Christians Tagebuch

The latest posts in full-text for feed readers.


Android: Spam-Apps

Ein Familienmitglied hatte eine Taschenrechner-App auf seinem Androidtelefon installiert und rief ein paar Tage später um Hilfe.

Der Taschenrechner war eine Werbeschleuder, und irgendwie wurden noch 3 weitere Spam-Apps installiert - und zusammen zeigten sie alle paar Sekunden neue Werbebenachrichtigungen an.

Hier zwei Screenshots, wie die Benachrichtigungen auf dem Samsung-UI aussehen.

Benachrichtigungen #1 Benachrichtigungen #2

Antivirus Shield
WhatsApp-Datenmüll mit einem Klick für reibungslose Chats …
Bereinigen
Speicherplatz freigeben. G…
Bereinigen
Instant PDF Reader
Hidden Gem Found! Rediscov…
Open to Discover! Your PDFs h…
Bereinigun | Virenscan | App | Große
Bereit zum Lesen
Öffnen
Eine aktuelle PDF ist be…
Jetzt prüfen
Sparen Sie Speicher…
Löschen Sie Datenmüll …
Nicht jetzt | Löschen
WhatsApp-Datenmüll
Bereinigen

Lösung

Einstellungen > Apps, und dort alle unbekannten/ungewollten Programme deinstalliert.

Published on 2026-09-24 in


Skoda Octavia: 300.000 km

Nach 16 Jahren hat unser Familienauto einen Kilometerstand von genau 300.000 km erreicht.

Es ist ein Skoda Octavia 1.4 TSI mit 90 kW/122 PS (Benziner), Erstzulassung 2010-03.

Foto vom Kilometerzähler

Published on 2026-09-24 in


Doppelprodukte bei computeruniverse

Bei computeruniverse.net fiel mir heute bei der Recherche nach einem Laptop etwas Kurioses auf: Über die Listenansicht fand ich einen Laptop für 1.387,75€, über die Suchfunktion den exakt selben für 1.464,55€. Die Suche zeigte den günstigen nicht an.

Beide Detailseiten haben den gleichen Titel, die technischen Daten sind gleich (lediglich an einigen Stellen etwas anders geordnet). Die CU-eigene Artikelnummer ist unterschiedlich (GWNE-571 und GWN5-026), die Hersteller-Artikelnummer ist gleich (90NB14W4-M00FU0).

Sucht man nach der Hersteller-Artikelnummer, findet man nur das teurere Produkt. Die gefilterte und sortierte Listenansicht zeigt den teuren nicht an.

Laptop in günstiger - GWN5-026 Laptop in teuer - GWNE-571 Listenansicht Suchergebnisliste

Published on 2026-09-10 in


AI crawler attack

Last week I wanted to demo my Open DMARC Analyzer installation to my colleagues. I shared my browser window, entered the analyzer's URL and ... waited for 15 seconds. Clicking on links also took over 10 seconds.

Afterwards I checked other websites on my server and also found them unresponsive; they took more than 10 seconds to load - even static pages. Sometimes they didn't load at all and Firefox showed a "could not connect" error.

The server load was ok - around 300% on a 12 core system. Next I checked the web server's load and was overwhelmed: Apache's server-status page showed that of the 150 workers, 150 were busy.

Nearly all of them were fetching content from my git server:


root@ahso5:~> curl -s localhost/server-status | html2text
[...]
0-0  x 195/ R 0.70 0  0   309  0.0   0.66  0.66 176.236.195.170 http/1.1 git.cweiske.de:443
2-0  x 123/ R 0.57 0  0   331  0.0   0.66  0.66 a100:a08b:7a85: http/1.1 git.cweiske.de:443
4-0  x 94/  R 0.48 28 0   37   0.0   1.57  1.57 81:e464:5ff7:   http/1.1 git.cweiske.de:443
5-0  x 84/  R 0.49 0  0   767  0.0   0.67  0.67 e254:8545:2fa1: http/1.1 git.cweiske.de:443
6-0  x 79/  R 0.47 4  0   59   0.0   0.46  0.46 181.94.228.41   http/1.1 git.cweiske.de:443
9-0  x 64/  R 0.43 0  0   211  0.0   0.43  0.43 177.170.151.186 http/1.1 git.cweiske.de:443
10-0 x 94/  R 0.47 3  0   25   0.0   0.50  0.50 168.220.176.186 http/1.1 git.cweiske.de:443
11-0 x 99/  R 0.48 0  0   1055 0.0   0.52  0.52 560e:54ad:4599: http/1.1 git.cweiske.de:443
12-0 x 145/ R 0.59 0  0   652  0.0   0.89  0.89 181.54.0.0      http/1.1 git.cweiske.de:443
13-0 x 120/ R 0.50 27 0   44   0.0   0.67  0.67 188.30.63.72    http/1.1 git.cweiske.de:443
[...]
  

Disable git server

As first measure, I wanted to stop returning any content on my git server and decided to return "HTTP/1.1 402 Payment required" errors to all requests on that domain.

/etc/apache/sites-available/cweiske/git.cweiske.de.conf

<VirtualHost *:443>
    [...]
    ServerAdmin "fuckoff@ai.bots"
    RedirectMatch 402 "^"
    ErrorDocument 402 "Fuckoff, AI bots"
    ServerSignature Off
</VirtualHost>
  

The RedirectMatch alone showed a "internal server error" message to the browser. Adding the error document solved it.

Unfortunately, the problem was not solved - loading the error page was still slow, took more than 10 seconds or timed out. I had so many AI crawler bots attacking my server that even sending out the 1k "402" error response was not fast enough and saturated the 150 workers:

Munin: Apache processes, day view

More workers

To cope with the onslaught, I increased the workers from 150 to 512 with a config option:

/etc/apache2/conf-enabled/90-cweiske-workers.conf

MaxRequestWorkers 512
ServerLimit 512
  

This temporarily worked until...


root@ahso5:~> curl -s localhost/server-status | html2text
Current Time: Monday, 20-Apr-2026 15:13:53 CEST
Restart Time: Monday, 20-Apr-2026 15:01:06 CEST
Parent Server Config. Generation: 1
Parent Server MPM Generation: 0
Server uptime: 12 minutes 46 seconds
Server load: 1.51 1.49 1.04
Total accesses: 76795 - Total Traffic: 538.0 MB - Total Duration: 1199990
CPU Usage: u74.88 s62.19 cu73.39 cs58.62 - 35.1% CPU load
100 requests/sec - 0.7 MB/second - 7.2 kB/request - 15.6259 ms/request
512 requests currently being processed, 0 workers gracefully restarting, 0 idle workers

RRRRRRRRRRRRRRRRRCRRRRRRRRRCRRRRRRRRWRRRRRRRRRCRCRCRCCRRRCCRRRRC
RRRRCRRRRRRRRRCRCCRRRRRRRRRRRRRRRCRRCRRRRCRCRRRRRRCRRRRCRRCCRRRR
RRCRCCRRRRRRCRRRCCRRRRRRRRRRCRCRRRRRRRRRRRRCRCRCRRRCCRRRRRRCKRRC
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRKRRRRCRCRRRRCRRCCRCRRCRRRRRRRRR
CRRRRCRRRRRCCRRCRRRRRRRRRRCRCRCRRRRRRCRRCRRRRCRRRRRRRCRCRRRRRRRR
RCRRRRRRRRCRRCRRRRCRRRRRCCCKRCRRRKRRRKRRCRCRRRRCCRCRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRCRRRRCRRRRRRRRRRRRRRWRRRRRRRRRRRRCRRRRRRRCRRRRRR
RRRRKRRRRRRRRRRCRRRRRRRRCRCRRRRRRRRRCRCRRRRRRRRRRRRRRRRCRRRRRRCR
  

512 requests currently being processed. The bots adjusted and just requested more error responses!

Luckily this was only a spike; the number of parallel requests averaged between 200 and 300, 80 per second:


$ tail -f /var/log/apache2/cweiske/git.cweiske.de-access.log | pv --line-mode --rate > /dev/null
[80,2 /s]
  

After ~3 hours, the bot controller noticed that no sensible responses came back from my server and the requests fell back to the normal ~20 per second.

Clients

Looking at the awstats log analytics I saw that most of the clients only fetched a single URL and then vanished:

Number of visits
1,295,538
Hits
1,544,307

The "user-agent" header did not indicate bots: They masked as normal browsers from all kinds of common operating systems with current version numbers.

