we have listen 13410 IP's now.
useful Links
- www.fail2ban.org
- Example Configuration (Vers. 0.8.4)
- X-Arf-Validator
- The Global Reporting Project
- Example Report (ssh, again)
- stopforumspam.com
- c-sirt.org
N e w s:
26.03.2013All IPs and Services works fine again.
25.03.2013
The web server has some problems which could be resolved after several hours in some cases.
However, we will once again need more hours to solve all outstanding issues. It may therefore still times to failure of the web server (api, www, lists) to come. The RBL servers and mail servers are not affected.
21.12.2012
X-ARF-Validator updated with Value-Validator: online X-ARF-Reports validieren
27.01.2012
X-ARF-Validator fixed and online
05.11.2011
The Spamer register Accounts in other Forums and Blogs with @blocklist.de This User/Comments are not from blocklist.de! Please create a Police Report against the spaming IP!
04.08.2010
The IP-Lists are now included in www.ipvoid.com.
PC infected / slow?
Export all blocked IPs
To use our Lists via DNS.
The rbldnsd-Zone-Files
To get only the last addedd IPs
Here the lists of the attackers IP addresses of the last 48 hours pro service or all addresses for downloading. *
The lists contain one line per IP address.
The lists are generated every 30 minutes new.
The files are compressed (gzip) from the web server (nginx). Windows editor, vi, and so can open the file so directly. Depending on the software used, possibly a unpack is necessary.
The files are as they are and use at your own risk.
Typ: all
Last change: T20:44:05 +0200 (CEST)Counts: 13410
Description: All IP addresses that have attacked one of our customers/servers in the last 48 hours.
Download: http://lists.blocklist.de/lists/all.txt
MD5: de662fe333786d41da64cd8544d0282b
Typ: ssh
Last change: T20:44:05 +0200 (CEST)Counts: 724
Description: All IP addresses which have been reported within the last 48 hours as having run attacks on the service SSH.
Download: http://lists.blocklist.de/lists/ssh.txt
MD5: 1e3ae7c2b4d055d7c8557c76a76a9f11
Typ: mail
Last change: T20:44:06 +0200 (CEST)Counts: 5810
Description: All IP addresses which have been reported within the last 48 hours as having run attacks on the service Mail, Postfix.
Download: http://lists.blocklist.de/lists/mail.txt
MD5: ccc0dd92457e6517f86226ebb9015552
Typ: apache
Last change: T20:44:07 +0200 (CEST)Counts: 339
Description: All IP addresses which have been reported within the last 48 hours as having run attacks on the service Apache, Apache-DDOS, RFI-Attacks.
Download: http://lists.blocklist.de/lists/apache.txt
MD5: 0dbb6d4670e1305f09c61761e8999886
Typ: imap
Last change: T20:44:07 +0200 (CEST)Counts: 170
Description: All IP addresses which have been reported within the last 48 hours for attacks on the Service imap, sasl, pop3.....
Download: http://lists.blocklist.de/lists/imap.txt
MD5: 285ff3cc1bf70a89f527588d3519c4c1
Typ: ftp
Last change: T20:44:07 +0200 (CEST)Counts: 57
Description: All IP addresses which have been reported within the last 48 hours for attacks on the Service FTP.
Download: http://lists.blocklist.de/lists/ftp.txt
MD5: 2492421239a8a2334b1104e8c699c9c4
Typ: sip
Last change: T20:44:07 +0200 (CEST)Counts: 33
Description:
Download: http://lists.blocklist.de/lists/sip.txt
MD5: 4535d78a0c78e25d9bc758f3ad2d5059
Typ: bots
Last change: T20:44:11 +0200 (CEST)Counts: 6364
Description: All IP addresses which have been reported within the last 48 hours as having run attacks attacks on the RFI-Attacks, REG-Bots, IRC-Bots or BadBots (BadBots = he has posted a Spam-Comment on a open Forum or Wiki).
Download: http://lists.blocklist.de/lists/bots.txt
MD5: c3a984056bc27966ff8e305bee2b7c02
Typ: strongips
Last change: T20:44:18 +0200 (CEST)Counts: 34
Description:
Download: http://lists.blocklist.de/lists/strongips.txt
MD5: 00656dbd2d1a3a148494728a5c196c97
Typ: ircbot
Last change: T20:44:18 +0200 (CEST)Counts: 0
Description:
Download: http://lists.blocklist.de/lists/ircbot.txt
MD5: d41d8cd98f00b204e9800998ecf8427e
To get only the last added IP-Addresses you can use:
https://api.blocklist.de/getlast.php?time=xx:xxtime = unixtime
OR
time = hh:ii
Policy:
In the Export-/DNS-Lists was all IP-Addresses listen there was attack one of our systems/partners in the last 48 hours and not used the Delist-Link.
* And two AS-Networks manually, because there are only a Spamer without Customers.