[TOOL] IP BlackHole

edited April 2023 in General

Just a new project. Nothing big.

IP.blackhole.monster

Is an IP blacklist that uses multiple sensors to identify network attacks (e.g. SSH brute force) and spam incidents. All reports are evaluated and in case of too many incidents the responsible IP holder is informed to solve the problem.

P.S.: If you have some idle servers or can sponsor us a server, please mail us at [email protected]

https://github.com/BlackHoleMonster/IP-BlackHole

๐Ÿšซ ALL IPs:
https://ip.blackhole.monster/blackhole

๐Ÿšซ TODAY IPs:
https://ip.blackhole.monster/blackhole-today

How to use?

To get a fresh and ready-to-deploy auto-ban list of "bad IPs" you can run:

sudo su
apt-get -qq install iptables ipset
ipset -q flush blackhole
ipset -q create blackhole hash:net
for ip in $(curl --compressed https://ip.blackhole.monster/blackhole-today 2>/dev/null | grep -v "#" | grep -v -E "\s[1-2]$" | cut -f 1); do ipset add blackhole $ip; done
iptables -D INPUT -m set --match-set blackhole src -j DROP 2>/dev/null
iptables -I INPUT -m set --match-set blackhole src -j DROP

Comments

  • how do you release the hash:net list safely? last time I tried similar method using maltrail, it refuses to drop the list until i reboot the machine.

    after some times if the stuck list is too big, it'll start screwing with your network (timed outs, not responding, packet dropped in the interface). but this is a non-issue if the machine has more than 256mb RAM

    Fuck this 24/7 internet spew of trivia and celebrity bullshit.

  • @Encoders
    https://ipset.netfilter.org/ipset.man.html

    flush [ SETNAME ]
    Flush all entries from the specified set or flush all sets if none is given.

  • This looks like a nice project. Good luck!

    Talistech.com โ€” ICT Consultancy and NVMe web hosting solutions.

  • edited April 2023

    @Talistech
    thanks :) soon we will add live tcpdump output from attacked servers listening on every ports, just to see whats happening in real-time

  • cool project, will use the 'All IPs' on my pfsense with pfblockerng. What update interval do you suggest 8hrs, 24hrs, weekly?

  • @xyphos10
    i am glad you like it :)

    about that update, hmm, ip lists are re-generated every 20min. so depend on you how much freq. you wanna update

  • Update:
    Added #5 new server - ๐Ÿ‡ต๐Ÿ‡ฑ Poland

    :)

  • i liked this if you continue updates and the fact you use ipset, its clean.
    Thank you B)

  • edited April 2023

    @ehab
    enjoy, yeah i will be keeping this updating, adding more server too :)

    btw footer also have dynamic generated image with stats:

  • Version: 0.3-ฮฒeta ๐Ÿ”ฅ

    • Added special live tcpdump page to see in realtime whats going on (for now its output from one server)

  • wow nice project!!

    LumanexAI: Our in-house AI model for free ๐Ÿš€

  • looks very interesting, thanks

  • Version: 0.4-ฮฒeta ๐Ÿ”ฅ
    Added #6 new server - ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands

  • Version: 0.5-ฮฒeta ๐Ÿ”ฅ
    Added #7 new server - ๐Ÿ‡ฉ๐Ÿ‡ช Germany

  • Whats the best way to use your script? By making a cron job and running it daily by updating the daily-IP addresses?

    Talistech.com โ€” ICT Consultancy and NVMe web hosting solutions.

  • edited April 2023

    @Talistech
    that depend how you want to use it, if you want to block only daily ips only then as the example in first post - run it in cron and you are set for daily ips.

    also you can parse the ips as you want, for example transform them in to iptables rules or ip route add blackhole ...

  • @xVPSx said:
    @Talistech
    that depend how you want to use it, if you want to block only daily ips only then as the example in first post - run it in cron and you are set for daily ips.

    also you can parse the ips as you want, for example transform them in to iptables rules or ip route add blackhole ...

    I'll try that out, thanks!

    Talistech.com โ€” ICT Consultancy and NVMe web hosting solutions.

