Ufw Blocklist

IP blocklist extension for Ubuntu ufw firewall

Cybersecurity & Ethical HackingShellGPL-3.0

Abstract

Ufw Blocklist is an open-source Cybersecurity & Ethical Hacking project. IP blocklist extension for Ubuntu ufw firewall. Add an IP blocklist to ufw, the uncomplicated Ubuntu firewall. It is built using Shell. The complete source code is publicly available on GitHub under the GNU General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Add an IP blocklist to ufw, the uncomplicated Ubuntu firewall

2. Objective

IP blocklist extension for Ubuntu ufw firewall

This project demonstrates how Shell can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Shell

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Linux / macOS terminal or WSL on Windows
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/poddmo/ufw-blocklist.git
cd ufw-blocklist
  1. The status option shows the count of entries in the blocklist, the hit count of packets that have been blocked and the last 10 log entries. The status option is further explained in the Status section below.
  2. The flush-all option deletes all entries in the blocklist and zeros the iptables hit counters:
sudo apt install ipset
sudo cp /etc/ufw/after.init /etc/ufw/after.init.orig
git clone https://github.com/poddmo/ufw-blocklist.git
cd ufw-blocklist
sudo cp after.init /etc/ufw/after.init
sudo cp ufw-blocklist-ipsum /etc/cron.daily/ufw-blocklist-ipsum
sudo chown root:root /etc/ufw/after.init /etc/cron.daily/ufw-blocklist-ipsum
sudo chmod 750 /etc/ufw/after.init /etc/cron.daily/ufw-blocklist-ipsum
curl -sS -f --compressed -o ipsum.4.txt 'https://raw.githubusercontent.com/stamparm/ipsum/master/levels/4.txt'
sudo chmod 640 ipsum.4.txt
sudo cp ipsum.4.txt /etc/ipsum.4.txt

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by poddmo and published on GitHub under the GNU General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship