Banning entire countries?
Recently, I've been having major problems with zombie computers from a Russian ISP doing a lot of comment spamming. This has occupied a very large segment of my time across the last week, resulting in a very tired and very fed-up sysadmin.
Ordinarily, such spammers are comparatively polite; they hammer you from one or two IP addresses, which, when you block them, they move on.
Not these guys. Near as I can tell, they've got control of a large part of the entire Caravan.ru IP block(s), because everytime I'd ban an individual IP, or even an IP range, using hosts.deny or iptables, they'd just pop right back up on another IP range.
Caravan.ru seems to use a lot of non-consecutive IP ranges, which has made my work considerably more difficult. So, I decided just to ban Russia altogether for a few days. Here's the tool I used: [link]
