From 8486ac40536c0933b22008e3c2de93026bb15f8d Mon Sep 17 00:00:00 2001 From: openhands Date: Thu, 24 Sep 2026 23:22:27 +0200 Subject: [PATCH] feat(security): add darklist.de source and raise the blocklist cap to 1M --- .env.example | 2 +- README.md | 4 ++-- scripts/blocklists-sync.sh | 2 ++ 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/.env.example b/.env.example index 837020c1..ebed6b34 100644 --- a/.env.example +++ b/.env.example @@ -135,7 +135,7 @@ CROWDSEC_LAPI_API_KEY= # Expiration for each blocklist decision (re-synced keeps them fresh). #CROWDSEC_BLOCKLIST_DURATION=24h # Combined cap per sync (safety valve against excessive decisions). -#CROWDSEC_BLOCKLIST_MAX_DECISIONS=250000 +#CROWDSEC_BLOCKLIST_MAX_DECISIONS=1000000 # Comma-separated IPs/CIDRs that a sync must always skip (allowlist). #CROWDSEC_BLOCKLIST_ALLOW=1.2.3.4,10.0.0.0/8 diff --git a/README.md b/README.md index f435d125..8c2caa03 100644 --- a/README.md +++ b/README.md @@ -848,8 +848,8 @@ bash cms security blocklists Defaults: Spamhaus DROP/EDROP, DShield, CINS, Greensnow, StopForumSpam, Binary Defense, blocklist.de, Emerging Threats, BruteForceBlocker, abuse.ch -Feodo/SSLBL, Botvrij, IPsum, Firehol ipsets and Tor exit nodes -(25 sources). URLhaus was removed because its `text_online` feed lists URLs, +Feodo/SSLBL, Darklist, Botvrij, IPsum, Firehol ipsets and Tor exit nodes +(26 sources). URLhaus was removed because its `text_online` feed lists URLs, not IPs; a malformed token in it could otherwise expand into a bogus huge CIDR. The validator only accepts whole-line bare IPs or proper CIDRs, enforces sane prefix bounds and drops reserved/private/loopback space, so a diff --git a/scripts/blocklists-sync.sh b/scripts/blocklists-sync.sh index 32eaa3ff..6f66e016 100644 --- a/scripts/blocklists-sync.sh +++ b/scripts/blocklists-sync.sh @@ -27,6 +27,8 @@ DEFAULT_SOURCES=( "https://feodotracker.abuse.ch/downloads/ipblocklist.txt" "https://sslbl.abuse.ch/blacklist/sslipblacklist.txt" "https://www.botvrij.eu/data/ioclist.ip-dst.raw" + # Live SSH/spam attackers (last 48h), bare IPs only + "https://www.darklist.de/raw.php" # Aggregated threat intel "https://raw.githubusercontent.com/stamparm/ipsum/master/levels/3.txt" "https://raw.githubusercontent.com/stamparm/ipsum/master/levels/2.txt"