  • Version: 0.6-ฮฒeta ๐Ÿ”ฅ
    Added #8 new server - ๐Ÿ‡ธ๐Ÿ‡ฌ Singapore

  • @xVPSx said:
    Version: 0.6-ฮฒeta ๐Ÿ”ฅ
    Added #8 new server - ๐Ÿ‡ธ๐Ÿ‡ฌ Singapore

    <3

  • Version: 0.7-ฮฒeta ๐Ÿ”ฅ
    Added #9 new server - ๐Ÿ‡ฆ๐Ÿ‡บ Australia

  • Version: 0.8-ฮฒeta ๐Ÿ”ฅ
    Added #10 new server - ๐Ÿ‡ซ๐Ÿ‡ท France

  • 2023 April 16
    Version: 0.15-ฮฒeta ๐Ÿ”ฅ
    - Added #11 new server - ๐Ÿ‡ฌ๐Ÿ‡ง Great Britain
    - Added #12 new server - ๐Ÿ‡จ๐Ÿ‡ฆ Canada
    - Added #13 new server - ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
    - Added #14 new server - ๐Ÿ‡บ๐Ÿ‡ธ United States

    2023 April 15
    Version: 0.14-ฮฒeta ๐Ÿ”ฅ
    - When searching now the output is sorted properly, newest attacks at the top

    2023 April 15
    Version: 0.13-ฮฒeta ๐Ÿ”ฅ
    - When searching for IP you can now see which server is sponsored
    - Clicking to the sponsor favicon will take you to our page /sponsors

    2023 April 15
    Version: 0.12-ฮฒeta ๐Ÿ”ฅ
    - Created new page for Sponsors
    -> /sponsors
    - Got our first sponsor - IncogNet.io
    -> Server #13 - ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands
    -> Server #14 - ๐Ÿ‡บ๐Ÿ‡ธ United States

    2023 April 15
    Version: 0.11-ฮฒeta ๐Ÿ”ฅ
    - Page ASNs moved to IPs
    -> /ips
    - Created new page for ASNs
    -> /asns
    -> Possible to filter the ASN by name to get all the IPs logged

    2023 April 15
    Version: 0.10-ฮฒeta ๐Ÿ”ฅ
    - Created this changelog page ๐Ÿ˜Š
    -> /changelog

    2023 April 15
    Version: 0.9-ฮฒeta ๐Ÿ”ฅ
    - Upgraded the main server
    -> 2 CPU cores to 4 CPU cores
    -> 4 GB RAM to 8 GB RAM
    -> HDD to SSD
    - Search for IP should also be little faster

  • 2023 April 16
    Version: 0.16-ฮฒeta ๐Ÿ”ฅ

    Got our second sponsor - Albanian Hosting SH.P.K.
    -> Server #15 - ๐Ÿ‡ฆ๐Ÿ‡ฑ Albania
    

    Thanks goes out to @AlbaHost :)

  • 2023 April 18
    Version: 0.20-ฮฒeta ๐Ÿ”ฅ

    • Removed /tcpdump old page
    • Created new TcpDump page
      -> Logging the network to see what is going on.
      -> tcpdump.blackhole.monster
    • Added #1 new server (tcpdump) - ๐Ÿ‡ฑ๐Ÿ‡บ Luxembourg
    • Added #2 new server (tcpdump) - ๐Ÿ‡ฆ๐Ÿ‡ฟ Azerbaijan
    • Added #3 new server (tcpdump) - ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine
  • 2023 April 19
    Version: 0.21-ฮฒeta ๐Ÿ”ฅ
    - Added new IP blacklist (list contains only IP from attack not older than 15 days)
    -> /blackhole-15days
    - Added new IP blacklist (list contains only IP from attack not older than 30 days)
    -> /blackhole-30days

  • Added your blacklist into my csf firewall, let's see how much records can my vm handle

  • 2023 April 21
    Version: 0.22-ฮฒeta ๐Ÿ”ฅ
    - Added #16 new server - ๐Ÿ‡ฒ๐Ÿ‡ฉ Moldova
    - Added #17 new server - ๐Ÿ‡ฆ๐Ÿ‡ฒ Armenia
    - Added #18 new server - ๐Ÿ‡ต๐Ÿ‡ฑ Poland

  • ConfigServer Security and Firewall (CSF)

    Edit CSF blocklist file:
    nano /etc/csf/csf.blocklists
    
    Navigate to the end of the file and append the following:
    # IP.blackhole.monster blacklist
    IPBLACKHOLE|3600|0|https://ip.blackhole.monster/blackhole-today
    
    After you finish editing the file, save it and restart CSF and lfd using:
    csf -ra
    
