stamparm / ipsum

Daily feed of bad IPs (with blacklist hit scores)
The Unlicense
1.58k stars 145 forks source link

Level List from x to 9 #8

Closed m-holler closed 4 years ago

m-holler commented 4 years ago

I use your IP List´s from 1.txt to 8.txt in my firewall, and it works great. Can you please create one file with 1x.txt with all the bad ip´s obove 8 ????? This would be realy great.

stamparm commented 4 years ago

A) There is really no need to do this. List 8.txt currently contains 48 IPs. One for (e.g.) 9.txt would contain maybe 10 B) I believe that you've missed the point of lists. You should pick one list and stick to it AND not use all lists. For example, list 2.txt contains all IPs that are appearing in 2 or more blacklists, which means that it also contains all the entries from 3.txt, 4.txt, 5.txt, etc.

m-holler commented 4 years ago

Hi Miroslav,

thanks a lot for your answer, and it make sense. 😊 But now i have a Problem, if i take list 1, and i will do this, my Firewall has a Problem that i can only Import 130000 IP´s In one File. 😊 Maybe you can split #1.txt in more Parts 1a.txt with 100000 IP´s and 1b.txt ……. If you can do this automaticaly, this would be great. By the way, i use a Fortigate, and this list would be great for other Fortigateusers as well.

Have a nice evening, greets, Martin. Martin Holler [m-holler@live.de]

Von: Miroslav Stamparmailto:notifications@github.com Gesendet: Montag, 24. Februar 2020 11:38 An: stamparm/ipsummailto:ipsum@noreply.github.com Cc: m-hollermailto:m-holler@live.de; Authormailto:author@noreply.github.com Betreff: Re: [stamparm/ipsum] Level List from x to 9 (#8)

A) There is really no need to do this. List 8.txt currently contains 48 IPs. One for (e.g.) 9.txt would contain maybe 10 B) I believe that you've missed the point of lists. You should pick one list and stick to it AND not use all lists. For example, list 2.txt contains all IPs that are appearing in 2 or more blacklists, which means that it also contains all the entries from 3.txt, 4.txt, 5.txt, etc.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/stamparm/ipsum/issues/8?email_source=notifications&email_token=AJ447JEJG7DUBGOPMDDNORTREOPUBA5CNFSM4KZZCS32YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEMXKGNY#issuecomment-590258999, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AJ447JHHRAJ7TGF5FVUCH4LREOPUBANCNFSM4KZZCS3Q.

stamparm commented 4 years ago

Please don't use 1.txt for such purposes. I would say that something like 3.txt (currently contains 11721 IPs) is more appropriate. Also, it would considerably lower the risk of false-positives