Public bug reported: 1) Ubuntu 26.04 2) UFW 0.36.2 3) Maybe a script could be written to extract malicious ip addresses from AnyRun malware tracker and output it to a data file. The data file would be downloaded from the Ubuntu server and the file(owned by root to prevent modification) would add entries to the block list in the Ubuntu system firewall. Automatically block connections to malicious ip addresses. Add option to display notification if web browser, local script, app tries to connect to malicious ip addresses. Exploit kits could infect a user’s web browser, disable browser protections and then attempt a connection to a malicious ip address. The Ubuntu system firewall is isolated from the web browser. If the web browser attempts a connection to a malicious ip address, the system firewall would block it. This might help protect Ubuntu users against zero day web browser based threats.
Indicators of compromise for a RAT: https://any.run/malware-trends/asyncrat/ 4) No malicious ip address blocking. ** Affects: ufw (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2161677 Title: Feature Request: Malicious ip address notification/block To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ufw/+bug/2161677/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
