blacklist-ips.conf 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. # EDIT THIS FILE AS YOU LIKE TO ADD OR REMOVE ANY BAD IP ADDRESSES OR IP RANGES YOU WANT TO BLOCK ###
  2. # This is merely an example and gets auto included as since Version 2.2017.05 introduced on 2017-04-19
  3. # This file must exist on your system or Apache will fail a reload due to a missing file
  4. # For all intensive purpose you can delete everything inside this file and leave it
  5. # completely blank if you do not want your Apache Blocker to do any blocking of bad IP's
  6. Require not ip 104.223.37.150
  7. Require not ip 104.5.92.27
  8. Require not ip 107.150.63.170
  9. Require not ip 109.236.83.247
  10. Require not ip 137.74.49.205
  11. Require not ip 137.74.49.208
  12. Require not ip 146.0.74.150
  13. Require not ip 148.251.54.44
  14. Require not ip 149.56.151.180
  15. Require not ip 149.56.232.146
  16. Require not ip 150.70.0.0/16
  17. Require not ip 151.80.27.90
  18. Require not ip 151.80.99.90
  19. Require not ip 151.80.99.91
  20. Require not ip 154.16.199.144
  21. Require not ip 154.16.199.34
  22. Require not ip 154.16.199.48
  23. Require not ip 154.16.199.78
  24. Require not ip 158.69.142.34
  25. Require not ip 166.62.80.172
  26. Require not ip 173.212.192.219
  27. Require not ip 173.234.11.105
  28. Require not ip 173.234.153.106
  29. Require not ip 173.234.153.30
  30. Require not ip 173.234.175.68
  31. Require not ip 173.234.31.9
  32. Require not ip 173.234.38.25
  33. Require not ip 176.126.245.213
  34. Require not ip 178.238.234.1
  35. Require not ip 185.100.87.238
  36. Require not ip 185.115.125.99
  37. Require not ip 185.119.81.11
  38. Require not ip 185.119.81.63
  39. Require not ip 185.119.81.77
  40. Require not ip 185.119.81.78
  41. Require not ip 185.130.225.65
  42. Require not ip 185.130.225.66
  43. Require not ip 185.130.225.83
  44. Require not ip 185.130.225.90
  45. Require not ip 185.130.225.94
  46. Require not ip 185.130.225.95
  47. Require not ip 185.130.226.105
  48. Require not ip 185.153.197.103
  49. Require not ip 185.159.36.6
  50. Require not ip 185.47.62.199
  51. Require not ip 185.62.190.38
  52. Require not ip 185.70.105.161
  53. Require not ip 185.70.105.164
  54. Require not ip 185.85.239.156
  55. Require not ip 185.85.239.157
  56. Require not ip 185.86.13.213
  57. Require not ip 185.86.5.199
  58. Require not ip 185.86.5.212
  59. Require not ip 185.92.72.88
  60. Require not ip 185.93.185.11
  61. Require not ip 185.93.185.12
  62. Require not ip 188.209.52.101
  63. Require not ip 190.152.223.27
  64. Require not ip 191.96.249.29
  65. Require not ip 192.69.89.173
  66. Require not ip 193.201.224.205
  67. Require not ip 195.154.183.190
  68. Require not ip 195.229.241.174
  69. Require not ip 210.212.194.60
  70. Require not ip 216.218.147.194
  71. Require not ip 220.227.234.129
  72. Require not ip 23.253.230.158
  73. Require not ip 23.89.159.176
  74. Require not ip 31.170.160.209
  75. Require not ip 45.32.186.11
  76. Require not ip 45.76.21.179
  77. Require not ip 46.249.38.145
  78. Require not ip 46.249.38.146
  79. Require not ip 46.249.38.148
  80. Require not ip 46.249.38.149
  81. Require not ip 46.249.38.150
  82. Require not ip 46.249.38.151
  83. Require not ip 46.249.38.152
  84. Require not ip 46.249.38.153
  85. Require not ip 46.249.38.154
  86. Require not ip 46.249.38.159
  87. Require not ip 51.255.172.22
  88. Require not ip 5.39.218.232
  89. Require not ip 5.39.219.24
  90. Require not ip 5.39.222.18
  91. Require not ip 5.39.223.134
  92. Require not ip 54.213.16.154
  93. Require not ip 54.213.9.111
  94. Require not ip 62.210.146.49
  95. Require not ip 62.210.88.4
  96. Require not ip 65.98.91.181
  97. Require not ip 69.162.124.237
