --jump ACCEPT

iptables --append OUTPUT --protocol udp --dport 53 --match state --state NEW,ESTABLISHED --jump ACCEPT

# ICMP Outgoing
iptables --append OUTPUT --protocol icmp --jump ACCEPT

# Default action is moblock
iptables --append OUTPUT --jump NFQUEUE


So as you can see, any outgoing traffic that does not match a rule should be going to moblock's NFQUEUE. Unfortunately nothing seems to happen to that, and moblock's log shows no signs of activity. When I do 'blockcontrol status' it says moblock is running, and also shows an increasing number of packets going to NFQUEUE 0.

Any ideas?

jre
November 6th, 2010, 10:36 AM
Your iptables setup looks correct to me. I'd suggest to remove

iptables --append OUTPUT --protocol icmp --jump ACCEPT
and then ping an IP from the blocklist.

IPTABLES_SETTINGS should be 2 if you use blockcontrol's custom iptables insert script. Or do you do this manually?


Besides that I'd suggest to use the MARKing feature for blocked packets, so that outgoing packets are REJECTed, instead of DROPped.

BTW, I see no target in this line:

# SSH
iptables --append INPUT --protocol tcp --dport 22

radarman
November 6th, 2010, 06:46 PM
Thank you for catching that SSH line, jre :D

I tried your suggestion with ICMP, and found out that moblock would indeed work as intended for outgoing ICMP. This made me wonder why it would work for outgoing ICMP, but it wouldn't work when I launched lynx and tried to browse. Soon I realized that the problem was not handling TCP connections properly. I need to accept established TCP connections like this:


# Established TCP connections
iptables --append INPUT --protocol tcp --match state --state ESTABLISHED --jump ACCEPT


Problem solved! :D

Thank you Mr. jre for working on such useful and robust software :)

jre
November 8th, 2010, 06:09 PM
This only makes sense to me if your CHAIN policy is DROP. But still I think, that you should have seen blocks before.

Of course you need to set your ACCEPT rule for established before the NFQUEUE rule.

dougww
November 17th, 2010, 05:08 AM
I just made new moblock/blockcontrol/mobloquer packages, also for Ubuntu Maverick (10.10). They are built now and will be available soon.

At the same time I dropped support for Ubuntu Jaunty (9.04)

Is this why I can't install moblock on Jaunty? I'm using

apt-get install moblock

If so, do you have any advice on how I can get moblock or a similar program running on Jaunty? I'm a beginner so simple-ish instructions would be appreciated.

Thanks.

jre
November 17th, 2010, 11:17 AM
Is this why I can't install moblock on Jaunty?
Yes. And first off, DO NOT USE JAUNTY, because it doesn't get any more security support (not only from me, but also none from Ubuntu/Canonical itself). Don't use it any more, update to a newer Ubuntu version.

Thus having said, you can either install the hardy packages (just replace in your /etc/apt/sources.list your old entry with

deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu hardy main
deb-src http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu hardy main), or add the same entry (or any other currently working) and follow the instructions "Build your own packages" on moblock-deb.sourceforge.net

Again, please update to lucid (Long Term Support) or maverick.

dougww
November 18th, 2010, 11:24 PM
Yes. And first off, DO NOT USE JAUNTY, because it doesn't get any more security support (not only from me, but also none from Ubuntu/Canonical itself). Don't use it any more, update to a newer Ubuntu version.

Thus having said, you can either install the hardy packages (just replace in your /etc/apt/sources.list your old entry with

deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu hardy main
deb-src http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu hardy main), or add the same entry (or any other currently working) and follow the instructions "Build your own packages" on moblock-deb.sourceforge.net

Thanks so much for the quick reply. Upgrading is of course the best advice. Unfortunately, Ubuntu apparently doesn't support my architecture beyond 9.04. (I say apparently, because the only direct statements I could find are from second-hand sources: e.g., here (http://www.tonido.com/forum/viewtopic.php?p=7186#p7186) and here (https://lists.ubuntu.com/archives/ubuntu-mobile/2010-May/002729.html). Ubuntu's own docs are much less (https://help.ubuntu.com/10.10/installation-guide/powerpc/hardware-supported.html) clear (https://wiki.ubuntu.com/ARM/).) Installing the Hardy packages didn't work either.

BTW, it's not like I'm trying to scrape along with old hardware, either. I bought it brand new less than three months ago, and the company is still selling the same model (http://www.tonidoplug.com/tonido_plug.html) today. Of course, when I bought it, I didn't know (and didn't have any reasonable way of knowing) that support had been dropped.

None of this is your problem I know! Thanks for you help and if you have any more ideas, they would be appreciated.

Right now, it looks like I'll have to look into a different distro, like Arch Linux, but I'll miss the ease of use and great community support of Ubuntu.

jre
November 19th, 2010, 05:20 PM
Well, I already posted my first idea: compile your own packages. The instructions are on moblock-deb.sourceforge.net

Generally the packages do work on all distributions. The only problem is that when they are compiled they depend on some certain software versions.

So next to "hardy" you may also try the packages from "karmic".

Otherwise, please post the errors that you get when you install.

EDIT: I just had a 10 second glance at your links and saw that you are using ARM hardware. So this is another problem. The ppa never contained packages for the ARM architecture (only i386, amd64, and for some distributions lpia packages can be built). So you have to build your own packages - either directly on your hardware or by crossbuilding it from your PC.

JKarp84
January 2nd, 2011, 08:22 PM
I have completely uninstalled: Firestarter, Moblock, BlockControl, and Mobloquer... and cleaned my iptables... all with the help and commands found in this thread, I noticed one other person in this thread has the same problem as I do, yet it is with older versions of ubuntu and programs from some time ago.

heres is what Im working with

Ubuntu 10.10 Maverick



||/ Name Version Description
+++-==============-==============-============================================
ii blockcontrol 1.6.13-1~maver Manage IP blockers
ii moblock 0.9~rc2-25~mav An IP blocker for Linux
un moblock-contro <none> (no description available)
ii mobloquer 0.6+svn2009081 GUI for MoBlock, an IP blocker for Linux

Reading symbols from /usr/bin/mobloquer...(no debugging symbols found)...done.
(gdb) run
Starting program: /usr/bin/mobloquer
[Thread debugging using libthread_db enabled]
[New Thread 0xb669ab70 (LWP 5627)]
** Warning: void Mobloquer::g_SetRootPath(const QString&) Preferred file "/usr/bin/kdesudo" could not be found, using "/usr/bin/gksu" instead
terminate called after throwing an instance of 'std::bad_alloc'
what(): std::bad_alloc

Program received signal SIGABRT, Aborted.
0xb7fe1424 in __kernel_vsyscall ()
BlockControl and Moblock seem fine, but the GUI will not load up when executed.
This problem possibly originated when I checked Firestarter and a couple active connections disconnected and a wget connection was activated and out of not know what was happening I locked Firestarter. After some searching on the net for wget and moblock Ive come to the conclusion BlockControl was updating its lists and it was simply bad timing on my part to lock Firestarter. This is when Mobloquer started locking up and the uninstall and reinstall mayhem began.
Any help?

jre
January 2nd, 2011, 08:40 PM
verify that moblock/blockcontrol is running. Go to a terminal and do a "sudo blockcontrol status". You should get a bunch of lines from iptables and 2 lines saying whether moblock is running. If something is wrong, then check /var/log/blockcontrol.log. If everything is fine, then I can't think of any connection to moblock/blockcontrol/firestarter. (firestarter can mess up blockcontrol's iptables rules only temporarily. But mobloquer and firestarter do not touch in any area.)
if everything is fine, but you still have problems with mobloquer, then install "mobloquer-dev" and make a backtrace again. Perhaps we may fix mobloquer then.

JKarp84
January 2nd, 2011, 09:33 PM
* moblock is running
PID: 1487 CMD: /usr/bin/moblock -p /var/lib/blockcontrol/guarding.p2p -q 92 -t -r 10 -a 20 /var/log/moblock.log

* blockcontrol.wd is running
PID: 1494 CMD: /bin/sh /usr/bin/blockcontrol.wd

blockcontrol log

2011-01-02 15:25:07 EST Begin: blockcontrol stop
Stopping blockcontrol.wd [194G[ OK ]
Deleting iptables ...
[194G[ OK ]
Stopping moblock ... [194G[ OK ]
2011-01-02 15:25:08 EST End: blockcontrol stop
2011-01-02 15:26:03 EST Begin: blockcontrol start
Inserting iptables ...
Allowing outbound traffic to DNS server 192.168.1.1 [194G[ OK ]
Allowing forwarded traffic to DNS server 192.168.1.1 [194G[ OK ]
Allowing loopback traffic [194G[ OK ]
[194G[ OK ]
Starting moblock ... [194G[ OK ]
Starting blockcontrol.wd ... [194G[ OK ]
2011-01-02 15:26:05 EST End: blockcontrol start
Allowing outbound traffic to DNS server 192.168.1.1iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
...fail!
2011-01-02 15:31:02 EST Begin: blockcontrol restart
Stopping blockcontrol.wd ...done.
Deleting iptables ...
iptables v1.4.4: Couldn't load target `blockcontrol_in':/lib/xtables/libipt_blockcontrol_in.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables v1.4.4: Couldn't load target `blockcontrol_out':/lib/xtables/libipt_blockcontrol_out.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables v1.4.4: Couldn't load target `blockcontrol_fw':/lib/xtables/libipt_blockcontrol_fw.so: cannot open shared object file: No such file or directory

Try `iptables -h' or 'iptables --help' for more information.
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
...fail!
* Don't worry! There occured some errors during the deletion of the iptables
* rules. The most common reason for this is that they did not exist, because
* moblock was not running.
* But if moblock was running there is some problem. Most probably you have
* installed another firewall application that did delete the iptables rules.
* A "blockcontrol restart" will then fix the situation.
Stopping moblock ... ...done.
Inserting iptables ...
Allowing outbound traffic to DNS server 192.168.1.1 ...done.
Allowing forwarded traffic to DNS server 192.168.1.1 ...done.
Allowing loopback traffic ...done.
...done.
Starting moblock ... ...done.
Starting blockcontrol.wd ... ...done.
2011-01-02 15:31:03 EST End: blockcontrol restartafter all this
i checked my blockcontrol status again


* moblock is running
PID: 2565 CMD: /usr/bin/moblock -p /var/lib/blockcontrol/guarding.p2p -q 92 -t -r 10 -a 20 /var/log/moblock.log

* blockcontrol.wd is running
PID: 2572 CMD: /bin/sh /usr/bin/blockcontrol.wd
mobloquer still wont run. I am new to linux so am unsure of what to do at this point.

jre
January 2nd, 2011, 09:35 PM
You issued the start commands 2 times, therefore the errors. But nothing to worry about. moblock and blockcontrol are running correctly!

Now, step 2!

JKarp84
January 3rd, 2011, 12:28 AM
after reinstalling mobloquer I ran the debug to "backtrace"
I couldnt find modbloquer-dev so assumed you meant to uninstall modbloquer-deb and reinstall it.
here is the result

(gdb) run
Starting program: /usr/bin/mobloquer
[Thread debugging using libthread_db enabled]
[New Thread 0xb6698b70 (LWP 3597)]
** Warning: void Mobloquer::g_SetRootPath(const QString&) Preferred file "/usr/bin/kdesudo" could not be found, using "/usr/bin/gksu" instead
terminate called after throwing an instance of 'std::bad_alloc'
what(): std::bad_alloc

Program received signal SIGABRT, Aborted.
0xb7fe1424 in __kernel_vsyscall ()
(gdb)

jre
January 4th, 2011, 01:45 AM
Sorry, I can't find anything useful there.

You might get that Warning away, by changing the appropriate line in ~/.config/mobloquer/mobloquer.conf to

super_user=/usr/bin/gksu
But I doubt that is related to your problem.

My last idea is to remove the logfiles /var/log/moblock.log and blockcontrol.log and create empty ones instead. Maybe something very strange is in there.

sudo rm /var/log/moblock.log
sudo rm /var/log/blockcontrol.log
sudo touch /var/log/moblock.log
sudo touch /var/log/blockcontrol.log

JKarp84
January 4th, 2011, 02:24 AM
This worked


sudo rm /var/log/moblock.log
sudo rm /var/log/blockcontrol.log
sudo touch /var/log/moblock.log
sudo touch /var/log/blockcontrol.log


First idea didnt sound logical but I am curious now, what could possibly be in a log file that effects the program itself? very strange...

thanks for your help. cheers!

jre
January 4th, 2011, 01:53 PM
Wow, I'm surprised this worked!
mobloquer reads and parses these logfiles, so there is a way that this /can/ cause problems. But I have no idea what really caused the problem.

Next time I'll suggest to backup these files, so that we can inspect them. Do you know if they were really big (more then 10 MB)?

JKarp84
January 6th, 2011, 06:31 AM
sorry for the late response, didnt expect your interest after fixing the problem.
I am unaware of the sizes of the log files during the problem.
however, It might be possibly to recreate the incident.
if you run firestarter and lock the connections using firestarter while mobloquer is sending a "wget" command in the "events" section of firestarter, it could very well shed some light on some things.

the "wget" connection might be under active connections but im fairly certain it was under events.

the wget function could also be something completely unrelated to mobloquer, I am unsure as I hardly know what a wget connection does and if mobloquer uses it to update the blocklists, which is what i was doing at the time of the initial problem after I locked firestarter out of being "scared"... so to speak...

anyway good luck in recreating this incident. Im afraid I cant be of much more use than to try recreating the incident myself, which im not too thrilled about doing unless its something you really need me to do.

ps
Im trying to find a way to whitelist an ip address net range I need for my messenger. msn messenger uses random IPs from 64.4.0.0 - 64.4.63.255 which are associated with MS Hotmail and Im getting perturbed that I have to unblock this range on a per IP bases as they popup in mobloquer. any help with this would make my day.

jre
January 6th, 2011, 11:17 PM
Hmm, I probably won't dig deeper into this, better concentrate on developing pgl-gui. But generally I try to learn what went wrong in order to improve the code, while just knowing how to workaround a problem is only second best solution.

Anyway, blockcontrol and the corresponding daily cron job use wget to download the blocklists. So mobloquer uses wget indirectly, but might get something strange from an wget entry in blockcontrol.log.

Thx, I took your information to the BUGS file, for future reference.

JKarp84
January 7th, 2011, 08:28 PM
glad i could help

DOS286
January 9th, 2011, 03:04 AM
Is there a way to block all Internet activity except white-listed URLs?

jre
January 9th, 2011, 03:22 PM
Yes, just use a list that covers the whole (IPv4) net.

Save the follwoing line as /etc/blockcontrol/custom-blocklist.p2p

The whole internet:0.0.0.0-255.255.255.255
Then disable all other lists in /etc/blockcontrol/blocklists.list and just enable (remove the #) the following line

locallist /etc/blockcontrol/custom-blocklist.p2p

Finally apply your changes

sudo blockcontrol restart

Note 1: per default port 80 and 443 are allowed - you might to change that.

Note 2: IPv6 is not checked per default, there are no lists available. You have the option to block all IPv6. Have a look at the example files in /usr/share/doc/blockcontrol/examples/

chinaski
January 10th, 2011, 07:12 PM
hello,

I have this problem on my desktop machine (10.04 Lucid 32bit): since last night blockcontrol stopped working properly.

I start it with sudo blockcontrol start but after few seconds the status command show me this:

* moblock is not running
* blockcontrol.wd is running

system log viewer shows:

desktop kernel: [ 347.440368] moblock[2136]: segfault at bee32fe8 ip b769d821 sp bee32fec error 6 in libc-2.11.1.so[b7631000+153000]

so I see there is a problem with libc-2.11.1.so but unfortunately I do not know what to do.

shall I reinstall moblock?

I followed this tutorial to install it:

https://help.ubuntu.com/community/MoBlock

thanks :)

jre
January 10th, 2011, 07:42 PM
Please also check /var/log/moblock.log and blockcontrol.log

Since the blocklists are the only thing that change, I'd just suggest to remove all downloaded blocklists and get new ones again (the first 2 commands just make a backup, so that we might investigate further, if my theory proves true):

mkdir ~/blocklists.backup
cp -rf /var/spool/blockcontrol/* ~/blocklists.backup
sudo blockcontrol force-update

chinaski
January 10th, 2011, 09:39 PM
jre *thank you* for your fast reply

blockcontrol.log and moblock.log did not show anything unusual (I always keep them running with tail -f) but I tried the operations you suggested... and it works! :D


cris@desktop:~$ sudo blockcontrol status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 31474 packets, 40M bytes)
pkts bytes target prot opt in out source destination
4 468 blockcontrol_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 blockcontrol_fw all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 22851 packets, 2904K bytes)
pkts bytes target prot opt in out source destination
463 32368 blockcontrol_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain blockcontrol_fw (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 208.67.220.220
0 0 RETURN all -- * * 0.0.0.0/0 208.67.222.222
0 0 RETURN all -- * * 192.168.1.0/24 192.168.1.0/24
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
4 468 RETURN all -- * * 192.168.1.0/24 0.0.0.0/0
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
pkts bytes target prot opt in out source destination
69 4814 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 RETURN all -- * * 0.0.0.0/0 208.67.220.220
21 1327 RETURN all -- * * 0.0.0.0/0 208.67.222.222
2 180 RETURN all -- * * 0.0.0.0/0 192.168.1.0/24
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
7 420 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
364 25627 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* moblock is running
PID: 9042 CMD: /usr/bin/moblock -p /var/lib/blockcontrol/guarding.p2p -q 92 -t -r 10 -a 20 /var/log/moblock.log

* blockcontrol.wd is running
PID: 9048 CMD: /bin/sh /usr/bin/blockcontrol.wdso it was something in the block lists that was no good?

DOS286
January 11th, 2011, 06:56 AM
Jre,

Thank for the quick response! I have tried to put the settings just as you have said, but now it blocks nothing. I cannot figure it out. I double checked all the files but they all look correct. How can I track down where the error is to fix it?

Before, it blocked some sites, now it does not block any.

I am running Mobloquer as a front end. Could that cause problems?

I did not understand how to implement Notes 1 or 2. I could not find settings in either Mobloquer or settings files that discussed this. Could this be a problem?

Thanks again for your help so far.

jre
January 14th, 2011, 09:13 PM
Thx, and sorry, I had no time this week.


@DOS286:
You are right, seems to be a bug. Use this entry instead:

The whole internet:1.1.1.1-255.255.255.255
Further, to apply the changes you have to do a "sudo blockcontrol reload" or "update" instead. You can verify that it has been applied by checking /var/lib/blockcontrol/guarding.p2p

mobloquer should not cause any problems here.

For Note 1: Edit /etc/blockcontrol/blockcontrol.conf and remove this entry:

WHITE_TCP_OUT="http https"

For Note 2:

sudo blockcontrol stop
Create /etc/blockcontrol/iptables-custom-insert.sh with:

# Block IPv6 completely:
ip6tables -I OUTPUT -j REJECT
ip6tables -I INPUT -j DROP
ip6tables -I FORWARD -j DROP

And /etc/blockcontrol/iptables-custom-remove.sh

# Remove the rules for complete blocking of IPv6:
ip6tables -D OUTPUT -j REJECT
ip6tables -D INPUT -j DROP
ip6tables -D FORWARD -j DROP


@chinaski:
You may send me the problmatic blocklists to jre-phoenix@users.sourceforge.net
Just compress them to a file named blocklists.tar.xz:

tar cvfJ blocklists.tar.xz ~/blocklists.backup/*/downloaded/*

chinaski
January 15th, 2011, 10:59 AM
@chinaski:
You may send me the problmatic blocklistsdone ;)

thanks

edit: oops, it seems the attachment (12.3mb) is too big for your mailbox:


Delivery to the following recipient failed permanently:

jre-phoenix@users.sourceforge.net

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 552 552 Message size exceeds maximum permitted (state 18).

any suggestions? :D

jre
January 15th, 2011, 04:08 PM
Send it directly to jre.phoenix@googlemail.com
I should have thought of that in the first place. Google allows up to 25MB.

chinaski
January 16th, 2011, 01:39 AM
ok everything is on its way :)

btw no problem it's my bad I probably should have warned you before sending the email that I enable *all* lists...

DOS286
January 18th, 2011, 05:30 AM
@jre,

Thanks again. I was on vacation last week. Before you responded, I was playing around with settings and decided that I really did not need a gui and that I should switch to pgl for future support, so I did. It introduced some new questions.

1. How do I add a custom block list? pgl does not have a custom block list to enable in blocklists.list. I tried adding the line and then creating the file without success; but perhaps pgl suffers from the same bug and I should try again with 1.1.1.1 instead of 0.0.0.0? After reading the header comments in blocklists.list I tried putting custom-blocklist.p2p in /var/lib/pgl without success.

2. How do I control pgl from a user login without supperuser privileges? I want the program to limit what my kids can see and do on the internet without me there watching. I set it up under my account and thought that I could do
sudo -u me pglcmd stop when the kids are logged in to turn it off. When I do that it asks for the kids password, not mine. That's probably more of a general linux question. Sorry if it's too newbie.

Thanks for the excellent support on this.

runeh76
January 19th, 2011, 10:16 AM
Hi guys

I have problems with Mobloquer and Thunderbird or Evolution email. (Email is Gmail.)
When i log in Ubuntu and open mail, mobloquer block connection "Google Inc".

Okey then i click "Stop blocking this IP"..everything is working, BUT when i reboot, same thing and just DIFFERENT "Google Inc" IP to block.

I tried to reinstall Mobloguer and Blockcontrol (sudo apt-get purge mobloquer) (sudo apt-get purge blockcontrol) but situation was same.
I did remove Mobloguer and everything worked, but i wanna use mobloguer sometimes and get this solved.

What i miss?

runeh

edit:

Got it solved with this: gksu gedit /etc/blockcontrol/blockcontrol.conf
IP_REMOVE="Google Inc"

jre
January 23rd, 2011, 08:13 PM
1. How do I add a custom block list? pgl does not have a custom block list to enable in blocklists.list. I tried adding the line and then creating the file without success; but perhaps pgl suffers from the same bug and I should try again with 1.1.1.1 instead of 0.0.0.0? After reading the header comments in blocklists.list I tried putting custom-blocklist.p2p in /var/lib/pgl without success.
There were some problems in the old version, which I fixed some time ago but never released. So I just did that. Please update to 2.0.4 and put your custom list to /var/lib/pgl. Everything should work then (even with 0.0.0.0)



2. How do I control pgl from a user login without supperuser privileges? I want the program to limit what my kids can see and do on the internet without me there watching. I set it up under my account and thought that I could do
sudo -u me pglcmd stop when the kids are logged in to turn it off. When I do that it asks for the kids password, not mine. That's probably more of a general linux question. Sorry if it's too newbie.
pgl needs superuser rights - these you can gain with sudo.
So first the administrator has to configure sudo for the specified user to have enough rights. In your case "me" gets superuser rights with sudo, but your kids probably not. sudo always asks for the password of the user who executes it.


sudo -u me pglcmd stop will execute pglcmd with "me"'s rights, not the superuser's. Try

sudo -u me sudo pglcmd stop or

su me
sudo pglcmd stop instead.

This will allow to stop pgl from your kids login, so that your kids can do what they want.

DOS286
January 24th, 2011, 12:45 AM
@jre: Thank you, thank you! all seems to be working as desired.


sudo -u me sudo pglcmd stopwould not work for me. It still asks for my child's password, not mine. But


su me
sudo pglcmd stopworks a champ.

I think that I have only one question left. Sorry to be a pest. How can I see the IP range that was blocked in case I want to white-list it? With moblock, I could issue the "status", or "stats" command (I don't remember which now). But in pglcmd, I get different looking output, which I cannot understand.

Thanks again for all your help.

jre
January 24th, 2011, 01:07 AM
sudo -u me sudo pglcmd stopwould not work for me. It still asks for my child's password, not mine.Grin, seems to have been some stupid advice ... This would just work if your kids were granted your rights with sudo ... which wouldn't be clever ;-)


How can I see the IP range that was blocked in case I want to white-list it? With moblock, I could issue the "status", or "stats" command (I don't remember which now). But in pglcmd, I get different looking output, which I cannot understand.
Just have a look at /var/log/pgl/pgld.log, there you will find lines like these:

Jan 23 01:52:51 OUT: 192.168.178.21:55334 239.255.255.250:1900 UDP || Bogon
The columns are


date of block (Jan 23 01:52:51)
direction (OUT). Possible are outgoing OUT (websurfing, most important for whitelisting), incoming IN (you run a server that someone from the net tries to access), and forward (e.g. routed traffic)
originating IP 192.168.178.21 (this is my LAN IP)
corresponding port 55334
destination IP 239.255.255.250
corresponding port 1900
protocol UDP. Most important here is TCP
range description Bogon

So in this case you could add

239.255.255.250 to WHITE_IP_OUT
1900 to WHITE_UDP_OUT
or Bogon to IP_REMOVE
(Most probably you would choose the first one.)

You'll get stats in a similar format per Mail (daily and on every stop per default to root) or directly on "pglcmd stats".

Thanks your thumbs up! Have fun

JKarp84
February 4th, 2011, 04:54 AM
Seeing as I need a GUI to make things understandable, im using blockcontrol, moblock , and mobloquer.
Problem is Everything is installed fine, and moblock says its running when I look at mobloquer. but if I block microsoft with the microsoft list that comes with my set up by default, I am still able to go to microsoft.com.
I know its not blocking anything, I would just like to know what I should do to fix it. Ive tryed running a search on these forums, but the results for "Moblock not blocking" and "Moblock not working" dont show the results as well as I would hope and Im getting tired of sifting through the posts one page at a time for an answer.
This forum could really use a search thread feature.

jre
February 4th, 2011, 05:15 PM
You probably allowed traffic to port 80 (http) and 443 (https). Therefore websurfing is not checked at all.