    Check the log file to ensure that the blacklist was added correctly:
    cat /var/log/lfd.log
    
  • 2023 April 23
    Version: 0.23-ฮฒeta ๐Ÿ”ฅ
    - Added #19 new server - ๐Ÿ‡ฎ๐Ÿ‡ณ India
    - Added #20 new server - ๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa

  • 2023 April 25
    Version: 0.25-ฮฒeta ๐Ÿ”ฅ
    - Added #21 new server - ๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico
    - Added #22 new server - ๐Ÿ‡ง๐Ÿ‡ท Brazil
    - Added #23 new server - ๐Ÿ‡จ๐Ÿ‡ฑ Chile
    - Added #24 new server - ๐Ÿ‡ณ๐Ÿ‡ฌ Nigeria

    2023 April 24
    Version: 0.24-ฮฒeta ๐Ÿ”ฅ
    - Created main page - blackhole.monster

  • 2023 May 14
    Version: 0.26-ฮฒeta ๐Ÿ”ฅ
    - Got our third sponsor - Hjelm Enterprises AB
    -> Server #25 - ๐Ÿ‡ธ๐Ÿ‡ช Sweden

  • 2023 May 18
    Version: 0.27-ฮฒeta ๐Ÿ”ฅ
    - Got our fourth sponsor - PT Atharva Telematika Persada
    -> Server #26 - ๐Ÿ‡ฎ๐Ÿ‡ฉ Indonesia

  • 2023 May 21
    Version: 0.28-ฮฒeta ๐Ÿ”ฅ
    - Got our fifth sponsor - Virtury Cloud
    -> Server #27 - ๐Ÿ‡ต๐Ÿ‡ฐ Pakistan

  • 2023 November 30
    Version: 0.29-ฮฒeta ๐Ÿ”ฅ

    • Removed servers:
      -> #1 - ๐Ÿ‡ท๐Ÿ‡ด Romania
      -> #5 - ๐Ÿ‡ต๐Ÿ‡ฑ Poland
      -> #7 - ๐Ÿ‡ฉ๐Ÿ‡ช Germany
      -> #8 - ๐Ÿ‡ธ๐Ÿ‡ฌ Singapore
      -> #9 - ๐Ÿ‡ฆ๐Ÿ‡บ Australia
      -> #10 - ๐Ÿ‡ซ๐Ÿ‡ท France
      -> #11 - ๐Ÿ‡ฌ๐Ÿ‡ง Great Britain
      -> #12 - ๐Ÿ‡จ๐Ÿ‡ฆ Canada
      -> #15 - ๐Ÿ‡ฆ๐Ÿ‡ฑ Albania
      -> #16 - ๐Ÿ‡ฒ๐Ÿ‡ฉ Moldova
      -> #17 - ๐Ÿ‡ฆ๐Ÿ‡ฒ Armenia
      -> #18 - ๐Ÿ‡ต๐Ÿ‡ฑ Poland
      -> #19 - ๐Ÿ‡ฎ๐Ÿ‡ณ India
      -> #20 - ๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa
      -> #21 - ๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico
      -> #22 - ๐Ÿ‡ง๐Ÿ‡ท Brazil
      -> #23 - ๐Ÿ‡จ๐Ÿ‡ฑ Chile
      -> #24 - ๐Ÿ‡ณ๐Ÿ‡ฌ Nigeria
      -> #26 - ๐Ÿ‡ฎ๐Ÿ‡ฉ Indonesia

    If anyone out there can sponsor little server i would be super happy :)

  • edited November 2023

    hello, any special specs? i have some anually i got from providers from here.

    even a nat will work?

  • If anyone out there can sponsor little server i would be super happy :)

  • Couldn't this be done without giving you the full server? I would help putting it in all my idlers listening for all unused well-known ports/services.

    How about a docker image with network ports redirected to it, like https://github.com/NetWatch-team/SSH-AttackPod did for SSH.
    Bummer that project looks very stale right now, I was hoping other services like that would come up.

  • how you detect and list ips?

    colonelserver | Cloud services, VPS and Dedicated Server provider | Contact
    Accepting European, US and crypto payments

  • To get a fresh and ready-to-deploy auto-ban list of "bad IPs"

    Dรฉjร  vu

    I was there during the early crowdsec days

    Got bootstrapped as a community project and then one day it had critical mass and a pricing page

  • How to deploy this with UFW?

Sign In or Register to comment.