chg: Add ip-src|dst and ip-dst|port as matching attr types to cidr lists

pull/270/head
Jeroen Pinoy 2024-04-22 09:20:14 +02:00
parent fcbcf65795
commit e48c2539c2
50 changed files with 155 additions and 88 deletions

View File

@ -273,9 +273,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Akamai IP ranges", "name": "List of known Akamai IP ranges",
"type": "cidr", "type": "cidr",
"version": 20210613 "version": 20240422
} }

View File

@ -2669,9 +2669,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Amazon AWS IP address ranges", "name": "List of known Amazon AWS IP address ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -6,9 +6,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Apple IP ranges", "name": "List of known Apple IP ranges",
"type": "cidr", "type": "cidr",
"version": 20210610 "version": 20240422
} }

View File

@ -25,11 +25,13 @@
"2c0f:f248::/32" "2c0f:f248::/32"
], ],
"matching_attributes": [ "matching_attributes": [
"ip-dst",
"ip-src", "ip-src",
"domain|ip" "ip-dst",
"domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Cloudflare IP ranges", "name": "List of known Cloudflare IP ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -260,9 +260,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "CRL and OCSP IP addresses", "name": "CRL and OCSP IP addresses",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -24,9 +24,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Fastly IP address ranges", "name": "List of known Fastly IP address ranges",
"type": "cidr", "type": "cidr",
"version": 20201106 "version": 20240422
} }

View File

@ -304,9 +304,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known GCP (Google Cloud Platform) IP address ranges", "name": "List of known GCP (Google Cloud Platform) IP address ranges",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -32,9 +32,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Gmail sending IP ranges", "name": "List of known Gmail sending IP ranges",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -71,9 +71,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)", "name": "List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240402
} }

View File

@ -205,9 +205,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Microsoft Azure China Datacenter IP Ranges", "name": "List of known Microsoft Azure China Datacenter IP Ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -41,9 +41,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Microsoft Azure Germany Datacenter IP Ranges", "name": "List of known Microsoft Azure Germany Datacenter IP Ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -181,9 +181,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Microsoft Azure US Government Cloud Datacenter IP Ranges", "name": "List of known Microsoft Azure US Government Cloud Datacenter IP Ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -2416,9 +2416,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Microsoft Azure Datacenter IP Ranges", "name": "List of known Microsoft Azure Datacenter IP Ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -78,9 +78,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Office 365 IP address ranges in China", "name": "List of known Office 365 IP address ranges in China",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -89,9 +89,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Office 365 IP address ranges", "name": "List of known Office 365 IP address ranges",
"type": "cidr", "type": "cidr",
"version": 20240418 "version": 20240422
} }

View File

@ -21,9 +21,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of RFC 5771 multicast CIDR blocks", "name": "List of RFC 5771 multicast CIDR blocks",
"type": "cidr", "type": "cidr",
"version": 3 "version": 4
} }

View File

@ -7,9 +7,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known IP address ranges for OpenAI GPT crawler bot", "name": "List of known IP address ranges for OpenAI GPT crawler bot",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -436,9 +436,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Ovh Cluster IP", "name": "List of known Ovh Cluster IP",
"type": "cidr", "type": "cidr",
"version": 20180222 "version": 20240422
} }

View File

@ -105,11 +105,13 @@
"99.83.154.118/32" "99.83.154.118/32"
], ],
"matching_attributes": [ "matching_attributes": [
"domain|ip", "ip-src",
"ip-dst", "ip-dst",
"ip-src" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "Parking domains", "name": "Parking domains",
"type": "cidr", "type": "cidr",
"version": 20221024 "version": 20240422
} }

View File

@ -62745,9 +62745,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known IPv4 public DNS resolvers", "name": "List of known IPv4 public DNS resolvers",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -267,9 +267,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known IPv6 public DNS resolvers", "name": "List of known IPv6 public DNS resolvers",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -111,9 +111,12 @@
], ],
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst" "ip-dst",
"domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known sinkholes", "name": "List of known sinkholes",
"type": "cidr", "type": "cidr",
"version": 1 "version": 2
} }

View File

@ -261,9 +261,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known SMTP receiving IP addresses", "name": "List of known SMTP receiving IP addresses",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -926,9 +926,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known SMTP sending IP ranges", "name": "List of known SMTP sending IP ranges",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -250,11 +250,13 @@
"98.190.94.128/25" "98.190.94.128/25"
], ],
"matching_attributes": [ "matching_attributes": [
"ip-dst",
"ip-src", "ip-src",
"domain|ip" "ip-dst",
"domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Stackpath CDN IP ranges", "name": "List of known Stackpath CDN IP ranges",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -44,9 +44,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Tenable Cloud Sensors IPv4", "name": "List of known Tenable Cloud Sensors IPv4",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -22,9 +22,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Tenable Cloud Sensors IPv6", "name": "List of known Tenable Cloud Sensors IPv6",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -11,9 +11,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "cisco-umbrella-blockpage-ipv4", "name": "cisco-umbrella-blockpage-ipv4",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -11,9 +11,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "cisco-umbrella-blockpage-ipv6", "name": "cisco-umbrella-blockpage-ipv6",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -24048,9 +24048,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters", "name": "Specialized list of vpn-ipv4 addresses belonging to common VPN providers and datacenters",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -1255,9 +1255,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "Specialized list of IPv6 addresses belonging to common VPN providers and datacenters", "name": "Specialized list of IPv6 addresses belonging to common VPN providers and datacenters",
"type": "cidr", "type": "cidr",
"version": 20220324 "version": 20240422
} }