You can change that in mobloquer.

To test moblock type "blockcontrol test" in a terminal.

Gavin77
March 2nd, 2011, 07:57 PM
It would be nice to have alternative sources for the blocklists as iblocklist.com is currently down so pgl, moblock etc cannot be installed as the lists fail to download.

lovinglinux
March 2nd, 2011, 09:54 PM
It would be nice to have alternative sources for the blocklists as iblocklist.com is currently down so pgl, moblock etc cannot be installed as the lists fail to download.

Any info if the downtime is temporary or permanent?

I don't use the automated blocklist download from moblock. So what I do is to untick all lists. You will be able to install moblock that way.

Gavin77
March 2nd, 2011, 10:38 PM
Any info if the downtime is temporary or permanent?

I don't use the automated blocklist download from moblock. So what I do is to untick all lists. You will be able to install moblock that way.


I did a google search and found mention of the site being under a ddos attack.

jre
March 3rd, 2011, 12:04 AM
iblocklist.com is under a ddos attack since feb 28 around 9pm. Work is done to restore the services. I'll keep you updated about that.

Meanwhile you can use alternate list entries, e.g. from bluetack.co.uk. Just add them to /etc/blockcontrol/blocklists.list

lovinglinux
March 3rd, 2011, 07:08 PM
iblocklist.com is under a ddos attack since feb 28 around 9pm. Work is done to restore the services. I'll keep you updated about that.

Meanwhile you can use alternate list entries, e.g. from bluetack.co.uk. Just add them to /etc/blockcontrol/blocklists.list

Thanks for the heads up.

Gavin77
March 3rd, 2011, 09:34 PM
The lists are available again now.
Official update from the site owner http://forums.peerblock.com/read.php?3,9886

Jerriy
April 22nd, 2011, 08:34 PM
Not sure what's going on but my moblock isn't working Jr.

Here's the result of "moblock status" details
Current IPv4 iptables rules (this may take a while):
Chain INPUT (policy ACCEPT 174 packets, 30733 bytes)
pkts bytes target prot opt in out source destination
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 212 packets, 23865 bytes)
pkts bytes target prot opt in out source destination
Please check if the above printed iptables rules are correct!
moblock is not running. ... failed!
blockcontrol.wd is not running. ... failed!

jre
April 22nd, 2011, 08:36 PM
Please check /var/log/blockcontrol.log

Jerriy
April 23rd, 2011, 07:12 AM
I got the problem: I had sweep-cleaned my "Desktop" that was full of clutter but one of the files that were there was "custom-blocklist.p2p" ](*,)

New file created and problem solved!

_T_
May 13th, 2011, 04:13 PM
First and foremost, thanks for this awesome piece of software. This is by far the best utility in it's category.

I have a quick question about how incoming packets are handled. Are they dropped or blocked? From my understanding, with blocked packets the sender is responded to and with dropped packets the sender receives nothing. In the file blockcontrol.defaults I see the section stating


# Set what happens to matched packets (IP is in the blocklist).
# 0 - DROP them directly (as in MoBlock 0.8).
# 1 - MARK them. Further iptables rules decide what happens to them. E.g. this
# allows to REJECT packets to avoid the long timeout, which occurs when
# packets are DROPped, see below. This setting is also necessary for
# iptables logging to syslog, see below.
REJECT="1"but I'm confused as to the exact meaning. Does this mean if I set REJECT="0" iptables could over-rule this setting? Just in case, here's the relevant section in my blockcontrol.defaults.


# Set how traffic is sent to the IP block daemon.
# 0 - Don't set any iptables rules.
# You or another script/firewall has to do this!
# 1 - Place the iptables rules in separate iptables chains (blockcontrol_in,
# blockcontrol_out and blockcontrol_fw). Afterwards the custom iptables
# scripts will be executed (if they exist).
# 2 - Only set custom iptables rules
# (/etc/blockcontrol/iptables-custom-insert.sh and
# /etc/blockcontrol/iptables-custom-remove.sh)
IPTABLES_SETTINGS="1"

# Activate the iptables chains?
# This section works only for IPTABLES_SETTINGS="1"
# 0 - Do nothing. You or another script/firewall has to do this!
# 1 - Send all NEW traffic to the iptables chains (blockcontrol_in,
# blockcontrol_out and blockcontrol_fw). These iptables rules are inserted
# at the head of the chains INPUT, OUTPUT and FORWARD. It is safe to only
# check NEW traffic.
# 2 - Send all traffic to the iptables chains (blockcontrol_in, blockcontrol_out
# and blockcontrol_fw). These iptables rules are inserted at the head of the
# chains INPUT, OUTPUT and FORWARD. Checking all (not only NEW) traffic
# might cause problems, because the IP block daemon has to check much more
# traffic then. Further, whitelisting gets more complicated, since you have
# to think of both directions, incoming and outgoing. Only do this, if you
# are sure that you want to.
IPTABLES_ACTIVATION="1"

# Set what happens to matched packets (IP is in the blocklist).
# 0 - DROP them directly (as in MoBlock 0.8).
# 1 - MARK them. Further iptables rules decide what happens to them. E.g. this
# allows to REJECT packets to avoid the long timeout, which occurs when
# packets are DROPped, see below. This setting is also necessary for
# iptables logging to syslog, see below.
REJECT="1"

# Set the corresponding MARK
REJECT_MARK="10"

# Set the iptables target for "marked block" packets.
# This section works only for IPTABLES_ACTIVATION="1"
# REJECT_IN is useless for the unpatched MoBlock source (0.8 and 0.9RC2), since
# there matched incoming packets are dropped directly. So the DROP rule in
# the iptables chain blockcontrol_in will never be met.
# Valid values are all iptables targets. Be careful: senseless values are also
# accepted.
# REJECT: The sender of the packet is notified that the packet was blocked.
# DROP: The sender of the packet is not notified that the packet was blocked.
REJECT_IN="DROP"
REJECT_OUT="REJECT"
REJECT_FW="DROP"

I'm asking this because this morning (via mobloquer) I noticed a non-stop flood of incoming attempts being blocked from a chinese IP address, and since I'd prefer to eliminate all chinese traffic (as it's mostly hackers and spammers) I added list.iblocklist.com/lists/cn to my blocklists. This got me to wondering if I'm actually replying (thus making myself visible) to these attempts.

jre
May 13th, 2011, 05:00 PM
Short story: everything is as you want it :-)

With REJECT="1" incoming traffic gets handled by REJECT_IN="DROP". This means traffic is dropped, and this is exactly what you want (same result as for REJECT="0").
So the chinese sender tried to connect, but didn't get any answer so he tried again.

So with your setting REJECT_IN="DROP" (the default setting) you are in "stealth mode" from the outside world (e.g. incoming traffic from China). But at the same time you actively tell your applications that you don't want to connect (REJECT_OUT="REJECT") to China, and thus avoid long waiting periods until the apps give up with a timeout.

_T_
May 14th, 2011, 02:44 PM
Excellent! Thank you very much jre.

berky
May 23rd, 2011, 05:21 AM
recently i just started getting these bogon blocks with moblock, but they aren't bogon addresses. the lists appear to block everything or almost everything. what is going on? i uninstalled and reinstalled and it does the same thing. if i stop using the bogon list, it finds it under some malware list.

jre
May 23rd, 2011, 10:14 PM
blockcontrol merges all single lists that are specified in /etc/blockcontrol/blocklists.list to one master blocklist. Overlapping and continuous IP ranges are merged to one IP range. IIRC only the description of the first range is kept for the whole new merged range. This explains why an IP is reported by its description to be part of an unrelated range.
I don't know though, why you get so many "bogon" hits. This may be normal (see above), but you may also have a look at the master blocklist /var/lib/blockcontrol/guarding.p2p to see if there are any other IP range descriptions.

You can find out the real IP range by executing

blockcontrol search $IP
Where $IP is the blocked IP. This will show you the original IP range and the blocklist where it was specified.
Since this is a very simple search function that just executes a "grep $IP" on the single blocklists it may be necessary to try a more common search term (Start it with ":" which separates the description and the IP. And just use the beginning of the IP). Repeat this until you find the matching range. E.g.

blockcontrol search :222.108.161.19
blockcontrol search :222.108.161
blockcontrol search :222.108.
I agree that this should be improved ;-)

berky
May 28th, 2011, 03:01 AM
here is what i get:

example "bogon" IP: 66.96.99.10



# blockcontrol search "\:66\.96\."
Checking your currently used blocklists for "\:66\.96\." (case-insensitive):

atma_atma (list.iblocklist.com/lists/atma/atma)
2011-05 Malware .....................:66.96.145.103-66.96.145.103
2011-04 Malware .....................:66.96.145.103-66.96.145.105
2011-05 Malware .....................:66.96.145.105-66.96.145.105
2011-05 Malware .....................:66.96.207.161-66.96.207.161
2011-05 Malware .....................:66.96.207.207-66.96.207.207
2011-05 Malware .....................:66.96.212.230-66.96.212.230
2011-05 Malware .....................:66.96.212.86-66.96.212.86
2011-03 Malware .....................:66.96.214.134-66.96.214.134
2011-03 Malware .....................:66.96.214.215-66.96.214.215
2011-04 Malware .....................:66.96.215.214-66.96.215.214
2011-04 Malware .....................:66.96.215.76-66.96.215.76
2011-05 Malware .....................:66.96.218.85-66.96.218.85
2011-05 Malware .....................:66.96.220.5-66.96.220.5
2011-05 Malware .....................:66.96.221.5-66.96.221.5
2011-05 Malware .....................:66.96.222.152-66.96.222.152
2011-05 Malware .....................:66.96.223.40-66.96.223.40
2011-05 Malware .....................:66.96.240.245-66.96.240.245
2011-03 Malware .....................:66.96.241.38-66.96.241.38
2011-05 Malware .....................:66.96.245.68-66.96.245.68
2011-05 Spammer .....................:66.96.215.214-66.96.215.214
2011-05 Spammer .....................:66.96.215.76-66.96.215.76
2011-03 Spammer .....................:66.96.248.199-66.96.248.199
2011-05 SSH Attack ..................:66.96.201.178-66.96.201.178
2011-05 SSH Attack ..................:66.96.255.69-66.96.255.69

Bluetack_badpeers (list.iblocklist.com/lists/bluetack/bad-peers)
test p2p abusers:66.96.18.9-66.96.18.9

TBG_Business_ISPs (list.iblocklist.com/lists/tbg/business-isps)
E. I. Catalyst:66.96.16.0-66.96.31.255
Equant, Inc.:66.96.32.0-66.96.63.255
HIVELOCITY VENTURES CORP:66.96.80.0-66.96.95.255
Packet Clearing House:66.96.112.0-66.96.127.255
Endurance International Group:66.96.128.0-66.96.191.255
Network Operations Center Inc:66.96.192.0-66.96.255.255

TBG_General_Corporate_Ranges (list.iblocklist.com/lists/tbg/general-corporate-ranges)
SEGUROS LA PREVISORA:66.96.56.96-66.96.56.127
Ket Partners Net Solutions:66.96.207.0-66.96.207.255
Redlight.org:66.96.208.225-66.96.208.254
Alex Beschetnov:66.96.211.192-66.96.211.207
Incyber Advertising Incorporation:66.96.212.2-66.96.212.99
ems10.your-freedom.de:66.96.216.181-66.96.216.181
interservers:66.96.231.115-66.96.231.124
Seventennet Partners:66.96.237.0-66.96.237.255
interservers:66.96.244.5-66.96.244.34
vpn4.world-secure-channel.com:66.96.249.101-66.96.249.101

TBG_Primary_Threats (list.iblocklist.com/lists/tbg/primary-threats)
Schlumberger Network Solutions:66.96.46.0-66.96.47.255
Eternity:66.96.214.135-66.96.214.149
Aspiration Hosting/anti-p2p activity:66.96.224.37-66.96.224.37
Seventennet Partners/anti-p2p activity:66.96.237.251-66.96.237.251
DediCatedNEW/anti-p2p activity:66.96.248.53-66.96.248.53
Network Operations Center/anti-p2p activity:66.96.251.26-66.96.251.32

"\:66\.96\." was found in these lists:
atma_atma (list.iblocklist.com/lists/atma/atma)
Bluetack_badpeers (list.iblocklist.com/lists/bluetack/bad-peers)
TBG_Business_ISPs (list.iblocklist.com/lists/tbg/business-isps)
TBG_General_Corporate_Ranges (list.iblocklist.com/lists/tbg/general-corporate-ranges)
TBG_Primary_Threats (list.iblocklist.com/lists/tbg/primary-threats)

If you don't want to block the above shown ranges, then you may add
"\:66\.96\." to IP_REMOVE in /etc/blockcontrol/blockcontrol.conf.
Or you may remove some of these lists from /etc/blockcontrol/blocklists.list.


This seems to mean that it's not found, but somehow it's getting blocked anyway. my assumption based on what i'm witnessing is that there is a 0.0.0.0/0 block somewhere in the mix that is auto-blocking everything. this only started recently.

Thanks.

berky
May 28th, 2011, 03:07 AM
Also, this just doesn't seem right, but I could be wrong:



<stop moblock>
# iptables -L -n
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination


<start moblock>
# iptables -L -n
Chain INPUT (policy ACCEPT)
target prot opt source destination
blockcontrol_in all -- 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT)
target prot opt source destination
blockcontrol_fw all -- 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
blockcontrol_out all -- 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain blockcontrol_fw (1 references)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 mark match 0xa
RETURN all -- 0.0.0.0/0 10.11.12.254
RETURN all -- 10.11.12.0/24 10.11.12.0/24
NFQUEUE all -- 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_in (1 references)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 mark match 0xa
RETURN all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 10.11.12.0/24 0.0.0.0/0
RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
NFQUEUE all -- 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain blockcontrol_out (1 references)
target prot opt source destination
REJECT all -- 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
RETURN all -- 0.0.0.0/0 0.0.0.0/0
RETURN all -- 0.0.0.0/0 10.11.12.254
RETURN all -- 0.0.0.0/0 10.11.12.0/24
RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
NFQUEUE all -- 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92


why is the 'reject' line in there with a 0/0 destination? doesn't iptables get populated with every subnet from all of the block lists, or am I not comprehending what moblock does?



****
EDIT
****

I disabled the following lists and everything appears to be working ok now:

atma/atma
bluetack/bogon
tbg/bogon

i'm not sure what these lists are supposed to do, but they seem to be messing everything up.

jre
May 28th, 2011, 09:46 AM
Indeed your "search" results don't explain the problem. But it may be a bigger range not matching your search pattern, in the worst case indeed even a 0.0.0.0-255.255.255.255. We'll try to add a real search function to pgld.

But it seems you found the solution on your own.

atma description:

Attackers who try to spy or remotely control others' computers by means such Microsoft remote terminal, SSH, Telnet or shared desktops.
Threats for email servers or users: spiders/bots, account hijacking, etc.
Sites spreading virus, trojans, spyware, etc. or just being used by them to let their authors know that a new computer has been infected.
Threats for servers: exploits, fake identities/agents, DDoS attackers, etc.
Port scans, which are the first step towards more dangerous actions.
Malicious P2P sharers or bad peers who spread malware, inject bad traffic or share fake archives.

TBGs bogon explanation (bluetack is very similar):
This list contains ranges from which no traffic should be appearing on the internet. These ranges are either for internal use of some sort or are address space not currently in use.

For the REJECT line: this is correct, because it also contains the "mark match 0xa". This means that it is applied to all packets that where marked by moblock to be blocked. This is essential!

Jerriy
July 30th, 2011, 06:09 PM
Hey Jre I got in trouble.

I was in Ubuntu and I did a bit of a cleanup using the standardly avalilable "Computer Janitor" ubuntu application and lo and be hold it turned out that moblock was in there. Not sure how it ended up there all of a sudden (I've been using both for the last few years without a hitch) but anyway now I'm without Moblock on my pc.

I went to your website (http://moblock-deb.sourceforge.net/) to reinstall it but it failed. I put this in
deb http://archive.ubuntu.com lucid main universeIt gets rejected :-(

Jerriy
July 30th, 2011, 06:15 PM
Failed to fetch http://archive.ubuntu.com/dists/lucid/main/binary-i386/Packages.gz 404 Not Found [IP: 91.189.88.45 80]
Failed to fetch http://archive.ubuntu.com/dists/lucid/universe/binary-i386/Packages.gz 404 Not Found [IP: 91.189.88.45 80]
Some index files failed to download, they have been ignored, or old ones used instead.

jre
July 30th, 2011, 06:59 PM
In most cases you are already fine with
sudo add-apt-repository ppa:jre-phoenix/ppa This will get you this sources.list entry:
deb http://ppa.launchpad.net/jre-phoenix/ppa/ubuntu lucid main

The line that you entered is only needed if your package manager complains about missing dependencies (libnetfilter-queue and libnfnetlink). But here you are right, I forgot /ubuntu in the instructions, so you'd need

deb http://archive.ubuntu.com/ubuntu YOURDIST main universe
But I guess this is already part of your system.

Jerriy
July 30th, 2011, 10:23 PM
Thanks jr!

Installed.

But I've one more question: when I reinstalled moblock a blue background colored setup-menu appeared within the terminal and I took the steps and installed the thing.

Now my question is: is it possible to reactivate that menu now (after install and while moblock is activated)?

jre
July 31st, 2011, 10:19 AM
Yes, just run

sudo dpkg-reconfigure blockcontrol

jre
August 14th, 2011, 12:23 AM
PeerGuardian Linux 2.1.0 - The GUI release!
Today we proudly present to you: pgl 2.1.0, including the long-anticipated pgl-gui. Try it, test it, report back. If you don't tell us otherwise the days of moblock, blockcontrol and mobloquer will soon be over.

Packages for lucid, maverick and natty are available as usual in my ppa (https://launchpad.net/~jre-phoenix/+archive/ppa). (oneiric currently fails to build, I'm on it.)

Gavin77
August 14th, 2011, 12:38 AM
Thanks a lot for the gui, I can finally stop using tail now :)

Gavin77
August 14th, 2011, 12:46 AM
Previous version of PGL automatically whitelisted ports 80 & 443 but upgrading didn't keep that setting. No big deal but someone might wonder why web pages don't work anymore :)

jre
August 14th, 2011, 12:53 AM
Thanks a lot for the gui, I can finally stop using tail now :)
hehe, you're welcome. But you can now also do a quick whitelisting (permanent or temporarily) by just right-clicking on the blocked IP or port (without "restart" as it was necessary in mobloquer). - so this really is an improvement over "tail".


Previous version of PGL automatically whitelisted ports 80 & 443 but upgrading didn't keep that setting. No big deal but someone might wonder why web pages don't work anymore :)
Thanks, you are absolutely right!
The just mentioned easy whitelisting is also the reason why there is no default port whitelisting any more. Having ports 80 and 443 whitelisted is a certain security risk, because a malicious host may listen on just these ports. I can't tell you though, whether this is paranoid. So either whitelist them again, or add (quite many) IPs to the whitelist, it is up to you.

Gavin77
August 14th, 2011, 12:55 AM
Thanks, I'd already whitelisted them using the right-click menu, very handy it is too :)

Gavin77
August 14th, 2011, 05:25 PM
Found a possible bug. If I right-click and select temporarily allow a port, it does nothing and continues to be blocked.

jre
August 14th, 2011, 07:31 PM
Please start "pgl-gui" from the console and watch its output, when you do this.
Which port did you want to whitelist? Does it happen for all ports? For all directions?
Which other ports were already whitelisted? Please post "sudo iptables -L -nv".

Background: on whitelisting pgl-gui first checks if the item is already whitelisted, probably there is a false positive.

Gavin77
August 14th, 2011, 07:53 PM
Please start "pgl-gui" from the console and watch its output, when you do this.
Which port did you want to whitelist? Does it happen for all ports? For all directions?
Which other ports were already whitelisted? Please post "sudo iptables -L -nv".

Background: on whitelisting pgl-gui first checks if the item is already whitelisted, probably there is a false positive.




pgl-gui
** Debug: gSudo: ""
** Debug: ""
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ""
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: list size: 0
** Debug: list size: 0
** Debug: true
** Debug: ******************EXECUTE COMMAND***************
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: "/usr/bin/gksudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: "/usr/bin/gksudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: ""
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ******************EXECUTE COMMAND***************
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: "/usr/bin/gksu"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: "/usr/bin/gksu"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: "OUT: 192.168.2.2:45186 94.125.182.255:6667 TCP || ATW Internet Kft. | 2011-07 Malware ....................."
** Debug: "OUT: 192.168.2.2:48529 95.141.29.22:6667 TCP || EuroTransit GmbH | 2011-07 Unspecified Threat .......... | Tor"
** Debug: "OUT: 192.168.2.2:41787 130.237.188.216:6667 TCP || 2011-07 Unspecified Threat .........."
** Debug: "OUT: 192.168.2.2:45756 194.109.20.90:6667 TCP || GTS NOVERA a.s. | servicing Tripos | State Research Library | I"
** Debug: "OUT: 192.168.2.2:45724 195.18.164.194:6667 TCP || Ventelo Norge AS | DATAMETRIX AS | Pineapple Publishing AS"
** Debug: "OUT: 192.168.2.2:49977 195.47.220.2:6667 TCP || Ten BERG IP Network"
** Debug: "OUT: 192.168.2.2:43779 208.83.20.130:6667 TCP || Desync Networksfake bittorrent trackers | LogicalSolutions.net"
** Debug: "OUT: 192.168.2.2:56768 64.18.128.86:6667 TCP || RackVibe LLC | proxy.xzibition.com | security.team.from.armed.us"
** Debug: "OUT: 192.168.2.2:44766 66.186.59.50:6667 TCP || Alchemy Communications, Inc | LIONSGATE FILMS | JuriSearch, LLC"
** Debug: "OUT: 192.168.2.2:39688 69.16.172.34:6667 TCP || Highwinds Network Group | Robbins Green, P.A. | Jarin Industri"
** Debug: "OUT: 192.168.2.2:33998 69.16.172.40:6667 TCP || Highwinds Network Group | Robbins Green, P.A. | Jarin Industri"
** Debug: "OUT: 192.168.2.2:34991 70.33.251.254:6667 TCP || InfoRelay Online Systems, Inc. | AODINC | Legal Discovery LLC"
** Debug: "OUT: 192.168.2.2:45198 94.125.182.255:6667 TCP || ATW Internet Kft. | 2011-07 Malware ....................."
** Debug: "OUT: 192.168.2.2:48541 95.141.29.22:6667 TCP || EuroTransit GmbH | 2011-07 Unspecified Threat .......... | Tor"
** Debug: "OUT: 192.168.2.2:38684 173.234.32.42:6667 TCP || Nobis Technology Group, LLC | Eisenberg, Christine | Wu, David"
** Debug: "OUT: 192.168.2.2:49987 195.47.220.2:6667 TCP || Ten BERG IP Network"
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: ("/usr/bin/kdesudo "iptables -L pgl_out -n | grep -x 'RETURN *tcp *-- *0.0.0.0/0 *0.0.0.0/0 *tcp dpt:6667 *' || iptables -I pgl_out -p tcp --dport 6667 -j RETURN"")
** Debug: start thread
** Debug: ******************EXECUTE COMMAND***************
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "iptables -L pgl_out -n | grep -x 'RETURN *tcp *-- *0.0.0.0/0 *0.0.0.0/0 *tcp dpt:6667 *' || iptables -I pgl_out -p tcp --dport 6667 -j RETURN"" () ...
** Debug: "Bad argument `|'
Try `iptables -h' or 'iptables --help' for more information."
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: "OUT: 192.168.2.2:45206 94.125.182.255:6667 TCP || ATW Internet Kft. | 2011-07 Malware ....................."
** Debug: "OUT: 192.168.2.2:48549 95.141.29.22:6667 TCP || EuroTransit GmbH | 2011-07 Unspecified Threat .......... | Tor"
** Debug: "OUT: 192.168.2.2:41807 130.237.188.216:6667 TCP || 2011-07 Unspecified Threat .........."
** Debug: "OUT: 192.168.2.2:45776 194.109.20.90:6667 TCP || GTS NOVERA a.s. | servicing Tripos | State Research Library | I"
** Debug: "OUT: 192.168.2.2:45744 195.18.164.194:6667 TCP || Ventelo Norge AS | DATAMETRIX AS | Pineapple Publishing AS"
** Debug: "OUT: 192.168.2.2:49997 195.47.220.2:6667 TCP || Ten BERG IP Network"





sudo iptables -L -nv
Chain INPUT (policy ACCEPT 66 packets, 16567 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 74 packets, 13589 bytes)
pkts bytes target prot opt in out source destination
59 3573 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 224.0.0.251-224.0.0.251
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 source IP range 224.0.0.22-224.0.0.22
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
9 573 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
22 1320 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 224.0.0.251-224.0.0.251
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 239.255.255.250-239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 destination IP range 224.0.0.22-224.0.0.22
3 180 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
25 1500 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92



The only ports I have whitelisted are 80 & 443. I was trying to temp allow 6667 so I can connect to IRC.

dino99
August 15th, 2011, 08:23 AM
Same issues here on Oneiric i386 (natty repo)

- before latest upgraded packages, all was working smoothly, now allowing the latest blocked url dont work (everything is shown as malware !!!)
- whitelisting dont work: both right-click and adding url
For example: i've tried to whitelist https://launchpadlibrarian.net
it fails both as url or port: says "invalid"

jre
August 15th, 2011, 06:07 PM
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "iptables -L pgl_out -n | grep -x 'RETURN *tcp *-- *0.0.0.0/0 *0.0.0.0/0 *tcp dpt:6667 *' || iptables -I pgl_out -p tcp --dport 6667 -j RETURN"" () ...
** Debug: "Bad argument `|'
Try `iptables -h' or 'iptables --help' for more information."


