blacklist-ips.conf 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202
  1. # EDIT THIS FILE AS YOU LIKE TO ADD OR REMOVE ANY BAD IP ADDRESSES OR IP RANGES YOU WANT TO BLOCK ###
  2. ##############################################################################
  3. # ___ __ #
  4. # / _ | ___ ___ _____/ / ___ #
  5. # / __ |/ _ \/ _ `/ __/ _ \/ -_) #
  6. # /_/ |_/ .__/\_,_/\__/_//_/\__/ #
  7. # __/_/ __ ___ __ ___ __ __ #
  8. # / _ )___ ____/ / / _ )___ / /_ / _ )/ /__ ____/ /_____ ____ #
  9. # / _ / _ `/ _ / / _ / _ \/ __/ / _ / / _ \/ __/ '_/ -_) __/ #
  10. # /____/\_,_/\_,_/ /____/\___/\__/ /____/_/\___/\__/_/\_\\__/_/ #
  11. # #
  12. ##############################################################################
  13. # This is merely an example and gets auto included as since Version 2.2017.05 introduced on 2017-04-19
  14. # This file must exist on your system or Apache will fail a reload due to a missing file
  15. # For all intents and purposes you can delete everything inside this file and leave it
  16. # completely blank if you do not want your Apache Blocker to do any blocking of bad IP's
  17. Require not ip 104.223.37.150
  18. Require not ip 104.5.92.27
  19. Require not ip 107.150.63.170
  20. Require not ip 109.236.83.247
  21. Require not ip 137.74.49.205
  22. Require not ip 137.74.49.208
  23. Require not ip 146.0.74.150
  24. Require not ip 148.251.54.44
  25. Require not ip 149.56.151.180
  26. Require not ip 149.56.232.146
  27. Require not ip 150.70.0.0/16
  28. Require not ip 151.80.27.90
  29. Require not ip 151.80.99.90
  30. Require not ip 151.80.99.91
  31. Require not ip 154.16.199.144
  32. Require not ip 154.16.199.34
  33. Require not ip 154.16.199.48
  34. Require not ip 154.16.199.78
  35. Require not ip 158.69.142.34
  36. Require not ip 166.62.80.172
  37. Require not ip 173.212.192.219
  38. Require not ip 173.234.11.105
  39. Require not ip 173.234.153.106
  40. Require not ip 173.234.153.30
  41. Require not ip 173.234.175.68
  42. Require not ip 173.234.31.9
  43. Require not ip 173.234.38.25
  44. Require not ip 176.126.245.213
  45. Require not ip 178.238.234.1
  46. Require not ip 185.35.63.128
  47. Require not ip 185.100.87.238
  48. Require not ip 185.115.125.99
  49. Require not ip 185.119.81.11
  50. Require not ip 185.119.81.63
  51. Require not ip 185.119.81.77
  52. Require not ip 185.119.81.78
  53. Require not ip 185.130.225.65
  54. Require not ip 185.130.225.66
  55. Require not ip 185.130.225.83
  56. Require not ip 185.130.225.90
  57. Require not ip 185.130.225.94
  58. Require not ip 185.130.225.95
  59. Require not ip 185.130.226.105
  60. Require not ip 185.153.197.103
  61. Require not ip 185.159.36.6
  62. Require not ip 185.183.96.33
  63. Require not ip 185.47.62.199
  64. Require not ip 185.62.190.38
  65. Require not ip 185.70.105.161
  66. Require not ip 185.70.105.164
  67. Require not ip 185.85.239.156
  68. Require not ip 185.85.239.157
  69. Require not ip 185.86.13.213
  70. Require not ip 185.86.5.199
  71. Require not ip 185.86.5.212
  72. Require not ip 185.92.72.88
  73. Require not ip 185.93.185.11
  74. Require not ip 185.93.185.12
  75. Require not ip 188.209.52.101
  76. Require not ip 190.152.223.27
  77. Require not ip 191.96.249.29
  78. Require not ip 192.69.89.173
  79. Require not ip 193.201.224.205
  80. Require not ip 195.154.183.190
  81. Require not ip 195.229.241.174
  82. Require not ip 200.7.105.43
  83. Require not ip 210.212.194.60
  84. Require not ip 216.218.147.194
  85. Require not ip 220.227.234.129
  86. Require not ip 23.253.230.158
  87. Require not ip 23.89.159.176
  88. Require not ip 31.170.160.209
  89. Require not ip 45.32.186.11
  90. Require not ip 45.76.21.179
  91. Require not ip 46.249.38.145
  92. Require not ip 46.249.38.146
  93. Require not ip 46.249.38.148
  94. Require not ip 46.249.38.149
  95. Require not ip 46.249.38.150
  96. Require not ip 46.249.38.151
  97. Require not ip 46.249.38.152
  98. Require not ip 46.249.38.153
  99. Require not ip 46.249.38.154
  100. Require not ip 46.249.38.159
  101. Require not ip 51.255.172.22
  102. Require not ip 5.39.218.232
  103. Require not ip 5.39.219.24
  104. Require not ip 5.39.222.18
  105. Require not ip 5.39.223.134
  106. Require not ip 54.213.16.154
  107. Require not ip 54.213.9.111
  108. Require not ip 62.210.146.49
  109. Require not ip 62.210.88.4
  110. Require not ip 65.98.91.181
  111. Require not ip 69.162.124.237
  112. Require not ip 69.64.147.24
