Gentoo Archives: gentoo-user

From: Walter Dnes <waltdnes@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] IPTABLES syntax change?
Date: Sun, 06 Jan 2013 21:57:15
Message-Id: 20130106215450.GB21848@waltdnes.org
In Reply to: Re: [gentoo-user] IPTABLES syntax change? by Mick
1 On Sat, Jan 05, 2013 at 11:57:10AM +0000, Mick wrote
2 >
3 > It will, but only partially. It seems that the list is long and it
4 > is getting longer and longer! Check this out:
5 >
6 > whois -h whois.radb.net -- '-i origin AS32934' | grep ^route
7 >
8 > (as advised by https://developers.facebook.com/docs/ApplicationSecurity/)
9
10 <ELVIS> Thank you, Thank you, Thank you verrry verrry much </ELVIS>
11
12 It's not as bad as it looks, because...
13 a) there's a lot of duplication
14 b) many of the blocks are subsets with a bigger Facebook block
15
16 31.13.24.0/21
17 inetnum: 31.13.24.0 - 31.13.31.255
18 netname: IE-FACEBOOK-20110418
19 descr: Facebook Ireland Ltd
20 country: IE
21
22 31.13.64.0/18
23 31.13.64.0/19
24 31.13.64.0/24
25 31.13.65.0/24
26 31.13.66.0/24
27 31.13.67.0/24
28 31.13.68.0/24
29 31.13.69.0/24
30 31.13.70.0/24
31 31.13.71.0/24
32 31.13.72.0/24
33 31.13.73.0/24
34 31.13.74.0/24
35 31.13.75.0/24
36 31.13.76.0/24
37 31.13.77.0/24
38 31.13.78.0/24
39 31.13.79.0/24
40 31.13.80.0/24
41 31.13.82.0/24
42 31.13.83.0/24
43 31.13.84.0/24
44 31.13.85.0/24
45 31.13.86.0/24
46 31.13.87.0/24
47 31.13.88.0/24
48 31.13.89.0/24
49 31.13.90.0/24
50 31.13.91.0/24
51 31.13.92.0/24
52 31.13.93.0/24
53 31.13.94.0/24
54 31.13.95.0/24
55 31.13.96.0/19
56 inetnum: 31.13.64.0 - 31.13.127.255
57 netname: IE-FACEBOOK-20110418
58 descr: Facebook Ireland Ltd
59 country: IE
60
61 66.220.144.0/20
62 66.220.144.0/20
63 66.220.144.0/21
64 66.220.152.0/21
65 66.220.159.0/24
66 NetRange: 66.220.144.0 - 66.220.159.255
67 CIDR: 66.220.144.0/20
68 OrgName: Facebook, Inc.
69 OrgId: THEFA-3
70
71 69.63.176.0/20
72 69.63.176.0/20
73 69.63.176.0/20
74 69.63.176.0/21
75 69.63.176.0/21
76 69.63.176.0/24
77 69.63.178.0/24
78 69.63.184.0/21
79 69.63.184.0/21
80 69.63.186.0/24
81 NetRange: 69.63.176.0 - 69.63.191.255
82 CIDR: 69.63.176.0/20
83 OrgName: Facebook, Inc.
84 OrgId: THEFA-3
85
86 69.171.224.0/19
87 69.171.224.0/20
88 69.171.239.0/24
89 69.171.240.0/20
90 69.171.253.0/24
91 69.171.255.0/24
92 NetRange: 69.171.224.0 - 69.171.255.255
93 CIDR: 69.171.224.0/19
94 OrgName: Facebook, Inc.
95 OrgId: THEFA-3
96
97 74.119.76.0/22
98 NetRange: 74.119.76.0 - 74.119.79.255
99 CIDR: 74.119.76.0/22
100 OrgName: Facebook, Inc.
101 OrgId: THEFA-3
102
103 103.4.96.0/22
104 inetnum: 103.4.96.0 - 103.4.99.255
105 netname: FACEBOOK-SG
106
107 173.252.64.0/18
108 173.252.64.0/19
109 173.252.70.0/24
110 173.252.96.0/19
111 NetRange: 173.252.64.0 - 173.252.127.255
112 CIDR: 173.252.64.0/18
113 OriginAS: AS32934
114 NetName: FACEBOOK-INC
115
116 204.15.20.0/22
117 204.15.20.0/22
118 NetRange: 204.15.20.0 - 204.15.23.255
119 CIDR: 204.15.20.0/22
120 OrgName: Facebook, Inc.
121 OrgId: THEFA-3
122
123 A grand total of 9 IPV4 ranges, of which I already have 6. Time for a
124 minor update. Thanks again for the whois lookup command.
125
126 > BTW, websites may break if you block all these ip ranges.
127
128 <LENNART> It's their fault that they're broken, not mine </LENNART>
129
130 --
131 Walter Dnes <waltdnes@××××××××.org>
132 I don't run "desktop environments"; I run useful applications