That's the rpoblem. Here exactly the same thing works. Pleasse check on your terminal:

sudo iptables -L pgl_out -n | grep -x 'RETURN *tcp *-- *0.0.0.0/0 *0.0.0.0/0 *tcp dpt:6667 *' || sudo iptables -I pgl_out -p tcp --dport 6667 -j RETURN
echo $? I guess this works.

What's your

ls -l /bin/sh

Does it work if you change /usr/bin/pglcmd first line to
#!/bin/bash

EDIT: That is probably useless, Try to change the /bin/sh link to bash (and revert it later to your current setting, so remember that. If unsure ask some Ubuntu guru.):

sudo rm /bin/sh
sudo ln -s /bin/bash /bin/sh

Which system are you on?


Same issues here on Oneiric i386 (natty repo)

- before latest upgraded packages, all was working smoothly, now allowing the latest blocked url dont work (everything is shown as malware !!!)
- whitelisting dont work: both right-click and adding url
For example: i've tried to whitelist https://launchpadlibrarian.net
it fails both as url or port: says "invalid"
Whitelisting URLs never worked! Did it? You have to use IPs instead. You may only use "service names" instead of port numbers.
I don't understand the "malware" - where is it shown?

Gavin77
August 15th, 2011, 06:42 PM
sudo iptables -L pgl_out -n | grep -x 'RETURN *tcp *-- *0.0.0.0/0 *0.0.0.0/0 *tcp dpt:6667 *' || sudo iptables -I pgl_out -p tcp --dport 6667 -j RETURN
gavin@kubuntu:~$ echo $?
0




ls -l /bin/sh
lrwxrwxrwx 1 root root 4 2011-08-06 00:55 /bin/sh -> dash


I'm on Kubuntu Natty.

DOS286
August 16th, 2011, 06:12 AM
I have several questions about the update.

1. I have been using peerguardian as a kiddie control service. It starts at system boot, blocks all internet activity except what I white list and the kids cannot change any settings with their login. I can deactivate from their account with a quick "su me" and "sudo pglcmd stop" and then turn it back on when I'm done. It worked a champ. Can I still have a similar set-up with the new version?

2. After the default install, will I need to change my settings to get it back how it was (ie., as a kiddie control system)?

I have forgotten a lot of what I did to get it setup the way I want. I want to update to the new suppa-fly gui, but don't want a week of 24-7 fiddling to get it to work the way I want. Any advice you can give would be great.

3. I noticed that in options -> settings, it lists kdesudo for the Sudo front-end. If I'm running gnome desktop, should I change this to gksudo? or keep it the same?

Thanks for the excellent program! It has worked a champ exactly as I want it to.:KS

jre
August 16th, 2011, 09:41 PM
@DOS286:
ad 1.) The way it works is generally unchanged, so yes.The GUI requires administrative rights to change settings, like pglcmd before.

ad 2.) Basically you just need to repeat your configuration steps. Relevant changes for you might be:

removed default whitelisting of ports 80 (http) and 443 (https)
place local blocklists in LOCAL_BLOCKLIST_DIR (/etc/pgl/blocklists.local) instead of MASTER_BLOCKLIST_DIR
removed debconf configuration (pgl-gui is better for this)
We got some issues reported for pgl-gui. Not major drawbacks, but generally you may wait a few days/weeks before updating. We have no official beta testers, only those which update the first day, and those who wait.

Just reuse the content of /etc/pglcmd to have a working identical pgl installation.

ad 3.) Both work, but with both ...sudo I have to retype my password everytime I need it (it doesn't remember it for e.g. 20 minutes). Therefore I use under Gnome gksu, which asks for root's password and allows to save it.

Jerriy
August 17th, 2011, 06:45 AM
Hi jre just for FMI (as opposed to FYI): do you happen to know which block list in moblock blocks Multicast addresses? Those kind of SSDP/DAAP/etc stuff that are instigaged by daemons like avahi (in my case usually triggered by media player programs that are roaming to find new local devices for supposedly "sharing" media files and stuff).

What should happen to that stuff? Should I allow or forbid media players from roaming or should I let moblocker bounce their requests (and thereby keep getting IPs like 224.0.0.251 and 239.255.255.250 appear on Moblocqer log every three or so minutes (I have the moblock supplied "bluetack/iana-multicast" disabled but they still appear on the "last blocks" log display because obviously there must be blocklists other than "iana-multicast" that are blocking Multicast IP addresses).

jre
August 18th, 2011, 05:59 PM
@Gavin77: you're still on the TODO!

@Jerriy: Probably some bogon list.
Try "blockcontrol search SEARCHTERM"
Where searchterm is the description of the blocked range from pgld.log

If you are ready to not use that lists, you will be absolutely fine with just allowing it. These ranges are just in the lists to prevent IP fakers from connecting to you. I'd just allow the ranges. Changing media players behaviour is ok of course, if you are fine with it.

Captain Easypants
August 19th, 2011, 11:09 AM
Sorry for the probably already answered question but...
just downloaded peer guardian 2.1.1 and I have no idea how to install it. Can anyone please help? I am running the latest ubuntu (11.04 natty narwal)

Gavin77
August 19th, 2011, 02:00 PM
Sorry for the probably already answered question but...
just downloaded peer guardian 2.1.1 and I have no idea how to install it. Can anyone please help? I am running the latest ubuntu (11.04 natty narwal)

https://launchpad.net/~jre-phoenix/+archive/ppa

Go to the above url and full instructions are under "Adding this PPA to your system".

Captain Easypants
August 19th, 2011, 10:33 PM
Well that was fairly simple in the end. thank you very much Gavin :)
now I just gotta figure out which blocklists are good and which are paranoia....
Also if anyone knows is there a quick option for allowing http traffic like there is on the windows version?

dino99
August 20th, 2011, 09:11 AM
Problem:
on Oneiric i386 (natty ppa) whitelist (pgl-gui) only works if "permanently" is chosen, i mean be able to unblock an url. If "temporarily" is chosen, moblock seems to do it job but the url is not unblocked, so its a fake allowing.

Request:
it should be usefull to add the url name for the allowed url (ie google.com) because xxx.xxx.xxx.xxx dont speak much some days/weeks later.

Could the pgl-gui box be more resizable (smaller) ?

jre
August 22nd, 2011, 07:55 PM
The temp-allow bug is fixed in the git repository (just wait for the upcoming 2.1.2 release).
Since it only occurs if you use kdesudo (the default) as graphical sudo frontend, you can use gksu instead as workaround for now. Note that gksu prompts for the root password, whil kdesudo prompts for the user password.


Request:
it should be usefull to add the url name for the allowed url (ie google.com) because xxx.xxx.xxx.xxx dont speak much some days/weeks later.I doubt that there is any technical solution to allow this. You'd need to do a DNS lookup for every IP. Do you know any app where this is implemented satisfyingly?
But you can still use the IP_REMOVE feature in pglcmd.conf, to remove lines containing the specified keywords.


Could the pgl-gui box be more resizable (smaller) ?Fixed in git.

jre
August 23rd, 2011, 09:37 PM
And here we are again: pgl 2.1.2

Most important it fixes the cannot-whitelist-temporarily-while-using-kdesudo bug.

The complete ChangeLog:


pgl 2.1.2

[jre]
* pgld/Makefile: moved LDFLAGS to end of rule. This should solve some
issues with newer gcc versions
* pgl-gui: swapped the restart and reload icons
* documentation updates

[freemind]
pgl-gui:
* fixed blank blocklist items, if blocklist is not from iblocklist.com
* fixed temporary allowing with right-click in the log window
kdesudo only accepts one command as argument, so execute all commands
through the tmp script.
* allow to specify the maximum log size (default 512 lines)
* reduced window's minimum width and height.
* removed unused mobloquer code
* minor fixes

If there are any issues left, that were mentioned in this thread, please remind me of them.

Gavin77
September 1st, 2011, 09:50 PM
I'm unable to install on 11.10 (Oneiric) as the files don't seem to be there due to a failed build.

https://launchpad.net/~jre-phoenix/+archive/ppa/+build/2739873

jre
September 3rd, 2011, 12:11 AM
Yes, I need to fix that. Anybody who knows what changed in oneiric?

Until then I think you can use the natty repository instead,

jre
September 5th, 2011, 10:27 PM
The oneiric build problems are solved. Just add my regular oneiric ppa to get pgl.

Gavin77
September 6th, 2011, 12:43 AM
Thanks for the updates.

Gavin77
September 18th, 2011, 01:06 PM
I just updated to pgl 2.1.3-1~oneiric and upon starting the gui I get an error message popping up several times.

jre
September 18th, 2011, 01:13 PM
Error code 6 means pglcmd is not configured correctly. So please check /var/log/pglcmd.log.
I assume you were running 2.1.2 successfully on oneiric. Did you change anything recently?

Gavin77
September 18th, 2011, 01:44 PM
It's not error code 6, there were 6 instances of the error message popping up :)
I haven't changed anything recently and the log files don't have anything relevent.

Gavin77
September 18th, 2011, 01:45 PM
Running from terminal gives:



gavin@kubuntu:~$ pgl-gui
** Debug: Graphical Sudo: ""
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: Graphical Sudo: ""
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: Connection to DBus was successful.
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: ""
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.

jre
September 18th, 2011, 01:46 PM
Ah, ok sorry.
Then please start pgl-gui from a terminal and check the output there. Beneath the error messages - does it work?

Gavin77
September 18th, 2011, 01:51 PM
I dismissed the error boxes and clicked the button to reload and it disabled itself. Clicking on start gives an error message saying starting pgl.. fail.

sudo pglcmd restart from the terminal works properly.

Gavin77
September 18th, 2011, 01:52 PM
Added info, 2.1.2 on oneiric didn't work either, I had to use the natty version.

jre
September 18th, 2011, 02:00 PM
Ok, same time posting ;-)

Is "/usr/bin/which" installed at your system?

I assume you have an empty value in "Options - Setting - Sudo frontend". Was this intended or did it happen on its own? Since when do you have this setting? Setting a valid one (e.g. /usr/bin/kdesudo or /usr/bin/gksu) in there will probably remove the error messages.

I can reproduce the popup error messages here now, but even with an empty "sudo frontend" setting my system figures out to get it automatically (so e.g. clicking "start" works then):
pgl-gui
** Debug: Graphical Sudo: ""
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: Graphical Sudo: ""
** Debug: virtual void ProcessT::run() Executing command "which kdesudo" () ...
** Debug: "/usr/bin/kdesudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: Connection to DBus was successful.
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: "/usr/bin/gksudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which gksudo" () ...
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: "/usr/bin/gksudo"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: "/usr/bin/gksu"
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which kdesu" () ...
** Debug: ""
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: virtual void ProcessT::run() Executing command "which gksu" () ...
** Debug: "/usr/bin/gksu"
** Debug: virtual void ProcessT::run() Command execution finished.
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd start"")
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd start"" () ...
** Debug: "INFO: Started."
** Debug: "Starting PeerGuardian Linux: pgld."
** Debug: virtual void ProcessT::run() Command execution finished.
** Debug: "INFO: ASCII: 210299 entries loaded from "/var/lib/pgl/master_blocklist.p2p""
** Debug: "INFO: Blocking 210299 IP ranges (2706263774 IPs)."
** Debug: "INFO: NFQUEUE: binding to queue 92"
** Debug: "INFO: ACCEPT mark: 20"
** Debug: "INFO: REJECT mark: 10"
Do you use Gnome or KDE? Or are there any other specific things to your system?

Gavin77
September 18th, 2011, 02:05 PM
Is "/usr/bin/which" installed at your system?

Yes, it is.


I assume you have an empty value in "Options - Setting - Sudo frontend". Was this intended or did it happen on its own? Since when do you have this setting? Setting a valid one (e.g. /usr/bin/kdesudo or /usr/bin/gksu) in there will probably remove the error messages.

That option is set to /usr/bin/kdesudo


Do you use Gnome or KDE? Or are there any other specific things to your system?

I use KDE, I'm not using any weird settings or anything, just default.

jre
September 18th, 2011, 02:14 PM
Does /usr/bin/kdesudo exist?
What happens if you start it with "sudo pgl-gui"?
Did you ever try the oneiric specific version 2.1.2.1-1~oneiric of 2011-09-04?
What was the problem with the oneiric version?
So 2.1.2-1~natty did work? What about 2.1.3-1~natty

Gavin77
September 18th, 2011, 02:15 PM
Can you reproduce this or is it only me?

In pgl-gui click on reload, it then disables.
Click start - error message saying failed.

Goto terminal - sudo pglcmd start - another fail message
sudo pglcmd restart - it then restarts

Gavin77
September 18th, 2011, 02:21 PM
Does /usr/bin/kdesudo exist?

Yes, it is there.

What happens if you start it with "sudo pgl-gui"?

Exactly the same problems.

Did you ever try the oneiric specific version 2.1.2.1-1~oneiric of 2011-09-04?

Yes, that didn't work for me.

What was the problem with the oneiric version?

Same problems with the gui (sorry for not reporting them then).

So 2.1.2-1~natty did work? What about 2.1.3-1~natty

Yes, the natty version worked perfectly.

I just removed 2.1.3 oneiric and installed the natty version and it works fine so it's definitely a problem with the oneiric one.

jre
September 18th, 2011, 02:29 PM
Clueless ... I thought I had solved the oneiric issues, once I got it building. So no, I can't reproduce this.

Since 2.1.3 Oneiric has the exact same source as all other packages, it is just built under a oneiric environment.

Is there any other oneiric user out there? Please report whether it works for you!

You may try to get more information with a backtrace. Start it with "gdb pgl-gui" and then type "run".

Gavin77
September 18th, 2011, 02:34 PM
gavin@kubuntu:~$ gdb pgl-gui
GNU gdb (Ubuntu/Linaro 7.3-0ubuntu2) 7.3-2011.08
Copyright (C) 2011 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
For bug reporting instructions, please see:
<http://bugs.launchpad.net/gdb-linaro/>...
Reading symbols from /usr/bin/pgl-gui...(no debugging symbols found)...done.
(gdb) run
Starting program: /usr/bin/pgl-gui
[Thread debugging using libthread_db enabled]
** Debug: Graphical Sudo: "/usr/bin/kdesudo"
[New Thread 0x7fffe8dba700 (LWP 16769)]
** Debug: Graphical Sudo: "/usr/bin/kdesudo"
** Debug: Connection to DBus was successful.
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd reload"")
[New Thread 0x7fffe1ff8700 (LWP 16775)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd reload"" () ...
** Debug: "* Reloading PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 16775) exited]
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd start"")
[New Thread 0x7fffe1ff8700 (LWP 16808)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd start"" () ...
** Debug: "* Starting PeerGuardian Linux pgld
...fail!"
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 16808) exited]
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd restart"")
[New Thread 0x7fffe1ff8700 (LWP 16827)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd restart"" () ...
** Debug: "INFO: Started."
** Debug: "* Restarting PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 16827) exited]
** Debug: "INFO: ASCII: 210337 entries loaded from "/var/lib/pgl/master_blocklist.p2p""
** Debug: "INFO: Blocking 210337 IP ranges (2706313290 IPs)."
** Debug: "INFO: NFQUEUE: binding to queue 92"
** Debug: "INFO: ACCEPT mark: 20"
** Debug: "INFO: REJECT mark: 10"
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd stop"")
[New Thread 0x7fffe1ff8700 (LWP 16991)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd stop"" () ...
** Debug: "INFO: Unbinding from nfqueue."
** Debug: "STATS: Blocked hit statistics:"
** Debug: "STATS: 0 hits total"
** Debug: "* Stopping PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 16991) exited]
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd start"")
[New Thread 0x7fffe1ff8700 (LWP 17048)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd start"" () ...
** Debug: "INFO: Started."
** Debug: "* Starting PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 17048) exited]
** Debug: "INFO: ASCII: 210337 entries loaded from "/var/lib/pgl/master_blocklist.p2p""
** Debug: "INFO: Blocking 210337 IP ranges (2706313290 IPs)."
** Debug: "INFO: NFQUEUE: binding to queue 92"
** Debug: "INFO: ACCEPT mark: 20"
** Debug: "INFO: REJECT mark: 10"
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd reload"")
[New Thread 0x7fffe1ff8700 (LWP 17169)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd reload"" () ...
** Debug: "* Reloading PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 17169) exited]
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: void SuperUser::executeCommands(QStringList, bool) Executing commands: ("/usr/bin/kdesudo "/usr/bin/pglcmd restart"")
[New Thread 0x7fffe1ff8700 (LWP 17202)]
** Debug: virtual void ProcessT::run() Executing command "/usr/bin/kdesudo "/usr/bin/pglcmd restart"" () ...
** Debug: "INFO: Started."
** Debug: "* Restarting PeerGuardian Linux pgld
...done."
** Debug: virtual void ProcessT::run() Command execution finished.
[Thread 0x7fffe1ff8700 (LWP 17202) exited]
** Debug: "INFO: ASCII: 210337 entries loaded from "/var/lib/pgl/master_blocklist.p2p""
** Debug: "INFO: Blocking 210337 IP ranges (2706313290 IPs)."
** Debug: "INFO: NFQUEUE: binding to queue 92"
** Debug: "INFO: ACCEPT mark: 20"
** Debug: "INFO: REJECT mark: 10"

Gavin77
September 18th, 2011, 02:36 PM
In the gui Start/Stop & Restart seem ok but the Reload button causes the problems.

Strangely enough, the popup error messages upon start of the gui seem to have gone away. I've closed/reopened the gui several times in a row without error.

jre
September 18th, 2011, 02:48 PM
According to your log you issued
reload
start
restart
stop
start
reload
restart
... and only the first "start" failed, but all other commands succeeded. Make sure to wait some seconds so that one command can finish.
Which version was this (dpkg -l pgl-gui)?

Gavin77
September 18th, 2011, 02:58 PM
dpkg -l pgl-gui
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Description
+++-==================-==================-================================================== ==
ii pgl-gui 2.1.3-1~oneiric PeerGuardian Linux GUI - pgl-gui


It doesn't matter how long I leave it, clicking on reload disables pgl and a following "start" will fail.

Gavin77
September 18th, 2011, 03:05 PM
I made a capture of what is happening.

http://www.youtube.com/watch?v=gyjdI6-IJOE

jre
September 18th, 2011, 03:08 PM
What happens for "pglcmd reload" on console?

Gavin77
September 18th, 2011, 03:11 PM
sudo pglcmd reload
* Reloading PeerGuardian Linux pgld [ OK ]

The gui shows it as disabled.
Maybe the gui isn't getting the message that it has reloaded and thinks it isn't running when it is?

jre
September 18th, 2011, 03:13 PM
"reload" is a no-op if pgl wasn't running before. So you have to first start it, and then "reload".
pgl-gui checks periodically if pgld is running.

Gavin77
September 18th, 2011, 03:17 PM
Yeah, pgl was running already before pressing reload.

"Reload" > terminal shows OK, GUI shows disabled

jre
September 18th, 2011, 03:42 PM
"Reload" > terminal shows OK, GUI shows disabled
Did only the command succeed or is it really running ("pglcmd status")

Gavin77
September 18th, 2011, 03:48 PM
After clicking on Reload in the gui:



sudo pglcmd status
<snip>
* pgld is not running
* pglcmd.wd is running
PID: 21217 CMD: /bin/sh /usr/sbin/pglcmd.wd

jre
September 18th, 2011, 03:51 PM
and after "pglcmd reload"?

Gavin77
September 18th, 2011, 03:51 PM
gavin@kubuntu:~$ sudo pglcmd reload
* Reloading PeerGuardian Linux pgld [ OK ]
gavin@kubuntu:~$ sudo pglcmd status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 1 packets, 105 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 1 packets, 52 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * * 0.0.0.0/0 224.0.0.251
0 0 RETURN all -- * * 0.0.0.0/0 239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 224.0.0.22
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6667
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* pgld is not running
* pglcmd.wd is running
PID: 22814 CMD: /bin/sh /usr/sbin/pglcmd.wd

gavin@kubuntu:~$ sudo pglcmd start
* Starting PeerGuardian Linux pgld [fail]
gavin@kubuntu:~$ sudo pglcmd status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 8 packets, 5717 bytes)
pkts bytes target prot opt in out source destination
1 64 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 9 packets, 2572 bytes)
pkts bytes target prot opt in out source destination
1 64 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
1 64 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
1 64 RETURN all -- * * 0.0.0.0/0 224.0.0.251
0 0 RETURN all -- * * 0.0.0.0/0 239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 224.0.0.22
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6667
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* pgld is not running
* pglcmd.wd is running
PID: 22814 CMD: /bin/sh /usr/sbin/pglcmd.wd

gavin@kubuntu:~$ sudo pglcmd restart
* Restarting PeerGuardian Linux pgld [ OK ]
gavin@kubuntu:~$ sudo pglcmd status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 6 packets, 1009 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain OUTPUT (policy ACCEPT 8 packets, 2602 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match !0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 RETURN all -- * * 0.0.0.0/0 224.0.0.251
0 0 RETURN all -- * * 0.0.0.0/0 239.255.255.250
0 0 RETURN all -- * * 0.0.0.0/0 224.0.0.22
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6667
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* pgld is running
PID: 23132 CMD: /usr/sbin/pgld -s -l /var/log/pgl/pgld.log -d -p /var/run/pgld.pid -q 92 -r 10 -a 20 /var/lib/pgl/master_blocklist.p2p

* pglcmd.wd is running
PID: 23141 CMD: /bin/sh /usr/sbin/pglcmd.wd

gavin@kubuntu:~$

Jerriy
October 11th, 2011, 05:10 PM
Hey jr I recently moved over to pgl

(...)

I have no idea what's going on but everything seems to be OK during the installation until a "configure pglcmd" menu came up and I pressed OK without changing anything and then the installation seem to abort halfway or whatever

And whatever is installed is not working (tray icon remains gray even when I press start/restart/reload/update
.

Jerriy
October 11th, 2011, 05:48 PM
Now I made a restart and get no error but a password question

Jerriy
October 11th, 2011, 06:00 PM
Oh never mind · it's working now (after reloggng and being asked a rather unfamiliar "kdesudo" dialogue appeared

I presume you have decided to make PGL some sort of "linux universal" program as opposed to the old ubutnu-spec mobloquer?

jre
October 11th, 2011, 06:29 PM
So no more problems?
I don't understand the picture in post 449.
Check your logfiles in /var/log/pgl/ to see what's going on.

I guess your initial problems were that the blocklists hadn't been downloaded yet, this may take some time.
All operations in pgl-gui require root priviledges. You can configure which graphical frontend is used to gain them (/usr/bin/kdesu or kdesudo orgksu or gksudo). Once you've given the password it will be remembered some time.

jre
October 11th, 2011, 06:33 PM
just seeing your post 551 now ... If you are running gnome you may change to /usr/bin/gksu,

moblock/blockcontrol/mobloquer always were general Linux. I'm on Debian. But we made some progress to make it easier to install on other distributions.

Jerriy
October 11th, 2011, 08:13 PM
Yes it's all working now thanks!

But I have one more question: With moblocker I used to work with the window open but at a minimum so that I have room for other windows while at the same time I can make a quick check on the status of what is "allowed"

But when I wanted to do that with PGL and open it at a minimum, then I no longer have access to all the features:


https://lh6.googleusercontent.com/-8sxsnHNSQzU/TpSRhLbxJtI/AAAAAAAAEtY/i51W5j9DW8o/Screenshot.png

Is that normal? Or is there something wrong?

I wish the "Whitelist" on the right was working (minimum of 1 line visible) just like the "Blocklists" on the left is fully functional within this "smallest" size window
.

jre
October 11th, 2011, 09:05 PM
Workaround for you, make the window a little bigger ;-)
We may increase the minimum window size to enforce this (bad idea). Or maybe save a little place in the items above. But IMO the Control tab is more important (see the log of blocked packets and do right-click-whitelisting), then the configuration tab which shouldn't be needed permanently.

Betyarka
October 28th, 2011, 11:21 AM
When i start peerblock /ubuntu 11.10/ this error send.

" p, li { white-space: pre-wrap; } Failed executing command(s). The following output was given:
""

You can also check "/var/log/pgl/pgld.log" or "/var/log/pgl/pglcmd.log" for more details.




What a problem ?

jre
October 29th, 2011, 02:11 PM
It's PeerGuardian Linux, not Peerblock.

What do you mean with "start": the automatic start of pgl daemon during boot, or the graphical pgl-gui? And what happens after you get this message - does it work anyway, or do you have any problems? Describe them.

If you have problems with the GUI, you may start it in a terminal with "pgl-gui" and check the output that you get then.

Further, you should do what you were told:


You can also check "/var/log/pgl/pgld.log" or "/var/log/pgl/pglcmd.log" for more details.

