Settings

Theme

Check for malicious IPs using DNS

ipshield.dev

26 points by shivam-dev a year ago · 13 comments

Reader

tok1 a year ago

I am not familiar with Firehol, so I might be missing something, but isn't this already solved in a (potentially) more powerful, mature and standardized way by DNS RPZ (Response Policy Zones, [1])? Well-established resolvers like Unbound fully support integrating multiple block lists (like oisd.nl, energized.pro, abuse.ch, etc), keeping them up-to-date via zone transfers or HTTPS download, see [2].

[1] https://www.isc.org/rpz/ [2] https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering...

  • shivam-devOP a year ago

    Yeah, it’s just a toy project, nothing much! Thanks for the references though, I’ll read it up :)

b112 a year ago

But why? Firehol seems entirely dead at this point.

Take a look at the bug reports on github, on the IP address change metric, and research the people behind it. They seem to have moved on. It's not being maintained, and still pulls from defunct lists, dead lists, and so on.

  • shivam-devOP a year ago

    I found no better alternative as the source of data TBH. Open to suggestions. This is a toy project anyway, It won’t be exhaustive for sure and I don’t expect anyone to use it in production.

    Thanks for the info though, I didn’t know firehol was in such a bad state

fragmede a year ago

Interesting. Why not offer the db as files to download for faster local lookup though? That's what geoip databases do (for a price).

  • b112 a year ago

    firehol seems to be unmaintained, running on auto, see my other post. However just google 'firehol', and you can download the lists.

    (Such lists are trivial to use with ipset + linux, for example.)

  • shivam-devOP a year ago

    As someone else pointed out, yeah its free to download anyway.

not_a_dane a year ago

dig 199.195.253.247 @ipshield.dev +short

Apparently, Tor Exit nodes are under safe category.

  • shivam-devOP a year ago

    Oops, the list isn’t meant to be exhaustive, just a toy project I built for fun. I really don’t expect anyone to use it

navigate8310 a year ago

I would rather have a API than digging around to find out abusive IPs

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection