Looking for testers Q-Feeds plugin

Started by Q-Feeds, October 01, 2025, 08:43:40 PM

Previous topic - Next topic
Quote from: Q-Feeds on October 16, 2025, 02:26:28 PMHere you can find the latest package with the bug fixes for Unbound and the Events page

Both fixes work as intended, thanks!

(In the Unbound settings, I had to reapply the DNSBLs and restart the service for it to merge and load the lists.)
OPNsense virtual machine images
OPNsense aarch64 firmware repository

Commercial support & engineering available. PM for details (en / de).

October 17, 2025, 03:09:19 PM #241 Last Edit: October 17, 2025, 03:11:48 PM by Lurick
Did the feeds get messed up?
At about 8:45am EST QFeeds started blocking EVERYTHING on my network out of nowhere.
I had to disable the firewall rules to regain connectivity.

Quote from: Lurick on October 17, 2025, 03:09:19 PMDid the feeds get messed up?
At about 8:45am EST QFeeds started blocking EVERYTHING on my network out of nowhere.
I had to disable the firewall rules to regain connectivity.

That's severe! Can you share some logs? Which blocks have been registered?

Your Threat Intelligence Partner  qfeeds.com

Quote from: Q-Feeds on October 17, 2025, 03:13:39 PM
Quote from: Lurick on October 17, 2025, 03:09:19 PMDid the feeds get messed up?
At about 8:45am EST QFeeds started blocking EVERYTHING on my network out of nowhere.
I had to disable the firewall rules to regain connectivity.

That's severe! Can you share some logs? Which blocks have been registered?


Just reverted the set (temporary) from a few hours ago, yet I'm not able to reproduce your problem without a bit more information. If you pull the list now it should solve.

Your Threat Intelligence Partner  qfeeds.com

October 17, 2025, 03:28:52 PM #244 Last Edit: October 17, 2025, 03:45:49 PM by Lurick
Quote from: Q-Feeds on October 17, 2025, 03:13:39 PM
Quote from: Lurick on October 17, 2025, 03:09:19 PMDid the feeds get messed up?
At about 8:45am EST QFeeds started blocking EVERYTHING on my network out of nowhere.
I had to disable the firewall rules to regain connectivity.

That's severe! Can you share some logs? Which blocks have been registered?


It seemed to be blocking everything outbound from the LAN interface, from 192.168.0.0/16
Which logs should I collect to help narrow this down?

October 17, 2025, 03:34:57 PM #245 Last Edit: October 17, 2025, 03:44:58 PM by Lurick



Quote from: Lurick on October 17, 2025, 03:34:57 PM



Thx! Still investigating but can't seem to find any RFC IOCs in our list. Which shouldn't either of course!

Your Threat Intelligence Partner  qfeeds.com

October 17, 2025, 04:28:07 PM #247 Last Edit: October 17, 2025, 04:45:32 PM by Seimus
Hey guys,

Can you tell me why did you pushed into your TI subnets

0.0.0.0/1
64.0.0.0/2

This caused a huge network outage and blocked everything..
This as well caused the issues described above...

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD

We've learned a valuable lesson just now. One of our premium suppliers pushed two IP Adresses into our list:

64.52.80.21/2
64.52.80.21/1

We do have several filters to filter False Positives and RFC related stuff. Unfortunately we were not prepared for IOCs as shown above.
As you've already experienced this caused a major disruption. We're really sorry for it, and obviously we'll take extensive measures to prevent this in the future.

Thank you very much for letting us know, it helps us to react quickly and improve our services. Once more very sorry for the disruption it has caused!

Your Threat Intelligence Partner  qfeeds.com

This was nasty,

Please be careful with such things pushing into TIs. As this is one of the things that should NEVER HAPPEN.

Also keep in mind not many users are able to restore their connectivity using the console. So this could result into a hard-lock.

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD

Quote from: Seimus on October 17, 2025, 05:01:50 PMThis was nasty,

Please be careful with such things pushing into TIs. As this is one of the things that should NEVER HAPPEN.

Also keep in mind not many users are able to restore their connectivity using the console. So this could result into a hard-lock.

Regards,
S.

Can't agree more! And thank you for staying polite... ;-) This was a huge one and we promise take measures against it!

Your Threat Intelligence Partner  qfeeds.com

Quote from: Q-Feeds on October 17, 2025, 05:08:58 PMCan't agree more! And thank you for staying polite... ;-) This was a huge one and we promise take measures against it!

Indeed there is no reason to be rude, my comment was in good will, so I am glad it didn't sounded like I am going to burn a farm.

Can happen to anyone, there is saying we like to use in work;
Quote"Trust but verify."
          - Bunch of tired engineers

Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD

Quote from: Seimus on October 17, 2025, 05:16:15 PM
Quote from: Q-Feeds on October 17, 2025, 05:08:58 PMCan't agree more! And thank you for staying polite... ;-) This was a huge one and we promise take measures against it!

Indeed there is no reason to be rude, my comment was in good will, so I am glad it didn't sounded like I am going to burn a farm.

Can happen to anyone, there is saying we like to use in work;
Quote"Trust but verify."
          - Bunch of tired engineers


Haha you're absolutely right, but I can imagine some nasty words came up your mind when this happend.. ;)
That said it was panic on our side as you can imagine and we might put that saying up on our wall :D

Your Threat Intelligence Partner  qfeeds.com

Quote from: Q-Feeds on October 17, 2025, 05:18:57 PMHaha you're absolutely right, but I can imagine some nasty words came up your mind when this happend.. ;)

It was more of an initial surprise "wtf did I do this time" cause I am lately doing a lot of implementations

Quote from: Q-Feeds on October 17, 2025, 05:18:57 PMThat said it was panic on our side as you can imagine and we might put that saying up on our wall :D
Feel free :), if nothing at least some fun.

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD

Quick question and two requests.

I try to access the main q-feeds page to access the account https://qfeeds.com/my-account (not speaking about TIP). But its not working getting Error 406.
Same happens now for some reason for https://qfeeds.com. TIP works okay.


R1: The subscription management looks like is on a different system from TIP. Would not be it better if subscription management is handled as well from the TIP?
As the license is there anyway?

R2: When we have multiples API keys, checking the API logs from TIP does not clearly state what API key did what. There is a key ID but that ID isnt clearly showing which key is which. Would it be possible for that specific ID associate the Description? Or include that ID in the API key management.

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD