Google
 

Monday, April 07, 2008

P2P IP Block List Using PeerGuardian 2

To help keep yourself safe when using P2P programs such as uTorrent, Limewire or any of the various BitTorrent/P2P programs I would suggest using Phoenix Lab's - PeerGuardian2.

When using P2P software, your computer makes a direct connection with the person you are downloading from, and since most of these applications force you to share your downloads the RIAA BPI etc can log on with various tools, obtain your IP address, and then serve a notice to your ISP asking for your details.

In addition to the RIAA etc, when downloading and sharing files this way, computers are vulnerable to unwanted downloads, spyware, viruses and having your IP address collected and harvested.

For those of you who are unfamiliar, an IP address is the numerical address assigned to each computer on the Internet - an easy way to think of it, is that your IP address is a little like your phone number. It is important to use IP blocking software that keeps lists of dangerous locations and prevents any connections to or from them.

A highly recommended application to use is PeerGuardian 2 which maintains a large block list of IP addresses known to contain bad downloads and other intrusions. These are updated daily. PG2 allows you to select each block list which you want to use.

If your using Windows Vista - there is an Alpha version of the software, and being Alpha, it does have the odd bug - but this can be downloaded from http://phrosty.phoenixlabs.org/pg2-rc1/

The set up for PeerGuardian is really easy, download the appropriate version, and follow the on screen instructions.

To add new block lists, do the following:

  1. Open PeerGuardian and click the 'Disable' button.
  2. Click 'List Manager'. This will open the list manager.
  3. Click the 'Add' button. This will open the Add List window. 
  4. Under 'Description' you can leave the text field blank
  5. Under 'Location' click the 'Add URL:' option and enter the address of the blocklist in the text field.
  6. Under 'Type' make sure 'Block' is selected and NOT 'Allow'
  7. Click 'OK'
  8. Close the 'List Manager' window.
  9. Click the 'Check Updates' button if the lists are not updated automatically.
  10. Click the 'Enable' button to re-enable PeerGuardian after updating.

I have my own block list which I have put together through various sources this can be found at:

http://spreadsheets.google.com/pub?key=pz4C1TUYPZERCgc2C59DkNA

I additionally have my own "allow" list which can be found at:

http://spreadsheets.google.com/pub?key=pz4C1TUYPZESB2gsV56z7Fw

I would also suggest adding the following lists. Each one needs to be added one at a time by repeating steps 3 through 7 for each one:

  • http://www.sublimestylee.com/other/mpa_trackers.p2p 
  • http://www.bluetack.co.uk/config/ads-trackers-and-bad-pr0n.gz
  • http://www.bluetack.co.uk/config/dshield.zip
  • http://www.bluetack.co.uk/config/edu.gz
  • http://www.bluetack.co.uk/config/fornonlancomputers.zip
  • http://www.bluetack.co.uk/config/hijacked.zip
  • http://www.bluetack.co.uk/config/level1.gz
  • http://www.bluetack.co.uk/config/level2.gz
  • http://www.bluetack.co.uk/config/spider.gz
  • http://www.bluetack.co.uk/config/spyware.gz
  • http://www.bluetack.co.uk/config/trojan.zip
  • http://www.bluetack.co.uk/config/bogon.zip

2 comments:

S1ndr0me said...

Good post,

I use peer guardian but am still concerned as to whether it contains the i.p's we need to have blocked here in the uk i.e. bpi ranges?

Also whats to stop a BPI employee just running the honeypot from outside of the company?

Paul James said...

I believe that peer guardians default block lists actually cover the BPI and RIAA, so I would assume they would be a start.

Your right, there is nothing to stop an employee from tracking outside of their network, the same applies with all PeerGuardian models.

The general feeling I get when reading reviews etc is that because IP ranges are so expensive, and in demand, and becuase of the logging equipment used it is generally done on an internal network.