PDA

View Full Version : Bad Ip Ranges With Zonealarm



99shassan
01-19-2004, 02:30 PM
Does anyone know how to add bad ip ranges to my zonealarm pro? The ip ranges are from the peerguardian site. It gives me an option to get the ip ranges for ZA. It takes me to a website with a text box. How do I add these?

abu_has_the_power
01-19-2004, 03:12 PM
rite here:

finalized zapro 4 xml instructions:

if you don't have xmlspy dl http://www.xmlspy.com/

you're going to want to click settings> folder options> view and uncheck hide file
extensions for known file types- the reason is that you'll be changing xml files to text
and vice versa (easy- just rename with .txt instead of .xml etc)


1. First you need to backup your current zone alarm settings, which will create a file in the xml format.
To do this, go to: Overview=> Preferences=> and click the backup button. Call the file backup.
the file will now be saved as ‘backup.xml’ in the location where you saved it, by default it saves
in my documents.

2. Copy the zone alarm pro xml dump from this site. Here is the link:http://methlab.tech.nu/pg2zap.asp (it is up to date and includes the thumbs up ranges)

3. Then copy the list from the above link and then go to this site: www.bluetack.co.uk and click on Security Blocklist Converter . select convert from: zone alarm to zone alarm. It will organize the information in a such a way that its easier to see where to remove the unwanted stuff, but that comes later on.

4. Then open your backup.xml in notepad. Browse the file and you should come to point where it looks like this:
CODE

<file extension="MHT" active="true" description="Web Archive File"/>
</quarantine>
</attachments>
<outboundMail ompEnabled="true" mailEnabled="true" maxMailSent="5" recipientEnabled="true" maxRecipients="50" interval="2" senderEnabled="false" authorizedSenders="******@***.com"/>
</email>
<firewall>
<expert>
<groups> </groups> <rules>
<execute action="drop"/>
<source>

</source>
</rule>

</rules>
</expert>
</firewall>
<zones>
<trusted clearOldEntries="true" defaultNetworkStatus="ask" defaultAdapterMode="off">
</trusted>
<restricted clearOldEntries="true" defaultNetworkStatus="ask" defaultAdapterMode="off">
&#33;&#33;&#33;&#33;&#33;&#33;&#33;PASTE THE FILE FROM BLUETACK HERE&#33;&#33;&#33;&#33;&#33; (please note you may already have ips listed
here so just paste the data after the last ip entry

5. Then paste the zone alarm pro dump from the bluetack.co.uk site after its been converted
(important note- only copy and paste the ip data and NOT the following: before:
<zones><restricted clearOldEntries="false" defaultNetworkStatus="ask" defaultAdapterMode="off">
and after: </restricted></zones>
and paste it under the highlighted area.

6. Now save it and close it. And open it in XMLSPY. (there&#39;s no need to grant internet access
to this program for this)

7. Xmlspy will now tell you that the file is not well formed. the cursor will be in front of
the first character that needs to be deleted, simply erase the > and then click recheck-
you&#39;ll have to remove several > characters, then you come to C&D and you just delete the &
and click recheck...move on to more > and the you come to Audifon Chat & Play- here you need
to hit backspace twice- erasing the & and one space...now it says ok you you need to save-
pick a name that you&#39;ll know it&#39;s for the final restore- like finalxmlready

8. Everything should be good now. (To be on the safe side turn off your modem when you&#39;re
changing your firewall settings) just save it and go to: overview=>preferences=>and click
the restore button in the zone alarm firewall. Load the file finalxmlready.xml and it should
open a box saying loading, once its complete It should say that there were no problems.
Now you need to check if that’s true, by going to the firewall=>zone section where all the
rules should appear.


you&#39;re welcome

99shassan
01-19-2004, 04:34 PM
I check for "well-formedness" by pressing the yellow tick button on the top. It tells me that it is well formed. However, when I save it and try to restore teh settings. It tells me that it is not formated well. This is the code where I inputed the ip addresses



