Herr Bischoff's Spam Blocklists(ipbl.herrbischoff.com)
ipbl.herrbischoff.com
Herr Bischoff's Spam Blocklists
https://ipbl.herrbischoff.com/
5 comments
I am ignorant, how would one use these lists?
I use such lists on my server's router and Firewall to block incoming connections from those IPs and bad ASNs, including with geographic blocking. Less traffic, smaller attack surface, less trouble.
As others implied, it doesn't make much sense to be afraid from port scans from the Kiwi Farms servers (maybe if you host ActivityPub services and want to block any Mastodon servers associated with them, or something like that). A lot of threats come from the big cloud providers networks, which are not so good at keeping out threat actors.
As with DShield (a similar collection by SANS Internet Storm Center), I have a problem with the TOR Exit Node category. It seems rather like 'every IP that has ever used TOR'.
As others implied, it doesn't make much sense to be afraid from port scans from the Kiwi Farms servers (maybe if you host ActivityPub services and want to block any Mastodon servers associated with them, or something like that). A lot of threats come from the big cloud providers networks, which are not so good at keeping out threat actors.
As with DShield (a similar collection by SANS Internet Storm Center), I have a problem with the TOR Exit Node category. It seems rather like 'every IP that has ever used TOR'.
You'd probably setup your own DNS server like Adguard or pihole and add these lists to your blocklist config
These lists are for firewalls. How you get the list on your firewall and keep it updated depends on the firewall itself. Not all firewalls support importing a list of CIDRs or IPs.
>TOREXIT
No it's not a list of exits but a list of ALL Tor relays. Please don't use this there is an official list [0] just use that if you need to.
Maybe the others are better maintained but this leaves a very bad impression.
>AS397702 1776 Solutions
Nice virtue signaling. This list is described as opionated so I guess it's fine.
[0] https://check.torproject.org/torbulkexitlist
No it's not a list of exits but a list of ALL Tor relays. Please don't use this there is an official list [0] just use that if you need to.
Maybe the others are better maintained but this leaves a very bad impression.
>AS397702 1776 Solutions
Nice virtue signaling. This list is described as opionated so I guess it's fine.
[0] https://check.torproject.org/torbulkexitlist
It is described as opinionated but is introduced with "they need to be blocked by default." The idea that you need to block entire ASNs from your network based on the content some of their IPs host is ridiculous.
Imagine banning an entire apartment block from entering your store based on the opinions some of the tenants hold. Using arbitrary lists like these devalues small, independent companies in favor of large corporations that are too big to be blacklisted. A requirement to police content disproportionately burdens smaller service providers, while mega corps essentially get to dictate what is allowed because no one dares to lock them out.
I cannot support far-right values like these.
Imagine banning an entire apartment block from entering your store based on the opinions some of the tenants hold. Using arbitrary lists like these devalues small, independent companies in favor of large corporations that are too big to be blacklisted. A requirement to police content disproportionately burdens smaller service providers, while mega corps essentially get to dictate what is allowed because no one dares to lock them out.
I cannot support far-right values like these.
I've just checked his blacklist against the BADASN list. Less than 30 IPs of the 6862 IPs on the IPBL list are from those BADASNs. On the other hand Cogent has over 700, Amazon over 600 and Microsoft over 200.
Which makes the insinuation that those ASNs "need" to be blocked even more ridiculous.
What exactly is virtue signalling about blocking 1776 Solutions? Should I know them?
They host and defend an alt-right forum famous for harassing, doxxing, stalking and swatting people. They've been celebrating mass-shooters, and trying to drive transgender people to suicide. The guy who runs this defends this as "free speech".
It’s operated by Joshua Moon, the owner of Kiwi Farms. It has been the target of deplatforming by various services and Tier-1 ISPs.
Is that ASN list potentially libellous?
Not so much the list but what is said in addition.
Not so much the list but what is said in addition.
[deleted]
I'd be extremely cautious with straight up blocking at AS level, especially with a plain list like this.
I ran it through our AS database and it seems to be extremely hit or miss. Some check out and fall well within the top 5% of most reported AS while others (for instance AS43097) we have simply never seen at all which makes it unlikely to be so malicious that it should be blocked on sight.
I ran it through our AS database and it seems to be extremely hit or miss. Some check out and fall well within the top 5% of most reported AS while others (for instance AS43097) we have simply never seen at all which makes it unlikely to be so malicious that it should be blocked on sight.