Really, if you want help, you should put some effort in your question :-/

Betyarka
October 29th, 2011, 03:09 PM
I little speak english. I am Hungary.

my pglcmd
:2011-10-27 22:15:30 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-27 22:15:30 CEST End: pglcmd stop
2011-10-28 07:26:48 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-28 07:26:48 CEST End: pglcmd stop
2011-10-28 09:35:27 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-28 09:35:27 CEST End: pglcmd stop
2011-10-28 12:02:52 CEST Begin: pglcmd reload
pgld is not running, doing nothing.
2011-10-28 12:02:52 CEST End: pglcmd reload
2011-10-28 15:05:25 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-28 15:05:25 CEST End: pglcmd stop
2011-10-28 19:13:05 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-28 19:13:05 CEST End: pglcmd stop
2011-10-29 06:31:49 CEST Begin: pglcmd update
Updating blocklists ...
Updating atma_atma... done.
Extracting atma_atma, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/atma_atma/downloaded/atma_atma

Extracting tzmtqbbsgbtfxainogvm.txt

Everything is Ok

Size: 6485753
Compressed: 506232
done.
Updating bluetack_dshield... done.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 7012
Compressed: 1714
done.
Updating bluetack_proxy... done.
Extracting bluetack_proxy, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_proxy/downloaded/bluetack_proxy

Extracting bt_proxy.txt

Everything is Ok

Size: 97578
Compressed: 17813
done.
Updating tbg_bogon... done.
Extracting tbg_bogon, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_bogon/downloaded/tbg_bogon

Extracting ewqglwibdgjttwttrinl.txt

Everything is Ok

Size: 38964
Compressed: 6061
done.
Updating tbg_business-isps... done.
Extracting tbg_business-isps, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_business-isps/downloaded/tbg_business-isps

Extracting jcjfaxgyyshvdbceroxf.txt

Everything is Ok

Size: 1675555
Compressed: 242247
done.
Updating tbg_general-corporate-ranges... done.
Extracting tbg_general-corporate-ranges, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_general-corporate-ranges/downloaded/tbg_general-corporate-ranges

Extracting ecqbsykllnadihkdirsh.txt

Everything is Ok

Size: 17744532
Compressed: 3374091
done.
Updating tbg_hijacked... done.
Extracting tbg_hijacked, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_hijacked/downloaded/tbg_hijacked

Extracting tbnuqfclfkemqivekikv.txt

Everything is Ok

Size: 14955
Compressed: 2619
done.
Updating tbg_primary-threats... done.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16296821
Compressed: 3528683
done.
Updating tbg_search-engines... done.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 56555
Compressed: 14915
done.
Blocklists updated.
pgld is not running, doing nothing.
2011-10-29 06:33:19 CEST End: pglcmd update
2011-10-29 07:21:32 CEST Begin: pglcmd stop
Stopping pglcmd.wd [ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld [ OK ]
2011-10-29 07:21:32 CEST End: pglcmd stop
2011-10-29 16:06:52 CEST Begin: pglcmd start
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 760668 entries loaded from "STDIN"
INFO: Merged 549435 of 760668 entries.
INFO: Blocking 211233 IP ranges (2781925720 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-10-29 16:06:55 CEST End: pglcmd start

jre
October 30th, 2011, 11:13 AM
/var/log/pglcmd.log seems ok, so pgl should be running and working.
The logfile should be rotated automatically every day. So I don't understand why you've got entries for several days in the same logfile. Or did you post several logfiles (like /var/log/pgl/pglcmd.log, /var/log/pgl/pglcmd.log.1, /var/log/pgl/pglcmd.log.2.gz, /var/log/pgl/pglcmd.log.3.gz, ...)?
When you post logfiles put them in code tags:

output Please edit your last post accordingly.
Now read my last post again, and give the missing answers to my questions asked there.

Betyarka
October 31st, 2011, 09:27 AM
http://www21.zippyshare.com/v/44358840/file.html
http://www21.zippyshare.com/v/33116866/file.html

Jerriy
November 23rd, 2011, 06:18 PM
I little speak english.LMAO you actor good very.


I am HungaryJre got no ham sandwich.

Jerriy
November 23rd, 2011, 06:24 PM
Jre I've got another question/new conundrum since my switch from moblock. How do I immediately end a temporary permission given to an IP or a port after I temporarily allowed it in PGL? Is it just by turning the whole PGL thing off/shutting down the program, and then back on? Or do I need to log off?

jre
November 24th, 2011, 07:54 PM
Just restart pgl.

To avoid the security risk during the restart, you may also remove the whitelisting directly:
Start pgl-gui from the terminal. Then you will see in the debug info some commands like "iptables -I pgl_out --destination SOME.IP -j RETURN" when you allow SOME.IP temporarily. Just execute the same command (with "sudo") with "-D" instead of "-I" to remove the temporary whitelisting, e.g.

sudo iptables -D pgl_out --destination SOME.IP -j RETURN

Logging out and in again won't change anything, because that is an user specifc action, while pgl acts system wide.

Post 561 was quite unnecessary, btw. Without it, I would have seen your actual question sooner in my mails.

Betyarka
November 25th, 2011, 11:47 AM
This my pgld.log



Nov 25 07:10:56 INFO: Connected to dbus system bus.
Nov 25 07:10:56 INFO: Started.
Nov 25 07:10:56 INFO: ASCII: 239367 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 07:10:56 INFO: Blocking 239367 IP ranges (2779143671 IPs).
Nov 25 07:10:56 INFO: NFQUEUE: binding to queue 92
Nov 25 07:10:56 INFO: ACCEPT mark: 20
Nov 25 07:10:56 INFO: REJECT mark: 10
Nov 25 07:11:01 OUT: 89.133.106.172:57086 209.85.148.104:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:01 OUT: 89.133.106.172:52839 209.85.148.106:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:01 OUT: 89.133.106.172:39655 209.85.148.147:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:01 OUT: 89.133.106.172:43188 209.85.148.103:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:01 OUT: 89.133.106.172:41717 209.85.148.105:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:01 OUT: 89.133.106.172:45989 209.85.148.99:80 TCP || AAA National | Norlight Telecommunications | Magnetek PCS
Nov 25 07:11:27 OUT: 89.133.106.172:57470 2.21.246.86:80 TCP || France Telecom | Akamai Technologies
Nov 25 07:11:27 OUT: 89.133.106.172:57884 2.21.246.96:80 TCP || France Telecom | Akamai Technologies
Nov 25 07:11:27 OUT: 89.133.106.172:57472 2.21.246.86:80 TCP || France Telecom | Akamai Technologies
Nov 25 07:11:27 OUT: 89.133.106.172:57886 2.21.246.96:80 TCP || France Telecom | Akamai Technologies
Nov 25 07:11:36 INFO: Unbinding from nfqueue.
Nov 25 07:11:36 STATS: Blocked hit statistics:
Nov 25 07:11:36 STATS: 2.15.0.0-2.23.255.255: France Telecom | Akamai Technologies - 4 hit(s)
Nov 25 07:11:36 STATS: 209.82.192.0-209.86.255.255: AAA National | Norlight Telecommunications | Magnetek PCS - 6 hit(s)
Nov 25 07:11:36 STATS: 10 hits total
Nov 25 07:19:16 INFO: Connected to dbus system bus.
Nov 25 07:19:16 INFO: Started.
Nov 25 07:19:17 INFO: ASCII: 266185 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 07:19:17 INFO: Blocking 266185 IP ranges (1318347224 IPs).
Nov 25 07:19:17 INFO: NFQUEUE: binding to queue 92
Nov 25 07:19:17 INFO: ACCEPT mark: 20
Nov 25 07:19:17 INFO: REJECT mark: 10
Nov 25 07:21:31 INFO: Closing logfile: /var/log/pgl/pgld.log
Nov 25 07:21:31 INFO: Reopened logfile: /var/log/pgl/pgld.log
Nov 25 07:21:31 WARN: pgld dbus is already initialized.

Nov 25 07:21:31 ERROR: Cannot initialize D-Bus
Nov 25 07:24:17 INFO: Connected to dbus system bus.
Nov 25 07:24:17 INFO: Started.
Nov 25 07:24:17 INFO: ASCII: 266185 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 07:24:17 INFO: Blocking 266185 IP ranges (1318347224 IPs).
Nov 25 07:24:17 INFO: NFQUEUE: binding to queue 92
Nov 25 07:24:17 INFO: ACCEPT mark: 20
Nov 25 07:24:17 INFO: REJECT mark: 10
Nov 25 07:28:47 INFO: Unbinding from nfqueue.
Nov 25 07:28:47 STATS: Blocked hit statistics:
Nov 25 07:28:47 STATS: 0 hits total
Nov 25 08:40:01 INFO: Connected to dbus system bus.
Nov 25 08:40:01 INFO: Started.
Nov 25 08:40:02 INFO: ASCII: 266185 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 08:40:02 INFO: Blocking 266185 IP ranges (1318347224 IPs).
Nov 25 08:40:02 INFO: NFQUEUE: binding to queue 92
Nov 25 08:40:02 INFO: ACCEPT mark: 20
Nov 25 08:40:02 INFO: REJECT mark: 10
Nov 25 08:41:31 OUT: 89.133.106.172:33468 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:31 OUT: 89.133.106.172:51147 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:31 OUT: 89.133.106.172:41940 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:31 OUT: 89.133.106.172:39916 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:33496 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:51175 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:41968 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:39944 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:33500 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:51179 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:41972 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:39948 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:40504 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:41:32 OUT: 89.133.106.172:33519 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:51198 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:41991 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:32 OUT: 89.133.106.172:39967 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:33536 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:51215 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:42008 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:39984 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:33541 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:51220 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:42013 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:39989 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:33545 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:51224 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:42017 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:39993 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:40535 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:41:39 OUT: 89.133.106.172:33552 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:51231 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:42024 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:39 OUT: 89.133.106.172:40000 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:42 OUT: 89.133.106.172:33557 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:42 OUT: 89.133.106.172:51236 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:42 OUT: 89.133.106.172:42029 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:42 OUT: 89.133.106.172:40005 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:54 OUT: 89.133.106.172:33564 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:54 OUT: 89.133.106.172:51243 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:54 OUT: 89.133.106.172:42036 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:41:54 OUT: 89.133.106.172:40012 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:22 OUT: 89.133.106.172:33571 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:22 OUT: 89.133.106.172:51250 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:22 OUT: 89.133.106.172:42043 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:22 OUT: 89.133.106.172:40019 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:33576 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:51255 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:42048 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:40024 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:33581 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:51260 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:42053 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:40029 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:40571 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:42:23 OUT: 89.133.106.172:33586 64.236.90.9:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:51265 64.236.90.72:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:42058 64.236.90.8:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:42:23 OUT: 89.133.106.172:40034 64.236.90.73:80 TCP || AOL Transit Data Network | Doubleclick
Nov 25 08:43:01 OUT: 89.133.106.172:45467 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:01 OUT: 89.133.106.172:45468 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:01 OUT: 89.133.106.172:45469 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:01 OUT: 89.133.106.172:45471 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:01 OUT: 89.133.106.172:45472 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:01 OUT: 89.133.106.172:45473 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:02 OUT: 89.133.106.172:45493 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:02 OUT: 89.133.106.172:58997 69.10.24.245:80 TCP || IGN Entertainment
Nov 25 08:43:02 OUT: 89.133.106.172:45495 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:02 OUT: 89.133.106.172:34411 66.235.156.132:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:02 OUT: 89.133.106.172:60130 66.235.156.129:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:02 OUT: 89.133.106.172:45498 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:02 OUT: 89.133.106.172:44093 69.10.25.34:80 TCP || IGN Entertainment
Nov 25 08:43:03 OUT: 89.133.106.172:45502 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:03 OUT: 89.133.106.172:45504 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:03 OUT: 89.133.106.172:45505 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:03 OUT: 89.133.106.172:45507 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:12 OUT: 89.133.106.172:45522 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:12 OUT: 89.133.106.172:55632 69.10.25.5:80 TCP || IGN Entertainment
Nov 25 08:43:12 OUT: 89.133.106.172:45524 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:12 OUT: 89.133.106.172:55636 69.10.25.5:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45528 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45530 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45531 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45532 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45537 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45538 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45539 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45540 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45541 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:15 OUT: 89.133.106.172:45542 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:17 OUT: 89.133.106.172:60184 66.235.156.129:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:17 OUT: 89.133.106.172:34467 66.235.156.132:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:17 OUT: 89.133.106.172:45553 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:17 OUT: 89.133.106.172:38328 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:17 OUT: 89.133.106.172:39433 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:18 OUT: 89.133.106.172:45557 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45563 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:40695 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:18 OUT: 89.133.106.172:45565 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:38345 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:18 OUT: 89.133.106.172:39450 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:18 OUT: 89.133.106.172:45574 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45575 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45576 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45578 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45579 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:18 OUT: 89.133.106.172:45580 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:33 OUT: 89.133.106.172:40730 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:33 OUT: 89.133.106.172:40731 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:34 OUT: 89.133.106.172:55714 69.10.25.5:80 TCP || IGN Entertainment
Nov 25 08:43:34 OUT: 89.133.106.172:55717 69.10.25.5:80 TCP || IGN Entertainment
Nov 25 08:43:34 OUT: 89.133.106.172:40744 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:34 OUT: 89.133.106.172:40745 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:43 OUT: 89.133.106.172:56793 69.10.25.14:80 TCP || IGN Entertainment
Nov 25 08:43:47 OUT: 89.133.106.172:60496 66.235.156.129:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:47 OUT: 89.133.106.172:34779 66.235.156.132:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:48 OUT: 89.133.106.172:45865 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45867 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45868 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45869 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45871 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45872 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45873 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45875 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45876 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:45877 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:48 OUT: 89.133.106.172:60512 66.235.156.129:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:48 OUT: 89.133.106.172:34795 66.235.156.132:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:43:48 OUT: 89.133.106.172:44847 63.251.28.128:80 TCP || FreeWheel Media
Nov 25 08:43:51 OUT: 89.133.106.172:45882 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:38657 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:39762 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:45887 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:45892 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:41024 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:43:52 OUT: 89.133.106.172:45894 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:38669 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:39774 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:45898 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:45899 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:45900 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:38675 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:39780 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:43:52 OUT: 89.133.106.172:45904 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:52 OUT: 89.133.106.172:45907 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:43:53 OUT: 89.133.106.172:45908 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:36 OUT: 89.133.106.172:37817 78.24.233.73:51759 TCP || SGS, a.s
Nov 25 08:44:39 IN: 92.26.72.191:23191 89.133.106.172:6881 UDP || Opal Telecom DSL | Detected AP2P on Opal Telecom
Nov 25 08:44:42 IN: 168.96.148.109:38082 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:44:42 OUT: 89.133.106.172:33896 194.151.100.129:6881 TCP || Albeda College
Nov 25 08:44:43 OUT: 89.133.106.172:44677 188.126.89.100:51545 TCP || Portlane VPN Services
Nov 25 08:44:45 OUT: 89.133.106.172:48053 92.26.72.191:19351 TCP || Opal Telecom DSL | Detected AP2P on Opal Telecom
Nov 25 08:44:45 IN: 168.96.148.109:38082 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:44:48 OUT: 89.133.106.172:60498 151.95.40.139:44331 TCP || Banca Popolare di Bergamo - Credito Varesino | Nuovo Pignone LAN
Nov 25 08:44:51 IN: 168.96.148.109:38082 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:44:53 OUT: 89.133.106.172:45938 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45939 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45940 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45941 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45943 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45944 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45945 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45947 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45948 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:45949 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:53 OUT: 89.133.106.172:60583 66.235.156.129:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:44:53 OUT: 89.133.106.172:34866 66.235.156.132:80 TCP || Omniture, Inc | Archer Communications | omniture.com
Nov 25 08:44:53 OUT: 89.133.106.172:45952 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:45954 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:45955 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:41087 66.220.156.32:80 TCP || Facebook, Inc
Nov 25 08:44:54 OUT: 89.133.106.172:45957 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:38732 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:44:54 OUT: 89.133.106.172:39837 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:44:54 OUT: 89.133.106.172:45961 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:45962 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:45963 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:54 OUT: 89.133.106.172:38738 138.108.7.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:44:54 OUT: 89.133.106.172:39843 138.108.6.20:80 TCP || SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company
Nov 25 08:44:54 IN: 194.151.100.129:58500 89.133.106.172:6881 UDP || Albeda College
Nov 25 08:44:54 OUT: 89.133.106.172:45967 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:55 OUT: 89.133.106.172:45968 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:55 OUT: 89.133.106.172:45969 69.10.24.213:80 TCP || IGN Entertainment
Nov 25 08:44:57 OUT: 89.133.106.172:48096 91.121.74.66:51413 TCP || OVH SAS | powerserv35 | adserver.ma-regie-publicitaire.com
Nov 25 08:45:03 IN: 168.96.148.109:59727 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:06 IN: 168.96.148.109:59727 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:08 IN: 78.24.233.73:9664 89.133.106.172:6881 UDP || SGS, a.s
Nov 25 08:45:12 IN: 168.96.148.109:59727 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:14 IN: 168.96.148.109:34878 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:17 IN: 168.96.148.109:34878 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:23 IN: 168.96.148.109:34878 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:34 IN: 145.53.74.202:53446 89.133.106.172:6881 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 08:45:35 IN: 168.96.148.109:60415 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:36 IN: 188.126.89.100:51545 89.133.106.172:6881 UDP || Portlane VPN Services
Nov 25 08:45:37 IN: 145.53.74.202:53519 89.133.106.172:6881 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 08:45:38 IN: 168.96.148.109:60415 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:45:43 IN: 145.53.74.202:53650 89.133.106.172:6881 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 08:45:44 IN: 168.96.148.109:60415 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:46:34 OUT: 89.133.106.172:55769 168.96.148.109:51413 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:46:36 OUT: 89.133.106.172:49563 78.24.233.73:51759 TCP || SGS, a.s
Nov 25 08:46:40 OUT: 89.133.106.172:58774 188.126.89.100:51545 TCP || Portlane VPN Services
Nov 25 08:46:54 OUT: 89.133.106.172:43076 194.151.100.129:6881 TCP || Albeda College
Nov 25 08:46:58 OUT: 89.133.106.172:38470 92.26.72.191:19351 TCP || Opal Telecom DSL | Detected AP2P on Opal Telecom
Nov 25 08:47:00 OUT: 89.133.106.172:40963 151.95.40.139:44331 TCP || Banca Popolare di Bergamo - Credito Varesino | Nuovo Pignone LAN
Nov 25 08:47:06 OUT: 89.133.106.172:44071 91.121.74.66:51413 TCP || OVH SAS | powerserv35 | adserver.ma-regie-publicitaire.com
Nov 25 08:47:07 INFO: Unbinding from nfqueue.
Nov 25 08:47:07 STATS: Blocked hit statistics:
Nov 25 08:47:07 STATS: 63.251.28.0-63.251.28.255: FreeWheel Media - 1 hit(s)
Nov 25 08:47:07 STATS: 64.236.0.0-64.236.255.255: AOL Transit Data Network | Doubleclick - 56 hit(s)
Nov 25 08:47:07 STATS: 66.220.144.0-66.220.159.255: Facebook, Inc - 10 hit(s)
Nov 25 08:47:07 STATS: 66.235.128.0-66.235.191.255: Omniture, Inc | Archer Communications | omniture.com - 10 hit(s)
Nov 25 08:47:07 STATS: 69.10.16.0-69.10.31.255: IGN Entertainment - 82 hit(s)
Nov 25 08:47:07 STATS: 78.24.232.0-78.24.239.255: SGS, a.s - 3 hit(s)
Nov 25 08:47:07 STATS: 91.121.60.43-91.121.82.124: OVH SAS | powerserv35 | adserver.ma-regie-publicitaire.com - 2 hit(s)
Nov 25 08:47:07 STATS: 92.24.0.0-92.29.255.255: Opal Telecom DSL | Detected AP2P on Opal Telecom - 3 hit(s)
Nov 25 08:47:07 STATS: 138.106.0.0-138.111.255.255: SAAB-SCANIA AB | OLYMPUS CORPORATION | A.C. Nielsen Company - 14 hit(s)
Nov 25 08:47:07 STATS: 145.0.0.0-145.191.255.255: Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl - 3 hit(s)
Nov 25 08:47:07 STATS: 151.94.0.0-151.98.255.255: Banca Popolare di Bergamo - Credito Varesino | Nuovo Pignone LAN - 2 hit(s)
Nov 25 08:47:07 STATS: 168.96.0.0-168.96.255.255: Asociacion Civil Ciencia Hoy - 13 hit(s)
Nov 25 08:47:07 STATS: 188.126.88.0-188.126.95.255: Portlane VPN Services - 3 hit(s)
Nov 25 08:47:07 STATS: 194.151.100.128-194.151.100.255: Albeda College - 3 hit(s)
Nov 25 08:47:07 STATS: 205 hits total
Nov 25 08:55:37 INFO: Connected to dbus system bus.
Nov 25 08:55:37 INFO: Started.
Nov 25 08:55:37 INFO: ASCII: 266185 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 08:55:37 INFO: Blocking 266185 IP ranges (1318347224 IPs).
Nov 25 08:55:37 INFO: NFQUEUE: binding to queue 92
Nov 25 08:55:37 INFO: ACCEPT mark: 20
Nov 25 08:55:37 INFO: REJECT mark: 10
Nov 25 08:55:55 OUT: 89.133.106.172:56855 78.24.233.73:51759 TCP || SGS, a.s
Nov 25 08:56:09 OUT: 89.133.106.172:56675 188.126.89.100:51545 TCP || Portlane VPN Services
Nov 25 08:56:21 IN: 168.96.148.109:37283 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:24 IN: 168.96.148.109:37283 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:30 IN: 168.96.148.109:37283 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:42 IN: 168.96.148.109:44560 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:45 IN: 168.96.148.109:44560 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:51 IN: 168.96.148.109:44560 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:51 IN: 168.96.148.109:52034 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:56:54 IN: 168.96.148.109:52034 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:57:00 IN: 168.96.148.109:52034 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:57:12 IN: 168.96.148.109:48943 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:57:15 IN: 168.96.148.109:48943 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:57:21 IN: 168.96.148.109:48943 89.133.106.172:6881 TCP || Asociacion Civil Ciencia Hoy
Nov 25 08:58:09 OUT: 89.133.106.172:50352 92.26.72.191:19351 TCP || Opal Telecom DSL | Detected AP2P on Opal Telecom
Nov 25 08:58:13 OUT: 89.133.106.172:49382 92.87.197.69:62364 TCP || Detected AP2P on ROMTelecom
Nov 25 08:58:24 OUT: 89.133.106.172:48151 145.53.74.202:10059 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 08:58:26 OUT: 89.133.106.172:33437 78.24.233.73:51759 TCP || SGS, a.s
Nov 25 08:58:34 OUT: 89.133.106.172:60652 91.121.74.66:51413 TCP || OVH SAS | powerserv35 | adserver.ma-regie-publicitaire.com
Nov 25 08:59:22 INFO: Unbinding from nfqueue.
Nov 25 08:59:22 STATS: Blocked hit statistics:
Nov 25 08:59:22 STATS: 78.24.232.0-78.24.239.255: SGS, a.s - 2 hit(s)
Nov 25 08:59:22 STATS: 91.121.60.43-91.121.82.124: OVH SAS | powerserv35 | adserver.ma-regie-publicitaire.com - 1 hit(s)
Nov 25 08:59:22 STATS: 92.24.0.0-92.29.255.255: Opal Telecom DSL | Detected AP2P on Opal Telecom - 1 hit(s)
Nov 25 08:59:22 STATS: 92.87.197.69-92.87.197.69: Detected AP2P on ROMTelecom - 1 hit(s)
Nov 25 08:59:22 STATS: 145.0.0.0-145.191.255.255: Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl - 1 hit(s)
Nov 25 08:59:22 STATS: 168.96.0.0-168.96.255.255: Asociacion Civil Ciencia Hoy - 12 hit(s)
Nov 25 08:59:22 STATS: 188.126.88.0-188.126.95.255: Portlane VPN Services - 1 hit(s)
Nov 25 08:59:22 STATS: 19 hits total
Nov 25 11:17:14 INFO: Connected to dbus system bus.
Nov 25 11:17:14 INFO: Started.
Nov 25 11:17:15 INFO: ASCII: 266185 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Nov 25 11:17:15 INFO: Blocking 266185 IP ranges (1318347224 IPs).
Nov 25 11:17:15 INFO: NFQUEUE: binding to queue 92
Nov 25 11:17:15 INFO: ACCEPT mark: 20
Nov 25 11:17:15 INFO: REJECT mark: 10
Nov 25 11:17:50 IN: 128.39.149.158:52507 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:18:06 IN: 128.39.149.158:52507 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:18:06 IN: 128.39.149.158:53702 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:18:09 IN: 128.39.149.158:53702 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:18:09 IN: 128.39.149.158:52507 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:18:10 OUT: 89.133.106.172:46974 145.94.225.197:30033 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 11:18:15 IN: 128.39.149.158:53702 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:19:45 IN: 128.39.149.158:52517 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:19:45 IN: 128.39.149.158:54116 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:19:48 IN: 128.39.149.158:52517 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:19:48 IN: 128.39.149.158:54116 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:19:54 IN: 128.39.149.158:54116 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:10 OUT: 89.133.106.172:60035 145.94.225.197:30033 TCP || Early registrations SURFnet bv | Grondmechanica Delft | pathe.nl
Nov 25 11:21:21 IN: 128.39.149.158:52526 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:21 IN: 128.39.149.158:54685 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:24 IN: 128.39.149.158:54685 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:24 IN: 128.39.149.158:52526 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:30 IN: 128.39.149.158:54685 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:21:41 OUT: 89.133.106.172:50964 216.238.226.23:28697 TCP || Caravela Software
Nov 25 11:25:39 IN: 128.39.149.158:52563 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:25:42 IN: 128.39.149.158:52563 89.133.106.172:6881 UDP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:26:10 IN: 128.39.149.158:55906 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:26:13 IN: 128.39.149.158:55906 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:26:19 IN: 128.39.149.158:55906 89.133.106.172:6881 TCP || SRI International | JIEO Center for Systems Engineering | USAMI
Nov 25 11:26:40 IN: 193.40.10.178:42982 89.133.106.172:6881 UDP || Estonian Educational and Research Network | Cybernetica AS
Nov 25 11:26:44 IN: 193.40.10.178:42982 89.133.106.172:6881 UDP || Estonian Educational and Research Network | Cybernetica AS
Nov 25 11:26:50 IN: 193.40.10.178:52951 89.133.106.172:6881 TCP || Estonian Educational and Research Network | Cybernetica AS
Nov 25 11:36:16 OUT: 89.133.106.172:59116 184.72.252.42:80 TCP || Detected AP2P on Amazon EC2 cloud
Nov 25 11:36:16 OUT: 89.133.106.172:49521 184.73.235.191:80 TCP || Detected AP2P on Amazon EC2 cloud
Nov 25 11:36:17 OUT: 89.133.106.172:45167 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:17 OUT: 89.133.106.172:44864 87.248.217.253:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:47222 87.248.217.254:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:45170 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:17 OUT: 89.133.106.172:44867 87.248.217.253:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:47225 87.248.217.254:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:45173 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:17 OUT: 89.133.106.172:45174 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:17 OUT: 89.133.106.172:45175 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:17 OUT: 89.133.106.172:44872 87.248.217.253:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:47230 87.248.217.254:80 TCP || Limelight Networks Inc
Nov 25 11:36:17 OUT: 89.133.106.172:53013 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:36:22 OUT: 89.133.106.172:58145 93.184.221.133:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:22 OUT: 89.133.106.172:37598 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:22 OUT: 89.133.106.172:37601 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:23 OUT: 89.133.106.172:37603 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:36:23 OUT: 89.133.106.172:53034 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:36:32 OUT: 89.133.106.172:53037 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:36:38 OUT: 89.133.106.172:53038 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:36:53 OUT: 89.133.106.172:53052 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:37:02 OUT: 89.133.106.172:53057 75.101.153.231:80 TCP || Detected AP2P on Amazon EC2 cloud | jessie2.notlong.com
Nov 25 11:37:33 OUT: 89.133.106.172:60142 208.80.184.203:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:37:33 OUT: 89.133.106.172:46182 208.80.184.202:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:37:34 OUT: 89.133.106.172:37649 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:37:34 OUT: 89.133.106.172:37650 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:37:34 OUT: 89.133.106.172:37652 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:19 OUT: 89.133.106.172:45289 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:19 OUT: 89.133.106.172:45290 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:20 OUT: 89.133.106.172:45291 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:22 OUT: 89.133.106.172:45298 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:22 OUT: 89.133.106.172:44995 87.248.217.253:80 TCP || Limelight Networks Inc
Nov 25 11:38:22 OUT: 89.133.106.172:47353 87.248.217.254:80 TCP || Limelight Networks Inc
Nov 25 11:38:22 OUT: 89.133.106.172:47354 87.248.217.254:80 TCP || Limelight Networks Inc
Nov 25 11:38:22 OUT: 89.133.106.172:45302 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:22 OUT: 89.133.106.172:45303 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:22 OUT: 89.133.106.172:45304 93.184.221.132:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:60207 208.80.184.203:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:46248 208.80.184.202:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:60211 208.80.184.203:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:46251 208.80.184.202:80 TCP || Cybernet Entertainment, LLC | Websense, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:37718 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:23 OUT: 89.133.106.172:37719 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:38:24 OUT: 89.133.106.172:37721 93.184.220.90:80 TCP || EdgeCast Networks, Inc
Nov 25 11:44:16 OUT: 89.133.106.172:59899 64.62.148.12:80 TCP || Hurricane Electric | Metamachine, Inc | New Media E.M.S | ads
Nov 25 11:44:16 OUT: 89.133.106.172:59900 64.62.148.12:80 TCP || Hurricane Electric | Metamachine, Inc | New Media E.M.S | ads
Nov 25 11:44:16 OUT: 89.133.106.172:59901 64.62.148.12:80 TCP || Hurricane Electric | Metamachine, Inc | New Media E.M.S | ads
Nov 25 11:44:16 OUT: 89.133.106.172:59902 64.62.148.12:80 TCP || Hurricane Electric | Metamachine, Inc | New Media E.M.S | ads





My pglcmd.log



2011-11-25 06:51:31 CET Begin: pglcmd stop
Stopping pglcmd.wd
[ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld
[ OK ]
2011-11-25 06:51:32 CET End: pglcmd stop
2011-11-25 07:09:36 CET Begin: pglcmd update
Updating blocklists ...
Updating atma_atma... done.
Extracting atma_atma, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/atma_atma/downloaded/atma_atma

Extracting tzmtqbbsgbtfxainogvm.txt

Everything is Ok

Size: 9471773
Compressed: 749183
done.
Updating bluetack_dshield... done.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 6994
Compressed: 1775
done.
Updating bluetack_proxy... done.
Extracting bluetack_proxy, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_proxy/downloaded/bluetack_proxy

Extracting bt_proxy.txt

Everything is Ok

Size: 100606
Compressed: 18382
done.
Updating tbg_bogon... done.
Extracting tbg_bogon, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_bogon/downloaded/tbg_bogon

Extracting ewqglwibdgjttwttrinl.txt

Everything is Ok

Size: 37260
Compressed: 5900
done.
Updating tbg_business-isps... done.
Extracting tbg_business-isps, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_business-isps/downloaded/tbg_business-isps

Extracting jcjfaxgyyshvdbceroxf.txt

Everything is Ok

Size: 1677025
Compressed: 242574
done.
Updating tbg_general-corporate-ranges... done.
Extracting tbg_general-corporate-ranges, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_general-corporate-ranges/downloaded/tbg_general-corporate-ranges

Extracting ecqbsykllnadihkdirsh.txt

Everything is Ok

Size: 17752557
Compressed: 3376424
done.
Updating tbg_hijacked... done.
Extracting tbg_hijacked, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_hijacked/downloaded/tbg_hijacked

Extracting tbnuqfclfkemqivekikv.txt

Everything is Ok

Size: 14634
Compressed: 2559
done.
Updating tbg_primary-threats... 2011-11-25 07:10:38 CET Begin: pglcmd start
Building blocklist ...
Updating tbg_primary-threats... done.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16364697
Compressed: 3539992
done.
Updating tbg_search-engines... . No update available.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16364697
Compressed: 3539992
done.
Updating tbg_search-engines... done.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 56555
Compressed: 14915
done.
Blocklists updated.
pgld is not running, doing nothing.
2011-11-25 07:10:47 CET End: pglcmd update
. No update available.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 56555
Compressed: 14915
done.
WARN: Invalid ASCII line:
INFO: ASCII: 807213 entries loaded from "STDIN"
INFO: Merged 567846 of 807213 entries.
INFO: Blocking 239367 IP ranges (2779143671 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 07:10:56 CET End: pglcmd start
2011-11-25 07:11:36 CET Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
2011-11-25 07:11:37 CET End: pglcmd stop
2011-11-25 07:15:08 CET Begin: pglcmd reload
pgld is not running, doing nothing.
2011-11-25 07:15:08 CET End: pglcmd reload
2011-11-25 07:15:44 CET Begin: pglcmd update
Automatic blocklist management disabled.
pgld is not running, doing nothing.
2011-11-25 07:15:44 CET End: pglcmd update
2011-11-25 07:16:02 CET Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Deleting iptables ...
Iptables deleted.
Stopping pgld ...done.
2011-11-25 07:16:02 CET End: pglcmd stop
2011-11-25 07:18:14 CET Begin: pglcmd reload
pgld is not running, doing nothing.
2011-11-25 07:18:14 CET End: pglcmd reload
2011-11-25 07:18:24 CET Begin: pglcmd update
Updating blocklists ...
Updating bluetack_ads-trackers-and-bad-pr0n... done.
Extracting bluetack_ads-trackers-and-bad-pr0n, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_ads-trackers-and-bad-pr0n/downloaded/bluetack_ads-trackers-and-bad-pr0n

Extracting bt_ads.txt

Everything is Ok

Size: 122411
Compressed: 36164
done.
Updating bluetack_edu... done.
Extracting bluetack_edu, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_edu/downloaded/bluetack_edu

Extracting bt_edu.txt

Everything is Ok

Size: 2766702
Compressed: 604011
done.
Updating bluetack_level1... done.
Extracting bluetack_level1, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_level1/downloaded/bluetack_level1

Extracting bt_level1.txt

Everything is Ok

Size: 12171493
Compressed: 2686191
done.
Updating bluetack_level2... done.
Extracting bluetack_level2, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_level2/downloaded/bluetack_level2

Extracting bt_level2.txt

Everything is Ok

Size: 4287519
Compressed: 999451
done.
Updating bluetack_spyware... done.
Extracting bluetack_spyware, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_spyware/downloaded/bluetack_spyware

Extracting bt_spyware.txt

Everything is Ok

Size: 147679
Compressed: 41805
done.
Blocklists updated.
pgld is not running, doing nothing.
2011-11-25 07:19:08 CET End: pglcmd update
2011-11-25 07:19:15 CET Begin: pglcmd start
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 359613 entries loaded from "STDIN"
INFO: Merged 93428 of 359613 entries.
INFO: Blocking 266185 IP ranges (1318347224 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 07:19:16 CET End: pglcmd start
2011-11-25 07:20:55 CET Begin: pglcmd update
Updating blocklists ...
Updating bluetack_ads-trackers-and-bad-pr0n... . No update available.
Extracting bluetack_ads-trackers-and-bad-pr0n, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_ads-trackers-and-bad-pr0n/downloaded/bluetack_ads-trackers-and-bad-pr0n

Extracting bt_ads.txt

Everything is Ok

Size: 122411
Compressed: 36164
done.
Updating bluetack_edu... . No update available.
Extracting bluetack_edu, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_edu/downloaded/bluetack_edu

Extracting bt_edu.txt

Everything is Ok

Size: 2766702
Compressed: 604011
done.
Updating bluetack_level1... . No update available.
Extracting bluetack_level1, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_level1/downloaded/bluetack_level1

Extracting bt_level1.txt

Everything is Ok

Size: 12171493
Compressed: 2686191
done.
Updating bluetack_level2... . No update available.
Extracting bluetack_level2, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_level2/downloaded/bluetack_level2

Extracting bt_level2.txt

Everything is Ok

Size: 4287519
Compressed: 999451
done.
Updating bluetack_spyware... . No update available.
Extracting bluetack_spyware, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_spyware/downloaded/bluetack_spyware

Extracting bt_spyware.txt

Everything is Ok

Size: 147679
Compressed: 41805
done.
Blocklists updated.
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 359613 entries loaded from "STDIN"
INFO: Merged 93428 of 359613 entries.
INFO: Blocking 266185 IP ranges (1318347224 IPs).
Blocklist built.
Reloading pgld ...done.
2011-11-25 07:21:31 CET End: pglcmd update
pglcmd.wd: pgld is not running!
The watchdog detected that the daemon is not running.
To disable the watchdog set WATCHDOG="0" in /etc/pgl/pglcmd.conf.
Now doing a restart:
* Restarting only PeerGuardian Linux pgld

2011-11-25 07:24:17 CET Begin: pglcmd restart_not_wd
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 25168: No such process
...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 07:24:17 CET End: pglcmd restart_not_wd
...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
* /var/run/pglcmd.wd.pid already exists, not starting pglcmd.wd again
2011-11-25 07:28:47 CET Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
2011-11-25 07:28:48 CET End: pglcmd stop
2011-11-25 07:36:29 CET Begin: pglcmd stop
Stopping pglcmd.wd
[ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld
[ OK ]
2011-11-25 07:36:29 CET End: pglcmd stop
2011-11-25 08:40:00 CET Begin: pglcmd start
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 08:40:01 CET End: pglcmd start
2011-11-25 08:47:07 CET Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
2011-11-25 08:47:09 CET End: pglcmd stop
2011-11-25 08:55:36 CET Begin: pglcmd start
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 08:55:37 CET End: pglcmd start
2011-11-25 08:59:22 CET Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
2011-11-25 08:59:23 CET End: pglcmd stop
2011-11-25 11:17:13 CET Begin: pglcmd start
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.53 ...done.
..Allowing OUTPUT traffic to DNS server 213.46.246.54 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.53 ...done.
..Allowing FORWARD traffic to DNS server 213.46.246.54 ...done.
..Allowing LAN traffic ...
....INPUT from 89.133.104.0/21 ...done.
....OUTPUT to 89.133.104.0/21 ...done.
....FORWARD from 89.133.104.0/21 to 89.133.104.0/21 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2011-11-25 11:17:14 CET End: pglcmd start

Jerriy
November 30th, 2011, 01:17 PM
Workaround for you, make the window a little bigger ;-)That would be a wonderful solution, but only if PGL had Moblock-GUI's superior capacity to (auto)save settings so that one doesn't have to repeat the same adjustments everytime PGL is turned on (* >> by settings I'm mainly referring to windows size and location/position on screen)
.

VcDeveloper
December 20th, 2011, 05:34 PM
Question, I upgraded from MoBlock to PeerGuardian, but I didn't completely remove MoBlock, just un-installed it.

Should it had been completely removed, because the gui looks almost the same and I get a "failed execution message" to check the log files, but I don't see any error messages.

Other than that is work perfectly! In-fact too good! Excellent work!

P.S. Is it safe to start the gui using gksu, because I have to several mods to the allow.p2p file?

VcDeveloper
December 20th, 2011, 05:55 PM
Oh Boy! I should of checked Synaptic before I did the manual install, because I already had it! Argh! How can I safely removed the manually installed pgl without messing up Synaptic pgl files? There's no enabled mark indicating its installed even though I did it manually.

VcDeveloper
December 20th, 2011, 07:07 PM
I got working now, when I used Synaptic it removed MoBlock and added its settings. One other question is can someone tell me if my setting look good and if I need to make some adjustments.


# pglcmd.conf - configuration file for pglcmd

# This file is sourced by a shell script. Any line which starts with a # (hash)
# is a comment and is ignored. If you set the same variable several times,
# then only the last line will be used.

# Refer to pglcmd.defaults (/usr/lib/pgl/pglcmd.defaults)
# for the complete set of possible configuration variables with comments.

# Do a "pglcmd restart" (sometimes even "reload" is enough) when you have
# edited this file.
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
LOG_IPTABLES="LOG --log-level info"
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_IP_IN=""
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_IP_OUT="8.23.224.121 8.23.224.255 8.23.224.120"
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_TCP_IN="22:22"
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_TCP_OUT="http https ftp"
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_UDP_IN="80:80 443:443 22:22 993:993"
# Automatically added from /etc/blockcontrol/blockcontrol.conf:
WHITE_UDP_OUT="80:80 443:443 22:22 993:993"


Thanks!...

MartijnNL
January 12th, 2012, 09:27 AM
Can pgl be run without the GUI? And if so, why is pgl-gui a dependency of pgld (in the ppa)? I'm running a torrent client on a server without GUI. Of course I could just install it, but it installs some qt dependencies as well. And I prefer to keep my server clean.

Edit: Ah, I found it. It's not a dependency but a recommend. I just have to use the --no-install-recommends option.

jre
January 12th, 2012, 07:37 PM
P.S. Is it safe to start the gui using gksu, because I have to several mods to the allow.p2p file?
You don't need that for the whole app. pgl-gui will prompt when needed for e.g. the gksu password only once per session and then remember the password for further actions that require root rights.


LOG_IPTABLES="LOG --log-level info"
With pgl this is not really necessary anymore. pgld can log to syslog on its own.

WHITE_TCP_IN="22:22"
totally ok, only your ssh daemon is not protected by MoBlock

WHITE_TCP_OUT="http https ftp"
generally ok, but e.g. an evil P2P user may just listen on these ports (instead of the standard P2P ports) and thus circumvent your protection if your P2P app connects to him. He can't connect to you unless you keep these 2 unnecessary whitelistings for IN:

WHITE_UDP_IN="80:80 443:443 22:22 993:993"
unnecessary, remove!

WHITE_UDP_OUT="80:80 443:443 22:22 993:993"
unnecessary, remove!


Can pgl be run without the GUI? And if so, why is pgl-gui a dependency of pgld (in the ppa)? I'm running a torrent client on a server without GUI. Of course I could just install it, but it installs some qt dependencies as well. And I prefer to keep my server clean.

Edit: Ah, I found it. It's not a dependency but a recommend. I just have to use the --no-install-recommends option.
Correct.

nymaar
February 9th, 2012, 04:54 PM
Dear friends,

I am starting to be really desperate about the installation. My distro is 11.10 Ocellot. I follow simple installation procedure:

sudo add-apt-repository ppa:jre-phoenix/ppa
sudo apt-get update
sudo apt-get install moblock blockcontrol mobloquer

I constantly get back errors that "E: Package 'moblock' has no installation candidate" and the same for "blockcontrol" and "mobloquer". (I dont copy / paste from Terminal because I have in my native language - Czech).

I am a total newbie in Linux so do not use "heavy guns" on me, I wouldn't understand. BUT I am not stupid so please help me with it or I will get mad (I really am trying to google it for some time now ...:)

Thanx

Gavin77
February 10th, 2012, 12:30 AM
Moblock is the old version, you should try installing pgl-gui (and it's dependencies). The Oneiric version has been broken ever since it was released but the Natty version works fine.

nymaar
February 10th, 2012, 01:56 AM
Hi! Thanx for a quick answer.

Just an adequate question following .. I tried install pgl-gui (dependancies including) from the Software Center some time ago but the result was in getting some error messages etc when launching it. I also tried this IPLIST by Uljanow with the same result and I hope I didn't spoile something with it.

So as You say the Oneric ver. is broken, You mean the pgl for Oneric OR the Oneric distro of Ubuntu is broken? :)

Also if there is some chance You could send me a link to Natty working version I would appreciate it (i don't know how to compile .deb packages though but I will try if there is no direct install link for terminal :)

The "underground" question is pointed to the pgl creators (with all respect and thanks for their hard work of course) why it is SO difficult to get some info about that. I mean if I simply want to and love to use this great app, why is it so hard to get it alive on a most recent Ubuntu system... this may be rhetoricall question and I mean it with a respect!

Thank You,

o_.

Gavin77
February 10th, 2012, 02:44 PM
When you add the repository for moblock/pgl just change the source from Oneiric to Natty.

In Muon Software Centre, goto Settings - Configure Software Sources
Under Other Software, find the jre-phoenix entry and click edit and change Oneiric to Natty.

Do this before installing pgl. If it's already installed just remove it, reload the package list and install again.

nymaar
February 10th, 2012, 05:59 PM
Oh Gavin77,

thank You much! Now it is as it is supposed to be and all working (up to now) like a charm :) Strange is that You really do not get this info so easy and especially from the official sources:) But never mind.

Anyway I thank You again!

Regards, O_.

jre
February 11th, 2012, 02:59 PM
Hi,

first off, thanks Gavin77, it's great to see that there is some community that does support.

Beginning with oneiric I only offer pgl packages. Today I already strongly recommend to use pgl on all distros, and will probably force the older distros to upgrade to pgl, too. So never install moblock.

Please tell me about the problem with the oneiric version (describe what happens when, post logfiles and the output of "pglcmd status" and "pglcmd test", ...).
The package builds fine, so I thought it was working. This is the first time I heard about that (unless I forgot it).

Generally about support: I still have to work more on replacing "moblock" with "pgl". You may help by spreading the word. E.g. https://help.ubuntu.com/community/MoBlock is freely editable, and creating a nearly identical page for pgl is not too hard. These are just little steps for you, but they will help the whole project.
You may also tell me, where you were directed to using moblock, and where you hoped to find information about pgl, but didn't find it. (Best option is always to directly update outdated information, otherwise comment on that site or contact the site owner to update the information).

Another problem is, that the old peerguardian project is dead and we basically lost our home phoenixlabs.org half a year ago. So you'll find us (or me) at peerguardian.sourceforge.net (peerguardian development).
Other ressources are moblock-deb.sourceforge.net (for Debian packages, similar to my Ubuntu ppa) and the above mentioned wiki. I strongly welcome any help with placing information on these places (preferrably by maintaining peerguardian.sourceforge.net and adding a wiki there, and redirecting there from all other places).

Did I mention I lack time?

nymaar
February 22nd, 2012, 01:49 AM
Hi jre,

for the start: I don't know if which You posted is directed to me but if so I am sorry for my late answer. I was more interested in a snb freerides lately and I was quite satisfied with the answer Gavin77 gave to me but now I will try to come back to it and kindly respond.

I will try to answer Your questions from the newbie point of view if You are interested and describe the way I took. I will presume You'll understand I am an Ubuntu (Linux) beginner and You can catch my drift.

First of all: As a Win user and a torrent lover I knew a Peerguardian. I was looking for a Linux substitution and I found this site https://help.ubuntu.com/community/MoBlock (https://help.ubuntu.com/community/MoBlock). I tried Iplist by Uljanov and found out it doesn't work as i expected or I was just not enough skilled to get it running properly on Oneric.

The site also provide some info about moblock and related packages so I tried to install it via PPA and also via Synaptics. The results were the same as I described in my first post here few posts back. The same it was with the links available throughout the "best things to do after installing Oneric" related articles ( e.g. http://debianhelp.wordpress.com/2011/07/05/installing-moblock-deb-moblock-nfblock-blockcontrol-and-mobloquer-in-ubuntu-11-04-natty-narwhal/ (http://debianhelp.wordpress.com/2011/07/05/installing-moblock-deb-moblock-nfblock-blockcontrol-and-mobloquer-in-ubuntu-11-04-natty-narwhal/)). After that I didn't give up but started to be a little desperate (I admit it might have been just some kind of "blindness" or incapability of finding something useful) and after while I found the site http://moblock-deb.sourceforge.net/index.html (THIS is the place where I really expected to find the information .. which You asked me). Even this site didn't give me much hope because I really don't find it very useful ( I know, now "linux users" will sigh and close the page but ... ) ... but Linux is fortunately starting to be more "user friendly" with all the Ubuntu distros and I think people like You have been trying to follow the stream and do things adequately "user friendly".

So "what happens when" is not my case... I couldn't simply find any working SIMPLE (please don't kill me for that) solution or a link to install properly MoBlock or PGL either via PPL or Synaptics until Gavin77 had directed me to this https://launchpad.net/~jre-phoenix/+archive/ppa/+build/2790886 (https://launchpad.net/%7Ejre-phoenix/+archive/ppa/+build/2790886) link which now works perfectly but is for Natty distro (I don't actually care but the thing is I was lucky to get a proper answer.). But anyway ... MoBlock is probably the thing I have installed now (or maybe not, I just followed Gavin77's advice and I can't recognize what is the version now:) I just know I have Mobloquer graph. interface installed which tells me "MoBlock is up and running".

I can't even give You logfiles because when I installled via PPA I got the terminal mesaages in Czech language which is my system language but it was as I wrote before: something about "Oneric has no installation candidate"...

So, sorry for my bad English and I hope I gave You some feedback. Finally I must say I admire Your work (free) very much and I hope I didn't offend You with something. Please let me know if there is something I could explain or do more.

Regards, Ondrej

Did I mention I lack the time either? :) Never mind. You do great job. I am just an user :)

uncleBez
February 28th, 2012, 06:18 AM
Not really sure how to go about this, or what information beyond what I supply here would be useful, feel free to tell me.

I'm not at the offending machine right now, so can get more info later if necessary.

However while running peerguardian on ubuntu 11.10 and while a couple of torrents are connected. After about 10 mins of having peerguardian running, browsing of websites becomes impossibly slow, if not stopped.

I have read snippets on how to determine what block file blocks what ip address etc, but that doesn't seem to be the issue here, since I was able to browse fine for around 10 mins and then not browse anything.

After stopping peerguardian usually a few seconds to a minute after stopping it browsing becomes possible again (it may be the torrents, but I stop those before stopping peerguardian).

Any tips on how one might diagnose such an issue?

Gavin77
February 28th, 2012, 02:12 PM
Assuming you have pgl-gui installed, click on the configure tab then on the right under whitelist click the green plus sign. Fill out the box like my attachment picture and you should be OK to go.

Since you're using 11.10 you might find it useful to read the previous few pages here as to why I'm using the 11.04 (Natty) version on 11.10. On Oneiric if you reload the lists it disables itself so if you have pgl running when it updates daily you'll find it istn't running afterwards.

Saying that, nobody else has confirmed or denied my problem but I've tried it on a newly installed system with the same results.

SirLafsalot
February 29th, 2012, 07:53 PM
Gavin77 said:

nobody else has confirmed or denied my problemI can confirm your problem. I run two systems, one with Ubuntu 11.10 (Oneiric) and one with Linux Mint 12, which is based upon Ubuntu 11.10 (Oneiric). Both do exactly as you describe.

Plus, whenever I open pgl-gui, I get the warning shown in the attached image.