Throwing 20 IP addresses into Maxmind's GeoIP demo page showed:

  • Requests are from all over the world - USA, Germany, Brazil, Iraq, Chile, ...
  • All requests came from "Cable/DSL" connections.

That makes them impossible to block because you can't identify them.

Maxmind GeoIP list #1 Maxmind GeoIP list #2

Limiting requests to the git vhost

My main problem was the the other websites on my server were unreachable because the bots downloaded every single page from the git server. The best solution would be if I could limit the parallel requests on this vhost, so that enough would be free for the other domains.

Apache2 has no native support for that (v1 had), but I found mod_vhost_limit. Compiled it, configured it and now I only allow 10 parallel requests to my git server.

Traffic

In 2026-01, the git vhost had 2.25 GiB of traffic. The april number is 120 GiB, and the month still has 4 days.

awstats: year awstats: Month

The sad thing is: Those git repositories take 419 MiB on the hard disk. When using git clone to download them, it would take ~500 MiB to get all of them at once.

"AI" training data crawlers are dumb as hell, and their operators do not care that they waste resources and bring down servers one after the other.

When you work for one of those companies: I hate you.

Additional idea: Basic Auth for expensive pages

In 2026-05-15 my feed reader brought me this: Blocking DDoS from scraper bots the easy way via HTTP-401 Basic Auth .

I decided to implement that: Require a username and password for expensive pages like commit messages, diffs and file listings - but not for the other URL paths.

At first I created a htpasswd file:


$ htpasswd -bc /etc/apache2/git-dummy.htpasswd let mein
  

and then I used that for some URL paths:

/etc/apache2/sites-available/cweiske/git.cweiske.de

    [...]
    
        AuthType Basic
        AuthName "AI crawler block: Use let as username and mein as password."
        ErrorDocument 401 "AI crawler block: Use 'let' as username and 'mein' as password."
        AuthUserFile /etc/apache2/git-dummy.htpasswd
        Require valid-user
    
    [...]

]]>

It turns out that browsers do not show the text in the "AuthName" configuration anymore, which are sent to the client in the WWW-Authenticate header:

WWW-Authenticate: Basic realm="AI crawler block: Use let as username and mein as password."

This is the reason error page for status code 401 has to contain the same text.

Myriads of web server operators have the same problem.

The issue are residential proxies (RESIP):

Published on 2026-04-26 in ,


Brother ADS-1700W: Attachments not visible in MacOS Mail

I bought a Brother ADS-1700W document scanner, so I can fully utilize my Paperless-ngx installation.

When scanning a document and sending it as e-mail, Mail 16.0 on MacOS 12.6.9 does not show the attachment of the scanned PDF document. Thunderbird, Claws Mail and K-9 Mail properly show the attachment.

I suspected something wrong with the e-mail and indeed got errors on mimevalidator.net:

Byteplant MIMEValidator V1.2.5.2
Errors: linebreak found, MIME syntax violation
(line 1) linebreak found
(line 2) linebreak found
(line 3) linebreak found
(line 4) linebreak found
(...) parser error: too many bad linebreaks
(line 45) MIME syntax violation: ';' expected (name)
(line 45) MIME syntax violation: ';' expected (=)
(line 45) MIME syntax violation: ';' expected
(Scan_20230921_080714_000264.pdf)

I sent an e-mail to the Brother customer support (ADS-1700W is still supported) .. and they told me that on MacOS, only Thunderbird is supported.

My reply that the mail is invalid and that the scanner's firmware needs to be fixed by their developers were rejected. They did not even acknowledge the error; it seems their support staff did not even understand them.

Hierbei liegt kein Problem bei der Firmware Update und wie Sie schon von meinem Kohlegin informiert worden sind, wird bei macOS nur Thunderbird unterstützt, wenn Sie mit Ihrer MacOS Mailprogramm Probleme haben dann müssen Sie sich leider mit Apple in Verbindung setzen oder Thunderbird verwenden. Bezüglich der Validierungsfehler müssen Sie auch bei Apple nachfragen denn dieser Meldung ist leider nicht von dem Gerät.

Brother Support person, ticket 7001569466

Those bad spelling and grammatical errors were really in their email.

Mentioning the XKCD tech support keyword did not help :(

2026-08: Fixed with firmware 3.78

After three support tickets over the course of 4 years, the issue is finally fixed in firmware 3.78, released on 2026-03-18 as Version "T".

The mime validator now says:

Byteplant MIMEValidator V1.2.5.2
Check complete - no errors found.

Published on 2023-10-05 in ,


WiFi: Access point denied association

I tried to connect to a wireless LAN guest network on vacation and got this:

wpa_supplicant[1125]: wlp192s0: SME: Trying to authenticate with a6:91:b1:aa:bb:cc (SSID='Lundstorp 2.4GHz Guest' freq=2462 MHz)
kernel: wlp192s0: authenticate with a6:91:b1:aa:bb:cc (local address=84:9e:56:dd:ee:ff)
NetworkManager[1118]: <info>  [1786034818.9310] device (wlp192s0): supplicant interface state: scanning -> authenticating
NetworkManager[1118]: <info>  [1786034818.9311] device (p2p-dev-wlp192s0): supplicant management interface state: scanning -> authenticating
kernel: wlp192s0: send auth to a6:91:b1:aa:bb:cc (try 1/3)
wpa_supplicant[1125]: wlp192s0: Trying to associate with a6:91:b1:aa:bb:cc (SSID='Lundstorp 2.4GHz Guest' freq=2462 MHz)
NetworkManager[1118]: <info>  [1786034818.9358] device (wlp192s0): supplicant interface state: authenticating -> associating
NetworkManager[1118]: <info>  [1786034818.9358] device (p2p-dev-wlp192s0): supplicant management interface state: authenticating -> associating
kernel: wlp192s0: authenticated
kernel: wlp192s0: associate with a6:91:b1:aa:bb:cc (try 1/3)
kernel: wlp192s0: RX AssocResp from a6:91:b1:aa:bb:cc (capab=0x1431 status=17 aid=6)
kernel: wlp192s0: a6:91:b1:aa:bb:cc denied association (code=17)
wpa_supplicant[1125]: wlp192s0: CTRL-EVENT-ASSOC-REJECT bssid=a6:91:b1:aa:bb:cc status_code=17
wpa_supplicant[1125]: wlp192s0: SME: Deauth request to the driver failed
wpa_supplicant[1125]: wlp192s0: CTRL-EVENT-SSID-TEMP-DISABLED id=0 ssid="Lundstorp 2.4GHz Guest" auth_failures=1 duration=10 reason=CONN_FAILED
NetworkManager[1118]: <info>  [1786034819.0737] device (wlp192s0): supplicant interface state: associating -> disconnected
NetworkManager[1118]: <info>  [1786034819.0737] device (p2p-dev-wlp192s0): supplicant management interface state: associating -> disconnected
  

The problem was that the wifi router/access point had a limit of 4 guest devices. Once we disabled one of the mobile phones, my laptop could connect to the WLAN.

Published on 2026-08-20 in ,


Spamming with Google groups

Today I noticed a new way to send spam to many people: Google Groups, a mailing list platform.

In the last days I got many automatic replies from people and companies I don't know and never contacted: out-of-office reminders and "thank you, we will take care" mails.

The mails were sent to support@gh.onlinebildunchkeiten.de and all contained mailing list headers:

Precedence: list
Mailing-list: list phn@gh.onlinebildunchkeiten.de; contact phn+owners@gh.onlinebildunchkeiten.de
List-ID: <phn.gh.onlinebildunchkeiten.de>
X-Spam-Checked-In-Group: suppsdhsdksdhee@gh.onlinebildunchkeiten.de
X-Google-Group-Id: 320817839263
List-Post: <https://groups.google.com/a/gh.onlinebildunchkeiten.de/group/phn/post>,
    <mailto:phn@gh.onlinebildunchkeiten.de>
List-Help: <https://support.google.com/a/gh.onlinebildunchkeiten.de/bin/topic.py?topic=25838>,
    <mailto:phn+help@gh.onlinebildunchkeiten.de>
List-Archive: <https://groups.google.com/a/gh.onlinebildunchkeiten.de/group/phn/>
List-Subscribe: <https://groups.google.com/a/gh.onlinebildunchkeiten.de/group/support/subscribe>,
    <mailto:support+subscribe@gh.onlinebildunchkeiten.de>
List-Unsubscribe: <mailto:googlegroups-manage+320817839263+unsubscribe@googlegroups.com>,
    <https://groups.google.com/a/gh.onlinebildunchkeiten.de/group/phn/subscribe>

This was a Google group mailing list! And as usual with Google things, there was no way to report spam or abuse.

I imagine the process to be as follows:

  1. Spammer creates Google group and marks it as private
  2. Spammer adds hundreds of e-mail addresses to the list
  3. Spammer sends spam e-mails to the list
  4. People get the spam, and some mail servers send automated replies to the list - which all subscribed people receive as well.

The nice thing for spammers is that Google servers have good reputation and won't be blocked by administrators. This spam mails have a high chance of passing mail filters.

It is possible to unsubscribe from this spam list by sending an e-mail to a personalized e-mail address that you can find in the e-mail's List-Unsubscribe header. Make sure you send it from the same e-mail address it is sent to; that can be found in one of the Received headers :(

Unsubscribing

When sending an e-mail to the unsubscription address, a confirmation comes back with an image:

Unsubscription footer image from https://www.google.com/a/cpanel/vay.xylontrix.cfd/images/logo.gif?service=groups2

The text is written in thai (according to ChatGPT):

โรงเรียนบ้านปางสุด - Ban Pang Sut School
สพป.นครสวรรค์ เขต 2 - Nakhon Sawan Primary Educational Service Area Office 2

At least the text part is signed with vay.xylontrix.cfd admins. cfd is a valid top-level domain, and xylontrix.cfd is registered, according to the ICANN lookup tool.

More

It does not stop. I got subscribed to more spammer lists:

  • 2026-02-15: Two groups from imoney727[.]com, which suddenly had ex@jzglv[.]com as sender when unsubscribing.
  • 2026-02-21: One group from cdtuotu[.]com
  • 2026-03-05: Two groups from sibyl7253[.]com (xp + service)
  • 2026-03-05: One group from a6wine[.]com (support), but three(!) of my e-mails were subscribed to it.
  • 2026-03-19: Four groups but from 9 different domains: capturesoul[.]com, cosmoroyal[.]de, festbock[.]de, hotsurf[.]de, leysite[.]de, pharnisch[.]de, saycon[.]de, sfp888[.]com, softytools[.]de. Group names were de3, de5, ds2 and ds9. When unsubscribing from de5, I got the message that I unsubscribed from "bv".

    This time with an unsubscription image! According to ChatGPT the text means Onprachak School 'Phet Rian'.

    Unsubscription footer image from https://www.google.com/a/cpanel/bas.hotsurf.de/images/logo.gif?service=groups2

  • 2026-04-27: 12 groups from 6 domains in the last week: bwty-sports[.]com, hethbeauty[.]de, foodletter[.]de, techshoppro[.]de, ttitu[.]de, signtunes[.]de

    When unsubscribing, I got this for the first time for some of the lists:

    Address not found
    Your message wasn't delivered to googlegroups-manage+23+unsubscribe@googlegroups.com because the address couldn't be found, or is unable to receive mail.

    The response was:
    Failed to load suspended group domain

  • 2026-07: 7 groups in the last week: live-haixingapp[.]com, zhw-qiuyou[.]com, 0335boli[.]com, smkgjt[.]com, chinapipa[.]com, info-jnhsport[.]com, kboysw131419[.]com

Others

Other people also noticed that problem:

Published on 2025-10-09 in ,


Black textures in games with Wine

In 2026-01 I bought the game "Kao the Kangaroo" in its 2022 version on GoG, to play it with the kids. Unfortunately the game starts with mostly black textures, making it unplayable. I opened a bug report for Wine 11.

Fast forward half a year, and I found out that one of my beloved childhood games "Tony Hawk's Pro Skater 2" got a 2020 remake, dubbed "Tony Hawk's Pro Skater 1+2". I wanted to buy it, but it isn't available on GoG.

It is available on Steam, but to play you have to accept another EULA, and it has an "always online" check - even for local gameplay. That's a no-go for me, and so I did not buy it for 18€ - instead I got a backup without the always-online DRM and installed it.

Here again I got bitten by the black textures bug:

Tony Hawk 1+2 with black textures

Time to do something.

Hardware + Software

My PC runs Debian 12, mesa 22.3.6-1+deb12u1, wine-staging 11.10~bookworm-1 and Linux kernel 6.1.0-49-amd64. The graphics card is a Sapphire AMD Radeon RX 7600 Pulse 8GB.

Others

The only other mention of black textures was in 2020-10 on Reddit: Cyberpunk 2077 black textures. Their solution was to install the vulkan-radeon package that is only available for Arch Linux.

DXVK

Somewhere I read about DXVK, which provides a Direct3D Wine graphics library based on Vulkan instead of OpenGL.

I tried the latest 3.0.1 release, but that did not work - my Mesa 22.3.6 version is too old for that.

Instead I tried the last 2.x version 2.7.1, installed it in my game-specific wine prefix and that worked!

The game has proper textures now, and it plays awesome. I really wisth the developers/publisher would make it available without DRM on GoG - I'd instantly buy it.

Kao the Kangaroo could be fixed the same way!

Tony Hawk with proper textures, thanks to DXVK

nodcc

Looking at the mesa releases, I saw that in the next version 22.3.7 a bug was fixed:

radv: Prototype 2 black textures on RDNA 3 when DCC is enabled

DCC is "Delta Color Compression". The bug report says

Using RADV_DEBUG=nodcc fixes it.

but that didn't help in my case. Another report recommends

Some other environment variables worth trying are: radeonsi_zerovram=true and AMD_DEBUG=nodcc

but I didn't try that yet.

Published on 2026-07-15 in , ,


Mopedversicherung: Eigenverwendung

Bei einem Versicherungsanbieter steht folgendes in den Regeln:

Der Einsatz des Fahrzeuges erfolgt nur zur Eigenverwendung und nicht als Selbstfahrervermietfahrzeug.

Mir war nicht klar, ob "Eigenverwendung" nur mich persönlich oder auch andere Personen aus meinem Haushalt einschließt. Ich fragte den Support und bekam die Antwort:

Eigenverwendung bedeutet private Nutzung.

Als Selbstfahrervermietfahrzeug gelten Fahrzeuge, die gegen Entgelt an andere Personen vermietet werden.

Die Nutzung durch Ihre Frau und Ihren Sohn ist ohne weiteres möglich.

Published on 2026-07-17 in


Docker and ufw: Block IP addresses

This does not work anymore on 2026-07-06, and I did not investigate why.

At work I had to block some very annoying spammers from POSTing to the contact form on the website. I ssh'ed into the Ubuntu server and blocked their IP addresses with ufw:

$ ufw insert 1 deny from 203.17.245.205

Unfortunately, this did not work. The spammers were still able to access the nginx webserver in the Docker container:

203.17.245.205 - - [17/Apr/2025:11:58:28 +0200] "POST /contact HTTP/1.1" 200 24111 "https://example.org/contact" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51"

It turns out that Docker heavily uses iptables for its container networking, and that the rules in the default INPUT chain of the filter table that are generated by ufw are too late in the game - earlier rules already route the packets into the containers.

The iptables section in the Docker documentation tells us that rules need to be put into the DOCKER-USER chain:

$ iptables -I DOCKER-USER 1 -j DROP -s 203.17.245.205

In the end, the chain looked like this:

$ iptables -L DOCKER-USER --numeric --line-numbers
Chain DOCKER-USER (1 references)
num  target     prot opt source               destination
1    DROP       0    --  103.106.241.170      0.0.0.0/0
2    DROP       0    --  113.176.64.56        0.0.0.0/0
3    DROP       0    --  176.102.128.140      0.0.0.0/0
4    DROP       0    --  193.163.116.88       0.0.0.0/0
5    DROP       0    --  103.255.9.53         0.0.0.0/0
6    DROP       0    --  116.212.106.162      0.0.0.0/0
7    DROP       0    --  5.254.26.39          0.0.0.0/0
8    DROP       0    --  5.254.26.37          0.0.0.0/0
9    DROP       0    --  203.17.245.205       0.0.0.0/0
10   DROP       0    --  172.111.204.6        0.0.0.0/0
11   DROP       0    --  94.43.48.194         0.0.0.0/0
12   DROP       0    --  188.169.38.71        0.0.0.0/0
13   DROP       0    --  181.204.9.178        0.0.0.0/0
14   DROP       0    --  103.246.84.78        0.0.0.0/0
15   DROP       0    --  122.175.12.83        0.0.0.0/0
16   DROP       0    --  92.255.57.64         0.0.0.0/0
17   DROP       0    --  185.208.8.200        0.0.0.0/0
18   RETURN     0    --  0.0.0.0/0            0.0.0.0/0

Published on 2025-04-18 in