&#60;firewall&#62;
&nbsp; &#60;expert&#62;
&nbsp; &nbsp;&#60;groups&#62; &nbsp;&#60;/groups&#62;
&nbsp; &nbsp;&#60;rules&#62; &nbsp;&#60;/rules&#62;
&nbsp; &#60;/expert&#62;
&nbsp;&#60;/firewall&#62;
&nbsp;&#60;zones&#62;
&nbsp; &#60;trusted clearOldEntries=&#34;true&#34; defaultNetworkStatus=&#34;ask&#34; defaultAdapterMode=&#34;off&#34;&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;192.168.0.1&#34; toAddress=&#34;192.168.0.5&#34; status=&#34;true&#34; description=&#34;Internet Sharing&#34;/&#62;
&nbsp; &#60;/trusted&#62;
&nbsp; &#60;restricted clearOldEntries=&#34;true&#34; defaultNetworkStatus=&#34;ask&#34; defaultAdapterMode=&#34;off&#34;&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.18.55.144&#34; toAddress=&#34;4.18.55.151&#34; status=&#34;true&#34; description=&#34;EMI Music Publishing EMIMUSIC6-55-25&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.19.90.0&#34; toAddress=&#34;4.19.90.127&#34; status=&#34;true&#34; description=&#34;LionsGate Entertainment LIONS-90-10 &#40;NET-4-19-90-0-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.19.90.0&#34; toAddress=&#34;4.19.90.127&#34; status=&#34;true&#34; description=&#34;LionsGate Entertainment LIONS-90-10 &#40;NET-4-19-90-0-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.20.192.32&#34; toAddress=&#34;4.20.192.47&#34; status=&#34;true&#34; description=&#34;Animation Technologies, Inc. ANIMATIONTECH-192-05 &#40;NET-4-20-192-32-1&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.21.166.64&#34; toAddress=&#34;4.21.166.79&#34; status=&#34;true&#34; description=&#34;Animation Technologies, Inc. ANIMATIONTECH2-166-12 &#40;NET-4-21-166-64-1&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.21.179.32&#34; toAddress=&#34;4.21.179.63&#34; status=&#34;true&#34; description=&#34;COPYRIGHT CLEARANCE CENTER COPYRIGHT2-179-15&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.23.0.0&#34; toAddress=&#34;4.23.255.255&#34; status=&#34;true&#34; description=&#34;IRC spybots&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.36.109.0&#34; toAddress=&#34;4.36.109.255&#34; status=&#34;true&#34; description=&#34;Universal Studios Inc. UNIVORLANDO-109-24&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.42.208.16&#34; toAddress=&#34;4.42.208.23&#34; status=&#34;true&#34; description=&#34;EMI Music Publishing EMIMUSIC4-208-02&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.42.244.160&#34; toAddress=&#34;4.42.244.175&#34; status=&#34;true&#34; description=&#34;Federal Bureau of Investigation&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.42.244.192&#34; toAddress=&#34;4.42.244.223&#34; status=&#34;true&#34; description=&#34;Federal Bureau of Investigation&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.43.96.0&#34; toAddress=&#34;4.43.96.255&#34; status=&#34;true&#34; description=&#34;MediaForce&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.43.108.0&#34; toAddress=&#34;4.43.108.255&#34; status=&#34;true&#34; description=&#34;IRC spybots&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.43.124.192&#34; toAddress=&#34;4.43.124.255&#34; status=&#34;true&#34; description=&#34;MediaForce&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.47.144.0&#34; toAddress=&#34;4.47.255.255&#34; status=&#34;true&#34; description=&#34;GTE Intelligent Network Services&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.67.18.0&#34; toAddress=&#34;4.67.18.255&#34; status=&#34;true&#34; description=&#34;Screen Actors Guild SAG-18-28 &#40;NET-4-67-18-0-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;4.67.43.0&#34; toAddress=&#34;4.67.43.255&#34; status=&#34;true&#34; description=&#34;IRC spybots&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.17.172.8&#34; toAddress=&#34;12.17.172.15&#34; status=&#34;true&#34; description=&#34;Hollywood Entertainment HOLLYWOO128-172-8 &#40;NET-12-17-172-8-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.25.165.232&#34; toAddress=&#34;12.25.165.239&#34; status=&#34;true&#34; description=&#34;Hollywood Entertainment HOLLYWOO424-165-232 &#40;NET-12-25-165-232-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.29.112.0&#34; toAddress=&#34;12.29.112.15&#34; status=&#34;true&#34; description=&#34;Motion Picture Licensing Corp MPLC-112-0 &#40;NET-12-29-112-0-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.31.116.32&#34; toAddress=&#34;12.31.116.47&#34; status=&#34;true&#34; description=&#34;RADIX COMMUNICATIONS RADIX914-116-32 &#40;NET-12-31-116-32-1&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.35.253.176&#34; toAddress=&#34;12.35.253.183&#34; status=&#34;true&#34; description=&#34;SONY MUSIC ENTERTAINMENT SONY-MUS98-253-176&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.37.128.32&#34; toAddress=&#34;12.37.128.47&#34; status=&#34;true&#34; description=&#34;WARNER &nbsp;HOLLYWOOD STUDIO WARNER-128-32&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.37.128.128&#34; toAddress=&#34;12.37.128.255&#34; status=&#34;true&#34; description=&#34;WARNER &nbsp;HOLLYWOOD STUDIO WARNER-128-128&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.38.31.216&#34; toAddress=&#34;12.38.31.223&#34; status=&#34;true&#34; description=&#34;Federal Bureau of Investigation&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.40.85.0&#34; toAddress=&#34;12.40.85.255&#34; status=&#34;true&#34; description=&#34;NAMEPROTECT, INC NAMEPROTEC626-85 &#40;NET-12-40-85-0-1&#41;&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.45.230.96&#34; toAddress=&#34;12.45.230.127&#34; status=&#34;true&#34; description=&#34;COPYRIGHT CLEARANCE CENTER INC. COPYRIGH85-230-96&#34;/&#62;
&nbsp; &nbsp;&#60;iprange address=&#34;12.45.231.0&#34; toAddress=&#34;12.45.231.7&#34; status=&#34;true&#34; description=&#34;COPYRIGHT CLEARANCE CENTER INC. COPYRIGH23-231-0&#34;/&#62;