  98. Require not ip 69.64.147.24
  99. Require not ip 72.8.183.202
  100. Require not ip 77.247.178.191
  101. Require not ip 77.247.178.47
  102. Require not ip 77.247.181.219
  103. Require not ip 78.31.184.0/21
  104. Require not ip 78.31.211.0/24
  105. Require not ip 80.87.205.10
  106. Require not ip 80.87.205.11
  107. Require not ip 85.17.230.23
  108. Require not ip 85.17.26.68
  109. Require not ip 91.185.190.172
  110. Require not ip 91.200.12.0/22
  111. Require not ip 91.200.12.15
  112. Require not ip 91.200.12.49
  113. Require not ip 91.200.12.91
  114. Require not ip 92.222.66.137
  115. Require not ip 93.104.209.11
  116. Require not ip 93.158.200.103
  117. Require not ip 93.158.200.105
  118. Require not ip 93.158.200.115
  119. Require not ip 93.158.200.124
  120. Require not ip 93.158.200.126
  121. Require not ip 93.158.200.66
  122. Require not ip 93.158.200.68
  123. # Cyveillance / Qwest Communications
  124. # **********************************
  125. # I am extensively researching this subject - appears to be US government involved
  126. # and also appears to be used by all sorts of law enforcement agencies. For one they
  127. # do not obey robots.txt and continually disguise their User-Agent strings. Time will
  128. # tell if this is all correct or not.
  129. # For now see - https://en.wikipedia.org/wiki/Cyveillance
  130. # IMPORTANT UPDATE ON Cyveillance / Qwest Communications !!!
  131. # **********************************************************
  132. # I have done a lot of research on Cyveillance now and through monitoring my logs I know
  133. # for sure what companies are using them and what they are actually looking for.
  134. # My research has led me to understand that Cyveillance services are used by hundreds
  135. # of companies to help them dicsover theft of copyrighted materials like images, movies
  136. # music and other materials. I personally believe a lot of block lists who originally recommended
  137. # blocking Cyveillance have done so to protect their torrent or p2p sites from being scanned.
  138. # I personally have now unblocked them as image theft is a big problem of mine but if you
  139. # do want to block Cyveillance you can simply modify the entries in the block below from "0" to "1"
  140. # Getty Images is one such company who appears to use Cyveillance to help monitor for copyright theft.
  141. # If you really do want to block them change all the "Allow from" statements below to "deny from".
  142. #Allow from 38.100.19.8/29
  143. #Allow from 38.100.21.0/24
  144. #Allow from 38.100.41.64/26
  145. #Allow from 38.105.71.0/25
  146. #Allow from 38.105.83.0/27
  147. #Allow from 38.112.21.140/30
  148. #Allow from 38.118.42.32/29
  149. #Allow from 63.144.0.0/13
  150. #Allow from 65.112.0.0/12
  151. #Allow from 65.213.208.128/27
  152. #Allow from 65.222.176.96/27
  153. #Allow from 65.222.185.72/29
  154. # BERKELEY SCANNER
  155. # ****************
  156. # The Berkeley University has a scanner testing all over the web sending a complex
  157. # payload an expecting a reply from servers who are infected or who just respond to such
  158. # a payload. The payload looks similar to this
  159. # "$\xC9\xE1\xDC\x9B+\x8F\x1C\xE71\x99\xA8\xDB6\x1E#\xBB\x19#Hx\xA7\xFD\x0F9-"
  160. # and is sometime VERY long. You may have noticed this in your logs.
  161. # I support research projects and all my servers respond with an error to this type of
  162. # string so I do not block them but if you want to block just uncomment the following line
  163. # or email them asking them not to scan your server. They do respond.
  164. # Visit http://169.229.3.91/ for more info
  165. # If you really do want to block them change all the "Allow from" statement below to "deny from".
  166. #Allow from 169.229.3.91