I checked the two log files, as directed, and found the following:

From pglcmd.log:


2012-02-29 07:19:38 EST Begin: pglcmd update
Updating blocklists ...
Updating bluetack_dshield... . No update available.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) [64] 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 6927
Compressed: 1728
done.
Blocklists updated.
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 120 entries loaded from "STDIN"
INFO: Merged 10 of 120 entries.
INFO: Blocking 110 IP ranges (5220 IPs).
Blocklist built.
Reloading pgld ...done.
2012-02-29 07:19:44 EST End: pglcmd update
pglcmd.wd: pgld is not running!
The watchdog detected that the daemon is not running.
To disable the watchdog set WATCHDOG="0" in /etc/pgl/pglcmd.conf.
Now doing a restart:
* Restarting only PeerGuardian Linux pgldFrom pgld.log:


Feb 29 07:19:44 INFO: Closing logfile: /var/log/pgl/pgld.log
Feb 29 07:19:44 INFO: Reopened logfile: /var/log/pgl/pgld.log
Feb 29 07:19:44 WARN: pgld dbus is already initialized.

Feb 29 07:19:44 ERROR: Cannot initialize D-Bus
Feb 29 07:23:54 INFO: Connected to dbus system bus.
Feb 29 07:23:54 INFO: Started.
Feb 29 07:23:54 INFO: ASCII: 110 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Feb 29 07:23:54 INFO: Blocking 110 IP ranges (5220 IPs).
Feb 29 07:23:54 INFO: NFQUEUE: binding to queue 92
Feb 29 07:23:54 INFO: ACCEPT mark: 20
Feb 29 07:23:54 INFO: REJECT mark: 10This occurred after I deleted all downloaded blocklists and set pgl-gui to only load the bluetack_dshield list as a test. I originally got the warning in the attached image when I first installed pgl with the default list selection, so I went through three tests, loading only one list (as shown), two lists and three. Every time, I got the same warning in the attached image, the same "WARN: Invalid ASCII line:" error, and the log files looked very similar to what I have shown here.

I am going to remove pgl, try changing the repository to "Natty", as suggested, reinstall pgl, and see what happens. <<Time passes>> Okay, I did that and got the following from pglcmd.log (not including all of the download and extract messages):


done.
WARN: Invalid ASCII line:
INFO: ASCII: 791177 entries loaded from "STDIN"
INFO: Merged 573455 of 791177 entries.
INFO: Blocking 217722 IP ranges (2800039871 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule [ OK ]
....Whitelisting IP ranges [ OK ]
....Inserting block rule [ OK ]
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule [ OK ]
....Whitelisting IP ranges [ OK ]
....Inserting block rule [ OK ]
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule [ OK ]
....Inserting block rule [ OK ]
..Allowing loopback traffic: INPUT OUTPUT [ OK ]
..Allowing OUTPUT traffic to DNS server 192.168.1.1 [ OK ]
..Allowing FORWARD traffic to DNS server 192.168.1.1 [ OK ]
..Allowing LAN traffic ...
....INPUT from 192.168.1.0/24 [ OK ]
....OUTPUT to 192.168.1.0/24 [ OK ]
....FORWARD from 192.168.1.0/24 to 192.168.1.0/24 [ OK ]
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld [ OK ]
Starting pglcmd.wd [ OK ]
2012-02-29 13:12:39 EST End: pglcmd startAnd this from pgld.log:


Feb 29 13:12:39 INFO: Connected to dbus system bus.
Feb 29 13:12:39 INFO: Started.
Feb 29 13:12:39 INFO: ASCII: 217722 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Feb 29 13:12:39 INFO: Blocking 217722 IP ranges (2800039871 IPs).
Feb 29 13:12:39 INFO: NFQUEUE: binding to queue 92
Feb 29 13:12:39 INFO: ACCEPT mark: 20
Feb 29 13:12:39 INFO: REJECT mark: 10As you can see, I still got the "WARN: Invalid ASCII line:" in the log file during the installation. When I opened pgl-gui, I again got the warning in the attached image. So far, I have tried an Update, a Reload, and a Restart, all of which worked without disabling pgl. But, I did get the following log entry in pglcmd.log:


2012-02-29 13:20:20 EST Begin: pglcmd restart
Stopping pglcmd.wd ...done.
Emailing stats ...done.
Deleting iptables ...
Please install an MTA on this system if you want to use sendmail!
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 192.168.1.1 ...done.
..Allowing FORWARD traffic to DNS server 192.168.1.1 ...done.
..Allowing LAN traffic ...
....INPUT from 192.168.1.0/24 ...done.
....OUTPUT to 192.168.1.0/24 ...done.
....FORWARD from 192.168.1.0/24 to 192.168.1.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-02-29 13:20:21 EST End: pglcmd restartNo, I do not have an MTA installed (that I know of), which is new to the log entry here, but did show up during my original tests of loading one, two and three of the blocklists.

I apologize if anyone objects to this very long message. I cannot make heads or tails out of what is going on, but figured I would post all of this in case it might help someone else to figure it out. Cheers!

masuch
March 1st, 2012, 09:31 PM
Hi,

I have a problem to start pgld on oneiric - part of pglcmd.log:
...
WARN: Invalid ASCII line:
...
Whitelisting portsiptables v1.4.10: invalid port/service `ssl' specified
...

Could you please help me what should i setup for port/service ssl ?
thank you,
kind regards,
M.

Gavin77
March 2nd, 2012, 02:29 AM
I just installed Kubuntu Precise (12.04) Beta 1 and PGL has the exact same problem as on Oneiric, it disables itself after an update/reload. I'm again using the Natty PGL without any problem.

Gavin77
March 2nd, 2012, 02:31 AM
Hi,

I have a problem to start pgld on oneiric - part of pglcmd.log:
...
WARN: Invalid ASCII line:
...
Whitelisting portsiptables v1.4.10: invalid port/service `ssl' specified
...

Could you please help me what should i setup for port/service ssl ?
thank you,
kind regards,
M.

You need to whitelist port 443.

masuch
March 2nd, 2012, 04:58 PM
You need to whitelist port 443.


This is what I do not know what I am doing wrong ?
I have had in pglcmd.conf file:
WHITE_TCP_OUT="http https ftp ssl ssh"
So, I thought that ssl is allowed but after pgld restart I have got the error message which I reported.

What did I miss/mess ?

Thank you for any clue.
M.

P.S. By removing ssl from config make it works but it is not probably the right solution.

masuch
March 2nd, 2012, 05:00 PM
I just installed Kubuntu Precise (12.04) Beta 1 and PGL has the exact same problem as on Oneiric, it disables itself after an update/reload. I'm again using the Natty PGL without any problem.

I have got the same error message when I removed and install natty version. So I am back in oneiric version for now.

Gavin77
March 2nd, 2012, 05:41 PM
Remove ssl from your whitelist, you have https there already.

If you need a list of valid port numbers try https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

masuch
March 2nd, 2012, 09:06 PM
Remove ssl from your whitelist, you have https there already.

If you need a list of valid port numbers try https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers


Thanks to confirm.
That was exactly what was bothering me - https was/is already there so why ssl ? I thought that ssl has some special (different to https) meaning ?

I have a another question if you can please help me:
I put to pglcmd.conf following:
WHITE_TCP_IN="80 443 22 5900"
My idea is to let some services to be accessible to my local network.
web server port 80 , web server with ssl port 443,
ssh/sshfs port 22 , vncviewer port 5900

is this all what I have to do to let its be accessible on local network or do I need to do some more configurations ?

Thannks for help,
Regards,
M.

Gavin77
March 2nd, 2012, 11:19 PM
Sorry, I don't know as I'm not an expert on these things.
Hopefully jre can help if he's still around.

uncleBez
March 3rd, 2012, 11:53 AM
Assuming you have pgl-gui installed, click on the configure tab then on the right under whitelist click the green plus sign. Fill out the box like my attachment picture and you should be OK to go.


Thanks Gavin77 for your resonse.

I have port 80 and 443 whitelisted for outgoing, witht the gui showing the same configuration as your screenshot. Which is exactly why I am
stumped as to why my browsing fails around 5 to 10 minutes after activating pgl. I find the 5 - 10 min lag rather odd.. To me, if the ip and or port is blocked, then it's blocked.. it should fail straight away.
???



Saying that, nobody else has confirmed or denied my problem but I've tried it on a newly installed system with the same results.

I've been starting it manually anyway, so that shouldn't be an issue for me.. should it?

uncleBez
March 3rd, 2012, 12:05 PM
I'm trying out the natty version. Worth a shot. Thanks for the tip.

masuch
March 3rd, 2012, 03:01 PM
Hi,

I am using i2p for long time.
After have installed peerguradian from ubuntu oneric repository I could not figure out how to configure pglcmd.conf for i2p ?

I have two problems:

1. Configure UDP ports for Tor:
I did the following:
WHITE_UDP_OUT="123 26719"
WHITE_UDP_IN="123 26719"

i2p has following config:
i2np.udp.port=26719

2. configure opera browser to use i2p proxy 4444.
WHITE_TCP_OUT="http https 4444"


Could anybody please help what am I missing/doing wrong ?

Thank you very much for any help,
Kind Regards,
M.

masuch
March 6th, 2012, 12:49 PM
Hi,

I am using i2p for long time.
After have installed peerguradian from ubuntu oneric repository I could not figure out how to configure pglcmd.conf for i2p ?

I have two problems:

1. Configure UDP ports for Tor:
I did the following:
WHITE_UDP_OUT="123 26719"
WHITE_UDP_IN="123 26719"

i2p has following config:
i2np.udp.port=26719

2. configure opera browser to use i2p proxy 4444.
WHITE_TCP_OUT="http https 4444"


Could anybody please help what am I missing/doing wrong ?

Thank you very much for any help,
Kind Regards,
M.

solved by opened additional udp in/out ports according to i2p port manual

masuch
March 6th, 2012, 12:53 PM
Thanks to confirm.
That was exactly what was bothering me - https was/is already there so why ssl ? I thought that ssl has some special (different to https) meaning ?

I have a another question if you can please help me:
I put to pglcmd.conf following:
WHITE_TCP_IN="80 443 22 5900"
My idea is to let some services to be accessible to my local network.
web server port 80 , web server with ssl port 443,
ssh/sshfs port 22 , vncviewer port 5900

is this all what I have to do to let its be accessible on local network or do I need to do some more configurations ?

Thannks for help,
Regards,
M.

solved by putting them into
WHITE_IP_IN and WHITE_IP_OUT

masuch
March 6th, 2012, 12:56 PM
Hi,

I did not figure out how to allow outgoing ICMP messages ?
I did not find command in documentation like:
WHITE_ICMP_OUT="ip address ranges"
Could anybody please help how to manage it ?

thank you,
regards,
M.

kosajaffe
March 23rd, 2012, 07:50 PM
Is it a good or a bad idea to white list 127.0.1.1 in pgl? Does this make my system vulnerable or not? I was trying to connect to a compilation daemon on my system which was being blocked by pgl. Got "Connection Refused" error... Now I can use the daemon but I'm not sure if white-listing was a good idea...

jre
March 30th, 2012, 07:51 PM
First off, seems I didn't have a look at this forum here for quite a time - sorry. And special thanks to Gavin77 for helping here!
After much work (real life) in the past weeks, I'll be in holidays most time of April. Prepare to see me again in May.

As some may have noticed, phoenixlabs.org doesn't exist any more. But pgl is still developed by me (jre-I-have-real-life-time-constraints), other old and new developers. Everyone who wants to contribute can contact me and can commit to the git repository at peerguardian.sourceforge.net. This way, I am sure that we keep pgl alive.

We will probably make a release before my holidays:
- fixing the "empty" warning on startup
- containing a new build system. If we are lucky this will fix the oneiric/precise problems. Please give me immediate feedback then, otherwise I will disable these dists to force everybody to use the working natty binaries (thanks again Gavin77).

jre
March 30th, 2012, 07:51 PM
Is it a good or a bad idea to white list 127.0.1.1 in pgl? Does this make my system vulnerable or not? I was trying to connect to a compilation daemon on my system which was being blocked by pgl. Got "Connection Refused" error... Now I can use the daemon but I'm not sure if white-listing was a good idea...

No problem, just do that.

jre
March 30th, 2012, 07:56 PM
Hi,

I did not figure out how to allow outgoing ICMP messages ?
I did not find command in documentation like:
WHITE_ICMP_OUT="ip address ranges"
Could anybody please help how to manage it ?

thank you,
regards,
M.

Add a file /etc/pgl/iptables-custom-insert.sh with lines like this

iptables -I pgl_out -p icmp -d 123.123.123.123 -j RETURN
This example allows outgoing icmp packets to the IP 123.123.123.123

To apply the change do a "pglcmd restart" or a "sudo iptables ..."

jre
March 30th, 2012, 08:04 PM
I have port 80 and 443 whitelisted for outgoing, witht the gui showing the same configuration as your screenshot. Which is exactly why I am stumped as to why my browsing fails around 5 to 10 minutes after activating pgl. I find the 5 - 10 min lag rather odd.. To me, if the ip and or port is blocked, then it's blocked.. it should fail straight away.
???
Correct. For me it sounds as if pgld is acting too slow and the buffer is filling up. For a similar problem the following commands in the terminal to increase the default receive/send window did help:

sysctl -w net.core.rmem_default=8388608
sysctl -w net.core.wmem_default=8388608

I've been starting it manually anyway, so that shouldn't be an issue for me.. should it?[/QUOTE]
No, shouldn't make any difference.



EDIT: Err, sorry if I missed something you already posted. Does this also happen after you restarted pgl? Perhaps you are just hit pgld crashed (the oneiric/precise) problem. Then traffic is sent to nirvana, until pgld gets restarted by pglcmd.wd.

jre
March 30th, 2012, 08:12 PM
Thanks to confirm.
That was exactly what was bothering me - https was/is already there so why ssl ? I thought that ssl has some special (different to https) meaning ?

I have a another question if you can please help me:
I put to pglcmd.conf following:
WHITE_TCP_IN="80 443 22 5900"
My idea is to let some services to be accessible to my local network.
web server port 80 , web server with ssl port 443,
ssh/sshfs port 22 , vncviewer port 5900

is this all what I have to do to let its be accessible on local network or do I need to do some more configurations ?
Depends on the services that you are running on your machine and want to be available on the net. But If you want them to be accessible on your local network only, I recommend to use IP whitelisting instead of prot whitelisting (port whitelisting opens that port for everybody, so it is a security risk).
Your whole LAN should already be whitelisted automatically, if not add it either to /etc/pgl/allow.p2p

My LAN:192.168.0.0-192.168.0.255
or to /etc/pgl/pglcmd.conf

WHITE_IP_IN="192.168.0.0/24"
(Above is an example, you have to use your real IPs of course. Check the IP after "inet" of your network interface (e.g. wlan0) in the output of "inet addr" to learn your IPs.

jre
March 30th, 2012, 08:20 PM
Plus, whenever I open pgl-gui, I get the warning shown in the attached image.
This will probably be fixed in the next releasse. That should happen if on your system "which" is not installed.


Every time, I got the same warning in the attached image, the same "WARN: Invalid ASCII line:" error, and the log files looked very similar to what I have shown here.
Don't worry about that (TM), just a malformed line in the blocklist which was detected by pgl.


No, I do not have an MTA installed (that I know of), which is new to the log entry here, but did show up during my original tests of loading one, two and three of the blocklists.
Doesn't matter, that's just to send statistics and error reports. If you don't have a MTA installed you can disable all this reporting by setting in /etc/pgl/pglcmd.conf

CRON_MAILTO=""
STATS_MAILTO=""
WD_MAILTO=""

jre
March 30th, 2012, 08:30 PM
So, that's for me catching up with all unanswered posts. If there are questions open, please ask again.

The current main problem seems to be the non-working binaries from oneiric/precise, which cause pgld to crash on every reload (which happens e.g. after the automatic daily blocklist update). The pglcmd.wd fixes this after maximum 5 minutes. Check the mails that are sent to root (unless you configured something else), if you want to know if you are hit by this bug, you will see mails with a subject "pglcmd.wd restarted pgld" next to the daily "Results of pglcmd blocklist update".
I have (at least a little) hope that the new build system (already in the git repository at sourceforge) fixes this, if not use the natty packages.

father_ted
April 3rd, 2012, 05:30 PM
linux gui says i have 4294967295 ip adresses blocked - which seems a bit harsh


Apr 3 17:28:32 INFO: Connected to dbus system bus.
Apr 3 17:28:32 INFO: Started.
Apr 3 17:28:32 INFO: ASCII: 1 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Apr 3 17:28:32 INFO: Blocking 1 IP ranges (4294967295 IPs).
Apr 3 17:28:32 INFO: NFQUEUE: binding to queue 92
Apr 3 17:28:32 INFO: ACCEPT mark: 20
Apr 3 17:28:32 INFO: REJECT mark: 10


tried reloading and updating lists. no joy.

father_ted
April 3rd, 2012, 05:42 PM
stopped pgld
removed spamhaus drop list.
update lists
restart

it seems blocking the entire Internet stopped the update process. updating with shields down worked.

all is well again.

David006
May 15th, 2012, 02:33 AM
.. If there are questions open, please ask again.

The current main problem seems to be the non-working binaries from oneiric/precise, which cause pgld to crash on every reload ..

Just to clarify ..

Should I just use Natty version on 11.10 (Oneiric) or 12.04 LTS (Precise)?

jre
May 15th, 2012, 10:31 PM
I have no reports for 12.04 (Precise), yet. So probably try the precise packages first and check the first few days the /var/log/pgl/pglcmd.log and your local mail to root for entries from the watchdog (pglcmd.wd). If there aren't any you are fine, but if you see something you should try the natty version.

For 11.10 (Oneiric) you should use the natty version. But verifying it works (like above) would be good anyway.

I hope the issue is fixed in the upcoming 2.1.4. There are some changes which might be related.

Gavin77
May 15th, 2012, 10:46 PM
I have no reports for 12.04 (Precise), yet.


I thought I'd already posted that it was the same on Precise as on Oneiric, it still turns itself off. I'm still using the Natty version without problem.

jre
May 18th, 2012, 08:02 PM
You are right, i forgot that over my holidays ;-)

So allOneiric and Precise users should use the natty sources.list entry until the next update (2.2.0)

masuch
June 2nd, 2012, 05:16 PM
Could you please help me to configure tor ?
what should I supposed to configure and how ?

(does exist something like
iptables -I pgl_out -p tcp -m tor -j RETURN
:-)) ?

thank you,
kind regards,
M.

jre
June 11th, 2012, 11:10 PM
@all: I uploaded a preview of the upcoming release last weekend. It should/may fix all known issues, hopefully also the issues with oneiric/precise. Please note that there is no release for natty yet.

@masuch: I'm not familiar with tor in detail. But I doubt that there is an module for iptables. Perhaps there is a port that you could whitelist. Instead I guess you should use this list (http://www.iblocklist.com/list.php?list=tor) as an allow list in pgl (ask if you don't know how to configure that).

Gavin77
June 12th, 2012, 12:40 AM
Unfortunately I still can't get it to work.
PeerGuardian Linux 2.2.0~pre23

After starting pgl as normal:


gavin@kubuntu:~$ sudo pglcmd status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 127.0.0.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 127.0.0.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* pgld is running
PID: 32378 CMD: /usr/sbin/pgld -s -l /var/log/pgl/pgld.log -d -p /var/run/pgld.pid -q 92 -r 10 -a 20 /var/lib/pgl/master_blocklist.p2p

* pglcmd.wd is running
PID: 32385 CMD: /bin/sh /usr/sbin/pglcmd.wd



After clicking on Reload in pglgui:


gavin@kubuntu:~$ sudo pglcmd status
Current IPv4 iptables rules (this may take a while):

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_in all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_fwd all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 pgl_out all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW mark match ! 0x14

Chain pgl_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 127.0.0.1
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_in (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 192.168.2.0/24 0.0.0.0/0
0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Chain pgl_out (1 references)
pkts bytes target prot opt in out source destination
0 0 RETURN all -- * * 0.0.0.0/0 192.168.2.0/24
0 0 RETURN all -- * * 0.0.0.0/0 127.0.0.1
0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0xa reject-with icmp-port-unreachable
0 0 NFQUEUE all -- * * 0.0.0.0/0 0.0.0.0/0 NFQUEUE num 92

Please check if the above printed iptables rules are correct!

* pgld is not running
* pglcmd.wd is running
PID: 32385 CMD: /bin/sh /usr/sbin/pglcmd.wd



And then clicking on Start in the gui I get the following popup (image attached).


Contents of pglcmd.log


2012-06-11 01:45:17 BST Begin: pglcmd update
Updating blocklists ...
Updating atma_atma... . No update available.
Extracting atma_atma, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/atma_atma/downloaded/atma_atma

Extracting tzmtqbbsgbtfxainogvm.txt

Everything is Ok

Size: 10273329
Compressed: 740830
done.
Updating bluetack_dshield... . No update available.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 6979
Compressed: 1781
done.
Updating bluetack_proxy... . No update available.
Extracting bluetack_proxy, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_proxy/downloaded/bluetack_proxy

Extracting bt_proxy.txt

Everything is Ok

Size: 108756
Compressed: 19798
done.
Updating tbg_bogon... . No update available.
Extracting tbg_bogon, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_bogon/downloaded/tbg_bogon

Extracting ewqglwibdgjttwttrinl.txt

Everything is Ok

Size: 34716
Compressed: 5771
done.
Updating tbg_business-isps... . No update available.
Extracting tbg_business-isps, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_business-isps/downloaded/tbg_business-isps

Extracting jcjfaxgyyshvdbceroxf.txt

Everything is Ok

Size: 1882357
Compressed: 263981
done.
Updating tbg_general-corporate-ranges... . No update available.
Extracting tbg_general-corporate-ranges, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_general-corporate-ranges/downloaded/tbg_general-corporate-ranges

Extracting ecqbsykllnadihkdirsh.txt

Everything is Ok

Size: 18116930
Compressed: 3435142
done.
Updating tbg_hijacked... . No update available.
Extracting tbg_hijacked, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_hijacked/downloaded/tbg_hijacked

Extracting tbnuqfclfkemqivekikv.txt

Everything is Ok

Size: 13719
Compressed: 2427
done.
Updating tbg_primary-threats... . No update available.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16719416
Compressed: 3603635
done.
Updating tbg_search-engines... . No update available.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 58218
Compressed: 15311
done.
Blocklists updated.
pgld is not running, doing nothing.
2012-06-11 01:46:22 BST End: pglcmd update
2012-06-11 04:16:45 BST Begin: pglcmd stop
Stopping pglcmd.wd * Stopping PeerGuardian Linux pgld
[%i%p1%dG[ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld ...done.
2012-06-11 04:16:45 BST End: pglcmd stop
2012-06-12 00:11:30 BST Begin: pglcmd stop
Stopping pglcmd.wd[ OK ]
Deleting iptables ...
Iptables deleted.
Stopping pgld[ OK ]
2012-06-12 00:11:30 BST End: pglcmd stop
2012-06-12 00:13:33 BST Begin: pglcmd start
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 837324 entries loaded from "STDIN"
INFO: Merged 596142 of 837324 entries.
INFO: Blocking 241182 IP ranges (2771731784 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IPs ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 192.168.2.0/24 ...done.
....OUTPUT to 192.168.2.0/24 ...done.
....FORWARD from 192.168.2.0/24 to 192.168.2.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-06-12 00:13:36 BST End: pglcmd start
2012-06-12 00:13:41 BST Begin: pglcmd update
Updating blocklists ...
Updating atma_atma... . No update available.
Extracting atma_atma, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/atma_atma/downloaded/atma_atma

Extracting tzmtqbbsgbtfxainogvm.txt

Everything is Ok

Size: 10273329
Compressed: 740830
done.
Updating bluetack_dshield... done.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 6950
Compressed: 1737
done.
Updating bluetack_proxy... done.
Extracting bluetack_proxy, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_proxy/downloaded/bluetack_proxy

Extracting bt_proxy.txt

Everything is Ok

Size: 113918
Compressed: 20109
done.
Updating tbg_bogon... . No update available.
Extracting tbg_bogon, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_bogon/downloaded/tbg_bogon

Extracting ewqglwibdgjttwttrinl.txt

Everything is Ok

Size: 34716
Compressed: 5771
done.
Updating tbg_business-isps... done.
Extracting tbg_business-isps, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_business-isps/downloaded/tbg_business-isps

Extracting jcjfaxgyyshvdbceroxf.txt

Everything is Ok

Size: 1882488
Compressed: 263872
done.
Updating tbg_general-corporate-ranges... done.
Extracting tbg_general-corporate-ranges, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_general-corporate-ranges/downloaded/tbg_general-corporate-ranges

Extracting ecqbsykllnadihkdirsh.txt

Everything is Ok

Size: 18119071
Compressed: 3436060
done.
Updating tbg_hijacked... . No update available.
Extracting tbg_hijacked, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_hijacked/downloaded/tbg_hijacked

Extracting tbnuqfclfkemqivekikv.txt

Everything is Ok

Size: 13719
Compressed: 2427
done.
Updating tbg_primary-threats... 2012-06-12 00:15:10 BST Begin: pglcmd reload
Building blocklist ...
WARN: Invalid ASCII line:
INFO: ASCII: 837532 entries loaded from "STDIN"
INFO: Merged 596261 of 837532 entries.
INFO: Blocking 241271 IP ranges (2771734722 IPs).
Blocklist built.
Reloading pgld ...done.
2012-06-12 00:15:12 BST End: pglcmd reload
done.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16718961
Compressed: 3604082
done.
Updating tbg_search-engines... . No update available.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 58218
Compressed: 15311
done.
Blocklists updated.
Problematic daemon status: 1
* pgld is not running
2012-06-12 00:16:21 BST Begin: pglcmd stop_quick
Stopping pglcmd.wd[ OK ]
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh[ OK ]
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh[ OK ]
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 29337: No such process
[ OK ]
2012-06-12 00:16:21 BST End: pglcmd stop_quick
2012-06-12 00:17:17 BST Begin: pglcmd start
Building blocklist ...
Updating atma_atma... done.
Extracting atma_atma, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/atma_atma/downloaded/atma_atma

Extracting tzmtqbbsgbtfxainogvm.txt

Everything is Ok

Size: 10273329
Compressed: 740830
done.
Updating bluetack_dshield... done.
Extracting bluetack_dshield, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_dshield/downloaded/bluetack_dshield

Extracting bt_dshield.txt

Everything is Ok

Size: 6950
Compressed: 1737
done.
Updating bluetack_proxy... done.
Extracting bluetack_proxy, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/bluetack_proxy/downloaded/bluetack_proxy

Extracting bt_proxy.txt

Everything is Ok

Size: 113918
Compressed: 20109
done.
Updating tbg_bogon... done.
Extracting tbg_bogon, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_bogon/downloaded/tbg_bogon

Extracting ewqglwibdgjttwttrinl.txt

Everything is Ok

Size: 34716
Compressed: 5771
done.
Updating tbg_business-isps... done.
Extracting tbg_business-isps, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_business-isps/downloaded/tbg_business-isps

Extracting jcjfaxgyyshvdbceroxf.txt

Everything is Ok

Size: 1882488
Compressed: 263872
done.
Updating tbg_general-corporate-ranges... done.
Extracting tbg_general-corporate-ranges, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_general-corporate-ranges/downloaded/tbg_general-corporate-ranges

Extracting ecqbsykllnadihkdirsh.txt

Everything is Ok

Size: 18119071
Compressed: 3436060
done.
Updating tbg_hijacked... done.
Extracting tbg_hijacked, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_hijacked/downloaded/tbg_hijacked

Extracting tbnuqfclfkemqivekikv.txt

Everything is Ok

Size: 13719
Compressed: 2427
done.
Updating tbg_primary-threats... done.
Extracting tbg_primary-threats, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_primary-threats/downloaded/tbg_primary-threats

Extracting ijfqtofzixtwayqovmxn.txt

Everything is Ok

Size: 16718961
Compressed: 3604082
done.
Updating tbg_search-engines... done.
Extracting tbg_search-engines, detected 7z...
7-Zip (A) 9.20 Copyright (c) 1999-2010 Igor Pavlov 2010-11-18
p7zip Version 9.20 (locale=C,Utf16=off,HugeFiles=on,2 CPUs)

Processing archive: /var/spool/pgl/tbg_search-engines/downloaded/tbg_search-engines

Extracting pfefqteoxlfzopecdtyw.txt

Everything is Ok

Size: 58218
Compressed: 15311
done.
WARN: Invalid ASCII line:
INFO: ASCII: 837519 entries loaded from "STDIN"
INFO: Merged 596241 of 837519 entries.
INFO: Blocking 241278 IP ranges (2771734729 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule[ OK ]
....Whitelisting IP ranges[ OK ]
....Inserting block rule[ OK ]
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule[ OK ]
....Whitelisting IP ranges[ OK ]
....Inserting block rule[ OK ]
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule[ OK ]
....Inserting block rule[ OK ]
..Allowing loopback traffic: INPUT OUTPUT[ OK ]
..Allowing OUTPUT traffic to DNS server 127.0.0.1[ OK ]
..Allowing FORWARD traffic to DNS server 127.0.0.1[ OK ]
..Allowing LAN traffic ...
....INPUT from 192.168.2.0/24[ OK ]
....OUTPUT to 192.168.2.0/24[ OK ]
....FORWARD from 192.168.2.0/24 to 192.168.2.0/24[ OK ]
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld[ OK ]
Starting pglcmd.wd[ OK ]
2012-06-12 00:18:42 BST End: pglcmd start
2012-06-12 00:21:00 BST Begin: pglcmd reload
Reloading pgld ...done.
2012-06-12 00:21:01 BST End: pglcmd reload
2012-06-12 00:22:50 BST Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running
2012-06-12 00:23:18 BST Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running
pglcmd.wd: pgld is not running!
The watchdog detected that the daemon is not running.
To disable the watchdog set WATCHDOG="0" in /etc/pgl/pglcmd.conf.
Now doing a restart:
* Restarting only PeerGuardian Linux pgld

2012-06-12 00:23:42 BST Begin: pglcmd restart_not_wd
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 31448: No such process
...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 192.168.2.0/24 ...done.
....OUTPUT to 192.168.2.0/24 ...done.
....FORWARD from 192.168.2.0/24 to 192.168.2.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-06-12 00:23:43 BST End: pglcmd restart_not_wd
...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
* /var/run/pglcmd.wd.pid already exists, not starting pglcmd.wd again
2012-06-12 00:24:16 BST Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld ...done.
2012-06-12 00:24:17 BST End: pglcmd stop
2012-06-12 00:24:22 BST Begin: pglcmd reload
pgld is not running, doing nothing.
2012-06-12 00:24:22 BST End: pglcmd reload
2012-06-12 00:24:29 BST Begin: pglcmd restart
Stopping pglcmd.wd ...done.
Deleting iptables ...
Iptables deleted.
Stopping pgld ...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 192.168.2.0/24 ...done.
....OUTPUT to 192.168.2.0/24 ...done.
....FORWARD from 192.168.2.0/24 to 192.168.2.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-06-12 00:24:29 BST End: pglcmd restart
2012-06-12 00:24:37 BST Begin: pglcmd reload
Reloading pgld ...done.
2012-06-12 00:24:37 BST End: pglcmd reload
2012-06-12 00:26:20 BST Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running
2012-06-12 00:27:34 BST Begin: pglcmd restart
Stopping pglcmd.wd ...done.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 32023: No such process
...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 192.168.2.0/24 ...done.
....OUTPUT to 192.168.2.0/24 ...done.
....FORWARD from 192.168.2.0/24 to 192.168.2.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-06-12 00:27:34 BST End: pglcmd restart
2012-06-12 00:28:01 BST Begin: pglcmd reload
Reloading pgld ...done.
2012-06-12 00:28:01 BST End: pglcmd reload
2012-06-12 00:28:19 BST Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running
2012-06-12 00:30:15 BST Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 32378: No such process
...done.
2012-06-12 00:30:15 BST End: pglcmd stop


Content of pgld.log


Jun 12 00:13:36 INFO: Connected to dbus system bus.
Jun 12 00:13:36 INFO: Started.
Jun 12 00:13:37 INFO: ASCII: 241182 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Jun 12 00:13:37 INFO: Blocking 241182 IP ranges (2771731784 IPs).
Jun 12 00:13:37 INFO: NFQUEUE: binding to queue 92
Jun 12 00:13:37 INFO: ACCEPT mark: 20
Jun 12 00:13:37 INFO: REJECT mark: 10
Jun 12 00:15:00 OUT: 192.168.2.2 173.194.67.103 ICMP || SoftLayer Technologies Inc. | FBI dont ask me why | Apollo | MCA
Jun 12 00:15:01 OUT: 192.168.2.2 173.194.67.103 ICMP || SoftLayer Technologies Inc. | FBI dont ask me why | Apollo | MCA
Jun 12 00:15:12 INFO: Closing logfile: /var/log/pgl/pgld.log
Jun 12 00:15:12 INFO: Reopened logfile: /var/log/pgl/pgld.log
Jun 12 00:15:12 WARN: pgld dbus is already initialized.

Jun 12 00:15:12 ERROR: Cannot initialize D-Bus
Jun 12 00:18:42 INFO: Connected to dbus system bus.
Jun 12 00:18:42 INFO: Started.
Jun 12 00:18:43 INFO: ASCII: 241278 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Jun 12 00:18:43 INFO: Blocking 241278 IP ranges (2771734729 IPs).
Jun 12 00:18:43 INFO: NFQUEUE: binding to queue 92
Jun 12 00:18:43 INFO: ACCEPT mark: 20
Jun 12 00:18:43 INFO: REJECT mark: 10
Jun 12 00:21:01 INFO: Closing logfile: /var/log/pgl/pgld.log
Jun 12 00:21:01 INFO: Reopened logfile: /var/log/pgl/pgld.log
Jun 12 00:21:01 WARN: pgld dbus is already initialized.

Jun 12 00:21:01 ERROR: Cannot initialize D-Bus
Jun 12 00:23:43 INFO: Connected to dbus system bus.
Jun 12 00:23:43 INFO: Started.
Jun 12 00:23:43 INFO: ASCII: 241278 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Jun 12 00:23:43 INFO: Blocking 241278 IP ranges (2771734729 IPs).
Jun 12 00:23:43 INFO: NFQUEUE: binding to queue 92
Jun 12 00:23:43 INFO: ACCEPT mark: 20
Jun 12 00:23:43 INFO: REJECT mark: 10
Jun 12 00:24:16 INFO: Unbinding from nfqueue.
Jun 12 00:24:16 STATS: Blocked hit statistics:
Jun 12 00:24:16 STATS: 0 hits total
Jun 12 00:24:29 INFO: Connected to dbus system bus.
Jun 12 00:24:29 INFO: Started.
Jun 12 00:24:29 INFO: ASCII: 241278 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Jun 12 00:24:29 INFO: Blocking 241278 IP ranges (2771734729 IPs).
Jun 12 00:24:29 INFO: NFQUEUE: binding to queue 92
Jun 12 00:24:29 INFO: ACCEPT mark: 20
Jun 12 00:24:29 INFO: REJECT mark: 10
Jun 12 00:24:37 INFO: Closing logfile: /var/log/pgl/pgld.log
Jun 12 00:24:37 INFO: Reopened logfile: /var/log/pgl/pgld.log
Jun 12 00:24:37 WARN: pgld dbus is already initialized.

Jun 12 00:24:37 ERROR: Cannot initialize D-Bus
Jun 12 00:27:34 INFO: Connected to dbus system bus.
Jun 12 00:27:34 INFO: Started.
Jun 12 00:27:34 INFO: ASCII: 241278 entries loaded from "/var/lib/pgl/master_blocklist.p2p"
Jun 12 00:27:34 INFO: Blocking 241278 IP ranges (2771734729 IPs).
Jun 12 00:27:34 INFO: NFQUEUE: binding to queue 92
Jun 12 00:27:34 INFO: ACCEPT mark: 20
Jun 12 00:27:34 INFO: REJECT mark: 10
Jun 12 00:28:01 INFO: Closing logfile: /var/log/pgl/pgld.log
Jun 12 00:28:01 INFO: Reopened logfile: /var/log/pgl/pgld.log
Jun 12 00:28:01 WARN: pgld dbus is already initialized.

Jun 12 00:28:01 ERROR: Cannot initialize D-Bus

masuch
June 12th, 2012, 02:07 AM
@masuch: I'm not familiar with tor in detail. But I doubt that there is an module for iptables. Perhaps there is a port that you could whitelist. Instead I guess you should use this list (http://www.iblocklist.com/list.php?list=tor) as an allow list in pgl (ask if you don't know how to configure that).[/QUOTE]

Thanks for that list - should it be managed by /etc/pgl/iptables-custom-insert.sh ?

Because Tor has many different ports and IPs (as I have noticed) -
Is it possible to allow in iptables everything for specific application ?
Something like following I have found in iptables-custom-insert.sh:
iptables -I pgl_out -p tcp --dport 80 -m owner --cmd-owner firefox -j RETURN

but without -dport and owner and --cmd-owner - which I did not find in man iptables anyway what does it mean ?

thank you for help.

jre
June 13th, 2012, 11:44 PM
We released "pgl 2.2.0 The autotools release"
our new Gentoo maintainer hasufell added a real buildsystem (GNU autotools)
renamed pgl-gui to pglgui
various fixes and for pglgui new features

Because the oneiric and precise problems (pgld crashes on reload) still exist with the packages that were built in these distributions, I copied the natty binary packages to the oneiric and precise dists in the PPA.
So you don't have to use the workaround (use natty entry in the apt sources.list) anymore, because I implemented that workaround on the server side.
Of course the root of this problem still needs to be diagnosed and fixed.


Thanks for that list - should it be managed by /etc/pgl/iptables-custom-insert.sh ?
Copy it to /etc/pgl/blocklists.local/



Because Tor has many different ports and IPs (as I have noticed) -
Is it possible to allow in iptables everything for specific application ?
Something like following I have found in iptables-custom-insert.sh:
iptables -I pgl_out -p tcp --dport 80 -m owner --cmd-owner firefox -j RETURN

but without -dport and owner and --cmd-owner - which I did not find in man iptables anyway what does it mean ?
You may try

iptables -I pgl_out -m owner --cmd-owner firefox -j RETURN
cmd-owner is a submodule of owner. But if it is not in "man", then your system probably doesn't support it either because it is just an netfilter extension (which I think needs special kernel support).

Gavin77
June 14th, 2012, 03:41 AM
Because the oneiric and precise problems (pgld crashes on reload) still exist with the packages that were built in these distributions, I copied the natty binary packages to the oneiric and precise dists in the PPA.
So you don't have to use the workaround (use natty entry in the apt sources.list) anymore, because I implemented that workaround on the server side.
Of course the root of this problem still needs to be diagnosed and fixed.



Thanks, this version works.

jre
June 19th, 2012, 10:21 PM
I just created a new PPA pgl-experimental: https://launchpad.net/~jre-phoenix/+archive/pgl-experimental
I'll add preview releases there from time to time in order to get tester's feedback without breaking the whole repository. Please use this PPA only additionally to the old one - the new one does NOT necessarily always contain the newest release.

I hope to have fixed the Oneiric/Precise bug there. Someone please test.

EDIT: the packages are still building and might just be available in a few hours.

Gavin77
June 20th, 2012, 04:22 AM
I just tried out the new version from experimental ppa performing my usual tests both from gui and the terminal and I'm happy to say it worked perfectly so far.

Congrats on fixing the reload bug :)

A strange oddity I've noticed for a while now is in the blocklists the atma/atma entry always shows a yellow icon as if I've just enabled or disabled it even though I've never touched it. It's no big deal but just weird that it does that.

jre
June 20th, 2012, 06:20 PM
Thanks Gavin77, your fast feedback really helps!

About the new problem: this happens here, too. I just told it to our GUI developer.

Sean Whitney
June 21st, 2012, 03:31 PM
I'm not a iptables, pgl expert so I'm sure that my comment below contains understanding failures.... :confused:

Be that as it may....

Is there a way to have the ipp2p iptables module redirect traffic to pgl to check? Right now I have pgl only looking at common p2p ports. What I want is to have it inspect any traffic (on any port) that the ipp2p module identifies as p2p traffic.

Note: I'm using shorewall to manage my iptables.

Thanks in advance,

Sean

jre
June 25th, 2012, 01:21 PM
Please welcome "PeerGuardian Linux 2.2.1"!

This version adds the last feature only present in mobloquer, but not in
pglgui: "whois information about blocked IPs".

Since I also fixed or workarounded all issues with older Debian and
Ubuntu versions I added transitional packages for the old
moblock/blockcontrol/mobloquer packages. This means the Debian/Ubuntu
world now moves to pgl automatically. (Except the 2008 Ubuntu Long Term
Release Hardy which I think is ok to be left behind forever ;P )

The packages are in the usual PPA at https://launchpad.net/~jre-phoenix/+archive/ppa and will find their way to you automatically if you enabled it.

The development code is in the git repository at sourceforge, see
https://sourceforge.net/scm/?type=git&group_id=131687


Complete 2.2.1 ChangeLog:


[jre]
* Disabled dbus closing and reopening on reload.
Fixes bug "pgld binaries built under Ubuntu Oneiric, Precise
and Mint 12 crash on reload" (Closes: SF Bug #3495654)
* fixed Makefile clean target

[freemind]
* Fixed log viewer dialog to not close on key press.
* Added whois action.
* Minor tweaks.
* Fixed (random) unapplied changes at start-up bug.
* Added sortable columns in whitelist view.
* Added automatic saving and restoring of window's state.



@Gavin77: fixed :)

@Sean Whitney:

Is there a way to have the ipp2p iptables module redirect traffic to pgl to check? Right now I have pgl only looking at common p2p ports. What I want is to have it inspect any traffic (on any port) that the ipp2p module identifies as p2p traffic.

First off:
per default pgl checks all NEW traffic. Ports that you add to WHITE_[TCP|UDP]_... (or whitelist in pglgui) are NOT handled by pglgui. So adding the P2P ports to the whitelisting normally is the completely wrong thing to do - just in case there was a misunderstanding.

Now about ipp2p - I don't use it, just read something about it. If you want to check all new ipp2p identified traffic you should do the following steps
Stop pgl
Disable the normal activation, where all NEW traffic is sent to pgl:
Set in /etc/pgl/pglcmd.conf:

IPTABLES_ACTIVATION="0"
Refer to /usr/lib/[I][YOUR ARCHITECTURE, e.g. x86_64-linux-gnu]/pgl/pglcmd.defaults to learn about the varaible meanings. This means pglcmd does NOT execute the following commands (this is the simplest case where pgl works on all network interfaces. I hope I made the variable substituion correctly):

iptables -I INPUT -m state --state NEW -m mark ! --mark 20 -j pgl_in
iptables -I OUTPUT -m state --state NEW -m mark ! --mark 20 -j pgl_out
iptables -I FORWARD -m state --state NEW -m mark ! --mark 20 -j pgl_fwd
Instead activate by sending all ipp2p traffic to pgl:
Add to a new file /etc/pgl/ipp2p.iptables.insert.sh

iptables -I INPUT -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_in
iptables -I OUTPUT -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_out
iptables -I FORWARD -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_fwd
To remove these iptables rules ater pgl stops you then need in /etc/pgl/ipp2p.iptables.remove.sh

iptables -D INPUT -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_in
iptables -D OUTPUT -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_out
iptables -D FORWARD -m state --state NEW -m ipp2p --ipp2p -m mark ! --mark 20 -j pgl_fwd
Start pgl
[/LIST]

Sean Whitney
June 26th, 2012, 07:02 PM
First off:
per default pgl checks all NEW traffic. Ports that you add to WHITE_[TCP|UDP]_... (or whitelist in pglgui) are NOT handled by pglgui. So adding the P2P ports to the whitelisting normally is the completely wrong thing to do - just in case there was a misunderstanding.


You are of course correct. I have whitelisted all port EXCEPT, the common P2P ports. I'm only really interested in apply pgl to P2P traffic. Thanks, I'll try it out and let you know.

Sean

masuch
July 6th, 2012, 10:58 PM
Hi,

I have came accross error message in /var/log/pgl/pgld.log:


ERROR: Unbinding from queue '23552', recv returned No buffer space available


using version 2.2.1

I have read something about it on this forum in post #131
and
http://www.vyatta.org/forum/viewtopic.php?t=6508&sid=a15464ed60549a515c43bca4c26909b7

but did not understand much.

Could you please let me know where to increase this buffer ?
Is it possible to do it without changing source code ?

thank you,
kind regards,
M.

masuch
July 8th, 2012, 05:36 PM
Hi,

I have came across some nice idea to block ICMP from internet but allow it from intranet:
http://serverfault.com/questions/84963/why-not-block-icmp



Copy/Paste from the web site:
# --- I allow ICMP traffic from local intranet, block it from Internet.
# --- That way my server is all but invisible online (it responds only on a non standard SSH port).
iptables -I INPUT 7 -d 208.180.X.X -p icmp --icmp-type 8 -j DROP
iptables -I INPUT 8 -d 208.180.X.X -p icmp --icmp-type 0 -j DROP
iptables -I INPUT 9 -d 208.180.X.X -p icmp --icmp-type 11 -j DROP
# --- This inserts it after the standard loopback, established, LAN whitelist, VOIP provider whitelist, and SSH port ACCEPTs. I allow the traffic I want, and then do my best to keep the server invisible to the rest of the world.


so I changed it to (in /etc/pgl/iptables-custom-insert.sh):


iptables -I pgl_in -p icmp --icmp-type 8 -j DROP
iptables -I pgl_in -p icmp --icmp-type 0 -j DROP
iptables -I pgl_in -p icmp --icmp-type 11 -j DROP

I would like to know if it is really working as it has been said on that web page and how to implement it for MoBlock (do I need to specify address as it is in original form) ?

thank you,
kind regards,
M.

PD808
July 19th, 2012, 02:53 AM
Hi, I'm sticking with Mobloquer on my 12.04 install because of the HTTP & HTTPS exception options, do you think you could add a GUI option to PGL of adding exceptions like Mobloquer had? I know you can edit the config file but it seems like a downgrade from Mobloquer and I haven't tested out PGL on my main computer as I'm afraid it will block various access like torrents and http.

Gavin77
July 19th, 2012, 03:34 AM
You already can do that, just make sure you have pglgui installed.

jre
July 19th, 2012, 09:07 PM
As Gavin77 already said.

Besides that:
as I'm afraid it will block various access like torrents and http.

Err, if you want to whitelist torrent ports, you really should re-think why you want to install pgl. Whitelisting torrent ports just contradicts the purpose of pgl. If you have problems connecting to trackers you should better whitelist trusted tracker IPs or use less blocklists.

jre
July 19th, 2012, 09:14 PM
Sorry for the long delay.



Could you please let me know where to increase this buffer ?
I last heard about this issue several years ago. So it's already in the TODO.
Anyway, add this to your system's config (you may add it to /etc/pgl/insert.sh if you don't know a better file)

sysctl -w net.core.rmem_default=8388608
sysctl -w net.core.wmem_default=8388608

jre
July 19th, 2012, 09:28 PM
Hi,

I have came across some nice idea to block ICMP from internet but allow it from intranet:
http://serverfault.com/questions/84963/why-not-block-icmp



so I changed it to (in /etc/pgl/iptables-custom-insert.sh):


iptables -I pgl_in -p icmp --icmp-type 8 -j DROP
iptables -I pgl_in -p icmp --icmp-type 0 -j DROP
iptables -I pgl_in -p icmp --icmp-type 11 -j DROP

I would like to know if it is really working as it has been said on that web page and how to implement it for MoBlock (do I need to specify address as it is in original form) ?

If you want ICMP to be checked by moblock/pgl you don't need to change anything. Every ICMP packet from an IP listed in your blocklists will be dropped (like every other packet from bad IPs). Because of the automatic LAN whitelisting feature of pgl intranet ICMP packets will not be checked by pgl. I think this is what you want.

If you want to block all ICMP packets (independent whether their origin is listed in the blocklists) then your approach seems to be correct. It doesn't matter whether you place these DROP rules in pgl_in or INPUT, both work because this stuff is independent from pgl.
I don't know these icmp types, so I just can say: with your rules all ICMP packets of type 8, 0 or 11 coming to your computer get dropped. To exempt intranet packets you may make use of pgl's automatic LAN whitelisting by changing the insert command in your rules to e.g. "insert on fourth place --> after the LAN whitelisting rules). Tell me if you want to go this way (I doubt so) and need help.

PD808
July 20th, 2012, 01:14 AM
Thanks jre / Gavin77, I installed pgl over mobloquer and it's working great, and it brought over my settings from mobloquer. Torrents are working. (No, I didn't whitelist my torrent ports) One thing is though now I have duplicate blocklists, any way to fix that? EDIT: nevermind there's a delete button.

Sean Whitney
July 23rd, 2012, 03:48 PM
So I have implemented the changes recommended http://ubuntuforums.org/showpost.php?p=12052547&postcount=619 and they seem to be working. Although now I only seem to be filtering UDP bittorent traffic. I think however this is a problem with ipp2p and not pgl.

I'm running pgl on my firewall/gateway box and right now all my bittorrent connections are being filtered in the forward chain because my ip range 192.168.0.0/24 is somewhere in the list. I really would only like it to check the external destination in this case and whitelist my local lan IPs in the forward chain. The allow.p2p file is for in/out and not forward.

Sean

jre
July 23rd, 2012, 05:23 PM
Use "pglcmd search 192.168.0.0" to identify the blocklist and the line that cause the blocking. Maybe you have to experiment a bit with the search pattern (it's used with grep -Ei "$SEARCHPATTERN" "$BLOCKLIST"

I think all other ways of whitelisting the LAN for FORWARD can't work. so it is good that you use allow.p2p not for FORWARD.

Sean Whitney
July 24th, 2012, 05:52 PM
Thanks. Just for completeness,



IP_REMOVE="\:192\.168\."


Has removed fwd filtering issues with my home LAN. I'm still receiving FWD block notices in the logs, which indicate that it's filtering on the other IP, which is what I wanted.

jre
July 24th, 2012, 06:00 PM
Good.

I know (tm) that its working correctly. Generally, when working with FORWARD you should always check if traffic with source from the web (to your LAN) and destination to the web (from your LAN) is checked.

lemwt
October 10th, 2012, 01:23 AM
Hello, I'm having some trouble getting PeerGuardian Linux to start/run on Ubuntu 12.04 Precise.

I just jumped from Ubuntu 10.10 to 12.04 and I'm still trying to get the hang of it (for your information).

I've installed Moblock several times successfully on older Ubuntu distros but I'm stuck on PeerGuardian Linux this time. If I understand correctly, my problem is this error:
ERROR: Error loading /var/lib/pgl/master_blocklist.p2p.