All the way to "</restricted></zones>"

Am I doing anything wrong? By the way there are entities
As you can see below:

http://www.geocities.com/hassanmiah/XML.jpg

Can you tell me what to do?

abu_has_the_power
01-19-2004, 04:41 PM
did u make sure u converted the rite file types?

99shassan
01-19-2004, 04:46 PM
Under options, Source format: Zonealarm v4 xml
Output format: Zonealarm v4 xml

Is that correct? Thats what I put.

abu_has_the_power
01-19-2004, 04:47 PM
Originally posted by 99shassan@19 January 2004 - 11:46
Under options, Source format: Zonealarm v4 xml
Output format: Zonealarm v4 xml

Is that correct? Thats what I put.
i think so. not sure. i ididn&#39;t ahve any probs with those instructions

fkdup74
01-19-2004, 04:55 PM
http://www.bluetack.co.uk/convert.html
this&#39;ll convert it for ya B)

if ya search that site theres also a resident proggie you can d/l
(but read up on it, i think i may remember reading
about em going through bug fixes for ZA&#39;s xml format)

99shassan
01-19-2004, 04:56 PM
Do you paste the source once, in your instructions you tell me to paste this twice (4. and 5.) I only pasted it once where you told me at 4.
Also, those entities, what do I do with those? I have zonealarm pro with web filtering (the latest one). I got the ip ranges from: http://methlab.tech.nu/

and then click ZApro4