
This site aggregates, analyzes, compares and documents publicly available IP Feeds, with a focus on attacks and abuse. It uses IP lists and related data provided and maintained by their respective owners (mentioned together with each IP list), IP-to-country geolocation data provided by (GeoLite2),, (Lite) and, javascript chart libraries provided by, comments engine provided by, social media sharing buttons provided by, the HTML, CSS and JS framework bootstrap, the bootstrap-table component, icons provided by and it uses several services provided by github. For the final result, it utilizes IP data and web services provided by third parties. This site is a single static page, with all its data uploaded as static JSON and CSV files every time an IP List is updated. IP Lists are a property of their maintainers. This site is provided as-is, without any warranty. Both are part of FireHOL, which is provided under GPL v2, so you are free to get, use, adapt and re-distribute. The data on this page are automatically generated using FireHOL's update-ipsets.sh (for downloading the lists from their sources and generating the data for this site), which utilizes iprange (for comparing and manipulating IP lists). Pay also attention to the 75% ( most probable) and the 90% ( expected max) marks.Ģ015-2017 Costa Tsaousis, for FireHOL a firewall for humans!. This is the average age of the IPs in the list.

Normally, longer ages should only be a small part of the list's size. In the chart below we show the exact age of the IPs currently listed. Since the world is full of dynamic IP users, false positives is the biggest problem of blocklist / blacklists. Many don't and almost all lists have exceptions that do not follow the announced rules.Ī false positive is in place when an IP that was properly detected and added to the list, was released and re-used by another person, before being unlisted from the list.

Many lists announce the duration they list IPs. Once an IP is listed, it remains listed for a pre-defined amount of time, unless it matches the criteria again, in which case its expiration time is refreshed. an attack or abuse is detected originated from the IP in question). Most lists include IPs that match some criteria (e.g.