Here's what the terminal says when I try to update, reload and start:



:~$ sudo pglgui
[sudo] password for:
** Debug: "/usr/lib/i386-linux-gnu/pgl/pglcmd.defaults"
** Warning: "sni-qt/3365" WARN 16:11:52.243 void StatusNotifierItemFactory::connectToSnw() Invalid interface to SNW_SERVICE
** Debug: Connection to DBus was successful.
** Debug: Executing commands:
("/usr/bin/pglcmd update")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) ""
** Debug: Executing commands:
("/usr/bin/pglcmd reload")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/pglcmd update"
** Debug: Executing commands:
("/usr/bin/pglcmd start")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/pglcmd reload"
** Debug: "INFO: Started."
** Debug: "ERROR: Error loading /var/lib/pgl/master_blocklist.p2p"
** Debug: "INFO: Blocking 0 IP ranges (0 IPs)."
** Debug: "ERROR: Cannot load the blocklist(s)"


I saw this thread here:
http://sourceforge.net/projects/peerguardian/forums/forum/446997/topic/5461334
but I got kind of lost at the end there and changing "IP_REMOVE=" didn't do anything for me.

Then I installed this:
http://sourceforge.net/projects/peerguardian/forums/forum/446997/topic/5461334
and that didn't change anything either.

Any other ideas I could try?

Gavin77
October 10th, 2012, 05:45 PM
Not sure about the errors but you don't need to run pglgui with sudo, just run as a normal user.

jre
October 11th, 2012, 09:20 PM
(Sorry I'm quite busy currently, answers may take a few days)

Try a "sudo pglcmd force-reload" to get new versions of all blocklists. (This rules out a corrupted blocklist.)

If you still have problems afterwards post your logfiles /var/log/pglcmd.log and /var/log/pgld.log (I don't need the parts before the force-reload). Maybe also the output of "pglcmd show_config" is necessary.

See also https://sourceforge.net/tracker/?func=detail&atid=721927&aid=3575581&group_id=131687

lemwt
October 12th, 2012, 03:38 AM
@Gavin77 #634:
Thanks, I'll do that.

@jre #635:
First of all, thank you for helping make this great program! And also thank you for taking the time to help out so many people with it too.

Yeah, sorry about the duplicate entries. I wanted to post here only but for some reason I couldn't find this thread for a few days.


In pglgui I pressed "Start", then "Update" and I get this error pop-up:

One or more commands(s) failed to ececute.
You can check below the commands that failed and their output.
You can also check pgld's and/or pglcmd's log through the view menu.
Command:
/usr/bin/gksudo "/usr/bin/pglcmd update"
Output: *Updating blocklists and reloading PeerGuardian Linux pgld ...fail!

...and the same thing happens when "Reload" is pressed too.


:~$ pglgui
** Debug: "/usr/lib/i386-linux-gnu/pgl/pglcmd.defaults"
** Debug: Connection to DBus was successful.
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd start"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) ""
** Debug: "INFO: Started."
** Debug: "ERROR: Error loading /var/lib/pgl/master_blocklist.p2p"
** Debug: "INFO: Blocking 0 IP ranges (0 IPs)."
** Debug: "ERROR: Cannot load the blocklist(s)"
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd update"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd start""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd reload"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd update""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd restart"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd reload""
** Debug: "INFO: Started."
** Debug: "ERROR: Error loading /var/lib/pgl/master_blocklist.p2p"
** Debug: "INFO: Blocking 0 IP ranges (0 IPs)."
** Debug: "ERROR: Cannot load the blocklist(s)"


Here's the pglcmd.log:


2012-10-11 18:42:50 PDT Begin: pglcmd start
Building blocklist ...
WARN: Invalid ASCII line: Binary file standard input matches
ERROR: Error opening (null) as binary.
INFO: Blocking 0 IP ranges (0 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-11 18:42:51 PDT End: pglcmd start
2012-10-11 18:43:01 PDT Begin: pglcmd update
Automatic blocklist management disabled.
Problematic daemon status: 1
* pgld is not running
2012-10-11 18:46:59 PDT Begin: pglcmd reload
Problematic daemon status: 1
* pgld is not running
2012-10-11 18:47:10 PDT Begin: pglcmd restart
Stopping pglcmd.wd ...done.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 3610: No such process
...done.
Building blocklist ...
WARN: Invalid ASCII line: Binary file standard input matches
ERROR: Error opening (null) as binary.
INFO: Blocking 0 IP ranges (0 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-11 18:47:11 PDT End: pglcmd restart
pglcmd.wd: pgld is not running!
The watchdog detected that the daemon is not running.
To disable the watchdog set WATCHDOG="0" in /etc/pgl/pglcmd.conf.
Now doing a restart:
* Restarting only PeerGuardian Linux pgld

2012-10-11 18:52:11 PDT Begin: pglcmd restart_not_wd
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 4519: No such process
...done.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-11 18:52:12 PDT End: pglcmd restart_not_wd
...done.
Warning: sendmail not found.
Check the SENDMAIL setting.
* /var/run/pglcmd.wd.pid already exists, not starting pglcmd.wd again


Here's the pglcmd.log:

Oct 11 18:42:51 INFO: Connected to dbus system bus.
Oct 11 18:42:51 INFO: Started.
Oct 11 18:42:51 ERROR: Error loading /var/lib/pgl/master_blocklist.p2p
Oct 11 18:42:51 INFO: Blocking 0 IP ranges (0 IPs).
Oct 11 18:42:51 ERROR: Cannot load the blocklist(s)
Oct 11 18:47:11 INFO: Connected to dbus system bus.
Oct 11 18:47:11 INFO: Started.
Oct 11 18:47:11 ERROR: Error loading /var/lib/pgl/master_blocklist.p2p
Oct 11 18:47:11 INFO: Blocking 0 IP ranges (0 IPs).
Oct 11 18:47:11 ERROR: Cannot load the blocklist(s)
Oct 11 18:52:12 INFO: Connected to dbus system bus.
Oct 11 18:52:12 INFO: Started.
Oct 11 18:52:12 ERROR: Error loading /var/lib/pgl/master_blocklist.p2p
Oct 11 18:52:12 INFO: Blocking 0 IP ranges (0 IPs).
Oct 11 18:52:12 ERROR: Cannot load the blocklist(s)


And here's the terminal after trying "sudo pglcmd force-reload":

:~$ sudo pglcmd force-reload
[sudo] password for:
* Reloading PeerGuardian Linux pgld [fail]

Some additional info:
After I press "Start" and "Update" in the pglgui, I cannot connect to any websites using my browser anymore, however, I can still run Ubuntu updates for some reason (Yet I can't load Ubuntu.com in Firefox...) and I have ports 80 and 443 allowed for outbound only. Running "pglcmd stop" makes the traffic go through again. I haven't tried whitelisting LAN addresses or anything like that yet, I'll work on that next. I'm not asking how to fix this, just want to tell you it's behavior.

I'm also using the same exact blocklists [files] I used with Moblock just a few weeks ago and I keep them in my home folder. They are also .gz format. I don't know if any of this may make a difference or not, just trying to give you as much info as possible.

Thanks for the ideas; if there's anything else I can try or information I could provide, I would be happy to.

lemwt
October 12th, 2012, 03:52 AM
Edit: Just adding the pglcmd.conf file I forgot to earlier [using the edit buttons in my own post did not work...]:


# pglcmd.conf - configuration file for pglcmd

# This file is sourced by a shell script. Any line which starts with a # (hash)
# is a comment and is ignored. If you set the same variable several times,
# then only the last line will be used.

# Refer to pglcmd.defaults (/usr/lib/pgl/pglcmd.defaults)
# for the complete set of possible configuration variables with comments.

# Do a "pglcmd restart" (sometimes even "reload" is enough) when you have
# edited this file.
WHITE_TCP_OUT="80 443"
INIT="0"
CRON="0"

jre
October 12th, 2012, 03:34 PM
No problem with the duplicate. That was more a notice for me and other readers.

You have to do the "sudo pglcmd force-reload" in a terminal. This command does more than a "reload" in pglgui.

lemwt
October 12th, 2012, 09:06 PM
@jre #638
Hi, and thanks for your response! I tried a variety of command orders because I wasn't sure exactly how it should be done. I also did "sudo pglcmd force-reload" in the terminal each time.

Here's the terminal for "sudo pglcmd force-reload" then "pglgui", then "Start" (start button in the GUI):


:~$ sudo pglcmd force-reload
[sudo] password for:
* Reloading PeerGuardian Linux pgld [ OK ]
:~$ pglgui
** Debug: "/usr/lib/i386-linux-gnu/pgl/pglcmd.defaults"
** Debug: Connection to DBus was successful.
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd start"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) ""
** Debug: "INFO: Started."
** Debug: "ERROR: Error loading /var/lib/pgl/master_blocklist.p2p"
** Debug: "INFO: Blocking 0 IP ranges (0 IPs)."
** Debug: "ERROR: Cannot load the blocklist(s)"


pglcmd.log after "sudo pglcmd force-reload":


2012-10-12 11:59:17 PDT Begin: pglcmd force-reload
pgld is not running, doing nothing.
2012-10-12 11:59:17 PDT End: pglcmd force-reload
2012-10-12 11:59:57 PDT Begin: pglcmd start
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-12 11:59:59 PDT End: pglcmd start



pglcmad.log for "sudo pglcmd force-reload" alone:


2012-10-12 12:27:36 PDT Begin: pglcmd force-reload
pgld is not running, doing nothing.
2012-10-12 12:27:36 PDT End: pglcmd force-reload


terminal:


:~$ sudo pglcmd force-reload
[sudo] password for:
* Reloading PeerGuardian Linux pgld [ OK ]





"sudo pglcmd force-reload" after pgl was started:


pglcmad.log for "sudo pgld start", then "sudo pglcmd force-reload":


2012-10-12 12:29:03 PDT Begin: pglcmd force-reload
Problematic daemon status: 1
* pgld is not running [ OK ]



terminal:
:~$ sudo pgld start
:~$ sudo pglcmd force-reload
* Reloading PeerGuardian Linux pgld [fail]


pglcmd.log for "pglgui", "pglcmd start", "sudo pglcmd force-reload":


2012-10-12 12:36:09 PDT End: pglcmd start
2012-10-12 12:36:32 PDT Begin: pglcmd force-reload
Problematic daemon status: 1
* pgld is not running


I hope this helps and was done correctly. If I needed to do the commands in a different order or try something entirely different, please let me know, I'm still learning too. Thank you!

jre
October 14th, 2012, 04:02 PM
Ah, sorry, force-reload doesn't work if pgl isn't running ...

Let's do it manually:

sudo pglcmd stop
sudo rm -rf /var/spool/pgl/
sudo pglcmd start

This way we remove all previously downloaded blocklists (I guess one of them is somehow corrupted, and causes these problems). They get redownloaded on "start" (which will therefore take a few minutes, depending on your internet connection).

I guess the problems will be solved than. If not, post again the current log and your /etc/pgl/blocklists.list.

Good luck!

lemwt
October 16th, 2012, 09:59 PM
Ok, I did this:

sudo pglcmd stop
sudo rm -rf /var/spool/pgl/
sudo pglcmd start


and here's the terminal:


:~$ sudo pglcmd stop
[sudo] password for:
* Stopping PeerGuardian Linux pgld [ OK ]
:~$ sudo rm -rf /var/spool/pgl/
:~$ sudo pglcmd start
* Starting PeerGuardian Linux pgld [ OK ]
:~$ pglgui
** Debug: "/usr/lib/i386-linux-gnu/pgl/pglcmd.defaults"
** Debug: Connection to DBus was successful.
** Debug: ~AddExceptionDialog()
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd start"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) ""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd reload"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd start""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd update"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd reload""

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd start""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd update"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd reload""
** Warning: bool hasPermissions(const QString&) Could not read from file "/etc/test_file"
** Debug: Executing commands:
("/usr/bin/gksudo "/usr/bin/pglcmd update"")

** Debug: void ProcessT::executeCommand(const QString&, const QProcess::ProcessChannelMode&, bool) "/usr/bin/gksudo "/usr/bin/pglcmd update""
** Warning: ~Peerguardian()
** Debug: ~GuiOptions()

:~$ pglgui
** Debug: "/usr/lib/i386-linux-gnu/pgl/pglcmd.defaults"
** Debug: Connection to DBus was successful.
** Debug: "INFO: Started."
** Debug: "ERROR: Error loading /var/lib/pgl/master_blocklist.p2p"
** Debug: "INFO: Blocking 0 IP ranges (0 IPs)."
** Debug: "ERROR: Cannot load the blocklist(s)"



And this is /etc/pgl/blocklists.list, but there's nothing in it:


# blocklists.list - lists the remote blocklists that pglcmd handles.

# Place one URL per line for every blocklist.
# Any line which starts with a # (hash) is a comment and is ignored.

# Have a look at /usr/share/doc/pglcmd/README.blocklists.gz for detailed
# information about some available blocklists.

# Instead or additionally to the remote blocklists that are specified here, you
# can put local blocklists in LOCAL_BLOCKLIST_DIR (/etc/pgl/blocklists.local/).
# All blocklists in that directory (except those in subdirectories, or which end
# in "~" or start with ".") are used. They may be in any supported format and
# have to be either unpacked or gzip'ped.

# Do a "pglcmd reload" (or "restart" or "update") when you have edited this
# file.



So my lists are not updated via URL/PGL because I download them manually with my browser and keep them in my home directory. The lists are local, could this be part of the problem? I also tried moving all the lists directly to /etc/pgl/blocklists.local and loaded them up from there, but that just made things worse. And as you can see, /etc/pgl/blocklists.list has not been changed in any way. Do I need to add the paths to my local blocklist here?

jre
October 28th, 2012, 02:01 PM
Placing them directly or linking them in /etc/pgl/blocklists.local/ both work here perfectly.
Can you test with only one blocklist, e.g. one with a line like

Multicast: 228.0.0.0-228.255.255.255

If this works, please try your local blocklists separately. I suppose one is broken. If you find the culprit you might send it to me for further debugging.

Did you make any changes, especially related to "LOWMEM"? What's your /etc/pgl/pglcmd.conf?
Did you compile on your own or do you use the binary from my repository?

lemwt
October 31st, 2012, 03:56 AM
"Did you make any changes, especially related to "LOWMEM"?"

Not that I'm aware of. I think the only thing I did was whitelist ports 80 and 443, TCP, out only.


"What's your /etc/pgl/pglcmd.conf?"


WHITE_TCP_OUT="80 443"
INIT="0"
CRON="0"


"Did you compile on your own or do you use the binary from my repository?"

I always go to http://moblock-deb.sourceforge.net and follow the install instructions there (I use your repository). This is what I put in my sources list:


deb http://ppa.launchpad.net/jre-phoenix/pgl-experimental/ubuntu precise main
deb-src http://ppa.launchpad.net/jre-phoenix/pgl-experimental/ubuntu precise main

I also added your ppa from here:
https://launchpad.net/~jre-phoenix/+archive/ppa

But on the last step, installing the .deb file, the software center said it was a dummy package and being ignorant of what that meant, I didn't install it. I was trying to install this because of what I had read earlier in this thread and thought it might solve this problem.

Just as a side note, I want to say thanks for the clear, step-by-step install instructions at moblock-deb.sourceforge.net. Having that there has always made a HUGE difference for me. I've even used it to help me figure out how to install other software when I was still learning how to do it.


So I removed all the old lists (and did "sudo pglcmd force-reload"),
made the multicast blocklist and added it (through the GUI),
restarted my system,
turned on pglgui, pressed start, got no error but the list didn't load.
Pressed start again and got the pop-up error message.

Here's the logs when I tried that:

pgld.log:


Oct 30 18:28:09 INFO: Connected to dbus system bus.
Oct 30 18:28:09 INFO: Started.
Oct 30 18:28:09 ERROR: Error loading /var/lib/pgl/master_blocklist.p2p
Oct 30 18:28:09 INFO: Blocking 0 IP ranges (0 IPs).
Oct 30 18:28:09 ERROR: Cannot load the blocklist(s)

pglcmd.log:


2012-10-30 18:28:08 PDT Begin: pglcmd start
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-30 18:28:09 PDT End: pglcmd start
2012-10-30 18:28:57 PDT Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running



I even tried manually adding the multicast IP range to the master_blocklist.p2p but it didn't take. But I don't know what the format looks like for IP ranges in this file anyway (I'm assuming it's different and don't even know if this would work).



I'd like to try adding a list just using the command line, but honestly, I don't know how to do it. I see


pgld [-c CHARSET] -m [BLOCKLIST(S)]

so if I have my list here: /home/anonymous/Lists/Multicast.gz, is this the command to load it?:


pgld -c UTF-8 -m /home/anonymous/Lists/Multicast.gz

I don't even know if it's UTF-8 or not, let alone figuring that out.



I also tried using the URL instead of local lists (blocklist name was bluetack_dshield here), and got some different results (pgld.log was the same as before though):

pglcmd.log:


2012-10-30 18:32:34 PDT Begin: pglcmd stop
Stopping pglcmd.wd ...done.
Deleting iptables ...
..Executing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
..Removing iptables remove script /var/lib/pgl/.pglcmd.iptables.remove.sh ...done.
Iptables deleted.
Stopping pgld/sbin/start-stop-daemon: warning: failed to kill 3675: No such process
...done.
2012-10-30 18:32:34 PDT End: pglcmd stop
2012-10-30 19:02:45 PDT Begin: pglcmd reload
pgld is not running, doing nothing.
2012-10-30 19:02:45 PDT End: pglcmd reload
2012-10-30 19:02:58 PDT Begin: pglcmd update
Updating blocklists ...
Updating bluetack_dshield... done.
Extracting bluetack_dshield, detected gz... done.
Blocklists updated.
pgld is not running, doing nothing.
2012-10-30 19:03:16 PDT End: pglcmd update
2012-10-30 19:04:20 PDT Begin: pglcmd start
Building blocklist ...
WARN: Invalid ASCII line: Binary file standard input matches
ERROR: Error opening (null) as binary.
INFO: Blocking 0 IP ranges (0 IPs).
Blocklist built.
Inserting iptables ...
..Setting up iptables for INPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for OUTPUT:
....Creating chain and inserting NFQUEUE rule ...done.
....Whitelisting ports ...done.
....Whitelisting IP ranges ...done.
....Inserting block rule ...done.
..Setting up iptables for FORWARD:
....Creating chain and inserting NFQUEUE rule ...done.
....Inserting block rule ...done.
..Allowing loopback traffic: INPUT OUTPUT ...done.
..Allowing OUTPUT traffic to DNS server 127.0.0.1 ...done.
..Allowing FORWARD traffic to DNS server 127.0.0.1 ...done.
..Allowing LAN traffic ...
....INPUT from 10.0.0.0/24 ...done.
....OUTPUT to 10.0.0.0/24 ...done.
....FORWARD from 10.0.0.0/24 to 10.0.0.0/24 ...done.
..LAN traffic allowed.
..Activating chains:
....INPUT
....OUTPUT
....FORWARD
..Chains activated.
Iptables inserted.
Starting pgld ...done.
Starting pglcmd.wd ...done.
2012-10-30 19:04:21 PDT End: pglcmd start
2012-10-30 19:05:01 PDT Begin: pglcmd reload
Problematic daemon status: 1
* pgld is not running
2012-10-30 19:05:16 PDT Begin: pglcmd start
Problematic daemon status: 1
* pgld is not running


Well, sorry it's been so difficult! I'll try anymore suggestions you have and I'd really like to try to load a list with the command-line only; if you don't mind teaching me how.

jre
November 11th, 2012, 04:11 PM
They are also .gz format.

While rereading your post I just realized that you are using packed blocklists. I think we removed support for that in pgld itself (IMHO extracting should be done with external applications, which are installed anyway. further there is not only gz out there, but also other like 7z).
Anyway, unpack your blocklists and try again.


Just for completeness:

"pglcmd status" gives you the correct line to start pgld:

/usr/sbin/pgld -s -l /var/log/pgl/pgld.log -d -p /var/run/pgld.pid -q 92 -r 10 -a 20 /var/lib/pgl/master_blocklist.p2p
Please note that pgld depends on correctly inserted iptables rules (this is done by pglcmd on "pglcmd start". Only starting pgld will not work.

CAUTION: master_blocklist.p2p is generated automatically from all local blocklists and the remote lists specified in /etc/pgl/blocklists.list. Manually adding ranges may, if at all, just work for a short time.


But on the last step, installing the .deb file, the software center said it was a dummy package and being ignorant of what that meant, I didn't install it. I was trying to install this because of what I had read earlier in this thread and thought it might solve this problem.
This relates to the transitional packages moblock, blockcontrol and mobloquer/pgl-gui, which just install the real new packages pgld, pglcmd and pglgui.

Whitelisting ports (e.g. 80 and 443 outbound) is still a security risk, because malicious hosts might listen on these ports and thus circumvent pgl's protection.

lemwt
November 19th, 2012, 12:25 AM
Hi, and thank you for your response!


Unfortunately, it's still not working. I tried everything you suggested but it's just being real stubborn.


I should have mentioned earlier that I had tried using different types of compression as well as plain text documents.

When I click "Add a remote or local blocklist",
then "Browse",
then "All Supported files",
the extension list lists: P2P, Zip, 7z, Gzip and Dat.

I actually am not allowed to select a plain text file (or an extensionless file), to load.


I haven't given up but I'm out of ideas. After switching to 12.04 (precise) I've had so many other problems that it wouldn't surprise me at all if it had something with the operating system.


Thanks for the diligent effort to help and for always responding. Thank you for explaining what a dummy package is. I appreciate all the time you put very much!

jre
November 19th, 2012, 03:30 PM
pglgui needs some improvement for local blocklists.
E.g. pglgui is too strict about the allowed local blocklists. pglgui is just an extension for pgld/pglcmd - they allow using blocklists with any extension (as long as they are in a known format).
There also seem to be some issues with removing local blocklists. We are working on this.

Although the problems I know of are not related to your problems, please don't use pglgui to set your local blocklists for now.

So let's start fresh again:
Please be careful to exactly follow the following instructions (not more, not less) to avoid any misunderstandings.


sudo pglcmd stop

sudo pglcmd status. You should get the following output:

Run "status" as root to verify your iptables settings!

[FAIL] pgld is not running ... failed!
[FAIL] pglcmd.wd is not running ... failed!

verify that your /etc/pgl/blocklists.list does not contain any blocklist entries (so you are still using the same as in you posted previously in this 641 (http://ubuntuforums.org/showpost.php?p=12299279&postcount=641)
remove any files from /etc/pgl/blocklists.local/
create the file /etc/pgl/blocklists.local/test.p2p with the following content:

test:0.0.0.0-255.255.255.255
sudo pglcmd start

Now, everything should work and your whole internet access should be blocked. Start pglgui, it should show "Blocking 1 IP ranges (4294967295 IPs).

If not, do you use the current version? Please check
dpkg -l pgld pglcmd pglgui and update to 2.2.2-1.
If the update fails (due to your current problems), check the update for a hint how to solve it (something like "dpkg-reconfigure ...")

This setup really should work!

If not, please purge your whole installation (sudo aptitude purge pgld pglcmd pglgui) and try again with the default configuration (default remote blocklists, no local blocklists).




Now, if this works, please test with your own local blocklists one for one. If one doesn't load, please send it to me: jre-phoenix at users.sourceforge.net

lemwt
November 20th, 2012, 08:30 PM
HOORAY it works!



2012-11-19 14:20:06 PST End: pglcmd stop
2012-11-19 14:28:40 PST Begin: pglcmd start
Building blocklist ...
INFO: ASCII: 1 entries loaded from "STDIN"
INFO: Blocking 1 IP ranges (4294967295 IPs).
Blocklist built.


I did step 1-6 and that did it! And yes, I am using v2.2.2-1. I loaded all my blocklists uncompressed with .p2p extension and can see that each one was accepted in the log.

Thank you very much! Sorry, one more question:

I'd like to add my allow list now. Where or how should I add it?

jre
November 20th, 2012, 10:40 PM
Well, that was easy ;)
Seeing this whole story, I guess you were just hit by the problems in pglgui we just recently realized. pgld and pglcmd were not affected.


I'd like to add my allow list now. Where or how should I add it?

Per default /etc/pgl/allow.p2p is used for incoming and outgoing connections (you should not use it for forwarded connections, e.g. in routers/for virtual machines).
No support for that in pglgui yet ;)
And in the long run, there are major changes planned for this. But nothing to worry about now. And I will make the changes compatible to the current setup.

Greets and have fun

Patty X
February 11th, 2013, 03:54 PM
I've posted these questions on sourceforge already but the forum there seems to be deserted...

So I'll try my luck here:


1) Is there any difference (especially concerning security) between running pglgui as normal user (and using gksu/gksudo to actually start the filter) and running it directly as root?
I know that I should avoid to start applications as root, but pgl needs root's power to change iptables anyway...


2) How to update default lists in pgl? Does pgl update them on its own somehow, if so, is there some indicator that the lists are actually up-to date?

jre
February 14th, 2013, 12:39 AM
I've posted these questions on sourceforge already but the forum there seems to be deserted...

Just answered at
https://sourceforge.net/p/peerguardian/discussion/446996/thread/3c02fb52/ and
https://sourceforge.net/p/peerguardian/discussion/446996/thread/e1826b35/

btw, yes I'm quite busy and the others probably too. But we are still around and everybody is welcome to join.