View File

@ -67,9 +67,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Wikimedia address ranges", "name": "List of known Wikimedia address ranges",
"type": "cidr", "type": "cidr",
"version": 20240405 "version": 20240422
} }

View File

@ -71,9 +71,11 @@
"matching_attributes": [ "matching_attributes": [
"ip-src", "ip-src",
"ip-dst", "ip-dst",
"domain|ip" "domain|ip",
"ip-src|port",
"ip-dst|port"
], ],
"name": "List of known Zscaler IP address ranges", "name": "List of known Zscaler IP address ranges",
"type": "cidr", "type": "cidr",
"version": 20230810 "version": 20240422
} }

View File

@ -72,7 +72,7 @@ if __name__ == '__main__':
'description': 'Akamai IP ranges from BGP search', 'description': 'Akamai IP ranges from BGP search',
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(networks), 'list': consolidate_networks(networks),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, "akamai") write_to_file(warninglist, "akamai")

View File

@ -23,7 +23,7 @@ def process(file, dst):
'description': 'Amazon AWS IP address ranges (https://ip-ranges.amazonaws.com/ip-ranges.json)', 'description': 'Amazon AWS IP address ranges (https://ip-ranges.amazonaws.com/ip-ranges.json)',
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(l), 'list': consolidate_networks(l),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, dst) write_to_file(warninglist, dst)

View File

@ -20,7 +20,7 @@ def process(file, dst):
'description': 'check-host IP addresses (https://check-host.net/nodes/ips)', 'description': 'check-host IP addresses (https://check-host.net/nodes/ips)',
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(l), 'list': consolidate_networks(l),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, dst) write_to_file(warninglist, dst)

View File

@ -11,7 +11,7 @@ def process(files, dst):
'description': "List of known Cloudflare IP ranges (https://www.cloudflare.com/ips/)", 'description': "List of known Cloudflare IP ranges (https://www.cloudflare.com/ips/)",
'type': "cidr", 'type': "cidr",
'list': [], 'list': [],
'matching_attributes': ["ip-dst", "ip-src", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
for file in files: for file in files:

View File

@ -99,7 +99,7 @@ def process(file):
'version': get_version(), 'version': get_version(),
'description': 'IP addresses that belongs to CRL or OCSP', 'description': 'IP addresses that belongs to CRL or OCSP',
'list': get_ips_from_domains(crl_ocsp_domains), 'list': get_ips_from_domains(crl_ocsp_domains),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
} }
write_to_file(warninglist, "crl-ip") write_to_file(warninglist, "crl-ip")

View File

@ -15,7 +15,7 @@ if __name__ == '__main__':
'name': 'List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)', 'name': 'List of known Googlebot IP ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)',
'version': get_version(), 'version': get_version(),
'description': "Google Bot IP address ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)", 'description': "Google Bot IP address ranges (https://developers.google.com/search/apis/ipranges/googlebot.json)",
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(ranges), 'list': consolidate_networks(ranges),
} }

View File

@ -15,7 +15,7 @@ if __name__ == '__main__':
'name': "List of known GCP (Google Cloud Platform) IP address ranges", 'name': "List of known GCP (Google Cloud Platform) IP address ranges",
'version': get_version(), 'version': get_version(),
'description': "GCP (Google Cloud Platform) IP address ranges (https://www.gstatic.com/ipranges/cloud.json)", 'description': "GCP (Google Cloud Platform) IP address ranges (https://www.gstatic.com/ipranges/cloud.json)",
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(ranges), 'list': consolidate_networks(ranges),
} }

View File

@ -9,7 +9,7 @@ if __name__ == '__main__':
'name': "List of known Gmail sending IP ranges", 'name': "List of known Gmail sending IP ranges",
'version': get_version(), 'version': get_version(),
'description': "List of known Gmail sending IP ranges (https://support.google.com/a/answer/27642?hl=en)", 'description': "List of known Gmail sending IP ranges (https://support.google.com/a/answer/27642?hl=en)",
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(spf.get_ip_ranges_from_spf("gmail.com")), 'list': consolidate_networks(spf.get_ip_ranges_from_spf("gmail.com")),
} }

View File

@ -19,7 +19,7 @@ def process(file, dst):
'description': 'OpenAI gptbot crawler (https://openai.com/gptbot-ranges.txt)', 'description': 'OpenAI gptbot crawler (https://openai.com/gptbot-ranges.txt)',
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(l), 'list': consolidate_networks(l),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, dst) write_to_file(warninglist, dst)

View File

@ -20,7 +20,7 @@ def process(file, dst, name: str, description: str):
'name': name, 'name': name,
'version': get_version(), 'version': get_version(),
'description': description, 'description': description,
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr' 'type': 'cidr'
} }

View File

@ -23,7 +23,7 @@ def process(url):
'name': 'List of known Office 365 IP address ranges', 'name': 'List of known Office 365 IP address ranges',
'description': 'Office 365 IP address ranges', 'description': 'Office 365 IP address ranges',
'type': 'cidr', 'type': 'cidr',
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
generate(consolidate_networks(lips), office365_ips_dst, office365_ips_warninglist) generate(consolidate_networks(lips), office365_ips_dst, office365_ips_warninglist)
@ -65,6 +65,6 @@ if __name__ == '__main__':
'name': 'List of known Office 365 IP address ranges in China', 'name': 'List of known Office 365 IP address ranges in China',
'description': 'Office 365 IP address ranges in China', 'description': 'Office 365 IP address ranges in China',
'type': 'cidr', 'type': 'cidr',
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
generate(consolidate_networks(lips), "microsoft-office365-cn", warninglist) generate(consolidate_networks(lips), "microsoft-office365-cn", warninglist)

View File

@ -79,7 +79,7 @@ if __name__ == '__main__':
'name': "List of known SMTP sending IP ranges", 'name': "List of known SMTP sending IP ranges",
'version': get_version(), 'version': get_version(),
'description': "List of IP ranges for known SMTP servers.", 'description': "List of IP ranges for known SMTP servers.",
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(spf_ranges), 'list': consolidate_networks(spf_ranges),
} }
@ -93,7 +93,7 @@ if __name__ == '__main__':
'name': "List of known SMTP receiving IP addresses", 'name': "List of known SMTP receiving IP addresses",
'version': get_version(), 'version': get_version(),
'description': "List of IP addresses for known SMTP servers.", 'description': "List of IP addresses for known SMTP servers.",
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr', 'type': 'cidr',
'list': map(str, mx_ips), 'list': map(str, mx_ips),
} }

View File

@ -74,7 +74,7 @@ def process(files, dst):
'description': "List of known Stackpath (Highwinds) CDN IP ranges (https://support.stackpath.com/hc/en-us/articles/360001091666-Whitelist-CDN-WAF-IP-Blocks)", 'description': "List of known Stackpath (Highwinds) CDN IP ranges (https://support.stackpath.com/hc/en-us/articles/360001091666-Whitelist-CDN-WAF-IP-Blocks)",
'type': "cidr", 'type': "cidr",
'list': [], 'list': [],
'matching_attributes': ["ip-dst", "ip-src", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
for file in files: for file in files:

View File

@ -10,7 +10,7 @@ def process(file, dst, name: str, description: str, prefixlist: str, prefixitem:
'name': name, 'name': name,
'version': get_version(), 'version': get_version(),
'description': description, 'description': description,
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"], 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"],
'type': 'cidr' 'type': 'cidr'
} }

View File

@ -11,7 +11,7 @@ def process(url, dst):
'description': 'Specialized list of {} addresses belonging to common VPN providers and datacenters'.format(dst), 'description': 'Specialized list of {} addresses belonging to common VPN providers and datacenters'.format(dst),
'list': consolidate_networks(process_stream(url)), 'list': consolidate_networks(process_stream(url)),
'type': 'cidr', 'type': 'cidr',
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, dst) write_to_file(warninglist, dst)

View File

@ -15,7 +15,7 @@ def process(url, dst):
'description': 'Wikimedia address ranges (http://noc.wikimedia.org/conf/reverse-proxy.php.txt)', 'description': 'Wikimedia address ranges (http://noc.wikimedia.org/conf/reverse-proxy.php.txt)',
'type': 'cidr', 'type': 'cidr',
'list': [], 'list': [],
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
matched = re.findall( matched = re.findall(

View File

@ -20,7 +20,7 @@ def process(file, dst):
'description': 'Zscaler IP address ranges (https://config.zscaler.com/api/zscaler.net/hubs/cidr/json/required)', 'description': 'Zscaler IP address ranges (https://config.zscaler.com/api/zscaler.net/hubs/cidr/json/required)',
'type': 'cidr', 'type': 'cidr',
'list': consolidate_networks(l), 'list': consolidate_networks(l),
'matching_attributes': ["ip-src", "ip-dst", "domain|ip"] 'matching_attributes': ["ip-src", "ip-dst", "domain|ip", "ip-src|port", "ip-dst|port"]
} }
write_to_file(warninglist, dst) write_to_file(warninglist, dst)