  113. Require not ip 72.8.183.202
  114. Require not ip 77.247.178.191
  115. Require not ip 77.247.178.47
  116. Require not ip 77.247.181.219
  117. Require not ip 78.31.184.0/21
  118. Require not ip 78.31.211.0/24
  119. Require not ip 79.110.128.17
  120. Require not ip 79.110.128.63
  121. Require not ip 79.110.128.252
  122. Require not ip 79.110.128.128
  123. Require not ip 80.87.205.10
  124. Require not ip 80.87.205.11
  125. Require not ip 85.17.230.23
  126. Require not ip 85.17.26.68
  127. Require not ip 91.185.190.172
  128. Require not ip 91.200.12.0/22
  129. Require not ip 91.200.12.15
  130. Require not ip 91.200.12.49
  131. Require not ip 91.200.12.91
  132. Require not ip 92.222.66.137
  133. Require not ip 93.104.209.11
  134. Require not ip 93.158.200.103
  135. Require not ip 93.158.200.105
  136. Require not ip 93.158.200.115
  137. Require not ip 93.158.200.124
  138. Require not ip 93.158.200.126
  139. Require not ip 93.158.200.66
  140. Require not ip 93.158.200.68
  141. Require not ip 93.238.202.44
  142. # Cyveillance / Qwest Communications / PSINET
  143. # *******************************************
  144. # I am extensively researching this subject - appears to be US government involved
  145. # and also appears to be used by all sorts of law enforcement agencies. For one they
  146. # do not obey robots.txt and continually disguise their User-Agent strings. Time will
  147. # tell if this is all correct or not.
  148. # For now see - https://en.wikipedia.org/wiki/Cyveillance
  149. # IMPORTANT UPDATE ON Cyveillance / Qwest Communications !!!
  150. # **********************************************************
  151. # I have done a lot of research on Cyveillance now and through monitoring my logs I know
  152. # for sure what companies are using them and what they are actually looking for.
  153. # My research has led me to understand that Cyveillance services are used by hundreds
  154. # of companies to help them dicsover theft of copyrighted materials like images, movies
  155. # music and other materials. I personally believe a lot of block lists who originally recommended
  156. # blocking Cyveillance have done so to protect their torrent or p2p sites from being scanned.
  157. # I personally have now unblocked them as image theft is a big problem of mine but if you
  158. # do want to allow Cyveillance you can simply modify the entries in the below from "Require not ip" to "Require ip"
  159. # Getty Images is one such company who appears to use Cyveillance to help monitor for copyright theft.
  160. # Use this section at YOUR OWN RISK, you may block some legitimate networks but after many hours of
  161. # Research this is now the completely updated list of all IP ranges IPV4 and IPV6 owned Qwest Communications
  162. # PSINET and Cyveillance.
  163. # IMPORTANT NOTE: If you really want to keeps bot and things out of certain parts of your web site
  164. # Rather implement a comlex Google Re-Captcha to reach sections of your sites and for people to be able
  165. # to access download links. Google Re-Captcha with images is too complex for any bot.
  166. # Only uncomment the lines below if you want to block these ranges otherwise rather just leave it as is.
  167. #Require not ip 4.17.135.32/27
  168. #Require not ip 38.0.0.0/8
  169. #Require not ip 63.144.0.0/13
  170. #Require not ip 65.112.0.0/12
  171. #Require not ip 65.192.0.0/11
  172. #Require not ip 65.213.208.128/27
  173. #Require not ip 65.222.176.96/27
  174. #Require not ip 65.222.185.72/29
  175. #Require not ip 206.2.138.0/23
  176. #Require not ip 208.71.164.0/22
  177. # BERKELEY SCANNER
  178. # ****************
  179. # The Berkeley University has a scanner testing all over the web sending a complex
  180. # payload an expecting a reply from servers who are infected or who just respond to such
  181. # a payload. The payload looks similar to this
  182. # "$\xC9\xE1\xDC\x9B+\x8F\x1C\xE71\x99\xA8\xDB6\x1E#\xBB\x19#Hx\xA7\xFD\x0F9-"
  183. # and is sometime VERY long. You may have noticed this in your logs.
  184. # I support research projects and all my servers respond with an error to this type of
  185. # string so I do not block them but if you want to block just uncomment the following line
  186. # or email them asking them not to scan your server. They do respond.
  187. # Visit http://169.229.3.91/ for more info
  188. # If you really do want to block them uncomment the line below.
  189. #Require not ip 169.229.3.91