Difference between revisions of "WAF 350000"
m |
m |
||
Line 15: | Line 15: | ||
'''False Positives''' | '''False Positives''' | ||
− | There are no known False Positives for this, however if you believe this is a false positive, it is recommended that you report this to the spamhaus project. '''Atomicorp does not run this RBL, and therefore can address false positives with IPs.''' You can access their website here: | + | There are no known False Positives for this, however if you believe this is a false positive, it is recommended that you report this to the spamhaus project. '''Atomicorp does not run this RBL, and therefore can not address false positives with IPs.''' You can access their website here: |
http://www.spamhaus.org/xbl/ | http://www.spamhaus.org/xbl/ |
Revision as of 14:17, 1 September 2011
Rule ID
350000
Alert Message
Global RBL Match: IP is on the xbl.spamhaus.org Blacklist
Description
This rules detects that an IP address connecting to your server is listed on the xbl.spamhaus.org blacklist run by the SpamHaus project. They describe this RBL as:
"The Spamhaus Exploits Block List (XBL) is a realtime database of IP addresses of hijacked PCs infected by illegal 3rd party exploits, including open proxies (HTTP, socks, AnalogX, wingate, etc), worms/viruses with built-in spam engines, and other types of trojan-horse exploits."
False Positives
There are no known False Positives for this, however if you believe this is a false positive, it is recommended that you report this to the spamhaus project. Atomicorp does not run this RBL, and therefore can not address false positives with IPs. You can access their website here:
Similar Rules
Outside References